#modules

1 messages · Page 304 of 1

safe star
#

I went to sleep mad then it was working normal after

#

Try terminating it and waiting a few minutes

elder kraken
grand portal
#

after cracking easy and medium labs for nmap module, in hard module, I find it really funny lol With our second test's help, our client was able to gain new insights and sent one of its administrators to a training course for IDS/IPS systems.

tender radish
#

i'm having an issue at footprinting lab - easy

#

i should be able to download the id_rsa from the ftp server

#

but it says permission denied.. i tried even setting chmod 600 and still doesn't work

#

mget id_rsa gives me cant access id_rsa: permission denied

supple scaffold
#

hey have a general question , where can i get the files that comes with the machines? i mean , i need to use a wordlist from the machine but i want to do it on my vm and dont have the wordlist on my vm

grand portal
real delta
supple scaffold
#

no , i just want the neccesary files that needed to complete the machine on my vm , eg wordlist

grand portal
tender radish
#

i can't 'open' it

grand portal
real delta
tender radish
#

prolly a bug, let me try to reset the machine

grand portal
supple scaffold
tender radish
#

easy test lab

grand portal
tender radish
#

it worked first time, but my VM crashed

#

then i reset my VM and it said permission denied

supple scaffold
grand portal
tender radish
#

still doesn't work

#

footprinting

real delta
grand portal
grand portal
tender radish
#

vim and nano are unknown commands

grand portal
#

how about cat?

tender radish
#

same..

grand portal
#

enter shell see if opens better terminal.

tender radish
#

nvm it worked

#

i had another id_rsa on my local

#

didnt overwrite

grand portal
#

alright

tender radish
#

thanks ❤️

supple scaffold
#

thank you both @real delta @grand portal , got everything i was needed

simple ledge
#

Module: Pivoting, Tunneling, and Port Forwarding -> ICMP Tunneling with SOCKS

Hi all, I was having an issue with ptunnel-ng not executing on the pivot host so I did some research and it seems like you need to compile (autogen.sh) with the same version of glibc as the pivot host.

Did anyone find a way around this? Seems like creating a new VM just to compile a single program is overkill.

autumn pilot
#

There was a method shared in the channel on how to statically compile it

simple ledge
late tapir
#

Guys is there anyone who completed "INTRO TO C2 OPERATIONS WITH SLIVER" module. I am having difficulties in "Establishing persistence" part.

shut vapor
#

NetExec / CME have a --local-auth option for authenticating against the local target machine. Is this functionally the same as passing "-d ." or is there more to it?

fathom pendant
#

There's likely more to it

untold wing
#

do the streak points do anything atm?

boreal token
#

Can anybody help my laptop doesn't just want to connect to my laptop Icon also not showing on desktop

fathom pendant
boreal token
#

I've asked in the general group aswell

untold wing
fathom pendant
final vine
fathom pendant
untold wing
fathom pendant
#

No ports or /etc/hosts entry needed

untold wing
#

why are you fuzzing a live website to start with

fathom pendant
fathom pendant
#

And the question asks for it

untold wing
fathom pendant
#

Inlanefreight is a fictional company that's used as a background company that's the basis of most of the modules

#

You'll see inlanefreight.htb, inlanefreight.local, and even freightlogistics.local

#

For some of the modules

untold wing
#

that's cool tbf, nice to see something outside of the standard vpn box's

fathom pendant
#

¯_(ツ)_/¯

final vine
fathom pendant
#

Ok good just making sure that you didn't goof

fathom pendant
#

Also don't put 100 threads

#

You might just be trying too many threads at once

fathom pendant
final vine
final vine
fathom pendant
#

Worked for me

#

I take it you're using pwnbox?

#

Or your own vm

#

Could be some misconfiguration in your vm

oak girder
#

hello

#

I have no idea. Can anyone help me?

fathom pendant
#

The credentials should be given to you in the section

spring forum
#

find / -name "restic" maybe? 🤣

fathom pendant
north bramble
oak girder
#

I have restored all the backup files

fathom pendant
#

The question is "what's the password for Restic Backup"

#

Aka you were overthinking the question

bright pivot
#

after i got this output how to login as selly.jones?

north bramble
fathom pendant
fathom pendant
north bramble
supple scaffold
#

i get this running monitor.sh on nibbles , and nc -nvpl doesnt get anything
/home/nibbler/personal/stuff/monitor.sh: 26: /home/nibbler/personal/stuff/monitor.sh: [[: not found

fathom pendant
bright pivot
fathom pendant
fathom pendant
supple scaffold
#

wait i added the wrong ip adress in it ill rework on it with my monitorbak i made

oak girder
#

@fathom pendantHow do I find out?

bright pivot
fathom pendant
bright pivot
#

at page 11

fathom pendant
supple scaffold
oak girder
#

No, that's all he gave me

fathom pendant
fathom pendant
#

Oh my god

#

It's asking for the password for the Restic Backup Service/tool

oak girder
#

hello ?

fathom pendant
oak girder
fathom pendant
#

And you found the answer

fathom pendant
oak girder
#

No, I didn't understand his steps

#

S* is the result of asking others, I want to learn by myself

#

I beg you to teach me

#

😫

fathom pendant
#

Configuration files are often low security

oak girder
#

I think I've read everything I can about backups

fathom pendant
#

Did you go to the Restic folder?

#

And look for a conf file there?

bright pivot
oak girder
#

I tried to open it

fathom pendant
fathom pendant
fathom pendant
oak girder
#

OMG

fathom pendant
#

Wdyk it's on the desktop 😉

#

Always enumerate what your user can see

oak girder
#

It turned out that he had been right in front of me the whole time, and I spent three hours searching for him

#

thanks

oak girder
#

@fathom pendantBoss Why haven't I recovered SAM

#

I see some questions from the community

north bramble
north bramble
north bramble
#

This is from the next part, using chisel. any way to fix this?

tepid vigil
#

hello am on web fuzzing assesment || i got admin/panel.php i just done both GET and POST commands but found nothing and lost where to go from here ||

nocturne hedge
#

me too

tepid vigil
#

@nocturne hedge what did you try

frosty tide
tepid vigil
rugged jewel
nocturne hedge
stoic estuary
autumn pilot
fathom pendant
rustic sage
#

Hello
I want to find a people who want to learn programming with me and i iwis if we be a team work together in the future
we will learn together and have fun together and i wish if we be a small family in the future
if you want to join send me

sonic plume
#

could i get some help with this question? " Review the NFS server's export list and find a directory holding a flag." (Miscellaneous Techniques section) linux pe).

Im getting this error; mount.nfs: access denied by server while mounting IP:/tmp, with this command 'sudo mount -t nfs IP:/tmp /mnt'. I've tried do everything which is mentioned in the section; also i've tried restting the box multiply times, change vpn. But really the strange part is, i could do the same command and it worked then but when trying to execute the shell owned by root it gave me a "htb-student@NIX02:/tmp$ ./shell
./shell: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./shell)
htb-student@NIX02:/tmp$".

I've no idea how to fix this or what to do.

marsh echo
#

url="http://94.237.59.63:45600"

for i in {1..20}; do
        for link in $(curl -s "$url/documents.php?uid=$i" | grep -oP "\/documents/Invoice.*?\.(pdf|txt)"); do
                wget -q $url/$link
        done
done```
hello i have a question in fact i don't understand why the files don't download yet i start in the script base and i modify it to download the useful files with a regex but it doesn't do anything but with the script provided in the course it doesn't do anything.
https://academy.hackthebox.com/module/134/section/1186
fathom pendant
sonic plume
#

yeah, in the config file and it shows on the showmount command

fathom pendant
#

That's not what I asked

#

Ip:/sharename

sonic plume
#

oh mb, yea the name is /tmp

fathom pendant
#

Does it require remote authentication to connect

fathom pendant
#

Also, capitalization is important

sonic plume
marsh echo
#

I really tested everything and restarted the server several times, thinking that maybe that was the problem, but no ...

tepid vigil
fathom pendant
tepid vigil
#

on the Web Fuzzing

fathom pendant
#

I meant idk wtf you're referring to with x-y-a

tepid vigil
#

for paramaters

fathom pendant
#

The parameter that you need to fuzz it's value for is given to you

tepid vigil
#

lol

fathom pendant
#

Idk what you mean by x-y-a

tepid vigil
#

ow

#

my bad i think i got it

#

i am currently using wenum

fathom pendant
#

Also once you find the value

#

Visit the webpage with that parameter=value

#

I only used ffuf tbh and it worked fine

tepid vigil
fathom pendant
#

Yes

fathom pendant
tepid vigil
#

ig i'll try ffuf

fathom pendant
#

once I got the page extension it worked for me ¯_(ツ)_/¯

#

I'll spin it up and try wenum to alleviate doubts

tepid vigil
#

alright

fathom pendant
#

But all FUZZ values will be in common.txt

tepid vigil
#

alright

knotty peak
#

hello
in password mutation section of password attacks , im kinda stuck since the question says to use the password list from the resources of the module and crated a mutated one to brute force the user sam in ssh , i did that but got no results after waiting for too long , any one got the same prob

#

this is the question : Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer.

#

when i looked in the youtube i saw someone using the same thing but the made a list with batman in it and mutated it

#

when i looked into the mutated file i made from the password list in the zip file there were nothing like batman

#

any ideas

safe star
#

The mutated list should be about 94k lines long

#

Did u try cat mutated | grep -i batman

knotty peak
#

actually thats what i did aftermaking the mutated file i did $ grep -i batman mutated.list

safe star
#

And nothing?

#

Usually it just takes an unnecessary amount of time to get the right password

upbeat oak
#

Did you make the mutated list like it says in the module using hashcat? resources gives you the custom rule and password list to make it

knotty peak
#

just found the problem

#

the problem was that i made my own rule file

marsh echo
# fathom pendant Worked for me

this script works for you too? curl -s "http://SERVER_IP:PORT/documents.php?uid=1" | grep "<li class='pure-tree_link'>" because me nothing displayed

knotty peak
#

which included the rules show in the module

#

but now when i did it for th 4th time i found when unziping the file i got the rule file

#

so i was using the wrong one

safe star
#

Yeah

dapper moth
#

Anyone would care to give a hand in the "Attacking Authentication Mechanisms" - Skills Assessment!?
Just to see if I'm banging my head against a brick wall or if I'm in the right direction

knotty peak
#

sorry for the inconvenience

oak girder
#

Hello

fathom pendant
#

@harsh oak can I help you? I don't do random dms

manic bramble
#

did anyone have trouble with File Upload Attacks - Type Filters? doing a double reverse method using extension htb.jpg.phar

#

I even modified the content-type

fathom pendant
#

Also make sure there's a newline between the Content-type and the signature

manic bramble
#

yup there is a new line

fathom pendant
#

Looking at my notes I used the gif* example and used a specific image/g* content-type

#

Wrong image content type

manic bramble
#

okay cool

#

image/gif?

fathom pendant
#

Try and see

manic bramble
#

kk

fathom pendant
#

You should have fuzzed for valid image/[type]

#

What does your fuzzing reveal

#

Don't just copy/paste from the walkthrough

manic bramble
#

okay i'll check my fuzzing

fathom pendant
#

Ik you are copying from the walk-through bc of the php command in your request

rugged jewel
#

WTF is going on today on the service?

fathom pendant
fathom pendant
manic bramble
#

what's a good image extension wordlist

fathom pendant
#

It shows creating a wordlist with just image/[type] from the SecLists Content-Type list

manic bramble
#

oh yes

#

thanks

fathom pendant
#

You won't have a walkthrough for the exam

manic bramble
#

it doesn't really show fuzzing content-type

#

it hints at it

#

am i sending it to intruder? all content-types are -> Only Images Allowed

median spade
#

When I RDP from Parrot OS terminal to a windows machine, I can not copy text from remote machine. How should I accomplish this task?

fathom pendant
#

then use the menu at the top to filter it by size

#

there are some that will work

median spade
sharp nexus
#

Hello @everyone, does anyone can help me with the first question of the Module OSINT: Corporate Recon, please?

acoustic owl
sharp nexus
#

@acoustic owl I wrote coordinates in DD. But it doesn't work.

acoustic owl
cerulean stone
#

Does anyone know if HTB runs through their modules after deployment? How does one get to the kali box if there isn't a start instance button like other instances?
Module: CDSA Path - Windows Att & Def - Kerberoasting

formal lintel
#

hello! i have a question
how did you make the xss phishing module?
I made the malicious form, I make the listening script to get the credentials when the person fills the form.
i send the link in phishing/send.php
then what ?
because if I test myself filling the form the credentials are not useful when I try to log in /phishing/login.php

what do I have to try?

bright pivot
#

why i got different output?

dim wolf
#

i believe you can RDP into the kali box after you've RDPed into WS001

north bramble
cerulean stone
# dim wolf you RDP into WS001, not the kali box

Understood...I tried to ssh from WS001...it wasn't listening. I tried to RDP and it is not listening either. The previous page states that Kali should be at 172.16.18.20. It is not responding to ping as well.

dim wolf
#

may not be there for that section then

cerulean stone
#

Bummer...going to be hard to perform the Kerberoasting questions without the kali box to perform hashcat

dim wolf
#

both the kali box and WS001 show up in the later sections IIRC

cerulean stone
#

Alright, I'll just go through the solutions and skip this module

dim wolf
#

wouldn't recommend that but you do you

viral snow
#

I did that

radiant stump
#

Hi everyone, quick question: Has anyone solved the assignment in the 'Broken Authentication' module, particularly the part on 'Enumerating Users'? I keep getting errors when I try to run the command and can't submit the question

surreal lichen
#

I'm struggling with this question, in CMD vs. PowerShell: " What command string can we use to view the help documentation for the command Get-Location? (full string)" I'm pretty sure the answer is ||Get-Help Get-Location -online|| what am i missing?

viral snow
#

I'll fire up my PC shortly

radiant stump
#

Enumerating Users

radiant stump
north bramble
# north bramble I got it to somehow work. now there is a new issue with the next part
surreal lichen
viral snow
#

I did that too.

I'll be firing up my PC in a few

surreal lichen
formal lintel
#

hello! i have a question
how did you make the xss phishing module on htb?
I made the malicious form, I make the listening script to get the credentials when the person fills the form.
i send the link in phishing/send.php
then what ?
because if I test myself filling the form the credentials are not useful when I try to log in /phishing/login.php

what do I have to try?

cerulean stone
marsh echo
dim wolf
cerulean stone
#

Yes, but you don't have it...unless you know where they are located on the parrot desktop. 😉

dim wolf
#

i'm not sure i follow

#

are you using pwnbox or VM

cerulean stone
#

pwnbox...the rockyou*.txt files are in an obscure folder in /opt.

dim wolf
#

because i just cracked the ticket offline on my own VM

#

ok that makes sense

cerulean stone
#

Yeah, I've not gone down the rabbit hole of VPN just yet...I'm not sure it is the best solution for this type of user base. Teach them to walk then stand then run.

dim wolf
#

that's covered in Infosec Foundations path

#

you should be acquainted with the tools you have in your environment if you're doing Windows Attacks & Defense

cerulean stone
#

Oh I am...it is just when the tools aren't available that I get stuck

fathom pendant
#

I mean they're still available

#

The update to pwnbox shuffled stuff around and the module text hadn't updated to reflect it

dim wolf
#

oh they did update pwnbox huh...

cerulean stone
#

Right...so now, take the viewpoint of someone trying this out for the first time...although with 20+ years of IT experience. This isn't supposed to be expert level stuff...yet

dim wolf
#

i recommend using your own VM then just so you know where all your tools are

fathom pendant
#

^

dim wolf
#

i forgot that they updated pwnbox so what you're told in the module in regards to pwnbox tools might not necessarily be what you get.. you'd be better off with your own VM

dapper moth
#

Anyone finished “Attacking Authentication Mechanisms” could care a hand?
Some of these modules feel like a black hole in the forum and in here…

fathom pendant
dim wolf
#

i also thought of that as well

#

but if you're struggling to find tools in pwnbox, it'd probably be better just to have your own VM at that point

rustic sage
#

module: shells and payloads
section: metasploit

#

I tried the logical thing which was "shell" because it gives u the shell with metasploit if u run that command, seems like it wasnt correct

#

nevermind figured it

safe star
arctic sentinel
#

Good afternoon!

dim wolf
#

some stuff is placed in /opt but that's not the case on a fresh install of Parrot

sleek moss
#

proxies = {"https": "https://127.0.0.1:8080", "http": "http://127.0.0.1:8080"}
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)

def sqlInject(url):
password_ext = ""
for i in range(1, 21):

        r = requests.get(url,proxies=proxies, verify=False, cookies=cookie)

why doesnt this work? it works if i dont do proxies=proxies but if i put in proxies=proxies it doesnt work and the r.status_code doesnt return even tho i have burpsuite set up nd stuff

#

for sql inject

arctic sentinel
#

Ive been trying to solve the thick applications module but I am super stuck... I have tried many ways but after changing the port and deleting the hashes from the MANIFEST.MF file

#

I tried from the pawnbox and I get errors and when I tried from the windows machine I double click but the java app does not start

#

now I manage from the pawn box to run the application but when I type the username and password I get error as well...

manic bramble
# fathom pendant yes use intruder

so i found what images are allowed and what web extension are sort of allowed. but when i put it all together in repeater, it still doesn't work? can i send you a screenshot of it?

fathom pendant
manic bramble
#

signature as in .png matches content-type: image/png?

#

how about my method? should it be get or post?

#

its' post right now

fathom pendant
#

well to upload it's POST

fathom pendant
arctic sentinel
#

I managed to access but now I dont see the lower tab for opening files...

#

I dont know why I dont see it...

#

I have tried closing and open and changing the size of the window

bright pivot
arctic sentinel
#

any ideas...

indigo flax
karmic orbit
#

Can anyone help please? I'm stuck on 'Firewall and IDS/IPS Evasion - Hard Lab' in the 'Network Enumeration With Nmap' module.

#

The question is 'Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer. '

#

And the hint is 'Our client also mentioned that they were forced to add a service that plays a vital role for their customer because they require large amounts of data.'

fathom pendant
#

you'll need to do a scan of all ports to find a service that may be running

karmic orbit
#

Okay. I used -v and it kept outputtingIncreasing send delay for 10.129.2.47 from 160 to 320 due to 11 out of 12 dropped probes since last increase and now the scan isn't progressing at all.

marsh echo
marsh echo
karmic orbit
fathom pendant
fathom pendant
#

sometimes SYN can be dumb

karmic orbit
#

Okay. I've done that now. Could you explain what was happening there?

fathom pendant
karmic orbit
#

Warning: xx.xx.xx.xx giving up on port because retransmission cap hit (6).
That happened one time. I googled it and it recommended lowering the timing value.

calm tapir
#

Hey I've been stuck on the last question of the Information Gathering - Web Edition (Updated)
Q: What is the API key the inlanefreight.htb developers will be changing too?
I found an API key on the vhost but not sure how to use it any tips?

karmic orbit
#

But when it was the default -T3, it didn't work either.

fathom pendant
#

it's pretty dumb you can do --max-retries=2

fathom pendant
#

you are just locating it

calm tapir
fathom pendant
#

wdym? the API key is the answer

#

the question asks for the new API key, nothing more -- nothing less

#

but if the answer isn't accepted, maybe go another level deeper

#

bc there's w*.inlanefreight.htb then there's another vhost under w*

#

so a.b.domain

karmic orbit
marsh echo
fathom pendant
#

don't worry about if it hits max retries for a port

fathom pendant
#

don't just blindly follow the module

#

utilize the knowledge being given to extract and discover info

#

intercept the request you make on your system to the target

#

see the type of request being made

#

and modify/make your script off that

#

you can't always follow the examples exactly

#

utilize the information that is surrounding the examples on how you'd discover it for yourself

marsh echo
#

i see okok

#

thx

fathom pendant
#

don't complain that "it just doesn't work" because there's generally a reason behind it not working

#

(and usually it's not bc the lab is broken)

#

it's also very fresh on my brain bc i just did it

#

currently doing my process map for the skill assessment

marsh echo
#

I understand, thank you, I'll follow your advice (I've always followed it and I've always succeeded, so there's no way I won't lol).

fathom pendant
#

back to screenshot and copy/pasting my scripts into my notes kek

karmic orbit
#

I got 2 open ports and 2172 filtered ones (no response) from the full scan. When I done a service version scan on the two open ones, neither contained the flag.

marsh echo
#

i found the flag but with intruder 😦 i'mgoing to try the script happy_ping

fathom pendant
#

i'd re-read the text on DNS Proxying in the IDS/IPS Evasion section; it might reveal something to you

#

also make sure you didn't incidentally trip the IDS kek

karmic orbit
fathom pendant
#

i believe it's also on http://ip/status.php

#

as given in the first assessment

#

in a normal engagement you wouldn't have access to this page

karmic orbit
#

I found a new open port! (: It was also faster when I changed my source port. Is there a reason for that?

marsh echo
#

but marcie i think you understand things better than i do but what i don't understand is why the post method is used knowing that get allows you to ask the server for documents based on the user's uid ?

karmic orbit
#

The service is shown as tcpwrapped and there's no version.

shut vapor
bright pivot
#

after this what should i do next?

#

how to acces the target?

shut vapor
#

You've got command execution, make the computer do anything you want!

bright pivot
#

so how to go home directory?

#

so just run the command in my terminal?

#

like this?

#

so where should i add wp-user?

#

so i need to check the wp-content,wp-include,etc?

#

can you give me some example?

zinc nimbus
#

change cmd input

bright pivot
zinc nimbus
#

i think replace cmd=id with other commands than id

#

that’s a webshell right?

bright pivot
zinc nimbus
#

ye if u wanna know the files just do cmd=ls+/home

#

then it’ll show users then after that u can keep searching

fathom pendant
fathom pendant
bright pivot
fathom pendant
zinc nimbus
#

ye but it’s a webshell it doesnt work the same

#

the webshell is being hosted on a specific directory idk how to explain

fathom pendant
#

at least for the purposes of changing your current working directory

#

the webshell will always be hosted at the directory it's planted at, so cd does nothing permanent; you'd need to chain together like cd <directory>;<other command>

zinc nimbus
#

yee chaining tho

#

cd..;ls

bright pivot
#

so what if i want to go wp-user which command should i use?

fathom pendant
#

you can't go to them

#

you can ls that directory

bright pivot
#

i mean see that file

fathom pendant
#

or cat that file, if it's a file

bright pivot
#

oh ok so just do ls../...?

fathom pendant
#

yeah, basically

#

or you can use the full path

bright pivot
#

cmd=ls wp-user like this?

fathom pendant
#

if it's in the same directory as your shell, yes

zinc nimbus
#

u never used web shells b4 😭?

fathom pendant
#

idk how if he's doing the cbbh path

bright pivot
zinc nimbus
fathom pendant
#

honestly though webshells are like dummy simple

zinc nimbus
#

u def cant ls a directory that isnt in the current directory

fathom pendant
#

would probably be faster to just use the path

#

/var/www/html/wp-users instead of a million ../../../../../../

#

or wherever the wp-users dir is located on the webroot

fathom pendant
#

you need to ls it you goon

#

i was referring to using the filepath + an enumeration command

#

since you know, you can provide a command like ls, or cat, with a filepath instead of the current directory to enumerate

dim wolf
fathom pendant
dim wolf
#

it takes so long to document the attack path, especially for me

bright pivot
#

is there module about webshell?

fathom pendant
#

it also took me an extra minute because i completely missed the u* endpoint kek and was trying to attack the t* endpoint

dim wolf
#

Shells and Payloads should go over web shells

fathom pendant
#

webshells being one of them

#

but like nothing that's crazy in-depth

#

you're just thinking a webshell is more than what it is

#

think of a webshell as a website in a way. By itself it only can see where its at, and you have to tell it where to look for your commands

#

i.e. in a NixOS environment for the webshell; you'd do something like cat /etc/passwd to read the passwd file, but you can't just tell it to cat etc/passwd as there is no etc/passwd file in the webroot (or wherever your shell is located)

#

you need to give it either a relative or absolute path to reach the destination

#

if you don't know what either of those are, then you're missing some fundamentals

#

relative == i am in /home/marcielee and i want to look at home, without changing my directory i can either:
ls ../ (which will tell ls to look one directory back, relative to my current directory) or ls /home/ (tell ls directly where to look)

viral snow
#

Two things I've learned with HTB

  1. Be patient
  2. Pay close attention to detail

Holy crap did I put myself in an unnecessary mess 😤

fathom pendant
#

yup

fathom pendant
#

you're staring at something more complex when the answer was 2 lines up from where you were at

#

or one of the modules where you dump the SAM/SYSTEM and it's in plaintext...right there...

cerulean stone
#

Did the domain crash on the pwnboxes?
Error: The trust relationship between this workstation and the primary domain failed

fathom pendant
#

I don't think so ¯_(ツ)_/¯

#

Looks like something just blipped on it

cerulean stone
#

I rebooted all my instances...except the Windows VM...just restarted it and it seems to be ok now

rustic sage
#

Hello. I am stuck on a module. I am working on File Upload Attacks, and I am on Blacklist Filters. I used burpsuite intruder to fuzz different php extensions. I found a couple that allowed me to get a successful upload in repeater. However now that I have my phpbash shell file uploaded I do not get the usual shell when I visit the page. I get what you see in this picture. Can anyone tell me where I went wrong? https://gyazo.com/f4c766b8c965fb668b26c71d0c27cc67

fathom pendant
#

i just used a standard php webshell ¯_(ツ)_/¯

#

to me it looks like there was some error in your phpbash script

rustic sage
#

ill try another webshell

fathom pendant
#

try another extension

rustic sage
#

oh ok

fathom pendant
#

don't just assume that a successful upload means that you'll get a shell out of it

rustic sage
#

understood

fathom pendant
#

but using a basic webshell or a simple test like <?php system('id') ?> should be used before trying to troubleshoot a pseudoshell

latent meteor
#

is there any foss alternative to xfreerdp? sonmehow it keeps on crashing on me

fathom pendant
#

is it a timeout error?

#

if so /timeout:999999

#

there's also other tools like rdesktop or remmina

latent meteor
#

something like

[17:47:23:883] [28787:28788] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 110: Connection timed out
[17:47:23:883] [28787:28788] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[17:47:23:883] [28787:28788] [INFO][com.freerdp.client.common] - Network disconnect!
#

every module I have to restart the thing multiple times..

#

thanks will try it out!

fathom pendant
latent meteor
#

yeah the thing is that I can't even reconnect without restarting the target

#

will try with the timeout parameter thank you

fathom pendant
#

i'd also suggest changing vpn regions, and using the tcp vpn download, instead of UDP

rustic sage
#

got it. thank you

fathom pendant
#

👍

hexed oyster
#

OK... I am done beating my head against a wall on this. I am absolutely stuck. Where do I get help with the File Upload Module? NOTHING is executing.

fathom pendant
hexed oyster
#

@fathom pendant sorry, working on file upload -> black listed filters.

#

tried the following wordlists: payloads all the things > extension PHP > extensions.lst

#

seclists>web extensions

#

fuzzdb > alt-extensions-php.txt

#

seclists > file-extensions-lower-case.txt

#

raft-*-extensions.txt

#

NOTHING is executing.

#

Its secure; I hate it.

#

I've been stuck on it for like 3 weeks. I feel like an idiot.

fathom pendant
#

i just did this one the other day; did you use the php list that's suggested by the module, also: filter by the response size, if you view the responses of the larger files -- it'll be successful (ignore what the reading says about its sizes)

#

you don't need to use raft or any ext like that

hexed oyster
#

can I dm you real quick? I want to make sure I've got the right file

fathom pendant
#

within the reading they directly reference a php list

#

gimme a sec to pull it up

fathom pendant
hexed oyster
#

yeah

fathom pendant
#

it's a matter of using burp intruder, waiting for it to finish, then sorting

#

you'll find a handful of extensions that "uploaded" but only one will actually execute

#

i believe if you view source it shows the failed payload in an html comment whereas on the success it will execute

hexed oyster
#

The response(s) I'm getting from Burp are all 200 ok, with either 'File successfully uploaded' or 'Extension not allowed'.

#

alright, I'm going to walk my dog and let this finish.

fathom pendant
rustic sage
#

Sir I'm a beginner in this field is there any recommended youtube channel from you to start hacking?

compact patrolBOT
fathom pendant
proper mountain
#

Helloo .. recently when I was trying to run custom queries on bloodhound it shows no match found for all the queries that I write, even the obv ones

#

does someone know how to solve this,

hexed oyster
#

@fathom pendant ran through the entire list, sorted by length. found an obvious difference. Tested larger ones, nothing executed.

#

I HAVE to be doing something wrong...

fathom pendant
#

from what i recall

#

what is the php code that you're testing?

#

<?php system('id'); ?> is generally a good test

hexed oyster
#

yeah... I uploaded that

#

how the hell am I realistically supposed to check all of these in any reasonable lenght of time?

#

@fathom pendant I found it. Thank you.

#

I'm so angry at myself right now

fathom pendant
#

:)

viral cobalt
#

who or where can i ask for help on a particular assignment in the academy modules?

dim wolf
#

you can ask your question here

fathom pendant
#

nobody, read the rules

fathom pendant
dim wolf
#

advertising "hack services" is not allowed

fathom pendant
viral cobalt
#

im stuck on this question
"Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable. "
its in Introduction to Bash Scripting Flow Control - Loops

fathom pendant
#

well what are you having trouble with?

#

what have you tried?

viral cobalt
#

i keep getting
"*** WARNING : deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
40E74883607F0000:error:1C800064:Provider routines:ossl_cipher_unpadblock:bad decrypt:…/providers/implementations/ciphers/ciphercommon_block.c:124:"

dim wolf
viral cobalt
#

not sure if my script is correct but no matter what i do i get bad magic number

fathom pendant
#

likely your script; but that doesn't necessarily tell us what you've tried

#

¯_(ツ)_/¯

#

bad decrypt generally means the password used to attempt to decrypt was incorrect

tender nimbus
#

Hey guys im stuck here is my awnser close ?

fathom pendant
#

and your answer is not close

#

some services, like SMB, report the hostname, generally enumerated via -sC

#

or scripts

tender nimbus
#

ow okej im gonna give it a try thanks

fathom pendant
#

reading the question generally gives you an idea of what the question wants

tender nimbus
fathom pendant
#

Click around for other databases

#

This is in the nmap module yeah? @tender nimbus ?

tender nimbus
fathom pendant
#
  • databases
fathom pendant
#

Using the tools and techniques you learned in that section... it's not like they asked you to do something completely out of pocket like run a whole separate other command

tender nimbus
fathom pendant
#

something will evenetually yield a database and table you can interact with to find more info, like a table to search under

fathom pendant
#

some do, some don't

#

but you don't know unless you try

tender nimbus
fathom pendant
#

what is it with people and asking about something and not being at their desk to check jfc

#

also you seem to be looking under security, not the databases list

#

tbf; the footprinting module is a little light on enumerating the MSSQL GUI

#

but it's mostly just clicking around

#

accounts might be interesting

#

try right-clicking it

#

:)

#

also look at -Tables

#

generally information in an SQL database is gonna be in a table of sorts

#

:)

#

you've gone one level too deep

#

right-click that table

#

also remember a table is made of columns and rows; so you see the columns there

twilit jacinth
#

guys im new to this , currently im doing the ftp modue in academy , and it shows 1/1 spawn , does this mean i only got 1 chance to pass the module , meaning like once i spawn it i have to finish it ?

fathom pendant
#

don't hate yourself dude, see this as a sign to take a little breather

fathom pendant
#

also i don't recall there being an ftp module, do you mean the file transfers module?

#

ftp is just a protocol; file transfers is the method (of which there are many beyond ftp)

twilit jacinth
#

yeah dude, thats the one hahha , really confusing 😫

fathom pendant
#

just take it slow my guy

#

no need to rush

hexed oyster
#

@fathom pendant Can I DM you about that Blacklisted File Upload? I found the answer but I'm still not understanding it.

#

i.e. I have the flag, but I still have questions.

fathom pendant
hexed oyster
north bramble
fathom pendant
nimble tundra
#

Is there a way to reset progress on a module we completed a few years prior? I completed a few one off modules in college and now I want to go back through with a fresh start on some of them...

fathom pendant
north bramble
north bramble
north bramble
fathom pendant
#

I ended up not using it, too clunky for me- I used a different method ¯_(ツ)_/¯

north bramble
simple ledge
north bramble
simple ledge
north bramble
north bramble
#

I added the dll file, why doesnt this work?

fathom pendant
north bramble
fathom pendant
north bramble
#

oh

north bramble
#

oh i think i got it

safe star
#

Same spot too

#

These last two sections are a pain 😭

north bramble
north bramble
safe star
#

yeah

#

that was so SLOW

#

i had to type the flag in

quiet trout
#

anyone been thru the first few intro segments (linux) on the intro to security module recently? i forgot to make a note and something they brought up... very simple get request using tcp socket, is bothering the heck out of me and i "NEED" to see the info again, and i cant find it T_T''

north bramble
fathom pendant
fathom pendant
quiet trout
#

yeah im hunting for it now but im having no luck... it was just a simple demo... it was in either the linux fundamentals or some other fundamentals type (mixed) segment where it discussed linux sockets and what im after is the part about tcp sockets and how they issued a get request to a tcp socket /dev/tcp/google.com/80 type deal ... and im trying to make note of that, i thought it was really... cool? dunno never really seen that... chatgpt gives me "something" but i want to re-read it make a note of it and commit it to memory... from htb

#

i get the concept and i get how to do it... but i just have a irk where i NEED to see it... to be like... "ok"

#

this problem has plagued me for most of my life... i have several songs in my head that i "NEED" to hear but dont know enough about them to find the artist/title, movie quotes i "NEED" to remember so i can find the name of the movie but cannot remember the actor or movie, just the quote itself... etc. etc... i create these problems for myself... kinda sad

fathom pendant
#

Well it might not have been in intro to linux tbh

#

Well linux fundamentals

quiet trout
#

im thinking you're right, now that im halfway thru my second search

#

it might've been the module prior... i went to the academy and started like... from the intro and just let it pass me along to whatever was "next" so now im having a little trouble back tracking

#

why didnt i just write it down... :/

oak girder
#

Hi guys

#

Do I need to install this manually?

quiet trout
#

did you check python --version ?

fathom pendant
oak girder
#

I checked it

fathom pendant
#

Latest python is 3.12

quiet trout
#

pwnbox doesnt installed backdated python? check python2 --version as well, just for grins before installing

fathom pendant
#

2.x has been officially dropped by many distros

quiet trout
#

oic

oak girder
#

Yes, no Py2

#

I'm trying to install Py2

#

But I feel it is very slow

fathom pendant
oak girder
#

curl https://pyenv.run | bash
echo 'export PYENV_ROOT="$HOME/.pyenv"' >> ~/.bashrc
echo 'command -v pyenv >/dev/null || export PATH="$PYENV_ROOT/bin:$PATH"' >> ~/.bashrc
echo 'eval "$(pyenv init -)"' >> ~/.bashrc
source ~/.bashrc
pyenv install 2.7
pyenv shell 2.7
python --version

#

So cool you guys

fathom pendant
#

Took a min using the discord search feature

quiet trout
#

man, im so confused ive been thru all my previously completed modules... im wondering if i just made this up? the bit about the get request using /dev/tcp/... ? its kinda nonconsequential but its driving me mad.

#

this is not friggin cool its gonna keep me up all night

oak girder
fathom pendant
#

/dev/{tcp|udp}/remote.address/port

quiet trout
#

it was so simple so elegant

#

it was like echo -ne 'GET ....' > /dev/tcp/yahoo.com/80

#

but i just cant be sure...

safe star
fathom pendant
#

¯_(ツ)_/¯

quiet trout
safe star
#

then im not sure

quiet trout
#

yeah same, just complaining is all

safe star
#

thats the only module i can think of

quiet trout
#

u know what... i bet you its in the module... i just cant "find" it because its a screenshot

#

man imma have to go thru this with a fine comb

civic hamlet
#

@fathom pendant I summon thy

Windows fundamentals, Windows security

What 3rd party security application is disabled at startup for the current user? (The answer is case sensitive).

ive already tried to query for security proccesess that arent running and dont have a microsoft vendor, the answers ive tried dont work so far , could I get a hint?

#

wait, a non running application is not considered a proccess is it?

quiet trout
#

get-service powershell

oblique jungle
#

Good morning frens
I'm just starting out in cyber sec, going through the setting up module should I install everything I'm learning about? Including them chocolate manager, Subsystems etc

quiet trout
quiet trout
#

personally i would do it on a windows vm or a custom user account though

civic hamlet
#

bit more than a hint my friend

#

but thanks

quiet trout
#

you should've been well prepared by the time you reached that question, though. i just went thru that exact module just a few days ago

#

are you taking notes?

#

(im clearly not one to speak, just curious... those were in my notes)

storm elk
#

Contact support via website. Discord is not the place for this

storm elk
#

They’ll get back to you asap 😄 (there is no billing support on discord)

low girder
civic hamlet
#

Get-Service | ? {$_.Vendor -NotLike "*MicroSoft*" -and $_.Status -eq "Stopped" -and $_.DisplayName -like "*Security*"}

#

Is this command wrong?

civic hamlet
#

I dont see why im not getting the correct answer? A security applicaton would usually have something security related in its displayname, its a proccess thats disabled upon boot, so it would be stopped, and its a third party app

#

ive been at this for 2 hours, going to go to bed

frosty tide
#

Hello for Sever Side attack, can I do it lab on my own VM? cuz I can't connect to the target on my VM even I connect to VPN
But when I try on HTB pwnbox it work fine. Anyone know how to fix this

simple ledge
#

Module: Pivoting, Tunneling, and Port Forwarding -> RDP and SOCKS Tunneling with SocksOverRDP

Hi all, anyone else have issues transferring SocksOverRDP-Server.exe onto 172.16.5.19 from the attack host? I'm able to RDP to the pivot host, install the dll and then RDP from there to the victim host (172.16.5.19) but when I try to move the files (SocksOverRDP-Server.exe) from my attack host to victim host (SMB and HTTP) they are getting blocked or not recognising my attack host IP.

safe star
#

Real time monitoring is on

#

U can also copy and paste the folder into the rdp window

simple ledge
# safe star Real time monitoring is on

Yeah I have already turned it off on the pivot host. I tried drag n dropping the files across but it shows that error icon (circle with slash) to show it won't accept it. Not sure if I need to config something to allow for it, I was just about to start looking into that actually.

safe star
#

Are u using xfreerdp

#

I just run it with /u: /p: /v:

simple ledge
# safe star Are u using xfreerdp

I am using xfreerdp from Attack host (Kali) -> Pivot host (Windows) and then Remote Desktop Connection from Pivot host (Windows)-> Victim (Windows). I wasn't able to directly xfreerdp to the Victim host from Attack host as it's a private network.

safe star
#

Oh I got confused on which was the victim

simple ledge
#

lol okay, I'm dumb. Drag n drop doesn't work but copy n paste does.

#

working now

tender radish
#

i have a problem at module 144 - information gathering - web edition ❤️

#

skills assessment

#

i spawn machine and i'm given vHosts needed for these questions: - inlanefreight.htb

#

i add this to etc/hosts

#

i can't whois, can't dig, can't do anything

#

if i do dig -x on the target ip i get a weird dns

rustic sage
tender radish
#

omg yes

#

the question says .com not .htb

rustic sage
#

yeahhh I did the same thing lol

#

**AD-Enum Credentialed Enum - Linux: ** Does anyone know why my netexec is hanging when tunneling it via ligolo? (I've also tried with proxychains and with socat redirection. This is through the Attack-01. I relize I could just the pivot host, but I want to be able to do this as on an actual assessment a real target won't have any tools on it and I don't want to install netexec offline. thanks!

#

here is the verbose ouput

#

adding to etc/hosts I just have issue with establishing the connection

rustic sage
#

I can use --shares, maybe it's a network issue?

honest egret
#

hlw i cant connect to the htb linux interface with ssh. I have installed server side ssh. says ssh htb-student@10.129.224.248
ssh: connect to host 10.129.224.248 port 22: Connection timed out

rustic sage
#

can you ping?

honest egret
#

i cant send ss.

rustic sage
#

are you sure its supposed to be port 22

honest egret
#

i didnt mention port. I only typed ssh htb-student@10.129.224.248

knotty anvil
stark lark
#

How should I downgrade PS when 2.0 is not available

rustic sage
wicked apex
#

Module: Password Attack
Section: Lab Hard
is netexec generally recommended over hydra (even the compiled one with rdp and smb2 acess?)

karmic orbit
#

I just completed the Firewall and IDS/IPS Evasion - Hard Lab in the Network Enumeration With Nmap module. The task was to find the version of a service, which will contain the flag. Port 50000 was filtered so I changed my source port to 53. Then it was shown as open

#

When I done a -sV scan, the service was shown as TCPWrapped with no version but when I used netcat instead of Nmap, it gave me the banner. Why did Netcat work but not Nmap?

honest egret
vapid forge
#

Search for all lines that contain a word that starts with Permit.
what is the command for that

#

i tried
grep "permit"

rustic sage
#

it's case sensitive

#

you could also do grep -e '*ermit"

sterile solstice
#

anyone have some experience with double pivoting with Ligolo? i've gone through multiple tutorials (written and on youtube) and i cant see to get the pivot right.

vapid forge
vapid forge
rustic sage
#
  • = anything of any size
#

for instance anything ending in at = *at

#

so it would find for e.g (cat,bat,sat,etc.)

vapid forge
#

not specifically an extension

#

a word

#

Search for all lines that contain a word ending with Authentication.

#

like this one

karmic orbit
vapid forge
rustic sage
rustic sage
rustic sage
#

it's a windows box

honest egret
#

i dont wanna use parrot terminal to complete tasks. can you give me any solution

fallen hull
acoustic osprey
#

Linux: Filter Contents module Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

how to solve this question

rustic sage
rotund anvil
#

What is right channel to ask about problem related to subscription problem?

rustic sage
sterile solstice
#

last machine needed to complete AEN

#

spent around 4hrs going through ligolo tutorials on double pivots but nothing has worked lol

cedar void
sterile solstice
#

in general, support are quick to respond

rustic sage
gray yacht
sterile solstice
obtuse haven
rotund anvil
autumn pilot
sterile solstice
rustic sage
#

when using WinRM to authenticate over two or more connections, the user's password is never cached as part of their login.

obtuse haven
sterile solstice
obtuse haven
#

yet typing a command on ssh takes ages

scenic path
sterile solstice
obtuse haven
gray yacht
scenic path
sterile solstice
obtuse haven
#

plus meterpreter shells keep dying and have to do everything again

sterile solstice
gray yacht
sterile solstice
#

yea. i did notice some differences on my screen compared to the tutorials. its a relatively young software too

scenic path
sterile solstice
#

well i can just hope that the exam doesn't rquire too much more than AEN with jump hosts lol

scenic path
#

or maybe the other way around 🤔

obtuse haven
#

im mostly using meterpreter tunnels though

gray yacht
obtuse haven
#

i dont know how meterpreter handles it internally but i think it has its own multiplexing mechanism and just sends the data rather then sending the whole tcp segments

trail ingot
#

What is the API key in the hidden admin directory that you have discovered on the target system? inforamation gathering web edition

#

can somebody help on this question

acoustic owl
#

Apply all the techniques described in the module. Then you should find what you are looking for

cedar void
drifting lily
#

Hey, I am aiming to be a web-pentest, and so far, a lot of what i study on HTB seems kinda useless to study currently. Like, most of the Windows stuff seems good for administrator roles, not Pentest. Is there some kind of good path to take within HTB, that someone recommends ? I do know that i need a good grasp of TCP/IP, Linux, Windows, Protocols just for the basics.

high sundial
#

HTB offers a specific web pentesting path, I don’t know if you’re taking the normal pentesting path (CPTS) but I imagine you are. The web pentesting path is much more expensive though.

#

That’s also because CPTS isn’t a web specific pentest certificate or course, it’s tailored towards network pentesting, and the overall gist of it all

pseudo kiln
#

Eh I would say CPTS is 50% infra 50% web, the web portion is too big to consider it a network pentesting cert

drifting lily
pseudo kiln
#

Well both, the cpts path prepares you for the cpts cert

drifting lily
#

Gotcha! Thanks

analog dock
#

He already did

sacred gull
#

Oh sorry I gave it a quick check 😅

foggy monolith
rustic sage
#

anyone know why netexec with bloodhound doesn't work on AEN lab

nxc ldap 172.16.8.3 -u 'USER' -p 'PASS' --bloodhound --collection All --dns-server IP -d inlanefreight.local

#

I can ping the IP and I configured my .nxc/nxc.config

junior helm
#

I think I missed something here. Can anyone explain why both shells are the same julio user but see different files?

#

On the left is a reverse shell on RDP machine. On the right is a shell using evil-winrm

wicked apex
#

Module: Password Attack
Section: Hard Lab
Any alternative than ||smbclient for transfering large file||?
im getting parallel_read returned NT_STATUS_IO_TIMEOUT even switching from US to EU

#

its actually smbget

shut vapor
# junior helm I think I missed something here. Can anyone explain why both shells are the same...

I just finished this section too. I had a really janky reverse shell and, similarly, I couldn't see c:\julio even with "dir /a", but I was able to "type c:\julio\flag.txt". My only guess is it's some kind of synthetic barrier limiting traditional access to force you to use a reverse shell like the question asks of you. Your screen shot adds context so now I'm curious too if this is synthetic or whats going on.

foggy monolith
warm shuttle
#

hi

foggy monolith
#

Also, try to use PwnBox instead of your home system to access the VPN whenever possible if your personal network isn't extremely high speed; it's got a connection 10x faster than even my Verizon 5G Home Plus on the backend.

gilded radish
#

what weekly reward are there? I got 6 strike, but no rewards yet :/

rugged jewel
wicked apex
rugged jewel
fathom pendant
#

The creds worked fine for me

rugged jewel
#

Did you connect via xfreerdp?

fathom pendant
#

yes, using my own vm

rugged jewel
#

wow, xfreerdp works

fathom pendant
#

or in the login screen .\

#

@manic bramble 1) don't dm without asking 2) i suggest always following the basic steps the sections take, without copying 1 for 1 the results

manic bramble
#

my bad

#

i followed the steps i believe

#

nevermind then

humble stirrup
#

Hey Guys. Is pwnbox easier and faster to use than using a VM for parrot os?

I am currently using parrot os in a VM at the moment to do all hackthebox modules.

junior helm
mint linden
#

okay so I am working through the Active Directory Enumeration & Attacks and enumerating users. This is fine and works but does anyone know a way to extract the output of kerbrute so you just get the valid users in a list without:
2024/08/13 10:38:07 > [+] VALID USERNAME: emercer@inlanefreight.local

So I can just have a user list?

fathom pendant
fathom pendant
humble stirrup
#

@fathom pendant Ok thank you, Thats what I was thinking as well. I also like the experience of just using linux as my OS

fathom pendant
#

a few hiccups here and there but those usually get fixed fairly quickly if they're minor things

humble stirrup
#

ok perfect. I am on the Linux fundies so its a good start for me

#

thankyou

rustic sage
#

anyone know why netexec with bloodhound doesn't work on AEN lab

nxc ldap 172.16.8.3 -u 'USER' -p 'PASS' --bloodhound --collection All --dns-server IP -d inlanefreight.local

#

I can ping the IP and I configured my .nxc/nxc.config

rugged jewel
#

Spawn is already almost 10 minutes... How to stop it and restart?

rustic sage
#

refresh

fathom pendant
rugged jewel
#

No luck

#

Restart my laptop

mint linden
rustic sage
#

you can also try to start another target which will kill the other one

fathom pendant
rugged jewel
fathom pendant
#

note changing vpn regions (if using your own vm) you'll need to download a new vpn

rugged jewel
#

How it should help if spawning machine does not depend on VPN? I login into acc and just spawn a target in a module.

#

I need the VPN to connect to the target. But my target in spawning state and I cannot see the IP to which I should connect.

fathom pendant
#

the VPN region dictates where the machine/what endpoint/network is able to connect

#

it's why some solutions genuinely are "just change vpn regions"

rugged jewel
fathom pendant
#

yes

rugged jewel
#

oh yes, it helped. Thanks a lot)

onyx rapids
#

Still need help with that?

nova wharf
#

qq in the nessus vul assesment this question is asking about windows but my nmap shows linux is that a possble error?

shut vapor
#

Since you're not interacting directly with that system, they may have used a Linux box with Samba to simulate a Windows system just for convenience. 🙂

#

Oh, unless you're scanning 10.129.202.116 -- that would be a linux box on which Neesus is installed. From what I recall with those assessments you're connecting to Neesus that then has access to another network you don't have direct access to. This seems to throw some people off too.

nova wharf
#

ah okay thanks

#

do I need to include the ip as well that they have provided? I saved the two from earlier in the mod for the windows and linux machines

shut vapor
# nova wharf ah okay thanks

I fired up the module. You can SSH into the Neesus system and NMAP the actual windows target to fingerprint and get a Windows response. It's not material to the challenge though.

shut vapor
nova wharf
#

so what I meant was they gave two IP's earlier in the modul and thats where I got the win and lin IP address info

shut vapor
# marsh echo what your tools for screen ?

xfce-screenshooter -> paste into GIMP -> make selections using CTRL to make multiple selections -> Selection [menu] > Invert Selection -> and airbrush around the selections.

marsh echo
#

thx ❤️

shut vapor
fathom pendant
#

POG I successfully got CVE-2019-10945 (Joomla Directory traversal) to work in python3

#

with a little python 2to3 magic and googling

nova wharf
#

@shut vapor And I didn't know I needed to ssh in first I thought I just ran the scan from my local machine. I wasn't using the attack box

shut vapor
fathom pendant
#

also no, you don't need to ssh in as @shut vapor said, you just need to interact with the web UI https://<spawned_ip>:nessusport/

smoky valley
#

Hello guys
I wanna start participating in hackathons
What are some pre requisites I should know , my team should include what kinda members ,etc?

fathom pendant
nova wharf
#

okay I added the spwaned ip address to my nessus scan and I gave me results this time

compact patrolBOT
smoky valley
fathom pendant
#

go to; https://<spawnedip>:nessus_port (can't be bothered to look it up atm)

nova wharf
fathom pendant
#

from there

nova wharf
#

Im in the web us

fathom pendant
#

you can interact with the given internal IPs

#

or even pull up one of the pre-finished scans to work off of

nova wharf
shut vapor
#

Yea he's mostly on track.

fathom pendant
#

you don't need to add anything to YOUR nessus scan

#

you're one step forward two steps back

#

you're scanning the spawned IP there

#

which won't yield anything useful for the questions

shut vapor
#

Oh hah, I see that now too. Yeah, you can just look through the existing hosts and scan results to answer the question. By all means, play around with Neesus though, but you don't actually have to go through with scanning the targets. It's all in there already.

fathom pendant
nova wharf
#

Okay now your confusing me

fathom pendant
#

ok

#

in your browser

shut vapor
#

marcielee on point as usual

fathom pendant
#

do not go to localhost:nessus_port

nova wharf
#

so what was the point of setting up all of the stuff in the mod

fathom pendant
#

go to: https://<the target IP>:nessus_port/

fathom pendant
#

but the actual scan itself against the internal targets would take AGES

#

which is why they have pre-finished scans for you to do your searches against

nova wharf
#

okay

nova wharf
#

sorry I was starting get mad when you said I wasn't listening, now I'll admit when I was going through the mod I miss understood when it was saying to modify the hosts in the nessus scan it even stated it would take up to an hour for the scan to complete so thats why when you started saying I wasn't listenin it erked me

fathom pendant
#

well, because you weren't listening kek

#

you were hearing/reading, but weren't listening

shut vapor
#

It happens, communication can be hard.
Harness the anger. I do my best hacking when I'm just a little bit pissed off. 😜

fathom pendant
#

frustration leads to anger, anger leads to mistakes, mistakes lead to frustration

shut vapor
#

the real advice 👆

fathom pendant
#

when you find yourself committing the same basic mistakes, take a step back and walk away for a minute

#

or go take a nap kek

livid zodiac
#

potentially dumb question, can i have the modules and machines open on one computer and use pwnbox on a separate device?

nova wharf
#

my therpist told me to mention these things while there fresh so I don't hold on to feelings later

fathom pendant
#

yes

livid zodiac
#

ok perfect thats exactly what i meant

fathom pendant
#

i don't see why though considering the pwnbox is in-browser

#

but you do you honey boo boo

livid zodiac
#

just some dumb window errors

#

you know how the pwnbox window shows up at the bottom of the module pages?

fathom pendant
#

oh

livid zodiac
#

if you open it in a fullscreen instance and go to a new module that also has a pwnbox, the window dimensions get destroyed lmao

fathom pendant
#

yeah even on another machine that will still happen

livid zodiac
#

and you have to refresh the box window to make it go back to fullscreen

#

dang really

fathom pendant
#

as it's drawing from the latest updated resolution

livid zodiac
#

any way to work around it?

fathom pendant
#

nope

livid zodiac
#

thats tough

fathom pendant
#

just gotta live with it

#

the work around is using your own vm Kappa

nova wharf
#

thats what I was going to suggest

livid zodiac
#

yeah i gotta set something up, the annoying bit is im not entirely sure if my pc has the space required and my other device is an m1 macbook

fathom pendant
#

you can run vms on an M1

livid zodiac
#

i thought the whole ecosystem was incompatible?

fathom pendant
#

UTM/parallels is the best solution for ARM/MX chips

#

no

livid zodiac
#

ah yeah ive heard of parallels

#

is that subscription based or is it a flat fee

fathom pendant
#

parallels is paid, UTM is free afaik

livid zodiac
#

ill look into utm

fathom pendant
#

i'm not in the Mac ecosystem so idk

nova wharf
#

I think its the ARM version for M1 thats what I'm using for my kali vm

fathom pendant
#

yup

#

different machine code insctructions

ember fern
#

never got UTM working myself

livid zodiac
#

ill check out the utm site and see if i can get anything set up, thanks for the advice

ember fern
#

although I tried to emulate not virtualize

#

so virtualization may work

fathom pendant
#

ARM = Mac/MX chips
AMD = All other systems

analog dock
#

Also the new snapdragon is arm

livid zodiac
#

do you guys prefer kali or parrot? i feel like im slightly more familiar with kali but im honestly really digging the pwnbox setup

#

found a repo on github that can emulate the pwnbox feel on a fresh parrot installation and im thinking of setting that up

analog dock
#

Kali

#

But just use whatever you like

nova wharf
#

I like kali I tried the parrot but couldn't get rdp to install properly so I went back to kali where I knew it would work. But that was mostlikly user error

#

there is also a ippsec walkthrough for setting up a pwnbox like system using parrot

civic hamlet
#

@fathom pendant

Windows fundamentals, Windows security

What 3rd party security application is disabled at startup for the current user? (The answer is case sensitive).

Could I get a hint? So far ive broken down the problem into, 3rd Party, deals with security, Process that (normally) runs at the boot, inferring its a service, but its stopped at boot.

im using powershell to query for a display name that does not have windows, microsoft, and has a stopped status. Im still recieving too many services to think my query is correct

fathom pendant
civic hamlet
#

anyone?

nova wharf
bright shore
#

Hello @fathom pendant thanks for the response wondering if you had some time to help quickly

calm tapir
#

Currently doing Module: Web Attacks , Section : Mass IDOR Enumeration.
I'm not sure where I'm going wrong here, I've used Burp Suite intruder to go through the first 20 uids but nothing. I've inspected the HTML source code and still have not found anything referencing to a .txt file. Manually inputting the uids just show a the same page without any documents listed. Any tips?

bright shore
#

module/176/section/1778 - I used smb to get the spn.txt but not I don't know how to run Hashcat or JohnTheRipper to crack the Kerberos hash file.

nova wharf
#

so Im trying to install the mysql server on my kali and I get this error. has anyone found a work around I looked on stackoverflow and only thing I could find was to install MariaDB

fathom pendant
fathom pendant
#

when you intercept the request you should see that it's a POST not a GET request, so you have to adjust your coding accordingly

fluid pivot
#

Hello everyone! I just started HTB Academy last week. I'm doing HTB Academy >> Linux Fundamentals >> Page 7 / Navigation. The question is asking me, "What is the index number of the "sudoers" file in the "/etc" directory?"

STEPS TAKEN:

  1. I change directory to /etc
  2. I use the command "ls -i | grep sudoers" to display the inode number.

RESULTS:
I get the following output:
1851558 sudoers
524086 sudoers.d

ISSUE:
I put 1851558 in the answer field and it says incorrect. I also put 524086 just to humor myself, but still says incorrect. Could this be a glitch, or am I doing something wrong? Any clarity on this would be greatly appreciated. Thanks!

fluid pivot
fluid pivot
livid zodiac
#

another potentially dumb question. i just got a vm setup running parrot security. for some reason it wont allow me to use pip3 install? says its an externally managed environment.

#

when i try to run apt it throws an error that says it couldnt get a lock on the frontend