#modules

1 messages · Page 355 of 1

foggy snow
#

Host is up (0.31s latency).
Not shown: 92 closed tcp ports (reset)
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
53/tcp filtered domain
80/tcp open http
110/tcp open pop3
139/tcp open netbios-ssn
143/tcp open imap
445/tcp filtered microsoft-ds

Nmap done: 1 IP address (1 host up) scanned in 2.77 seconds

#

it is port 53 I need to enumerate right? since it is asking me for DNS version

lusty thicket
foggy snow
# lusty thicket udp buddy now run it again

Host is up (1.8s latency).
All 100 scanned ports on 10.129.118.193 are in ignored states.
Not shown: 100 filtered udp ports (host-unreach)

Nmap done: 1 IP address (1 host up) scanned in 134.70 seconds

worthy solstice
#

any hint for Modern Web Exploitation technique SA Q3-What is the password for the admin user of the Vault web application?

foggy snow
foggy snow
#

Ahh okay, that took me 1148 seconds so -p- will probably take ages

lusty thicket
foggy snow
worthy solstice
#

my stress from modern web exploitation skill assessment last 2 questions are gone now. Thanks to that guy

foggy snow
#

Stats: 0:54:06 elapsed; 0 hosts completed (1 up), 1 undergoing UDP Scan
UDP Scan Timing: About 4.94% done; ETC: 18:22 (17:20:23 remaining)

tranquil axle
#

full udp is my last resort kind of thing. Scanning the snmp ports specifically can yield good results, but in the machines I've done there was rarely anything useful on udp (except for snmp)

lusty thicket
#

i could just tell you the port

#

but what fun would that be

foggy snow
#

why would it not be port 53 though?

foggy snow
foggy snow
#

it also uses port 53

lusty thicket
foggy snow
#

yea but for this certain excersize its 53 right?

lusty thicket
#

yes

foggy snow
#

do you reckon the lab could have a mistake?

#

since I am getting a version, just not the correct one

lusty thicket
foggy snow
#

not the correct one

#

Host is up (0.22s latency).

PORT STATE SERVICE VERSION
53/udp open domain NLnet Labs NSD

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 1.45 seconds

#

thats the version im getting

#

NLnet Labs NSD

foggy snow
lusty thicket
#

can you say that out loud

foggy snow
#

I know it from looking in the solution

#

but I haven't been able to get it myself

foggy snow
#

its not about the flag or being able to continue, I just want to know what im doing wrong / misunderstanding

lime lake
#

Hello! 😄

lusty thicket
#

reset the target and try again

foggy snow
#

atleast I've learned to try that sooner next time hahahha

lusty thicket
#

awesome

raw hornet
#

Hi, please, Can you help me please? I’m in HTB DACLs I module, I’m in Password Abuse section, I’m stuck on the last part, abusing Marcos’ account to get the gMSA of the htb-svc$ account to get the contents of the flag.txt file, I already have the hash of the htb account, I tried to connect with pth-winexe, with psexec, winrm, crackmapexec, and others, but it refuses the connection, then I try to do pth with mimikatz but to run it I need to access as administrator, but I don’t have those credentials. What should I do to get that flag, or what am I doing wrong? Thanks for your help.

calm pier
#

Morning, I am at the skill assessment of the using web proxies module. I cannot get the flag for the first task. I can get the POST request that contains the getflag=true. I used ZAP for fuzzing the POST request 100 even 1000 times and can't get the flag. I insert a number in the body and choose numberzz from the payload and define the range. Every response has the same length. I looked at the posts of the forum and I am doing it the way like people describe it. Can anyone help me?

crimson ocean
#

How to download python in my windows 7 laptop

cloud urchin
acoustic owl
normal sand
#

Module: Cross-Site Scripting (XSS)
Section: Session Hijacking
Link to Section: https://academy.hackthebox.com/module/103/section/1008

I was just revisiting this module and had a question based on the example scenario discussed in the mentioned section. When it comes to blind XSS - session hijacking/cookie stealing attacks, in reality we'd have to wait for the admin to access the page in order for the payload to execute, right? Or have I misunderstood and there's actually no need for an admin to visit the page?

The "page" I'm referring to is, of course, the admin review page or whatever that we're targeting where our payload lies, to which we don't have access.

midnight kindle
#

Hi,
I too was stuck , and ran this command and it works.
gobuster vhost -u http://94.237.63.109:32594 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --domain inlanefreight.htb -t 100 --append-domain

IDK, i specified the DNS in the hosts file but it didnt work for me but specifying the domain in the command does smh....

royal geyser
#

how to get roles sir

acoustic owl
tulip gyro
#

good day, do you have hosting that can suggest that supported to paymongo api? thank you

cloud urchin
#

maybe ask in #general this channel is for the academy modules

real delta
#

no, I think both are custom groups. You can protect users in AD with preventing them from being delegated to

real delta
#

not sure if that's what the module or section was about tho

#

interesting. I never knew there was a "protected Users" and "Protected groups" groups

fathom pendant
#

Don't overthink it i believe the group's name is specifically "Protected Users" so by trying to dig deeper your looking at an apple and calling it an orange

#

And the "Built-In" groups require audit configuration to be tracked in that manner that you described

hasty mauve
#

In Pivoting, Tunneling, and Port Forwarding Module, specifically in Web Server Pivoting with Rpivot.
as soon as I run proxychains firefox <ip> <port> the system starts to lag then freeze, then crash and tell me to logout and login again.
I'm using Debian 12, any help?

#

I tried ssh -D method and rpivot method.

cobalt osprey
#

hello, i am currently doing the passwords attack module, and now i have to use crackmapeexec but when i try to use it from command line it says that he doesen't find the module, i tried a lot of metod sto install it but none of them works, what can i do? ty guys

cobalt osprey
#

ty so much

vernal dove
#

.

limpid hemlock
#

Hey in the wifi pentesting basics modules there is a section connecting to wifi networks

#

I want to briwse to an http address and locate flag but i cant use chrom curl wget nothing is also working any help

primal adder
#

I'm trying to pass the "How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)" question at "Linux Fundamentals / Filter Contents" and I found a lot of ways to solve it but I don't understand any of them since I've never been told that I need to know literally every Linux command before starting to learn Linux Fundamentals.

  • What's netstat -tunleep4 command?
  • What's ss -l -4 command?
  • What's systemctl command?
  • What's netstat -luntp command?
  • What's service command?
#

And why is everything in this course based on that I'm supposed to already know everything before I start learning?

pseudo juniper
#

Thanks for the hint!

#

I wasted a long time scraping tom's ssh. You're a life saver

zenith wing
#

Can anyone help me regarding the skills assessment of the Wi-Fi Penetration Testing Basics module? Thank you in advance!

limpid hemlock
#

Hey @zenith wing can you help me

zenith wing
#

i wrote private message @limpid hemlock

pseudo kiln
#

Hey guys, I got a question when it comes to running LaZagne on Linux. Do I just transfer these files to the target and run .laZagne.py all ? Or am I missing something ? Am I supposed to create a reverse proxy to the target and do pip3 install -r requirements to allow the target to reach the internet first and install the other requirements ?

edgy bough
#

Hey, I want in help of Reverse Engineering, or algorithm makers..
Anyone can help.me

gray yacht
sudden harbor
#

For anyone working on brute forcing WPS with reaver, if you aren't getting the answer in like less than 3 minutes, either revert and/or try something different from the section. If you're waiting longer than 5 minutes, something's wrong

gray yacht
dim fossil
#

Hi

sick pilot
#

got stuck in Windows Privilege Escalation - Other files section need help

pseudo kiln
# gray yacht I'm pretty sure I just used wget

and then you just ignore these errors ?

-] Module Env_variable is not used due to unresolved dependence:
No module named 'psutil'
[-] Module Rclone is not used due to unresolved dependence:
No module named 'Crypto'

mainly wondering what else it could find if it had these modules installed on the target

gray yacht
pseudo kiln
#

on Linux machine, never had them on windows

gray yacht
#

I brought over the entire Linux folder and had no issues running it, lol.

knotty anvil
pseudo kiln
#

yeah I did the same, scped the entire Linux folder and still got those errors
the tools runs and displays some passwords, I am mainly wondering what else it could discover if those modules were present on the target

sick pilot
#

tried command from cheatsheet and modules got some passwords but none of the bob_adm

gray yacht
pseudo kiln
upper ruin
opaque sundial
#

Ey

pseudo kiln
#

eh, still no luck ,maybe in your case the target already had the crypto and psutil modules

gray yacht
pallid fulcrum
#

Hello to everyone

next stone
#

Anybody here have completed the Tier 4 Secure Coding 101: JavaScript module?
I'm interested to take it but not sure that if it is worth 1000 cubes or not??

It says it's a 8 hrs long module, and doesn't seems like a big module.

limpid hemlock
#

Spent 500 each on tow tier 3 modules thats more worth it

#

Bypassing mac filtering module to find essid of 5gz band i ran command with sudo airodump-ng wlan0 --band a but the name i get isnt the answer

burnt spruce
#

hi guys

burnt spruce
#

trying to solve Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

I used metasploit, smtp-user-name and got 37 result, and any of this result isnt valid. Surfing the internet, i find out that there should be button resource with wordlist, but i think it was deleted few days ago. So how to solve it?

analog dock
burnt spruce
#

yes

analog dock
#

Nmap -sV

#

Which module is this?

burnt spruce
#
25/tcp open  smtp
| fingerprint-strings: 
|   Hello: 
|     220 InFreight ESMTP v2.11
|     Syntax: EHLO hostname
|   NULL: 
|_    220 InFreight ESMTP v2.11
|_smtp-commands: mail1, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN, SMTPUTF8, CHUNKING
burnt spruce
analog dock
#

Banner + version number

burnt spruce
analog dock
#

Yes

burnt spruce
#

i need second

#

first one i already solved

analog dock
#

That’s the first question

burnt spruce
#

you asked for nmap

#
Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

this is secon

analog dock
burnt spruce
#

i said that there is not button resource

analog dock
burnt spruce
analog dock
#

Scroll up

#

Above the table of contents

burnt spruce
#

solved

analog dock
worthy solstice
#

can anyone verify the last Q of SA for modern web exploitation is working as intended?

brazen plover
#

Good morning guys, could someone give me a foothold in the skill assessment XSS and csrf of CWEE

#

@analog dock Can you give me a foothold in the skill assessment? 🥹

analog dock
#

Maybe check the forums

shut vapor
#

File Inclusion > Basic Bypasses # Path Truncation https://academy.hackthebox.com/module/23/section/1491
Suggests that if an extension is being forced into the user-supplied string (e.g. "./lang_" + $user-input + ".php"), it can be bypassed by pushing it out of the 4096 character boundary, however, the path must start with a non-existent directory while the section prior says that for a relative path to work the directory must exist (i.e., there example was "/lang_/../../../" where if "lang_" doesn't exist then the relative path is invalid).

#

Does anyone have insight on this contradiction if both are accurate or one is inaccurate?

#

Lab testing - referencing a bogus directory (e.g. ./bogus/../../../../etc/passwd) fails, so the requirement to reference a non-existent directory doesn't make sense to me, but I can't test that in the lab.

bright shoal
#

hello guys how do yall take notes

glass moat
#

Hello,
Attack and defense -> PKI - ESC1.
Connect to the Kali host first, then use RDP to access WS001 as bob:Slavi123, and practice the techniques shown in this section. What is the flag value located at \dc1\c$\scripts?

I found the flag in \dc1\c$\scripts\flag.txt, but it is not being accepted

shut vapor
# bright shoal hello guys how do yall take notes

I use a wiki, but plenty of people recommend obsidian or cherry tree. Probably anything where you can link sections to each other. Play around with a few options and settle on one that meets your expectations & needs.

bright shoal
shut vapor
#

I rarely go back to reference my hand-written notes, but the act of hand-writing helps me absorb things. The labs are a great way to make sure I can rely on my notes to perform a certain task. It all ties together.

bright shoal
midnight kindle
#

Hi All,
i am stuck in Information Gathering - Web Edition module , Chapter - Web Archives

question is very simple - + 0 Going back to March 2002, what website did the facebook.com domain redirect too? Answer with the full domain, eg http://www.facebook.com/

However, on wayback machine, its giving the same domain, i cant find any redirection.
picture attached.

#

cant attach picture 😦

#

any help will be highly appreciated, thanks

acoustic owl
shut vapor
bright shoal
#

@shut vapor btw asking from a newbie perspective which linux do you use and do you recommend it ? and why ? big_think

civic steeple
#

if you want to take a screenshot but the output in the terminal is much longer than what shows on screen, what do you do there?

shut vapor
limpid hemlock
#

Hey in the bypassing mac filtering section in wifi pentesting module i dont see the wifi to connect to the 5g one

bright shoal
shut vapor
lusty thicket
#

if you're attempting the character overflow you dont care if the path exists because the malformed path exploits truncation and not resolution

#

if you're relying on the relative path transversal the path resolved must exist for the transversal to be valid

toxic lava
#

Greetings folks. New to this discord and getting my feet wet with cybersecurity in general.
I'm having some trouble getting through the Linux Fundamentals module, specifically the Working with Web Services section. I am using the online Parrot VM instance the module provides.

I follow along with the instructions to install Apache. Starting the service resulted in an error, which I was able to correct by editing the ports.conf file to listen on port 8080 instead of 80. Now I can start Apache and get the service running with no issues.

Next it says to navigate to the default page in a web browser by going to "http://localhost". This does not work (see attached image). What am I doing wrong?

#

Running "systemctl status" gives me the following:

acoustic owl
toxic lava
#

Of course. That was it. Thanks!

last haven
#

In Getting Started Section > Knowledge Check, I obtained my initial foothold on the system, but I am unable to use wget to download LinEnum.sh from my machine after setting up the http server with python. My issue seems identical to this - https://forum.hackthebox.com/t/nibbles-privilege-escalation-python-http-server-wget-download-linenum-sh-stuck-at-0-downloading/285736 but it doesn't have any answers either.
wget log says:

Read error at byte 0/46631 (Connection timed out). Retrying.
I've confirmed I'm able to use curl and read a small text file i created in the same directory as well.
Can someone help?

scenic ibex
#

I have a problem with submitting the flag... The flag is correct but not accepted?!!

#

in : HTB academy
Current Path : Bug Bounty Hunter
Q: For HTTP Headers

viral lotus
scenic ibex
#

I did all the ways

limpid hemlock
#

Anyone help me with the bypassing mac filter section i wifi pentesting basics module i cant seem to connect to the 5g network after doing all whats mentioned in this section

#

?

rustic sage
#

Does anyone finds the introduction to windows command line module boring???

gray yacht
cloud urchin
last haven
cloud urchin
shut vapor
fathom pendant
shut vapor
#

Right, it's not setup in the lab so I can't experiment with it to validate one way or another.

fathom pendant
#

It's likely just how it works tbh

#

Idk

shut vapor
#

Thanks. I've recorded the requirement in my notes to play with if I encounter it, but I'm open to clarification if anyone more familiar with PHP drops by.

cloud urchin
#

When the path starts with an existing directory, the server resolves part of the path relative to it, breaking or limiting the traversal. A non-existent directory ensures the server doesn't prematurely resolve or restrict traversal logic, keeping the payload intact. Imagine the following path on the server:

/var/www/html

Now, a user submits this payload:

?language=existing_dir/../../../../etc/passwd

If existing_dir exists in /var/www/html, the server might resolve the path as:

/var/www/html/existing_dir/../../../../etc/passwd

This would then normalize to:

/var/www/etc/passwd

In this case, the traversal fails to escape the /var/www directory because the server resolves existing_dir as a valid starting point and truncates traversal relative to it.

#

Many web servers or file inclusion mechanisms resolve paths sequentially, checking the existence of each directory in the path. If a directory in the path exists, the server may switch to resolving the file system path relative to that directory.

winged egret
#

Hello has anyone managed to download and use the tool xcat, it automates XPATH injections

lusty thicket
shut vapor
lusty thicket
#

php has its quirks..

winged egret
acoustic owl
winged egret
loud dagger
#

can you not have two academy labs running at once?

last haven
acoustic owl
loud dagger
#

shit

#

password attacks is going to take forever

acoustic owl
loud dagger
#

ok it's taking a very long time for me

#

the lab for the password mutations section requires a wordlist of 187k passwords

#

and it's taking absolutely ages

#

even after i split the wordlist into 10 different files and set hydra to max speed it still takes like an hour and a half per wordlist

#

wtf am i doing wrong

acoustic owl
#

If I remember correctly, there are two services. One of them can only be attacked very slowly

loud dagger
#

it's ssh

tranquil axle
#

the password attacks module showed me that bruteforce of online services is the absolute last resort option for me

loud dagger
#

yeah this fucking sucks

tranquil axle
#

but yes, you are not supposed to bruteforce ssh

loud dagger
#

well tell that to the htb academy team

#

idk i'll try something else then

#

brute forcing ssh is clearly not the right solution

cloud urchin
# loud dagger well tell that to the htb academy team

if you read the question, it doesn't say to brute force ssh. it says to find the password for the user and then simply log into ssh with that. not saying it isn't ssh, i'd have to go back and look, but just saying that's not what the question is saying to brute force.

loud dagger
#

yeah i just noticed that

tranquil axle
#

tbh password attacks is one of my least favorite modules for this reason (and that some of the bruteforces just take way too long, even if you do everything right)

#

just bite your teeth together and push through this module

loud dagger
#

that's what i'm doing, i just wish i could do something else in the meantime

#

as in something productive

sinful mirage
#

Hello guys, I am on linux fundamentials, filtering exercises and i have a question:
"Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer. "
but i cannot connect to the website, entering the website url in the browser also does not work. Is the website down and i cant complete it because of that?

#

also, why is it required to use the pwnbox for that particular exercise?

#

alright, the website works, but the question about the pwnbox still stands

shut vapor
#

I don't know why it says something about the target machine. Did a machine spawn for the lab? Maybe that's what it's referring to.

sinful mirage
#

maybe they are referencing the machines which we usually run with vpn

#

and connect to them

shut vapor
#

What section is this? I'll load it up to verify curl on Kali works.

sinful mirage
#

but it still makes no sense to use anything other than even your own machine if the target is an existing website

cloud urchin
sinful mirage
shut vapor
#

I mean, I can't imagine why you'd need pwnbox for that, but I make mistakes answering questions on a semi-regular basis.

sinful mirage
cloud urchin
sinful mirage
#

The question itself:
"Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer. "

cloud urchin
#

yeah.. i can see where you're coming from, but it doesn't say you have to use the pwnbox. you can also have a vm of the pwnbox. either way you may want to post it in #1234357888114364508 and ask them to make it more clear

sinful mirage
#

alright thanks

last adder
#

Hi all, i'm on CWEE path, whitebox, race conditions module. pretty stuck here on exploiting e-shop lab for getting 100$ balance, not because its hard, the vuln is pretty easy and obvious, I fully understand it. but getting the flag is not easy due to randomness, network latency etc. any suggestions to improve my odds with turbo intruder?

quasi wave
#

Can someone help me out here?

#

what am I doing wrong?

cloud urchin
#

make sure not to spoil stuff

quasi wave
#

can someone DM me?

#

I need help from someone

#

hi can someone help with getting the flag from David's folder? I have his account hash but the hash won't work for getting flag from his folder. It still says access denied. The hash they gave me for julio works for getting Julio's folder and I got the flag in that folder. I have David's account hash but I think the issue is that's not the same as his password hash.

#

can someone help me get his password hash?

#

I'm assuming that's what's necessary for a pth attack

#

this is for Password Attacks Module's Pass the Hash section

#

if someone could DM be I would be very happy

cloud urchin
#

how are you trying to use the hash

#

there are a lot of tools that can use the hash instead of the password, i'd look into trying different ones

analog dock
past hemlock
#

I'm currently working on a server-side attack module related to Blind SSRF and have encountered a challenge. While I can interact with the default HTTP port (80), I'm struggling to identify other open ports—particularly the one potentially serving non-HTTP (or sensitive) content.

If anyone has experience with advanced port discovery techniques or methodologies to identify such ports in the context of Blind SSRF, I would greatly appreciate your guidance.

last adder
last adder
#

thanks @analog dock

analog dock
last adder
#

I only got some succeeded when I was on pwnbox, when I use my VM over VPN connection, 0 succeeded... not sure if thats because of my internet somehow not fast enough?

analog dock
#

Might be

last adder
#

yeah for modules that time-sensitive like race cond. and enumerating users, I also found using pwnbox got more accurate results than over VPN

deft lily
#

am i doing something wrong?

#

just trying to ssh to a target

safe star
#

Remove the brackets

mortal locust
#

Hey

Can anyone help me using Chisel?

I m doing AD room (AD Enumeration & Attacks - Skills Assessment Part I)

But i dnt know how to use metasploit with autoroute. So i m using Chisel instead. But cant make it work

#

i m not able to work though and get the pivoting thing working
In the module (pivoting) we have both linux machines

But in AD i have the pivot host as windows machine.

I am able to get a reverse powershell on the windows machine and have the chiesel.exe on that machine as well

deft lily
mortal locust
#

while connecting the both i m not sure if it gets connected or not!! i try proxycahins nmap to the other network, but that does not help

cloud urchin
gray yacht
mortal locust
gray yacht
mortal locust
mortal locust
fading seal
coral karma
#

Hey, anyone else working windows evasion module? I feel like I'm going crazy, I don't have access to the DEV box right? Only the target box? so I need to go fire up my own Windows dev VM and connect to the VPN? I was hoping to just use their VM while I'm travelling Sad_Squidward_Pepe

gray yacht
coral karma
#

thx

#

agreed sadglas

#

can you tell I always fail shit by not reading the question properly?

deft lily
#

hey im trying to ssh to target with my own VM but i need the VPN provided right?

#

how do i get their VPN working with my VPN i dont really get that part

coral karma
#

What do you have set up? a personal VPN and you have the OVPN file for labs?

deft lily
#

well i was just gonna get nord onto my machine once i know how that works

#

so personal

coral karma
#

Yeah that should just act as a pipe to the internet, so you can just VPN through that into HTB with openvpn --config ./your_file.ovpn

#

personal VPN or no shouldn't matter

deft lily
coral karma
#

Yeah go for it, but I am sending good vibes

#

should just work all OK vi VPN mgic

deft lily
#

i already ran into a wall cause nord is saying it doesnt detect an OS

last adder
#

I'm in client-side js pollution module. I played around with jquery's getScript() in js console. Can someone explain why jquery getScript() uses the code from "src" property instead of the url in its first argument? the module kind of glossed over this as one of gadgets that just works. ```js

$.getScript("data:,console.log(Date.now());//");
1732489222608

Object.prototype.src = ["data:,console.log('pwned');//"]
Array [ "data:,console.log('pwned');//" ]

$.getScript("data:,console.log(Date.now());//");
pwned

regal kernel
#

Heyy

cloud urchin
#

what? you can't spawn more than 1 target in academy.. you can just pivot into the dev machine.

#

still find it much easier to just build the code on your host machine and copy it over

#

i thought i remembered pivoting over, can you actually spawn 2 machines at once?

#

i see, they expect you to spawn the dev machine and create the code then try it on the target? really way easier to just do it on your own machine or windows vm

coral karma
#

Yeah that seems to be the way to go but hte VS build is broken sadglas I'm gonn sleep and just use my own machine when I'm back tomorrow

#

part of the appeal of academy was being able to do stuff on their boxes

odd pond
#

Just finished SQL Injections modules skill assessment , it’s extremely frustrating that the input box capitalized all input but apparently it wasn’t actually capitalized? Wasted an out creating web shells because input made it seem that ‘REQUEST[0]’ was being passed as all caps

midnight verge
#

Anyone can help ? I followed the steps of the example and it still doesn't work ?

#

Module :

fathom pendant
midnight verge
#

thx I will look into that !

fathom pendant
#

Something running in real-time

midnight verge
#

yeah real-time protection

#

I just turned it off and tried , but it still doesn't work

fathom pendant
midnight verge
#

is it normal when I run the server it only loads for a split second ?

fathom pendant
#

[Not enough details] you mean it starts then stops? Are you running with sudo?

midnight verge
#

because when I now run the command : regsvr32.exe SocksOverRDP-Plugin.dll. I have this issue

fathom pendant
midnight verge
#

it worked lol

tawdry finch
#

I want to learn how to hack

compact patrolBOT
dark hedge
loud dagger
#

anyone else having a ton of trouble with academy labs today? every time i do like an nmap scan or something the lab just goes down and i have to reset the target

#

i'm home from college right now and i'm on my (windows) desktop (i'm usually on a debian laptop) which means the issue is either windows, my home network, or htb academy

burnt spruce
#

so im trying with Enumerate the custom script that is running on the system and submit its output as the answer.. i used all scripts that was in module, but WHAT THE CUSTOM SCRIPT I NEED TO FINDD??????

#

is it smth from here?

cloud urchin
#

hard to say unless you include the module and section you're on

burnt spruce
cerulean hinge
#

Hello, i'm stuck at Sqlmap bypassing WAF (Case #10).
I think that I found the specific keywords that is behind detected and blocked, but I don't know how to change the sqlmap behavior here...

loud dagger
cerulean hinge
weak oasis
#

simple questioni

low tide
#

hey

weak oasis
#

I am given a target IP address in my module and I just have to save the file i belive I have to use curl -s -o

#

I get no URL specified

#

What do I need to do to adjust?

safe star
#

what module

weak oasis
#

Web Requests

fathom pendant
viral snow
#

Anyone available to help me out? I don't understand why I'm getting time out errors.

I deleted my proxychains, then reinstalled it, hoping that would fix the issue, but that didn't work.

I'm using socks5 127.0.0.1 9050 in my /etc/oroxychains4.conf

Im trying to use proxychains to ssh into a user, but I keep getting time out messages.

I'm all out of ideas.

fathom pendant
#

It's a script that was run on the target that you're looking into

burnt spruce
#

0-0

fathom pendant
burnt spruce
burnt spruce
#

0-0

fathom pendant
#

¯_(ツ)_/¯

burnt spruce
#

can u say first ;etter?

fathom pendant
#

It's been a minute since I've done this, so no

#

Just pay attention to the output

burnt spruce
#

but its huge

cerulean hinge
#

bruh i'm fucking dumb I was targetting the table of the previous question... I want to kill my self right now 🙂

burnt spruce
#

omggg, and its says nothing about this flag, even previously i tried it, it was wrong, maybe spacebar in the end(((((( stupid question

fathom pendant
worn sundial
#

Can someone explain something about arp spoofing please

viral snow
#

I'm in the new Active Directory Pentester Job Role Path, and I'm the Windows Lateral Movement - Secure Shell module,

It made no mention of having a port forward/proxy set up.

cloud urchin
worn sundial
#

So at the end of the mac adress section in introduction to networking it shows an arp cache posion i believe, i dont understand why the same reply is sent twice

#

Context \/

lusty thicket
worn sundial
#

Well i assume its correct but i dont understand how this shows a successful arp spoof

quiet notch
#

in the modules it suggests that it will take a certain number of days to complete. do you know how they are basing that? I know it is completely dependent on ones prior knowledge and how well one pics up the concepts but on average is it based on 8hrs a day or ??? just trying to get a rough estimate on how long to shoot for.

cloud urchin
quiet notch
cloud urchin
#

whats most important is that you absorb the material and understand what everything is

quasi wave
#

in my experience at least

cunning frigate
#

did you solve it?

#

found it was adding --no-http-server for future referance
FAILED: [('SSL routines', '', 'no protocols available')]

onyx rapids
#

Why is this a module? When was the last time anyone has seen a WEP protected network?

safe star
#

Tomorrow

loud dagger
#

LMAOOO GOOGLE DRIVE AND WINDOWS DEFENDER BOTH THINK MY NOTES ON SHELLS AND PAYLOADS ARE MALWARE AND WINDOWS DEFENDER KEEPS DELETING THE FILE

acoustic owl
loud dagger
#

yeah i know it's just hilarious

#

it literally won't let me move the file to my documents folder without deleting it

acoustic owl
cunning plume
#

Hi, I'm almost finished the moduelo Network Enumeration With Nmap.
It was hard but I would like to improve with this tools, any tip to practice?

sick pilot
#

need help in windows priv esc citrix breakout

#

not able to access SMB share from restricted environment

#

i'm using my own kali linux
do i need to use pwnbox?

wooden silo
#

I'm attacking the nibbles box rn and I keep getting an error in metasploit that says "exploit completed but no session was created"

cloud urchin
#

also could be the wrong exploit

deft lily
#

hey can anyone help me out? when i run this command on my personal VM (have the VPN connected) it doesnt take the command an just keeps spacing until i cntrl C. Same command on pwnbox in htb academy actually goes through... im kinda confused at this point on what to do

cloud urchin
deft lily
cloud urchin
# deft lily yeah

terminate it. it shares the same IP as your VPN and messes up the connection.

deft lily
#

done and same thing

cloud urchin
#

sudo killall -9 openvpn

#

restart the target, reconnect to the vpn, wait 3-5 mins and try again

deft lily
#

will do thnx

novel finch
#

Hello everyone, it's the local village idiot, hard stuck again and I've came back to this one like 20 times

novel finch
#

I'm stuck on Firewall and IDS/IPS Evasion - Hard Lab

#

This is as far as I've gotten in terms of my scan command

#

sudo nmap 10.129.253.124 -p- -sS -sV -sC -O -Pn -n --disable-arp-ping -S 10.129.253.200 -e eth0

#

And it has the audacity to just throw up an error

#

sudo nmap 10.129.253.124 -p- -sS -sV -sC -O -Pn -n --disable-arp-ping

This is the last scan that produced results

#

But for the life of me I can't figure out what services it's asking for

#

I even tried the ncat scan but it was strange and didn't help

#
22/tcp open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   2048 71:c1:89:90:7f:fd:4f:60:e0:54:f3:85:e6:35:6c:2b (RSA)
|   256 e1:8e:53:18:42:af:2a:de:c0:12:1e:2e:54:06:4f:70 (ECDSA)
|_  256 1a:cc:ac:d4:94:5c:d6:1d:71:e7:39:de:14:27:3c:3c (ED25519)
80/tcp open  http    Apache httpd 2.4.29 ((Ubuntu))
|_http-title: Apache2 Ubuntu Default Page: It works
|_http-server-header: Apache/2.4.29 (Ubuntu)
Device type: general purpose
Running: Linux 5.X
OS CPE: cpe:/o:linux:linux_kernel:5.0
OS details: Linux 5.0
Network Distance: 2 hops
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
deft lily
autumn pilot
#

provide the name of the module and the section you are working on

deft lily
autumn pilot
#

you

deft lily
#

Linux Fundamentals - worling with files and directories

autumn pilot
#

How many tun interfaces do you see in the output of ifconfig or ip a

deft lily
#

1

autumn pilot
#

How many ports are open to you via an nmap scan

deft lily
autumn pilot
#

You can do a simple sudo nmap -sV <IP>

quick crane
#

do you solved this,I also have this question

deft lily
#

i had a personal vpn on parent OS LMFAO

autumn pilot
#

Additionally, you can try to ping the target machine to verify that you can reach it

deft lily
#

its working now

#

ty

quick crane
#

which module

#

do you solved this

quick crane
#

@autumn pilotcan you help me to solved this

autumn pilot
#

Check if the update has been successfully downloaded on the target system, if not follow the steps outlined in the section related to such behavior

quick crane
midnight galleon
#

Windows Privilege Escalation - Miscellaneous Techniques - Always Install Elevated
I am trying to replicate this section in a vm and i enabled both the registry entries. but when i try to execute msfvenom's payload i still get the policies denied error

autumn pilot
quick crane
midnight galleon
#

HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
AlwaysInstallElevated REG_DWORD 0x1
DisableMSI REG_DWORD 0x0

quick crane
rigid condor
quick crane
#

can I dm you

rigid condor
#

Sure

surreal chasm
#

Hey, I'm on transferring files with code
and i encountered this problem
tried to download a file with the provided command and it errors me
anyone knows why?

htb-student@nix04:~$ perl -e 'use LWP::Simple; getstore("https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh", "LinEnum.sh");'
Can't locate LWP/Simple.pm in @INC (you may need to install the LWP::Simple module) (@INC contains: /etc/perl /usr/local/lib/x86_64-linux-gnu/perl/5.30.0 /usr/local/share/perl/5.30.0 /usr/lib/x86_64-linux-gnu/perl5/5.30 /usr/share/perl5 /usr/lib/x86_64-linux-gnu/perl/5.30 /usr/share/perl/5.30 /usr/local/lib/site_perl /usr/lib/x86_64-linux-gnu/perl-base) at -e line 1.
BEGIN failed--compilation aborted at -e line 1.
urban elk
#

(you may need to install the LWP::Simple module)

autumn pilot
#

note that target machines are not connected to the internet

surreal chasm
hasty mauve
#

at the end of the Pivoting module in CPTS it mentions a track about pivoting but I cannot find it

#

any idea where it is? I could really use some pivoting practice

tranquil axle
#

I dont think there are many free moduels offering pivoting

#

the prolabs/endgames usually do, but those cost money

hasty mauve
#

I'm a HTB Labs Subscriber already I just can't find it

#

I clicked on it and it took me to the tracks page

#

I searched there but couldn't find it

tranquil axle
#

hm yea It feels like they cleaned up the tracks at some point?

hasty mauve
tranquil axle
#

if I google it I find write ups of machine that apparently were part of this track like here https://0xdf.gitlab.io/2021/04/27/htb-toolbox.html

#

"Toolbox is a machine that released directly into retired as a part of the Containers and Pivoting Track on HackTheBox."

hasty mauve
tranquil axle
#

kind of weird, I don't see any mention of them removing tracks officialls, yet a lot of them are gone

regal hare
#

Analyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25. Conduct a similar investigation as outlined in this section and provide the name of the executable responsible for the modification of the auditing settings as your answer. Answer format: T_W_____.exe

#

Iam not finding any TW_.exe file

#

Please advice

hasty mauve
spare fossil
#

Intro to C2 operations with sliver / initial acces/ ............. why do we need two listeners, and it's on different ports, why? and it works , why ? I am a bit confused this part

safe star
#

the first listener is holding the stager that will then execute the shellcode in memory to connect to the second listener

final elbow
#

hi, i have recently been having issues with metasploit on my own VM and the Pwnbox as i see, is there any one that can let me know whats wrong, i have followed every step in the module

autumn pilot
#

check the port

final elbow
#

have done that and now a new error has appeared XD

autumn pilot
#

Note that docker containers cannot communicate back to you via the internet; in case of getting a reverse shell

final elbow
#

true, i am using the pwnbox to see if it works

#

the target is HTB target

autumn pilot
final elbow
smoky snow
#

I'm basically at the same point you were a couple month ago, did you find out what was wrong with process injection ?
The course is pretty straightforward (litterally a walkthrough, so easy to follow), but even redoing everything step by step, debugging and stuff, even copying the solution of the gold annual solution, using msfvenom+aes encrypt or micr0_shellcode, the calc.exe is triggered but not the shellcode :
https://academy.hackthebox.com/module/254/section/2930 "Introduction to Windows Evasion Techniques"

quick crane
#

do you solved this?

#

can you help me

gray yacht
gray yacht
quick crane
#

this module

gray yacht
quick crane
#

ok thanks

finite abyss
#

HTB Academy Assessment IP: 10.129.x.x
This is not accessible. Should I use Pwnbox itself?

autumn pilot
#

The VPN will re-route any traffic related to targets in the 10.129.0.0/24 subnet

fathom pendant
#

If you're having connection issues, kill the vpn, change regions, download a new one

finite abyss
fathom pendant
#

Typically

#

So still http, just not default

finite abyss
fathom pendant
finite abyss
remote citrus
#

helloo

hexed matrix
#

i need help with the question im doing rn

smoky snow
hexed matrix
#

which place should i go to to ask for assistance

storm elk
#

If its a module, this is the right place @hexed matrix

hexed matrix
#

i need help with this question

#

The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search, and use cURL to search for 'flag' and obtain the flag.
I have tried everything to find the flag but it wont even budge

#

I do not understand what went wrong

quick crane
#

can you help me

#

can you help me

#

can you help me?

fathom pendant
#

Dude stop @ people and asking, it's giving desperation

#

Like chill

tough zealot
#

i need help with the skills assessment test for the web attacks module. I'm at the last step where i need to do an xxe to get the flag content. when i try to do the LFI bit, i stop getting any output in the field name so i get an empty response like this: Event '' has been created. what am i doing wrong?

harsh wren
#

does any one finished the wifi pentesting module ? iam stuck at last step

autumn pilot
#

there are a few

#

which one to be precise and section

harsh wren
#

Connect to the WiFi network and submit the flag found at IP 192.168.1.1 or 192.168.2.1.

#

i have get the essid and the password but it gives me error when connecting

acoustic owl
#

I don't know which module you mean exactly, but what does the error message say?

harsh wren
#

Wi-Fi Penetration Testing Basics

#

the skill assessment

acoustic owl
#

Okay and what does the error message say?

harsh wren
#
Successfully initialized wpa_supplicant
rfkill: Cannot open RFKILL control device
rfkill: Cannot get wiphy information
nl80211: Could not set interface 'p2p-dev-wlan0' UP
nl80211: deinit ifname=p2p-dev-wlan0 disabled_11b_rates=0
p2p-dev-wlan0: Failed to initialize driver interface
p2p-dev-wlan0: CTRL-EVENT-DSCP-POLICY clear_all
P2P: Failed to enable P2P Device interface```
acoustic owl
#

Try it as root, not with sudo

harsh wren
#

no thing also

acoustic owl
#
$ sudo su
# wpa_supplicant -c wpa.conf -i wlan0

Do you get the same error message?

harsh wren
#

yes

#

i don't know what is the problem i have tried all solutions and the machine is without interned so i can't install the required dependicies

buoyant pulsar
#

Is there any admin that can help me getting price quotas for Cloud environment BlackSky for businesses?

autumn pilot
#

You'll need to get in touch with a sales representative through the website

hexed matrix
noble falcon
#

Hey everyone

#

How are you all doing?

buoyant pulsar
autumn pilot
#

There is, but they are more general stuff related than sales

compact patrolBOT
buoyant pulsar
#

Thanks will try that!

limpid hemlock
#

Anyone solved skill assesment forwifi pentesting basisvs

#

Im trying to solve 2nd question password for wifi network with bssid d8 d6 3d eb 29 g5

harsh wren
acoustic owl
acoustic owl
harsh wren
drowsy forge
#

Hello, I'm new to this field. I'm in the process of solving the alert machine. I'm having a few problems. Could someone help me?

urban elk
fervent iris
#

windows fundamentals module -> introduction to windows.
the lab it spawns doesn't even ping, and it looks like any lab spawned in this exact module doesn't ping.
i tested other modules, the labs' pings normally, what may be the issue here?

shut vapor
fervent iris
shut vapor
#

or at least modify the firewall to allow ICMP

fervent iris
shut vapor
rustic sage
#

accepted the fact that ill probably never complete the wifi pentesting basics skills assessment 🔥

limpid hemlock
#

Im trying to somve the last question

limpid hemlock
rustic sage
golden scroll
#

I have completed the cpts and cbbh and done zephry, dante prolab. I used the prolabs to further learn the art of report writting. Also I have completed 61 machines from the tj nulls for OSCP and i find myself been able to complete easy-hard machines with little to no write-ups. I don't plan on taking the cpts or cbbh certs.

Questions

  1. Do i need to go over the oscp course materials and pwk to pass
  2. what could be the recommended next step
tranquil axle
#

whats your plan? Pass oscp or just get more knowledge?

#

For oscp you are probably well prepared, if you want to gain more knowledge the next steps could be looking into the advanced cpts path, towards malware dev (evading av and edr solutions) like maldevacademy or towards red teaming with certs like crto

granite canopy
#

Anyone available for a quick hint for the SA for Advanced SQL injection? I'm stuck on Q2 and I don't know if I'm even trying to exploit the correct vulnerability.

rich galleon
#

did you ever find a solution?

fathom pendant
severe orchid
#

The issue might be your grep filter grep -v '127.0.0.1' may be two specific try a broader search with grep -v '127.0.0' instead

fair mural
#

I just finished Attacking Common Services Hard lab. I still feel like there is a lot I need to know about MSSQL and the modules didn't touch on everything I needed to complete the lab. Anyone have some resources?

safe star
#

what didnt they go over?

lusty thicket
fair mural
#

I mispoke out of exhaustion. They did go over everything in the module for the lab, what I am meaning to say is that I want a deeper understanding of why certain things work. For example when identifying users that we can impersonate it gives us the following command to use: 1> SELECT distinct b.name 2> FROM sys.server_permissions a 3> INNER JOIN sys.server_principals b 4> ON a.grantor_principal_id = b.principal_id 5> WHERE a.permission_name = 'IMPERSONATE' 6> GO
What is "distinct b.name" and how would I have known to use that without them telling me to, etc.?

frozen blade
#

Just a general ask. Is brute forcing the footprinting dns exercise on a laptop from 2009 on public wifi supposed to take like an hour lmao

I'm assuuming yes, but just want to make sure.

safe star
#

they wont break down every command shown

fathom pendant
#

Also why are you doing this on public wifi

frozen blade
fathom pendant
#

That's about the dumbest thing you can do

frozen blade
fathom pendant
#

Assume any network you don't have control of is hostile

fathom pendant
#

If you're not specifying an interface to bind to

frozen blade
fathom pendant
#

Learn how to bind your tools to an interface :)

frozen blade
#

Idk what that means I just use systemctl and netstat to show me what I have running on my machine. Thanks for the answers marcielee and TLattice, btw. Gotta go back to work.

fathom pendant
#

Instead of (usually) default of all interfaces [0.0.0.0]

loud dagger
#

ok this is absolutely not supposed to happen why is this happening

#

this is auxiliary/scanner/smb/smb_login metasploit module

#

null authentication is disabled btw

loud dagger
#

thank you

safe star
#

try nxc

fathom pendant
loud dagger
#

it's just smbclient -N right

fathom pendant
#

smbclient -U '' -N //ip/sharename

loud dagger
#

oh

#

oh dear

#

ok nope still doesn't work

fathom pendant
#

¯_(ツ)_/¯

frozen blade
fathom pendant
#

What I'm referring to, more specifically, is telling a program to only listen on that interface and no other ones

frosty tartan
#

I just want to add for those struggling with Knowledge Check using metasploit, using the second exploit will work much easier to get a foothold. just add RHOSTS, make sure TARGETURI is "/", and change LHOST to VPN ip. Also I suggest checking for the first metasploit exploit, make sure you got your TARGETURI correctly set. It should lead to the upload page. I did not go through with that one but I watched some help videos and thats seems to be where my problem was. I imagine its very easy to make that mistake.

gray yacht
loud dagger
#

the only thing i have not tried is brute forcing ssh which i really wanted to not have to do but i literally have no idea what else to do

#

i'm gonna save that for later so i can have it running while i'm away from my computer

gray yacht
loud dagger
#

ok so interestingly it appears the username sam does not work with any other password but every other username works with every other password

#

which implies... something

lusty thicket
#

interesting

haughty pumice
#

Can anyone give me a hint on Active Directory Enumeration and Attacks Skills Assessment part 2, question 8? I have a system shell on SQL01, and I've dumped SAM, tried to PTH with both the admin an mssqlsvc account hashes. I also found the cleartext password for the mssqlsvc account, but can't use it anywhere...

gray yacht
fierce dock
#

anyone here know python ?

#

and ethical hacking

#

im lost with this python script i made and dont know where to ask

haughty pumice
haughty pumice
gray yacht
unique ether
#

Submit the contents of C:\Flag.txt located on the Domain Controller. can someone help me with this question in Pivot and tunneling assessment

#

im in using rdp ip 172.16.6.25

#

pls help

fathom pendant
lusty thicket
fathom pendant
unique ether
#

can i dm u

fathom pendant
#

You need to link your account following #welcome

#

And no

fathom pendant
#

Check network shares in file explorer

unique ether
#

i saw the file system there is not networkshares

#

no *

fathom pendant
#

Click on "this pc" and wait a moment

unique ether
#

aight

fathom pendant
#

you don't have to hop anywhere else from what I recall ¯_(ツ)_/¯

#

Iirc that's the vf* user you get to last

unique ether
#

Ya

#

But shit ain't loading

#

Maybe I restart rdp

#

Also theres another IP active 172.16.6.45

#

I can ping to it but not rdp

gray yacht
#

You don't need to RDP

unique ether
#

I'm guessing that's the IP of the domain controller that gives the share

unique ether
gray yacht
lusty thicket
#

great idea

fathom pendant
gray yacht
fathom pendant
unique ether
#

how to know the ip that share belongs to and like other details

#

or iis that in ad enumeration module

fathom pendant
loud dagger
#

besides maybe AEN, is AD enum and attacks the hardest and/or most time consuming cpts module?

fathom pendant
#

Password in single quotes

cloud urchin
#

it shows you a valid error message

#

so i wouldn't think it's the box

urban raptor
#

did you ever figure this out? i am facing the same error

gray yacht
low girder
#

I see. So, I close the ticket?

#

Not the infra

loud dagger
#

okay i'm completely lost on password attacks/credential hunting in linux
the hint gives an SSH user/pass pair which idk how we were supposed to know? because i've tried brute forcing all three services that are open on the remote host with the provided username and password lists and none of them work. am i doing something wrong or is it a technical issue? i've had a few times in academy where i got the right solution but for some reason it just wasn't working on my computer, including earlier in this module.

lusty thicket
loud dagger
#

i have tried many many target resets

lusty thicket
shut quest
loud dagger
#

the mutated passwords list? you mean all 187k of them? that's gonna take like 10 hours

#

and that's assuming the provided username works too

#

i tried using the provided username and a list of mutations of the provided password and that didn't work

shut quest
unique ether
loud dagger
unique ether
loud dagger
#

yeah

shut quest
# loud dagger

You likely missed a step, it should be 93k or somewhere around there, I don't remember the exact number

loud dagger
#

ok what the hell

#

either way that's going to take longer than the lab is able to stay open

unique ether
#

Nd see

shut quest
loud dagger
shy hill
#

Question with Web Requests/GET. I have read the page, I have more search results in curl. I do not see any flag. It feels like I am missing one small thing.... looking in the wrong place... missing one flag...

#

Any hints, suggestions?

loud dagger
#

i really need to start making a list of things i've tried that have failed when i'm really struggling with a lab because approximately 95% of the time the correct answer has been a variation or combination of things that i've tried and that have failed

shy hill
#

yea, it is just maddining.... like you can not find your glasses... spend 4 hours looking for them..... they where on your head the entire time...... Or something like, it is -U and not -u....

loud dagger
#

yep

shy hill
#

I am not sure if the wording is messing up my tired brain...

#

The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search, and use cURL to search for 'flag' and obtain the flag.

loud dagger
loud dagger
#

i can't count how many times i've been up late trying to figure something out only for me to log on the next morning and figure it out immediately and think "how the fuck did i not figure this out last night"

shy hill
#

Yea, I am going to have to tap out then, tis that time where I go lay in bed, waiting for the insomnia to let off...

loud dagger
#

if this doesn’t work i’m off for the night

rich lark
#

What's the deal lol. I had to disable Windows Defender Firewall and disable Microsoft Defender Firewall to connect remotely? Are these the same thing with different names? It's just a little confusing I had to disable the same thing twice it felt like

fathom pendant
#

sam is an account that exists, thus requires a valid password

unique ether
#

fiona is nice

#

hopefully im thinking of the right lab

loud dagger
#

holy shit i literally used the same credentials for SSH earlier in this module and i wrote "PASSWORD REUSE" on my notes and i still missed it lmao

#

well either way i got a foothold

urban elk
rocky estuary
#

doing AEN blindly is really brutal too many rabbit holes at least i think they are

burnt spruce
#

hi, trying to solve Footprinting Lab Easy
Enumerate the server carefully and find the flag.txt file. Submit the contents of this file as the answer.

I connected via ftp 2121 port, find the .ssh directory, but when im trying to cd .ssh, i just get permission denied, had someone else same problem?

midnight galleon
remote citrus
#

anyone know how to hack into friends snapchat account for fun?

#

ofc this is just for entertainment purposes

waxen totem
remote citrus
remote citrus
#

im not gonna do anything just text myself

waxen totem
#

tell that when snapchat files charges

storm elk
burnt spruce
acoustic owl
west canopy
# burnt spruce

I'm not able to reproduce. Maybe it's something with your ftp client?

west canopy
#

it's actually the ||User-Agent header|| that determines whether or not it shows the flag 😉

unique agate
#

Have an improvement idea for requiring creds to auth inside modules.
At the end of a section where the target is spawned, you can click on the target IP and it copies to clipboard.
When it also specifies credentials, might it be useful to make the username and password fields clickable as well?
E.g.: Authenticate to "IP:PORT" with user "user@site.com" and password "password123"

hexed matrix
#

what is wrong here

hexed matrix
#

someone actually help

harsh gorge
#

Did you confuse the curl command by using -h instead of -H

storm elk
#

Also - check your json and your quotes encoding

harsh gorge
karmic plover
harsh gorge
#

Uhh yes it is. curl -H "<header>" URL

#

@karmic plover

karmic plover
#

Oh

harsh gorge
#

You have to use -H instead of -h

karmic plover
#

Oh yeah my bad, -h is more like for —help

waxen totem
#

Istg half my problems is always using -h when I mean -H

hexed matrix
hexed matrix
#

however tho its saying the cookie is invalid

#

while i literally just copied the cookie from here

karmic plover
#

I think you should set the header cookie instead of using -b

hexed matrix
#

okay let me try

quick abyss
#

Can anyone give some advice on the footprinting Medium Lab. I scanned TCP/UDP ports and have tried to enumerate different services. I found a fileshare related to support but can't seem to mount it I get a permissions error. I don't see another route to take, am I missing something?

karmic plover
hexed matrix
#

cause i dont know where to place the cookie in the header

karmic plover
hexed matrix
#

ok i found it

#

I tried what you told me

#

it did work, but i still figured out how to make the -b work

#

now it returned this

#

do i need to do Content-Type too

harsh gorge
#

Yup

karmic plover
#

🙂

harsh gorge
#

Delete that

#

@hexed matrix

#

I don’t want you to get in trouble

hexed matrix
#

mb

#

so basically yes i found the flag

#

thanks for the help

harsh gorge
karmic plover
#

Oh btw what module are you on?

hexed matrix
#

Web Requests

karmic plover
#

Oh that one

hexed matrix
#

the one about GET reqs

hexed matrix
#

well now im onto api

karmic plover
hexed matrix
#

oh shoot

#

i meant post

karmic plover
#

Hehe

hexed matrix
#

which one are you on

waxen totem
#

web requests are fun, I can never understand them, but they're fun

hexed matrix
#

so that means even if i do not understand this chapter i could still do the others without being affected right

karmic plover
#

Funny how I learnt to use those stuff before I actually learn the module

#

I learnt sql injection before I knew how to use burp suite

#

Something like that

#

Kinda weird

karmic plover
lusty thicket
hexed matrix
#

i do understand how it works

#

but i could not memorize the things to type in

#

do i need to llike memorize the commands and stuff

gray yacht
quick abyss
covert meteor
#

Some please help me with the exercise I copy pasted above

#

Cause I suck at hacking

#

And can’t figure it out

acoustic owl
#

What exactly is not working?

quick abyss
gray yacht
shy hill
karmic plover
#

Because we always have —help or man in every tools

#

And every tool follows a basic usage pattern

quick abyss
karmic plover
gray yacht
upper ruin
#

Attacking Common Applications
Exploiting web vulnerabilities in thick client applications

So...I modified the Invoker and the ClientGUI thingy, compiled it and made the traverse jar, instead of doing it 1 by 1 and taking time.

For some reason, the .jar displays the content of the file instead of downloading it. I have used the 1:1 script provided in the module, anyone got an idea what could be the issue?
I am stuck for about 3+ weeks on that.

upper ruin
tardy sand
#

have you found the solution?

rustic sage
#

can anyone give me some tips on command injections module? i cant find the injection point, and there are over 1000 lines in the http response. ive tried a few things but im not getting any useful outputs so far.

hexed matrix
rustic sage
scarlet bronze
#

hello good day, i am new to cyber security will need help and guideline

lusty thicket
#

lab*

#

what lab is that

rustic sage
#

command injections

lusty thicket
wary turret
#

hmm

#

@sterile hawk sorry to ping and disturbing u but i dont have permission to write their

#

any help

scarlet bronze
#

hello

wary turret
#

ig i need to ping to the staff then

rustic sage
boreal crest
#

Hello !
I just finished to read this HTB module :
https://academy.hackthebox.com/module/58/section/530

I'm surprised that the protection against SQL injections that involves "preparted statements" is not mentioned, i guess this is because it simply impossible to escape prepared statements parameters, but i am surprised that HTB does not mentions this dead-end

#

so i prefer to ask in order to be sure (as HTB doesnt seem to validate this) : are SQL Prepared statements completely immune to SQLi ?

rustic sage
#

and he left Nvm he just dont have any role...

tranquil axle
#

"completely immune" is a pretty strong term, but assume you are not gonna get around a prepared statement

boreal crest
#

"completely immune" is a pretty strong term
Why that ? is there any known vulnerability

tranquil axle
#

ultimately the DB has to implement the sanitation used during the prepared statement and there could be bugs in the implementation

boreal crest
rustic sage
boreal crest
#

Yay i am initialised

#

Thank you!

rustic sage
#

First step!

tranquil axle
rustic sage
#

YAY

boreal crest
#

okay okay

rustic sage
#

The Active directory introduction module is very good but it is very comprehensive as well as good to think outside the box.

granite canopy
loud dagger
#

i'm trying to run a python enumeration script on a remote host but it won't let me install requirements.txt. is there any other way for me to do this

granite canopy
loud dagger
#

on the remote host

boreal crest
#

install it then

loud dagger
boreal crest
#

why

loud dagger
#

take a guess

#

i'm on a lab and i don't have sudo perms

naive sage
#

But lab doesn't have internet?

loud dagger
#

do you think i would be asking how to run an enumeration script if i had sudo perms

#

yeah that too

loud dagger
naive sage
gray yacht
# loud dagger lazagne.py

You can use wget to pull it over along with everything to run it. I'm fairly certain I know which module/section you are working on. You can do a few things for that one.

naive sage
#

If it is, then use pre statically complied bin.

pseudo kiln
#

well yes and no, like you can transfer the whole Linux directory that you pull from lazagne github and it will work, but the tool does not come with all the dependencies included like some python modules

#

so it will work, but won't be able to pull chrome passwords (if they exist)

#

one that thing that may work, but I have not tested is to set up a ligolo tunnel with your attack box as the agent, and the target as the proxy and that way you can download pip and then the modules

#

htb probably does not mention that as it would be very bad opsec, nobody would do that in normal operations, there are likely tools that can pool google chrome files and then extract the credentials

lusty thicket
loud dagger
#

wtf was htb academy thinking coming up with these amounts of time to complete the module bruh

#

they say password attacks is supposed to take 8 hours? hashcat is telling me it's going to take about 6 hours just to crack this shadow file

#

at least i can crack it offline this time

hasty mauve
loud dagger
#

i am not looking forward to the final labs for this module

#

i'm really hoping it's mostly offline cracking so i can work ahead while i wait

#

there's no way i'm getting this course done by january ;~;

urban elk
loud dagger
pine dune
#

Hi guys, why is my seclists an executable program (is it supposed to be?) and can I make it a directory?

faint yacht
#

You're in /usr/bin which is where programs are located

#

The actual text files are in /usr/share as the tool output says

pine dune
#

ok

neon furnace
#

Just clone it from github

pine dune
#

anyone know whats wrong with my command? ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://94.237.58.94:43479:FUZZ

dark hedge
#

/

#

instead of :

#

on the URL

neon furnace
#

Also why double FUZZ

pine dune
neon furnace
#

I dont think you need the first one

pine dune
#

ohh ok

neon furnace
#

Maybe, never did it like this

dark hedge
#

it works

neon furnace
viscid furnace
boreal crest
#

Hello, i am on the Skill assessment of SQL injections, i am struggling to configure sqlmap to exploit the injection of the /action POST request.
I'm not 100% sure to understand what sqlmap needs in order to check if a parameter is injectable, does it requires the response of the SQL query be part of the HTTP response ? like for example, when you exfiliate data from the database, does it gets the data from the HTTP response or does it uses other ways

loud dagger
#

so a little over 33%

viscid furnace
loud dagger
#

great

pine dune
#

ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://94.237.58.94:43479/FUZZ.php

#

is the above command ok?

loud dagger
#

although that kinda means 33% is a lot further than i thought it was

viscid furnace
pine dune
#

ffuf -w /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://SERVER_IP:PORT/blog/FUZZ.php

viscid furnace
viscid furnace
fathom pendant
#

Ye

viscid furnace
loud dagger
pine dune
fathom pendant
viscid furnace
fathom pendant
#

¯_(ツ)_/¯

viscid furnace
urban elk
fathom pendant
#

If you blitz through just to finish, you're gonna have trouble on the exam

pine dune
loud dagger
#

i mean i usually learn really fast, the only reason i need to get this done before january is because i literally will not be able to take this exam until the same time next year

pine dune
loud dagger
#

winter break is the only time of year that i can put aside 10 full days to do anything

urban elk
fathom pendant
#

don't put arbitrary pressure on yourself to learn ¯_(ツ)_/¯

#

Who cares if you get it this year or next year tbh

loud dagger
#

i fucking care

pine dune
fathom pendant
#

Unless it's a hard deadline requirement, you're adding more pressure on yourself than you really need

loud dagger
#

it's a pretty fucking hard deadline requirement

viscid furnace
pine dune
loud dagger
#

i will literally have to wait an entire year to take the exam

fathom pendant
#

¯_(ツ)_/¯

loud dagger
#

did you not read what the fuck i just said twice?

fathom pendant
#

Will it really hurt to wait until next year to be sure you're ready?

loud dagger
#

and i would really really like to get an internship this summer

#

i'm going to kill myself if i have to work retail for the 8th year in a row

urban elk
# pine dune

/opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt doesn't seem to contain what you think it contains

fathom pendant
#

I'm gonna be brutally honest Jane, it sounds like you're close to burnout. I hit burnout when I took my exam causing me to fail it.

fathom pendant
loud dagger
#

i'm actually having a ton of fun with the course, i just really don't like you trying to tell me how i should feel

urban elk
analog dock
fathom pendant
#

I'm saying how it sounds, based on how you're describing your situation. That's all

pine dune
fathom pendant
#

You're lashing out really fucking hard, when I'm literally just offering honest feedback. You asked for feedback about being able to finish before January

compact matrix
#

trying to access the website from SSRF first exercise and the website is not loading

fathom pendant
#

It's possible. Just be careful to avoid burnout

urban elk
#

@pine dune finally, not finding results doesn't mean the tool is not working, necessarily. You need to be looking for the right thing. But one step at a time

loud dagger
#

yeah i asked for feedback about being able to finish before january, not about how to feel if i don't finish it before january

#

i generally appreciate constructive criticism but i really really really do not like people, especially people who know nothing about me, trying to tell me how i should feel about something

viscid furnace
fathom pendant
#

And i am advising on the dangers of trying to blitz your way through.

pine dune
#

Tip: Taking a look at this wordlist we will notice that it contains copyright comments at the beginning, which can be considered as part of the wordlist and clutter the results. We can use the following in ffuf to get rid of these lines with the -ic flag.

fathom pendant
#

Sorry that I didn't give you just a yes/no answer

pine dune
#

I really dont like this 5 second timer... 😅

fathom pendant
#

Because the cop out is "it depends"

compact matrix
#

its not that deep jane take an aspirin

fathom pendant
compact matrix
#

lol I was on your side

loud dagger
loud dagger
compact matrix
#

Thank you

analog dock
#

You 2 should move to dm

fathom pendant
#

I'm not taking anything Jane is saying personally, I understand how you're feeling about being rushed to finish the course and take the exam. I was in the same boat

pine dune
fathom pendant
#

Yes, it's possible, and all I'm saying is as long as you're also learning you can go as fast as you're comfortable with

pine dune
#

wtf is this whys it going ham

compact matrix
fathom pendant
pine dune