#modules

1 messages · Page 344 of 1

fathom pendant
#

If you don't know how to spot a public ip, please refer to basic networking

quiet trout
#

i mean, my vm would be connecting to vpn as well?

fathom pendant
#

The reason they say use your own vm is bc the pwnbox has an external facing interface

#

Using your own vm allows you to lock down the network access and retain a lot of control

quiet trout
#

ok so connect my vm and down any external itnerfaces?

#

does that work after connecting to vpn?

fathom pendant
#

What is mean by external interface is the pwnbox literally has a public ip

quiet trout
#

im with you there

fathom pendant
#

I haven't done this module so idk what all they have you analyze, but if it's a file, then you don't connect to a target

#

If there is no 'spawn target' button, there's no target to connect to

quiet trout
#

ah, ok

midnight galleon
safe phoenix
#

For anyone experiencing this same issue it seems that Powershell is interpreting the 1 at the beginning of the IP address as an index. The fix I found was to wrap everything in quotes. Ex. dig ns inlanefreight.htb '@1.1.1.1' You'll probably only be encountering this issue if you're connecting using PWNBOX

normal sand
#

Hypothetical: If I've found a command injection vulnerability on a public-facing web app and I'm trying to run a reverse shell command. The reverse shell command should use my public IP address, right? Do I need to port forward the port on which my listener is active?

I'm asking since in all the web modules I've done, the web applications I've compromised are on the local network. So I was just wondering if I understood the concept for how things would work for an external facing web app since I've never pentested against an external facing web app.

strange pivot
strange pivot
normal sand
normal sand
strange pivot
#

I usually only catch stuff with ngrok, and burp collaborator

#

but i'd imagine you need to configure your firewall and maybe even portforward on your router even ?

normal sand
strange pivot
#

Its usually all local on the AEN and in the exam

#

so you dont have to worry about attacking anything on the internet

normal sand
# strange pivot Its usually all local on the AEN and in the exam

Oh okay, cuz I was worried since they both said external pentest, so I thought I'd have to port forward on my router. Thanks for the ngrok tip though, hadn't occurred to me to use that for port forwarding instead of going through the trouble of setting the port forward on the router and restarting the router and all that hassle.

normal sand
#

It was Domains and then I gotta start a tunnel, right?

normal sand
strange pivot
#

read the documentation of ngrok

finite crane
#

were you able to figure this out?

normal sand
strange pivot
#

hmm I think I played aq like 14 years ago when i was younger lol

#

I just like the word tbh 😄

normal sand
#

Nice, it is a cool word 😂

somber summit
#

Hello !
Looking for the syntax of an answer question for DACL Attacks I. The question - RIGHT_WRITE_OWNER allows modifying what attribute of an object?
The answer must be ||Security Descriptor's Owner||
But it doesnt work

dim wolf
#

nope. sick

finite crane
#

what exactly does it mean by universal attack chain?

quiet trout
woven bronze
#

hello guys , i'm trying to solve the EvilCUPS box i've followed the ipsec video and i've downloaded the exploit from its github repo then when i want to execute the test print job of the my malicious machine to get a reverse shell i got this error on the cups dashboard "stopped
"Filter failed"" and when i go and see the python code i got this error too "Exception occurred during processing of request from ('10.10.11.40', 48740)
Traceback (most recent call last):
File "/usr/lib/python3.10/socketserver.py", line 683, in processrequestthread
self.finish_request(request, client_address)
File "/usr/lib/python3.10/socketserver.py", line 360, in finish_request
self.RequestHandlerClass(request, client_address, self)
File "/usr/lib/python3.10/socketserver.py", line 747, in __init
self.handle()
File "/usr/lib/python3.10/http/server.py", line 425, in handle
self.handle_one_request()
File "/usr/lib/python3.10/http/server.py", line 413, in handle_one_request
method()
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/server.py", line 101, in do_POST
self.handle_ipp()
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/server.py", line 140, in handle_ipp
ipp_response = self.server.behaviour.handle_ipp(
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/behaviour.py", line 71, in handle_ipp
return command_function(ipp_request, postscript_file)
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/behaviour.py", line 163, in operation_print_job_response
self.handle_postscript(req, psfile)
File "/home/hacker/.local/lib/python3.10/site-packages/ippserver/behaviour.py", line 410, in handle_postscript
raise NotImplementedError
NotImplementedError

target connected, sending payload ..." so please anyone can help me

wild sage
#

Is there someone I can DM about File Upload Attacks Skill Assessment? I've been stuck on this for days and I have tried a lot of combinations to no success.

nova ginkgo
#

helo help please i stuck here from 3 hours

Submit the contents of the flag.txt file in the /home/srvadm directory.

Attacking Enterprise Networks | Initial Access

bypassed this filter previues theme but in Initial Access i can't I used all methods for bypassing

woven bronze
dim wolf
woven bronze
dim wolf
#

that's not part of the verification process

storm elk
dim wolf
#

there are four steps you need to follow

woven bronze
#

done i verified my self

storm elk
woven bronze
#

so what to do next ?

dim wolf
woven bronze
#

i go to the boxes channel then i ask my question or what ?

storm elk
#

Yes

nova ginkgo
#

Bro I can't reverse shell

rustic sage
#

I've had nothing but issues with the tunneling lab machines.

safe star
#

<@&861185840277487616>

jolly cradle
#

ty

nova ginkgo
safe star
#

Then ur messing something up

nova ginkgo
dusk crater
#

good evening, can anyone help me with C# module ?

junior flicker
#

Howdy People, I'm working through the Password Attacks Medium lab. I have the logins for root, jason, and dennis, extracted and cracked the Docs.zip and the docx file, but the hint leads me to believe I need root's id_rsa to login as root. Any hints to get me to that end?

rustic sage
#

Meterpreter Tunneling & Port Forwarding lab boxes are just dieing on me. I can't get a tunnel to last for more than a single command. @jolly cradle @surreal rain

solid quarry
next bronze
rustic sage
next bronze
vast horizon
#

Guys I m new in this field
I want to learn cyber security and ethical hacking
And I need resources and guidance at free of cost
Pls help me to find resources

compact patrolBOT
safe star
junior flicker
safe star
#

I think meterpreter might be the worst way tbh

rustic sage
surreal rain
stark lark
#

Hey, is it possible you can help explaining this?

The payloads in the red field are responding with “Only images are allowed” which means that these are likely filtered by the whitelist.

The rest are responding with “This extension is not allowed” meaning that these extensions are probably blacklisted.

So essentially, by now I should've figured out which extensions are blacklisted and I "only" need to figure out how to bypass the whitelist filtering.

I tried replicating your steps using the Character Injection Bash script to make a extension list with .phtml .phar .pgif. The only thing I see that I might've done differently is using jpg for the bash script and not png but I don't see why that would make a difference since both are whitelisted?

safe star
jolly cradle
#

@rustic sage - Try changing to a different payload and/or setting a different EXIT FUNC on your payload. Could be killed by AV. Also in the future, if you want potentially faster responses, don't ping 2 admins of the community. Ask the community without pinging anyone and be patient.

rustic sage
nova ginkgo
plain charm
#

Hi. I've been stuck on the "Active Directory enumeration & Attacks" module. I am currently stuck at the last question of submodule " Domain Trust , Child Domain --> Parent Domain" or something like that. I can't figure out how can I extract the Nt hash of the given User B. I have completed all steps of ExtraSids and compromised the DC.

#

I try to upload binaries of popular tools, but the output is not showing( or showing as a stdout

solid quarry
low roost
plain charm
#

can't do backspace, nothing

low roost
#

evil-winrm?

obsidian rampart
#

Hi am completing a module windows defender evasion
In static section it show
Ok - undetected by Microsoft Defender
But not giving flag.txt
If anyone completed this plz guide

low roost
#

try getting a meterpreter

junior flicker
solid quarry
#

dennis should have a .ssh

low roost
#

imagine not doing ls -la

junior flicker
solid quarry
plain charm
# low roost evil-winrm?

Meterpreter is out of question. But though I did it through golden tickets and dont have Hard credentials for the DC. the golden ticket is stored as FILE

plain charm
safe star
#

bro deleted it 😭

stark lark
low roost
rare swan
low roost
#

and try to steal the ntlmv2 hash

#

im not really good in AD so idk

solid quarry
#

what is the problem at the ad one? I didn't found the question

plain charm
low roost
#

in your attacker machine

solid quarry
#

i will check

fathom pendant
#

think where web servers tend to be located on a linux based machine

next bronze
solid quarry
# plain charm here it is

"Perform the ExtraSids attack to compromise the parent domain from the Linux attack host. After compromising the parent domain obtain the NTLM hash for the Domain Admin user bross. Submit this hash as your answer." ?

#

yeah you can do what Xre said, impacket-secretsdump from your linux machine

solid quarry
#

instead of psexec you can use secretsdump -just-dc flag

marsh echo
#

even using xp_cmdshell to reverse its not works

fathom pendant
#

please refrain from spoiling the AEN module

#

also you don't need to use the sql service to do anything

#

you'll need to use the built-in file manager

plain charm
#

lets try that also

solid quarry
#

let me know if you got it

fathom pendant
#

the rest of what's in AEN is nothing you haven't encountered in some form before

#

just gotta enumerate; enumerate; enumerate

marsh echo
fathom pendant
#

didn't say it would be simple, but it is stuff you should know

#

don't look for any hints or nudges forward, gotta learn to unblock yourself -- treat it as the exam

plain charm
plain charm
#

i didnt think of running the help of secretdump. it accepts the same flags as psexec

marsh echo
#

well I know that you have to make a reverse shell from the but when I saw xp_cmdshell plus the priv allows by the user I understood directly which tools should be used, but only errors ...

fathom pendant
solid quarry
fathom pendant
#

gotta figure out how to upload files first

marsh echo
fathom pendant
#

i suggest googling the web framework in use and "how to upload files in <Web Framework> app"

marsh echo
#

thx 🙂

fathom pendant
#

I know you can get through this; and don't be afraid to take several hours to figure it out

#

it's easy to want to reach for the instant gratification of "what do I do next"

#

but putting in the time and effort to research what you've run into helps develop a mindset

marsh echo
#

ta really says it’s real I’m in a hurry to switch to reverse shell instead of seeing the easiest thing

#

but I was able to unblock myself thanks a day to look in the void x)

fathom pendant
#

not to mention how you're connected to it plays a role

rare swan
fathom pendant
#

nope

#

you're thinking too smart

#

think dumber

#

where are web server files located on linux

#

aka the webroot

obsidian bronze
#

does anyone know how to launch a .sh file on windows?

fathom pendant
#

but fr why do you need to launch a .sh file on windows??

#

what academy module is this related to?

obsidian bronze
fathom pendant
#

oml

#

why do you need to run a .sh on windows

#

.sh is a bash file, generally gonna be linux

#

windows executables are .exe

obsidian bronze
fathom pendant
#

well that's a skill issue then

#

¯_(ツ)_/¯

#

also you weren't "supposed to run it on vmware"

#

you're supposed to run it on a vm

#

:)

obsidian bronze
fathom pendant
#

yes but you're not running it on vmware

#

you're running it on a vm

#

:) learn the difference

rare swan
fathom pendant
obsidian bronze
rare swan
#

but its not writable

fathom pendant
fathom pendant
rare swan
#

but it isnt

#

permission issues

fathom pendant
#

or maybe try writing to the folder you're in :)

obsidian bronze
midnight galleon
#

does most pentest end with DC compromise? or is it just a sweat dream?

midnight galleon
#

on?

fathom pendant
#

The scope

#

Some scopes may include multiple forests

midnight galleon
#

i mean is it that possible?

fathom pendant
#

in which case you'd need to compromise the Enterprise Admin account

fathom pendant
#

but it all just boils down to; it depends -- if you couldn't compromise everything fully to DA then you just note what you could for the company to fix up or ignore

#

¯_(ツ)_/¯

#

like a pentest is about discovering and reporting vulnerabilities in a network not just getting DA, DA is just a bonus

midnight galleon
fathom pendant
#

IT DEPENDS

#

lol

#

there's a lot of factors that play into it

#

most companies that get a pentest done have some level of security maturity that would at least make it difficult

#

but not wholly impossible to reach DA

#

plenty of vulnerable things within Windows or installed apps that make it easy to privesc

#

but if a company has done their due diligence in locking down accounts, preventing NT;LM use, etc. it is gonna be harder

vagrant light
#

solve it?

fathom pendant
#

it also depends on the timeframe scope

midnight galleon
#

Ok
thanks!

dapper moth
vagrant light
dapper moth
#

Sure

vagrant light
#

Check dm

shut quest
#

If anything mod/staff deleted what I said, not sure as to why, I try to keep things in the spirit of the academy.

lyric quiver
#

Hi

#

anyone who has done Pass the Hash can help me ? Really stuck on "Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account?" I must be dumb

#

Like I did use mimikatz to extract the hash of current session, also did it plenty of others ways

old oasis
#

I am going to sleep now. If someone else hasn't helped you by tomorrow feel free to DM then I will get to it when possible.

mental tapir
mental tapir
#

Is HTB staff AFK?

safe star
safe star
mental tapir
mental tapir
mental tapir
safe star
#

you dont need any of those tools for this

mental tapir
# safe star you dont need any of those tools for this

Why not? The section in this module starts with "Once we identify the services running on ports identified from our Nmap scan, the first step is to look if any of the applications/services have any public exploits. Public exploits can be found for web applications and other applications running on open ports, like SSH or ftp."

#

Need to know what kind of services are running to find exploits for them..

safe star
#

those sections have different machines

mental tapir
night crypt
#

is the Citrix Breakout module any less painful if I use the pwnbox?

safe star
night crypt
#

RIP

mental tapir
#

The question at the end of the section " Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)"

#

In order to do that I need the nmap scan to work..

#

Said "No targets were specified"

safe star
#

if they give you a target with a port attached to it they want you to use that port

mental tapir
#

Did sudo nmap 83.136.254.47:51866

Got error Failed to resolve [IP address...]
WARNING: No targets were specified

safe star
#

u didnt specify the port with -p

wanton jasper
#

Go do some research on how to scan a specific port with nmap

safe star
#

they just want you to to open the ip on ur browser

wanton jasper
#

also look at your hint

mental tapir
maiden field
#

File Inclusion
Skills Assessment - File Inclusion

I found the hidden page but after ||uploading a shell no commands|| seems to work I see nothing in the response on the page ||access.log|| page

#

Ok I don't know what was the issue but after reseting the box it worked

mental tapir
safe star
#

i doubt that scan would find the port too

safe star
#

the ip should be 10.129.x.x for that

mental tapir
# safe star you wont find the answer with nmap

OK it finally spit out a bunch of info. Why wouldn't I need to run nmap to find out what services are running so I can search for exploits for the apps and versions running for metasploit?

safe star
#

the question says "(note: the web server may take a few seconds to start)"

mental tapir
#

I now know that OpenSSH 9.2p1 is running

safe star
#

meaning the web server is on the port attached to the target

mental tapir
safe star
#

you just scanning for extra practice or what? 🤨

mental tapir
safe star
#

its a webserver.

#

open it on ur browser

#

thats all the question wants you to do

mental tapir
#

OK wow I just realized I was scanning an old target SMH

wanton jasper
#

TLattice is right, you know it’s a web server. The hint even mentioned plugins. Just open the link and see what is running. Plug-ins make me think cms

#

Nmap would be needed if you had no information and didn’t know it was a web server. But in this case you know it is.

night crypt
#

Just want to confirm for the Windows PrivEsc Interacting with Users section, is there a particular directory in the ||FS01|| share I'm supposed to create my file in? I've been waiting almost 10mins and no hits (other than my own user after creating the file).

night crypt
safe star
#

yeah you can somewhere in there

#

check all the ones you can write to

night crypt
#

yeh so I've put it in there & it "works" but it's only hitting my htb-student account, nothing else hits it

quick eagle
#

Hello! I am working on 'Lateral Movement' in Attacking Enterprise Networks module and trying to proxychains nmap 3389 on 172.16.8.20 but it says its filtered. It should be open for RDP? Is there something wrong with the VM or I am not doing it right?

night crypt
#

as well as every possible sub-directory that's in the share I mentioned above - is there a different one I'm not seeing?

night crypt
#

thanks TL appreciate it

#

might also try restarting the box just in case 🤷

quick eagle
safe star
#

did you use the -sT flag also

quick eagle
night crypt
#

ah interesting resetting the box didn't clear my file from it either haha

cloud urchin
#

the target? it didn't reset then

night crypt
#

I think I just figured it out

#

was putting it in the wrong share -.-

safe star
quick eagle
safe star
quick eagle
safe star
#

Did it work after setting it up again?

quick eagle
# safe star Did it work after setting it up again?

sudo proxychains nmap -sT -p3389 172.16.8.20 -Pn
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-10-22 20:39 CDT
[proxychains] Strict chain ... 127.0.0.1:8081 ... 127.0.0.1:8081 ... 172.16.8.20:3389 <--socket error or timeout!
Nmap scan report for 172.16.8.20
Host is up (15s latency).

PORT STATE SERVICE
3389/tcp closed ms-wbt-server

safe star
#

Might just need a restart

wanton jasper
#

Could be worth trying while you are connecting to a vpn on your main box. A lot of my commands stopped working without vpn because my ISP flagged me

#

Or see if it works in pwnbox.

junior marten
#

how do i solve this problem i cant able to acces web browsers on instance i tried restating

dim wolf
#

if you have free pwnbox, your internet access is limited

junior marten
#

why i can use it before but from few days I can't able to use it from few days is it a new update

quick eagle
rustic sage
#

Did everyone else experience near persistent instability with lab boxes in the Pivoting/Tunneling module? I'm using Pwnbox to rule out my own stuff and can't RDP into boxes either at all, or with near immediate disconnects. I then have to spam retry a connection and hope I get lucky.

unique ether
#

cme is not running on pwnbox

#

command not found

#

i tried installing it still has issues

safe star
#

Use netexec

unique ether
#

im attacking winrm

safe star
#

Netexec not installed?

cloud urchin
#

are you just typing cme? the command is crackmapexec

unique ether
#

both

unique ether
shut quest
unique ether
#

but whats the difference between and why cme not there

shut quest
#

Because cme is no longer active, and the people that were active forked the repo into nxe

unique ether
#

ohhh ok alright

#

thanks

idle marsh
safe star
#

i thought rdp was closed cause it just never worked

eager ledge
#

Hi,

Module: Attacking Common Applications
Section: Exploiting Web Vulnerabilities in Thick-Client Applications
Section link: https://academy.hackthebox.com/module/113/section/2164

I have managed to update the ClientGuiTest.java file, compile it, create a new jar file. Now when I go to FileBrowser > Configs, I see new files. However, when I enter fatty-server.jar as filename, it doesn't get downloaded as described in the section. Instead it just gets displayed. Why is it not being downloaded?

#

Got it, I also need to modify invoker.java to download the file!

empty trout
#

i am on medium lab in footprinting section and i am stuck at mssql server i am connected to the target with rdp and run sql server manager there is a databases but i cant figure it out which table or which database to focus on

#

?

rustic sage
#

Hi Guys, I'm having trouble installing the wenum in Web Fuzzing module. Above is the screenshot. Is there any other way to install it?

#

I'm using this command : pipx install git+https://github.com/WebFuzzForge/wenum like it shown on the Web Fuzzing module.

GitHub

Wfuzz fork. Contribute to WebFuzzForge/wenum development by creating an account on GitHub.

safe star
idle marsh
empty trout
#

Port?

empty trout
safe star
#

on pwnbox

safe star
empty trout
#

Users tables maybe

rustic sage
empty trout
#

I found the db but i dont understande how to print those i mean there is select query but when i give absolute path tk that table it gives invalid object and if i give just the name of the table again the same error

safe star
#

i think ffuf would work better tbh

safe star
rustic sage
rustic sage
viral mica
#

I'm going a little wonky trying to remember what i did a week ago in previous modules. I don't remember much about XSS attacks

#

I mean the notes help me remember but then ill forget again

safe star
#

thats what the notes are for

#

if you want to solidify the concept without notes then you need to repeatedly do xss

surreal chasm
#

Hey, need some help with Footprinting Lab - Hard
I've found the next ports ||TCP: 22,110,143,993,995; UDP:161|| but have no idea where to go from now...
I mean my next thought would be to brute force each service but doesn't this is the intended way of solving the problem

viral mica
surreal chasm
#

Yeah, but all of the services need some sort of authentication

viral mica
#

Well the instructions give you a username, HTB

surreal chasm
#

That's right

#

I mean, should I try bruteforce each service? because it doesnt fit right in my mind

viral mica
#

hmmm.... i can't recall, does crackmapexec have an imap option

#

oh no wait you're not up to that yet.

surreal chasm
#

We didnt really talk about brute forcing yet.. this is why its a bit weird to me

surreal chasm
viral mica
#

use snmpwalk on it anyway

surreal chasm
#

i've

#

and found nothing

viral mica
#

or onesixtyone

#

?

surreal chasm
#

onesixtyone is for bruteforcing community strings only i think

#

i think snmpwalk is the right answer but i should get a user list

viral mica
#

right, then you use braa to brute force the individual OIDs and enumerate the info in them

surreal chasm
#

yeah i remebver talking abour braa

#

well, thanks, ill try

fathom pendant
#

One tool gets the string, another tool actually reads the OID

#

[<string>] is part of the output

round marten
#

In the "File Upload Attacks" module section "Whitelist Filters" how on earth does that work? I found the right extension by following the tutorial but how would that extension ever get executed by the php interpreter?

viral mica
#

hehehhe yeah what we said was on the right track.

surreal chasm
# viral mica or onesixtyone

It has been my mistake, its not snmpv3 which means i can run onesixtyone
Ugh i feel stupid because I waisted on it so much time

But how is it that NMAP shows that the service is running SNMPv3?

viral mica
round marten
viral mica
viral mica
surreal chasm
light ore
#

beginner here, Im on the active directory basics, managing users in AD. It asks that I RDP into Phillips account to prompt Sophie to change her password. When i go to RDP its asking for a computer name, however, the credentials given only give a username and password. ( no computer name) what am i doing wrong here?

surreal chasm
viral mica
#

I mean i never setup snmp on a network so i don't know too much about this

viral mica
light ore
#

got ya, but without a machine name doesnt that become an issue?

viral mica
#

you just need an ip address

#

of the machine

#

The target machine should be in green on the section page.

near oriole
#

40 mins of vpn hopping to get AEN spawned 💀

timber hatch
#

in the web attack modul, burp look like in the screenshot below, but my burp does not have the response at the right side, is this different in new versions or can i configure this?

next bronze
#

that's in repeater, you're probably looking at proxy

timber hatch
#

alright, yes this is the case

surreal chasm
fathom pendant
#

Just try what's taught

#

Or use the --script banner in nmap to be sure

#

Either way always try what's taught first

surreal chasm
#

I mean that's what I did
Information was still unaccurate..
I guess its part of the game

fathom pendant
#

Don't worry about the situation

#

Assume what's being given to you is similar to what's taught

wispy current
#

Hey im trying to solve the first one in the forensics category and i dont seem to be close no matter how i tried can anyone help me

timber hatch
#

Web Attack / Chaining IDOR Vulnerabilities
i've changed the email as requested, but i dont get how i receive the flag now?

young spade
#

@drifting grail could you please check your inbox. I 've sent an dm.

visual socket
timber hatch
idle marsh
visual socket
jolly yacht
#

In Intro to Assembly Language/Registers, Address and Data types. can you guys please help me to understand this "The big-endian processors would store these bytes as 00000001 10101010 left-to-right," How the 00000001 (least byte) was stored in left ? because the author specified "while with Big-Endian processors, the big-end byte is filled/retrieved first left-to-right." since the big-end byte should be stored first from left to right so the 10101010 should be on the left and 00000001 which results in 10101010 00000001 ?

timber hatch
jolly yacht
jolly yacht
#

But in the Module:

#

That's why i thought its appropriate to ask in the module channel instead of trusting on chatgpt completely.

timber hatch
#

yes so the big endian stores the most significant byte first and the little endian the least significant byte first. the most sinificant byte is so to say the biggest value of the number....

#

for example the number: 1234
big endian stores: 12 and then 34
little endian stores: 34 and then 12

#

this is my understanding

jolly yacht
timber hatch
#

yes...isnt that what i also explained with the example...? for me it is a match...

#

0000000110101010 = 426
big endian = 426
little endian = 624 (only an analogy)

surreal chasm
#

what is your goto documentation, do you summerize every page on every module? or only write key commands on each section?

jolly yacht
# jolly yacht But in the Module:

@timber hatch the thing I confused about was as you can read in here, it was mentioned as the big end byte will be stores from left to right and so upon the given example, it was mentioned as 00000001 10101010 was correct but as the 10101010 byte was the big end byte and the 00000001 is the least end byte. if we store the big end byte at left then the least end byte in the right (left- right) we should get 10101010 00000001 as the answer right?

timber hatch
#

ah, no 00000001 is the big part

#

maybe you should look first how binary works...

jolly yacht
jolly yacht
timber hatch
#

no the number i meant like one thousand two hundred thirty-four
and then 1 is the biggest because it is the tousand

timber hatch
jolly yacht
#

I am genuinely confused, in the module it was mentioned as it will be store/retrieve byte by byte, by comparing which byte is smaller or larger according to the endian.

timber hatch
#

2 bits are 1 byte

jolly yacht
timber hatch
#

yes

#

sorry

jolly yacht
#

fk sorry, I just specified the bit by bit as byte by byte.

#

Sorry for the confusion, In the module it was specified as it will store the binary values bit by bit, by comparing which bit is smaller or larger according to the endian. I mean on the example.

timber hatch
#

it stores byte by byte and one byte is = 00000001 and the other is = 10101010
1 byte = 8 bits
no we have it right?

bleak flicker
#

hey uh i joined the vpn via openvpn and i want to ping my target but that doesnt work :d idk

jolly yacht
timber hatch
#

yes

idle marsh
bleak flicker
#

downloaded new file and also tried the old file

idle marsh
#

what lab/module were you tring to access?

bleak flicker
#

all good the problem is solved :d thanks for answering tho

idle marsh
#

dw. nice name btw lol

bleak flicker
mellow saffron
#

Somehow htb academy don't shows me hints any fix ?

indigo rock
#

Hey guys, please note that to use ffuf on Pwnbox you will have to install it using sudo apt insatll ffuf and that crackmapexec is now netexec pepepray

acoustic owl
mellow saffron
#

the site somehow getting bigger but no hint message

acoustic owl
#

deactivate all AdBlockers and then try again

rustic sage
river jetty
#

This is a dumb question but in the module Windows Attacks & Defense they ask me to use the file passwords.txt to crack the hashes but it says there's no file in the directory. Here are my questions.

Where is the file on the machine given?
Is there a way to make my machine scan without a complete file path?

rustic sage
quiet trout
dawn bloom
#

Hello guys im on the file uploads module on the skill assesment section, i was able to read the source code of upload.php and find the directory where is storing my file and the file name scheme but im still getting a 404 not found

final shale
#

Hey guys i need a hint for the Skills Assessment - SQL Injection Fundamentals.
I dont want to lookup the write up because i want to learn after all, but i am stuck. I cant even get anything out with the injection techniques that are in the lessons.

wicked apex
#

oh actually, make sure if you really know the naming scheme

river jetty
wicked apex
wicked apex
final shale
#

O hold on i might have gotten myself unstuck 🙂

#

All done it was pretty easy actually. I just got a bit stuck in the begining

low roost
#

hey yall have a lil problem on footprinting module - > lab medium

found creds on smb share for mssql but cant login with it ?

acoustic owl
#

Try another user or password

low roost
#

mind if I dm ya

acoustic owl
#

sure, you can send me a dm

primal adder
#

Does anyone know why this command for this question doesn't work? It's at Linux Fundmanetals / Find Files and Directories

marsh drum
#

any one else currently on information security?

low roost
primal adder
low roost
#

remove the -exec ls -la ...

primal adder
low roost
#

you forgot the 2>/dev/null at the end

dim wolf
low roost
#

ahahahahaha

#

always kills me people who wants to hack their ex gf insta

eternal spindle
#

Im a girl mate

low roost
#

lool

eternal spindle
#

And its not abt tht

low roost
#

sorry its really not the place to

eternal spindle
#

Idk whats the fkn place 😭 am new here how do u Evennn use this app

#

Like what server do i even

#

💔💔

primal adder
dapper moth
eternal spindle
#

(Maybe)❤️

#

Ok fr though

fleet bough
#

Someone, please help me with que onda. I tried spawning the instance but it doesn't even work😭

fleet bough
eternal spindle
#

No someone help me instead HHAHAHA

#

OH

fleet bough
#

Yes

eternal spindle
#

🤠

#

Thx for the help pookie

fleet bough
#

Your'e welcome

storm elk
weak kindle
rapid lichen
#

Greetings all. I'm working through the CPTS "Documentation & Reporting Practice Lab" and have rearranged all of the notes to get some orientation. I've found the LFI and would like to exploit it for (I assume) the command injection but none of the attacks in the notes seem to work. I'm obviously missing something and have looked HTB forum posts and searched Discord for hints. I assume next step is to somehow read the index.php file for config using encoding but am a bit stuck. Any pointers here pls?

#

Ah, think I may just have solved it. Seems it's pretty basic and was staring me right in the face in the "command injection" module.

viral mica
#

so try starting with " as your starting character

final shale
viral mica
#

I never figured it out on my own

#

i kept writing payloads without the "

final shale
#

I am not sure we are talking about the same thing. the <img src tag wasnt involved in the method i used

rare swan
#

Sql injection: Assessment --> could read the flag through a webshell
Im wondering if it is also possible to establish a reverse shell out of a webshell at this specific task?

near abyss
#

i have a problem submitting the right answer at this module Detecting Windows Attacks with Splunk with section Detecting Pass-the-Hash

merry stone
#

hey i am at Footprinting Lab - Hard andI guessed the cred for SNMP , is there another way to get it?

rare swan
#

how did you guess the creds for snmp

merry stone
rare swan
#

actually you could try to bruteforce community strings

#

and you would get the same answer

fathom pendant
merry stone
#

ok thx

final shale
rustic sage
#

One day soon I will be hackerman

proven crane
#

has anyone recently had any luck with the Linux Privelege Escalation - Logrotate section?

#

I haven't been able to get it to work, even with simple payloads that just create a file on the target system

proven crane
#

simply wasn't working

#

had to keep trying

#

race condition moment

#

not a great demo for a learning module

glass quail
#

module: linux privilege escalation
section: linux services and internal enumeration

I'm having trouble finding the latest python version I put in like four different versions and used various commands

proven crane
#

use the number only

#

the flag format is unclear for that one

glass quail
#

that did it

proven crane
#

no problem

gentle bear
#

Hi guys, I need help with the last question:

"Connect to the WiFi network and submit the flag found at IP 192.168.2.1."

I can't connect even after following the steps, I even tried changing my MAC address. Any clues?

pulsar oak
#

Hi guys, I'm asking for help, I'm running a lab on HTB, using the web-delivery metasploit module, for some reason it gives this error

fathom pendant
rustic sage
#

Hello, i have a question, am i supposed to browse answers for htb academy questions? Im at the module 18 of the linux learning path, on the filter contents section, and there are some weird questions that i think the average reader wouldn't know, like "How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)", i got no idea on how to discover the answer because no tools were mentioned to find out how to discover the services etc

dapper moth
mellow saffron
#

wait this maybe gave too much info what I wrote so I deleted it my tipp is use netstat with -tuln flags

rustic sage
dim wolf
#

as far as i know, Linux Fundamentals is the only module that requires you to do a lot of your own research to answer the questions

rustic sage
#

i switched to linux mint on my actual desktop

#

it helps alot

fathom pendant
#

Imo most of the tools you'll use are given in like the first page or two of that module

#

It's a list of tools with a brief description

rustic sage
#

I think there are some in the cheat sheet

#

i never check that, should prob check it more

fathom pendant
#

Reading the content is generally useful

#

And no, I wasn't referring to the cheat sheet

dim wolf
#

read the sections, also read the friendly manual

rustic sage
#

man <tool>?

dim wolf
#

man

fathom pendant
#

Yup

#

You can even google "man <tool>" and find an online man page lol

rustic sage
#

with these tips i should be able to actually pass these questions

#

and googling too

dim wolf
#

if you're using tmux, split the pane and have the man page open in one pane

rustic sage
dim wolf
#

terminal multiplexor

fathom pendant
#

tmux is a terminal emulator that allows you to split panes and things like that

rustic sage
#

so it helps with openvpn

dim wolf
rustic sage
#

openvpn is annoying because it makes 1 terminal unusable

#

until you terminate the process

dim wolf
#

i have a window dedicated to openvpn

rustic sage
#

i will check that out

fathom pendant
safe star
#

yall dont close it?

rustic sage
rustic sage
safe star
#

no it doesnt

#

might depend on the terminal im guessing

dim wolf
#

if i bg it i forget about it

safe star
#

i just click the x on kali and it runs in the backgrond

safe star
#

try it out 🤷‍♂️ dont know how it would work with that terminal

rustic sage
#

lemme see on kali

rustic sage
#

on kali it doesnt do any warning

untold mica
#

hello

rustic sage
#

If it helps to see -- I keep a utilities tab open for vpn, smb share, webserver and my initial nmap output . I got into the habit of ctrl + shift +d to split terminals quickly

tender nimbus
#

hey guys im on the Pivoting, Tunneling, and Port Forwarding module and have a problem with the chisel section, after clonning the chisel tool + launching the go build command, after transfering the chisel to the pivot host i can't launch the server i get this error

lean kestrel
#

I need a little nudge with these questions from the password attack module. Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam." Once successful, log in with SSH and submit the contents of the flag.txt file as your answer. Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer. please

lean kestrel
#

I found the SSH, WinRM, and RDP keys, but only the SMB one is giving me trouble.

lean kestrel
tender nimbus
#

but you need to connect with ssh why are you searching for the smb creds?

lean kestrel
# tender nimbus but you need to connect with ssh why are you searching for the smb creds?

OK. This question, "Create a mutated wordlist using the files in the ZIP file under 'Resources' in the top right corner of this section. Use this wordlist to brute force the password for the user 'sam.' Once successful, log in with SSH and submit the contents of the flag.txt file as your answer," I haven't found it yet. I don't know which hashcat rule to combine with the password.list to find the credential for 'sam.'

tender nimbus
#

i remember a lot of people had problems with that part, when u use hydra how much time does it take to do all the file?

lean kestrel
tender nimbus
lean kestrel
tender nimbus
#

okej try again and tell me if you got it

#

did you use that

lean kestrel
quick pulsar
#

Omg, I just finished the footprinting module. So much information and for some reason the medium challenge didn't work on pwnbox, too bad it took me days to figure that out lmao. Spent days on that, but only maybe an hour on footprinting hard

#

I think the command you use to get into the computer didn't work for me for some reason. Had to use an alternative. Saying it this way to avoid spoilers

#

Gotta give props to the HTB team. Genuinely made a great course and I'm absorbing information like a sponge

limber surge
#

can i ask if this statement is true. hashcat when you run there the potfile right. Does the potfile consist of the ntds.dit and system registry?

hushed patio
#

Guys, quick question if anyone can help.
if I got SYSTEM shell on one of the machine in AD, but do not find any valid domain user on that system that is no NTLM hash from mimikatz and no TGS accounts through kerberoasting. What could be my next step in this scenario because till now I dont have any domain user with me, just local admin account this machine. Is this something I can do with my SYSTEM shell on this current machine?

cloud urchin
#

what module/section

next bronze
#

if whatever ntlm/aes hashes in ntds were cracked, potfile will record it, otherwise it won't be in there

limber surge
misty current
crimson moon
#

Password attacks section Credential hunting in Linux I’m not getting any output using hydra with mutated wordlist how much time does it take for it to complete? Because the flag is password of the user Will.

vestal fern
#

hey yall working through session security atm and first time using burpsuite, what do i configure the firefox proxy to be? default at 127 8080 or something specific to my pwnbox?

cloud urchin
cloud urchin
eager ledge
#

Phew! Just completed the Exploiting We Vulnerabilities in Thick-Client Applications section of Attacking Common Applications and it was a lot to take! I followed what was taught in the section step by step. Even then, I was getting stuck at so many places. There is no way that I could have figured all the things out by myself. So, when taking CPTS, we are expected to do these things by ourselves? If so, can anyone give me some advice on how I can be better prepared?

safe star
#

I’m goin in hoping it’s just not in there 😂

#

I doubt everyone who passed knows Java applications that well too

eager ledge
#

You haven't taken CPTS yet? You were helping people out. So I thought you had already taken the exam

safe star
#

I’m guessing it’s not in the exam

safe star
eager ledge
#

You reached "Attcking Common Applications" within two months!

#

I started the path way before. I have been doing this for 7-8 months

#

How much time do you dedicate per day?

safe star
eager ledge
#

I only do it for 2-3 hours per day though 🤐

safe star
#

No school, no internships🥲, no jo, so just cpts

eager ledge
#

When are you planning to take the exam?

weak kindle
#

Kerberos Attacks - Final Assesment
In the very last question I've done ssh local port forwarding to access the server machine but after that the RDP is very slow and laggy then I checked I wasn't able to ping the initial access machine anymore. I tried restarting it the third time and now it's been loading since eons

safe star
eager ledge
#

Best of Luck!

weak kindle
# cloud urchin CTRL+SHIFT+R

Tried that already, seems like ssh local port forwarind and X11 forwarding is crashing the initial machine a lot

safe star
#

Just finished the sliver module, skills assessment was good practice

cloud urchin
#

make sure you have no adblock on

weak kindle
cloud urchin
#

it's possible the platform is down, but no one else has said that, so it's probably your browser

#

you could also try another region

weak kindle
#

Check this the initial access machine is crashing again and again just after I perform ssh tunnelling or x11 port forwarding which is the itended path

#

Nothing wrong with my browser for sure

#

@cloud urchin

cloud urchin
#

i've only seen that happen under 2 scenarios. 1) browser issue. this is the most common reason. 2) platform is down.

weak kindle
cloud urchin
#

you showed a picture of your browser where the target is spawning and stated it's been loading for eons

#

you aren't pinging your spawned target, you're pinging something else. you'd only get your spawned target ip if it actually spawned and the IP was visible to you in your browser.

weak kindle
cloud urchin
#

use the tcp vpn if you're not on it, try another region.

weak kindle
#

This shouldn't be the case cause I'm at the very last question of the final assessment and everything was working well until I did the ssh tunnelling to access the internal joined AD Windows machine which messed everything up

cloud urchin
#

ok then reach out to support on the website

weak kindle
#

Understood will do

cloud urchin
#

i'd really suggest at minimum trying my troubleshooting steps first, aka another region and tcp vpn

#

you might be surprised in the performance difference

#

i'm in the US and switching to EU vpn was night and day

grand portal
#

could not find anything with the whole wordlist.

#

Password attack module, hard lab. im trying to ||brutefore using mut wordlists for bitlocker, my command is john --wordlist=mut_password.list hash.hashes idk but it only gives possible password with whole wordlist, that is 123456789! || anyone could point me in right direction?

weak kindle
cloud urchin
# weak kindle I'm from west asia region

ok, but you say there's a problem, i provide something to try, and you brush it off without trying... i can't really help you much more especially when you don't take the basic troubleshooting steps

grand portal
weak kindle
safe star
grand portal
#

i downloaded it properly, im sure of it, i used smget generally used for larger files over smb

safe star
#

I think others were able to tho

grand portal
#

do you need password during mounting? or need password to open the drive after mounting?

safe star
#

After

grand portal
#

okay thanks.

#

okay i tried mounting it with windows, password incorrect.

#

i dont get it, i used mut wordlists, password.list, used rockyou.txt for 4 hours.

safe star
#

Should not take 4 hours to crack the hash

#

Are you cracking on a vm?

grand portal
#

pwnbox

safe star
#

Do you have hashcat on your host machine

grand portal
#

yes

#

pwnbox

#

i hear hashcat is not good when hash is collected via john

#

plus i feel john is used for this cracking.

safe star
#

I used hashcat on my windows host

grand portal
#

does not matter. matters is the wordlist. right?

safe star
#

Yeah but it shouldn’t take that long tho

grand portal
#

||should i run again with rockyou.txt? mut, plain password.list could not crack it.||

#

if you use wrong wordlists, always gonnna take long.

safe star
#

Mutated is a lot shorter and it’s in there

#

Try the pass again

safe star
grand portal
#

okay

#

check dm

normal sand
#

Module: Windows Privilege Escalation
Section: Citrix Breakout
Link to section: https://academy.hackthebox.com/module/67/section/2502

I'm having trouble launching the Citrix environment. I RDP'd to the machine using the provided credentials. Then visited http://humongousretail.com/remote/, downloaded the client, and obtained the launch.ica file. After clicking to download the client, I got a the file, linuxx86-11.100.158406.tar.gz. I extracted the contents of this file but now I'm unsure how to proceed.

safe star
normal sand
#

I tried clicking on the monitor icon, but it just keeps downloading launch.ica files.

safe star
#

lemme check

normal sand
#

I think I may have found it. I think I need to open the launch.ica file using the citrix receiver application. Trying it now.

#

Okay, it wasn't Citrix receiver. Still stuck.

safe star
normal sand
# safe star i just opened the ica file and it worked

Was just trying that and it worked. I'd tried to give it execution permission earlier and launch from the cmdline but that didn't work for whatever reason. Just launched it from File Manager and it's connecting. Thanks.

safe star
#

i just clicked the download on the top right of firefox

normal sand
safe star
#

nah mine just loaded instantly

#

you clicked launch.ica?

normal sand
safe star
#

try on firefox

normal sand
idle marsh
normal sand
#

Anyone know how to get out of the Citrix window? When I launched it, it went full screen and now I'm stuck 💀

#

Ended up just disconnecting to setup the file transfer since I couldn't find a way to minimize/escape it.

safe star
#

🤣 I was pressing the windows key and opening a new terminal every time

#

There’s def a better way to do things

normal sand
opal nexus
#

Does anyone knows what is the reward for keeping streak of 30 weeks?

misty saddle
#

I was quite bummed out when I found out that was the "special reward" for keeping your streak FeelsBadMan

next bronze
#

you get a sense of pride and accomplishment

jolly yacht
#

is it possible to directly copy paste from the host to the pwn box without using the clipboard every time as a middle man to copy the info we needed from the host to pwnbox?

next bronze
jolly yacht
nova ginkgo
#

Attacking Enterprise Networks | Lateral Movement
Escalate privileges on the MS01 host and submit the contents of the flag.txt file on the Administrator Desktop.

I found password backadm but when i try to connect ms01 output is:

Error: An error of type WinRM::WinRMAuthorizationError happened, message is WinRM::WinRMAuthorizationError

Error: Exiting with code 1

I've been trying to connect since last night but it doesn't seem to work

fathom pendant
#

Don't read the questions or module material

#

Just work through it to DA without worrying about answering questions

nova ginkgo
fathom pendant
#

I understand that

#

What I'm telling you is working through it without reading the q's

#

Authorization error generally means that the username or password didn't work

#

The questions lead you on, which defeats the purpose of doing it blind

#

You'll feel far better working through it blind imo

unreal stream
#

does anyone know if the wayback machine is up? (for the info gathering module)

next bronze
#

spoilers

fathom pendant
#

Make sure you're using the right pw bc there's 2 backup accounts

fathom pendant
nova ginkgo
#

thanks

unreal stream
fathom pendant
#

Ah I see what you mean now

#

their api is taking a nap ¯_(ツ)_/¯

unreal stream
#

☠️

#

i'll just move onto the next section then

#

i'll see if tools like finalrecon work

#

if not then i'll probably leave it until the entire internet archive drama is over

naive sage
naive sage
#

Cheers!

high sky
#

Hi, I am working on the Attacking Common ApplIcations, I am using my own Kali linux... specifically I am trying to use the joomla-brute.py right now in the Joomla section, I am a little concerned i am not sure why, I guess because it is taking awhile, I am using rockyou.txt, I don't know if I am wasting my time or not. I assume this script is working because I am getting the pairs in red for fail, but it is not very verbose.

In addition to that I was unable to use droopescan because of imp and I messed with that a lot I tried the docker route and I still could not find imp to get it to run. I think there has been some significant changes with python in kali recently. I don't know if I need help even, but I sure hope I am running the right list.

fathom pendant
#

Yeah a fair bit of the tools are outdated

tall acorn
#

Hey guys recently I won htb vip+ in ctf competition but i don't wanna use it now cuz of exam so what is the expiry date of the code I mean is it there any? I am new to htb thing

fathom pendant
#

Droopescan worked fine for me

compact patrolBOT
tall acorn
naive sage
#

lee is fast ⛈️

high sky
fathom pendant
#

i remember fucking around with some stuff ¯_(ツ)_/¯

high sky
# fathom pendant Yeah a fair bit of the tools are outdated

maybe there is some new alternatives... I dont know what the imp is, I guess kali is having all the python packages with the python prefix now, and you have have to make a venv which is what I normally do anyways, but I could not find this imp that would not import, and it is my understanding that they got rid of the package... I was really suprised when I went the docker route I just just got the same fail to import imp

fathom pendant
#

But i wouldn't use rockyou btw

#

Id use a smaller wordlist

high sky
fathom pendant
#

No idea about imp

high sky
#

me either

fathom pendant
#

¯_(ツ)_/¯

night jasper
#

Can anyone help me with hacking wordpress

#

The module, I'm stuck at finding the directory indexing part 😦

river jetty
#

I'm trying to execute a Get-GPPPassword on a remote desktop and it isn't working. At first it was giving me this error:

.\Get-GPPPassword.ps1 : File C:\Users\bob\Downloads\Get-GPPPassword.ps1 cannot be loaded because running scripts is
disabled on this system. For more information, see about_Execution_Policies at
https:/go.microsoft.com/fwlink/?LinkID=135170.
At line:1 char:1
+ .\Get-GPPPassword.ps1
+ ~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : SecurityError: (:) [], PSSecurityException
    + FullyQualifiedErrorId : UnauthorizedAccess

After I did some research I found and used this to allow me to run the script:

Set-ExecutionPolicy -ExecutionPolicy Unrestricted -Scope Process

But now it's just running the script with no output or errors. Any help? Module: Windows Attacks & Defense: GPP Passwords

high sky
fathom pendant
next bronze
cerulean grail
#

In the Nessus Skill Assessment in the Pentesting job path there are several times where there could be two answers but it's onl accepting one of them. Is this a bug or am I misunderstanding some things? For example, there are two readable shares and it only accepts one answer.

river jetty
tender nimbus
tender nimbus
next bronze
# river jetty I did.

did you? because just running the script like that is not the correct way to use it

river jetty
tender nimbus
river jetty
solid quarry
#

without .\

#

and without .ps1, just "Get-GPPPassword"

river jetty
#

Interesting. Thank you @next bronze and @solid quarry. Appreciate it. I thought the . / was like "Sudo" but I guess it doesn't work like that?

next bronze
solid quarry
fathom pendant
#

When you import a module, using .\ tells you cwd to look for the file to import

neat ginkgo
#

Where can i ask questions about proLabs like Dante?

river jetty
#

Oh that makes sense. My mistake came from auto completing with tag instead of just writing it out. Thanks a bunch.

tender nimbus
#

With that article i founded it pretty easy to decrypte and read the file

tender nimbus
fathom pendant
onyx rapids
#

Still need help with that?

young flume
#

can you please help me?

onyx rapids
onyx rapids
marsh echo
spring sedge
storm elk
spring sedge
onyx rapids
onyx rapids
lean kestrel
tender nimbus
mellow saffron
#

When I click on hint button there is no hint only the page getting little bit bigger any clur why id this happening?

steady valve
#

I'm working on the Burp Intruder section of the Using Web Proxies module. I'm meant to get the html of a certain file under the admin directory. I've tried every combination I can think of but for the life of me when I send the payload it doesn't stick to the /admin directory. Can anyone tell me how it's actually set up?

My get line is GET §/admin§.html HTTP/1.1

Ive tried every combination of the above I can think of, but I just can't seem to get it to work. Any advice?

foggy knot
#

im sorry im gonna ask a bunch of questions

#

but i am stuck currently on HyperText Transfer Protocol (HTTP) web requests

misty saddle
onyx rapids
foggy knot
#

its module web requests

steady valve
foggy knot
#

and the section i belive is one

misty saddle
foggy knot
#

it asks me To get the flag, start the above exercise, then use cURL to download the file returned by '/download.php' in the server shown above. and gives me a dns to do but it isnt making sense

misty saddle
#

Or I would guess so since as @onyx rapids mentioned, it would also replace the "/", with the command you've been running.

misty saddle
foggy knot
#

ive tried -o -0 -s -h

#

and i plugged in the dns

steady valve
#

But thank you! I'll report back 🫡

misty saddle
foggy knot
#

in that format?

misty saddle
#

Yes

foggy knot
#

lemme try again brbr

onyx rapids
# steady valve I'll give it a shot when I'm back in like an hour, sudden family errand

If you do GET $/admin$.html and you use common.txt then each request will look like this:

advertise.html
advertisement.html
advertisers.html
advertising.html

This won't work because the / needs to be there before each payload. That forward slash might not seem important, but it's necessary for all requests
It should look like this:

/advertise.html
/advertisement.html
/advertisers.html
/advertising.html
misty saddle
foggy knot
#

i never got the url

onyx rapids
foggy knot
#

it stays as a dns?

misty saddle
foggy knot
#

yeah does the target not matter then?

misty saddle
#

I'll DM you, that's a bit easier.

foggy knot
#

ok

#

im just confused is all

misty saddle
#

No worries.

viral lotus
#

in the password attack module, section Passwd, Shadow & Opasswd, I am assuming getting the unhashed credentials will take some time?

subtle oriole
#

hello guys

#

is shodan installed on parrot for the CPTS path?

#

it seems it is not and some of the modules have exercises using it

#

any ideas?

#

it is FootPrinting Domain information

#

module

cosmic tide
#

Hello, I'm working on File Uploads Skill Assessment.
I think I'm almost done but stuck on the last step..
I got succeeded uploading a php code and found the uploaded file.
But the only thing I can see from the URL is blank image icon.
I tried to send ?cmd=ls commands to it, but it's not working.
Anyone can let me know what I'm doing wrong?

cosmic tide
#

I tried with pht.jpg and it was successful to upload the file.
Did I do something wrong?

safe star
subtle oriole
valid gate
#

Stuck on IMAP & POP3 Footprinting Modules.

I was able to answer the first 4, but I'm not able to list directories or mailboxes using anything taught in the module to answer the last 2 questions.

I logged into the IMAP server, checked the namespace, ran "a list "" "%" to get the directories", but can't use LSUB. Keep getting LSUB Bad error

safe star
#

thats why they dont ask a question at the end

subtle oriole
#

so should be ready

#

isnt

safe star
#

i dont think shodan is free to use

subtle oriole
#

is just I wanna try

#

oh, ok

polar widget
#

Can I DM the author of "User Behavior Forensics" module?

foggy knot
#

i thought i did it i guess not

#

module web requests section one i think

#

im having difficulties finding the flag

#

ive tried everything i can think of

cosmic tide
safe star
#

no curl flags needed

urban elk
viral lotus
# safe star Wym?

Examine the target using the credentials from the user Will and find out the password of the "root" user. Then, submit the password as the answer.Im assuming as it is root it will take time I used rockyou, as i didn't really know whether the given one would work

viral lotus
#

ahhh ok lol

valid gate
viral lotus
urban elk
# valid gate nope, not yet. found an interesting article I might try some stuff from though.

yep, I was going to say that. I found that section to be lacking as well, unfortunately. This is the one that did it for me, but I'm sure there's many: https://nickb.dev/blog/introduction-to-imap/

nickb.dev

Introduction This will be a detailed, though not exhaustive, quickstart into using IMAP. Initially this was also going to highlight the python library, imaplib, but the post became too long! Maybe next time.
The hope is that this’ll contain enough information about querying email servers that additional questions would most likely be redirected ...

#

LSUB also didn't work for me, until I realised that curl had already given me the list, so no more need to LSUB

safe star
#

did you use the mutated list?

viral lotus
viral lotus
valid gate
foggy monolith
#

In Joomla - Discovery and Enumeration I found what appeared to be a valid version number in the admin joomla.xml manifest, yet when I go to enter that into Fingerprint the Joomla version box it's saying it's wrong — why?

foggy monolith
#

Well Python2.7 isn't even in the PwnBox APT repositories anymore which automatically throws one of the options out the window.

#

And droopescan is throwing around 20 different possible versions that would take forever to narrow down.

fathom pendant
#

But also make sure you pay attention to what is being output for the versions, like plug-ins and other stuff

#

Also make sure you're looking at the right subdomain

safe robin
#

why this ssh is so slow

dapper moth
#

HTB is launching modules faster than I can unlock them and complete pepehands

steady valve
#

@onyx rapids @misty saddle not sure if either of you are still up, but i did what you guys asked and its still not working

i did GET /§admin§.html HTTP/1.1 and GET /§admin.html§ HTTP/1.1 but neither of them are getting me the flag

#

i think what im meant to be doing is scanning every single .html file that is within the admin directory

#

but when attacking with the payload, it just gives me this format

#

with a bunch of numbers

#

its not /admin/0.html or whatever its meant to be, it just gets it from the root directory i guess

#

i think i figured it out, but its just a matter of waiting and hoping for a flag

#

WE GOT IT

vestal fern
#

working on Webattacks atm whenever i am using curl with my target IP and port I feel like I am never getting results or the intended results, do I have to configure something in the terminal beforehand? here is the command i am trying

curl -s "http://94.237.54.201:30740/documents.php" | grep "<li class='pure-tree_link'>"

onyx rapids
twin cape
#

Hello guys and girls, how are you all doing? I have a question I need help with. So, for HTB pentesting, they had Kali Linux through WSL (which I didn’t expect, so I deleted it today) and Parrot OS through VMware. However, I did things a bit differently. I just downloaded Linux as a VirtualBox VM, and now I’m planning to download Parrot the same way, so both will be on VirtualBox. The tricky part is that my Linux setup has some configurations (not too extensive, but still something). Should I delete it and start fresh, or should I just go ahead and set up both Linux and Parrot on VirtualBox?

ocean night
#

You don't need both to be honest, pick one and stick with it. Parrot comes pre-loaded with tools, like Kali

#

If you want to build up your own Linux VM with tools as you go, that's fine too

#

It's really personal choice

steady valve
# onyx rapids can you link the section, i'll have a look

i found the issue on my own. anything between the $$ is something that is replaced for whatever reason, so when we were doing /$admin$.html, it would replace admin with literally everything. to search the /admin directory, we shouldve done /admin/$flag$.html or something for it to go through everything within the admin directory that ended with .html

twin cape
ocean night
#

Linux is not a distribution - it is more of the operating system. Debian, Ubuntu, Parrot, Kali, etc etc, those are distributions, so likely you have installed one of these?

#

The Academy uses the Pwnbox, which uses a Parrot image, if you choose to use the Pwnbox provided.

#

..but, you do not need to use the Pwnbox provided, you can indeed and without issue use your own VM, whatever distribution that may be

twin cape
#

this part got me confused :
"
Among the most popular include, but not limited to:

ParrotOS (Pwnbox) Kali Linux BlackArch BackBox
In this case, we will deal with ParrotOS Security as our penetration testing distribution of choice.

VM Setup

"

then they start with parrot , and that what got me thinking or doubting which or what should be done next ?

ocean night
#

Hack The Box and ParrotOS (Parrot Linux) are partners, together.

#

The team who maintain and update Parrot are part of HTB

#

It is kept up to date with all the tools required in order to complete the Academy content

twin cape
#

Okay, I guess I'll just keep Linux for my own use and use Pwnbox for the Parrot OS tasks. Would that be a correct approach?

ocean night
#

I mean, there are no Parrot OS specific tasks

#

The only difference is that ParrotOS comes pre-loaded with the tools you'll need to use in order to progress through Academy modules

cloud urchin
#

toyota vs honda, they're both cars, they will both take you to your destination, it's personal preference as to which one you want to use

ocean night
#

You don't have to use it however, and can build up your own Linux installation, whatever distribution it may be with the tools you need as you go

#

Again, personal preference

twin cape
#

Okay, thanks to both of you for the advice and good night then .

ocean night
#

You're welcome 🙂

steady valve
#

On Using Web Proxies > Skills Assessment, I'm so lost at this question:

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

I have no idea what I'm meant to do. Since when could I just fuzz some characters? How do I even do that?

#

GET 3dac93b8cd250aa8c1a36fffc79a17a§{fuzzed_char}§ HTTP/1.1

this is what i have so far. i loaded the alphanum-case.txt into payload settings, and set payload processing to encode base64 and encode as ASCII hex, but im only getting one result and i dont think im doing it right

bright nova
#

I seem to have issues with the targets in an early module, is it normal that my targets are in "spawning" status for more than 10 mins?

cloud urchin
#

no, try ctrl+shift+r

bright nova
#

It goes to "fetching status" to then go back to spawning

cloud urchin
#

try another browser

#

make sure you have any adlock disabled including things like pihole

bright nova
#

jmm it finaly timed out and then a retry after it showed me the targets

shut quest
dim wolf
#

@untold barn are you using a VM

untold barn
#

Yes, I have tested on Kali and Parrot

dim wolf
#

you mentioned your RAM but unless you're allocating 32 GB RAM to your VM it's not going to utilize that much

#

how much are you allocating to your VM

untold barn
#

I saw cpu usage was only ever at 10% but i will check ram usage now, i currently allocate 8gb ram

#

ram is also only 10%

#

im stuck on module because this command is not reasonable lol

dim wolf
#

the command is reasonable, it's just something up with your setup

#

unless you're getting rate-limited as part of the module exercise

#

are you supposed to let the command finish?

untold barn
#

right now it runs at 2 req/second. I tried -t 50 but I think it gives false negatives

#

The module metnions "
Let us repeat the first command we used, add the recursion flags to it while specifying .php as our extension, and see what results we get:
As we can see this time, the scan took much longer, sent almost six times the number of requests, and the wordlist doubled in size (once with .php and once without). Still, we got a large number of results, including all the results we previously identified, all with a single line of command.
"

#

But actually i cannot get any results because this one command on one ip with only 1 depth takes 5 days

dim wolf
#

maybe try respawning the target, using a different VPN region

untold barn
#

The VPN only offers EU and USA for academy, but i live in Vietnam, the ping to both of those regions is around 200.

#

correction, i had checked another module and it only showed EU and USA. I have checked this module and it has the same regions as htb labs, i will swap regions. This is my bad

#

Now 250 rq a second, much better lol. Thank you 😄

primal adder
#

Good morning. I'm stuck at Linux Fundamentals / File Descriptors and Redirections. Can someone tell how to find how many total packages are installed on the target system using find?

ocean night
#

feck

cloud urchin
#

hacked

primal adder
ocean night
#

Trolled the wrong channel 😦

eager ledge
#

Hi,

I am doing IIS Tilde Enumeration module. It says that we can discover the hidden directory secretDocuments by using the 8.3 format ~sec. But isn't it supposed to be numbers after ~ sign? I mean why is alphanumeric character after ~ that too not after a .?

obtuse veldt
#

Hi, I'm encountering an issue while using xfreerdp to connect to an RDP server. The certificate verification fails with a self-signed certificate error and a hostname mismatch warning. Here's a snippet of the error:

Common Name (CN): ACADEMY-EA-MS01.INLANEFREIGHT.LOCAL
The hostname (10.129.188.112) does not match the name in the certificate (ACADEMY-EA-MS01.INLANEFREIGHT.LOCAL).```
Active Directory Enum > LLMNR/NBT-NS Poisoning - from Windows.
autumn pilot
#

You can ignore the error

obtuse veldt
#

but the connection still fails

autumn pilot
#

The connection wont fail just from the error message you've provided

analog dock
#

/cert:ignore

latent frigate
#

Hello, did u mange to find a way to get the double pivoting with ligol in the end?

obtuse veldt
#

I don't know why, but after restarting env the problem is solved))

#

thx guys

safe star
latent frigate
sterile solstice
latent frigate
sterile solstice
#

i can find where they are for AEN. but ask away for whatever issue you have, and i may be able to help. i used ligolo in zephyr and dante, which improved those skills a bit

surreal chasm
#

Hey, from a legal perspective,
Is subdomain bruteforcing considered illegal activity?
Using the known subdomains for inlanefreight.com (www, ns1, ns2, ns3, blog, support, customer), find any missing subdomains by brute-forcing possible domain names. Provide your answer with the complete subdomain, e.g., www.inlanefreight.com.
Under Information Gathering Web Edition - Subdomain Bruteforcing

fathom pendant
#

So they have allowed a broad scope

sterile solstice
shut vapor
#

I'm in Using Web Proxies > Skill Assessment
How do I hexencode a value while fuzzing with ZAP? I've found a community script to do as much, but after installing it doesn't show up in my list of preprocessors. Has anyone solved this one using ZAP?

grand portal
#

Finally done with the password attack module. it was a good module.

fading olive
quiet trout
unborn plaza
#

Hello, When will videos be added to the academy instead of just reading? it's too boring

#

now all platforms also have videos except htb

weak kindle
#

Folks, Im planning to do the "Active Directory Trust Attacks" in Academy section I wanted to know if the each attacks explained are both in linux and windows hands-on? Or
Has anyone done that module?

vagrant wraith
#

hey gusy currenlty working on [ACL Enumeration academy] i just really dont get this part "What flag can we use with PowerView to show us the ObjectAceType in a human-readable format during our enumeration? " id appreciate the help thank you

shut vapor
fading olive
shut vapor
#

Yea I'll have to run through it again when I get back to my kali VM.

shut vapor