#modules

1 messages ยท Page 298 of 1

wraith pelican
#

the result is not the same if you pipe the command into base64, bashfuscator does some tricks:

fathom pendant
#

How did you grab the samaccountname ๐Ÿ˜‰

floral talon
#

@heady vine lmk if youve got something

heady vine
fathom pendant
#

your command was close. You literally just need to add "description" to the -attr flag

vital zephyr
#

thanks marcie

#

i dont know if you are girl or boy, btw u are king or queen

#

thanks very much to help me

fresh lantern
#

I am kind of stuck:
this is what i have som far. That i think is right but it says no.
I have tried both of the outputs:
here are the version thing and this to it says is wrong

fathom pendant
jaunty musk
#

Hey guys, I'm in the file upload module whitelisting section and I managed to upload a php file using file.php/.png or file.php.\.png - The thing is I dont know under which filename they get saved. I was guessing they will get saved as file.php but I get a 404. Any ideas?

fresh lantern
hexed oyster
#

OK, I need help: Currently working on the File Upload Attack module -> Blacklist Filters. I've run through the following lists: PayloadsAllTheThings/upload insecure files/extension php/extension.lst

#

seclists/discovery/web-content/raft-*-file-extensions.

#

not finding anything that is executing. Thoughts? Advice?

vital zephyr
#

now i am in this module:
LLMNR/NBT-NS Poisoning - from Windows

i have to answer this question:
Run Inveigh and capture the NTLMv2 hash for the svc_qualys account. Crack and submit the cleartext password as the answer.

i found the hash, can you recommend a wordlist that works? because when i go to use rockyou it takes really many hours

wraith pelican
#

The issue could be that your are fuzzing too fast. Try with removing the -t 60 . I had to add --timeout 20s.
Like said before do not grep. You have to see the output and then you filter the results you do not want.

heady vine
jaunty musk
hexed oyster
wraith pelican
hexed oyster
jaunty musk
restive trail
hexed oyster
hexed oyster
vital zephyr
#

good evening again, I am in this module:
LLMNR/NBT-NS Poisoning - from Windows

I have to answer this question:
Run Inveigh and capture the NTLMv2 hash for the svc_qualys account. Crack and submit the cleartext password as the answer.

I found the hash, can you recommend a wordlist that works? because when I go to use rockyou it takes really many hours

#

a wordlist that isn't thousands of hours or miles long

wraith pelican
vital zephyr
wraith pelican
#

sorry to say but it is only in rockyou

vital zephyr
#

๐Ÿ˜ข

#

sad react

wraith pelican
#

are you hashcating from the vm?

vital zephyr
#

yes i use hashcat

fathom pendant
fathom pendant
wraith pelican
fathom pendant
#

estimated time != actual time btw

vital zephyr
#

its to loooooong

fathom pendant
vital zephyr
#

a 0 ?

wraith pelican
#

no -a

#

just -m 5600

vital zephyr
#

ok thanks quet

heady vine
# floral talon any luck?

Unfortunately. Changing threads and adding timeout didn't change anything 100,000 403s still. I'm still messing around. Not ready to call it quits yet.

floral talon
#

will get back to trying in a few mins

heady vine
fathom pendant
#

it would have nothing to do with htb infra as these are docker containers, not private machines

wraith pelican
fathom pendant
#

unless the endpoint people they use to host/launch also is fucked

floral talon
#

does the box work on your end?

heady vine
wraith pelican
#

why do you pipe everything to something? : D

heady vine
#

tee lets me save it to a file for easy searching

wraith pelican
#

you dom't need to do that

heady vine
#

Yes, but it doesn't affect the output. It just makes it easier to search.

wraith pelican
#

if you are motivated enough, try to send your fuzzing through burpsuite and see what you are actually fuzzing

#

it will make total sense if you see the actual request

heady vine
#

Ok, thanks for the tip. let me try it again.

fathom pendant
heady vine
fathom pendant
#

hmm

wraith pelican
#

i do think the whole thing is broken lol

#

i'm trying the working commands and everything gets 403

fathom pendant
#

nah someone goofed on the backend for the spawns

#

even the correct subdomain is 403

heady vine
#

LOL well honestly that is good to hear. I'm going to keep poking at it, because I am curious at what gobuster sends anyway.

fathom pendant
wraith pelican
fathom pendant
#

ALL subdomains and even the main domain is 403

heady vine
#

Ya, I'll try it on a valid vhost on my own machine, spawn a docker or something.

floral talon
#

do we just let it be for today?

fathom pendant
#

probably for the best

#

i submitted a help ticket for it

#

:)

wraith pelican
#

you just lost some life in this...

floral talon
#

thanks for trying to support us either way though :D

fathom pendant
#

at worst i'm bugging Tejas to fix it Kappa

unborn hatch
#

So for the Attacking Domain Trusts - Child -> Parent Trusts - from Linux - I seem to be at a loss. I've spawned my target, it says to SSH to it, in reality its a windows box. I RDP to it, and its a windows system. I tried using the default parrot VM mentioned in a previous section, its up and I can ssh. However, whenever I try to replicate the steps of running secretsdump as shown in the screeshots - it doesn't work . Any idea what I am doing wrong?

heady vine
#

I'll give it a go another day, maybe move onto another module for now.

fathom pendant
wraith pelican
fathom pendant
#

three times: neuron activation

unborn hatch
heady vine
#

LOL no worries

fathom pendant
wraith pelican
unborn hatch
vast thorn
#

so i setup a vm with parrot os and each time i try and ssh into the target i spawn i get connection refused, anyone know why or am i dumb lol

fathom pendant
#

it's somewhere in one of the previous sections

fathom pendant
heady vine
fathom pendant
#

but the password is indeed not the same

#

as a note; any credentials you should always save

vast thorn
#

im ngl, i didnt have openvpn running, so imma just cry now as i am dumb, been using the pwnbox and decided to switch to a vm for more practice and i forgot about that

unborn hatch
fathom pendant
#

yes

slow ether
#

any idea why I keep getting error

rustic sage
#

I haven't been able to get it to work, is there another guide? I install ParrotOS, shutdown, remove the installation media, turn back on, but files do not save still?

fathom pendant
wraith pelican
dim wolf
fathom pendant
dim wolf
#

check your first command

fathom pendant
#

you're supposed to change that homie

slow ether
wraith pelican
#

bro got out with new clothes and the tags are still on

pallid wing
#

Hi! Has anyone solved this web proxies exercise? I'm having difficulty, and I would appreciate talking to someone.

#

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

fathom pendant
#

or zap?

#

i believe the section goes over how to set a custom thing/prepend a string

pallid wing
#

In this exercise, I am using two Python scripts to encode and decode. Once I had the 31-character cookie, I created a line for each alphanumeric character. After that, I encoded it in reverse, used all the options, and it was never correct. I have the 88 characters from the hint; maybe I'm doing it wrong.

#

hint "With payload processing in Burp Intruder, first add the decoded cookie as a prefix to the payload, then encode the entire payload with the same encoding methods you identified earlier (in reverse order). The final payload should be 88 characters long, similar to the one from the previous question.
"

fathom pendant
#

and the intruder has an encode function

#

you basically just do the reverse of how you decoded

pallid wing
#

Do I just need to use the Intruder?

fathom pendant
#

yes

#

what section exactly is it?

pallid wing
#

Skills Assessment - Using Web Proxies

#

Web Proxies

fathom pendant
#

ah it's the skill assessment

pallid wing
#

Yes

fathom pendant
#

decode cookie, put that as your prefix for the intruder command

unborn hatch
#

In Attacking Domain Trusts - Child -> Parent Trusts - From Windows Module - what is the DC to target the INLANEFREIGHT.LOCAL. It appears when I'm trying to follow the instructions, my system is pointing to the LOGISTICS.INLANEFREIGHT.LOCAL domain, rather than the parent domain

fathom pendant
#

then, you use the "encode" options to REencode the payload basically back as it's processing

fathom pendant
unborn hatch
#

you told me i had to go back to get what i needed...

fathom pendant
unborn hatch
#

i'm just following your instructions...

fathom pendant
#

it's that simple

#

they give you the htb-student_adm creds

unborn hatch
#

youre saying these are the creds from the previous section?

unborn hatch
#

those were the creds i was using

fathom pendant
#

I thought you said you were using the regular htb-student creds

unborn hatch
#

they are literally identical in terms of the password as htb-student

fathom pendant
#

no... they aren't

unborn hatch
#

nevermind...ugh

fathom pendant
#

"htb-student" and password "HTB_@cademy_stdnt!"
"htb-student_adm" and password "HTB_@cademy_stdnt_admin!"

#

they are in-fact... different

pallid wing
#

I don't have Burp Pro; can I do this work anyway? I'm doing it right now.

fathom pendant
fathom pendant
unborn hatch
pallid wing
#

i send dm

unborn hatch
# fathom pendant idk why you're getting frustrated lol... i'm telling you the pw are different

there was definitely a glitch of somekind, because the first nmap scan is of the system that spawned for me when I ran into issues (note my initial confusion around it not allowing me to SSH and I had to RDP). Second screen shot is of nmap of re-spawned system, after i shut down the old windows system to respawn the previous module, and then coming back to the linux module and spawning it

fathom pendant
#

all the options you need are in the intruder menu

#

add โ†’ prefix (the 31 character string)
encode โ†’ last decode you did
encode โ†’ first decode you did

#

it's that simple

#

and it should give a handful of hits for the flag

#

it also helps to look at all the responses, it's not like in some assessments where the result will just be the flag

pallid wing
#

Thank you, I will see how I can solve it. I'm having some trouble since I have always worked from the console and not with the Intruder. I have used the Repeater more for CTFs, but now I am entering this world of bug bount

#

Can I give Burp Suite the alphanum-case.txt file from SecLists to append each line at the end and then encode?

fathom pendant
fathom pendant
#

if you highlight the the value 4d... in the request and then right-click -> send to intruder it'll automatically set it for replacement

#

if you want to get fancy with it you can use the "grep match" setting too; and add HTB{.*} (and be sure to select the regex option radio button)

ancient sand
#

Hi,

I was working on the Skills Assessment for the "Information Gathering-Web Edition" module.

When I try to access the page, it says I don't have permission (403 Forbidden) at http://ip:46606.

I've already added the IP to the hosts file and I'm connected to the VPN.

I wanted to ask if anyone else is experiencing the same issue because I searched for an updated walkthrough of the room on YouTube and the person was able to access the page.

acoustic owl
#

You can access the Docker containers without a VPN
If you have entered the IP and the domain in the hosts file, you should be able to access the website via http://domain.tld:<PORT>

ancient sand
acoustic owl
ancient sand
acoustic owl
#

And the command
curl -I inlanefreight.htb:46606 gives a 403 error?

#

If so, restart the lab

ancient sand
# acoustic owl And the command curl -I inlanefreight.htb:46606 gives a 403 error?

yeah give me the same error and I've already restarted the target 3 times and still have the same problem

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>403 Forbidden</title>
</head><body>
<h1>Forbidden</h1>
<p>You don't have permission to access this resource.</p>
<hr>
<address>Apache/2.4.61 (Debian) Server at inlanefreight.htb Port 46606</address>
</body></html>

#

I donโ€™t know what the problem might be. Iโ€™ll move on.

Thank you for your time.

acoustic owl
#

Contact the support team. Something doesn't seem to be working properly

ancient sand
pallid wing
#

i have a question

ocean night
#

๐Ÿ™‚

pallid wing
#

anti CSRF-Tokens and CSP header not set

#

ZAP found 2 medium vulnerabilities: "Anti-CSRF Tokens and CSP header not set."

ocean night
#

Which module is this?

#

Module / section

pallid wing
#

Using web Proxies / Web Scanner / Zap Scanner

#

hint in the web "i am trying the ping devtool but it is not working.
I tried the following:
/ping.php?ip=127.0.0.1"

ocean night
#

Firstly, that's a tier 2 module, so please don't discuss any potential spoilers (you haven't so far), but rather ask for generic advice - someone may reach out to you to nudge you in the right direction. Secondly, I think perhaps you have missed some details from a previous section - Automatic Modification

#

I'd advise you go back and re-read and practice what that is teaching ๐Ÿ™‚

#

That should get you on the right path

pallid wing
#

I understand, I will review and reread the section. Thank you very muc

#

for the advice as this is my first time on the server

vague dust
#

can i get a little guidance to the Windows Event logs and finding evil first question on the skills assessment? it says to examine the directory to determine the process responsible for executing a DLL hijacking attack. am i supposed to imitate the attack and then look at the log ?

dim wolf
#

no, all you need is to inspect the provided log files

vague dust
#

ok ty

orchid pine
#

Anyone know what is the prerequisite to do a petit potame attack is the ad cs is necessary to able to exploit or we can carry out the attack wothout the ad cs to be present

cloud urchin
#

AD CS is required

next bronze
#

petitpotam is not even strictly an attack, it's just a coercion method

#

it's useless if you can't chain it to something else

mint peak
#

Having a hell of a time trying to find some initial foothold on AEN, doing it blind... Learning Web stuff might not be my strong suit right now LUL

dapper moth
#

Hey, @next bronze can I DM just to confirm it's a issue on the VM / Pwnbox or routing problem and not spoil some of the info on the module?

next bronze
#

I also don't use pwnbox

dapper moth
#

On the Windows Lateral movement module

dapper moth
shut wraith
#

Can anyone help me in the Broken Authentication module for getting the OTP. This is my command:

ffuf -w mixed_otps.txt -u http://83.136.252.57:35419/2fa.php -X POST -H "Host: 83.136.252.57:35419" -H "Content-Length: 5" -H "Cache-Control: max-age=0" -H "Accept-Language: en-US" -H "Upgrade-Insecure-Requests: 1" -H "Origin: http://83.136.252.57:35419" -H "Content-Type: application/x-www-form-urlencoded" -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.6478.57 Safari/537.36" -H "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" -H "Referer: http://83.136.252.57:35419/2fa.php" -H "Accept-Encoding: gzip, deflate, br" -H "Cookie: PHPSESSID=ub39g1j86hfu7gpj0mmmkp5ohq" -H "Connection: keep-alive" -d "otp=FUZZ" -fr "Invalid OTP."

rustic sage
#

Module: XSS
Section: Phishing

My issue is im not obtaining the credentials from the user, however i tested it on myself and it worked, im just stuck when it comes to the php part im not understanding what im supposed to do

rustic sage
cloud urchin
shut wraith
#

@cloud urchin ^

acoustic owl
shut wraith
acoustic owl
dapper moth
#

This one! I can ping the IPv6 address with 0 loss, but nmap returns all ports filtered or closed
Just to confirm.

#

Also could only achieve this with ligolo-ng
Proxychains + chisel donโ€™t want to work for anything

next bronze
#

need to add the ipv6 route tho

#

that's all I can remember

pallid sparrow
#

hi

#

h r u all

#

??

#

i want to write penetrate in msf

#

any one help

#

[;z

dapper moth
# next bronze need to add the ipv6 route tho

Iโ€™ve added the IPv6 subnet to the ligolo interface routing table already but still nmap returned nothing.
So you used ligolo and not chisel+proxychains then!?
Saw that you had some issues on the WSUS section that was resolved by switching VPN servers right?

next bronze
#

yeah I don't use chisel unless I have to since ligolo is much easier to use

dapper moth
#

I guess

next bronze
#

the WSUS thing was fixed, the rouute wasn't configured properply for US vpns

dapper moth
#

Itโ€™s more reliable and flexible I think

next bronze
#

yep

dapper moth
#

Will try again in a while

#

Thanks

pallid sparrow
#

please any help

cloud urchin
pallid sparrow
#

sorry i want to write exploite and tried multible things to make it done well but without solution

#

i use msf

storm elk
pallid sparrow
#

do u have knowledge about what i am talking about

#

metaspolite

#

kali

storm elk
#

Might be just best to check out Academy

sonic plume
pallid sparrow
#

dont know Eng very well

#

and these apps also

#

but in need for this help

sonic plume
#

they provide a book with everything about shellcoding, and are you talking about porting exploits?

pallid sparrow
#

please

cloud urchin
# pallid sparrow dont know Eng very well

this discord is about the hack the box website and their platforms, this channel is specifically for help with the modules on academy, you probably won't find help with that on this server.

storm elk
#

thats very specific ๐Ÿ‘€

fathom pendant
#

@wary stump huh?

wary stump
fathom pendant
#

we don't do soliciting here, read #rules

fathom pendant
#

no. soliciting. for. jobs

#

this is not a hacker for hire server

#

i suggest you stop asking

wary stump
#

I wnat u help me.

storm elk
sweet nimbus
#

hey, im having some issues with information gathering virtual hosts. im trying to run the gobuster to solve the exercise at the bottom but don't get any hits on my wordlist

storm elk
#

show us your command ๐Ÿ™‚

sweet nimbus
#

gobuster vhost -u http://83.136.252.57:45218 -w /opt/useful/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain inlanefreight.htb

this is what i have at the moment, when i try with inlanefreight instead i get an error

#

i am using the htb pwnbox system

fathom pendant
#

--domain inlanefreight.htb --append-domain

sweet nimbus
#

okay i see, i was just missing --domain. thank you!

#

working now!

supple light
#

Hi. I need help with the ~~pivoting ~~ Lateral Movement module please. the MeshCentral section. Authenticate to (ACADEMY-LTMOV-SRV01) with user "admin" and password "RemoteManagement01"

  • 2 Connect to MeshCentral (https://<IP>. What's the device group name where DC01 belongs to?
#

I tried to authenticate with rdp, evil-winrm without success. How are we supposed to aauthenticate ?

#

Thank you !

fathom pendant
#

huh? meshcentral? that's not in the pivoting and port forwarding module

#

what's the name of the module?

supple light
#

sorry Lateral movement module

upbeat elbow
wraith pelican
edgy gale
#

hey everyone, i am facing an issue

#

any one help me ๐Ÿ™‚

#

even after entering correct url but still i am getting incorrect

#

๐Ÿ˜ฆ

wraith pelican
#

i guess this has to do with the port you specified

edgy gale
#

Thanks buddy,
have a good day

wraith pelican
sudden merlin
#

Guyz hello

edgy gale
edgy gale
sudden merlin
#

I want to learn hacking and cybersecurity

#

Is there who can support me and give good courses

edgy gale
edgy gale
ocean night
edgy gale
#

hey goblin how are u?

edgy gale
ocean night
#

Same old, how're you?

edgy gale
shut wraith
storm elk
#

I'll be on my computer in about an hour

fathom pendant
fathom pendant
fallen hull
#

It is technically impossible to solve the C# module without using vpn connection and only pwnbox.

#

The directory at the final skills assessment is something with h******s but I donโ€™t have permissions to access it via browser and yes Iโ€™m the pwnbox

fathom pendant
#

?

#

pwnbox naturally uses the vpn but idk what you're talking about

fathom pendant
#

:( ik it's broken because on a fresh spawn i'm curling with the host header of the subdomain i know works

#

chatting with support about it now

#

as a note for anyone doing the Information Gathering Module - Skills Assessment; there is currently an intermittent issue where sometimes the targets spawn but don't let you actually connect to them (403, and scans reveal a load of 403)

#

note: this does affect the subdomain/vhosts that are correct too, so scanning won't find anything

#

support said looking into it ๐Ÿ‘

quartz patio
#

I wanna learn ethical hacking from hack the box can anyone please provide the direct link of the module?

fathom pendant
#

there's no one module my guy

jade latch
#

search htb academy and click on the first link

fathom pendant
#

learn to walk before you run

fallen hull
fathom pendant
#

that's spoiling the module, most people do it blind

jade latch
#

aight. keep your web root to yourself then ๐Ÿ˜„

fathom pendant
#

you goon

jade latch
#

oops

#

i should try not reading the questions

#

found flag!

fathom pendant
#

most people do it Blind

#

blind = not reading the question and going for full domain compromise

#

then going back through and answering the questions

eager siren
#

hello i am doing Bleeding Edge Vulnerabilities on Active Dir Enumeration and Attacks, i am trying the petitpotam attack, when i am running the PetitPotam.py i am getting an error that looks like this
Trying pipe lsarpc
[-] Connecting to ncacn_np:172.16.5.5[\PIPE\lsarpc]
[+] Connected!
[+] Binding to c681d488-d850-11d0-8c52-00c04fd90f7e
[+] Successfully bound!
[-] Sending EfsRpcOpenFileRaw!
Something went wrong, check error status => The NETBIOS connection with the remote host timed out.

fathom pendant
#

also i didn't do petit for this

#

for this section i used the exploit referenced in Q1

eager siren
#

yes i already running, i did this with nopac, but i heard ADCS vuln are more common so i want to try petitpotam

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

eager siren
#

hahaha okay

fathom pendant
#

ADCS is a t3 module; so it's not expected for the CPTS exam

eager siren
#

Nevermind, the petitpotam crashed but i still got the cerificate on the ntlmrelayx, so i can proceed with the attack, i didnt check the ntlmrelayx beacuse i saw the error on the petitpotam program thinking it didnt work

fathom pendant
#

LOL even the example technically shows an error happen

eager siren
#

not the same error though, i mean a nice hardcore python error
Traceback (most recent call last):
File "/usr/local/lib/python3.9/dist-packages/impacket-0.9.24.dev1+20211013.152215.3fe2d73a-py3.9.egg/impacket/nmb.py", line 984, in non_polling_read
received = self._sock.recv(bytes_left)
ConnectionResetError: [Errno 104] Connection reset by peer

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "/opt/PetitPotam/PetitPotam.py", line 461, in <module>
main()
File "/opt/PetitPotam/PetitPotam.py", line 457, in main
dce.disconnect()
......

fathom pendant
#

Connection reset == Bad connection

#

the AD enum module is a bit of a pain sometimes, changing vpn regions can be more stable for the internal network

robust quartz
#

I am now at section PKI - ESC 1 in Windows attacks and defenses module.
When I RDP to the WS001, I can't login because "The trust relationship between this workstation and the primary domain failed.".

How to fix this issue?

@simple loom

robust quartz
#

xfreerdp /u:bob /p:'Slavi123' /v:172.16.18.25 /dynamic-resolution

next bronze
sweet nimbus
#

Hey, im stuck on the skills assesment for information gathering web edition. i am doing curl -I ||http://inlanefreight.htb:32634/admin/|| and only seeing|| apache|| for the server header. this is for the question what http server software is powering the inlanefreight.htb site on the target system?

robust quartz
sweet nimbus
#

im using the pwnbox and when i do that with the top subdomain wordlist, i get 200 on every attempt which doesnt seem right

#

apologies, that was happening without the hidden page, let me try now

stark lark
#

Tried following what you explained here but having some trouble working it out. It is for Pivoting Skills Assessment.

I've found two accounts which may be subjective to PtH (ape......... and Adm..........)

sweet nimbus
next bronze
#

try some remote tools like impacke'ts psexec

stark lark
next bronze
sweet nimbus
stark lark
next bronze
#

I would just set up a pivot and do it from my attack host tbh

sleek moss
#

hi guys when choosing a vpn what to look for for low ping

stark lark
upper imp
#

hi

stark lark
next bronze
next bronze
upper imp
#

hi

oak girder
#

hi, why does my RDP connection fail

silk anchor
split glade
oak girder
dapper moth
silk anchor
#

Anyone else having issues spawning targets?
Working now

fathom pendant
fathom pendant
# oak girder

xfreerdp has been having issues on pwnbox as well, use rdesktop or remmina

fathom pendant
#

Most scoped things fall in an ipv4 cidr range

dapper moth
#

You mean the flags?
If I don't set them it will take forever

latent raft
#

hello guys

fathom pendant
dapper moth
#

Even if I set a 'nmap -T5 -6 -p' will have to set port ranges for it to work

dapper moth
next bronze
#

nah that module has ipv6 targets

fathom pendant
#

Really? Huh

#

Weird

next bronze
mint peak
#

Currently practicing some reverse shell work. Set up a listener nc -lvnp 5454.

When I execute socat with EXEC:bash from the victim host, I get a stable reverse shell that doesn't drop, but if I use EXEC:/bin/bash, it connects and immediately closes the connection. Anyone have an idea? Can't seem to find anything on the internet and ChatGPT isn't helping

exotic turret
#

Think there is an error in web requests module. On the search.php?search= one where you are supposed to figure out that search.php is used, the script.js throws an error so you never get to that point. Watched a tutorial after struggling and network tab was different to mine with same steps

eager siren
#

does this machine Attacking Domain Trusts - Child -> Parent Trusts - from Windows take more than 10 min to spawn?

sudden merlin
#

guyz i need help with androrat

timber hatch
#

anyone else having trouble with rdp?

#

[ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]

timber hatch
#

i can ping yes

eager siren
#

try again now myabe it had problem until initalized

timber hatch
#

nvm

storm elk
formal nimbus
#

hello
for the module Intrusion Detection With Splunk (Real-world Scenario) im struggling on the question Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through SPL searches against all data the method through which the other process dumped lsass. Enter the misused DLL's name as your answer. Answer format: _.dll
im sure that the answer is ntdll.dll but that doesn t work

silk anchor
#

Run it with -v 6 and look at the actual error.

digital junco
#

Hallow

#

Can you tell me where the error is in my payload?
`throw({message: 'The input ""' + console.log(input[0]); + '"" contains the following invalid characters: [",',;,',"]', statusCode: 403})`

normal sand
silk anchor
digital junco
#

Can anyone who has completed the intro to whitebox pentesting module give me a little help with a question?

normal sand
normal sand
silk anchor
#

Read the error, Read the payload. Check the difference. You already know what the issue is from blindly running the script so it should be easy to spot.

normal sand
#

There's no 274, 1, 686, 0) at the end of my payload.

#

I can see there's zfuy but the part before that doesn't match the payload either.

#

That still doesn't explain where 274, 1, 686, 0) came from.

#

Oh, the 274, 1, 686, 0) could be the suffix of the original query.

#

I wanna ask if I understood it right, but certainly doesn't feel like it psyduck

#

Oh, great. What encoding is that?

silk anchor
#

It will be some kind of blacklist/blocklist

normal sand
#

I see.

fathom pendant
#

Don't spoil skill assessments answers

normal sand
fathom pendant
worn matrix
# oak girder

i dont know if it worked,but try to add the password inside '' ,and also add a fixed size for the RDP

noble fiber
#

Hi everyone, has anybody done the Dynamic Analysis section from Introduction to Windows Evasion Technique Module? I'm running into some issue with the microshell shellcode. I don't receive a call back from the revshell whilst the self-written c# reverse shell give me a call back. If someone else has had the same problem and figured this out please let me know

fathom pendant
#

No

#

You never go positive in cubes

#

T0 modules give back all the cubes spent on them, t1 and higher only return 20%

olive fiber
#

Hello,
any tips for second question DACL Attacks II Skills Assessment?
I have a new user and trying to find the path to next target? It has to do with logonscripts? gpos? I have enumerated multiple ways but without sucess

next bronze
minor dome
#

why the progress bar and errors the same?

#

This is my first time using ffuf so Im not sure what to expect

dim wolf
#

you're not going to get any hits for subdomains, you have to fuzz for vhosts instead

minor dome
#

so what changes? i get confused between those 2

dim wolf
#

you need to add the Host header
ffuf -w wordlist.txt -u http://example.htb -H 'Host: FUZZ.example.htb'

minor dome
#

Gotcha ok ill try that. if its not to long of an explaination, what does the host part of the command do?

dim wolf
#

subdomains will not resolve since they use DNS, and there are no DNS records for any of the domains you'll find in HTB machines

fathom pendant
#

^

#

You'll need to add it to your /etc/hosts file

#

And if it is a public ip, you don't put the port in the hosts file

dim wolf
#

you'll need to fuzz for vhosts instead, and you can do that by adding the Host header and fuzzing that

fathom pendant
minor dome
#

yes

fathom pendant
#

Then it's public

minor dome
#

Ok thank you

fathom pendant
#

10.129.x.x = private
Everything else = public

dim wolf
#

filter hits by response size, and you'll find your vhosts. add them to your hosts file and you should be able to access them in your browser

fathom pendant
dim wolf
#

what it do, not on pc rn

fathom pendant
dim wolf
#

sounds awesome maybe

#

if it filters automagically

fathom pendant
#

It does

dim wolf
#

gotta try it out at some point then

fathom pendant
#

I adopted it bc ffuf fuzzing likes to give a bunch of 200s

minor dome
fathom pendant
dim wolf
#

yea, run it once it'll give you a ton of 200s

fathom pendant
#

What is the common size among them

dim wolf
#

filter by that common size

minor dome
#

Does it have to run all the way thrugh before it gives me anything back?

fathom pendant
#

You mean after you set the filter?

minor dome
#

I havent set the filter bc i dont see anything being sent back yet

fathom pendant
#

Are you getting errors?

minor dome
#

yeah

fathom pendant
#

Your command also needs to have the port in it

minor dome
#

... i put the port in the wrong spot

fathom pendant
#

ffuf -u http://inlanefreight.htb:port -H "FUZZ.inlanefreight.htb" -w 'wordlist'

#

As said earlier, the port does NOT go in the hosts file

minor dome
#

I didnt do that ik that. I just put in front for some reason. idk y

fathom pendant
#

Lol

minor dome
#

So if this is some of the returns i get, the filter is what? the size is the same so its not fs id assume

wraith pelican
# dim wolf subdomains will not resolve since they use DNS, and there are no DNS records for...

hey sorry but i don't think that is true, if I'm not mistaken there are DNS records in htb machines, just not in that exercise.
It is not because machines use private DNS to resolve the name that there is no DNS records, they are just not in public servers.
When you add an IP and domain to /etc/hosts, it is useful for resolving a domain name locally. Some tools accept you specify a remote resolver and then /etc/hosts entry is not imperatively needed, even though it is a good habit to add entries in that file.
So saying that could be misleading to there is only vhosts in htb and never dig or fuzz for subdomains.

fathom pendant
#

So does dig and basic subdomain fuzzing

wraith pelican
#

dig accepts remote resolver

fathom pendant
#

Yes. But that's not the default lol

#

You're skipping the point lol

wraith pelican
#

i dont think so

fathom pendant
#

The point is; by default you're not gonna get hits with queries unless you manually specify

dim wolf
#

yea, i meant to say no records in public DNS servers. if there's an HTB box running DNS, you could have some records in there for subdomains (which are actually vhosts) that you can potentially enumerate and access

wraith pelican
#

no the point is saying there is no dns records is misleading

fathom pendant
#

This is a case of distinction of vhost and subdomain

#

Vhost means that the host is on the same ip

#

Subdomain just means it belongs to the subdomain

#

While colloquially, they are interchangeable- they are different

minor dome
minor dome
fathom pendant
#

But your results tell you what size to likely filter

minor dome
#

which is whats confusing me bc all the hosts are 120

#

plus the rest of the random stuff

fathom pendant
#

With ffuf, the filter discards results that are in the filter

#

The opposing would be the match

minor dome
#

OH I thought it was just gonna spit the same stuff. ok thank you

wraith pelican
fathom pendant
fathom pendant
dim wolf
#

vhosts can most definitely have DNS records

fathom pendant
#

It would be pointed to with 127.0.0.1 on the dns record

wraith pelican
#

even if that does not diminish my previous point : D

fathom pendant
#

Major point being, you're not gonna get routed to a .htb tld

#

Not without manually setting it up

dim wolf
#

i think the only module that you'll maybe see subdomain fuzzing is Information Gathering and possibly DNS Enumeration Using Python

#

because the .htb domains you're given simply don't resolve to anything

#

unless the box has DNS + web server running

rugged pecan
#

Can ANYONE help me find what I'm looking for?

Path: SOC Analyst
Module: Windows Event Logs & Finding Evil
Lab: Analyzing Evil With Sysmon & Event Logs
Detection 2 | Question 2

In the lab, Detection 2 guides to complete Detecting Unmanaged PowerShell/C-Sharp Injection. In the command that is provided, I am unable to find locate how they got -PoshCode.

Command:
Invoke-PSInject -ProcId [Process ID of spoolsv.exe] -PoshCode "V3JpdGUtSG9zdCAiSGVsbG8sIEd1cnU5OSEi"

wraith pelican
dim wolf
#

it's important, you just won't see it very often in the context of HTB boxes

minor dome
#

I switch was I was looking for to directories using ffuf, and am getting stuff back but, I need to find a API key. I see that the 'admin' directory exists (whihc is where i need to go) with stuff in it but i dont know how to access that.

#

did i use this right?

wraith pelican
rugged pecan
#

I'm trying to find how they found it in the tutorial.

#

It's just provided

wraith pelican
# rugged pecan I'm trying to find how they found it in the tutorial.

I'm not sure I'm understanding what you mean. The command in the tutorial is just an benign example, printing Hello, Guru99.
Let say an attacker want a reverse shell. They will write the reverse shell command in plaintext, base64 encode it and then inject the b64 string into a process.

#

Does that clear things for you or am I just explaining something you obviously already understood? ๐Ÿ˜„

rustic sage
#

@next bronze the sections makes multiple mentions of "tickets" without specifying if they r TGT or TGS and stuff are generally confusing there, look at the first mimikatz snippet for example

next bronze
#

huh? nowhere in the pass the hash section did they talk about tickets

rugged pecan
rustic sage
#

"mimikatz - export tickets" What tickets??

next bronze
#

where in the pass the hash section?

rustic sage
#

the first cmd snippet

#

sekurlsa::tickets /export

#

what is the use of these tickets, are they tgt

next bronze
#

the first cmd is about passing the hash

wraith pelican
rustic sage
#

yo mb lol i meant the next section

#

execuse me

next bronze
#

oh yeah that's about passing the ticket

#

completley different thing

rustic sage
#

exactly

#

hard stuff

next bronze
#

I would suggest to do the Introduction to Active Directory module to get a better understanding of kerberos

rustic sage
#

i did it

#

ik the theory stuff, prob

next bronze
#

yeah there's a whole section about Kerberos Authentication Process

rustic sage
#

yea its TGT and TGS, but what is the first mimikatz command supposed to do?

rugged pecan
next bronze
rustic sage
#

TGT tickets?

wraith pelican
next bronze
rugged pecan
#

As users, are we not able to add images here?

wraith pelican
spare fossil
#

Hello, module: web attack/Mass IDOR enumeration, why am i not getting that uid parameter like in the module? i have been struggling on this for few days... please help?kek

rustic sage
tranquil crystal
#

./odat.py all -s 10.129.165.181 I run this and it doesn't find any logins.

wraith pelican
wraith pelican
rugged pecan
#

Can ANYONE help me find what I'm looking for?

Path: SOC Analyst
Module: Windows Event Logs & Finding Evil
Lab: Analyzing Evil With Sysmon & Event Logs
Detection 2 | Question 2

In the example, they don't show how they got the -PoshCode as it's only given/provided. For me i'm just curious if anyone would know how or where to find this so i have a reference point to look it up.

Command:
Invoke-PSInject -ProcId [Process ID of spoolsv.exe] -PoshCode "V3JpdGUtSG9zdCAiSGVsbG8sIEd1cnU5OSEi"

spare fossil
rugged pecan
wraith pelican
wraith pelican
spare fossil
wraith pelican
pseudo kiln
#

any Obsidian wizards around ? I dont get why it is highlighting the first IP octet as purple

jade latch
#

when you go into reading mode it will highlight the second one too ;)

fathom pendant
pseudo kiln
#

ah ok, I thought I messed it up somehow still looks better than no color highlighting at all

fathom pendant
#

Ye

pseudo kiln
spare fossil
tranquil crystal
#

Now I get a problem trying to run sqlplus

tranquil crystal
#

I'll try to figure out why. I may have to get a non distro package

spare fossil
wraith pelican
pallid spindle
#

sorry, where can i get help with linux?

spare fossil
storm elk
vocal turtle
#

Hey guys i am stuck in blind xpath injection. if anyone can help please dm me

storm elk
vocal turtle
#

@storm elk i am currently exfiltrating the nodes and it came up as /accounts/acc/acc. now when i am trying to exfiltrate the values in nodes "acc" its string-length value is 0.

storm elk
#

If you get string length 0

pallid spindle
#

sorry, how can i ssh into htb-student?

#

i dont understand this

storm elk
pallid spindle
#

i am following

#

okay did it

storm elk
#

๐Ÿฅณ

#

well done

gray yacht
spare fossil
spare fossil
storm elk
spare fossil
storm elk
#

Great job!

spare fossil
#

how do you guys URL encode ? in the bash terminal, i'm stuck at web attacks/IDORs/bypassing encoded reference

dim wolf
#

Burp Suite has an encoder

sonic plume
#

curl --data-urlencode

spare fossil
spare fossil
sonic plume
#

could anyone say if im in the right or "almost there" direction on the "Linux Local Privilege Escalation - Skills Assessment". so i got the hidden creds in || /var/logs with the user that has the permissions for it ||. Tried to spray the common creds on the tomcat login page, spend here a lot of time so i moved on and i tried mysql, and the other users but no luck here...

#

i want do to this blind, so i dont want hints/nudge. just tell me i am close prayge

minor dome
#

Can anyone give me a hint on how i can find a API? I did this hoping to find a directory but im confused and dont even know if im asking the right question

sonic plume
#

maybe use bigger wordlists?

#

and if you wanna try finding directories like /api you gotta change the command btw. now youre searching for api subdomains

minor dome
#

the question asks about the admin directory and thats what I searched after this one but came up with nothing again

autumn pilot
#

did you add the domain in your /etc/hosts file

sonic plume
#

you tried inlanefreight.fuzz for directory fuzzing?

#

thats incorrect, it should probably look like inlanefreight.htb/FUZZ (for directories)

fervent vector
#
In our math example, we must decide where to place the smallest number to make it as easy as possible.

    either we place it on the first open digit
    or we place it on the second.
#

whats meant by this

#

20 * ________ + ________ = 65535

autumn pilot
#

from which section/module is that?

fervent vector
#

infosec

autumn pilot
#

infosec?

fervent vector
#

basically "learning process"

#

on "decision making"

heavy edge
#

what encoding is this
<?php system($_GET[fe8edbabc5c5c9b7b764504cd22b17af]);?>

#

i dont understand where they got it from

#

and i cant find anything that decodes it

autumn pilot
#

looks like it is a md5 value used for the command execution parameter

inner adder
#

Hi, In module Linux privilege escalation in lab environment Enumeration and Linux Services & internals Enumeration it return error when I try submit answer. Can you check it's everything ok?

autumn pilot
#

make sure you don't have any white spaces in the answer

inner adder
#

I'm sure it's ok I try multiple times

unborn oriole
heavy edge
vast thorn
#

currently on linux fundamentals, im stuck on the question "submit the full path of the "xxd" binary." and i thought the answer was /usr/bin/xxd but i was wrong and now im feelin a little stuck

sonic plume
autumn pilot
#

you can use the which command to find the full path to any binary

sonic plume
#

probably typo

vast thorn
#

ye, ment usr

inner adder
#

I just found flag.txt in root dir and can't submit

#

Second is python version and can't submit too

#

Others labs not have issues

shut wraith
#

Hello can I please DM anyone about XXE? I have a question

unborn oriole
# heavy edge its supposed to be a php command injection, but im guessing its encoded become n...

I'm not looking at the module but IMO it's not encoded, it just looks like a random parameter name. like normally that shell looks like <?php system($_GET["cmd"]); ?> and to use it you use query string?cmd=whoami to pass whoami to system to execute but maybe an IPS or something looks for $_GET["cmd"] to trigger a signature. So in your example they just use a random parameter fe8edbabc5c5c9b7b764504cd22b17af which you would use like ?fe8edbabc5c5c9b7b764504cd22b17af=whoami

#

(my example isn't very realistic but just using it to illustrate why there could be a random parameter)

#

cause functionally there'd be no reason to encode the parameter name. (that I can see)

#

but if i've made an error plz someone come shame me

dim wolf
#

unlikely but possible

#

that's why they used an md5 hash

sonic plume
#

could anyone say if im in the right or "almost there" direction on the "Linux Local Privilege Escalation - Skills Assessment". so i got the hidden creds in || /var/logs with the user that has the permissions for it ||. Tried to spray the common creds on the tomcat login page, spend here a lot of time so i moved on and i tried mysql, and the other users but no luck here...

gray yacht
fervent vector
#

i finished "learning process"

split glade
gilded plaza
#

i have big error when i login in academy how to solve that there is anyone can help me

heady vine
gilded plaza
heady vine
gilded plaza
heady vine
#

We're regular users just like you.

compact patrolBOT
gilded plaza
gilded plaza
split glade
#

It may take some time yes, from what I read

gilded plaza
#

fine

heavy edge
minor dome
#

whats wrong with this? gobuster dir -u http://94.237.55.236:49175 -H "Host: inlanefreight.htb" -w /home/ianworm/directory-names.txt (It says wordlist must be specified but I checked the path and its right, and the it also says domain must be specified and thats whats in the module

slow ether
# minor dome whats wrong with this? gobuster dir -u http://94.237.55.236:49175 -H "Host: inla...

gobuster dir -u http://94.237.55.236:49175 -H "Host: inlanefreight.htb" -w /home/ianworm/directory-names.txt
also... check: File exists and is readable:

bash
Copy code
ls -l /home/ianworm/directory-names.txt
This should display the file with appropriate read permissions.

Correct usage of -H option:
The -H option should be used correctly as it is for headers. Ensure there are no extra spaces or incorrect characters.

If the command still fails, you can try running gobuster with minimal options to isolate the issue:

bash
Copy code
gobuster dir -u http://94.237.55.236:49175 -w /home/ianworm/directory-names.txt
If this works, then add the -H option:

bash
Copy code
gobuster dir -u http://94.237.55.236:49175 -H "Host: inlanefreight.htb" -w /home/ianworm/directory-names.txt

dim wolf
#

-w first

#

might be looking for the flags to be in a certain order

minor dome
#

Ok

#

Same thing pops up

#

should I not be using the ip and be using the 'inlanefreight.htb'?

#

w the port

dim wolf
#

i don't use gobuster so this is outside of what i know

#

but the error messages point to some clues

#

check to make sure that your wordlist is where you're specifying

minor dome
#

i did w -ls

dim wolf
minor dome
#

ok

dim wolf
#

and make sure you made the appropriate entry in your /etc/hosts file

minor dome
#

I did that.

#

I dont put the port there right

dim wolf
#

don't put the port there

minor dome
#

ok ill try that

dim wolf
#

what module/section is this

minor dome
#

Information Gathering web edition skills assessment

#

same error

slender violet
dim wolf
#

i'm actually doing this module rn..

slender violet
minor dome
#

What is the API key in the hidden admin directory that you have discovered on the target system?

dim wolf
#

ok well mine worked

#

deleted bc spoilers

slender violet
#

Gotcha

minor dome
dim wolf
#

something might be wrong with your install

minor dome
#

what is an unkown shorthand flag in 'u' -u

#

jk got it

rustic dew
#

Hi all, quick question hopefully, I'm trying to run smbmap for the "Attacking SMB" section of the "Attacking Common Services" module... when I run it in Pwnbox, not problems connecting to the share with 'smbmap -H <target_ip>', when I try and do this using my Kali VM over VPN to the target IP, I'm getting the attached...

I've updated Kali, tried downloading the latest python script and running it directly... and even created a new Kali VM (fresh install) on a 2023 version of Kali, and I'm getting the same issue...

Is this a problem with smbclient? or an issue with trying to use smbclient via the VPN tunnel?

#

If I recall, that's the list I used...

spring mirage
civic hamlet
#

@fathom pendant btw, the issue with my xfreerdp not working lie with me having a backup vm that may or maynot have also been using the academys vpn

#

getting rid of the backup fixes the issue

slender violet
#

@civic hamlet I was also having issues with RDP not loading and having a black screen and I fixed it by hitting space bar.

#

Also sometimes I have to wait a couple minutes, or run the command multiple times.

slender violet
#

Are you having similar issues? Also are you attempting to connect from Pwnbox, or from a VM?

civic hamlet
#

from a vm

#

it worked after I got rid of my backup vm, so everythings good

shut creek
#

I'm looking for a hint: I'm doing some fundementals work in academy and am having trouble with the question "How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)"
I've been using netstat -lp and trying various greps to get the count of running interfaces but these answers are wrong so there's something I'm doing wrong.

split glade
slender violet
#

Yep..

turbid echo
#

Eyy,

Has anyone attempted the Advanced CSRF and XSS module? Specifically the Abusing CORS misconfiguration for CSRF

#

If I add Origin: any.htb to the request the server responds with Access-Allow-Origin: null

#

I did use the sandboxed iframe

#

It is just refusing to send any cookies and the browser says the error is because the cookies are treated as Third Party

turbid echo
#

Am I missing something or is the lab just broken?

#

I respawned the challenge and still same behaviour.

mint peak
#

Currently practicing some reverse shell work. Set up a listener nc -lvnp 5454.

When I execute socat with EXEC:bash from the victim host, I get a stable reverse shell that doesn't drop, but if I use EXEC:/bin/bash, it connects and immediately closes the connection. Anyone have an idea? Can't seem to find anything on the internet and ChatGPT isn't helping

turbid echo
civic hamlet
#

Password for [WORKGROUP\htb-student]: 

tree connect failed: NT_STATUS_BAD_NETWORK_NAME```

Why is this happening? ive spent 10-15 minutes trying to look for answers (firewalls, incorrect path to the shared file) This is giving me a headache, I guesss its deserved for not using pwnbox eh?
split glade
turbid echo
sonic plume
split glade
elder matrix
#

hey! i completed the Pivoting, Tunneling, and Port Forwarding skills assessment with chisel and im wondering if i can replace chisel entirely with ligolo-ng from now on? I had to try many times to get a xfreerdp session with the last machine

#

i knew i had the right credentials and all... took 3 attempts to connect with proxychains -q xfreerdp

quasi wave
#

what metasploit exploit am I supposed to use for the Automating Payloads and Delivery with Metasploit section of shells and payloads module? I tried eternal blue and two others and its not working. I thought if I tried to attack the SMB port because port 445 is open that I would get a reverse shell.

#

I also tried exploiting port 139 and it did nothing

#

am I exploiting the right port? I know if nothing else I'm getting the exploit wrong because I get this error that it won't let me post in this Discord server no matter what port I pick

#

I think I am getting something right because it won't let me post my output in this Discord.

#

which means it might partially be a spoiler?

dim wolf
#

automod blocked your message

cloud urchin
#

did you try the exploit in that section of the module?

dim wolf
#

my advice is to use another exploit since it says "The target is not vulnerable"

cloud urchin
#

try what the section shows.

elder matrix
#

another question about ligolo...
if i double hopped, and that new machine im connected on has a local port not detectable with nmap..
in this example port 3306.
Is it possible to use ligolo-ng to make port 3306 appear in my nmap scan and give me access to the local mysql service (if i have the creds for it.)?

#

aka port forwarding.

cloud urchin
#

ligolo-ng is just a tunneling tool. it doesn't port forward for you.

elder matrix
ocean night
#

I need to watch that again ๐Ÿ˜„

elder matrix
#

i thought of that extra scene earlier today ๐Ÿคฃ

quasi wave
quasi wave
#

ok I finished section I'm on next section

vocal turtle
dim wolf
#

alternatively double the backslashes: \\\\10.129.206.249\\Company Data

#

\ is treated as an escape character, so you have to specify \\ for one backslash

civic hamlet
#

Am I supposed to know this stuff? Feel like intro to bash scripting shouldโ€™ve been higher up on the security foundations path

cloud urchin
#

i'd consider the escape character linux fundamentals

civic hamlet
#

funny guy haha

cloud urchin
#

?

civic hamlet
#

Wait that wasnโ€™t satire?

dim wolf
#

it's not satire, that's basic linux bash shell

civic hamlet
#

I took detailed notes for Linux fundamentals and it never mentioned anything about escape characters

cloud urchin
#

i'm not saying it's in the linux fundamentals module, it's a basic os thing

civic hamlet
#

mightโ€™ve been on introduction to operating systems

cloud urchin
#

you should probably delete the pic as it contains module content and spoilers

oak girder
cloud urchin
#

you simply ask your question

slender violet
#

My question is why is my correct command not working.

#

If I don't provide the command I'm using, how would anyone help me?

cloud urchin
#

because many people have completed the module

slender violet
#

Ok I can delete it but can someone please take a look at it and tell me if my command is correct? Or can I DM someone?

cloud urchin
#

your error says timeout

slender violet
#

So I need to change the timeout in my proxychains file?

cloud urchin
#

no it means it timed out

#

you could try that if there's a timeout in there

#

make sure you can reach the target still

slender violet
#

So I don't get an error running CME against 172.16.6.50, but I do get an error when running secretsdump.py against 172.16.6.3. They're on the same subnet and I have the autoroute and SOCKS proxy set up for that subnet.

#

Oh it's because I needed sudo

cloud urchin
#

i don't really use metasploit so i'm not sure. it's a timeout error not a permission error you had.

slender violet
#

I got it to work.

#

After I prefixed the command with sudo.

#

It doesn't work for me without sudo

cloud urchin
#

may be something with metasploit then

slender violet
#

Interesting. Thanks anyway for the help!

runic remnant
#

ive been trying to upload a zip file to bloodhound but it just stays at 0% when uploading the data, ik bloodhound is discontinued and I tried uploading the same data to bloodhound CE which worked but isnt too useful for giving the info like the orignal bloodhound does. Do I need to use CE or is there a way to fix the data not uploading?

oak girder
civic hamlet
oak girder
#

No I don't have access to that

next bronze
#

yes you do, right click cmd > run as admin

rustic sage
#

guys so can someone help me i dont know what's wrong but how to solve this?

#

Where are the Applications related to the system stored at?

#

on Macos fundementals module

cloud urchin
#

the password has underscores in it

shut wraith
#

Hey guys what do you think about the Senior Web Penetration Tester course and cert?

cloud urchin
#

i think its a fun course

shut wraith
cloud urchin
shut wraith
cloud urchin
#

advanced xss & csrf exploitation, modern web exploitation techniques

#

i have more unlocked i need to do

shut wraith
cloud urchin
#

both are good

spring mirage
#

I'm so confused on this module...there isn't enough time allotted by HTB to complete the required task. You literally have to have your script go through 10 million usernames...I must be missing something.

#

Anyone able to give me some sort of hint on the Enumerating Users module, by chance? Using the xato-ten-million.txt list doesn't seem to be possible unless I want to sit and wait here for like 6 hours.

spring mirage
honest gyro
#

and u dont need to go through them all

#

just use the first one u get i remember its was fast

civic hamlet
#

I also thought the point of using single quotation marks was to deal with the backslash issue

#

which would mean its not the issue

queen merlin
#

I just finished starting point boxes and jumped into academy, i finished Intro and Learning Process, im now looking through all tier 0 fundamental modules and honestly theres a lot and i dont really know where to start, does it matter what i pick? Should i just pick what feels interesting? Or do u have any recommendations?

wraith pelican
queen merlin
#

ohhh

#

i didnt even realize what paths were

#

its just like a prebuilt path/order of modules XD thats exactly what i was looking for

#

tysm

cloud urchin
#

Attacking Authentication Mechanisms - Attacking Signature Verification. Does the first method work here? I'm only able to get admin via the second method.

left pawn
#

hey guys I am an absolute beginner to CyberSecurity

#

can anyone guide me on how to gradually become good at it and I am currently learning MERN stack

fathom pendant
#

Idek what that is

#

This channel is for help with academy modules

#

I suggest reading and following #welcome and asking in a channel like #web or something

#

Yeah it's a web dev thing

nova wharf
#

hey everyone, qq I'm currently in the login brute forcing mod working on the Service Auth Brute section and when I try to use hydra to BF SSH it gives this error am I missing something or should I restart the box? i doubled check the ip to make sure I put the correct syntax\

storm elk
#

Maybe you need to check you port

#

That doesnโ€™t seem right ๐Ÿ‘€

nova wharf
#

port 22 is for ssh

storm elk
#

But does your lab also tell you itโ€™s 22?

#

What port does your target tell you to connect to?

#

You can change the port of ssh to any port you want in config

nova wharf
#

so insead use the port at the end of the ip and not 22?

storm elk
#

Yes

#

Always use port the provided

#

22 is the default port, but you can change it to be any port really

nova wharf
#

heard thanks I was just thinking since it was port 22 thats what I should be going after

#

alright its working thanks

storm elk
#

Glad itโ€™s working now. Have fun ๐Ÿฅณ

fathom pendant
nova wharf
fathom pendant
#

As the target is a public container, it's easy to get mixed up

nova wharf
#

okay should I assume the same for every box moving forward?

#

for the services being ran?

quiet trout
quiet trout
nova wharf
#

for instance the one I'm working on both ssh and ftp port should I put it as the port as the provided

fathom pendant
#

Same section?

#

Go from within

#

Start ssh, then internally go to ftp

#

127.0.0.1 is powerful prayge

nova wharf
fathom pendant
#

Correct

nova wharf
#

heard

#

thanks

fathom pendant
#

Not all services running are accessed externally, this can be true in many scenarios

nova wharf
#

any reason the rockyou.txt got split like it is now?

fathom pendant
#

Just makes it faster in some instances

#

Bruteforcing with rockyou overall would suck if the password was in the bottom 10% of that file

#

But if it's in a specific segment, just use that segment

nova wharf
#

whats a good starting point not trying to spend all night wait on 9k tries lol

fathom pendant
#

In this module the passwords are generally near the top

#

So you don't have to wait too long

#

If you dont get it within 5 minutes, go to the next one

nova wharf
#

the examples was using -10 I was thinking about using 30

fathom pendant
#

Always start small go big

#

But as I said usually within 5-10 minutes it would crack

#

So if not then then next list

nova wharf
#

okay cool thanks

#

do you think it will hurt to run the default 16 task when using hydra vs the 4 task the example is showing

#

or will the box crash due to the requests

quiet trout
#

if you're doing the hashcat module theres one or two labs there that are prohibitively time intensive to crack... and best to skip as mentioned, or check solution make sure you have it down pat then move on

#

i havent done the haschat (password cracking?) module in about 2 years now though, so it may have changed. i just recently got academy access bac ktho

quiet trout
#

yeah i might be misremembering but if you're on the password cracking module there will be some that are kinda obscure and took forever to crack and i had to just move on;.

nova wharf
#

Im on the rockyou-20txt and no dice as of yet got bout 200 more tires to wait on

#

7min left

#

the mod is Login Brute forcing I'm on ther service Auth brute forcing section

autumn pilot
#

rockyou wont yield anything

upper imp
#

hi

nova wharf
autumn pilot
#

build a dictionary file

nova wharf
fathom pendant
#

<@&861185840277487616>

hoary depot
spiral scarab
#

Am I the only one having issues spawning targets ?

nova wharf
#

I shouldn't have more than one use able password combo correct

nova wharf
storm elk
nova wharf
storm elk
#

try to switch your quotes around, maybe that helps (not sure though)

#

so enclose the entire bit by ' and your ```<form name="login"````

nova wharf
#

could I use the formmethod='post'

#

nvrmd didnt work

#

hydra -l user -P /opt/useful/seclists/Passwords/Leaked-Databases/rockyou-10.txt 94.237.55.236 -s 46736 http-post-form "/admin_login.php:user=^USER^&pass=^PASS^:F=<formmethod='post'"

#

I'm trying that because of the reponse I got in burp

#

I think I see what I did wrong hahaha

#

got it lol

storm elk
#

good job

jolly yacht
#

Hey, In Introduction to Networking Module's section. About the OSI Model, it looks like this statement is inaccurate : "The OSI model is usually referred to as the reference model because it is newer and more widely used.". Is it correct ?

jolly yacht
fathom pendant
#

Yes it's more widely used

#

Whenever people make a joke about layer 8 issues, it's a reference to the 7 layer stack

#

I.e. the issue is outside the stack, the user

timber hatch
#

Windows Privilege Escalation / Windows Desktop Versions
You can't install the windows-exploit-suggester.py tool to find the vulnerabilities. it only generates errors...or did someone else here manage it?

fathom pendant
#

Or to your system

#

The target machines don't have internet access

jolly yacht
timber hatch
fathom pendant
fathom pendant
#

Do you mean the in-browser vm?

#

Also it helps to read the errors

timber hatch
dapper moth
#

There are some work arounds youโ€™ll have to do to get it to work as well

#

Will have to convert the DB file from xlsx to xls with libre office

#

And install an older version of a python xls parser library

#

I have a step by step in my notes for the older boxesโ€ฆ
On how to resolve the issue using the python2 version and python3 version of the win exp suggested script

#

You can DM me if you find a problem on how to make it work but it will take a couple of hours for me to reply cause I should be sleeping. Just woke up to feed the dog ๐Ÿ˜‚

timber hatch
severe cedar
#

Hi. I'm not understanding what am I doing wrong in introduction to windows command line -> skills assessment -> User10 question

sonic plume
rustic sage
#

in the password attacks module in section PtH from linux, last question..how do i get Linux01$'s ticket?

#

i tried(as svc:workstation's root)

find / -name *.keytab
find / -name *.kt
find / -name krb5cc*

fathom pendant
river ocean
#

Hello every1 ๐Ÿ™‚ In the module "Getting Started" section "Staying Organized" I have been provided with various examples of tools to keep our notes. Is there a reason there isn't Obsidian there? As this is my main note-taking tool atm.

fathom pendant
#

You can submit /feedback and suggest it be added

river ocean
#

Will do, thank you

fathom pendant
#

Imo canvas feature super underrated

river ocean
fathom pendant
#

... just type /feedback in the discord

river ocean
river ocean
fathom pendant
#

Yes

river ocean
#

Looks promising

fathom pendant
#

Organize separate things into one idea

#

I.e. for a skill assessment I can write my whole flow instead of referencing a/b/c in a file

shut creek
#

I have a question: I'm doing the windows fundementals box and when I try and use smbclient -L [ip] -U htb-student I get an error.
Error NT_STATUS_IO_TIMEOUT

rustic sage
#

yes

rustic sage
#

i've already tried it(base64 copy pasting and stuff) and i've had an error "/bin/bash^M incorrect interpreter" smth like that, when i openned the file i didnt find any error in the first line (#!/bin/bash, just like that)

fathom pendant
#

scp source destination

#

or use a basic http.server to transfer the files

#

you only need to resort to b64 if for whatever reason other methods don't work

rustic sage
#

alr tysm

shut creek
fathom pendant
#

the timeout is due to it not being able to connect/unstable connections

shut creek
#

I'm using openvpn

#

or do I have to change which region the box is in?

#

which US academy is east coast?

fathom pendant
#

idk

#

my guess is like 1/2

#

but that generally doesn't matter