#modules

1 messages · Page 266 of 1

fathom pendant
#

¯_(ツ)_/¯

hexed oyster
#

--data="POST DATA GO HERE"

#

eh, no worries. I'll keep plugging away.

ebon storm
#

hey guys ive been stuck on this question Hunt 2: Create a KQL query to hunt for "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder". Enter the content of the registry.value field in the document that is related to the first registry-based persistence action as your answer.

#

Can anyone help me out?

#

so far I've used event.code:13 as my filter alongside registry.path: Run

#

but im not exaclty sure what answer the question wants?

fathom pendant
#

The value

ebon storm
#

registry.value?

#

omg, i just went one by one and copy and pasted and then one of them worked... dead

#

thanks, but i would really like to know the why behind the question and answer. I've been stumped on this question for a while

fathom pendant
#

It's setting persistence

#

So a specific value is changed/added

ebon storm
#

I see its the only one that had the host.name with powershell as well

#

sorry, process.ext

bitter meteor
#

thks! I'm looking in "Job Role Paths" section...

lucid halo
#

Hey, @everyone I'm working in Linux Fundamentals Module 18, I'm stuck on the first question. I've tried using "find /etc/ -name *.log 2>/dev/null". When I use this command I'm brought back to the Command Line. I am novice, hoping someone could walk me through this question and the second.

zinc nimbus
#

in **Active Directory enumeration and attacks module section Attacking Domain Trusts - Child -> Parent Trusts - from Linux ** someone pls help idk why this is happening
it takes forever for me to get a shell and it doesnt give it

#

i already made the golden ticket and found the domain sid, enterprise group sid and nt hash for krbtgt but it doesnt work

mint beacon
#

Where should I begin

#

Somebody help

spark charm
#

target ip not spawning ???

mint beacon
#

I have no experience in hacking or programming. But I am interested in learning can somebody help

compact patrolBOT
next bronze
zinc nimbus
#

i will try again right now tho.
it's also weird that when i use lookupsid.py the output always ends in a timeout(1st img) but the output should be like (2nd img)

shut quest
next bronze
spark spruce
#

module- intro to NOsql injection skill assess ||
i am unable to get right path
anyone can instruct me

mortal locust
#

New-ADUser -Name "MTanaka" : We issue the New-ADUser command and set the user's SamAccountName to MTanaka.

can anyone explain me this??

I had an idea that SAM accounts are used in Local machines, but HTB is saying that when we use New-ADUser command with a name, we are seting a user's sam account.

I m a bit confused

cloud urchin
#

you're thinking of a SAM account. they're talking about a sAMAccountName, which is a different thing

icy marsh
#

SSTI Exploitation Example 1” Server-Side attacks module

Use what you learned in this section to obtain the flag which is hidden in the environment variables. Answer format: HTB{String}

I spent a many hours but can’t find a flag. I think I did everything

cloud urchin
#

same tool/syntax, but it actually works

#

i didn't write down the challenge for that, but the basic idea is identify the template engine, then inject code into that template engine based on the flow chart

novel lynx
#

I am currently in Nibbles Initial Foothold, and i am having trouble understanding this "We will add our tun0 VPN IP address in the <ATTACKING IP> placeholder and a port of our choice for <LISTENING PORT> to catch the reverse shell on our netcat listener."

#

is this the ip of my vm instance?

shut quest
# novel lynx is this the ip of my vm instance?

It is the IP of your VPN connection which will typically be tun0. If you do a ifconfig you'll see a tun0 interface, that IP is what you'll want. Then you'll want to pick a port available on your attacking machine that will match when listening for the remote connection.

novel lynx
#

ok, so i had that right

#

i set the port to listen on port 9443, and also have the port set to 9443 in the image.php file, but when i try to connect with ncat it reads "Ncat: Connection from 10.129.215.86.
Ncat: Connection from 10.129.215.86:59116.
/bin/sh: 0: can't access tty; job control turned off
"

#

i don't know if that was right? it appears that it established some kind of connection, but i didn't get a tty, and that port number was different. I don't know if the port number being different is relavent

#

nvm, i'm seeing that i am moving in the right direction, and i am at the part where i need to import python

shut quest
novel lynx
#

thank you!

blissful zealot
#

Idk if im missing something haha is there any reason I cant post in general?

zinc nimbus
#

trying to fix this for hours but it keeps 😭

cloud urchin
#

which regions did you try?

zinc nimbus
#

let me try that

cloud urchin
#

yes, if you're US try EU, and vice versa. many regions have been having issues recently especially with internal hosts

zinc nimbus
#

ok

eager ledge
#

Hi I am doing the Skills Assessment section of "PIVOTING, TUNNELING, AND PORT FORWARDING" module. I am using SSH dynamic port forwarding along with proxychains to discover the internal hosts. I am currently scanning 172.16.5.0/24 network. However, nmap is showing all the IP address in this network as up. Why is it happening?

eager ledge
#

I am scanning again against 172.16.5.0/16 network right now, and it shows 3 hours 48 minutes as estimated time to completion.

zinc nimbus
stark lark
#

Wanted to hear your guys' take on this:

Let's say i get a rev shell that is not the most stable.

I accidentally run "python" and it is stuck inside the python cmd line

Is there any way to properly exit this when the shell is not that stable? I've tried exit() and quit() but no luck.

spark spruce
ocean night
#

Sorry, but I cannot provide support for modules etc. Please avoid pinging people randomly like this too.

eager ledge
muted kindle
acoustic owl
acoustic owl
eager ledge
acoustic owl
eager ledge
spark spruce
#

Don't know which dot are you talking about

eager ledge
acoustic owl
#

but I'm not online regularly at the moment. So don't be mad if an answer takes longer

muted kindle
#

proxychains 8 hours nmap scan

acoustic owl
acoustic owl
cloud urchin
next bronze
#

you did tell them to change region, I didn't

stark lark
#

Module options (exploit/linux/50064):

   Name       Current Setting  Required  Description
   ----       ---------------  --------  -----------
   PASSWORD   demo             yes       Blog password
   Proxies                     no        A proxy chain of format type:host:por
                                         t[,type:host:port][...]
   RHOSTS                      yes       The target host(s), range CIDR identi
                                         fier, or hosts file with syntax 'file
                                         :<path>'
   RPORT      80               yes       The target port (TCP)
   SSL        false            no        Negotiate SSL/TLS for outgoing connec
                                         tions
   TARGETURI  /                yes       The URI of the arkei gate
   USERNAME   demo             yes       Blog username
   VHOST                       no        HTTP server virtual host


Payload options (php/meterpreter/bind_tcp):

   Name   Current Setting  Required  Description
   ----   ---------------  --------  -----------
   LPORT  4444             yes       The listen port
   RHOST                   no        The target address


Exploit target:

   Id  Name
   --  ----
   0   PHP payload


msf6 exploit(linux/50064) > set vhost blog.inlanefreight.local
vhost => blog.inlanefreight.local
msf6 exploit(linux/50064) > run

[-] Exploit failed: One or more options failed to validate: RHOSTS.
[*] Exploit completed, but no session was created.
msf6 exploit(linux/50064) > set rhost 172.16.1.12
rhost => 172.16.1.12
msf6 exploit(linux/50064) > run

[*] Got CSRF token: 733fe2889f
[*] Logging into the blog...
[+] Successfully logged in with demo
[*] Uploading shell...
[-] Exploit aborted due to failure: unexpected-reply: Unexpected json response
[*] Exploit completed, but no session was created.
msf6 exploit(linux/50064) > 

What could I be doing wrong?

eager ledge
# eager ledge When using nmap within `/24` network for host discovery, it shows all the hosts ...

I can also see server name server01 in the note. So I am trying to perform DNS resolution for the server. I can see that DNS server is running on the target server. But it is not able to resolve the address. nslookup and dig is not present on the target server. I tried proxychains with dig, but doesn't work:

└──╼ $proxychains dig server01 @127.0.0.53
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.14
;; communications error to 127.0.0.53#53: connection refused
;; communications error to 127.0.0.53#53: connection refused
;; communications error to 127.0.0.53#53: connection refused

; <<>> DiG 9.18.12-1~bpo11+1-Debian <<>> server01 @127.0.0.53
;; global options: +cmd
;; no servers could be reached
light sentinel
#

Why can’t I talk in general

shut quest
#

<@&861185840277487616>

spark spruce
light sentinel
#

Wym

eager ledge
acoustic owl
#

@spark spruce Just enter a username and password. ||You can find a potential username on the website.
See what happens if you change the username so that it is guaranteed not to exist||

shut quest
#

He's wanting hacker for hire and deleted his message after I pinged rule break

ocean night
#

Ah, ok

#

I missed that, sorry then @next bronze

next bronze
#

idk what happened but it's all good

light sentinel
#

Wait so this is a cybersecurity server not hackers

shut quest
light sentinel
ocean night
#

There are hackers, and there are hackers. You're in the wrong place buddy.

light sentinel
#

Dam

stark lark
stark lark
shut quest
viral night
#

Hello, I'm doing the windows fundamentals module, and have a question about the behavior I'm seeing.
Whenever I create an SMB share on "C:\Users\htb-student\Desktop\Company Data", and then enumerate the SMB server's shares (smbclient -L), instead of seeing the sub folder I shared I just see \Users, why was the entire \Users folder shared and not the specific folder I shared?

timber hatch
#

today i have to do everything over the clipbaord...that kind a suck...why is that?

inland sonnet
#

Does anyone else feel like the RDP machines have been very slow for the past few days?

spark spruce
acoustic owl
spark spruce
acoustic owl
gritty jetty
#

guys i need some help

#

ive been stuck at the msfconsole module for ages now

#

it keeps telling me Msf::OptionValidateError The following options failed to validate: RHOSTS

#

and yes i type RHOSTS

tulip perch
#

Guys if i purchase a module with cubes do i get access to it lifetime?

digital hollow
#

Hello I am currently on the footprinting module smb I entered to the smb server and I can't find the flag.txt.

bright coral
gritty jetty
gritty jetty
burnt owl
#

Could you send a screenshot of your options in msfconsole?

gritty jetty
bright coral
spark spruce
quaint dagger
#

anyone else having problems spawning a pnwbox atm?

digital hollow
#

@bright coral I connected and I just don't see the flag.txt

acoustic owl
digital hollow
#

@bright coral it is the third question when it is says find flag.txt file

spark spruce
bright coral
fathom pendant
dense pewter
#

Is anyone here CURRENTLY doing the AEN module?

acoustic owl
spark spruce
#

there is dot difference

acoustic owl
spark spruce
digital hollow
#

@@bright coral hello how what are the commands I am currently sees only
Profile
Contents
Bash_logout
bashrc
No flag.txt

fathom pendant
#

also what module are you working on

acoustic owl
bright coral
digital hollow
#

So what is the solution for this @bright coral

fathom pendant
#

bro

#

ngl use your brain

#

just look around

#

that's all you gotta do

#

dir/ls, cd

#

just... look

digital hollow
#

@fathom pendant thank you for some reason I don't find it

fathom pendant
#

well you're dropped into a base directory

#

with other directories in it

#

what logical place might flag.txt be in

spark spruce
fathom pendant
#

and look

digital hollow
#

Still can't find it I tried to look at every one but no such file as flag.txt I can't understand why@fathom pendant

fathom pendant
#

there is definitely a flag.txt

#

where have you tried looking in smb?

digital hollow
#

Like I said my friend there are this
Profile
Contents
Bash_logout
Bashrc@fathom pendant

fathom pendant
#

one of those is not a file; and is a directory

digital hollow
#

Yes I know I will check again

fathom pendant
#

which you can cd into

#

like you would on any Windows/Linux machine

digital hollow
#

No one this it the problem

fathom pendant
#

?

digital hollow
#

I can't send photo to show here can I send you a message

fathom pendant
#

you can cd into the directory that has the flag.txt in it

#

that's as much as I can lead the horse to water, so to speak

acoustic owl
spark spruce
fathom pendant
#

you see how when you do dir/ls in smb there's a letter next to filesize? that indicates if it's a Directory/Hidden/Not Hidden

#

i just spun up the lab myself and was able to cd to the directory

#

the reason you can't find it is because you haven't listened to what @bright coral or I have been telling you

#

is that there's another layer to look in

digital hollow
#

But how to look it if it is hidden I don't know can you please tell me @fathom pendant

fathom pendant
#

brother

#

idk how more clearly i can say this

#

one of those is a DIRECTORY

#

as indicated by 2 things

#

the filesize being 0; and the dir listing as D

fathom pendant
#

but again you have the answer to move forward in what you can see

#

i've told you at least twice now that what you're looking for is a Directory

#

and 2 stop dming me

#

I highlighted the specific letter for a reason

digital hollow
#

Man I understand but I will tell you again when I am doing ls it not giving me the content of the directory

fathom pendant
#

D = directory
H = hidden
N = Not hidden
in a normal OS the H files would not show up under a normal ls/dir

fathom pendant
#

ls with no arguments just lists the current directory

#

same thing with cd

digital hollow
#

Ohhhh I see I forgot it thank you for you help and time appreciate it💪

fathom pendant
#

you can just CD to it

#

and then ls

#

and boom it works as intended

#

you vastly were underthinking it

rustic sage
#

can't even terminate it!

dense pollen
#

I currently can't start any exercise, tried different browsers although i am connected via vpn

fathom pendant
dense pollen
fathom pendant
#

sometimes it takes a bit; also connected via vpn has no bearing on target spawning

#

it's not like the labs site

#

you can spawn a target without being connected

dense pollen
rustic sage
fathom pendant
#

if there's no "Click here to spawn target" Button, then the questions solely relate to the reading/research you do

dense pollen
fathom pendant
dense pollen
zenith canopy
#

Module - footprinting (smb), why am i not able to access the share anonymously after having 'guest ok = yes' in smb.conf, i have also changed the permissions of mnt and exampleshare folders

haughty tree
fathom pendant
haughty tree
#

Perhaps since your user exists it tries to authenticate you

fathom pendant
#

but also; you don't need to set up an smb share for this

#

the provided target has all the stuff

zenith canopy
#

yes i was just trying to setup and learn the configuration better

#

-U anonymous doesnt work as well

fathom pendant
#

-U ""

#

smb doesn't use anonymous

#

it uses Null/Guest Sessions

zenith canopy
fathom pendant
#

did you try -U guest?

zenith canopy
fathom pendant
#

¯_(ツ)_/¯

zenith canopy
#

didnt work

fathom pendant
#

i'd say just move on with this

#

since technically setting it up is out of scope

#

did you restart the smb service is my last question

zenith canopy
#

yes i think is should, i wasted a lot of time in this

fathom pendant
storm elk
#

Is there a way to locally redirect to port 80 while doing academy courses? I now got an external IP with a port, but I'd rather have it on port 80

zenith canopy
fathom pendant
#

like redirect the pwnbox?

storm elk
#

I am doing some web modules. So I don't have to add the port each time

fathom pendant
#

that whole sentence kinda confused me ngl

storm elk
#

yeah sorry lol

fathom pendant
#

oh

#

no there isn't

#

as the ports and such aren't controlled by you

storm elk
#

yeah that's what I thought :d

acoustic owl
fathom pendant
#

they're on the target, and the scope of docker containers is solely the ip:port

storm elk
#

a local tunnel from localhost:80 to docker:port perhaps

fathom pendant
#

and at that point it's just faster to copy/paste --> http://<paste>

#

you do know you can click the spawned IP and it copies to clipboard yeah?

storm elk
#

Yeah. But these CSRF XSS module sections use 3 vhosts

#

but port 80 is taken on pwnboxes

#

I will just have to remember putting in the port 😄

bright coral
#

You should be able to bend all the traffic to IP X with port 80 to IP X with port Y with iptables 😉 but remembering to use the port is probably easier

storm elk
#

ah yes

spark spruce
spark spruce
# acoustic owl Read through the sections again.

In this section
When it uses regex payload
It shows some result
But when I try to enumerate the password using regex
It shows missing password parameter
It means this parameter is sanitized well to avoid this payload.
Now I don't know which type of payload should I use?

acoustic owl
wild helm
#

On the Windows Logs and Finding Evil Pg 2, Sysmon was already installed so I just ran the config file, then replicated the DLL attack yet I still can't get Event Id 7 to generate in Sysmon. I have no clue what I'm doing wrong

spark spruce
wild helm
cinder mortar
#

For advanced XSS and CSRF exploitation module, can anyone explain to me why sometimes the line xhr.withCredentials = true; is needed and sometimes it isnt needed in the payload? i've reread the section multiple times but i still dont get it

spark spruce
civic oar
#

hey

#

anyone could give me a hint for third question on Sliver's skill assessment?

#

thank you so much ^^

#

I've tried Kerberos delegation and DACLs but I can't see any path to DC

empty imp
#

Am I the only one that can't seem to get DNS working with inetsim (in my own vm)?

The DNS service just does not start up. Everything else starts up.

shut vapor
acoustic owl
surreal quiver
#

Anyone knows how to break family link in phome without the parent noticing

spark spruce
surreal quiver
#

Can anyone give me mc apk phone link

#

Dm me

sullen trench
#

Any idea where to find a feedback channel, having some issues with a dedicated module.

sullen trench
limber surge
#

└──╼ [★]$ xfreerdp /v:10.129.202.136 /u:{username}/p:{pass}
No protocol specified
[15:05:09:586] [32311:32311] [ERROR][com.freerdp.client.x11] - failed to open display: :0
[15:05:09:586] [32311:32311] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.

any1 know how to fix this issue?

storm elk
#

use remmina

analog dock
limber surge
next bronze
#

don't use root

storm elk
#

$ means he's in a user terminal?

limber surge
lucid halo
#

Hey, @everyone I'm working in Linux Fundamentals Module 18, I'm stuck on the first question. I've tried using "find /etc/ -name *.log 2>/dev/null". When I use this command I'm brought back to the Command Line. I am novice, hoping someone could walk me through this question and the second.

acoustic owl
acoustic owl
acoustic owl
# spark spruce Username

If you get stuck, send me a DM.
But I won't be able to reply until later. I'm off again for a while

storm elk
#

Anyone else experiencing issues with the module "ADVANCED XSS AND CSRF EXPLOITATION " that you have to press the deliver to victim button a few times before even 1 request comes through?

shut vapor
earnest raven
#

Hey did you ever solve this question? I've been stuck on it for a few hours? Thanks.

#

Hey did you ever solve this question? I've been struggling with it for a few hours?

north bramble
#

have added subdomain and domain to /etc/hosts

storm elk
#

perhaps you need to define a server you're querying

shut vapor
# cinder mortar ah okayy thanks

I hope that clears it up. I don't have the full context to say for sure. And, full disclaimer, XSS is a weak point for me so if someone else has a clearer explanation please speak up.

north bramble
storm elk
#

I am saying, read the page

#

you forgot part of the command

#

for your dig command you'd need the @

north bramble
#

it had failed before on that but I think I understood my mistake

storm elk
#

try it out and let us know 🙂

#

You know you've done too much frontend stuff for the day when you keep writing xhr.widthCredentials

north bramble
storm elk
#

what's in your hosts file? did you put in the right ip?\

north bramble
#

should I remove the subdomain?

#

wait lemme remove and try

#

didnt work lol

storm elk
#

the @ means that you will query that server, so in thise case you'd need it to be in your hosts file

#

so what happens when you keep on using subbrute and enumerate the subdomains?

fringe urchin
#

You dont need to specifiy @ with nslookup but with dig you have

#

Ah already got answered vy sparkling

north bramble
#

I know this seems to be the valid one, it was a hint on the forums

north bramble
storm elk
#

so try to dig that one

north bramble
#

okay on it

#

thanks bro got it

#

thanks for the help

storm elk
#

the reason your nslookup couldn't find it is that that subdomain isnt in your hostsfile

fathom pendant
#

With nslookup you just put the ip/nameserver after

#

Also spoilers

north bramble
north bramble
fathom pendant
#

Nslookup queries nameservers

fathom pendant
#

Iirc it has to be in resolv.conf

bright coral
cinder mortar
shut vapor
cinder mortar
lucid halo
tulip dragon
#

why does it ask for sign in 2-3 time a day

#

before it used to ask sign in after 1 month

fathom pendant
#

Just take the L and click sign in with htb account

#

And click remember me

tulip dragon
#

i did many time in last 7 days but

fathom pendant
#

But on a real note. Reach out to support

tulip dragon
#

it always ask everyday

fathom pendant
#

that's not something any of us plebs can answer ¯_(ツ)_/¯

#

Could be a backend misconfig not storing the cookie properly

shut vapor
#

I won't do you the disservice of walking you through it, but I'll point the way. 🙂 Maybe someone else will though.

lucid halo
fathom pendant
fathom pendant
#

Also section name is gonna be better than page #

sacred ermine
#

anyone who can I ask for help on Kerberos Attacks Skills Assessment? I guess the last question is broken, tried many ways to leverage it, could not manage to get it still.

#

the reason why I am making such assumption is bc pass-the-ticket was broken as well, after I messaged the support, they fixed it, so wanted to know if its me or the final part is broken, thanks

#

tried to reboot the target and many many attempts, still no results

next bronze
#

it worked when I did it, if you're on US servers try switching to EU

sacred ermine
#

I am on eu 5 or it was 4 I guess

cinder mortar
#

Anyone can help for Bypassing CSRF Tokens via CORS Misconfigurations section under ADVANCED XSS AND CSRF EXPLOITATION? I think i have the correct payload but im unable to get any response

polar haven
#

Hello
how can i get a permession to talk in general chat ?
and
can i delete my payment methode in the academy website ?

fathom pendant
#

Second; you gotta message support to get it removed

polar haven
burnt oasis
#

Hey hope your having a good day! Working in the Information gathering module and in the Active Infrastructure Identification section question two asks which cms is in use for app.inlanefreight.local as you can see im attempting to use the whatweb -a3 command but i keep getting an error. Is my syntax wrong or is it issue with connection?

next bronze
fathom pendant
#

Also http, not https

#

I don't recall these using https

#

Also your syntax for curl was bad

sacred ermine
# next bronze iirc it's just KUD

yeah, I was trying the user j. and an. both did not work, also tried the spooltrigger and SharpSpooltrigger, seems they are not designed for a computer KUD, only users are allowed

fathom pendant
#

You can just use ip, you don't need to do ${...}

next bronze
#

have you tried using coercer?

sacred ermine
next bronze
#

coercer does more than just printerbug

#

sorry I don't have more notes than this, all I have is just "kud, coerce auth from dc, ptt"

sacred ermine
#

thanks!

wraith pelican
#

hello all, i've finished the 'retrieve hardcoded credentials' in thick-clients from Attacking Common Application module. I liked it but I got a lot of whys as I go through my notes and trying to generalise if I have to do it with another one.
Some things remain kinda obscure or too magical like: 'Checking the memory maps at this stage of the execution, of particular interest is the map with a size of 0000000000003000 with a type of MAP and protection set to -RW--'.
Ok I understand the words but if it wasn't told 'look, there!', I don't know how i would have found it. Do we search for MZ magic byte and explore all MZ pattern? Or we search for memory type MAP with RW protection owned by user, then we explore each one with strings until we find something? I mean what's the key here, what's the process? How do we know to set breakpoint solely at exit? Now I feel I have to follow this vulnerable thick client rabbit hole to satisfy my curiosity but if someone has some quick insights, I would be grateful!

fathom pendant
#

Tbh the thick client applications is a one-off

#

It was added extremely late, and from out of nowhere

wraith pelican
#

Ow ok thanks! that's too bad, it feels like too less. I'll check other sources anyway, that's sometimes tricky to stay on cpts path without getting lost

fathom pendant
#

The thick clients/java/mem stuff is not likely to come up again in CPTS path

north bramble
fathom pendant
wraith pelican
fathom pendant
#

Actually mb connecting is covered in the footprinting module @north bramble

fathom pendant
north bramble
fathom pendant
#

So I suggest going back to footprinting > IMAP/POP3 and seeing how to connect via imap(s)/pop3(s)

north bramble
fathom pendant
#

Even if you don't go through the provided labs for them

sacred ermine
digital hollow
#

Identify if its possible to perform-a-zone-transfed-submit-the-TXT record as the answer. (Format: HTB. What they are wanting I don't understand can someone try and solve this it is footprinting module

shut quest
fathom pendant
digital hollow
#

Manged to answer it the other question is problematic

#

What is the ipv4 address of the hostname DC1

digital hollow
#

Someone please

sacred ermine
#

I dont know the answer maybe you need to dig further, but thats just an assumption

fathom pendant
fathom pendant
dire abyss
fathom pendant
fathom pendant
#

Well the whole thing is HTB{7..7}

muted lotus
#

I have a problem with the module Windows Attacks & Defense, on this sub-module PKI - ESC1, im trying to log in to the RDP to WS001 , but im getting a black screen, is not loading the system.

muted lotus
#

i did, but is not loading

fathom pendant
#

Try clicking around the lower 2/3 of the screen then

#

Otherwise chat with support

dire abyss
fathom pendant
#

So I'd take a stab at what you think the whole phrase would be given what you see

#

This is a known thing with this

dire abyss
#

cool, i cheated a bit on this one question and lookup the solution, i see what it should be

#

the 1337 phrase makes sense now

#

i thought i was doing something wrong

fathom pendant
#

All good, I think Jared said he spent like 5 hours with someone on this previously

stable bone
#

ik whats wrong with it

#

aint got no gas in it

viral lotus
#

just a quick one and I guess its a preference question, I am running trough the CREST Path, when doing the web request module obviously you can use burpsuite etc but I am assuming the ideas is to manually run through it as if I haven't got access to it etc? thanks

weary torrent
#

deleting this cus i got it

stable bone
fathom pendant
stable bone
viral lotus
viral lotus
stable bone
#

music taste fire tho btw @viral lotus

viral lotus
viral lotus
stable bone
viral lotus
#

its cool lol

fathom pendant
#

Ignore the kid, he's got squirrels in his brain

viral lotus
#

They are alright no harm done haha

little bear
#

And I'm a caffiene crackhead lmao (all in good fun)

#

Turns out I will be using EU to complete the skills assessment afterall.

fathom pendant
past kite
#

hi, i can't connect to mysql server. Intro to MySQL. ERROR 2002 (HY000): Can't connect to MySQL server on '94.237.49.212' (115)
Why?
mysql -u root -p -P 3306 -h 94.237.49.212

little bear
#

Slow every bow and then

Instructions not clear, troops invading jk

Yeah, there was quite I bit I spent yesterday walking through, but now I understand the issues I had. Appreciate the time contributed Marcie!

shut quest
past kite
#

yes, it's default port

burnt oasis
shut quest
fathom pendant
past kite
#

I'm sorry, guys. I forgot about hint

fathom pendant
#

Most only run http

past kite
#

"Make sure to specify the non-default MySQL port in your command."

fathom pendant
#

Mood

dire abyss
#

im having a bit of hard time understanding prefix in sqlmap module. well to be clear is how to find what the prefix should be, any tips?

#

if i run "sqlmap -u 'http://targetip:port/case69.php?col=id' -v 3" i see the payload gives a hint but idk if thats the best method or if theres a better way of checking this

soft plume
#

Hello I am once again asking for assistance on the "Skills Assessment" lab for the "PIVOTING, TUNNELING, AND PORT FORWARDING" module. The command: proxychains xfreerdp /v:IP /u:creds /p:"creds" /cert:ignore /drive:smbshare,/home/kali/smbshare works fine in the pwnbox but when I use it on my VM it doesn't complete. The reason to why I'm not using the pwnbox, is that every time I get to the RDP section the connection will consistently crash/disconnect/freeze. So I am back to my VM and I'm trying to figure out how to bypass/use another tool for RDP. I tried ```proxychains rdesktop IP -u creds -p "creds" -V 1.2 -r disk:smbshare=/home/kali/smbshare

fathom pendant
soft plume
#

fixing rn

fathom pendant
#

Also your screenshot is missing a character

#

Iirc there's a ! at the end

#

(For pass)

#

Also case sensitive

#

But yeah checked, you're missing a char in your pw in the screenshot

#

(Which is also spoiling btw)

soft plume
#

sorry Im trying now but whenever I try to put the ! in the password it'll just delete the quotation

#

yea ill delete

soft plume
#

ahh right

fathom pendant
#

! Is a special character

soft plume
#

welp it worked, Im a dumbass like usual, sorry for wasting your time

fathom pendant
#

It happens

#

Slowing down and double checking often does wonders

soft plume
#

yep I've always had the problem of tunnel vision

dim wolf
#

tunnel vision in tunneling module

soft plume
#

😭 😭 😭

fathom pendant
#

The irony

smoky pumice
#

I just finished the ZAP Scanner section of Using Web Proxies Module. I had to find the answer in a write up because no matter what I did ZAP would not find the 'high-level vulnerability' referenced in the question. I have two questions 1. Is anyone able to get the scan to reveal the correct vuln at this point? 2. Is anyone willing to DM me another path to finding the flag I could put in my notes for future reference should I run into this situation again? I would prefer to learn something even if the platform isn't working as designed. TIA.

fathom pendant
#

It was literally just running the scan from the section and just waiting

smoky pumice
#

Shoot. I tried that and waited at least that long three times. I’ll try again tomorrow. Thanks!

loud dagger
#

i know PoC stands for proof of concept in this field but i cannot stop reading it as person of color in my head

olive slate
#

Just a quick question. Using fileless method to download and execute using IEX, does that only work for powershell files? Does it work with exe?

fathom pendant
#

fileless can also be a misnomer, if it creates persistence, for example, it has to create/edit a file to do so

olive slate
#

Thanks @fathom pendant. Helpful as always

fathom pendant
#

as shown in the first paragraph, it basically uses native tools

brittle crest
#

I hope everyone is well! I'm hoping that someone can explain how something works. I am working on the skills assessment for the command injection module. I already solved it but want to explore different solutions to it.
$(tr '!-}' '"-~'<<<[)
$(tr 'set1' 'set2'<<<input)
How does this work exactly
I know tr translates the input such that the chars that are in the input and also in set1 are replaced by set2
In the example, the input does not contain any chars from set1 so there is nothing to convert the input to from set2, so how does this shift the character to the right by one?

fathom pendant
#

magic

brittle crest
#

@fathom pendant lol thanks!! This site will come in handy!!

fathom pendant
#

in short it does some funky stuff that shifts it

#

you could probably find a lengthy article explaining it

brittle crest
#

cool cool, I found this https://stackoverflow.com/questions/6441260/how-to-shift-each-letter-of-the-string-by-a-given-number-of-letters
and then I pulled up an ascii table and noticed that set1 '!-}' is a range of chars from ! to } and set2 is the same, just right-shifted by one. So when the input is passed in, it matches it to set1 and since set2 is right-shifted by one it replaces it with the right-shifted character. At least that's how I understand it. Better than before cause it was legit just magic for me for a bit lol!!! thanks again @fathom pendant

karmic knoll
#

Has anyone here done and/or finished Intro to C2 w/ Sliver? I’ve been stuck for a bit on the first question of the assessment. I’ve tried seatbelt, winpeas, kerberoasting, no luck so far. I appreciate any nudge or pointed in the right direction to look! Thanks

limpid field
#

Is the vulnerability assessment module out of date? The vm does not have nessus pre installed and there's no scan file for me to use if I don't want to wait for it to finish like the module says

ocean night
#

Fair to be said, perhaps that port number should be included on the target string provided

#

Note that the Pwnbox you spawn is not the target - down where you fill in the answers, there is another Spawn button to spawn the target

limpid field
#

Forgot about that

cloud urchin
#

just tested, it is indeed running on the default port (the port mentioned in a previous section) on the target

ocean night
#

Yup me too, and got the answer (go me)

cloud urchin
#

great job g0blin, maybe one day you can be a pentester too 😛

limpid field
#

The module says to run the scan against the windows target so do I ssh to the target and run it on the Windows machine or run nessus on the parrot machine against the target

ocean night
#

You don't need to run a scan - the results will be there waiting for you within Nessus once you have logged in

cloud urchin
fathom pendant
#

You can run a scan

cloud urchin
#

the scan takes a long ass time

fathom pendant
#

But there's one already populated, so you don't have to wait the 40+ minutes for the scan

cloud urchin
#

i was going to do it but just ended up using the prefilled data

limpid field
#

How do I remote in to the nessus session running on the "target" not that it's spawned in, cause the lab gave instructions for running it myself like I would access it from the normal desktop environment

cloud urchin
#

navigate to the target's nessus web interface, attack the attack target from there

#

vm/pwnbox -> target box (the thing you spawn that provides an IP) -> internal ip to attack

#

nessues is running on the taret which you can access from the pwnbox/vm, and also has a 2nd network connected to the internal network for your victim box

fathom pendant
limpid field
#

I got it

fathom pendant
#

From there you're connected to the spawned 10.129.x.x nessus service

#

And the 10.129.x.x device has an interface, as Nut said, that connects it to the 172.16.x.x or w/e internal ip

limpid field
#

I just got back into working through the modules now that college is slowing down for a bit and i forgot how htba has a different way of conveying instructions than I am used too

cloud urchin
#

understandable, most of the time you use the vm/pwnbox to initiate attacks

#

or scans

limpid field
#

Do targets get stuck spawning sometimes the openVAS target has been spawning for almost 20 mins

cloud urchin
#

you can CTRL+F5 and try again, however recently there have been problems all over, especially with modules that have another internal network and boxes. if refreshing with ctrl+f5 doesn't allow you to spawn it, try changing your region entirely (eu -> US or US -> EU)

limpid field
#

Ctrl f5 refreshed my attack vm and it cancelled the target so I'll wait and see what happens

cloud urchin
#

yeah probably a region issue then

round moat
#

What version of the SMB server is running on the target system? Submit the entire banner as the answer
Why every answer of this is wrong

#

i tried smbclient -L -N //<ip>

#

i got SMB V3.1 but it says answer wrong

#

InFreight SMB v3.1
isnt this a right answer?

shut quest
round moat
#

i also used nmap,
nmap --script banner <ip> -p 445

#

and nmap --script smb-os-discovery <ip> -p 445

shut quest
#

There's an example in the section that will provide the result you're seeking

#

Also future note, it makes it easier to provide the module/section that you're working on

round moat
#

do i have to reset the ip and try again?

shut quest
#

Make sure you don't have any white space before or after your answer

round moat
#

okay thanks

shut quest
#

Also delete this as it is a spoiler

round moat
#

okay

#

thanks for your help

sterile epoch
sterile epoch
#

thanks

next bronze
stable bone
#

also random but what is github? and how do i work it

#

its just a long list of files idk what to do

acoustic owl
normal sand
#

Module: INFORMATION GATHERING - WEB EDITION

I was on the main HackTheBox platform working on a medium machine, trying to perform subdomain enumeration. In the module I've mentioned it talks about subdomain enumeration and vhost discovery. Under the active subdomain enumeration section of the module, it uses the tool GoBuster. And in the following section it uses ffuf for Virtual host discovery.

Can someone explain the difference between the two to me? From my understanding vhosts and subdomains follow the same format (<subdomain>.<second-level-domain>.<tld>) and vhosts have the same IP address as the domain but subdomains may not. Please correct me if I'm wrong.

stable bone
stable bone
#

nvm its over an hour long i'll figure it out

#

cant focus that long

acoustic owl
acoustic owl
normal sand
acoustic owl
normal sand
# acoustic owl Both are fuzzers. Use whichever you like better.

Please correct my understanding if I'm wrong. gobuster uses a wordlist to generate subdomain URLs and then confirms their existence with the use of DNS? Whereas fuff uses a wordlist to generate subdomain URLs and then confirms the existence by making a request to the URL?

normal sand
acoustic owl
#

Depending on what you are looking for, you can query DNS or vHosts

eager ledge
#

Hi I am doing Pivoting Skills Assessment exercise. I have access to a domain joined Windows server. The domain is INLANEFREIGHT.LOCAL. From this Windows server, I am trying to find the domain controller. I have tried echo %LOGONSERVER%, Get-ADDomainController -DomainName INLANEFREIGHT.LOCAL, nltest /dsgetdc:INLANEFREIGHT.LOCAL, but none of these give me the Domain Controller.

eager ledge
#

Can anyone help me on how I can find the domain controller

normal sand
next bronze
eager ledge
normal sand
acoustic owl
eager ledge
next bronze
normal sand
next bronze
#

if you have the domain name you can try nslookup

normal sand
eager ledge
glass quail
#

Module: Broken Authentication
Section: predictable Reset Token
I have translated the time that it shows me to epoch time with the milliseconds then hashed it with md5 and tried the script that comes with the section none of them are working. Do I have do something with the script?

normal sand
eager ledge
acoustic owl
next bronze
#

also nltest should do it

normal sand
# acoustic owl Then search for vHosts

Sorry, but could you confirm something for me? This command has the same functionality as my previous ffuf command?
||```
gobuster dns -q -d "runner.htb" -w "/usr/share/SecLists/Discovery/DNS/subdomains-top1million-20000.txt

eager ledge
normal sand
next bronze
#

or just nslookup and it should tell you the DNS server

eager ledge
#

Is it possible that I am not getting the domain controller due to connectivity issue?

#

Like the Windows server I am currently accessing is not connected to DC at the moment?

next bronze
#

maybe

#

if all else fails, sweep the subnet shruge

eager ledge
#

How do I "sweep the subnet", you mean like ping sweep?

next bronze
#

ping, nmap, netexec, etc

next bronze
#

read #welcome so that you can post images

slender wraith
#

Can anyone help me with an error i encounter while trying to do the Print Spoller and NTLM Relaying, please. I want to use the impaket-ntlmrelayx followed by dementor but when i try to do so the output from the impaket-ntlmrelayx is the following: ^^^. Thanks!

next bronze
normal sand
#

I'm doing a box on the main platform and currently trying to perform subdomain enumeration. I used the following ffuf command and found a subdomain.

ffuf -w subdomains.list -u http://10.10.11.13 -H "HOST: FUZZ.box.htb" -fs 154

Does anyone know how I can do the same using gobuster and/or dnsmap?
I have tried the following gobuster command but it did not output the subdomain. I have confirmed that the subdomain I'm expecting in the output is part of the wordlist (subdomains.list)

gobuster dns -d box.htb -w subdomians.list
acoustic owl
#

With your ffuf command you check the vHosts.
But with Gobuster you want to query DNS

#

This is not the same thing

bold sinew
#

Module: Attacking Web Applications with Ffuf > Skills Assessment - Web Fuzzing

Currently on question 3, which states "One of the pages you will identify should say 'You don't have access!'. What is the full page URL?"

I am struggling to find it. I have plenty of valid urls which return 403 Forbidden but they apparently arent the correct answer.

This is the command I am currently using to try and find this: ffuf -w /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://archive.academy.htb:35303/FUZZ -recursion -recursion-depth 2 -e .phps -v

Am I doing anything wrong here?

normal sand
#

What other tool would you recommend for subdomian enumeration?

timber hatch
#

in the module windows priv escaltion pillaging i need to transfer the file cookies.sqlite to my host. i tried scp and sftp but it does not work. how can i transfer the file?

autumn pilot
#

use one of the methods from File Transfers module

#

Also, if you are on a windows host and neither SSH/FTP related service is installed why would you rely on them?

timber hatch
#

the fuck is lagging, just awful...

acoustic owl
acoustic owl
timber hatch
#

i try to trasnfer it with smbshare. but it does not work. i started the share, try to copy after the command the file has size 0 at my windows machine and at my linux machine also size 0

#

not my strenght to transfer files😂

muted kindle
timber hatch
#

you are right, lol missed the file. stupid 😉

cunning cape
#

having trouble transferring shadow.bak and passwd.bak to my attack machine. struggling as the host doesn't have simple-server, uploadserver etc on the machine. I'm connected via ssh but it keeps timing out when I try to use scp to transfer. I figured I could just take the code for simpleHTTPserverwithupload.py from github and using vim save it on the machine as simpleHTTPserverwithupload.py and then move it to /usr/bin/python3 but I don't have the permissions to move it there. any ideas?

Edit: Got it, I had been using scp on the victim machine instead of my attacking host

rustic sage
#

I'm revisiting the pivoting skills assessment. I can't figure out why this wont work from my VM but tested with support via pwnbox the proxychains RDP worked. I can proxychain scan the target box. Everything is setup through msf and is in line with solutions for it to work
proxychains nmap 172.16.5.35 -Pn -sT -p3389 PORT STATE SERVICE 3389/tcp open ms-wbt-server

xfreerdp fail even after accepting the cert

#

Anyone have a similar issue?

past kite
#

how to tell the admin about error? Login Brute Forcing, last Skills Assessment, I can't connect to ip-addr. I tried on my VM and PWNBox

bright coral
iron solar
past kite
#

I simply copy and paste

next bronze
bright coral
dense pollen
#

Are links to modules/paths broken for anyone else?

bright coral
rustic sage
#

@bright coral /timeout:10000 /network:broadband
works

#

What a headache this has been

dense pollen
past kite
past kite
hexed lintel
#

can anyone help me,
session creates for a second and then powershell gives error

bright coral
shut quest
past kite
#

ahahahah, okay, thanks. brothers))

worthy tartan
#

hello, total noob here. Anyone can tell how I can find the TARGETURI to set on metasploit ?

shut quest
hexed lintel
worthy tartan
#

It's the getting started module*

fathom pendant
#

it's fine at its default

#

but in general to set an msfconsole option for an exploit it's set OPTION value

#

a lot of times you only need to worry about;

worthy tartan
#

doesn't that mean I need to set it?

fathom pendant
#

RHOST, RPORT, LHOST,LPORT

fathom pendant
#

if it was blank, it wouldn't be set

#

/ means http://10.129.9.76/ is the base path

worthy tartan
#

oh ok sry I thought you'd need to have the name of a directory of some kind. I'm gonna try going forth with that. Thank you very much for your clear answers

fathom pendant
#

if you set /pages/ then it would be http://10.129.9.76/pages/

fathom pendant
#

nothing beyond surface level digging

worthy tartan
#

What should I type to change the LHOST adress in the payload?

#

Is it "set payload LHOST 'adress'" ?

fathom pendant
#

LHOST is YOUR tun0

#

you can simply do set LHOST tun0

worthy tartan
#

Ok thanks !

fathom pendant
#

and metasploit will do the rest

#

L = listening

#

R = Remote

worthy tartan
#

understood

inland radish
#

Hello all, I am in the “Network Enumeration with NMAP” module in the medium lab section. My initial scans were being filtered and I took some time to research issues I was having with spoofing the source IP. About 45 minutes later I returned to find that my scans are no longer being filtered and I answered the question for the section. Was this intended at the beginning or did I glitch it out by waiting somehow?

worthy tartan
#

I have another question, i've been running a -p- nmap and it's been half an hour, is this normal or did something bug ?

shut quest
worthy tartan
#

will do

fathom pendant
#

with Syn-scans they can get caught in loops and auto-readjust their retry and timers

#

on default

#

-T4 sets a limit iirc

#

but it's more aggressive timing overall

hexed lintel
inland radish
# fathom pendant don't spoof

I got that off of the Google results. I was confused because my original scan “sudo nmap <ip> -p53 -Pn -n” was filtered when I first tried, then 45 minutes later was giving me the flag.

fathom pendant
#

sometimes it's just dumb

#

but spoofing isn't required

#

i didn't have to spoof at all

#

it came back filtered because you got "blocked" which sets like a 5-10 minute timer to try again

inland radish
#

Ok cool, so I didn’t circumvent the lab’s intent. Thanks!

fathom pendant
#

even the official guide doesn't spoof

#

although it may have helped to do -sU

marsh echo
fathom pendant
#

for the hundreth time regarding this

marsh echo
#

thx

warm portal
#

SQL injection module might need a look. Skills assessment took 3 resets to get a system that had a non-empty flag file

bold sinew
hexed lintel
fathom pendant
#

nope

#

i don't think i ever messed with the socat one

worthy tartan
#

does anybody know why it won't let me wget linenum ?

fathom pendant
#

or if I did i blocked it from my memory

fathom pendant
west dove
#

Hey can anyone help with the web attacks advanced file disclosure? Not sure how to create the dtd, I've read through the module sooo many times I dont get it!

warm portal
#

you might want to check your extensions; also 403 is not the same as a page saying you dont have access.

fathom pendant
#

/ is the root of the filesystem, it is a write-protected access

worthy tartan
#

how do I know where I should write it ?

fathom pendant
#

well /tmp/ is always world writeable

worthy tartan
#

ok thanks i'll try that !

warm portal
bold sinew
fathom pendant
#

also as Rad said, your ext list is missing some extensions

bold sinew
fathom pendant
#

just -mr "Text/regex"

fathom pendant
#

since you have the text you're looking for...

bold sinew
#

should be able to filter results by that then

fathom pendant
#

also as an fyi

#

whenever you get a bunch of results

#

you should probably be filtering out those response sizes

#

since they're all gonna be the same size, it can be safely assumed it's a default page of sorts

worthy tartan
#

when I am here, is there a way to search for a file called user.txt through a command line instead of having to explore each directory ?

worthy tartan
#

thank you !

urban fable
#

in the pivoting skills assessment, what did you guys use to crack the NTLM hash of user vf...., I got the lsass.dmp file, tried using rockyou.txt and mutated password list from the password attacks module, also tried xato-net-10-million

bright coral
fathom pendant
#

sometimes it's right in front of you and you miss it

urban fable
#

hmmmm

#

found it lol

#

I just had to re read the pypykatz output

steady plume
#

Hi there! I am working on Cracking into Hack the Box skill path and I got stuck at Public Exploits exercise. Is this a correct place to ask for direction to help me get unstuck? 🙏

fathom pendant
#

getting-started?

#

if so: just view the webpage 😄

#

then from there you should be able to search for an appropriate exploit 😉

steady plume
#

Yes Getting Started Cracking into hack the Box...Topic is Public Exploits

fathom pendant
#

as I said

#

just view the webpage

#

and go off that info

#

You don't need to specify the path you're doing btw

#

just module name and section are enough

#

as modules aren't directly tied to their paths

#

you can even do a module without being enrolled in a path

steady plume
#

ok, thanks! Will try to go off from here. Because I used nmap, whatweb and curl to get some info, so I could search the exploit using msf, but I couldn't get anywhere

fathom pendant
#

well because you're likely looking at the wrong thing

#

the webpage directly tells you what plugin is being used

fathom pendant
fierce mason
#

in the dnsadmins section on windows privilege escalation, i had gotten the netadm user into the domain admins group, but i wasn't able to read the flag.txt until i opened another session using evil-winrm, is there a reason for this

gilded patrol
#

For the error when using hashcat:
'CL_BUILD_PROGRAM_FAILURE' and 'Device #1: Kernel /usr/share/hashcat/OpenCL/shared.cl build failed.'

I found this comment on a page and it worked for me:
Using Hashcat on a VM with your AMD CPU, you just need to install POCL by using the following command : sudo apt install pocl-opencl-icd. It works just fine!!

steady plume
bright coral
fathom pendant
steady plume
fathom pendant
#

well, read the file it downloaded -- and figure out what you might need to change

#

the question tells you where the flag is

sly nebula
#

Use the VM in the "Introduction" section (EVASION-DEV).

steady plume
sly nebula
#

I am having this exact problem. Did you find out what is wrong?

sterile epoch
fathom pendant
#

just a thought though

#

given the error being "file.exe" does not exist

sterile epoch
#

can I compile it in pwnbox?

fathom pendant
#

¯_(ツ)_/¯

#

it looks like it's meant to be compiled in windows

#

i suggest adding the file(s) to an exclusion list for defender

sterile epoch
#

ok

#

I added the folder to the whitelist but the result was same

fathom pendant
#

you may have to re-download the files

#

or save and try and recompile

stable bone
#

literally 70

fathom pendant
#

¯_(ツ)_/¯

fathom pendant
stable bone
slate zinc
slate zinc
#

its 70

rustic sage
#

Bro they are credits

stable bone
#

told you it was 70

slate zinc
#

one small issue

rustic sage
#

Not boxes

slate zinc
#

they are cubes
not boxes

fathom pendant
#

cubes

stable bone
#

oh so whats a box

rustic sage
#

Whatever

rustic sage
fathom pendant
#

boxes are the main lab site's machines

rustic sage
#

Made purposefully vulnerable

fathom pendant
#

that's what's referred to as a box

rustic sage
#

For you to hack

slate zinc
fathom pendant
#

this is also a box

stable bone
#

mine doesnt show machines... do i have to pay or sum

slate zinc
#

bro please spare us some slack and watch a introduction to htb video

rustic sage
#

No

fathom pendant
rustic sage
#

You need to sign into HTB machines

slate zinc
#

marcie how do u do it 😭

fathom pendant
stable bone
slate zinc
stable bone
#

guys i already knew this ik everything remember

fathom pendant
rustic sage
#

Wait is this free? The academy?

#

I never tried the academy

fathom pendant
#

tier 0 modules are the free modules

#

after that it's a pay to learn system

rustic sage
#

Oh ok

fathom pendant
#

relatively affordable compared to most other platforms ¯_(ツ)_/¯

stable bone
sterile epoch
fathom pendant
rustic sage
#

Do you increase your rank by doing academy as well?

stable bone
stable bone
fathom pendant
rustic sage
#

Oh ok

fathom pendant
#

they are separate sites, so progression is not linked in anyway

#

rank on HTB is a reflection of %active content you've done at some point

stable bone
#

marcie use your skills to link them

fathom pendant
#

not something I can do ¯_(ツ)_/¯

stable bone
#

arent you a mod?

fathom pendant
#

that's up to HTB if they even want to implement something like that

#

even if I were mod, still nothing I can do

rustic sage
#

" ¯_(ツ)_/¯" I am saving this

fathom pendant
#

mod != staff

fathom pendant
stable bone
#

(╯°□°)╯︵ ┻━┻

fathom pendant
#

┬─┬ノ( º _ ºノ)

rustic sage
#

¯_(ツ)_/¯

fathom pendant
#

calm your tits my dude

#

i thought you were gonna go play Valo

stable bone
slate zinc
#

hey its serious discussion for off topic move to #general

stable bone
fathom pendant
rustic sage
#

╱╱▏┈┈╱╱╱╱▏╱╱▏
▇╱▏┈┈▇▇▇╱▏▇╱▏
▇╱▏▁┈▇╱▇╱▏▇╱▏▁
▇╱╱╱▏▇╱▇╱▏▇╱╱╱
▇▇▇╱┈▇▇▇╱┈▇▇▇╱

fathom pendant
#

everyone's a dude

#

he's a dude, she's a dude

stable bone
#

dude thats deep

fathom pendant
#

anyway, we're straying far off-topic

rustic sage
#

Back to #general I go. This isnt my territory

icy marsh
#

footprinting - DNS - What is the FQDN of the host where the last octet ends with "x.x.x.203"?
i'mn stuck in this question. I'm bruteforcing subdomains for 30 minutes using wordlist /opt/useful/SecLists/Discovery/DNS/subdomains-top1million-110000.txt but that one not came ?

fathom pendant
#

make sure you have an accurate list of base subdomains to go with

wicked oxide
fathom pendant
#

dig axfr inlanefreight.htb @target_IP < start with this to get your subdomain list

wicked oxide
fathom pendant
finite acorn
#

hey y'all. i'm waiting for the support team, but I figured throwing my question in here may help as well. I'm on starting point, Tier 2, Archetype and trying to execute the sudo python3 -m http.server 80 and getting an OSError: [Errno 98] Address alrady in use. Any way to get past that without killing the machine?

fathom pendant
#

It's that simple

icy marsh
finite acorn
fathom pendant
fathom pendant
sly nebula
fluid basin
#

In the 1st skills assessment for Attacking Common Apps I managed to get to basic command execution via following a blog post, however my shell only executes the dir command. I tried specifying the full paths of the binary I want to execute, however nothing of that nature works for me. Any tips would be appreciated

#

btw I also have tried url encoding my payloads

oak hollow
#

Erm, I think I might’ve found an error for the flags on vhosts inside of information gathering, where a flag 4 string is actually submitted and marked correct on flag 3. So the flag actually has the HTB{flag fourSOMESTRINGHERE} should I put it in erratum even tho it would share the flag?

fathom pendant
#

It's not really an error since you found it on the flag 3 host

#

Most people don't pay enough attention anyway

oak hollow
#

Ah yeah it threw me off - cause I submitted to flag four thinking the string was a true flag 4 flag

#

the goof - thank you 🙂

#

as long as its intentional!

unreal seal
#

Investigate all records for the domain "inlanefreight.com" with the help of dig or nslookup and submit the one unique record in double quotes as the answer.

I am trying to solve this question.
I have found that is ||SPF|| record.
but it is not being accepted as answer.

Am i missing something? i have enumerated all other records and found nothing interesting.

fluid pine
#

can yall help me?

#

in here

fathom pendant
fluid pine
#

i just got connected with starting point vpn

fathom pendant
#

Well generally you want to connect in a linux vm via the command sudo openvpn <file>

#

Also this channel isn't for starting-point machines

fluid pine
#

oops

fathom pendant
fluid pine
#

im sorry

fathom pendant
#

There's also a help article related to getting connected

fluid pine
#

oh

#

i couldnt connect the one for machines

fathom pendant
vernal hamlet
#

Hi

soft plume
#

@fathom pendant sorry for ping, but is there any way I can make the xfreerdp connection not be so bad? I've tried pwnbox, different regions, new vpns. Every single time it'll first start blue screen windows tghen freeze and close after like 20 minutes, then it';ll open and freeze on desktop. It just keeps freezing and disconnecting.

fathom pendant
#

Otherwise contact support my guy

vernal hamlet
#

im in Attacking LSASS Password Attacks and im trying To Solve This Question ( Apply the concepts taught in this section to obtain the password to the Vendor user account on the target. Submit the clear-text password as the answer. (Format: Case sensitive) ) i tried everything Possible after Creating dumpFile For The LSASS and Transfer it to my Local Machine i tried to use pypykatz to extract The Credentials im only Getting Errors even after reinstall the tool

#

i only get few lines of INFO Then alot of errors

split glade
vernal hamlet
#

i dont think i can share a screenshot

#

How Can i share a screenshot ?

#

This is the command i used ( pypykatz lsa minidump /home/kali/Desktop/htb/HackTheBoxAcademy/Modules/PasswordAttacks/AttackingLSASS/lsass.DMP )

fierce mason
#

how long is AEN blind supposed to take on average

split glade
#

The command is the right one, although I see .dmp in lowercase

vernal hamlet
fathom pendant
wanton idol
#

for detailed walkthrough in the report do u also include the way u got a foothold into the internal network instead of starting from the internal network?

soft plume
fathom pendant
wanton idol
#

yeah it is, i was just following the cpts format and they didnt say include the foothold or anything

fluid pine
#

hey i dont get how to work this question: Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.

wanton idol
#

just straight into internal

#

so i was double checking

fathom pendant
#

Aka use nmap scripts

fluid pine
#

--script vulns

#

?

fathom pendant
#

¯_(ツ)_/¯

#

Don't ask. Just do

#

I will not give a yes/no answer, work it out on your own

rustic sage
fluid pine
#

i got an "answer"

fathom pendant
#

Try, fail, ask better questions

#

Also sometimes some environments work better in pwnbox than vm

#

Same exact syntax, tools, etc

fluid pine
#

so i did smth and i got smth like this http-enum: /robots.txt

#

nmap 10.129.165.146 -p80 --script vuln <--this is what i did

#

this was my output: ```Starting Nmap 7.93 ( https://nmap.org ) at 2024-06-06 20:00 BST
Nmap scan report for 10.129.165.146
Host is up (0.075s latency).

PORT STATE SERVICE
80/tcp open http
| http-enum:
|_ /robots.txt: Robots file
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-vuln-cve2014-3704: ERROR: Script execution failed (use -d to debug)

Nmap done: 1 IP address (1 host up) scanned in 37.97 seconds```

sterile epoch
#

How do I gain a ssh shell to my pwnbox instance? before the credentials file used to have the host address now I cannot find it. I want to transfer binaries from my local machine to pwnbox

fluid pine
#

im lost 😭

#

idk where to go from that output

sterile epoch
fluid pine
sterile epoch
#

look at the task at hand

#

then think what you need to get the answer

fluid pine
#

ok i need to find a flag that one of the services contains. now how do i look and see which one has the flag

sterile epoch
#

whats the task?

fluid pine
#

Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.

sterile epoch
#

well when you do not know what to look for try looking into everything

fluid pine
#

idk how to look in them

sterile epoch
#

now that you have to ask google

fluid pine
#

oh

#

ok well ill come back to this later then

fathom pendant
fathom pendant
#

Port 80 is default http yeah?

fluid pine
#

yh

fathom pendant
#

So

#

Did you try visiting the page itself

#

Since it's saying there's a robots.txt page

#

http://ip/resource

fluid pine
#

so for me... http://10.129.165.146/robots.txt??

fathom pendant
#

Don't ask me

fathom pendant
#

Do it and come back if it doesn't work

sterile epoch
#

i tried using the public ip

fathom pendant
#

And did you use the creds in the pwnbox credentials text file?

sterile epoch
#

yes

fluid pine
#

FINALLY

#

thank you so much Marcie

fathom pendant
sterile epoch
#

any other way to transfer binaries to pwnbox

fathom pendant
#

You're sure the password is on your clipboard when you paste it

sterile epoch
#

let me try again

fathom pendant
sterile epoch
#

for the skill assessment of windows priv esc I have to build them

#

using visual studio

fathom pendant
#

Well; the creds on the desktop should work

#

¯_(ツ)_/¯

#

If not then message support, I can't help you with this my guy

sterile epoch
#

any tips with this exploit?

#

this was the one shown in the module

fathom pendant
#

No idea

#

Haven't done that module

sterile epoch
#

ohk

neon wadi
fathom pendant
#

Also using msf as your proxy connection is a pain

#

Is msf using your tun0 ip for it's listening/forwarding?

neon wadi
# fathom pendant Is msf using your tun0 ip for it's listening/forwarding?

proxychains msf sends the traffic over tun0: [*] 172.16.5.19:3389 - Detected RDP on 172.16.5.19:3389 (name:DC01) (domain:INLANEFREIGHT) (domain_fqdn:inlanefreight.local) (server_fqdn:DC01.inlanefreight.local) (os_version:10.0.17763) (Requires NLA: No). proxychains xfreerdp connects over tun0 through the Ubuntu jump host to the Windows host. The only thing not working is proxychains nmap.

fathom pendant
#

¯_(ツ)_/¯

#

Nmap sucks over proxy anyway