#modules

1 messages · Page 252 of 1

fathom pendant
#

If you have extra spaces it says it's wrong

quasi wave
#

hi I need some help with figuring out the Nessus Vulnerability Assessment section. I'm looking for an SMB share but the scanning the server doesn't get me an SMB share. What am I doing wrong with the scan?

heavy marsh
#

cURL command in the Web Attacks Bypassing Basic Authentication section is not showing "Allow: ..." section for the headers.

shut quest
heavy marsh
#

This is what the module shows

quasi wave
#

this is for the vulnerability assessment module

heavy marsh
#

This is what I get

woven stone
#

That was the mistake thx

fathom pendant
heavy marsh
#

Looks like the allow is the only portion not showing

#

This is my command:

curl -i -X OPTIONS http://SERVER_IP:PORT/

cloud urchin
#

i think i ran into that same thing and just fuzzed the options with burp intruder

shut quest
quasi wave
fathom pendant
#

The target [10.129.x.x] doesn't have smb running, its simply hosting the nessus (or openVAS) service

quasi wave
#

ok

#

so where do I find the preloaded scan I don't see it?

#

There’s no preloaded scan

fathom pendant
#

It should be

#

By preloaded I just mean it's an already done

#

So you don't gotta wait the 40+ minutes for it to go

quasi wave
#

I don't see a scan that I didn't do myself

#

like they didn't put a scan on there that was already done

shut quest
#

It's been a while, but the report is there. Is there maybe a filter?

fathom pendant
rustic sage
#

I figured it out! Thank you and @cloud urchin. Much appreciated.

fierce mason
#

for the last question on the acl primer for ad enum and attacks, is there supposed to be multiple answers to the question?

fierce mason
#

the answer that the section gives is different to the answer that i gave, but i still got it right

mellow holly
#

maybe HTB can look into it ¯_(ツ)_/¯

quasi wave
#

got it

stark knoll
#

Has anyone completed the Bloodhound AD module?

cloud urchin
#

best to just ask your question

rustic sage
#

Hello

stark knoll
#

I was able to figure it out. Thanks!

#

actually...

#

This is the question.

#

How is DC01 not the right answer?

fathom pendant
gray merlin
stark knoll
#

Tried it. Upper case, lower case, camelCase.

rustic sage
#

hey

stark knoll
#

Ran the analysis three different times.

fathom pendant
#

But also it would be odd if it was just one computer that had one admin

strange forge
#

in the drupal attack section in attacking common applications. not able to find option to add own module. tried `Once downloaded go to Administration > Reports > Available updates.

Note: Location may differ based on the Drupal version and may be under the Extend menu.`

gray merlin
stark knoll
#

Thanks. Running collection again.

rustic sage
#

GUYS IS THERE IS ANYONE HAS COMPLETED THE CRACKPASSWORDS USING CATHASH??

#

MOUDULE

cloud urchin
#

i would wager yes

rustic sage
#

DID U COMPLETED IT??

cloud urchin
#

no

rustic sage
#

KK

ocean night
#

Dude, capslock

#

😛

cloud urchin
#

how do i get the beard role

rustic sage
rustic sage
ocean night
#

Can you just stop with the all caps, but ok, what's the question?

rustic sage
#

kk

rustic sage
ocean night
fathom pendant
strange forge
rustic sage
strange forge
#

this available updates option in drupal

fathom pendant
buoyant void
#

Got a bit of a general question regarding the reporting and documentation module. In a professional setting I can see the benefit of using a tool like WriteHat or GhostWriter and I've been playing around with some local instances of these tools. The biggest benefit seems to be the ability to have a database of findings that you can quickly import into your final report, but it seems that you have to populate that database manually. Is that really what people do, just manually populate hundreds of findings into these databases? Or is there some publicly available database of findings out there that can be used with all the relevant information (CVSS score, description, remediation etc.)

fathom pendant
#

They generally write their findings as they find them

fathom pendant
#

They don't just wait until the end to update it

fathom pendant
rustic sage
buoyant void
strange forge
#

okey

fathom pendant
#

Anyway @rustic sage what's your q about the hashcat module

rustic sage
#

is there anyone completed the craking passwords using hacshcat

fathom pendant
#

Yes but is there more to the question?

#

Like. The broad answer is yes

rustic sage
#

ya

#

kk

fathom pendant
#

What is your actual question about the module then

#

Like are you having trouble with a specific section? Need clarity on something?

rustic sage
#

i didnt compete it bc was complex so am asking who has completed the module

#

complete

gray merlin
rustic sage
#

nice kk

#

BTW WHY WE CANT SEND MESSAGES IN GENERAL CHAT??/ban

rustic sage
#

KK

#

tnx

upper ruin
#

I repoRts diz to ceo of HakDaBooks!

#

How dare you read the modules >:CCCC

rustic sage
dim wolf
#

uh,

ocean night
meager dirge
#

Hi

ocean night
coarse gulch
#

Why does it say everything I need is in the reflective injection folder😀

#

Thanks bro I appreciate you. Honestly that makes me happy because I know there was no way I was messing up filtering for ID 7😂

#

Ahhh the duality of man

dim wolf
#

everything you need is there in that folder

strange forge
#

backdoor is getting uploaded but it is not able to get the session

coarse gulch
#

Am I trippin

#

Yes

dim wolf
#

that's it

coarse gulch
#

I used certutil on it and it gave me a different hash than the answer

#

Wild lmaooo

#

I’m thankful for you. It would have bothered me for quite sometime

cloud urchin
#

Are you talking about the Attacking Common Applications - Tomcat section?

coarse gulch
#

Yes

#

The bot banned my message

#

Thanks again though @dim wolf

fathom pendant
#

Because it treats it as spam

#

And you're unverified

strange forge
fathom pendant
strange forge
#

my message got deleted too

fathom pendant
#

It's following the instructions in #welcome

ocean night
#

👋

fathom pendant
#

Your message was likely deleted due to spoilers

ocean night
#

Spoilers for a module over Tier 0

fathom pendant
ocean night
#

Come on man

cloud urchin
#

i mean if he deletes it you probably shouldn't post it again

strange forge
cloud urchin
strange forge
#

in the attacking common app module. in the tomcat section. using metasploit tomcat_mgr_upload is producing below error " failed to execute the payloadand no session was created"

#

please dont this time

woven stone
#

I only have one question left و I need help

#

I feel like I haven't been able to understand everything. I feel like I'm wasting time

fathom pendant
#

I believe if you do type(variable) it tells you the type

cloud urchin
strange forge
cloud urchin
#

ahh ok nm then

#

metasploti sucks

strange forge
#

The multi/http/tomcat_mgr_upload Metasploit module can be used to automate the process shown above, but we'll leave this as an exercise for the reader.

fathom pendant
#

Well, that's a bunch of messing around you'll have to do

#

To get the right settings and such

woven stone
strange forge
#

ohh it requires admin credentials. wont work with manager onr

fathom pendant
woven stone
fathom pendant
#

Again

#

Try either whats just in the quotes, or without the angled brackets

#

Try multiple different things instead of just one and immediately giving up

woven stone
fathom pendant
#

"Not work" isn't descriptive

#

Also yes it's a set, as it's a list of items

dim wolf
#

if it's better, you can translate the page into your primary language

woven stone
fathom pendant
#

Also taking a look the answer should accept <class 'type'>

fathom pendant
woven stone
fathom pendant
#

¯_(ツ)_/¯

#

The answer works for me

#

Idk why it's not working for you

fathom pendant
stark knoll
#

I've tried every combination. Doing a bit of research, seems like this is a "problem" question.

fathom pendant
#

Weird it'd be a clean 10%

#

So something seems off there with your math

stark knoll
#

yeah, that was the last of maybe a 100 educated guesses.

ocean night
#

Just say thanks, no need to post a screenshot of answers. Well done.

woven stone
stark knoll
#

Am I the only one that feels some of the module questions are "gotchas"? It's also frustrating that you can't get through the module without 100% of the question completed.

#

Is there help anywhere else? I've tried the forum and most seem stumped by the same question. The ones that got it admit it was guessing.

cloud urchin
#

overall not really. i like how they put a twist on the concepts to make sure you understand the content. one thing that you may think is a gotcha may be easy for someone else, and vice versa.

stark knoll
#

@cloud urchin you're saying "overall not really" to any other help?

cloud urchin
#

i'm saying overall i don't really feel the modules have gotchas

stark knoll
#

got it.

cloud urchin
#

the help part, i used discord and got help here

#

sometimes the forums had a good hint

stark knoll
#

I'll repost the question as it looks like my screenshot was removed.

#

Looking for help on the final question of the Active Directory Bloodhound module:

Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Submit the number as your answer (to two decimal points, i.e., 11.78).
fathom pendant
#

If it was removed it's likely because it contains some form of spoiler

stark knoll
#

BloodHound question: When wanting to see all values of a particular category (User, Group, Computer, etc) are the results limited to just 10?

next bronze
#

some default queries return only 10 yeah, at leat for the legacy version

#

use that to calculate for the last question in the module

stark knoll
#

how can I get more nodes from a query?

next bronze
#

check the raw query at the bottom

#

it's usually set by the n variable

stark knoll
#

I'm using 4.3.1, the raw query isn't being populated.

rustic sage
#

I finally got through the phishing section of the XSS module!

#

pwnbox was messing with me so i used a different machine to listen from and it worked perfect

#

on the bright side I really really understand it now after spending all damn day working on it

cloud urchin
#

that's what it's all about

rustic sage
#

@wintry skiff were you able to get through the phishing section of XSS? I just got the flag if you still need help

solar grove
#

Hi im stuck
INFORMATION GATHERING - WEB EDITION
Submit the number of all "A" records from all zones as the answer.

solar grove
#

@strange forgeI tried all zone transfers but I counted 19 A records

fathom pendant
#

There's 2 zones

#

Inlanefreight.htb and {subdomain}.Inlanefreight.htb

solar grove
#

@fathom pendantYes, I found it inter***.Inlanefreight.htb
I counted the sum but I don't get the result

fathom pendant
#

Add the 2 together

strange forge
fathom pendant
#

I'm not staff

solar grove
#

@fathom pendantWhat do you mean

fathom pendant
#

If you're having issues, change vpn regions

strange forge
fathom pendant
strange forge
#

okies

#

btw target ip also depends upon vpn? iam not able to get the target ip even.

solar grove
#

@fathom pendant ty bro

strange forge
#

it keeps ongoing target is spawning

tender vine
#

Does anyone know if we will continue to have access to the step-by-step solutions to modules we've already finished once our annual subscription ends?

fathom pendant
#

nope

#

once sub ends all perks associated with the sub also end

tender vine
last quarry
#

Hi guys I have a problem with the module Hunting for Stuxbot

With the mimikatz question, when I enter arguments behind it's said that it's false but I don't understand why, arguments seems correct 😅

#

Okay nevermind my fault

bold sinew
#

Hiya.

Having an issue with the module in the title. I am tasked with examining a target and finding out the password of user "Will" and submitting it.

The password hint states Sometimes, we will not have any initial credentials available, and as the last step, we will need to bruteforce the credentials to available services to get access. From other hosts on the network, our colleagues were able to identify the user "Kira", who in most cases had SSH access to other systems with the password "LoveYou1". We have already provided a prepared list of passwords in the "Resources" section for simplicity's purpose.

Using the password list provided in the module with the name Kira using Hydra to crack does not yield any valid username password combinations.

Using the full username list provided in the module results the crack taking 7 hours with Hydra and the spawned target ends up timing out and despawning before it completes.

Im not sure what im missing here. Am I on the right track or is there something im missing?

fathom pendant
#

Kira != kira if the system is linux

bold sinew
#

Im gonna feel really silly if that was my issue this entire time lmfao

fathom pendant
#

it is

bold sinew
fathom pendant
#

if you haven't already, i also suggest using -t 48 in hydra

burnt shore
bold sinew
#

Yeah been using that

fathom pendant
burnt shore
bold sinew
#

Bros just helpful

fathom pendant
#

literally just woke up

feral sapphire
# fathom pendant literally just woke up

Do you live here ? I guess when, consciousness will be digitalised and we dont have to take care of biology we coud stay up in our favourite subjects for ever )

stuck fable
#

Hi all, I am in the module "Shells and Payloads," in the section "The Live Engagement" at target number 2. I found the exploit to use: php/webapps/50064.rb, but I can't find it in msfconsole using the search command. I then tried the use command with the path: use usr/share/exploitdb/exploits/php/webapps/50064.rb, but it doesn't work. any hint?

cloud urchin
#

did you try use exploit/php/webapps/50064

stuck fable
stuck fable
fathom pendant
stuck fable
#

I manage to finish target 2, tx to your help guy ty. and yes use 50064.rb work ty very much

maiden glen
#

can someone help me with zephyr, give some tips on initial foothold?

fathom pendant
maiden glen
#

okay sorry!

bold sinew
bold sinew
#

👍

fathom pendant
#

And it still was part of it

bold sinew
#

i'll give that a go

fathom pendant
#

In general you'll use the mutated wordlist throughout this module

bold sinew
#

Aight, lets see how this goes

fathom pendant
silk dagger
#

Hi everyone... i'm stuck in
"Signatur Exclusion Attack"

Every time when I change the value of htb-stdnt to:
<saml:AttributeValue xsi:type="xs:string">admin</saml:AttributeValue>

I'm getting this error:
<b>Warning</b>: DOMDocument::loadXML(): Start tag expected, '<' not found in Entity, line: 1 in <b>/var/www/sp/vendor/onelogin/php-saml/src/Saml2/Utils.php</b> on line <b>87</b><br />
Something went wrong.

Even by just changing one single attribute value. How could a '<' vanish in the process? Any ideas?

rustic sage
#

how can i view only 200 ok responses when brute forcing a login using burp intruder

fathom pendant
#

filter by only 200

#

I forget exactly the steps to filter

rustic sage
#

yeah i found it

#

thanks by the way

bold sinew
#

Is there a way I can force the lab to stay there for longer?

fathom pendant
#

at most should be ~30 min

bold sinew
#

exact command you're using gives me this

#

im using the pwnbox for reference

fathom pendant
#

just be patient

tough tiger
#

<@&861185840277487616>

bold sinew
#

Im using the mutated password list using the provided custom file

#

Is that the wrong password list?

dreamy yew
#

Module: Windows Privilege Escalation, Question: Leverage membership in the DnsAdmins group to escalate privileges. Submit the contents of the flag located at c:\Users\Administrator\Desktop\DnsAdmins\flag.txt. Problem faced: I have injected the adduser.dll, however the netadm wasnt added to "Domain Users", and some have suggested to log out and log in again, but the changes were not reflected.

mellow holly
#

did you stop/start dns service?

dreamy yew
#

do i have to do that before i log out and log in again? :0

mellow holly
#

after you inject it. Do it after you use the dnscmd.exe

#

you shouldn't have to log out for this to take affect, but if others say so

#

¯_(ツ)_/¯

dreamy yew
#

I did whatever was mentioned in the module, but netadm user wasnt added to "Domain Admins"

#

@mellow holly any idea why it didnt work

mellow holly
#

sc query dns after each command

#

check to see if it actually started or stop

#

also mmay want to post your payload

dreamy yew
#

this was the payload ```
msfvenom -p windows/x64/exec cmd='net group "domain admins" netadm /add /domain' -f dll -o adduser.dll

#

@mellow holly I sc query dns, but nothing was printed on the terminal as well

mellow holly
#

???

#

hmm, do it from CLI

#

not Powershell

dreamy yew
# mellow holly not Powershell

Yep it works on cmd, however though my user netadm was added to Domain Groups, I was denied access to C:\Users\Administrator, might need a nudge

mellow holly
#

Domain Groups?

dreamy yew
#

sorry "Domain Admins"

mellow holly
#

not sure how you got that

#

ok, then you should be able to get the flag

#

you have what you need

dreamy yew
#

hmm thats weird then, why am i still denied access

mellow holly
#

dont try to access it from the same command window

sly nebula
#

Are you attacking a DC or a regular domain-joined machine? Certificate templates are different.

dreamy yew
wanton idol
#

and log in as that user

mellow holly
#

you need to start a new session, it doesnt extend to your existing session

dreamy yew
dreamy yew
mellow holly
#

you can do that, or do runas

#

or do it from your attack box

#

you have multiple options here

wanton idol
#

even evilwin-rm

mellow holly
#

the point is, dont get stuck into thinking you have to stay in your existing session to leverage your new privilege.

dreamy yew
#

@wanton idol @mellow holly thanks for the hint, i have learnt some lessons from this

valid viper
#

Anyone else having trouble with the VPN?

#

It says I'm connected but I can't ping boxes.

fervent relic
#

Hi can anyone help me in the SSI injection lab

last quarry
#

Am I the only one ?

sly nebula
#

Anyone on the last question of the ADCS attacks skills assessment? I can't seem to approve a failed certificate request. I'll share briefly what I have tried so far.

valid viper
last quarry
mellow holly
#

Was able to spawn academy box and pwnbox just now, FYI

burnt oasis
#

hey hope everyone is having good day!! Could use some help with the footprinting module for dns. The Last question asks "What is the FQDN of the host where the last octet ends with "x.x.x.203"? After running dig axfr inlanefreight.htb (ip) i found the different domains and checked the domains from the output using dig axfr. When ever I then try to uses dnsenum I get the following error, I even checked and made sure my seclist waas updated and did that. Is this a error because the domains cant be brute forced or because a error is preventing it from even attempting to brute force?

acoustic owl
burnt oasis
#

@acoustic owl

acoustic owl
tame urchin
#

when doiing netstat -ano in dual home machine(has more than one nic)
TCP 10.129.43.8:139 0.0.0.0:0 LISTENING 4 means port 139 is available for one nic where
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING 4 means port 47001 is available for both nics

#

am i right?

burnt oasis
#

@acoustic owl thank you for that, I changed to source from opt to "usr" but Im still receiving the same error

acoustic owl
fathom pendant
burnt oasis
glass quail
#

Module: File inclusion
Section: Basic Bypass
Can someone help me with what filter I need to bypass in /index.php?language=languages/en.php I found out that I can put anything after languages but nothing before it I have tried encoding multiple and putting other things beside the ./

cedar yew
#

Hello guys,

Active Directory module - Kerberos sectiyon

İ use the cred for htb student but not working how to fix it

im use forend acoount sqldev account not working

twin lion
#

anybody else having problems with connection? i will start a target instance and after interacting with it (icmp request, ssh) after maybe a min it will stop.
i did killall openvpn, changed server, reset and it never worked
switching to eu made it a bit better, but still very wonky and not working at least remotely smooth (laggy ssh session, but stable)

#

could it be this? I am est so idk

glass quail
#

all good here

twin lion
#

hmm i will reset my machine, 1 day uptime which isn't usual for it

glass quail
#

thanks

daring totem
#

find through an SPL search against all data the other process that dumped lsass. Enter its name as your answer. Answer format: _.exe

#

anybody able to give any hints or tips, currently trying to solve this problem, any help is appreciated

dim wolf
daring totem
#

thank you!

twin lion
#

i was running openvpn in tmux but i've reset now running in a normal terminal window

#

nvm , am good

glass quail
#

Got it I thought I need to do something more was overthinking it

#

thanks supernuts

tight hedge
cloud urchin
#

are you connected to that subnet?

tight hedge
#

Can someone please give a hand with this one, I just don't understand. Should I install anything?

#

i'm connected, but it said that cannot find dementor.oy

cloud urchin
#

yeah it can't connect, address not valid. you're not preceeding your command with proxychains, how are you piping that to the ip's?

tight hedge
#

ok hold on a sec

#

this is the real problem

cloud urchin
#

if it's in your folder just type python3 dementor.py ...

#

don't include the ./

#

also make sure you're connected to that network

tight hedge
cloud urchin
#

i'm pretty sure they give the link in the module

tight hedge
#

I got it, but shows this now

cloud urchin
#

yep, again looks like you're not connected to that subnet

#

you'll need to pivot/tunnel

tight hedge
#

yeah it just expired a min ago ill connect again and try

tight hedge
#

ok, i'm confused. I got three ip in the example:
-172.16.18.4 this one is for the impacket-ntlmrelayx
then I got other 2:
-172.16.18.20 and 172.16.18.3 these ones are used with dementor.py
My question is, should I change one of these ip for the one that im connected to, in this case 10.129.15.151?

tight hedge
#

I feel so dumb.... Sorry. I was making the connection from my own kali and never rdp on the provided one xD. that's why, I wasnt connected. thanks for the help

dull thunder
#

im working on the documenting and reporting module and the sample report zip file is password protected. did i miss something? i tried cracking it with johntheripper but no luck.

wanton idol
#

We've included a sample Obsidian notebook and a sample Internal Penetration Test report (in both MS Word and PDF formats - zip password hackthebox) that can be downloaded from the Resources tab in the top right of this or any other module section. These are great supplementary resources to keep for yourselves but also helpful to have on hand while working through the content.```
idle kestrel
#

Anyone available for help on the exercise section of HTTPS/TLS Downgrade attacks? I'm fairly certain I have the right answer, but I don't know what format it wants it in.

dull thunder
spark spruce
#

hey guys
why I am getting this error

fathom pendant
#

timed out
likely unstable connection

cloud urchin
short hare
#

I don't know where to ask this but
Just creating an account in (ISC)² = Being a member of (ISC)² ???
Also is there any fee for being a member if I don't take any of their certifications?

I visited their website and still not getting answers to the above questions

cloud urchin
#

try reaching out to their support

next bronze
#

isc2 is for their certs and stuff, CISSP most noteably, you'll need a certain amount of points per year to keep the certs that's why academy has that option, the membership is $50 a year. if you don't have/want their certs there's not really a reason to be a member

spark spruce
#

does anyone knows
how long will it take to brute force the password for sam

little bear
#

Interesting little trick at the end of Attacking Enterprise Modules with Double Pivot. I have genuinely appreciated (and currently) the entire CPTS path.

little bear
#

Also, depends on which tool you decide to use.

spark spruce
little bear
#

DM me 🤝

fathom pendant
#

it will take far longer to attack ssh than other services

spark spruce
fathom pendant
#

if it's open, sure

#

also you can use more threads with hydra

#

-t n

#

48 is the most stable

spark spruce
#

so it means
account credentials are same for ssh and ftp?

fathom pendant
#

tip: whenever you achieve credentials for a service, always check for reuse

fathom pendant
#

default is to use the account's existing password for other services unless otherwise specified

spark spruce
#

do you know esteemeted time to brute force
bcoz its taking longer

fathom pendant
#

~20-30 minutes on average

#

Patience is a virtue for this module

spark spruce
fathom pendant
#

Some questions don't

#

¯_(ツ)_/¯

#

Overall you'll receive 20% of the cubes spent

fathom pendant
#

Your focus shouldn't be on the cube reward tbh

#

Just learning tools

spark spruce
stuck pier
#

Any help on this skill assessment of windows event log By examining the logs located in the "C:\Logs\Dump" directory, determine the process that performed an LSASS dump.

stuck pier
last quarry
#

Hi, I currently have a problem on the CDSA module called "using splunk applications"

The splunk base website loading without no end, someone find a way to do it differently ?

fathom pendant
#

https?

zenith mango
#

hi guys, i need help. i am stuck at command injection skill assessment.

north bramble
next bronze
#

add the port in the url

north bramble
north bramble
next bronze
#

http

north bramble
#

meanwhile it works if I just copy past <IP>:<PORT>

fathom pendant
north bramble
# next bronze http

ah it worked.

I tried this yesterday and it worked till here, but there were too many errors on ffuf. Ima run ffuf again. I will see if there are any more issues. Thanks for your help

fathom pendant
#

these targets are running http

next bronze
wooden trail
#

Hi guys, no intention on interrupting you but, do you have any info regarding Attack Passwords Skill Assessment easy? Running bruteforce over FTP using given usernames and password lists (haven’t done mutations as that would be insanely large) but not success yet. Am I skipping something? (im hating the bruteforcing along this module🤮, should’ve been wordlists with 10 o 20 passwords, not 200)

fathom pendant
north bramble
fathom pendant
#

using 48 threads should get you the next part

north bramble
fathom pendant
#

the issue is likely you're getting a bunch of "does not exist" errors

#

aka not a 400/404

north bramble
fathom pendant
#

oh that's a whole separate issue

north bramble
#

all errors?

fathom pendant
#

that sounds like something is going on on your end

wooden trail
fathom pendant
fathom pendant
#

yeah that'll severely limit

north bramble
fathom pendant
#

switch to bridged

#

it's likely that since nat is using host adapter and AP, it's getting hit with your host's firewall rules

north bramble
fathom pendant
#

weird

wooden trail
north bramble
fathom pendant
#

switching to bridged worked for me --> ~400 req/s

north bramble
fathom pendant
#

what's likely happening is there's some weird thing going on with your adapter or router that's causing this to happen

#

what's your ffuf command?

north bramble
north bramble
fathom pendant
#

is academy.htb in your /etc/hosts?

north bramble
fathom pendant
#

i see admin.academy.htb in yoru earlier output... but is just the base academy.htb

north bramble
fathom pendant
#

:)

#

the errors are likely DNS errors

north bramble
#

Thanks @fathom pendant

fathom pendant
#

i just happened to think about your /etc/hosts screenshot kek

rustic sage
#

Why can't I ask in general?

woven stone
rustic sage
fathom pendant
#

there's instructions on how to link your htb labs account to the discord

rustic sage
rustic sage
fathom pendant
#

lol no

#

staff have a lime green colored name

#

staff that aren't also mods have Green cube next to their name

woven stone
rustic sage
rustic sage
fathom pendant
#

mods and admins have a neat shield next to their name

woven stone
fathom pendant
#

no

#

see the above rules :P i neither work for HTB nor am an admin

#

I just live here

rustic sage
#

Can you help me how to find ...

#

your Account Identifie

woven stone
fathom pendant
rustic sage
fathom pendant
#

because you need to be signed into your lab account to access it :P

#

that link works for me on my account

#

¯_(ツ)_/¯

rustic sage
#

Invalid account identifier ???

rustic sage
fathom pendant
woven stone
fathom pendant
rustic sage
next bronze
#

wat

fathom pendant
next bronze
#

please don't sent randos on the internet your email and pass

fathom pendant
#

you should never share your username and password with anyone, ever

next bronze
#

even staff won't ask you to do that

woven stone
fathom pendant
#

☠️

woven stone
#

I think she likes me😂😂

fathom pendant
#

this is why cybersecurity is an important field

#

and security awareness is important

#

@rustic sage i highly suggest you delete that login info from your DMs with them

fathom pendant
woven stone
#

She knows I'm good

fathom pendant
#

sharing login info is still highly irresponsible

fathom pendant
next bronze
#

I hope this is a joke ICANT

rustic sage
fathom pendant
#

while they may not have malicious intent, it's still not good security practice to share login details

#

ever

woven stone
fathom pendant
#

it's why policies in businesses is to do a password reset. Not ask for login info

#

@rustic sage since it's resolved I also suggest changing your password

#

as a "just in case" policy

#

:P

woven stone
#

And She changed the password

fathom pendant
#

brother did you actually log into her account?

#

☠️

woven stone
fathom pendant
#

omfl

#

i would have guided without logging in

#

as that would have been the more responsible thing to do

woven stone
#

I'm kidding, I didn't log into her accounts

#

I took a screenshot and explained to her how

fathom pendant
#

sure i'll believe you

#

¯_(ツ)_/¯

#

anyway it's resolved now

rustic sage
#

and he said you should learn Python at first.

#

Is that true??

fathom pendant
#

it depends

#

python is a fairly easy to learn programming language but it isn't required depending on what you wanna do ¯_(ツ)_/¯

rustic sage
fathom pendant
#

but if you're interested in penetration testing stuff as found on HTB academy; then python isn't really as necessary

#

if you're looking into doing bug bounties tools can be made quickly in python to automate simple tasks

rustic sage
fathom pendant
#

i don't really watch coding content or anything like that on YT ¯_(ツ)_/¯

woven stone
fathom pendant
#

we're getting off-topic for the channel you can look in #programming for any sort of tips or stuff that other people have found and shared

woven stone
rustic sage
fathom pendant
#

if you wanna sign up for HTB academy to look into some of their learning options, that's also helpful (be aware it's a bunch of reading). They also have a beginner bug bounty cert

sullen zenith
#

Hey guys, newbie here..

rustic sage
fathom pendant
#

yes

#

1260 is for the gold annual

#

there's cheaper options

north bramble
north bramble
sullen zenith
fathom pendant
rustic sage
fathom pendant
#

the discount is a monthly sub of $8 and includes all modules up to and including tier 2

north bramble
fathom pendant
#

so you'd have to still purchase an exam voucher separately

fathom pendant
#

some of them are fairly easy, comparatively, if you know some of the underlying concepts ¯_(ツ)_/¯

north bramble
fathom pendant
#

do skill paths then

#

build up skills, the job role paths also build up basic skills

#

and it's recommended to do those paths in order ¯_(ツ)_/¯

#

as they build off each other mostly

#

i.e footprinting before attacking common services teaches you how to 1 sniff them out and test for basic misconfigurations

#

like anonymous logins for ftp or NULL/Guest sessions for SMB

rustic sage
fathom pendant
#

there's no "free trial" so to speak

rustic sage
fathom pendant
#

I also suggest setting up a VM to work off of

#

it's just overall best practice to work off a VM

hollow knoll
#

Hello I am kinda stuck on this question for quite a while "Investigate the USN Journal located at "C:\Users\johndoe\Desktop\kapefiles\ntfs%5C%5C.%5CC%3A$Extend$UsnJrnl%3A$J" to determine how "advanced_ip_scanner.exe" was introduced to the compromised system. Enter the name of the associated process as your answer. Answer format: _.exe" if anyone could provide some hints that'll great

sterile hinge
#

OMG.. getting pretty annoyed with the instability of the pivot and target systems in RDP and SOCKS Tunneling with SocksOverRDP. I get all the way to logging in as jason on the target system and before the desktop loads it times out. I tried to kill and re-initiate the RDP session to the pivot host and now I can't even connect to it. This is my 3rd attempt after resetting the targets.

fathom pendant
#

use the tcp vpn download

#

it facilitates the multi-pivoting better than UDP

sterile hinge
#

nice, ok

#

Although.. the issue is from the foothold host to the other hosts, so I'm not sure how my vpn connection factors in?

fathom pendant
#

Maybe in the remote desktop settings switch to modem as shown in the section

sterile hinge
#

I have been doing that

#

Finally! got it 🙂

warm kernel
#

anyone able to give me a hand/insight? Im trying to get php wrappers to work, but / and = are caught as malicious and dual url encoding gets it through, but never renders anything on the page

fathom pendant
#

If it's not related to academy then maybe #web would be better

warm kernel
#

ah ok thanks, ill take it there

tepid notch
#

Hello can anybody give me a hint, I am on Attacking Common Services > Attacking FTP. I managed to find the right FTP port and have already got the username r..., I was not able to get the passwords.list file from the FTP . I have tried with my normal kali user and the root user, but the file just doesn`t download (stuck like in the screenshot). From the comments I found I need this file to brute force the login with medusa. What am I doing wrong? ^^

fathom pendant
#

You don't need to be root to connect, as you're just logging in as anonymous anyway
It seems like a connection issue

#

Try changing vpn region and respawning target

tepid notch
#

Strange I was able to nmap and connect without issues, could also download the users.list, just not the passwords.list

limber river
fathom pendant
#

¯_(ツ)_/¯

tepid notch
#

I will try to reset the target and change my VPN region if this is not working, thank you!

charred gust
#

I'm looking for some guidance on how to get past SSL_ERROR_RX_RECORD_TOO_LONG when trying to get the sites in the tests at the end of modules. All the docs I'm finding say it's a server-side issue.

next bronze
#

have you tried using http?

tepid notch
charred gust
#

I have, but then I get connection timed out.

next bronze
#

is there a port you need to use?

charred gust
#

Yeah, I did account for that.

next bronze
#

what module and section?

pseudo birch
#

I need some direction for Windows Privilege Escalation Skills Assessment 1. I'm attempting to run JuicyPotato.exe on the target using nc.exe binary. I've been through almost all of the CLSID.list (system only) after running GetCLSID.ps1. Yet, I dont receieve any output or error when running the JuicyPotato.exe command. I've seen in some examples that they get a "Testing {Enter CLSID here}" but I dont receive that. I've also run Set-ExecutionPolicy bypass -Scope process. I can provide screenshots if need be.

charred gust
fathom pendant
#

but i could be mistaken in how it works

pseudo birch
#

Import-Module GetCLSID.ps1 ?

fathom pendant
#

ye

#

but iirc there's other tools that take advantage of a similar thing

pseudo birch
#

I was just running it. I'll try and import

fathom pendant
#

a lot of .ps1 scripts are just import-modules

#

if JuicyPotato doesn't work maybe PrintSpoofer might

#

¯_(ツ)_/¯

little bear
pseudo birch
#

I have more success with PrintSpoofer tbh. However, I need to get more comfortable with JuicyPotato. I'll reset target and try again! Thanks!

tired pasture
#

Can anyone help me with a phishing email I keep getting it's so confusing

fathom pendant
tired pasture
#

Ah apologies it isn't

fathom pendant
#

we don't help with any phishing emails or such

tired pasture
#

No problem

fathom pendant
#

you can keep it to yourself for posterity if it's horrendously bad grammar

#

those are always fun

tired pasture
#

It's just the series of events seem very strange but I won't divulge if it's against the rules 🙂

fathom pendant
#

this wouldn't be the place to really discuss it anyway

#

as this channel is for academy modules

tired pasture
#

No problem

fathom pendant
#

you can read and follow #welcome and maybe there's a channel that may be more apt

tired pasture
#

Okay thanks

fathom pendant
#

just be mindful of not sharing personal details such as email

little bear
# pseudo birch I was just running it. I'll try and import

I believe your issue might be surrounding CSLIDs and the system itself. If you look as the powershell script, you can sort of glean what the logic is attempting to do. My theory is that if it isn't a Valid CSLID, or the script isn't working, then you could try to adjust the script in the Parrot OS on the target box, or, try a different CSLID. Hopefully this helps with JuicyPotato. ;D Also, PrintSpoofer is also nice for LPE if available as Marcie pointed out.

#

Also, dont forget syntax

pseudo birch
fathom pendant
#

sounds like it

#

sounds like your shell isn't sending error to terminal

pseudo birch
#

exactly. Back to square one! Thanks everyone. I'll grind it out

little bear
#

DM me how/when you figured it out! Would love to know how you got it!

next bronze
# charred gust XPath - Authentication Bypass

I don't have the module unlocked but I doubt it's an issue with the module. doesn't sound right that there's an SSL error on https and times out on http, so is there a response or not?

#

make sure the url parameters are correct

charred gust
regal cliff
#

Im in the Broken Ath module, cbbh path, so im stuck in the default credentials, section, looking for scada dafult passwords, but none works, what should i do?

fathom pendant
#

one set should should work; just gotta dig around a bit for default passwords

fathom pendant
#

look for all the keywords on the page

#

not just SCADA and HMI

regal cliff
#

Just to confirm, i'm ins scada-pass.csv, im i good?

regal cliff
fathom pendant
#

ah

#

idk if the seclist one is the same

#

but keywords on the page may help

#

such as company name

#

iirc it might also be in the Title of the webpage

regal cliff
regal cliff
fathom pendant
exotic mango
#

Guys, i don't see explanation on pwnbox usage/access by premium plan or other subscription ...

#

I'm platinium at the moment

regal cliff
exotic mango
#

I know but where is it to access it

fathom pendant
exotic mango
#

on the web page ...

fathom pendant
#

when you open a module there's usually either at the side/towards the bottom the "spawn instance" button

exotic mango
#

ah alright

#

I thought it was like HTB VIP

#

thanks

fathom pendant
#

the spawn is only accessible within a module

#

the other annoying thing is it resizing whenever you go to the next page

#

which there is no way around that

#

as it draws it's size from the most recently loaded window/portal

gaunt roost
#

Hello, I hope you are well. Please I need help to do pivoting with ssh combined with proxychains. I'm currently following HTB's “Pivoting, Tunneling, and Port Forwarding” module. I just installed proxychains and not proxychains4. When I do dynamic port forwarding (ssh -D 9050 username@external_ip) and use proxychains to scan an internal network address (proxychains nmap internal-ip) I always get this error until the end: |S-chain|-<>-127.0.0.1:9050-<--timeout
|S-chain|-<>-127.0.0.1:9050-<--timeout

cloud urchin
#

if you 'just installed' proxychains then it may be using the proxychains4.conf. on my kali box it uses proxychains4.conf i believe. if that isn't it, double check to ensure you're selecting the correct type of proxy

cunning cape
#

hey, having problems with Attacking active directory and NTDS.dit module in the password attacks module. so I'm having problems running crackmapexec, I've done this a few times now in other modules with no problems. when I run the command I am not getting any output. I did once get it and it was coming back but can't mind was it said. is there a way for crackmapexec to display logs of what it is doing so I can troubleshoot and see where it is failing. image for reference:

gaunt roost
next bronze
cunning cape
cloud urchin
regal cliff
fathom pendant
#

it's bad opsec to be running around your system as root; very easy to accidentally break something

cunning cape
high reef
#

Anyone having issues with academy ?

cunning cape
#

gonna try a fresh machine and reboot vm, see if that changes anything

fathom pendant
#

make sure you're still connected to the vpn

high reef
#

i'm using EU VPN and i keep getting booted out my RDP session and i can't run commands becasuee its so slow

pseudo birch
fathom pendant
#

¯_(ツ)_/¯

#

i don't generally use msfconsole multi

#

i'd say make sure the payload is set right

pseudo birch
#

I dont either but I tried it as another option. The reverse shell is coming from a command injection. Even after loading a payload. I still can't execute it. So, I'm a little confused there

spark spruce
#

guys pls help here

cloud urchin
cloud urchin
cunning cape
#

rebooted VM, rebooted machine, running as regular user, can ping machine, ifconfig showing tun0 for VPN connection. is there not a way to do verbose to see where it is reaching in the process? might just have to try on the pwnbox instead of VM

gaunt roost
high reef
cloud urchin
# gaunt roost no i delete it before installing proxy

Well I don't know about your setup but that could be the issue. I have the latest version of proxychains on my kali box and it uses proxychains4.conf. maybe restore that and try it with that, your ssh command looked right for dynamic port forwarding so as long as proxychains is setup correctly it will work. you didn't show your /etc/proxychains.conf but from your description 'it is setup properly'. maybe reboot the victim box.

high reef
cloud urchin
# high reef

that wmic command needs to be ran in cmd, not powershell

cunning cape
fathom pendant
little bear
# gaunt roost no i delete it before installing proxy

Your command looks off to me. Technically by default you can use 9050 as the port to dynamically proxy into/out of; so your ssh syntax looks fine as long as you a) know the password b) the next best thing to a password. What I see that looks off is the command for the nmap scan. Try using the IP address specifically. No Port Number.

(You may dm me a screenshot of your command output.)

cloud urchin
fathom pendant
#

ah

#

yeah weird stuff

cloud urchin
#

i'm not really sure, but that's my guess based on his screenshot plus the info from the module saying to run it in cmd

fathom pendant
#

yeah

high reef
#

why can't i access the admin desktop ?

little bear
#

check privs

cloud urchin
#

i've retrieved the sid before a bunch with powerview

#

i'd more curious to know why the module says to use cmd and why it doesn't work in powershell but works in cmd

fathom pendant
#

it's likely because wmic in powershell is aliased to get-wmiobject

#

so syntax is likely slightly different

#

it's likely a case if needing to do -Identity

cloud urchin
#

that makes sense, the error he showed did say invalid query

fathom pendant
#

or because it's useraccount instead of win32_useraccount

#

and that slight change might make it work

#

¯_(ツ)_/¯

cloud urchin
#

if anyone is interested and hasn't heard, broadcom has made vmware pro free for personal use, so you can get the pro version right now totally free. i believe you can take snapshots with it and create a virtual network for a separate vlan for your vm's, and some other little stuff.

glass quail
#

nice

#

I haven't used vmware in a long time I been using VirtualBox

spark spruce
#

pls look at this

fathom pendant
#

not SAM.save or SECURITY.save?

#

etc.

spark spruce
fathom pendant
#

even with capitalization?

snow ridge
spark spruce
urban fable
#

guys I need help with the shells and payloads module, last question, I tried using the metasploit modules for eternal blue (PSEXEC and others)
and still no luck

#

and @fathom pendant wdym closing and reopening it

fathom pendant
#

as in exit msfconsole

#

then running it again

urban fable
#

already did

#

I also closed the lab and machine

fathom pendant
#

and making sure you set LHOST to the proper interface

urban fable
#

and regenerated a new target

urban fable
fathom pendant
#

no

#

considering the targets are on an internal network; the callback IP should match the similar interface

urban fable
#

gotcha

fathom pendant
#

as the internal machines don't have access to the vpn network

spark spruce
#

shit
everytime when I try to move system.save
it shows error

fathom pendant
#

no need

#

your attack host has an interface on that network

#

172.x.x.x

spark spruce
fathom pendant
#

yes

urban fable
#

kk thanks

fathom pendant
#

/drive:name,/path/to/directory/

urban fable
spark spruce
fathom pendant
#

name would be whatever you wanna name it
/path/to/directory/ would be the path to w/e directory you wanna share

#

i believe you can do ./ for current one

spark spruce
#

okay

marsh fulcrum
#

Module: Attacking Enterprise Networks

I'm having a similar problem, I have the ||pivot with ssh dynamic port forwarding||, I can reach the ||172.16.8.20 web application from my host machine|| but when I try to login ||with the administrator password found on smb the page begins loading infinitely until it gives me a "the connection was reset error|| can someone help me?

fathom pendant
spark spruce
fathom pendant
#

means do the path before the name

#

also try putting the password in single quotes and see if that fixes it

#

sometimes it's a bit touchy

spark spruce
fathom pendant
#

well you didn't specify the name

cloud urchin
fathom pendant
#

just the path

spark spruce
fathom pendant
cloud urchin
#

i believe you must have the /drive flag syntax correct like MarcieLee said

fathom pendant
#

after /PassAttack add ,name

dim wolf
#

/drive:name_of_drive

#

you put the path you wanted to mount as the name

cloud urchin
#

isn't it /drive:name_of_drive,/path/to/folder ?

fathom pendant
#

it works either way afaik

dim wolf
#

xfreerdp goated??

cloud urchin
#

if it's not the syntax then restart the victim box, make sure you're on the vpn etc

analog dock
#

Either way works

fathom pendant
#

sometimes it's just silly

dim wolf
#

i didn't know that

analog dock
#

I always do path,name

fathom pendant
#

idk if you need to close off the folder with / or not

cloud urchin
unique remnant
unique remnant
pseudo birch
cloud urchin
cloud urchin
#

yeah see if that helps

spark spruce
unique remnant
pseudo birch
open summit
#

Guys im doing an nmap on an ip adress and its taking ages its gonna take forever how do i speed it up

fathom pendant
#

what module

cloud urchin
#

how long is 'taking ages'? depending on your scan settings you may need to change your expectations

gray merlin
open summit
#

ye im just doing an nmap -p- scan on an ip address

fathom pendant
open summit
#

not doing a service scan

fathom pendant
#

:)

open summit
#

service scanning section

fathom pendant
#

ah

candid night
#

Hey guys. Does anyone have an idea why would my webshell not run when it apparently starts with a letter "b"? I was naming my shells "backdoor" and couldn't make them work but when re-named them "webshell" they ran just fine

gray merlin
fathom pendant
#

yes...it does

gray merlin
mellow holly
fathom pendant
#

ah

#

i was mistaking it for max-retries and the timeout

#

even still it's faster than default (-T3)

open summit
#

doesnt let me paste screenshots here

fathom pendant
#

my point was that -T4 sets a slightly more aggressive scan time

#

because your account isn't linked

open summit
#

how doi link

fathom pendant
#

but anyway

#

setting -T4 will speed up your scans usually

shut quest
#

Which one of those skips DNS resolution...?

fathom pendant
#

and sometimes specifying -sT

gray merlin
#

-n

fathom pendant
#

it's separate from timing

open summit
#

i did -p- but its taking so long

#

cuz its gonna scan 65000 ports

fathom pendant
#

then do as we say and do one of the additional flags to speed it up

#

like -T4

open summit
#

ok

#

do i add the flag after the p flag or before

fathom pendant
#

at any point

#

nmap doesn't care afaik

open summit
#

what exactly does -t4 do

cloud urchin
#

look at the chart/link ChopperBZ#! linked above

open summit
#

what exactly does retransmission cap hit mean

mellow holly
#

nmap sent probe packets to a host and it hit its limit

#

nmap will retransmit a number of times befoer it hits it cap. You can increase it with ``` --max-retries ````

open summit
#

no telnet service is here

cloud urchin
#

you sure about that?

mellow holly
#

yo usure about that 😁

open summit
#

whats a telnet service lol

#

hm

mellow holly
#

google is your friend

gray merlin
# open summit

Good time to learn the lesson that Nmap service names are not a "source of truth", it is guessing.

open summit
#

got it = 3d-nfsd

mellow holly
fringe urchin
fathom pendant
#

Also to save you some time: the creds for the "bob" user is on the page somewhere

haughty tree
#

(File Transfer Module) So i'm trying to upload a file from a windows machine to my parrot box and I cannot really access the github page https://raw.githubusercontent.com/juliourena/plaintext/master/Powershell/PSUpload.ps1 in order to download the script that allows for uploading from powershell, I tried the commands they've shown on the module and other commands like curl and nothing work. Eventually I resorted to uploading the file encoding it in base64 and copy pasting then decoding it but I seem to get an error when running the script and I couldn't find ways to resolve it online

cloud urchin
#

i don't think that host is connected to the internet, so you can't download it from github. download it to your machine and transfer it over to the windows host.

haughty tree
#

Well, I have done that but the script returns and error

#

due to "unclosed comment" although it is closed

#

I also tried downloading and running a different script and I got pretty much the same error

cloud urchin
#

my guess is you didn't download the raw file

haughty tree
#

You can check the link, its a raw file

#

I ran wget

#

And I also tried to donwload it again from github gui by clicking the download button ¯_(ツ)_/¯

fathom pendant
#

You'll need to download it to your machine, then transfer it over

haughty tree
#

Yeah the problem is that it does not run

fathom pendant
#

¯_(ツ)_/¯

cloud urchin
#

welp, the error says where the script is failing you can just edit it

haughty tree
#

That's the problem

#

If I delete the comment it says that I am not closing the function

#

Even tho I am

#

Maybe I'm not supposed to use IEX like that?

cloud urchin
#

throw it into chatgpt and ask why it doesn't work

haughty tree
gray merlin
haughty tree
#

I managed to "solve" this by just editing the script to send a specific file to a specific host and make it without any functions (I guess technically it has a main function)

open summit
#

how do i use the ftp command line utility

cloud urchin
#

'ftp'

open summit
#

'command not found'

candid night
#

Regarding webshells. What can I do when my shell downloads, rather than displays on a browser when I access it via url?
I tried to curl to it, but then it only displays the script inside of it, not executes it

cloud urchin
#

wget

sharp cove
fathom pendant
pseudo birch
fathom pendant
#

There's more than one revshell you can get from revshells

open summit
#

ftp aint workin bryh

#

whats dpkg

cloud urchin
#

weird ftp isn't on the parrotbox already

#

try locate -i ftp see if it's just a path issue

wooden trail
#

Hi! I'm working on password skill assesment hard. I have already accessed file d* has access to, and got the password with our friend j*. Anyways, when I try to interact with that file, it asks for Administrator password, which I clearly don't have. But I do have the password of the "file" itself. Am I doing something wrong?

open summit
#

thats cuz i havent installed it cuz it just doesnt work

#

ive installed it like 3 timesand when i restart the system

#

its back to thisit never actually installs
~

cloud urchin
#

i use kali so idk

open summit
#

i might

#

is parrot or kali better

fathom pendant
#

Preference

#

I use parrot

#

Just do sudo apt install ftp

#

Not ftp.app

#

Also looks like your dpkg is messed up

open summit
#

ye my parrot is buggy asf icl

#

it nevre wants to install either

fathom pendant
#

Baremetal or vm

open summit
#

like i install it i go through the whole process says its done and now i need to restart it, i restart it and then its just back to the normal screen

#

vm

fathom pendant
open summit
#

wdym

#

how i do that

fathom pendant
#

Google

open summit
#

so do i unmount after or before installation

fathom pendant
#

It depends on the software

wooden trail
fathom pendant
#

So again. Google. The steps for virtualbox are different than vmware

open summit
#

i use virtualbox

fathom pendant
#

If it's the .vhd file: mounting it on a device you own will help

wooden trail
#

I was mounting it on the machine itself

fathom pendant
fathom pendant
wooden trail
#

sure

fathom pendant
#

Plenty of online articles, and articles linked in this chat on how to mount on linux

wooden trail
#

I know how to do so, yes, I was so focused on the machine didn't notice the obvious

open summit
fathom pendant
#

A handful are as simple as do as you read

wooden trail
#

thank you very much

open summit
#

erase disk?

fathom pendant
#

If you want to just install fresh again

#

If you've already gotten to the restart machine portion, it's as simple as going into the settings for the vm and unmounting iso/changing boot order

open summit
#

where is that setting?

fathom pendant
#

Right click the iso

open summit
#

which one

fathom pendant
#

It may not let you if the vm is running

open summit
#

HTB.vdi

fathom pendant
#

Brother

#

The one that has the .iso file extension

open summit
#

whats the HTB.vdi part

fathom pendant
#

That's the virtual disk image

open summit
#

cold

fathom pendant
#

Aka the place that your storage goes in the vm

open summit
#

so after my parrto finish installing i 'unmount' the iso correct

dim wolf
open summit
#

doesnt let me

#

unless i turn it off

candid night
dim wolf
open summit
#

done

#

now do i just launch

dim wolf
#

yeah, launch and it should give you the GRUB boot menu

fiery berry
open summit
#

sweeeeeeeeeeeeeeeeet

#

it worked thank u guys

candid night
open summit
#

i installed ftp but it still says command not found

#

says its installed but it just doesnt work