#modules

1 messages Β· Page 234 of 1

cloud urchin
#

when i took the ADCS a few weeks ago, i went to the specterops blog posts and found they are up to like esc14 or something by now. i wonder if they'll add those too.

#

or is it 13?

fathom pendant
#

Wasn't there a recent update or windows blog post about mitigating one of the esc things?

valid spear
#

Yeah ESC14 is out now as well, but I'm specifically referring to Bloodhound-CE integrating ADCS support without needing to use the fork

cloud urchin
#

adcs support was there when i used bloodhound for the module?

#

the edges show the attack path

valid spear
#

I'm referring to Bloodhound-CE, distinct from the forked version of bloodhound that was used in the current module

next bronze
#

I doubt it will be added anytime soon, it's new and many changes are being made, they'd had to keep updating the module when something changes

#

just read the blog and set up a lab yourself 4Head

fathom pendant
#

They also generally don't update modules with new stuff unless absolutely required... I think they learned from the push back of "thick client" in attacking common applications

valid spear
#

Ah, that's a shame. Thanks

fathom pendant
#

ADCS is a tier 3 yeah?

cloud urchin
#

yeah

fathom pendant
#

It's also likely they're working on an advanced pentest cert with the current ADCS module, so hesitant to make changes ofc

shell ore
#

hey, facing a problem in AD attacks module, cross-forest from windows section, i got the hash for TGS for mssqlsvc but i cant crack it why? it gives a no hashes are loaded in john and hashcat, any idea why? πŸ˜…

next bronze
full nimbus
#

Hi folks, i'm on the windows privilege escalation module, section "Interacting with Users". "Using the techniques in this section obtain the cleartext credentials for the SCCM_SVC user." Anyone can point how to get the right shell to drop the scf file , I'm trying procmon but can't see any share

shell ore
#

1 sec

#

Custom charsets are not supported in attack mode 0 (straight). hashcat error

next bronze
#

you should use a dictionary for mode 0, what's the hashcat command?

shell ore
#

i had an error in the command, tho weird it didnt work in john, cuz i usually use john more

shell ore
#

in john it was saying no hashes loaded for some reason

soft cedar
full nimbus
next bronze
full nimbus
#

but just found out with || net share || πŸ™‚

#

thx

valid viper
#

I'm trying to login to the Antak shell on the Shells and Payloads module...

#

It's not taking the htb-student username htb-student password?

next bronze
#

look at the source code

valid viper
#

Oh yeah I was looking at the screenshot wrong XD

#

Thanks my friend.

cedar forum
#

hey has anyone noticed that H I V E M I N D says... thing?

fathom pendant
#

Yeah?

cedar forum
#

what is that πŸ’€

rustic sage
dim wolf
#

what is this poll

rustic sage
#

it's a survey on whether or not you'd like to have a video walkthrough for the module you're on in case you ever get stuck

dim wolf
#

i don't think they'll ever add video walkthroughs

fathom pendant
rustic sage
#

they will if we keep asking lol

fathom pendant
#

They've stated multiple times that they won't

rustic sage
#

or add something like the writeups we get for the retired labs

fathom pendant
#

That's also not happening

rustic sage
#

why not

fathom pendant
#

Because the academy content isn't retired lol

rustic sage
#

i'm not asking for answers to exams

fathom pendant
#

It's considered active content under their content guidelines

#

That's basically what a guide would do

rustic sage
#

you basically have the answers to every section of the exam in the modules

fathom pendant
#

And the point of the modules is to be able to get the answers without needing a guide

#

Or the modules themselves are essentially a guide

rustic sage
#

a video or walkthrough would help you see if you're understanding things correctly

#

or make sure that you are doing it correctly and there is something wrong with the lab

fathom pendant
#

You can find video walk-throughs of the techniques

rustic sage
#

yes

fathom pendant
#

Which isn't happening

rustic sage
#

not siler but gold

fathom pendant
#

And I stg if you say "well I'm paying for it"

#

Everyone is paying for the content, I had purchased the cubes before winning my sub.

#

I find the content mostly sufficient, and things I don't understand are easily researchable

#

Or you're given additional reading within the module to help understand

#

If you're watching someone else do it, why bother? The point is a majority of people would just copy/paste the commands from the video without actually learning

#

And htb doesn't want that

rustic sage
#

you copy and paste from the module itself though

shut quest
#

The content is a great guide on the basics you should know. Any more content and they'd have to charge way more

fathom pendant
#

There's already enough people c/p the example without modifying anything

rustic sage
#

the only thing you modify at this level is the ip and port kek

fathom pendant
fathom pendant
#

Sometimes you have to modify certain arguments within the command e.g. an ldap query

#

Moo you really gotta stop talking out your ass consistently

shut quest
fathom pendant
#

Not to mention: if HTB doesn't want to do it- then they really don't gotta justify themselves on it

#

They're a company, and it devalues the overall experience if they just cater to the people who can't read or can only rely on videos to learn

#

If you need a video for a technique, you can google it and it's likely ippsec has a video with that technique in it for some box

rustic sage
#

i can recall one time when i was doing everything right, watched a video, and the same commands that i was typing the person in the video typed, but the only difference was that my commands didn't work but his did

#

this was on academy content and i think that video got taken down

fathom pendant
#

If the video got taken down then it broke content guidelines

rustic sage
#

the video was immensely helpful for me to continue forward and ensure that i'm understanding everything correctly

fathom pendant
#

Htb has a restriction on content for modules of tier1 and higher

cloud urchin
#

the thing is, htb isn't going to teach you every single thing about hacking, no one can. this role requires a lot of research on your own, reading command synax for tools you've never seen before, etc, i think it gives a good balance of providing the info required and also making you think for yourself.

rustic sage
fathom pendant
#

Applying critical thinking is essential to being a good hacker

dim wolf
#

then you're perfectly capable of watching a video of the same technique being taught

cloud urchin
#

some modules simply due to the nature of them will be cut & paste, but you still need to understand the material. same with the higher level stuff, you probably can't copy/paste most of it, but you need to understand the fundamentals

fathom pendant
#

The technique would be the same/similar just the target and output would not be

#

Which if you can apply critical thinking, you can translate a --> b

rustic sage
#

no but they just have the best ctf stuff i've come across

#

just 3

cloud urchin
#

they also have the best training lol

dim wolf
#

me pivoting into a rabbit hoel

rustic sage
#

over the wire is one and i have to look on my main pc for the other ones

fathom pendant
#

The only complaint I have for htb is sometimes they're just info dense

rustic sage
#

i think vuln hub

fathom pendant
#

Which can be good/bad

shut quest
cloud urchin
#

proving grounds, thm, sans, pnpt, nothing close to htb

fathom pendant
#

But it's just parsing what the "what if" scenarios are from the "do this" parts

#

If only they could ban the stupid

rustic sage
dim wolf
#

don't worry they are making new certification HTB Certified Discord Member

fathom pendant
#

I can definitely think of a few

#

Certified Discord Moderator

dim wolf
#

no

cloud urchin
#

i'd be happy if they just made new members go through #welcome before coming here lol

dim wolf
#

it needs to have a different name

fathom pendant
tepid path
#

Hmm

rustic sage
#

nobody reads any of that it's like reading the eula or the terms before signing up lmao

dim wolf
#

Step 1: Complete the Discord User Job Role Path

#

Step 2: Take the exam

fathom pendant
#

Or they read it and say "I can't access #general "

#

Impossible with discord my dude

rustic sage
#

who completed the xss module?

cloud urchin
#

i can only imagine what kind of cesspool that would breed

fathom pendant
#

You'd need to have a layered bot for that that takes text and spits it back out

#

Ntm the inability to moderate

#

And for discord to operate as a public server they need to have moderation

#

Especially since children can access this server

dim wolf
#

i think my idea is best

#

you need to be certified in order to access the entire htb server

shut quest
#

And that's how you get unofficial crud to start, no and this is off topic

dim wolf
#

i'm only kidding

rustic sage
#

in xsstrike how do you know which payload is going to work without having to manually check? (is there a way to make the program run and then sort by what worked and what didn't?) every payload i checked manually ends up not executing

cloud urchin
#

burpsuite?

#

you can automate the payload with it maybe

rustic sage
#

i'll use burpsuite i guess... i was hoping to use xsstrike since that is what they were using in the module

#

i would have probably finished the module already if i was using burp lol

shut quest
#

The xxs discovery section?

rustic sage
#

yeah the phishing section one lol

cloud urchin
#

man, the pivoting module keeps freezing my vm when i launch metasploit rev shells

rustic sage
#

the pivoting module sucked for me too

#

i think that's the one i was watching a video walkthrough on and where all of my commands were identical to the video

#

i don't exactly remember

shut quest
#

Put all the query/params in the url and let it rip, it will give you the answer

rustic sage
#

in burp or xsstrike?

shut quest
#

xsstrike

rustic sage
#

every payload i have copied from xsstrike ends up not executing

#

i'm thinkingn of just doing what i know and use burp and a random github list

shut quest
#

You don't need to test the payload it generates

cloud urchin
#

is the freezing with metasploit revshells in the pivoting module just my vm? it spikes my network usage and the vm goes to a crawl and no longer accepts inputs/freezes

rustic sage
#

i remember the module telling me that i do need to manually check

rustic sage
shut quest
#

to verify the above payload by testing it on one of the previous exercises.

rustic sage
#

one time i had so many sessions open that i needed to retart the vm

shut quest
#

That was for the output they generated for that to be used on the previous section

rustic sage
#

oh i see

#

so basically grab any random payload i get from xsstrike and use it to create the phishing payload

#

brb gonna try that

shut quest
#

Wut?

rustic sage
#

so like any one of these put the phishing stuff in there somewhere and put it in the text box and i should be good to go

shut quest
#

Phishing section != Xss discovery section

rustic sage
#

that one lol

heavy edge
#

im runnong out of colors for my notes OMEGALUL

cloud urchin
#

you have like 16 million colors to choose from

dim wolf
#

9 colors?

#

impressive

rustic sage
shut quest
#

That WHOLE section is a walkthrough, just read it and you'd be done with it already

rustic sage
#

the only problem i'm having is the payloads not executing lol

heavy edge
#

just execute it 4Head

rustic sage
#

i haven't used burp but i'm gonna

shut quest
#

Just follow the section, slap the url in and mash that enter button, ???, profit

#

I'm failing to understand your difficulty finding the payload when they give it to you

rustic sage
#

Xsstrike has payloads that aren’t working for me for whatever reason

#

Everything was working in the previous sections so I’m not sure why they stopped working

shut quest
#

If you read the whole page before taking any action you'll notice they don't mention xsstrike and they give you the payload

rustic sage
#

Thank you

wanton idol
#

bro fr skipped and rushed LMAO

fathom pendant
shut quest
#

Only took stating the payload is provided three times

cloud urchin
#

does the skill assessment for the pivot module rely heavily on meterpreter listeners?

#

my vm just keeps freezing using it

fathom pendant
#

same can be said for all the pivoting sections

cloud urchin
#

well there are specific examples and a whole section on using meterpreter

fathom pendant
#

Yes

#

Iirc the meterpreter section asks meterpreter specific questions

shut quest
#

You can even choose not to pivot, but I'd look into what's causing it to freeze up.

cloud urchin
#

meterpreter is lol

fathom pendant
#

Meterpreter/msfconsole is dumb

shut quest
cloud urchin
#

yeah not really sure how to troubleshoot it beyond what's causing it. my linux troubleshooting skills aren't great, and the vm straight up freezes except for a few mouse skips. it no longer accepts inputs so i have to restart the whole box, can't really troubleshoot it when it doesn't respond.

#

if i get stuck i'll just try on bare metal or the pwnbox

shut quest
#

It's a vm you can at least look at the host to see what's going on

green girder
#

Not specifically modules relate but it seems that I can't post in the community-help section because after I did the first time I get "the original message was deleted" and also the MEE6 bot msgs me "don't send the same message over and over again!" even though I posted once. I tried again after deleting post and same issue.

woven zenith
#

CBBH- Broken Auth: Predictable Reset Token
-I've got my script to run and it goes through all the tokens for htbadmin and it finishes without matching or giving flag.
-I'm assuming my time is off so: the webpage time is UTC time and my pwnbox is an hour ahead, pretty sure I'm supposed to do the time from the webpage and covert it to epoch *1000

  • (ex. 11:26:54pm on webpage --> 24 hr time= 23:26:54--> epoch=1712806014 *1000= 1712806014000)
    -Can I get some help on this, as my scripts are just running and then ending with no flag
valid viper
#

This is a general FYI/Announcement for anyone using Parrot...

#

Basically if you update Parrot right now it will screw up your Burp install. This fixes it.

fathom pendant
gritty breach
#

Can anybody help with broken authentication-predictable reset token

noble oxide
#

i am a new user

#

hello evry boddy

green girder
fathom pendant
shell vessel
#

I just started using Linux

#

Cd

#

Cd /

#

Cd

#

Cd ..

#

Hmm it's not working

#

Pwd

#

Whoami

dim wolf
#

what

#

is this a bot

shell vessel
#

My commands aren't working. I just started using Linux.

#

I'm not a bot

fathom pendant
#

Discord isn't linux

shell vessel
#

Oh ok. Where's my terminal then?

fathom pendant
#

In your linux vm

shell vessel
#

I just started using Linux

fathom pendant
#

Or machine

shell vessel
#

I installed bare metal

fathom pendant
#

Ctrl+shit+T should be the keyboard shortcut to open terminal iirc

shell vessel
#

Oh ok nice.

fathom pendant
#

Otherwise usually it's pinned to the taskbar/dock

shell vessel
#

Linux so much better than windows. It's a shame I just found out about the Linux world.

fathom pendant
#

There's pros and cons depending on what you wanna do

shell vessel
#

I just want to use my little 4gb ram PC in peace. Windows was working the shit out of my PC for no reason.... And God the bloatware...

wanton idol
#

gaming on linux sadglas

fathom pendant
#

I believe when you go through the OOBE if you set the language to English universal or w/e then it doesn't install a lot of bloat but it's still a pain

green girder
graceful mortar
cold rivet
#

anyone else have this issue in active directory guided lab part 2? don't really know what's happening here, logged in with the provided creds (htb-student_adm: Academy_student_DA!) and verified that the computer is in the domain. also opening active directory with admin just doesnt work at all.

cold rivet
alpine umbra
#

hi after some times

quasi wave
#

do most people here find the footprinting module to be confusing?

#

is it a slower module the first time you do it? Its taken me a little while to get through.

#

I'm in the last few sections. Actually, I'm currently taking notes on Windows Remote Desktop Protocol section of it.

brazen saffron
#

Well I found myself by testing one bye one and searching something interesting... but I did not find a link.

patent oak
#

Hello peeps, when you say to do AEN blind, does it mean not to read anything at all? Or just the questions?

#

Also what do you guys use to have a fresh Kali install for each test. If you even do.

soft cedar
soft cedar
#

fresh install = build the tools.

rustic sage
patent oak
vital adder
grand portal
#

Hii everyone. Is there anyone who has done the module "introduction to digital forensics"?

solar zodiac
#

Hi everyone πŸ™‚ . I'm stuck on the XSS via websockets exercise in the Modern Web Attacks module. Could anyone possibly help me out πŸ™‚

marsh echo
#

hello i have to write on an existing file i confess i don't really know how to do it i'm stuck on the skill assessement of attack common service easy

marsh echo
#

I checked f* on all the privileges in the database

solar zodiac
cloud urchin
#

sure

cloud urchin
soft cedar
#

^

#

how do you know that is the correct webroot path?

marsh echo
#

I find the path but how to find the flag you have to use the cmd c=dir C:/

#

??

soft cedar
#

how did you find the path?

cloud urchin
#

btw, every single person needs to see this because you guys keep blinding me: Burp -> Settings -> User Interface -> Display -> Theme: Dark

brazen saffron
marsh echo
soft cedar
#

alright, then you're gtg

marsh echo
#

but there are a lot rabbit holes with lots of useless services for easy skill

brazen saffron
soft cedar
fathom pendant
#

And using double quotes not single

cloud urchin
#

just finished the pivoting module.. is ||172.16.10.*|| just a red herring?

brazen saffron
cloud urchin
#

ya

#

i was going to try and pivot till i found the final flag on the box i was already on, but there was a 4th network

soft cedar
#

if we found the creds for the DC then it would work.

fathom pendant
#

Some shells and configs are weird with grep and regexp

#

At least I think it's -e or I'm thinking something else

marsh echo
soft cedar
#

by the way.

pseudo kiln
#

I cannot ssh into the target from either VPN and pwnbox, I already reseted it, what can I do ?

fathom pendant
#

What module and section, and is ssh running on the target/the intended method of authentication

pseudo kiln
#

linux fundamentals, working with files and directories, I would assume it is intended

#

in the morning it was working fine for other sections, took a break, returned and now nothing, does not respond to ping ssh nmap etc

unborn pilot
pseudo kiln
#

yes did that, VPN is UP, but the issue not related to VPN, machine is not responding from Pwnbox either

unborn pilot
#

which region your vpn is ? I will try in my side to check if it is only you who has an issue with it

pseudo kiln
#

UK

#

good point guess I could try to switch to Germany

fathom pendant
#

If not, then there's other reasons that your system isn't connecting to the target

#

Also what is your ssh command?

pseudo kiln
#

got it, so it does not allow both vpn and pwnbox to interact at the same time

fathom pendant
#

Correct, because the pwnbox connects to the same vpn config

unborn pilot
#

i have an issue too

brazen saffron
fathom pendant
#

So it receives the sane ip

unborn pilot
#

i tried UK vpn and it dosn't work

pseudo kiln
twilit epoch
#

Hello, im new here. I would like to ask if the interactive pwnbox should be able to ping the target system? I am not using any vpn

pseudo kiln
#

pwnbox works after taking down vpn, so maybe there is something with UK

fathom pendant
unborn pilot
#

pwn box

fathom pendant
#

There's EU, and US

unborn pilot
fathom pendant
#

Yes pwnbox is not the same as vpn

unborn pilot
#

Or I mistaken i still need to use the ovpn file with pwnbox ?

twilit epoch
#

I am currently on SG Pwnbox location.

fathom pendant
fathom pendant
unborn pilot
#

well, i can't ping the machine then

fathom pendant
#

Us-academy-[1,2,3] or eu-academy-[1,2]

unborn pilot
#

i will connect my vm with kali and try with the ovpn file

brazen saffron
pseudo kiln
#

ah I see vpn server is diff from pwnbox location

fathom pendant
#

Yes

twilit epoch
fathom pendant
pseudo kiln
#

got it working, thanks guys, I think having both pwnbox and vpn connection on VM is what prevented the connection

fathom pendant
#

It causes network collisions

#

As the vpn config will assign both machines the same ip on the vpn network

pseudo kiln
#

interesting, I initially assumed that pwnbox is part of the internal subnet, good to know

patent oak
#

Is it supposed to be hard to nmap the WPE assessment 1 box? Or is it goosed?

brazen saffron
fathom pendant
#

Or [[:alpha:]] for just a-zA-Z

brazen saffron
fathom pendant
#

Also alnum encompasses :upper:

fathom pendant
#

grep -E "^\[\[:alnum:\]\]\{2,12\}$"

fathom pendant
#

does it need to start with an upper/lowercase character?

#

because here's what your current grep looks for; any uppercase laters then any of those matches that have any alphanumeric characters (so basically a nonsense sort) then for any that start with any character that's between 2 and 12 characters long

patent oak
#

I just spent a considerable amount of time trying to do command injection with Linux commands on a Windows machine. In the Windows Priv ESC module blaze

#

Learn from my mistakes people

graceful mortar
fringe urchin
patent oak
#

I was like whoami, great. Now ls ...hmm l's' ... Whyyyyyy???

soft cedar
fathom pendant
#

most binary commands in linux are ported to PS

#

well "ported"

#

(they're just aliased)

#

like wget is just an iwr alias

patent oak
#

Ah so that's why they sometimes work

soft cedar
#

sometimes ?

fathom pendant
#

a few minor differences with PS is that it really wants you to specify an outfile

harsh sonnet
#

Hello,
I'm stuck at the beginning of the assignment from "WINDOWS PRIVILEGE ESCALATION : Print Operators"
I compiled UACme and used the appropriate "key" for the command but i can't get it to work.
Any hints pls so i can advance ?

soft cedar
harsh sonnet
rustic sage
#

hallo where can i find help

unborn pilot
brazen saffron
#

And minimum 3* (I was doing something wrong, I was saying 2 but it's free) characters.

#

I started with : Qwertyuiop12345!@#$%, no need special character.

#

One or more numbers :

#

Q1 works:

#

Need a capital letter :

brazen saffron
#

😭

#

Well I'll try them.

silent sequoia
#

PasswordAttacks - Pass The Ticket Module

Not sure why this is happening but when rubeus uses the /ptt option without relying on the kirbi file generated by mimikatz it fails to perform listing on a target despite the tgt being cached, as well as being a tgt of a domain admin, kinda sus. However, doing a /ptt with a kirbi file gives no problems when trying to list a target. Can I get some help on this, please? Thanks πŸ™‚

brazen saffron
nova pollen
#

yo anybody knows a machine that focuses of Azure AD?

sly moon
#

Anyone else having trouble xfreerdp'ing to the host in "Windows Privilege Escalation Windows Server"? It won't let me spin up pwnbox on this either even though it says I have an instance. I can ping the host ok but xfreedrp gives me "ransport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]"

next bronze
#

<@&861185840277487616>

rustic sage
#

No available instances for labs. What’s going on

patent oak
sly moon
sly moon
rustic sage
#

I’m down

#

Ca works

#

East coast is fucked for some reason

heavy edge
#

are they finally fixing their garbage instances

sly moon
rustic sage
#

Try that one just got on

sly moon
brazen saffron
#

Date : 2024-04-11 03:17:00pm
1712805420000 ms
1712805420 s

No hash :
htbadmin1712805421000
htbadmin1712805419000

Hashs :

  • c7bc56455c6c12227f20953f10efa218
  • cbfb2d01d1c158d4d7420e54f4fae996

Is this normal if after trying my two hashs it's wrong ? https://academy.hackthebox.com/module/80/section/779

I have use this algo to find the hash for htbadmin, but it tell us that there is -+1 seconds between the generation of htbuser hash & htbadin hash, so I added 1s or removed 1s to have 2 possibilities, but no one worked.

 
<?php
function generate_reset_token($username) {
  $time = intval(microtime(true) * 1000);
  $token = md5($username . $time);
  return $token;
}
brazen saffron
#

Well so we need to use the python script given :(.

limpid hemlock
#

Hey I thr remote reverse port forwarding with ssh section on pivoting and portforwarding module

#

I need to rdp into windows internal server to download a payload I uploaded to the Ubuntu serverBut I try to do xfreerdp and connect and it fails any idea what to do?

limber river
next bronze
#

no only till 11

limber river
next bronze
#

there's also 12

#

13 and 14 are very new, only announced couple of months ago

limber river
#

ig still worth it tho

buoyant escarp
#

Password Attacks Medium Lab
i cant get any service by nmap scans, tried all ports in UDP and TCP, Full TCP, SYN
disabled Ping. I already reset the target to see if it is just bugging. can someone tell me what scan type u succeeded with?

next bronze
cedar yew
#

Module - Attacking Common Service - Ftp attack

is this normal almost 1 hours

buoyant escarp
# wide river I just use - - open

im not even getting filtered ones, despite open
like all ports i scan are closed, i wanna know what exact scan you guys used, to check if the Lab is buggying or its my fault

fathom pendant
mint trout
fathom pendant
#

Didn't notice the -f

#

Lol

#

I'm used to all args being before the IP

brazen saffron
#

Tried with ZAP as well to be faster :

brazen saffron
#

But it's about this you think?

#

Because juste before I typped something wrong it did not give me this error.

#

I will try to set the valid one.

#

Mb bc I sent a request and valid it so the password changed before my fuzz, thanks :).

azure fog
#

Does anybody else experience issues with machines performance now? I'm doing an assessment for the Modern Web Exploitation Techniques and the machine response is super slow. It's just impossible to do anything. I restarted the machine, it helped for a couple of minutes but now everything is freezing again. (No, I'm not running scanners)

fathom pendant
#

Try changing vpn regions

azure fog
fathom pendant
#

Did you try the US regions?

azure fog
#

Trying it right now

azure fog
#

Thanks for the advice anyway

buoyant escarp
#

Password Attacks Medium Lab

||i used crackmapexec against the smbserver, found the user and his password
logged in via smbclient ad downloaded the zip file
stuck at the part where i try to crack the hash of the zip file

is this a rabbit hole? should i focus more on the ssh servie and brute it even more?||

fathom pendant
#

You're on the right path also delete the password and user part as it's still a spoiler (spoiler text does nothing)

buoyant escarp
#

which path of the two i mentioned is the one i should focus on πŸ˜„ brute ssh or offline cracking the zip hash

shut quest
#

brute force is rarely an option, not when you have something to crack πŸ˜‰

#

plus bruteforcing ssh is painfully slow

buoyant escarp
fathom pendant
#

Also: it's likely the pw may not even be in the list πŸ˜‰

brazen saffron
topaz zenith
#

I'm on Windows Escalation Privileges in Academy the "Communication with Processes" part. How am I supposed to get accesschk.exe onto the target machine? I've tried starting up a python http server but doesn't seem to have python on it either.

heavy edge
#

there are many ways

#

py server smb server scp xfreerdp with /disk

fathom pendant
heavy edge
#

πŸ™„

#

the point is, there are many, many ways to xfer files

#

even IEX/IWR

soft cedar
brazen saffron
topaz zenith
#

Thank you @soft cedar

fringe urchin
#

Isnt that crackstation?? I didnt know you can "crack" cookies with itsusge

sly kelp
#

i never cracked a cookie with that

#

only hashes

fringe urchin
#

Sameshruge

#

Cookies and hash not the same thing

brazen saffron
#

I know but maybe because it's an hash idk lol.

#

There is cookie as base64 for ex.

#

Just testing.

sly kelp
amber ore
#

For me the best way is to go with browser and burpsuite, surf each page and click each button. And then look for parameters in burpsuite in history tab.

buoyant escarp
#

PW Attacks Medium
i need a hint for cracking this zip hash, do i need to make a mutated list?

crystal tree
#

Has anyone done the Whitebox Attacks module? I'm stuck on the Client-side Prototype Pollution question and would appreciate some help. I got a simple XSS payload to work (an alert to show up), and am now trying to construct a payload that will actually perform the attack (i.e. elevate my privileges so that I can access the Admin panel). This is what I have so far, am I on the right path?

||/profile.php?proto[src][]=data:,$.get('/admin.php?promote=2')||

brazen saffron
buoyant escarp
worldly pagoda
#

Which channel is for pro labs?

shut quest
fathom pendant
#

If you read and follow #welcome you can find it

#

At least you asked kek

fringe urchin
tawdry osprey
#

is there also a chan for help on the academy?

shut quest
#

this is it fabu

tawdry osprey
#

in here?

fringe urchin
fathom pendant
#

Yes

shut quest
#

RIGHT HERE

tawdry osprey
#

AH !

#

my quest comes to an end πŸ™‚

fathom pendant
brazen saffron
tawdry osprey
#

damn my super long message disappears in here for some reason, mee6 is warning me

fathom pendant
#

If your message is getting deleted then it's because it's very long and automod sees it as spam

tawdry osprey
#

ok i ll type it again -_-

fathom pendant
#

If you read and follow #welcome you'll be able to do long posts and add images

#

Its an anti-spam and troll measure

worldly pagoda
fringe urchin
tawdry osprey
shut quest
#

It's how the mods keep us from getting steam cards -.-'

fringe urchin
#

If on mobile copy before you send it againkek

fringe urchin
fathom pendant
fringe urchin
#

If you think its gonna be long

fathom pendant
fathom pendant
fringe urchin
fathom pendant
#

Which usually indicates a misunderstanding of the source material or an xy problem

fringe urchin
#

Do higher ranks get bigger message count?

fathom pendant
#

@tawdry osprey also, unsure if you did so in your og post. But be sure to include Module Name and Section names

fathom pendant
fringe urchin
#

Ah so it can happen to everyoneFeelsBadMan

fathom pendant
#

It's literally just getting verified/linked has it gated

fringe urchin
shut quest
tawdry osprey
fathom pendant
#

You don't really need to output it to a .txt file

#

Also you want to sort -u

tawdry osprey
fathom pendant
#

Otherwise sort just lists alphabetically

#

-u removes dupes

tawdry osprey
#

i have the same result : 20

#

curl $url > htb.txt && cat htb.txt | tr " " "\n" | cut -d"'" -s -f2 | sort -u | awk '/inlanefreight.com/ {print $0}' | wc -l

brazen saffron
tawdry osprey
#

it skips the /index.php/* and /* for some reason

tawdry osprey
fathom pendant
#
tawdry osprey
#

thank you sir

amber ore
#

.

fathom pendant
limber cobalt
#

oh okey, so when i get to the final question, what do you suggest to dont look with periferical view the answer? xD

brazen saffron
#

Read the flag is not a problem?

#

You don't care?

limber cobalt
#

actually i do care

#

anyway, its okey

fathom pendant
#

No there's no way to hide or remove progress from a completed question/module

brazen saffron
#

I just did not notice the button "remmeber me".

fathom pendant
#

That would cause many issues in the long-run

brazen saffron
#

Like an idiot. 😭

tacit bay
#

is the citrix breakout module supposed to be so painfully slow?

shut quest
brazen saffron
#

?

full nimbus
#

Hi folks, ii'm on the windows privesc module, on the citrix section

#

i'm not able to copy files to citrix, i got the cmd.exe and userflag, but can't seem to use smb or anything to my kali

full nimbus
#

if I can avoid typing powerup I'd be fine πŸ˜„

patent oak
#

Guys can I ask about CLSID with JuicyPotato? I'm just wondering if they have different permissions. Like if you find one that lets the program run, are you reet? Or do they have different privs? Trying to suss out if my command is wrong or could I just need to keep trying CLSIDs

limber river
patent oak
patent oak
#

I think I'll go eat a potato in celebration

tacit bay
full nimbus
soft cedar
full nimbus
#

this has to be the most painful module ever πŸ˜„

#

anyway, I kept this one for the end πŸ˜‰

mint trout
#

im about to buy the gold annual package; looks like I get access to t0-3. it also seems like some courses reward you cubes..? does that mean if i want to do a t4 i need to either buy cubes or save up reward cubes?

limber river
mint trout
#

is 1000 reachable?

limber river
#

imo tier 3 modules are more interesting execpt the OSINT module

mint trout
#

seems like gold + vip labs should be more than enough

shut quest
#

If you do all the modules in the gold annual, at this time you should be able to unlock all the t4 modules. that's a lot of learn'n to do in a year

old vector
#

I’m on windows file transfer methods and connected to target through rdp. When trying to use powershell it won’t work for file downloads because the network on target says there is no internet

cloud urchin
#

are you trying to transfer from your vm connected to the vpn?

old vector
#

Im not on the vpn and I’m not having trouble with those kind of transfers it’s IEX transfers

#

And anything related to downloading files off internet

#

On target machine not host

cloud urchin
#

where are you trying to transfer the file from

old vector
#

Following the screen from this long list of examples raw.githubuser….

shut quest
#

why not try the methods to/from the windows box to yours?

old vector
#

I don’t have windows

#

I’m on a windows transfer method

cloud urchin
#

so you're trying to download a file directly from the Internet? if your victim box doesn't have network connectivity you'll need to download it to your machine which does have internet and transfer it over

#

you aren't going to be able to download from powershell if the computer has no internet access

#

you can download using powershell on a webserver you host on your attacker box, for example python -m http.server

#

then use the PS command to download from your kali box

old vector
#

Ok

shut quest
#

write that one down, you'll use it a lot, you can specify the port by adding the port number to the end python3 -m http.server 8000

fringe urchin
#

All the techniques mentioned in the module doesnt mean they all work on that specific target

#

But its more "one of the ways"
There are aswell more ways not covered by the module

old vector
#

Was about to say it says β€œfileless” transfer kind of defeats the purpose to download a file transfer a file to be fileless but ok

fathom pendant
#

Iwr and stuff can still get a file and execute from memory and not download to disk

#

Once my life stops being flipped turned upside down

#

I also need to finish the course

topaz zenith
#

So I have connected to the SQL server using mssqlclient.py for Selmpersonnate module in Microsoft Privilege Escalation. I am getting no output with any xp_cmdshell commands. I did enable it. Have restarted the target a couple of times. SQL (WINLPE-SRV01\sql_dev dbo@master)> xp_cmdshell whoami
SQL (WINLPE-SRV01\sql_dev dbo@master)>

mint trout
#

looks like xml vs the raw request

shrewd hazel
#

so in sqlmap, it must be the xml vs the raw request?

fathom pendant
#

Also request vs output

shrewd hazel
#

ohhhhhhhh

fathom pendant
#

It looks like you're only highlighting the request portion in your right side

#

Which is gonna be different from the output kek

shrewd hazel
#

so i was legit copying the post request itself in text file for sqlmap, but should have actually gotten the output

fathom pendant
#

Yes.

shrewd hazel
#

i thought i just had to copy the post request itself vs the output for sqlmap

fathom pendant
#

You were copying the literal request used

shrewd hazel
#

aghhh no wonder. i was bugging like i had the right command but kept throwing errors at start

#

yup lol so terminology wise, the output for this post request is the response

fathom pendant
#

If you navigate to the output side in burp it should be the same

#

Yes

#

You send a request and receive a response

shrewd hazel
#

yeah lol everytime i think i got it boom some dumb mistake like that lol

#

thank you

fathom pendant
#

2xx is generally success, 4xx is generally error

solid quail
#

whats up ya'll currently stuck on a module skill assessment Introduction to windows command line. "User4 has a lot of files and folders in their Documents folder. The flag can be found within one of them."

I have tried Get-ChildItem | get-member | Select-Object name, .txt to retrieve flag info but yet have had no luck. any advice would be highly appreciated

#

it may be me not knowing how to properly use PS and filtering

fathom pendant
#

You'll need to either loop through and read all the flag.txt files (only one has a flag) or find a way to find the one that does have data in it and only read that

buoyant escarp
#

Password Attacks Medium Lab

||when logged in as user d....., why does HIS id_rsa also work for r... ? is this a random trial and error, or did you find any evidence that r... has the same private key||

fathom pendant
#

Also: spoilers still again spoiler text does nothing

#

When asking for help, when it comes with usernames always go with first letter then *. Those that have done the module will know what you're referring to

brave linden
#

not sure if you still stuck here. Just use Wireshark and look for DNS.

cloud urchin
#

You can DM me if you want

steep loom
heavy marsh
#

Looks like SQL Injection Fundamentals labs are down.

#

Anyone else having issues?

#

This doesn't make any sense, why would we even need to add a comment?

wanton idol
heavy marsh
#

Wouldn't this work just the same

SELECT * FROM logins WHERE username='admin'

??

wanton idol
#

thats why you would use a comment so after the commend nothing will be executed

#

the AND operator checkes to see if both are true

heavy marsh
#

Why add it in the first place then if you're not sure if it's true?

wanton idol
#

so if username is admin AND password is something is correct then its correct, if username or pass is incorrect then it wont work

wanton idol
heavy marsh
#

So is the password actually "something" in this case?

wanton idol
#

no thats just an example

#

it just showing as an example

heavy marsh
#

Hmmmm...

#

Still doesn't make sense.

wanton idol
#

what part?

#

maybe i can try to clarify more

heavy marsh
#

Why you need the AND and the command after AND

#

also why "admin'--" is passed as "admin"

#

wouldn't this be passed as "admin'"

wanton idol
#

ok they are showing the sql code just to help you visualize but in reality we wont even know what the code of the sql database would be

#

the AND command is there to see if username and password match in the database

#

if they match then you can log in if not then you cant

heavy marsh
#

Well how does that command bypass authentication then?

#

I guess that's the ultimate question here.

wanton idol
#

yeah which is where the -- comment comes into play

#

you will put the username in this case admin then put the comment after username. so like admin'--

#

the comment makes everything after it not be executed

heavy marsh
#

but what is the ' for and how am I authenticated with just admin and no password?

#

Wouldn't that be a NOT AND?

wanton idol
#

there is one account that is created which is admin so if you basically choosing an acc that does not require password bc you used a comment to not execute to see if the password matches to admin

heavy marsh
#

So the database is seeing the AND as true in this case even though it's false since it's commented out?

wanton idol
#

comment just makes it seem like there was never an AND password = 'something';

#

it makes it seem the whole code is just `SELECT * FROM logins WHERE username='admin'-- '

#

thats it

heavy marsh
#

So this is just an example and SELECT * FROM logins WHERE username='admin' would work then. So what is the point?

wanton idol
#

but you are missing AND password = 'wtv';

#

thats the point

#

if the code was written SELECT * FROM logins WHERE username='admin' AND password = 'wtv';

#

the comment would bypass it

#

and we are able to log in as admin in the web

#

do you get it now?

heavy marsh
#

I'm going to hit the "I believe" button, and just put it in my notes. I appreciate your explanation.

wanton idol
#

LMAO fs prolly someone else can explaiin it better than me

heavy marsh
#

No you did great, better than the module, I kind of see what's going on now.

#

So the comment makes the rest of the string not matter, but it still gets passed as being true?

wanton idol
#

yeah basically

heavy marsh
#

So why wouldn't

SELECT * FROM logins WHERE username='admin'-- AND password = 'something';

#

not work without the extra ' ?

#

what's the point of that '

#

after the --<space>

shut quest
heavy marsh
#

Then to me it would look like ''admin' -- '

shut quest
#

If they used double quotes you would need to match, admin"--

heavy marsh
#

So which quote is tied to which? Those first two in my example I just wrote are two single quotes.

#

This example is weird too, there's an odd number of parenthesis.

#

And the --<space> is not part of the original command since it's escaped from the parenthesis

shut quest
#

In that example you're closing the variable username, then closing the where clause, and finally commenting out the rest of the string

#

The single quote that is after the comment you injected is part of the original code

heavy marsh
#

So I made it down to the question at the end of the module and it's asking to login as a certain "id", but id is not a parameter that I have access to with SQL injection, as I can only modify the code adjacent to username.

#

Also tried this

wanton idol
#

the -- wont work bc its taking as a username as you can see

#

even then you still need to specify a username

shut quest
#

With something like that you can try ' or id=5 --
You would need to close the username, inject the id, but you can't have it be an and

heavy marsh
#

it's somehow not escaping the pasword

wanton idol
#

you forgot to )

#

somewhere around there

#

you got this

#

just look where to put the )

heavy marsh
#

Yeah, it won't escape the password

wanton idol
#

show me what u did?

shut quest
wanton idol
#

shhh let him figure it out

analog pebble
#

this isnt so much relevant to a specific module - but ive been studying HTB academy/followed up with hacktricks.xyz and ive noticed theres a ton of overlap. did one copy the other?

#

its almost word for word in the footprinting modules

wanton idol
#

if u fr stuck stuck then we can show u the answer but u got to show us what u have done first

heavy marsh
shut quest
heavy marsh
#

I guess I'll build a local SQL server so I can run trial and error injections on labs and the exam.

analog pebble
#

nonetheless its been pretty helpful to summarize the massive sections like ftp with hacktricks

heavy marsh
#

Thanks @shut quest and @wanton idol

#

I appreciate the help!

wanton idol
#

anytime!

shut quest
heavy marsh
wanton idol
#

LMAO

#

it somehow worked

heavy marsh
#

Somehow

wanton idol
#

LOL but im so glad i was able to help!

heavy marsh
#

Me too! The rest of the module has been easy thus far, just took a second to wrap my head around this. I guess it's one of those harder to explain, easier to trial and error to see input vs output for what is really happening.

#

Especially because I imagine each case is different.

shut quest
#

Most SQL injections can simply be avoided if the dev takes the 3 seconds to rewrite their queries properly.

limber river
#

can we remove this is kinda annoying

shut quest
limber river
twin lion
#

someone help, i'm doing the pivoting skills assessment and i've gained initial access as a user on the first server.
I couldn't find creds so I decided to start enumerating the other hosts through this ssh session, I tried -D 9050 on ssh and when I went to use proxychains with it configured correctly socks4 127.0.0.1 9050 I ran nmap with -sV, -sT, -Pn. I was seeing a whole load of messages, i cant remember what it said but it had DNS and a 5:1 in it (or something like that). The thing is it spammed that msg and ends up causing a memory leak or just a lot of memory usage. It's been working fine before but all of a sudden it's just fucking me over. The only other way I think I can get around this getting a meterpreter shell, putting a nmap binary on the server to get ports then forward what I want to attack.

shut quest
twin lion
#

would logging in to ssh with a ssh key change anything?

#

I think this might have something to do with it

netstat -antp | grep 9050

tcp        0      0 127.0.0.1:9050          0.0.0.0:*               LISTEN      -                   
tcp6       0      0 ::1:9050                :::*                    LISTEN      -       

I recall seeing a port and then the ssh service on that site where it says LISTEN, I can't see it here

twin lion
#

i just need to enumerate more so I can get creds

shut quest
#

-n will prevent nmap from trying to resolve DNS

twin lion
#

i got it, i put chmod 600 on id_rsa without trying it with default perms so i was opening ssh as root, that's why I saw the port open but not listening

rustic sage
#

I wish someone would shorten the brown notification at the top of the labs now it’s so big it’s an eyesore

unborn pilot
#

Is there someone who has done the advanced sql injection ? I need to ask a quick yes or no question please.

twin lion
limber river
#

make sure that the 9050 is uncommented and the 1080 is commented

twin lion
#

Only entry is
socks4 127.0.0.1 9050
And I was doing ssh -I id_rsa -D 9050

twin lion
frail ice
#

anyone having problems with the footprinting module section SMTP when attempting to spawn the exercise machine

wooden perch
#

I got this one with RDP but the wording says to upload the file before rdp. Im wondering if we missed something. I've tried using SMB and ftp with no luck. If rdp is the way they should have mentioned this on the course material right?

grand portal
limber river
wooden perch
#

The course only showed how to upload or download from windows and there are no credentials working for smb and ftp

limber river
limber river
wooden perch
#

Hmm impacket?

limber river
wooden perch
#

I know, Im in this module.. but this exercise ask something that its not explained on windows transfer files part

#

Maybe later on the linux methods this will be explained

alpine umbra
#

hi i am stuck on shell and payloads module

#

having more erors with ps code

#

i disable AV

#

but still no luck

cloud urchin
alpine umbra
#

mm

#

problem solved

tidal kelp
#

Hi, can i DM you for the same issue?

fossil crescent
tribal loom
#

in the CPTS "getting started - knowledge check" anyone else had issues with not being able to connect to the target? I ended up finishing the module questions in pwnbox because my vm woud work for a couple minutes and then no longer be able to communicate with the target.

it would start working again when I terminated/respawned or just refreshed target but only for a minute or two till it stopped working again.

lavish mango
worldly pagoda
#

I am sorry I am posting this in "modules" But I can't see pro labs channel. No administrator/moderator I messaged is responding. When trying to do identify this is what I see "I get this message upon identify - Identification error: please contact an online Moderator or Administrator for help."

#

In #welcome I cannot see the pro lab as an option

shut quest
#

enterprise account or just regular htb? I don't think the enterprise accounts can register

limber river
shut quest
#

that's their problem they are trying to resolve

worldly pagoda
shut quest
#

yes

worldly pagoda
#

ok. thanks

shut quest
worldly pagoda
weary owl
# alpine umbra

So if you are already in PowerShell you do not need to add poweshell -nop -c... Essentially you are trying to launch PowerShell while in PowerShell

alpine umbra
#

thanks

#

@weary owl

weary owl
#

Np

gritty breach
#

can anyone help with this question from Broken Authentication-skill Assessment- Assess the web application and use various techniques to escalate to a privileged user and find a flag in the admin panel. Submit the contents of the flag as your answer.

alpine umbra
#

Exploit the target using what you've learned in this section, then submit the name of the file located in htb-student's Documents folder. (Format: filename.extension)

#

can anyone remember where is the file

#

i am on this target but no any documents and files

fathom pendant
#

"Located in htb-student's documents folder"

#

Linux is case sensitive

latent glen
#

Hello guys, I'm on the Windows Privesc module doing the Citrix escaping. I'm giving the machine 5 minutes to load, however when I rdp into the IP, the thinclient doesnt come up

#

Im just stuck in the linux host

alpine umbra
latent glen
#

the other day it worked nice, today its not working anymore

ruby cargo
#

Hello (totally new here, so forgive me if i am in the wrong place)
I am doing the skill assessment of the FFUF module, and on the first question i am sure i have the right answer. however I get message that its wrong. maybe i am needing to put the info in a different format or something. I dont want to put the found answer here for spoilers.
question: Run a sub-domain/vhost fuzzing scan on '*.academy.htb' for the IP shown above. What are all the sub-domains you can identify? (Only write the sub-domain name)
can someone help me out?

lucid gyro
#

What are you guys discussing about

small stone
#

Hi guys πŸ‘‹

covert atlas
#

I need help in finding flag of WordPress directory listing challenge

#

I can see wp includes shows n number of files

#

But unable to find flag.txt

#

Help me in finding

oblique ore
#

some help?

autumn pilot
#

please contact customer service

oblique ore
#

a

pseudo kiln
#

I am creating a Windows attack VM as per HTB academy guide. Issue is vmware player has no snapshot function, but I found 2 work arounds. One would be to manually copy all the files where the VM is stored to another location. The other one would be to create an .ova file of the current VM. Is one of these 2 the better option ?

next bronze
#

use virtualbox

#

vmware workstation is great but player is not worth using because it's missing some important functions like snapshots

pseudo kiln
#

I agree, I just got accustomed to using vmware ESXI from work

#

it;s what offsec recommends too

next bronze
#

yeah esxi is great, but player is not exsi

#

does your work not give you a workstation license?

pseudo kiln
#

πŸ€” never actually asked them, good point

analog dock
#

English

ebon jasper
#

Hi everyone!
I am in "Windows attack defense" modules skill assessment.
Can anyone help me there is no log with above ID. I did what module showed. I guarantee, I 100% followed module without problem but I can't find events

inland shoal
#

most normal xfreerdp experience

slate halo
#

im doing LLMNR/NBT-NS Poisoning - from Linux and some users are getting cracked and some are not. What other wordlist to use other than rockyou?

#

can somebody help?

alpine umbra
#

module?

#

@slate halo

slate halo
#

Active Directory

soft cedar
#

rockyou works just fine

slate halo
#

why am i getting exhausted then?

soft cedar
#

or you can use JtR.

limber river
#

Sometimes the password are strong so they cannot be cracked

patent oak
inland shoal
slate halo
alpine umbra
slate halo
#

Linux

next bronze
slate halo
#

its really strange that some crack and other not

next bronze
#

it's not strange at all, some hashes can be cracked, others can't

slate halo
#

so i just need to try different hashes until one cracks

next bronze
#

wdym try different hashes, if you can't crack a hash from a user, then you can't get access to that user

slate halo
#

I cant asnwer the question''Crack the hash for the previous account and submit the cleartext password as your answer.'' I have cracked only two users

next bronze
#

did you get the answer for the first question

slate halo
#

yes, I got it

#

im stupid, I thought they were asking for a different user

twin lion
inland shoal
lucid gyro
#

Ah

#

Ouch

twin lion
# inland shoal what does that do

Ngl I don’t know but it should allow the session to be made , it worked for me when I got a timeout error. I believe it increases the timeout length

rustic sage
#

God damn the latency on these lab servers is buck wild.

fathom pendant
#

It's in ms

#

So 5000 = 5 seconds

twin lion
#

Thank you!

dark hemlock
#

hi, what modules can I do on HTB without paying? also is there a subscription fee instead of a per-module basis?

acoustic owl
dark hemlock
#

ty!

tulip dragon
#

is after doing cpts and cdsa can i able to land job in SOC entry level

acoustic owl
#

HTB's certificates are not yet very well known. But you will definitely have the knowledge afterwards

tulip dragon
#

not with cert , iam asking the knowledge gained from those path

viscid dock
#

I have been at it for a few days,
Is anyone able to help me?
I just need to answer this one question to finish the whole module

brave linden
#

take a look at the example 3 in that section.

#

the answer includes "; "

patent oak
#

Anyone able to offer a nudge to get "iamtheadministrator" creds on Windows Priv Esc Assessment 2?

#

I have a root shell

#

SYSTEM

viscid dock
alpine umbra
#

guys this is a insane problem for me

#

see this carefully i cannot see bottom bar how i work with this issue

#

can anyone help me?

#

can not scrol down and see bottom bar.

next bronze
#

refresh the page and mixmise the window

alpine umbra
#

yep do it no work

#

any sugestions?

next bronze
#

make the window smaller

alpine umbra
#

yah did it also

#

htb not well maintain it i think

next bronze
#

that's got nothing to do with it

#

just adjust the window

alpine umbra
#

so terible

#

final step on this module

#

try hard to finish this within a day

#

but no luck

next bronze
# alpine umbra

I mean if you're looking at leaks it should be easy right?

alpine umbra
#

no i used to it for zero cubes questions or get some idea

#

no that shit

next bronze
#

sure buddy

alpine umbra
#

i waste my time and give a hard try all over the day

#

not a leaks i use my own

dim wolf
#

i don't follow.

mint trout
#

on Escaping restricted shells, is it expected that I use the methods outlied in the article or research my own?

next bronze
wanton idol
#

im doing the lfi skills assessment and i cant seem to find a method that would gain me rce any help for a nudge would be appreciated

marsh echo
dreamy solar
#

Hello man

#

I have my paylaod :

#

My listener :

#

But it is not okay ?

#

Can you help me please?

mint trout
next bronze
#

try something with echo

mint trout
#

thanks mate πŸ™‚

#

ended up getting in via another method but im gonna try to find that one as well lol

#

understand it now, was really close before but makes sense now. thanks again ❀️

dreamy solar
fathom pendant
#

Also: Jason isn't on the target ip, he's on the given final ip in the q

#

(Your msfvenom payload is also wrong)

mint trout
#

hes using 172.x subnet as well

fathom pendant
#

But this section doesn't require it

fathom pendant
mint trout
#

i know lol, htb is always a 10.x isnt it

fathom pendant
#

Read his ssh command carefully

fathom pendant
#

That's not fully incorrect

#

The first host has a 10.129 ip for you to connect with and a 172 subnet to move through the network

#

He's also not on the right system to access 172.16.6 subnet

#

The section very much walks you through it

#

(And if you wanna do it with another method you'd have to adapt to work with it)

dreamy solar
#

Okay now I'm fine but I must to do ? I have to do something because it's not explained how to get on the machine 172.x.x.x

fathom pendant
#

There's another user and internal machine they give you

#

172.16.5.x

rustic sage
#

Todays not the day to make OJ Simpson jokes, but I may take a stab at it tomorrow

fathom pendant
rustic sage
#

She’s too young for you bro

dreamy solar
#

And I am reading 4x ^^"

fathom pendant
#

And I've been staring at the second machine ip and creds

#

You're also meant to rdp

dreamy solar
#

Yes I see I tried the same method, it is not thought out. Do you have documentation recalling the method?

fathom pendant
#

I literally followed the section step by step and it worked

#

Rdp to htb-student -> disable the real-time-protection -> start the socksdll

#

The section is a walk through

#

With pictures of what to expect at different points

soft cedar
#

^

#

and run powershell as administrator.

misty hazel
#

Hey all- having an issue on the ESC1 module of the ADCS attacks course. I've gotten Certify to output a cert for the correct user to the PS window, but when I try to copy it over to a pem file and encode it using the windows OpenSSL app installed on the windows VM provided, it throws a "no supported data to encode" error

#

Is the preferred method of getting the pem file running certify > copying the RSA key and Cert content from the PS window > pasting it into a txt file and coverting that text file to a pem file?

patent niche
#

need to convert the PEM certificate to the PFX

misty hazel
patent niche
fathom pendant
next bronze
next bronze
misty hazel
next bronze
#

try converting with linux then

misty hazel
#

I can't, the module provides a windows host, not a linux one. I'm connected to it via xrdp on my kali vm

next bronze
#

do it in kali

misty hazel
#

It's one of those ones that makes you login to a specific host

slate halo
#

when i execute this command sudo kerbrute userenum -d inlanefreight.local --dc 172.16.5.5 /opt/jsmith.txt -o valid.txt the valid usernames are not in the txt file?

slate halo
fathom pendant
slate halo
#

is it possible to give me the correct way?

fathom pendant
#

Try --output or something

fathom pendant
slate halo
#

with -v it just shows also the not valid users

fathom pendant
#

The outputfile?

slate halo
#

no in the command line

fathom pendant
#

I'm saying use v with the output option

slate halo
#

im putting -v in the end

valid viper
#

I'm stuck on: Use the Metasploit-Framework to exploit the target with EternalRomance. Find the flag.txt file on Administrator's desktop and submit the contents as the answer.

The output I'm getting says that the target is running on MS Server 2016 --> And the payload is failing.

drowsy phoenix
#

"I'm stuck on the Nmap module that has the challenge of discovering the version of the DNS server, however, every command I use doesn't show the version. Can someone help me?"

valid viper
#

Show the nmap command you're using please.

drowsy phoenix
#

nmap -p 53 -sV IP --version-light

valid viper
#

-Pn

#

Try adding that.

drowsy phoenix
#

─# nmap 10.129.53.244 -Pn -sV -p 53
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-04-12 15:52 EDT
Nmap scan report for IP
Host is up.

PORT STATE SERVICE VERSION
53/tcp filtered domain

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 13.23 seconds

valid viper
#

Nevermind on my question

fading shale
#

can someone help me with ssh

#

I literally cannot do the openvpn thing. Doesnt work

valid viper
#

--version-all @drowsy phoenix

drowsy phoenix
#

└─# nmap 10.129.53.244 -Pn -sV -p 53 --version-all
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-04-12 15:54 EDT
Nmap scan report for IP
Host is up.

PORT STATE SERVICE VERSION
53/tcp filtered domain

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 13.22 seconds

valid viper
#

-sSu --script dns-nsid

drowsy phoenix
#

└─# nmap 10.129.53.244 -Pn -p 53 -sV --script dns-nsid -sSU
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-04-12 15:57 EDT
Nmap scan report for IP
Host is up.

PORT STATE SERVICE VERSION
53/tcp filtered domain
53/udp open|filtered domain

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 131.15 seconds
😩

next bronze
#

do it in pwnbox

fathom pendant
#

Try with the pwnbox

#

This one is kinda dumb

#

Also I see you're running around your system as root

drowsy phoenix
#

yes rs

valid viper
#

I keep a root window open myself, gotta have the power ready 😐

fathom pendant
valid viper
#

sudo su

wanton idol
#

no no

#

just sudo

fathom pendant
#

sudo <command>

#

Running around as root and starting services as root is deeply irresponsible and can lead to things breaking unintentionally

#

You can make a new user. You can't make a new root

barren dew
#

in academy, any idea how to remove the banner about the Exams VPN? its taking up page space

valid viper
#

Defender keeps erasing this:

valid viper
#

😐

fathom pendant
valid viper
#

It deletes it from my Bash Bunny.

fathom pendant
#

"Bash Bunny?"

valid viper
#

I know, but I wanted to pop a shell from my lab to the cloud.

mint trout
fathom pendant
valid viper
mint trout
#

doas even better, historically more secure

barren dew
wanton idol
#

ik lol

drowsy phoenix
#

I'll keep trying.