#modules

1 messages Β· Page 290 of 1

next bronze
#

again you didn't include the command and you should use netexec instead

burnt grail
next bronze
#

cme is deprecated

burnt grail
#

When trying to do it using kerbrute, using this command

kerbrute passwordspray -d inlanefreight.local --dc 172.16.7.3 users.txt Welcome1

I am getting this error:

@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
@inlanefreight.local:Welcome1 - NETWORK ERROR - Can't talk to KDC. Aborting...
next bronze
#

looks like your pivot isn't working then

burnt grail
#

it is, i can xfreerdp using it

next bronze
#

you can rdp to dc?

burnt grail
#

yeah

burnt grail
next bronze
burnt grail
#

sorry not DC01, MS01

next bronze
#

that's not the dc

burnt grail
#

my bad

next bronze
#

if kerbrute doesn't work there are other tools for password spray

next bronze
# burnt grail

you should target the dc with kerbrute, it works for me

burnt grail
#

it keeps giving the error β€œcan’t talk to KDC”, even when targeting the DC

next bronze
#

you can try resetting it, the lab I just spawned works

burnt grail
#

alright, ty!!

next bronze
#

it shouldn't use port 53 by default

#

that's your own ubuntu machine yeah? I'm afraid you'll have to google it

#

yeah ubuntu will have more services running than a pentesting distro

wraith pelican
fathom pendant
#

You're giving a lot of spoilers dude

vague pewter
#

marcie

#

how you sof ast to responding to people

earnest sequoia
fathom pendant
#

I suggest doing the exercises before asking questions

storm elk
fathom pendant
vague pewter
# storm elk MarciePedia

I wanna help but the second I notice an unread message you three are already there >:( Xre0us marcie, and you

storm elk
vague pewter
fathom pendant
#

I also just woke up

storm elk
vague pewter
#

I spoke to you earlier this morning tho :p

storm elk
#

@languid fjord , we can jot it down in our notes. Marcie Lee slept

fathom pendant
#

God forbid a girl has hobbies

vague pewter
#

yeah right

vague pewter
earnest sequoia
fathom pendant
vague pewter
#

almost half T_T

#

okay leave some for teh rest of us 😭

wraith pelican
vague pewter
fathom pendant
#

I also read stupidly fast

vague pewter
#

also my hands smell like fries and it's bothering me a lot

wraith pelican
#

chatgpt is more poilte though

fathom pendant
vague pewter
#

marcie take me under your wing prayge

#

teach me the forbidden craft of the comm contributers

jolly yacht
#

Hey, In Windows Fundamental Module. I can't able to reach out internet from the deployed windows instance in the module section. I ran network diagnostic and it shown me some DNS server issue so i changed the dns server to 8.8.8.8 and also thought if it maybe a firewall blocking and disabled it. But nothing resulted as expected, Any help please?

wraith pelican
fathom pendant
#

First: sell your soul to tech support

vague pewter
#

^ what marcie said

fathom pendant
vague pewter
fathom pendant
#

Any downloaded tool you'll need to transfer to the target

vague pewter
#

So download first to your host, then open a share on the target and then copy paste to target

fathom pendant
#

Preferably portable executable

jolly yacht
vague pewter
#

/s

fathom pendant
#

Β―_(ツ)_/Β―

vague pewter
#

marcie you done any of the prolabs?

ocean night
#

Hey @median anvil

#

Do you like Marvel films?

#

BAM

fathom pendant
last forge
#

hello

fathom pendant
#

Try running the collector again

next bronze
#

what module?

idle python
#

is possible to ask question for the academy

next bronze
#

iirc you don't count certain users

#

so the number you have - 3

next bronze
#

yeah number you have with path but -3

fathom pendant
#

Jk ask the question @idle python that's the point of the channel my dude

idle python
fathom pendant
#

In short though; your hint is πŸ€–

idle python
#

Is INFORMATION GATHERING - WEB EDITION in section Skills Assessment

fathom pendant
#

It's on one of the subdomains

idle python
fathom pendant
idle python
fathom pendant
fathom pendant
next bronze
#

huh

#

that's the correct answer once you convert it to %

#

unless they changed the answer

#

I'm saying you can't count some accounts so it's gonna be the number that I gave

coarse bane
#

anyone else experiencing troubles with Easy Lab of Attacking common services module?

spark spruce
idle python
#

sir how find admin directory? and after to find hash

fathom pendant
idle python
fathom pendant
#

What's one of the default files that tells what web crawlers can/can't access

rustic sage
#

πŸ€–

fathom pendant
#

^

rustic sage
#

πŸ€–.txt

fathom pendant
#

Also as a hint; read above the skill assessment.

#

There's a list of things you'll be tested on

idle python
rustic sage
fathom pendant
#

Well ffuf/gobuster might find it

#

But it's a common file

idle python
rustic sage
fathom pendant
#

Analyzing πŸ€– will show you the way to the hidden admin

#

Not scanning

fathom pendant
#

It's in like 90% of directory lists afaik

rustic sage
#

Oh ok

thorn hawk
#

Hello amigos. Hope everybody is feeling epicly good. I have a question regarding the data gathering module. When you perform a zone transfer with dig to get additional subdomains and info does this affect the initial zone and deletes it? or we can request a zone transfer to get the info wihtout affecting the target?

fathom pendant
#

Kali and parrot have it installed by default. But if you're facing dependency issues idk

fathom pendant
rustic sage
#

Yeah

wraith pelican
#

maybe pipx is conflicting with system packages, just pick one and uninstall the others

fathom pendant
#

A zone transfer is like travelling to a city and getting a map

rustic sage
#

You can easily git clone impacket and install it

next bronze
#

you shouldn't get depency errors with pipx, it should install all the needed stuff for you

fathom pendant
#

^

thorn hawk
#

Did you try installing Kali in a VM?

next bronze
#

that's the whole point of it

thorn hawk
#

Nice :D

#

8 gigs for VM for me is enough

#

you could even put 4

fathom pendant
somber sentinel
#

^

fathom pendant
#

8 gigs if you have 16 is different than 8 gigs if you have 8

rustic sage
#

Still wouldn't use 8 gigs even if you have 16 on system

next bronze
#

generally half is fine but just leaving host with 8 gigs is rough

rustic sage
#

Ye

#

4 should be more than enough for a VM

next bronze
#

either way I've never seen pipx having dependency errors, maybe give the command you've used and the errors

#

what's the command and what's the error

bitter yoke
#

I'm stuck on the Patch skill assessment in Secure Coding 101. I have what I believe to be a working solution to validate and sanitize the inputs. I've tested it by replacing eval with console.log to verify that the check function call looks clean in the output and it seems to work locally after rewriting it, but when I upload it I get an error stating that the check function is not being called. Prior to patching I was able to execute command injection successfully, so I think I'm on the right track if anyone can offer a nudge? DM's welcome

next bronze
#

try with just pipx

sudo apt install pipx
pipx install impacket --force
#

or maybe uninstall first before you install

bright coral
#

pkg_resources was removed from the standard library with 3.12 and moved to setuptools

rustic sage
#

python3 -m pip install setuptools

next bronze
#

setuptools should already be installed thonk

rustic sage
#

Cool 😎

next bronze
#

huh venv is not used at all with those commands

rustic sage
#

Sometimes Kali doesn't need venv to install pip packages

next bronze
rustic sage
#

Nah

next bronze
#

why do you need bluetooth for a pentesting os

rustic sage
#

I suggest debain and using a VM for pentesting

next bronze
#

that's fine but don't use a pentesting distro for that, you can run it in a vm

wraith pelican
next bronze
#

yeah

#

proper pipx install will call the ones in their contained venvs

wraith pelican
#

yeah without sudo and without python -m.
never had an issue with that either

next bronze
#

there's no reason why pipx shouldn't work but idk shruge

wraith pelican
#

if they do not do pipx ensure path for instance so they call the old packages? since old system and new pipx packages will be called by the same name?

next bronze
#

oh yeah that's probably it

#

it's still calling the old stff installed by pip

soft reef
acoustic owl
soft reef
#

Well its confusing wether or not I should authenticate at the start.

acoustic owl
soft reef
acoustic owl
#

No, the task at the end of the section does not give you any creds. You do not need any

timid umbra
#

i just downloaded kali linux

#

using discord with it

vague pewter
timid umbra
#

but not used to it

#

it's kinda hard

unique valve
#

The academy team are goats!

fossil crescent
soft reef
rare swan
#

Footprinting --> Assessment hard -- any hint on this task - used onesixtyone and braa --> no results

pastel kernel
#

Hello all

next bronze
#

netexec

#

it's not an alternative, it's an upgrade

dusk shale
#

How to enumerate users in exercise in "Brute-Forcing Password Reset Tokens" from "Broken Authentication"? I tried to enumerate it by the response timing, but it didn't works.

eager siren
#

I am currently in the Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer. I added the inlanefreight.htb in the /etc/hosts. and i found at there is a ns. subdomain, i added the subdomain in the resolvers.txt and when i run the subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt
i get a IndexError: list index out of range

acoustic owl
eager siren
#

nice thank you

rapid flume
#

Please anyone send the mod of gesture suite

high reef
#

when i run the command i get al these codes but none of them work fot OTP

soft reef
high reef
#

I get no result

soft reef
high reef
#

The command I provided does that automatically

soft reef
#

No all youre results have a size of 2867, what happens if you filter those.

high reef
#

get nothing

soft reef
high reef
soft reef
acoustic owl
# high reef

Attention, you are not pinging your target here. All IPs that are specified with a port are Docker containers.

soft reef
#

Bunny can I DM you regarding api attacks

bitter yoke
acoustic owl
normal sand
#

Module: Information Gathering - Web Edition
Section: Creepy Crawlies
Section link: https://academy.hackthebox.com/module/144/section/3079

We are provided with a custom script (ReconSpider.py) for crawling. Do ya'll have any go-to alternatives that perform the same functionality as this script? Does ZAP do it?

coarse bane
#

Just finished Attacking Common Services - Easy (tbh not that easy today kek ) . What a journey....

wraith pelican
normal sand
wraith pelican
#

you got issues with the script?

normal sand
#

It presents information wonderfully and even retrieves comments.

#

I just wanted to have alternatives at hand, y'know?

wraith pelican
#

yup, i found katana randomly so i've not search for crawling tools, i'm sure there is plenty out there

rain zodiac
#

i am script kiddie

torpid grail
#

Hello. Are you getting a false positive using crackmapexec?

tawdry mural
#

Hello, I am doing Unconstrained Delegation - Computers from the Kerberos Attacks module. The first question asks us to capture the TGT of a user that authenticates to our machine and then list a specific share on DC01. I have the TGT, tried renewing it and also requesting a specific TGS ticket, but none of it seems to work. The user is also not part of the Domain Admins group. Is this intended? I could just compromise the whole domain and answer both of the questions. EDIT: I can see the domain administrator's ticket in memory with klist tickets, but I am still not able to access the shares on DC01. => SOLVED: apparently net view does not use Kerberos authentication? Using Get-ChildItem or the alias dir works just fine.

analog perch
#

Hi, I have a question,
What is ldap and kerberos and why they are important

bright aurora
#

I need help with hashcat idk what I'm doing wrong

fathom pendant
fathom pendant
fathom pendant
hushed sail
surreal totem
#

I need help with What does the header on the title page say when opening the aquatone_report.html page with a web browser? (Format: 3 words, case sensitive) in Attacking Common Applications > Application Discovery & Enumeration . I feel completly stupid but i tried every combination in this:

#

I literally have the complete module finished execpt for this

#

The second question πŸ˜„

fathom pendant
#

It's likely changed since the creation of this question

#

Wait

#

It's looking for <Header> not < Title>

surreal totem
#

There is no <header> tag in the html

fathom pendant
#

No

bright aurora
hushed sail
fathom pendant
#

However it has nothing to do with the title or menu bar @surreal totem

#

Pages...

surreal totem
#

wow

#

Ok thank you, got it

fathom pendant
#

Also header tags in html are <hN>

trail sail
#

This is the original command without obfuscation:
find /usr/share/ | grep root | grep mysql | tail -n 1

#

Can I share with you guys the obfuscated payload I am using here?

sly trench
#

Hello, I don't think that the VPN is working, I downloaded the file on my VM, did "openvpn htbvpnfile" and its connected but the box doesnt respond to pings

fathom pendant
#

<@&861185840277487616>

maiden shell
#

sorry

fathom pendant
#

Illegal bro

west rampart
#

absolutely not

fathom pendant
trail sail
#

Module of Command Injections:
Section: Advanced Command
Hi,
Can I share the obfuscated payload I am using in the lab? I’d like to know if I am doing something wrong.

muted jacinth
#

Hey guys. I'm currently doing the DACL II skill asess and i'm having a question

#

PS Microsoft.PowerShell.Core\FileSystem::\SDE01\Shared> whoami
nt authority\system
PS Microsoft.PowerShell.Core\FileSystem::\SDE01\Shared> icacls .\clearcache.bat
.\clearcache.bat Everyone:(I)(RX)
NT AUTHORITY\SYSTEM:(I)(F)
BUILTIN\Administrators:(I)(F)

Successfully processed 1 files; Failed processing 0 files

#

PS Microsoft.PowerShell.Core\FileSystem::\SDE01\Shared> echo 'test' > .\clearcache.bat
out-file : Access to the path '\SDE01\Shared\clearcache.bat' is denied.
At line:1 char:1

  • echo 'test' > .\clearcache.bat
  •   + CategoryInfo          : OpenError: (:) [Out-File], UnauthorizedAccessException
      + FullyQualifiedErrorId : FileOpenFailure,Microsoft.PowerShell.Commands.OutFileCommand
#

how is this possible?

fathom pendant
#

UnauthorizedAccessException

muted jacinth
#

doesn't the icacls output means that nt system can full control the file?

fathom pendant
#

Haven't messed with icacls in a minute

#

But are you running the powershell as admin?

#

Wait nvm I missed that

#

If you read and follow #welcome you can wrap the output stuff in ``` so it formats properly
```

Like this

```

#

Makes things way easier to parse

muted jacinth
#

i am

fathom pendant
#

Could have some other protections

#

> overwrites

#

Maybe you can append to it

devout dragon
#

I'm on the virtual hosts section of Information Gathering - Web Edition, and I'm facing some difficulties. I read on a forum that there are some issues in this module. Is anyone else facing problems solving it?

devout dragon
muted jacinth
#

denied as well

fathom pendant
#

Command slightly varies between them

devout dragon
#

Yeah, I got both of them to execute fine. Gobuster is still going, and Ffuf gave me a huge output. I saved it into a file, and I grepped "web" to answer the first q, but there are so many lines.

zenith vale
#

its greyed out for some reason

#

nvm i needed to change it to string

fathom pendant
#

and for gobuster you made sure to do --append-domain yeah?

devout dragon
#

I'll rerun it after editing. Let's hope it goes well

devout dragon
devout dragon
fathom pendant
#

At least for gobuster

devout dragon
#

thank you

fathom pendant
#

Yeah, it needs a domain to append

#

It grabs the header info from the connection

devout dragon
#

yeah, it wouldn't make sense to not include it

#

i wanted to include it initially, then i looked at the module and it mentioned IP address

fathom pendant
#

As opposed to ffuf where you define the host header with -H

devout dragon
#

so i was like, "oh, nvm then"

devout dragon
#

i didn't know how to comb through the details

fathom pendant
#

2 methods; use -ac or -fs [common size of responses]

devout dragon
#

-fs 612, right?

fathom pendant
#

-ac autocalibrates to throw out junk responses

wraith pelican
devout dragon
devout dragon
fathom pendant
sterile solstice
sterile solstice
sly trench
#

Guys if I'm using dirbuster and I see robots.txt and in robots.txt there is another directory in text, why didn't dirbuster catch that directory that is in robots.txt?

#

Like dirbuster said robots.txt and inside of robots.txt there is adminlogin but dirbuster didn't show adminlogin

sterile solstice
#

can anyone help with 'attacking common services' - 'PTRG Network Monitor'

https://academy.hackthebox.com/module/113/section/1094

I have followed all the steps. at this step, there is supposed to be a 'Test' button in the middle columns, next to 'Active/Paused' but its not visible on me. and the code in 'pwn' doesn't appear to be running (its a blind code execution.

next bronze
#

logon scripts

muted jacinth
#

ty for fast answer as always

fathom pendant
#

the purpose is to give a scope to bots

#

Β―_(ツ)_/Β―

#

also could just be that directory isn't in the wordlist you used

next bronze
#

one of the users you have can edit it, check again

muted jacinth
#

okay thx i'll look into it

next bronze
#

also spoilers

sly trench
muted jacinth
#

yeah sorry, will remove that

gilded radish
fathom pendant
next bronze
#

well are you able to get the cookie using that payload?

fathom pendant
#

because your account isn't linked ( see #welcome)

next bronze
#

if you can get the cookie that would be the answer, the flag is the cookie

raven axle
formal lintel
#

hello

#

someone can help me with the first lab of broken autentication pls

#

i have to enumerate users

copper parcel
#

Footprinting - DNS Q4
What is the FQDN of the host where the last octet ends with "x.x.x.203"?

How long does this scan take? I'm trying to speed it up but it's still taking quite some time...

I'm using DNSenum and a wordlist, I tried many yesterday but had no luck so far. I'm just concerned there is a much faster way to do this that I'm missing so any advice would be appreciated πŸ™‚

Thanks

cloud urchin
cloud urchin
copper parcel
#

I tried a few from SecList but currently using the namelist.txt one

cloud urchin
copper parcel
#

Yesterday I worked through the subdomain lists 5000, 20000 and 110000 I think but I will look at trying other lists, thank you πŸ˜„

copper parcel
#

for my own personal curiosity though, besides --threads and the size of the wordlist, is there anything else that one can look at in regards to adjusting speed?

cloud urchin
#

is there "anything" you can do is pretty broad, of course there are things you can do

#

in practice the answer is no though

sly trench
#

Do rooms change? I was in getting started module and I did 10.10.10.10:1234/adminloginpage.php and there was the login page with username and password in the source code. Now that directory isn't there anymore and also robots.txt gives me 404

cloud urchin
#

rooms?

sly trench
#

Module

#

I'm used to thm

cloud urchin
#

no the modules don't change, unless they are updated which isn't very frequent

sly trench
#

Idk bro I tried a good amount of stuff. It looks like the directories changed

#

Also gobuster can't find robots.txt and adminloginpage

cloud urchin
#

well i do know

sly trench
#

And I found the flag : ( but I wanted to try another exploit and I left it there

cloud urchin
#

the modules are not dynamic upon spawn, they are static

sly trench
#

I'm almost sure there is a problem with the "victim" machine, sometimes gobuster works sometimes it times out, some pages load on the website some don't even tho they exist

cloud urchin
#

you could try changing vpn regions

formal lintel
cloud urchin
#

why can't you enumerate? what's the error/issue?

formal lintel
#

i have to find a valid username, i tried with ffuf with the list they mentioned and i recieve an error, after that i tried manually and i didnt find a valid username

cloud urchin
#

what error did ffuf give you?

formal lintel
cloud urchin
#

can you ping the target? dm me the command you're using

shy bison
#

Hey guys, i have no experience or knowledge in AD , do you think i should start with the introduction to active directory module from the academy or something else ?

sly trench
#

Both on the workstation and on my own vpn

cloud urchin
sly trench
#

Idk also tried on chrome

#

Like to open the workstation on chrome same thing

cloud urchin
#

if that doesn't do it, you're probably doing something wrong and it would help if you gave the module/section you're stuck on because it would provide a lot more context. sorry if you already mentioned it i just got here a bit ago.

sly trench
cloud urchin
#

k then you're probably just doing something wrong

sly trench
#

The module is "getting started" under "public exploits"

#

I saw the freaking flag and I skipped it because I wanted to try another thing : (

#

And now it keeps timing me out

cloud urchin
#

sorry i haven't done that module so i can't really help

fathom pendant
#

as that one is using a public IP and port if i'm recalling

fathom pendant
#

(note it doesn't dive into great detail of stuff that's covered in the higher tier AD modules)

#

but enough of an overview for you to go "oh, i get it"

wet tapir
fathom pendant
#

no need to send stickers in multiple channels

fathom pendant
#

<@&861185840277487616>

fathom pendant
slender shoal
#

Thank you

fathom pendant
#

holy shit he lives

surreal rain
fallen tusk
#

Hey everyone, how might I use the USN journal to determine where a file originated from? Is it possible? I've tried following the parent entry numbers but it hasn't taken me anywhere useful.

round epoch
#

Hi, I'm going through Info. Sec. Foundation module, Linux Fundamental and have hit on an issue. I need to find the name of the last modified file in a specific directory. I searched and eventually found a solution that provides the name and not the inode, or modification time and date. However, the command is quite long and as the introduction to Bash commands is terse, I was wondering if (hoping) there was a more concise solution than the one I have. I'm not sure whether I should post my solution, so I would also appreciate guidance on this.

fathom pendant
#

but also this module requires a bit of tinkering with commands

#

to introduce you to the linux environment

#

ls can be pretty useful

#

i'm often always including -la whenever I do it

#

also biggest and hugest tip when dealing with linux commands

#

man <command> or <command> --help often give you info on how to use a given <command>

#

also sometimes some critical thinking is required

#

also it's not information security foundation module, that's the path; there is no InfoSec Foundation module

round epoch
#

@fathom pendant ls is wieldy! I have no idea what I am looking for; I have read it - but not in its entirety. If you consider the solution to be in the ls command and its attributes, then I'll be a bit more thorough in reviewing.

fathom pendant
#

index node

#

:)

round epoch
#

@fathom pendant Thank you for the correction.

Thank you, also, for the search tips.

My present solution utilises find and pipelines. It works very well, but is too much to remember. On remembering; I have heard that in order to be successful in programming/coding, the skill is not in remembering, but in researching. The manpages are very useful, but not always accessible where solutions are required.

fathom pendant
#

not everyone has a vault of a memory to know exactly which section you're referring to

#

but learning in this field is all about breaking out of your comfort zone to learn something new

vague pewter
#

another day, another person helped, good job marcielee

fathom pendant
#

@coral acorn I did not give permission to DM :)

round epoch
#

@fathom pendant
I thought I had provided that information (Linux Fundamental(s)), but I understand; I'll be more diligent in future.

fathom pendant
#

the specific section you're on is generally near the top of the page

#

or is highlighted when you look at the index on the right

#

the PATH you're on is the Information Security Foundations path, it is not a module itself

#

modules are the learning things you unlock, like a book you purchase; Sections are like the chapters in the book

coral acorn
#

anyways can u help me with that?

fathom pendant
#

A pathway is like an anthology of the books -- a pre-arranged collection for the best experience

fathom pendant
round epoch
#

@fathom pendant
Ah...
"Working with Files and Directories"
Got there in the end.

fathom pendant
coral acorn
fathom pendant
#

i'm not obligated to read unsolicited DMs Β―_(ツ)_/Β―

#

you can't post images btw because your HTB labs account isn't linked (read and follow #welcome)

coral acorn
fathom pendant
#

Β―_(ツ)_/Β―

rustic spire
#

I am currently doing the Tapping Into ETW in the Windows event log and evil module, I followed the instructions to the dot but for some reason the json file generated by silk does not contain Seatbelt

#

can anyone explain what i might be doing wrong here

fathom pendant
#

did you run silk then seatbelt?

#

that's my only thought Β―_(ツ)_/Β―

#

gotta run a before b otherwise it doesn't catch it

rustic spire
#

it didn't say that in the module :(

fathom pendant
#

how is it gonna catch seatbelt if it's not running to catch it?

rustic spire
#

i thought seatbelt is like a log parser

#

which cleanly puts specific stuff from a log into a json file

#

guess i misunderstood

fathom pendant
#

i forgor which is which tbh

frosty tide
#

Hello I going throught the Info Gathering Web Edition. I am at the Assessment part. The question is asking for API Key in hidden admin directory. I try bruteforcing and many other technique that show in the module it doesn't work.

Is there any other approach for this?

fathom pendant
#

mb it is seatbelt then silk @rustic spire

frosty tide
#

Also the crawling it only provided empty json file

fathom pendant
#

that is the hint

rustic spire
#

and i found the info in the json file

fathom pendant
rustic spire
#

maybe that module needs an update?

#

it doesn't say that in the module, would help people with zero experience in windows event log like me

elfin drum
#

Hello I'm having trouble with "RDP and SOCKS Tunneling with SocksOverRDP" I rdp to foothold host 10.129.XX.XX then successfully load dll and setup proxifier then mstsc to Pivot Host 172.16.5.19 and run SocksOver-RDP-x64.exe successfully, then back to Foothold Host, I set proxifier with 127.0.0.1:1080 SOCK5 then I connect to the target host 172.16.6.155 and this error shows up. I think I do everything correctly including ||turning off antivirus at Initial foothold and uninstall windowsdefender at Pivot Host and run every tools with Administrator Privilege|| is there a mistake I made or is this suppose to be a Lab error since I don't see anyone else having this issue.

fathom pendant
fathom pendant
rustic spire
#

in the explaination on the other hand it doesn't specify

#

like the main module

fathom pendant
#

if that fails, change vpn regions (EU β†’ US or US β†’ EU)

elfin drum
fathom pendant
#

After that, we can proceed to simulate the attack again

rustic spire
#

m

#

might just be slow

fathom pendant
#

:) it took me a min to find it but it is indeed there

rustic spire
#

only me lmfao

fathom pendant
#

nah

#

trust

#

you're not the only one that's asked

rustic spire
#

that's comforting πŸ˜‚

#

also as a suggestion for this module could be to add different hex values for finding different specific things

#

in the options for silk

fathom pendant
frosty tide
#

Anyone have finish the updated Info Gathering Web Edition Assessment? Please provide me some clue. I got stuck with getting API Key in hidden admin dir

fathom pendant
#

a certain .txt file πŸ˜‰

frosty tide
#

i try the robots.txt it display 404 error

fathom pendant
#

Β―_(ツ)_/Β―

frosty tide
#

I try doing dnsenum to get subdomain also got nothing too

fathom pendant
#

dnsenum won't work

#

as DNS isn't running

#

you'll need to use ffuf/gobuster

frosty tide
#

ohh I see. I try it

#

thank you

fathom pendant
#

since i believe this assessment is on a public_IP:port you're gonna have to adapt

frosty tide
#

I need to add to /etc/hosts

#

kind of confusing at first

fathom pendant
#

brother it's something that you kinda gotta do a lot, especially in this module

#

it even gives you the base vhost/domain

#

it's not like they just threw the IP at you and said "good luck," the entire module up to that point should have prepared you for the skill assessment

frosty tide
#

Aight, I do my best

wraith pelican
# frosty tide Aight, I do my best

if i may add, just try to understand DNS on a high level, difference between vhost and subdomains, what the tool do, does it query a dns server, try to recognize a private domain, since it is private, it could not be in public records so how can we resolve the private domain, etc. it will help you use the tools with more ease

fathom pendant
#

it's a public_IP:port

#

so seeing that it's a private/public IP doesn't do much

#

it's moreso realizing that since it's a given target; use given info to attack it

wraith pelican
#

the domain is .htb or .local isnt it?

fathom pendant
#

yeah

#

either or; it's not gonna be on public DNS

#

and since it's a public_IP:port; your only scope is that IP:port

#

no other ports

#

so DNS enum won't work- - since 53 isn't running

#

(and if it was it's not set up to interact with that port, likely)

#

the scope of any public_IP:port given in academy is solely the port given on that IP

wraith pelican
#

i understand what you mean i think. It is just i find more useful to understand those concepts than knowing tricks related to the htb platform. Both are important and useful but i just see lots of questions which could be answered by basic dns understanding or other basic grasp of the subject in question

#

also i do not mean to undermine what you are saying, just trying to help, and what helps me most of the time is going back to some basic understanding

fathom pendant
#

yeah i agree

#

basic understanding is necessary

#

but also kinda normalizing a statement too much may lead to confusion

frosty tide
#

@fathom pendant I finally finish the assesment thank you man

#

but I found an issues or maybe I doing it wrong. The question that want me to craw the inlanefreight.htb to get full email. It output nothing and I got the answer from the last question instead

fathom pendant
#

it's not an issue

#

it's just something that requires a bit of digging

frosty tide
#

Aight it was stressful, but fun at the same time

#

thank for your advise, on my way to another module

stark lark
#

Crazy fast speed you are going. Do you have previous experience with pentesting techniques etc?

mint peak
mint peak
fathom pendant
#

you really shouldn't be blitzing through the content tbh

torpid thistle
torpid thistle
gilded radish
#

how many similar modules are there in cbbh and cpts? I completed one, and I got some percentage in cbbh

fathom pendant
mental phoenix
#

Hi, team! I need help on this module. I do following the step-by-step tutorial, but after I upload the splunk_shell on the target, I did not get any connection on my listener.
Can someone help me?

I already tried many times.

fathom pendant
mental phoenix
#

I already archive this folder into .tar.gz and .spl. But after many times looks like it didnt working well.

#

Is there any step that I missed?

thorn hawk
#

hello amigos. I hope everybody is having an amazing morniiing :). I have some issue with the VHOST chapter under the Gathering information module. I was able to include the ip and the inlanefreight.htb name server inside the /etc/hosts file. Then i try to run this command with gobuster to get the vhost but i can't seem to get any results. Do you know why this is happening. A lot of people are reporting that this module might be broken, Do you know if this is the case?

fathom pendant
fathom pendant
#

Also you need a domain for gobuster to append

thorn hawk
#

you mean after the --append-domain flag?

fathom pendant
#

You don't include the port in the hosts file

thorn hawk
#

Sniped the human base error :D

#

Will go and do that

#

Done deal. it worked :D

#

No ports in Hosts file locos

#

Thank you @fathom pendant for your daily answers. wish you an excellent day ahead

fathom pendant
#

o7 broken brains

thorn hawk
#

hahahah

mental phoenix
dusk shale
#

Hello, community!
I'm trying to solve a "Brute-Forcing Password Reset Tokens" section in the "Broken Authentication" module. I have successfully reset the password for the admin user but I don't know how to find another user and reset the password for him. If anyone has solved this exercise, please give me a hint.

fathom pendant
#

smtp-user-enum

#

you might need to adjust the timeout variable to at least 20 seconds for a response it is rather slow

soft reef
fathom pendant
#

nope it's a standalone script

fathom pendant
#

the wordlist from the module resources yeah?

#

yeah that'll work

#

also you might need to remove the @domain from the result

#

:P

spice anvil
#

Hello , I recently joined HTB Academy and wanted to learn windows fundamentals. But I realized that they were using certain terms that I didn't know about.
Should I do Linux fundamentals before windows fundamental

acoustic owl
#

Which terms do you not know? I don't think you will learn things in the Linux fundamentals module that will help you for the Windows fundamentals module

dusky surge
#

Hi everyone, how can i solve the challenge related to AI-Ml challenges

#

Any guide for start

#

in HTB Academy maybe or anything else

pseudo kiln
#

does anyone know how to mark a module as favorite ? it seems you can only do that with owned modules for some reason

acoustic owl
#

Just click on the heart

spice anvil
pseudo kiln
#

i only get the heart option if I enter a module, and to enter a module you need to own it

wraith pelican
#

you have to go to the module search page, then you can click on heart

pseudo kiln
acoustic owl
spice anvil
#

Thank you. If there is any prerequisite to windows fundamentals kindly let me know.

fierce granite
#

hello, can anyone help me with enumerating subdomains/vhosts on htb?

rustic sage
#

Sure

fierce granite
#

so the issue is that i literally cant enumerate them

#

the correcet sub/vhost is in my wordlist

#

but no matter what tool i use i cant find it

rustic sage
#

What command are you using?

fierce granite
#

only after i add the sub/vhost to my /etc/hosts

rustic sage
#

What tools are you using

pseudo kiln
#

which module ?

fierce granite
rustic sage
#

Commands?

fierce granite
acoustic owl
#

Have you entered board.htb in the hosts file?

fierce granite
#

yes

#

im also using wsl2 if thats important

rustic sage
#

So what's your output?

fierce granite
#

nothing

#

it just goes through my wl and says it didnt find anything

#

no errors too

calm comet
#

Is wsl connected to the VPN?

fierce granite
#

yes

#

with root too

rustic sage
#

Can you ping the box?

fierce granite
#

board.htb yes

#

but not the correct vhost

rustic sage
vernal lily
#

help please i have connection issue to a machine

fierce granite
rustic sage
vernal lily
#

im connected to a vpn and i cant ping the machine

rustic sage
fierce granite
rustic sage
#

capital btw "FUZZ"

acoustic owl
vernal lily
#

this machine should

#

ok i found out the problem

#

i download udp connection config file

#

instead of tcp

clever topaz
#

can normal domain user be able to query domain information? like user and group or is this a vulnerability?

fierce granite
rustic sage
wraith pelican
#

did you tell which module you are doing?

fierce granite
#

||└─> ping crm.board.htb
ping: crm.board.htb: Name or service not known||

rustic sage
fierce granite
rustic sage
#

Add this to the hosts file and try to visit it

fierce granite
#

i can enter board.htb in chromium , but i cant visit the subdomain

fierce granite
#

but i would have to look up the solutions for boxes just to get the subdomain to work

rustic sage
fierce granite
#

no, this is my /etc/hosts

#

now i cant access or enumerate ||crm.board.htb||

#

i can only do this after i add it to my /etc/hosts

rustic sage
fierce granite
#

i added board.htb to my /etc/hosts after the first nmap scan

olive fiber
#

Any advices from which module do unlock from the following?

Active Directory LDAP
NTLM Relay Attacks
DACL Attacks II
Active Directory Trust Attacks

fierce granite
#

but now its impossible for me to discover subdomains without cheating

rustic sage
#

He did

fierce granite
#

dude omfg

fierce granite
rustic sage
fierce granite
#

guys, i want to discover the subdomain on my own. Now i would have to look up the solution to find the subdomain on the web, then add it to my /etc/hosts, because otherwise i cant access/enumerate it

fierce granite
rustic sage
fierce granite
#

crm is on line 107 in my wl

faint hazel
#

guys if i didnt spend any money in HTB academy, and i am a total beginner, and i want to try to do a XSS attack what do you recommend me to do?

#

what is it?

bright coral
next bronze
next bronze
faint hazel
#

and if iwant to speak in general how can i do that ? like get the roles

#

ok, is it like a module in the academy if so how much does it cost?

#

oh really ? nice what is the name again?

#

ty mate

rustic sage
faint hazel
#

i will check that. and if i am like a total beginner will i manage to succeed the course? or will it be tough because i do want to learn and try but i do not have a lot of knowledge. are they explaining good there/

fierce granite
rustic sage
fierce granite
faint hazel
#

and how much time did it roughly take you?

fierce granite
#

wait, lemme try gobuster

rustic sage
bright coral
rustic sage
vague pewter
rustic sage
#

Now just filter size

fierce granite
rustic sage
faint hazel
#

i understand, ty mate

fierce granite
#

oh shit

bright coral
fierce granite
#

damn thanks, gobuster also worked

bright coral
#

just no

fierce granite
#

but i dont get it why it didnt work

bright coral
#

but thatβ€˜s not the reason… The webserver serves a default vhost if no specific match was found

rustic sage
rustic sage
#

The one I sent you?

fierce granite
#

but i tried --append-domain yesterday and it didnt work then lol

rustic sage
#

There could've been some sort of connection issue. That sometimes happens to me too

fierce granite
#

yeah

rustic sage
#

Yeah reset it

naive field
#

is there going to be any modules regarding to devsecops or sys administration or sm like that? πŸ‘€

#

that would be reaaallyyy cool

misty crag
#

Hi

rustic sage
#

Hello

misty crag
#

I want a roadmap where can I find one ?

compact patrolBOT
misty crag
#

HTB doesn’t work in my country

rustic sage
#

How are you here then?

misty crag
#

VPN

#

HTB servers doesn’t allow vpn

#

Solutions?!

acoustic owl
#

If I set up a VPN connection with Proton, I can reach the HTB portals.
Why do you think that HTB would not allow VPN connections?

misty crag
#

And I can’t buy proton vpn either because of sanctions

torn lotus
#

Guys It's been long time where the ssh username is for connection to pwnbox ? there is only IP address and (password) I assume?

rustic sage
#

On the desktop probably

torn lotus
#

thank you!

rustic sage
#

Was it there?

torn lotus
#

yeah but couldn't connect again...

#

there is username and password when I go for ssh username@IP, always give me permission denied

rustic sage
#

I assume you entered the password correctly?

#

And double check the IP of pwnbox

torn lotus
#

yeah also copied and pasted

rustic sage
#

Lemme check

torn lotus
#

No way in hell I can handle it πŸ˜„

#

I don't even know why it doesn't work so sad, how stupid I am

rustic sage
#

Well it works for me

#

Make sure you're connected to the academy VPN

torn lotus
#

well I didn't

rustic sage
#

Connect lol

#

use the "ens3" IP when SSHing to pwnbox

torn lotus
#

wdym ens3?

rustic sage
#

ifconfig in the terminal

#

What IP were you trying to connect to?

torn lotus
#

academy nmap default

rustic sage
#

no, you need to ssh into pwnbox

#

Use the IP of the pwnbox machine

rustic sage
#

I am not sure

#

If it is, then you're trying to ssh into yourself

#

in pwnbox, open terminal and type ifconfig or ip a find the "ens3" interface and use it's IP to ssh. For example, ssh your_username@ens3ip

torn lotus
#

It should be so easy to connect as I've done several modules 5 months ago but It says permission denied lul

#

I'm just doing academy modules πŸ˜„ is it changed?

rustic sage
#

Do you wanna ssh into pwnbox?

torn lotus
#

y

#

can I ss here?

rustic sage
torn lotus
#

thanks anyway prayge

next bronze
#

section?

rustic sage
#

rax will contain a value that is 8 less than the initial stack pointer value.

next bronze
#

make sure you have stopped at the right instruction, send a screenshot of your gdb

#

well your rax is 0 so you didn't stop at the right instructions

glad ferry
#

Hello!. Right now I am working my way toward finishing the 'web-attacks' module. Still, I am stuck at the skill assessment part, which may look like I failed to understand the module or didn't really take the time to learn it but no I absolutely grasped every bit of info I could so here are the steps I took and the part that I am stuck at :

  1. I found that the website has 100 configured users.
  2. I created a script to go through all users retrieving their info. would look something like that. {"uid", "username", "full_name", "company":}
    3 Then I found the administrator user.
  3. trying to privilege escalate that user.
    .Tryed SQL injection in the login form with the user username (failed)
    . I tried to change the user password by logging in as the HTB user and then
    changing the uid in the cookie to the UID of the user but still failed
    this is the point where I am stuck, If any one Knowes a solution or another path I would appreciate the help sorry for writing a whole essay and thanks in advance.
torn lotus
#

guys please help me 😦

#

I've got issues about login into pwnbox for academy modules. I don't know why but when I go like ssh username@IP and enter password as the same one with my_credentials.txt. Doesn't work for me

next bronze
acoustic owl
#

Did you take the IP from the external NIC?

verbal turtle
#

Web Service & API Attacks - Skills Assessment

why

torn lotus
next bronze
torn lotus
# next bronze

yeah couple months ago It was like that but now I'm back and there is nothing like that only IP and it says (ACADEMY-NMAP-DEFAULT)

next bronze
#

oh for this one you're not supposed to login, use nmap on the target

torn lotus
#

no way in hell

#

thank you πŸ˜„

verbal turtle
#

Web Service & API Attacks - Skills Assessment

why

#

i already add SOAPAction header and same problem

acoustic owl
#

Remember that you have to encode special characters in XML

verbal turtle
#

bro

#

the error is Missing SOAPAction header

tacit grove
#

bro what's line 13

verbal turtle
#

nothing

#

in image is d

#

but i already delete it

#

and same problem

tacit grove
#

deez nuts

acoustic owl
verbal turtle
#

thx its works !

compact cobalt
#

can anybody help me with the challenge of the advanced command obfuscation module in command injections?

fierce granite
#

anyone with rockyou downloaded can crack a hash for me?

split glade
# fierce granite anyone with rockyou downloaded can crack a hash for me?
fierce granite
#

i need to decrypt a bcrypt hash

#

nvm i cracked it

devout onyx
#

Hi everyone,
Is it normal that my "Spawns" shows 0/1 after I terminated mine ?

#

Now I can't start one

acoustic owl
#

As a free user you can start a PwnBox once a day

devout onyx
#

oh, even if I terminate it ?

acoustic owl
#

Yes

devout onyx
#

Would be nice if that was in the "intro to academy"

acoustic owl
#

Ur you can use your VM

devout onyx
#

Thank you @acoustic owl

devout onyx
#

well, worth to subscribe then

pseudo kiln
#

does anyone have a command to open a port with ligolo ? Like if the pivot is listening on 127.0.0.1:9001, how would we make that available to attacker machine too ?

devout onyx
dim wolf
#

listener_add --addr 0.0.0.0:9001 --to 0.0.0.0:9001

#

optionally add --tcp

#

do this command while in a session

pseudo kiln
#

problem is the target is already listening on that port for a service

#

but it's only listening on 9001 locally so looking for away to make it available from outside

dim wolf
#

then use a different port

#

--addr 0.0.0.0:9002

#

then when you want to add a new session from another host, specify -connect x.x.x.x:9002

pseudo kiln
#

hmm this time the command took, but I still cannot scan it with nmap

#

ahhh

#

nvm it worked, I am mega dumb

#

thanks a bunch

dim wolf
#

also i fcked up the last part of the command, it should be --to 127.0.0.1:9001

#

0.0.0.0:9001 works but it has caused me some issues in the past

topaz zenith
#

Has anyone had problems with the Dante prolab? The web server is just not working anymore.

opal nexus
#

Hello, does anyone can help me with Windows Privilege Escalation Skills Assessment - Part I third question please?

opal nexus
olive fiber
#

what access do you have on the machine?

#

and what is the syntax

opal nexus
# olive fiber what access do you have on the machine?

i've obtained reverse shell from that web page, I set there a folder called 'Tools', downloaded some tools there, and did the same precedures that worked in "SeImpersonate and SeAssignPrimaryToken" section and more. and for syntax for example i tried: - .\PrintSpoofer.exe -c ".\nc.exe 10.10.15.241 4445 -e cmd

olive fiber
#

if you do whoami, what is the level os access you have?

opal nexus
olive fiber
#

ok

#

clisid are you using?

opal nexus
# olive fiber ok

I believe it is called 'CLSID', either way i got a value of which in some of the tool's outputs.
so i have it

olive fiber
#

which is the value of that?

opal nexus
olive fiber
#

wna how your juicypotato command is structured?

mental phoenix
#

Hi, I need help with this module.
After I change the PORT to the 1337 and add IP of the hosts file
It seems still doesnt works
The fatty-client.jar still has connection issue.

Can someone help me?
I already deleted the file 1.SF and 1.RSA and clear the hash verification on manifest file

olive fiber
#

for me juicypotato was they way usind the right clsid

opal nexus
olive fiber
#

ok good enough but where is the clsid value?

opal nexus
olive fiber
#

i mean in your command

#

it is not there

opal nexus
olive fiber
#

{7A6D9C0A-1E7A-41B6-82B4-C3F7A27BA381}

#

use the following

#

of wpnservice

opal nexus
opal nexus
violet eagle
#

Hey everyone !
So basically I'm doing the Getting Started module and I'm stuck on the part where I have to find a public exploit and use it against a system.
I'll explain : I've done a scan of the IP, I've got the service used and his version. I'm stuck on "finding the exploit"
I keep searching online with the name and version of the service but I don't find anything, even on ExploitDB or Rapid7.
I keep going back and forward with the lesson about searching an exploit but I feel like I'm missing something big.
I don't want the answer, only a hint or something that can push me a bit.
Thanks πŸ™‚

olive fiber
soft reef
violet eagle
soft reef
violet eagle
#

I found Wordpress 5.6.1

#

but didn't found anything about it too

soft reef
violet eagle
#

Okay I'll try to orientate my research on this thanks @soft reef πŸ™‚
I'll come back if I'm still stuck

glad ferry
dim wolf
glad ferry
#

yes, I leveraged the IDOR vulnerability to get all the user's data. The only form of privilege escalation in the module was to change the HTTP request . The function that handles the password reset uses only the post HTTP request so if I change the request type to any other one like put it gives me "Missing parameters"

glad ferry
dim wolf
#

i don't remember anything from the skills assessment... but you should have everything you need to privesc

glad ferry
#

πŸ‘

dim wolf
#

based on the info you have, i believe you can privesc to admin account now

glad ferry
#

Yes, but the function that the server uses to reset the password only accepts the POST http request any other input is handled to out put "Missing parameters"

#

same output "Missing parameters"

GET /reset.php HTTP/1.1
Host: 94.237.58.3:34537
Content-Length: 63
Accept-Language: en-US
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.6478.127 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Accept: /
Origin: http://94.237.58.3:34537
Referer: http://94.237.58.3:34537/settings.php
Accept-Encoding: gzip, deflate, br
Cookie: PHPSESSID=hdsev2v82pg6dn829c80gndndc; uid=52
Connection: keep-alive

uid=52&token=e51a85fa-17ac-11ec-8e51-e78234eb7b0c&password=1234

#

ok after I fixed it but the output page was 2 of the old page under each other. How can I send a a screen shoot

#

Password changed successfully

Why the f was I even trying to do it manually when I am still learning thank you so much for your help and I am sorry for the trouble for a dume fix

bright coral
glad ferry
#

will do

olive fiber
next bronze
olive fiber
#

what about the second one, i had no success authentication as gabriel, i had to use martha there

next bronze
#

don't remember but martha's creds are not given

olive fiber
olive fiber
#

just did the first questions abusing wayns and not julio..

next bronze
#

abuse the rights of user julio

#

julio has the rights

fathom pendant
#

There's an intro to ad module

#

Also the information Security Foundations path is considered a pre-req and includes Intro to Windows CLI, and intro to activedirectory

sly trench
#

Hello I still have a problem with "getting started" module, at "public exploits" i have to hack a website and login to the admin page.
Yesterday I did it and also found the flag but I wanted to try something different so I left it there thinking I could just do the same and find it again, that box should be solved by using gobuster, finding robots.txt, looking at the source code and finding the login information for the admin and also the directory to login in to. Now there is no robots.txt and no login page
I did find the flag yesterday tho I am 100% sure thats how the room should be solved. I reset the target, changed vpn, updated my Kali VM, changed the workstation on htb, waited for more than 12 hours and the problem is the same.

covert vortex
#

||When running crackmapexec on SQL01 machine as Admin user as mentioned on the forum, cleartext creds shoud come up but unfortunalty nothing seems to work. Can someone help ?||

fathom pendant
#

Spoilers

sly trench
fathom pendant
#

But I honestly wouldn't worry about doing it in alternate ways

sly trench
fathom pendant
sly trench
#

Because I tried to do that and I couldn't find the directory so I just tried to type the directory next to the ip and port and it doesn't show it

sly trench
fathom pendant
#

Genuinely though, not needed

#

Also make sure http:// not https://

sly trench
#

Yea it says not found

#

Http not https

#

And now gobuster keeps timing out

solid quarry
#

Did someone here finished lateral movent skill assesment? The Vnc question / Wsus part does not work no matter what I try

sly trench
#

Buonasera fabbrΓ­

covert vortex
fathom pendant
mellow prism
#

where can i learn buffer overflows, return oriented programming an stuff like that?
linux and windows

fathom pendant
#

There's a buffer overflow module in academy

solid quarry
covert vortex
mellow prism
solid quarry
#

Rop I would say for linux you have a lot of places, on windows your options are limited, for me rop on linux is way easier than on windows

fathom pendant
mellow prism
#

the rop-thing and further stuff i am interested in. 15 years ago i learned the easy strcmp/strcpy easy peasy bof stuff

fathom pendant
#

The only writeup is the one accessible via an annual sub, which doesn't use lsa dump (for this user at least)

#

Kerberute is the method used

solid quarry
fathom pendant
#

It uses get-domainusers to generate a user list

mellow prism
#

ret2libc i also have done earlyer. i am wondering where to learn modern x64 linux bof stuff.
2024 style. not that x86 stuff i did years ago

fathom pendant
solid quarry
covert vortex
solid quarry
#

Maybe I have the writeup here with me, I can check

covert vortex
solid quarry
#

Which question are you stuck?

covert vortex
solid quarry
fathom pendant
covert vortex
#

thanks mate

solid quarry
#

You do not have sql01 access right?

covert vortex
fathom pendant
solid quarry
#

You are inside ms01?

covert vortex
fathom pendant
solid quarry
#

They changed the writeup then, got admin on ms01, dumped creds with meterpreter and got a cleartext creds

#

Sorry sql01

fathom pendant
#

sekurlsa::logonpasswords

#

Also could be in lsass not lsa (yes they are different)

solid quarry
#

Got a cred for the mssqlsvc user

covert vortex
#

all right thanks, will try

solid quarry
#

Try with mimikatz, if no meterpreter load kiwi module, if still no creds reset the lab

fathom pendant
#

You need to crack the plain_text_hex

#

Either way you're not looking for admin user per se

#

Just an account that can have admin privs

vernal lily
#

Please some1 help
sudo apt install gobuster
Error: Unable to locate package gobuster

fathom pendant
#

Gobuster should already be installed in most pentest distros

acoustic owl
ashen frost
#

Does pwnbox let you modify /etc/hosts?

ocean night
#

Yes, you can sudo

ashen frost
#

Even with sudo I kept getting permission denied

ocean night
#

sudo nano /etc/hosts ?

#

or sudo su then edit as normal

#

You can definitely edit the hosts file on pwnbox

ashen frost
#

Duh. I was trying to sudo echo "" | tee -a /etc/hosts

#

Thanks @ocean night ... I realized the sudo goes before the tee

ocean night
#

No worries πŸ™‚

#

Yeah, sudo there would affect echo, but then piping in to tee would not make tee execute elevated

rustic sage
#

Hey folks. I'm looking for somebody who has ocmpleted the Intro to Whitebox Pentesting skills assessment. Anybody on who might be able to help out with a nudge?

civic hamlet
#

Wasnt going to mention it, but its becoming a bit confusing. Why does the linux module im working on keep having sections that are completley unrelated to the module infromation?

#

Will this be a common theme as I go on?

fathom pendant
fathom pendant
#

Most sections in modules directly deal with what you read

#

Only one question in that module is a bullshit curveball (the curl one)

civic hamlet
#

thats the one im on kek

fathom pendant
civic hamlet
#

I cant use cURL or curl on my kali vm or the vm provided by htb-academy

#

tempted to skip the question

fathom pendant
#

Why can't you use it? Lol

#

Also it's curl in the cli

#

cURL is it's government name

civic hamlet
#

kek ahh

#

spelled inlane "inlaine"

#

wait it still isnt working (?) guess the spelling issue wasnt the problem

civic hamlet
fathom pendant
civic hamlet
#

I cant attempt to solve the question if I cant get the soure code

fathom pendant
#

Start with just curl then see what happens

#

Can your device reach the internet?

civic hamlet
#

Yes, it can

#

the terminal hangs for a bit then returns me nothing

fathom pendant
civic hamlet
#

Yes I can

fathom pendant
#

Ok now curl that also I suggest copy/paste instead of manual typing

civic hamlet
#

dont want to bother you too much but it still isnt returning me anything

fathom pendant
#

Hmm what do you get with curl -I?

earnest sequoia
#

Hello, can I check for the Password Attacks Module, Protected Files section, am I supposed to mutate passwords from password.list and conduct a dictionary attack for kira

earnest sequoia
#

Thank you

fathom pendant
#

Or mutate the hint password

#

Both will result in a correct answer

earnest sequoia
#

guess its another round of waiting for hydra

civic hamlet
fathom pendant
#

Weird

#

And you're trying from your kali vm yeah?

civic hamlet
#

ive tried from both

#

mhm

#

itll be a pain but ill try restarting my vm

fathom pendant
#

for w/e reason curl isn't following the redirect to www

#

alternatively you can add -L to it

civic hamlet
#

cant connect to openvpn now, obscure error?

#

options error: In [CMD-LINE]:1: Error opening configuration file: academy-regular(4).opvn
Use --help for more information.

fathom pendant
#

also delete old files and rename that to just academy-regular.ovpn

#

also; tab autocomplete saves some level of typo mistakes

civic hamlet
#

Alright im finally getting source code

#

Thanks immensely

fathom pendant
fathom pendant