#modules

1 messages Β· Page 236 of 1

fathom pendant
#

Yes

hardy sand
#

I found the question very confusing

fathom pendant
#

It's basically asking for after you install the submodule

#

What command would you run

fringe urchin
#

Access to the subnet through the provided machine(foothold) and not through your openvpn

fathom pendant
#

Using npm is just telling you "with npm, find a way to start a simple http server"

rotund steppe
#

Ohhhhh

hardy sand
#

I suppose using npx I could run the command without first using npm, and after installing with npm I don't technically need to use npx. I see your point

rotund steppe
#

Gotcha. Thanks

fathom pendant
#

It's one of the more silly questions

hardy sand
#

Is this the flavor of trick-question with a match-or-fail design I can expect during certification exams?

fathom pendant
#

Can't tell you what's on the exam

#

But the exam is flag based

#

So I doubt it's a "what command is used" and more "submit flag on machine x"

steady dust
#

I just saw, crackmapexec is down? πŸ˜„

fathom pendant
#

It's been forked to netexec

hardy sand
#

that's good to hear and answers my question, thanks πŸ‘

fathom pendant
#

There's a whole discussion thread on the cme github as to why

fathom pendant
hardy sand
#

that's especially good to hear

fathom pendant
#

It's tough but fair from those that have taken it

#

The exam will only have stuff from it's required path (plus fundamentals)

#

So you're not expected to know all the ADCS techniques or Custom Exploits in CPTS

hardy sand
#

nice

old atlas
#

Didn't we talk about " Sticky Notes" !

steady dust
fading comet
#

Hey, guys please tell me where to start to get better in cybersecurity. Anyone?

steady dust
fading comet
#

I just started the course

#

I like to know and practice

#

Any website on YouTube to watch or practice

ocean night
hardy sand
#

@fading comet I can recommend darknetdiaries, they have their own podcast site or you can find them on youtube. It's a lot of interviews with hackers and cybersec specialists. A lot of the time people will talk about how they got started in the industry and there are a lot of useful insights.

You can also query your prefered AI chatbot with a properly engineered prompt. For example:
"I have the following experiences/education with computers/networking/programming:
[...]
I would like to get acquainted with fundamental cybersecurity principles. Could you create a roadmap for me showcasing the different areas I should research and add sub-points for specific technologies and practices I should look into?"

Then you can use that roadmap as a starting-off point for your research.
I am currently taking the HTB Academy Cybersecurity Fundamentals path and can recommend it as a good starting point if you want to get more familiar with Linux, Windows, Networking, etc.

fading comet
hardy sand
#

my pleasure

bitter mist
#

Good evening everyone , i have this kind of problem today. I can't ping and reach any target machine from academy. I tried both my own machine with vpn and Pwnbox

half skiff
#

Can I DM you regarding this? I though I was on the right track but I'm still lost

hardy sand
#

if so, did you remember to spawn the target machine?

bitter mist
barren root
#

aany ideas why the LFI skill assesment on the ||log poisoning|| part is basically impossible to do through default burp install / settings?

#

I had to curl my way through it

bitter mist
#

idk why , but it started to work again . Guess admin buff xD

hardy sand
#

haha πŸ˜„

#

once I SSH into a target machine on my Parrot VM, the terminal gets so slow, I can basically brew myself a tea while I wait for a command I typed in to appear. Maybe there's just a lot of server load lately.

pseudo kiln
#

I rdped onto a target, lasted for a few secs then it closed itself and now I can no longer rdp into it....very weird, not sure what to do sometimes I am spending more time debugging these issues than on the contents of the materials themselves....

hardy sand
#

sure, no worries

pseudo kiln
#

and again I get access for 30 seconds almost get to run a command and it closes itself again

barren root
#

will take as long to type in as it would one letter

hardy sand
#

that. Is an excellent idea πŸ˜„

barren root
#

yea, get used to it πŸ˜… . Lotta latency on them targets sadly

hardy sand
#

ISDN era Problems require ISDN era solutions πŸ˜„

barren root
#

I will pretend that I got the reference LOL

pseudo kiln
#

latency is one thing but losing access to the machine intermittently is another

steady dust
hardy sand
#

well, it's the type of dial-up connection you had before DSL

hardy sand
#

it wasn't fast

barren root
#

/bpp:8 /compression -auto-reconnect -wallpaper +f -clipboard
flags to xfreerdp
use ctrl+alt+enter to leave fullscreeen

#

it's shit and it will be shit. had to go through the same process. In one module in particular I basically had to cheat past one creds step because that's the only way I could finish the exercise without using RDP

pseudo kiln
#

interesting, thanks for the settings, I guess this is where I should have thought outside the box

barren root
barren root
#

I mean RDP will always have more latency than remote shells

hardy sand
#

I am German, explaining jokes is in my blood.

#

It is the way.

barren root
#

but this is unacceptable. Whenever I had an issue like that I wondered "would an employee working in such an environment be able to get anything done" great way to discern quality issue from your own skill issue

barren root
barren root
pseudo kiln
#

you mean like more stable RDP clients ?

barren root
#

no that's just RDP being RDP and latency being what it is. Oh also increase the timeout using a flag I forget what's it called exactly just go xfreerdp --help | grep time and set that to 100000

hardy sand
#

well, excessively exact standards and regulations often sound silly in isolation, but then again, it makes the supply chain more resillient against greed the same way standards and regulations in development can make applications more robust and secure in production πŸ˜„ There are some really funny ones though, the EU in large has them too

#

good catch on the timeout flag

barren root
#

np, one of the community moderators taught me that flag combination

#

okay, Im off to play some apex to chill after that LFI BS I had to go through

hardy sand
#

hf

barren root
#

happy haacking and good luck. Feel free to dm me anytime if you've got any questions greenhorn.

hardy sand
#

I appreciate that

pseudo birch
#

I'm pretty sure a malicious IP just attacked the Pwnbox I was in while I was working on the skills assessment for AD. I have some screenshots. Where do I report it? The IP came back as a known malicious IP in VirusTotal. I dont even know if this is the right section in Discord XD

twin lion
#

Probably just send a explanation of the incident to HTB Support

steady dust
pseudo birch
pseudo birch
fringe urchin
#

Wait but wasnt that ip internal then? Like 10.x?

pseudo birch
#

nope 167. IP

#

and the skills asssessment box is 172.16.7.x

fringe urchin
#

Oh you can access from outside to pwnbox. I never tried

steady dust
hardy sand
#

well, I mean if he is hosting a webserver on it

pseudo birch
#

at the very least I thought someone could tell me I was wrong and at least tell me why otherwise could be useful information?

fringe urchin
#

Well its not how i meant it

pseudo birch
#

Can I share screenshot on this thread? Maybe someone can illuminate me, if I'm dumb or not.

wanton idol
#

i would love to see it ngl

pseudo birch
hardy sand
#

When you host an http server on a machine with a real ip address, it'll try to expose a port on that IP address to the internet for web-access. So, your pawnbox may have been web-accessible at that point. Does look like it from the screenshot.

#

There are bots that will scan far and wide for accessible ips on all sorts of ports to try and find vulnerabilities. If you expose a service with default authentication credentials, that becomes a potential attack vector for turning the machine into a botnet bot. It's kind of what the labs challenges are about.

barren root
#

||wrong channel mb||

hardy sand
#

rly? but that made sense, it could have been a crawler lol Not all bots mapping accessible ips also do attacks, some just map the internet

pseudo birch
#

That's actually good information. Learned something new then. Do yall think this should be reported or nah? IP in VirusTotal shows malicioua

hardy sand
#

While it may very well have been a malicious IP, I doubt it would have found anything interesting. Since it only made GET requests and a PRI request and didn't get anything, it should be fine.

#

had to look up PRI requests, actually, so I learned something too lol

#

On the servers I manage, requests like this and worse come in constantly. It's a real barrage πŸ˜„ They try to go right for the juicy stuff too.

pseudo birch
#

I just definitely wasn't ready to see that in the environment so I thought I'd say something just in case xD.

hardy sand
#

Seems like a solid proceedure. And now we both learned something, net benefit all around πŸ˜„

pseudo birch
#

Yeah forreal. I'll take that!

south folio
steady dust
hardy sand
#

yeah, that stuff can happen very easily.

pseudo birch
#

Would yall recommend a different method of file transferring? I was moving mimikatz and printspoofer. Or just use a different default port?

cloud urchin
#

remmina is stupid easy

hardy sand
#

what's the scope? Are you transferring on the same machine, between machines on the same network or over the internet?

pseudo birch
#

10.129.x.x to 172.16.7.x on Skills Assessment 2 - AD. So, different networks. Using SSH to get from one to another. RDP port not open for remmina though that's typically what I use for RDP sessions.

hardy sand
#

@pseudo birch is SFTP or RSync an option? I can't really assist on this one, I'm not that experienced with network stuff on windows yet Gotta get into that Windows Fundamentals Module first xD

cloud urchin
#

You can dm me

hardy sand
#

since SFTP should use SSH it would probably be a question of whether the service is available or installable

pseudo birch
cloud urchin
#

sometimes you can enable rdp

#

i haven't done that module though so i don't know specifically about that

hardy sand
#

might be worth a try. See if you have enough privileges to enable/install stuff

cloud urchin
#

honestly downloading through a remmina copy/paste is going to be just about as fast or slower than using the command line to grab it from the python webserver you have

hardy sand
#

establish the ssh connection in vs-code, having vs-code install the vs-code server package on the target machine, then see if you can get into the explorer and download/upload stuff via the editor πŸ˜‚

#

I doubt that'll work, but if it does, I'd say it'd probably be up there with the worst possible solutions.

wanton idol
#

i use smb or python or evil-winrm to transfer files

barren root
#

or meterpreter ; p

Honestly one of 3 reasons I use it πŸ˜‚

#

outside of that, if you've got a fancier keyboard / mouse, set up a macro to paste a command template to fill out

unkempt kestrel
#

Hello all, I have a question about setting up the HTB Parrot OS on VMware in the Setting Up module. Everytime I close the VM and turn it back on, it asks me to install Try/Install. Will it always do this? Am I setting it up incorrectly? Do I have to do the Parrot OS installation on the desktop every time I power it on?

fathom pendant
#

It's booting from the cd first

#

Which is the install iso, and not the vhd you installed

unkempt kestrel
#

Thanks for the quick response, I will try this

buoyant escarp
#

can someone give me a oneliner for powershell to upload a file over ftp to my kali?

#

lost all my notes, my vm crashed, had to setup a new one 😦

strange forge
#

iam stuck at snmp footprinting. snmpwalk and snmp-check both are giving "SNMP request timeout". applied delay too. sometimes the query is working, sometimes it does'nt work. Its the same query. is it some kind of glitch or it is meant that way?

fringe urchin
#

If you dont set a long enough of timeout the script will well just go over the user too fast and it wont get a response from the server yet, meaning it will drop the user

#

The sweet spot id say was 15-20s

#

Around that

patent niche
#

is the certificates unstable ?\

strange forge
#

Got the problem. The target ip is getting offline. smh

fringe urchin
strange forge
fringe urchin
strange forge
#

ping <ip>

#

even this is not working lol

fringe urchin
#

Lol

ocean night
# strange forge ping <ip>

Do you have openvpn running in multiple places? Do you see multiple instances from ps aux | grep openvpn?

#

If you do, each client will fight each other for the connection, resulting in your lab connection going up and down frequently

fringe urchin
patent niche
#

Kappa"works fine"

ocean night
#

killall openvpn, or just reboot and give it another go. Hope it helps!

ocean night
#

Note on Pwnbox it connects to the VPN automatically on your selected lab, so you don't need to run the openvpn command yourself

tulip dragon
#

is vpn not working rn

strange forge
fringe urchin
strange forge
strange forge
fringe urchin
fringe urchin
strange forge
#

237ms is the minium. F

fringe urchin
#

I jsut ran the command and i got all the info instantly

fringe urchin
strange forge
fringe urchin
#

Well im pretty sure that matters aswell which server since pwnbox is based on it

#

Pwnbox connects to it automaticly

#
  • has the location
strange forge
#

yeah checking out different servers now. dk wtf is going on

#

--- 10.129.185.100 ping statistics ---
161 packets transmitted, 5 received, 96.8944% packet loss, time 162083ms
rtt min/avg/max/mdev = 99.232/7383.196/33356.948/13006.885 ms, pipe 33

#

wtf seriously

fringe urchin
#

πŸ’€5 recieved is wild

strange forge
#

missing those days, when ping respinse used to be fast.

buoyant escarp
#

look at dat packet loss xD

strange forge
ocean night
#

That's a pretty mental loss / latency. Which lab server / target?

#

(on Pwnbox I think you said?)

strange forge
#

snmp footprinting. academy module. UK server.

ocean night
#

Got a link to the module / section please?

fringe urchin
strange forge
#

wish to be done with footprinitng module. done with snmp finally

fringe urchin
strange forge
#

can i report anywhere, son of a gun. target goes offline midway

#

I guess its just real time practice. Unintentional real time frustration

fringe urchin
spring abyss
#

something wrong with servers? my target keeps dying on windows priv esc

strange forge
spring abyss
#

yes when i try to connect with xfreerdp

strange forge
#

i have to keep doing ping to check if target is up, then run the command

spring abyss
#

yea same but it wont come back up this time

strange forge
strange forge
spring abyss
#

PING 10.129.43.44 (10.129.43.44) 56(84) bytes of data.
^C
--- 10.129.43.44 ping statistics ---
137 packets transmitted, 0 received, 100% packet loss, time 137816ms

fringe urchin
#

they lied to me... should have been 1kKermitAngry

ocean night
#

I did face some issues - I've reset the Pwnbox a couple of times and it's now come up fine and can access the target. Unsure what's going on there - might be an issue with one of the nodes hosting Pwnboxes.

#

Could you try terminating / starting the Pwnbox again, and when it's up check if you've got tun0 in ifconfig?

spring abyss
#

i think i tried bout 15 different targets now

strange forge
#

ohh just noticed you are the staff member

ocean night
#

academy-eu-1, yes?

strange forge
# ocean night academy-eu-1, yes?

Connect to Pwnbox
Your own web-based Parrot Linux instance to play our labs.

Pwnbox Location
UK
170ms
Terminate Pwnbox to switch location

valid viper
#

I'm getting the following error from evil-winrm with credentials I picked up from nxc:

Error: An error of type OpenSSL::Digest::DigestError happened, message is Digest initialization failed: initialization error

strange forge
spring abyss
#

been like this for hours

ocean night
strange forge
valid viper
#

Does anyone have any ideas regarding my evil-winrm error? Error: An error of type OpenSSL::Digest::DigestError happened, message is Digest initialization failed: initialization error

#

Okay, it is working through pwnbox...but now none of the commands work.

#

Except for cd

strange forge
#

switch to eu-academy-2 vpn. eu-academy-1 is having some problems

valid viper
#

Should I switch to 1?

ocean night
#

The issues on eu-academy-1 should be resolved now

#

Our sincere apologies for any inconvenience caused 😦

valid viper
#

This still isn't working for me.

#

I'm connected via PowerShell over pwnbox, but the commands are timing out.

#

And then it's disconnecting.

ocean night
#

Can you DM me your VPN IP and target IP please?

nocturne flint
#

Thanks for your post!

onyx halo
#

if you do http://127.0.0.1:3002, connection stays open and for port 2222 it errors. I would assume this is POC.

sleek moss
#

||[*] Exploit completed, but no session was created.
msf6 exploit(unix/webapp/get_simple_cms_upload_exec) > options

Module options (exploit/unix/webapp/get_simple_cms_upload_exec):

Name Current Setting Required Description


PASSWORD admin yes The right password for the provide
d username
Proxies no A proxy chain of format type:host:
port[,type:host:port][...]
RHOSTS yes The target host(s), see https://do
cs.metasploit.com/docs/using-metas
ploit/basics/using-metasploit.html
RPORT 80 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing con
nections
TARGETURI admin yes The full URI path to GetSimplecms
USERNAME admin yes The username that will be used for
authentication process
VHOST no HTTP server virtual host

Payload options (php/meterpreter/reverse_tcp):

Name Current Setting Required Description


LHOST yes The listen address (an interface may b
e specified)
LPORT 4444 yes The listen port

Exploit target:

Id Name


0 Generic (PHP Payload)

View the full module info with the info, or info -d command.||

im on getting started lab i found the username and password ||admin:admin|| the login page is at ||/admin ||but idk what to set for targetURI

shut quest
#

Might want to look up what a URI is, that should give you the answer

sleek moss
#

its the full url but in the prev examle they just put down the nibbleblog and not full url

shut quest
#

Can't say, not sure where my notes went for that, I'm missing half the module including the lab. If I had to guess it should just be the IP, if that fails just add the rest.

fathom pendant
#

I don't recall needing to change the uri but it's been a minute

cloud urchin
#

I used a regular poc for that instead of metasploit

strong forum
#

Hello. I got a flag while solving the nmap problem, but I wonder what the solution is.
.....delete....

dense pewter
#

BloodHoung is making me very confused. While looking at the data I collected while in a domain-joined machine, it clearly states that the user X has no admin or RDP privileges on machine Y. But I just found out that user X can in fact RDP to X and run admin commands. What gives? SharpHound is compatible with my version of BloodHound.

fringe urchin
old atlas
#

Just look into the folders you got!

fathom pendant
#

I'd hope they got it by now

#

If you scroll down too you'll see they figured it out

feral nimbus
#

Hey guys was doing the Learning Process module, but couldn't understand a part where it's being defined what is a question:

Let us, therefore, create a situation with a question to test this statement. Let us assume we see host A and host B. To do this, we can ask the following question, which we will also ask during our penetration tests:

How is Host A connected to Host B?

Our goal was to obtain or acquire information with the help of the question posed. Did we obtain or acquire any information from this question? - No. Regardless of the form of the questions asked, strictly speaking, the official definition of the question also missed the point.

Context: The module is debating about how the official definition of question doesn't always apply and gives the example of the question above: How is Host A connected to Host B? and then says that we do not acquire the any information from this question, however don't we? For example Host A could be connected to Host B with a cooper wire, so that's the information we obtain after posing the question.

I know this a weird question, but I wanted to see what point the creators are trying to convey that I'm failing to understand, if anyone could answer that'd be great!

old atlas
#

They are looking for the NT part of hash only!

fringe urchin
#

Thats... Thats 1 year ago

strong forum
fringe urchin
#

what did your command look like?

#

-D RND from what i remember is used to specify a decoy scan

fathom pendant
fathom pendant
gritty nexus
#

Hello everyone. I'm quite stuck on a module and it has been 3 days with no respose from my HTB academy support request. I was hoping one of you may be able to help/clear something up for me.

Module: Using Web Proxies
Section: Proxying Tools

[RESOLVED] Issue: the section mentions editing proxychains.conf but I don't have the permissions in the VM to save the advised changes to get proxychains working.

[RESOLVED]Question/Concern: wtf am I supposed to be looking for/doing to pass the section question? I have started burp and metaspoloit. I've set the "use auxiliary/scanner/http/http_put" but when sending the "run" command while monitoring via burp I get "error: file doest seem to exist. the upload probably failed"

I'm not sure what I'm supposed to be looking for/doing at this point as this module just feels all bugged out.

EDIT for anyone looking for an actual answer:

How-to: edit proxychains.conf:

open MATE terminal
enter command: sudo vi /etc/proxychains.conf
to enter insert mode- hit the letter "i". you will see -insert- at the bottom.
move to where you want to insert the "http 127.0.0.1" and/or go to remove the # from the #quitemode line.
hit esc/escape to exit insert mode and enter back to "command mode"
type :w or :wq , :wq saves and quites the terminal. :w only saves.

note: looks like sudo vi lets you modify as root whereas sudoedit will only save the modified version under var/temp/

gritty nexus
fathom pendant
#

Sudo works for me to edit files I might not be able to write to as user

gritty nexus
fathom pendant
#

When I've needed to edit, yes

jade agate
#

is the optional exercise necessary?

dim wolf
#

it's optional but recommended

jade agate
#

but im lazy dont want to write 500 words

fathom pendant
dim wolf
#

that's fine

fathom pendant
#

Not at min

jade agate
strong forum
fringe urchin
fringe urchin
fathom pendant
#

Β―_(ツ)_/Β―

fringe urchin
#

Footprinting medium lab. He apperently got it somehow differently

#

shruge doesnt ring a bell for me

rustic sage
#

Hey guys, stupid question but I need to make sure. Once I complete the modules, they are mine correct? If I don’t finish the module, then I have to pay for it again right?

dim wolf
rustic sage
#

If I miss one little portion of the module, then can’t be re-looked at right

#

Let’s say I do it all but forget the final assessment etc etc

dim wolf
#

then you won't have access to the module once your subscription expires

#

if you unlock a module with cubes, then i think you keep it forever regardless of completion

rustic sage
#

OK, so the entire module needs to be 100% completed not a single question missed

dim wolf
#

yes

rustic sage
#

I will be done with the modules by August for all three of the exams. I’m doing that to save money.

#

Then test later

#

Done with bug 75% for pen, tester and half done with SOC

dim wolf
#

i really want to do the senior web pentester path..

runic depot
rustic sage
dim wolf
#

we can't really know until we do it ourselves or enough people give their reviews about its contents

#

i'm already torso-deep in academy content anyway

distant island
#

Can someone help me i get this in the session hijacking xss module bug bounty

dim wolf
distant island
marble spire
#

Hey, does anyone know how to deal with this RDP error ? I see it quite often and cant manage to solve it

[17:00:16:425] [136556:136557] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 0: Succès
[17:00:16:425] [136556:136557] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
distant island
acoustic owl
dim wolf
distant island
distant island
runic depot
#

@dim wolfcan you help me out with my question

#

im 99% the way through cdsa 😭

dim wolf
#

try checking the Debugging section again

#

iirc there's something there that can potentially help

runic depot
#

my last attempt would be to use inetsim let me try that

dim wolf
#

yea try that

#

open wireshark as well

runic depot
#

@dim wolf llittle confused on what to do here

dim wolf
#

set it to your vm IP, not target IP

#

actually you cant use inetsim here if you don't know the domain name it's connecting to

runic depot
#

yeah thats the problem i thought about

dim wolf
#

you will just have to try and use wireshark

shut quest
#

I think I used IDA to solve that one. Inetsim was only used on orange

dim wolf
#

i used x64dbg

#

but i think you can also use wireshark theoretically

runic depot
#

alr ill use wireshark

shut quest
#

Possible that it was x64dbg

runic depot
#

for wireshark do i just start a capture, run the exe, and start looking?

shut quest
#

If you're asking that then you should go over the traffic analysis module again

pseudo kiln
#

A question asks about the serial number of a windows system, this should be it right ? it does not seem to accept it

pseudo kiln
#

i spawned another machine, got a different serial number, still not accepting it....

#

apparently it's a different command for vm

shadow cargo
#

where do i start?

mint lodge
#

<@&861185840277487616>

#

Atlist i hope this is a rule break

final orchid
#

I just send a question once, and the bot sent me a warning about not sending the message again and again

final orchid
fathom pendant
#

automod doesn't like large messages for unlinked accounts Β―_(ツ)_/Β―

#

Same reason as to why you can't post images

dire abyss
#

am I using the wrong wordlist?

sleek aurora
shut quest
shut quest
dire abyss
#

ah dang lol i was doing too much

#

thanks for that

mint lodge
shut quest
#

Going to need more info, like module / section, maybe the question...

pseudo kiln
final orchid
fathom pendant
shut quest
pseudo kiln
shut quest
#

Your image and spoiler do not match, your image is correct. Also be sure to remove both spoilers as they provide the answer

final orchid
pseudo kiln
#

lmao I typed it manually and it worked, how can copy pasta copy something different ?

shut quest
#

That's on you to figure out

fringe urchin
#

AnnoyingSadgeCry

pseudo kiln
#

i dont think it was, deleted the last character and retyped it to be sure, my theory is something with powershell ASCII formatting, but who knows, first time i encountered something like this in the modules

novel hinge
#

password attacks lab - easy : ive been trying to ssh2john these to try to get the root password. but i just cant. ssh doesnt work for mike. is there more files i need to try?

shut quest
# novel hinge

Not sure why you're trying to do that in that directory. If ssh2john isn't in your path just call the full path

graceful mortar
open yew
#

I know this was asked many times with no resolution but is there a way to change to light mode on HTB academy without using an extension?

final orchid
#

so, I have two sep accounts one for htb and one for academy, I have subcription for academy but obviously is not showing when doing the identify command, what could I possible do here? or plz direct me to somewhere I can ask this question

toxic apex
#

can someone give me a hint on the advanced xss / csrf skills assement, I can already extract all 5 pieces of data i can find but there is no flag in there?

shut quest
final orchid
shut quest
#

There is just for cert holders at the academy.

final orchid
#

if I get a cert, how would that be verified?

shut quest
#

It's pinned at least in the CPTS chan

final orchid
#

got it, thanks!

buoyant escarp
#

what tool do you use to enter the password into a .img (bitlocker) so that you can mount afterwards

unborn plaza
#

hi guys. is available a specific module on htb where to learn how to build malware from scratch?

#

or where to find it? thank you

tulip dragon
#

vpn is not working from yersterday what i can do

acoustic owl
tulip dragon
#

usa,eu all

acoustic owl
#

Then reach out to support

tulip dragon
#

k

unborn plaza
#

can i start from scratch there?

wanton idol
fringe urchin
proper lagoon
#

anyone know how to access Kibana on the pwnbox or is this something I have to set up myself? Trying to do the SOC Analyst path and I am on "Introduction To The Elastic Stack", can't seem to find anything on pwnbox to do the task

buoyant escarp
#

Password Attacks Hard Lab
i got the password from one of the .img that were inside of the B......vhd
now i try to use dislocker to decrypt the .img but i cant get it to work, does it mean the password is wrong?

unborn plaza
#

and should I also learn assembly x86 before starting?

wanton idol
patent niche
#

Guys grep '^re.*\.exe$' example.txt is this the correct way to filter out word that starts with "re" and ends with ".exe" in a .txt file?

tulip dragon
wanton idol
fringe urchin
#

I usually always make a dummy file. Put some stuff in and test if it works. There is always a chance that you/someone else looking at a regex misses smthing

unborn plaza
wanton idol
rustic sage
#

Colleagues I have a question, I'm in the ssh tom but I can't find a way to find the HTB user, what I see is a script reovery.sh module Footprinting --> hard lab

fringe urchin
rustic sage
#

I see several strings like changing the password for Tom @fringe urchin

dire abyss
#

anyone not able to get vpn working? just went down for me in the middle of a section 5 minutes ago

rustic sage
#

chpasswd: (user tom) pam_chauthtok() failed, error: @fringe urchin

fringe urchin
rustic sage
#

I see that you are generally changing your password but you have not been able to make the change

#

@fringe urchin I see that you are generally changing your password but you have not been able to make the change

fathom pendant
#

history can often be useful

rustic sage
#

There is a mysql service in bash_history you would have to log in on this side to be able to log in****

cosmic grail
#

I'm having an issue with the ACTIVE DIRECTORY ENUMERATION & ATTACKS module. I'm trying to exploit the PrintNightmare vulnerability with CVE-2021-1675.py exploit. I followed the lab instructions but I keep getting an error when I try to use the exploit

fathom pendant
#

It shows you how he logged in

cosmic grail
strange umbra
#

Hello

fringe urchin
#

Sorry that it confused youpepeSadge thats on me

rustic sage
#

I see that I have to access a mysql service but what I can't find is the password for that service @fathom pendant @fringe urchin

dim wolf
#

bash history

fathom pendant
#

Don't overthink

rustic sage
#

What I can deduce in the strings is that I couldn't change the password and in the hsitorial it leaves the mysql service to be seen but I'm trying to log in with the password and it won't let you access @fathom pendant

fathom pendant
#

You don't need to change a password

#

You login internally

fringe urchin
fathom pendant
#

^

hexed oyster
#

Hi all, I'm working on "Attacking Web Applications with ffuf" on the "recursive fuzzing" sub-module. Attempting to answer the question "use what you've learned so far to find the flag". What I've done so far is: 1) fuzz index for possible file extensions 2) after confirming the file extension, I start a recursive "scan". but I'm not finding any new directories. 3) back to step one, I'm currently performing another directory scan to verify that I've not missed any directories. Is there something obvious I'm missing from the content?

fringe urchin
#

So try to internally login like its shown in bash history

rustic sage
#

Shit is that I have a problem starting the mysql service, sorry for the inconvenience from my local machine @fringe urchin @fathom pendant

fringe urchin
#

But via the ssh tom session

rustic sage
#

'Cause I never thought about it 😦

fringe urchin
rustic sage
#

Esotoy performing the queries in the database

fringe urchin
rustic sage
#

I've made it thanks to @fringe urchin

fringe urchin
#

Or is it in bash history?(I dont have the full bash copied)

rustic sage
#

I've found it through snmpwalk where the strings indicate that the passwords could not be changed @fringe urchin

fringe urchin
red bridge
#

Are modules ever broken? I'm doing the Skill Assessment of the Command Injection Module. I'm litearlly sitting here for a full 6 hrs and I am as far as I was when I started. I read through the entire module 2 times and I am not even sure if I am working with the correct field. It never says anything unless I put in less than 3 characters 😣

red bridge
#

ty

cloud urchin
#

feel free to DM me if you need some tips

fringe urchin
buoyant escarp
#

omg this module is so big, finnaly i can head to the next module phew

shut quest
cosmic grail
shut quest
cosmic grail
shut quest
#

No, read #welcome to verify your account, you'll be able to add images then. Also no because someone else may have a similar issue and it could help them down the road. And lastly no cause I come and go and between me disappearing someone else may chime in to offer as well.

What section?
What command(s) did you use?

Not saying any of that to be mean, but to help.

ocean night
shut quest
ocean night
#

Aha

hexed oyster
#

nvm. got it. 😏

novel hinge
#

any reason why im getting no results doing this/

#

it doesnt even seem to run

strange forge
novel hinge
ocean night
#

--verbose - the option is shown right there πŸ™‚

novel hinge
#

omg

ocean night
#

If in doubt, run man <command>, e.g. man crackmapexec to read the documentation πŸ™‚

onyx halo
novel hinge
ocean night
#

--verbose needs to come before smb

novel hinge
#

@onyx halo i think so, it just has port 22, 139, 445

#

it doesnt look like its attempting brute forcing

ocean night
#

It really doesn't... you have a tun0 up in ifconfig?

shut quest
#

Might be a dumb question but you still connected to the VPN?

novel hinge
#

yes to both

#

tun0 is up / vpn is still running and connected

#

im on password attacks medium lab if that helps

ocean night
#

DM me the VPN server you're connected to, your tun0 IP and the target IP

onyx halo
novel hinge
#

0 hosts serving smb

#

now my nmap isnt populating

#

let me try resetting the target

onyx halo
novel hinge
#

so i got connected again, found \myaccount share. but dont have a username yet. can you maybe help point me in the right direction? should i try hydra on ssh?

shadow dune
#

maybe add more slashes

#

////10.129.75.79//myaccount

#

maybe you have to escape the slashes in the name.

ocean night
#

Other slashes, I think

#

\\\\<ip>\\<account>

#

Also check man smbclient for usage examples

#

I gotta go, good luck

#

Yeah, re-read the material @novel hinge

#

There are examples there of how to use smbclient

cloud urchin
#

he is correct it's smbclient //<fqdn/ip>/<share/

#

but his error says nt bad network name

#

so there's something going on there

ocean night
#

That's not what the module documentation states

cloud urchin
shut quest
#

The attacking common services / smb section will provide info

ocean night
#

Could be that's under Powershell?

#

They're running under a bash shell

#

Anyway, the module documentation in the Password Attacks > Network Services has the information you need to use smbclient

#

nn

shut quest
#

Get some sleep

soft needle
shadow dune
#

HTB{$(cat flag.txt)}

analog pebble
#

hi i am stuck on footprinting easy lab. when trying to connect to ftp proxy nc -nv 10.129.54.11 2121 the server just hangs after sending the banner

shadow dune
#

type ls

analog pebble
#

im not logged in so it returns nothing

#

nevermind, reseting the lab fixed it πŸ€·β€β™‚οΈ

#

still interested to know if the ftp proxy is supposed to hang when connecting

shut quest
#

Sometimes that lab just breaks, or I've never been patient with it

analog pebble
#

not sure if this is another error on the lab's part, but i copied .ssh/id_rsa to my home folder w/ perms 600 and its denying it when using -i id_rsa

shut quest
#

Using correct username?

analog pebble
#

yes, ceil

#

command looks like ssh ceil@10.129.54.11 -i id_rsa

shut quest
#

chmod, correct path to id_rsa?

Your command is correct

analog pebble
#

yep, id_rsa is in the same directory that im running SSH

shut quest
#

Check the id_rsa file to see if it is correct?

analog pebble
#

i re downloaded and its the exact same size

#

i even b64 encoded it and compared the first and 2nd download and theyre the same

shut quest
#

Like make sure no extra new line in file

analog pebble
#

yes

#

should i just restart the server again

shut quest
#

i guess? Β―_(ツ)_/Β―

tidal mango
#

Ok I feel kinda dumb for having to ask this.. in the Using CrackMapExec module, Basic SMB Reconnaissance section, the last question is What's the OS version? The should be simple from what I can see, but no matter what I try to put in for the answer, it says incorrect...

novel hinge
#

did u run a nmap -sV?

tidal mango
#

yeah

novel hinge
#

show the screenshot

tidal mango
#

just running crackmap smb give me the OS as well...

soft needle
tidal mango
shut quest
#

I don't have that module but if you try to connect it should just spit out the os on the first line

tulip dragon
#

in xss and file inclusion php payload are used , should i be expert in php or should i know enough what the code is doing

novel hinge
#

ohh its not CPTS.

fossil wing
#

Anyone can help me?

Module: Password Attacks
Section: Lab hard

I get the kdbx file, so I try guess the pass but, I'm waiting for hours, is this a rabbit hole? I get the first user, just J...

shut quest
naive shell
tulip dragon
shut quest
tulip dragon
#

there will be like js , php , python and low level lang

tulip dragon
#

bruhhhhhhhhhhh

shut quest
tulip dragon
tulip dragon
naive shell
naive shell
#

lol, what?

soft needle
shut quest
fossil wing
tidal mango
naive shell
soft needle
#

the password cracking module can take more than 10 min

valid viper
#

I'm not sure where to ask, but I'm trying to work on the new box Usage...

mint trout
valid viper
#

And I can't ping the box. I tried re-downloading the VPN.

tulip dragon
mint trout
#

too slow @tulip dragon

valid viper
#

'You do not have access to this link.'

valid viper
#

Okay well...

#

I also can't get retired boxes to spin up either.

#

Is HTB just FUBAR at the moment?

#

So the machines that I can get to won't spin up, and machines that I can't get to will spin up.

mint trout
#

fine for me, what vpn are you using? not academy still right

valid viper
#

No, I'm using the right VPN.

#

Machine is spawning, please stand by...

#

This is what I'm getting for retired boxes.

mint trout
#

well, I am using the vip boxes, someone else just reported an issue in #cpts so maybe the free ones are overloaded

valid viper
#

I'm using the same.

#

EU VIP+

#

I'm not sure if that's the problem as I'm in the US?

mint trout
#

I am CREATING INSTANCE now as well too

#

I use US VIP+

analog pebble
#

my academy lab isnt launching either

valid viper
#

It's not just the labs, but the boxes

#

And for some reason it's defaulting to EU instead of the US.

#

Alright, well I guess HTB is done for a while.

#

😐

mint trout
#

appears to be back @valid viper

valid viper
hexed lintel
#

why academy guided lab machine are so slow.

gleaming nimbus
#

Is there anyone else having issues connecting to the target machines via the modules?

warped gorge
#

Im too

#

They are generating but they not working

uneven roost
#

hey! im struggling on just one question on the Windows Attacks & Defense module, in the Print Spooler & NTLM Relaying section, is this the right place to ask for advice?

cosmic grail
uneven roost
# cosmic grail Are you trying to exploit PrintNightmare?

no its the question dealing with preventing the PrinterBug attack. The question specifically is:

After performing the previous attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and make the appropriate change to the registry to prevent the PrinterBug attack. Then, restart DC1 and try the same attack again. What is the error message seen when running dementor.py?

#

i feel like im for sure missing something simple, i was able to do the question before it with no issues but am stuck here...

cosmic grail
cosmic grail
uneven roost
left owl
#

Hello, i am on the nmap module and looking into ids/ips evasion. I am trying the technique with the ACK scan (-sA) combined with a 5 ips decoy and it just runs soooo sloow. I know -sA runs slower than the syn scan but it barely goes 1% in about 20min. Is that to be expected?

potent ruin
#

😭

autumn pilot
#

The SQL console as explained in the section can be found in the Settings

potent ruin
#

@autumn pilotHey man, can I ask you a private message?

autumn pilot
#

you can ask here

potent ruin
#

The problem I'm currently having is that the PersonaBar is not loading

autumn pilot
#

PersonaBar?

rugged harbor
#

Hey guys! Anyone encountered this issue on the module Windows Event Logs & Finding Evil-Tapping Into ETW: After I started capturing ETW events I created the cmd command process form spoolsv.exe but I cannot find any process id info in the etw.json file. No log info about this spoolsv.exe.

wraith pelican
#

Hi everyone, I'm on the Windows privesc module from cpts path. I'm playing with permissive registry ACLs in attacking the os/weak permissions section. I was able to complete it with other privesc in the section but this particular method seems like a dead end from htb-student user perspective. The course example is to use accesschk.exe with 'mrb3n' as user. That dumps a lot of 'KEY_ALL_ACCESS'.

With htb-student, we got some permission like CREATE_SUB_KEY in BTAGService, so ok i write a setting and link the setting IMAGEPATH to a netcat command. But first the BTAGService is a bluetooth thing, i guess it is just disabled in the vm, I can't restart it, it does not start after reboot and then I don't know if a setting I own in a service will trigger the command. I tried the technique in my home lab where i was able, as admin, to create a service and give a low priv user KEY_ALL_ACCESS, so i know it works. Am I missing something here or the course was just stating 'this technique exists'? I'm asking because I can't think straight about it anymore... Thanks!

cloud urchin
potent plover
acoustic owl
potent plover
still grail
#

hi

agile owl
#

Right lads need someone to point out where I’m being stupid here, currently doing the ARP spoofing and abnormality detection and have wireshark filters set to β€œarp.code == 1 && eth.src == 08:00:27:53:0c:ba” should filter out correctly if I’m not mistaken, what am I missing here? Just a nudge would be appreciated

royal sigil
#

hello have you make web service api attack because i have problem with this question (Exploit the command injection vulnerability of the target to execute an "id" command. Submit the privileges under which the server is running as your answer. Answer options (without quotation marks): "user", "www-data", "root")i have tried like this curl http://10.129.202.133:3003/ping-server.php/system/id

royal sigil
cloud urchin
#

did you curl the url?

royal sigil
cloud urchin
#

dm me

open oxide
#

Hey guys can anyone help me with usage room

fathom pendant
royal sigil
fathom pendant
open oxide
#

Okay

strange forge
#

Hey can i do academy modules on vip+ instance?

cloud urchin
#

you don't. vip+ is on the other platform. academy is its own platform.

quartz coral
#

Hello, I'm on "SeImpersonate and SeAssignPrimaryToken" page of "WINDOWS PRIVILEGE ESCALATION" module.
The page says ' Attackers often abuse this privilege in the "Potato style" privescs - where a service account can SeImpersonate, but not obtain full SYSTEM level privileges.'
What is the reason why it is called "potato style"?πŸ₯”

valid spear
quartz coral
potent ruin
potent ruin
old atlas
#

Command exec!

candid lily
#

help with windows attacks and defence

#

it seems like everyone is getting this error with impacket-ntlmrelayx

feral totem
#

.

candid lily
#

screw rdp its slow as tortoise

astral beacon
#

Hey

candid lily
#

anyone done with Print Spooler & NTLM Relaying section?

#

in windows attacks and defence

astral beacon
#

Can weekly streaks can be setting?

#

I just want it a bit more harder

candid lily
#

nice idea but not there yet

cloud urchin
#

i've performed that exploit but not that module

candid lily
#

i keep getting errors from ntlmrelay

cloud urchin
#

well that's not good

candid lily
#

why do we even need rdp for kali :( its so slow, if i type it appears after like 30 seconds

dim wolf
#

i think you can also ssh

candid lily
#

i think they have a firewall blocking ssh

#

nvm i got ssh now

#

wow the exploit worked with ssh

#

screw rdp again, ssh ftw

cloud urchin
#

samAccountName != UPN

upper ruin
#

Yup, got it.

candid lily
#

lol

upper ruin
#

Wrote it without the

#

ilfreight

candid lily
#

i found the error and submitted it but i doesnt accept ( i dont understand the format)

upper ruin
#

I assume this isn't the pentester path.

candid lily
#

windows attacks and defence

#

windows modules are hell

tranquil axle
#

when you connect via winrm it doesn't pass your tickets, so when you use sharphound to gather data it is as if you were unauthenticated, that is also the last error message in your screenshot

candid lily
#

after few minutes i got a different error and it was accepted

strange forge
#

what's the command for connecting with mongo server?

#

mongo db enumeration

candid lily
#

just type mongo i guess?

zealous rune
#

hi everyone

#

I'm trying to complete the exercise to find a flag in one of the services by using the nse and it's scripts

#

so far I have :
ran nmap with --script all against various services

#

tried running various scripts targetted to the service running on the port

fringe urchin
#

Without you telling us the module and section you stuck on we have have a hard time giving help

tulip dragon
#

why webrealted modules only include php not any other lang

#

hmm

zealous rune
#

ah yes

#

My message seems to not have sent. So I am on the nmap enumeration module

#

Network Enumeration with Nmap

#

section nmap scripting engine

fringe urchin
dark garden
#

Hello. Do you know if the skills assessments of the modules can be solved independently? Or should I grab information from the easy ones to solve the hard ones? Thanks.

zealous rune
#

thanks schainy

#

i have a question... does nmap select scripts based on the service detected running on the port if combined with sV?

#

so nmap -sV --script all -p80 <target>

#

will that result in only scripts that are relevant to the service running on the port 80?

inner mulch
#

hello im new to hack the box can someone help me set it up

#

?

zealous rune
#

setup what?

fringe urchin
zealous rune
#

perfect thanks schainy

#

I can also use "http-*" as a regex

#

i see from the doc

fringe urchin
fringe urchin
# zealous rune perfect thanks schainy

to get the flag you need to visit the website aswell and check if the vuln/ or any other stuff can give you more infoπŸ€– just looking at nmap for detail wont help you in a lot of cases. (Dont overthink hard)

fathom pendant
snow ridge
#

FIX: Update visual studio, if that doesnt work try reinstalling.

Advanced Deserialization attacks, Section: Example 1: JSON

I'm getting following error on visual studio: CS0234: The type or namespace name 'Data' does not exist in the namespace 'System.Windows' (are you missing an assembly reference?)

Just using the same code as in example. I'm using own windows machine. I tried adding reference to PresentationFramework but did not help. Not familiar with visual studio.

using System.Windows.Data;

namespace RememberMeExploit
{
    internal class Program
    {
        static void Main(string[] args)
        {
            ObjectDataProvider odp = new ObjectDataProvider();
            odp.ObjectType = typeof(System.Diagnostics.Process);
            odp.MethodParameters.Add("C:\\Windows\\System32\\cmd.exe");
            odp.MethodParameters.Add("/c calc.exe");
            odp.MethodName = "Start";
        }
    }
}
fringe urchin
snow ridge
fringe urchin
#

does the program work if you just remove the using System.Windows.Data;?

snow ridge
#

Then we come to another problem: There will be an error regarding ObjectDataProvider. Visual Studio will not reference the necessary namespace by itself for this class, so it is necessary to hover over it, select Show potential fixes and then select using System.Windows.Data; (from PresentationFramework)

#

I have to use that to fix another error

fringe urchin
#

was it shown to use framework? or core'

snow ridge
#

It only says this: With Visual Studio installed, we can open it and create a new Console App (.NET Framework).

fringe urchin
# snow ridge It only says this: With Visual Studio installed, we can open it and create a new...
snow ridge
#

Can't get it to work now. Im going to try this with pwnbox tomorrow, even though it was recommend to try on own machine.

toxic apex
#

pwnbox isnt windows is it?

#

I don't think most of the stuff for advanced deser will work underlinux

snow ridge
#

There was a windows lab setup where I can rdp, not really a pwn box

#

Basically instead of exercise box you can spawn yourself a windows machine which has those tools installed

toxic apex
#

I don know that for two packages you have to add them in vis studio in that course

#

like you create a .Net app but also you have to do something in the vis studio itself to modify what libs you include to get that to work

lost aurora
fathom pendant
valid spear
#

Is there a recommended method for dealing with the stack trace that results from installing powerview.py and running as described in the ADCS Certifried module? I've tried copying msada_guids.py to the directory that contains dacledit.py and removing "impacket" from the line that's sourcing it, but that doesn't seem to help either.

limber river
#

why rdp are always to sloooow sadglas

half stag
#

hey could someone help me with atacking common services "DNS Attacks" Section?

patent niche
#

Determine the folder that contains all Mimikatz-related files and enter the full path as your answer.

I have ran the ||Windows.Search.FileFinder|| artifact is this not the right one?

Is this is not the related path ? ||C:/Users/j0seph/AppData/Local/mimik/x64/mimikatz.exe||

steep loom
#

can anyone that has done the NTLM RELAY ATTACKS skills assemnt give me a hint for the second question: Compromise BACKUP01 and then submit the flag located at 'C:\Users\Administrator\Desktop\flag.txt'

limber river
#

anyone know how to copy a file from rdp to my machine using the /drive , I get access denied

next bronze
#

should be \\tsclient\<shareName>

limber river
#

even that I am local admin

strange forge
#

Hey a question regarding the starting labs. can i ask here?

limber river
next bronze
#

do you have access to that folder?

winged egret
#

Hello guys, any good gui apps to interact with imap and pop3 ?

limber river
next bronze
#

yes I'm asking if you have access to the dir that you're sharing

steep loom
limber river
#

yes , I can see the files , copy from the share to the windows machine ,
but not vice versa asking if there's a way to copy from the windows to my machine

next bronze
#

never seen that happen, you can use other ways, smb, upload server, etc

steep loom
#

i figured that was the step for the later questions x.x

astral inlet
#

i can see bytes becoz so slow ;/

limber river
limber river
next bronze
#

the kali user doesn't have write perms to opt

pseudo birch
#

Has anyone done AD Enumeration & Attacks - Skills Assessment Part 1 recently that could help me figure out why I can't get chisel to work on the compromised host [Question 4]? I'm sure I'm doing something wrong, potentially my proxychains.conf or how I'm moving the chisel.exe to the compromised host. (I know there are a handful of ways to do handle the question, I chose chisel because of the PF/Tunneling Module) Will take any advice.

quasi wave
#

does medium lab for footprinting require hash cracking? is there cryptography involved?

#

I don't know where to begin. Which sections from the footprinting module should I review to get started?

#

I wanna get my brain into gear

fathom pendant
quasi wave
fathom pendant
#

Also the footprinting skill assessments do fairly well at giving you an overview of what to expect

limber river
patent niche
#

Can someon help with this question the only persistence I found related to the malware was ||HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reverse|| is this not the one?

trail shuttle
#

can someone explain to me how the --prefix and --suffix work in sqlmap. been trying to understand but I can't

dim wolf
#

not value per se but it's not the key itself

spiral spoke
#

Hi! Someone could give me a hand with Web Attacks > Advanced File Disclosure > Error Based XXE please?

I've been trying to get the /etc/passwd of the machine but it seems that it doesn't work the technique

This is what I've done so far:

#

And this is what I've got pepehands :

buoyant void
#

Let's go only 2 to go, this one was a fun module

zealous rune
#

i'm still working on the enumeration with nmap module. Trying to find the flag in the nse scripts section. What format is the flag supposed to be in?

buoyant void
#

I do have a question about something that came up in one of the Windows privesc assessments, without spoiling anything I was wondering why I would get more hashes when I use secretsdump.py vs dumping lsass and using mimikatz directly on the target machine? I was trying to get the hashes using mimikatz but was having no luck and secretsdump.py took the same lssas.dmp and got all the hashes I needed

fathom pendant
fringe urchin
zealous rune
#

hmmm i want to be more selective with the scripts i run against the service as it takes a long time

buoyant void
zealous rune
#

sudo nmap -Pn -v -p80 --script "(not dos and not fuzzer) and http-*" 10.129.2.49 -oA http_scripts_port80

fathom pendant
zealous rune
#

ok,

#

it's just that a full script scan takes a looooong time

buoyant void
#

But my question remains, is there a way to get similar output from Mimikatz that I was getting from secretsdump.py? The relevant module section outlined dumping lsass using procdump and then suggested some mimikatz commands to dump the hashes, which is what I was doing but not getting any of the hashes that secretsdump got

fathom pendant
#

Just doing --script vuln should be fine

fathom pendant
#

It's one of those quirk things

buoyant void
#

Gotcha appreciate the answer

quasi wave
#

I got the hostname of the device and operating system for medium lab of footprinting module. I have the username because they gave it. so how do I get the password?

zealous rune
#

i'm running sudo nmap -v -p80 --script "vuln" 10.129.2.49 -oA http_scripts_port80

fathom pendant
zealous rune
#

i could be a bit more precise with -n and -Pn etc. but should still yield more output I think....

topaz zenith
#

Having an issue with access : RDP to 10.129.225.217 with user "svc_backup" and password "HTB_@cademy_stdnt!". It keep's saying password incorrect. This is on the Windows Built-in Groups part of the Windows Escalation module.

fringe urchin
fathom pendant
zealous rune
#

same result.... with or without. The quotes are just to stop shell interpreting characters like spaces i guess?

fathom pendant
#

Also sometimes just exploring can help. You might see a certain txt file

topaz zenith
#

Nvm, xfreerdp worked for some reason

zealous rune
#

ah

#

i actually didn't do this πŸ™‚

fringe urchin
#

Since its in the question

quasi wave
#

ok got it

#

but then I don't need a password then?

fathom pendant
#

You do need a password

quasi wave
#

ok

fathom pendant
#

And there's a wordlist you can bruteforce with

fringe urchin
#

you will find about that in the end, there is many steps between you and HTB. you need a password but not for HTB user

fringe urchin
fathom pendant
#

Oh yeah

#

I'm thinking of the old one with Ceil

quasi wave
fringe urchin
fathom pendant
fringe urchin
quasi wave
#

ok thanks

fathom pendant
fringe urchin
#

yep^

#

just ignore HTB user, till you find him manually

quasi wave
#

well I can't RDP in just with domain or IP address

fathom pendant
#

No. But there's ways to enumerate a user

#

Look at the open ports and techniques to enumerate them

fringe urchin
#

shruge then you missing something, you didnt enumerate enough

fathom pendant
quasi wave
#

ok I will keep enumerating

fathom pendant
#

Look at all the sections and see which ones match up to what you see

zealous rune
#

ok i see

#

although in practice i would likely have used gobuster and web enum scripts to get there....

fringe urchin
fathom pendant
#

This is showing how to get there from nmap first

zealous rune
#

although this is a good lesson in paying attention to detail

fringe urchin
zealous rune
#

i guess in "my process" i would say that once i identify http server, i'm noting this and to further enumerate the web service i would go to whatweb and gobuster and other specialised tools/scripts for webserver enumeration

steep loom
#

NTLM RELAY ATTACKS skills assment question 2:

i have used ntlmrelayx.py ||-t ldap://172.16.117.3 -smb2support --no-da --no-acl --lootdir ldap_dump|| to enmrate the domain and get usernames
||dob mozhar sqladm Administrator Guest krbtgt||
from reading other questions it looks like i need to use the cleartext password taken from the sql_ftp_test account with responder?

however no combo of those account names and the password seems to work. Anyone do this before that can point me in the right direction?

upper ruin
#

has anyone had problems with xfreerdp not loading recently

fathom pendant
#

Have you tried pressing enter after it pops up?

upper ruin
#

Nah like as in it doesn't connect.

fathom pendant
#

Did you put the password in single quotes?

upper ruin
#

Been going on for a month.

#

I will try

fathom pendant
#

timeout

#

Try changing vpn region

upper ruin
#

How the hell do I do that,

#

is this eu / emea related

fathom pendant
#

Download a new vpn pack for your account

upper ruin
#

Ohhh, this.

#

Yeah aight.

fathom pendant
#

^

upper ruin
#

yh, will do

#

I live in europe, it wouldn't be a problem to dowload USA

#

right?

fathom pendant
#

Don't forget to close and delete the old vpn

upper ruin
#

Done that, ser

fathom pendant
#

The difference, if any, would be negligble

upper ruin
#

Well, let's see how it goes.

fathom pendant
#

You don't need domain

upper ruin
#

tried it beforehand witout domain

fathom pendant
#

Did you copy/paste the pw?

upper ruin
#

Last scenario Ima use rdesktop.

#

Nah, wrote it manually.

#

No mistakes,checked it.

fathom pendant
#

Try copy/pasting

#

:)

upper ruin
#

teh f it worked

#

I removed the cert-ignore

#

????

fathom pendant
#

Did you also copy/paste?

upper ruin
#

Nah

fathom pendant
#

Ah

#

Then it's a weird cert thing

upper ruin
#

what does certificate got to do with it

fathom pendant
upper ruin
#

Don't matter, if it works, no touchy

fathom pendant
#

Always copy/paste pws when able

#

It avoids the need to manually check

upper ruin
#

I love how it says logon failure but it still lets me in kek

upper ruin
upper ruin
fathom pendant
#

Student va stdnt

#

idk how to answer that one Β―_(ツ)_/Β―

upper ruin
#

Idk which module it is

#

OH wait, didn't I do that

fathom pendant
#

They're on NTLM relay attacks

#

It's a t3 module iirc

fringe urchin
#

maybe at the end the 013 was changed to a newer one kek

upper ruin
#

oh nah, i am too dymb for that

#

still finishing AD

upper ruin
#

:D

sly nebula
#

I am running into this very problem. DId you find out what's wrong?

astral inlet
#

if you use impacket tools try -debug

#

btw on AEN the priv esc does not trigger

#

and its slow AF

#

i am so fed up

#

the path is so good, the technical part is so fucked up

wanton idol
#

I am stuck at the command injection section Bypassing Other Blacklisted Characters, i am stuck i tried this ls%09${HOME:0:1}home but nothing shows up

#

nvm solved

astral inlet
#

what a pain

upper ruin
astral inlet
#

from learning perspective , yes

upper ruin
#

then it's worth the pain, ser

#

now u gotta do ze

#

cpts

astral inlet
#

its sad that thayt the techical part is so bad

#

rdp is pita

#

vpn was slow

#

for EU

hexed spindle
#

Is anyone available to help with Active Directory Enumeration and Attacks Skills Assessment II? I am having trouble figuring out how to access MS01 as administrator.

astral inlet
#

do youhave the creds ?

hexed spindle
#

Not any that give admin permissions

onyx rapids
#

Skills Assessment - Intro to Whitebox Pentesting

Has anyone succesfully uncommented the ||// router.post("/cat", cat);|| on the live server and gotten it to work? I can do it when I run my own Node server, but doesn't work on the live one. I'm guessing because my changes are not being made while the server is up and I have no way to force the server to reload my code. I find this absolutely insane that I spent hours developping a payload that can do this, but in the end that's not how you solve the lab. Why would they have that line commented out? To drive me insane ?

ocean night
#

It's possible it's not the intended path

#

Not sure, haven't done that module, but in reality commented code can hang around.

soft needle
astral inlet
#

thx πŸ™‚

lost aurora
flint bane
#

@ocean night look at offical aws website and check webstie url

ocean night
#

Got a URL?

#

I'm on the cloud computing page, and don't see it

flint bane
ocean night
#

Ah, I see.. hm

flint bane
ocean night
#

Hah, I don't think so

fathom pendant
#

it's a fairly generic design Β―_(ツ)_/Β―

#

It's not like the htb logo is heavily artistic imho

#

Just a cube that's outlined green and filled black

flint bane
#

yeh almost similer to hack the box

ocean night
#

OMG Nintendo stole it too?

#

ffs

fathom pendant
#

GameCube frfr

flint bane
#

Yep

fringe urchin
#

I was scared one of those gifs are the horny oneskek

fathom pendant
#

You can never tell

gray merlin
#

woot! Just AEN left. Going to start it blind tomorrow.

fathom pendant
#

Gl

plain cosmos
#

Anyone knows what is the CVE needed for Kernel exploits Linux privesc module(https://academy.hackthebox.com/module/51/section/467)?
I tried all of the 2021 that exploit suggester suggests, and none of them work.
Also, when I tried a standart privesc with common vulnerabilites don't work and don't escalate the privilege to root, never seen that happen before

hollow tapir
#

Does anyone know why I am getting prompted for a password when running the following command in Kerberoasting - from Linux section

#

was that not allowed? My bad, if so

ocean night
#

Better to keep questions generic, and avoid posting specific details.

hollow tapir
#

Sounds good, can I post the error message?

ocean night
#

Hard to tell if I don't know what it is πŸ˜…

hollow tapir
#

oh yeah, good point lol. Can i DM you?

ocean night
#

Yeah I guess

ocean night
hollow tapir
#

Does anyone know why I am getting this error Error in bindRequest -> invalidCredentials: 8009030C: LdapErr: DSID-0C090690, comment: AcceptSecurityContext error, data 775, v4563 when trying to run Impacket for the linux kerberoasting lab? I am unable to pull TGS tickets

fathom pendant
#

I believe the examples show a Password: prompt

hollow tapir
hallow remnant
#

MODULE: Introduction to Deserialization Attacks
SECTION: Skills Assessment II

Could I request a nudge on attaining RCE?

fading matrix
#

Any help on this one mate ?

rustic sage
#

who deleted my question?

#

😦

ocean night
#

πŸ–οΈ

rustic sage
#

why

ocean night
#

Spoilers

rustic sage
#

it was inside spoiler tag

#

and the flag doesn't work

ocean night
#

Still a spoiler

rustic sage
#

who would know more about my question i am genuinely confused

ocean night
#

If you want to ask for advice or assistance, please do it without posting such specifics as your screenshot did

runic depot
rustic sage
#

how would i rephrase it?

runic depot
#

second

rustic sage
#

the flag i got is incorrect i can figure out what it's supposed to be from context clues but it's still the wrong answer

fading matrix
# runic depot yeah gie me one question

After performing the ESC1 attack, connect to PKI (172.16.18.15) as 'htb-student:HTB_@cademy_stdnt!' and look at the logs. On what date was the very first certificate requested and issued? this one

rustic sage
#

something happened within sqlmap and i am trying to figure out why before i move on to the next exercise

ocean night
#

Just the message without the image would've done I reckon. If anyone is able to give you a nudge they will

rustic sage
#
Table: flag5
[1 entry]
+----+-------------------------------------+
| id | content                             |
+----+-------------------------------------+
| 1  | HTB{***_****_****_***_\x02A0r7h_17} |
+----+-------------------------------------+

the asterisks are censored because they contain the flag but the end of the flag is incorrect and it's what sql map outputted... why did it do this?

#

i don't understand why it gave back \x02a

fathom pendant
#

Tfw I'm trying all other systems for the smb except the DC kek

rustic sage
#

\x means binary and 02 in binary is 42 in ascii and that is an asterisk but it's supposed to be a w if you're reading the leeted flag... what causes sqlmap to do this?

fathom pendant
#

I mean I take it you tried the whole thing itself as the answer

#

And not trying to reverse engineer the flag

ocean night
#

Shouldn't have to interpret the flag further though tbh

#

Wanna DM me the command you're using?

rustic sage
#

okay

ocean night
#

That wasn't a DM πŸ˜…

rustic sage
#

i'm so sorry i'm having a long day 🫠

runic depot
#

@fading matrix are you here

fading matrix
runic depot
#

can you tell me what you did already

fading matrix
#

did as the modules

runic depot
#

oh thats correct, think about formatting it differently

#

tell me when you get it right

fading matrix
#

Can I curse @runic depot

wanton idol
fading matrix
fading matrix
wanton idol
#

just trolling XD

fading matrix
#

I wrote it right but the format is pain in my ass

wanton idol
#

but idk i think u can since its not towards anyone

fading matrix
#

Anyway I'm learning well, THANKS for all the help from the members

runic depot
#

no problem

#

that answer should really be changed, why is the HTB answer different than how the answer on the vm has it

heavy ridge
#

is anyone else having trouble with targets spawning?

fading matrix
#

Yes Sir

#

they just keep on loading
but never loaded

heavy ridge
#

damn i guess its down then

#

wait mine went up @fading matrix

fading matrix
#

Alright I think they are UP ^

fathom pendant
#

hmm

#

i'm either stupid or lab is being dumb

sleek moss
#

will Documentation & Reporting be on the cpts/

fathom pendant
#

technically; yes

#

as documentation and reporting is part of completing CPTS

sleek moss
#

i c ok danke

earnest mulch
#

lsass.dmp takes like 2 billion years to dump at this point

shut quest
#

Wut?

glass quail
#

has anyone done the module file upload attacks

#

I think its broken