#modules

1 messages · Page 238 of 1

buoyant void
#

Did you get anything useful from SMTP enum?

winged egret
#

nope nothing

#

ran it several times and added the -D for domain

#

although im suspecting i should get a user from it at least so I can bruteforce it

buoyant void
#

Yeah you have the right idea. I don't remember because I did this assessment a while ago, but was there a users list included in the resources of the module? If so, try doing your user enum with that list

winged egret
#

thx mate ill try again

buoyant void
#

no problem, you're on the right track

shut quest
winged egret
#

yup I think that was it cz I got it on a retry

rustic sage
#
└─$ cat /etc/hosts    
127.0.0.1       localhost
127.0.1.1       kali
::1             localhost ip6-localhost ip6-loopback
ff02::1         ip6-allnodes
ff02::2         ip6-allrouters

10.129.42.195 app.inlanefreight.local
10.129.42.195 dev.inlanefreight.local
10.129.42.195 drupal-dev.inlanefreight.local
10.129.42.195 drupal-qa.inlanefreight.local
10.129.42.195 drupal-acc.inlanefreight.local
10.129.42.195 drupal.inlanefreight.local
10.129.42.195 blog.inlanefreight.local

#

that's what mine looks like right now but i'm not sure if that's correct

worn hill
#

Would anyone be fine giving me a helping hand designing a very very very easy and most basic network diagram based on the most basic of basic equipment requirements it should have

plush tinsel
#

Try using just one IP and the hosts after.
10.129.42.195 vhost vhost vhost etc. etc.

rustic sage
#

this is what it looks like now ```10.129.42.195 app.inlanefreight.local dev.inlanefreight.local drupal-dev.inlanefreight.local drupal-qa.inlanefreight.local drupal-acc.inlanefreight.local drupal.inlanefreight.local blog.inlanefreight.local

warm mountain
#

Hello, could someone help with exercise 1 of the Predictable Reset Tokens - Broken Authentication module?

#

I can't get the script to return the correct token. I've already read the previous hints on this forum.

plush tinsel
#

@rustic sage Try pinging or 'curl -I' one of the hosts i.e. dev.inlanefreight.local to test

rustic sage
#

curl: (7) Failed to connect to dev.inlanefreight.local port 80 after 3101 ms: Couldn't connect to server

#

strange because

#

i feel so dumb i didn't bother to check the vpn... the thing crashed!!!

#

ooops

plush tinsel
#

It happens. no worries.

#

<@&486603600085123073> I'm on Attacking Enterprise Networks. This is triggering when I go to support.inlanefreight.local the rest of the vhosts are normal. Just an FYI.

heavy edge
#

Are you typing it in right? Because this is redirecting

plush tinsel
#

The URL is in the SS.

zealous rune
#

I'm working through the footprinting module and trying to anser the question in the SMB enumeration section

#

The question that I am struggling on is: Find additional information about the specific share we found previously and submit the customized version of that specific share as the answer.

#

not sure if i understand the question

#

or is it thaat I will understand the question once I find the answer 😄

plush tinsel
#

Connect and enumerate 🙂
***client > ********enum > Version will be obvious

zealous rune
#

version

#

i already enumerated the version of the server

plush tinsel
#

The wording on that question isn't the greatest...
It's not the version of the server, but the version of a service..

fathom pendant
#

smbclient or rpc might be good for finding it out

zealous rune
#

using

#

netsharegetinfo <SHARE>

#

to further enumerate the specific share

plush tinsel
#

enum

fathom pendant
#

i believe it's also case specific

zealous rune
#

case specific?

#

hmmm found a bunch of completions for enum.... in rpcclient

fathom pendant
zealous rune
#

ah yes

#

i do get output relating to the share by running netsharegetinfo

loud dagger
#

wowie wow i am officially 50% done with the infosec fundamentals path 😐

zealous rune
#

well done!!!

#

keep going 🙂

#

ok what format is the answer in

#

it's not a flag i suppose?

fathom pendant
#

Nope

zealous rune
#

ok so more info than before

loud dagger
#

i can't wait to get the fuck out of school so i can actually start focusing on this

zealous rune
#

well rpcclient command netshareenum <sharename> does giive more info

#

i don't get from the question what extra nfo is being asked for

#

sorry no

fathom pendant
#

Custom version

zealous rune
#

i mean netsharegetinfo

fathom pendant
#

I'm sure I..freight isn't an official version

zealous rune
#

I already submitted the version for that

#

didn't seem to take

#

ok i needed to submit the whole thing

fathom pendant
#

Yeah lol

zealous rune
#

i think the supplying the format of the answer might have been useful there

fathom pendant
#

custom version

zealous rune
#

one of the first things i did was submit the different version

#

i just supplied x.x

fathom pendant
#

:)

#

Always try everything for the answer before ruling it out

zealous rune
#

okidoki

#

thanks!

#

time for bed

buoyant escarp
#

Attacking Common Services
-> Attacking SQL Databases

im stuck at the first question.

i logged into the given htb credentials with impacket mssqlclient.py
listing all DBs with enum_db

need a little hint from now on

buoyant escarp
#

what is the pw for mssqlsvc user

keen shuttle
#

I need help with password attack pass mutation module

twin lion
#

try & find credentials

buoyant escarp
analog pebble
#

make sure not to say too much in this channel without blocking spoilers

#

(|| ||)

twin lion
wanton idol
buoyant escarp
wanton idol
#

yeah that works just need to find the correct table and database

#

this also works as well select * from tablename;

fathom pendant
wanton idol
#

yeah true i just thought it was mssql

buoyant escarp
#

mssql

fathom pendant
#

But he's gotta be the right user to see the right table

buoyant escarp
#

im trying the catching ntlm hash but im not getting an event on responder

fathom pendant
#

Is responder running on the right interface?

buoyant escarp
#

tun0

fathom pendant
#

And you're having it do the xp..dirtable //ip/share yeah?

buoyant escarp
#

okay, as always.... i redid it and it worked, might have had some syntax error xD

fathom pendant
#

Oh yeah been a min

buoyant escarp
#

3:17 AM
this might be the cause 😒

#

ah the issue was i did it inside of apostrophe ' cmd '

buoyant escarp
#

this was an very interesting section, crazy how harmful it can be, that the DB can access remote shares via SMB

sinful drift
#

The destination machine does not load, does this happen to anyone else?

#

Target is Spawning

rustic sage
#

Thoughts on arch Linux

sinful drift
#

someone?

split spruce
rugged zenith
#

Hello everyone,
Just to be sure there is no issue on my side. The target stuck on "Target is spawning..." on the Attacking Enterprise Networks module. Is there any potential issue for which I'm maybe not aware please?

next bronze
#

refresh the page and try to spawn again

rugged zenith
#

I did it many times even by changing the browser but it didn't work unfortunately

next bronze
#

I can spawn it, eu-2

rugged zenith
#

Yes you are right. It's working now. After a reboot. Thank you very much.

sinful drift
#

getting started
knowledge verification
I am trying to escalate privileges to root with the file /usr/bin/php since it is the only file with which I have all permissions but I cannot modify the content of the file, nor edit the name of php to example.sh
I have tried other methods with other files but I have permission denied
Can someone who has done this module give me a clue please?

quasi summit
#

Hi All, im in the Analyzing Evil With Sysmon & Event Logs module and am getting into the windows vm's ok. The module requires me to download stuff from the internet but there is
internet access on the vm's.

#

I've already changed the pwnbox location a few times

honest gyro
#

how did u solved it? im currently facing the same error

inner sand
#

can i still access my modules i finished in the academy even though i cancelled my subscription ?

acoustic owl
weary owl
#

What really that's awesome 😎

zinc nimbus
#

pls can someone help me with Password Attacks Lab - Medium. I'm trying to crack for 3 days and 3 nights now and Im getting no where. Ive tried. and after trying smb2 it just says. Ive also tried crackmapexec but its not providing any results. I've tried cracking ssh and smb but i dont know what Im doing wrong anymore please someone save me

#

I havent found any user's credentials or anything I've enumerated and found that ssh and smb is running and i couldnt crack 😭

#

i tried to install the libsmbclient support module for my hydra so it can support smb2but it failed and i used pwnbox but it also doesnt have the hydra module installled

wanton idol
zinc nimbus
wanton idol
#

im pretty sure i used hydra but i dont remember

zinc nimbus
#

why is it saying i dont have oepnssl support let me recheck rn im unwilling

heavy edge
#

Heh

wanton idol
#

that idk

heavy edge
#

I think hydra is wonky I had to load hydra in with certain modules before I could crack smb

zinc nimbus
#

ok i will try and load more modules

heavy edge
#

Like complete reinstall with the libsmb-dev module

#

Because smb wasn’t supported

wanton idol
#

maybe restart your pawn box

zinc nimbus
#

im using my own vm but i tried pwn box and it was the same thing

wanton idol
#

restart the machine?

zinc nimbus
#

ok let me try

#

see. Why is this happening 😭

#

wait its not smb? or wrong port??

wanton idol
#

maybe run a nmap scan and see whats open

zinc nimbus
#

it might rlly be smb2 it says it in the host script results

wanton idol
#

yeah it is smb version two but there isnt a command on hydra for smb2

#

well smb 4.sum sum

fathom pendant
#

Cme works iirc

zinc nimbus
cloud urchin
#

read your hydra error and it will reveal all you need to know

#

"target does not support smbv1"

glass quail
#

can anybody help me understand why im getting this message

#

module file upload attacks and section type filters

digital shale
#

I'm attempting the Password Attacks module, Pass the Ticket (PtT) from Linux section, "Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory. " question.

#

|| I managed to impersonate svc_workstations to gain access to \dc01\svc_workstations, but the flag in flag.txt does not look right to me.|| Can anyone tell me what I missed or am doing wrongly?

azure saffron
#

yoo anyone having issues with Attack Tuning -> SqlMap module, flag5 issue? I've literally got the flag from the output flag5, but its incorrect apparently

weary owl
#

@zinc nimbus I used metasploit to crack SMB hydra doesn't always work right for SMB

#

I just finished this lab like 5 hours ago

next bronze
solar zodiac
#

hi everyone! I was wondering if anyone could nudge me on the last question of the skills assesment of the game hacking fundamentals module

#

i've identified the score in the data structure, but everytime i change it it reverts back to the previous score

#

i've tried seeing what opcodes write to the value, but it isnt rendering any results

#

any help would be greatly appreciated 🙂

torpid thistle
#

hi, all. I have to bother you with a noob question: I'm at https://academy.hackthebox.com/module/77/section/726 atm. I try to brute-force bobs smb password with crackmapexec. I crafted the coorrect prompt but I don't use a wordlist containing the actual password. The hint says 'Bob likes to use weak passwords.' What wordlist should I use? Is the hint pointing to a specific one? Or should the password even be 'guessable' by hand?

azure saffron
digital shale
solar zodiac
#

nevermind got it 😄

cloud urchin
torpid thistle
mint lodge
solar zodiac
#

the game fundamentals module was really cool! Academy rocks 🙂

gray cloud
#

well now I don't remember what I wrote

#

I'd appreciate that mods would've move the message upon deleting the thread :/

#

@autumn pilot

ebon minnow
#

VM's are messing up lol

gray cloud
#

Well anyway I'll try to ask again, I have a problem on the skill assessment for file upload module, I successfully uploaded a file and got /etc/passwd content but can't get the flag.txt file, tried to get a reverse shell through msfvenom, it uploads successfuly but kills the connection instantly when my nc is listening, hopefully somebody can help a bit

cloud urchin
gray cloud
#

nop

cloud urchin
#

you need to upload something that gives you command execution

gray cloud
#

I do upload the reverse.php file crafted with msfvenom the upload successfuly work

cloud urchin
#

you sent an xml payload to read /etc/passwd?

gray cloud
#

no

#

I used xxe payload with file:///etc/passwd

cloud urchin
#

you're doing the file upload module?

gray cloud
#

yes

cloud urchin
#

there's no xxe in that module

#

well there is but

gray cloud
#

whether it's with xss or xxe I still could read the /etc/passwd which is a good starting point to me

#

and it was xxe for me

cloud urchin
#

yeah you're right

gray cloud
#

but I can do it with xss too tho

cloud urchin
#

so you got it with the xml, you said no at first

gray cloud
#

mb

#

I upload the file with an xss payload through a JS function that call for the reverse shell on my server

cloud urchin
#

there could be protections in place to prevent that, so you'll need to find another way

#

you don't do it via revshell

gray cloud
#

so it means something is killing the connection when I try to rev shell ?

cloud urchin
#

i'm not sure, i didn't do it that way. i don't think it's intended to get a shell via msfvenom

gray cloud
#

Is there some kind of shell involved or should I only try to read what's stored on the server ? because if it's the second one I never succeed in reading other file at the same root folder level

cloud urchin
#

theoretically if you have command execution you should be able to get a shell, but if you have command execution to run msfvenom payloads, just read the flag instead

gray cloud
#

by using other techniques

cloud urchin
#

ok but you can execute commands right

#

so just get the flag for the skill assessment

#

you can practice that other stuff that's fine, but there may be other protections htb has in place to prevent that

gray cloud
#

that is true

distant island
#

Whats wrong here subverting query logic / sql injection fundamental module

#

SELECT * FROM logins WHERE username='tom' AND password = 'admin' or '1'='1';
SELECT * FROM logins WHERE (username='admin' or '1'='1') AND (password = 'something' or '1'='1');
SELECT * FROM logins WHERE username=" or '1' = '1' AND password = " or '1' = '1' ;
i tried everthing

#

yeah my bad i should write only tom OR '1'='1'
becasue the select for part already written

gray merlin
#

For the Attacking Enterprise Networks module. How do these two internal subnet ranges make sense? The 172.16.9.0-255 IP addresses are part of the 172.16.8.0/23 subnet.

ebon minnow
#

Module: Password Attacks
Subsection: Protected Files

Question: Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer.

My inquiry: where in the heck is Kiras password

#

😄

#

nvm

#

i think the vm was messing up earlier

next bronze
#

someone sent a message in general that crashes discord, wtf

#

any mods around

potent thorn
#

Hi guys. Can someone please help me on the attacking SQL databases section of Attacking common Services module?

I have connected to the database as htbdbuser using smqlcmd, and I am trying to force it to authenticate to responder and steal the hashes user the xp_dirtree funtion but can't get it to work.

Any help? these are my commands, I feel like I am on the right lines, as I don't know how else I would gain the pw.

sudo responder -I tun0


2> GO```
azure marsh
honest gyro
ancient ice
#

Guys does penetration testing job role helps to improve capture the flag skills or do I need to take bug bounty path for CTF skills just confused let me know

gray cloud
#

@cloud urchin coming back to you I actually don't execute command through XSS payload, I successfuly found the upload dir which is nice for what I want to do but can't wrap my head around how to upload a .php file that could successfuly execute my commands

#

though I don't know the way I interprated your message but XXE vuln allowed me to read the content of the upload and submit web page that allowed me to know what's the upload dir

gray chasm
#

Can anyone give me a hand with this question?

Password Attacks ---> Windows Credential Hunting

What are the credentials to access the Edge router (Format: username:password, case sensitive).

buoyant escarp
#

<@&861185840277487616>

ebon minnow
#

LOL

gray cloud
cloud urchin
cloud urchin
scenic slate
#

who is the owner of the website?

cedar yew
#

Hello guys,

Attacking Common Services - Attacking SMB

When I connect to SMB, I cannot read or download the id_rsa file and when I ssh, I get a permission denied error. What can I do?

cloud urchin
cedar yew
fresh plinth
#

I'm working on the FFUF module skill assessment where I'm supposed to fuzz a page that says You don't have access!. I'm guessing I'm meant to use a regex matcher (-mr) for this.

the command I've been using is ||ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -w academy-htb.subdom.txt:HOST -u http://HOST.academy.htb:49584/FUZZ -recursion -recursion-depth 1 -ic -v -mr "You don't have access" -e .php,.phps,.php7||, which I'm now guessing is too broad, because my problem is that the target machine is up for 90mins and my ffuf scan takes too long; it doesn't even finish the first scan (before recursing). Should I be using a different approach?

cloud urchin
cedar yew
#

I'm waiting for it to finish, but when I typed ssh jason@ip it gave me an authorization error without asking for a password.

cloud urchin
cedar yew
#

cme brute force

#

rackmapexec ssh 10.129.203.6 -u jason -p pws.list

cloud urchin
#

don't forget the --local-auth option for non-domain joined computers

cedar yew
#

I think we do not use this command when doing brute force.

#

while doing brute force

cloud urchin
#

no, you use the command when it's a non-domain joined computer.

#

has nothing to do with brute force

#

it has to do with the logon method, which is important when you're brute forcing logging into something

cedar yew
#

understand

#

trying

#

crackmapexec ssh 10.129.203.6 -u jason -p pws.list --local-auth

cloud urchin
#

ssh is slow

#

remember you're on the attacking smb section

cedar yew
#

im try hydra but not working

cloud urchin
#

yeah you can't brute force ssh.

#

use crackmapexec like the module shows you

cedar yew
#

yes but I couldn't read or download the id_rsa file so I decided to try ssh

cloud urchin
#

what was in the shared folder

#

im looking at this i dont think you brute force his pw here

#

but there's a share you CAN read, is there anything in there that may give jason's pw away?

cloud urchin
#

well the hint says this A colleague has shared with us a password list that we can find in the resource. He was able to compile this during his research.

cedar yew
#

aaa

#

understand oky

#

im trying smb not ssh

cloud urchin
#

ok i double checked im right

cedar yew
#

found cred

cloud urchin
#

yeah use smb, dont brute force ssh

#

nice

cedar yew
#

oky oky thx

quasi summit
#

Hi All, im in the Analyzing Evil With Sysmon & Event Logs module and am getting into the windows vm's ok. The module requires me to download stuff from the internet but there is no internet access on the vm's.I've already changed the pwnbox location many times. Please help.

dim wolf
quasi summit
#

there is no net acess though

#

no matter which country i connect to

#

i think it might be broken

dim wolf
#

it's not asking you to download that though

#

it's already on the machine

quasi summit
#

yes i checked that sysmon already is

dim wolf
#

and all targets you spawn will have no internet access

quasi summit
#

ah ok

#

i was not aware

#

so i ahve to find this git hub gile somewhere

#

*file

dim wolf
#

it should be easy to find

quasi summit
#

thank you

dim wolf
#

search for a sysmon config file (that is what is on the machine)

quasi summit
#

thanks again, ive been at this like an idiot

#

of course that makes sense

cedar yew
#

Hello Guys,

ATtacking common service - attacking sql databases,

im connect the sql server but not working my command

pine dagger
#

Need to select the DB first

cedar yew
#

I want to list the databases but I don't know what's in them right now.

pine dagger
#

or

#

wait, youre doing q1 or q2?

cedar yew
#

q1 q2?

pine dagger
#

there's two parts iirc

pine dagger
#

Yeah, there's two questions

cedar yew
#

yes

pine dagger
#

So are you doing q1 or q2? looks like q1

cedar yew
#

q1

pine dagger
#

Right

cedar yew
#

q =question

#

right?

pine dagger
#

so you shouldnt need to do any of those commands

cedar yew
#

i dont understand

pine dagger
#

Try the commands from the "Capture MSSQL Service Hash" section

cedar yew
#

oky

#

I couldn't run the commands he gave me.

potent thorn
# cedar yew 😐

I would say if you're running the commands with the IP that is hosting the sql database then you have misunderstood the section and need to go back a reread what it is actually telling you. You need to capture the hash.

vocal sphinx
#

Gotta start reminding myself to read the questions fully... Spent days trying to exploit something for sudo rights abuse and turned out they just wanted to know what could be exploited...

ancient parrot
tender acorn
#

No connection possible

Today i get the error Timers: ping 10, ping-restart 120 when i try to connect to the academy.
I try diffrent VPN connections nothing works.

Have today any other problems?
On the top of the site are a massage box
Exams VPN Scheduled Maintenance eu-academy-exams-2 eu-academy-exams-2 should not be used on 23/4 (10:00-11:00 UTC). Please use eu-academy-exams-1
Are this the reason? (i try difrent connections and it is the wrong day)

faint dragon
#

I'm on the amazing module Introduction To Splunk & SPL

"Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.

I hear this question is misleading.

I've played around with Range but the existing example in the docs sucks. Any discussion around range for SPL is about setting timeframes. Any help here?

I've used Bin for a 10 min timeframe but I think they want a rolling window

fathom pendant
fathom pendant
#

That's not an error btw

tender acorn
fathom pendant
#

Message support then, as you said it's on every vpn

#

¯_(ツ)_/¯

shut quest
shadow dune
#

Hello, I had a question about the Nessus labs. Am I suppose to install Nessus on my kali box and scan the vm? It tells me to scan another box that it has access to. I am confused on what to actually do. It's not very clear

#

I can SSH to the box, but I am not sure what to do next.

next bronze
normal sand
#

Is it alright for me to host my module notes on my Gitbook? Or is it against HackTheBox Academy's terms of service?

fathom pendant
honest gyro
#

hello guys im stuck at the last step in web attacks-skill assessment but for some reason the xxe dosent seem to work nor the xxeinjector i'd be glad for any info

normal sand
south falcon
#

Hi

glass quail
#

hey can I view directories with store XSS

valid viper
#

You can use stored XSS to redirect someone to an exploit that'll let you view everything...lol

glass quail
#

I don't have access to that just stored XSS that only I can view im trying find a way do some like cat

narrow nacelle
#

Does anyone know why I'm getting this error while using enum4linux to enumerate smb shares using a hosts file. If I do it one (IP) by one, it works.

valid viper
#

I mean if the lab is set up to run any script uploaded... You could probably pop a shell.

#

If we're talking in the wild, you need to wait for a user to execute the payload.

glass quail
#

rightr

nocturne flint
#

I need a nudge for "AD Enumeration & Attacks - Skills Assessment Part II". I was able to get a shell on SQL01. I am not sure how to proceed after that.

tawdry vapor
#

hi, can anyone help me wiht Windows Privilege Escalation Skills Assessment - Part II?

buoyant escarp
#

im waiting for ages, also tested with google.com but i dont get anything, nor an error

nocturne flint
valid viper
#

Or Bloodhound.

nocturne flint
#

Found the command that helped whoami /priv

valid viper
#

You said tool... Not command.

fathom pendant
valid viper
#

Hot wings.

#

😐

nocturne flint
wet coyote
#

hey everyone i'm doing Login Brute Forcing - Skills Assessment

on this question

Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside?

i got the user name and the password for the admin login page but when i login it re-load the page and doesn't login to the page

valid viper
wet coyote
# valid viper It's the exact same page?

like got access to the normal login page and then got the first flag and then when i try login to second one because there is a path for the admin page so when i try to login it re-load the page like i'm just re-fresh the page no result

valid viper
#

Does the login work?

wet coyote
#

for the admin login page no

#

i can show if you want

valid viper
#

How do you know the creds are correct?

#

Can't, I'm in a crappy signal area.

wet coyote
#

oh ok but i did use hydra and gave me the username and password but idk why it's not working

valid viper
#

Clear your cache.

#

Are you using the IP, or did you assign it a domain?

#

Try both domain and IP.

#

Try a different browser. Try pwnbox.

wet coyote
#

i did

valid viper
#

Reset the box?

wet coyote
valid viper
#

Last resort is to use curl or burp to see what it says.

wet coyote
valid viper
#

Damn... That's weird.

wet coyote
#

yeah lmao

valid viper
#

Maybe use Burp to brute force instead?

wet coyote
#

same result like i did everything you can think about

valid viper
#

Dayum.

#

@fathom pendant he needs halp.

fathom pendant
#

I haven't done this module

wet coyote
#

you can see the community-help

fathom pendant
#

Don't ping me. If I'm actively not helping I'm either busy or don't know enough to assist

valid viper
#

Understood.

wet coyote
#

the name login brute forcing - Skills Assessment

tawdry vapor
#

anyone can help me with first question in Windows Privilege Escalation Skills Assessment - Part II?? (Find left behind cleartext credentials for the iamtheadministrator domain admin account.)

twilit ruin
cloud urchin
glass quail
twilit ruin
#

oh thanks

#

that worked

glass quail
#

\o/

cloud urchin
#

just finished AD enum & attack. kinda rude how they onlt had PS 1.0 on there lol

glass quail
#

lol

#

is that the hard one

#

ADCS attacks

fathom pendant
#

It's a different module

glass quail
#

ok

#

congrats

cloud urchin
#

ADCS was really fun and really well put together

glass quail
#

nice will be excited when I get there

ebon minnow
#

for Johannas password, is 30 hours normal to brute force it?

#

module: password attacks lab - hard

fathom pendant
#

Use small lists first, and not against ssh

ebon minnow
#

yup, used the given list against rdp

#

using mutated now with crackmapexec

buoyant escarp
#

Attacking Common Services
DNS

what i tried so far and cant get any further
||dig any inlanefreight.htb atIP
here i find the nameserver, which i add into resolvers.txt
ofc is inlanefreight.htb in /etc/hosts
./subbrute.py inlanefreight.htb -s names.txt -r resolvers.txt||

cloud urchin
cloud urchin
#

in this module, the box you spawn is acting as the nameserver.

buoyant escarp
#

okay, so no need to get ns.inlanefreight.htb from dig

cloud urchin
#

i don't think you need to modify /etc/hosts at all, and just use the IP you spawn in resolvers.txt and you sohuld be able to complete it

fathom pendant
#

Yep

buoyant escarp
#

okay got the flag, i just hate dns stuff xD

topaz zenith
#

Can someone help me with the Windows Privilege Escalation - Weak Permissions. I keep trying to replace the binary with msfvenom and everytime I try to send it over I keep getting these errors: 10.129.225.128 - - [19/Apr/2024 15:12:48] "GET /service.exe HTTP/1.1" 404 - worked fine in the previous module.

cloud urchin
#

404 error means it can't be found on the web server

topaz zenith
#

I understand that. I don'

cloud urchin
#

check the folder location where you're hosting the server

topaz zenith
#

It's there

cloud urchin
#

make sure your msvenom payload is in the same directory

#

make sure the name is correct

topaz zenith
#

Yeah, i've done that, tried moving it into different directories, renamed it ect.

cloud urchin
#

also 10.129.225.128 doesn't look like a HTB vpn IP to me. is that your tun0 IP you're hosting the file on?

topaz zenith
#

Target: 10.129.225.128

cloud urchin
#

there really are only a couple of things that will cause it to 404. it can reach the ip you're giving it, but it can't find the file there. so you either have the wrong ip, wrong file, or the file isn't in the directory you're hosting the http server on.

next bronze
#

if it's there it wouldn't be a 404, take a look in your brower

topaz zenith
#

Yeah, its not there. But it's in the directory I am currently staring at in my terminal lol

#

SecurityService.exe bin boot dev etc home initrd.img initrd.img.old lib lib32 lib64 lost+found media mnt opt proc root run sbin service.exe srrstr.dll srv sys tmp usr var vmlinuz vmlinuz.old

cloud urchin
#

what is your tun0 ip?

topaz zenith
#

10.10.15.73

next bronze
#

...you placed it in your file root?

cloud urchin
#

and that's the ip you're running the web server on?

topaz zenith
#

Yes

next bronze
#

put it somewhere else and start the server there, in tmp maybe

topaz zenith
#

and I have placed it in different directories just to see if I was getting the path wrong

cloud urchin
#

why does your GET command say it's reaching out to 10.129.225.128 if you're hosting it on 10.10.15.73

eager bear
#

can I dm someone about zephyr pro lab?

topaz zenith
#

I'm trying to retrieve it from the target.

#

which is 10.129.225.1285

#

10.129.225.128*

cloud urchin
#

no, you're trying to download it to the target... aren't you?

topaz zenith
#

10.10.15.73 - - [19/Apr/2024 15:20:09] "GET /service.exe HTTP/1.1" 404 -

cloud urchin
#

why would you want to retrieve your msfvenom payload from the victim machine to your host machine? that doesn't make sense

#

maybe i'm just confused

topaz zenith
#

That is what Im using on the victim machine^^

#

from powershell

cloud urchin
#

what's your web server command

topaz zenith
#

python3 -m http.server 8080

cloud urchin
#

and it would probably be better to do what Xre0us suggested and try hosting it out of tmp or something

topaz zenith
#

Ok, I have a dedicated folder for HTB stuff I tried retrieving from first but i'll give her a try

cloud urchin
#

there are other ways as well, scp, smb server, xfreerdp and remmina can both share folders very easily so you can xfer via the gui

topaz zenith
#

It worked!

buoyant escarp
#

afaik when launchig http.server from python the root directory is where its started from

cloud urchin
#

noice

topaz zenith
#

Thanks guys!

topaz zenith
#

Same module, now everytime I try to start the service to trigger the reverse shell in my listener I get this on the target machine: The service did not respond to the start or control request in a timely fashion.

shut quest
cloud urchin
#

instead of creating a rev shell, keep it simple and just escalate yourself to admin

topaz zenith
#

Be nice to practice doing so

cloud urchin
#

nothing wrong with that and it should work

#

oh wow a whole new module appeared

next bronze
#

sick

buoyant escarp
#

im already stuck behind, there are so many modules xD

shut quest
#

Oh that looks like a fun module

ebon minnow
#

is this normal for the mutated list over rdp

password attack lab - hard

cloud urchin
#

probably. looks like you're using low thread count too. if you're bruteforcing RDP i would recommend crowbar, it's faster.

pseudo birch
# ebon minnow

That seems a little slow. 🙂 increase threads if you're using hydra. -t

shut quest
#

crowbar go brrr

pseudo birch
#

what protocol are you running it against?

ebon minnow
#

rdp

cloud urchin
#

crowbar would have had it cracked by now

buoyant escarp
#

Attacking Common Services
Email

i found a valid user via enumeration
now i try to brute this account via hydra on pop3, imap, smtp with the given pws.list from resources, but got no valid password. Do i need to make a mutated list, even tho it isnt mentioned in this module?

#

question 2

cloud urchin
#

no, you don't need a mutated list.

buoyant escarp
#

oh i think i know what might be the issue

shut quest
#

You need the pw list from that module

buoyant escarp
#

my format is wrong
username
username@inlanefreight.htb <---- this one

cloud urchin
#

is there one for that module> I used rockyou lol

buoyant escarp
#

got the creds now

#

men always i make stupid mistakes

cloud urchin
#

damn lol

ebon minnow
#

||crowbar -b rdp -u johanna -C ~/Desktop/Password-Attacks/new_mut.list -s 10.129.202.222/32||

#

is that good?

shut quest
#

did you run it? or asking?

ebon minnow
#

running it

quasi wave
#

hi I need a hint in the right direction. this is for hard lab on footprinting. I enumerated ssh and I see that its an Ubuntu server. I enumerated ssh with SSH ssh-audit.py and my results aren't very meaningful

#

what am I doing wrong here? do I try other ssh audit stuff?

#

I did nmap scans already which is how I found ssh is open

#

but don't have password which is my issue

#

I also see its aes encrypted so hashcat isn't gonna do it and neither is bruteforce right?

shadow dune
#

I had an issue with this earlier this week.

ebon minnow
shadow dune
#

Did you do a udp scan on nmap ?

quasi wave
#

to get open ports

shadow dune
#

thats where the creds are

quasi wave
#

ok

mint trout
quasi wave
#

why udp scan? I don't understand

#

aren't udp scans super slow?

#

do I need to do udp scan on ssh?

shadow dune
ebon minnow
shadow dune
#

you get creds from there and then everything makes sense

shut quest
shadow dune
#

@ me if you get it. I am going to the store for awhile. bbl

buoyant escarp
#

what program do you use for taking notes? i want to switch form my .txt to something more modern UI based

shadow dune
#

I use notion

rustic quiver
#

Hey guys quick question how do you ssh to a target with the user and pw?

shut quest
shadow dune
#

ssh [user]@host

buoyant escarp
#

thx ill have a look into them

midnight slate
zealous rune
#

i'm using obsidian, i find it decent.

rustic quiver
rustic quiver
south falcon
#

Anyone help me for injection attack

shadow dune
#

ssh htb-student@10.129.218.204

rustic quiver
#

it still refused the connection for some reason

shadow dune
#

you can ping the box ?

#

and port 22 is open ?

lavish mango
rustic quiver
#

I forgot to connect, thank you guys

lavish mango
#

Happens.

rustic quiver
#

Everything works now

#

magic

shadow dune
midnight slate
# dim wolf it should be easy to find

Please how can you find the reflective.dll.x64.dll file on the machine. Im stuck on the part where you are supposed to rename the dll file. Thank you

tulip dragon
#

i need help in FILE inclusion skill assement , i have found flag but i can't get the cat output from the flag , ping me

hexed oyster
#

Hi all, working on the "web fuzzing" module's skills assessment and need a sanity check. I've started the machine, configured my hosts file to point 'academy.htb' -> IP ADDRESS. curl -I IPADDRESS:PORT to verify it's up, curl -I academy.htb to verify my hosts file is configured correctly, and grab the host header as well. Question 1 asks me to perform vhost and subdomain enumeration on the target. I perform subdomain enumeration, then vhost enumeration, nothing is popping out at as indicating next steps. Given the above does it look like I'm missing something?

ebon minnow
shut quest
#

a minute or two iirc

shut quest
tulip dragon
ebon minnow
tulip dragon
#

i am seeing many people stuck in password modules now a days 🤔

shut quest
ebon minnow
midnight slate
tulip dragon
#

nah i solved that modules fast even though i am also noob

ebon minnow
#

||crowbar -b rdp -u johanna -C ~/Desktop/Password-Attacks/password.list -s 10.129.202.222/32 -v||

shut quest
ebon minnow
shut quest
ebon minnow
#

does capital or lowercase j matter in her name?

vital falcon
#

Hello everybody 😄 , can someone help with RDP bruteforce ? On password attacks, i got 3/4 flags, but the RDP one seams to not work , crackmap doesnt have anything , and hydra a lot of false positives ..

hexed oyster
#

Is there a better place to ask this question?

fathom pendant
#

Nope

#

This is the right channel

ebon minnow
#

||crowbar -b rdp -u Johanna -C mut_password.list -s 10.129.202.222/32 -v||

#

ok

shut quest
ebon minnow
#

its exactly what i typed and mutated a fresh copy of the given lists

ebon minnow
shut quest
#

wc -l mut_password.list should give you 93912

ebon minnow
#

i got double that lol

#

this was before but i ignored it because false positive

shut quest
ebon minnow
fathom pendant
shut quest
ebon minnow
#

curse word!

fathom pendant
#

Unless they updated it

#

It was missing last time I checked it

ebon minnow
#

its missing lol

vital sphinx
#

Any updates on rass issues posted bout it last time

fathom pendant
#

Like I said from the cheatsheet

#

That's from the section itself

shut quest
fathom pendant
ebon minnow
#

reassuring

#

once more into the breach

#

worked

shut quest
zealous sandal
#

Can someone help me in the Pentester Testing module, Footprinting smb section, there is a question that I can't find the answer to.

mint trout
grave path
#

I'm doing Module 211, section 2276: SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe)

I performed all the steps and the timeframe mentioned in Mar 5, 2023 to now. The question asks me to input the common date when all events were created.

However, the creation date is before Mar 5, 2023 and I've tried creating the dashboard multiple times with different time fields, yet the answer is same. What should I do?

zealous sandal
shut quest
buoyant escarp
#

Try enum4linux
Lost my notes so i cant confirm for sure 🙄

zealous sandal
shut quest
grave path
shut quest
grave path
shut quest
high reef
#

I've found the exploit but when i run it i get nothing back

limber river
#

new module

high reef
#

any help greatly apprecaited

#

any help

limber river
high reef
limber river
#

did you find the first answer ?

high reef
#

thats how i was able to find the RCE

dim wolf
#

HTB CADE certification?

limber river
high reef
grave path
limber river
#

but the application is it hosted on linux/win ?

high reef
#

windows

limber river
#

so the problem from the payload you use

limber river
limber river
# high reef

did you setup your listener because , I got hit using this

limber river
# high reef

try to remove the single quote -Uri http;//ip:port"

high reef
limber river
#

this just for testing that the vulnearable exists

sinful drift
high reef
rustic sage
#

Hi all

I'm currently on the Hard lab for Password Attacks, I've tried a few things to get past where things are at and I've hit a wall.
Cracked the RDP password for Admin but can't connect via RDP
And the password doesn't work for the file needed, I'll avoid spoilers.
Can anyone give me some guidance on this one?

limber river
high reef
rustic sage
# shut quest What error for rdp?

Doesn't connect at all, I checked the Admin account groups and it should be RDPing in. Perhaps the password from the mutated password list is wrong for the Admin account? But hydra looks to have a correct match

limber river
high reef
#

thanks for your help

shut quest
rustic sage
#

@shut quest I get 94044 from wc -l

shut quest
wanton idol
#

for the web attacks Bypassing Encoded References, what other method would have been easier to do to accomplish that section bc i made a whole python script then used curl to download all of the pdfs

wet coyote
#

i tried curl and nothing

shut quest
mint trout
#

service scanning... the hint is 'bob has a weak password'.. i tried spraying smb and telnet, i see tomcat am i meant to be exploiting this for a shell or am i overlooking something super simple..

austere oracle
mint trout
#

yes but not uppercase hold on.............

#

nah still cant get in.. tried Bob, bob, Bob!, bob1 etc

#

using GS-SVCSCAN/bob

#

do these labs still have account lockouts? should i try reset

austere oracle
#

Injection Attacks: Skills Assessment
I've found the PDF Generation vulnerability and am looking to read the source code of the internal site. Can anyone send me a message to help with that?

onyx rapids
#

WHITEBOX ATTACKS - Privilege Escalation

I feel like a newb having to come out and ask for help on the first question, but I inserted the payload they provided, got the 400 error and tried to visit /admin, but I still get redirected. Am I missing something here?

nocturne flint
#

I am confused about the module "Windows Privilege Escalation" - "Initial Enumeration"
The answer to the question "What non-default privilege does the htb-student user have?" isn't what I expected. The state of the privilege shows as ||"Disabled"||. So why is the answer that?

wanton idol
shut quest
silent burrow
#

hello guys, newb here... I just enrolled for the SIlver plan, and want to unlock the Getting Started module or any module, but I press UNLOCK and nothing happens, sorry if this is not the place to ask this questions... thanks for your help

shut quest
silent burrow
#

ok thx

mint trout
shut quest
silent burrow
cloud urchin
random pulsar
#

Can someone help me or give me a hint on this question: 'find through SPL searches against all data the process that started the infection. Answer format: _.ex '”

dim wolf
shut quest
mint trout
#

hm it actually is in 2023-200_most_used_passwords.txt

#

fml in crackmapexec i forgot to put domain/user

#

thank god i wont make that mistake again.. id probably cry if i did that in the exam

cloud urchin
mint trout
shut quest
#

I even did a search on the academy and it didn't return for that module

cloud urchin
shy aspen
#

Network Enumeration with Nmap - Host and Port Scanning

is there ever any practical reason we would want to disable ICMP echo requests or ARP pings with -Pn or --disable-arp-ping, or is it just used in this module to illustrate the different scan types?

rustic sage
#

They're commonly filtered out to block those packets

shy aspen
#

ah ok, so if nmap doesn't receive replies to those packets, it labels those ports as filtered right?

rustic sage
#

by memory if nmap cannot determine whether its open or closed it can return filtered

#

if its firewall blocked it should say filtered

#

you can use the --reason to get results on the ports

#

I may be wrong but that's by memory

shy aspen
#

ok thank you!

rustic sage
indigo locust
#

has pawnbox acting up today for anyone? it stop/terminates itself after ~10 minutes and then have to respawn it again

tiny brook
#

Hi all

jade latch
#

on attacking common services sql portion. i cant sudo apt install sqsh or run mssql-cli because of its numerous errors.
mssql
fixed import lines where it has called a deprecated library from 3.9, but another error from a function popped up. i tried to download python3.9, but apt can't find it. mssql-cli should be a lost cause, and it's a bigger problem that i somehow can't install python3.9(i can install other packages)

#

ah i forgot pwnbox existed

tiny brook
#

I need some help

acoustic owl
frail dawn
#

Could someone give me some help with Information Gathering - Web Edition First question of the virtual host section?

Enumerate the target and find a vHost that contains flag No. 1. Submit the flag value as your answer (in the format HTB{DATA}).

I'm doing ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/namelist.txt -u http://10.129.226.112 -H "HOST: FUZZ.inlanefreight.htb" -fs 10918

but i'm not getting any hits. What am I doing wrong? Thanks in advance

I've also tried FUZZ.www.inlanefreight.htb as well

wary magnet
#

hi guys!

seeking home help with server-side attacks skills assessment.

||i have found the url from a javascript file. when i try visit the url. it just displays "are you sure?" and nothing else. ||

is there anything else i'm missing to get the flag?

Edit: I'm blind. lol

cloud urchin
frail dawn
cloud urchin
cloud urchin
#

in the pic i took i used the url though

#

make sure you have www.inlanefreight.htb added to your /etc/hosts file

frail dawn
#

@cloud urchin Well ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/namelist.txt -u http://10.129.226.112 -H "HOST: FUZZ.inlanefreight.htb" -fs 10918 didn't get any hits,

but ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/namelist.txt -u http://www.inlanefreight.htb -H "HOST: FUZZ.inlanefreight.htb" -fs 10918 does give me hits.

and yeah I got both www.inlanefreight.htb and inlanefreight.htb in /etc/hosts. Thanks for the help.

frail dawn
fringe urchin
cloud urchin
#

are you visiting the vhosts?

frail dawn
frail dawn
fringe urchin
next bronze
#

iirc for vhosts you'll need to use the domain and not the ip

fringe urchin
next bronze
fringe urchin
#

but was using pwnbox so maybe thats why it worked for me

next bronze
frail dawn
next bronze
#

huh why are the subdomains before www

limber river
#

what the heck is this

limber river
#

i don't understand this

fringe urchin
#

you added to every subdoman a www which isnt correct

limber river
frail dawn
#

That makes sense. I thought I needed the www because of this

next bronze
#

www is already a subdomain, if you want to visit another, you'll need to replace that

#

subdomain.domain.tld

#

that's the format for urls

frail dawn
#

right. I thought I was supposed to find sub domains of the sub domains lol

frail dawn
limber river
next bronze
#

did you add specifically inlanefreight.htb to your hosts file

limber river
#

if you trying to get access to www.inlanefreight.htb just add it to you /etc/hosts

frail dawn
fringe urchin
cloud urchin
#

worked fine for me

#

you mentioned earlier this also worked for you, add the vhosts you found in your /etc/hosts and visit them for the flags

echo gulch
#

Aha, I need a lot of heat on the roads for five bucks TR300006400000134032350237

fringe urchin
frail dawn
fringe urchin
#

whats the size of the valid sites?

echo gulch
#

whats the size of the valid sites?

#

Aha, I need a lot of heat on the roads for five bucks TR300006400000134032350237

frail dawn
#

I'm not getting anything 😦

cloud urchin
#

your command is not the same as mine

limber river
#

-H.......?

frail dawn
cloud urchin
#

show your /etc/hosts

#

if you have the correct vhosts in /etc/hosts with the same ip as the www.inlanefreight.htb one, it should work

#

actually don't show your /etc/hosts because that'd probably break rules

#

but i'm guessing that's the issue, because if you don't set that up then you'll get the default apache page

frail dawn
# cloud urchin show your /etc/hosts

Got it. I still has the subdomain.www.inlanefreight.htb in my etc/hosts.

Thanks for the help everyone. That took way more time than it should of lol

kind venture
#

Hello everyone!
I am here to ask for your support in fixing an OpenVPN error. As shown in the course, when I try to connect using the "academy-regular.ovpn" file, I encounter an error: "WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set."

This occurs when I try to open the file from the downloads folder. When I try to open it without navigating to the folder, it displays the error: "Options error: In [CMD-LINE]:1: Error opening configuration file: academy-regular.ovpn."

I have tried all the solutions from forums, YouTube, Reddit, and even searched for a solution on the TryHackMe forums regarding OpenVPN, but I couldn't resolve it.

I have attempted to connect to all the servers and even changed to TCP 433, but I still couldn't fix it. So, I'm reaching out to ask for your help. What could be the solution? Am I doing something wrong?

I have attempted to connect using both the website and VMware. In my VMware, I'm using Parrot OS HTB.

next bronze
#

that looks fine, I don't see any errors about opening the config file

#

run ifconfig, if you see an ip for tun0 you're good, open another terminal and do your things

kind venture
#

I did as you told, run ifconfig, my ip is still the same but I can see tun0.
Does this mean I am connected? @next bronze

next bronze
#

sudo killall openvpn, connect again, then go do a module

kind venture
limber river
#

try to ping your target

kind venture
#

Wow! Let's do this!

#

Let me try and come back here again.
Thank you @next bronze

next bronze
#

yeah you're good

limber river
next bronze
#

I'd recommend doing the Information Security Foundations path

kind venture
limber river
kind venture
#

@next bronze @limber river Okay! I will do that. Thank you 👍

fringe urchin
#

Doing password attacks, network services
just having a question about RDP, did someone try it with crackmapexe? i saw its not covered in the module but when checking out crackmap it has the possibility?

cloud urchin
#

yeah it can

#

crowbar probably still better for rdp

next bronze
#

hydra works with rdp

fringe urchin
fringe urchin
cloud urchin
#

i didn't use CME for it, i used crowbar

fringe urchin
#

ah ic

#

ssh and winrm both went flawlesly with crackmap, dont know yet why rdp doesnt function well

cloud urchin
#

btw ~ is the shortcut for your 'home directory' so you can just do ~/Desktop/pass.list or whatever

next bronze
#

imagine still using cme

cloud urchin
#

don't mad dog cme

fringe urchin
#

well cme isnt worked on anymore so maybe that broke something with rdp, ill use hydra

fading oracle
#

Hi all! i am doing LDAP module this is the question..What is the domain functional level?
i am doing my query but the answer is wrong..
also tbh 1000 cubes for this module is a theft...

next bronze
#

which section is that

#

also lmao I agree

cloud urchin
#

yeah i thought it was pretty weak for a 1000 cube module..

fading oracle
#

LDAP Anonymous Bind section

#

i mean i am using the go version of windapsearch which is only 4 years old

stark fractal
fading oracle
#

in the module the tool they recommend is 8 years old

next bronze
fading oracle
#

in this version its the metadata is the equivalent

cloud urchin
next bronze
cloud urchin
#

Xre0uS' command will work too

fringe urchin
stark fractal
#

I guess I'll keep a note so I can submit it later haha

kind venture
#

Hi again!
I was able to connect with ssh htb student..... but when I type the password it says Permission denied.

#

Am I missing something?

next bronze
#

enter the right password then 4Head you can copy and paste

#

and in the future, include the module and section so that people will know the context

civic locust
#

I have problem with last question of module Network Services

#

Hey. Why i am getting
smb: > ls
NT_STATUS_ACCESS_DENIED listing *

#

I've found credentials of john... (Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer.)

cloud urchin
#

access denied is a permission issue, the user you're using doesn't have permission to do that

civic locust
#

But how am i supposed to do it then? I've used bruteforce smb with given pass-user lists and found john credentials. There are no other occurencies

cloud urchin
#

how did you brutce force it?

civic locust
cloud urchin
#

then you'll need to --continue-on-success or use another tool

inner sand
#

because there are modules i still didnt finish

fringe urchin
inner sand
#

ok that makes sense

#

thnx

umbral fulcrum
#

hey guys, someone up for a little help on "Exploiting Web Vulnerabilities in Thick-Client Applications" section in
"Attacking Common Applications" module please ??

next bronze
#

was planning to do the Active Directory Trust Attacks module but the target won't spawn

#

guess I'm not doing it shruge

umbral fulcrum
next bronze
#

yeah I have thousands of cubs to be used

limber river
#

share some cubs , I am poor

#

xD

next bronze
#

just get money 4Head

limber river
#

you push me to do bad things

fringe urchin
#

Pedro me doing mutated passwords section

#

got itpepefriends

covert vortex
#

Hi there! can someone help with Password attacks medium lab? I've got zip archive from smb share, but when trying to crack the password of it, by using john and multiple password lists with different formats - im just getting nothing

rustic sage
hoary harness
#

hello, I'm new in cybersecurity and im trying to learn through the HTB : academy (path : Information Security Foundations). I like to understand and manipulate tools but in module : "Setting up" there is a lot of things that's seems not mandatory but also usefull. I don't get the point of talking about thoses things but not make it clearly understandable like Tmux (a video of a man just speed running options and his keys binding), modifying bashrc to modify the prompt but writing just after that to keep it simple, talking about command and vps but not explaining how to setup one (just some specific case where it would be usefull were told).
It feels like If i dont get knowledge about that I would skip some important info but it also feels like it s not important. Can someone tell me if I should just going trought like it s ok to not understand it at 100% (sorry bad eng I m a bit confuse about this module)

rustic sage
#

It's OK 👍

#

You can't understand everything about hacking

hoary harness
#

so what the point of doing all that if it's not usefull...

next bronze
#

a lot of things you'll need to research yourself if you want to know more, tmux, bashrc and vps could be modules on their own, but they're not essential to finishing the path, they're good information for you to know and explore yourself

hoary harness
#

thanks for clarification!

vital falcon
#

Hi guys , anyone who completed the module password attacks that can explain me why my RDP brute force is not working ? :/

vital falcon
#

I tried these commands , they show output , but only false positives :/

#

I got 3 out of the 4 flags , just the RDP one is not working , kinda frustating :/

fringe urchin
#

Iirc cme wasnt getting worked on anymore.
So most likely something broke with maybe a new rdp version.
Just dont use cme, use hydra or smthing

vital falcon
#

Hydra was the same thing :

#

Just in case , I'm using the list they provided , and I added inside the users found in the sever

potent thorn
#

Can anyone who has completed the attacking common services easy lab please dm me? I have got the flag but apparently there are two methods and I'd like to understand thhe second one

fringe urchin
#

Yea command looks good, worked for me like 3 hours ago(from what i can remember)

vital falcon
buoyant escarp
#

Oh nvm now i see it

vital falcon
#

No , is there a diference ?

fringe urchin
#

shruge it could help

vital falcon
#

Ok let me try 🫡

fringe urchin
vital falcon
civic locust
#

Hey.

hydra -l fiona -P /usr/share/wordlists/rockyou.txt 10.129.59.142 smtp -t 64 -f```

I am trying to get through "Attacking Common Services - Easy". Found username with smtp-enum but now struggling to bruteforce smtp. I've tried rockyou.txt and provided passlist but notjing has shown up. Any hints?
fringe urchin
#

pepeSadge sorry

vital falcon
#

Yes , I'm lauching hydra in pwnbox, because I thought it would be easy ahhaha

No problem , thanks already for helping mister !

fringe urchin
#

You did the last question aswell? Im pretty sure there you find the rdp password aswell

vital falcon
#

the SMB ? Yes I did

#

Oh really ? looking in the shares ? or dumping ?

fringe urchin
#

When cracking it, if you left it at user.list and password.list
It found every password we used before for other services

vital falcon
#

Using cme ? It only gave me 2 users not all

fringe urchin
#

I think i used hydra for smb aswell, and it gave my others too. Like 4 together iirc. Ill be home in 10-15min so i can double check

#

Maybe used cme tho since i had to use --continue-on found or whatever is the command

vital falcon
#

Yes, I need to get the laptop so I can tell you what I used , I think hydra for ssh ,smb user , cme for winrm and smb shares , not sure tho

tribal plinth
next bronze
#

was eu-2 I think, switched to us-3 and it's fine

tribal plinth
#

Thank you, I will verify from our end as well.

fringe urchin
vital falcon
#

Yeah I don't know , rackmapexec is not even working anymore

fringe urchin
vital falcon
#

update : finnaly did it 😄 thanks

cloud urchin
fading oracle
#

Hey guys. i am doing skills assesment on the LDAP module.What non-default privilege does the htb-student user have? this is the question, i saw earlier someone told that i need to run an elevated powershell but its not possible.

wet coyote
fading oracle
#

this shit module cost 1000 cubes

#

outdated as f****

#

chatgpt makes better queries

#

and it is very slow

#

a copy paste takes 20 second

#

well i tried all privs one worked..

shut quest
# wet coyote all of them

I don't know what to tell you then since all of them does not tell anyone anything when there's only one thing in the section I said to look at was and you replied a while back curl which also is not on that page.

fading oracle
#

😄

next bronze
mossy garden
#

All of them

autumn pilot
covert vortex
next bronze
#

indeed

fringe urchin
#

How is the module?

next bronze
#

not sure yet, still on the first part, but seems pretty good

cosmic grail
#

Are there any free Active Directory machines on HTB?

sly kelp
runic fox
#

Guys am fresh student need someone who'd want to help me.witb just feel knowledge when I stuck on a question..thank you guys

digital portal
#

Doubts in Broker HTB machine(Privilege escalation), Anyone?

worn edge
#

hello guys im new to linux and im taking the linux fundamentals course. Could anyone help me with the second task?

#

It may be a bit overwhelming at first to deal with so many different tools and their functions if we are not familiar with them. Take your time and experiment with the tools. Have a look at the man pages (man <tool>) or call the help for it (<tool> -h / <tool> --help). The best way to become familiar with all the tools is to practice. Try to use them as often as possible, and we will be able to filter many things intuitively after a short time.

Here are a few optional exercises we can use to improve our filtering skills and get more familiar with the terminal and the commands. The file we will need to work with is the /etc/passwd file on our target and we can use any shown command above. Our goal is to filter and display only specific contents. Read the file and filter its contents in such a way that we see only:

  1. A line with the username cry0l1t3.
  2. The usernames.
  3. The username cry0l1t3 and his UID.
buoyant escarp
#

cat /etc/passwd | grep cry0l1t3

austere oracle
#

Injection Attacks: Skills Assessment
I've found the PDF Generation vulnerability and I've found the XPATH injection, but I'm unable to get any useful data from it. I haven't figured out how to read the source code of the internal site, either. Can anyone that's completed this offer me a nudge?

snow ridge
timid hazel
#

Could anybody send me the answers for Practical Digital Forensics Scenario and Skills Assessment (SOC Analyst)? Thank you

cloud urchin
#

nah

fringe urchin
acoustic owl
sleek moss
#

What stuff in the cpts path doesn’t need for oscp?

acoustic owl
frail dawn
sleek moss
#

I c

fathom pendant
buoyant escarp
#

ah right

fathom pendant
#

You can just do grep "pattern" file

#

And you can do multiple files this way

buoyant escarp
#

nice, didnt knew that

fathom pendant
#

I believe as well if you add -n it'll tell you line number it's been a sec

#

-A, -B, and -C are context flags

#

A for after, B for Before, C for context around so like a combination of a and b

violet pasture
#

I'm currently going through the starting point machines, on sequel. I can scan the target with nmap, however if I use any flags in my scan it gets stuck at 0%. My next task is to obtain the version of MySQL running, however if I use nmap -sV <IPADDRESS> it gets stuck, and also tried nmap -sV -p 3306 <IPADDRESS>. Also tried sudo. However if I just use nmap <IPADDRESS> it works fine. Any idea?

fathom pendant
buoyant escarp
#

Attacking Common Services - Easy
what a great lab, realy enjoyed it, my struggle was not using rockyou, i tought i have to use the lists from resources :/

#

btw i used the way with mysql, not the way with the XAMP vuln

uneven dune
#

where i can report a possible bug in a module ?

pine dune
#

Hi

#

I need help with this command

#
echo 'W1BIUF0KCjs7Ozs7Ozs7O...SNIP...4KO2ZmaS5wcmVsb2FkPQo=' | base64 -d | grep allow_url_include

allow_url_include = On```
ocean night
#

Explain what the problem is you're facing - that command is valid, but what do you expect it to do?

pine dune
#
  1. that is not my command...when I ran the first command I saved it to a file called phpgrep.txt
#
  1. I want whatever command I run next to say "allow_url_include = On"
#

I had to save the very first command I ran to a phpgrep.txt file as I couldn't paste the content to the screen as it was too big

ocean night
#

That step is simply to demonstrate encoding text in base64, for use in the next step in the module

pine dune
#

ill tell u the commands I ran

#

cat phpgrep.txt | base64 > new.txt | grep allow_url_include

#

before I ran the above command I ran this

#

curl "http://<SERVER_IP>:<PORT>/index.php?language=php://filter/read=convert.base64-encode/resource=../../../../etc/php/7.4/apache2/php.ini"

ocean night
#

That step is part of information gathering. This is used in the next step in order to achieve your goal.

pine dune
#

this module didnt say anything about information gathering?

ocean night
#

You're reading the PHP config, and checking to see if an option is enabled

#

Confirming it is means you can continue to utilise the method described in the next step

#

You gathered information by reading data from the PHP config file on the target

#

This allows you to determine what method you could use to move further in to the target

#

Read up on what the allow_url_include option actually means and enables

#

It's also described in the module

pine dune
#

yes it should say "allow_url_include = On" and not just give me a bunch of random strings, right?

ocean night
#

The fact you got that output means you have confirmed that option is enabled in the PHP configuration on the target

#

Move to the next step, Remote Code Execution, it may make more sense then 🙂

#

Essentially the request you sent above utilized a feature in PHP to use filters to perform actions on the target. Some actions are enabled by default, others are not.

#

The action in that step allowed you to retrieve the php.ini config file from the target, in order to determine which options are enabled on the target.

pine dune
#

thank you..its kinda hard to understand this particular page atm and I'm not enjoying it 😦

ocean night
#

Maybe re-read the previous section on PHP Filters

#

You'll get it 🙂

pine dune
#

shouldn't it create a shell for me? or am I mistaken?

ocean night
#

That step should execute a command and return the output. I'm afraid I can't stick around to help any more, I need to turn the light out and go to sleep

#

For last bit of help, DM me the output from that command

pine dune
wanton idol
frail dawn
#

could use some help with ATTACKING WEB APPLICATIONS WITH FFUF skills assessment: One of the pages you will identify should say 'You don't have access!'. What is the full page URL?

I got the correct answer, but only because someone posted it in here, and I saw the endpoint.

Why does ||ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://faculty.academy.htb:31822/courses/FUZZ -recursion -recursion-depth 3 -e .php,.php7,.phps -fs 287 ||

or ||ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://faculty.academy.htb:31822/FUZZ -recursion -recursion-depth 3 -e .php,.php7,.phps -fs 287||

not reveal the file for this question? The correct endpoint is clearly in the ||directory-list-2.3-small.txt|| wordlist. It should only take ||5641|| or so requests to find it, but i'm at almost 200K request with no hits.

What am I doing wrong?

pine dune
#

stuck on this page

wanton idol
pine dune
#

how to execute rce on the website

#

can I please dm u?

wanton idol
pine dune
mint trout
#

struggling spawning machine, specifically "Nibbles - Enumeration", stuck on " Target is spawning..."

shadow ginkgo
mint trout
#

just got an ip kek

#

try refreshing and spawning

ocean night
#

It can take a minute sometimes

mint trout
#

i notice when its working and you refresh, it stays spawning, if its not working or stuck and you refresh it will ask you to spawn

ocean night
#

Likely due to events pending to be published to the browser - unsure if the state is polled on page load or not, I would have thought so.. but I don't know 100%

wanton idol
#

but for me i couldnt spawn it at all for a couple of days 💀

fathom pendant
#

I think it's some mix of the call not going so it stays in the loading state

#

I.e. pushing the power button but nothing turns on

ocean night
#

..I think

#

Hm no, I see machine is spawning after a refresh still

fathom pendant
#

Interesting