#modules

1 messages · Page 276 of 1

idle sigil
#

Hey can someone help me with this new question "What is the API key the inlanefreight.htb developers will be changing too?" from Info Gathering module please? Ive spent the whole day on this T_T I've gotten to the 2nd enumeration part and cannot seem to use any tools / crawlers on the subdomains

royal python
#

guys i need hellp i can't desative a machine on hack th ebox

#

and i am vip , pleaz helpe me , i can't delete this account

muted kindle
#

ping is not reliable way to determine if the machine is online or not, try to port scan it and if the supposed port is closed then reset the target
If it’s still not working then contact support

next bronze
#

you got it?

sterile solstice
#

using the pwnbox and its working but annoying i cant get my own VM to connect....will figure it out another time lol

sly kelp
#

is there malware development module coming in future?

fickle thicket
#

anyone knows for the akagi64.exe in UACMe . how to know which number to use?

#

for example .\Akagi64.exe 61 powershell.exe . like how to know which number to use? whr can i find out

next bronze
#

just test them

#

they have a list of which one works

rustic sage
#

Wow, finally finished that API key question

#

ohhh that's not the answer interesting

#

We continue on then

slender wolf
#

in the Footprinting easy lab in htb acadmy how did we get the username (based on the youtube videos on the walk thorugh) on port 2121. I did a nmap scan and was not sure on how to procede seen 2 video and both login into ftp on port 2121 with the username ceil. right after doing a nmap scan

fickle thicket
slender wolf
fickle thicket
#

the number which is the key

umbral fulcrum
#

Hey guys did u notice the updated "Information Gathering - Web Edition" module ?

is it buggy or it's just for me?

fickle thicket
next bronze
#

yes

umbral fulcrum
#

it showed my old answers as correct (which make no sense)

#

this isn't an integer ....

acoustic owl
#

This is a known problem

umbral fulcrum
acoustic owl
#

The answers are not changed, but the questions are changed. Therefore the answer is no longer correct

umbral fulcrum
#

but if I want to do it now I can't ...

wraith pelican
#

you can do the last question and you'll need most of the other ones to complete it

acoustic owl
#

As far as I know, HTB is looking for a solution to be able to delete the answers, but you will no longer receive cubes when submitting new answers. You already got them the first time

muted jacinth
# next bronze you got it?

not at all but i'll keep on trying i guess, the worst fucking part is that the labs i so buggy bro i swear the connections keeps on failing and stuff

silver iris
#

Hey guys,

i have a question about mimikart in evil-winrm. When try to run anything, i get a lot of this:
mimikatz #
mimikatz #
mimikatz #
mimikatz #
mimikatz #
mimikatz #
mimikatz #
mimikatz #
mimikatz #

Anyone know, what this means and how i can use it properly?

silver iris
autumn pilot
#
.\mimikatz.exe "command" exit
dim wolf
#

^

silver iris
#

I love you guys 🙂

next bronze
#

if you're still stuck dm me what you have done

next bronze
muted jacinth
next bronze
#

yes

muted jacinth
#

okay at least i'm going the right way, ty dude i'll stop bother you

umbral fulcrum
wraith pelican
clever lotus
#

is it just me or vms on academy lose connection every 2-3 mins and then connect again?

slender wolf
#

hey guys in the Footprinting easy lab in htb acadmy how did we get the username (based on the youtube videos on the walk thorugh) on port 2121. I did a nmap scan and was not sure on how to procede seen 2 video and both login into ftp on port 2121 with the username ceil. right after doing a nmap scan

sterile solstice
#

"Additionally, our teammates have found the following credentials "ceil:qwer1234", and they pointed out that some of the company's employees were talking about SSH keys on a forum."

umbral fulcrum
#

Someone did the new Information Gathering - Web Edition module > Creepy Crawlies section and can give me a bit of a nudge on it ...

not sure what I'm missing...

keen valve
#

I'm at the Windows PKI - ESC1 module and I had to RDP through 3 machines, I spent hours with this slow connection

placid quest
#

@umbral fulcrum same with me I am not understanding that section

old oasis
#

if you installed scrapy properly it should work

umbral fulcrum
umbral fulcrum
old oasis
main spear
#

Hello, i'm doing the module privilege escalation for windows and on the part about bypass UAC, i don't understand how to find the technique which will works on the specified build version ?

#

Like, how on the repo UACME i find the correct technique for my build ?

next bronze
umbral fulcrum
silver iris
#

Hey guys i need a sanity check.
I´m currently doing the AD- Skill Assessment Part 2.
I got a systemshell in multiple ways on SQL01. Also got one as ||user administrator||.
||But i cant get any usefull credentials with mimikatz or crackmap.||
I checked and the solutions use an identical aproach to the one (of multiple) that i used but i dont get the password i´m supposed to get.

fickle thicket
#

sorry, after escalating privilege i used mimikatz

#

u will get the mssqlsvc credential

silver iris
#

Or can i pth`?

fickle thicket
#

that's weird. i got the credential.

#

the actual password

silver iris
#

yeah solutions got them aswell. Was banging my head against the wall about this step for 3 days, since i always dont get the password. And it´s not crackable either :/

next bronze
#

look elsewhere besides LSASS

#

logonpasswords is not the only thing mimi can do

silver iris
#

ok, i will look onward, but the solutions also used this so i assumed it was correct.
I will delete my output, for spoiler reasons.

rustic sage
#

@low girder yo

fickle thicket
rustic sage
#

I was asked to ping Tejas in the channel, I'm not violating any rules

low girder
#

thanks

#

I'll DM

next bronze
silver iris
#

Ah ok got it, thanks 🙂
But i still wonder, why the solutions didnt work for me

next bronze
#

where in the solution did they say to dump lsass tho

silver iris
next bronze
next wind
#

Yep

silver iris
next bronze
#

Yea that's where that password is stored

left topaz
#

i have question from SEIM fundamentals modules that is : if it is available, so that it includes failed logon attempt data where the username field contains the keyword "admin" anywhere within it. What should you specify after user.name: in the KQL query? .. Plz give me hint about this..

autumn pilot
#

keep it simple and you will get it

#

do not overcomplicate it

left topaz
#

i had tried simple admin , wild card , with bol and evet code but idk where i am wrong

lone ferry
#

Information Gathering Web Edition- The updated Skills Assessment spawns a server pointing to upcloud I’m pretty sure we’re not supposed to attack. Any clarification would be excellent

thorn hawk
#

Hello to all. I am stuck on the skill assessment for SSRF module. I have recon the target and it has provided me with so many open ports and services. I went through one by one but couldn't find a target to concentrate to perform SSRF. Due to this I haven't identified what type of SSRF to perform (normal, blind, ssi or ssti). Any hint on how to find a vulnerable target to concentrate on?

#

mainly I have found different applications with different technologies. I suppose I have to just continue searching one by one for a potential entry. Any hint is welcome. thank you

potent thorn
#

In the reporting section, how would we figure out the cvss score for a technique we use? I havent seen anywhere where it talks about scoring in much detail

wraith pelican
lone ferry
lone ferry
wraith pelican
lone ferry
lyric ingot
#

Hey all. I'm on the last question of the last section of Intro to Assembly Language. It says, "The above server simulates a vulnerable server that we can run our shellcodes on." I'm unclear as to what that's referring to. I assume it's the Pwnbox. When I spin that up it's just a vanilla VM. Am I on the right track?

wraith pelican
lyric ingot
wraith pelican
#

in the question section, where it always is, it should be there

lyric ingot
#

Am I allowed to post a screenshot?

#

And now I see it. smh.

#

I swear it wasn't there before. Y'all got a wall of shame?

#

And just like that, I wrapped up a most excellent course. Thanks, @wraith pelican !

wraith pelican
worldly pagoda
#

I have trouble with HTB account linking, which room is right to post such problems?

acoustic owl
worldly pagoda
#

Support is not helping.. The support person disappears for hours

acoustic owl
worldly pagoda
#

Thanks

spark osprey
#

nvm solved

thorn hawk
fathom pendant
thorn hawk
fathom pendant
#

That doesn't matter

#

If it's public_ip:port, you're only attacking public_ip:port and ignoring other ports

#

Those other ports were likely hosting services for other modules that another person may be working on

tardy jungle
#

Hey guys, im stuck at “intro to whitebox” skills assessment, and kinda need a small push, anyone successfully completed this module?

sly nebula
#

Hello, i need a sainity check on the very last step of the Advanced SQL Injections skill assessment (RCE); is anyone available? I'll show what I have tried so far. Thanks.

dusky lake
#

I am tring to use https://web.archive.org with hackthebox.com on 8th August 2018. I get redirected to a godaddy page...Trying to find how many labs they had on that date for a module question.

wraith pelican
dusky lake
#

Worked great thank you

marsh fulcrum
#

Hey, I'm doing the windows attacks & defense modules but some labs when I'm trying to RDP I receive the message "The trust relationship between this workstation and the primary domain failed", anyone know the cause of the problem and how to fix?

narrow solar
#

i am super confused at Windows Privilege Escalation Skills Assessment - Part I, using ||JuicyPotato|| trying different ||CLSIDs||, according to references i have to use them with the {}, but i keep getting Wrong Argument error, without them i get "COM -> recv failed with error: 10038", i used ||test_clsid.bat|| to validate them

wanton idol
narrow solar
fathom pendant
#

Also make sure you're running it on the right host

#

This is for the SQL01 admin yeah?

wraith pelican
narrow solar
fathom pendant
#

Oh wait I'm thinking a diff module

#

Long morning lol

narrow solar
fathom pendant
#

I'm used to people yelling about the ADENUM module

narrow solar
fathom pendant
wraith pelican
narrow solar
next bronze
#

that's a different issue now

#

specify -l

wraith pelican
narrow solar
#

it worked finally 🥲 thanks so much guys, that was a long day 😂 i hate this ohpe guy, why didnt he just said so

next bronze
#

a lot of the tools are down to you to rtfm

wraith pelican
#

congrats! what was the issue?

narrow solar
#

in the readme it didnt mention the quotes 🙆‍♂️

marsh fulcrum
next bronze
#

you're using powershell, ps and cmd interpret some characters differently

narrow solar
dusky lake
#

Currently working on: https://academy.hackthebox.com/module/144/section/1311

The questions seem to suggest looking at the robots.txt file to find the path to a admin page revealing an answer.

I have tried the obvious going to inlanefreight.htb/robots.txt with no luck
I have also used gobuster vhost -u http://inlanefreight.htb:34968 -w ./SecLists/Discovery/DNS/subdomains-top1million-110000.txt -t 50 --append-domain which found || web1337.inlanefreight.htb ||

no luck going to /robots.txt from there either.
I have tried crawling both pages with ReconSpider but it returned nothing

anyone have a suggestion?

silk anchor
#

Any nudge for a foothold on the Attacking common services medium lab?

||So far I've only managed to extract some info from dig which looks like there is an internal ftp server and nfs share based off the domains it found. Checked all the domains and found nothing.

Tried brute force on ssh (zzzzz),pop3/pop3d,ftp with the normal user list and made a @inlanefreight.htb list for pop3. Tried normal pw list and rockyou.

Tried manually checking accs in pop3 (Doesnt work)

Tried ftp bounce but I need auth, I see that its running on port 2121 and seems to be ccproxy ftp? Seems like there is a couple vulns for it but didnt find anything useful and it seems out of scope for the module.

I did find something running on port 30021 but its "tcpwrapped" so wont give out any info.||

I feel like I should've found a username or something sadglas

wanton idol
dusky lake
fathom pendant
wraith pelican
wanton idol
fathom pendant
#

You don't need to bounce @silk anchor

fathom pendant
#

But you can likely guess what service is running on that extra port

fathom pendant
# dusky lake

Also keep inlanefreight.htb in the hosts file for that entry

dusky lake
#

I tried with it and then removed to see if it made a difference. no change

fathom pendant
#

Also make sure http://

wanton idol
#

^

dusky lake
#

it is there just diapears with firefox when you hit enter

wanton idol
#

manually type it

dusky lake
#

I promise you its there

wanton idol
#

well then restart the box if u say its using http instsad of https

dusky lake
#

I'll reset it then try again and report back. both http and https not working

fathom pendant
#

Don't forget to update your hosts file with the new ip

wanton idol
#

also add the inlanefreight.htb to hosts

wanton idol
#

ah

dusky lake
#

LOL yes resarting it and it worked fine

#

thats some bs spent like an hour on that

wanton idol
#

yessir

#

it happens lol

dusky lake
#

Moving on

#

Thanks for the help.

fathom pendant
#

Likely your bruteforcing DoSed it

dusky lake
#

Intresting. Would it still be trying to answer all the queries or just overloaded and shut down?

fathom pendant
#

Just shut down

#

A DoSed server can't respond to queries

#

It'll just respond "unavailable"

wraith pelican
livid talon
#

guys i cant text on geeral chatt?

fathom pendant
safe yoke
#

Hey can anyone help me to change to the student email in academy, i have a issue cuz i have my account linked in HTB and i have my personal email in the main account and i need to change the academy account's email to my student email for the student subscription and i have no idea what to do

fathom pendant
#

Message support

safe yoke
#

Thankyou will do

scenic haven
#

after some try and error, i finally made it

graceful mortar
silk anchor
dusky lake
wanton idol
fathom pendant
#

Using first letter or replacing [subdomain].inlanefreight.htb works just fine to get your point

#

And /dir

dusky lake
#

Okay I havent use a fourm or anything before my bad

fathom pendant
#

It's basics, try not to spoil anything that could directly lead to answering the questions such as direct usernames/passwords, subdomains, directories. Obfuscate if it's necessary

#

Username: a*
Password: b*
Subdomain.inlanefreight.htb/hidden_dir

#

Just basics to avoid spoiling it for others because spoiler text honestly does nothing

dusky lake
slate hollow
#

I am on module 2 and attempting to VPN in from my Kali Laptop.

With:

  • TCP 443 Openvpn config file, I get 1000+ ms on ping.
  • UDP 1337 I am averaging around 350 ms.

Already verified no other OpenVPN is open. Speedtest with OpenVPN off, I have 413 Mpbs down and 235 Mpbs up

wanton idol
wanton idol
slate hollow
wanton idol
#

and whats the problem with that

slate hollow
wanton idol
#

well you can always change vpn connection to like EU and try again not really sure what we can do lol

fathom pendant
#

Otherwise message support

#

sometimes some vpn regions are just slow (traffic is high due to the amount of users) ¯_(ツ)_/¯

clear zephyr
#

I got a unique problem. I am able to get a meterepter session but I am not able to get a shell. I think it has something to do with my proxychains configuration

fathom pendant
#

If you get a session you can drop into a shell

fathom pendant
#

^

#

But if you're not getting a session, make sure all variables are set properly

#

It also helps if you provide the module and section name you're working on. kek

dusky lake
clear zephyr
fathom pendant
#

Did you press enter after a minute?

#

Did you try changing vpn regions and trying again

fathom pendant
#

Did you pray to God for the answers

wanton idol
#

u got jokes today XD

clear zephyr
heady sleet
#

Hi im doing the file inclusions module and on the Log poisoning sessions i have manage to RCE using the PHP session cookie vulnerability, when i run the pwd command the output is not accepted by the exercise

#

is anyone else run a similar issue?

slate hollow
fathom pendant
#

The latency is simply the distance from your computer to the server

#

If it's stable, you can manage, if it's unstable you're gonna have a bad time

slate hollow
#

its unstable

fathom pendant
#

I.e.
200
200
1600
200
Is abnormal

fathom pendant
#

The problem is conflating latency with performance

#

The instability is known as jittering (what's colloquially known as lag)

hallow remnant
#

Can someone direct me to a resource for installing an old version of Postgresql? Namely: postgresql-server-dev-13?

I'm having a devil of a time downgrading to such a version.

slate hollow
heady sleet
#

the fact that the value of the cookie stays the same is a bit confusing

dusky lake
#

https://academy.hackthebox.com/module/144/section/1311

stuck on "What is the API key in the hidden admin directory that you have discovered on the target system?"

I have solved all other questions but this one.

I have tried many subdomain combinations looking for the hidden directory which I've gotten the name of but have had no luck. I've used FinalRecon on every subdomain looking for the hidden directory but can't find anything. Any nudge is appreciated.

muted jacinth
next bronze
muted jacinth
#

absolutly i can't find anythings really

#

no nested groups nothings with Find-interestingacl and stuff

next bronze
#

reun your collectors, make sure you captured both domains

muted jacinth
#

okay i'll try harder 😦

#

think i have it. my bloodhound was just not complete

#

makes me fart i sweaer

dusky lake
wraith pelican
dusky lake
#

I got everything else

wraith pelican
#

what have you got on that?

dusky lake
#

what do you mean

wraith pelican
#

what options did you try ?

dusky lake
#

I have tried many subdomain combinations with the few you get while bruteforcing, looking for the hidden directory that i know the name of. I get 404 error on every page looking for it. I've used FinalRecon aswell on every subdomain looking for the hidden directory but can't find anything.

upbeat oak
#

Does anyone remember in the shell and payloads module reverse shell if they had to use a different shell code then the module provided? All cool if thats the case just having issues with the one they provided

dusky lake
wraith pelican
#

not to be overly simple but when you read the skill assessment brief, i guess there is one thing you have not tried, without brute forcing

upbeat oak
#

interesting okay

dusky lake
wraith pelican
#
  • Using whois
  • Analysing robots.txt
  • Performing subdomain bruteforcing
  • Crawling and analysing results
fathom pendant
wraith pelican
dusky lake
upbeat oak
fathom pendant
#

The payload should start with powershell -e iirc

wraith pelican
upbeat oak
dusky lake
fathom pendant
dusky lake
fathom pendant
#

Oh wait @upbeat oak I misremembered this section

viral lotus
#

Not sure what channel to post this in but here goes, I have completed all the fundamental modules of the CREST CPSA/CRT path, I am looking to obviously complete it all and then do the exam, what is the best way to do it buy all the cubes upfront and go through it that way or is it more cost effective to sign up to a subscription? I am conscious with subs as I already have HTB subscription for boxes and a THM one so I am not an endless pot of money so want to gain the most, any opinions or advice is welcome many thanks

wraith pelican
dusky lake
#

dont wanna spoil here

wraith pelican
fathom pendant
#

You need to adjust the 10.10.14.158,443 to your own tun0 ip and port @upbeat oak

#

You also need to run the command in commandline/cmd not powershell

upbeat oak
fathom pendant
upbeat oak
fathom pendant
#

Reading helps 😉

upbeat oak
#

Lol definitely assumed use powershell

fathom pendant
#

Even the cmd example has the cmd background 😉

upbeat oak
#

wow it definitely does

dusky lake
viral lotus
wraith pelican
fathom pendant
#

The monthly subs are a significant discount to the relative cost of outright buying the cubes

viral lotus
#

well from what I can see the syllabus covers very cimilar to the CPTS and I have been advised to do that after doing the CREST paths (thats a big recruitment tickbox) so which membership makes the most sense? I study pretty much everyday and I have already covered things like win priv esc and linux priv esc before so it is more revisiting content specific knowledge

fathom pendant
#

Platinum sub

#

As i believe the crest pathways themselves contain t3 modules

viral lotus
#

yeah I believe it does, one off topic questiona and I will stop filling up your time 😂 the OS Fundamentals course I only have the Mac OS module left, I have used macs in the past but do not have one currently is there a way to get this a s vm or virtual instance to complete the content? If not no big deal more just a knowledge refreshing exercise

viral lotus
fathom pendant
viral lotus
#

I will stop filling space now and sort my sub out, thanks

fathom pendant
viral lotus
#

yeah I know, was more just so the incomplete course wasn't constantly staring at me haha

grizzled schooner
#

Shells and Payloads: MS17-010 keeps failing, not sure why. Have reset the host a couple of times. Originally thought it was because I had the listener on port 4444 and dropped it to 999 but still failed. Any ideas would be appreciated

fathom pendant
#

the others are actually shells or RCE

grizzled schooner
#

Ah, I think that's it, I recall that when doing ||blue|| thanks

tardy topaz
#

Need help: In module Windows Attack & Defense: Print Spooler & NTLM Relaying, q2 of the page requires connection to the kali target spawned and the DC1 at the same time. Although I'm able to both ssh and rdp to the spawned kali, I'm unable to rdp to the DC1, which was provided the address of 172.16.18.3 and using credential htb-student:HTB_@cademy_stdnt! Not sure if I'm doing it right using xfreerdp /u:eagle\\htb-student /p:HTB@cademy_stdnt! /v:TARGET_IP /dynamic-resolution , but it doesnt work ;-;

fathom pendant
#

172.16.18.3 is an internal IP address that your tun0 ip does not give access to

#

also wrap commands in backticks `like this`

grizzled schooner
#

hey marcie, just tried the other one and that didn't work lol

fathom pendant
#

make sure you set all the settings appropriately

#

not all of the exploits are created equally

grizzled schooner
#

yeah I can't seem to get it to pop

#

unless it wants me to use doublepulsar, which wouldn't make sense

fathom pendant
#

it does not

#

make sure that it's one of the exec ones

#

also sometimes resetting msfconsole gets it to work

grizzled schooner
#

well there's code and command, command injection is listed as an auxiliary lol

fathom pendant
#

(quit and open it again)

grizzled schooner
#

code injection failed

fathom pendant
#

the one that the section shows is the psexec one

grizzled schooner
#

unless it wants me to run the kernel pool corruption first and then do the psexec code execution im lost

fathom pendant
#

it does not

#

you don't need to run another module prior lol

grizzled schooner
#

I feel like I'm actually going crazy lol - I've done this machine before and I'm so lost why it isn't working lamo

fathom pendant
#

quit msfconsole then reopen it

#

and try again

grizzled schooner
#

nope - fail lol

fathom pendant
#

just spun it up

#

make sure you have the lhost and everything set correctly

#

btw; in msfconsole you can use the interface name instead of IP for LHOST

grizzled schooner
#

what port did you use?

fathom pendant
#

i didn't adjust any ports or anything like that

#

just
set LHOST tun0
set RHOST target_IP

#

what msfconsole module are you running?

grizzled schooner
#

exploit(windows/smb/ms17_010_psexec)

fathom pendant
#

then setting those variables should work

grizzled schooner
#

"Exploit completed, but no session was created)

fathom pendant
#

check options and make sure your lhost variable is correct

#

because I literally just spun the target up for that section and it worked flawlessly

#

unless you're referring to the host on the skill assessment; in which case make sure the interface matches

#

exploit completed but no session means (generally) that the exploit did what it was meant to, but your listener isn't set up right

grizzled schooner
#

no idea, reset it and it worked fine lol

#

swear im not going crazy

fathom pendant
#

sometimes just resetting it should work ¯_(ツ)_/¯

#

they can be touchy at times

smoky snow
brazen pilot
#

can someone share any discount coupon for academy full pass. Need help during crunch times.

fathom pendant
#

there's no discount coupon bro

#

also wdym "full pass"? you mean one of the annual subs?

brazen pilot
fathom pendant
#

there's no coupon codes going on for the annual subs atm

#

just gonna have to suck it up and buy it yourself or settle for one of the monthly subs

fathom pendant
rustic sage
#

¯_(ツ)_/¯

fathom pendant
#

lmao

normal sand
#

Module: AD Enumeration & Attacks
Section: Kerberos "Double Hop" Problem (https://academy.hackthebox.com/module/143/section/1573)

In other words, the account's TGS Ticket is cached, which has the ability to sign TGTs and grant remote access.

Is there a mistake in the quoted text? Shouldn't it be the other way around? A TGT ticket is the one with the ability to sign TGSs and grant remote access, no?

distant island
#

can someone help with this question in CPTS foot printing DNS Identify if its possible to perform a zone transfer and submit the TXT record as the answer. (Format: HTB{...))

cloud urchin
distant island
#

there is 3 TXT rec in the resault

#

what exactly he wants

halcyon horizon
#

can anyone help me too? how do i fix this error?

cloud urchin
halcyon horizon
#

aight

normal sand
halcyon horizon
#

i do not know where to find it. can someone hop in vc and i will start a steam ?

normal sand
#

Look near the search at the top, the machine Crafty is running.

distant island
manic spoke
#

im redoing the file upload skill assessment for CBBH and i am positive i have the correct upload directory in the url bar, can someone give me insight as to why im still getting 404 error

cloud urchin
distant island
#

and will it just give me a clear flag

halcyon horizon
#

thank you @normal sand 🙏

cloud urchin
distant island
manic spoke
#

never mind, for anyone else that comes across this, when you get past viewing the upload.php source code, it will show todays date on file name, but just know that depending on the time zone it may be a day ahead. For example it's supposed to be YYMMDD -> 240625 (todays date), but in my case it needed to be 240626 due to time zones...

native sundial
#

need help on CBBH XXS modules . it didnt give me any pop up

cloud urchin
#

you will probably get better help if you say which module, section, and question you're on and what you've tried

oak hollow
#

hey did you ever solve this.. I'm experiencing the same thing where I have the HTB{} flag but its marking it incorrect (and not the one that is previewed on the webpage) this is one thats been decoded and ran through serial.php again in a POST

#

or if anyone has done the bug bounty path with java deobfuscation im speaking of the suorce code flag

fathom pendant
#

Read the source code of the base web page

#

It's really that simple

#

It's hiding in an html comment

oak hollow
#

its an obfuscated code - it was simple - but the flag I'm trying to submit is saying its wrong

fathom pendant
#

Source code section yeah?

oak hollow
#

yeah inside the java deobfuscation module

fathom pendant
#

Go to the /serial.php page and view source

#

There is no Deobfuscation needed

normal sand
oak hollow
fathom pendant
#

A lot of the work you did is gone over in the other sections

oak hollow
#

lol im cackling at the flag for this section.. of which I DID NOT DO /secret.js was my landing LOL - thank you for giving me a swift kick back @fathom pendant

sterile solstice
#

anyone have any recommendations for SMTP ?

sterile solstice
#

im trying to finish off the Attack Common Services for SMTP. i have the user/pass but im struggling to get into the mail box

#

the telnet option is shit. its confusing AF

native sundial
#

which module, section

sterile solstice
fathom pendant
fathom pendant
#

Imap you need to prefix commands

sterile solstice
#

i managed to run EHLO inlanefreight.htb which then gave an output, but then its just slow AF

fathom pendant
#

<literally anything> <command> <args>

fathom pendant
#

Also be wary of being 2 steps ahead, it can bite you in the exam too

sterile solstice
#

faaaaar out. it just took a few minutes for the server to respond to my commands....

oak hollow
fathom pendant
fathom pendant
sterile solstice
oak hollow
sterile solstice
#

i wish HTB would provide something on how to get around in these environments. i cant even find much on google tbh

fathom pendant
#

334 btw is the authentication response code with the following text being the challenge code (aka its nothing)

sterile solstice
#

roger. will try no

fathom pendant
#

When dealing with services via CLI you'll often see a [response code] text

#

Where response code indicates the type of response generally is

#

It's not important to memorize all the codes

#

Btw it's base 64 if you want to copy/paste that then decode

sterile solstice
#

i just want to get into this damn email inbox

#

who wouldve thought breaking the user/pass would be the easiest part....

#

i tried:
1 login <user> <pass>
and got
535 auth failure.

#

so now trying:
1 LOGIN <user>@inlanefreight.htb <pass>
and got
503 bad sequence of commands

fathom pendant
#

Aka what you found

sterile solstice
#

i put in the actual user/pass. i just didnt put it into chat for spoilers

fathom pendant
#

Take out the @ domain

#

Oh btw that string you sent earlier decodes to Password

sterile solstice
#

is there another way to connect without CLI?

#

this is taking forever....approx 2mins for responses from CLI

fathom pendant
#

Also try putting the "user@domain" and "pass"

sterile solstice
#

its been 4min

fathom pendant
sterile solstice
#

might have too

fathom pendant
#

If it's taking this long, assume either target soft died, or your connection is messed up

sterile solstice
#

ive already done that just to crack the password

fathom pendant
#

If you ping the ip, do you have consistent ping?

#

Or is it random and extremely high

sterile solstice
#

nah, consistently 286

fathom pendant
#

Also might help to change from US --> EU or vice versa

sterile solstice
#

and from aus thats not bad

fathom pendant
#

Ah

#

Yeah many people from the SEA/OCE region said the pwnbox was the most manageable. Even with latency

#

But it shouldn't take 4 minutes for a response

sterile solstice
#

well i switched from my VM to the pwnbox because sometimes it just didnt work in the vm

#

and since youre learning, youre not 100% if its your fault

fathom pendant
#

Just know it was only partially your fault Kappa

sterile solstice
#

took me 3days to finish password attacks, long days too, and it turns out the machines were at fault a few times

#

hahahah yea thanks

#

i still find the lack of help for getting around in things like SMTP to be a bit annoying. googling and looking at youtube is all the same stuff. login with telnet (no auth) and write a test email. its crazy theres no other vids on using SMTP commands lol

fathom pendant
#

Also I hope it was obvious to not include the brackets with the login attempt

fathom pendant
#

You generally only interact with mail services via imap or pop3

sterile solstice
#

ok, the lack of IMAP help is annoying lol

fathom pendant
#

Well I linked to an article earlier

#

If you search in the discord from:marcielee has:link in:modules imap I've shared a few imap related articles

sterile solstice
#

thanks. i see those links

#

terminated my pwnbox and target

#

and now respawning too. hopefully it helps

fathom pendant
#

I also suggest just messing with some of the commands to familiarize yourself with them

#

Also if you're using pwnbox don't forget to turn off the vpn on your vm

#

And vice versa, they can cause issues with each other

sterile solstice
fathom pendant
#

Also as a general FYI, imap isn't case sensitive

#

Once you read the email though be prepared to chuckle before you grab the flag

sterile solstice
#

so i do AUTH LOGIN <user> and it gives back "Password:" in base64

#

so i send back the password in base64 and it fails

fathom pendant
#

It's just basically saying you didn't input the password for the login

#

The login command accepts both user and pass on the same line

#

And you do need to include the @domain for the user

#

Just checked

fathom pendant
sterile solstice
#

ive tried so many commands and it still says failed

sterile solstice
fathom pendant
#

(Without brackets)

sterile solstice
#

'503 bad sequence of commands'

#

tried with and without quotes

fathom pendant
#

Oh

#

Brother

#

Are you connecting to the imap port?

#

143

sterile solstice
#

25

fathom pendant
#

That's why you're getting errors

#

And it's not accepting the imap commands

#

Because you're on the smtp port

sterile solstice
#

damn it....i used hydra on that port and thats how i got the usr/pwd

fathom pendant
#

143 is the imap port my guy

sterile solstice
#

now im in ... f m l

fathom pendant
#

Yep always make sure to use the right port

#

Also with hydra you can specify protocol://ip if it's running default

sterile solstice
#

yea i think i specified the protocol at the end

#

but i swear it found it through p25

fathom pendant
#

Nope

#

You may have found the username through 25

#

As that's what's intended

sterile solstice
#

right

#

i honestly find imap so incredibly confusing

fathom pendant
#

It's better, structurally, than pop3

sterile solstice
#

im in the inbox but i cant even undersand how to figure out what sin here

#

or how to read anything. lol

fathom pendant
#

Just prefix <command> <args>

sterile solstice
#

yea i get that

fathom pendant
#

So, you see how there's the *[n] exists

sterile solstice
#

yup

fathom pendant
#

You can do just 1 fetch [id] body[] where id (without brackets) is a number between 1 and n

#

Or 1:n body[subject] if you're looking for subject lines

sterile solstice
#

even going through those links that wasnt clear. thank you!

fathom pendant
#

The body[] is the email itself from the headers to the message

#

You can even do body[message] to just grab the message without the headers (subject, sender, etc)

sterile solstice
#

flag submitted .... think it took me 1.5hrs for this lol.

fathom pendant
#

Speed doesn't matter

#

Understanding the material is more important

#

I could easily blitz through the remaining cpts modules using the silver annual walkthroughs, but I wouldn't learn anything

sterile solstice
#

yea i get that.

fathom pendant
#

And it'd only end up hurting me

#

I take plenty of notes to understand and solidify my understanding of content

#

As well as help out here to additionally cement the knowledge in my brain

sterile solstice
#

yes, i get that. i have a tone of notes too.

fathom pendant
#

I don't just help out of the altruistic nature of my heart, there's a selfish reason to me assisting others

sterile solstice
#

i didnt see that fetch command referenced anywhere, not even in the links. flailing around not even knowing how to get around imap doesn't really help.

#

yea, i also get that too mate.

fathom pendant
#

Though they give you the fetch ID all command, which doesn't do much

#

Or at least it only gives data about the structure of the email

sterile solstice
#

yea. and those links you sent me do the same thing of just reference a number. i had no idea i could just reference the first 1 and not have to specify anything else other than body[]

fathom pendant
#

I mean

#

It seems unintuitive until you realize how emails are stored

#

Then it's like "ohhh"

#

It fetches the id sequentially based on what's in the inbox

sterile solstice
#

well im sure ppl who have never used linux feel the same way

#

but not being able to just see what is in there with a 'ls' type command is annoying. feel super blind using imap

#

i hope i never have to use that damn thing again.

fathom pendant
#

I suggest, to learn basic linux commands, a terminal based game -- bashcrawl

sterile solstice
#

im fine with linux

#

it was just an example. if ppl have only ever used windows and suddenly need a cli and linux im sure they feel overwhelmed

fathom pendant
#

I hope the email from <user> to admin gave you a little chuckle

sterile solstice
#

much like me an imap

#

i got the flag and rage quit it

fathom pendant
#

Lol if you still have the terminal open scroll up

sterile solstice
#

closed it. moving on. lol

fathom pendant
#

Lol

#

Just a silly message regarding passwords

sterile solstice
#

ah ok

fathom pendant
#

It's in the email with the flag

sterile solstice
#

i already closed it, and im definitely not going back in

fathom pendant
#

Lol

#

But to answer your question earlier, there is the evolution email client you can use to set up auth to the target with

sterile solstice
#

i opened that and it wouldnt connect at all

fathom pendant
#

You gotta set it up to connect

#

Setting the remote server address, smtp, imap, pop3...

sterile solstice
#

yea i tried and none of it wrked

#

that was before i terminated everything and then restarted the pwnbox and machine. so maybe i wouldve worked after that

mossy epoch
topaz fossil
#

isn't that the first API key?

#

there's a 2nd api key elsewhere, for the final question

snow garden
#

Hello I am on the PIVOTING, TUNNELING, AND PORT FORWARDING module with the Web Server Pivoting with Rpivot section. And I am doing the last question " Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer." And after setting up the client.py and server.py and getting a connection, when I go to proxychains firefox <internal IP> I can only see the default apache page, and I have tried curl as well.

#

I tried also the method to connect through http proxy and NTLM auth but all I get it a Caught socket error trying to establish connection to proxy. Code 111. Msg Connection refused
Unable to connect to 172.16.5.129 port: 9999. Caught socket error trying to establish connection with RPIVOT server. Code 111. Msg Connection refused

fathom pendant
#

you getting to a page instead of a "can't connect" message via firefox means it's working

snow garden
#

Got it

#

Thanks.

#

It was just confusing because I was expecting something else, but now I see it within the source code.

fathom pendant
#

it's kinda right there

#

i take it though you were expecting HTB{..}

#

a fair bit of modules don't use the HTB{..} format for the flags/answers

#

but chances are if it's l337speak it's the answer

shut quest
#

iirc that one is there on the page, in red? I only saved a snip it of the curl output

fathom pendant
#

i had to double check myself

candid lily
#

can anyone help with advanced xss skills assesssment, i found the vuln and the exploit works on my side but doesnt work on bot

#

if there is a script.txt file hosted on a server, can i use it in script src?

candid lily
#

oooh i understand whats the problem

mossy epoch
#

hi, I see that you found the solution, can you give me a hint to follow? thx

thorn hawk
#

Hey amigos. Does somebody understand why the SSRF last assessment was done is such way? We learned all these amazing procedures but none was used to be able to find the flag. it felt that it could have been better implemented. it was just a question of searching correctly rather that using a vulnerability

main spear
#

Hello, there is a problem with the section crawling in the module information gathering web edition ? I can't find the comment for the location of future reports

#

even if i try to read the source code of the website i can't find the comment

wraith pelican
main spear
#

No, i have some comments but nothing related to reports

#

you did the module ?

mossy epoch
wraith pelican
main spear
#

hmmm, so maybe i have a probleme with my reconspider ? is that possible ?

mossy epoch
#

run again the tool to generate the results

#

yes, if you run some time only save last execution

main spear
#

Ok i got it thank you, i had to execute the tools like 3 times 😅

rustic sage
#

Ah I'm late to the party

silver iris
#

Finally finished the AD Module. What banger of a module. Especially the Skill Assesments were really great to learn.

rustic sage
#

on the road to victory now

sterile solstice
#

good work mate

#

i just finished Attack Common Services - Medium, it was waaaay easier than the Easy lab lol

#

i dont think ill do too well on the AD module but i heard HTB is way more indepth than OffSec for that component. so looking forward to it

#

damn its nice when you try something out, something new, and you hit enumerating gold!

vague flint
#

How to learn hacking from starting

normal sand
silver iris
main spear
sterile solstice
#

yea im looking forward to it. though i find myself feeling more at home on linux than windows lol

#

and OSCP is also a goal of mine. though i figured the HTB learning path would be better for the longrun

next bronze
normal sand
#

Thanks

next bronze
#

you don't have to worry about double hop if you're authenticating directly from linux

#

whatever you want to access, just open a new connection to it, it will always be only one hop

normal sand
next bronze
#

there's no need to use any methods there if you're connecting directly

normal sand
next bronze
#

yes

#

that's also where pivoting comes into play

normal sand
#

Btw @next bronze , weird question, but would you say the modules after AD Enumeration and Attacks take longer than the modules prior to it?

hexed lintel
normal sand
hexed lintel
#

why cant i run the file kernel which have executable permission

next bronze
#

I also didn't do the modules in sequence

normal sand
#

Ouhh

normal sand
next bronze
#

nah, I just did the topics I'm more familiar with first

normal sand
#

Ahh ok.

hexed lintel
old oasis
hexed lintel
#

yes, didn't work
Sorry, user htb-student is not allowed to execute './kernel' as root on NIX02.

old oasis
hexed lintel
silver iris
sterile solstice
#

i have anything sql lol

pastel lava
#

Im working the the Active Directory Enumeration and Attacks module. Specifically the kerberoasting from windows section i tried spawning the machine and its been stuck on target spawning for about 20mins now ive tried refreshing the page and restarting my PC but its just stuck any suggestions? https://academy.hackthebox.com/module/143/section/1423

candid lily
#

advanced xss and csrf module skills assessment, i suspect the admin bot is not working

#

they payload works on myside to enumerate internal api

silk anchor
#

Attacking common services hard done! That was a very cool attack chain

#

I'd be interested to know if there was a way to ||read the flag directly since I ended up needing to change some settings but I dunno if that is the intended way.||

fierce island
#

Anyone care to give me a nudge on the "Broken Authentication Skill assessment?

candid lily
#

is that module updated, i only know the previous one

fierce island
#

Yeah recently updated it seems : <

sterile solstice
#

I actually found most of it easier than the easy lab if im being honest...

silk anchor
sterile solstice
#

Yea, I understood conceptually but how you go about it was crazy imo. I wouldn't have thought of those linked things allowing you to circumvent the way you do

#

Will probably try it again at the end of the path, or look for a machine with those vectors. I imagine sometbing similar will show up in the exam

silk anchor
#

I fully expect everything covered in the modules to be in the exam in some shape

sterile solstice
#

Yea thats everything I've read

#

I heard there is a big risk to overthinking things as everything you need is in the modules

#

I wanted to try a retired machine but without a proper subscription it seems that is hard to do ... (im using the student sub for academy)

silk anchor
#

I've came across that a few times so far with some of the module skill assesments too, Just need to remember to keep it simple and make sure you have tried all the obvious things before you start attempting the wild stuff.

sterile solstice
#

The free retired machine in the lab is all web related stuff and I haven't got to that yet in the learning path 🤣

sterile solstice
#

But carefully re reading the module often helps

sterile wharf
#

Hello everyone

I am doing Windows Privilege Escalation Skills Assessment - Part 1

I am struggling to get the initial reverse shell, any hints on what I should use?
tried to inject commands to get a shell but had no luck so far

silk anchor
sterile solstice
#

I downloaded obsidian which I hope helps. Been using sublime

#

I will sign up when it's exam time. They have templates for OSCP as well.

silk anchor
sterile solstice
#

Ill have a look at notion tomorrow 🙂

fierce island
old oasis
sterile solstice
fierce island
tardy snow
#

will I get hard copy if I passed HTB Certified Bug Bounty Hunter?

strange forge
#

rdp connection is so slow in windows privesc module

ember fern
#

In the Web Fuzzing Skills Assessment, part 3 says

One of the pages you will identify should say 'You don't have access!'. What is the full page URL?
but none of the index.FUZZ results are the answer. Does this mean I am expected to fuzz the pages to find one? I've spent half an hour fuzzing with various wordlists and domains with all of the extensions

sterile wharf
gloomy lichen
#

Hello there, if any kind soul has completed the Sliver module, I've been stuck on the SA - first domain compromise. Keep going over the material but seems like I have skill issues 😞

wraith pelican
ember fern
#

I am fuzzing recursive rn

#

I find the folder

#

but (a) the first scan has another 28 minutes to go and (b) if I cancel it and start another in the subfolder, it finds nothing and (c) I have another 2 subdomains to look at

#

so that's like

#

3 hours on the top end of things

acoustic owl
#

I can't remember it taking so long

#

do you use this list?
|| /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt ||

ember fern
#

yes

#

@acoustic owl

#

with ||.php,.phps,.php7||

acoustic owl
#

In the two previous questions you found subdomains and file extensions. Use this information to get further

ember fern
#

I am using all 3 subdomains and extensions

#

but I shall keep looking ig

acoustic owl
#

But then you should actually find what you are looking for

ember fern
acoustic owl
late sinew
#

I found that some modules progress seem to be rolling back, is it just me?

fathom pendant
quasi moth
#

Hello, I am completing Password Attacks Pass the Hash (PtH) task, and can't get to david.txt file, firsty I get access to machine with administrator creds via impacket-psexec, then used mimikatz for PTH as david with ||mimikatz.exe privilege::debug "sekurlsa::pth /user:david /rc4:c39f2beb3d2ec06a62cb887fb391dee0 /domain:inlanefreight.local /run:cmd.exe" exit ||
/run:cmd.exe command. And if I'm trying to type ||\DC01\david\david.txt|| it just shows me Access Denied

dusky gyro
fathom pendant
#

sorry -mr *

#

match regex

fringe urchin
quasi moth
fringe urchin
next bronze
#

can't you smbclient to dc to access the file thonk

topaz holly
#

I'm having trouble with host 2 in the shells and payloads module. As it seems like its a pretty common issue but I keep getting the exploit to fail because of 'get-cookies'. Im only being vague cause I've already looked through here and this seems like this module causes lots of problems.

I have tried:
ensuring my vhost is set correctly
restarting pwnbox and the target vm
changing servers from US to EU
and using different interface addresses for rhosts

compact patrolBOT
shut quest
#

^^^

fathom pendant
zealous rune
#

hi. when using netexec like so:
nxc smb 10.129.247.105 -u <user> -p mut_password.list --continue-on-success
it seems like it stops when finding out that <user> has guest access
10.129.247.105 445 NIX01 [+] \<user>: (Guest)
and I'm expecting it to continue trying passwords in the mut_password.list for <user>

fathom pendant
#

since for single user it won't just continue on success

zealous rune
#

ah i c

fathom pendant
#

the continue on success is to go to the next user

zealous rune
#

ah ah

#

it's finding guest domain login?

fathom pendant
#

basically

zealous rune
#

--local-auth switch also stops soon as it discovers user can login as guest

fringe urchin
topaz holly
#

Can I put a video within a spoiler here? I can show the process that way

fathom pendant
#

no

#

Host 2 is the blog site yes?

next bronze
topaz holly
#

yeah it is

next bronze
#

do you have a user list?

fathom pendant
#

you should be using the mentioned exploit

#

the xxxx.rb

#

(the creds are on the desktop for authentication)

topaz holly
#

Its weird. I extensively looked up questions about it here before I said anything after what I was trying wasnt working, and the only solutions outside of that were to restart everything and change servers

#

yeah Im using the 50064.rb from msf

zealous rune
#

@next bronze I'm trying to get it to try all passwords in given list for the user specified

#

i have a password list

#

i have already enumerated users on system

topaz holly
#

checked for typos and everything. For quick reference before I share the output of my options, should I be using the 10.xx..... or the 172.xxxxx address as the rhost for the blog site?

fathom pendant
next bronze
fathom pendant
#

as it's on a separate internal network

topaz holly
#

thats the only thing im fundamentally not sure on. Everything else should be working fine but ive tried with both addresses and nothnig

#

okay, finally I think I may have one more variable to share

#

Im using msf from the foothold that i am RDP'd into

#

is this correct or should I be running it from pwnbox?

fathom pendant
#

that is correct

topaz holly
#

okay let me share my output

fathom pendant
#

as you can't reach the 172 directly from the pwnbox/your vm

topaz holly
#

I figured but due to these errors I was second guessing haah

fathom pendant
#

if all else fails

#

close msfconsole, then restart it, and try again

#

sometimes that legit fixes it

zealous rune
#

@next bronze because I think it is just telling me that the user has Guest access as a pose to finding the users actual password

#

of course... al progress is good. just keep going

next bronze
zealous rune
#

ah

fathom pendant
#

brother this isn't an idle chatter channel

#

read and follow #welcome to access more channels

#

see my second sentence

#

then reach out to an online mod or admin

#

just have patience

#

mods and admins also have lives outside of monitoring the discord

#

some have actual jobs that takes priority over answering discord dms

zealous rune
#

@next bronze thx for th hint. it seems like it tries a password finds and is able to log in with guest privileges

#

so it basically stops on every line

#
SMB         10.129.247.105  445    NIX01            [*] Windows 6.1 Build 0 (name:NIX01) (domain:NIX01) (signing:False) (SMBv1:False)
SMB         10.129.247.105  445    NIX01            [+] NIX01\will:00000 (Guest)
#

hmmm something i'm not understanding here

fathom pendant
#

just make sure you're following the instructions in #welcome properly

topaz holly
#

I have tried closing msf and restarting it, as well as the vm and switching reigonal servers! Like i said, these were suggestions I had found before I asked here. So its like i got to the point where its like wut... so I asked

fathom pendant
#

sec

shut quest
#

Rhosts doesn't look correct to me

fathom pendant
#

yeah

#

the RHOSTS isn't correct

#

the RHOSTS should be the ip of the entry in /etc/hosts for blog.inlanefreight.local

#

that's why it's failing

#

LHOSTS is the one that should be your ip

#

L - Listening/Local
R - Remote

topaz holly
#

okay. So I may need to dig the blog site then?

fathom pendant
#

no

#

look at your /etc/hosts

topaz holly
#

I assumed the blog site was being hosted as a vhost from the device im rdpd into

fathom pendant
#

are the other sites the same? no

#

don't make assumptions without confirming them

topaz holly
#

I gotcha. And thanks looking at the hosts file is a lot easier to see what the ip is for the blog

celest bronze
#

hi CROSS_SITE SCRIPTING (XSS) Module — Skills Assessment i cant get a callback on my kali vm sudo php -S 0.0.0.0:4004 plz help

fathom pendant
wanton idol
#

or change the xss payload port to 4004 so it can reach you machine

topaz holly
#

thanks for the tip

#

Am i missing anything else? I still am getting the same issue as before while using the ip for the blog site as the rhost.

topaz holly
#

Haha jesus, thanks. Im sure you know how it feels to be thrown off

#

I orginially had that before restarting everything

#

There we go. All taken care of. Thanks for the good tip moving forward

acoustic owl
#

I can help you. Send me a DM

steady torrent
#

Can I DM someone for a bit of help on the ffuf module for the filtering section ?

quasi moth
fathom pendant
#

Just ask here

steady torrent
#

I want to avoid spoiling the challenge... it is about the filter option -fs I don't know if I'm right and I need a bigger wordlist or a setting issue

fathom pendant
#

Filter out the common size

#

Don't use the fs from the example, use what you find through doing

steady torrent
#

That is what I'm doing

zealous rune
#

need a hint on passwords attack module section credential hunting on linux. so far i have managed to enumerate users and shares via guest smb access. I've been trying to brute force the users passwords using the passsowrd lists provided as well as mutated lists generated using the rule list provided. So far I've tried brute forcing the smb service.

fathom pendant
#

You need to get a base user first, try cracking ftp. Don't be afraid to look at the hint for the username (make it lowercase)

zealous rune
#

its the one that has firefox tool and lazagne

#

goddamit

#

i didn't pay attention to my nmap output

fathom pendant
zealous rune
#

i was using the three users i found by rid cycling

fathom pendant
zealous rune
#

just checked hint- had found that user

fathom pendant
#

But yeah

zealous rune
#

sid cycling then

#

samba server

fathom pendant
#

Well to be more precise

zealous rune
#

can connect using rpcclient

fathom pendant
#

It's a thing added with samba server

zealous rune
#

then cycling the uids

fathom pendant
#

But you don't need to necessarily do all that

zealous rune
#

it worked to enumerate the users

#

also found all the users in passwd

steady torrent
zealous rune
#

/etc/passwd

fathom pendant
#

Either way. Make sure you save all users and passwords you find

fathom pendant
#

k* is the key

zealous rune
#

that's plenty good

#

i was actually bruteforcing the users i found, i overlooked the ftp service like an idiot

#

i got fixated on ssh and smb

fathom pendant
#

Not all users may have access to smb

zealous rune
#

i need to focus on enumerating better

fathom pendant
#

Just slow it down

#

You focused on smb because that was for SAM

#

Well that or ftp

zealous rune
#

yes. but i also didn't pay attention to the nmap properly

fathom pendant
#

Then slow down

zealous rune
#

good advice

fathom pendant
#

Don't try and rush it

#

This module is all about patience

zealous rune
#

i built the foundation using shaky assumptions

#

your hints helped, investigating new leads 🙂

fathom pendant
#

Be prepared to spend up to 20 minutes on password bruteforcing

#

Just know hydra has a threads option to increase threads

zealous rune
#

yes i remember optimising hydra runs in another module

#

netexec definitely not the fastest

quasi jungle
#

https://academy.hackthebox.com/module/136/section/1288
Trying to fuzz the extension with burp suite
Using the https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Upload Insecure Files/Extension PHP/extensions.lst as the wordlist
Added ".php" as the word to replace
Replaced Content-Type with "Image/png"

In Intruder:

POST /upload.php HTTP/1.1
Host: 94.237.59.63:56164
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://94.237.59.63:56164/
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------372853939017620031634039361819
Content-Length: 255
Origin: http://94.237.59.63:56164
DNT: 1
Connection: keep-alive
Sec-GPC: 1

-----------------------------372853939017620031634039361819
Content-Disposition: form-data; name="uploadFile"; filename="shell.php"
Content-Type: image/png

<?php
echo "Hello World";
?>

-----------------------------372853939017620031634039361819--

This request works and shows "File uploaded Successfully" but when I forward the same request to Repeater it fails.

GitHub

A list of useful payloads and bypass for Web Application Security and Pentest/CTF - swisskyrepo/PayloadsAllTheThings

dire abyss
quasi jungle
dire abyss
#

when your fuzzing, do you get 193 like in the chapter? because i get 230 saying upload is successful

quasi jungle
#

That's one of the weird things.

dire abyss
#

something is wrong with your fuzz approach, did you turn off url encoding in the payloads tab?

quasi jungle
#

Didn't turn it off entirely

#

That worked, Thanks.

dire abyss
#

this is what i got

#

i dont get a response code of 193 but i do get 230 as successful

dusky gyro
quasi jungle
#

All are 200

dire abyss
steady torrent
dire abyss
fathom pendant
#

Note don't put the port in the /etc/hosts file

quasi jungle
fathom pendant
#

Just the ip

quasi jungle
old oasis
quasi jungle
#

Filtered out the ones which have successfully uploaded, now to see which one executes.

fathom pendant
old oasis
# fathom pendant ?

nvm just me thats messed up. I read it as "Just the tip" thought you edited

steady torrent
dire abyss
#

mine does this

#

idk if thats error with my one liner or part of the experimenting process

fathom pendant
#

You still need to specify port

quasi jungle
fathom pendant
quasi jungle
#

You have to try other ones to see which one can execute code on the server

fathom pendant
#

^

dire abyss
#

alright ill stop being lazy and keep pushing

#

at least i know my code is good

quasi jungle
steady torrent
fathom pendant
#

Instead of just uploading a webshell. Upload one that just runs the id or whoami command

quasi jungle
#

Currently just seeing with this which one can execute code

fathom pendant
quasi jungle
#

Yeah, just trying manually now from the few choices

neat ginkgo
#

Can someone help me with the module Information Gathering - Web Edition. I am stucked on the last part Skills Assessment question 3 "What is the API key in the hidden admin directory that you have discovered on the target system?". I found the subdomain and the robots.txt but cant seem to access to the key.

quasi jungle
#

Found the extension.

quasi jungle
dire abyss
#

nice, thanks for the sanity check

quasi jungle
wraith pelican
neat ginkgo
#

Yes but i get 404 on everyone except from index.html

dusky gyro
neat ginkgo
dusky gyro
dusky gyro
wraith pelican
royal python
#

guys what is th difference betwween a tool and a scirpt?

wraith pelican
fathom pendant
#

i.e. if you write a script to run your openvpn command, it's not really a tool... it's just a script to do a simple task

royal python
fathom pendant
#

programming languages

#

and it depends on the tool you're writing

royal python
fathom pendant
#

a tool can be a compilation of scripts, but a script itself is not a tool

fathom pendant
royal python
#

but a tool can be write on bash?

fathom pendant
#

you can write a tool in python, C, rust, go

fathom pendant
#

A script does a small very niche thing that a tool generally doesn't cover

royal python
#

thx u

fathom pendant
#

i mean that statement can extend to writing a tool in any language

#

¯_(ツ)_/¯

royal python
#

u have your own tool?

fathom pendant
#

but usually you write a tool for multiple platforms

#

so you don't really want to restrict it to a shell language

#

unless you want it to be run on certain platforms only

#

i.e. compiling .exes for windows, .sh for linux

neat ginkgo
royal python
fathom pendant
royal python
fathom pendant
#

yes

royal python
zealous rune
#

@fathom pendant no need to wait 20 mins 🙂

fathom pendant
zealous rune
#

read the hint properly

fathom pendant
zealous rune
#

and it was easy

royal python
fathom pendant
#

they are

royal python
zealous rune
#

once i read it

fathom pendant
#

they are executable files for windows

fathom pendant
royal python
#

i catch u baybe

fathom pendant
#

don't call me baybe either

royal python
#

lol

fathom pendant
#

if you continue i'll just block you and stop helping you

royal python
fathom pendant
#

these are also things you can just google

royal python
fathom pendant
#

i'm setting my boundaries

#

if you can't respect that then that's a you problem

royal python
fathom pendant
#

?

wraith pelican
#

i think you ask those questions to know if you are a script kiddie

royal python
#

u and kharaone have the same picture of a sexy deamon

fathom pendant
#

this isn't an idle chatter room anyway; read and follow #welcome

wanton idol
fathom pendant
#

also not a daemon

glass quail
#

Module: server attacks
Section: SSTI Exploitation Example 1
Can someone help me on the section I don't know if I should keep searching for the variables by directory or find a different method for finding the flag

clear zephyr
fathom pendant
#

oof

leaden yew
#

For the updated "Information Gathering - Web Edition" module, is there a way to reset the section questions? Currently they have old answers to the newer questions...

fathom pendant
#

no