#modules

1 messages · Page 286 of 1

paper flare
#

please restart your VPN

split glade
#

Switching VPN and trying to spawn a target doesn't work either

sterile solstice
humble ravine
#

same, I'm currently on Linux Fundamentals, can't spawn the target

wicked apex
#

I see, ima move that there ig

rustic sage
#

im on footprinting but it doesn't seem to give me anymore available subdomains

#

I think its fixed now

#

even with a large wordlist, not sure what i'm doing wrong

#

Just spawned a target guys

humble ravine
sharp latch
#

hey guys, how to get permission to talk in general?

pseudo kiln
humble ravine
#

same

#

still no targets

wary plover
rustic sage
pseudo kiln
uncut sequoia
#

it's fixed for me

shut vapor
wary tendon
#

is there someone who can help me read through the report in the documenting and reporting section its difficult to know where to start and what to take screenshots and notes on. its all over the place. i was able to get into the dc01 host but i failed to document as i went. but everything was still up so i could capture it

latent frigate
#

Module: Windows Privilege Escation
Section: SeImpersonate and SeAssignPrimaryToken htb

impacket-mssqlclient slq_dev:'Str0ng_P@ssw0rd!'@$TARGET -windows-auth
Result: Encryption required, switching to TLS ==> breaks

Does anyone know what I am doing wrong. I am following the steps of the session

wary plover
# latent frigate Module: Windows Privilege Escation Section: SeImpersonate and SeAssignPrimaryTok...

The module uses a different branch from impacket. It is recommended as per the documentation to use pipx.

You can install it using the following commands:

sudo apt update
sudo apt install pipx
pipx ensurepath
sudo pipx ensurepath --global # optional to allow pipx actions with --global argument

Then clone the official git repo of impacket to get it's unreleased changes from https://github.com/fortra/impacket/tree/master

Installing them by going into the directory where impacket is installed and running python3 -m pipx install .

Now you should be able to use mssqlclient.py and try logging in again

GitHub

Impacket is a collection of Python classes for working with network protocols. - fortra/impacket

next bronze
wary plover
#

oh yeah even with v0.11.0 it works

next bronze
#

I think it's just impacket on pwnbox being weird, reinstalling with pipx is the right way to do things tho

wary plover
rustic sage
#

can someone please help me on the "The above server employs Client-Side, Blacklist, Whitelist, Content-Type, and MIME-Type filters to ensure the uploaded file is an image. Try to combine all of the attacks you learned so far to bypass these filters and upload a PHP file and read the flag at "/flag.txt" question in the type filters section of the file uploads module? am a trying everything but i just cant get rce? i am very confuesed and there dont seem to be any totorials on it besided this medium artical which i still cant follow.

wary plover
rustic sage
#

file uploads, type filters

hard sand
#

Hello

normal sand
#

I'm on the skills assessment for the Active Directory Enumeration & Attacks module. I was just wondering but when is a domain considered "compromised"? Is it when I gain local Administrator access on the DC? Is it when I have the credentials to a user belonging to the Domain Admins group?

next bronze
next bronze
normal sand
#

So I don't need to necessarily have the password for the user either, even a pass-the-hash to gain admin access would suffice as domain compromise?

rustic sage
#

ok

next bronze
#

compromising the DC vs compromising the domain is slightly different, to compromise the domain you should have domain level access, but once you have locan admin on DC getting DA is pretty straight forward

wary plover
next bronze
next bronze
#

yes

normal sand
next bronze
normal sand
next bronze
#

any user/users that have privledged access over the domain

#

well it doesn't even have to be a user, as long as you have privileged access

normal sand
next bronze
#

anything that gives you admin

normal sand
#

Okay ,thanks.

rustic sage
normal sand
wary plover
#

so you can perform a DCSync attack with a local admin on a DC

normal sand
next bronze
#

nah a local admin can't dcsync (talking about local accounts or SYSTEM here), but you can use the rights to save ntds which contains all domain creds or dump the registries to get the DC machine hash and dcsync with that @normal sand

wary plover
humble ravine
#

Module : Linux Fundamentals Section : Filter Contents

Hello, I'm currently done reading the whole section about "less/more , head/tail, sort, grep, cut, column, and more" commands.

Now I am at questions, and it is asking me to "Determine what user the ProFTPd server is running under. Submit the username as the answer." and "Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com/" website and filter all unique paths of that domain. Submit the number of these paths as the answer."

I have a feeling those questions are not related to the module I'm currently working on, is there an error or I should be able to solve those task with just what I learnt so far?

I'm srsly confused at "obtain the source code of the "site""

rustic sage
#

Module information gathering, i cannot seem to do this.

#

section fingerprinting

#

IP address and vhosts added in the /etc/hosts

#

hang on

#

^^ fixed my issue, vhost wasn't correct in the /etc/hosts file added ".htb" at the end instead of ".local"

next bronze
spare fossil
#

moduel:Login Brute Forcing/Service Authentication Brute Forcing/ssh service brute force, i have used the rockyou-10.txt, but nothing, and the full rockyou.txt is too long and server is only up for an hour. any hint?

#

i must be missing something,i also tried the other rockyou-20.txt and up

next bronze
spare fossil
spare fossil
spare fossil
brave vale
#

Information Gathering (web edition)
Skill Assestment

Can't find the hidden hash of the admin api

#

Also in Information gathering I got issues installing Scrappy

next bronze
#

if it's a 301 you should follow it

brave vale
#

got it let me check

humble ravine
trail egret
#

stuck in this question : Enumerate the target Oracle database and submit the password hash of the user DBSNMP as the answer.

brave vale
trail egret
next bronze
humble ravine
#

thanks Anyways, I gotta do a bit of skipping and going back but I can proceed

wild cape
#

Hey guys!, I found an issue with one of the sections in the OSINT: Corporate Recon module, how/who do I report it?

brave vale
#

unable to connect

next bronze
#

did you add it to your vhosts? and try add a / at the end

brave vale
#

yep, is only where the hash is I cant access, I can connect to the robots.txt and else

hard sand
#

Hello

brave vale
#

sometimes I can curl it but I can't see it from browser btw

next bronze
#

just checked it works for me

brave vale
#

if you do curl can you see the redirection?

#

ill try to reset

hard sand
#

Hello

brave vale
next bronze
#

works for me

#

did you enter the port number

brave vale
#

yep

#

can I send ss dm?

next bronze
#

you can send it here and delete after

brave vale
#

got it

next bronze
#

use the browser

#

also you can add -i to show where the redirect goes

brave vale
#

btw now it shoes this

next bronze
#

https?

brave vale
#

no way

#

btw when I was in the robots file I only changed the directory to the admin one

next bronze
#

got it? remember to delete the screenshots

brave vale
brave vale
clever topaz
#

been trying for 2 hours im dying

#

someone pls send help for windows priv escalation SeDebugPrivilege

hidden hemlock
#

please some one can help me with question 58 ATTACKING ENTERPRISE NETWORKS (Web Enumeration & Exploitation)?

clever topaz
hidden hemlock
#

question 5

#

please some one can help me with question 5 ATTACKING ENTERPRISE NETWORKS (Web Enumeration & Exploitation)?

solid wadi
#

Hey guys, im currently in the Nmap module, doing the last lab (Hard Lab 3) and i'm currently stuck (spoiler alert to those who still dont get here):
||Im stuck in finding the port of the service i got to scan, to the moment i've tried using decoys, setting the initial-rtt-timeout to 10000ms, setting --max-retries to 10 (Last 2 to avoid missing any incoming packet) and tried running a UDP scan just in case the service was in UDP and not TCP, i also tried running ACK scans with even less results. Some ports are still shown as filtered but are way too many like to be possibly be something (tends to be around 20%) of each scan. The question of the lab is Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer. and the hint is Our client also mentioned that they were forced to add a service that plays a vital role for their customer because they require large amounts of data.. I Don't know what else to do here, if possible, could anyone give me a hint on which direction to go?||

brave vale
#

Did you use port 53 for evasion?

#

that worked for me

solid wadi
#

i did aswell, altho it worth giving it another shot

brave vale
#

ok tell me if you got it

solid wadi
#

tcp scan gave me nothing to the moment with -g 53

vale geyser
solid wadi
#

doing udp scan rn

solid wadi
brave vale
#

also disable arp ping and host discovery

solid wadi
#

did it

brave vale
#

you are doing all ports scan, right?

#

try with 1 max retry just to prove

solid wadi
#

doing -F since theres a IPS installed on target

#

but gonna do -p- rn

#

which scan type should i do, Stealth SYN or UDP?

brave vale
#

very specific hint:

#

||you're trying to find a tcp service||

solid wadi
#

saves me a lot of time, thx

solid wadi
#

gonna try once again

brave vale
brave vale
next bronze
solid wadi
#

been doing this for a couple hours last night, couldnt find the port i had to attack

#

thx a lot dude

brave vale
#

nw

solid wadi
#

althought something i actually cant get my head around is, why would setting the tcp source port to 53 avoid IPS detection and by doing so, avoiding dropping the connection?

next bronze
#

port 53 is commonly used by dns servers

brave vale
brave vale
solid wadi
#

yea, i know that, but what would be the point of just allowing the source port to be 53

#

"Im gonna let DNS servers to connect to my secret FTP service cus why not"

next bronze
#

this is an inbound rule, the target could be sending requests to a dns server and it's replying from port 53

solid wadi
#

Ohhh, alright alright

#

and by doing so, it would allow any incoming connection as long as its source port is 53?

next bronze
#

that's how it's configured in the lab

solid wadi
#

yea, i know this is scenario-specific configuration, but i just figure out then what was the 'mistake' in the machine that allowed enumeration in that port with nmap

solid wadi
next bronze
#

I wouldn't call it a mistake, just abusing common rules

solid wadi
#

alright

next bronze
#

but it's just how this lab is set up

brave vale
solid wadi
brave vale
#

awsome

solid wadi
# next bronze but it's just how this lab is set up

I know that, i remembered that guy from few days ago that did this same lab and questioned the same thing, but i think he didnt know how to ask his question and neither how to understand other people's answers

brave vale
#

When I did the module the hardest for me was connecting to grab the flag but you've already do it haha

#

althoug it was only nc

solid wadi
brave vale
#

for sure

solid wadi
#

well, gonna take a break, thx again yall :D

spiral scarab
#

Hey everyone, where could I get help for the skill assessment for the module Linux Privilege Escalation ?

spiral scarab
#

lol

#

Well simply put, I'm doing the skill assessment and currently trying to get the flag 4. This flag can be read only by the tomcat user. So far I managed to find the credentials for the Tomcat Web Application Manager. Checking on both the manager and mfs, I found out I can upload a war file to then get reverse shell. I'm trying to use mfs with the exploit multi/http/tomcat_mgr_upload but I keep getting an error.
Here's the what I get :


[*] Started reverse TCP handler on 10.10.15.96:4444 
[*] Retrieving session ID and CSRF token...
[*] Uploading and deploying 5wVDX...
[*] Executing 5wVDX...
[-] Exploit aborted due to failure: unknown: Failed to execute the payload
[*] Exploit completed, but no session was created```
next bronze
#

<@&861185840277487616>

wary plover
dim wolf
spiral scarab
hidden hemlock
wary plover
# hidden hemlock how ?

the question states to enumerate the accessible services, the path goes over how to enumerate this and try to probe at those services looking for a flag, else you'll need to go over the modules again

hidden hemlock
#

that is the question
Steal an admin's session cookie and gain access to the support ticketing queue. Submit the flag value for the "John" user as your answer.

rustic sage
hidden hemlock
#

i try to use the cookie but i can't, if u have command please help me

rustic sage
#

Did you get the cookie?

wary plover
#

it even recommends a certain tool / plugin

rustic sage
hidden hemlock
#

yes i do all but is not work i have error message for firefox when i add cookie

rustic sage
#

Can you send a screenshot of it?

hidden hemlock
#

5 mns please

rustic sage
#

Where are you adding the cookie to?

fathom pendant
hidden hemlock
#

First-Party Isolation is enabled, but the required 'firstPartyDomain' attribute was not set.

#

that is the message i have

rustic sage
#

Well in that case, you need to navigate to the browser dev tools --> network ---> storage and add the cookie by using the name and value accordingly

hidden hemlock
#

ok i try

rustic sage
#

Do you know how to do it?

  1. Type about:config in the address bar and hit enter

  2. Search for "privacy.firstparty.isolate"

  3. Double click the preference to set It to false.

hidden hemlock
#

ok thank i do

#

thank is work now

latent frigate
fathom pendant
latent frigate
fathom pendant
#

No need to clone the repo

latent frigate
#

Result: "impaclet already seems to be installed

fathom pendant
#

Then pipx upgrade impacket iirc

#

Or it's update

next bronze
#

the default impacket install works, I tested it on the module with pwnbox

#

mssqlclient.py

latent frigate
#

Im using right now the pwnbox.
The default mssqclient.py gives me the same error

fathom pendant
#

Did you specify --local-auth

latent frigate
#

yes

fathom pendant
latent frigate
#

ill restart the pwnbox and try again. Maybe it got mixed with cloning the repo, reinstalling all that thing

fathom pendant
#

Did you try without?

latent frigate
#

i am following the description in the module, it means always using -windows-auth

next bronze
#

fresh pwnbox and target

latent frigate
#

should I have the same result my local machine (not pwnbox)?

next bronze
#

you should have the same result anywhere

#

if you're having problems on your own machine upgrade impacket

latent frigate
#

ok ill do that. I have the impression that i have a lot of "impackts" now im my machine

next bronze
#

you can remove the apt version, all you need is the pipx install if you just want to use it in the terminal

latent frigate
#

just with apt purge impacket* and keep the rest?

sharp pike
#

is there a preferred connection limit when using hydra?

next bronze
next bronze
fathom pendant
sharp pike
#

smtp

fathom pendant
#

Don't need too many, it's a slow service to respond

sharp pike
#

i ask bc im getting this error

fathom pendant
#

I don't recall using hydra to attack smtp

sharp pike
#

attacking common services/attacking email services

latent frigate
#

Thks all for the support.

sharp pike
fathom pendant
#

Also the service used to bruteforce is pop3 not smtp

#

Or imap

#

As those services have authentication protocols

#

Rockyou should work I just checked

sharp pike
fathom pendant
#

Instead of just copy/paste

#

As harsh as it sounds. If you're just hitting the question then immediately jumping to the guide, you're setting yourself up for failure

low crescent
#

^ The way modules are designed in most cases is that they teach you to understand

fathom pendant
#

I suggest the walkthroughs as a red-button last resort

#

After checking everything else

hybrid current
vale knoll
#

I have a problem in Pivoting, Tunneling and Port Forwarding module in ICMP Tunneling task.

I can ping the pivot host, the nmap successfully finds 22 port, I can see a SSH banner when I connect with netcat but performing ssh login times out every time and results in error connection closed by <pivot ip> port 22. I have reset the target multiple times. Do I not understand something and should try a different approach or the host is simply not working properly?

#

The task states that I should ssh to the pivot host

young cove
#

Did you solve It?

hexed kestrel
#

heya. i recently decided to start learning bug bounty again. currently doing the using web proxies module, and running into an issue in the automatic modification chapter, specifically when using ZAP's replacer. I try to replace the User-Agent string with User-Agent: HTBAgent 1.0 as instructed by the module (well, a similar string)

my match type is set to Request Header (will add if not present)
Match string is set to User-Agent
Replacement string is set to User-Agent: HTBAgent 1.0
Match Regex is enabled
The replacer thing is enabled
in the initiators tab only Apply to all HTTP(S) messages is enabled

Anyone know if any of this is wrong? when i enable breaker and look at what the user agent is in my requests it is still the standard thing. what did i mess up in my settings?

Nevermind i'm just dumb

#

The URL field is empty in the replacer window ^^

spiral spoke
#

Hi! I'm in Password Attcks - Password Reuse / Default Passwords
I've already solved the lab and... I dont know why the instruction is "Use the user's credentials we found in the previous section and find out the credentials for MySQL", I mean, it wasn't necessary to use those credentials, but the default cheat sheet or am I missing something? I was looking through the ssh session of the user sam but I found nothing

#

When I found the answer I was like.. wtf why?

runic depot
#

Q1 How many Pen Testing Labs did HackTheBox have on the 8th August 2018? Answer with an integer, eg 1234.

#

clicking on august 8 2018 i just get a godaddy site

sharp pike
runic depot
#

can someone check out what im clicking wrong on the webarch site

glacial bay
#

I am on Password Attacks > Credential Hunting in Linux in the Academy
The hint states "From other hosts on the network, our colleagues were able to identify the user "Kira", who in most cases had SSH access to other systems with the password "LoveYou1". "
But this doesnt work to get me on the system. Do I need to do a mutation list of that password?

jolly raptor
#

guys i’m currently looking at smbclient in a module im doing, im trying to install smbclient on my ParrotOS VM but keep getting errored

#

i’m doing sudo apt install smbclient

#

error i’m getting is unmet dependencies, with samba-common and samba-libs

glacial bay
jolly raptor
#

appreciate it

fathom pendant
fathom pendant
wary plover
wary plover
fathom pendant
#

<@&861185840277487616> Ban @rustic sage

quasi wave
#

hi for the linux file transfers section of file transfers module, I am trying to transfer the file but its saying permission denied. Here's my terminal after I SSH into target server and start http server in pwnbox. This is the terminal for target only, not pwnbox:

htb-student@nix04:/home/mrb3n$ wget http://10.10.15.19:8000/upload_nix.txt
--2024-07-11 20:19:50--  http://10.10.15.19:8000/upload_nix.txt
Connecting to 10.10.15.19:8000... connected.
HTTP request sent, awaiting response... 200 OK
Length: 32 [text/plain]
upload_nix.txt: Permission denied

Cannot write to ‘upload_nix.txt’ (Permission denied).
#

if you need pwnbox terminal its just I have http server running

fathom pendant
#

what's the error message in your pwnbox?

#

oh

#

wait

#

even simpler issue

#

you're not mrb3n so you can't write to his home

fathom pendant
#

cannot write to == local == you can't write to the file location/cwd you're in

quasi wave
#

ya but in htb-student location won't let me write either

#
htb-student@nix04:~$ sudo wget 10.10.15.19:8000/upload_nix.txt
[sudo] password for htb-student: 
Sorry, try again.
[sudo] password for htb-student: 
htb-student is not in the sudoers file.  This incident will be reported.
fathom pendant
#

why are you trying to do sudo?

quasi wave
#

without sudo it worked

fathom pendant
#

amazing that kek

quasi wave
#

solved challenge

fathom pendant
#

the original reason for permission denied is because you were trying to write to another user's home directory

quasi wave
#

Ok. Why didn't it work with sudo?

fathom pendant
#

because in this instance, htb-student doesn't have sudo permissions

quasi wave
#

yes that explains error message silly me

fathom pendant
#

as stated htb-student is not in the sudoers file.

quasi wave
#

ya ok. then in this case sudo not required so I'm good

vernal hedge
#

yep, you can check what you can run with sudo by typing “sudo -l”

vernal hedge
fathom pendant
#

there are only a handful of times where the error is complicated and doesn't explain the issue

quasi wave
#

ok got it

vernal hedge
#

Oh no my GIF didn’t work 😂

fathom pendant
vernal hedge
#

Alright, thanks

glacial bay
#

||L0vey0u1!||

fathom pendant
#

in which case; yes the mutated wordlist

#

but it depends on which section

glacial bay
#

yes, just the initial access with Kira

fathom pendant
#

the will section yes does require kira

glacial bay
#

yeah, now onto finding will's stuff

fathom pendant
#

btw for this module: always check C:/Users and /home/ for a shortened userlist

#

the Windows labs and Linux labs are directly connected to the other respective OS labs

#

so all Windows labs are connected and all Linux labs are connected in this module

#

(except the skill assessment)

#

but kira password does exist in the large mutated password list

glacial bay
#

and that didnt take long to finish that section after I got on, lol

worn matrix
#

.

jade latch
#

I turned off real time check for windows defender ( it shows a text alert in the windows security home page). i've tried resetting the target, but it happened twice already. it does say it wants to update, and searching up the error code it is related to updating. i don't think there would be an issue with that though

#

Pivoting, Tunneling, and Port Forwarding - Double Pivots - RDP and SOCKS Tunneling with SocksOverRDP

zealous rune
#

Hello. Looking for hint on password attacks easy lab. Found a couple of services and trying to bruteforce using password lists and hydra. I've tried the module resources, mutations and couple other lists. Am I on the right track?

fathom pendant
#

Also most services can handle 48 threads

zealous rune
#

The regular wordlist provided in the module resources?

fathom pendant
#

Yes

zealous rune
#

Ok I thought I had tried that I'll double back and make sure I'm not getting confused. Thx 4 the hint

#

I forgot that there was also a username list in the resources.... gonna give it a try with that

#

This should take half hour or so at least right?

fathom pendant
#

also -u to have it cycle through the username list first instead of trying every password against a user then switching to the next user

#

also threads

onyx cairn
#

For Web Requests page 6, I tried doing it in curl on my local pc, and it didn't work unlike the previous ones? My workstation instance ended so I'm trying to figure out if I need to wait a while again or if I'm missing something myself.

#

I just got this 🤔

rustic sage
#

I mean you're getting 200 ok?

#

I don't think "test" is a valid city for you to get any results back

sour copper
#

what does -p in this command do?
bash -p

ocean night
#

man bash

rustic sage
#

privileged shell

ocean night
#

No

sour copper
ocean night
rustic sage
#

Lol

ocean night
#

TLDR it clears a number of variables - it doesn't grant privileges, but rather provides a "clean slate", with some behaviors disabled. TIL

rustic sage
#

Oh ok

ocean night
#

The bash binary has no SUID flag, so would never escalate to another user, unless it's been modified. To escalate, you'd need to sudo bash, or sudo su.

#
The -p flag in the bash command stands for "privileged mode". When you run bash -p, it starts a new Bash shell in privileged mode. This mode makes the shell act as if it had been invoked by the superuser, even if it hasn't been. Here are some key aspects of what this mode does:

Disables Processing of the $ENV File: Normally, Bash processes the $ENV environment variable when it starts in non-interactive mode. In privileged mode, this processing is disabled to prevent potential security risks.

Disables Import of Shell Functions: When in privileged mode, Bash does not import shell functions from the environment. This helps prevent untrusted functions from altering the behavior of the shell.

Disables BASH_ENV Variable Processing: The BASH_ENV environment variable, which can specify an initialization file to be executed when the shell starts, is ignored in privileged mode.

Disables History File Expansion: History file expansion is turned off to prevent inadvertent or malicious command execution from the shell history.

The primary purpose of this flag is to enhance security, especially when a shell is being started in an environment where security is a concern.
#

Every day is a school day 😆

rustic sage
wary plover
ocean night
#

Yeah, done a load of house work, gonna go back to bed shortly for attempt number two

wary plover
#

hope you'll be dreaming of vileda products 😛

ocean night
#

lol

#

I'm not that civilized

glad citrus
#

I hate the password attack module. I’m almost done with it, but now I need to go back and find Kira’s password again to even start the much later lab.

acoustic owl
fathom pendant
glad citrus
#

Yes I’m working the path. Would really like to get this module behind me.

onyx cairn
onyx cairn
#

actually content-length is 12 instead of 0

#

I don't see any content though?

rustic sage
fathom pendant
tacit grove
#

stuck on this, any clue?

fathom pendant
acoustic owl
runic depot
#

What is the API key in the hidden admin directory that you have discovered on the target system? (if you need help DM. very hard for me and took like 2 hrs)

rustic sage
#

i did '$pip3 install scrapy' but had to change it i dont remember what to though

#

also i am trying to do what was stated in the conversation, and dont really understand

#

like are the modules in my files

#

or is it something external

runic depot
#

@rustic sagewhich q are you on

rustic sage
runic depot
#

A

clever topaz
quasi wave
#

how good is the OSINT module and which main platform boxes are for practicing OSINT?

#

I think OSINT is something I plan to study at some point in the future

#

I’m thinking its a complement to pentesting

supple agate
#

Has anyone completed the API attacks module? Currently stuck on the Broken Authentication part. I think the solution involves brute forcing the otp api endpoint but ffuf isnt returning a password. I might be attacking the wrong endpoint, not sure

rustic sage
#

Nvm you have an output lmao

#

You can see content length is more than 0

storm elk
next bronze
rustic sage
fathom pendant
rustic sage
#

😂

fathom pendant
silk void
#

If they give me a VIP htb voucher, how much time do I have to claim before it expires?

tacit grove
rustic sage
#

What

next bronze
#

<@&861185840277487616>

glass quail
#

bot?

eager ledge
#

Hi,

Module: ACTIVE DIRECTORY ENUMERATION & ATTACKS
Section: Bleeding Edge Vulnerabilities

I am doing the steps shown for "PetitPotam". So far, I have managed to get the base64 encoded certificate for DC in the ntlmrelayx window by executing petitpotam.py. Now, I am trying to get the TGT from this certificate using gettgtpkinit.py. The base64 certificate that I get is very long and its starting is same as the one shown on the section. But the end of the certificate is different than the one shown in the section. And when I execute the command python3 /opt/PKINITtools/gettgtpkinit.py INLANEFREIGHT.LOCAL/ACADEMY-EA-DC01\$ -pfx-base64 MIIStQIBAzCCEn8GCSqGSI...SNIP...CKBdGmY= dc01.ccache, I get the following error:

#

Since the base64 certificate is very long, I tried storing its content on a file and then use -cert-pfx file instead of -pfx-base64 {base64_string} and it also gives me following error:

shut quest
eager ledge
#

I am copying the whole string

viscid crescent
#

Hi

#

Im having issues connecting to an IP address from Information gathering module, I've already tried reset the machine, but kinda seconds later of started, I have no connection anymore with the addres in question

rustic sage
#

Is the correct VPN connected?

fathom pendant
viscid crescent
#

Im pretty sure im using vpn

fathom pendant
#

As it's using your 192.168.x.x internal ip

viscid crescent
#

double, triple check

fathom pendant
#

Not the 10.10.x.x assigned by htb

#

ip a

fathom pendant
#

You're generally not gonna ping them as they're containers

viscid crescent
fathom pendant
#

http://ip:port in the browser

viscid crescent
fathom pendant
#

Use bridged networking for your vm

viscid crescent
viscid crescent
fathom pendant
#

Oh

#

Then yeah it's your router throttling it

viscid crescent
#

thx im on it

fathom pendant
#

Basically some protection on your router is thinking that there's something malicious going on

rustic sage
#

Can it be disabled?

fathom pendant
#

Depends on ISP

#

some let you mess with the router more than others ¯_(ツ)_/¯

#

Imo you shouldn't be doing pentesting (even learning) on baremetal

fathom pendant
rustic sage
#

Routers run Linux mostly so if you could get an exploit working and get root on the router you could mess around

fathom pendant
#

Most ISP (in US) only lend you the router, meaning they still own it

#

As it's a router/modem combo

rustic sage
#

Same here yeah

fathom pendant
#

Most allow a level of administrative access on the router

rustic sage
#

The only admin access you get is the ability to manage the network/passwords and stuff

viscid crescent
#

Is -my router- issue

#

pwnbox works good

rustic sage
#

I am talking actual root shell on the router

fathom pendant
rustic sage
#

I'm not doing it

fathom pendant
#

Yes and I suggest not advising others to do it

#

Because if you brick it ISP can basically tell you you're SOL

shrewd vine
#

Hey, i'm stuck on 3rd Question of "Password Attacks" module Section "Network Attacks" which states "Find the user for the RDP service and crack their password. Then, when you log in, you will find the flag in a file there". Already tried all possible techniques I remember, no results. Can someone help please, thanks in advance!

spring horizon
#

Im not sure if I remember correctly, but I think you can just brute force it using hydra with the provided lists in Resources

shrewd vine
# spring horizon Im not sure if I remember correctly, but I think you can just brute force it usi...

I attempted brute-forcing using Hydra, but it's yielding numerous false positives. I also used crackmapexec, but it didn't yield any results. I generated a custom user wordlist using 'net users' commands via Evil Winrm and tried brute-forcing with it, yet still no success. Additionally, I created a custom password wordlist using John, based on the provided rules.list from the resources, but it generated over 100,000 passwords, which will take days to process.

rustic sage
#

Hello 👋

spring horizon
#

i dont think you need to mutate the lists yet for this question.

#

i ll check if i have some notes somewhere for this

shrewd vine
thorn hawk
#

Good morning locos. I am on the Web Attack module at the XXE exercise Advance File Inclusion. I have made all the steps required and i get a behaviour that is normal. But while my script gets downloaded as we see in the second picture when ithe response in Burp does not show what is intended. The text inside the script is <!ENTITY joined "%begin;%file;%end;"> . Do you know why this behaviour does not bring the requested file in the BURP answer?

spring horizon
#

ok i ddint have notes, but i spinned up the machine again and was able to get creds using brute force

#

are you sure you tried the lists provided in Resources in the lesson?

shrewd vine
spring horizon
#

i ll try to log in to make sure it works

rustic sage
#

I'm an Hacking professional

#

Feel free to contact me regarding help

shrewd vine
spring horizon
#

well it works for me, using: hydra -L username.list -P password.list rdp://10.129.202.136 -t 32 i got a valid login and could RDP to target with xfreerdp

shrewd vine
shrewd vine
spring horizon
#

thats weird.. nope, user starts with c and psw 7

shrewd vine
#

Got it

shrewd vine
spring horizon
#

yea

shrewd vine
spring horizon
#

what error you get?

shrewd vine
#

Thats the issue, because of which i wasted around 7-8 hours now

spring horizon
#

i have problems with rdp too sometimes, xfreerdp just refusing to connect, but usually it was ok after resetting the box

shrewd vine
# spring horizon what error you get?

[05:20:41:797] [1254475:1254476] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[05:20:41:797] [1254475:1254476] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[05:20:44:018] [1254475:1254476] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[05:20:44:018] [1254475:1254476] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[05:20:44:018] [1254475:1254476] [ERROR][com.freerdp.core] - freerdp_post_connect failed

shrewd vine
spring horizon
#

:\

shrewd vine
spring horizon
#

no worries. check your dms

stone hare
#

I'm on attacking common services SQL db's, if i access the server without -windows-auth i can use commands, but i can't access flagDB, and if i use the windows auth flag, it just closes and I can't do anything. Any guidance?

supple scaffold
#

hello , can someone help me with Web Enumeration under start with hackthe box

im trying to find this file /usr/share/dirb/wordlists/common.txt

but its not there , i dont find the right txt file

supple scaffold
#

ok thanks

#

it found nothing

split glade
supple scaffold
stone hare
#

and i cant enumerate anything else

supple scaffold
#

no error , it finish but with no result , because i coudnt find the file i used a guide on the internet and he do get results

split glade
stone hare
supple scaffold
split glade
#

The share doesn't need to exist, responder will catch any request with a NTLM hash made to a smb share on your tun0 IP

split glade
stone hare
#

I didn't add share because idk the share

split glade
#

The share doesn't need to exist, responder will catch any request with a NTLM hash made to a smb share on your tun0 IP

soft reef
#

I done all questions on the new API Attacks but this question. Any that could help?

stone hare
#

@split glade even after adding the share, nothing has happened, this is so confusing to me

split glade
stone hare
split glade
#

I had troubles with sqsh on kali

wet aspen
#

am facing the similiar issue... i tried many ways but it still isnt working

stone hare
#

Both instances nothing is captured @split glade

#

actually i think i might have figured it out

viral lotus
#

Quick Question is there a way to bookmark modules on the dashboard of your pathway to make it easier to remember which are priority to re-visit? if not is this something I can raise a feature request for?

storm elk
#

no

#

and you can use /feedback

thorn hawk
split glade
rustic sage
upbeat oak
#

I haven't been able to connect to the target host for 2 days now. Trying to run a simple metasploit exploit, can't even nmap the target host is anyone else experiencing this issue?

thorn hawk
thorn hawk
thorn hawk
steady jetty
#

Module: Information Gathering - Web Edition
Section: Skill Assessment
Question: What is the API key in the hidden admin directory that you have discovered on the target system?
I used gobuster but I couldn't get any output, can anyone help?

upbeat oak
steady jetty
#

yes

upbeat oak
#

Then you just need to go through that results.json file again

viral lotus
#

module: Network Enumeration with Nmap - Question: how do you get the IP you are required, I used the one thast is mentioned/used above 10.129.2.18 but it doesn't bring any results, I know how to use nmap through CTFs. I have gonbe back through the material to find another IP but couldn't I guessed the OS but obviously, im curious about the process as when I rsan the nmap command it kept coming back with a 10.10.16.1 traceroute. thanks for any help

rustic sage
viral lotus
quick pond
#

anitadik

#

ah god please

#

fk me

thorn hawk
#

very strange. Could it be that for the submitDetails.php folder there is some type of protection for xxe which I dont see? but for /flag.php there is not?

sweet jewel
#

hey, im doing the "Intro to C2 Operations with Sliver" module and am getting weird errors when running a bloodhound collector via bloodhound-python
my command:

proxychains bloodhound-python -u [redacted] -p [redacted] -ns 172.16.1.15 -d child.htb.local -c all --dns-tcp --dns-timeout 30`

error:

dns.resolver.NoNameservers: All nameservers failed to answer the query _ldap._tcp.gc._msdcs.child.htb.local.localdomain. IN SRV: Server Do53:172.16.1.15@53 answered SERVFAIL`
  • running the collector locally with sharphound works perfectly well
  • omitting --dns-tcp causes a lifetime resolution timeout, same with --dns-timeout
  • 172.16.1.15 dc01.child.htb.local child.htb.local is added to my /etc/hosts
  • specifying -dc dc01.child.htb.local does not resolve the error
  • afaik, there is not a secondary domain controller (dc02.child.htb.local)

any help would be appreciated 😄

next bronze
next bronze
#

HMM can you reach the host in the first place

next bronze
#

hmm yeah looks like problems with the dns server there

sweet jewel
#

voodoo magic

next bronze
#

increase timeout with nslookup

#

oh there might not be an easy way with nslook up, maybe dig dig @8.8.8.8 example.com +timeout=10

high reef
#

i tripppled encoded the payload

#

and i still can't get it to work properly

next bronze
#

it's joever

#

restart the lab lmao

sweet jewel
#

confusion maxed out

high reef
next bronze
#

I assume if it's a machine in the domain the hosts and ip are already cached

high reef
sweet jewel
clever topaz
#

I need put the dmp into mimikatz directory?

next bronze
#

no? any dir you have write and read access to is fine

#

dump it with procdump and load into mimi

bright coral
clever topaz
next bronze
#

doesn't matter as long as you can read from it

#

what's the error you're getting

clever topaz
#

Memory error

next bronze
#

... yeah like... what's the exact error

atomic arch
#

hi

viral lotus
#

random question, why would a port number be different on the raw scan to the port in the html file?

eager ledge
#

Hi
Module: ACTIVE DIRECTORY ENUMERATION & ATTACKS
Section: Bleeding Edge Vulnerabilities

I am doing the PetitPotam attack. After using getnthash.py, I get the NT hash for the Domain Controller from the TGT. Now, to perform DCSync using hash, I also need the LM hash. How can I find this?

next bronze
#

if you're using impacket you can just do --hashes :<nt hash>

eager ledge
#

Yeah, just tried that and it works!

clever topaz
wide river
eager ledge
#

Why is this happening and what can I do to resolve it?

next bronze
#

try to coerce again, but for this attack there isn't much point of using rubeus

#

if you've able to use getnthash and secretsdump you're good to go

eager ledge
#

What do you mean coerce again? Use petitpotam.py to get the certificate base64 again?

next bronze
#

yes

onyx cairn
onyx cairn
storm elk
onyx cairn
#

hmmm I shall try that 🤔

storm elk
#

it is at the very second to last line of your screenshot

onyx cairn
#

Yeah I see what they mean now

#

it just blends in xD

sly lark
calm pewter
#

I had a query in a challenge. Is this the right place to ask? Or some other channel?

calm pewter
#

For some reason

dim wolf
calm pewter
pulsar fossil
#

I have a question I am trying to do the linux fundamental module I'm stuck on the "find files" it keeps giving me permission denied and the solution is doesn't help.

pulsar fossil
#

yes I am @fathom pendant

#

@fathom pendant do I need to update?

fathom pendant
#

So when you do whoami it says "htb-student"?

#

If not: then you aren't ssh

#

The target is the "Click here to spawn target!" / 10.129.x.x ip

#

Spawn Instance is the in-browser vm, pwnbox

#

They are not the same

pulsar fossil
#

@fathom pendant nevermind I need to 2>/dev/null to remove the errors

fathom pendant
#

Btw you won't be able to update targets

#

As they're not connected to the internet

onyx cairn
# storm elk I see it too

huh that doesn't work though, I'm looking for a flag, that's just the output it's giving to the search result

grand loom
#

whats your guys opinion on the web services and api module? it seems really confusing to me

dim wolf
#

Windows Lateral Movement, focusing on both offensive and defensive?

#

actually, the module artwork has the win11 logo, so we're getting some good up-to-date content

fathom pendant
#

I mean

#

Plenty of offices still use 10

ebon nymph
#

can someone explain me about this question actually what i need to do here even i am able to login with provided details :- Module:-Broken authentication (section:-Enumerating users) do i need to fuzz ?

ebon nymph
#

dont worry i have changed the target ip

dim wolf
#

yea but it's nice to see the win11 content as well

next bronze
#

I mean win11 and win10 are pretty much the same under the hood

dim wolf
#

i haven't seen too much of it

onyx cairn
next bronze
#

yes

fathom pendant
rustic sage
#

I could be wrong I don't remember exactly

dim wolf
#

still curious about the module though

rustic sage
#

web requests

fathom pendant
#

He means the new one

dim wolf
#

no, the Lateral Movement module

ebon nymph
#

can someone also help me

rustic sage
next bronze
dim wolf
#

those all seem to correlate with privileged access

onyx cairn
dim wolf
#

i think there are impacket scripts that exploit access to those

fathom pendant
#

As described by the section @ebon nymph

ebon nymph
rustic sage
ebon nymph
#

bro can i use burpsuite here instead of ffuf

proven pasture
#

Footprinting module - DNS
I am struggling for the last question, from what I understood I am supposed to do some dns subdomains bruteforcing, but I can't get anything useful back, I don't even find all the hosts that I know exist from the zone transfer (especially dev doesn't show up, i tried with my own list to make sure)
Here is my command

dnsenum --dnsserver 10.129.73.53 --enum -p 0 -s 0 -f /usr/share/wordlists/seclists/Discovery/DNS/namelist.txt -r inlanefreight.htb

Am I doing something wrong, or should I just keep trying every wordlist from SecLists until it works ? I tried to enumerate the internal zone as well but it returns an error so I am guessing it is not there
Any help will be greatly appreciated !

fathom pendant
fathom pendant
#

dig axfr inlanefreight.htb @ip

proven pasture
#

Wait is there no bruteforce for the last question ? The hint is about wordlists so that seems odd

fathom pendant
#

it is

onyx cairn
fathom pendant
#

but to get the right initial subdomain you don't need to bruteforce it

#

but you can't bruteforce a subdomain of a subdomain that you don't know about

fathom pendant
#

the answer will be a.b.inlanefreight.htb

proven pasture
#

Oh yes ok, it is ||internal|| right ?

fathom pendant
proven pasture
#

oho

fathom pendant
#

you can already transfer to that subdomain, why do you need to bruteforce it?

stone pilot
#

hi guys,i have problem, mysql -h 127.0.0.1 -u chamilo -p chamilo
Enter password: 03F6lY3uXAP2bkW8 .I enter right pass,but mysql just silence. if i enter wrong pass,it write what pass wrong

proven pasture
#

I thought maybe it didn't show me everything but it makes sense now that I won't find anything more
If it accepted to transfer then it trusts me completely

fathom pendant
#

well

#

it just means that it's set up for those 2 zones

#

inlanefreight.htb and ||internal||

frosty parcel
#

Hello, any news about the push of the module api attacks in cbbh ? il will launch my exam next monday and i don't want to be surprised ^^

proven pasture
#

ok interesting
And is there anything that can help me find which subdomain to brute force, or should I try everyone of them ?

#

Thanks a lot already thats very helpful

frosty parcel
fathom pendant
#

what I did was just generate a list of all base b.inlanefreight.htb subdomains i found in my initial transfer then use dnsenum against those

fathom pendant
stone pilot
soft reef
proven pasture
stone pilot
proven pasture
austere hazel
#

Hi , Regarding the Client Side Prototype Pollution module, I am facing some difficulty creating the final payload. Cannot seem to send the = in between parameter 'promote' and the value 2 /profile.php?__proto__[src][]=data:,$.get("http://ngrok-app/admin.php?promote=".concat("2")) Tried using this payload, put = in both the end of promote and before 2, have been checking the responses using ngrok forwarding, whenever I'm sending =, the request isn't being made. For context, ngrok-app will be replaced by the target and is meant to be a XSS session riding attack

sharp pike
#

Pivoting, Tunneling, and Port Forwarding>Dynamic Port Forwarding w/ SSH & SOCKS Tunneling: on question 2, my rdp connection is failing

#

and on my ssh connection its showing a refused connection

onyx cairn
#

Why doesn't this work?

#

Not sure why it wouldn't be vaild, I tried another one to double check and the same thing happened

#

also idk why there's the error "could not resolve host" 🤔

fathom pendant
#

Escape the quotes

#

Idr if you need to also escape the curly braces

quasi wave
#

can somoen help me out with this? I just want to get this working in Python and it won't

ocean night
#

Your target may not have internet access. It's failing to resolve the domain.

quasi wave
ocean night
#

-m you're asking to execute a module

quasi wave
#

that's part of why I'm confused

ocean night
#

DM me the module link?

quasi wave
#

ok

#

done

mild python
#

Module: Attacking Common Applications
Section: Attacking GitLab
Question: gain RCE on gitlab instance. Submit the flag in te directory you land in.

Hi, I need help with this question. I found the user D... but the password no. I tired hydra with rockyou, and review code. But nothing. Somebody pls help :cSOLVED

ocean night
#

@trail sail that's a Tier 2 module, please avoid posting spoilers like that. Ask for a nudge mentioning the module and section, but don't post potential spoilers like that please.

#

Tier 0 modules, it's fine, but anything above please avoid

onyx cairn
fathom pendant
#

Before each "

onyx cairn
#

oh fun...

ocean night
#

One point, I know that's not a Powershell prompt, but Powershell be weeeeird when it comes to characters like { and quotes.

fathom pendant
#

Looks like rdp isn't running

sharp pike
ocean night
#

More Tier 2 module spoilers, maaan

#

Good night, I'm done 😆

fathom pendant
#

{"a":"b"} On linux
{\"a\":\"b\"} on Windows

#

See my message just above dude

#

The double quotes need to be escaped

#

Not single

#

Anyway try not to spoiler the module

onyx cairn
#

hm my message was deleted?

onyx cairn
onyx cairn
#

ohh nvm I see some

#

now it says no url specified

#

oh nvm I missed one

onyx cairn
fathom pendant
onyx cairn
#

alright

fathom pendant
#

i remember looking it up

#

short answer though is: windows sucks for this sort of thing

onyx cairn
#

hmm it still says the same thing :/

calm pewter
#

Hello, sorry to interrupt, has anyone done escaping IDS/IPS in Nmap? I am stuck in the medium challenge :/

onyx cairn
fathom pendant
#

@onyx cairn I also just thought of something; visit the webpage -- open devtools --> network -- do a search -- select the request -- copy for curl (Windows)

fathom pendant
#

it'll provide you the proper formatting

#

so you're not just guess and checking

#

idk why you're not doing this in a linux vm

calm pewter
onyx cairn
fathom pendant
calm pewter
#

Moreover I get this weird error on both pwnbox and my local system:

nmap: traceroute.cc:653: virtual unsigned char* ICMPProbe::build_packet(const sockaddr_storage*, u32*) const: Assertion `source->ss_family == AF_INET' failed.
zsh: IOT instruction  sudo nmap -p 53 10.129.2.80 -A -T3 --script dns-nsid -D RND:5 -Pn
fathom pendant
#

but that's at least a start here

#

now you just need to fix the -d if it's not escaped any characters

onyx cairn
#

hm first of all why can't I paste things into the Linux terminal 🥲

calm pewter
fathom pendant
#

ctrl+v enables verbose mode- it enters the literal next character you press

#

in ye-olde days it was ctrl+shift+c == ctrl+shift+v

calm pewter
#

Got it now, had to change to different scan type!

calm pewter
#

Just curious

onyx cairn
ocean night
#

@onyx cairn use --trace-ascii with curl to see exactly what it is sending

#

If the server is saying invalid JSON, then something funky is going on with how cmd is parsing your input

#

Last time I remember this coming up, easiest was to go to a bash prompt instead 😅

onyx cairn
#

oh nvm I got it in the Linux vm, regardless ty for the help!!

ocean night
#

👍

sharp pike
fathom pendant
sharp pike
fathom pendant
#

can you try connecting to it? or still same error?

fathom pendant
sharp pike
#

same error, nmap shows its closed, xfreerdp connection refused - gotta run some errands I'll try again tonight

#

thanks for the help though!

ocean night
#

Yeah.. seeing advice like "{"""key""":"""value"""}"

#

It's just.. what..

fathom pendant
ocean night
#

Just be normal and treat ' wrapped strings as literals

#

Yup

dapper moth
#

Don't know if this is the right topic, but I'm busting my head up against the wall for 6 hours!
Can't seem to find a way on the second question.

fathom pendant
#

it helps to include the module and section name

dapper moth
#

Sorry! These 6 hours are taking it's toll! 🤦‍♂️
Active Directory Trust Attacks - Skill Assessment

ocean night
#

Take it to DM, if someone is willing 🙂

next bronze
#

goblin that's barely a spoiler

#

if we can't talk about the modules at all then this channel is pretty pointless imo

#

anyways @dapper moth you saw that so just go with it

ocean night
#

Perhaps I'm being too sensitive..

#

Sorry. I should just leave it to the mods 😅

dapper moth
next bronze
next bronze
ocean night
#

It's a balance between nudging and spoiling.. I sometimes get that balance wrong when removing messages.

#

I'm only human 🙈

wary plover
#

🎵 I'm only human, after all 🎵

ocean night
#

My daughter loves that song

#

...and NGL, I enjoy it too

wary plover
#

the song indeed bangs

dapper moth
next bronze
#

dm me what you've got

faint minnow
#

xls

quasi jungle
digital vessel
#

anybody willing to answer a question on https://academy.hackthebox.com/module/23/section/513 ((( Skills Assessment - File Inclusion ))) i got in i got to where you fuzz i got the access log i use burp.. and nothing i donno if i have enough or not enough ../ i have picture would like to pm so does not break rules pls ping me / reply so i know i got msg

digital vessel
cerulean grail
#

Hi, in the "Footprinting Oracle TNS" module in the pentester jb path it says "From this point, we could retrieve the password hashes from the sys.user$ and try to crack them offline."

How would we do the cracking?

floral sinew
#

anyone have any advice for issue starting impackets mssqlclient during the archetype box? (using pwnbox)

#

every time I try to authenticate using the password and username i know is correct but keep seeing “login failed”

digital vessel
digital vessel
#

i need to log a bit pls ping me if i can pm / send pic so i can see what im doing wrong ty ^=^

cloud urchin
#

a new module, interesting. wonder what the difference is between that and the pivot module since the pivot module shows you several ways to pivot through windows machines

floral sinew
cloud urchin
dim wolf
keen plank
#

hey need some admin help I can't identify my user here !

fathom pendant
#

just dm one

#

anyone with a shield next to their name is a mod/admin

keen plank
#

Thank u!

normal sand
#

If your command output contains ANSI escape characters, how do ya'll get rid of it?

cloud urchin
#

you can output it to a file

normal sand
# cloud urchin you can output it to a file

If I use the following command to enumerate Domain Users in AD, it returns a file containing ANSI escape chars

sudo crackmapexec smb 172.16.5.5 -u username -p password --users > output.txt
#

So how do I remove it from that file?

cloud urchin
#

you can use sed/awk

#

even grep

#

python, pearl, text editor, choose your poison really

normal sand
normal sand
# cloud urchin even grep

How would you do it using grep? My aim to to be able to filter the list and obtain a user list using grep, that's why I wanna remove the ANSI chars.

next bronze
#

first don't use cme anymore, we use netexec now, second --users --log ./users.txt

normal sand
next bronze
#

it's just a fork of cme that's being maintained

#

you don't need to change anything other than calling nxc instead of cme

normal sand
next bronze
#

nope

normal sand
#

Okay, thanks for letting me know. I was under the impression that it was a fork but the syntax was changed 😂

fathom pendant
#

It's literally the same tool

normal sand
#

Thanks

fathom pendant
#

Forked by the main people that were actually maintaining cme

normal sand
fathom pendant
#

The discussion thread in cme is the background to it

normal sand
next bronze
#

just pivot 4Head

fathom pendant
#

^

#

lol

fathom pendant
next bronze
#

indeed

normal sand
#

Okie, but just for the know-how, how would I install the tool using the repo?

fathom pendant
#

well considering the targets and such don't have the internet; you'd be spending more time trying to get it compiled to move than you would just pivoting

fathom pendant
#

the pivoting module and pivoting in general is an important skill

#

if done properly you barely need to spend time on any other host once you get what you need

normal sand
#

I know how to pivot, was just curious on compiling the tool using the make command.

#

Noted that I'll prolly never have to compile it tho.

next bronze
#

iirc they do have precompiled binaries but those are not recommended

fathom pendant
#

i'm sure you can try

#

¯_(ツ)_/¯

obsidian belfry
#

quick question, so i'm working on a skill assessment and the admin is supposed to do something and trigger my payload and I'm sure that my payload works because it worked in the previous section but it's not working here. I've reset the machine many times and the admin just won't trigger the payload no matter what. I checked the network tab in dev tool and can see that my web browser triggers the payload OK but still the admin doesn't trigger it. So i was wondering if there's a case where the admin is broken?

normal sand
# next bronze just pivot <:4Head:865291850859413514>

Btw when pivoting, I obviously can't ping hosts using their domain name, for example, ms01.inlanefrieght.local. But is there a way to do it? Do I need to modify the resolver file or something? (FYI I'm using ligolo).

next bronze
#

your hosts file

normal sand
# next bronze your hosts file

So if the DC's IP is 172.16.5.3, then I just set the file to this and it should work?

<SNIP>
172.16.5.3    INLANEFRIEGHT.LOCAL DC01.INLANEFREIGHT.LOCAL
<SNIP>
fathom pendant
next bronze
#

yeah always add those 3 things for DC

#

especially if you're messing with kerberos

fathom pendant
#

you need the: Domain -- FQDN -- Machine name

#

Kerberos is funky with how it checks

#

if you don't reply to what it asks with the right info it's like "nah, i don't trust you"

normal sand
ebon nymph
#

module:- Broken authentication && section:-Bruteforcing password which custom worlist i need to use ?

muted kelp
normal sand
#

I can't seem to recall even tho I'm finishing up the module now 💀

ebon nymph
shut quest
cloud urchin
#

the classic

#

rockyou

ebon nymph
muted kelp
cloud urchin
#

follow the module, it shows you how to cut down rockyou into a smaller wordlist

fathom pendant
next bronze
cloud urchin
#

there's a password policy in place, you should do exactly as the module says, it's pretty much a walkthrough and tells you exactly how to make the custom list from rockyou

next bronze
#

@sweet jewel @vapid zodiac I found the trick to fix the insane rdp and other lag: use a 3rd party vpn to connect to the US (full tunnel), then connect to academy vpn

vapid zodiac
#

wat da hel

next bronze
#

rdp is actually useable now cryge

vapid zodiac
#

singapore server plz i beg

next bronze
#

they said they have no plans for it last I checked Deadge

shut quest
#

Which US server?

next bronze
#

I'm using US5 now but any one of them works I think

vapid zodiac
#

i guess theres not a lot of usage within asia on academy?

next bronze
#

idk I would pay extra to have servers here

vapid zodiac
#

real

shut quest
#

i've been living off 1 this whole time and rdp still bad even in the US

vapid zodiac
#

wait seriously?

#

how KEKW

next bronze
#

it's joever

cloud urchin
#

i'm accepting donations to stop using my instances

next bronze
#

they added 2 new US servers, 5 and 6, 5 seems alright for now

cloud urchin
#

they have to keep adding them cuz you dang eu'ers keep coming over here

#

our servers would be great if you weren't over here. we should build a wall.. a fire wall.

next bronze
#

I'm not even from eu kekhands

cloud urchin
#

oh lol

vapid zodiac
#

we're from SEA pepeHands

cloud urchin
#

build that fire wall

next bronze
#

just give us local servers prayge

cloud urchin
#

is it really because there isn't enough servers or they just need better specs though

fathom pendant
#

Overhead costs and such

drifting grail
vapid zodiac
#

well i guess it makes sense that it'd help

next bronze
#

but it's a dumb solution tbh

vapid zodiac
#

truly

#

but hearing that even within US the rdp is laggy is surprising KEKL

cloud urchin
#

kek 🇺🇸

vapid zodiac
#

the only 'vpn' i have is exitlag and thats not even a vpn PEPEGA

white vault
#

I have issue connecting to the windows target. I am on Windows Fundamentals and struggling to connect to the target using xfreerdp. i can't connect to it. dont know why. can anyone help?

ebon nymph
#

how i can add extra time so i can work on same ip (target) ?

wraith pelican
cloud urchin
#

spin around 3 times, flap your arms 10 times, stomp each foot once, then press the button that extends time

wraith pelican
white vault
cloud urchin
#

also add /dynamic-resolution

fathom pendant
white vault
white vault
fathom pendant
fathom pendant
#

also you don't need sudo for xfreerdp

#

perhaps running with sudo is doing something weird

white vault
#

i dont know what is happening

wraith pelican
#

you have to put the password into single quotes '<password>' and you have lost the exclamation point ! at the end of it

fathom pendant
# white vault

Different error this time but yes put the password in single quotes

white vault
fathom pendant
#

Also you're missing the ! From the pw in that last screenshot

#

Utilize the arrow keys to bring a command back up and just replace small parts instead of rewriting every time

white vault
fathom pendant
white vault
#

I tried with rdesktop but it is too slow

cloud urchin
#

try adding /cert-ignore

white vault
#

is it because of the target?

cloud urchin
#

or use remmina

fathom pendant
cloud urchin
#

yeah their syntax isn't uniform haha

sweet jewel
wraith pelican
#

thought the same thing doing those modules even if located in eu on eu servers and rdp can still lag badly last time i checked

next bronze
clever topaz
#

already run as admin

fathom pendant
cloud urchin
#

^

fathom pendant
#

and it's trying to access the 64bit lsa process

clever topaz
#

eiiii how to change to 64 bit

cloud urchin
#

architecture issue

wispy pilot
#

printf(“meow\n”);

clever topaz
#

or should i download

fathom pendant
#

don't be in the \win32 folder

clever topaz
#

ooo

clever topaz
#

haih wanted to cry so hard, i always stuck on problem like this....

#

still nope

wraith pelican
#

at least that's another issue

fathom pendant
#

looks like it's not able to get the memory process freed

rustic sage
atomic arch
#

hey

clever topaz
rustic sage
#

To run Mimikatz

atomic arch
#

anyone help me for hack

clever topaz
atomic arch
#

im new

fathom pendant
clever topaz
atomic arch
fathom pendant
#

i suggest resetting the target tbh

atomic arch
#

bye

compact patrolBOT
rustic sage
atomic arch
#

hack so bad and evil

fathom pendant
atomic arch
rustic sage
fathom pendant
#

plenty of free resources; and I already volunteer plenty of info here for free.

atomic arch
rustic sage
#

Yeah

cloud urchin
#

not illegal here sorry

atomic arch
#

hey

cloud urchin
#

feels good to live in a free country

atomic arch
#

anyone rob

atomic arch