#modules

1 messages · Page 328 of 1

fathom pendant
#

There might be

#

Maybe url encode as you type and hit enter

rustic sage
fathom pendant
#

I mean you can manually type it lol

rustic sage
fathom pendant
dim wolf
#

Attacking GraphQL will be replacing Session Security, huh..

dim wolf
#

i've experienced this only two times. every other question was fair

loud dagger
#

it’s not consistently it’s only been a few times

dim wolf
#

if you are having trouble, you might have to reread the section/module again and perhaps do some additional research to fill in the gaps

acoustic owl
limber river
#

tbh session security wasn't the best module

#

I am expecting a big change on CBBH

#

a lot of new modules

dim wolf
#

i'm wondering how they're going to teach CSRF now since Session Security was the module that introduced it

#

CWEE has Advanced XSS & CSRF Exploitation so it has to be taught in some module

limber river
#

maybe they will add it to xss module

vocal river
#

After crawling the inlanefreight.htb domain on the target system, what is the email address you have found? Respond with the full email, e.g., mail@inlanefreight.htb.

What is the API key the inlanefreight.htb developers will be changing too?

i need help with these questions from Skills Assessment Information Gathering - Web Edition cbbh

vocal river
#

it tells me the IPstack api key not found

fathom pendant
#

?

#

Ah

#

That's the wrong reconspider my guy

vocal river
#

how can i do it ?

fathom pendant
#

There's one provided by the module

#

There's a command given to download it

vocal river
fathom pendant
vocal river
#

ok thanks

stark lark
#

How do I make this bigger

fathom pendant
#

But fr just drag it

stark lark
#

It is fullscreen and I tried to drag it all I can

fathom pendant
#

Where the 3 dots are

#

Drag that up

#

If that's as big as it gets you need a bigger screen or window

stark lark
fathom pendant
#

Then you have a shit resolution

#

¯_(ツ)_/¯

stiff bone
storm elk
topaz cliff
#

In the current Broken Authentication assessment, a fuzzed user was found, but the password was not found using the same wordlist (10 million used in the module). It seems that another wordlist may need to be used. Any help, please?

acoustic owl
topaz cliff
stark lark
storm elk
#

If the server responds with a Set-Cookie: name=value, your next request should contain the header Cookie: name=value

candid notch
#

i have problem i am scanning using the IP address mentioned in the modules but NMAP tells me the host is not available ??

candid notch
#

ok

distant island
#

i have a stupid question if now the questions is find the flag on the desktop of user SQL01 i am on the skill assessment 2 in AD module
how can i know the ip of SQL01

distant island
#

and what if there is like 50 users in the AD

autumn pilot
#

How would be the two related?

#

Are you assuming that every user has a machine?

distant island
limber river
distant island
#

its literlly learning its called ACADEMY

fathom pendant
#

Well if you have a foothold on one of the windows machines, often you can ping <hostname>

fathom pendant
limber river
fathom pendant
#

Nothing to do with it being academy, but pings hell nmap scans with -sCV may reveal hostnames

#

I believe the second assessment gives you a parrot foothold that's sitting in the network

limber river
fathom pendant
limber river
#

yeah exactly this part

fathom pendant
#

Otherwise it looks like you're linking him to the module he's doing 😉

#

Oi no spoilers

#

Also I'm assuming you added -Pn to the scan

distant island
#

-sn

limber river
#

-sn ?

distant island
limber river
#

why ?

distant island
#

to see the open IPs

fathom pendant
#

Well -sn won't run port scans, and you said you found 3 ips, put those in a list

distant island
fathom pendant
#

Are you sure you're using the right exploit

limber river
fathom pendant
#

You're not understanding the breadth of what I'm saying

#

You have ips

#

You can utilize port scanning to discern which hosts are which

#

Such as -p 3306

#

For mssql

#

Or 1433/1444

#

Again basic service enumeration can go a long way

distant island
# fathom pendant For mssql

yes i got what u r saying but is this the only method cause if i am in a big env with like a huge number of ips it will be super hard

fathom pendant
#

Don't overthink this

#

You're literally hindering yourself because you're overthinking

#

You have a small environment so don't think too hard

distant island
fathom pendant
#

What ifs are fine and all; but you're not in the what if

#

You're in a specific scenario

placid edge
#

Hey, so im currently super stuck on the Attacking Authentication Mechanisms module during the SAML Signature Wrapping Attack. Anyone that i can dm for advice on my XML payload, cause for some reason it is not working...

fathom pendant
#

Also the key bit of the "a firm grasp of the following..." is the pivoting module

mellow flicker
#

Hi

hazy laurel
#

is it possible that bloodhound doesnt show all the permissions a user or group has over other users and groups?

fathom pendant
#

And you'll need to run another collection

hazy laurel
#

is that because the user that ran sharphound doesnt have read rights over that user /groups acls?

distant island
#

And so on

hazy laurel
#

that makes sense

#

thank you

distant island
#

This is why its also advisable to recollect data if you managed to escalate preivlage or pwned a higher value user in the domain

rustic sage
#

how to delete zombie files

vivid sigil
#

i tried 3 diff wordlist non of them work, what should i do

What is the FQDN of the host where the last octet ends with "x.x.x.203"?

module:/Footprinting/DNS

night terrace
#

Are we not allowed to type the answer on the tasks anymore? Now it’s a “ show answer” sup with that?

placid edge
#

anyone done Attacking Authentication Mechanisms - SAML Signature Wrapping Attack here?'

steep loom
#

It appears liike the flag for Injection Attacks in the brand new Attacking GraphQL module is not working.

anyone else have this problem?

placid edge
#

<@&861185840277487616>

#

i think this is how that works at least

rustic sage
#

@steady dock has been typing for ages

fathom pendant
#

The missing info is just a query that didn't return in time

steady dock
fathom pendant
#

Often you may find info sharphound/bloodhound misses and vice versa

#

Because the user didn't delete their message

steady dock
#

I though the mods removed them

#

whatever though

glad frost
#

Hi everyone,

I'm working on the Injection Attacks Skills Assessment. I managed to find ||xpath injection|| on the internal app. However, when I dump the data, I'm unable to fully display the output. When I try to get each element at a time, I'm not succeeding. If anyone could provide a small nudge, I would appreciate it.

spark spruce
quasi wave
#

hi I am literally following along with the section that seems to want me to follow along. the section is Attacking SAM section of Password Attacks module. I am doing the exact command it says to do and it won't let me do the command on Windows and it can't find the share even when I specify a share network I just created on Linux.

#

I don't want to share actual content publicly because I know that's not allowed in Tier 1.

#

anyways, can someone help me out here?

marsh echo
#

Did you run your cmd as administrator

quasi wave
#

yes

#

cmd is run as admin. I can close and open it again but I'm 100% sure it is being run as admin

#

in fact it even says "Administrator" at the top of the cmd prompt

#

brb

marsh echo
#

You try to run reg.exe rigth ?

#

Do you find yourself in the System32 directory? For dump the file into Of their respective repertoires

quasi wave
#

I'm in C:\

#

and on linux I have the Python script running

marsh echo
#

On C:\Windows\System32\

#

Execute the command

split marsh
#

Hello all.
I’m just starting out on HTB academy, Linux essentials and I’m trying to figure out the questions at the bottom but some of them I feel so lost like I’m missing a piece of the training I should of read or should know already but I was recommended this by HTB as the one to start off with. I’m unsure if this is the right place to say this or even if I’m wrong. It feels like I’m tier -1 and I’m so lost. If anyone could dm me give me tips on what modules I should do first?

quasi wave
#

hi I think I may have solved the problem

marsh echo
#

And mv the result on C:\ or I imagine there is your sharing

quasi wave
#
c:\>move sam.save \\10.10.14.143\CompData                                                                               Access is denied.                                                                                                               0 file(s) moved.```
#

I had to change the IP address

#

but it still denies access to move it to Linux

marsh echo
#

Move Sam.save \ip\compData work for me did you run smbserver with sudo ?

quasi wave
#

I did run it with server but had to modify which Linux user I was transferring it to

#

now its fixed

marsh echo
#

Okok yes I forgot to ask if the directory existed NotLikeThis

quasi wave
#

what folder in Linux do I look for to list the files?

#

wait found it

echo pilot
#

i'm stuck on modules 18 section 78, im trying to find the name of the last modified file in /var/backups but I can't figure it out.

#

i've tried ls -it and looking through the directories file but I still can't find it

#

can someone give me a hint?

fathom pendant
bright shore
#

@fathom pendant do you know if I rdp from the bob's windows machine or do I do it from my machine to trigger event 4771?

fathom pendant
#

From bob

#

As the DC is an internal machine

bright shore
#

Okay I tried this I will reset the target Ip and try again

vivid sigil
#

how can i get email address from IMAP/POP3 ?

fathom pendant
#

You ask it nicely

#

But imap and pop3 have different syntaxes

#

<literally anything> command <args> is the basic imap structure

distant island
#

can i use printspoofer or rouge potatos without metasploit

fathom pendant
#

Yes

#

They exist as standalone portable executables you can download

#

At least prinspoofer does

distant island
fathom pendant
#

Running a command using printspoofer?

#

NC isn't a privesc tool. It'll execute under the user context of whomever launched it

distant island
#

this return as a normal user but it help with escaping the sql

#

how can i excute the printspoofe the right way

#

for priv esclation

safe star
fathom pendant
#

^

#

Working through wonky pseudo shells isn't fun

distant island
fathom pendant
#

Also I think sql doesn't like \ paths

#

Could be wrong though

bright shore
#

@fathom pendant am I doing something wrong? sorry the chat is overloading on you but I tried again and 4771 doesn't appear anywhere

safe star
#

i didnt know about the print spoofer exploit then, so i just ran a base64 powershell reverse shell

fathom pendant
distant island
fathom pendant
#

Or -e cmd

#

So it can actually execute stuff somewhat properly

distant island
fathom pendant
#

¯_(ツ)_/¯

distant island
lofty scarab
#

hi

#

Is there a path in Tryhack me for web penetration testing?

distant island
lofty scarab
#

or web

lofty scarab
distant island
#

Under job role path

lofty scarab
#

i have my ceh exam tomorrow

distant island
#

Good luck

lofty scarab
#

thanks my men

sly citrus
#

SOEMON

distant island
#

<@&861185840277487616>

sly citrus
sly citrus
cerulean hinge
#

Hello,
I'm doing the FootPrinting Skill Assesment "Easy" but I'm currently stuck
So I started by performing an nmap and found 4 interesting ports.
For both FTP ports I can login using the credentials provided but I can't do any enumeration. Each time I use ls or any other command I have the following message (see screenshot).

For the DNS enumeration I found several subdomains & IPs but nothing helping me to retrieve the flag.txt.

PS : I managed to retrieve the files using wget but I still don't understand why using ftp command I couldn't retrieve anything.

rustic sage
#

anyone got a way for fixing this problem whenever i boot my kali linux up?

#

using a VM for it

cloud urchin
#

use a better hypervisor like vmware workstation pro (its free now) or change your graphics controller to vboxsvga in settings

rustic sage
#

i've been using a virtualbox my whole life

cloud urchin
#

ok then change the graphics controller

distant island
rustic sage
cloud urchin
#

it says right there what your error is

rustic sage
cloud urchin
#

'vmwgfx seems to be running on an unsupported hypervisor'

rustic sage
#

ah

echo pilot
distant island
#

so i am on the last part in the skill assessment 2 in htb i finished all but i am only stuck here cannt login to user

#

AD moule in CPTS

cloud urchin
#

what's the actual thing you're stuck on unless you literally mean you can't log in.. in which case what's the error

distant island
#

but cannt login to him

cloud urchin
#

that's a lot of words with no real substance as to your actual issue

#

if you have domain admin, you can do whatever you want, including log in

distant island
cloud urchin
#

is your keyboard plugged in?

safe star
cloud urchin
#

"i can't log in" isn't describing the problem in any way that anyone can help you

#

you can't log in.. to what? with what app? what syntax? etc

#

you're saying absolutely nothing about your actual problem

safe star
#

iirc having rights over something does necessarily mean ur in a group

cloud urchin
#

bruh you are giving away way too much of the module

distant island
safe star
#

😭

cloud urchin
#

it is, you spoiled the username

cloud urchin
#

and how to abuse it etc

safe star
#

Have u thought about adding ur self first?

distant island
#

sorry i am kinda brain fried ngl

distant island
#

but dont know how

safe star
#

Powershell?

cloud urchin
#

he said his problem was that he couldn't log in

distant island
distant island
safe star
#

Login which way?

#

If u have domain admins why not dump creds

distant island
safe star
#

Ye

normal sand
distant island
normal sand
distant island
#

In some instances u will not be able to run scripts at all or even create and save ones

cloud urchin
#

no, this is privesc, not evasion

normal sand
#

Module: Linux Privilege Escalation
Section: Wildcard Abuse
Link to section: https://academy.hackthebox.com/module/51/section/473

In order for this to work, the cron job should be running with root privileges, right?

Also, I'm assuming that the wildcard character * goes alphabetically? Since it'll take the checkpoint arguments first?

normal sand
safe star
#

if u edit the path it will run urs first

leaden hound
#

hello everyone I'm new to htb, how does the module works in htb academy? I would like to do the cpts module path, does it has a limited time for access ? sorry for repeating this question as I'm not sure where to ask

cloud urchin
#

any binary like TLattice said

safe star
#

yeah like "ls" shown in the module

#

it will go to your directory first then check /bin

sacred gull
#

In the Windows Evasion Techniques module, is there a supposed to be an IDE installed to compile programs?

#

Or do I need to compile everything on my machine and then move it over?

normal sand
cloud urchin
#

you could use it to run whatever command you want

normal sand
#

Nvm, I just realized as long as permissions are there, it can be done, my bad.

safe star
#

i think cronjobs have the path as the user running it

#

so yeah, it wont run through ur path

normal sand
sacred gull
#

No because you might have permissions to execute a file. But within that file it executes commands with root privileges or you might have the power to run the binary with sudo

safe star
#

yeah, u need to be able to execute it

proud pine
#

If you don't want to install tools locally, you'll have to bounce between firing up the VMs in each section, and the original development VM.

cloud urchin
#

honestly i used my own comp because it was slow a f

sacred gull
sacred gull
proud pine
sacred gull
#

Okay thankyou, you'll probably find I will

normal sand
cloud urchin
#

what?

normal sand
#

Does it list every single file name in that one command?

cloud urchin
#

* is a wildcard for any character and any number of characters

normal sand
cloud urchin
#

no

#

it'll run them separately

#

it doesn't just run anything in the folder

normal sand
# cloud urchin it'll run them separately

Separately? So like this?

tar -zcf /home/htb-student/backup.tar.gz --checkpoint=1 

tar -zcf /home/htb-student/backup.tar.gz --checkpoint-action=exec=sh root.sh

tar -zcf /home/htb-student/backup.tar.gz somerandomfile.txt

tar -zcf /home/htb-student/backup.tar.gz root.sh
cloud urchin
#

the file names are arguments for the tar command. it only executes the thing you have after exec=

#

yeah like that

normal sand
#

Like I'd expect the first command to throw an error and maybe even the second.

cloud urchin
#

no 1 and 2 are the same command

#

they're just arguments into the tar command

normal sand
#

I'm confused as to how that works, still don't understand how it processes the * wildcard.

empty trout
#

i was wondering that is there any nse script which will tell the contents of robots.txt file i have seen many time that it displayes the content of that file . i used -sC default script option

cloud urchin
#

* is just a wildcard in linux itself. if you have file1.txt file2.txt file313137.txt, you can type "rm file*.txt" and it will delete all three files. if you typed "rm file?.txt" it would only delete file1.txt and file2.txt, because the ? is a wildcard for only one character while the * is a wildcard for any character and any number of characters.

#

that's all it is, is a wildcard that can replace characters

normal sand
normal sand
cloud urchin
#

essentially you're telling tar to backup all the files, but you hijack the command with filenames that act as arguments to the tar command

#

tar -zcf /home/htb-student/backup.tar.gz --checkpoint=1 --checkpoint-action=exec=sh root.sh somerandomfile.txt root.sh this is correct

#

you're telling tar to backup all the files in that directory, but because the filenames are also tar arguments it triggers that action from tar, in this case an action is executing your script

safe star
#

Chatgpt can also explain some topics in your preference too @normal sand

normal sand
normal sand
normal sand
# cloud urchin https://medium.com/@polygonben/linux-privilege-escalation-wildcards-with-tar-f79...

Btw follow up question, I already tried asking GPT, but it didn't really provide an explanation. In the man page for tar, it states the following:

--checkpoint-action=ACTION
              Run ACTION on each checkpoint.

In our command, we use the exec action but I didn't find this to be specified anywhere in the man page. And when I asked GPT, it just said that it's not mentioned in the man page but it's well-known.

So, if I wanted to perform wildcard abuse like this but on another binary, I'll just have to Google and see if the other binary has got some sort of execution parameter since it may not be specified in the man page?

balmy egret
#

can someone help me I'm tring to solve the question Within the "webfuzzing_hidden_path" path on the target system (ie http://IP:PORT/webfuzzing_hidden_path/), fuzz for folders and then files to find the flag. in the Directory and File Fuzzing module and whatever I do I can't find the hidden path?

#

I tried finding hidden 301 pages the only one that comes up are w2ksvrus and any HTML page I open up says this is a example page

crystal ruin
#

for pivoting skill assessment, am i supposed to be able to rdp to the last dc? thinkw thinking that rdp is fried rn

empty trout
#

if someone configured a firewall to resoponde with rst flag nmap will consider it closed and if the port is actually open so how can we determine the state here

hexed lintel
#

netexec indicated user Johanna cannot rdp
but i am able to rdp using xfreerdp

#

can anyone clear my confusion here.

safe star
eager ledge
crystal ruin
crystal ruin
#

doesn't look like it's domain joined

hexed lintel
grand portal
#

im here to rant. why are remote rdp machines so slow? registering a click takes 10 seconds.

normal reef
#

Hey how do i install httpx on windows

acoustic owl
normal reef
crystal ruin
vivid sigil
#

anyone finsh footprinting module
i need hint

silk lagoon
vivid sigil
safe star
#

need more details

silk lagoon
#

for what question

vivid sigil
# silk lagoon for what question
  • 1 What is the FQDN of the host where the last octet ends with "x.x.x.203"?

i tried all subdomain@

how can i use dnsenum for sub subdomain

blissful elm
#

do we get access to tier 2 maacine in 38$gold sub?

#

or only cubes

acoustic owl
#

monthly subscriptions, except the student subscription, only give cubes

blissful elm
#

i was using the student sub before which give access till tier 2 i though gold one will give same exp but with 500 cube but it seem it only give cubes

acoustic owl
#

Only the annual subscription gives access to the modules.

#

The monthly subscriptions give you cubes so that you can unlock modules

blissful elm
#

ok

silk lagoon
#

that should initially have given you a subdomain

normal sand
hexed lintel
#

what am i wrong doing here?

hollow ibex
hexed lintel
polar flint
#

Hey I have a question about the SQL module. Can someone explain why one is wrong and the other is right. I find it very contradicting

hexed lintel
#

notAdmin doesnot exist so it fails the login attempt

polar flint
#

it returns a true

hollow ibex
# hexed lintel

python3 /usr/share/doc/python3-impacket/examples/mssqlclient.py <USERNAME>@<TARGET IP> -windows-auth try this might work

blissful elm
#

guys , i have 1000 coins and wanted to open the modules based on web security , i have ssecure js 101 in mind or advanced xss/csrf,Modern Web Exploitation Techniques which one should i try first

#

JS cost 1000 and other two combined cost 1000

hollow ibex
hexed lintel
vocal river
#

1- What is the API key the inlanefreight.htb developers will be changing too?
[ creepy crawling ]

2- After spidering inlanefreight.com, identify the location where future reports will be stored. Respond with the full domain, e.g., files.inlanefreight.com
[skills Assessment]

what is the answer for these questions from ( information gethering web edition )

exotic copper
#

please can someone help with attacking session cookies

shut vapor
#

you can fire up sqlite and play around with it, that helps me at least

#

I'm trying to find that section to take a look. The only question I might have is the stacked username = '...' or '1'='1' and password='something'... it can depend on how those and/or statements are evaluated. I didn't add password in my example above.

acoustic owl
green musk
#

Anyone can help me with smb-os-discovery nmap script I'm trying to usd it but it shows me just port not script output

shrewd bolt
#

try to run it with -sC

#

or with verbosity

green musk
green musk
shrewd bolt
#

what module / section is this from

green musk
shrewd bolt
#

can you list the shares with smbclient?

green musk
#

I tried to use other nmap scripts such as enum user and those too doesn't working out for me but in msfconsole auxiliary are working fine for me

shrewd bolt
#

not sure then, i dont have notes on the module so cant verify what i did

#

your command looks correct tho

#

if the script files are propely installed and placed where they're supposed to be it should work

green musk
next bronze
#

also probably run it as root

rough tree
#

Anyone who managed to pass the check on the last question of Active directory bloodhound skill assestment?
Seems like no number works :/

next bronze
#

that quesiton is kinda cooked

green musk
acoustic owl
next bronze
#

some users didn't get counted

rough tree
next bronze
#

don't round up kek

next bronze
rough tree
acoustic owl
vague tundra
#

Hello

vague tundra
#

Is there a phishing module?

acoustic owl
vague tundra
green musk
vague tundra
#

I am tasked to figure out why our phishing campaign is going to spam folder and to propose solutions

fathom pendant
acoustic owl
fathom pendant
#

^

vague tundra
acoustic owl
#

No, there is no module about it.
But as I said, your company has done its homework and configured the mail server correctly.

rustic sage
#

Hello guys! Anyone know a good resources for SELinux, AppArmor and TCP Wrappers?? I’m on “Linux Fundamentals”
Thanks

quiet trout
quiet trout
# rustic sage Hello guys! Anyone know a good resources for SELinux, AppArmor and TCP Wrappers?...

For SEL These were the two best resources I found. One of course is the fedora stuff... the other is a walkthru. Im sure theres others but this got me familiarized pretty good.

https://www.computernetworkingnotes.com/linux-tutorials/selinux-explained-with-examples-in-easy-language.html

https://docs.fedoraproject.org/en-US/quick-docs/selinux-changing-states-and-modes/

vague tundra
fathom pendant
cerulean hinge
#

Hello,
I'm currently doing the FootPrinting Skill Assessment - Hard.

So I started by an nmap with -sC -sV and on all ports and found ports linked to Imap/POP3 and the ssh port are open.

I tried to apply what I learned in the module but without any creds I couldn't get any useful information. I also tried to do some brute force without any success.

fathom pendant
#

Those are 100% optional

quiet trout
cerulean hinge
rustic sage
quiet trout
rustic sage
quiet trout
#

Its not essential to the module, but its no less important

rustic sage
fathom pendant
#

¯_(ツ)_/¯

quiet trout
# rustic sage Thank you 🙏

it seems i skipped tcp wrappers, if you find a primer that you find enjoyable and wouldnt mind sharing i'd be appreciative. i think i have just the tcp wrapper notes from the module, havent "done" it though.

fathom pendant
#

Have fun

rustic sage
fathom pendant
#

It was sarcasm lol

#

Setting up any stuff like that is not fun

pastel zodiac
#

Good afternoon

I have gone into /etc/hosts.

10.129.201.90 gitlab.inlanefreight.local
10.129.201.90 inlanefreight.local

The thing is, I have to find more subdomains. I make a ffuff

ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt:FUZZ -u http://FUZZ.inlanefreight.local

And it does NOT find subdomains.

If I incorporate the subdomain in /etc/hosts.

10.129.201.90 gitlab.inlanefreight.local
10.129.201.90 inlanefreight.local
10.129.201.90 blog.inlanefreight.local

It does find it, launching exactly the same command with the same dictionary

blog [Status: 200, Size: 50120, Words: 16140, Lines: 1015, Duration: 892ms]
gitlab [Status: 301, Size: 339, Words: 20, Lines: 10, Duration: 7ms]

Does anyone know what's going on here? Shouldn't it find it even if it doesn't have an entry in hosts?

fathom pendant
normal sand
fathom pendant
#

While normally used interchangeably, when fuzzing it does matter

#

What your current fuzz command is doing is trying to fuzz using public dns

green musk
fathom pendant
#

And asking public dns "hey do you know where x.inlanefreight.local is"

quiet trout
fathom pendant
pastel zodiac
#

@fathom pendant and @normal sand BINGO! thx a lot!

green musk
fathom pendant
#

Ok?

#

There's also multiple ports tied to smb btw, not just the one

#

I believe the reading goes over this

#

And it goes beyond scanning

green musk
next bronze
#

what are you trying to find?

fathom pendant
green musk
#

Script isn't giving any outputs

normal sand
# green musk Os version

Then it doesn't have to be done via that script, right? How about running an aggressive scan or OS fingerprinting?

fathom pendant
#

Everything you need is provided by the section. Beyond just scanning

green musk
green musk
fathom pendant
#

This is the footprinting module yeah?

normal sand
fathom pendant
#

I didn't see where you clarified the module you're working on

green musk
quiet trout
#

@green musk do you need the exact OS or just a is this windows/linux? you can check the TTLs 64 = linux 128 = windows. this can give a rough estimate.

fathom pendant
next bronze
#

huh where in the section did they ask you to find the os version

green musk
fathom pendant
#

But none of the questions ask about OS version

next bronze
#

-A does return the os version

#

just ran it

green musk
fathom pendant
#

You're heavily overthinking it

#

Also your image was removed bc it didn't embed

#

Yep the scan discovered the os btw

#

Whatever file format its being saved as isn't supported by discord embed btw

green musk
fathom pendant
#

Dude

#

Fuckin

#

Look at

#

The output

#

Of the image you took

#

Os: ..

green musk
#

Yes I can see that but when I'm trying to input that same command to my kali instance it doesn't show me host script results::

fathom pendant
#

Ah

#

Well

#

it's not important

#

It's not integral to answering the questions

green musk
fathom pendant
#

Just ignore it and move on

#

The only thing I could maybe say is reinstall nmap or make sure it's updated

green musk
fathom pendant
#

¯_(ツ)_/¯

quiet trout
#

sudo nmap ?

#

theres instances where you need to run it as sudo, cant remember the specific scneario(s) at the moment, worth a shot

#

chatgpt suggests OS Detection might be one scenario, though they suggest a diff cmd for this, Example Command: sudo nmap -O -sV <target>

#

take that with a grain of salt.

fathom pendant
quiet trout
#

right on

fathom pendant
#

At least I think

#

At least -A is

#

Which does a whole lot of nmap commands wrapped into it

inner arch
#

Does everyone have a connection to their machines?

fathom pendant
storm elk
#

English please

#

Marcie is too fast

compact patrolBOT
humble prairie
#

Hello, I'm new here. I have just completed my degree in computer systems security. I was very keen to develop my skills in this area and I am open to your suggestions on how to become an ethical hacker.

humble prairie
#

@fathom pendant I want a plan to be competent in IT security

storm elk
#

Get it from the link above, and follow academy modules

#

choose a path

humble prairie
#

@storm elk All right dear thank

#

@storm elk send the link please I don't see it

compact patrolBOT
granite estuary
#

This is my second message here since 2022

#

Op

fathom pendant
#

Been here for 2 years, still haven't linked to access #general

fleet pawn
#

Hi. Im trying to open the vpn of the academy in the linux terminal with "sudo openvpn academy-regular.ovpn" but there is an error "Options error: In [CMD-LINE]:1: Error opening configuration file: academy-regular.ovpn". What is happening?

fathom pendant
#

If it's in your Downloads folder you'll have to cd Downloads

#

Then run

fleet pawn
#

its in desktop

fathom pendant
#

Then you'll need to cd ~/Desktop

fleet pawn
#

ok ty

#

i will try

fathom pendant
#

When you open a terminal it Defaults to home

#

/home/<your username>

#

Which is what ~ is usually aliased as

fleet pawn
#

Ty man now it works.

#

I have to do this everytime i want to connect to a htb vm?

fathom pendant
#

Only once per session, not every single time

#

You can do as many modules as you want with that one connection

olive grove
#

"TRX leaves his mark", Can anyone give me a clue? FullHouse Machine

olive grove
#

on my private please

#

i not have access

storm elk
#

Please read #welcome and #rules 🙂 it will explain how to get verified

fleet pawn
#

what i have to do to connect to a htb vm? the command says error conneting to that ip

#

The authenticity of host '10.129.105.95 (10.129.105.95)' can't be established.
ED25519 key fingerprint is SHA256:PHsjpBEAl6hSCzjVohppUybupbLXdBZy8FqtwlMpmjU.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])?

olive grove
fleet pawn
limpid hemlock
#

Hey im doing the attacking thick client applications section i try to change permisions of temp folder but i cant understand how to do it by reading whats written in this module could anyone help me out

fathom pendant
#

It's a windows basics thing

#

Disable inheritance--> remove your user from having delete access

fleet pawn
#

What is the path to the htb-student's mail?
Which shell is specified for the htb-student user?
I dont know how to resolve that 2 questions with the info in the linux fundamentals module.
Maybe is bc i dont understanding the question english is not native language

fathom pendant
#

A lot of the required tools are given

fleet pawn
#

Ok i will search info about that command

fathom pendant
#

Literally just run it

fleet pawn
#

ye i see but idk why is show that info haha

fathom pendant
#

env lists environment variable details

#

man env

fleet pawn
#

ok

empty trout
#

hey i was solving firewall evasion lab and when refreshing the status page of alerts of the target it is automatically increasing and i dont even started scanning . is it bcz different user are on the same subnet and scanning the same target

fathom pendant
#

No

#

Labs are independent

#

It's just like that

#

I wouldn't worry too much about the status thing

sacred jacinth
sacred jacinth
empty trout
#

if i refersh the page it should increase by one but it is increasing like 80 to 85

sacred jacinth
#

just carry on with your lab

fathom pendant
#

I ignored the status page entirely

#

Only if the box stops responding you should check

dapper birch
#

Hello guys, when accessing the labs in the module "API Attacks" the target fails to come up and the status continously reads "Target is spawning". Can anybody assist me.

fathom pendant
#

Change vpn regions

#

Hard refresh page

forest gust
fathom pendant
forest gust
fathom pendant
#

You can edit the library it's calling directly

fleet pawn
#

is it the terminal where i start the vpn all the time "typing"?

forest gust
fathom pendant
#

Or at least not that I remember

#

Linux privesc module yeah?

forest gust
#

yep

fathom pendant
#

Oh

#

It's because you're doing ./

#

Do the full filepath

#

The way to interpet the sudo command is that it's explicitly stating a path

#

You might get away with dropping the ./

fathom pendant
#

Try the other things

icy marsh
#

#modules I'm stuck in kerberos attacks unconstrained delegation - computers part .

C:\Tools>.\SpoolSample.exe dc01.inlanefreight.local sql01.inlanefreight.local
[+] Converted DLL to shellcode
[+] Executing RDI
[+] Calling exported function
TargetServer: \\dc01.inlanefreight.local, CaptureServer: \\sql01.inlanefreight.local

I ran multiple times but not able to capture the dc01 hash on rubeus. what is going wrong.

fleet pawn
quiet trout
forest gust
fathom pendant
#

SETENV <

fleet pawn
#

now i think im in but its too slow i cant type

#

ssh: connect to host 10.129.245.60 port 22: No route to host

#

I have that problem

limber river
fleet pawn
#

they are all medium load. Maybe is that the problem?

limber river
#

try to ping 10.129.245.60

fleet pawn
#

its what im pinging

limber river
fleet pawn
#

I dont know man im new. I just try to connect to a htb vm using ssh htb-student@[ServerIP] and that error appears

#

I tried with diferent IP refreshing them

fathom pendant
#

What error appears?

fleet pawn
#

ssh: connect to host 10.129.245.60 port 22: No route to host

fathom pendant
#

Nvm I scrolled up

#

Connect to vpn

#

If you changed vpn regions you need a new download

fleet pawn
#

im already connected

#

i will try to download a new file but...

fathom pendant
#

But?

#

If you change vpn region you need to use a new file

#

Otherwise you're not gonna connect

limber river
#

and send us the output

#

it's hard to help without knowing what's the problem

fleet pawn
#

it worked now. I just regenerate everything after deleting "sudo killall openvpn"

limber river
#

so something was wrong with VPN

frosty ferry
#

Do i need to know everything that's taught in linux fundamentals for example in back up and restore i didn't quite understand the encryption that well so like just basic understanding is good or do i need to be understand everything fully ?

dim wolf
#

no

old oasis
#

I'm pretty sure asking for answers is against the rules

tender nimbus
fathom pendant
exotic copper
#

How many possible values are there for a 6-digit OTP ? i am putting 10,000 as the answer as that is all i can see please can someone point me in the right direction

fathom pendant
#

Also 100000 wouldn't be right

old oasis
#

1000000 would be correct

fathom pendant
#

Consider all digits are 9s

exotic copper
#

On what do password recovery functionalities provided by web applications typically rely to allow users to recover their accounts?

#

please can you help me with this question too ?

#

and thankyou for your help with the previous question

#

I thought it was a one time reset token

fathom pendant
#

I suggest fully reading the material before just seeking answers

exotic copper
#

Ok cool ill give it another read

rocky estuary
#

the password attack module is very heavy specially the active directory section i spent 4 days and didn't finish it yet 💀

ember fern
sullen bear
#

Hi

#

New here

stark lark
frosty tide
#

Hello, I want to ask some tip on Directory Listing on Hacking WordPress. When I do it I navigate through all the file and folder manually. So I want to know if there a way to automate the process

frosty tide
#

I try it but dont know which switch

fathom pendant
#

I don't think you need a special switch

jaunty vigil
#

if i wanted to use the pwnbox, is there an easy way to download files related to the module?

fathom pendant
#

right-click > copy link > wget <paste>

limber river
fathom pendant
jaunty vigil
#

yeah that wont work :9

fathom pendant
#

it will work LMFAO

jaunty vigil
fathom pendant
#

i've done it

jaunty vigil
#

maybe ur magic

sacred jacinth
#

it should work

fathom pendant
jaunty vigil
#

yes, thats what i meant as the challenge files

fathom pendant
jaunty vigil
#

so is there any easy way to download the files, or am i going to stop using pwnbox

fathom pendant
#

if you open the browser dev tools and go to the application tab (on Chrome) or Storage (on firefox iirc) and click cookies you can find the "htb_academy_session" cookie

sacred jacinth
#

can't you use curl with cookies and output the downloaded file?

fathom pendant
#

that's literally all it needs for that

#

since it's not calling to the storage server for whatever reason

jaunty vigil
#

alright

fathom pendant
#

i mean you can also use the network tab to see if it's calling out to that instead

#

¯_(ツ)_/¯

jaunty vigil
#

i am going to use a vm

#

but thanks for the ideas, i was hoping for a simpler solution

#

i just wanted to try something out quickly

fathom pendant
#

yeah this is one of those few cases that because it's in the module instead of a resources bucket

#

which doesn't require any authentication to pull

#

@jaunty vigil the footprinting one (as an example)

#

since it's from the resources directories bucket it doesn't actually require authentication

bright pivot
fathom pendant
#

that's ffuf being ffuf

#

but also somewhat spoilery

#

make sure you're also filtering for the right size, if you changed the size of the terminal that's running ffuf it'll do that

#

look for the common size returned if you're getting multiple positives

#

and use that as your response size to filter against

#

-fs

#

the examples don't always match up to what you're testing

open mica
#

Has anyone here used sysreptor for reporting on the exam? If so, did you find an easy way to export the report as plain markdown?

bright pivot
#

the size that i filter is already correct

fathom pendant
#

did you make the screen bigger after starting the command?

bright pivot
#

no

fathom pendant
#

try opening a new terminal, maximize it, and run ffuf in that

#

ffuf is dumb like that sometimes

#

also your size doesn't look correct if you're getting a bunch of 200s

#

use the common size returned by all those 200s

#

SIZE: 7..

sacred jacinth
#

or words?

fathom pendant
#

the correct one will return something that is not 7..

bright pivot
#

i try to run the command again with fullscreen and then i already got the new output

fathom pendant
#

it always depends

sacred jacinth
fathom pendant
#

again it depends

sacred jacinth
#

true

fathom pendant
#

do you know what words will and won't be on the returned outputs

#

bearing in mind ffuf looks at the html code

sacred jacinth
#

if im correct

fathom pendant
#

it's filtering for a parameter value

sacred jacinth
#

I understand

fathom pendant
#

so it has nothing to do with a non-existent subdomain

#

there may be a word to filter by, if the bad parameter value elicits that response

#

it all depends how it's coded

sacred jacinth
#

got it 🤔

fathom pendant
#

they aren't fuzzing for fuzz.htb they are fuzzing for 'param=FUZZ'

#

so nothing to do with subdomain/vhost

sacred jacinth
#

yeah I understand

#

basically burp param miner

fathom pendant
#

your line of thinking isn't entirely incorrect

#

just needed to be worded better to be able to expand into broader thinking

#

such as using qualifying words like "For Example"

#

For Example, a server responds in a specific way to a non existent subdomain or page

#

allows a person to broaden that thought to other ways

#

as opposed to the definite:
a server responds in a specific way to a non existent subdomain
this may lead the reader to not really think outside the box of it's definite meaning you give it

somber fiber
#

here goes my 10+ hours

Web Fuzzing > Directory and File Fuzzing

Within the "webfuzzing_hidden_path" path on the target system (ie http://IP:PORT/webfuzzing_hidden_path/), fuzz for folders and then files to find the flag.

Tried:
ffuf -w /usr/share/seclists/Discovery/Web-Content/* -u http://94.237.49.212:31069/FUZZ
ffuf -w /usr/share/seclists/Discovery/Web-Content/* -u http://94.237.49.212:31069/w2ksvrus/FUZZ
ffuf -w /usr/share/seclists/Discovery/Web-Content/* -u http://94.237.49.212:31069/hidden_fuzzing_path/FUZZ

didn't got any result got the same endpoint as mention in module
| URL | http://IP:PORT/w2ksvrus/dblclk.html
* FUZZ: dblclk

[Status: 200, Size: 112, Words: 6, Lines: 2, Duration: 0ms]
| URL | http://IP:PORT/w2ksvrus/index.html
* FUZZ: index

Nothing new.

#

can someone help here?

#

Like i have tried so many combinations

#

brain is actully fked

dim wolf
#

more context is useful for those helping you. (module name, section name, what you have tried, your current understanding, etc.)

somber fiber
#

thanks for guidence.

fathom pendant
somber fiber
#

yap its still running

fathom pendant
#

They literally mean start from that exact directory kek

somber fiber
#

anything wrong here?

#

will add files -e flag too later once this finish

fathom pendant
sacred jacinth
topaz cliff
#

In the broken authentication assessment, I found several users, but I only found the password for one of them. For that user and pass, I have tried everything, but I cannot bypass the OTP stage (from brute-force OTP to URI and method manipulation). Is it possible the user for whom I found the password and reached the OTP stage could be incorrect?

rose pagoda
#

In the "Introduction to Threat Hunting & Hunting With Elastic" Skills Assessment, I have been stuck on Hunt 2 for a few hours.

I feel like I have entered every single registry.value into the answer field, based on the KQL queries I made from the hint provided. The corresponding article link provided doesn’t seem to help much either.

Does anyone have any advice or a further clue for Hunt 2?

rustic sage
#

😉

somber fiber
#

It seems i'm working with infinity still no results

viral snow
#

Hey y'all! I'm in Active Directory Enumeration & Attacks-Initial Enumeration of the Domain.

I SSH'd as instructed, and then ran sudo nmap -A -v -Pn 172.16.x.x. But I'm getting a response say 0 hosts up.

somber fiber
#

delete the box

viral snow
#

Actually, it's saying (host down). Is there anything I can do?

viral snow
somber fiber
#

check UDP i guess or try -Pn flag with TCP scan

safe star
quasi wave
#

Hi, when I try to transfer files in the SAM section of password attacks it denies my access to the share

#

even if the share is being run with sudo on Linux and CMD prompt is run as admin on Windows

#

how do I get it to approve?

safe star
#

Does it say something about the administrator?

quasi wave
#

yes

quasi wave
#

ok

safe star
#

Yeah u have to edit the registry I think.

#

U can just use powershell and ftp

quasi wave
#

ok cool

somber fiber
#

but if copied file work i don't this reg changes are required.

#

but yes can be a way

#

can try both

safe star
#

Other ways are a lot quicker tho

quasi wave
#

but section says nothing about registry

safe star
#

Ik

quasi wave
#

ok. in that case I'll do this the powershell way

safe star
#

That’s not part of the module

quasi wave
#

but if its not a part of the module and its not in the section why is it a requirement?

#

just by accident?

somber fiber
safe star
#

By removing html?

somber fiber
somber fiber
safe star
somber fiber
#

@safe star check these

safe star
#

Is that actually the name of the path?

somber fiber
#

the hidden one ?

safe star
#

Yea

quasi wave
#

I tried it in PS but it won't work

somber fiber
#

have got only one so far w2ksvrus

#

and its showing the same demo flag only

safe star
somber fiber
#

and index.html

#

dblclk > HTB{18...89}

safe star
#

I found it instantly @somber fiber

somber fiber
#

not working for me for some reason

safe star
#

Are u on the directory or page fuzzing?

somber fiber
#

got only one dir > w2ksvrus for this don't page one

tranquil lark
#

Hi there, I'm working on this module (it's around gobuster, ffuf, whatweb, etc) directory and dns mapping, I found a wordpress, the version of it and it's still on a (setup state) I believe there is a vulnerability there but I can't find the exploit, anyone aware of it ?

safe star
somber fiber
coral forge
#

I was trying to do the module footprinting section "SMTP", but I can't seem to get my script for trying multiple users to work ||for name in $(cat /opt/useful/seclists/Usernames/Names/names.txt); do telnet 10.129.171.248 25; VRFY $name | grep -v '550' | tee -a usernames.txt;done|| this is what I have

safe star
#

Page or directory fuzzing?

somber fiber
safe star
#

Did u try fuzzing the b*** directory?

#

Like the question asked

somber fiber
#

yes

#

there i got only one directory "w2ksvrus "

safe star
#

That’s not it

#

Dm me the command

sacred jacinth
#

it should be present in the PwnBox

tranquil lark
coral forge
#

Or is that an nmap script?

sacred jacinth
coral forge
#

Ohhh I see

sacred jacinth
coral forge
#

Gotta do my research then ahaha

sacred jacinth
coral forge
#

Ty very much for the help

sacred jacinth
sacred jacinth
quasi wave
#

hi I got to the end where I need to dump the credentials on the target and its not working even when I copy exact command and change the IP

#

btw the stuff @safe star and @somber fiber recommended to previous questions didn't work. I figured out the prior two questions. For this third one please don't tell me to do something that doesn't work. So can someone who knows this one section and what I need to do here please help me. The stuff people recommended the other day worked much better

#

anyway, I'm on the third question again

median gale
#

Is the VAT percentage standard for all countries in the subscriptions ?

somber fiber
quasi wave
#

I probably went a little far. Its just some of the stuff you recommended work not even on topic to the section and I tried it and it didn't work.

#

That said, I think ideally if you have a hint for the third question you can hopefully make up for it

somber fiber
safe star
quasi wave
hazy laurel
#

is there a way to abuse writedacl from linux? I dont think powerview is actually making the changes when i use Add-DomainObjectAcl

quasi wave
#

I guess each case is different

#

can someone help me with question 3?

safe star
#

did u run the impacket smbserver just like it said?

quasi wave
#

but I had a couple minor things wrong

#

but I got the SMB server running

#

I'm on question 3. the files have been moved

#

I got first two flags already

slender delta
#

Academy's File Inclusion Box is either really hard or my notes are really bad

#

Anyone who has solved it?

safe star
quasi wave
safe star
#

it should be at the bottom

quasi wave
#

ok

#

here's the command I use:

┌─[us-academy-1]─[10.10.14.143]─[htb-ac-605555@htb-dvdmy7b9tc]─[~]
└──╼ [★]$ crackmapexec smb 10.129.42.198 --local-auth -u bob -p HTB_@cademy_stdnt! --sam
#

I think there's something off about the command

#

hold on let me change IP address

safe star
#

thats not the lsa

#

secretsdump shouldve found it too

quasi wave
#

the secretsdump gave a password for an unknown user

safe star
#

u can assume what user that belongs too

#

crackmapexec also shows the user and password

#

u didnt use --lsa

fathom pendant
safe star
#

thought the discord code block removed them

quasi wave
#

so command processed but where do I get output?

#

what folder is the output in?

fathom pendant
quasi wave
#

I have had multiple outputs like this

safe star
#

it should have output and write to a folder

fathom pendant
#

Well nxc tells you where it's writing to

#

I believe it's in /tmp/ by default but idk enough about cme to say

safe star
#

it says ~/.cme/logs on my screen

#

but you should have output on your screen

#

can you ping the machine?

autumn garnet
#

could someone give me a hand with using crackmapeexec skill assessement

quasi wave
#

I gotta go

#

I need to make and pack my dinner for later

#

I will try again later

fathom pendant
fathom pendant
#

Netexec

#

It's literally crackmapexec but better

#

Due to a disagreement the people actually maintaining and updating the code forked to their own thing

fathom pendant
#

But the syntax largely remains the same

autumn garnet
fathom pendant
#

Haven't done that module so I can't tell ya

#

I was moreso joking that you gave so little info that it makes it hard to actually help

tranquil lark
#

anybody able to help out with the "Web Enumeration" module please ? I'm stuck on a technicality x)

fathom pendant
#

Sorry my psychic powers are still out

safe star
#

Wait, they don’t use nxc in the module?

fathom pendant
safe star
#

Oh

tranquil lark
fathom pendant
#

I haven't done the module so can't tell ya

#

I'm sure the section gives you tools you can use

#

Also there's no "web enumeration" module

tranquil lark
#

yes it is to use gobuster then it says that there is RCE on a non-installed wordpress install page, but there is nothing else, been poking at it for couple hours now 💀

fathom pendant
#

At least that's not the title

safe star
#

It’s the getting started module

fathom pendant
#

What does it say at the top of the page above the section name

#

Thanks boss

tranquil lark
#

appologies "Getting Started" module!

#

Web enum *section

fathom pendant
#

🤔 I don't recall needing to do anything crazy

#

Just looking at the source a lot

#

And robots

#

No bruteforcing or any tools really used

tranquil lark
#

humm maybe it's simpler than what I'm trying then, I fuzzed it to find the wordpress, then fuzzed the /wordpress itself am I missing something ?

fathom pendant
#

Also gobuster likely wouldn't have found anything useful

fathom pendant
#

Because that's not the target

tranquil lark
#

no no I'm looking at my ip target

fathom pendant
#

Either way

#

Check for robots 😉

#

That will be your first step forward

tranquil lark
#

sure I'll keep checking, just knowing I don't need to be looking at CVEs is already a great help!

fathom pendant
#

You don't

#

You're way overcomplicating it

#

Stick to basics

tranquil lark
#

got it, I'll have another stab at it, thanks

fathom pendant
#

If it seems needlessly complex do something else

tranquil lark
#

ok so this is crazy the common.txt I was using did not have what I needed, logged inthrough vpn with a fresh kali and had it all just with the common.txt list x)

tranquil lark
fathom pendant
#

:)

#

check the source code of the login 😉

tranquil lark
#

Yup once I got the robot, it was all smooth sailing, cheers! I

fathom pendant
#

you didn't need to even fuzz for it dude

cunning quarry
#

when adding something to etc/hosts for HTB do i put something like gettingstarted.htb or gettingstarted.com

fathom pendant
#

it's a common enough thing that you should always look for it off rip

fathom pendant
#

generally a vhost for htb machines will take the form of .htb or .local if it's 100% required

tranquil lark
fathom pendant
#

in fact it's mentioned in the section

#

😉

tranquil lark
#

yes they got me good with this part in the same section

#

||visiting http://10.10.10.121/wordpress in a browser reveals that WordPress is still in setup mode, which will allow us to gain remote code execution (RCE) on the server.||

fathom pendant
#

break away from the thought that the examples will always 100% be what you encounter unless it's explicitly mentioned

#

like for the upcoming nibbles sections

#

think of it as broad tooling

hazy laurel
#

I have GenericAll over a container that has the domain administrator in it, I also have GenericAll over the DC. I'm having trouble understanding how to use ACLs to take over the domain from this point. Can anyone help?

fathom pendant
#

what academy module is this for?

spiral spoke
#

hi everyone! I'm at Skills Assessment - WordPress and I'm using wpscan with --enumerate ap to adjust the scanning towards the plugins, but the thing is it doesn't show anything about the vulnerabilities of the plugins found (When in the Modules says that is in the output of the scan)

#

Anyone knows why?

cloud plaza
#

hey everyone,

I'm on the linux fundamentals have have a questions:

The questions posed at the end of the section is:

"What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?"

I used the "find" command to locate the file but its saying that its wrong and when I attempt to click the "show solution" button nothing happens.

any help would be appreciated

Here is what I believe the proper name of the config file is:
/usr/share/drirc.d/

spiral spoke
fathom pendant
cloud urchin
spiral spoke
#

Yeah I read it but an API Token is not necessary in this assessment but HTB tells you that in the output you will find information about plugins vulns

cloud urchin
#

i haven't done that module but i'd assume it's not necessary because you can manually enumerate it. if you want vuln output from wpscan you're going to need an API.

spiral spoke
fathom pendant
#

yeah

#

also as your output states you can get a free API token

#

good for 25 host scans per day:D

spiral spoke
#

Yeah, it's good to know xD

fathom pendant
#

it was likely touched on in the module btw

#

i doubt they'd talk about the tool without telling you an important bit of info about it

spiral spoke
#

It was touched in a command (with API token btw) but just as an example of how a the vuln looks like in the output, not how to search and use an API Key 😅

#

its in WPScan Enumeration section

cloud urchin
#

pretty sure it's the exact same but with like an --api argument or something

safe dock
#

Anybody here know how to find the flag in nmap service enumeration ?

unique ether
#

Windows File Transfer Methods 1st question can anyone give me hint

#

like how to get shell in the windows machine is that part of the question or?

fathom pendant
#

wpscan -h 😉

fathom pendant
safe dock
#

I got the flag from http/ip/robots.txt , but it's showing wrong answer

cloud urchin
#

try scanning the services

fathom pendant
#

wait nvm

#

it's something else

cloud urchin
#

enumerate the services

fathom pendant
#

the hint refers to nmap not always being able to recognize everything

#

perhaps look for something out of place in your scan and utilize a tool like nc to grab the banner

safe dock
#

Ok let me try

cloud urchin
#

you can find it with nmap alone by using the commands shown in the section

fathom pendant
#

probably

#

but just to be extra sure :P

safe dock
#

I already got the flag but wrong answer

fathom pendant
#

because the flag isn't on http

#

:)