#modules

1 messages · Page 331 of 1

next bronze
#

but this is just straight up wrong way to use a code block, the string after ``` should denote the language

#

with the plugin you can get it to look like this

pseudo kiln
#

hmmm i will have to look into this plugin, thx

safe star
#

change the FILEPATH

junior flicker
#

Morning, I'm working through the Password Attacks module and am stuck on the Linux Credential Hunting where I need to find Will's password. I saw the hint about another user, but I've spent a few evenings trying to brute force FTP & SSH with the password.list the hint referenced to no avail. Any ideas what I'm doing wrong?

rocky mist
#
└──╼ $netexec winrm 10.129.42.197 -u user.list -p password.list
┌─[aesliex@parrot]─[~]
└──╼ $```
#

why isnt my netexec thing working

next bronze
#

either way don't try to bruteforce winrm, it's slow af

rocky mist
next bronze
#

well it says to crack the password

#

also what module and section

rocky mist
rocky mist
junior flicker
#

crackmapexec and I think I used a password list from SecLists

next bronze
#

oh that section

rocky mist
junior flicker
#

@rocky mist

next bronze
#

yeah you have to use winrm then, are you connected to the vpn?

rocky mist
junior flicker
next bronze
next bronze
midnight galleon
#

Attacking Common Services - Easy
what is the other way in? i used the mysql one

#

tried to poke at the ftp server but didnt find anything

safe star
midnight galleon
#

when listing

midnight galleon
safe star
#

the ftp server is also on http

midnight galleon
#

which means?

safe star
#

have u logged on the http ftp?

pseudo kiln
# next bronze netexec is just cme but better

sorry for the tag, can I ask how you figured out how to change the codeblock text color ? I can only change the inline text color, but not the code block text color, no matter what color I chose it stays the same

midnight galleon
#

the ftp server only have two files

#

i think they are talking about what you just said

next bronze
safe star
pseudo kiln
#

no just regular text

#

the expectation is to color it black, but its not

midnight galleon
#

upload shell to the ftp server

#

and execute it over the web app

safe star
midnight galleon
#

huh, not taught in the module but its a good way

pseudo kiln
midnight galleon
#

now what is the rdp doing?blaze

safe star
#

idek

jade latch
pseudo kiln
#

thats the point :), it's too grey to decypyer when it should be black instead

next bronze
#

use a different theme then

#

or the style settings plugin should work

pseudo kiln
#

i just use the default, which theme are you using ?

jade latch
#

minimal theme has many themes

next bronze
#

yeah I use minimal

pseudo kiln
#

installed minimal, and no change

#

guess I have to troubleshoot from a default obsidian install, maybe there is something confilicting

next bronze
#

install and activate it, then change the color scheme

pseudo kiln
#

yeah, what I did, installed minimal selected it, tried to change the color again

limpid hemlock
#

Hey

normal sand
#

Module: Linux Privilege Escalation
Section: Docker
Link to section: https://academy.hackthebox.com/module/51/section/2411

Found this section to be a little confusing. So, the only exploit discussed in this section is the final command?

||```sh
docker -H unix:///var/run/docker.sock run -v /:/mnt --rm -it ubuntu chroot /mnt bash

If someone could provide some additional explanation I'd appreciate it.
limpid hemlock
#

Im doing the exploiting we vilnerabilities thick client section there we have a creds to logon to a fatty client jar app using a creds given but i cant login even after i did as mentioned in the section

pseudo kiln
safe star
zenith schooner
#

any body working on xSS module? I am working on the phishing exersise. I test my payload and it works but when I send it to he valdation page it says invalid URL. What is the criteria to validate the url? thank you

safe star
#

I don’t remember the module explaining the commands tbh

normal sand
safe star
#

Ur mounting the hosts / directory to the /mnt directory in the container

rustic sage
#

Pivot, Tunneling and Port Forwarding Module - SKILLS ASSESSMENT :

  • Question 6: "For your next hop, list the networks and then use a common remote access solution to pivot. Send the C:\Flag.txt located on the workstation"
    Am I performing a network scan but only find IP addresses 15 and 35 that I'm performing wrong? And I imagine that I have to look for a username and password to pivot but I get lost because I can't find the password as such, I appreciate if someone helps me
safe star
#

Chroot changes the containers / directory to /mnt so its automatically in the hosts /

narrow mesa
#

im at the windows section under "setting up" and im confused on how to set up windows vm after downloading the zip file for vmware can anyone help me out?

normal sand
pseudo kiln
normal sand
pseudo kiln
#

hmmm, I have it my notes as "Docker Membership Priv Esc", not sure if it has a specific name

limpid hemlock
#

Any help i cant seem to login to the jar file using the creds given in the exploiting web vulnerability in thick client section

safe star
#

Did u switch the port?

limpid hemlock
#

Yss

tender nimbus
#

Hey guys any idea why its not working?

safe star
#

And recompiled it?

tender nimbus
#

I dont understand the error?

safe star
tender nimbus
#

i uploaded the zipped file on the targed but i can't connect to it rn with rdp to unzip it and take the hash

safe star
#

Try restarting it

tender nimbus
#

i already did a full port scan but only 22 and 80 are open

safe star
#

worked fine for me

reef jay
#

hey guys, the Attacking Common Services "Attacking FTP" has no port open

#

anyone faced that issue?

safe star
#

maybe u need to switch vpn servers

safe star
#

if the machine lags when u scan, u will miss it

reef jay
#

I did restart the Target IP many times, no use

#

It's just purely closed.

safe star
#

its there, the machine is just really laggy

reef jay
#

Alright

tender nimbus
#

it was with ssh

junior flicker
#

I'm working through the Password Attacks module and am stuck on the Linux Credential Hunting where I need to find Will's password. I saw the hint about another user, but I've spent a few evenings trying to brute force FTP & SSH with the password.list the hint referenced to no avail. Any ideas what I'm doing wrong?

safe star
junior flicker
#

Ahh, I was thinking of doing that, thank you!

safe star
#

yeah idk why they hid a core part of the question in the hint

wanton jasper
#

Question on sqlmap "What's the Kimberly user's password? (Case #1) " I got the answer by dumping everything and using grep. Was there an non grep method I missed? I know we can search for specific table and column names but can we search for specific values like a user name?

languid ginkgo
#

Module: [Active Directory Enumeration & Attacks]
Chapter: [AD Enumeration & Attacks - Skills Assessment Part I]
Question: [Submit the contents of the flag.txt file on the Administrator desktop on MS01]
hello,
how can i make a pivot ? i tried with ligolo and chisel (bind and reverse), but it doesn't work.
Maybe I can give more explanation in DM

safe star
steady valve
#

in linux privilege escalation > priveleged groups, i found the flag but for some reason it's telling me its incorrect

#

not sure how possible it is, but can someone confirm the flag i got is the actual flag?

safe star
steady valve
#

nevermind, just got it

#

two identical flags but one had a special character and i thought i had to exclude it

rough tree
#

Any nudge on the Skill assestment lab of the Windows lateral movement lab?

hard matrix
#

for some reason im mega stuck on AD skills assessment 1 Find cleartext credentials for another domain user.
I can get the NTLM hash for tp****** user using lsassy with nxc, and pth with nxc to auth as that user, but i feel like im missing something from the module. I'm starting to go down various rabbitholes but feel like im missing something extremely simple

languid ginkgo
hard matrix
safe star
#

did u run a reverse shell through the web one?

hard matrix
fathom pendant
languid ginkgo
languid ginkgo
hard matrix
# safe star did u try mimikatz

yeah, but still was only really able to get an ntlm hash. im trying to go back through my notes and see what other ways of dumping cleartext creds were covered but i feel like its right in front of my face and im just ignorant

#

is mimikatz for sure the correct path for getting the cleartext password its looking for?

twin lion
#

The first targets to go for for finding clear text creds after SYSTEM access

SAM Db
LSASS process memory dump
Dpapi + Browser creds
Files found on system

#

But to get clear text you’ll have to crack the NTLM hashes in Sam db

hard matrix
#

yeah im clearly doing something slightly wrong, ive checked lsa / dpapi with mimikatz +nxc
the NTLM isn't crackable with rockyou (and probably isnt the intended way to get the password its expecting)
i went and checked sysvol/powershell history/some program file directories because that seemed to be another place to check for cleartext creds
maybe i need to just bang my head against the box a little more

fathom pendant
#

Iirc there's lsadump::sam which requires admin

#

There's a hacktricks page that has them listed

cedar cobalt
#

hey all, I am struggling with this question on the Windows Cmd Line Skills Assessment. I am able to see all the "flag.txt" files but not entirely sure has the flag in it because there are tons.

#

"User4 has a lot of files and folders in their Documents folder. The flag can be found within one of them."

fathom pendant
#

Well you might want to learn about recursion then

#

gci [get-ChildItem] in powershell

#

Since all but the actual flag one is empty you'll only receive output for the flag :]

#

If you're sure the format is HTB{..} you can pipe the output to "Select-String" (powershell's grep)

rustic sage
#

Is it possible for bloodhound to miss information about an AD environment? I guess it depends on what domain user you're running as, right?

fathom pendant
#

But it can miss some stuff

#

@nova ginkgo let's not reveal contents of the AEN module as many do it blind, since the module itself is the walkthrough

#

I suggest using a larger list

rustic sage
fathom pendant
#

And using filters

vale island
fathom pendant
cedar cobalt
fathom pendant
foggy monolith
#

Given what came out of today's AMA, are there any plans to offer an "ICS Penetration Tester" role path and associated certification? After all, attacks on industrial control systems can cause far more damage than attacks on anything else, so it follows that this is where the most demand lies.

fathom pendant
#

I gave you a powershell command you can look into

fathom pendant
fathom pendant
tender nimbus
#

New question, it don't work here any help, i cant use unzip and the gunzip is the hint i received

fathom pendant
#

If not, then your notes suck

fathom pendant
#

Is that the common size returned?

#

I generally just throw -ac and let ffuf decide kek

cedar cobalt
# fathom pendant Sorry I'm gonna be busy soon

Yeah, I don't know what is going on but I just get a "'Get-ChildItem' is not recognized as an internal or external command,
operable program or batch file." while in the Windows terminal

fathom pendant
#

There's also findstr

#

But findstr can be clunky (since it's built for CMD)

nova ginkgo
fathom pendant
nova ginkgo
gilded lion
fathom pendant
#

Just from a base observation

fathom pendant
#

? Well I'm sure the file you need to extract on the linux host is not the "win_upload.zip"

#

Mb upload_win.zip

tender nimbus
fathom pendant
#

🤦

fathom pendant
#

Second unzip should be on that host no?

sacred jacinth
tender nimbus
tender nimbus
fathom pendant
fathom pendant
#

But it helps to use the right file

safe star
#

the command worked fine for me

#

just copied and pasted it

sacred jacinth
#

^

tender nimbus
fathom pendant
tender nimbus
#

its jsut weird bcs with scp upload everything worked fine im just trying other ways

safe star
#

try transferring with scp or wget @tender nimbus

nova ginkgo
tender nimbus
fathom pendant
#

??

tender nimbus
#

id its not the same hash then my awnser on the question

fathom pendant
#

You ran the hasher command on it yeah? Weird then if there's some difference

#

The zip and txt file will have different hashes ofc

nova ginkgo
safe star
#

i think its because you use -o instead of -O

tender nimbus
#

Ow okej wait there is a problem with the file? when i download it on my host it becomes the _win and not the _nix?

fathom pendant
fathom pendant
tender nimbus
#

No its the only one on htb

#

but im logging out and cheking it

fathom pendant
#

I clicked the link from that section and download the upload_nix.zip just fine

tender nimbus
#

okej know it worked sorry that was weird

fathom pendant
#

Maybe some cache error

tender nimbus
#

Yeah maybe but stil cant unzip it srsly im gonna try again with scp

rustic sage
# safe star Dump creds

But in this case I would have to perform the sam dump and bring the data to my attacking machine to do the decryption?

fathom pendant
#

You can do that, yes

#

Iirc linikatz can do lsass dumps

#

Been a hot minute

tender nimbus
#

weird with scp it work but not if i run my own server on my machine

rustic sage
#

What I'm trying to do is move the files to my local machine to do the decryption and I do it with smbserver.py

#

I want to know if I need to transfer the Mimikatz tool or this is the way to use it within the Pivot Host

fathom pendant
#

You can

#

There's multiple ways to achieve an objective

rustic sage
#

This hacking when you are learning is a headache jejejje

sick whale
#

Learning anything is a headache, that's your brain working :p

fathom pendant
#

It's hard to break out of "only one true method"

#

You will generally fall into a method that's the easiest or simplest to do for you

#

But knowing multiple tools for the same goal is helpful

rustic sage
#

I think that in order to move the files as it does not reach my attacking host then there is where I am like stuck because I don't know if I have to move them to the point of support

fathom pendant
#

Pivoting is a helpful skill to know

fathom pendant
#

^

#

Otherwise you transfer to your pivot host then from your pivot host to you

rustic sage
#

If I have the ideas ogranized I have to dump LSASS but I need to transfer that to my attacking machine to be able to decrypt it and be able to enter RDP from the pivot host to the other machine with the information it finds is something like this?

sick whale
#

How does one report a typo in a module?

hard matrix
sick whale
shell ore
#

just state the module name in the title, and tell where the typo is in the content

sick whale
#

Thanks!

wide glade
#

XPath - Data Exfiltration (Excercies
Why does GET /index.php?q=ave&f=full+|+//* work - prints all the data
Why GET /index.php?q=ave&f=full+|+/*/* Doesn't work - print just 3 <br>
in returning the data in XML doc

sick whale
#

I think the question is more about the regex for f= (the GET is just before in his message, I assume he messed the code quote)

cobalt shoal
#

hi

#

i'm struggling with Firewall and IDS/IPS Evasion - Hard Lab in NMAP. can't find the flag requested

sick whale
#

You will need to ask a more specific issue to get an answer (haven't done this module yet so it won't be me, but many helpful people around will nudge you in the right direction if you describe your struggle)

cobalt shoal
#

"Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer."

#

also why I can't send the screen

shut quest
#

Not what HaTxx meant. Provide more details on what you've tried without posting spoilers

cobalt shoal
#

Network Enumeration with Nmap Module. I tried different nmap scan to find the version of services but can't find any flag that they are requesting

old oasis
cobalt shoal
#

I mean I found port 22 and 80 and the relative version of services running on it. BUT any answer submitted results incorect

sick whale
#

I've not done the module, so here is a question: What service the client was talking about?

shut vapor
sick whale
sick whale
river spear
#

I am currently working on Footprinting > IMAP/POP3. I am currently trying to figure out the admin email address. I have tried:

  1. ||sudo nmap <target> -sV -p110,143,993,995 -sC||
  2. ||openssl s_client -connect <target>:imaps||
    2a. ||Running commands inside of the connection||

However, the only email address I have been able to find is ||cto.dev@dev.inlanefreight.htb|| (which is not correct)

cobalt shoal
olive birch
#

Hi
I am currently working on the Linux Fundamentals. At a moment I need to count how many services are listening on the target system on all interfaces (not on localhost and IPV4 only)
Spoil on answer be careful if you are working on that
||I wanted to use netstat as teached and was getting 10 as an answer but it was wrong. When I checked some forums they told me to use ss instead of netstat.||
||Could someone explain to me why ss which is supposed to replace netstat is not getting the same answer?||
||For reference this is was I used : ss -l -4 | grep -v "127.0.0" | grep "LISTEN" | wc -l instead of netstat -l -4 | grep -v "127.0.0" | grep "LISTEN" | wc -l||

gray yacht
gray yacht
river spear
#

Yeah, I have read this a few times, but have not been able to replicate anything useful. Is there a specific section that may be of use? All of the commands which they recommend, turn out to not be accessible on the connection

gray yacht
cobalt shoal
cobalt shoal
gray yacht
vivid sigil
#

is there anyone who finish this module Stack-Based Buffer Overflows on Linux x86 ?

cobalt shoal
#

yes I just realised that you need to ncat that stuped thing NotLikeThis

wind fossil
#

In Misc CSRF Exploitation, I’m struggling to get this one working.

  1. gobuster does not find any subdomains as mentioned
  2. the app stays on the profile only a few seconds then logs out. By the time I deliver the payload the app has logged out.
hard matrix
#

for the username enumeration i think nmap has a script to try all the different methods

rocky estuary
#

i'm doing the attack common service - easy lab i found both the user and its password but can't connect to mysql i get this error ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it

somber fiber
#

if that can get you through with that.

rocky estuary
somber fiber
rocky estuary
somber fiber
rocky estuary
somber fiber
#

you should have greped it

rocky estuary
wheat meadow
#

hi guys im new here
im a student and interested in learning cyber security can yall help

compact patrolBOT
frosty ferry
#

@wheat meadow use this ☝️

mint vector
#

Hi, a new student here

lusty thicket
river marsh
#

starting at the beginning with cracking into HTB curl inlanefreight.com is failing, do i need to be connected to the VPN for it to work or is that just a completely made up website name?

cloud urchin
#

that's a real website you can visit

river marsh
quasi wave
#

hi I'm stuck on the Attacking SAM section of the Password Attacks Module. I'm specifically stuck on the 3rd question. I'm gonna try again tomorrow but would it be a bad idea to look at a walkthrough of it up until the third question? Would it be possible for me to get a hint tomorrow if I'm still stuck? I don't want to be stuck on this one section for several weeks. I still want to get it obviously.

#

What do you recommend because I still want to learn?

cloud urchin
#

you should just post where you're stuck at

quasi wave
#

Ok. I will try again tomorrow because I think I'm missing some stuff but tomorrow I will try the whole thing again and post where I am stuck at.

#

When it gets to that point

#

its mainly on the third question if you look at the last major thing the section teaches

#

The Remote Dumping and LSA Secrets Considerations part

#

I do it but it won't get me the result I want

#

I kind of played with it a lot

cloud urchin
#

ok but the question itself tells us nothing about where YOU are stuck

#

you haven't said what you've tried, where you can't get past, etc

#

so like i said before.. just say what you're stuck on

quasi wave
#

ok I need to do it again to tell you so tomorrow morning I'm gonna do it again and then tell you where I'm stuck

late moth
#

on the pivoting module I am trying to do the RDP Socks Tunneling with socksverRDP section with chisel instead. I have a chisel client and server set up and connected. But I cannot for life of me get an rdp session from my attacker box. Have proxychains set up to use the proper local port. Any suggestions?

cloud urchin
#

for all we know you're trying to dump SAM by going to the bathroom

quasi wave
#

that's exactly right

#

no but seriously, I think I want to try again when I'm focused and can make a good attempt and give you a good in depth report of everything I've tried

#

and why I'm stuck as well, because I think that it would take actual focus to explain

late moth
#

On my attack box i set up chisel by "./chisel_1.7.6_linux_amd64 client -v 10.129.6.89:1234 socks " on the windows pivot box I have ".\chisel_1.10.0_windows_amd64 server -v -p 1234 --socks5" but when i use "roxychains xfreerdp /v:172.16.5.19 /u:victor /p:pass@123" from my attack box it doesn't connect

cloud urchin
quasi wave
#

I try the exact command and I don't get results or I'm not accessing the results properly

cloud urchin
#

alright well come back with more info then because 'not working' doesn't tell us anything

#

for example, maybe it's not working becasue your keyboard isn't plugged in

#

we have no starting point to know where you're at by just telling us 'i need help'

quasi wave
#

actually I'm gonna try to get it over with right now so I can show you

cloud urchin
quasi wave
#

that way I can show you what's going on

late moth
cloud urchin
late moth
#

i gotcha. True. I'll give it a shot

quasi wave
#

now its not letting me RDP into it. I have RDPd into it in the past:

┌─[us-academy-1]─[10.10.14.27]─[htb-ac-605555@htb-a5lessvu94]─[~]
└──╼ [★]$ sudo xfreerdp /v:10.129.202.137 /u:htb-student /p:HTB_@cademy_stdnt!
Authorization required, but no authorization protocol specified

[20:46:06:642] [9015:9015] [ERROR][com.freerdp.client.x11] - failed to open display: :1
[20:46:06:643] [9015:9015] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.
plain folio
#

Is it just me or is the linux fundamentals module not beginner friendly?

quasi wave
#

so should I just reset target or Pwnbox?

plain folio
cloud urchin
quasi wave
#
┌─[us-academy-1]─[10.10.14.27]─[htb-ac-605555@htb-a5lessvu94]─[~]
└──╼ [★]$ sudo xfreerdp /v:10.129.26.27 /u:Bob /p:'HTB_@cademy_stdnt!'
Authorization required, but no authorization protocol specified

[20:49:00:081] [13531:13531] [ERROR][com.freerdp.client.x11] - failed to open display: :1
[20:49:00:081] [13531:13531] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.
#

still won't work even after I reset target

cloud urchin
#

what module/section

#

rdp and socks tunneling with socksoverrdp?

quasi wave
#

this is for the Attacking SAM section of Password Attacks Module

cloud urchin
#

you don't need sudo for xfreerdp btw

shut quest
quasi wave
#

hold on let me try something

#

got it working the rdp

#

now I'm gonna try the next step

cloud urchin
#

i ran the command they showed in the module and was able to do it np

quasi wave
#

so I ran the command

#

and here's what showed up

#
┌─[us-academy-1]─[10.10.14.27]─[htb-ac-605555@htb-wuloikg0dj]─[~/Documents]
└──╼ [★]$ crackmapexec smb 10.129.42.198 --local-auth -u bob -p HTB_@cademy_stdnt! --lsa
[*] First time use detected
[*] Creating home directory structure
[*] Creating missing folder logs
[*] Creating missing folder modules
[*] Creating missing folder protocols
[*] Creating missing folder workspaces
[*] Creating missing folder obfuscated_scripts
[*] Creating missing folder screenshots
[*] Creating default workspace
[*] Initializing MSSQL protocol database
[*] Initializing WINRM protocol database
[*] Initializing LDAP protocol database
[*] Initializing SMB protocol database
[*] Initializing SSH protocol database
[*] Initializing VNC protocol database
[*] Initializing WMI protocol database
[*] Initializing FTP protocol database
[*] Initializing RDP protocol database
[*] Copying default configuration file

So it might have worked but then where do I get cracked username and password?

#

see my issue? same thing for the other variation on the command

#

that's what I'm having issues with

#

that's the main thing

cloud urchin
#

quotes being wrapped around special characters is a linux thing, not just a xfreerdp thing.

quasi wave
#

ok

cloud urchin
#

you need to do it every single time you're trying to input a literal string.

quasi wave
#

ok

#

but then it shows this:

┌─[us-academy-1]─[10.10.14.27]─[htb-ac-605555@htb-wuloikg0dj]─[~/Documents]
└──╼ [★]$ crackmapexec smb 10.129.42.198 --local-auth -u 'bob' -p 'HTB_@cademy_stdnt!' --lsa
#

and nothing after that

#

where is the data stored then?

river marsh
#

so going through the module curl https://inlanefreight.com should print out some sort of error, but when i run it nothing prints out. i dont have the -s flag and confirmed curl http works

cloud urchin
quasi wave
#

its not displaying it on my screen

#

even when I do it in single quotes and capitalize Bob

#

like first letter of Bob

cloud urchin
#

the only time i've seen CME not return results is when it can't connect to the target, from what i recall

#

you can also try nxc, which is the successor to cme

river marsh
quasi wave
#

wait I changed target IP which I did earlier but it may have worked this time hold on a sec

cloud urchin
river marsh
#
@htb[/htb]$ curl https://inlanefreight.com

curl: (60) SSL certificate problem: Invalid certificate chain
More details here: https://curl.haxx.se/docs/sslcerts.html
...SNIP...

but the example is should i should get this

cloud urchin
river marsh
river marsh
#

part of the Cracking into HTB

quasi wave
#

I got flag

cloud urchin
#

ez

quasi wave
#

minor thing I was not figuring out ya

cloud urchin
river marsh
#

is there any way to find a https:// web page that has an invalid cert?

cloud urchin
river marsh
cloud urchin
#

i just gave you one

river marsh
#

ty

orchid monolith
#

Have anyone done the blind sql injection module?😅

shut quest
orchid monolith
#

I have been stuck at time based data extraction section, the Python script I don’t understand why when I get the result and submit it the flag isnot true whether I set delaytime is 1,2,3,4 s. Can anyone give me hints, I guess the problem at the oracle function.

storm elk
#

Oh wait that’s the blind sql injection module. Didn’t have this issue there tbh

shut quest
orchid monolith
shut quest
orchid monolith
shut quest
#

Exactly what I said then, run it multiple times, and figure out the common parts of the string.

limber river
#

weird

shut quest
#

You also might have better luck from the pwnbox as I'd expect it might have a more stable connection to the spawned instance.

limber river
#

maybe using a longer timeouts will help

orchid monolith
orchid monolith
#

ah, I see, thank you.

storm elk
#

Feel free to dm me your code and I’ll have a look

orchid monolith
orchid monolith
orchid monolith
#

I got flag thank you so much everyone

cloud urchin
#

you should remove those creds from your post its revealing info from the skill assessment you dont need to reveal

restive heath
#

I am doing Windows Priv esc module at SeTakeOwnershipPrivilege lesson. In the lab my whoami /priv does not even have SeTakeOwnershipPrivilege. How am i suppose to do this lab?

somber fiber
#

Remove this

#

and have you really checked for what you actually got the credentials for?

#

or you just saw the credentials and applied it?

#

altho same creds are going to get used twice.

restive heath
forest gust
restive heath
hexed tartan
flat sleet
#

where can i ask help on networking? im new guys

forest gust
dull sparrow
#

hi guys

#

im new here

next bronze
#

statically compile it or grab one from the repo release page

hot lodge
#

Hi guys for the footprints medium lab I keep getting permission denied, any reason why

faint geode
#

Please give more information, like what have you tried, show the commands etc, more information you provide the more people can help

hot lodge
#

I can't attach images for some reason

#

showmount -e 10.129.135.131
Export list for 10.129.135.131:
/TechSupport (everyone)

mkdir target-NFS

sudo mount -t nfs 10.129.135.131:/TechSupport/ ./target-NFS/ -o nolock

cd target-NFS/
bash: cd: target-NFS/: Permission denied

next bronze
#

moutning is done with sudo

#

but which user are you changing dir as

hot lodge
#

Htb-ac

next bronze
#

yes

hot lodge
#

Thank you, I switched to root user and it worked, crazy how I didn't think of that before

somber fiber
#

issue must be related to latest build vs old build of chisel

somber fiber
forest gust
restive heath
forest gust
forest gust
restive heath
scarlet tundra
#

hey, I'm in the password attack trying to do the Network Services to get the flag from the user victim but the dir command doesn't work

#

I can't upload an image for the problem

gray yacht
scarlet tundra
#

im in the user victim machine now

#

after I get the user name and the password i do "evil-winrm -i <target-IP> -u <username> -p <password>"

#

And it is an excellent aspect that I can't write anything

#

warning: remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

this is the problem

next bronze
#

that's just a warning, won't affect you sending commands

scarlet tundra
#

yes but the command line dont work

next bronze
#

why not? just type something and send it

scarlet tundra
#

First of all, thank you for helping me, but it is important to note that the problems I encounter will always be strange

next bronze
#

if you see that warning that means you're connected to the winrm shell

scarlet tundra
#

That's right, I logged in, and then I have to go into the file to remove the flag, the problem is that the commands don't work

next bronze
#

if you wanna send images, read #welcome and get verified

gray yacht
next bronze
#

maybe because there's no files in that dir?

#

have you tried other commands

scarlet tundra
#

yes

#

nothing works

gray yacht
#

Most of the time the flags are elsewhere.

#

Just look around but don't over think it.

scarlet tundra
#

I tried to go to john folder its dont do nothing

quiet trout
gray yacht
#

Also images that have spoiler information, i.e., the answer shouldn't be shared, which is why I said to DM a screenshot.

next bronze
#

run whoami

#

what do you see

quiet trout
# scarlet tundra I did,

you seem to be unable to do basic file system traversal and are missing a key understanding of file system hierarchy and such, tho? what would lead you to believe the flag would be in one dir, then when you dont find it, not know to look elsewhere? i think you should start over. unless this is a troll.

scarlet tundra
gray yacht
scarlet tundra
gray yacht
#

But like exciton said, if you don't understand how to move around a file system, it is recommended to get those basics down first.

quiet trout
quiet trout
#

can you link us to the module? i think i know the one you're doing.

scarlet tundra
gray yacht
#

I am running through that section for funsies and it works. The flag is where it would normally be.

quiet trout
#

ok i dont have access to that one. best of luck, you'll get it sorted. normal location should be something to note when you do find it. also since you're in powershell consider using the Get-ChildItem cmdlet to search for a flag.txt or whatever the lab tells you its called to search the system to find it.

make note of where "normal" locations are so you can just keep that in the back of y our head for later labs

gray yacht
# scarlet tundra you did "dir"?

Eh, there are a few ways of displaying the flag, but yeah I changed directories to where the flag was and used dir to identify it's existence.

quiet trout
#

@scarlet tundra man Get-ChildItem or check the msdocs page, look for the examples that searches the entire filesystem, it seems like you're close.

#

Do most of yall pair a module or concept with a box? Ive been ignoring this in an attempt to force feed myself info as fast as possible... answering questions though (sometimes) helps to reinforce the info... or atleast makes me think i know what im talking about

#

@gray yacht ^

#

and anyone else currently active for that matter.

#

wondering about ways to solidify the info and not have it forgotten as soon as the next module is begun, but balance that against a continuing effort to learn/retain info (i need this stuff learned, quickly)

next bronze
#

practice does help but the assessments in modules are sufficient for the most part

quiet trout
#

oh thats a good point, i should prob return to them and redo after a few days/week just to double check

gray yacht
scarlet tundra
#

I did it, thanks

gray yacht
midnight galleon
#

what is the intended for Attacking Common Services - Medium?

limpid hemlock
#

Hey im in the exploiting web vulnerabilitiws in thick clietn part i try to download a fatty servwr jar file into system at a point in the exervixe but i get this error

limpid hemlock
safe robin
#

i cant be able to upgrade to fully intractive shell anyone?

midnight galleon
#

Ctrl + z

#

stty raw -echo

#

fg

#

reset

safe robin
safe robin
safe robin
midnight galleon
safe robin
#

naah didnt worked

midnight galleon
#

depends on ur terminal but if you are not into weird ricing / distros its xterm-256color

midnight galleon
#

that is next level script kiddingkek

#

xterm-256color

safe robin
#

oh shit now i get it i copied that word "probably too"

midnight galleon
safe robin
#

i have been working for hours and maybe i need a break for now

#

i fffffff up my mindkek

midnight galleon
shut quest
#

I've re-wrote this message 3 times now 😄

Yeah those were the things I was going to suggest.

midnight galleon
#

for now i think the intended way is to use rustscanbig_think

shut quest
#

I wouldn't, it misses ports left and right. Also would you mind removing your replies as they are a bit spoiler ish

pale granite
#

same issue here, were you able to solve it?

forest gust
shut quest
forest gust
shut quest
forest gust
#

Through the console works thank you.

#

Despite the fact that I have been using Windos console commands for a very long time, unlike Linux, I do not know, you need to learn 😦

shut quest
finite chasm
#

Hi everyone,
a few months ago I completed the SSRF section of the server-side attacks module and really enjoyed the content and labs. I would like to go back to refresh those techniques, especially the use cases in SSRF Exploitation Example and Blind SSRF, however the module has been completely updated. Therefore I would like to ask, is there a possibility to access the old contents of the module?

shut quest
nova ginkgo
#

Hello I waited about 1 hour spawning but still spawning why ?

Attacking Common Applications : PRTG Network Monitor

fading kettle
#

Hello, I am stuck on the skills assessment for Understanding Log Sources & Investigating with Splunk " find through SPL searches against all data the process that started the infection. Answer format: _.exe". I found the answer already to the previous question that asks for the "the process that created remote threads in rundll32.exe." Steps taken so far: used the previous executable identified and pulled the destination IP and Source IP preivously identified, created a Table with the messages field and went through all the executables. No luck there. Tried filtering for the previous day and first day the previous executable was found and used "exe" to try and identify any suspicious exe events in that time period. Also tried a query involving EventID=1 | table _time ComputerName ParentImage ParentCommandLine ParentProcessId Image CommandLine ProcessId to try and identify process creations with no luck. Currently stumped, does anyone have any hints/advice they can give to put me on the right track?

nova ginkgo
#

Help me pls

Attack the PRTG target and gain remote code execution. Submit the contents of the flag.txt file on the administrator Desktop.

Attacking Common Applications : PRTG Network Monitor

I did what I learned but

─(forever㉿kali)-[~]
└─$ sudo crackmapexec smb 10.129.x.x -u prtgadm1 -p 'Pwn3d_by_PRTG!'
SMB 10.129.216.158 445 APP03 [*] Windows 10 / Server 2019 Build 17763 x64 (name:APP03) (domain:APP03) (signing:False) (SMBv1:False)
SMB 10.129.216.158 445 APP03 [-] APP03\prtgadm1:Pwn3d_by_PRTG! STATUS_LOGON_FAILURE

#

@fathom pendant

slender violet
cloud urchin
storm elk
#

Ohai SuperNuts

cloud urchin
#

hello

slender violet
#

It is correct....

cloud urchin
#

no it's not

slender violet
#

I checked the walkthrough

#

Did you look at my screenshot?

cloud urchin
#

did you enumerate yourself?

slender violet
#

Yes

cloud urchin
#

look at the samaccountname then, that's what it's looking for

#

there's a big difference between a user account and a computer account

slender violet
#

Copy that

latent relic
#

Is there a way to gift a learning path to someone or only gift cards?

#

Cube gift cards*

cloud urchin
dim wolf
#

never mind

#

no, because that's illegal

#

i think it's obvious you want to do something malicious so we aren't going to help you

storm elk
#

He’s gone

cloud urchin
#

great now he's going to hack you instead

storm elk
dim wolf
#

no it isn't, you didn't give permission

storm elk
#

Better start a defensive course now

cloud urchin
#

totally not an alt guys

dim wolf
#

lol what the heck

storm elk
#

Okay one moment lol

nova ocean
#

hi guys is there any problem with the academy? i have issue with spawning targets

cloud urchin
#

i just tried to spawn a random machine and it worked for me

#

try ctrl + shift + r then spawn again

nova ocean
nova ocean
#

i wasted 5hours today :<

cloud urchin
#

because it's a hard refresh that clears the cache and completely redownloads the page

#

normal refresh doesn't clear the cache

nova ocean
#

nice thank u

cloud urchin
#

now don't use hard refresh to hack donald trump without permission

hexed lintel
#

try password in single quotation marks '

cloud urchin
#

can you ping the target

#

what module and did you just reset it

#

ok when did you click spawn now

#

how long was it before you spawned the target and ran that command

hexed lintel
#

try with remmina

cloud urchin
#

ok then it's most likely because you changed vpn's.

#

despawn the target, disconnect from the vpn, re-download the vpn file, reconnect to the vpn, hard refresh the section (ctrl shift r) then respawn the target

#

then wait ~3-5 mins for the environment to spawn

limpid hemlock
#

Hey im in the exploiting web vulns in thick client section and im trying to rebuild a jar file after i edited someting in it but im getting an error anybody knes what to do

hexed lintel
limpid hemlock
#

Mm but i edited in invoker.java file

cloud urchin
#

windows + shift + s, then you can ctrl v the pic

somber fiber
hexed lintel
limpid hemlock
#

What

#

I dont understand im sry

unique ether
#

Nice got sick when I was having good progress

fiery comet
#

someone can help me?

#

i hava txt file, but have noting

#

it has 4kb and flag

#

i cant find

safe star
#

what module

fiery comet
#

its a homework

safe star
fiery comet
#

hahahaha

#

trust me bro, its a college homework

cloud urchin
#

this channel is about the academy modules so no one can help you with homework here

lusty thicket
#

hdd

safe star
south rune
#

lol

#

nah bro

storm elk
safe star
#

💀

south rune
#

you deleted my hard work

storm elk
storm elk
safe star
#

type shi

south rune
#

that wasnt very welcoming as a new member

storm elk
lusty thicket
#

npc behavior

south rune
#

ok, but is that server suposed to be? corresponding to the title and description, it looks like a place to learn hacking, is it?

cloud urchin
#

i mean he said read #welcome and #rules if you did that you'd know more. this discord is about the hackthebox platform, this channel specifically the academy platform

storm elk
south rune
storm elk
#

Just also know that you need to be 18 or have parental consent to create an account.

south rune
#

discord account?

storm elk
south rune
storm elk
stable sparrow
#

Hi,
working on the medium lab of Footprinting
I have been stuck after getting acces to the SQL Management thing directory that i guess is the MSQL that the hint is talking about, but I believe it is not externally acessible since it is not discovered by port scans
Am I supposed to download the whole folder and open it localy as if I installed it to explore it ?
It is the sole idea that I have this far and got quite stuck for a long time
Any hint ?

lusty thicket
stable sparrow
# lusty thicket there’s a hint in that section iirc

ye that is talking about some obscure MSQL app running
i found what i believe to be credentials for sys admin, but I am wondering how am i supposed to connect to this service since it not running on any external port

south rune
# storm elk Awesome

To be honest, this server isn't really what I'm looking for after reading the welcome thing because its more for professional stuff, I found that server in the gaming category, which is why I'm here

storm elk
lusty thicket
storm elk
#

But good point 🙂

south rune
storm elk
safe star
#

What a gamer kermit_thnk

storm elk
#

He’s unspawned himself

gray yacht
stable sparrow
stable sparrow
# gray yacht Cool deal.

would there be any reason the password found for the sys admin account fails to log in SQL Server ? (bad grammar english is not my primary lang)

gray yacht
stable sparrow
gray yacht
junior flicker
#

I'm working through the Password Attacks module, but am struggling to get Will's password in the Credential Hunting in Linux exercise. I saw the hint and have tried to brute force FTP & SSH with Kira using the provided password list and a mutated list that mutated the password in the hint. I also tried brute forcing FTP & SSH with Will using the provided password list. I am able to login to the IPC$ share with Kira's account, but there's nothing there and Kira's account doesn't have permission to the SHARE share. What am I missing?

stable sparrow
# gray yacht Would be worth a shot.

i must be doing something wrong
but i figured out an admin user on the machine, and try to connect to rpc with it but no password worked
is it because I use xfreerdp ? (weird because it worked for the other user)

gray yacht
stable sparrow
midnight galleon
#

hello, in the attacking password hard lab, i found the pass for d** and went to his share but when trying to download the b.vhd file it downloads it but the file is 0bytes

#

is there any other way to get that file?

#

rdp and evil winrm with this user isnt working

midnight galleon
#

yes it is giving an error when getting it

#

something in the lines of this is too big to download

safe star
#

i cant remember what logon services there were, but i remember using powershell and python ftp to get it

#

dm a pic

limber river
midnight galleon
#

it was -t

rugged turtle
#

Good evening guys, anybody there for a few questions concerning Attacking DNS ?
I've exhausted all my ideas 😄

limber river
rugged turtle
#

I'm doing Attacking Common Services > Attacking DNS.
I'm kinda lost. Given that we have the records that we wanna query and the ns is given from the target's ip, I've tried a few things without success.
Zone Transfer, leads to transfer failed.
Enumeration, subbrute goes in error if I add this nameserver to the resolvers. Subfinder, does not return anything

#

I must admit that I still have some fog in my head trying to wrap up the DNS concept, not as a concept itself, more from the results being returned from a dig query, for instance.
When I dig ns @ip inlanefreight.htb, does it mean I'm basically reading the /etc/hosts file of that ipaddress and looking for the inlanefreight.htb ns refs ?

safe star
#

With the name server as the only ip in the resolvers file

rugged turtle
#

ns.inlanefreight.htb

#

my god, it is not returning errors now, I guess it was due to that

safe star
#

Yeah, you don’t need the FQDN to use the name server

rugged turtle
#

but why doesn't subbrute works with the FQDN as well?

safe star
#

It should if u added it to your /etc/hosts

rugged turtle
#

goddamn

safe star
#

But it’s not needed

rugged turtle
#

definitely need to make some DNS-related exercises

midnight galleon
#

pwend!
i was expecting some pth/ptt tbh

rugged turtle
rustic sage
#

good evenings I'm stuck with the following question: For your next hop, list the networks and then use a common remote access solution to pivot. Send the C:\Flag.txt located on the workstation. I have the base Sam but nose how to copy this to my attacking machine module Pivoting, Tunneling, and Port Forwarding

river marsh
#

following the reading for HTTPS module in cracking into htb curl -k https://inlanefreight.com which is the command shown in the article produces nothing to the terminal but curl -k https://www.inlanefreight.com whats going on?

#

also does my pwnbox save its state across instances if i create folders and files?

vivid sigil
#

when i connect with netcat the first lines about banner right ? and the administrator he can change it ?

safe star
#

ive seen the banner changed to different things sometimes too

tender nimbus
#

Hey guys im doing the file transfer module, do you know why i cant do the transfer here? i do the same then the explication?

ocean night
tender nimbus
#

Yeah i know that it dont reconize the -Post argument but when i took a look again on htb and asked gpt it give me both the same but it dont work

ocean night
#

Where do you see the -Post argument in Academy out of interest?

ocean night
#

hm

tender nimbus
#

need to be updated maybe?

ocean night
#

Did you type out the command by hand, or copy paste?

tender nimbus
#

and the commande is the same from lolbas

ocean night
#

Weird, I don't get that error here

#

Oh

#

You're in Powershell

tender nimbus
#

yes

ocean night
#

The example shows in a Command Prompt

#

I wonder if there is a difference in PS compared to CMD, sounds weird, but just a thought

clear rover
ocean night
#

I don't see the -Post argument in the documentation on Windwos though

#

..but here locally I see it

tender nimbus
ocean night
#

Oh, I've not pulled the binary from lolbas

#

Seems something odd is going on for sure

#

Oh nvm

#
If you get an error when running certreq.exe, the version you are using may not contain the -Post parameter. You can download an updated version here and try again.
tender nimbus
#

okej wil do it lolbas should update it to

ocean night
#

That's below the example

tender nimbus
#

oooh yeahh okej wait

#

nice exercice im gonna try to transfer the exe from my attack host to target host

junior flicker
#

Hey Peeps, I'm working through the Password Attacks module, but am struggling to get Will's password in the Credential Hunting in Linux exercise. I saw the hint and have tried to brute force FTP & SSH with Kira using the provided password list and a mutated list that mutated the password in the hint. I also tried brute forcing FTP & SSH with Will using the provided password list. I am able to login to the IPC$ share with Kira's account, but there's nothing there and Kira's account doesn't have permission to the SHARE share. What am I missing?

river marsh
#

the description for the Host header reads as:

    Used to specify the host being queried for the resource. This can be a domain name or an IP address. HTTP servers can be configured to host different websites, which are revealed based on the hostname. This makes the host header an important enumeration target, as it can indicate the existence of other hosts on the target server.

but how can it indicate the existence of other hosts?

safe star
#

they also gave you kiras password already, so u could try and make variations of that

river marsh
safe star
#

yes, when you come across vhosts

#

have you yet?

river marsh
#

no, im just starting

safe star
#

which module

river marsh
safe star
#

depends on what path you will be taking next, but ik that they cover vhosts in "Web Fuzzing" and "Attacking Web Applications with FFUF"

#

also, "Information Gathering - Web Edition"

river marsh
#

havent fully planned that out, my current thinking was Cracking into HTB -> Basic Toolset -> OS Fundamentals, and then go from there

safe star
#

sounds good, they go over it in Basic Toolset

river marsh
supple sparrow
#

just finished web service and API attacks, it seem like there's an unintended path for the skills assessment?

junior flicker
fickle topaz
#

hello guys
on Attacking Common Services
Attacking FTP

fickle topaz
#

i am trying to bruteforce the ftp using medusa

#

it's returning error

junior flicker
safe star
#

u def shouldve got a hit

fickle topaz
safe star
junior flicker
#

Weird, right?

safe star
#

yeah, it worked for me

safe star
#

its not on port 21 @fickle topaz

fickle topaz
safe star
#

just switch the port number

fickle topaz
fickle topaz
safe star
#

what about that?

#

change the port number on hydra

#

<@&861185840277487616> looks like one

vivid sigil
#

in nmap moudle Firewall and IDS/IPS Evasion - Medium Lab

what does mean this

http://<target>/status.php
Recorded alerts: 49 / 100 alerts

Refresh Page (button)

safe star
#

you get locked out for 3 minutes if maxed out

vivid sigil
#

ty

indigo rune
safe star
#

got deleted

marsh echo
#

except for the first one, but when I take the administrator hash to connect with evil-winrm it doesn't work.

#

here have got a shell with meterpreter but the commande guid does'nt work

weary shell
#

Hi - can I get pointer for the the academies - firewall and ids / ips nmap hard lab - i can only see 2 ports open but can’t find the answer to the question not even with the hint

lusty thicket
weary shell
desert brook
#

Anyone able to give any hint for question 3 about the API key on information gathering web edition skills assessment? None of the wordlists in seclists are producing any results

uneven cairn
#

why this injection works? | whoami on a direct command injection?

limber river
uneven cairn
uneven cairn
#

hm ok let me try

limber river
#

this how bash works

uneven cairn
#

yes sorry i didnt see the sense but it actually works ty

vivid sigil
#

Does anyone have any clues to solve Firewall and IDS/IPS Evasion - Hard Lab?

rustic sage
#

Hey guys

gray yacht
hoary adder
#

Pc o laptop

storm elk
hoary adder
#

Work games VMware etc

storm elk
#

If you will use the device at the same place all the time, I’d go for a desktop

limber river
#

desktop is better , but that's if you don't move too much

empty trout
#

i got confused in smb enumeration some extra resouce which can help me here

empty trout
#

if netbios is used for hostname resolution and hostname registration why i see microsoft-ds as a service name in nmap scan on port 139 . this is a part of netbios API which provides network services like file and printer sharing but wait a min we are using smb for this perpose so why the hell i see that

#

someone helping me here ???????🙂

grand portal
#

same question. anyone can hint?

empty trout
#

footprinting module in smb section

grand portal
empty trout
#

there is no nmap scan i was saying this as i see a lot of time microsoft-ds on port 139 . no there is no exercise or que just my doubt

full wagon
#

The webshell section with the laudanum aspx shell. First of all, uploading and accessing an aspx-shell on pwnbox didn't work, got 404 however I tried accessing it. Connected with vpn from Kali and still 404. When switching || to another aspx webshell, not laudanum specifically, || it worked to get the shell access. So far so good. But the question 2, even copy/paste, the entire path from pwnbox, and I get wrong answer 😱 I love your course, but these kind of questions slows the learning process up, have to spend to much time just getting past a qustion that is not technical, not fruitful, just annoying. How to bypass this since not even correct answer is ok???

grand portal
sacred jacinth
sacred jacinth
sacred jacinth
somber fiber
#

how sure are you?

sacred jacinth
#

that is definitely an issue on your end. I just did xfreerdp and it was working

#

have you tried remmina?

#

ohhhhh. try resetting your vpn config?

somber fiber
#

try remmina

#

there is rdesktop too

#

or krdc

#

or vinagre

#

but i think first 2 should work

full wagon
somber fiber
#

is that even running?

sacred jacinth
somber fiber
#

try ping that ip and port

#

which module is it?

sacred jacinth
#

🤔 this either happens with a faulty vpn config or a down target

#

have you tried it on Pwnbox?

somber fiber
full wagon
somber fiber
#

module sir

somber fiber
#

what other port is there open?

#

dm

full wagon
somber fiber
hexed lintel
#

working fine for me

sacred jacinth
#

see

#

np

hexed lintel
#

what was the problem?

somber fiber
hot lodge
#

I need help on the skills assessment question 3 of information gathering web edition, I got all the other questions but I can't seem to find the api key in the admin directory

limber river
hot lodge
#

I got that, just not the third question lol

limber river
#

Leeme check for you

hot lodge
#

Thanks

#

@limber river I found it using ffuf, thank you 😊

sacred jacinth
#

is your VPN config udp? UDP is weird with rdp

somber fiber
#

the thing is you are able to connect its just not letting your user to login

#

here

#

can you drop the command?

#

you used here.

#

right

#

is it possible its not taking in because of this ' but need this " insted in password?

#

there is another command that i used not sure if that will work but try xfreerdp /v:10.129.230.228 /u:<user> /p:"Academy_student_AD!" +sec-nla +sec-tls

sacred jacinth
#

wait an off-topic question are you using cloudlfare warp? or any custom DNS in your primary host?

somber fiber
#

xfreerdp /v:10.129.7.53 /u:htb-user /p:'Academy_student_AD!' /cert:ignore /sec:rdp

#

try this it will force it to connect

#

the error is related to time out

nova ginkgo
#

Hello everyone
help me pls

Osticket : Attacking Common Applications

Find your way into the osTicket instance and submit the password sent from the Customer Support Agent to the customer Charles Smithson .

I created ticket and signed in

Now what should I do

shell ore
#

i had this in another module yesterday, not sure if it's connected, but just reset a couple of times

#

if u check port 3389 might be closed

#

MIGHT, cuz that what happened w me

#

try nmap it on port 3389 only

somber fiber
#

let me check with gpt

shell ore
#

oh it is open

somber fiber
#

is there any other port which might be there for rdp

shell ore
#

weird, ok which module is this? which section?

somber fiber
#

try -p- in this nmap command

shell ore
#

ehm

#

1 question @rustic sage, why ur using htb-user as the username? 😅

somber fiber
shell ore
#

hope it helps :D

somber fiber
#

tho i haven't opend the module

#

5+ hour on same blunder i did 3 days back on other module lol

#

have you tried -p- ?

shell ore
#

did u try switching the vpn server?

shell ore
#

waiting target to spawn 🙂

somber fiber
#

well thats how things work in this field 😋

shell ore
#

its okay, connection issues happens a lot

#

and issues in general lol

empty trout
shell ore
#

also, did u try remmina?

#

if ur using parrot its pre-installed prolly

empty trout
#

xfreerdp

limber river
#

Contact support, there's also the /tls-seclevel:0 flag it could help

shell ore
#

does it say fail to connect or connects w black screen?

#

target still not spawning for me, there's prolly some issues in academy labs rn, i would say move a bit to other sections then come back to this

#

oh

#

at this point contact support then, i tried to help but i cant even spawn the target 😂

somber fiber
limber river
#

Academy labs are self instance and you can reset the labs whenever you want

somber fiber
somber fiber
somber fiber
#

anime site and got sql error

#

its not able to connect with the sql

limber river
storm elk
#

Unknown command ls.

rustic sage
#

Good morning mates, I'm still stuck in the port forwarding and tunneling module, I don't know how to send the Sam base to my local host to do the decryption, can anyone give me details?
C:\Users\mlefay\AppData\Local\Temp>move lsass.DMP \10.10.14.63\CompData
The network path was not found.

shut vapor
#

Moin, in AD Enumeration & Attacks > Initial Enumeration: general Q about kerbrute
I got tripped up trying to run kerbrute from my attack host before finding it's installed on the pivot this lab provides.

Still, I don't understand if there's a way to run kerbrute from my attack host through a proxy. I had ligolo working. I could ping and nmap on TCP+UDP ports 88 showing I could communicate with the service. No luck though, I kept getting communication errors.

Is there a way to do this through a proxy or, alternatively, has anyone found instructions for statically compiling kerbrute?

user@box:~$ sudo ./kerbrute userenum -d INLANEFREIGHT.LOCAL --dc 172.15.5.5 ./jsmith.txt -o ./valid_ad_users
failed to communicate with KDC. Attempts made with UDP (error sending to a KDC: error sneding to 172.15.5.5:88: 
shut vapor
#

What computers can they reach?

iron gale
#

hello

#

why i can not text on off topic channel?

shut vapor
shut vapor
ember stirrup
#

I need help

ember stirrup
#

What is that

safe star
#

I got the thumbs up for a reason

shut vapor
# ember stirrup What is that

Sorry, I was mobile for a minute and should have added more context.
If you need assistance with an Academy module, state both the module and section with which you're having difficulty + ask your question. We often get people saying "I need help with ..." or "can I ask a Q about..." instead of just saying what they need help with. Don't ask to ask, just ask the question.

grand portal
sacred jacinth
nova ginkgo
#

help me pls :
Attacking GitLab

Gain remote code execution on the GitLab instance. Submit the flag in the directory you land in.

I have a username but I dont have a password

grand portal
grand portal
storm elk
nova ginkgo
#

ccan you give me some hint

storm elk
#

Haven’t done that module, sorry

nova ginkgo
mellow saffron
#

Hi I Need help with this question: According to the paypal.com website in October 1999, what could you use to "beam money to anyone"? Answer with the product name, eg My Device, remove the ™ from your answer. there is no 1999 Octover record anymore for paypal

storm elk
#

I just meant, be patient, you can’t expect to have an answer if you post something at xx:08 and you have no response at xx:09

mellow saffron
#

If someone can help me I would really appreciate it Im stuck on this last question for 1+hour

calm geode
#

for

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the count of distinct computers accessed by the account name SYSTEM.

is it not 4/four/Four? used dedup and dc(host) by hostname

quiet trout
#

palm0s instead of palmos

#

silly stuff

pine grove
#

Thought I'd ask if someone has more insight. On https://academy.hackthebox.com/module/112/section/1073 footprinting IMAP / POP3, why does Evolution mail successfully connect to the server as expected, while Thunderbird seems to be unable to; even after trying various connection settings + ports for IMAP and trusting the TLS certificate? If you can get Thunderbird to successfully connect, what settings are you using? 🤔

acoustic owl
mellow saffron
#

Yeaaaaaa

#

Legit now I see it Lmao I tried this 2 hour before and it wasn't showed me

calm geode
grand portal
nova ginkgo
#

Hello bro how to find Dxxx password

mellow saffron
#

Ok I found it now

#

Ty for the help

quiet trout
#

Anyone done the Session Attacks skill assesment?

https://academy.hackthebox.com/module/153/section/1458

RE: Question 1 -- Im wondering if i need to fuzz for first.last@example.com email addresses, this could take a WHILE and may not be technically related to the assessment and im unsure how else to go about finding the admin account by email, no API to return role or anything that im aware of

calm geode
quiet trout
# calm geode first

curious, is this part of the SOC path? im looking forward to doign that soon

grand portal
# calm geode first

i'd suggest using gpt to create queries as needed, do you understand the question?

grand portal
quiet trout
acoustic owl
sacred jacinth
#

after that just run msfconsole the module will be there

nova ginkgo
old oasis
grand portal
quiet trout
# old oasis did you find out what field is vulnerable

yes, i know the vuln field. and i learned how to fuzz unknowns like this in previous modules it just seems al ittle over kill to take seclist/../firstNames.txt & lastNames.txt and like, ... pitchfork them (or whatever ffuf calls it)

sacred jacinth
#

you don't need to worry about them though

old oasis
quiet trout
# old oasis and you tried getting the cookies

i havent tried that yet, is there some sort of automated admin request being made that will deliver the cookie without an actual user (admin) viewing the page? i hadnt considered that.

calm geode
acoustic owl
acoustic owl
calm geode
#

ok thanks

grand portal
#

sure

grand portal
old oasis
quiet trout
quiet trout
shut vapor
old oasis
quiet trout
gray yacht
grand portal
sacred jacinth
quiet trout
#

@old oasis now i feel silly, I made that WAY more difficult than it needed to be. The description (the endpoint) did fool me a bit, dunno if that was the intent or somethin got lost in translation there.

grand portal
grand portal
old oasis
grand portal
#

@sacred jacinth got it! i had to run reload_all command inside metasploit to get it right.

rocky mist
#

" Find all TCP ports on your target. Submit the total number of found TCP ports as the answer." how do i find the amount of all the TCP ports?, i ran sudo nmap <ip> but it didnt give me the number of all tcp ports, just showed me tcp ports and their numbers

sacred jacinth
old oasis
sacred jacinth
grand portal
#

yeah.

rocky mist