#modules

1 messages · Page 260 of 1

sharp nexus
#

now after hitting forward once I get this

#

Is that helpful?

#

rip

fathom pendant
#

Sec

sharp nexus
#

I mean I'm getting the render tab now... it's not selectable but it's there...

fathom pendant
#

Worked fine for me

sharp nexus
#

wat

#

how

#

what'd your setting with proxy look like??

fathom pendant
#

After loading page and pressing forward I got the expected html source response

#

¯_(ツ)_/¯

#

I changed no settings

sharp nexus
#

I know, but what settign differences do you have compared to mine

fathom pendant
#

I just clicked enable under "response interception rules"

sharp nexus
#

bruh

fathom pendant
#

I didn't select any "or" options

#

And yes I used the same webpage you're using

#

Since it's a docker container

sharp nexus
#

confusion

fathom pendant
#

¯_(ツ)_/¯

#

I literally only enabled response interception and pressed forward once

sharp nexus
#

ok where's that box?

#

Do I have the selected??

fathom pendant
#

Looks like it

sharp nexus
#

bruh

#

time to restart burp

fathom pendant
#

¯_(ツ)_/¯

#

Like I said I messed with nothing

sharp nexus
#

oop

#

hold on

fathom pendant
sharp nexus
#

..

#

brain hurty

#

bruh

#

i'm a dumbass omg

#

I enable the wrong checkbox

#

is not this

#

🤦‍♂️

#

Thanks @fathom pendant

fathom pendant
#

. you had this here

sharp nexus
#

oh wait

#

nvm, it's not fixed

#

confusion

fluid granite
#

Hi guys

sharp nexus
#

hola

fathom pendant
#

Try restarting burp and taking it from step 1

sharp nexus
#

ay carumba

fathom pendant
#

All you should have to do is enable request

#

After that it's just grab request, make quick edits, and boom, ez

sharp nexus
#

all I'm getting is that first page

#

not the HTML or anything

#

frustration

#

I mean the options aren't even saving after I exit burp and reopen it

fathom pendant
#

That's normal

#

Saving settings is for paying customers 🙄

sharp nexus
#

uuuhhh

#

wut?

fathom pendant
#

That looks like your IDE crashed

sharp nexus
#

rip my IDE

fathom pendant
#

O7

sharp nexus
#

aaaaaannnnnnddddd

#

nothin

cloud urchin
fathom pendant
#

I really don't know what you could be doing differently

sharp nexus
#

wtf what am I doing wrong psyduck

cloud urchin
#

when in doubt reboot the box

inner geyser
#

So I've got a question about module 'Show Solution' documentation...basically wondering if my thought process is correct and if this should be corrected? At some point early in the module, you are able to obtain the Administrator PW. Then, towards the end of the module, one of the goals is to add the 'CT' user to the Domain Admins group.

So the last 2 questions are about obtaining the flag on Administrator's desktop and submitting the KRBTGT hash. It would seem to me the goal of adding CT's user to the Domain Admins group would be so that you can get the flag and krbtgt hash as the CT user. However, the documentation completely pivots from "cracker the CT user's hash" to "submit the contents of the flag.txt file on the Administrator desktop on the DC01 host"

Obviously you would have the option to use the Administrator user to get the flag and the hash...but does it make sense to anyone else that the payoff of adding the CT user to Domain Admins would lead to getting them? The 'Show Solution' gives you the Administrator user performing those tasks instead of the CT user.

fathom pendant
#

Open webpage; make sure proxy is enabled; intercept requests and responses enabled; refresh page

#

Are you hard or soft refreshing? (Ctrl+r vs ctrl+shift+r)

sharp nexus
#

I mean this isn't an issue that needs fixed now because it's not an intereactive portion of the lesson, but I can't follow along with the lesson if I can't recreate the steps they're taking to help me learn..

sharp nexus
#

I'm just clicking the refresh button

#

I dunno

fathom pendant
fathom pendant
#

Might be some cacheing in play bypassing the response

#

As said in the module/section

inner geyser
# fathom pendant If domain admin they can see local admin

Yeah, had to edit the end of my question to hopefully make it make more sense? Since CT is an admin you'd think the solution would have you use that account...the but examples in the solution are using the administrator account...instead of the CT account that you just added to the 'Domain Admins' group

sharp nexus
fathom pendant
sharp nexus
#

yup

#

that's a fucking dumb browser thing, wtf, that's so confusing

inner geyser
fathom pendant
fathom pendant
#

Think how annoying it'd be for a large webpage to load if it wasn't cached

sharp nexus
#

that probably should've been mentioned in the lesson to be fair. I know it said to do ctrl+shift+r but it could've explained the difference

#

tis whatever, I understand now, so thanks again @fathom pendant

fathom pendant
#

Np

regal cliff
#

currently stuck on broken authentication, predictable token, i haven an script, shlod work, but dont know why is not working, need some help

static roost
#

Anyone having issues with NTLM Relay Attacks Skills lab? I completed it not too long ago but I'm going back to practice and the same method I used before leads to a timeout.

trail flicker
#

is their anywhare to ask question abt Hackthebox Main website

shut quest
trail flicker
#

Ty !

worldly pagoda
#

Not able to connect through HTB Academy VPN since yesterday. Is there any specific channel to seek help on such issues

cloud urchin
#

try re-downloading the vpn file, and if you've done that try another region

hard lagoon
#

Hi all - I'm doing the Active Directory Enumeration and Attacks module, and I'm up to the page Initial Enumeration of the Domain. I'm trying to use kerbrute to enumerate users with jsmith.txt, but I'm not sure how to get the text file jsmith.txt.

#

Do I need to do something to connect to the internet on the target computer?

hard lagoon
#

thanks mate you're the best

#

Was going down a big rabbit hole trying to figure out if I had to do something to pull it off github

shut quest
#

They did provide the github link for the files, so you could have.

hard lagoon
#

How would I go about doing that? I was trying to at first, but I couldn't figure out how to connect to the internet on the target machine to do that

shut quest
#

pull it down to your machine then scp/ssh/nc/wget/etc the file over

hard lagoon
#

ah ok thanks - I'll keep that in mind!

inland sonnet
#

Hello all, I have completed the module, UNDERSTANDING LOG SOURCES & INVESTIGATING WITH SPLUNK. I am currently doing the assessment and stuck on the last question for a few days.

What I have Discoved : I have discovered A chain of infection but cant seem to get further or trace back this chain to understand which .exe file is being asked for, So far I have understood that :
10.0.0229:8080(IP from which RandomFile.exe was downloaded by msedge.exe) -> Randomfile.exe -> rundll32.exe -> lsass.exe -> credentials dumped.

Question : What else should I search for in Splunk to find the Infection Source... Any Ideas or Suggestions? The idea is to find some exe that came before "Randomfile.exe"

green basalt
#

I have tried so hard that I have lost hope. Who can explain my mistakes to me?

#

footprinting-dns-Identify if its possible to perform a zone transfer and submit the TXT record as the answer. (Format: HTB{...))?

green basalt
#

yes

acoustic owl
#

Did you also try to perform a zone transfer for each zone?

green basalt
#

I have done a zone transfer to each other but i don't know if it is the right command

acoustic owl
green basalt
#

🆗

hexed lintel
#

how to fix rdp black after connected

autumn pilot
#

by waking up the computer

hexed lintel
#

esc, enter space, nothing working

shut quest
civic locust
#

@shut quest Hey. Can I DM you about burnout topic?

shut quest
civic locust
#

Maybe you faced the same problem and can give an advice

stable bone
#

i have advice for you

civic locust
shut quest
civic locust
shut quest
#

¯_(ツ)_/¯

stable bone
acoustic owl
acoustic owl
stable bone
acoustic owl
civic locust
stable bone
acoustic owl
stable bone
#

brother its different for everyone its all up to you and how much time you need to relax... you know your potential and how much time you have just be responsible... or be like me and pop that adderall kekw

shut quest
# civic locust For how much time?

but in all seriousness, it's healthy to take breaks from learning, it's healthy for repetition as well. No one can tell you how much rest you need. I take breaks from learning this kind of material for months at a time. Then the itch comes back and I go at it for 2-3 months, rinse and repeat.

civic locust
#

Sorry for asking maybe stupid questions, I am really confused because of this right now. Thank you.

stable bone
shut quest
#

2 months for the CPTS path is faster than most everyone here. even 3 months is pushing it. it's a lot of material to cover even if you have been in IT for years

lavish mango
# civic locust Maybe you faced the same problem and can give an advice

I cycle between long periods of study and long periods of playing computer games to decompress. Been doing that for years. Mostly I suggest spending time outdoors and with friends and family. Eventually you will miss nerdy stuff. Watch ippsec videos every now and again to remember how fun it is. Enjoy music. Take good care of yourself. Get good sleep and exercise.

#

I enjoy switching to studying programming in periods. Learning C is really nerdy. I recommend the book Advanced Programming in the UNIX Environment.

#

Maybe go swimming in the ocean or lakes. Be in beautiful places. Relax. Have fun.

granite dove
lavish mango
#

Listening to music really sparks joy for me. So go to concerts. Listen to loud favorite music. Relax.

#

Hell, go on a trip. See waterfalls. Go hiking. Stuff like that.

granite dove
#

Drop the nerd playlists I need to update my library plz and thank

lavish mango
granite dove
#

Thank you 3000

zenith canopy
#

Module - password attacks, Single Crack Mode is one of the most common John modes used when attempting to crack passwords using a single password list. It is a brute-force attack, meaning all passwords on the list are tried, one by one, until the correct one is found this paragraph is confusing, isnt this considered a dictionary attack?

marble island
#

ask ai

#

still confusing

#

Understand that you are only going to really learn how to use john by actually using it, so if these details sound daunting ,don't worry, if you can do the exercises and the skill assessment by yourself youre set

fathom pendant
marble island
#

Yo i'm on the same module (again) password attacks

#

Crackmapexec has been archived in their github repo

trail egret
#

Hey , I just started CPTS Path

#

Why am i not allowed to text in #general ?

next bronze
marble island
#

Thank you!

#

I was about to send that link and ask if i should use this

next bronze
#

yes, it's the up to date fork

marble island
#

Are yall updating the module?

#

I'm out, continuing the module using netexec

dry halo
#

hey from the past few days I am unable to connect to the HTB VPN using openvpn. The internet connection is fine on my VM
It stops at establishing TCP connection. I tried changing regions and also the protocol

uncut ocean
#

Reinstall openvpn

dry halo
#

I tried that too 😦 no luck

fathom pendant
shadow cradle
dry halo
shadow cradle
# dry halo nope 😦

what I would do on my machine is to check the routing table and see if you can reach correctly the vpn endpoint.

dry halo
shadow cradle
shadow cradle
dry halo
shadow cradle
dry halo
winged egret
#

hello guys , In the local file inclusion skills assessment... I managed to get RCE a few times however after refreshing the server several time its still getting frozen when I try to execute commands can som1 help ?

#

can I dm som1 who has completed this

shadow cradle
#

then if you can't ping it you can try a traceroute to see if there is something in the networks

#

if so maybe it's a problem with the generation of your certificate and support would be the best option imho

dry halo
#

yes the packet just get timed out. I will reach support

shadow cradle
dry halo
#

Thanks for the help anyway

olive slate
#

in module Attacking Enterprise Networks - Active Directory Compromise, how can i authenticate to the domain controller? Rdp is not listening and i tried winrm but it didn't work. Is there other ways or did i miss something

#

Wait nevermind, i tried to pass the hash with evil-winrm and it works

hexed lintel
#

i am currently in password attack module, Password mutations section ,
||hydra -l sam -P mut_password.list ssh://10.129.68.44||
it is taking forever to get the correct credential

#

am i doing something wrong or this is normal

dry halo
#

try a different protocol may be there is a password reuse

granite dove
fathom pendant
#

I mean don't forget about increasing threads

#

The default amount is so slow

iron ibex
#

Hello,
I am in module Linux Fundamentals section "Filter contents".
I have successfully answered this question :
Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

I used this command to find the answer :
|| curl https://www.inlanefreight.com | grep -E "https://www.inlanefreight.com\\S+" -o 2> /dev/null | tr \" ' ' | tr \' ' ' | cut -d' ' -f1 | sort | uniq | wc -l ||

My intuition is that it feels really too complex (for example regular expressions are not supposed to be known yet at this point) so I was wondering if there was a "basic/easy" solution ? 🤔

hexed lintel
fathom pendant
#

64 is often too much and causes packet loss

#

And you often skip over what the answer would be

#

It should take roughly 30 minutes give or take

fathom pendant
#

There's one forum answer that describes the commands they used

#

I believe I've shared it in this channel before if not it's not too hard to find

iron ibex
fathom pendant
#

Yeah it doesn't help that RegEx is after this one

#

The other thing you can do is copy the source code and ask chatGPT kek after a few nudges it provides the right answer

#

But it can't give you a curl command for it

#

Goofy aaah gpt

#

That's for a diff module

#

Once you get to the module my command references you'll see how it makes sense

#

But yeah I would say that the curl question is the toughest one as it requires knowing how some commands work, as well as knowing html coding (src= and a href=)

zenith canopy
#

Guys how do i install crackmapexec on debian

dim wolf
zenith canopy
#

what is netexec?

dim wolf
#

the successor to cme

#

it's just cme with a different name

zenith canopy
#

thanks, is the syntax same as cme?

fathom pendant
#

Yes

#

It's a fork of CME as the main people holding up the codebase had some disagreements with the original author (to put it mildly)

#

Name was changed to avoid confusion

zenith canopy
#

Thank you guys, ive downloaded it

primal drift
#

New module with C2 wow
Is it collaboration with LockBit?

sly nebula
#

Has anyone done the DACL Attacks II skills assessment? I am stuck on the first question. I'ìll share what I have tried.

fathom pendant
#

I mean the module description and announcement would say if it was

#

@sinful elbow I don't accept random dms, what do you want

stable bone
#

@sinful elbow yeah geez bro smh

naive egret
#

Hi guys, I'm stuck on a question in ACL Enumeration.
The question is -
What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)
Tried lots of things but none seem to work. can somebody give me a hint or something?

dry halo
dry halo
acoustic owl
jaunty vigil
#

hey anyone can give me a hint on sliver skills assessment first flag?

dry halo
acoustic owl
dry halo
#

absolutely yes

wanton idol
#

bros gonna be waiting an hour for a nmap scan to finish 😭

sleek epoch
#

Hey guys, is anyone hiring in 🇩🇪 Germany, into ai/ml? I have someone who is talented enough looking out for opportunities. If you have or know someone kindly let me know. Thanks once again!!

haughty tree
#

Hey so in the Passwords Attacks module under the Password Mutations section we are asked to create a mutated wordlist and use that to find credentials for SSH, my question is, is that suppossed to take a lot of time? I know cracking attacks take time but usually we get a small wordlist/ a word early in the wordlist gets chosen so it does not take a lot of time to get the answer to questions.

limber river
haughty tree
#

Okay, thanks

fathom pendant
fathom pendant
#

Scan the target and see if another protocol would be better to attack

#

Ssh is an extremely slow protocol for hydra/cme/nxc to crack

haughty tree
#

I thought about maybe trying to find another serivce and trying that but I ended up being like "nahh I can wait" but i'll try

fathom pendant
fathom pendant
#

You'd have to constantly extend the lifetime until max and pray

#

The logical thing is;
See ssh would take forever
Think that there must be another way
Scan

haughty tree
#

So I just extended the lifetime a bit and it was enough

#

but yeah

main bolt
#

Hi is anybody created htb machine on hackthebox and submitted it to them

fathom pendant
candid night
#

Hey, so I can't really grasp the concept of running a shell in a context of a different user. How does that differ from just using the victim's account? Say I got a NTLM hash. Why does mimikatz start a shell in the context of a user and not just log-in with it to the account?

#

I know that hash is not a password, but we still use it to authenticate as an account so what is the difference under the hood?

next bronze
#

wdym by login? mimi opens a shell as the user, it is logged in as the user

eager ledge
#

I had the same question. The answer I got was "since you access the contents only that user is allowed, you know you are working on the context of that user"🙄

eager ledge
candid night
# next bronze wdym by login? mimi opens a shell as the user, it is logged in as the user

Per my notes from the PtH section - after authenticating to a user and executing a cmd.exe with this command
mimikatz.exe privilege::debug "sekurlsa::pth /user:julio /rc4:64F12CDDAA88057E06A81B54E73B949B /domain:inlanefreight.htb /run:cmd.exe" exit

"Now we can use cmd.exe to execute commands in the user's context. For this example, julio can connect to a shared folder named julio on the DC"

And now, when I'm working on kerberoasting the same separation of using a domain account and using a shell in the context of a domain account appears

strange forge
#

Anyone who passed the CPTS certification, are the user/pass list from different modules beneficial in the exam?

fathom pendant
#

So it, in essence, is the user's login

#

Yes rc4 is the same

candid night
fathom pendant
#

The point is, since the command actually ran successfully-- it worked and you're in the cmd prompt as that user

#

Otherwise mimikatz would throw some error at you

#

I do agree that the text could be clearer about it

candid night
#

'Aight, so essentially. "running a shell in the context of a user" just means "running a shell as the user". Meaning, when we do a PtH with mimikatz we just get a shell that is the same as we would get if we knew clear text password and just sshed to that user?

fringe urchin
fathom pendant
#

Basically, yes

#

You basically (for all intents and purposes) are the user you pass the hash with

umbral merlin
candid night
#

Okay, thanks a lot guys. That cleared a lot of confusion for me

eager ledge
umbral merlin
eager ledge
#

Thanks!

next bronze
#

klist only works if you have a kerberos ticket

#

if it's ntlm only it won't show

#

but generally pth is best used from a linux host or a c2

umbral merlin
stark lark
sleek moss
#

why dont this work
┌──(sam㉿kali)-[~/Desktop]
└─$ gobuster vhost -u inlanefreight.local -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt -t 50 -k -q
Found: 1 Status: 400 [Size: 436]

#

Attacking Common Applications - Skills Assessment II

stark lark
sleek moss
#

i aded it to /etc/hs10.129.78.178 inlanefreight.local

#

10.129.78.178 inlanefreight.local
to /etc/hosts but none of the vdomains pop up

#

to get subdomains

#

i ltierally copied it from the answer solution

#

cause ik the freaking answer was in ther and it still not work

stable bone
#

i have a question

#

about cyber things

haughty tree
haughty tree
stable bone
dim wolf
ocean night
fringe urchin
#

Can i go to the toilet?senpaienjoyingicecream

ocean night
#

Well.. can you?

#

That's a question only you can answer

fringe urchin
#

senpaienjoyingicecream idk thats why im askin

ocean night
#

Off topic, ability to go to the toilet is not covered in Academy modules, sorry.

fringe urchin
#

💀 ok let me go to oscp and pay 1000€

fiery berry
stark lark
fiery berry
#

Well, it's the same as the one shown so the answer is not

stark lark
#

My cmd:
ffuf -w SecLists/Discovery/DNS/namelist.txt -u http://10.129.254.237/ -H "HOST: FUZZ.inlanefreight.htb" -fs 612

Academy:
ffuf -w ./vhosts -u http://192.168.10.10 -H "HOST: FUZZ.randomtarget.com" -fs 612

#

I mean maybe the output is correct but I dont think I'm supposed to be spammed completely with requests

fiery berry
#

Are you completely sure it's the same as shown from the command you copy/pasted?

stark lark
#

You are referring to fs 612... correct?

fiery berry
#

Even from the screenshot you pasted I can see something different

stark lark
#

Yes, they respond with 200 but from what I know that means it is accepted/open right?

fiery berry
#

Can you check the response length of a false positive?

stark lark
fiery berry
#

Now, are you sure 612 is correct?

stark lark
fiery berry
granite idol
#

Hey I'm fairly new to HTB and pwnbox in general. I'm doing the Detecting Windows Attacks with Splunk module because I'm trying to get as much practice in with Splunk as possible for my BTL1 cert exam and one problem I'm having is that it tells me to:

"Let's now navigate to the bottom of this section and click on "Click here to spawn the target system!". Then, access the Splunk interface at http://[Target IP]:8000 and launch the Search & Reporting Splunk application. The vast majority of searches covered from this point up to end of this section can be replicated inside the target, offering a more comprehensive grasp of the topics presented."

The problem is that I don't see a target ip anywhere in the module. I know that typically I can get to Splunk with 127.0.0.1:8000 but doing that in Mozilla in the Parrot OS lab doesn't seem to work and I'm trying to workout where I'm going wrong and no target ip seems to be listed anywhere in the module...
tying "sudo systemct1 start Splunkd" in the parrot terminal doesn't seem to help either as I get a "Unit Splunkd.service not found" error

dim wolf
#

scroll down to the bottom of the section, click on "Click here to spawn the target system"

granite idol
#

Yeah I did that

dim wolf
#

once it's ready, you'll get an IP address and port

#

connect to that in your browser on the Pwnbox

granite idol
#

I'll try it again, mustve missed the ip address and port

dim wolf
#

or connect to it with your own VM

fiery berry
granite idol
fiery berry
stable bone
#

hey chat i have a question

barren timber
#

Hey french are here?

fathom pendant
#

?

stable bone
stable bone
fathom pendant
#

Just ask it nerd

stable bone
#

awww you lil silly flirt you

fathom pendant
#

It's how I express frustration

stable bone
#

damn 💀

fathom pendant
#

Usually before I actually block 😄

stable bone
fathom pendant
#

Yeah, and I was nice enough to do it free of charge

stable bone
#

:(

#

well

#

are you nice enough to do it one more time bro

fathom pendant
#

Fuckin ask your question I swear to God child

stable bone
fathom pendant
#

Doubt that

stable bone
#

im 20

fathom pendant
#

27

stable bone
#

anyways why does binary now have letters in it in the IPv6?

fathom pendant
#

Because IPV6 uses hex

stable bone
#

so would all the rules we learned yesterday be the same? (like range and broadcast address)

fathom pendant
#

2 rules of IPv6
You can short any string of 0000:0000:0000 to :: once, and you can omit leading 0s

stable bone
#

idk wdym by "::"

fathom pendant
#

Most practical application of subnetting occurs within IPv4

#

AAAA:0000:00000:0000:0000:0000:0000:BBBB is shortened to AAAA::BBBB

stable bone
#

but what about the 1s?

fathom pendant
#

Brother

stable bone
#

thing

fathom pendant
#

If you wanna calculate the binary for hex values, be my guest

acoustic owl
stable bone
#

so basically im fuckin ghandi

fathom pendant
#

Yeah, but you're converting a VERY large number

stable bone
#

or einstein

fathom pendant
#

Remember 1111 in a hex system means
1 x 16^3
1 x 16^2
1 x 16^1
1 x 16^0

#

As you can see, hex numbers get very big

stable bone
#

so it uses 4 bits?

fathom pendant
#

Way more

stable bone
#

but 16 means 4 octets

fathom pendant
#

16 bits

#

And nope we aren't in octets anymore

#

FFFF = 65535 = 1111 1111 1111 1111

stable bone
#

where tf did you get F from

fathom pendant
#

That's hex baby

#

IPv6 is written in hex

#

It's 8 sets of 16 bits

#

128 bits total

#

Compared to 32 bits of IPv4... it's exponentially larger

#

Hex uses 0-9 then A-F which represent 10-15

stable bone
#

ok but why use IPv6 instead of IPv4 whats the difference?

fathom pendant
#

Much more space

#

Because of the limited space of IPv4, IPv6 was invented

stable bone
#

wdym limited? doesnt it have like 4.3 billion combinations??

fathom pendant
#

Lmao and that's not enough

acoustic owl
fathom pendant
#

Consider; how many humans exist

stable bone
#

bro menace bunny got all the connections

fathom pendant
#

Or just used google

stable bone
#

oh wait

acoustic owl
#

Google is my friend 😉

fathom pendant
stable bone
#

10pm for you simpleton americans

stable bone
compact patrolBOT
fathom pendant
stable bone
fathom pendant
#

You're fired

stable bone
fathom pendant
#

Cooked

#

Roasted into a congratulation

stable bone
#

marcie what are you on rn 😭

#

i need wtv youre smoking fr

fathom pendant
#

You need to focus

#

Fuckin 5 second attention span headass

stable bone
#

my adderall wears off around 3pm every day

#

sometimes sooner

fathom pendant
#

Learn constructive ways of managing it then

stable bone
#

and im on 40mg xr daily

stable bone
fathom pendant
#

meds only get you so far ¯_(ツ)_/¯

#

Anyway

stable bone
#

you sound like my mom rn 😭

fathom pendant
#

Well maybe she got a point

stable bone
#

nah she pisses me off

fathom pendant
#

The sooner you learn to manage yourself without meds the better off you'll be

stable bone
#

last time i tried to be off of them i got into a car crash and broke ribs so no thx im ok

fathom pendant
#

Such as, not saying everything that comes into your head

stable bone
#

I DONT??

fathom pendant
#

I said manage when you're off them

#

You should never drop prescription meds flat out without consulting your doc

stable bone
#

alr gn im going to bed

granite idol
#

So I'm at the beginning of the Detecting Windows Attacks with Splunk module and I gotta admit my Splunk skills are coming up short on the same question. It's wanting me to modify the search so that it'll show all process names that made LDAP queries where the filter includes the samAccountType=805306368 so that I can enter the missing process name from a list given in the question.

I've tried adding "AND ProcessName" to the search filter, tried to specify the names of the relevant processes of it and I've also tried adding Event Id 1644 (seeing as Event 1644 is the LDAP performance monitoring log) to the top line of the search query but none of this is working.

I'm not wanting anyone to give me the answer, I'm just wondering if someone could give me a hint that would put me in the right direction for solving it...

#

I'm definitely not equipped to help with that directly but I would say maybe be quite specific about what you're asking for with it? You're more likely to get responses if it doesn't come off as a "please do my homework for me" type of request if you know what I mean....

dim wolf
granite idol
dim wolf
#

look at what the query is, and see what it is that's restricting the results

#

the obvious freebie is the timeframe but you will need to modify it further

granite idol
#

@dim wolf thanks, I think I need to take a small break and look at it again later. At least the more time I spend with Splunk in general the less foreign it'll feel in the BTL1 exam

onyx halo
#

👍

#

Probably vm mem management... Not sure why it would jump from 0x0000... to 0x5555...

fathom pendant
#

Just how mem works my dude

final kite
#

i need help on this one One of the pages you will identify should say 'You don't have access!'. What is the full page URL? Skill assesment web fuzzing i fuzz with all 3 vhosts i got but i get ton of pages not sure how i should find the one i need

fathom pendant
#

Also don't forget the file extensions

onyx halo
final kite
fathom pendant
#

There should only be one response from the right subdomain, extension, and response text

#

If you're getting too many, maybe you're at the wrong spot

#

Make sure to be recursive

#

Oh and don't forget the size

#

Remember with ffuf
f is filter out
m is match

final kite
#

would that mean filter out ones with size: 0 bcs i keep getting those

fathom pendant
#

What does your match string look like

#

Including flag

#

(Flag is argument tag)

final kite
#

ohh mb

#

so i gotta include like match for HTB{

fathom pendant
#

No

#

What does the question say you're looking for

final kite
#

oh riht

fathom pendant
#

I'm meaning flag in the context of running a command, a flag is also known as an argument

final kite
#

you dont have acces to

fathom pendant
#

It's case sensitive

#

But also, show your command where you have the string

#

Including the -argument

#

Technically it's matching regex

final kite
#

u mean this one part ? -mr "You don't have access!"

fathom pendant
#

Yep

#

Try with single quotes instead

final kite
#

ye i put all that

#

it just takes so long

fathom pendant
#

It'll take a minute

#

Here's another hint, use the subdomain that you found all the extensions for

fathom pendant
#

Your -e is revealing an answer btw

final kite
#

oh bm

fathom pendant
#

Also. Turn on verbosity

#

Whenever you do recursion, verbosity helps

#

When you run it btw, is your ffuf requests dropping really low? If so, try changing to bridged networking in your vm

#

Something with NAT and your router causes issues

final kite
#

i am doing it in their instance

fathom pendant
#

Ah

#

Then it should be fine

final kite
#

library gonna close soon

#

hope i can find it

runic inlet
#

hello everybody
can someone help me with ssh-keyggen, a day ago i generated keys and imported to authorized keys, it worked properly, but when the machines reseted it required me to regenerate the keys again to connect back, but this time its prompting me to the password

fathom pendant
#

what module?

ocean night
runic inlet
#

i added my keys again, chmod 600 authorized_keys, still not working

fathom pendant
#

Well chmod 600 authorized keys won't do anything

#

You need to use the id_rsa to sign in

ocean night
#

Ah.. yeah, if using pwnbox the id_rsa would not be there any more..

#

Question is then, are you using Pwnbox, and if so do you still have the same instance as last time you worked on the machine?

#

Which port are you listening on?

#

Oh

#

You said Kali.. you forwarded the port to an external IP?

#

Module instances are hosted on public IPs and ports. In order for the module instance to reach your Kali instance you're running locally, you'd need to expose your Kali instance (port 80) to the internet

#

Hm ok, nevermind then. So the Kali machine is connected to the VPN, and you can reach the target from you Kali VM?

#

No if the target is on a VPN you shouldn't need to

#

Perhaps try a different port, like 8080. I'm not fully up to date on firewall rules for those instances, but it's worth a try.

#

So you'd connect back to your VPN IP from the module instance (which I guess you have a shell on)

#

I should be in bed, I'm gonna regret this.. hit me up in DMs

#

First time I've had that reaction

#

Thank you

#

No come on, let's do this

#

One more problem solved before sleep

#

otherwise it'll tick me off lol

#

o_0

#

You sure you're not still on the kali vm lol

#

Otherwise gg

#

Sorry, dumb question, but gotta ask them

#

Noice

#

nn then 😄

#

Rubber ducky debugging 🦆

#

Cheers!

twin ocean
#

I am doing the Windows Fundamental course. Is there a plan to update it with info on Win 11 in the future?

next bronze
#

windows still work the same between 10 and 11, there's not really much to update for fundamentals

ocean night
#

Ahhhhh 😄

#

A facepalm sometimes feels good.

proud pine
ocean night
#

They just added one

#

/s

runic inlet
fathom pendant
#

Classic PEBKAC

fathom pendant
#

You use your private rsa key

#

Problem exists between...

runic inlet
fathom pendant
#

Idk how you used the authorized_key file to connect

fathom pendant
runic inlet
fathom pendant
#

Yes and you use your private key to ssh in

#

That's how ssh keys work

runic inlet
#

yes i did, it worked

#

only in my first attemp

fathom pendant
#

Again though you're not answering my initial question

#

what module are you working on

runic inlet
#

its box

fathom pendant
#

Then wrong channel

fathom pendant
#

This channel is and the other academy channels are for assistance with HTB academy. This one in particular, is for the academy learning modules

stray prairie
#

does anyone able to spawn a target machine for this module INTRODUCTION TO WINDOWS EVASION TECHNIQUES

ocean night
#

In fact, for which specific section?

stray prairie
#

I was able to spawn now it was just slow.

ocean night
#

Yep.. it can take some time for instances to spawn, especially Windows instances

#

Good hunting 🙂

stray prairie
#

just wondering, will HTB release more for evasion modules ?

cloud urchin
#

Working on AD Trust Attacks, Trust Account Attack section. It's asking me to proxychain ssh into the DC which I can do without issue, the problem is when combining proxychains with ssh it seems to stop scrolling the screen. so when I run a command like mimikatz it just updates the last line on the screen making it impossible to read. is there a way to make it scroll or do I just need to use tmux and log it all or something?

sterile epoch
#

Hi I am in windows priv escalation module miscellaneous section, I am trying to do CVE-2019-1388 but i cannot get the browser to open as SYSTEM is it patched in this target?
I did right click on hhupd.exe tool and run as admin > clicked on the hyperlink and then tried to view from task manager but the user column was empty

cloud urchin
#

it's not patched

normal sand
#

Could someone please explain what this means?

Note: If you are using Impacket tools from a Linux machine connected to the domain, note that some Linux Active Directory implementations use the FILE: prefix in the KRB5CCNAME variable. If this is the case, we need to modify the variable only to include the path to the ccache file.

Module: https://academy.hackthebox.com/module/147/section/1657

cloud urchin
normal sand
#

By FILE prefix, do you mean KRB5CCNAME?

cloud urchin
normal sand
cloud urchin
#

no, KRB5CCNAME is the variable itself

#

it's the environmental variable

#

the FILE prefix would be part of the value of that variable

#

i think you got it though

normal sand
#

Yup, thanks.

shut quest
cloud urchin
#

gimme dat edr evasion module

quick ingot
#

Need help in Advanced SQL Injections skills assessment. Anyone free?

sterile epoch
#

?

vernal falcon
#

Hi im currently going through the pivoting module, at the rdp and socks section you need to transfer SocksOverRDP binaries to the target. the target identifies the binary as a virus and immediately deletes it. anyone knows how to solve?

sterile epoch
#

try using ligolo

sterile epoch
vernal falcon
sterile epoch
vernal falcon
#

yeah

sterile epoch
#

I am spawing the machine wait a sec

unique remnant
#

I think I posted my question to a wrong channel accidently earlier:
can someone who has active Pwnbox give me the Powesrhell version number from $PSversiontable? Thanks

autumn pilot
#

is there something preventing you from spawning it

sterile epoch
oblique sedge
#

hello not having access to the pwnbox channels I would ask my questions here if that suits you, I have a problem with my virtual machine and also that of hackthebox I cannot manage to 'fatal: unable to access' https:// github.com/Hackplayers/evil-winrm.git/': Failed to connect to github.com port 443 after 130180 ms: Couldn't connect to server" how to resolve this problem thank you for your understanding moreover being French and to facilitate me the task reply to me by pressing the arrow above a message to mention it

vernal falcon
oblique sedge
sterile epoch
#

is it related to academy or main boxes?

#

if its academy stuff can you send the link to the module

oblique sedge
#

I try to download evil-things for the optional exercise but I can't do it all the time, errors even with the different download methods

unique remnant
oblique sedge
unique remnant
#

remove the SPACE character from the address

oblique sedge
#

I'll try I'll tell you again

oblique sedge
flint ore
#

Hi everyone!
Can someone give me hint? I'm stuck on DACL I Attacks Modules - Granting Rights and Ownership.

We have access to lilia account, she have owns rights on Manager group. I try abuse with owneredit, but have some issues:

#

BH show edges:

#

And if check DACL rights on chap user use Managers with lilia creds, we detect WriteOwner rights:

#

Task:
Lilia is owner of the Managers group; abuse her privileges to gain access to the shared folder \\DC01\Managers and submit the contents of flag.txt as the answer.

hallow fable
#

fuck

#

it

flint ore
snow ridge
flint ore
#

Yes, i'm not in group. I try add lilia in Managers group via net rpc group addmem 'Managers' lilia -U inlanefreight.local/lilia%DACLPass123 -S 10.129.205.81 but access denied and other users i can't add to group

#

And via addusertogroup.py can't add user:

snow ridge
flint ore
#

Can you show command?

snow ridge
#

Otherwise its right

flint ore
#

May be i just use owneredit with target chap?

hexed lintel
#

smbserver is not running , any solution

flint ore
#

Try -smb2support share .

hexed lintel
flint ore
#

May be some problems in impacket packages?

hexed lintel
civic oar
#

hey

#

anyone could help me with task 3 of getting the password of ftpsql in the NTLM Relay skill assesment?

#

I have a clear text cred for a local user called sql_ftp_test but I have no access with that account to any share

limber river
hexed lintel
limber river
sweet girder
#

Hi everyone. I have a question. I'm actually following the module "Setting up" and I just read the section "Organization", but I'm scared to not remember all the organization this section talk. Any advice ?

normal sand
#

Anything you're afraid you won't remember and may need in the future, take notes.

sweet girder
#

Okay thanks !

zenith canopy
#

trying to connect to the host using evil winrm

lavish mango
strange forge
#

In the attacking common applications under PRTG Network Monitor section. the reverseshell is not executing commands.

inland sonnet
#

Why is the Connection being refused? I am using attackbox to connect to the target.

hexed lintel
#

module is teaching about Pypykatz
now mimikatz is available on linux also,

#

so any recource to learn mimikatz in linux

autumn pilot
inland sonnet
autumn pilot
#

If you are going to use the kali machine just to crack the hashes, better use the workstation instead

inland sonnet
open snow
#

Hi, i think question in Identifying Filters section in Command Injection module has a bug, there are multiple answers to the question, both (the one from solution, and the other one), are not accepted.. even though application seems to be responsive to the provided command injection.

inner oyster
#

Hi everyone, I have a simple question (i hope it is the correct place to aks it) do you know if it is possible to perform pth attack with Remmina ? In order to access a machine with RDP

open snow
#

will try, thanks Volter

unique remnant
honest gyro
sacred laurel
#

Hi guys, I'm on file upload attacks skills assessment but I'm unable to progress. I was able to read the source code of contact/upload.php with SVG/XML payload but when I decode the base64 I don't see anything about where it uploads my file to

open snow
icy marsh
#

#broken_authentication reset token question 1,

I'm using a python script that generates md5 hashes using username htbadmin and the time . but can't get the matched token .... any help ?

sacred laurel
open snow
#

sure

unique remnant
icy marsh
#

#broken_authentication reset token question 1,

I'm using a python script that generates md5 hashes using username htbadmin and the time . but can't get the matched token .... any help ?

sacred laurel
unique remnant
sacred laurel
icy marsh
#

#broken_authentication reset token question 1,

I'm using a python script that generates md5 hashes using username htbadmin and the time . but can't get the matched token .... any help ?

acoustic owl
honest gyro
#

guys i am stuck at INJECTION ATTACKS -->Exploitation of PDF Generation Vulnerabilities i think i have the multiple working ip and port but im unable to get any file when i send my payload i just reseve the title and the note is just empty i tried using the xml req and then encode it with base64 and it didnt work i dont get it

any help?

acoustic owl
mossy tiger
#

Anyone having issues with AD attacks and enumeration - bleeding edge vulnerabilities? the exploits keep failing with "remote host timed out" for both noPac and PrintNightmare

icy marsh
true marlin
#

guys I want to ask if I have "currenti plan silver" and I want to open "student plan" without end of the month, can I do it or should I wait until the "silve" plan ends?

true marlin
#

okey thx

fiery berry
#

If you go to the "/opt" folder over the pwnbox you can find the "noPac" exploit directly there to use it

mossy tiger
#

I'm not sure if i'm missing something silly, or if the DC01 box is having issues and needs to be bounced

fiery berry
#

You may want to remove the screenshots since I don't remember if the passwd for the user is already disclosed by the module. Give a me sec to re-verify everything myself or possibly you want to restart the target

fathom pendant
mossy tiger
#

my bad

fathom pendant
#

Yeah this module is a grey area since like the entire lab is reused throughout

final kite
fathom pendant
mossy tiger
final kite
#

I even fohnd the answer somewhere

#

But I dont get it

#

I cant even open it in mozilla

mossy tiger
fathom pendant
#

Recursion and verbosity helps

final kite
#

Some issue I put them all in etc/hosts so its not that

fiery berry
mossy tiger
#

I'll try that again. was having same issue last night so not sure

#

thanks!

fathom pendant
#

And you do still have to specify the port even if it's in your /etc/hosts

final kite
#

Ye i know I put like ****.academy.htb

fathom pendant
#

As you don't specify port in that file

final kite
#

Finally it worked

#

Think I missedspelled port since it wasn't written in fuzz output

burnt oasis
#

Hey how’s everyone doing!? Quick question about hascat. Everytime i try i use —force because of kernel autotune failure but it never finishes. Last night said estimate of 1hr i woke up and its not saying 25 days. Is this because im using a virtual machine or because host machines gpu isn’t good enough?

dim wolf
#

use your host machine. not a vm

limber river
#
  • why using this --force ?
timber hatch
#

windows priv escaltion module / kernel exploits, why is this CVE-2021-1675 a kernel exploit? when i read it, it is a Windows Print Spooler Remote Code Execution Vulnerability?

limber river
night pumice
#

yo im new here, where can i ask about a machine?

acoustic owl
#

If you have no access, read and follow #welcome

fathom pendant
wide river
#

wait, they take away the tutoring service on academy now ?

dim wolf
#

it's been replaced by step-by-step solutions

wide river
#

im doing C2 with sliver module

#

and maybe the module still new

#

so there's nothing on the solution yet

fathom pendant
#

Usually the walk-through for new modules is like a week after release

wide river
#

make more sense now, i will wait until then

fathom pendant
#

or you can just ask your question and maybe someone can help

#

Instead of waiting however long

#

¯_(ツ)_/¯

wide river
#

module: "INTRO TO C2 OPERATIONS WITH SLIVER "
section: "Probing the Surface"
description: I created ||staged.txt|| and made a payload with msfvenom. But I might do something wrong when replacing the payload from ||staged.txt|| to|| sliver.aspx|| because i don't have any sessions return

burnt oasis
#

Ok thanks for that used pwnbox and all worked. When it comes to exam is it best to use pwnbox or virtual machine? Or should i just use both to be prepared @dim wolf

dim wolf
#

whatever you're more comfortable with

#

if you want to have tools at the ready, use a vm

snow ridge
#

Has anyone done "Domain Reconnaissance" section in INTRO TO C2 OPERATIONS WITH SLIVER. Im constantly getting errors like this when I try to run SharpView ```[] Output:
[Get-DomainSearcher] search base: LDAP://DC=child,DC=htb,DC=local
[Get-DomainObject] Get-DomainComputer filter string: (objectClass=
)
An error occurred: 'System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.DirectoryServices.DirectoryServicesCOMException: An operations error occurred.

at System.DirectoryServices.DirectoryEntry.Bind(Boolean throwIfFail)
at System.DirectoryServices.DirectoryEntry.Bind()
at System.DirectoryServices.DirectoryEntry.get_AdsObject()
at System.DirectoryServices.DirectorySearcher.FindAll(Boolean findMoreThanOne)
at SharpView.PowerView.Get_DomainObject(Args_Get_DomainObject args)
--- End of inner exception stack trace ---
at System.RuntimeMethodHandle.InvokeMethod(Object target, Object[] arguments, Signature sig, Boolean constructor)
at System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(Object obj, Object[] parameters, Object[] arguments)
at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
at SharpView.Program.Run(String[] args)
at SharpView.Program.Main(String[] args)'``` Its basically impossible for me to do exercises, I have already switched to different VPNs tried both UDP and TCP. Rdp is not also working on that module. I can connect once and then I disconnect and then cant connect to it anymore. I even submitted ticket to htb because machines were not spawning with EU vpns, but they fixed it today.

#

If someone knows a fix or how to make sliver connection better, let me know. My network is fully stable fiber with hight speeds so its not my internet and this is the only module I have ever had issues like this.

candid night
#

How exciting!

fathom pendant
#

Not all questions award cubes

#

¯_(ツ)_/¯

#

The sum total of cubes you get from the module will be 20% (or 100% for tier 0) of what you spent

candid night
#

Yea I think I read that somewhere before. Still, it's a funny pop-up

shut quest
fierce mason
#

on skills assessment for web attacks, ive managed to reset the password for all users up to uid 100, but i seem to be stuck at this point

loud dagger
#

is it worth doing the basic toolset path before i start the cpts path just so i can start getting some ctfs under my belt

fathom pendant
#

Ctfs won't help with cpts

grave kiln
snow ridge
# shut quest Can you run any other commands?

Yes, I think its some kind of timeout problem but not 100% sure about that. For example this ran successfully ```sliver (http-beacon5) > execute-assembly /home/kali/SharpCollection/NetFramework_4.5_Any/SharpView.exe "ConvertTo-SID -Name websec" -t 240 -i -E -M

[*] Output:
S-1-5-21-2749819870-3967162335-1946002573-<SNIP>```

cloud urchin
fierce mason
loud dagger
cloud urchin
cloud urchin
loud dagger
#

think i might do that then

#

i know ctfs won’t help with cpts, i just want to start doing ctfs because they’re fun

dim wolf
#

intro to network traffic analysis is covered in infosec foundations

loud dagger
#

yep yep

cloud urchin
#

it's not part of the pentester's path though

loud dagger
#

i finished it already

dim wolf
#

infosec foundations is the prerequisite to pentester path

loud dagger
#

i just finished infosec foundations

cloud urchin
loud dagger
#

that’s cool but i still already finished infosec foundations

dim wolf
#

yes but it is highly recommended to do so for beginners

cloud urchin
#

sure i agree but the question was specific to the pentester's path

dim wolf
#

the pentester path assumes you've completed infosec foundations anyway

snow ridge
# shut quest Can you run any other commands?
SMB         10.129.205.234  445    WEB01            [*] Windows 10 / Server 2019 Build 17763 x64 (name:WEB01) (domain:child.htb.local) (signing:False) (SMBv1:False)
SMB         10.129.205.234  445    WEB01            [-] Connection Error: The NETBIOS connection with the remote host timed out.``` I had to run this 3 times before it worked, so I think theres definitely some problems with the machine and not in sliver. But the thing is that I have already restarted it 3 times 😄
cloud urchin
snow ridge
cloud urchin
#

ok but you showed me cme, not sliver

#

for cme, add that argument and it probably won't time out

snow ridge
#

I was just testing where the problem might be

pine fjord
#

Hi

next bronze
dim wolf
#

no :(

next bronze
#

huh what

#

that's such a crucial tool

pine fjord
#

What is this server about

dim wolf
loud dagger
cloud urchin
#

i think when hashcat comes up they just kinda give you the command, but yeah agree hashcat is pretty crucial lol

pine fjord
#

My friend invited me

loud dagger
#

yeah i thought it was weird that hashcat isn’t included in cpts

fathom pendant
dim wolf
#

also covered a smidge in AD enum and attacks

#

but like, that's just a review

loud dagger
pine fjord
#

No😅

dim wolf
#

if you read #welcome it will tell you what the server is about

pine fjord
#

Oooo ok

loud dagger
#

people confuse me

median gust
#

can soemone help me with nibbles in nmap enumeration htb academy

#

slide in dms

dim wolf
#

just ask your question

#

people will be cool enough to help you in this chat

rustic sage
#

in "Getting Started" section in CPTS path, in bind shell section it says
"Note: we will start a listening connection on port '1234' on the remote host, with IP '0.0.0.0' so that we can connect to it from anywhere.".
can someone explain why use no ip address in reverse shell or bash command. ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc -lvp 1234 >/tmp/f"),
does it mean we can connect it from any IP address?

fathom pendant
#

Generally yes

#

However since it's an isolated environment

#

You can only access it via the vpn connection

rustic sage
#

i see, thank you

hexed lintel
stable bone
#

erm why does my parrot say duplicate launchers

hexed lintel
#

i cannot find the file with flag.

#

what am i missing

#

tried looking into all the shares

fathom pendant
#

Well because you're not connected to the right share

#

Also as a note; each service has a different user

#

IPC$, C$ Are system shares

#

You need to connect to the actual share broadcasted

#

smbclient -L -U "user" //ip/

#

-L will list all shares

#

Once you know the share that's not a system/default it's just connecting to that

hexed lintel
#

there is one non system share
i am connected to that but

cloud urchin
#

you're either in the wrong share or the user you're using doesn't have permissions to access it.

fathom pendant
#

^

#

Could be that your password enumeration net a false positive

#

Hence flags like -local-auth or --windows-auth are used in some instances

limber river
#

and I perfer to use smbmap since it gives a better output and cleaner info than smbclient

fathom pendant
#

Password attacks

hexed lintel
#

got it

#

crackmapexec stopped after getting 1st correct username and password

#

there were more user

keen cairn
#

Hi i was just wondering is there a way to reset your progress back too the start on HTB Academy i have been away for a while and would like to start some of the material from the begging any help would be apriciated thanks 🙂

limber river
sweet girder
#

Hello again. I have a problem with my parrotOs VM. I use Virtualbox, and during the first installation, I allocated 20 go of space to this VM. I tried to update the OS with this command :
sudo apt update -y && sudo apt full-upgrade -y && sudo apt autoremove -y && sudo apt autoclean -y
but I get the error
insufficient space in /var/cache/apt/archive

I tried to allocate 20 more Go, but I still get the error
I followed the instruction in the module Setting up, section Linux
I used LVM during the installation of the OS
Any advice please ?

dim wolf
#

i had created a 40 GB Parrot OS VM when i started

#

when i finished CPTS, it was completely full

#

so i created a new one and gave it 80 GB of storage

#

that's overkill imo

cloud urchin
#

on top of that you don't want to run a full upgrade before doing an update

next bronze
next bronze
#

fair

dim wolf
#

it was already a year old and i couldn't update sh!t

sweet girder
#

Okay I will remember to add more space Kappa

next bronze
dim wolf
sweet girder
#

I don't know how to do that. I tried google but I'm lost. It's the first time I use a VM

loud dagger
cloud urchin
#

depends on your hypervisor

next bronze
sweet girder
#

I already increased the disk space. I will do more search to increase the partition using lvm. Thanks !

dim wolf
#

i had to do the same thing when my game server ran out of space

loud dagger
#

at long last i am finally enrolled in CPTS

pine dagger
sweet girder
sweet girder
#

Thanks !

next bronze
pine dagger
#

afaik, its actually lvextend, not lvm though /shrug

next bronze
pine dagger
#

Well, hopefully they'll have the sense to snapshot before attempting to mess with the disk at all 😄

#

Otherwise... it'll be a learning experience \o/

next bronze
#

or maybe the comment is wrong, either way just use the lvm commands directly lol

#

take a snapshot before you mess with the disks

haughty jetty
#

Quick question for the Module "Footprinting" - Section "SMTP"

How do I increase the 'wait time' for pentestmonkey's smtp_user_enum perl script?
According to the help file, it should be '-t <seconds>', yet -t is already used to define the target IP - seems odd.

Setting -t twice (first for the IP, second for the wait time) does not seem to work, as I cannot get it to actually find the correct user name (which I already know and am explicitly searching for).

./smtp-user-enum.pl -M VRFY -u ||robin|| -t 10.129.233.90 -t 100

Any idea what I am doing wrong?

haughty jetty
#

-w is not working, sadly.
"Unknown option: w"

#

I could try to edit the script and change it to -w, maybe that'll work 😄

pine dagger
#

lol, I just noticed the -t is in there twice

plush urchin
#

please what’s the difference between remote port forwarding and a reverse shell.

#

From what I have gathered, local port forwarding is when traffic from an application/service attached to a port on my local machine is sent to that same application on the same port on another computer through a tunnel. While remote port forwarding allows applications outside your network to connect to an application running on a port within your network/computer

#

And is port forwarding only possible using ssh, I saw a YT video on how to set up port forwarding within a router. It sounds like remote port forwarding.

cloud urchin
compact patrolBOT
cloud urchin
#

chatgpt can break this down more into more granular explanations if you need more details

pine dagger
#

Awww dammmmmn, they dropped a lmgtfy

haughty jetty
open summit
#

used this as shown and it says file ot found

pine dagger
open summit
haughty jetty
#

Yeah, it should be correct.
The IMAP / POP3 section also mentions it (which is where I got the answer in the first place) 😛
Feels like something is broken.

open summit
#

doesnt make sense to me why does it say passwords not found

fathom pendant
haughty jetty
#

Are you sure your SecList is in that exact directory?

open summit
#

im using the integrated vm

wide river
open summit
#

LOGIN BRUTE FORCING - login form attacks

fathom pendant
#

Can you ls /opt/useful?

#

Or just locate SecLists

open summit
#

whats happened here?

#

i found it but it has an X on it

autumn pilot
#

If you can't find it take use of the commands in linux to find the file

wide river
#

sudo chmod 777 <filename>

open summit
#

i just used file rockyou-75.txt

#

and it worked

wide river
#

sweet

fathom pendant
#

As I belive it'll recursively chmod

open summit
#

pepecoffee okay

dim wolf
#

you only need 644 perms

shut quest
strange forge
#

attacking common applications- skill assesment. unable to find initial foothold. what i tried is using ghostcat but it failed too. i have website- backup thou. unable to fing anything in it. can anyone hint what i should be looking for in it?

pine dagger
#

Skill assessment 1 or 2?

#

And which question

#

Be more precise

strange forge
strange forge
pine dagger
#

So you're stuck on q1?

sweet girder
#

Just to be sure. Do I need to install Python2.7 ? I've seen it reached end of life since 2020

pine dagger
strange forge
sweet girder
#

Okay. I just started so no I don't have script. Thanks

pine dagger
#

You're jumping ahead without doing the basics. Follow the standard methodology:
Recon <--- you are here
Enumerate/Scan
Gain Access <--- you're jumping to here
Priv Escalate
Cleanup/Cover Tracks
Report

#

Start with the basics, nmap. Find services that are hosted. Dig into them. Then go from there.

fathom pendant
pine dagger
#

Python 2 is 😱

sweet girder
#

Oh okay. I will find a way to install python2.7 just in case. Too bad I can't install it with apt install. I will find a way

fathom pendant
#

Virtual environments (venv)

#

Or docker

urban fable
#

@fathom pendant do you know of some way to mount a VHD file in linux ?

pine dagger
#

parrot uses apt iirc, so should be able to install it with apt install python2, but definitely go with MarcieLee's suggestion of venv's. If you dont know them, learn them first before installing python.

fathom pendant
#

Once you identify the filesystem on the vhd, you'll know what to look for

sweet girder
#

Thanks I will look into that

fathom pendant
#

Since a lot of common questions can be likely answered by a quick search

urban fable
fathom pendant
#

The blog is fairly straightforward

urban fable
#

I didn't understand how to use dislocker and got an error with losetup

fathom pendant
#

Just read

urban fable
fathom pendant
#

¯_(ツ)_/¯

fathom pendant
#

Losetup is a similar thing to the article

#

Just using lo-device instead of npm

urban fable
#

I keep getting an error with it

#

👍

fathom pendant
#

well have you tried with sudo? ¯_(ツ)_/¯

urban fable
#

yup

fathom pendant
#

Most half-baked guides assume root

pine dagger
#

half-baked, haha

open summit
#

i wanna use a -P william.txt file on hydra

#

but it cant find the file and i cant either

#

LOGIN BRUTE FORCING - Service Authentication Brute forcing

#

am i meant to use the william.txt file for my -P flag

urban fable
#

took me quite a bit to understand it lol

fathom pendant
#

Following the steps

#

Either in that section or a previous section

pine dagger
fathom pendant
#

In general this module walks you through creating the necessary files or how to for most of the module

#

And emphasizes using the flag that loops through users first

fading oracle
#

@proud pine i dm-d you if you dont mind!

open summit
#

how can i tell which port is open

fathom pendant
#

Subdomains of subdomains

fathom pendant
#

It doesn't want ipv6

#

It only wants ipv4 and not localhost btw

open summit
#

so port 80

fathom pendant
#

There's port 80 and ftp

#

I forgot you were on the brute force one

open summit
#

ye

#

so i want port 21 for ftp

fathom pendant
#

You gotta chain. Basically

#

And yes

open summit
#

wdym by chain so i tried using the rocky-10txt file didnt work

fathom pendant
#

It should

#

I just mean doing it from the host you just ssh into

open summit
#

ah

fathom pendant
#

Since it's only listening internally you can only access it internally

open summit
#

so hydra -l m.gates -P /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou-10.txt ftp://94.237.57.173:80
wouldnt work

zealous rune
#

hi, really struggling with the end of module engagement on shells module

fathom pendant
#

Docker containers are only accessible via one port

zealous rune
#

I managed to successfully exploit 1 machine

fathom pendant
#

But they can be running stuff on localhost/loopback

fathom pendant
zealous rune
#

but the machine with the address 172.16.1.11 I am getting stuck

#

thanks I got the creds

fathom pendant
#

Blog?

zealous rune
#

I exploited the blog that machine i got shell no issue

#

it's the "first one"

#

running tomcat service

fathom pendant
#

it's all about enumeration ¯_(ツ)_/¯

zealous rune
#

I also investigated smb

fathom pendant
#

Something about war never changing

#

The smb one is the easiest

#

It's eternal

zealous rune
#

🙂

#

thanks

#

i'll try both the smb and tomcat ones

#

basically i figured that the metasploit modules don't work out of the box for the tomcat

#

so far that's as far as i got

#

then i started poking at smb