#modules

1 messages ยท Page 299 of 1

shut creek
#

do I need to redownload the vpn connection file?

fathom pendant
#

it's just some weird instability with your connection

fathom pendant
shut creek
#

mmk

fathom pendant
#

whenever you change vpn regions it generates a new vpn profile

#

also the obvious (dumb) question, are you running the vpn in your vm?

shut creek
#

unrelated question: is there a way to slowly "grind" cubes? like dailies?

fathom pendant
#

no

#

t0 modules are "free" in the sense they give back the cubes you spent on them

shut creek
fathom pendant
#

t1+ all give back 20% of cost

fathom pendant
shut creek
#

mmk

fathom pendant
#

paying for cubes outright is scamming yourself

shut creek
#

yeah I read that

fathom pendant
#

plat monthly gives 1k cubes for $68
1k cubes outright is $100

shut creek
#

hmm same error after changing box

#

my laptop is vpned into htb

#

i rdesktop to the windows box spawned

#

in a new terminal on my laptop I run smbclient [flags]

hexed trout
#

hey, im doing the stack based buffer (linux) module and following the steps, but wehenever i try to run x/2000xb $esp+550 to check the stack the shell becomes completely unresponsive and i have to close the tab and start over, anyone know how i can fix this

fathom pendant
#

also you should be doing //ip/ not just ip

shut creek
fathom pendant
#

that won't really change much

#

try changing completely to EU instead and seeing if that makes a difference and spawns it properly

rustic sage
#

@fathom pendant hey it says permision denied, i wrote the password correctly

fathom pendant
rustic sage
rustic sage
fathom pendant
#

oh

shut creek
#

does TCP / UDP make a big difference for this for my vpn?

fathom pendant
#

you're in rdp

rustic sage
#

yeah

fathom pendant
#

xfreerdp has the /drive: option

#

btw the perspective of this section is from only shell access

#

rdp isn't necessary

rustic sage
fathom pendant
#

?? that's not right

#

lol

#

you should be able to ssh directly from the first go

rustic sage
#

i cant bother doing the things the section told abt

#

do i have to?

fathom pendant
#

i'd highly recommend doing it that way

#

as you shouldn't be on a windows host at all

#

the host should be a linux host

#

and you perform pth from what i recall

rustic sage
#

yeah

#

pth from linux

fathom pendant
#

the initial host should be a linux host

#

that you can ssh to

rustic sage
#

no its a win one

#

i should ssh into the win one

#

but instead i did rdp

#

man my brain is fked up

fathom pendant
rustic sage
#

yes

fathom pendant
#

you should be dropped into a ssh session that's a linux host

#

not windows

rustic sage
#

last question

fathom pendant
#

that's why things seem fucked up

rustic sage
#

hold on lemme try

fathom pendant
#

you should definitely be doing things as described in the module

#

don't do things outside of what's taught; get through the questions first and THEN fuck with things and try other stuff

rustic sage
#

oh

fathom pendant
#

RDP is not how you're initially meant to access this box

rustic sage
#

do i have to download proxychains...?

shut creek
#

I've regenerated this vpn connection 4 times accross the US and it's still not working. I'll try an EU server and if this doesn't work I think Imma move on lmao

fathom pendant
#

no

fathom pendant
rustic sage
#

i got all the questions right tho, only last one is remaining

fathom pendant
#

do things as described in the module. deviating means you're going out of scope, and it'll be harder to get help

fathom pendant
fathom pendant
#

besides, you'll need to specify the port with scp

#

since the box is running ssh on port 2222

#

not 22

rustic sage
#

ok let me try it one last time, then i do thr proxychain stuff

fathom pendant
#

for fucks sake

#

fine continue being stubborn

#

ya hmar

rustic sage
#

sry lol i'll download proxy chains

fathom pendant
#

you can ssh directly into the target

#

PROXY CHAINS ISN'T REQUIRED

rustic sage
#

wait look

fathom pendant
#

ssh user@ip -p 2222

rustic sage
rustic sage
fathom pendant
#

ya hmar just ssh into the 10.129 target

rustic sage
#

ok

fathom pendant
#

as the initial question tells you to do

#

also; wrap the user in singlequotes

rustic sage
#

ok

#

i'll try

heavy mango
fathom pendant
#

also specify port 2222

#

SINCE THAT'S THE PORT THAT SSH IS RUNNING

rustic sage
#

okok

fathom pendant
rustic sage
fathom pendant
#

literally in the first question

#

wdym "didn't work"

hexed trout
fathom pendant
#

you need to specify the port with -p

heavy mango
rustic sage
#

hold on it isnt pingable

hexed trout
rustic sage
#

vpn issues 1 sec

fathom pendant
heavy mango
fathom pendant
#

that's the full proper username

#

david@inlanefreight.htb is the username

rustic sage
#

im fking in finally

#

ty

#

now how to transfer linikatz? i have it copy pasted there

hexed trout
fathom pendant
#

I suggest you go back over the File Transfers module

#

as this is a very fundamental and basic skill

rustic sage
fathom pendant
#

apparenlty not since you're asking how

rustic sage
#

but can the linux hosts speak to my tun0?

storm elk
rustic sage
#

...

fathom pendant
#

...ya hmar because it has a tun ip

#

do ifconfig

#

and you'll see

rustic sage
#

ok 1 sec

fathom pendant
storm elk
#

I don't even know what those things are ๐Ÿ˜†

rustic sage
storm elk
#

its an insult according to google ๐Ÿ˜ฎ

rustic sage
#

it means you donkey xd

fathom pendant
#

i'm aware of it's connotation

storm elk
#

๐Ÿ˜ฎ ๐Ÿ˜ฎ

fathom pendant
#

i'm not saying it without knowing

rustic sage
#

k

fathom pendant
#

I rarely use words/phrases without knowing their meaning

rustic sage
#

yo i got linikatz inside of david

#

i mean his ssh session

fathom pendant
#

๐Ÿ‘

rustic sage
#

do i do the same for svc_workstations?

storm elk
#

are you following a specific path amar?

fathom pendant
#

you can just switch to svc/root and run it

rustic sage
storm elk
fathom pendant
#

you don't need to copy it to every user

rustic sage
fathom pendant
#

you have access to svc_workstation so you could easily have tested there

hexed trout
rustic sage
storm elk
rustic sage
heavy mango
hexed trout
heavy mango
rustic sage
#

same error

fathom pendant
# rustic sage

you know you can just sudo su you don't need to do sudo bash

#

also make sure it's executable

rustic sage
#

ye i chmod it

hexed trout
#

my other vms are 8 at max

fathom pendant
#

instead of switching to root

rustic sage
#

ok lemme sudo su

#

same err

#

/bin/bash^M: bad interpreter

fathom pendant
#

run it with sh

#

just do bash linkatz.sh

rustic sage
#

sudo sh?

fathom pendant
#

if you're root you don't need sudo

rustic sage
#

ok

#

i thought u wanted me to exit root

#

i think the bash is doing smth with those $

#

i'll try googling

#

yeah it worked

#

@fathom pendant i finally solved the question tysm

storm elk
#

great job amar

rustic sage
heavy mango
hexed trout
storm elk
#

I sometimes have these things too. Like I can't run mongodb on my mac, even when emulating to amd64 (and building a docker image for amd64)

maiden marten
#

Hello, for the question where you start the SSH in linux fundamentals module , it asks me to choose between 3 identities and require a password which i dont have ... am i missing something ?

maiden marten
#

we cant send screenshots here ?

split glade
split glade
maiden marten
#

doesnt work for me , i have to choose between mrb3n and cry0l1t3 where the usual pasword doesnt work

acoustic owl
split glade
# maiden marten

No this is to start the ssh service on your machine (or any server you want people to be able to ssh to). Here you're already connected to the box, so the ssh service is already up. You don't have to do those steps

maiden marten
#

i am confused why they ask us to do it this way knowing that everyone already connected to the SSH beforehand hence ruunning into this issue

severe cedar
#

Introduction to BASH Scripting -> Comparison operators. I'm 1 hour was trying to understand where I was wrong. But it appears that I needed to submit last 19 characters, and not 20 as was stated in question.

queen patio
#

heeeloooo

#

i am new

#

hi

#

hi

final garden
#

HII i will learn THe hacking pleas

gaunt knot
#

hi

#

im new too can someone help me ?

compact patrolBOT
acoustic owl
#

@final garden ^

acoustic owl
fathom pendant
hoary gull
#

Hello ! I had some questions regarding the reports part for the pts exam. In the documentation modules they gave us an example report where they show the walkthrough of how they managed to root one host by the help of finding information on some other host. But since we are going to have a network, we will probably hahve to root more than one host, do I have to detailed as much for every host that I managed to root ? Just to make sure, thank's in advance !

final garden
fathom pendant
#

it's telling you how you'd start the service on your own machine

fathom pendant
hoary gull
#

Oh it's because I'm afraid to write too much on the Assessment Overview and Recommendations part. In the module they advised us to write 1-2pages tops for this part and then detailed on the walkthrough part !

fathom pendant
#

worry about underwriting

#

i'd rather have too much than too little

#

submit the report and if you fail, you'll get feedback on it

hoary gull
#

okayy perfect, thank's for the advice !

fathom pendant
#

If you're a car person, think of it this way: You take your car into the shop for an inspection, the inspection says xyz is broken and abc is needed to fix it. Later you find out that they did find def but didn't tell you about it, and it becomes a serious issue

#

how upset would you be?

hoary gull
#

yeah you're right, better overwrite than miss something important :/

gaunt knot
fathom pendant
#

i'm sure you'll be fine :)

gaunt knot
#

anyone can help me im new

acoustic owl
fathom pendant
gaunt knot
acoustic owl
hoary gull
shut creek
#

weird the user/password for this module isn't working when I rdesktop to this machine

fathom pendant
#

and section?

#

is the instructions to RDP to the machine?

shut creek
#

and yeah, I'm supposed to RDP

#

oh this is all part of Active Directory

#

This is the 2nd thing I've had broken this morning :/

#

lemme try resetting my vpn

fathom pendant
#

which one

astral siren
#

hey

shut creek
#

also; redid my vpn and it's still broken

#

I'm using rdesktop from a kali laptop. idk if that interacts with a weird way to the box. It shouldn't.

astral siren
#

can i connect to the hackthebox's vpn ??

next bronze
#

and there are two parts, which one?

shut creek
#

I've tried both typing and copypasting

next bronze
#

you didn't answer my question

shut creek
#

part 1 sorry

next bronze
shut creek
#

the exact command I'm using is:
rdesktop -u htb-student_adm -p Academy_student_DA! 10.129.8.235

next bronze
#

use the xfreerdp command provided in the module

shut creek
#

rdesktop worked on the other windows module

next bronze
#

yes but you didn't tell me what error you're getting

shut creek
#

I'm trying to get it again and I can't even get the box to come up right now

maiden marten
#

for the question : Use the "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles managed internally by snapd" as the answer. i havee tried with different methods but i do not have all the details

shut creek
#

I just got an unable to connect error

next bronze
#

well are you connected to the vpn and is the ip correct

shut creek
#

yes

#

I'm resetting everything again

maiden marten
#

linux fundamentals - Service and Process Management

livid lotus
#

What does the acronym Linux PAM stand for?

fathom pendant
livid lotus
#

done

next bronze
maiden marten
#

oh thats weird i had to reconnect to the SSH. is it normal i have to do it several times per hour ?

next bronze
#

each section will probably have a target you'll need to spawn

shut creek
#

my windows rdp connection seems to be getting slower every time I try and connect to the box

shut creek
#

hmm my openvpn isn't working correctly

#

my IP isn't changing. I'm running the exact same command I was earlier

split glade
#

It reminds me of xmind

shut creek
#

hmm my vpn has stopped working completely

next bronze
#

change servers and download a new vpn file

fathom pendant
shut creek
fathom pendant
#

It'll set up its own interface [tun0 if not using other tunneling vpns] and assign an ip to that

shut creek
#

how do I check my vpn is working properly?

fathom pendant
#

Have you tried using the tcp instead of udp download?

fathom pendant
shut creek
#

checking

#

yeah

fathom pendant
#

Then it should be working, granted you don't have any other tun interfaces

shut creek
#

inactivity timeout

#

then attempts to reconnect

#

cool I'm atleast able to touch the windows vm now

#

getting "invalid username or password" again

#

hmm my vpn keeps having to reconnect

fathom pendant
#

Sounds like potentially it's a your internet issue

shut creek
#

that's kinda what I'm guessing

#

cox says it's fine but I don't trust them at all.

fathom pendant
#

You need a domain to append egg boi

fathom pendant
#

If you can ping Google.com do you get a variable ping?

shut creek
#

whats the ip for that?

#

isn't it 8.8.8.8?

opal nexus
#

Hello HTB-Academy team. Is there a change the Windows target machine you provided in Windows Privilege Escalation module is available for download? i try to get my own Windows 10 build 18363 (aka version 1909) iso but there isnt any on the Internet. I need it for a University project.

shut creek
fathom pendant
#

Within 20 is normal

#

Greater than that = isp shenanigans potentially

#

I also suggest resetting your router as well

shut creek
#

yeah I got a 40 spike

#

actually that's 50, math hard

maiden marten
#

in Linux fundamentals - Task scheduling , the first question doesnt even work ...

random wyvern
#

Windows Event Logs & Finding Evil need help with this please i don't know if I should use my system or there vpn and there's no good walkthrough on how to setup I'm kind of lost.prayge

acoustic owl
maiden marten
split glade
# maiden marten

You really need to differentiate the commands they show you and what you need to do for the exercise, it's not just copy pasting and it's true for all HTB modules.
I think you might want to first focus on understanding the whole chapter without trying the commands, and then try the exercise.

maiden marten
#

its not an exercice , its the first step of the chapter

split glade
#

And in this particular example, I think you can try this part on the pwn box (cf #modules message )

maiden marten
fathom pendant
#

This is an example of how you'd do the thing

#

Sometimes examples are just that

maiden marten
#

whats the point expect driving people nuts and make them rethink their life choices

fathom pendant
#

I suggest reading the whole section instead

acoustic owl
fathom pendant
maiden marten
#

because that means by having the "htb-student is not in the sudoers file." error, i technicaally do not know how to create a timer. why not giving us example we can try throught the Pwn Box and then play around to learn

fathom pendant
maiden marten
#

and i bet the question at the end expect you to perfectly master everything that was "teached" before

#

i did it on the pwnbox and i got that error

fathom pendant
#

I suggest taking a break

#

?

split glade
fathom pendant
#

Btw the creds for pwnbox are on the desktop if needed but I believe they have it so sudo doesn't ask for it

split glade
fathom pendant
#

Open a new terminal

#

Also you can click the full-screen button to open a new tab in full-screen mode

#

Instead of that small windows

maiden marten
fathom pendant
maiden marten
#

it was just to prove i was in the instance

fathom pendant
dapper moth
maiden marten
fathom pendant
#

You're running the command in the ssh session, for which the htb-student account does-- in-fact not have sudo access

maiden marten
#

ahhh

fathom pendant
#

Open a NEW TERMINAL such that it says htb-ac[nnnn]

dapper moth
#

Spent 8-10 hours yesterday to be able to scan a target from a Windows stand alone port scanner

maiden marten
fathom pendant
#

Ssh is generally only to answer the questions

maiden marten
maiden marten
dapper moth
#

Got a couple of boxes hanged using the Pwnbox due to not having disk space after getting the necessary compilation libraries as well

split glade
# maiden marten

Use ifconfig and look carefully at the tun0 part.
If you see the target IP, that means you're through a SSH session (same as next to Target(s):)
If you see an other IP, that means you're on the pwn box (at least in that case you have only 2 options)

maiden marten
#

so to create a timer you need "admin" acess i suppose and by being connected throught SSH you are just a normal user that cannot use any sudo command ?

fathom pendant
#

Sometimes the user you ssh to does have root access to the system

#

root is for Linux devices

#

It's a built-in account, like Administrators for Windows

maiden marten
#

okay makes sens

#

i can now untie the rope

#

thanks !

fathom pendant
#

just all depends on the actual question of the section ยฏ_(ใƒ„)_/ยฏ

#

Sometimes they're nice and you'll know directly (htb-student_adm)

#

Or you can figure it out through context

maiden marten
#

the only time they were nice was during the "how to learn" module

#

๐Ÿฅฒ

fathom pendant
#

Making informed assumptions is what this field is about

split glade
#

Even if it's tempting, it's best to first try to understand the whole chapter and only then try to reproduce the commands, otherwise are you really understanding what you're doing?

maiden marten
#

i get that but that would be great to be tested in this way after knowing the "basics " and not already being tortured . i might struggle to understand their wy of teaching but sometimes it feels like they barely cover some subjects and then they test you ike youve been studying that part for 2 months

#

i will probably go over old chapters and try to find more info throught forums and ChatGPT later on

fathom pendant
#

Tbh just read the whole chapter first

#

You don't need to replicate every command shown

#

Just the ones relevant for the section you're on

#

Or be given enough info to google your way through it

maiden marten
#

okay that could be a way

fathom pendant
#

90% of this field is just going to google

fathom pendant
maiden marten
#

okay so i suppose i shouldnt feel ashasmed asking chatGPT to breadown a whole line of command and explain every aspect

fathom pendant
#

Nope

#

Though chatGPT can be confidently incorrect at times

#

Also

#

TAKE NOTES

maiden marten
#

yeah i always double check

fathom pendant
#

always.

split glade
maiden marten
#

do you recommand pen and paper or like Notion ?

fathom pendant
#

But whatever way works for you

maiden marten
split glade
#

I use obsidian too since a few years (and love it) but yes it's a personal choice

maiden marten
#

it looks great !

digital crown
#

is everything okay with academy labs?

uncut ocean
#

Hey guys i want to ask a samll question regarding HTB CPTS Pass the Hash (PtH) Here in this question Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account? i am facing problem i dont understand why i already enable Restricted Admin Mode , but i cant get rdp

fathom pendant
#

That module isn't exclusive to the cpts path

fathom pendant
#

Try adding /timeout:60000 as the error you're getting is a timeout error

hidden steppe
#

Windows event logs and finding evil Module:

I haven't done a module in the skills path yet that has taught me how to rdp...
I've tried amending this in a few ways inside powershell, which they provide just above the pwnbox, but haven't managed to get it right:

"An0ther1bytesDDoS@htb[/htb]$ xfreerdp /u:Administrator /p:'HTB_@cad3my_lab_W1n10_r00t!@0' /v:[Target IP] /dynamic-resolution"

Filled in the target IP
Tried getting rid of eveyrhing before xfreerdp

uncut ocean
fathom pendant
#

Just the xfreerdp and after part

fathom pendant
split glade
#

@fathom pendant
Do you use some kind of check list, for example for Windows Privilege escalation (I'm talking in general, not a particular module)?
Like a bullet point list of each privilege escalation vector that you copy paste (the whole list), and then you verify each point one by one, marking them as verified once a point is

uncut ocean
fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

hidden steppe
#

well I had tried that, but for some reason it worked this time, so thanks haha, sometimes it takes that magic touch

split glade
#

OK, I think I'll create check lists, at least a windows privesc one and an AD one before trying the CPTS

last bolt
#

Guys, anyone still remember the module "Server-side Attacks", section "Exploiting SSRF"?
It's the one that teaches about gopher, gopherus.
I can't get the flag. My enumeration shows that the server has service running on 3306 which is MySQL.
But no matter how I put the gopher link, I'll get 500 internal server error.

acoustic owl
fathom pendant
#

Make sure the date is right

last bolt
nova ginkgo
#

Hello, can anyone help me pls Password Attacks Lab
I found Johanna password then I tried to connect with rdesktop and xfreerdp but not worked why rdesktop said wrong password or username

last bolt
hidden steppe
#

windows event viewer and finding evil module:

In windows event module, when trying to set up a filter, where ON EARTH is the okay button?
How do I apply the filter?
All I see is the clear button

hidden steppe
#

Pretty please

#

I see... it is below the clear button...
It's just that the only way you can see that in the pwnbox is by hiding the taskbar

shut vapor
last bolt
shut vapor
#

Or by lab maybe you mean one of the final assessments?

hidden steppe
fathom pendant
#

You can just close, hit the up arrow key, and add /dynamic-resolution to the end

hidden steppe
#

I think I did, but it just opened the desktop normally, so I found event viewer in the searchbar instead

fathom pendant
#

Don't need the ip in brackets btw

hidden steppe
#

thank you

fathom pendant
#

Then resize the screen

#

It should redraw the screen to the appropriate resolution

hidden steppe
#

ahh you mean click the fullscreen button below the pwnbox? ahh of course

#

yeah i can see it now haha

#

thank you

fathom pendant
#

Well yeah... that too

#

Lol working in a tiny window with rdp is a pain

hidden steppe
#

Thank god for fullscreen mode

fathom pendant
#

There's no workaround for it

sonic plume
#

i've a question about the module command injections;
in this question: Try all other injection operators to see if any of them is not blacklisted. Which of (new-line, &, |) is not blacklisted by the web application?
so when i test with burpsuite for injection operaters || & || is the only one that sends the pings and doesnt give me an "invalid input" error. But why is the || new-line (\n) || the right answer even tho it is blacklisted because it gives me an "invalid input" error?

#

my brain isnt braining anymore

hidden steppe
#

yeah that has happened to me once or twice, it is a little annoying, but nowhere near as bad as when you can't find the bug in your code ๐Ÿ˜‚

split glade
sonic plume
#

burp suite (pro), ill reset the machine hope it fixes somehow

#

nope it just the same... thats pretty weird

split glade
sonic plume
#

yea thats what im doing, so it doesnt trigger || the command blacklist ||

#

but it doesnt work either

#

ah url encoding does work, but still are confused why || & || is wrong even tho it gives me the pings

quick badger
#

anyone having issues with Targets Spawning? been waiting for over an hour for targets to spawn in Password Attacks > Attacking SAM

split glade
split glade
quick badger
sonic plume
hidden steppe
#

Windows event viewer & finding evil module, Windows event logs:

Task 1

I am struggling to apply the investigation examples in this section to task 1, in order to get the Answer.

I sucessfully found the log they asked about, and I then followed the investigation example, I came to the conclusion the answer is Services.exe as that is the ProcessName AND the ONLY .exe I can see anywhere in the log information.

This did not work,
I tried applying the rest of the investigation to it, which is taking the LogonId and finding other logs containing this, to find when this all started, so as the page shows I created this XML query containing the logonId of the target log: <Select Path="Security">[EventData[Data[@Name='SubjectLogonId']='***']]</Select>

Now I have a whoooole load of logs, and I'm just not sure which to look at

fathom pendant
#

Then it just depends what you're tasked to actually look for

#

What is the question asking for?

hidden steppe
#

Analyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25. Conduct a similar investigation as outlined in this section and provide the name of the executable responsible for the modification of the auditing settings as your answer.

#

So I have to find the log which modified the auditing settings, which also has the logonId of 0x3E7?

fathom pendant
fathom pendant
#

That will narrow down a lot

#

Windows logs everything that's done

hidden steppe
#

Thank you, I may need to do some external research on how to add that to my XML query, as I'm locked into the XML type of querying with this ** search

fathom pendant
zealous rune
#

Hi I'm really struggling with the icmp tunneling section in pivot module.

limpid hemlock
#

Hey i have a simple doubt in the web proxies section i have to decode an encoded data to submit the answer i decoded it from base64 2 times and still have encrypted stata the hint says to url encide is also needed i cant seem to figure it out

fathom pendant
#

Also things can be encoded multiple times

zealous rune
#

Specifically the mismatch in glibc between my system and target

fathom pendant
#

Otherwise you'll need to build it with the specific glibc on the target

limpid hemlock
#

I tried multiple times decoding with url not working

zealous rune
#

I've tried to install a version of glibc that matches the target

hidden steppe
fathom pendant
#

Then you look back at how relatively simple it was

limpid hemlock
#

Encodeing decoding in the webproxies module

hidden steppe
fathom pendant
#

When it's fully decoded you'll get HTB{..} flag

limpid hemlock
#

Got it

fathom pendant
#

You'll know when it's time to URL decode

limpid hemlock
#

๐Ÿ˜…

fathom pendant
#

It's very obvious

fathom pendant
limpid hemlock
#

I thought when the == was gone base64 encryption was over so i stoped decrypting it with base 64 and tries to url encode

#

I had to do base64 decrypt one more time befor url encodinh

fathom pendant
limpid hemlock
#

Ohhk

vital lance
#

Can someone tell me what I'm doing wrong?
The ip address I created the payload is 172.16.1.5

fathom pendant
#

So you can have a b64 string that doesn't have = or ==

fathom pendant
limpid hemlock
#

Which section is this the skills assesment in Ad section

fathom pendant
#

Are you doing it from cmd?

vital lance
limpid hemlock
#

Ptt which section

fathom pendant
vital lance
#

172.16.1.5 as i said

fathom pendant
fathom pendant
#

Run it in cmd, not powershell

#

As the module states

#

Trust

vital lance
#

you mean I have to use cmd and using powershell inside cmd ?

fathom pendant
#

Yes

#

Read the text just above where it gives you that command

#

And even the command example is in cmd, not powershell

hidden steppe
#

I have looked at the link provided in the unit to help with XMLqueries, that's one of the screenshots

minor dome
#

Working on Windows fundementals - Windows Security and it wants me to find the SID of user: bob.smith but the connection name it gives is the normal 'htb-student' and when i connect to it it only has one user which isnt bob.smith. any hints?

fathom pendant
#

Likely wrong eid

fathom pendant
vital lance
#

yes sure xd

fathom pendant
#

?

#

So that's a yes that you have nc.exe running on the port you specified in the revshell?

split glade
fathom pendant
vital lance
#

Nothing is wrong with the port and IP, could I be doing something else wrong?

fathom pendant
#

The reading calls out a specific id

hidden steppe
#

yes **

fathom pendant
fathom pendant
minor dome
fathom pendant
minor dome
split glade
fathom pendant
#

Get-WMIObject will be helpful

minor dome
fathom pendant
fathom pendant
#

Or Bob isn't an ad user

#
minor dome
fathom pendant
minor dome
#

thank you ill look into these

hidden steppe
#

I'll try reading the XML resource a bit more

dim wolf
#

check your SubjectLogonId again..

hidden steppe
#

oh awesome, thank you

fathom pendant
#

The funnier part of this screenshot is you manually retyped the query

#

Instead of copy/paste

hidden steppe
#

@fathom pendant and @dim wolf I got the answer, thank you so much

hidden steppe
fathom pendant
#

You had it right in the ss with the wrong event

#

Since it's a t2 mini module the screenshots have to go

#

As spoilers

hidden steppe
#

fair enough

fathom pendant
#

Since most of that query structure is in that section

hidden steppe
#

yeah true

#

Have you got any advice so I can prepare for instances dying?
It is all I can do to watch the clock, and click extend life?

fathom pendant
#

Yup

#

Tbf most instances shouldn't die before you crack it

hidden steppe
#

Hahaha

#

I'll take the flak haha

civic hamlet
#

@fathom pendant are you online?

fathom pendant
#

But you can extend a target life to like a max of 6 hours

#

And if you really can't crack it @ 6 hours, go be a farmer

civic hamlet
#

Iโ€™ve also tried to use double black slashes, (even if the single quotations should deal with that), but I seem to get the same error

fathom pendant
civic hamlet
#

Iโ€™ll try that again I suppose

fathom pendant
#

Also try double quotes instead

dim wolf
#

or try //ip/'Company Data'

hidden steppe
#

Windows event viewer & finding evil, windows event logs:

Task 2

Judging by the structure of the 'details' section when reading a log, I'm not sure why EventData is followed by Data and @name... but as it worked for the last thing I queried that is within event data, I tried this:

fathom pendant
#

With different names

#

<Data Name="thing"> data_related_to_thing </data>

hidden steppe
#

ahh, and I'm not even searching for the culprit excecutable, need to change that too

maiden marten
#

Hello it is me again ๐Ÿ™‚ in Task scheduling, What is the Type of the service of the "dconf.service"?, i tried with different methods such as systemclt list-units --type=service | grep dconf or like systemctl show dconf.service but it is not there.. i even did a sudo apt-get install but still nothing ...

fathom pendant
#

Or if you view the xml of the event in event viewer you'll see it

fathom pendant
tender nimbus
#

Hey guys, any idea which packets i need to download? I can't find the right one

fathom pendant
#

sudo apt install python3-impacket in case impacket isn't installed

tender nimbus
#

did it but same reslut @fathom pendant

fathom pendant
#

sudo apt install smbclient

#

Also might be under core-utils

tender nimbus
fathom pendant
#

Add -t lory-backports

hidden steppe
fathom pendant
#

You do

civic hamlet
tender nimbus
fathom pendant
tender nimbus
fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

tender nimbus
dim wolf
tender nimbus
dim wolf
#

was demonstrating what worked and what didn't

tender nimbus
#

oh srry

ebon rivet
#

Hey all, not a VIP, but everything says offline. Did something change?

civic hamlet
#

where did you get the idea to put quotation marks only around company data is what im curious about

fathom pendant
fathom pendant
dim wolf
#

it just happens to work with smbclient and most other tools

ebon rivet
#

what I thought, been over a year since I have logged in and all say offline

fathom pendant
#

Offline = not connected/running

#

Nothing wrong with the site

zealous rune
#

I tried compiling the glibc lib that's on target on my machine

#

My make failed with errors I couldn't debug

fathom pendant
zealous rune
#

I did download the glibc source

#

And tried to compile glibc

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

zealous rune
#

Then I eas hoping to link the glibc lib in compile for prinnel

#

Ptunnel

fathom pendant
#

Biggest suggestion though is just use a precompiled version

zealous rune
#

But failed at compiling glibc

fathom pendant
#

Way less headache

zealous rune
fathom pendant
#

On the ptunnel github should be a releases page

zealous rune
#

Perfect I'll take a look

#

Suppose I need the version that was compiled with the "correct" glibc version

#

Need to finish off pivot so I can get into AD module

#

Btw is it a bit strange there's no mention of ligolo-ng?

fathom pendant
#

Ligolo came out after this module was written

zealous rune
#

Ok

fathom pendant
#

Technically it's not even at 1.x yet

zealous rune
#

But still some useful knowledge

#

I mean the pong and dns tunnels is good knowledge for evasion

fathom pendant
#

Not really, most will still get caught

civic hamlet
#

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$ smbclient -N \\\\10.129.91.158\\'CompanyData'
session setup failed: NT_STATUS_ACCESS_DENIED
#

ive tried every single variation reccomended to me here, maybe its the share permissions on the Company data share?

#

this is getting a tad annoying

civic hamlet
#

ive tried without -N

#

i shouldve clarified sorry

fathom pendant
#

Calc had -N because he set up an example on his system

fathom pendant
civic hamlet
#

yeah, the target password

gilded glacier
#

Hi! I probably have a fairly basic problem with connecting to the machines described in the course content (https://academy.hackthebox.com/module/77/section/726).

Following the instructions, I downloaded the VPN connection configuration and successfully set up the tunnel:

2024-08-02 15:07:10 Preserving previous TUN/TAP instance: tun0
2024-08-02 15:07:10 Initialization Sequence Completed
2024-08-02 15:07:10 Data Channel: cipher 'AES-256-CBC', auth 'SHA256', peer-id: 68, compression: 'lzo'

โ””โ”€$ ifconfig tun0
tun0: flags=4305<UP,POINTOPOINT,RUNNING,NOARP,MULTICAST> mtu 1500
inet 10.10.15.98 netmask 255.255.254.0 destination 10.10.15.98
inet6 fe80::1890:ddab:310f:d3c4 prefixlen 64 scopeid 0x20<link>
inet6 dead:beef:2::1160 prefixlen 64 scopeid 0x0<global>
unspec 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00 txqueuelen 500 (UNSPEC)
RX packets 9 bytes 792 (792.0 B)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 22 bytes 1236 (1.2 KiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$ netstat -rn
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
0.0.0.0 172.16.169.2 0.0.0.0 UG 0 0 0 eth0
10.10.10.0 10.10.14.1 255.255.254.0 UG 0 0 0 tun0
10.10.14.0 0.0.0.0 255.255.254.0 U 0 0 0 tun0
10.129.0.0 10.10.14.1 255.255.0.0 UG 0 0 0 tun0
172.16.169.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0

The problem, however, is that when I try to connect to any service, I get the "no route to host" message:

โ””โ”€$ nc -nv 10.129.42.253 21

(UNKNOWN) [10.129.42.253] 21 (ftp) : No route to host

Exactly the same thing happens when I try to connect via pwnbox (same message).

I've already changed the server location (eu, us, etc) but it makes no difference.

Please help.

fathom pendant
#

Also you'd want to connect with ftp

#

Ah I see your issue

fathom pendant
#

You're trying to connect to the example

gilded glacier
#

How stupid I am... Thank you!

civic hamlet
lime quest
#

guys can someone help me with this david question I'm trying to access the dc but it says david does not have access to it the question is Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.

#

PS C:\tools\Invoke-TheHash> Invoke-WMIExec -Target DC01 -Domain inlanefreight.htb -Username david -Hash c39f2beb3d2ec06a62cb887fb391dee0
[-] inlanefreight.htb\david WMI access denied on DC01
PS C:\tools\Invoke-TheHash> Invoke-SMBExec -Target DC01 -Domain inlanefreight.htb -Username david -Hash c39f2beb3d2ec06a62cb887fb391dee0
[-] inlanefreight.htb\david does not have Service Control Manager write privilege on DC01

#

this is what I got when I tried

rustic sage
#

@lime quest try dc01 instead of DC01

#

also idk which question u r on but the first command(the lengthy base64 one) is actually the right way for one of the questions, u just need an other console i think for the nc listener

violet talon
#

Remember, you can do it

maiden marten
#

for the Fawn case, i need to get the FTP file but i get this and it is stuck in a loop

rustic sage
#

Hello all

I am working on pass the hash - password attacks modules but I cannot access the rdp, it says password incorrect

verbal dagger
#

hey, i'm on the pivoting tunneling and port forwarding module. i'm on rdp and socks right now. i managed to get the dll on windows but the real time defender blocked it. i restored the file, and everything is fine. my question is, if we are on an engagement, would we need to reach out to the client to let them know we are changing software configs like firewalls or antivirus before we do it?

gilded radish
civic hamlet
#

What could potentially block us from accessing this share if all our entries are correct and our permissions list has the Everyone group present with at least Read permissions?

Why am I so stupid? why couldnt i literally read 2 words down after encountering my issue?

#

@fathom pendant could it have been this

#

This is comedic... I was intended to not be able to access the share

hidden steppe
#

Windows event viewer & finding evil, windows event logs:

My event viewer IS filtering for the former query tags, but not the latter, however no error comes up when I click ok on the xml query to apply it:

#

I'm just trying to figure out how I can get the filter to check for both at the same time.
The former checks for this .exe being the cause of the log, and the latter checks for if this .dll is affected by the log

#

or is supposed to, anyway

#

I am supposed to filter for both of these at the same time to have a chance of finding the correct log

manic quiver
#

Hello

dapper moth
civic hamlet
#

@dim wolf in my near infinite foolishness Ive discovered another error

#

I was trying to connect to the Company Data share assuming it was an actual share, and not the share that the module section created as a demonstration

I also hadnt known that the inbound firewall had to be configured anyways

edgy gale
#

hello everyone, i hope you all are well.

Module :
CRACKING PASSWORDS WITH HASHCAT
Page 10
Working with Rules

Question:
Crack the following SHA1 hash using the techniques taught for generating a custom rule: 46244749d1e8fb99c37ad4f14fccb601ed4ae283. Modify the example rule in the beginning of the section to append 2020 to the end of each password attempt.

Command that i have use :

hashcat -a 0 -m 100 46244749d1e8fb99c37ad4f14fccb601ed4ae283 /usr/share/wordlists/rockyou.txt -r '/home/raza/Desktop/rule.txt'

Content in rule.txt:

$2 $0 $2 $0
#

but i am not getting any result.

cloud urchin
#

it would greatly help if you said what module/section you're on, otherwise no one can really answer your question other than maybe the password isn't in rockyou

edgy gale
shut wraith
#

Hey guys I had a question. There is a session stealing module in the CBBH. However, it makes the user himself act like the target and makes the user request the malicious page. It also automates the target accessing a malicious page.

Is there going to be an automated target that accesses a malicious page that you send to it in the CBBH exam?

dim wolf
#

no one can answer that question

#

that would require divulging exam information

edgy gale
dim wolf
#

don't have my notes rn so no

edgy gale
small atlas
#

Can someone point me in the right direction to find the API key in the admin directory. I am in Information gathering - web edition skill assessment. I have answered all other questions and am still brute forcing sub domains and curling. Thanks in advance!

tranquil crystal
brave scroll
#

hello everyone

quiet trout
#

anyone having failed target instance spawns? i had one take the better part of an hour before it finally timed out

#

seems to be working now, albeit a little slow

inner moss
#

Hello, I was wondering if someone could help me, I'm currently taking Intro to Assembly Language Module, in the Shellcoding tools section, there is this excercise: "The above server simulates an exploitable server you can execute shellcodes on. Use one of the tools to generate a shellcode that prints the content of '/flag.txt', then connect to the sever with "nc SERVER_IP PORT" to send the shellcode. " I'm currently trying to execute the shellcode but I get no output. I'm not sure what I am doing wrong.

next bronze
brave scroll
#

plz someone help me

quiet trout
#

pwnbox cant ping target, but web dashboard is showing target as spawned with ip address... just reset the target and obtained a new ip and same issue... an hour or two ago the target instance load-looped for 45+ minutes before finally failing out... should this be reported?

inner moss
#

Its not printing anything

#

I created the shellcode out of this command: msfvenom -p linux/x64/exec CMD=โ€˜cat/flag.txtโ€™ -a x64 --platform linux -e x64/xor -f hex

next bronze
#

you can test it in your own system

#

just make a /flag.txt

quiet trout
#

have you tried to tee your cmd and redirect to file so you can inspect the output? do you know what the rule is actually showing? its certainly doing something

brave scroll
#

i conme to know now

inner moss
#

Do I create a flag.txt which prints whatever?

quiet trout
#

try @next bronze suggestion

brave scroll
#

HTB rule: "Think out of Box"

#

and i got it
Thanks HTB

quiet trout
quiet trout
#

not sure if there needs to be, but in typical command entry you put a space (as you prob already know)

inner moss
#

msfvenom -p linux/x64/exec CMD=โ€˜cat /flag.txtโ€™ -a x64 --platform linux -e x64/xor -f hex

#

like this?

quiet trout
#

yes

#

well...

#

use the full path, cat /root/flag.txt or cat /home/user/flag.txt type deal if its in cwd then use cat ./flag.txt

inner moss
#

alright alright, I'm going to try

quiet trout
#

can everyone ping their target box? im still having problems spawning, connecting and pinging to target instances

#

im not sure if this is supposed to be this way (hardening) or what but ive never had an academy module target box that wouldnt ping

inner moss
#

yeah I can ping

quiet trout
#

thx

next bronze
quiet trout
quiet trout
#

looks like this may be a me issue, a super long nmap just returned 2 ports open... no port 139 or 445 whcih would explain why i cant connect with smbclient maybe im not supposed to actually follow this part along but just read instead?

#

let me try to do something from the actual question/answer section

next bronze
#

yeah that doesn't repond to ping, just rdp in

quiet trout
#

hmm last question sorta suggests that you should be on an smb share to correctly answer the question (ie: its not theoretical) but i dunno?

#

oh goodness ive got the cart before the horse here... i prob cant connect to smb share cause i need to rdp in and create a shared folder first... >_< (sorry ive been at this for a few hours with interruptions)

#

this might be false alarm

#

@next bronze just rdp'd in created the dir and shared it but still cant connect via smb client as outlined in the guide, 139 and 445 port showing filtered with -sSV scan, -sV scan and a --script smb-vuln* scan (respectively or combinations thereof) not sure where im going wrong here

#

wait... firewall

next bronze
#

there is a part about firewall in the section

#

yes

quiet trout
#

didnt realize this was setup in this manner i thought it was supposed to be just open, as its an easy module

next bronze
quiet trout
#

yeah, i wish they would've outlined the specific fire wall rules to enable... i tried doing the ones i know about in the gui (file and printer sharing, file/printer sharing smb) couldnt get it to work until i disabled the whole firewall >_<

hidden steppe
# dapper moth AND Youโ€™re making 2 queriesโ€ฆ try making one query with both conditionals

Yes I tried that initially, then as it ignored the second one I tried using the and operator, then I assumed perhaps you cant request two things in event data within the same query... judging by how this query is inside <query list> tags it made sense to assume you can list multiple query tags so I tried that, I even tried an and operator between the two query tags. I even used an AI to see if one queries syntax is different from the other (which it shouldn't be because it is nested in exactly the same fashion).
Tried looking up xml querying on YouTube and couldn't find a thing in depth enough.
The link within that unit of the module didn't detail the syntax for this either.

I ended up just totally guessing, and decided to switch the queries' order.
This worked by luck because there are only two logs that contain the desired .dll as an affected file.
Maybe I am just being dumb, but I'll mention it to the course content guys, because maybe I am not ๐Ÿ˜‚

upper imp
#

hi

pine dune
#

Hey guys, is there gonna be a 1 year student plan in htb academy by any chance in the near future?

dim wolf
#

highly doubt there will be a Student Annual sub. the Student sub is already extremely good as it is now

pine dune
#

oh well

analog ferry
#

because i still have 2 more years of this shit hole

night crypt
#

they really could've picked a shorter flag for the SQLMap "flag5" question* this is taking FOREVER ๐Ÿ˜…

#

(connecting from Australia means a big ol' delay is needed on the time to get a real result)

ember fern
night crypt
#

I'm scared of next paging & the machine dying on me

#

ahaha guessed the last 8 characters to save a little time

serene trout
#

Hey guys Iโ€™m about to finish Linux fundamentals.. Iโ€™m still way off grasping the fundamentals. Do you think I should go through it again before moving on

acoustic owl
pine dune
pine dune
analog ferry
analog ferry
arctic sentinel
#

Hello everyone, good morninr!

#

I am stuck in the Attacking Thick Client applications... Someone has recently done this section_!

pine dune
fathom pendant
#

Idk what this has to do with academy

mint peak
#

Oh wrong chat lmao

#

whoops

#

Make sure to go through all chat above and let em know

#

Chats gotta stay โœจ sterile โœจ

rustic sage
#

Module: Footprinting
Section: OracleTNS

Problem: Cannot find the login with odat.py, i specified my IP address

#

command i issued: ./odat.py all -s 10.129.205.19

#

@fathom pendant possible to get some support maybe?

autumn pilot
#

are you connected to the VPN

rustic sage
#

Yeah

#

maybe the protocol wasnt properly selected holdon

#

Okay yeah that makes sense im using the wrong protocol

#

will redo again

digital crown
#

i had some real troubles with parsing ssh private key on one of the modules, and it turned out to be tmux issue, is there someone i could discuss it with?

rustic sage
#

also does the exam tell you where you went wrong, and what you need to improve on for a better success rate on your second attempt?

#

Or does it say nope, here are ur results.

#

WHOOHOO!! it's working ๐Ÿ˜„

arctic sentinel
#

Some that has done recently the Attacking Thick Applications module, I am in the last step but I have been stuck for a while

fathom pendant
rustic sage
fathom pendant
#

Yep

rustic sage
# fathom pendant Yep

well that's okay hopefully when i do it, i get a nice feedback, what's the amount of marks needed to pass it?

fathom pendant
#

?

#

There's no x/y grading for the report

#

You either pass or fail

#

Other than that 12/14 flags are required

#

But you can absolutely fail on the report

#

Flags are only half of the exam

rustic sage
rustic sage
# fathom pendant ?

so let's say u try to obtain 12 flags right, even if ur report sucks you will fail still?

fathom pendant
#

The report is literally the other portion of the exam

rustic sage
#

u still fail? so it's a must to get 12 atleast

fathom pendant
#

Correct

rustic sage
#

damn that is quite challenging

fathom pendant
#

But I wouldn't worry about the report until you get the flags

rustic sage
#

but isnt the report like how u got the flag and what the problem was and how to secure the issue?

fathom pendant
rustic sage
#

oohh

fathom pendant
#

Also it's not how you got the flag

#

It's reporting on what's vulnerable

#

And risks, severity, impact

rustic sage
#

OHH so u got to give in the risk, severity, impact and what the vulnerability is in depth

#

in order for you to do well?

fathom pendant
#

Again

sterile solstice
#

its what a company will expect when they pay a company lots of money for a pentest

fathom pendant
#

The documentation and reporting module goes over it

rustic sage
fathom pendant
#

And it's required in the path

sterile solstice
#

well thats where it is. right before Attacking Enterprise Networks

fathom pendant
#

Since you should do a practice report on the enterprise network module

rustic sage
fathom pendant
#

You should be doing it in order

rustic sage
#

fudge, i done it randomly in diff orders didnt even think order mattered

sterile solstice
#

you can learn whatever you want, where/when you want. but the path is the recommended path.

fathom pendant
#

The path is laid out that way for a reason

#

Pivoting before AD, footprinting before attacking

rustic sage
fathom pendant
#

You don't need to "start over"

#

Just finish the path in order

rustic sage
#

okok

fathom pendant
#

And I can guarantee some modules you skipped over would have made modules you struggled on a lot simpler

rustic sage
#

ah u right, that's my bad i didnt even know i just thought they would cover what to do for each thing without involving anything else

fathom pendant
rustic sage
#

some of the modules i went to do i had no problems doing them at all even when i went in different orders

fathom pendant
#

It's why the information Security Foundations path is a prerequisite

sterile solstice
rustic sage
#

like the metasploit one i understood properly to do without going to any previous modules

fathom pendant
#

Well yes

#

Because that is dealing with specifically metasploit

#

Without needing much other knowledge

rustic sage
#

and ffuf

fathom pendant
#

Again

#

Tool specific

rustic sage
#

ur right

fathom pendant
#

So not requiring much brain power

rustic sage
#

fax, anyways yeah i will be back if im struggling with anything

fathom pendant
#

Tip: don't rush for answers

#

Exhaust all available options before going and asking for a nudge

woven aurora
#

Hey guys.

#

I am having a problems with the pwnbox instance a lot of the questions in the linux fundamentals are not accurate can anyone help me with the issue?

fathom pendant
#

Most questions require you to ssh to a target

rustic sage
#

in the pass attacks module hard skill assessment, how do i crack the .vhd bitlocker password? i tried bitlocker2john then john but its taking forever

zinc talon
#

I need help with the very easy sherlock called noxious

#

Task 8 is not working and i hve done everything right

fathom pendant
fathom pendant
#

This channel is for academy modules, not main site content

zinc talon
#

I am not seeing a follow button

civic hamlet
#

@fathom pendant ive tried to allow all inbound traffic on ports 445 and 139, and Im still not able to send my smb request for the share I created. any hints?

fathom pendant
rustic sage
fathom pendant
rustic sage
#

ok

wooden trail
#

Hi guys, I'm struggling with the "ACL Abuse Tactics" question, inside the Active Directory Enumeration & Attacks module.

I'm running the following commands:

$SecPassword = ConvertTo-SecureString 'Pwn3d_by_ACLs!' -AsPlainText -Force
$Cred2 = New-Object System.Management.Automation.PSCredential('INLANEFREIGHT\damundsen', $SecPassword) 
SharpView.exe Set-DomainObject -Credential $Cred2 -Identity adunn -SET @{serviceprincipalname='notahacker/LEGIT'} -Verbose

The thing is that I'm getting this error:

[Get-Domain] Using alternate credentials for Get-Domain
[Get-Domain] Extracted domain '$TargetDomain' from -Credential
An error occurred: 'System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.ArgumentException: The specified string parameter is empty.
Parameter name: name
   at System.DirectoryServices.ActiveDirectory.DirectoryContext..ctor(DirectoryContextType contextType, String name, String username, String password)
   at SharpView.PowerView.Get_Domain(Args_Get_Domain args)
   at SharpView.PowerView.Get_DomainSearcher(Args_Get_DomainSearcher args)
   at SharpView.PowerView.Get_DomainObject(Args_Get_DomainObject args)
   at SharpView.PowerView.Set_DomainObject(Args_Set_DomainObject args)
   --- End of inner exception stack trace ---
   at System.RuntimeMethodHandle.InvokeMethod(Object target, Object[] arguments, Signature sig, Boolean constructor)
   at System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(Object obj, Object[] parameters, Object[] arguments)
   at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
   at SharpView.Program.Run(String[] args)
   at SharpView.Program.Main(String[] args)'
#

any idea?

rustic sage
#

its cracking now but wont that take much more time?

rustic sage
#

just to make sure im in the right track.. i found a .vhd file and then bitlocker2john'd it, and thats what im trying to crack

sullen bone
#

Hi! Did anyone finish the skill assessment for the NTLM Relay attacks module? I just got the last flag, but it suggests a different attack path than the one I took. Anyone available for a sanity check?

jovial sable
sullen bone
rustic sage
next bronze
next bronze
sullen bone
rustic sage
#

Hello.....I ran into a small problem here. I am trying to use python http server and then use it to fetch the file into the remote machine. Btw, I am solving privesc assessment from getting started module from cpts.

wooden trail
#

I mean, I import it but cannot run the methods needed

#

they show as non existing methods

fathom pendant
#

You can do scp linpeas.sh user1@ip:~/linpeas.sh -P port

next bronze
fathom pendant
dapper moth
#

You can curl and pipe it into sh

sullen bone
#

(sorry, replied to the wrong message, but it was intended for you)

rustic sage
#

i've finished the section

#

now password attacks module is done

fathom pendant
#

man idk why people keep complaining about the log poisoning section in File inclusion... it was EZ literally just did as shown kek

acoustic owl
fathom pendant
acoustic owl
fathom pendant
#

:)

#

i had the braincell from my twin bestie for like 3 seconds :D

#

tfw ffuf errors because i forgot to specify http:// before the IP:port kek

limpid hemlock
#

Hey in the zap scanner section in intro to web proxis module i ran zap active scan but isnt able to find any high vulnerability as mentioned in the question

fathom pendant
#

easily the most annoying part of that; as I checked the walkthrough while waiting and the vulnerable thing is deep in the list

#

easily 20-30 minutes wait

limpid hemlock
#

Hmm

fathom pendant
#

trust me it will find it but it won't be the only "high severity vuln" that's found

#

so don't go hunting rabbits, so to speak, if the vuln looks complex it's likely not the droid you're looking for

sly kelp
#

web fuzzing new module anyone having issues with fuzzing directory question

#

tried all directory lists from seclist no luck

ember fern
#

run Spider first

#

find the file that looks exploitable

#

then run Active Scan on that

#

should only take a few seconds

ember fern
sly kelp
#

Within the "webfuzzing_hidden_path" path on the target system (ie http://IP:PORT/webfuzzing_hidden_path/), fuzz for folders and then files to find the flag_

ember fern
#

mb

#

I thought that was the ffuf one

sly kelp
#

it is updated version of that module

sly kelp
limpid hemlock
sly kelp
#

There is bug in Web fuzzing Module it is not accepting any flag as answer

#

even the correct ones

fathom pendant
#

I mean selecting the suspicious endpoint to test *

ember fern
#

otherwise you have to enable recurse, which was greyed out for me

ember fern
#

just blindness on our part lol

#

because tbf you don't really think of that as being part of it

fathom pendant
#

yeah likely glossed over bc my brain went "ok random bullshit go"

fair briar
#

Can anyone help me solve the two skill assessment questions ?

fathom pendant
#

for?

fathom pendant
fair briar
still wolf
#

hello, I am having the same issue, could you figure out a way to connect?

fathom pendant
#

probably not helping you to be doing 2 modules at once

#

my biggest suggestion is go back over the module to see what you may have missed

fathom pendant
fair briar
still wolf
fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

fathom pendant
#

tbh that doesn't help your learning

#

i do hope you've been taking notes while going through the modules

#

otherwise I suggest start doing that

fathom pendant
#

as notes will be your savior

#

but it doesn't hurt to go backthrough and double check that you didn't miss context

fair briar
#

I have excellent note taking skills ๐Ÿ™‚

fathom pendant
#

then don't be afraid to spend extra time to make sure you understand a concept before moving forward

fathom pendant
#

ik it's tempting to just copy/paste and move on, but always make sure you understand the section content before moving forward

#

i.e. i'm doing the FIle Inclusions module atm, and I'm making sure that my notes include the important text; screenshots of me performing the commands; and any additional bits of info

#

also if you needed to google for additional info, include a link to what you looked up

#

my notes for imap include a link to a blog that talks about IMAP commands that goes over it a bit better (especially FETCH) than the footprinting/common services module does

#

it solidified my understanding even more

#

if it also helps; break down commands if you need to

#

ffuf -w wordlist -u url -H "HOST: Fuzz.domain" is my notes for vhost fuzzing with FFUF

fathom pendant
#

well yeah

#

at this point i have most of my common commands memorized

fathom pendant
#

like xfreerdp /v:ip /u:user /p:'password' /drive:share,/path/to/share /dynamic-resolution /cert:ignore

#

but when you're just learning new syntax, it helps

fair briar
#

Okay, i`ll look at S.As again

fathom pendant
#

โค๏ธ sorry if it seemed like i was ragging on you about it; also 90% of issues in skill assessments comes from missing one simple thing

#

(like the port...)

tender nimbus
#

Hey guys can you help me? I need to find to flag but when im trying to scan to identify the services its says that 0 hosts are up but i can acces it in the searchbar?

fathom pendant
#

what module and section are you on?

tender nimbus