#modules

1 messages ยท Page 329 of 1

fathom pendant
#

it's on a different port altogether

#

if you do a full port scan it'll be more enlightening

#

another hint, it relates to the previous sections results as well

unique ether
#

my pwnbox is linux but the questions are for windows file transfer

#

am i missing something

safe star
#

what questions

#

nvm

unique ether
#

Windows File Transfer Methods 1st question

safe star
#

does the target have a webserver open?

unique ether
#

yea

safe star
#

just do what the question says

#

no windows needed

fathom pendant
#

Is the target windows?

#

:)

safe star
#

the target is windows but the only thing needed is just a wget for flag.txt

bright seal
#

Can our instance pop out and follow like videos on opera

fathom pendant
#

No

#

But there is a fullscreen button

#

That opens a fullscreen tab

rustic sage
#

hlp idk how to make my ffuf look reaedable

#

also my keyboard is wonky

#

It always looks like this

normal sand
# rustic sage

Gonna need a little more info to help you out. What's the command you ran?

vagrant osprey
rustic sage
#

my treminal was too skinny so i had to fatten it up

#

and it stopped spouting nonsense

fathom pendant
#

yeah ffuf is silly like that

rustic sage
#

Like the random junk

fathom pendant
#

[i]gnore [c]omments

#

it's literally in the help page

rustic sage
rustic sage
normal sand
fathom pendant
#

some services report the hostname of the device that's running the service

vagrant osprey
rustic sage
#

good luck amal

#

you have my wishes

fathom pendant
#

rather something close

#

@vagrant osprey type hostname in your own machine to give you an idea of what it's meaning

vagrant osprey
cunning quarry
#

yes

vagrant osprey
#

hello stranger

rustic sage
#

hi

wanton idol
#

just wondering if you buy a module with your cubes do you have unlimited time on the pawn box?

cloud urchin
#

yes

wanton idol
#

a friend of mine brought the web request module and got this, just waiting for him to confirm he actually owns it

cloud urchin
#

i believe the rule is they have to spend some kind of money on academy to get it

wanton idol
#

yeah he owns the module

cloud urchin
#

did they actually put money in to buy the module or get it some other way

wanton idol
#

idk he has cubes on his acc and he used it to buy the web request module

vagrant osprey
cloud urchin
vagrant osprey
#

am i doing this right? or do i need to reevaluate something

cloud urchin
#

try some of the ways they showed in the module

#

i believe it notes you can add a parameter for more verbosity

vagrant osprey
#

i'll try nc

fathom pendant
cunning quarry
#

im on Nessus Skills Assessment and found every one except the first one about What is the name of one of the accessible SMB shares from the authenticated Windows scan? (One word)

#

can i have some helpo\

fathom pendant
cunning quarry
#

YEs

cloud urchin
cunning quarry
#

I got evetrhing

fathom pendant
#

i'm sure you looked then at SMB

cunning quarry
#

what does it look like

#

shouldnt it be something like ADMIN$

fathom pendant
#

no

#

if you check the windows_basic_authed scan you should be able to look at vulnerabilities then search "SMB shares"

#

it won't be a default sharename

#

so that narrows it down

cunning quarry
#

OH MY

#

WOW OKAY I WAS JUST BLIND

#

Thank you i just used to default C$ something like that

vagrant osprey
cunning quarry
#

thank you very much @fathom pendant

fathom pendant
valid osprey
#

Hi everyone, I have a question I want to resolve and I hope you can help me.

I'm doing the Active Directory Penetration Tester > Active Directory LDAP > Credentialed LDAP Enumeration module, where I need to know which user account has ENCRYPTED_TEXT_PWD_ALLOWED

And the other exercise...

What is the userAccountControl bitmask for NORMAL_ACCOUNT and ENCRYPTED_TEXT_PWD_ALLOWED? (decimal value)

The exercise mentions two tools, ldapsearch-ad and windapsearch, but when I use windapsearch, with the user james.cross and the password Academy_Student!, it returns a credential error, when I use ldapsearch, it works, I don't know why it works in one tool and not the other. If I only use ldapsearch, was I able to finish the module? I've tried several commands, searches but nothing works, windapsearch still returns an error in the credentials. And they are right, the exercise itself recommends using it.

vagrant osprey
fathom pendant
#

instead of using the limited window size

vagrant osprey
#

omg i can fullscreen

fathom pendant
#

also it won't be a vulnerability per se

#

and it's funny bc this is the one you found earlier i believe kek

vagrant osprey
fathom pendant
#

also you'd only run the vulnerability scan against a port you might want to check, as it'll test everything

vagrant osprey
#

ohh

fathom pendant
#

basic discovery scripts are fine

vagrant osprey
#

i ran it against all five at once lol

fathom pendant
#

because this is just a lot of info that means ultimately nothing

#

as some of these CVEs would be out of scope even if you were testing

#

as they can cause DDOS on the server

#

:)

vagrant osprey
#

didnt get anything out of individual scans

#

would -A help any?

#

it did not help

#

i will try again tomorrow

unique ether
#

But the other exercise had that

#

So its ok

fathom pendant
cloud urchin
#

aren't you on a windows machine in the first place?

fathom pendant
#

like

cloud urchin
#

nothing stopping you from connecting to the vpn with your host machine and doing it

fathom pendant
#

also that

#

but the provided target is windows

#

so like

unique ether
#

Yea I dint know you could do that until I read the next qn

fathom pendant
#

a lot of the stuff is built-in

#

:)

unique ether
#

But we good I finished the module just wanted to make sure if the way I did was correct

safe star
#

tbf it did ask to do it from the pwnbox

unique ether
cloud urchin
#

pwnbox has powershell too

#

at least kali does, i assume it's on the pwnbox

fathom pendant
#

it is

#

ugh report writing suuuucks lmao i finally stopped putting off doing my AEN report

unique ether
cloud urchin
#

yeah AEN is kinda huge

fathom pendant
#

ik the chain off rip but like double checking i got the right images sucks kek

#

i at least documented for notes sake

#

so some of that is there

unique ether
#

U doin the exam?

fathom pendant
#

but some of the intermediary stuff that doesn't quite need a code block

#

nah Enterprise Networks module

#

doing the exam likely soonish

cloud urchin
fathom pendant
#

so like

#

there's that

cloud urchin
#

i'm taking time off work around the holidays to get my 10 days for the exam. maybe we'll get our badge at the same time, finally. feels like forever for me.

fathom pendant
#

well i'm in a time constraint to start it

cloud urchin
#

i'm sure you'll crush it

fathom pendant
#

10 days + up to 20 bd for review and potential other 10 days if fail

#

chatting with rat has helped alleviate some of my worries and thoughts about my report before i've even finished it

#

about certain practices

fathom pendant
#

literally just said i hadn't lmao

#

if you take like 5 seconds to scroll up

full wagon
#

One question for the file transfers module and specifically the python uploadserver. I have previously used it, but downloaded it from GitHub. Now I saw it could be installed with pip or pip3, great.! Could someone explain why it in one part explains the download as 'pip3 install uploadserver' and in the linux part they run 'sudo python3 pip install --user uploadserver'. My question is specifically related to the use of sudo for a python install (since my understanding is it should normally be avoided). Or am I missing some angle?

fathom pendant
#

you're missing a slight angle on it

#

the pip3 is just to install it for your user

#

the sudo is to install it for all users on the machine (including root)

#

though a lot of it should be attempted first with sudo apt install python3-[insert package name here] though not all packages are in the repo for distributions

#

so you have to fall back to pip3/pipx or sudo

#

sudo also allows you to skip some checks that it does sometimes

#

either way it doesn't necessarily matter

#

multiple ways to perform the same functions

normal sand
#

Module: Linux Privilege Escalation
Section: Escaping Restricted Shells
Link to section: https://academy.hackthebox.com/module/51/section/1845

Tried running basic commands such as ls and cat, and obviously they didn't work since it's a restricted shell. I then tried each of the escape methods listed in the module, but none seemed to work.

# Command Injection
echo `ls`

# Command Substitution
`ls`

# Command Chaining (Tried with multiple different meta characters, such as ; | && ||)
echo "Hello"; ls

# Environment Variables
# Couldn't print env variables and when I tried modifying the PATH variable, it said that it was read-only.

# Shell Functions
my_function() {
  ls
}

my_function

I tried combining multiple methods as well, but wasn't able to escape the shell.

next bronze
#

iirc I did it with ssh

#

set the env in your ssh command

fathom pendant
next bronze
#

there's another way inside the restricted shell but I don't remember exactly

normal sand
next bronze
#

yeah I think so

fathom pendant
#

something like that

#

i found something literally in the first google search

#

so

#

ยฏ_(ใƒ„)_/ยฏ

normal sand
safe star
#

bro just kinda throws us in there

normal sand
next bronze
#

yeah so you found the two ways

fathom pendant
#

let's be mindful of spoilers even close to the answer ๐Ÿ˜‰ but there's enough info here for others to figure on their own past it

normal sand
#

Btw @next bronze when you doing a pentest, are there times where you need to read your notes on an attack to remember why it works and how to do it?

next bronze
#

usually always

#

I'm not gonna remember everything lol

normal sand
#

Or ya'll notes just like a cheat sheet like "Try this attack if you have this info and run these commands" without an explanation ๐Ÿ’€

normal sand
# next bronze usually always

Ahh, okay, good to know. Now that I'm near the end of the path, I sometimes see things about active directory, even though I completed the module a while back, and I'm like "Oh, I've forgotten how that works."

next bronze
#

depends on the context, usually there are some explanations since things can and will change for different enviroments

normal sand
next bronze
normal sand
#

Okay, I thought maybe it was just me who had to refresh his mind ๐Ÿ’€

next bronze
#

I usually carry two laptops with me, one for notes the other for pentests

next bronze
normal sand
#

Like the other day, I saw something about Kerberos Double Hop and I was like "I swear I learnt that" but mind throwin blanks till I looked at the notes and spend 2 min reading it.

#

I gotta really improve my notes before I do the AEN blind. Some of my notes I just copy-pasted things cuz I was lazy at the time NotLikeThis

next bronze
#

copy pasting is fine, if you find that it's not good enough, just edit them while you're at it

normal sand
#

Btw does the Documenting and Reporting module have you write a report? (I'm assuming yes? kek )

next bronze
next bronze
normal sand
normal sand
next bronze
#

you can send it to me, I'll take a look if i have the time

next bronze
#

or @proud pine is happy to help too

normal sand
#

Noted.

next bronze
#

@sweet jewel gonna say gitbook is better? kekw

sweet jewel
#

i do my notes in notepad

#

in point form ๐Ÿ˜ก

normal sand
#

That's hardcore ๐Ÿ’€

next bronze
next bronze
#

too based

normal sand
next bronze
#

it generates the message for you, default its just a timestamp but you can set it to be whatever you want

normal sand
#

Got it.

next bronze
#

push, pull and commits are auto once you have it configured, you don't have to do it manually

proud pine
#

Well, reviews for it, that is.

normal sand
next bronze
#

my bad didn't know that

#

why tho

next bronze
#

yep

proud pine
# next bronze why tho

They temporarily blocked everyone except me from doing them a few weeks back, while they talked internally on what they wanted to do. As of right now, even I can't do them anymore.

next bronze
#

hmm

#

because they don't want you to do free work or other reasons

cloud urchin
#

it's allowed still

proud pine
cloud urchin
#

welp

#

to me the documentation stuff is one of if not the most challenging thing

proud pine
cunning quarry
#

Vulnerability Assessment
Page 16
OpenVAS Skills Assessment
" What type of FTP vulnerability is on the Linux host? (Case Sensitive, four words)" where can i filter for this for

proud pine
#

They're still reviewing what they'd like to do going forward, but as of right now, nobody can do AEN reviews.

next bronze
#

well to be fair the documentation module did mention to reach out to academy stuff for reviews but I don't think that has ever happened

cloud urchin
#

they also said the makers of that module have kinda moved on to other things within the company so they're not really available themselves to review

uncut ocean
#

I have a small question here in Port Forwarding with Windows Netsh here the question is Using the concepts covered in this section, take control of the DC (172.16.5.19) using xfreerdp by pivoting through the Windows 10 target host. Submit the approved contact's name found inside the "VendorContacts.txt" file located in the "Approved Vendors" folder on Victor's desktop (victor's credentials: victor:pass@123) . (Format: 1 space, not case-sensitive) but how i am supposed to get window 10 or pivot host access??

proud pine
next bronze
#

fair enough

normal sand
#

Is there a sample report that's a good reference for what standard the report should be up to?

proud pine
#

Most of my reviews process is just getting someone to have their report mimic it as much as possible.

full wagon
proud pine
#

It's still easy to miss some of the details/structure, or forget to redact creds or such, so having a real person to review was really beneficial. There's no way an automated system could ever really help with it.

normal sand
next bronze
#

yeah, you don't want them plaintext in the report, what if it gets leaked

#

and I will usually clean up the output too

crystal ruin
normal sand
proud pine
fathom pendant
#

Also you don't include passwords

next bronze
#

flameshot has a blur tool as well for screenshots

normal sand
proud pine
#

Passwords, hashes, anything sensitive.

next bronze
#

yep

fathom pendant
#

Anything that could incidentally be used to gain unauthorized access to the environment

normal sand
proud pine
#

It's also very easy to forget about where all you might leak creds, so having a human review can help bring your attention to it. Like, you might redact a hash in a tool output, but then forget to redact in a PTH command.

crystal ruin
#

@uncut ocean just had a look at the module again, the RDP machine that they provide has access to the subnet with the DC. You pivot through there

uncut ocean
#

i also stuck in same thing but i cant remember ryt now but yes look around other things also and enumerate a little

cunning quarry
#

i got the operating sytem and ip of target

ocean night
#

That's just the first page of results...

#

Perhaps have a look through the rest, or filter the results

cunning quarry
#

I did filter for the address and looked at each one

#

I think its my wording

ocean night
#

You're on the results page there - is there another page that might give you a better and more descriptive list of results?

#

What does the first page of results look like on that page?

#

and what page are you on?

#

(bottom right, pagination)

cunning quarry
#

but cant i ingore the ones that are 0.0

#

WAIT

#

I GOT IT

ocean night
#

Nice

cunning quarry
#

IM JUST BLIND
AND NEED GLASSES thank you

cunning quarry
ocean night
#

No worries, removed the screenshot, even though it is a tier 0 module. Think the advice above is enough ๐Ÿ™‚

steady dock
#

DETECTING WINDOWS ATTACKS WITH SPLUNK >Detecting Kerberoasting/AS-REProasting

can someone hint me for this.

Modify and employ the Splunk search provided at the "Detecting Kerberoasting - SPN Querying" part of this section on all ingested data (All time). Enter the name of the user who initiated the process that executed an LDAP query containing the "(&(samAccountType=805306368)(servicePrincipalName=)*" string at 2023-07-26 16:42:44 as your answer. Answer format: CORP_

coarse isle
#

Linux fundamentals
trying to ssh, user@IP just fine, but when it comes to enter the password, I'm unable to input anything?

I feel like im missing something very basic here.

smoky vortex
#

HI, could anyone help me with LPE-logrotten section, I'm trying to backup access.log, but getting the file with payload in /etc/bash.. directory with htb-student permissions. Should I use another log file for the escalation?

dim wolf
fathom pendant
coarse isle
smoky vortex
fathom pendant
#

Nvm reread what you said

#

The access.log is indeed the one I'm referring to

#

Logs don't always have to be in /var/log

smoky vortex
# fathom pendant Nvm reread what you said

Yes, but the problem that I'm able to get the paylod, but with htb-student permissions.

htb-student@ubuntu:~/logrotten$ ll /etc/bash_completion.d/access.log
-r-xr-xr-x 1 htb-student htb-student 43 Sep 18 07:02 /etc/bash_completion.d/access.log*

So, the reverse shell is also as htb-student.

fathom pendant
#

So... find a way to got your payload to not be htb-student and be root ๐Ÿ˜‰ logrotten is the key.

#

Also you don't necessarily need it to be a reverse shell

smoky vortex
icy marsh
#

#modules kerberos abuse constrainsed delegation....
i am getting this error repeatedly

PS C:\tools> .\Rubeus.exe s4u /impersonateuser:Administrator /msdsspn:www/WS01.inlanefreight.local /altservice:HTTP /user:DMZ01$ /rc4:813XXXXXXXXd0f8764531bc8c52fa66 /ptt

   ______        _
  (_____ \      | |
   _____) )_   _| |__  _____ _   _  ___
  |  __  /| | | |  _ \| ___ | | | |/___)
  | |  \ \| |_| | |_) ) ____| |_| |___ |
  |_|   |_|____/|____/|_____)____/(___/

  v2.2.2

[*] Action: S4U

[*] Using rc4_hmac hash: 81322a06e7a6d0f8764531bc8c52fa66
[*] Building AS-REQ (w/ preauth) for: 'INLANEFREIGHT.LOCAL\DMZ01$'
[*] Using domain controller: 172.16.99.3:88

[X] KRB-ERROR (24) : KDC_ERR_PREAUTH_FAILED:

what is going wrong ?

fathom pendant
#

You need to trigger the log rotten payload somehow

next bronze
icy marsh
#

but it is right . i checked multiple tims

fathom pendant
#

But focus on the log you can access at home @smoky vortex

#

It's a race condition thing

icy marsh
next bronze
#

you probably copied the wrong hash earlier

icy marsh
next bronze
#

anytime mate

safe dock
#

I tried but netcat connection timed out

hoary mauve
#

hi, for the information gathering web edition, ii'm stuck on question 4. recon spider ||on both inlanefreight.htb and the webxxxx.inlanefreight.htb|| do not come up with any sort of output whatsoever. i'm not really sure where i'm supposed to get the email address from. finalrecon does not seem to find anything other than the ||robots.txt entries in the subdomain||. i've manually enumerated those, to no avail. i don't know how to proceed, since there's not a ton of further surface area i can find to enumerate. i'm fairly certain that the answer lies within the ||webxxxxx subdomain||, but, directory brute forcing the root and the admin directory hasn't found anything

drowsy vector
#

Hi, I am currently doing the password attack hard lab
I need help for the initial foothold for the lab.
I have tried using crackmapexec, hydra and crowbar and can't crack the password for johanna and it also takes really long. I am using a mut_password.list that was made using the password.list and custom.rule provided in the module. The services I tried are ||rdp|| and ||winrm||.

sacred jacinth
#

perhaps there is something you are overlooking

crystal notch
#

Hello everyone, I need some advice which wordlist should I use from seclists to find last host which ends .203 in DNS in Footprinting module. I have used already some wordlists but with no success.

safe star
#

have u tried smb?

drowsy vector
#

Nope, I will try it right now

safe star
#

remember to use local auth

drowsy vector
#

How long will it usually take?

#

Because reading the previous discussions about it, some say it takes fast

safe star
#

it just takes some time ๐Ÿ˜…

#

at least u know its in there

drowsy vector
#

Ah I see

#

Thank you

safe robin
acoustic owl
safe star
safe star
#

u have to be user2 to see the contents

safe robin
safe star
#

have u checked what commands u can run with sudo?

safe robin
#

yeah

#

as user1 evn_reset , mailbypass and secure path

#

and as user2 /bin/bash without pass

safe star
#

do you know what /bin/bash does?

safe robin
#

no

safe star
#

it spawns a new shell for the user running it

safe robin
#

ohkye and if i can spawn the new shell with the user2 it wont ask for password and i will be able to cat the contents of flag.txt? is that right?

safe star
#

๐Ÿคทโ€โ™‚๏ธ try it out

safe robin
safe star
#

there might be private files somewhere

rocky estuary
#

need help with the pasword attack easy lab i couldn't find the root password i tried bruteforcing the ftp service using root name and both the the password list given and the mut one but no result
also tried the rockyou.txt didn't find anything any idea what i'm missing ?

pseudo kiln
#

IIRC they give you password lists to use in the resource tab in that module right ?

safe robin
#

yehyyyyyyyyyyyyyyyyyyyyy

pseudo kiln
#

think about what other file in the resource tab that might be useful ๐Ÿ™‚

shell ore
#

if im not mistaken, u should use the other file too

rocky estuary
shell ore
#

another one

rocky estuary
#

username file ?

shell ore
#

maybe?

#

i honestly dont remember much detailas about this skill assessment, but try using what you have, you maybe able to get a foothold on some service using that

drowsy vector
#

@safe starThank you! I got the password

rustic sage
safe robin
#

how to knw what to write instead of 0.0.0.0

shell ore
safe robin
#

here serverrunning on 0.0.0.0 but how to wget?

shell ore
safe robin
#

i used but it refuse

shell ore
#

0.0.0.0 here means that its reachable from all interfaces on the network, which means let's say ur IP is (10.10.16.5), anyone one that network can reach it on (10.1.016.5:8000)

shell ore
safe robin
shell ore
#

show me how you used wget please

safe robin
#

ohk

rustic sage
safe robin
shell ore
#

you sure thats ur local IP when you do "ip a" ?

safe robin
#

got it worked

safe robin
rustic sage
#

XD

shell ore
# rustic sage XD

not everyone has done that module to help, so u better respect people here who try to help at least

acoustic owl
shell ore
#

and keep "advancing" ig

rustic sage
#

Im on this site for 2 years , i know what im talking about

shell ore
rustic sage
#

the internal application that was found is port 3306 (SQL)

acoustic owl
#

The module shows you how to access the internal web application

acoustic owl
rustic sage
#

how woud i get to this chapter if i do it step by step ?

#

im on Identifying SSRF

#

i did , i ffuf the ports

#

and found 3306

#

the module left it hang like this :

The results show that the web server runs a service on port 3306, typically used for a SQL database. If the web server ran other internal services, such as internal web applications, we could also identify and access them through the SSRF vulnerability.

shell ore
rocky estuary
#

i found the password also for root but no sure if its the right way hahaha

rocky estuary
acoustic owl
rustic sage
#

HTTP/1.1 200 OK
Date: Wed, 18 Sep 2024 10:48:54 GMT
Server: Apache/2.4.59 (Debian)
Content-Length: 45
Connection: close
Content-Type: text/html; charset=UTF-8

Error (1): Received HTTP/0.9 when not allowed

acoustic owl
#

Perhaps your port is incorrect

rustic sage
#

i will tell u

#

that who wrote this module just did a mistake ...

acoustic owl
rustic sage
#

there are not 100% right with the engagment with users ... to be in the place i am i did try hack me too and it took me 2 years

shell ore
#

stop sharing answers pls ๐Ÿ™‚

acoustic owl
#

The modules are structured in such a way that you cannot simply copy commands and apply them. It is important that you understand what you are doing.

rustic sage
#

stop messing with my brain with easy thing just to make me a subscrubtion for 2 years

shell ore
rustic sage
storm elk
#

If you don't like how the modules are taught, you can always provide feedback via /feedback

rustic sage
storm elk
rustic sage
#

i see some errors i have an opinion

acoustic owl
storm elk
#

If you have feedback and want to be heard /feedback is what you should do

rustic sage
shell ore
rustic sage
#

pay 10K usd for good course ?

#

u have the full control and the work to keep it clean ...

shell ore
rustic sage
#

opinions could be hard to hear sometimes

#

in cyber they all deletes it XD

shell ore
#

anyway i think we should stop and keep this chat on topic

acoustic owl
rustic sage
#

my current feedback is for the specific module

#

"NEW"

spare crown
storm elk
#

As mentioned before @rustic sage , if you don't like it, provide /feedback and if you think there's errors in it, post in #1234357888114364508 . Let's try to keep the rest of the chat clean for other users of Academy who might need help ๐Ÿ™‚

rustic sage
#

thanks atleast there are some activity here and u educate me with new things

rough tree
#

Am I the only one having connection issues with the Skill Assestment LAB on "Using CrackMapExec"?
Chisel connects to the server but the subnet 172.16.15.0/24 can't still be reached.. Obviously using proxychains ๐Ÿ˜„

rustic sage
#

Hello guys ! I try to install and enable SELinux on my Parrot Virtual Machine. When I set โ€œpermissive modeโ€ on config file and reboot, SELinux status is always on โ€œdisableโ€. Config file is correct . Anyone have suggests?

topaz cliff
#

Need help, the broken authentication seems to have changed. I have done everything this chapter said to do this module for assessment, and I've done everything the people in the forum said to do, but I'm still stuck on it.

tranquil lark
#

100%, thanks a lot. Really appreciate it

rustic sage
#

nmap not working for me, i dont know what i've done wrong

#

Im connected to the config and so on

slate zinc
rustic sage
#

thanks

#

trying now

#

it worked i can see the ports coming up

#

wowee LMAO

slate zinc
#

you can ignore logs

rustic sage
#

i wish i had GalaxyArts without an extra S, my old account had it but i just created a new htb account since i forgot about it

#

i deleted it but i cant seem to have it changed with the singular "S"

tender nimbus
#

Hey guys im stuck here

rustic sage
tender nimbus
#

Module

#

I tried ReconSpider, gobuster and all but nothing

#

idk where to begin im stuck :p

spare crown
#

both gobuster and reconspider will will be helpful. You'll also need to add any domains you enumerate to /etc/hosts

#

what have you got so far?

tender nimbus
#

but idk the gobuster to find the admin dir dont work and when i use ReconSpider my result file is empty

spare crown
#

so what subdomains have you been able to enumerate so far?

tender nimbus
spare crown
#

okay nice, and what have you done since finding that one

tender nimbus
spare crown
#

what other tools do you have at your disposal?

tender nimbus
#

gobuster

spare crown
#

yessir

tender nimbus
#

ow wait

#

im on the right path thank give me a sec ^^

spare crown
#

yeah np, by adding the web1337 subdomain to vhosts you've essentially just uncovered another layer, just gotta keep going from there

tender nimbus
#

just need to try to go in the admin dir

spare crown
#

yeah have a look and see what you can find

shut vapor
#

yes, you can go through the pivoting module with ligolo. I just did it a few days back. Connection refused suggests the system/port to which you're connecting is closed. What are you doing there; it looks like you're trying to run the agent on your attack system? I think you want to start with a proxy on your system and the agent on the pivot.

#

The ligolo quickstart had everything I needed to step through.

shut vapor
#

Sure, I'm not at my primary deck but I can do what I can to answer questions.

tender nimbus
#

but im prety sure for the last 2 questions i need to user ReconSpider but idk i always receive an empty result.json

spare crown
#

right, have you uncovered any other subdomains other than the web1337 one?

tender nimbus
#

not yet should i reuse a subdomain enum on web1337?

#

i guess yes ^^

spare crown
#

yeah I suggest trying that

#

then go ahead and spider anything else you find, I believe that should put you on the right track

tender nimbus
#

thanks for you help

tender nimbus
versed relic
#

Hi guys I meant to scan this website but it does not let me, is there something Iโ€™m doing wrong?

autumn pilot
#

You need to specify the port in the port argument of nmap not include it alongside the IP address

tired garnet
#

Anyone available to help me with a practice exercise? (windows powershell)

tender nimbus
tired garnet
#

I will post the question and i will post what i did 1 sec

#

Question: What user account on the Domain Controller has many Event ID (4625) logon failures generated in rapid succession, which is indicative of a password brute forcing attack? The flag is the name of the user account.

What I did so far:

$event = Get-WinEvent -FilterHashtable @{ LogName = "Security"; Id = 4625 }

run command, prints the list of entries and i can see visually a bunch of failed attempts, then i pick one from the list of the entries that fits the description in the question (in this case for example the 7th entry)

$event[7] | Format-List * | findstr "Name"

I can see the info, but when i put ACADEMY-ICL11$ the answer is wrong

exotic copper
#

on the broken authenticaton module brute forcing passwords i have unzip the rockyou.txt file and used the cat command to show its there but when i use this command wc -l /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt it says no file or directory. What am i doing wrong. Please can anyone help ?

tranquil lark
#

The nibbles machine on the academy path, you have to pay to play it ?

mortal valve
exotic copper
#

I have done this and I am still getting the same thing

acoustic owl
#

The path to SecLists is probably different in your distro

tranquil lark
exotic copper
#

Sorry you have lost me KamalCh

tranquil lark
#

when you you cat the full path /opt/useful/SecLists/Passwords/Leaked-Databases/rockyou.txt

#

does it work ?

exotic copper
#

i have not tried that yet but I will see what happens

#

I get the same thing no file or directory

tranquil lark
#

then chances are like said above your SecLists has a different path, so you can crawl into it sowly directory by directory to make sure you have the right one

exotic copper
#

Please can you give me a clue on how to do that ?

tranquil lark
#

are you using the HTB virtual machine or are you doing it through VPN ?

exotic copper
#

I am using the HTB virtual machine

acoustic owl
exotic copper
#

Ok thanks for the help

acoustic owl
#

Here you will learn the fundamentals of Linux

tranquil lark
#

yes definetly you'll need to get used to linux and its basics, for now you can google the 'find' command on linux to find the SecLists directory on your machine

#

on the other hand, I'm giving a shot to the cpts training, and in the getting started module, they talk about the nibble machine and a walk throught, is there a voucher or something to get it ? or do I have to subscribe to the labs monthly too ?

#

(I only have a sub to the academy for now)

exotic copper
#

Thankyou both for the help

tired garnet
tranquil lark
exotic copper
#

Would it be possible to give me a little hint on where to look so I know i am going in the right direction ?

acoustic owl
tranquil lark
exotic copper
#

thats what i have been using

exotic copper
#

I have also tried to see if i could make a new directory with the rockyou.txt

#

i have used the cat command to show the rockyou.txt is there

acoustic owl
#

You cannot search for a file with cat

#

But you can use find to search for it

exotic copper
#

i Know

#

I know

acoustic owl
#

But honestly, these are things you really need to learn first before you get into hacking

tranquil lark
#

@exotic copper when you run this what does it show ? find / -type d -name "SecLists" 2>/dev/null

exotic copper
tranquil lark
#

good so that confirms two things 1- you have SecLists and 2- The path to it is /usr/share/wordlists

rocky estuary
#

guys i'm doing password attacks the hard lab i got access using johanna creds and i found the kdbx file and cracked it and i got david creds but i can't do anything with it tried to rdp with it and didn't work and i found smbserver running so i tried to use it there but no luck anyone got an idea ?

exotic copper
#

yes I know this i have looked into my files and they are all there

exotic copper
tranquil lark
#

you will really have to do the linux fundamentals, I think it will unlock a lot for you

ornate pine
#

found a fix?

final sparrow
#

certbros showed brute force login and i cant find it in the actual website does it have a diffrent name or something

rocky estuary
ruby pewter
#

suppp

near steppe
#

Hi, who knows how to do a real hack?

storm elk
near steppe
storm elk
#

Contact legal authorities

#

And your bank

near steppe
#

That's why I'm so angry at that person.

storm elk
#

Wait for the process. We canโ€™t help you.

#

This isnโ€™t hacker for hire

near steppe
#

Are you just teaching cybersecurity here or what?

acoustic owl
#

We can't help you. As EverydaySparkling has already said, contact the police and your bank. There is nothing more you can do.

full patio
#

Can someone please give me a nudge on this: What is the API key in the hidden admin directory that you have discovered on the target system?
From: Info Gathering - Web Edition - Skills Assessment

So far I've tried:
||- ffuf

  • gobuster
  • finalrecon
  • wfuzz
  • scrapy with ReconSpider
  • Read comments in the forum
    All with trying to get subdomains and vhosts||

I'd appreciate some help hugthebox

near steppe
#

I don't have bad intentions, I just want to prove to this idiot that what was done to me was wrong, like withdrawing money from a card.

near steppe
#

I want to learn something, what is the reason for this server It has 250 thousand members.

acoustic owl
#

These are all people who want to learn cybersecurity

#

or playing CTFs

exotic copper
full patio
exotic copper
#

let me know how you go

sacred jacinth
full patio
sacred jacinth
exotic copper
#

I am on the broken authentication module brute forcing passwords. i have the rockyou.txt file and i have checked it to see thats is there but when i try to complie some passwords into a file it wont let me, what am i doing wrong also for the rockyou.txt it says file or directory does not excist what am I doing wrong ? I am getting really frustrated

sacred jacinth
#

my guess would be that you didn't make any edits in the /etc/hosts/ file

exotic copper
#

I am confused what do i need to edit in the host file if i only want to nake a new file ?

sacred jacinth
acoustic owl
#

But as I mentioned before, I recommend that you first familiarize yourself with the basics of Linux before studying other modules. Most modules require knowledge of Linux or Windows.

exotic copper
#

Ok thankyou

full patio
sacred jacinth
exotic copper
orchid monolith
#

Hi, have anyone done the moduel blind sql injection yet?

acoustic owl
exotic copper
warped oasis
#

Anyone able to give me some direction here? I'm on the Intro to Assembly module, nearly done on shellcoding tools and the lesson has us writing a short simple assembly code and converting it to shellcode with no null bytes. However, upon running my python script it errors out with "elf_assert(magic == b'\x7fELF', 'Magic number does not match'". I've googled around and can't seem to nail it down.

next bronze
warped oasis
#

You know what, I overlooked that, good call. I think it's time for a coffee break.

#

thanks @next bronze

novel lynx
#

Credentialed Enumeration - from Windows
what am i doing wrong? I'm using the neo4j: and provided password and it's not letting me in

regal stream
#

I am trying to complete the "Windows Event Logs & Finding Evil" academy lab. When starting the RDP connection I am able to connect initially but then it disconnects and I am not able to connect again. I have tried both the VPN and the pwnbox. Initially I was having an issue with the "allow connection from other PCs on the local network prompt" but I realized I just needed to click "yes". I am still having connection issues however. I am able to connect for around 30 seconds and then I loose connection and am not able to connect back to the machine.

novel lynx
fathom pendant
somber fiber
#

yes

somber fiber
fathom pendant
#

Text wrapping pushed the password part to the next line

somber fiber
novel lynx
#

still doesn't work, i downloaded the zipfile to my pwnbox, do i need to be using bloodhound from the windows machine?

fathom pendant
#

So you used neo4j as the user yeah?

novel lynx
#

yes

fathom pendant
#

Ohhhh you're on the pwnbox

novel lynx
#

yes

fathom pendant
#

Default is neo4j:neo4j

#

The credentials given are for the windows host

#

:)

novel lynx
#

omg

#

how was i supposed to know that?

fathom pendant
#

It's likely able to be figured out through context

somber fiber
fathom pendant
#

First sentence kekw

fathom pendant
#

Do ... do we need to get you an eye doctor appointment (joking)

last sorrel
#

Why am I not allowed to type in #general ?

fathom pendant
somber fiber
#

or SC?

last sorrel
#

I can't find my acc identifier

fathom pendant
somber fiber
fathom pendant
#

Can't share screenshots, he's not linked

storm elk
last sorrel
#

Come on, I don't want to download an app

fathom pendant
#

It's not downloading an app

#

Lol

#

That's just the subdomain

last sorrel
#

Yh yh I got it

#

Alr I linked my dc acc to the web in the settings

fathom pendant
#

Linking in settings does nothing

last sorrel
#

Bruh

#

Why make it an option lol

fathom pendant
fathom pendant
#

/verify will have the bot dm you to handle the process in private to prevent leaking your identifier

last sorrel
#

Now the bot isin't even working well in the dms

somber fiber
warped oasis
#

I just iden. like a minute ago.

last sorrel
sturdy ingot
#

My module labs have been stuck like this. Any suggestions on how to fix it?

fathom pendant
last sorrel
#

I guess I should just download linux on wsl2 and learn the basics myself instead of playing these petty games with a broken bot

somber fiber
#

don't do anything

#

try refresh the page

#

it will eventually be there.

sturdy ingot
somber fiber
#

no need to change the vpn

#

how much time its been

sturdy ingot
#

Like 20 minutes

somber fiber
fathom pendant
#

Pwnbox location and vpn region are completely separate

#

You will need to respawn your pwnbox to connect to the changed vpn

fathom pendant
sturdy ingot
#

I've changed it to different regions, but it's stuck still. Am I doing it wrong?

somber fiber
fathom pendant
fathom pendant
#

Vpn regions are generally [us|eu]-academy-[1-6]

#

Not sure about enterprise differences though

sturdy ingot
#

I'm on HTB enterprise.

fathom pendant
#

Reach out to support then

#

ยฏ_(ใƒ„)_/ยฏ

astral steppe
#

Any way to force restart a target? My target has been spawning for about 20 mins

astral steppe
fathom pendant
somber fiber
#

or tried to start the module again

astral steppe
sturdy ingot
#

Maybe HTB servers are messed up rn if multiple people are having the issue.

fathom pendant
#

Exiting the module doesn't do much tbh

astral steppe
#

rip guess ill read next module aha

fathom pendant
#

As the request is being sent to the backend

#

Like you can start it on one device open the page on another and you'll see the same thing :p

sturdy ingot
astral steppe
#

odd then, not been able to pass thru 2 diff modules bc stuck on spawning unfortunately

fathom pendant
#

The status page isn't always accurate

sturdy ingot
#

I demand free cubes

fathom pendant
#

If enough people go to support with the same issue then they can raise it

fathom pendant
olive fiber
#

Hello to everyone,

last 2 weeks i am having problems connectin to some windows machine on the labs through rdp.

This happens only with some modules, once i change module or submodules i have noi problems connecting.

In particular i have huge problems on connecting on he "Trust Attacks" module. So i am 2 weeks now i cannot finish not only the assessment but sobmodules included.

Once i change module or something i have no problems

#

Any clues?

#

[14:17:19:708] [158024:158025] [WARN][com.freerdp.crypto] - CN = SQL01.inlanefreight.ad [14:17:23:724] [158024:158025] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server [14:17:23:724] [158024:158025] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014] [14:17:23:724] [158024:158025] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail [14:17:23:724] [158024:158025] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

fathom pendant
#

Logon failure is the main thing meaning something about the credentials is incorrect

#

Can you log in with other tools?

olive fiber
#

credentials are correct, this happens to me only to some trust attacks labs

olive fiber
#

it works for like 20 seconds everytime i reset, and then stops working

fathom pendant
#

Can you log in with other accounts from the module?

#

ยฏ_(ใƒ„)_/ยฏ

#

I'd raise the issue to support then

warped oasis
#

using TCP or UDP?

olive fiber
olive fiber
smoky vortex
# fathom pendant It's a race condition thing

It't would be valuable to add on the page some info about "/etc/bash_completion.d" and how the actually the payload is executed or at least, a link on blog posts where it's described in more details. I think, one step of explanation is missing.

fathom pendant
#

You probably did something slightly different to me

#

@sturdy ingot @astral steppe what vpn regions are you on/tried

ocean night
#

Infra team are looking in to a potential issue. Please stand by.

astral steppe
nova ginkgo
#

Web Attacks - Skilss assesment

Try to escalate your privileges and exploit different vulnerabilities to read the flag at '/flag.php'.

I cant find any parametr in website but I foun user id and uid then I listed users but still I cant find anything

ocean night
#

Was it just the one issue with academy @fathom pendant ?

fathom pendant
#

Looks like it

ocean night
#

(re starting instances)

fathom pendant
#

But that infinite spawn thing has been a thorn for a while tbh it comes and goes when it pleases

#

Usually though only one or two people not a bunch

nova ginkgo
#

I listed until 100

fathom pendant
#

?

fathom pendant
#

We're talking about something unrelated to your question

fathom pendant
#

You will definitely use all techniques taught to an extent from the module

#

Also grep -i can be helpful for finding things where you may not be sure of how it's capitalized

spiral spoke
nova ginkgo
#

thanks I will try

green lantern
#

Glad to join this great group

regal sigil
#

Module: AD Enumeration & Attacks - Skills Assessment Part I
Section: Skills Assessment Part I
Question: Submit the contents of the flag.txt file on the Administrator desktop on MS01
My Approach so far-
I initially tried to use chisel but I was unable to transfer this file, So I am using netsh.exe right now to pivot, But I am making some mistake and cannot figure it out, I cannot figure it out

I have listed some screenshots, please help me understand what is wrong here

acoustic owl
#

In particular, Rule #4

royal granite
#

Hello, Everyone im new to this. Trying to sign up for a student account, has anyone gone threw the Domainless Student process if so how did it go and how long did the process take. Thank you. Feel free to dm me.

fathom pendant
sturdy ingot
#

I finally got a new "Spawn Target" button so keeping my fingers crossed that it works this time ๐Ÿ™‚

echo pilot
#

i'm stuck on module 18 section 81 trying to use the find command to answer the question "What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?" but I have been typing find -type f -name *.config -user root -size -25k -newermt 2020-03-03 -exec ls -al {} ; 2>/dev/null in the terminal and nothing shows up

#

Am I formating the command wrong?

fathom pendant
echo pilot
#

yes

fathom pendant
#

And you're running that command from the ssh session

#

And doing whoami should say "htb-student"

regal sigil
echo pilot
#

yes

fathom pendant
echo pilot
#

whoami says "htb-student"

fathom pendant
#

Oh

#

Your size flag is wrong

sturdy ingot
#

Does anyone know if HTB Enterprise allows you to change the VPN at all? I only see this 1 server:

fathom pendant
#

-size -25k _<< is size less than 25k

fathom pendant
echo pilot
#

oh ok

fathom pendant
sturdy ingot
#

Yeah I've already reached out to support, but my question still stands.

fathom pendant
#

If you want a range you need -size +[min] -size -[max]

sturdy ingot
#

Just curious if there is another VPN or if my company gets allocated a single dedicated server.

fathom pendant
#

That's a question generally only support knows since a majority of people here aren't EP users

#

So troubleshooting and help is gonna just overall be different

#

See if other EP users know, and your Q doesn't get drowned out

nova ginkgo
fathom pendant
nova ginkgo
fathom pendant
#

Yes there is

#

Log into the other user and compare

echo pilot
fathom pendant
#

Are you sure it's .config

#

Some config files are .conf

#

Or even .cfg

echo pilot
#

that is what the question is telling me

fathom pendant
#

Is it though?

#

Or is it just saying a config file

echo pilot
#

oh let me try like that then

#

its saying config file

fathom pendant
#

It didn't specify an extension

#

๐Ÿ˜‰

sacred jacinth
fathom pendant
#

Most times people shorten the word "configuration" to "config"

echo pilot
#

i figured it out

#

i forgot to put the / at the front of the command

fathom pendant
#

?

#

Ohhh

echo pilot
#

sorry for the trouble

fathom pendant
#

Yeah

sacred jacinth
fathom pendant
#

find <directory to recurse from> [rest of options]

nova ginkgo
fathom pendant
#

There's something on the admin home page that isn't available on the users

nova ginkgo
#

I opened 2 windows
1 user
2 administrator

but there are the same

fathom pendant
#

They shouldn't be

#

Look for a schedule

#

I'm trying to push you to it

#

But I can only push so far until you're off the cliff into the ravine

sick whale
#

Hello everyone,
Quick question regarding the Pivot and Tunnelling module.

In the skill assessment, after the second pivot, both flag (in C:/ and in DC disk) are accessible from the same account once you RDP in the host. Is that normal or that's something that should have been cleaned up at reset? I was expecting one more step to get DC access. But all it took was a click on that volume...

nova ginkgo
fathom pendant
#

I thought you did that already

sick whale
# fathom pendant This is intentional

Oh?

I checked a walkthrough after I was done, and the guy was importing data into bloodhound etc... going full AD pentest and I was like "right click was enough..."

#

That's where I got confused haha

fathom pendant
#

Since pivoting isn't a tier 0 module iirc

sick whale
#

Oh, didn't even know that wasn't allowed to write walkthrough for non-tier 0 modules

#

Well, all it did was confusing me that time

fathom pendant
#

You can report stuff like that btw with /spoiler command

sick whale
#

Alright thanks a lot for the swift answer!

regal sigil
#

But I still want to know what was wrong with my netsh proxy setup

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

I'm not familiar enough with it

#

Ligolo is op

sick whale
#

I couldn't double pivot with logolo, somehow the agent was getting connection refused...

#

Ended up using netsh for the second pivot

regal sigil
fathom pendant
#

Listener_add --addr [victim]:port --to [you]:11601

sick whale
#

Yeah I assumed I did a mistake somewhere, first I was using port < 1000 which was taking admin permissions I didn't have.
Then re-did the whole thing and still got stuck -.-

fathom pendant
#

To get the second one on

#

And you need to make sure to start the session and tunnel

sick whale
#

I closed everything after using netsh and solving the problem, so I can't show you the conf

#

I need to get used to discord still haha. I'm used to doing things by myself.

fathom pendant
#

New ligolo even lets you make new interfaces on the fly

sick whale
#

Yeah that's pretty neat, same for the routes

fathom pendant
#

Super user friendly

#

With ligolo the tunnel interface means you don't have to forward to specific ports and can directly interact with the network tunneled to

fathom pendant
lofty phoenix
#

Im in the using crackmapexec module trying to answer the question in the MSSQL enumeration and attacks section. I found the flag in the DB but its not accepting my answer

storm elk
fathom pendant
#

Oof

storm elk
#

I think it has brainrot

last sorrel
storm elk
#

Killed it and all good

storm elk
fathom pendant
#

Looks like they got linked though

storm elk
#

But Iโ€™ll take that as a no

last sorrel
#

FeelsWeirdMan @storm elk

cerulean grail
#

Is PlsqlExclusionList a config file for Oracle TNS? It's unclear to me whether it also falls under that category or if its a different thing. My searches indicate that it's used for Oracle SQL Developer as opposed to Oracle TNS, but I'm not sure if they're the same thing.

vivid sigil
#

I've been working through the Footprinting Medium Lab and when i enum nfs share (TechSupport) i got 'TechSupport': Permission denied any idea ?

fathom pendant
#

It's one of the weird things about it

#

I'm assuming as well you used -o nolock when mounting as well

summer lava
#

when you have LFI in windows machine - which file will you likely target the most

fathom pendant
#

You mean like a world readable file?

summer lava
#

yes

vivid sigil
fathom pendant
fathom pendant
#

Careful with spoilers

summer lava
fathom pendant
#

@shut raft Your post contained a flag, be mindful of that when asking for help

fathom pendant
#

If it's not an academy module you'll need to ask in a diff channel

lofty phoenix
fathom pendant
lofty phoenix
#

I tried to enter that flag without the b and quotation marks but its not working

fathom pendant
#

Someone else also posted a question with a flag

lofty phoenix
#

im in the section for MSSQL enumeration and attacks

fathom pendant
#

๐Ÿ‘ I haven't done this module but always be careful with sharing the commands/output for modules above tier 0 especially

#

Especially if it contains a flag

lofty phoenix
fathom pendant
#

Using the spoiler tag for screenshots and images does nothing

#

As anyone can still click it

vernal sphinx
#

Hi friends, I'm in the last step in the using web proxies module, I can't answer the third riddle, what is the flag, 88 characters, I'd appreciate your help

#

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

tranquil lark
#

Help please, I think something is wrong with my target, reset the target twice and still everytime I nmap the new ip nothing :

fathom pendant
#

Also make sure to untick the "encode special characters" button at the bottom

fathom pendant
#

And section?

#

Did you try resetting the pwnbox

tranquil lark
#

Getting started - Nibbles - Initial Foothold

fathom pendant
#

Did you change vpn regions while the pwnbox was running?

tranquil lark
#

nope still always same region, I thought there was maybe a trick to it but if it's really just set up, I'll try it out later when I get home with a vpn connexion instead of the pwnbox

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

vivid sigil
tranquil lark
#

I was using US academy 2, humm maybe just a one off

tranquil lark
fathom pendant
fathom pendant
tranquil lark
#

yup pretty cool!

fathom pendant
#

That you give a link to a website/video that's spoiling content

#

It's not for redacting text

#

Either way

tranquil lark
#

||pretty neat to have it in the server tbh||

fathom pendant
#

The best way to redact/spoiler your message is to shorten things as much as possible like user *x

vivid sigil
#

||gdrghndkrghkgz||

fathom pendant
#

The manual way btw is ||text||

#

But again the spoiler text doesn't do shit

#

As anyone can click on it

#

Redacting is generally better

#

Like user t* or flag HTB{ab..90}

vivid sigil
#

alright ๐Ÿ‘Œ

tranquil lark
#

what's the redact command ?

fathom pendant
#

It allows those that have done the module to know what step/place you're on without fully spoiling

fathom pendant
#

Redacting is a manual thing

tranquil lark
#

ahh misunderstanding then x)

fathom pendant
#

Redact means to remove potentially sensitive info

#

Consider anything that you need to discover in a module as a spoiler if you ask for help

#

Such as usernames, passwords, techniques, payloads

tranquil lark
#

btw @fathom pendant have you had a stab at the cpts cert ?

fathom pendant
#

Not yet but soon

#

Been focusing on some other stuff atm

tranquil lark
#

was gonna ask you how long did it take to finish the pen testing path

fathom pendant
#

Overall time spent ~4 months

#

Actual time closer to a year due to unfortunate life circumstances

#

One of those circumstances left me without internet for a bit

tranquil lark
#

hope nothing too bad

fathom pendant
#

Thankful I had family to help

#

Otherwise I wouldn't be here most likely

tranquil lark
#

that's unfortunate, glad you got back on your feet and also got back that internet, mainly thanks to it you're able to help us out too :p

fathom pendant
#

I was still helping without internet, just mobile data

#

And I was not about to do academy via tethering

#

While possible, it would be painful

tranquil lark
fathom pendant
#

I kept good notes ยฏ_(ใƒ„)_/ยฏ

tranquil lark
#

speaking of which does the path fully prepare you for the cert test ?

fathom pendant
#

From what the dozens of people have said, yes

#

The exam doesn't stray from the course

tranquil lark
#

that's very good news

#

so good note taking and prepping will def help

#

guess you'll have a good time at the exam

willow heron
#

hello huys i am stuck in password attack module exactly in PTH module: Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt. i did get all hashs including david's, and did PTH attack when i try to list sahre folders \dc01\david i get permission denied any hints?

weak dagger
#

Broke Authentication Skills Assessment

I realised that brute forcing OTP is a rabbit hole, what do I actually look for here could anyone please give me an hint?

acoustic owl
#

The module shows you many possibilities, except bruteforce. Try it with one of this

weak dagger
tender nimbus
#

hey guys im doing the vulenrability assigment rn, do you guys use nessus a lot or not? I never heard about it?

acoustic owl
fathom pendant
#

from what i've heard others say those tools are best used if you've run out of ideas

tender nimbus
tranquil lark
#

Iโ€™d suggest you spin an OpenVAS if you want to do a vuln scan for free since itโ€™s open source and free instead of Nessus. Also itโ€™s just a scan so you still need to take a stab at it manually but to just practice using it OpenVAS is plenty good

fathom pendant
#

generally you'll have a better idea of what to test by evaluating a target manually

#

vuln scan tools generally get better in places where there may be > 10 hosts internally to scan

vivid sigil
#

Footprinting Lab - Medium

any hint for what database or anything that can help someone he didn't use sql interface for whole life

fathom pendant
#

sometimes a service may be running internally and not exposed externally

#

also he could have used it via the GUI not via Commandline

#

๐Ÿ˜‰

vivid sigil
#

so clear

fathom pendant
#

did you discover the important file?

#

i mean the SQL section did discuss the MSSQL Studio

vivid sigil
fathom pendant
#

so now just click and look around for a non-standard database

#

once you find the table, you can right-click and find what you're looking for

vivid sigil
#

got it with gui

#

i uesd mssclient but it didnt work

fathom pendant
#

did not work isn't an error

#

as i said though a service can be running but not be exposed to the outside

tender nimbus
#

hey guys who already did this?

weak dagger
fathom pendant
#

it's literally utilizing the existing scan to run queries against

#

just gotta connect to https://[target_ip]:8834

novel lynx
#

lol NSFW content immediately taken down from content hosted in HTB

fathom pendant
#

potential spoiler was taken down

#

:P

#

also there was nothing nsfw about it it's just about ms exchange

#

which is microsoft's mail server stuff

novel lynx
#

wow, I really thought that was something else entirely

cloud urchin
#

you should delete that as it spoils the skill assessment

weak dagger
#

I mean put it in the hidden quotes ๐Ÿคทโ€โ™‚๏ธ

fringe shell
#

has anyone done the injection attacks assessment? I'm some way through it and think I know the path but it's going to take some effort. Just wanting to confirm I'm on the right path before investing the time ๐Ÿ˜…

uneven cairn
#

Hi, why this isnt working? im SQLMap Essentials Bypassing Web Application Protections sqlmap -u http://ip:port/case8.php --data="id=meme&t0ken=sl49lFNxPH2KtsrJ2ZdKr38NbNManBaNOnsDhpQbw" --csrf-token="t0ken" --batch --level 2 --risk 2

#

module/58/section/530

cloud urchin
uneven cairn
#

sorry i already solve it i forget --dump

frank sun
#

hey guys, https://academy.hackthebox.com/module/158/section/1441
In previous pentests against Inlanefreight, we have seen that they have a bad habit of utilizing accounts with services in a way that exposes the users credentials and the network as a whole. What user is vulnerable?

After being stuck on this for a sometime, I took the hint and proceeded. How to transfer the file from target host to my machine, I tried the file transfer methods via proxychains wrapper but from target its unable to reach my machine ip.

in previous sections, I used copy & paste from GUI to pwn machine (parrot from HTB) it worked, but now from my personal machine its not copying. Strangely I can copy from my machine to RDP but not vice versa.

#

any hint/suggestion on how transfer file from RDP to my machine?

uneven cairn
#

it is recommended to perform only basic UNION tests if there is not at least one other (potential) technique found. Do you want to reduce the number of requests? [Y/n] Y

[6]+ Stopped sqlmap http://ip:port/case9.php?id=hp
bash: Y: command not found

#

wtf litreally i cant answer Y or n cause command not found

sick whale
#

I also struggled with that part, I couldn't copy paste, and the SMB share way was very convoluted and confusing to me (as I was using a ligolo/netsh mix).

#

So the meterpreter way ended up working well

unique ether
#

Another day

frank sun
#

okay, let me try meterpreter way, thanks

sick whale
#

No prob, let me know if you succeed

frank sun
#

no portfwd command on msf6?

sick whale
#

Hmmm I don't know, I already had all my tunnels in place, so I only used the multi handler and spawned a reverse shell on the pivot

#

But there should be a portfwd

#

Yup doc is saying it exists

frank sun
#
[-] Unknown command: portfwd. Run the help command for more details.
msf6 > help portfwd
[-] No such command
sick whale
#

meterpreter > portfwd add โ€“l 3389 โ€“p 3389 โ€“r [target host]

#

Aaaaah that's after you get your meterpreter session then...
Not super familiar with this tbh

frank sun
#

upgrading ... msfconsole

#

NotLikeThis didn't see target machine time out. Okay, I am out, will give it a try later today. thankxx buddy

sick whale
#

Hahahaha the same happened to me

#

Next time I tried, I just extended the machine by 4h when I spawned it

#

Good luck!

fringe shell
rustic sage
#

Working on the Whitebox Attacks - type juggling authentication bypass and could use a nudge. DM would be appreciated

plain folio
#

Im looking to buy the htb cpts and was wondering if I could get an annual student plan instead of a monthly plan?

storm elk
#

there is no annual plan for students @plain folio

plain folio
#

Is that something that could be set up if I contact support maybe? Its because my company are going to fund it and its easier to claim back for annual subscriptions

storm elk
#

but with the monthly plan you can access all tier 2 modules

plain folio
olive slate
#

Hi folks. Can anyone help with Introduction to Windows Evasion Techniques > Statis Analysis? I've followed the steps to create the exe and tested that it works on the DEV box. But after transferring to the target and putting it in the target folder, the log.txt said it passed the check but I've waited and waited but the flag.txt file is not created.

foggy monolith
#

Pivoting, Tunneling, and Port Forwarding

ICMP Tunneling with SOCKS

$ sudo ./ptunnel-ng -p10.129.202.64 -l2222 -r10.129.202.64 -R22 &
Segmentation fault (core dumped)

Why would ptunnel-ng ever be throwing SIGSEGV here? Remote server works fine; it's the client on my local machine (again, running Arch-based Garuda Linux with all the BlackArch tooling installed on top of it) that's doing this.

cloud urchin
olive slate
cloud urchin
#

do you have a port forward setup or something?

olive slate
#

No. I did it on the pwnbox

cloud urchin
#

right but the dev box can't reach the pwnbox can it?