#modules

1 messages · Page 284 of 1

young wyvern
#

Yeah, I must have missed a step? But I’ll keep trying some things

fathom pendant
young wyvern
fathom pendant
#

Make sure to go line by line

elder citrus
#

anyone?

next bronze
#

dm me the whole thing

#

@elder citrus that's the same as the answer I have, make sure there's no space before and after your answer

elder citrus
#

sent you a pic

next bronze
#

clear cache, refresh page

elder citrus
#

now i am kind of panicking

fathom pendant
#

If using pwnbox go fullscreen

next bronze
#

the answer is correct, it's not being accepted for some reason

vague token
#

Could anyone help me with this question "Locate a configuration file containing an MSSQL connection string. What is the password for the user listed in this file?" in the module "AD Enumeration & Attacks - Skills Assessment Part II". I have tried running Snaffler and a few other tools like Lazagne, but I don't seem to be getting back anything that relates to the question

fathom pendant
#

I believe snaffler should find it

elder citrus
vague token
fathom pendant
#

You also might need to be the B* user

vague token
#

Yeah it was me been a dumbass and not changing to the B user, thanks for the push

next bronze
void tendon
#

Good morning people. I have a question. I just finished the "Penetration Testing Process" module. This module mentions that every time I read two modules, it recommends making machines to practice what I learned. Are there machines designed to practice each module? I see that there are machines but they require knowledge in several modules.

vague token
fathom pendant
vague token
#

True

fathom pendant
#

The suggested machines only partially have what you just learned

elder citrus
fathom pendant
#

Restart the target. Do the steps. Get the answer

next bronze
#

all your progress like previously submitted answers and modules?

next bronze
#

the data is stored on the server side, clearing cache wouldn't remove them

#

logout and log back in

elder citrus
#

nothing's happening

fathom pendant
#

Message support

next bronze
#

yep message support

elder citrus
#

I have. It's to wait now

elder matrix
#

Hey!
I want to brute force SMB on the Credential Hunting in Linux section.
Using the auxiliary/scanner/smb/smb_login as shown in another module, this is what I entered:

msf6 > use auxiliary/scanner/smb/smb_login
msf6 auxiliary(scanner/smb/smb_login) > set SMBUser will
SMBUser => will
msf6 auxiliary(scanner/smb/smb_login) > set pass_file mut_password.list
pass_file => mut_password.list
msf6 auxiliary(scanner/smb/smb_login) > set rhosts 10.129.174.90
rhosts => 10.129.174.90
msf6 auxiliary(scanner/smb/smb_login) > run

i get this:

[+] 10.129.174.90:445     - 10.129.174.90:445 - Success: '.\will:!'

The password is most certainly not a dot. What can i do to make it brute force?

#

is it because it is a samba service instead of a Windows smb service?

fathom pendant
elder matrix
#

dont care.

#

why is it not working is what im asking!

fathom pendant
#

...because this isn't the method

elder matrix
#

maybe i want to brute force another user... wink wink

cloud urchin
fathom pendant
#

i don't care that you "don't care" this method isn't how you'll get it

#

will's password isn't even in the mutated list

#

i suggest other services to bruteforce instead of smb

elder matrix
#

i used "will" because "kira" is a spoiler.

#

kira's password is in the list

fathom pendant
#

well that doesn't alleviate confusion now does it

#

but you're not gonna get it through smb

#

at least with metasploit

#

haven't tried with other protocols

#

but smb is set up for guest access

void tendon
fathom pendant
#

so it'll just say any password is good

fathom pendant
#

and often require learning/knowing other things

void tendon
restive trail
#

Hello, I'm trying to do Creepy Crawlies within the INFORMATION GATHERING - WEB EDITION module, but when I try to run ReconSpider.py I get the error of ModuleNotFoundError: No module named 'scrapy.downloadermiddlewares.offsite'. I did make sure scrapy was installed (/usr/bin/scrapy). Please help.

timber hatch
#

install it as described with the break flag, than everything should work fine

restive trail
restive trail
elder matrix
#

in "credential hunting in linux", am i actually supposed to press "hint" ?

#

i know what to do with the hint....but how did "the colleagues" find that?

rustic sage
#

you get hints when you are stuck.

elder matrix
#

yeah but that hint.... that hint in particular... is it intended to be pressed?

#

first one i pressed

oblique oak
#

Hi

Is it possible to reset the module's progress?

timber hatch
#

sombeody online who did digital forensic?
i would need a hint in the section Evidence Acquisition Techniques & Tools
i've collected the artifacts as described, but i dont know how to look for the process which start with a and ends with g.
would be nice if somebody could nudge me in the right direction

winter field
#

I'm on the last question of INTRO TO C2 OPERATIONS WITH SLIVER and unable to solve the question. Anyone that has completed the module that can confirm dumping the hashes on the DC is not possible?

elder matrix
young wyvern
fathom pendant
#

That mutated pw is in the big lists

#

You can safely use 48 threads for most services in this module

elder matrix
#

oh i got the password... just wanted to know if this was a dirty trick from htb...and yes! dirty trick! don't press the hint = don't get to complete the exercise!

fathom pendant
#

It just takes patience

elder matrix
#

thats what i want to know!

#

crap...ssh

fathom pendant
#

Don't attack ssh

elder matrix
#

it has to be ssh

#

ftp? no way on earth!

fathom pendant
#

There's other protocols running

fathom pendant
elder matrix
#

but the password is not on the mut_password.list

fathom pendant
#

I also suggest investigating /home/

fathom pendant
#

Her password is

#

You will use pretty much all tools in this section

snow root
#

Hi! Someone done the API Attacks module....Stuck on last assessment. Any suggestions where to begin? Tried the "new" function in so many ways....What am I missing? grrrhhhhh

timber hatch
#

sombeody online who did digital forensic?
i would need a hint in the section Evidence Acquisition Techniques & Tools
i've collected the artifacts as described, but i dont know how to look for the process which start with a and ends with g.
would be nice if somebody could nudge me in the right direction
should i use tools like timeline explorer? or just in text editor search for the right strings?

#

but on this host aren't tools so i think only search in edtior for the right strings?

#

found it lol

#

lucky punch

clever lotus
#

greetings, is there some bug with Web Server Pivoting with Rpivot. i sucessfully got new connection from pivot target but when i try launch firefox with proxychains it cant load site. it is loading but after 20 secs it says unable to connect. i tried add in /etc/hosts ip address of target but it dosent matter. anyone had same issue?

cloud urchin
#

I didn't have that issue

clever lotus
#

its strange but curl with proxychains goes well

#

but load on firefox nope

#

at leat i got the flag

cloud urchin
#

try manually putting http:// instead of https://

clever lotus
#

tried

#

it dont work

cloud urchin
#

works for me ¯_(ツ)_/¯

wet aspen
#

guys been struggling with the linux priv escalation room ..... the one where you gotta get the flag by escaping the restricted bash shell
[22:19]
spent like 3 hours on this .... but i just cant solve it

wet aspen
#

i tried with this command echo "$(<flag.txt)"

#

but does not seem like the ideal way

#

but i still got the flag though

cloud urchin
#

i used one of the methods from this site

wet aspen
#

alr will check it out thx bro

snow root
fathom pendant
brittle crest
#

File Upload Attacks - Skills Assessment - File Upload Attacks
I was able to find the upload directory and dump the SRC code but it looks like the VM is on a different date. Does anyone know how to get the date of the target vm using an XXE attack?

cloud urchin
storm elk
fathom pendant
#

East Coast US is -4, West is -7 iirc

#

i only was thinking about it bc my weekly streak rolled over at 8PM EST last night

cloud urchin
#

are you hoarding answers to keep your streak going too?

fathom pendant
#

no

#

it's called laziness

#

you wouldn't understand

shy cipher
#

Hi, I am working on the Linux Privilege Escalation module, Environment enumeration section. Stuck on the 'Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer.' Used grep, but as user htb-student wasn't able to see the result. How can I escalate the privileges to user lab_adm ?

fathom pendant
brittle crest
cloud urchin
#

just do it for tomorrow, at most it can only be 1 day ahead

fathom pendant
#

Server is GMT; it's 10PM there, not tomorrow yet

cloud urchin
#

oh ok

fathom pendant
#

2 more hours it will be

cloud urchin
#

then what's the issue

umbral gazelle
#

Hi all. I'm having a bit of trouble with one of the modules. Here is my problem: In the footprinting module in the MySQL section, I'm working on the second question where I am trying to log in to the MySQL server but when I use the MySQL command, the terminal says: bash: MySQL: command not found. Anybody have this problem and does anyone have a solution?

fathom pendant
#

sorry i can't read

#

i lied they're only 4 hours ahead of EST

#

8 PM; so 4 hours to midnight GMT

shy cipher
cloud urchin
#

there are only two options here

#

it's either today, or tomorrow, so if one doesn't work try the other

cloud urchin
#

pretty much that simple. if you're not finding the dir like that then you should inspect the source code again

fathom pendant
#

also is the file formate yymmdd??

#

or is it ddmmyy?

umbral gazelle
#

Thank you! I'll give this a go

brittle crest
cloud urchin
#

eu has weird ass date formats too

calm pewter
#

Hello, I had a small doubt if anyone has any idea...

In intro to AD, I can't xfreerdp from my host system to the windows server. It just shows black screen with normal log messages.

From pwnbox it loads normally

cloud urchin
#

did you try pressing a button when you connect, like enter or space

calm pewter
#

Okay wait, after logging in from pwnbox, I suddenly got logged in now from host as well without pressing anything this time

sometimes it's just weird I guess

#

Thank you 😊

cloud urchin
#

make sure you don't run the pwnbox at the same time as being on the vpn

fathom pendant
brittle crest
#

OMG im retarted lol I forgot to disable noscript and that was preventing uploads.

fathom pendant
#

Even if you can't spell it right

brittle crest
#

lol told you, sure thing!

fathom pendant
#

Point stands, just avoid using it

young wyvern
#

@fathom pendant still getting the password prompt, I tried checking the path on the target and the personal directory is actually a zip? Could be the wrong place

fathom pendant
#

As said, by the sections regarding this

young wyvern
fathom pendant
#

It's why I said to follow the steps exactly as outlined

#

You skipped a few paragraphs ahead and missed the plot

sharp pike
#

password attacks lab - hard: I'm attempting to pull the a file through SMB & I'm getting this error: parallel_read returned NT_STATUS_IO_TIMEOUT & then it disconnects my session

#

I have tried this on two reverted machines, my own VPN connected VM & the pwnbox (not simultaneously)

fathom pendant
#

Change vpn regions

#

Restart target

calm pewter
fathom pendant
#

Well that's a different issue

#

And by host do you mean your vm?

faint trellis
#

Hey there!
Who could assist me to access DC01 (DACL Attacks I - Skill Assessment - the last question).
I have got Jose's hash but it seems to be uncrakable, and I can't access by this one nowhere.

calm pewter
#

Yes, from my VM

fathom pendant
#

In terminology the Host is your base OS that's running the virtual software

young wyvern
calm pewter
#

Okay to clarify now, my VM on my host system

fathom pendant
calm pewter
#

No problem, I will troubleshoot for a bit. Thank you!

sharp pike
# fathom pendant Restart target

it appears the backend thinks my VPN is still connected, which i manually exited out of - is there a way to reset it instead of waiting for the session to die?

faint trellis
fathom pendant
sharp pike
fathom pendant
#

I haven't seen htb track whether I'm connected to academy vpn or not

sharp pike
#

oh

next bronze
sharp pike
#

its been happening occasionally when there is an issue disconnecting my VPN connection to academy & it wont let me start a new one, even after changing regions, getting a new VPN pack (UDP or TCP)

fathom pendant
#

I've had no issues like that

#

Unless you're referring to the pwnbox, which is different

#

In which case, just refresh the page

sharp pike
fathom pendant
#

Ctrl+shift+r to reload the page and clear cache

faint trellis
muted jacinth
#

Hey guys, anyone here?
Im having a question on the Introduction to Windows Evasion Techniques : Process Injection
i Developped somethings trying to reproduce the lesson but when i Upload the file. It seems like it doesn't get executed by the user.
the log doesn't output anythings new, is this normal?

#

[05/07/2024 05:57:00] C:\Alpha\ProcessInjection\AlsoNotMalware.exe - OK - Timeout reached, killing process
[05/07/2024 05:57:14] Checking...
[05/07/2024 05:58:14] Checking...

#

the log file isn't getting refreshed, even after the uploading of the file, and the previous output (displayed above) seems outdated and are in the log file even before we upload the malware

next bronze
#

yeah it's broken

muted jacinth
#

haha ok

#

good

#

Is it supposed to be fixed soon or?

next bronze
#

yeah hopefully

muted jacinth
#

okay, ty

sterile solstice
#

re-strating my VM this morning, i appear to be able to run nc on port 80 now...though my version of nc doesn't give me any verbose that its listening which is annoying.

fathom pendant
#

nc -lvnp [port] is the format iirc

sterile solstice
#

yea, nc -lvnp 80. im going to run through an exercise that requires it, so hopefully it still listens. but i have a few versions of netcat

fathom pendant
#

Why do you have multiple versions?

sterile solstice
#

because it wouldnt work on my parrot os when i got it, so i went through and tried to install something that would work

#

and there are multi forks ...

fathom pendant
#

works on my machine ¯_(ツ)_/¯

sterile solstice
#

dunno what to tell you, it didnt on mine.

fathom pendant
#

Iirc netcat is bundled in core-utils if [for some reason] it's not already installed

#

You can also install ncat [nmap's netcat]

sterile solstice
#

yea thats what i thought.

fathom pendant
#

The one that's common though is netcat-openbsd

sterile solstice
#

just installed ncat, and it is giving me verbose

fathom pendant
#

👍

sterile solstice
#

this makes me happy. i know its listening lol

coarse snow
#

<@&861185840277487616>

fathom pendant
#

<@&861185840277487616>

cloud urchin
#

<@&861185840277487616>

#

get out of here loser.

fathom pendant
#

Already reported their shit to discord as well

jolly cradle
#

They were banned

cloud urchin
#

yeah he comes back every so often

fathom pendant
#

waiting for messages to be whiped

fathom pendant
cloud urchin
#

yeah

fathom pendant
#

Join date today

cloud urchin
#

what a waste of time

sterile solstice
#

i dunno what the point of all that was

jolly cradle
fathom pendant
coarse snow
#

People don’t have anything better to do 😒

fathom pendant
#

Iirc those reports are archived

jolly cradle
fathom pendant
#

But sock account so

#

¯_(ツ)_/¯

jolly cradle
#

eh yea idc enough for discord to review it

sterile solstice
#

yea very unoriginal. surely it'd take more time to create their troll account then their account would survive to do useless trolling lol

cloud urchin
#

probably just some 12 year old

sterile solstice
#

...yea, probably. lol

topaz fossil
#

good day. I need help with something. module Linux Fundamentals, section Task Scheduling. the question asks about dconf.service, but I don't see this in pwnbox. and there's no target machine. am I expected to install this?

topaz fossil
sleek moss
#

hi for burseuqe box i added searcher.htb with the ip and i can ping it └─$ ping searcher.htb
PING searcher.htb (10.10.11.208) 56(84) bytes of data.
64 bytes from searcher.htb (10.10.11.208): icmp_seq=1 ttl=63 time=108 ms
64 bytes from searcher.htb (10.10.11.208): icmp_seq=2 ttl=63 time=114 ms
64 bytes from searcher.htb (10.10.11.208): icmp_seq=3 ttl=63 time=91.3 ms
but when i go to the website it says Unable to connect

An error occurred during a connection to searcher.htb.

The site could be temporarily unavailable or too busy. Try again in a few moments.
If you are unable to load any pages, check your computer’s network connection.
If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the web.
#

10.10.11.208 searcher.htb

#

in my /etc/hossts

#

i can wget the page

cloud urchin
sleek moss
#

why

cloud urchin
#

is it a module?

junior oxide
#

quick question on the juicypotato in windows privilege escalation skill assessment: what does -l mean? through a section it says COM server listening port. How do i get that number exactly?

cloud urchin
#

-l is the listening port

junior oxide
#

so i have to view what ports are open in the machine right?

cloud urchin
#

-l is the parameter juicypotato uses to specify the listening port for the COM server that jucypotato sets up, the port is used internally by juicypotato to interact with the COM service it is exploiting, so you can pick the port yourself. you'd want to pick a port that isn't in use.

junior oxide
#

ok so i can pick something random that isn't in use got it now

cloud urchin
#

yep

junior oxide
#

i did it but i keep receiving "COM -> recv failed with error: 10038"

#

wait i changed what's inside -c and got something

#

this is weird i don't know why it happened tbh

#

edit: it gives out without actual results i think i have to edit something with the nc.exe that i uploaded its not working for a reason

distant island
#

Try to create the 'ids.txt' wordlist, identify the accepted value with a fuzzing scan, and then use it in a 'POST' request with 'curl' to collect the flag. What is the content of the flag?
need help with this in fuff module i dont know why it dont work

distant island
cloud urchin
#

where exactly are you stuck

distant island
cloud urchin
#

dm me a screenshot of the actual command

distant island
wary tendon
#

is there anyone available to help me understand the doc and reporting section they didnt do a very good job of explaining it or how to do it. you can dm me if your interested

cloud urchin
#

which part did you not get

wary tendon
#

im on the assesment and it tells me to do this and that but to be honest the notes are all over the place and im not sure where to start or how to add things to the notes i read the module and i understand it but also like its thrown at me and not sure where to begin ive ran responer to get some hashes

cloud urchin
#

yeah, the previous pentester did a terrible job, its your job to clean it up

wary tendon
next bronze
#

it's the scond last module of the path, you're expected to be able to complete the pentest yourself

cloud urchin
#

sorry i can't do that

wary tendon
#

cant really complete if i cant understand what this report is telling me

cloud urchin
#

ignore what they put in the report then, just do it all fresh yourself

wary tendon
#

there are ips all over and whatnot

next bronze
#

use full path

cloud urchin
#

yeah you can see it's trying to download from your cwd

#

also maybe delete that post because many people try that module blind

#

check the "info" line -- it shows you're not downloading from the right spot

next bronze
#

oh that's AEN, yeah delete that

slender violet
#

Got it. Thank you.

junior oxide
umbral gazelle
#

Hi all. I'm having a bit of trouble with the second question in the Footprinting module in the MSSQL section. When I try to log in using mssqlclient.py backdoor@<target_IP> -windows-auth, it gives me a message saying 'SSL routines, no protocols available'. Has this happened to anyone else and what can I do to fix this?

cloud urchin
#

the clsid is the class id, it's used by juicy potato for exploiting the COM objects. the ones listed on that site are known to be exploitable for priv esc.

junior oxide
cloud urchin
#

the website shows you which ones are known

#

i don't know enough about it to know why some would work and some wouldn't if the target machine matches where you're getting the cslid's. maybe something was updated there or something i have no idea really.

umbral gazelle
fathom pendant
#

it's an error with the impacket installation on the pwnbox

#

two options are reinstall completely or force an upgrade

junior oxide
fathom pendant
#

staff/engineers are aware of the issues that are going on with the current pwnbox

umbral gazelle
next bronze
fathom pendant
fathom pendant
cloud urchin
#

x and y are valid, but only x worked

fathom pendant
#

¯_(ツ)_/¯

cloud urchin
#

i think that's what he's saying at least.. unless i misunderstand

fathom pendant
#

idk

fathom pendant
fathom pendant
cloud urchin
#

he pointed to a specific version list though

#

so i assume he was targeting that version, maybe not

fathom pendant
#

as in specific install version beyond 2016

#

i.e. 2016 R2

#

or some subversion within

next bronze
#

I mean sometimes that clsid just isn't being use by whatever registered it

fathom pendant
#

^

#

it's kinda just a guess and check thing

junior oxide
#

I'm confused.

#

so i'll have to brute force it?

fathom pendant
#

to a degree, yes

cloud urchin
#

i wouldn't really call trying a couple brute forcing, but sure 😛

#

clsid spraying

junior oxide
#

that's sad but thank you

fathom pendant
#

there's not always a clean way to do everything ¯_(ツ)_/¯

#

also ew no background png

junior oxide
fathom pendant
#

just use the gif selector

sharp panther
#

Hey guys I am on the assesment section of password attacks and am stuck at the initial enumeration of easy.
PING 10.129.212.177 (10.129.212.177) 56(84) bytes of data.
From 10.10.14.1 icmp_seq=1 Destination Host Unreachable
From 10.10.14.1 icmp_seq=2 Destination Host Unreachable
From 10.10.14.1 icmp_seq=3 Destination Host Unreachable
^C
--- 10.129.212.177 ping statistics ---
4 packets transmitted, 0 received, +3 errors, 100% packet loss, time 3232ms
pipe 3

fathom pendant
#

Try resetting the target or changing vpn regions

sharp panther
#

I feel I should manipulate the hosts file, but I'm not sure how Ishould do so. I'm getting a response from whatever sits in front of the box

fathom pendant
sharp panther
#

I reset the target I will try changing region

rustic sage
#

Well the VPN doesn't seem to be connected at all

fathom pendant
#

hosts file won't help you

fathom pendant
sharp panther
#

I am connected to vpn , confirmed

#

I will see if changing region works

rustic sage
#

Yeah try another VPN then

sharp panther
#

still unreachable using ping. -Pn worked for nmap?

rustic sage
#

Then ICMP is probably off in the target

fathom pendant
sharp panther
#

No, PN actually gave no results

rustic sage
sharp panther
#

I am still not talking to it

fathom pendant
#

did you download a new vpn file after changing regions? and reset the target?

#

(yes you need to reset the target when you change regions)

sharp panther
#

says all tcp ports are in ignored states which i know is incorrect

fathom pendant
#

Terminate --> start, not just the refresh button

rustic sage
sharp panther
#

ah , I dint reset the target

fathom pendant
sharp panther
#

thanks for responding by the way guys

#

lol no, still unreachable via nmap and ping. I reset the target, generated and connected usingm a new vpn file of another region, nada

#

I'm sure if I do it from the provided attack host it will connect

rustic sage
#

How do you know you're connected to the VPN?

sharp panther
#

I see that i am connected to 10.10.15.50 in the top right of my kali instance

#

i have never had this happen before

rustic sage
#

ping that

sharp panther
#

ok

#

replied

#

very odd

fathom pendant
#

it's the same as pinging your own host from any other interface

rustic sage
#

At least if the connection is actually working

sharp panther
#

lol yeah i tried it tho

fathom pendant
sharp panther
#

I can touch the target from within the parrot os they give

fathom pendant
#

you need to ping another machine to test

rustic sage
#

Hm

fathom pendant
#

sudo killall openvpn then reconnect and try again

sharp panther
#

ok

rustic sage
#

Other machine ain't responding

fathom pendant
#

also terminate the pwnbox when you go to use nmap the target

rustic sage
#

Maybe some kind of firewall issue?

fathom pendant
#

weird to be running a firewall on a pentest machine

#

¯_(ツ)_/¯

rustic sage
#

Yeah I mean idrk what's happening here lol

sterile solstice
signal wing
#

Hey guys I’m having some issues with one of the modules. Basically it’s asking me to rdp into a windows machine and then either ssh or rdp into a kali machine to answer the questions

I can rdp into the windows machine but I get a connection refuses when I ssh into the Kali machine or I get an error when trying to rdp into it. This happens on my vm and in the pwnbox/workstation. Any ideas? I can ping the target, and nmap doesn’t say 22 is open but this doesn’t explain why I can’t rdp to the Kali machine

fathom pendant
#

you use it as a jump host/pivot point

sharp panther
#

@rustic sage @fathom pendant thanks again my fellows. have a good night

junior wasp
#

y can’t i use general chat

cloud urchin
signal wing
junior wasp
#

that’s so extra

sterile solstice
#

the chanel gets spammed

fathom pendant
fathom pendant
pastel gull
#

Hi I want to do bug bounty for business logic flaws, but I wanted to know, do people actually get the things in their cart from intercepting?

fathom pendant
#

it's a server revolving around the HackTheBox website; expect to need an account to have further permissions in the server

fathom pendant
signal wing
fathom pendant
#

it's exposing a weakness or flaw with database backends

fathom pendant
pastel gull
#

Okay thanks.

willow wasp
#

for the hard password attack labs I'm having troubles trying to mount the drive since it's asking me for an admin password. david's (which seems to be the local admin if i understand it correctly) doesn't seem to work -- is there a credential I missed (johanna, david, keepass)?

fathom pendant
#

there's plenty of guides if you use the discord search feature that people have shared

willow wasp
#

solved, thanks for the tip

heady finch
topaz fossil
heady finch
topaz fossil
#

did you see the contents of the file?

heady finch
#

Yes able to see the contents

topaz fossil
#

then you should find the answer in there 🙂

heady finch
quasi wave
#

I completed Windows File Transfers.

#

now doing linux file transfers starting tomorrow

#

I was way overthinking it for a while

rustic sage
#

Good morning colleagues I am stuck on this question module password attacks section Credential Hunting in Linux the question is the following: Examine the target and find out the password of the user Will. Then, submit the password as the answer.

  1. I'm creating the password policy with hashcat as follows

hashcat --force LoveYou1.txt -r custom.rule --stdout | sort -u > mutPasswd.list
hydra -l Kira -p mutPasswd.list ssh://<host>
But at the time of checking the ssh service it does not get my password, what am I doing wrong?

#

Might need help, no users pop up

shut quest
candid lily
#

use enum4linux maybe its easier

rustic sage
#

footprinting, smb

rustic sage
shut quest
#

Delete your screenshot it contains spoilers. What question are you on? Not sure why you're trying to enum users for the section.

rustic sage
shut quest
#

You already have that in the screenshot I said to delete

rustic sage
#

the share was sambashare right? But then when i try look for it, all i see is "C:" for everything

#

o really holdon

shut quest
rustic sage
#

\

shut quest
#

-.-'

rustic sage
#

\\ ?

stark lark
#

└─$ hydra -L users.list -P pass.list -s 2121 ftp://10.129.131.49 -t 10

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2024-07-09 01:03:14
[DATA] max 10 tasks per 1 server, overall 10 tasks, 26307 login tries (l:79/p:333), ~2631 tries per task
[DATA] attacking ftp://10.129.131.49:2121/
[ERROR] all children were disabled due too many connection errors
0 of 1 target completed, 0 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2024-07-09 01:03:18

What could cause this error? I tried -t 10 to see if it would help from 16.

shut quest
rustic sage
#

Can someone help me with the question is that I've been stuck for several days and I can't find a solution 😦

rustic sage
#

OMG I DID IT

shut quest
rustic sage
candid lily
#

trying to install tls-breaker

rustic sage
#

Am i doing something wrong?

next bronze
rustic sage
shut quest
candid lily
#

eee so annoying

next bronze
#

the target address is inlanefreight.htb, that's the vhost you need to add to your host file

candid lily
#

ok it works if i change java version

pastel gull
#

Hello I want to do bug bounty, but I had a question. When people intercept prices on sites and try to buy does it work if the website is server side rendered?

autumn pilot
#

no

next bronze
#

yeah don't put the port

shut quest
#

Or the protocol

rustic sage
#

and then put the port at the back of inlanefreigyht.htb in my gobuster cmd

next bronze
rustic sage
#

alr its going tysm guys

#

shower time at two AM

#

pop quiz will my parents kill me

signal wing
#

For anybody else on the Windows attack and defense module for the SOC analyst path whos having issues connecting through SSH/RDP to the kali machine, heres the workaround I used

RDP to WS001 and obtain the file using ruebus 
Use SMBClient as guided in the overview page of the module to get the file onto your host machine
When the file is located in your host machine, close the connection with WS001
Establish connection with kali as target generated from Coercing Attack page in this same module
password.txt is located here, so we can retrieve the password.txt to our host using scp 
 end connection to kali, and execute ripper or hashcat in your local
void hemlock
#

For the Active Directory Trusts Attacks, I am having difficulties to RDP into the target machine (via the Pwnbox or my own VM). I am using xfreerdp to RDP into it.

[01:34:30:908] [11352:11353] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[01:34:30:908] [11352:11353] [WARN][com.freerdp.crypto] - CN = SQL01.inlanefreight.ad
[01:34:39:918] [11352:11353] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[01:34:39:919] [11352:11352] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]```
void hemlock
#

I had also the same issue in the section before

#

the labs doesn't look stable to me

next bronze
void hemlock
#

ok thanks I will try US4 VPN then

robust quartz
#

What "pane history" mean in tmux?

void hemlock
#

oh I am already on US4

next bronze
next bronze
robust quartz
#

I know..😅

next bronze
#

yeah so what are you asking? the history just contains the previous commands and output

void hemlock
next bronze
#

use tcp vpn

stone hare
#

On password attacks modules

#

Am I doing something wrong? Did exactly as the module said, create a mutated list with the custom rule they provide

nvm, i didnt capitalise the p 💀

void hemlock
next bronze
#

shruge it works for me

#

contact support

signal wing
robust quartz
#

The history is not cleared..

next bronze
#

did you install the plugin and did you try scrolling back up after clearing?

#

it clears the scroll buffer, not what's currenly shown in the pane

robust quartz
#

which plugin? In the module I was not shown to install certain plugins to "clear pane history"

#

I did try scrolling back up but there's many command before

next bronze
robust quartz
#

oh that one, yes I have it installed

next bronze
robust quartz
#

I still don't understand what is "cleared" from the clean pane history feature. like it doesn't have any effect

next bronze
#

you will see a message pop up at the status bar and the scroll buffer will be cleared

stone hare
#

Does the password attack module actually expect you to wait 6 hours to crack a password

robust quartz
sterile solstice
fiery owl
#

Hi all... just started my Adademy journey... I'm stuck in my box using ZAP Spider. I'm starting ZAP in my cloud instance... then I start the browser and browse to my target... the ZAP HUD appears... YAY... continue to target ad when I want to start a spider it tells me the ip is not in the scope... should I add it... YES please... start and nothing 😦 Does anyone have any clues?

#

Tried to add the IP manually doesn't work... clicking the out scope to add it doesn't work...

sterile solstice
#

hey mate. when you open up ZAP, are you clicking on the firefox icon in ZAP?

fiery owl
#

yes indeed

sterile solstice
#

awesome (i made that mistake took me a while to figure out ...)

fiery owl
#

ow... seemed like the way to go 😉

sterile solstice
#

in the initial screen, you should have a list of Sites on the left-hand side, and the ip and/or hostname in a list

fiery owl
#

yes found them

sterile solstice
#

i click on the IP, right click, then to attack --> then to spider

#

then the screen comes up with the starting point. it should be loaded. make sure recurse is clicked. then 'start scan'

fiery owl
#

ok that works.. skipping the HUD completely

sterile solstice
#

i found the HUD is very hit and miss...its been more miss for me, and others in here told me similar.

#

so i've just avoided it tbh. unsure if thats wise. but i just use the main screen/gui

fiery owl
#

Thanks... wil try it using the main screen then

sterile solstice
#

im very new myself .... so dont take my process as gospel . very much trial and error (focus on the error haha)

fiery owl
#

I hoped the cloud instance would reflect the course

sterile solstice
#

you can post in #1234357888114364508 for errors. that may be a good place to bring up something. i understand they are responsive.

fiery owl
#

okay you have your local parrot instance

sterile solstice
#

agreed! i think its meant to be 1 day, it took me a lot longer but i got a lot out of it.

fiery owl
#

that's a great idea

sterile solstice
#

i did a few modules on the cloud instance, but did transition to my own VM. a few times the pwnbox was better, for whatever reason.

fiery owl
#

thanks for the tips

sterile solstice
#

i recently noticed that some of my stuff wasn't being processed, and figured out it was likely my ISP filtering (or something similar), as it was obvious XSS attacks. no such issues on the pwnbox though.

fiery owl
#

ow yeah that's nasty... but nice they are kind of 'protecting' you 😉

sterile solstice
#

pivoting, and then AD attacks, are great modules coming up. if you know networking then pivoting will be easier but still great/difficult at times. and AD attacks features heavily in the exam, from what i've been told. and far better teaching than OffSec provide. i enjoyed it.

sterile solstice
obtuse haven
#

what should i do if its stuck in Targets are spawning for a while?

sterile solstice
#

are you using pwnbox or your vpn?

obtuse haven
#

but i dont think that even matters when its the targets that aint spawning

sterile solstice
#

refresh the page, change your region for pwnbox, and then try to re-spawn

#

targets are spawned based on your region that you are connected to, so it may.

sterile solstice
#

the pwnbox, or your own vpn, are connected to certain servers (your region). so if you spawn a target, it'll be spawned within that network (in that region).

#

that is my understanding of it all. so i hope it is correct ... i have had targets not spawn for a while though. sometimes there are just a lot of ppl and it doesn' work well.

tiny mulch
#

I have also question with pwnbox because for free version we have access for pwnbox only for 2 hours and with for example starting point on htb is no problem to connect with VPN but how can I connect VPN for htb academy?

waxen oasis
#

quick question, any reason why I wouldn't be able to chat in the off topic chat

obtuse haven
#

oh and it started

sterile solstice
jolly raptor
#

any idea when the maintenance will be completed?

tiny mulch
sterile solstice
#

there it has some instructions. get yourself something to run a VM, I use Oracle VM. download a copy of your VM (I'm using Parrot Security. You can use Kali if you like), then choose a VPN server at the bottom of the page.

#

its sudo openvpn <file>

jolly raptor
#

VM is definitely the way forward, although pwnbox is good having a VM set up makes life much easier

tiny mulch
sterile solstice
sterile solstice
sterile solstice
sterile solstice
#

no problem

sterile solstice
rustic sage
tiny mulch
#

Yes but guy in this video in module has an address IP for the VM and in module MacOS I don't see any

#

I have connect VPN but how can i connect to my VM (parrot os)

rustic sage
#

YOUR VM?

sterile solstice
#

you connect the VPN in your VM

rustic sage
#

Do you mean pwnbox?

tiny mulch
#

Becuase questions is abuot their pwnbox

sterile solstice
#

Pwnbox is a cloud based VM. you don't VPN into it. think of it as a separate computer

rustic sage
#

Pwnbox is not something you connect via a VPN. You access pwnbox via the browser.

tiny mulch
#

Yes but can I use their system in module via VPN?

sterile solstice
#

the Pwnbox is connect to the HTB intranet. when you look at a target, its in the same network. when you use your VM at home you are connecting that VM to the HTB intranet.

rustic sage
#

What module are you trying to do?

tiny mulch
daring wraith
#

Hello, anyone have a job in cybersecurity?

sterile solstice
#

why, you recruiting? hahaha

daring wraith
#

@sterile solstice only ur mom, hahaha

rustic sage
shell solar
tiny mulch
rustic sage
#

Well if you don't have a VPN+ account, you can download your own ovpn file and use it via your machine/VM

sterile solstice
tiny mulch
sterile solstice
sterile solstice
shell solar
sterile solstice
#

i found i had to spam RPD on some of them, as my connection kept dropping

tiny mulch
daring wraith
#

Just finished playing watch dogs boutta become a hacker

autumn pilot
sterile solstice
tiny mulch
rustic sage
tiny mulch
#

Oh that explains

rustic sage
#

¯_(ツ)_/¯

spark spruce
#

is API attack (new module) is fully web based???

tiny mulch
daring wraith
#

Who has a job in cybersecurity

rustic sage
#

pwnbox is still a Linux machine not MacOS

tiny mulch
rustic sage
#

Lol

shell solar
tiny mulch
# rustic sage Lol

I have another problem becuase this is the question: "Read the zsh configuration shown in the section above to find what command is mapped to 'll'. Submit the command as the answer. " and when I do this command in parrot system: chsh -s /bin/bash it asked me for password and HTB don't give us password for parrot system so what can I do?

shell solar
tiny mulch
rustic sage
#

Well

  1. you can't run MacOS commands in a Linux machine

  2. This is designed to be run on YOUR own device, so you would know the password

sterile solstice
#

but in my limited experience, its just very slow going with rdp on the modules.

tiny mulch
#

And this command worked but i don' know password in pwnbox

rustic sage
#

What's the section of the module exactly?

tiny mulch
#

MacOS terminal

rustic sage
# tiny mulch MacOS terminal

So what you basically have to do is download a configuration file that they provide to YOUR MacOS device, read it, then answer the questions accordingly

tiny mulch
#

Ok so their pwnbox is in this section useless 😄

#

Thank you very much for help, I will use my own MacOs device 🙂

rustic sage
shell solar
sterile solstice
#

no problem mate. glad its working.

tiny mulch
fathom pendant
#

Dude stop @ing people

#

I haven't looked at it but considering it's API and it's going to be thrown in the cbbh path, I'm gonna say yes

spark spruce
fathom pendant
#

Yes

#

And it's annoying

spark spruce
spark spruce
fathom pendant
#

If you do it again I will block you

spark spruce
fresh plinth
#

and revert your module progress

fathom pendant
rustic sage
#

but one can always go back and re-read the stuff.

fathom pendant
opaque forge
#

I'm going nuts on a side quest in the DFIR module. Trying to use cyber-chef to decode a powershell command that's been encoded and then compressed. I can remove the first layer, but am stuck. Can anyone help me? 🙂

rustic sage
#

But you should use your own MacOS device as they recommend

tiny mulch
#

Oki thank you 😄

pine vault
#

Hi ! I'm working on the "INTRO TO WHITEBOX PENTESTING" module - section Skills Assessment.
I've found one of the RCE method but looking for the second one.
Does anyone can nudge me?

olive jasper
#

Where i can find a good network course from basic to advanced?

fathom pendant
#

There's no one course that will take you from 0 to hero and it depends

fathom pendant
#

Most of what you need for hacking is basics

sterile solstice
# violet kite CCNA

Very vendor specific. Juniper's JNCIA is free and less vendor specific (due to how the OS works)

#

Or Network+ for genuine vendor neutral training. In that case, Dion or Prof Messer on YT or Udemy.

#

Oh, and NetworkChuck on YT for his explanations on subnetting. Honestly the best explanation I've come across.

fathom pendant
#

Depends how in depth you need it to be

#

But that's off-topic for this channel

violet kite
fathom pendant
#

Again this is all off-topic for the channel, there's other channels this conversation can be had in

candid lily
#

does academy has another payment option except credit card

fathom pendant
fathom pendant
dire birch
#

Introduction to Windows Evasion Techniques Section Process Injection, I'm stuck on this task because my code isnt being run, so i guess the task is broken

violet kite
fathom pendant
#

At most

dire birch
violet kite
fathom pendant
#

When it starts taking over the channel, and it gets filled with unrelated chatter, yes

#

This channel is specifically for help with academy modules

dire birch
#

any mods willing to help?

#

k just found that it's broken

fathom pendant
#

You can also reach out to support to try and resolve issues

mild flower
#

OCKS5 Tunneling with Chisel.

  • 1 Using the concepts taught in this section, connect to the target and establish a SOCKS5 Tunnel that can be used to RDP into the domain controller (172.16.5.19, victor:pass@123). Submit the contents of C:\Users\victor\Documents\flag.txt as the answer.

xfreedp wasn't working, so i tried rdesktop. i get the error invaild username / password but i've double checked. any help?

mild flower
#

also tried ligolo-ng, socat, reverting didn't solve it

fathom pendant
mild flower
#

nope

fathom pendant
#

Also make sure your proxychains config is correct (only socks5)

#

Also put the /v: argument first

mild flower
#

think the box is broken

next bronze
#

try adding /timeout:60000

mild flower
mild flower
next bronze
#

that worked? nice!

mild flower
#

Yep

coral forge
#

Heyy, while doing the IPS/IDS easy box from the network enumeration with nmap module, I noticed when I open the webpage with the /status.php, the number keeps going up even though i haven't started my scanning, is it due to other people using the same IP?

fathom pendant
#

It's just triggering as well off the web requests

coral forge
#

Ohhhhh I see, that makes sense

fathom pendant
#

Academy labs on the 10.129.x.x network are independent and not shared

coral forge
fathom pendant
coral forge
coral forge
fathom pendant
#

This narrows issues down to 2 things:
User error (skill issue)
HTB infra issues

fathom pendant
#

Btw if you trigger the ids/ips just reset the target

coral forge
# fathom pendant And scans

Okok, just asking because , I haven't started scanning and it was like 50/100 when I started , so it must have been just web requests I guess

fathom pendant
#

As it locks you out from interacting with it for like 5 minutes

coral forge
fathom pendant
#

But you can go through the whole easy --> hard without triggering

jolly raptor
#

can someone help, i can’t connect to the VPN i keep getting TLS handshake failed

coral forge
fathom pendant
#

At most you'd trigger 30 alerts

#

Just don't trip it

jolly raptor
#

on the website?

fathom pendant
#

Yes

#

Support doesn't monitor the discord

clever topaz
#

for every section in AD modules, time spent for rdp > time spent on solving question

#

anyone know how to make connection stable

#

really spending 1 hour+ for each question cuz keep disconnecting

fathom pendant
#

Use TCP vpn pack

#

Set high timeout

clever topaz
#

if im using pwnbox?

fathom pendant
#

Ah use a different region

#

Still set high timeout

wicked apex
#

Module: Information Gathering Web:Subdomain Bruteforcing

ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -u http://FUZZ.inlanefreight.com -H "Host: FUZZ" -fs 915

Am I doing it the right way with ffuf by only filtering size 915? I observed that most response with 915 are all 403s

is it about picking a different wordlist like before?

fathom pendant
#

If it'd a public ip

#

You don't put the port in the hosts file, you specify it in the http://domain:port

#

Also using -ac will let ffuf automatically toss junk responses

wicked apex
#

by port you meant 80/tcp for the http port?

fathom pendant
#

Read my statement again

#

if it's a public ip

#

If it's private, then you don't need to specify

#

As it's running on 80, http assumes 80 by default

#

The public_ip:port is the scope of the target if it's given in that format

little helm
#

Does anyone know why this error is occurring? I successfully executed this earlier for root, but accidentally forgot the flag so I executed the attack again later and it's throwing this error:

KRB5CCNAME=ticket3.ccache impacket-psexec support.htb/administrator@dc.support.htb -k -no
-pass
Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[-] SMB SessionError: code: 0xc0000016 - STATUS_MORE_PROCESSING_REQUIRED - {Still Busy} The sp
ecified I/O request packet (IRP) cannot be disposed of because the I/O operation is not comple
te.

fathom pendant
#

Reset the target

vital ice
#

Hello all, I just need some guidance for one of the questions in skills assessment on introduction to windows command line module.

For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host.
This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them.
hint
How can we view loaded modules and their members?

fathom pendant
#

Well, the hint gives you what to at least think about and look for

#
rustic sage
fathom pendant
slender shoal
#

Please respect m4cz's wishes.

#

This is not the proper channel for that, if you wish to see the rest of the server please follow #rules and read #welcome to gain access to the other parts.

thorn hawk
#

hello guys. I have a strange behaviour regarding a target. The below image is the ip I get. I found it strange that there is a text next to the IP is the first time I see this. When i try to connect to this I get no connection. I tried to download different VPN and I still get the same behaviour. My next step would have been to go to support but maybe is best to check firstly here. Let me know what you think.

slender shoal
#

i'm going to ask you to be respectful and read #rules. Thank you.

thorn hawk
elder citrus
#

Has anyone done the macos fundamentals. I got the module and I don't have a mac. Anyone willing to send answers to my DM?

next bronze
#

you can do the module without a mac, google them

elder citrus
#

yeah, i did it

vapid python
#

In the Linux Fundamentals - User Management section, the question is *" Which option needs to be set to lock a user account using the "usermod" command? (long version of the option)" *

the accepted answer to this is "--lock", howerver, the man page explicitly says: "Note: if you wish to lock the account (not only access with a password), you should also set the EXPIRE_DATE to 1."
Shouldn't either the question or the expected anser be changed?

daring peak
wild cape
#

Hey guys

Module: OSINT: CORPORATE RECON
Section: Public Domain Records

Question asked: What is the name of the registrar of this domain?

What I have done:

  • WHois lookup using both ip and domain name
  • shodan
  • dig
  • dnsdumpster
  • whois ||-B --sources RIPE,ARIN-GRS digitalocean||
  • and hours and hours of searching through different resources

Can any body please help or give me a quick sanity check? Thanks

clever topaz
#

rubeus no need username and password to do kerberoasting?

acoustic owl
wild cape
acoustic owl
lofty shore
#

Hi, I have read that when application whitelisting is in place I should use LOLBins and it gives an example of GfxDownloadWrapper.
Is there a way to enumerate LOLBins installed/available? Or do you guys keep a list of common LOLBins to try?

wild cape
#

I've also done the same when using ||the domain name|| as well, which provide different results, but still no luck

wet aspen
#

guys i cant find walkthroughs for htb academy modules

#

y is that? coz i used to find alot for THM rooms

acoustic owl
weak horizon
#

Anyone else not able to access the openVPN services for HTB? (Tried multiple things like restarting, logging out/on. Deleting & redownloading etc etc

weak horizon
#

It just started doing this after creating a new account and logging into it in HTB

#

Happening to another person i know ^^

acoustic owl
weak horizon
#

Should also mention the error i popping up when i try to download the OpenVPN file

#

Fixed it

untold breach
#

INFORMATION GATHERING - WEB EDITION
Skills Assessment
What is the API key in the hidden admin directory that you have discovered on the target system?

I have tried fuzzing, gobuster, and no luck. doing to the endpoint takes me to a permanantly removed 301 page... Any help?

dark nova
#

Hi everyone,

I am attempting to complete "RDP and SOCKS Tunneling with SocksOverRDP" but when I connect to the final host 172.16.6.155 it claims the host is offline.

I am confident I have carried out the steps correctly but happy to be wrong.

Steps:

RDP to jump host 10.129.x.x

Drop SockOVerRDP and Proxy, turn off AV and run

RDP to second host 172.16.6.19 using mstsc.exe as victor drop Socks....exe run as admin

run mstsc.exe connecting to 172.16.6.155

Any help appreciated greatly fingerguns

mild flower
dark nova
#

sometimes mostley been fine though

#

switching between us eu or browser if gets tilting

spare fossil
#

hey guys, i have an issue, in the login brute forcing module ,login form attacks section, i found the correct password, try to log in, but i keep being kick back... did you encounter something like that? i'm pretty sure i got the correct password though

fathom pendant
#

Make sure with the login forms your fail string is properly set (for post forms)

fathom pendant
#

"Keeps kicking you back" genuinely unsure what that means btw

spare fossil
#

got it

#

Thank you @fathom pendant 🦾

#

i was logging in on the wrong page 😂

daring wraith
#

Yo, im curious on how hackers hack into cameras, do they break in the system and crack the password of cameras?

vague token
#

Struggling with the last two questions on **MS01 **(AD Skills Assesment part 2)
After importing, I run Get-Module and it says it successfully loaded but it seems to be getting blocked. I've also tried running PowerShell as admin with Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass but I keep getting the error
The term '...' is not recognized as the name of a cmdlet, function, script file, or operable program.
Any one got an idea what I'm doing wrong?

fathom pendant
daring wraith
#

@acoustic owl which channel😉

fathom pendant
daring wraith
#

So they hack in the system

fathom pendant
daring wraith
#

Im good lil bro

acoustic owl
daring wraith
#

Im good for now lil bro

dim wolf
split glade
#

That "Exploiting Web Vulnerabilities in Thick-Client Applications" was violent

fathom pendant
#

@vital ice i don't accept random DMs btw

fierce dock
#

Legal questinon regarding osint tool h8mail

#

Would it be legal to run a check of all emails and password leaks associated with one domain for example facebook.com, like this would be the command to explain better (h8mail -t fcorp.com -q domain -c h8mail_config.ini). These passwords are already leaked on databases all the tool does is search those data bases using api keys. I do not want to accidentally get in trouble so can someone say if this is legal or not?

acoustic owl
dark nova
#

Did this fix the error? 😁 I am having the same issue, my understanding is the final host isnt booting up

fathom pendant
fierce dock
#

It would have been interesting to try and find my account

fathom pendant
#

Also there's haveibeenpwned

#

Checks if your email has been exposed in data breaches

fierce dock
#

Yes it searches a bunch of different databases such as haveibeenpwned when you provide api keys I don't think it actually brute forces the website or servers itself

dark nova
#

apologies didn't realise there are several tabs, you are very active in here thank you!

olive saddle
#

which module to chose after finishing the Kerveros attacks module?

  • NTLM Relay Attacks
  • ADCS Attacks
  • Active Directory Trust Attacks
next bronze
#

all of those are s tier

olive saddle
next bronze
#

probably ADCS, it's a very common vector

dim wolf
#

how does Kerberos Attacks hold up to those other three modules

next bronze
#

I'd say they're all very close

clear coral
#

I'm having some trouble connecting to the VPN using the connection file. Is this the right channel to ask?

next bronze
#

it's not vulnerable, there's 0 mention of vulnerabilities in the module

clear coral
#

I already checked the KB and the FAQ and found nothing relating to my particular issue\

dark nova
mild flower
#

yeah i just gave up, trying again tomorrow, thing is way to slow

fathom pendant
#

Not vulnerable, just misconfigured to allow inbound connections

clear coral
fathom pendant
#

Just above the exit message it says "operation not permitted"

#

Aka permission denied aka need root perms/sudo

next bronze
clear coral
fathom pendant
clear coral
#

Thanks it's working now

fathom pendant
#

Not allowing inbound port 53 connections from external entities

#

¯_(ツ)_/¯

#

yes

#

It's also just a showcase of how you can find info from dns

#

¯_(ツ)_/¯

#

You won't always need to

#

The source port bit is mostly just as a more stealthy approach

#

It's configured to accept requests from port 53

#

As it's seen as a DNS server making the request

#

Because dns default port is 53

#

Normally when you connect to a port, your system chooses a random port >40000 to establish the connection

#

It's why if you open a webpage then use netstat you'll see a random port and port 443/80

#

It's basics of how systems talk to each other on the connection layer, you need to send data as well as receive data

#

Yes

#

Like how ssh is 22

#

Ftp is 21

late moth
#

in using the metasploit framework moduel I'm trying to set up a postgresql database with metasploit and i'm following exactly the instructions in the module on the pwnbox and its failing . Anyone else have the same issue?

fathom pendant
#

I mean you asked why and you got a general answer, and started acting like a dick

#

Nah

#

Either way, you got your answer

late moth
#

keep getting no connection when i do db_status

next bronze
#

plenty of people has answered you properly but you refused to listen

fathom pendant
#

I mean, that's what it boils down to

#

And now you learned, don't ask questions in #general

#

You don't need to see things at a net admin level lmao

#

Just basic networking level

#

Key thing to learn; don't overthink

#

Sometimes the simplest answer is the most correct

#

And the nmap module explains why port 53 btw

#

It's where I got my info for it

dim wolf
#

yes that is what i said as well

#

the module explains why you would use something like source port 53

#

well i'm not the one teaching you. the module is

next bronze
#

what makes you think @dim wolf is a newbie

dim wolf
#

i believe the module gives you an example of when you would specify the source port

#

that should be adequate enough to answer your question then

late moth
#

if it isnt good enough then ask chatgpt

dim wolf
#

a sysadm will set up firewall rules to ensure that traffic is routed to proper ports

late moth
#

then cross reference it with google searches

dim wolf
#

in this case, port 50000 to port 53 (port 53 is likely not blocked by firewall rules)

fathom pendant
#

brother

#

HTB rank doesn't mean shit

#

chatGPT can be good at explaining concepts

#

but anything complex it loses the plot

#

like asking it a 20 paragraph question is different from asking a one sentence question

#

small questions yield stronger results

#

depends what you ask it

#

¯_(ツ)_/¯

dim wolf
#

your question basically comes down to critical thinking

fathom pendant
#

let's not dive into this as a hypothetical

#

whenever you want

#

no

#

nmap is just the beginning

#

nmap and footprinting tell you what you're looking at

#

most labs are web based as their entry point

#

lol no

#

here's the thing; not everything taught in the modules will be reflected in the labs

#

some require a bit more info than the base of what you're given

#

sure you can have a strong base of understanding

#

but you gotta be ready to just say "fuck it, we're sending it"

#

and research

#

as active machines are barred from having writeups

#

so there's no guide to fall back on

vital ice
# fathom pendant <@999651378471387136> i don't accept random DMs btw

It’s totally understandable and my apologies it’s just I wasn’t able to figure it out and was wondering if u can shed some light on the same question.

I will be trying again sometime soon and hopefully I’ll be able to find which module and figure out the damn answer to move on to something new.
Thanks for your suggestions also

fathom pendant
#

you can also google things

#
vital ice
# fathom pendant everything needed is in the module

I did check everything but not throughly but I will again once I sit down again. I also checked and tried google but wasn’t much of a help that’s why I decided to put it in here.
I will try again and if I couldn’t get the answer I will probably pop back here and get some more help

#

Much appreciated btw 🙏🏼 thank you’re for time

fathom pendant
#

my literal google query "get commands of an installed powershell module"

umbral gazelle
#

Hi all. I'm having a bit of trouble with the Oracle TNS section in the Footprinting module. I used the script in the lesson to download odat.py but when I try to run it, it gives me an error message saying: File "/home/htb-ac-1123725/odat/./odat.py", line 5, in <module>
from libnmap.parser import NmapParser
ModuleNotFoundError: No module named 'libnmap'

#

Anyway to resolve this issue?

next bronze
umbral gazelle
fair locust
#

General question. I'm new here and working through one of the modules. The content is great, but the lab access is horrible. The connection keeps freezing after about a minute, which makes it impossible to complete the exercises. Is this normal with high load times?

verbal dagger
#

working on this same module right now, still getting the error with mssqlclient after running the pip command. tried in my own virtual machine to make sure everything is up to date. i don't get the error, but it just doesn't connect at all. not sure where i can troubleshoot from here

verbal dagger
#

for mssqlclient?

fathom pendant
#

no for pip install

verbal dagger
#

still get the error

#

after mssqlclient, not the pip install

vital ice
fathom pendant
verbal dagger
#

i did run it with sudo tho..

fathom pendant
#

then sudo pip uninstall impacket --break-system-packages && sudo pip install impacket --break-system-packages

#

to force it to reinstall

verbal dagger
#

aight

fathom pendant
#

but i generally suggest just sticking to your own vm

#

it'll be an overall better experience ¯_(ツ)_/¯

verbal dagger
#

might do that. going to try reinstalling impacket on my vm and see what happens. if not, i'll move on

next bronze
#

use pipx pls

fathom pendant
verbal dagger
#

yea

fathom pendant
#

did you turn off the pwnbox when testing with your machine?

fathom pendant
verbal dagger
#

no, i just terminated it, i'll try again

fathom pendant
#

also pip is fine for the pwnbox testing

next bronze
#

they said so

fathom pendant
#

but pipx is better for your own machine

verbal dagger
#

just get "encryption required, switching to tls" and nothing else. i'm coming back to it later, going to work on something else. thank you for your help though, marcie

fathom pendant
verbal dagger
#

alright

fathom pendant
#

or reinstalling it

verbal dagger
#

same pip command?

fathom pendant
#

pipx is better

#

but if you don't have it installed

verbal dagger
#

got it

fathom pendant
#

sudo apt install python3-pipx iirc if it's in the repos

steep loom
#

has anyone been able to get the skills assement for the new API ATTACKS module? if so please send me a DM

verbal dagger
acoustic owl
steep loom
steep loom
acoustic owl
#

Or have one created by AI

steep loom
nova ruin
#

bug bounty hunting process module:

Which base metric value of the base score considers that attackers can only exploit a vulnerability if they reside in the same physical or logical network as the target host/application?

I tried all the answer formatting, but still I didn't get it.

acoustic owl
nova ruin
runic depot
#

couldn't run mysql in the pwnbox, anyone else have that problem? just did mysql and mysql not found

faint minnow
grizzled schooner
#

Web Shells: Laudanum
Uploaded the shell, but can't figure out how to find the path. When uploaded the website gives me a path, which brings me to a 404, noticed in the module that the syntax written was "//file/shell" tried that and it did a google search, any nudges?

grizzled schooner
#

tried \files\shell.aspx, \files\shell.aspx both to no avail, is it the type of shell I'm trying to use?

grizzled schooner
#

figured it out

trail sail
#

Hello,
I am doing the SQL Injection Fundamentals section "Intro to MySQL." The Pwnbox does not have MySQL installed. Is this normal?

SOLVED

Update, you need to install it with the following commands:
wget https://dev.mysql.com/get/Downloads/MySQL-8.0/mysql-server_8.0.35-1debian12_amd64.deb-bundle.tar
tar -xf mysql-server_8.0.35-1debian12_amd64.deb-bundle.tar
sudo dpkg -i mysql-{common,community-client-plugins,community-client-core,community-client,client,community-server-core,community-server,server}_*.deb

loud dagger
#

anyone else having issues with nmap version scan right now?

#

it's not working on my host machine, my vm, or pwnbox

rustic sage
#

What's happening?

cloud urchin
#

nmap not working would be a local issue. do you mean it's not working vs a specific target?

loud dagger
#

okay so i haven't tried it against other targets yet but turns out it only doesn't work with port 21 at least on this particular target. the scan just stops at around 83% and never finishes.
when i specify no ports it finishes the scan, but it doesn't give me the answer i need. i need the FTP server version and all it's giving me is the server name

#

it's for some reason refusing to enumerate port 21 which is coincidentally the only one i need

cloud urchin
#

the default service for port 21 is FTP. have you tried just ftping into it?

loud dagger
#

yeah i was able to ftp in and get the flag perfectly fine

#

i think the nmap thing might have been intentional because i got the correct answer from banner grabbing with netcat

normal sand
#

Module: Active Directory Enumeration & Attacks
Section: Skills Assessment Part I

Kerberoast an account with the SPN MSSQLSvc/SQL01.inlanefreight.local:1433 and submit the account name as your answer

I was gonna Kerberoast using Rubeus, but obviously the Tools folder we've had so far isn't present on the target machine. Do I have to compile Rubeus myself or is there a simpler method to get the Rubeus binary?

sharp tartan
#

.

wary plover
fathom pendant
normal sand
#

I'm thinking of committing all the binaries to a git repo for me to clone easily whenever I need it.

fathom pendant
#

just always make sure to checksum them (Get-FileHash -Algorithm md5 C:/path/to/file in powershell)

normal sand
fathom pendant
sturdy ivy
#

Howdy gang, currently going through the web-proxies module and used burp to inject the ;cat flag.txt;.
My question is, why do we need the ; ? Or a better question, what 'language' is being used?

fathom pendant
rustic sage
#

It's to end the previous command

fathom pendant
#

it's bash

#

it's no special language

fathom pendant
#

I believe it should be explained if not; there you go

#

it's basically as if you're doing
ping 127.0.0.1; cat flag.txt on the host itself

#

where it's reading the file in the webroot, flag.txt

spark spruce
#

does it only needs 20 points now