#modules

1 messages · Page 250 of 1

sterile epoch
#

I face lag when using academy vpn maybe cuz of my region

candid lily
#

storage keeps building up idk how

sterile epoch
#

make a template

feral sapphire
#

Gays! have simple issue , cannot connect using RDP. connection is very bed here. just moved the location to middle east and it just dont connect ot connects and with black screen. maybe there is another way to acesss. using command line without UI. im on mac

#

connection round trip is to high

next bronze
#

if it's a black screen hit enter, and choose a vpn server closest to you

shut quest
#

If enter doesn't work, center left third of the window, try clicking around that area, there's a button there.

naive wadi
#

is the general consensus to do the attacking enterprise networks blind and just do it as if it's a real engagement?

shut quest
lyric inlet
#

HI! Anyone for Active Directory Trust Attacks module ?

#

Skill Assessment

rapid sparrow
#

did you fix it? I want to ask some question about it

#

hi, did you fix it? I want to ask some question about it

snow ridge
#

They added a note about it 😄

kind turret
#

The walkthrough for the Evasion module has been published by the way.

#

In case someone needs extra help

wicked oxide
#

That was a problem from me, all was right except the template i chose

#

I see that we all don't know how to read correctly 🤣🤣

compact halo
#

Good day. I have a question on the Intro to Assembly module; specifically, “Debugging with GDB.” #i am trying to find the solution but am having trouble. I’ve hit the breakpoint on the gdb file and tried using the x/wx 0x4**** to review the rax in hex. The one I’m getting is wrong. Any idea on what I may be doing wrong

rapid sparrow
next bronze
wicked oxide
compact halo
#

I did x/5xb $rip

next bronze
#

the question asked for rax no?

compact halo
feral sapphire
#

Is there alternative to RDP for windows? cose my connection is to bad, so it loads forever

#

Or maybe i can run target widows on my own

fathom pendant
#

in most cases no

#

if you're getting a black screen, just hit enter

fathom pendant
feral sapphire
fathom pendant
#

you can

fathom pendant
#

either way: you can use the vpn connection on your own vm

#

it's generally not recommended to do hacking related activities on your main OS, and even Windows

lyric inlet
#

Just one question about active directory trust attacks

#

I share what I have try if I can ask

fathom pendant
#

as long as you can ask the question without spoiling anything you're fine to ask

next bronze
lyric inlet
#

Its about question2 on skills assessment

#

I think I miss something but I want to be sure

fathom pendant
compact halo
feral sapphire
fathom pendant
#

and is the target running rdp services

#

2 important questions

#

if on your own vm, are you running the vpn. if so; don't be using the in-browser instance (pwnbox) at the same time

compact halo
#

Then I did x/wx 0x4….. and got 0x00c0… hTB says wrong

calm abyss
#

hello i am stuck on PIVOTING, TUNNELING, AND PORT FORWARDING/Meterpreter Tunneling & Port Forwarding section. I dont know what to do.

dim wolf
next bronze
#

or amybe jus tlook at the top of gdb

feral sapphire
fathom pendant
#

could be firewall

#

which is why it's recommended to do this in a VM

calm abyss
lyric inlet
#

@fathom pendant I could PM you ? I dont want to spoil 🙂

fathom pendant
lyric inlet
#

Ok 🙂

compact halo
# next bronze why 0x4? try $rax

Ok, I’m a fool. Maybe I read the question wrong or misunderstood. That’s what I found when it said can’t access memory. That hex was the right answer - thanks a bunch

dim wolf
calm abyss
feral sapphire
dim wolf
#

oof automod

calm abyss
calm abyss
next bronze
dim wolf
#

you can't start a proxy server without setting up the agent first

#

you have to transfer a msfvenom binary to the target first and run it

sharp wren
#

module 81/section 774, Tcpdump question Were absolute or relative sequence numbers used during the capture? I'm pretty sure the answer that the system accepts is incorrect. without discussing the answer here, how should i go about it? Is this something to submit to erratum?

calm abyss
dim wolf
#

yes, did you set up a listener in msfconsole?

#

your console output doesn't show that you did

calm abyss
# dim wolf your console output doesn't show that you did

[msf](Jobs:0 Agents:0) auxiliary(server/socks_proxy) >> use exploit/multi/handler
...
[msf](Jobs:0 Agents:0) exploit(multi/handler) >> run

[] Started reverse TCP handler on 0.0.0.0:8080
[
] Sending stage (3045380 bytes) to 10.129.97.54

#

i got a shell from ubuntu

dim wolf
#

ok, now set up your socks proxy again

calm abyss
dim wolf
#

no

#

you can background your session

#

type bg

calm abyss
dim wolf
#

then you can set up your socks proxy

calm abyss
# dim wolf then you can set up your socks proxy

[msf](Jobs:0 Agents:1) auxiliary(server/socks_proxy) >> run
[] Auxiliary module running as background job 1.
[msf](Jobs:1 Agents:1) auxiliary(server/socks_proxy) >>
[
] Starting the SOCKS proxy server
[*] Stopping the SOCKS proxy server

dim wolf
#

what is your config?

#

for the socks proxy

calm abyss
dim wolf
#

maybe set SRVHOST to 127.0.0.1

cloud urchin
#

0.0.0.0 is correct, that's all adapters

dim wolf
#

i don't remember and i don't have notes 😰

cloud urchin
#

either use that or tun0

#

or if you're on parrotbox whatever the ens number is

calm abyss
#

tun0

#

SRVHOST => 10.10.16.59

#

it works now

dim wolf
#

then i guess you don't need the agent to fire up the proxy

#

i thought it required a session number

calm abyss
cloud urchin
#

damn bro you really got us

calm abyss
dim wolf
#

thank SuperNuts too

cloud urchin
#

haha i did nothing

calm abyss
dim wolf
#

<@&861185840277487616>

lucid mountain
#

I'm having trouble with the final three questions of the skills assessment on intro to digital forensics. I've been using the Windows.Kape.Targets with the SANS and KAPE triage configuration to collect data, and I've manually parsed the downloaded files.
I've searched for strings related to registry key persistence in the relevant modules but haven't found anything. I also tried looking for mimikatz files and .DOCX files without any luck.

dim wolf
north bramble
#

Does anyone know how to fix this error? local parrot vm connecting to rdp

cloud urchin
#

it says it timed out waiting to connect, try increasing your timeout

north bramble
cloud urchin
#

i have no idea what the default is. i set mine to like 100,000

north bramble
#

okay thanks I will try it

north bramble
cloud urchin
#

i don't even know what app you're using

north bramble
#

xfreerdp

cloud urchin
#

/timeout:100000

north bramble
#

okay

#

thanks

north bramble
cloud urchin
#

i pretty much always add /drive, /timeout, and /cert-ignore to all my xfreerdp commands

strange pivot
#

you can't forget /dynamic-resolution 😄

cloud urchin
#

ah yeah that too

#

that's a must have

rustic sage
#

guys someone can help me ? i'm trying to get the subdomains on the module " ATTACKING WEB APPLICATIONS WITH FFUF" but i get this error all time

soft cedar
cloud urchin
#

is it?

lucid mountain
dim wolf
#

did you try it?

lucid mountain
#

Its a blank file

rustic sage
#

@soft cedar

soft cedar
rustic sage
#

i try 2 always https and http

cloud urchin
#

it is https

rustic sage
#

yes i know but i got error

#

the same error in http

cloud urchin
#

this is subdomain not vhost i believe

soft cedar
fleet tinsel
#

Hi, is it possible to dm someone for an hint about Skills Assessment - File Upload Attacks ? Can't find the upload dir despite a lot of tries

cloud urchin
rustic sage
#

it is https

soft cedar
#

~~oh I get you now but does it actually work? ~~

cloud urchin
#

yeah, you have to find the subdomain

#

we would need more information though, your command is correct so i would assume some kind of connectivity error to the server

rustic sage
#

can i show you on the academy room ?

#

i share my screen

soft cedar
cloud urchin
#

interesting, try that then

#

should work with both i imagine

soft cedar
#

I have another target spun up, i will check later

#

but I just checked the step-by-step solutions, they ended up using http lol

rustic sage
#

lol lemme try again with http

#

error lol

soft cedar
rustic sage
#

sure

cloud urchin
#

It works with https as well

soft cedar
cloud urchin
#

i just tested it on the pwnbox, no issues

rustic sage
#

wait you recive no errors?

soft cedar
#

what error are you getting?

rustic sage
#

only error and the numbers

cloud urchin
tawdry vapor
#

hi, can anyone help me with the attacking entrenprise networks?? I'm in the lateral movement. I want to connect via RDP in the machine 172.16.8.50, but how?

rustic sage
cloud urchin
#

yeah works no problem, copy/pasted the command right from the section

#

try restarting your pwnbox

rustic sage
#

lemme try

#

wait a sec

#

i dont know why

#

alots error again

gray merlin
# rustic sage

Do you have DNS setup correctly? It looks like you are trying to resolve each name and unless you have dns configured it will fail.

cloud urchin
#

what command are you using

rustic sage
bright coral
# rustic sage alots error again

There will always be "a lot" of errors, but if you increase the size of the terminal window or decrease the font size, the output is much more readable 😉

gray merlin
rustic sage
gray merlin
#

Can you include the error text in a screenshot?

rustic sage
cloud urchin
#

yeah something up with the connectivity somewhere then

rustic sage
gray merlin
rustic sage
#

it says Errors: 1325

gray merlin
rustic sage
rustic sage
gray merlin
rustic sage
#

i will try from my kali linux machine

dim wolf
lucid mountain
#

I feel I’ve looked at every json for a .docx file extension but I’ll keep looking

rustic sage
#

lol still Errors, well i will go to next steps

coarse lichen
#

Hello I have a question about the optional exercise in the "How to Write Up a Finding" section of the "Documentation & Reporting" module.
I'm trying to gather additional evidence for the findings where evidence was not provided.
When I try to access any IP discovered in the pre-populated Obsidian notebook from the target I get a routing error like "No route to host" or "Destination Host Unreachable".
Am I missing something ?

rustic sage
#

@soft cedar @gray merlin @cloud urchin solved here finally lol

#

i only spend 1:30 hours for this haha

cloud urchin
#

nice

compact halo
shut quest
#

Just did it a moment ago, it does work. Did you check the log?

#

Fine to both checks?

#

Looks like its failing the other check

#
[05/10/2024 14:21:24] C:\Alpha\Static\NotAMalware.exe - OK - Undetected by Microsoft Defender Antivirus
[05/10/2024 14:21:24] C:\Alpha\Static\NotAMalware.exe - OK - Passed all checks
wicked oxide
#

Did you select the correct template ?

shut quest
#

Did you test in on the dev machine first?

wicked oxide
#

Console App (.Net framework)

#

Not just console app

regal jewel
#

"Active Directory Trust Attacks" section "Unconstrained Delegation" .
I managed to get TGT of DC01$ by abusing the printer bug. I imported it in my session using .\Rubeus.exe /renew command, which said TGT was successfully imported. Klist command confirmed that. I need to get flag on DC01 ,but I cannot connect to it or list files on it. How am I supposed to get the flag on DC01 if I have TGT of DC01?

cloud urchin
#

try opening a new powershell window and re-importing and then renewing the ticket.

regal jewel
#

you mean creating sacrificial process with /creatnetonly:C:\Windows\System32\cmd.exe with Rubeus?

cloud urchin
#

yeah

regal jewel
#

ok

tender nimbus
#

Hello guys can someone explain me in simple terms what the Get-NetLocalGroup command is in powershell?

#

if i understand to be used i need to import it first and when used it gives you the users that bellows to a given group am i right?

cloud urchin
tender nimbus
#

like permission, users that bellows to it etc? @cloud urchin

fading oracle
#

Thanks!

cloud urchin
tender nimbus
tender nimbus
cloud urchin
#

yep

tender nimbus
#

Last question, after a certain time i will try some pentesting on cerain machines, for penteesting, is it always adviced to install all the needed tools on a vm and trying some pentest on you vm instead of you "real pc" ?

lavish mango
# tender nimbus Last question, after a certain time i will try some pentesting on cerain machine...

The trouble with running tools you're not familiar with on your host PC is that you may inadvertently open yourself up to exploitation by having services running you weren't aware of. Granted, those services would be running on your VM but at least all of your personal files won't be on there. Working from a VM is smart because you're working with a lot of moving parts and unknowns. Take snapshots and keep your host PC clean of hacking tools I say.

tender nimbus
bright crag
#

Hello, did anyone do Game Reversing & Modding skills assesment? I have a question about first step, I skipped it but I think not the intended way and I do not get the JWT Token afterwards 😦

fading oracle
#

@shut quest dm sent:)

shut quest
#

wut why?

mortal raven
fading oracle
brittle solar
#

Apologies if this is the wrong area to post this, but I'm doing the Network Enumeration with Nmap module and on the question for the Nmap scripting engine "Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.", I believe I found the flag, but the grader says it is incorrect. I initially did nmap -p- IP, and found all the open ports, including one that was 31337, so i did nmap -sV IP -p 31337 and the result gave me an unrecognized nmap fingerprint that included "HTB{flag}" in the get request. I also then tried nc -nv IP:port and recieved the same flag as a 220 get request message. I entered that exactly, took off the HTB, took off the curly braces, and none of them worked. So i googled the question and found a reddit post where someone posted this exact flag and people said it worked, so has the flag changed, am I doing something wrong, or is this a bug/misconfiguration in the acedemy? If any of my terminology is incorrect, apologies as I am a newb still so feel free to correct me

fathom pendant
#

Make sure you don't include spaces

#

The full flag is the HTB{..}

#

Copy/pasting is also a better way to confirm than manually typing

#

They don't change the flags in academy content

brittle solar
fathom pendant
#

Refresh the page and try again then

#

Otherwise message support

brittle solar
#

I did that multiple times, tried restarting the vm, and switched VPN profiles and even my computer sadglas

fathom pendant
#

Actually taking a look

brittle solar
#

So i should probably just message support?

fathom pendant
#

The answer you got was for the service enumeration section

#

Not the scripting engine section

brittle solar
#

Big Oof lmao

#

Thanks I did that one yesterday and didn't realize that was the same flag

#

Appreciate the help

fathom pendant
#

Follow the section and use the same tactics shown. You may need to use something else to find the flag still

brittle solar
#

Thanks yeah I just needed to know if I was looking for the wrong thing. I'll figure it out!

sleek moss
#
  • 1 Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.
    AD Enumeration & Attacks - Skills Assessment Part II
    can someone please tell me how? i trie winrm psexec rdp i cant get int oDC01 im on administraotr acc :SAD:
sleek moss
#

i did it...

#

finally... i completed dem......

#

im 70% complete

#

how long will it take to complete all?

#

Command Injections
onwards

cloud urchin
#

command injection is fun

sinful drift
#

Footprint Module
DNS
What is the FQDN of the host whose last octet ends in "xxx203"?
I am stuck on this question, I have tried all the domains I have found on the right side and none of them give me an answer with the fierce-hostlist.txt list, only the main domain
Can somebody help me 🙂

shut quest
little bear
#

@sinful drift Retract then redact your images.

little bear
#

Can't wait for my 26 week badge

worn matrix
#

Hello guys,i am checking msfvenom ,but i only find it in the module METASPLOIT.i have an exercise for university,where i have to make a malware,which only gives a reverse shell,in a legitimate program(for example zoom.exe ) .So i also want zoom to open and also revshell run.I got in virus total 11/70,something like this.Do you have any tip?is there any way to get it to 0/70? or 5/70?There is another module that saying these tactis?any youtube video?Thanks a lot

cloud urchin
#

not the right place. check the course material from your school

worn matrix
#

there is not really course material....i sent here to modules,because i was reading from modules ;p

cloud urchin
#

how is there no course material for a university

worn matrix
#

ahahahah,there is no course material for malware development + avoidance8

cloud urchin
#

then why'd they assign you that

#

ask the professor how they want it done based off the course material

worn matrix
#

he said we should look for it,15-20/70 is okay,but the <10 will get extra.

#

i think the new module HTB launched is about this,ahhaha

cloud urchin
#

yeah and people can help with the module but not your homework

worn matrix
#

relax bro

cloud urchin
#

what do you mean? i answered your question

worn matrix
#

cool,thanks

cloud urchin
#

np

shut quest
tranquil axle
#

If you use xfreerdp look into the /drive parameter to directly map a folder of your attackbox onto the windows machine

#

Then you can just copy paste

pliant coyote
#

How do I decrypt it?

cloud urchin
#

2john?

pliant coyote
#

yes

earnest mulch
#

ugh the academy password attacks pass the ticket module have expired tickets or something

uneven oracle
#

I keep getting a connection timed out error when trying to download packages. I know it’s not my internet because I have no issues with my own Linux with my own VM.

rustic sage
cloud urchin
#

nfs is probably already installed on the parrotbox

uneven oracle
rustic sage
#

^ Try locate that. Im using my own Kali box so I don't remember if this is installed or not in the htb parrot distro

#

@uneven oracle Can you ping to google for example?

uneven oracle
rustic sage
#

Yeah looks like it's not responding

uneven oracle
rustic sage
#

Is that NFS server already on your host?

uneven oracle
rustic sage
uneven oracle
rustic sage
uneven oracle
rustic sage
#

🤔

#

maybe try kali again with another VPN server config

uneven oracle
rustic sage
#

in the module page where it says "VPN Servers" use a different VPN server and download that connection file

#

US-1 has not given me any issues

uneven oracle
rustic sage
#

Try US-2 perhaps? I'm unsure what the issue is for you

fathom pendant
#

Because in the in-browser vm you don't need to download/run the vpn

uneven oracle
fathom pendant
#

Are you on the free plan? Works find on mine

cloud urchin
#

there's a free academy plan?

fathom pendant
#

Also regarding using your own kali vm: go to network manager --> tun0 connection --> ipv4 settings "only use resources on this network"

fathom pendant
uneven oracle
fathom pendant
#

That's why

#

Free users have very limited network access with the pwnbox

#

It should work in your own kali vm since they're both Debian based

uneven oracle
cloud urchin
#

really?

fathom pendant
#

¯_(ツ)_/¯

fathom pendant
cloud urchin
#

it should come with all the tools on it, i'm surprised nfs isn't already installed anyway

brisk leaf
#

Can any one help me to view attlog.dat file

cloud urchin
#

i'm on a 'free' plan and i can ping google from the pwnbox without issue

fathom pendant
fathom pendant
cloud urchin
#

i can also update

#

yes, but never on a subscription

uneven oracle
fathom pendant
#

If so, that sets a flag on your account

cloud urchin
#

interesting, never knew

fathom pendant
uneven oracle
fathom pendant
#

It's whatever is showing your ip

#

Again this is for your own vm not the pwnbox

uneven oracle
fathom pendant
#

On kali, it shows your ip yes?

#

In like the top right or bottom right

uneven oracle
fathom pendant
#

I meant on the gui

#

Or maybe you have an icon near the date

uneven oracle
fathom pendant
#

Weird

#

Can you screenshot your desktop?

uneven oracle
fathom pendant
#

Hm I don't have much experience with kali tbh

#

Ah you have the zSec download of it instead of the official download

#

Which is why things look diff

uneven oracle
#

But I should be able to find what you’re talking about. Idk.

fathom pendant
#

¯_(ツ)_/¯

#

You say you can connect to the internet in your kali yeah?

uneven oracle
#

This looks like what you were talking about, but it isn’t specifically referring to tun0.

fathom pendant
#

That's setting a new profile

uneven oracle
fathom pendant
#

You need to use this menu when you connect to the vpn

#

¯_(ツ)_/¯

cloud urchin
#

again, what module and section? if it's asking you to use nfs, it's probably already installed

fathom pendant
#

Could be a difference that HTB overlooked in a parrot update

cloud urchin
#

doesn't the pwnbox come installed with everything you need?

fathom pendant
#

The pwnbox is a static config across academy

uneven oracle
fathom pendant
#

It's not dependent on which module you're working on

uneven oracle
cloud urchin
#

right but it should include all the tools

fathom pendant
#

It includes most tools

#

Not all

#

Creating an nfs share isn't required for the module

#

This is purely an example of how you would set one up

fathom pendant
#

It contains a lot of the normal offensive tools, but not a lot of the other basic tools

uneven oracle
#

The HTB platform isn’t quite as cohesive as I would hope. It’s not flowing smoothly…

fathom pendant
#

small hiccup for you, most other people get through it fine ¯_(ツ)_/¯

#

I'm also assuming your kali is updated

uneven oracle
fathom pendant
#

¯_(ツ)_/¯

#

Either way

#

The vpn connection shouldn't freeze your vm

#

I've heard it doing dumb stuff requiring you to set the option to only use network resources

uneven oracle
fathom pendant
#

tun0 is the interface given when you connect to the vpn

cloud urchin
#

are you connected to the vpn? i just connect and have no issue connecting to the course resources

fathom pendant
#

You have an interface in that menu regarding your local/regular interface (generally eth0)

cloud urchin
#

tbh use the terminal instead

#

much easier to read the info

fathom pendant
#

After connecting via terminal

uneven oracle
fathom pendant
#

go back to that network menu

#

identify the vpn interface

#

select it

#

set "only use resources on its network"

uneven oracle
fathom pendant
#

¯_(ツ)_/¯

#

i also find it weird you have 3 eth devices

#

but that's whatever

cloud urchin
#

probably install the regular kali

fathom pendant
#

^

#

zSec is a customized Kali version

#

which has many differences to regular kali

uneven oracle
#

Ugh…

fathom pendant
#

but can you show your terminal that shows you have the tun0 interface?

autumn pilot
#

just use the terminal to connect to the vpn

#

and use the terminal again to verify the connection

cloud urchin
#

that's what i said 😛

#

i don't like that gui

fathom pendant
#

yeah, my steps are applying post-connection; to see if there's a (known) issue with the vpn overtaking the regular connection

autumn pilot
#

on top of that why would you choose a custom vm image from 2 years ago over the official one that is up to date

fathom pendant
fathom pendant
#

brother

#

it's not like it's leaking your full public IP

uneven oracle
fathom pendant
#

tun 0 --> tun1

#

sounds like you have multiple vpn configs running

#

and i'm seeing tun2 there

#

sudo killall openvpn

uneven oracle
fathom pendant
#

also; don't run around your system as root

fathom pendant
uneven oracle
fathom pendant
#

well don't

#

it's extremely irresponsible to run around your system as root

#

you can very easily and accidentally break your system doing that

uneven oracle
fathom pendant
#

check the ifconfig to see if it killed all the openvpn connections

#

also try installing the nfs tool on kali

uneven oracle
fathom pendant
#

even in a vm

#

don't generate bad habits

rustic sage
#

Never a good idea to be root user as a main account

fathom pendant
#

especially since most people don't change default root password on their installs

rustic sage
#

If its a box you revert then whatever, but generally speaking it's not recommended

fathom pendant
#

root:toor
root:parrot

rustic sage
#

kali:kali

fathom pendant
rustic sage
#

yeah i know haha

fathom pendant
#

i'm more specifically referring to --> root

rustic sage
#

I know i just felt like typing it

fathom pendant
#

which is more dangerous

uneven oracle
fathom pendant
#

tunX

#

as it's a split-tunnel vpn

uneven oracle
fathom pendant
#

yes

#

now reconnect and try pinging the target

#

the reason it freezes is because by having multiple tun interfaces it has no idea which one to bind the request to since they all can access the same resource

uneven oracle
fathom pendant
#

yes

#

the "Click here to spawn target" button

#

ping that IP

uneven oracle
#

I think it’s working.

fathom pendant
#

that's the bare minimum basics of testing connection

#

if you're getting a response from the IP, then it's working

uneven oracle
fathom pendant
#

weird

#

¯_(ツ)_/¯

#

but anyway: if there's no questions related to the section -- the reading is purely informational

rustic sage
#

Do you have enough resources to the VM?

uneven oracle
cloud urchin
#

i would still recommend using the regular version of kali. with your distro being so out of date you're bound to run into issues moving forward.

uneven oracle
#

Frozen

cloud urchin
#

looks like you're connected

uneven oracle
fathom pendant
fathom pendant
#

there are times where they give you examples and configurations to worry about

#

and then showcase how they take advantage of it

uneven oracle
fathom pendant
#

then; change vpn region there should be a spot on the page to do so

uneven oracle
fathom pendant
#

steps to change after you get the new connection file; --> kill the current vpn --> download new file --> run it

uneven oracle
cloud urchin
#

yeah again, the freezing could be a myriad of things and you really strongly need to consider installing a modern non-custom version of kali

rustic sage
#

Running ls locally looks to me an issue with VM resources.

fathom pendant
#

ya goon

rustic sage
#

hang on

fathom pendant
#

that's a remote system

rustic sage
#

that above screen?

#

ahhh right

#

carry on

fathom pendant
#

if all else fails: Message support

#

¯_(ツ)_/¯

#

this bubble in academy; if you don't see it --> disable vpn

uneven oracle
fathom pendant
#

they're gonna be better at actually working with you to resolve an issue

uneven oracle
fathom pendant
#

well if you're using the same config file it could be the vpn region that's giving you the trouble

#

you don't have to use the closest one to you

uneven oracle
fathom pendant
#

the ping difference is often negligible

#

well yes, but on a technical level if it's purely related to a box connection --> then support is the way to go

#

to test if it's a connection issue;
ping the host --> let it go for around 2-3 minutes --> see if there's large variance in response times

#

i.e. random 5k ping jumps

fathom pendant
#

sometimes some servers just get messy for a bit and work fine later

uneven oracle
fathom pendant
#

nope

#

1y+

#

basically around the time i joined the discord

uneven oracle
fathom pendant
#

life circumstances forced me to change priorities

uneven oracle
uneven oracle
pliant coyote
#

I would like to ask why the password for cracking ssh is the same as the password for cracking ftp, is this a coincidence or is it just a coincidence?

bright crag
#

Hi, anyone some hints about the first step in Game Reversing and Modding Skills Assessment? I found a way to play the game, I jumped straight to the playable scene but BepInEx says that the token (JWT) is null and no requests are made to the server. Either I have some misconfiguration regarding the scoring server’s IP and port or this is not the intended way and I jump to the playable scene too soon and thus skipping the login process. I tried to the insert the load scene method call in multiple spots to try to be after the login process but the result was the same. Any help would be appreciated.

Thank you!

fathom pendant
#

often on the same device people will re-use the same password for things

uneven oracle
#

Does the same on Ubuntu.
And that’s the standard image.

umbral apex
#

Please I need help. I still can't start my pwnbox

#

'You have used your allowed pwnbox time'

#

It's being more than 6 days now.

fathom pendant
#

if it's academy, that time should reset daily, if it's main platform -- you need to upgrade to VIP/VIP+ to continue using pwnbox

#

suggested solution: just set up your own vm

compact patrolBOT
umbral apex
#

Thanks

young flume
#

hello team can someone help me with BROKEN AUTHENTICATION module Brute Forcing Passwords
section

zealous swallow
#

Good morning guys, a question I have and it is all the machines, can brute force tests be done on them?

acoustic owl
acoustic owl
young flume
#

can’t brute force it

#

stuck here 3 days tried all things

#

if you did that section can you help me

acoustic owl
young flume
#

yeah i sorted rockyou 50

#

with that policy

#

however showed only 3, 4 passwords and tried all of them

#

but no success

acoustic owl
young flume
#

can you give a hint me please bro

#

or can you help me

acoustic owl
pliant coyote
#

What does pwnbox use to view docx

polar widget
#

Anyone doing Windows Evasion module? I am on static section, my binary has evaded windows defender, but the flag isn't created?!

swift rain
polar widget
snow ridge
#

And also use release mode when building

fathom pendant
pliant coyote
#

Password Attacks Lab - Hard

#

why error?

bright coral
pliant coyote
#

damn it

polar widget
civic dawn
#

Hello, I have problem at Password attacks module, Protected files section

When I run ssh2john.py I get this error:

Traceback (most recent call last):
File "/usr/share/john/ssh2john.py", line 193, in <module>
read_private_key(filename)
File "/usr/share/john/ssh2john.py", line 103, in read_private_key
data = base64.decodestring(data)
AttributeError: module 'base64' has no attribute 'decodestring'

errant moss
#

Are you using the right Python version? Sometimes I get similar errors when running a script written for Python 2 using Python 3 and/or vice-versa...

fathom pendant
errant moss
#

Ah, then try Python2, as pointed out by MarcieLee

fathom pendant
#

iirc 2.7 works

#

a lot of submodules were changed in 3 and even 3.9+ (btw latest python is like 3.12)

civic dawn
errant moss
#

Yes, seems likely

fathom pendant
#

yes

bright coral
#

What does the shebang in that script say?

fathom pendant
#

the base64 subprocess no longer uses .decodestring

pliant coyote
#

Password Attacks Lab - Hard

#

How do you mount the last step? I don't know how to do that at all.

timber trellis
#

why it wont work??

soft cedar
fathom pendant
pliant coyote
#

I followed gpt4 and it came out like this

kind turret
fathom pendant
kind turret
#

The module uses .NET Framework ...

#

What you are doing will never work

fathom pendant
#

also did you mkdir the /mnt/vhdmount?

kind turret
#

This is wrong @polar widget

fathom pendant
#

if you didn't then that's why it's not recognizing the vhdmount as a mount point

#

@kind turret (mostly because I'm too lazy to check) I'm curious, does the guide for the Password Attack - Hard Lab incl steps to mount in linux/reference any article?

kind turret
#

I do not remember

#

Its been maybe over a year since I have done that one

fathom pendant
#

lol

fathom pendant
#

neat!

fierce mason
polar widget
fathom pendant
shut quest
fathom pendant
#

¯_(ツ)_/¯

#

pretty quick imo

shut quest
#

That's it? mnt the rest?

fathom pendant
#

yep basically once you do the dislocker -u<password> you mount that to another mountpoint (so requires 2 mnts) and it's accessible

#

the guide makes mounts in /media/

shut quest
#

Interesting, I'll have to give that a try as well since I used also another tool

fathom pendant
#

ye

#

losetup is as simple as losetup -Pf <file>.<ext>

#

and it should create the partitioned setup on the first available loopN device

#

the rest is just using dislocker to open and put it on your system to read

shut quest
#

Ty

fathom pendant
#

np, it's fairly straightforward

#

at least if you're familiar with dislocker

pliant coyote
fathom pendant
#

(also it's never recommended to mount anything to your home directory)

#

but since you're on pwnbox it's not as big of a deal

#

just don't go making bad habits

fathom pendant
# pliant coyote

just to give you some hope: you're in the home stretch -- this is the last set of things you need to do

pliant coyote
#

Why is the ntml I cracked out this

analog dock
#

Not sure why you’re trying to crack

valid viper
#

I'm trying to run proxychains (nmap) on the final challenge of the pivoting module...and I get this error - dig: parse of /etc/resolv.conf failed

pliant coyote
#

I'm used to cracking passwords because here's the chapter on cracking passwords

fathom pendant
#

using the right pw list of course

valid viper
#

Please help me Marcie.

analog dock
fathom pendant
#

you use the mutated list for this

fathom pendant
analog dock
#

Ah I see

valid viper
#

Does anyone have any idea why proxychains might not be working?

fathom pendant
#

sounds like your conf file is messed up

valid viper
#

I've got socks4 127.0.0.1 9050 in /etc/proxychains.conf

fathom pendant
#

i also don't recall using dig for it

valid viper
#

I didn't use dig, I just ran proxychains.

fathom pendant
#

¯_(ツ)_/¯

#

idk what exactly your command is so I'm just going off error

valid viper
#

I'll reset the box.

#

It's really annoying because I have to shutdown my computer to make the error stop looping.

fathom pendant
#

¯_(ツ)_/¯

#

also having you say "Just ran proxychains" doesn't really help much

#

like you just did proxychains?

#

no other command following it?

pliant coyote
#

finally

fathom pendant
valid viper
#

proxychains nmap 172.16.5.35 -Pn -sT

#

Then it spits out the dig error and a bunch of [DNS-request]: IPv6 address blah blah blah.

#

Definitely not the proxychains conf file.

fathom pendant
#

add -n

valid viper
#

Where?

#

I have to shut down my computer every time this error occurs, so I'm not wanting to experiment a whole lot.

fathom pendant
#

to the nmap command

#

but also; why are you scanning that IP?

#

it sounds like something in your setup has gone wrong somewhere

valid viper
#

That IP turned up in the ping sweep.

hazy cave
#

So. Just a question what are. Thought. On the the lockbit . Guy they offer 10 million to find

fathom pendant
#

read and follow #welcome to access more of the server

valid viper
#

Guess I have to format again.

#

Linux is not without its problems. 😐

hazy cave
#

Apologies I thought I was in general

fathom pendant
fathom pendant
#

might be a layer 8 Issue

valid viper
#

I'm playing with the proxychains conf file.

fathom pendant
#

¯_(ツ)_/¯

valid viper
#

LOL now the payload won't work...

#

Segmentation fault (core dumped)

#

Cute.

#

Well, figured that out.

fathom pendant
#

with a simple dynamic chain i was able to get it to work just fine ¯_(ツ)_/¯

valid viper
#

It was set to static.

#

Er, strict.

#

Dunno how that happened, but whatever.

fathom pendant
#

so was my config

#

¯_(ツ)_/¯

valid viper
#

Yeah well, now when I go to start a proxy server in Metasploit, it starts and then stops immediately.

#

Any ideas for that...?

sleek moss
#
  • 0 Try adding any of the injection operators after the ip in IP field. What did the error message say (in English)?

Command Injections

Page 2
Detection

Detection
Im on firefox and I do the ip and then the ; and it doesnt do any error message it just shows my cmd why

valid viper
#

auxiliary(server/socks_proxy) >> run
[] Auxiliary module running as background job 0.
[msf](Jobs:1 Agents:0) auxiliary(server/socks_proxy) >>
[
] Starting the SOCKS proxy server
[*] Stopping the SOCKS proxy server

fathom pendant
civic locust
valid viper
#

LOL good point @fathom pendant

valid viper
civic locust
#

Recently I faced a similar issue and restarting my Pwnbox helped.

#

But jobs (in pwnbox) are displayed near the enter field

#

Also you can use jobs -l

valid viper
#

No active jobs.

silent knoll
#

Can anyone help with the skills assessment on sqlmap? i keep getting empty responses when dumping the database

civic locust
sleek moss
#

yo is the show step by step buying annual worth it?

sleek moss
#

ic but does it give the steps to how to do it?

fathom pendant
fathom pendant
sleek moss
#

i c

fathom pendant
#

¯_(ツ)_/¯

#

imo i've had little issue with following the course content and getting answers

civic locust
fathom pendant
#

the Write-up/solution is there for me if I want to double-check if i'm missing something

civic locust
#

So. It may help, but not too necessary

sleek moss
#

i mean bruh ive wasted hours cause of some dumb system technical stuff

#

when i was doing right ting

fathom pendant
shut quest
# sleek moss yo is the show step by step buying annual worth it?

Many people have completed many modules without it. If you don't like reaching out to others and are hard stuck and researching the problem isn't providing results then yes I can see it being worth it. I'd only use it to see how my solution compares to theirs which can be valuable as well.

fathom pendant
#

^

fathom pendant
sleek moss
#

Command Injections

Page 2
Detection

Detection + 0 Try adding any of the injection operators after the ip in IP field. What did the error message say (in English)?

#

i put in the ip and the escape sequence

#

and no error pops up even though im doing right ting

valid viper
#

VPN failing for anyone else?

sleek moss
#

then i add cmd after and my cmd pops up

fathom pendant
#

it's just asking for you to input any injection operator

sleek moss
#

i did it works but theres no error

fathom pendant
#

not full injection command

#

just the operator

sleek moss
#

i did just the operator

#

i did all the operators after ip

#

no error msg im on firefox...

fathom pendant
#

it's not gonna be a full popup

sleek moss
#

ik im on burpsuite

fathom pendant
#

it's literally asking you to do it in the input field

sleek moss
#

im looking at the html code no error

fathom pendant
#

you don't need burpsuite

#

think; it's like trying to type something invalid in some forms

next bronze
#

the response is on the client side, you're not gonna see it in burp

sleek moss
#

bruh

#

i got it..

fathom pendant
#

so again; not a box issue -- a you issue :)

sleek moss
#

😦

fathom pendant
#

you need to take a step back and read the question carefully at times

#

"in the IP field" meaning in the textbox where you'd put the IP

sleek moss
#

tru

fathom pendant
#

you're doing something that's likely meant for a later portion

#

after you discover your input is being sanitized or detected in some way

valid viper
#

proxychains nmap 172.16.5.35 -Pn -sT
|DNS-request| fe80::de8d:8aff:fe52:ed88%wlx788cb5a00b21
|DNS-response|: fe80::de8d:8aff:fe52:ed88%wlx788cb5a00b21 does not exist
dig: parse of /etc/resolv.conf failed
D-chain|-<>-127.0.0.1:9050-<><>-172.16.5.35:3389-<--denied
Nmap scan report for 172.16.5.35
Host is up (0.000031s latency).
All 1000 scanned ports on 172.16.5.35 are in ignored states.
Not shown: 1000 closed tcp ports (conn-refused)

#

So we're making a bit of progress, it stopped looping.

fathom pendant
valid viper
#

Well it's working for me too.

#

But the point is that the box isn't working.

fathom pendant
#

i mean literally just dropped the nmap scan with proxychains and it worked

valid viper
#

Connected ^

fathom pendant
#

i literally just ran through this skill assessment and changed nothing in my conf files

#

and it worked

valid viper
#

Well, guess I get to format.

fathom pendant
#

¯_(ツ)_/¯

valid viper
#

It's just really weird.

fathom pendant
#

idk why your proxychains is doing a DNS request

#

it looks like it's checking your /etc/resolv.conf for some reason

civic dawn
#

I’m at Password Attacks Lab - Easy

Any hints please? I tried Resources, mutant list and rockyou, used hydra to brute force ftp

fathom pendant
#

root is not going to be your entry point if you're trying to bruteforce that way

civic dawn
fathom pendant
#

drop to -t 48

civic dawn
#

Examine the first target and submit the root password as the answer.

I don’t know who first target is so I used username.list too

fathom pendant
#

also since the username list is much shorter it's faster to do -u

#

64 threads tends to break the ftp service and drop packets

#

yes; even if you're using the pwnbox

civic dawn
civic dawn
fathom pendant
#

no

#

-u goes goes through the username list and iterates instead of password list and iterates

earnest mulch
#

I fucking hates password attacks

#

at the final hard one but it's getting on my nerves really

fathom pendant
#

what's getting on your nerves about it?

earnest mulch
junior oxide
#

i have a problem in file upload module under whitelisted filters here is the problem when i upload a file using the reverse double extension method and try to access the reverse shell AFTER i fuzz it using the intruder in burp i can only access the file extension without the first name and get a blank page with the reverse shell itself without being able to interact with i've got on burp the two files were successfully uploaded and so far i've managed to access both but with the same issue and i've used the simple-backdoor.php payload in kali linux located in /usr/share/webshells/php/simple-backdoor.php

fathom pendant
#

it's fairly high up in the list tbh

#

iirc i brute it with winrm

#

not with smb

valid viper
#

I switched to my Kali box and now the VMs keep shutting down.

fathom pendant
#

¯_(ツ)_/¯

valid viper
#

Yeah, just one of those days. Got it working now.

#

Totally different box...

#

Now giving me 3389/tcp closed ms-wbt-server

#

I used ssh -D

#

I was able to get NMap to run through proxy chains, but every port is showing as blocked.

#

What a joke.

fathom pendant
#

Whenever you start a windows lab you should generally wait a few minutes for the services to start up

valid viper
#

Still showing closed.

#

Two boxes, several restarts

#

Kali and Parrot both say the same thing.

#

I sure hope the actual test isn't like this. Because this is extremely frustrating.

fathom pendant
#

change vpn region and try again ¯_(ツ)_/¯

valid viper
#

I guess.

#

After that whatever.

fathom pendant
#

like i said, it worked for me idk why it's not working for you

valid viper
#

I don't know either. I've used two different boxes, restarted a couple times, dozens of VMs...

#

And now the boxes won't even ping.

fathom pendant
#

change vpn --> terminate lab --> respawn it

valid viper
#

All the VPNs are giving me a ping time above 600ms.

#

Is that normal?

#

Maybe my Internet is screwed up.

fathom pendant
#

depends; if you know your average and it's above that then no

#

is it a stable time above 600?

#

if so that's manageable

#

if it's unstable then definitely no

valid viper
#

I restarted my modem, yeah the ping is now down to 120ms.

#

xfreerdp isn't working through proxychains either.

#

I'm going to try another lab for a sanity check...

#

And if that works I'm going to write a very nasty email.

fathom pendant
#

Make sure you type the ip correctly

valid viper
#

I know it should.

#

Believe me...I am triple checking everything

fathom pendant
#

Is the pw wrapped in single quotes?

valid viper
#

Yes.

#

Dynamic chain ... 127.0.0.1:9050 ... timeout

fathom pendant
#

Hmm

fierce meteor
#

Anyone have issues with metasploit socks proxy server with proxychains? It starting SOCKS proxy server and after that already Stopping the SOCKS proxy server. I using both sametime, 9050 and 1080 port. I use 1080 for metasploit and 9050 for SSH dynamic tunneling. I think issue is that proxyxhain command is always try use first port in list in .conf file. If there is any method to choose which port to use which proxychain command

valid viper
#

Got it.

#

I established the -D connection via SSH.

#

Let me try proxychains now.

#

Port 3389 is still showing as closed on NMap... Even though I'm using the -Pn flag.

#

Is that an NMap problem?

fathom pendant
#

Maybe, if you can rdp it's open

valid viper
#

Right. Well now I'm just letting the scan run fully to see if it lists the port.

#

If it lists the port... As least I can test it.

#

Now it's showing open, hmmm

#

Well, it's been an adventure, Marcie. I really appreciate your patience and the sanity checks.

#

Have a good rest of your weekend.

slow wind
#

Little effort went into making the ffuf module due to this I would appreciate some help from some peers

#

No context is provided for fuzzing of the parameters

#

In the examples they use the FQDN admin.academy.htb:port

#

I'm not sure where to fuzz at this point

fathom pendant
slow wind
#

They do not

#

The problem is that you're given an IP any new student will not understand how dns works

#

You can fuzz a subdomain unless there's a record for it

fathom pendant
#

Look at the full command, they specify -H "fuzz=key" --> -H "<fuzzed_param>=FUZZ"

fathom pendant
slow wind
#

No sub is given

fathom pendant
#

ip domain

slow wind
#

Yes I've been recursively fuzzing looking for an extension with php for an hour

#

Without anything applicable

fathom pendant
#

If you need to fuzz for a subdomain then you put the FUZZ at http://FUZZ.domain

slow wind
#

I should have been more clear

#

Sorry the goal is to fuzz a parameter

fathom pendant
#

Look at the example given

slow wind
#

That's the problem

#

It doesn't work because admin.cademy.htb does not exist

fathom pendant
slow wind
#

With no enumeratable subdomains for obvious reasons

fathom pendant
slow wind
#

Yes I've done that

fathom pendant
#

You don't include the port in the hosts file

slow wind
#

I'm sorry I'm not trying to be rude I'm just very frustrated with this man like I get it you're community but I really believe there is a lack of context for this challenge

fathom pendant
#

I just did this the other day with no issues

#

It gives you the full uri of http://admin.academy.htb:port/academy/admin.php?FUZZ=key

slow wind
#

I got it

fathom pendant
#

Then you just need to determine the fs that would yield no useful info

slow wind
#

I stg an hour ago I had tried using ip sub.dom.htb

#

My bad, user error

fathom pendant
#

It happens

#

I've been there before

#

You miss one thing

slow wind
#

Yeah specially after rolling through the module then hitting brick wall

#

Messes up the flow you got going

#

Thanks @fathom pendant

zealous swallow
#

Good evening guys, someone who knows about vurneravidilidaes, could you tell me if this text sees any vurneravidilidades?

#

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 8.9p1 Ubuntu 3ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 3f:d6:c3:c5:f9:20:4e:37:76:15:f8:31:f1:8f:55:9d (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBGX+sgrYOhdqxwGagOyGEOyYGRk8CCmuJkUYwUb6iLYM768wKrKHSpAexT54tw1YrQQBATfV66j+xz9oFt0isls=
| 256 5e:aa:a4:e6:5b:d7:40:c0:0c:ad:e5:ff:61:c7:91:0e (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIbjDG+DkDWrXksvoE+kkgxN/owCQxHNSLCqHm4Zn4q5
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

cloud urchin
#

wut

#

what module do you need help on

zealous swallow
fathom pendant
#

This channel is for help with academy modules

zealous swallow
#

a ok sorry

fathom pendant
#

And helping the occasional lost soul find the right channel (by reading and following #welcome )

tender nimbus
#

Hey guys do you know why its not working?

#

PS C:\Users\administrator> Get-ADUser -Filter {Name -like 'Robert'}
Get-ADUser : The server has rejected the client credentials.
At line:1 char:1

  • Get-ADUser -Filter {Name -like 'Robert'}
  •   + CategoryInfo          : SecurityError: (:) [Get-ADUser], AuthenticationException
      + FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.Security.Authentication.AuthenticationException,Microsoft.A
     ctiveDirectory.Management.Commands.GetADUser
sharp umbra
#

how do i install the cheat

tender nimbus
#

The question is Connect to the target host and search for a domain user with the given name of Robert. What is this users Surname?

cloud urchin
tender nimbus
cloud urchin
#

try a username/password combo that will authenticate

tender nimbus
#

thanks 🙂

vernal viper
#

Heyy wsupp

lucid mountain
dim wolf
#

wish i could help you more but i don't have access to my notes

lucid mountain
#

thanks anyways

slow wind
#
└─# ffuf -w ./subs.txt:FUZZ1 -w /usr/share/wordlists/seclists/SecLists-master/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ  -u http://FUZZ1.academy.htb:31985/FUZZ -recursion -recursion-depth 1 -fs 0 


 :: Method           : GET
 :: URL              : http://FUZZ1.academy.htb:31985/FUZZ
 :: Wordlist         : FUZZ1: /root/subs.txt
 :: Wordlist         : FUZZ: /usr/share/wordlists/seclists/SecLists-master/Discovery/Web-Content/directory-list-2.3-small.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
 :: Filter           : Response size: 0
________________________________________________

[Status: 301, Size: 337, Words: 20, Lines: 10, Duration: 85ms]
    * FUZZ: courses
    * FUZZ1: archive

[INFO] Adding a new job to the queue: http://archive.academy.htb:31985/courses/FUZZ

[Status: 301, Size: 337, Words: 20, Lines: 10, Duration: 85ms]
    * FUZZ: courses
    * FUZZ1: faculty

I'm struggling to finish the module ffuf, skill assessment section. Is anyone able to identify something that could possibly be setting me up for failure here that is familiar with the module?

#

Or share a hint that I'm possibly missing

#

I shouldn't have to specify file extension right? I would assume thats irrelevant

#

Potenially could a directory file size be 0, containing additional pages be missed by my -fs 0 setting?

fathom pendant
#

you found ||3|| file extensions yeah?

slow wind
#

yeah currently looking for the page then so on

fathom pendant
#

i believe it's -x .ext1,.ext2,.ext3 to specify extensions

#

or it's -e

#

i genuinely forget for a sec

slow wind
#

I think its -e

#

Its just that this scan/fuzz has been going on for a while now

#

and the expected requests is plus 1Mil + 3 jobs

#

I dont know I was thinking that usually a HTB bruteforce is pretty quick

fathom pendant
#

usually is :) what question exactly are you on?

#

i'll give you another hint: you only need the subdomain that returned all found file extensions

inner geyser
#

Having some difficulty with the format for the answer of the last question in "Web Server Pivoting with Rpivot" within the Pivoting,Tunneling, & Port Forwarding module. I'm running "proxychains curl -v 172.16.5.135" and there is basically a variation of "I Love Proxy Chains" in the title header(?)....and copy/paste from there directly into the answer field is giving me an "incorrect answer". I've ensured no extra spaces at the beginning/end of the string. Any thoughts on what I should do here?

fathom pendant
#

i believe so yeah

slow wind
#

damn what am I doing wrong then

#

Ah I found it, that took a long time tbh

sleek moss
#

any tips for skill assessment command injection?

cloud urchin
#

i don't think there are any broad tips, the module goes over the material really well so make sure you take good notes

earnest mulch
#

(deleted the spoilers)

frail ice
#

I am aswell

#

Password Attacks - Protected Files

fathom pendant
#

change vpn regions

little bear
#

I also have difficulty getting a target VM to spawn for this module. RIP

#

Try what Marcie suggested^^

earnest mulch
#

Would there be C module in the future?

solid moth
#

i am doing ATTACKING COMMON SERVICES-Attacking DNS . i am using subbrute and i added the ip address to the resolvers.txt. but its been two hours . nothing came out. can someone tell me what went wrong ?

solar zodiac
#

Hi everyone! I was wondering if someone could nudge me on the Adavanced XSS and CSRF skills asessment. I can make the CSRF callback to me, but can't do much else with it. Not quite sure why this is... if anyone could clear this up for me it would be greatly appreciated 🙂

fathom pendant
solid moth
#

python ./subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt

fathom pendant
#

it should work as long as you didn't edit the names.txt file

cloud urchin
#

show cat resolvers.txt

fathom pendant
#

if resolvers.txt was incorrect it wouldn't run at all

#

also if it's been 2 hours it's likely the target is dead at this point and needs to be respawned

solid moth
#

cat resolvers.txt
10.129.203.6

fathom pendant
#

in which case you'll need to update the resolvers.txt to reflect the new 10.129.x.x ip

solid moth
#

the target is alive i think i extended it

#

i got inlanefreight.htb and hr.inlanefreight.htb

fathom pendant
#

and did you try doing a zone transfer to any of them?

#

:P imo if you're waiting for it to finish it's gonna be a bit (wc -l names.txt to see how big that list is)

#

the names.txt file is 101 entries long

inner geyser
solid moth
#

its 101010

#

so i'm not doing anything wrong ? i just wait?

pure jetty
#

how is everyone doing !! Is hacking going well or anyone over thinking it like me lol !

fathom pendant
#

i don't recommend waiting the whole time

#

you can check those as you wait

pure jetty
fathom pendant
#

not taking any on atm, got a lot goin on

pure jetty
#

i will wait on the line when you can take me, while waiting i will keep learning to improve myself

pure jetty
solid moth
#

i tried host and nslookup. nothing came out

shut quest
solid moth
#

ohhhhh! i found the flag

#

but i honestly don't kown why

shut quest
solid moth
#

dig AXFR @10.126.xxx.xxx

fathom pendant
#

you mean dig axfr @ip domain

deep token
#

i need help

fathom pendant
#

also 10.126 looks wrong

#

mistyped likely

fathom pendant
#

we aren't mind readers

solid moth
deep token
fathom pendant
#

anyway you got the answer via a zone transfer to the subdomain

fathom pendant
#

it falls under illegal

deep token
#

dont have time to read that my man i just wanna find my bro

fathom pendant
#

not to mention we err on the side of caution here what with "my friend" or "my girlfriend" type shit

deep token
#

missing for weeks and months like holy shit

fathom pendant
#

this isn't the server for that

#

if you have any mutual friends reach out to them, or know someone that knows them irl

#

but this server isn't for finding people

deep token
fathom pendant
#

since you don't wanna bother to go read the rules; i'll just post it here

deep token
#

sucks cuz we never gave each others real names

fathom pendant
#

as much as it sucks, you're requesting an illegal activity

#

i know a good portion of my good online friends real names

cloud urchin
#

don't get scammed if your 'friend' comes back and needs money

fathom pendant
#

go pay a PI to find him ¯_(ツ)_/¯

shut quest
fathom pendant
#

iirc the dns section of that module goes over finding basic info with zone transfers and such

shut quest
fathom pendant
#

it gives a decent enough overview considering DNS isn't that big from what i've seen

deep token
#

I just wanna find my bro, im not gonna pay a reverse search just to find his name.

fathom pendant
cloud urchin
#

no, and not the right place

fathom pendant
#

<@&861185840277487616>

cloud urchin
#

you can go to the authorities that's it

fathom pendant
#

I get that you found this server by just searching "hackers" but at best you're gonna get scammed

#

and no one is gonna take pity on you for free

#

"just pay for a reverse search" then do it yourself

#

you're all concerned and shit - do it yourself ¯_(ツ)_/¯

solid python
#

I suggest you read #rules and #welcome to understand what this server is.

sacred laurel
#

Hi folks, anyone have tried solutions feature in academy? looks like annual subscribers can access to this feature which provides step-by-step solutions for all questions.