#modules

1 messages · Page 249 of 1

rustic sage
#

Pls help me

radiant eagle
#

Does anyone is having issues this last week with the academy?

fathom pendant
#

targets have been spawning and responsive

#

¯_(ツ)_/¯

gray merlin
#

I have not had issues either.

rapid citrus
#

Question

wraith delta
#

Hey guys ive been trying to run mimikatz on a evil-winrm session but it doesnt seem to work and just starts spamming these ####
Evil-WinRM PS C:\Users\svc_sql.INLANEFREIGHT\Documents> cd mimikatz
Evil-WinRM PS C:\Users\svc_sql.INLANEFREIGHT\Documents\mimikatz> cd x64
Evil-WinRM PS C:\Users\svc_sql.INLANEFREIGHT\Documents\mimikatz\x64> .\mimikatz.exe

.#####. mimikatz 2.2.0 (x64) #18362 Feb 29 2020 11:13:36
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)

/ \ ## /*** Benjamin DELPY gentilkiwi ( benjamin@gentilkiwi.com )

\ / ## >

'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > / ***/

mimikatz #
mimikatz #
mimikatz #
mimikatz #
mimikatz #
mimikatz #

rapid citrus
#

I am white hat

#

But I want to became black hat how

wraith delta
#

hahahaha

acoustic owl
rapid citrus
#

Ok

#

Thanks for fucking questions

haughty tree
#

Hey, this is referring to the NFS section in Footprinting module. Can somebody explain to me what the solution to the problem raised here is? I don't know if my english is just trash but I can't understand what they're explaining here

fathom pendant
#

./mimikatz.exe "<command>" "exit"

wraith delta
#

can i specify 2 commands?

fathom pendant
fathom pendant
#

so "<command1> [args]" "<command2> [args]" "exit"

#

it's very important that you add the "exit" at the end

#

otherwise you get the repeated prompt loop

haughty tree
wraith delta
#

thanks again how do u know all this 😆

haughty tree
#

btw, congrats on community contributor I apperciate you helping

fathom pendant
#

also a lot of the cheatsheet stuff that uses mimikatz will highlight that syntax

rustic sage
#

.

slender night
#

Me too bro I'm genuinely angry it's been 2 days now

strange pivot
#

Quick question, I've done AD assessment 1, but I couldn't load powerview modules or use them during the assessment, is that intentional? Or was I doing something wrong?

snow ridge
strange pivot
#

I did that 😛

#

I even tried with . .import

snow ridge
#

Did you get any errors?

#

Because it should work, maybe you had a broken copy

strange pivot
#

it just wouldnt recognize the cmdlet modules lol

#

I managed to pass it though, but it would of been nice to of been able to use it to enumerate the users etc...

fathom pendant
#

but everything is doable without it

strange pivot
#

How do you mean load it in a different way?

#

Was it how i was importing it?

fathom pendant
#

sorry not powerview

#

but activedirectory

#

but import-module should work if you bring in the ps1 file for powerview

#

iirc

strange pivot
#

Maybe i wasn't in the right directory when importanting it 🤔

fathom pendant
#

it just doesn't work well in a webshell

strange pivot
#

I used msfvenom and gained a regular shell with that

#

The meterpreter shell wouldnt work

fathom pendant
#

¯_(ツ)_/¯

#

meterpreter is interesting

#

after finding credentials from q1/2 i just used a pivot to do the rest

#

ligolo was my go to

strange pivot
#

I used netsh, to gain rdp, then i used it again to gain a winrm session

#

chisel wouldnt work for some reason 😮

fathom pendant
#

chisel is dum ¯_(ツ)_/¯

strange pivot
#

I'll have to give that ligolo a go

dim wolf
#

certified ligolo-ng shill

#

give it a try after you complete the module

fathom pendant
#

also remember because it's a webshell infinite loading when an output would result in either no output/loading until cancelled means it's working

#

i.e. doesn't print output/is a polling output

radiant eagle
#

Hi, can an admin see whats going on with the module ATTACKING ENTERPRISE NETWORKS , im trying to finish the module from the pwnbox but i have a lot of connection problem with the target

fathom pendant
#

this contains a spoiler

#

different types of password dumps exist

radiant eagle
fathom pendant
wraith delta
#

Hey guys i need help with getting the users t***** on ad skills assesment i dont seem to get anything whend umping on MS** :Evil-WinRM PS C:\Users\svc_l.INLANEFREIGHT\Documents\mimikatz\x64> .\mimikatz.exe "privilege::debug" "sekurlsa::logonpass**" "exit"

.#####. mimikatz 2.2.0 (x64) #18362 Feb 29 2020 11:13:36
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)

/ \ ## /*** Benjamin DELPY gentilkiwi ( benjamin@gentilkiwi.com )

\ / ## > http://blog.gentilkiwi.com/mimikatz

'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > http://pingcastle.com / http://mysmartlogon.com ***/

mimikatz(commandline) #
Privilege '20' OK

mimikatz(commandline) #
Authentication Id : 0 ; 230195 (00000000:00038333)
Session : Interactive from 1
User Name : t***

Domain : INLANEFREIGHT
Logon Server : DC01
Logon Time : 5/8/2024 10:30:06 AM
SID : S-1-5-21-2270287766-1317258649-2146029398-4607
msv :
[00000003] Primary
* Username : t****
* Domain : INLANEFREIGHT
* NTLM : fd37b6fec5704cadabb319ceb****
* SHA1 : 38afea42a5e28220474839558f073979645a1192
* DPAPI : da2ec07551ab1602b7468db08b41e3b2
tspkg :
wdigest :
* Username : t***
* Domain : INLANEFREIGHT
* Password : (null)
kerberos :
* Username : t****
* Domain : INLANEFREIGHT.LOCAL
* Password : (null)

fathom pendant
#

admins/staff really can't do much without a ticket open

#

and even then, not all admins are staff - support staff doesn't necessarily monitor the discord

fathom pendant
#

lsass and lsa are different, so they may contain different results

wraith delta
#

Ight lemme check it out

rustic sage
#

.

proven willow
#

Hi guys, I'm doing the "Attacking Authentication Mechanisms", I'm to the "Algorithm Confusion" of JWT, but after that I run jwt_forgery.py, get the public key and generate the new JWT with CyberChef, I cannot solve the assessment at the end of the session because the server replies always with "Token is invalid"
Did someone solve it?

fathom pendant
#

while sqlmap does the thing

haughty quiver
#

I feel so dumb
On the first section of the web requests module, I was trying to use the cURL command as:

curl -o /download.php (IP here)

Instead of:

curl (IP here)/download.php

#

I spent half an hour trying to find out what was wrong 🤣

fathom pendant
#

been there before

#

also get used to them sometimes throwing in webroot to mean http://ip:port/

haughty quiver
#

I got confused by them saying you can use -o to select the file name to be downloaded

#

Well, I'm brand new to all of this

#

Setting up a VM for doing the challenges was already quite a ride lol

acoustic owl
#

Sorry, I've lost track. Which module are you talking about?

acoustic owl
#

This one?
What is the password for the htb-stdnt user?

#

If yes, you should answer this question with the output from a tool from the first question

#

Try it with the ||Database||

dim kettle
#

i did everything a module asked me to but i cannot find the flag

random bear
#

How do i find my IP of my pwnbox? if config is bringing up 192 address and 127 address. on my OpenVPN Connect, it says Your Private IP (IPV4) but when I try to ping the machine from a target machine it doesn't work. I set up a httpserver and its not connecting via that Private IP 10.10.xx.xxx

fathom pendant
#

the ip will be the tun0 adress

#

also by pwnbox do you mean the in-browser vm or your own

random bear
#

my own

fathom pendant
#

since you mention OpenVPN Connect

random bear
#

i have no tun0 address

fathom pendant
#

are you running the vpn in your vm or on your host

random bear
#

host

fathom pendant
#

you should be running the vpn in your vm

random bear
#

ah...

#

ive been doing labs with that on host for 95% of cdsa modules

fathom pendant
#

¯_(ツ)_/¯

#

it seems generally fine for outgoing but incoming is not so good

radiant eagle
#

Oh men the last module is the worst of all the pentesting lab, such a waist of time trying to finish with such intermittence

fathom pendant
#

it's likely due to the Host firewall rules

random bear
#

👍 Thank you

sleek moss
#

it just exhautss da list

fathom pendant
#

do you need to get the password?

#

remember hashes have many uses

proud patrol
#

hi guys in the Practical Digital Forensics Scenario first question; I am unable to decode the second b64, only getting rubbish data out of decoding it ?

dim wolf
#

i don't believe you are required to decode that

fathom pendant
#

What's the error you're getting from winrm?

#

Also what module and section are you on?

sleek moss
#

AD Enumeration & Attacks - Skills Assessment Part II

  • 1 Submit the contents of the flag.txt file on the Administrator Desktop on the MS01 host.
#

im on sql server i used meterpreter and dumped memory and found admin hash

#

now i try to connect to ms01 with has

next bronze
#

WinRMAuthorizationError usually means the creds are wrong or the user is not allowed to winrm

#

where'd you even get the admin hash from

fathom pendant
#

Perhaps this is not the way

fathom pendant
rustic sage
fathom pendant
#

Maybe one of the privs you have on the sql host can lead to a juicy exploit, or maybe spoofed answers

sleek moss
#

from the sql server

fathom pendant
#

Yes

sleek moss
#

im arleady meterpreter nt system

fathom pendant
#

Ah right mimikatz is the way

#

Maybe you used the wrong submodule

#

Because one of the password related ones definitely outputs in plaintext

#

Alternatively nxc/netexec can also get it

#

It can't be cracked because it's not in the wordlist

#

Also the user you're looking for isn't necessarily "Administrator"

sleek moss
#

i c ok danke

#

mssqlsvc

#

rite?

fathom pendant
#

Perhaps

proud patrol
dim wolf
#

i don't know what the question is so i couldn't tell you

tribal wharf
#

i am going through the intro to AD. The kerberos auth process seem to be incorrect. The user's ntlm never being to encrypted tgt (which suppose to be encrypted kdc secret key). yet the article in module state this "1. The user logs on, and their password is converted to an NTLM hash, which is used to encrypt the TGT ticket. This decouples the user's credentials from requests to resources."

cloud urchin
#

what's wrong about that statement?

random bear
#

In x64dbg when I click run for my shell.exe for INTRODUCTION TO MALWARE ANALYSIS - Debugging, I am not getting any pop ups. I put the proper breakpoints toggled, I changed the code, and I have the INetSim functional. Any idea why I am not getting the pop-up for "This is the INetSim default binary" "Connecton sent to C2"
I am not getting any of these checks or any pop up after clicking the "run" button in x64dbg.

tribal wharf
velvet peak
#

How does this server work? What is his purpose?

dim wolf
#

this is the official community Discord server for Hack The Box

velvet peak
#

I'm a little uninformed

random bear
cloud urchin
glass quail
#

People help each other in this one channel

dim wolf
#

it's pretty much the central hub for the HTB community

#

whether it's the main platform, CTF, or academy

#

i think enterprise as well

tribal wharf
fathom pendant
#

Part of krb auth is the ntlm hash

#

Otherwise it wouldn't be tied back to the user

cloud urchin
fathom pendant
#

There has to be some form of identification that the user in the ticket is the one being authed

dim wolf
#

the NTLM hash is inside the TGT

fathom pendant
#

^

dim wolf
#

if it wasn't, Kerberoasting wouldn't exist

fathom pendant
#

It's nested in it

dim wolf
#

at least in its current form

fathom pendant
#

I swear we have this convo at least once a month lol

cloud urchin
#

The NTLM hash itself is not contained within any tickets.

fathom pendant
#

Well no

#

But a form of it nested within the ticket

tribal wharf
#

it is different to the explanation to the video show in 'kerberos deep dive' which make more sense. just have a look. also, client ntlm encrypting tgt kinda defeat the purpose as client can simply decrypt tgt .

fathom pendant
#

That contains the authentication (password/credential) info

cloud urchin
#

The NTLM hash is only ever used locally, not transmitted with the ticket. The ticket keys are derived from the NTLM hash of the user.

#

but it is USED to encrypt the ticket

#

so the statement is correct

dim wolf
#

i am incorrect yes it is not actually inside the TGT

#

BUT it is definitely used to encrypt the TGT

cloud urchin
#

yes, exactly

#

it's used with a timestamp to derive a key

#

The KDC already knows the hash

glacial bay
#

I'm on the Footprinting MSSQL module

Connect to the MSSQL instance running on the target using the account (backdoor:Password1), then list the non-default database present on the server.

sqlcmd and metasploit are all saying this is the wrong user:pass

glacial bay
#

thank you

fathom pendant
#

Short answer, it's dumb
Long answer, it's very dumb

glacial bay
#

makes no sense why that work but native tools such as sqlcmd didnt

#

way to ruin 30 minutes of my time

dim wolf
#

i have had 0 luck with sqlcmd

#

another W for impacket

glacial bay
#

when hackers write better tools than Microsoft with their own software

fathom pendant
#

MariaDB be like:

#

Mssql gui? Hell no

tribal wharf
# cloud urchin The NTLM hash is only ever used locally, not transmitted with the ticket. The ti...

the statement talk NOT about how TGT ticket derived. But ntlm is used to decrypt tgt ticket. I am not even sure you understand my question. If you don't , i am happy to elaborate. Below are response from chatgpt The statement contains a misunderstanding of the Kerberos authentication process. The obvious mistake is that Kerberos does not use NTLM hashes to encrypt TGT tickets. Instead, during the authentication process, the user's password is used to generate a Ticket Granting Ticket (TGT), which is encrypted with a symmetric key derived from the user's password and stored on the Key Distribution Center (KDC). This TGT is then used to request service tickets for accessing specific resources. So, the use of NTLM hashes and the claim that they encrypt the TGT ticket is inaccurate. Additionally, Kerberos authentication does not entirely decouple the user's credentials from resource requests, as the TGT is still used to obtain service tickets for accessing resources.

dim wolf
#

oof, automod

sleek moss
#

im on AD Enumeration & Attacks - Skills Assessment Part II how the frick do i get bloodhound gui to open up? on the attack device?

dim wolf
#

you can get around automod if you verify your account -> #welcome

dim wolf
#

there are instructions to do so

fathom pendant
dim wolf
#

oh shit

#

i'm keeping quiet from now on

fathom pendant
# dim wolf oh shit

I believe it's mentioned in the engagement statement for the skill assessment that you can either/or

#

Or both

sleek moss
fathom pendant
#

Have an ssh and an rdp session

fathom pendant
sturdy otter
#

AD Enumeration & Attacks - Skills Assessment Part I:

Already got every Question except the "Cleartext one for t...y".

What I already tried to find the password:

Overall lookaround on MS01
Dumped LSA/SAM with lsassy and mimicatz
Lookup with lazagne
Cracking the NTLM Hash
But no cleartext password for the user.

Any hints?

sleek moss
#

i have the .jsonfiles

fathom pendant
#

Lsass != lsa

fathom pendant
#

Alternatively transfer the files back to your host and run the bh gui on your host

sleek moss
#

ohh i c danke

sturdy otter
halcyon dock
dim wolf
#

two months in between college coursework

#

more like 3 months to actually get the cert though

sleek moss
#

PS C:\Users\mssqlsvc\Desktop> runas /user:CT059 "powershell"
Enter the password for CT059:
Attempting to start powershell as user "MS01\CT059" ...
RUNAS ERROR: Unable to run - powershell
1326: The user name or password is incorrect.

PS C:\Users\mssqlsvc\Desktop>

BRUH i put in the password ||charlie1|| but it not work why

#

AD Enumeration & Attacks - Skills Assessment Part II

gray merlin
sleek moss
#

domain

gray merlin
sleek moss
#

danke

gray merlin
#

bitte

craggy musk
#

bite

burnt oasis
#

Hey hope everyone is doing well having issues and don’t know if it’s a mistake by me or issue with exercise. Today working through nmap module on cpts training the port i was told to scan using nmap scripts is coming back filtered anytime i scan the specific port regardless of triggers used. If i scan all ports -p- it comes back open. Can using your own virtual machine running Kali Linux cause issues connecting to the target ip? Should i be using the htb instance instead? Same issue when using nc on specific port like when doing tcpdump. Been stuck for a min so just curious if it’s tech issue or am i messing up and just need to try harder lol !?

cloud urchin
#

You can use either one you like, if you're connected properly via kali and the vpn you won't have issues connecting to the target

sleek moss
#

u need to sudo openvpn the vpn

burnt oasis
#

@cloud urchin @sini12349 thanks for info I’m connected to vpn it’s showing the new ip by the network tab on top right in my vm

cloud urchin
#

can you ping the target

sleek moss
#

PS C:> Set-DomainObject -Identity "DC01.INLANEFREIGHT.LOCAL" -SET @{userAccountControl=4096} -Verbose
VERBOSE: [Get-DomainObject] Get-DomainObject filter string:
(|(|(samAccountName=DC01.INLANEFREIGHT.LOCAL)(name=DC01.INLANEFREIGHT.LOCAL)(dnshostname=DC01.INLANEFREIGHT.LOCAL)))
VERBOSE: [Get-DomainSearcher] search base: LDAP://DC=INLANEFREIGHT,DC=LOCAL
VERBOSE: [Invoke-LDAPQuery] filter string:
(&(|(|(samAccountName=DC01.INLANEFREIGHT.LOCAL)(name=DC01.INLANEFREIGHT.LOCAL)(dnshostname=DC01.INLANEFREIGHT.LOCAL))))
VERBOSE: [Get-DomainObject] Error disposing of the Results object: Method invocation failed because
[System.DirectoryServices.SearchResult] does not contain a method named 'dispose'.
VERBOSE: [Set-DomainObject] Setting 'userAccountControl' to '4096' for object 'DC01$'

#

why cant i enable rdp on dc? i am amdinsitraotr

burnt oasis
#

No i get message back that it’s down @cloud urchin

cloud urchin
burnt oasis
#

Yes it’s off @cloud urchin

cloud urchin
#

if you're connected to the correct vpn, the pwnbox isn't spawned, and the victim host is up, you should be able to connect without issue. if you hammer the victim it may die, or maybe for some other reason, you may need to restart the victim box

#

beyond that, run a traceroute to see where the connection issue is, or reach out to support

runic inlet
#

hello guys

#

anybody can help me on Sauna box?

gray merlin
runic inlet
#

do u have the link ?

sleek moss
#

i want to change the settings to allow rdp on the domain controller from my device is it possible t o change the D.C settings

cloud urchin
#

yes if you have admin privs

sleek moss
#
  • 1 Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.
    AD Enumeration & Attacks - Skills Assessment Part II

I changed admin password and can use admin pass bu ti cant rdp or connect to dc cause it s not enabled how do i enable

cloud urchin
#

there's a crackmapexec module for it, you can enable rdp via a registry key, and you can disable nla if needed via a registry key as well

gray merlin
cloud urchin
#

there might be gpo's that block it too you'd have to disable those somehow

sleek moss
gray merlin
sleek moss
#

no

sterile epoch
#

Hi I am in linux privilege escalation linux module shared libraries section and in on the given target /development directory has write privilege to my user as shown in the section but the library present there is write protected so how in the world can I replace it with a malicious binary?

#

hello?

cloud urchin
#

the question says to use LD_PRELOAD, go over that section again

#

use sudo -l to see what you can do with root privileges is step 1

sterile epoch
#

and it is kinda my fault I forgot to mention hijacking in shared library hijacking

#

it was not necessary to follow the section to get the answer just had to do a version check and there was the answer

#

but according to the section it was supposed to work by swapping the shared library binary in the runpath with a malicious one

#

the run path would be rwx for the current user

#

but the shared library was not.

#

I checked the code for payroll.c and found that it was using dbquery.h header and thought maybe I had to put a dbquery.h header file in the runpath. but as soon as I compiled the malicious file in the runpath and executed the binary the libshared.so read-only binary mysteriously vanished

#

and then I did the usual and got my way

#

any idea as to why this happened?

cloud urchin
#

you should delete those i think its against the rules

sterile epoch
#

its not an issue cuz they do not have the answer nor the method of getting the answer and what I showed is directly whats written in the section

#

I was hoping someone might be able to shed some light on this

#

but regardless the task was done

cloud urchin
#

yeah but it's taking pics of the content of the module and posting it in a public forum

#

just delete the msgs

sterile epoch
#

any idea why I am getting password prompt when its NOPASSWD

bold sinew
#

~~Hi, I am doing the PHP Web Shells portion of the Shells & Payloads module on HTB Enterprise. The module is asking me to Use BurpSuite to bypass file type restrictions on rConfig and it wants me to configure proxy settings in BurpSuite.

The exact wording is "Start Burp Suite, navigate to the browser's network settings menu and fill out the proxy settings. 127.0.0.1 will go in the IP address field and 8080 will go in the port field to ensure all requests pass through Burp."

I cannot for the life of me find where exactly these are configured. I cannot find such a config menu in BurpSuite nor the Chromium Browser built into BurpSuite. Any insight?~~

Edit: Disregard, the module was referring to the pwnbox's browser. Not BurpSuite's built in Chromium browser.

wanton idol
sterile epoch
#

yep it worked

#

thanks

wanton idol
#

anytime 🙂

random bear
#

I got same errors, how did you fix this? For Zeek Running this command/usr/local/zeek/bin/zeek -C -r /home/htb-student/pcaps/revilkaseya.pcap

stable lava
#

gm

burnt oasis
#

@cloud urchin thanks for help!! Support got back to me, and after switching redownloading my vpn for a new region the target is responding!

solid moth
#

is there any way i can download a .vhd file from pwnbox ?

random bear
languid fjord
#

parrotsec htb edition is close though

slow dirge
#

use this filter -fl

tranquil axle
#

@mortal basin sorry for ping, Im working through the new Windows Evasion Module rn and in the section Microsoft Defender Antivirus the spawned VM (and also the VM from the previous section) do not contain a Threat with the ID asked for in the questions. Is the wrong image being spun up here or is it me?

slender tapir
#

Folks, I'm on the Hard lab at the end of the Footprinting module and I'm getting a bit frustrated with trying to find my way to any valid credentials. I've found the SNMP string with 161 and braa gives me ||Admin tech@inlanefreight.com|| but that's it. Any pointers? - NVM, I switched regions and it all came through

distant island
#

in the headless lab

autumn pilot
#

please do not post spoilers of active content

limber river
autumn pilot
#

on top of that this is not the channel

distant island
dim wolf
#

I NEED THIS MODULE

#

THIS IS THE ONE

#

i have never wanted a module this bad until now

dim wolf
#

as soon as i have my hands on a computer i will buy it

cloud urchin
#

anyone else having issues spawning victim boxes?

shell ore
#

can i get help regarding skill assessment I in AD attacks module? stuck at getting the "t" user's password

vital adder
#

jesus christ the new module look nice 🔥

next bronze
#

I'm too busy to do the module peepoCry

fringe urchin
next bronze
#

we?

#

no man it's friday

#

oh the module is pretty basic but a good start nonetheless noice

snow ridge
tranquil axle
snow ridge
#

Okay ill try restarting box

honest gyro
#

hello guys im stuck at the session security skill assessments
i was able to gain the admins's cookie but every time i use it i get (noaouth) can somone give me a hint

cloud urchin
#

maybe try it in a private window or another browser

halcyon dock
#

Hi

sly nebula
#

Finally finished the AD Trust Attacks Module. It honestly felt more like a ProLab than a regular course. Great content though!

honest gyro
snow ridge
#

@tranquil axle Did you have any problems in section Static Analysis? ```[05/09/2024 05:28:13] C:\Alpha\Static\ConsoleApp1.exe - OK - Undetected by Microsoft Defender Antivirus

[05/09/2024 05:29:11] Checking...

[05/09/2024 05:29:11] C:\Alpha\Static\ConsoleApp1.exe - OK - Undetected by Microsoft Defender Antivirus

[05/09/2024 05:30:11] Checking...

[05/09/2024 05:30:12] C:\Alpha\Static\ConsoleApp1.exe - OK - Undetected by Microsoft Defender Antivirus``` Checks already ran many times and it was undetected but flag.txt is not spawning

rustic sage
#

Hey is anyone working on the box Corporate

next bronze
#

yeah, I haven't even finished trust attacks

fathom pendant
remote latch
#

anyone did wordpress module?

#

i need a bit of help

#

cant find that anywhere

#

nor do i know which file to download

tranquil axle
sly nebula
#

How come some modules are still tagged as "updated" even if I solved all updated content?

snow ridge
#

It just means the module updated recently

#

Nothing to do with your personal progress

fathom pendant
#

Sometimes it's just a wording change

sly nebula
#

The module I am looking at was last updated in march 2023

#

OK

#

I see

fathom pendant
#

Considering how often those likely happen

limber river
#

@remote latch which question ?

remote latch
#

i literally have smart shell and cant find shit

limber river
#

try to download file from the website

remote latch
limber river
#

then see which directory you are looking for

remote latch
#

i can just search

fathom pendant
#

Your ss has spoilers for 1 and 2, holy 1983 camera batman

remote latch
fathom pendant
#

Shitty aaa phone camera having ass

remote latch
#

deleted photo

remote latch
limber river
#

and stop sending those pictures

remote latch
limber river
remote latch
fathom pendant
fathom pendant
limber river
fathom pendant
#

Those are standard wp stuff

limber surge
#

INFORMATION GATHERING - WEB EDITION > Active Infrastructure Identification

What Apache version is running on app.inlanefreight.local? (Format: 0.0.0)

can someone hint me on this?
i tried this command but it does not give me any suitable result.

whatweb -a 3 10.10.14.167 -H “Host: app.inlanefreight.local” -v

faint dragon
#

Getting some connection issues with RDP.

tribal plinth
fathom pendant
#

The vhost is running on the target web server

#

Specifically in that section, the vhosts dev.inlanefreight.local and app.inlanefreight.local are running on that server

#

In your command you're using your ip

#

Not the target ip

#

It's also best to put the vhosts in your /etc/hosts

#

As ip vhost1 vhost2

limber surge
distant island
#

any tips for understanding linPEAS and winPEAS resaults better ?

tranquil axle
# snow ridge That worked

yea my problem is if you get to dynamic analysis this method no longer properly executes the rev shell? I think the module would profit from a small section explaining what the check scripts actually check or how they expect you to build the .exe files on the provided vm

fathom pendant
#

If it's not a simple path, ignore it

snow ridge
distant island
kind turret
#

I developed the walkthrough for the entire module (will be published today) without needing any clarifications from the module author...

quartz trail
#

hi anyone can plz help me in setoolkit
i have creat a pdf payload but i cant find it whare can i find it

#

kali linux

kind turret
remote latch
#

ur kind tho, tnx

kind turret
tranquil axle
# kind turret I developed the walkthrough for the entire module (will be published today) with...

what settings to use to compile, when I used the provided vm then neither the Debug nor Release settings created a single .exe file, and putting .exe, .dll and .json file from the release/debug folder into the Static folder to get checked did not work. Only when I used the publish feature to make it into a single .exe did the check script "pass all tests". But publishing doesn't work on the development machine so ???

snow ridge
# kind turret What exactly is unclear?

For example this from Static analysis. ```[05/09/2024 05:28:13] C:\Alpha\Static\ConsoleApp1.exe - OK - Undetected by Microsoft Defender Antivirus

[05/09/2024 05:29:11] Checking...

[05/09/2024 05:29:11] C:\Alpha\Static\ConsoleApp1.exe - OK - Undetected by Microsoft Defender Antivirus

[05/09/2024 05:30:11] Checking...

[05/09/2024 05:30:12] C:\Alpha\Static\ConsoleApp1.exe - OK - Undetected by Microsoft Defender Antivirus```
Checks already ran many times and it was undetected but flag.txt is not spawning. After I published it as single exe file it worked

#

Payload itself worked fine on dev machine

kind turret
#

What do you mean "Publish" it as a single file

tranquil axle
#

well yea the script says av successfully bypassed and when I run the .exe manually on the dev machine it also does what I want it to (inlcuding rev shell and everything) yet the script says undetected but doesn't provide the flag. And I don't know what is wrong so I have no way to fix it

#

if you press build solution on visual studio you get a .exe, a .dll and a .json

#

if you publish via studio you can tell it to pack these into a single .exe

kind turret
#

If you get the flag, you solved the question. Nothing else matters.

#

If you dont get it then you need to retry.

tranquil axle
#

because if I dont it doesnt accept the file?

kind turret
#

You are supposed to compile it

tranquil axle
#

thats my problem with the module, I dont know what the script is checking for so I cant even tell you why the published standalone one works but the other with .exe, .dll and .json doesnt

kind turret
#

You are not supposed to know. You are supposed to do what it wants to get the flag.

#

We are not teaching how to build labs nor sharing such material

flint linden
#

hello guys i am current stuck

#

i am trying to spawn a target and i do not know how to do so

tranquil axle
#

I think you are misunderstanding me. I bypass AV and get the rev shell to work if I execute it. The script says it bypasses av. But unless I pack it into a single .exe it does not give me the flag

fathom pendant
kind turret
snow ridge
kind turret
#

Sure

halcyon dock
#

Hi

limber surge
#

INFORMATION GATHERING - WEB EDITION > Active Infrastructure Identification

Which CMS is used on app.inlanefreight.local? (Format: word)

i ran this but i cant seem to find any cms related info.

whatweb -a 3 XXX -H “Host:XXX” -v

fathom pendant
#

Just specify it as the site

#

Also look for the word 'management'

#

Or something like 'content'

#

Read the output, basically

turbid crest
#

that medium footprinting lab machine is crashing (disconnect the rdp) always after 30 sec to 2min when work on it via rdp. is there a way to work around? its feels super slow.

north bramble
#

Hello, can someone help with skill assessments for password attacks module?
I finished the material a month back and have started after a break. I need a little help please.

fathom pendant
#

Or change vpn servers

#

It's worked fine for me

turbid crest
#

is pawnbox

fathom pendant
#

Vpn servers are different from pwnbox servers

turbid crest
#

k will try to change

north bramble
fathom pendant
#

Vpn = target
Pwnbox = pwnbox region

haughty tree
#

Hey, in this example we have the SOA record containing inlanefreight.htb. in the place you'd expect to see the primary NS, however, we see a couple of lines down that the NS record points to ns.inlanefreight.htb., my question is, are the 2 domains CNAMES of each other? or are they two differnet NS?

turbid crest
north bramble
haughty tree
fathom pendant
fathom pendant
north bramble
haughty tree
# fathom pendant Ns is primary

so shouldn't the SOA record show ns.inlanefreight.htb. before the root.inlanefreight.htb. (which I assume is the admin email)

north bramble
fathom pendant
#

In this case the domain, is the ns

fathom pendant
#

¯_(ツ)_/¯

#

A nameserver doesn't always have to have ns.

#

But anyway

north bramble
fathom pendant
#

I generally don't do -v though

north bramble
fathom pendant
#

It clogs the screen

haughty tree
# fathom pendant SOA shows the domain

It shows the domain at the beginning but should also show the primary name server I think, for eaxmple: here is one of the previous examples they've used in this section

north bramble
fathom pendant
#

That's threads bud

north bramble
fathom pendant
#

In this instance it's a private server, so it doesn't need to follow public convention

limber surge
haughty tree
fathom pendant
#

Exactly

haughty tree
fathom pendant
#

Not to mention, since the NS record is defined separately, it doesn't need to be in SOA

#

What module?

#

Oh wait nvm

#

In future separate with a dash between the module and section name

#

I will tell you, all services have their own user

#

Then what tool is giving you the error?

#

As that's a python related error

opaque edge
fathom pendant
#

Also what is your syntax [omitting usernames and passwords]

fathom pendant
fathom pendant
#

Yes

#

Also it's a windows machine so ...

viscid token
#

I just realized I wasn’t using type and full path….how embarrassing. Haha. Thank you.

north bramble
pseudo kiln
#

is there an issue with spawning targets in modules currently ? been waiting for a while usually it's pretty fast

torn drift
pseudo kiln
#

it's just stuck forever in Target is spawning...

torn drift
#

oof yeah, terminate and try again, grab a fresh cup of coffee

pseudo kiln
#

i logged out, refreshed the page, and it's still stuck in "Target is spawning...", is there some trick or work-around ?

soft cedar
north bramble
pseudo kiln
#

great if only the platform was half as good as the content..... I thought the ssh performance was bad enough, then there is this

#

so I found this trick on reddit which seemed to work. I spawned a target from a different module, which worked, came back to the original module and spawning there worked too

fickle panther
#

l

regal bluff
#

I am doing assembly module , specifically stack section. In this section a hex immediate value is loaded into register and then pushed onto stack. This operation is done multiple times. Finally a flag will form after combining all values. But What i am observing is after first part is pushed to stack. second part is pushed to stack. now rsp should point to this second part only but rsp points to concatenated value of first part+second part. And as per my stack understanding how is that possible. Shouldn't rsp be pointing to only last value pushed. Any help would be appreciated and sorry if this dumb. But i checked with my test code pushing values 1,2,3 onto stack and in that case it doesnt concatenate as expected.

#

partial assembly code

candid lily
#

damn i just spent all my 500 cubes and they release this?! sadglas

#

is there anyway i can sell an module 😅

candid lily
fickle thicket
#

just finished AD attack and enum module. Before that i didn't know it is impossible for user to have MORE privilege on the same host when using different protocol. like winRM vs RDP. learn alot these few days.

zenith vale
#

hey, im doing the java deobfuscation module. and at the http request section im curling the /secret.php page. but i get a page 404

fathom pendant
#

are you curling the http://ip:port/secret.php?

zenith vale
#

ye

#

tried to respawn the machines

#

maybe i was doing something wrong idk

fathom pendant
#

i'm seeing it mention serial.php

fickle thicket
fathom pendant
#

and it specifically saying to do a post request to /serial.php

zenith vale
#

🫣 bruh i read it as secret php the entire time

#

embarrasing

fathom pendant
#

you were likely thinking of secret.js

zenith vale
#

yes

fathom pendant
#

from previous sections

zenith vale
#

awkward haha

fathom pendant
#

it happens

#

usually means it's time to step away and take a break

zenith vale
#

i wanna keep myself at a pace of a module a day

#

atleast

fathom pendant
#

i didn't mean for the whole day

#

just take a break for like a little bit

#

even just a half hour away

#

it's a marathon, not a sprint ¯_(ツ)_/¯

zenith vale
#

got u 😉

fathom pendant
#

some modules make you feel crazy, spending lots of time on goofy shit

#

until you realize syntax error

#

and your life is ruined kek

zenith vale
#

ye, the fuzzing one bruh, i was getting so many errors.

#

man i inputted in /etc/hosts the ip:port , not just the ip. which resulted in errors while fuzzing

fathom pendant
#

you never put the port in /etc/hosts

glass quail
#

can someone help me on web attacks skill assessment

pseudo birch
#

For Linux Privilege Escalation: Environment Enumeration, I found the flag after escalating privileges to lab_adm. I found the flag, yet when submitting it doesn't take it. Are there other flags that I need to find?

fathom pendant
#

so just avoid spoilers if possible

glass quail
#

Module name is web attack
section is skill assessment

pseudo birch
# glass quail the first part of it I have a lot of user names and token just don't know where ...

Check out Mass IDOR Enumeration section. Use Burp Intruder/Repeater. Try to guide your search by asking yourself questions like what kind of user am I looking for? Whats the role/privilege of the user I'm looking for? What token do I have is it mine or is it another users? What user? Do I have a sessionID? Can I get someone elses? What kind of HTTP request am I using, can I try others? Etc.

fathom pendant
#

^

glass quail
#

ok ya I got more than 80 users and tokens I know which one is mine thank you

fathom pendant
#

perhaps running a request where you check tokens against users, and etc - or maybe something about the token might identify which user it could belong to

glass quail
#

Oh I know who they belong too just need to figure out how to use them. I think I have an idea tho

#

haha I looked through the users and found a user I need now to get into their account

old oasis
#

Nice I just finished that skill assessment was a fun one

shell ore
#

@atomic stream here

atomic stream
#

hey

#

i have a question on module 3 on cdsa section 2

#

can someone help me ?

#

Replicate the Unmanaged PowerShell attack described in this section and provide the SHA256 hash of clrjit.dll that spoolsv.exe will load as your answer. "C:\Tools\Sysmon" and "C:\Tools\PSInject" on the spawned target contain everything you need.

#

this question

#

after i did the injection i could not see an event related to this question

#

even tho everything worked fine

marsh echo
#

it's me or the pwn box it's not available ?

glass quail
fathom pendant
fathom pendant
#

also do you have sysmon running to catch the inject?

atomic stream
#

thanks anywaysi solved it

fathom pendant
#

¯_(ツ)_/¯

fathom pendant
atomic stream
#

the problem was the sysmon didnt log event id 7 for spoolsv

the reason was i didnt configure it before the injection so i realized that then i configured it and tried ti inject again but it didnt cause an event so i restarted the machine and it worked

fathom pendant
#

yeah sometimes with those labs restarting the machine makes it work

#

general tip with the windows related labs, wait a few minutes before connecting and doing the thing ¯_(ツ)_/¯

north bramble
#

Okay I finally got the password and username for Password attacks module - easy skill assessment

#

got id_rsa id_rsa.pub and authorised keys files.

tried to
ssh root@IP -i id_rsa

but it asks for passphrase

what am I doing wrong

fathom pendant
#

maybe you should take a lesson in history

#

also general suggestion, make a separate folder for doing academy stuff

#

that way you don't clutter your home directory with a bunch of stuff

north bramble
rocky yew
#

Hello guys, I'm new here and I need someone to learn and practice together

fathom pendant
#

secondary note, ffuf can be installed on parrot with apt

fathom pendant
north bramble
fathom pendant
#

from there it's really only like... maybe one or two steps

north bramble
fathom pendant
#

¯_(ツ)_/¯

north bramble
fathom pendant
#

but that's just a secondary note

#

ssh user@ip

#

<password>

#

oh wait

north bramble
fathom pendant
#

ssh user@ip -i id_rsa as per my enumeration

#

and yes if a user exists on ftp; it's likely they exist to ssh with

north bramble
fathom pendant
#

from my notes directly

north bramble
fathom pendant
#

so it's asking for the passphrase to the rsa file (which you need to chmod to 600)

fathom pendant
#

¯_(ツ)_/¯

#

just telling you what my notes say from that

north bramble
fathom pendant
#

it means exactly that

#

that the rsa key was password protected

north bramble
#

So how do you crack it. SshtoJohn?

fathom pendant
#

meaning that you need to provide a passphrase/word when using the id_rsa

#

2john*

#

but yes ssh2john

north bramble
#

Ah ok.

#

Convert idrsa using that am I correct?

fathom pendant
#

it's not converting

#

it's extracting

north bramble
#

Uh crack sorry

fathom pendant
#

you extract the password hash

#

though I generally suggest to check password reuse

north bramble
#

Then crack the hash to find the password?

fathom pendant
#

always check reuse before going to cracking

north bramble
#

I will try this in the morning. Thanks for you help. Its 2:30 am for me.

fathom pendant
#

np

#

it's all about developing a methodology

north bramble
fathom pendant
#

my steps

  • get ftp user:pass
  • check with ssh
  • log in to ftp, extract files
  • check with RSA file
north bramble
fathom pendant
#

actually it was more like 3 months i wanna say

north bramble
fathom pendant
#

actually scratch that it was more than that

#

more like 18 months

#

6-7 actual months of working on it

north bramble
#

More than a year youve been doing this on and off then...

fathom pendant
#

I know some programming things, but that's not helpful to this particular course

north bramble
fathom pendant
#

and I knew some basic networking things

#

but as far as what the course expects you to know (which is basic level networking, networking 101 stuff)

north bramble
#

Alright. I must sleep gn.

heavy marsh
#

For the File Upload Attacks skills assessments I got stuck on the last part. My payload was giving "only images are allowed", but when I checked the writeup I had the same payload, just some XML code I had used previously in front of it.

#

I don't see a reason for the code to be there, since I have the payload in there

#

And I already used that XML payload for it's purpose to get to where I was at

#

I figured it out eventually, just wondering what the reason for that XML code is, it wasn't covered in the module except for source code discovery, not being part of a final payload

old oasis
#

I don't remember using any xml in that module.

#

are you talking about the walkthroughs you get with the annual sub?

old oasis
#

oh ok imma shut up then

heavy marsh
#

There was some XML code I couldn't get it to work without

fathom pendant
heavy marsh
#

Yeah, I just didn't see that method in the module

fathom pendant
#

it was likely explained but you glossed over it

#

¯_(ツ)_/¯

heavy marsh
#

They used that for source code discovery, not prepending it to a legitimate payload

fathom pendant
#

it's likely the way it interacts that it has to be there

#

¯_(ツ)_/¯

#

the writeups don't really explain much of anything

heavy marsh
#

It was explained in the "Limited File Uploads" section under XXE, but that was for reading source code of php pages, it did not cover appending a payload to that portion, so I am confused. Is there another way to do this?

#

To me <?php system($_REQUEST['cmd']); ?> is a PHP payload

#

Not
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE svg [ <!ENTITY xxe SYSTEM "SPOILER"> ]> <svg>&xxe;</svg> <?php system($_REQUEST['cmd']); ?>

#

Spoiler removed

fathom pendant
#

¯_(ツ)_/¯

heavy marsh
#

Is there another way to do that?

fathom pendant
#

haven't done this module so couldn't tell you ¯_(ツ)_/¯

heavy marsh
#

I think I figured it out, XXE is covered in Web Attacks

cloud urchin
#

i felt like that module was straightforward, the xxe portion is literally just copy/paste from what i remember

heavy marsh
#

Which is after the next module

cloud urchin
#

it walks you throught exactly how to do it within the file upload module itself

heavy marsh
#

Then how to check source code

cloud urchin
#

yep, that's all you need for this

heavy marsh
#

Nothing about appending a PHP script to the end of an XML script

cloud urchin
#

i didn't do that to complete the module

heavy marsh
#

What did you do?

#

That's what the writeup showed me

cloud urchin
#

i don't really want to give the steps away for completing a skills assessment i can dm you

#

pretty much exactly as the module outlines

heavy marsh
#

@cloud urchin cleared it up, writeup gives incorrect information

#

Thanks!

cloud urchin
#

ya there are multiple ways to complete it

fathom pendant
#

I believe @kind turret does a pretty good job at giving the right commands, one of my only complaints is they use msf/meterpreter 🙄 but the theory behind them remains the same. They pull from either the module itself or the prescribed pre-req modules.

heavy marsh
fathom pendant
#

¯_(ツ)_/¯

marsh echo
fathom pendant
marsh echo
fathom pendant
#

It's a basics of Windows thing

#

Just because Defender isn't running, doesn't mean there isn't some protection running

marsh echo
#

I was able to bypass the real time protection but when I want to access my remote server via the proxy server on 172.16.5.19 it gives me this error message

cloud urchin
#

did you apply the RDP performance configurations section's suggestions?

sterile epoch
#

I cannot sudo

marsh echo
tepid crag
#

A

vague valve
#

Any news on when the next batch of CDSA results are coming out?🤔

marsh echo
#

if someone for help me please for skill assessement tunneling and port forwarding

#

i find the ip but idk how do for acces on, i use brute forcing via port forwarding use the port 9050 for proxychains . I read the text which say me use the account mlefay, i try mutated him and bruteforce rdp and ssh but nothing

little bear
#

I am having having a walk in the park on my last and final module. It's a blast and almost serene trying to remember everything--all the days I've spent.

The closest I can compare to is like, mayhem the entire way. And then coming to understand, yeah, x was the time that y .

Still quickly working on my D&R framework and how I'd want to standardized my Reports with my notes, but it's looking like time will only be my issue approaching the engagement exam.

Actually, the last module feels a lot more like that moment of being rung out for the last 6 months and then looking into the light only to hear "It's not your time yet, finish the job" like a sweat nothing, to then be thrown back down into the pits of shits about to get real except--in a better place than before lmao

Feel free to modify this how you'd like for better effect. Learning a lot, basically.

Hiboox, you should:

  • Establish your pivoting and forwarding; ensure that it works.
  • Ensure you're using proper syntax and the right proxy tool (again, follow syntax and understand your tools)
  • Once you've confirmed that everything works in your environment, then attempt the tool that you think you need to test with.
  • Also, Good luck with either rdp or ssh. I cannot remember which one that takes forever. Try another then come back around if the tree doesn't fall.
  • I am impressed you're mutating passwords, but consider your list and complexity as required.

Im off for the night. Later guys.

marsh echo
cosmic obsidian
#

Hi!
I have a query in Command Injections Module in Identifying Filters Section.
The question is "Try all other injection operators to see if any of them is not blacklisted. Which of (new-line, &, |) is not blacklisted by the web application? "
I got the answer it is the new line operator but i am not able to submit that answer i even tried URL encoded version of that string.
Any help on how the format is to submit the answer for that particular question?

cosmic obsidian
marsh echo
#

i put the right password and user it gives me this error i really can't understand its problem at rdp

north bramble
#

Thanks 🐸

cloud urchin
#

says in your error message 'unable to connect to ldap, verify your credentials'

sick frost
#

Thanks mate. I might have overlooked it. It's working now

fathom pendant
#

friendly note that many people do AEN blind; so be careful with asking questions here, especially since AEN itself is the walkthrough

glass quail
#

man that was fun completed web attacks thanks for the help

marsh echo
fathom pendant
#

timeout waiting for activation; sounds like it couldn't connect

cloud urchin
#

yeah that's why i always do a high timeout just in case

fathom pendant
#

especially in you're in an area like SG or something; the latency makes other additional settings necessary

north bramble
north bramble
haughty tree
#

Is anybody else not able to search for modules on HTB academy on firefox? It shows me that there are no results regardless of what I type in

#

also the billing page doesnt work

next bronze
#

disable adblock

haughty tree
#

Its disabled

next bronze
#

then there are other things messing with it

haughty tree
#

I disabled all extentions and the firefox shield

#

still doesn't work

#

Maybe its because im using user.js

next bronze
#

there shouldn't be anything from firefox that's blocking it, I have the enhanced shielf turned on and it still works

wicked oxide
#

Hey ! I've got a problem on the new module "Introduction to Windows Evasion Techniques" in the Static Analysis section. I managed to recreate all steps on the DEV machine, i uploaded the EXE in the static folder of the TARGET machine. Got "OK - Undetected by Microsoft Defender Antivirus" in the log but the flag isn't spawning. Am I missing something?

pine dune
#

Hi guys...I am currently doing "Firewall and IDS/IPS Evasion - Medium Lab" on academy from the "Network Enumeration with Nmap " module...what I am struggling with is the question

#

After the configurations are transferred to the system, our client wants to know if it is possible to find out our target's DNS server version. Submit the DNS server version of the target as the answer.

haughty tree
pine dune
fathom pendant
pine dune
#

is there a way to reset the whole module? so that I can have another go at it?

fathom pendant
#

no

pine dune
#

ahh

fathom pendant
#

you can just click on other sections and re-read the content though

pine dune
#

ahh okay

fathom pendant
#

also sprinting through content is not smart

#

as you're just infodumping your brain

candid lily
#

actually sprinting is fine as long as you reread

fathom pendant
haughty tree
#

It depends on what you mean by "sprinting"

candid lily
#

i find it super hard to understand the first time

fathom pendant
haughty tree
#

Rushing to the end of a module is not beneficial imo but you could definetly allocate a lot of time for studying per day and accomplish a lot in 1 day

candid lily
#

so i only see what i understand, then visit later after i get some experience

haughty tree
fathom pendant
candid lily
#

hmm

haughty tree
fathom pendant
#

it's a marathon not a sprint, the end goal isn't changing or getting further away if you spend 5 minutes on a module vs 5 hours

pine dune
fathom pendant
fathom pendant
haughty tree
fathom pendant
#

also utilizing quotes in a google search is helpful

#

if you utilize quotes you are telling google i want to include exactly this

#

also it gets around some other google search things i.e. +/- so "-P" for instance will show you results with "-P"

haughty tree
#

Yeah I've done some online OSINT courses so I learned it there

thick remnant
#

Hello, i'm trying to do a module exo, i need to rdp to a machine, but i have a black screen, and nothings happen when i'm reaching the windows VM, i did it on the web parrot OS and reset 2 times the VM i need to reach

#

did anyone had the same problem ?

haughty tree
#

Press enter

thick remnant
#

ok... it's working... tf is this xD : thx

fathom pendant
#

it's the enterprise welcome screen

haughty tree
#

Lmao

thick remnant
#

yh, but why a blackscreen xD

fathom pendant
#

"You acknowledge that you are only using this device for it's intended purpose"

fathom pendant
#

and so it doesn't properly draw or get sent in an rdp session

#

resizing the screen gets it to show

thick remnant
#

ok, it appears on the first login, so i thought smth went wrong after

fathom pendant
#

it also just depends

#

sometimes it does and sometimes it doesn't show up

#

the main reason though is that it's screensaver

#

when you initiate a login it doesn't fully wake up the screen sometimes

#

that post is from 2 years ago btw

slow dirge
fathom pendant
#

i mean the solution could be derived in many ways

#

also it can be considered a spoiler

#

¯_(ツ)_/¯

slow dirge
fathom pendant
#

everything is available in the module ¯_(ツ)_/¯

#

they provide a direct namelist to generally use

slow dirge
fathom pendant
#

if you're struggling with a namelist you likely weren't paying attention much

#

(not to mention the other questions actually prep you to get that last Q)

#

spoiler tags don't do shit btw

#

i suggest renaming it to "parameter"

#

as the parameter is part of the answer to another question

slow dirge
fathom pendant
#

eh

#

mostly

#

but the best would be to just not have posted it, as someone should naturally have derived that

#

as the subdomain/vhost is also part of another answer

slow dirge
#

should i delete it?

fathom pendant
#

¯_(ツ)_/¯

rustic sage
#

HI

#

this is MarkRober server?

fathom pendant
fathom pendant
slow dirge
#

Done, happy?

rustic sage
#

and what server is this?

fathom pendant
fathom pendant
rustic sage
#

ok

slow dirge
timber pewter
#

pluh

fathom pendant
#

<@&861185840277487616> i fear a dumbass raid is upon us

#

Brother that's illegal

#

No, it's not

autumn pilot
#

please keep the channel on topic

rustic sage
#

how can I remove paypal account from academy acount
I want to add a fresh card instead of paypal

fathom pendant
#

message support, afaik Update Payment method should work in the Billing page

cedar void
rustic sage
next bronze
#

dehashed is just an example on what you can use for public websites, try the creds given in the module

fathom pendant
cedar void
raw field
fathom pendant
raw field
pliant coyote
#

I can't find the corresponding keytab

fathom pendant
raw field
fathom pendant
#

but also read the question carefully

#

"Check sudo priveleges"

fierce mason
#

for the skills assessment in pivoting tunneling and port forwarding, do i need to scan the entire subnet to find the other active host

fathom pendant
#

I believe so yes

plain coral
pliant coyote
#

is this

fathom pendant
#

well your original q was regarding the next question

#

also crontab -l

lyric inlet
#

Hello anyone for question 2 on module "Active Directory Trust Attacks" ?

pliant coyote
#

Why is there no corresponding keytab for searching from the / directory?

fathom pendant
pliant coyote
#

Files with the original kt suffix can also be extracted.

fathom pendant
#

yes

#

but again; that's not the point

#

check crontab -l --> check what it reveals --> basic code reading

pliant coyote
#

This AES doesn't seem to crack out

fathom pendant
#

it should give you an NTLM hash

fathom pendant
fathom pendant
#

the write-up shouldn't replace your learning ¯_(ツ)_/¯

#

I personally use it to verify that i'm on the right path as I wait for stuff to go, like a ffuf scan or something

fading oracle
#

the new module already giving me trip

#

What is the full value of the CmdLine which triggered a detection?

#

copying out the full line and it doesnt accept it

#

is it intended to fuck people over really?

#

with copy paste?:D

wicked oxide
#

don't forget the '_'

fading oracle
#

i know but why

wicked oxide
#

🤷‍♂️

rustic sage
#

how can i show the ProcMon accessing file path? It doesn't show them at my setup. in the guide it shows that it accesses \temp... but i only see some non useful details at my procmon

autumn pilot
#

use the filter, 6th icon next to delete

rustic sage
#

it still doesnt show the path

fathom pendant
#

delete this as that's a spoiler

#

and the answer isn't necessarily garbled; the question tells you where to start

pliant coyote
#

Yes, there's a hint.

fathom pendant
#

starts with *

#

that's the part you copy

pliant coyote
#

Do I have to do all the Optional Exercises or can I skip them?

#

If I want to pass the cpts

fathom pendant
#

they are optional, so don't get too frustrated if you can't do them.

#

they just showcase other ways to do things

rustic sage
#

Nvm fixed it by running powershell with admin mode

cedar void
#

So all skill assessment modules in the pentesting path now have the step by step solution feature enable button now?

fathom pendant
tacit grove
#

the new module is RDP usage heavy, and the eu lab getting worse accessing from sea

tacit grove
#

I swear it was 150-200ms last time, heck I passed CPTS on eu server with 200ms

next bronze
#

it's now 360 for me on eu

#

have to switch to us servers lol

misty cypress
#

People there's a serious problem

tacit grove
misty cypress
rustic sage
misty cypress
#

they're working but not working

shut quest
next bronze
#

yeah annual will renew automatically

#

cancel it, you'll still keep your sub until it ends

snow ridge
#

no

next bronze
#

not downgrade, just cancel

#

then you should be good, check with support if you want to make sure

sterile epoch
#

I guess they are launching an advanced pentest path for gold

#

too many releases of new stuff that I cannot access with student

#

is there any kind of checklist before giving the exam??

#

like a list of boxes to capture to ensure good luck?

misty cypress
#

but the server is kicking/banning the proxies

#

and i'm getting really angry about it

sterile epoch
#

are you doing any module?

misty cypress
#

no

sterile epoch
#

anything on the main ctf platform?

#

or just messing around in local lab?

misty cypress
#

just messing around

#

fucking around you know i'm sayin

tacit grove
#

this guy high af

misty cypress
#

What is the thing

shut quest
civic dawn
#

Hello guys, I have problem here at Passwords Attack module, Pass the Ticket from windows

RDP doesn’t work, I can’t connect to the target

sterile epoch
#

did you go through the module??

marsh echo
#

hello everyone, you mentioned earlier a problem with the timeout but I added it in my xfreerdp command, it doesn't work and I'm sure I have the right information to connect to the remote machine.

sterile epoch
marsh echo
sterile epoch
#

whats the command u using?

sterile epoch
# marsh echo

why would you need a timeout what module are you doing?

marsh echo
#

i can't display login information because of htb rules i respect

sterile epoch
#

yea no issue can you tell me which task? the number will do

#

I do not think I needed a timeout

lucid mountain
#

On the skills assessment of intro to digital forensics in SOC path, are we supposed to not use tools like registry explorer and timeline explorer? They were on all the previous machines but now all I've been doing is going through what I get from velociraptor manually

marsh echo
#

i'm at question 4 i need to connect to rdp through the port forwarding i created in ssh

#

my error :

sterile epoch
#

before we go ahead did you try ligolo for pivoting?

marsh echo
#

connection is refused

sterile epoch
#

can you ping the target?

#

if not then I guess its a pivoting issue

marsh echo
#

the ping work

marsh echo
sterile epoch
#

mp?

fathom pendant
#

i think they mean pm

sterile epoch
#

try enum on the target to make sure rdp is available and see more attack service

#

yea sure

marsh echo
sterile epoch
#

try getting more info on the target

civic dawn
sterile epoch
#

what are you trying to send?

civic dawn
sterile epoch
#

whats the gist of the error?

marsh echo
#

this problem i watch a video youtube on the skill assessement I did the same as the guy and when we get to the rdp part it works for him and not for me.

naive wadi
#

"Dump the NTDS file and perform offline password cracking. Submit the password of the svc_reporting user as your answer." I have domain admin, have dumped NTDS & LSA and I cannot find this user. Did anyone else have this issue? If anyone reads this in the future, just dump the NTDS with CME again, it will eventually work, just takes time. It failed 3 times for me before working.

fathom pendant
civic dawn
# civic dawn The error

[17:15:05:920] [4456:4457] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[17:15:05:920] [4456:4457] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[17:15:05:920] [4456:4457] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

naive wadi
sterile epoch
#

not that far yet

fathom pendant
#

sounds like bad creds

sterile epoch
#

any hints on this?

fathom pendant
#

spoilers

#

wrap the password in single quotes

#

$$ is a variable call to get the PID of the current shell

#

so it's basically calling <password><PID>

civic dawn
# fathom pendant spoilers

Sorry didn’t know this consider spoilers 😥, i mean the credentials was write by HTB on the question, it wasn’t some thing you need to find out it or crack to get it

sterile epoch
fathom pendant
#

ah right

#

it's been a minute

sterile epoch
#

but try putting it under quotes

fathom pendant
sterile epoch
#

like marcie said

fathom pendant
#

specifically

#

'password'

sterile epoch
#

yes not double cuz they parse $ as command

fathom pendant
#

"pa$$word" is interpreted as a complex string; which will eval the variable

shut quest
civic dawn
#

RDP to 10.129.67.54 with user "Administrator" and password "AnotherC0mpl3xP4$$"

Connect to the target machine using RDP and the provided creds. Export all tickets present on the computer. How many users TGT did you collect?

sterile epoch
#

ok

fathom pendant
civic dawn
#

The technique showed in the section all after connect with RDP

fathom pendant
#

xfreerdp /v:ip /u:'username' /p:'password' [other options]

fathom pendant
#

and we told you how to get connected with RDP

#

and why it's failing; as it's a common question

candid lily
#

alias xfreerdp='nohup >& /dev/null xfreerdp /w:1600 /h:900 /timeout:100000 /cert-ignore /drive:home,"/home/vigneswar/Temporary" +auto-reconnect' i use this its very convenient

fathom pendant
#

i often use different mount locations depending on my needs

#

also /dynamic-resolution

civic dawn
#

Alright it worked now, somehow

candid lily
#

anyway rdp is shitty lag

fathom pendant
sterile epoch
fathom pendant
#

single quotes tells bash that you are using a literal string

sterile epoch
#

nowadays ssh is giving a lot of lag

candid lily
#

is it me or windows is hard to understand than linux, so many things happen in windows underthe hood

fathom pendant
#

not really

candid lily
#

try ssh with udp vpn

fathom pendant
#

¯_(ツ)_/¯

sterile epoch
candid lily
#

oh

#

i use wsl lol

sterile epoch
#

me too but only for main app

#

wsl is fast

candid lily
#

even wsl drains storage i got my kali to 80 gb

fathom pendant
#

i've had little issues with rdp using virtualbox ¯_(ツ)_/¯

sterile epoch
#

like flash on steroids and other enhancements

fathom pendant
#

i've heard many people have complaints with wsl2

candid lily
#

i have to reinstall it every month