#modules

1 messages · Page 362 of 1

mint verge
#

thanks

opal flume
#

hello who know you to reverse engineer an private api ? (i use mitm) i need help thx

rough comet
#

Hi

#

Can someone please help me here... I am trying to do the last exercise on AD Enumeration, which is Privilege Access. This one is the MSSQL question, getting the flag from DB01.

#

I keep getting an error when running this: ||Get-SQLQuery -Verbose -Instance "172.16.5.150,1433" -Username "contoso\joe" -Password "Password123!" -Query "EXEC xp_cmdshell 'powershell -c Get-Content c:\flag.txt'"||

#

I edited a bit to avoid spoilers. But I do not understand why it fails.

#

I get a connection a connection success, connection failed

#

I am very very close.... to upload ligolo and use commands from Kali, but I am trying to not deviate from exercise's main goal. I just do not understand why this keeps failing. By the way, RDP is painfully slow; I've tried remmina, rdesktop, xfreerdp, regenerate the VPN, you name it.

autumn pilot
#

you can use the parrot instance that spawns alongside the windows targets

#

Connect to it using the internal IP (subnet) address

rough comet
#

Thanks for reply. That's what I am trying to avoid. Regardless, I use it and that command still failed.

#

Ohhhhhh

#

I know what it is.

#

Formatting issues, when copy pasting those single and double quotes

thorn urchin
#

its always quotes

rough comet
#

well, at least I am making some progress

#

almost there, lol

thorn urchin
#

its a chunky module but my favorite so far

#

kerberos attacks being a close second

buoyant escarp
#

love this module

cyan lark
#

Hey! I got stuck on the last section of the Getting Started module in the CPTS roadmap.

I got a reverse shell, but I am attempting to write a bash script in order to root the machine.

I have ALL : ALL (NOPASSWD) perms to /usr/bin/php

/usr/bin/php is a soft symlink that points to /etc/alternatives/php

/etc/alternatives/php is another symlink that points to /usr/bin/php7.4 which I do not have write access to.

I have tried to make the symlink point to my own script file using ln -sf, but I have no permissions to do that, and running that command with sudo requests password input.

buoyant escarp
cyan lark
safe star
buoyant escarp
#

yes /usr/bin/php is a binary/programm/command

cyan lark
#

Thanks guys ❤️

buoyant escarp
#

cli basicly

#

may be worth a try

cyan lark
#

Any clue why it's not grabbing the CMD var?

young ore
#

You supposed to start looking for a date from a specific timeframe mentioned in the example

thorn urchin
#

sometimes GTFObins recommends some unnecessary extra steps, gotta use your brain sometimes to prune em for the situation

cyan lark
cyan lark
#

Can I use php to just run a .php file?

thorn urchin
#

yeah you have some syntax errors

#

its still has to be correct php

buoyant escarp
#

u removed the ;

cyan lark
#

Dang you guys are sharp.

buoyant escarp
#

it literaly tells syntax error 😄

cyan lark
#

You're right 😂

thorn urchin
#

reading is OP, trust

cyan lark
#

Now it froze my shell

thorn urchin
#

its the meta strat

cyan lark
#

Yeah you're right guys I'm just after a few hours on this module so becoming a bit less effective

safe star
thorn urchin
#

taking a quick walk is always helpful too

cyan lark
#

It's because my target expired

cyan lark
#

This is the second time the target expired lol

buoyant escarp
#

staring at my screen for a while now my eyes are squares now ;D

sacred gull
#

using windapsearch.py I get this error, just want to confirm its with the server and not me:
[!] {'result': -1, 'desc': "Can't contact LDAP server", 'errno': 107, 'ctrls': [], 'info': 'Transport endpoint is not connected'}

cyan lark
#

Thanks guys ❤️ @buoyant escarp @thorn urchin

safe star
#

Type shi

sacred gull
#

annoying, had 3 server resets but I can never connect

#

might have to leave it for a bit

thorn urchin
winter schooner
#

Hello, when I'm trying to kerberoast, i keep getting this error.
Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

I tried using faketime and still same error, does anyone have any quick fix they do generally to combat this?

buoyant escarp
thorn urchin
#

they do for me, less eye strain

#

the make non-corrective glasses that help too but you will look like a dork wearing them

sacred gull
buoyant escarp
#

would be op to use apples ar glasses for hacking lol

thorn urchin
#

no lol would probably be a huge headache

sacred gull
winter schooner
quasi wave
#

hi which previous sections of Password Attacks Module should I reread before reattempting the Pass the Ticket from Linux Section?

#

I have done several of the question in the Linux Pass the Ticket section I just think I need to make sure I understand the material

thorn urchin
#

have you tried just sitting down and seeing what you remembered? what about your section notes?

safe star
lusty thicket
thorn urchin
#

Ive known queuemark for a long time. theres a legitimate chance they havnt

#

you got anything better to do then pester me? never see you answering questions

lusty thicket
#

you're not above giving useful advice

thorn urchin
#

ill just block now. youre useless

lusty thicket
#

cool

dim ridge
cunning frigate
#

@sacred gull Have you done DACL II module?

sacred gull
#

No, just started yesterday properly so only upto the BloodHound module

cunning frigate
#

I have been stuck on DACL 2 last question for couple days now

thorn urchin
#

im planning on starting that one tonight after work

cunning frigate
thorn urchin
#

I set a reminder

solid storm
#

hi

lusty thicket
#

hi

silk adder
#

Hi

dark hedge
#

they left

silk adder
#

How to run hack the box in my computer

compact patrolBOT
viral slate
#

ABUSING HTTP MISCONFIGURATIONS : Skills Assessment - Hard

Hey guys!
Currently working on hard skills assesment, but unfortunately couldn’t find any solution at the moment.
Can I DM for a nudge please?

unique ether
#

hi

safe star
#

yo

viral slate
#

wazzup

lusty thicket
#

hi

vivid sigil
#

hi

Active Directory Enumeration & Attacks > Miscellaneous Misconfigurations

Find another user with the "Do not require Kerberos pre-authentication setting" enabled. Perform an ASREPRoasting attack against this user, crack the hash, and submit their cleartext password as your answer.

i found another user that start with letter (m) and i cracked his pass (start with W) and its not accepting my answer

thorn urchin
#

answer does not start with W

vivid sigil
# thorn urchin sounds like wrong user

there are two users and the first Q the user that start with y and in second Q it said (find another user)

Q1 Find another user with the passwd_notreqd field set. Submit the samaccountname as your answer. The samaccountname starts with the letter "y"

Q2 Find another user with the "Do not require Kerberos pre-authentication setting" enabled. Perform an ASREPRoasting attack against this user, crack the hash, and submit their cleartext password as your answer.

thorn urchin
#

Im aware I checked my own answer

#

the answer does not begin with the letter W, you found the wrong user or performed the wrong attack

vivid sigil
#

okay, i will try

thorn urchin
#

np

pearl token
#

Hello guys, I have a question. In AD Enum and Attacks. I tried recreating enumeration and attack techniques using a Linux host, in which the module suggest that I must SSH into a Linux host and do the activity there. But I want to exercise my pivoting skills and want to do it in my Kali Box through pivoting. I used dynamic port forward using SSH and Chisel, but I don't seem to be able access the DC and other hosts in the internal domain environment. Is this because of a network restriction in the module labs themselves? Like in some Bounty Hunter Modules where you can't establish a reverse shell because of restrictions or am I missing something?

autumn pilot
#

Explain what you've done so far and we might be able to pinpoint the issue

safe star
#

not with chisel tho

quasi bridge
viral slate
pearl token
pearl token
autumn pilot
#

Try adding -sT in nmap, additionally, if it still doesn't establish the connection through the socks proxy use sudo proxychains.. (if using the workstation)

safe star
#

but ssh and proxychains should work just fine

pearl token
pearl token
compact matrix
#

@pearl token hi can I dm pls

subtle cave
#

Anyone doing the crackmapexec Module currently by Chance or has already done it?

autumn pilot
#

ask your question

subtle cave
#

With pleasure! It touched the silver C2 Framework, is there any other ressource where this gets Covered maybe a little more in depth?

autumn pilot
young ore
minor sonnet
#

hello everyone , can anyone help me with
module : bloodhound
section : bloodhound for blouteams
question : Using BlueHound custom dashboard. What percentage of users have a path to Domain Admins? (Do not include %)

i found that the total of users is 31 and the number of users that have a path to domain admins is 4
but my answer is wrong , can anyone help me

wanton vault
#

AM I too slow to be on Red TeAmNotLikeThis

autumn pilot
#

The dashboard will provide you with the correct number

somber token
#

Yoo

#

I'm new

minor sonnet
somber hawk
#

how do i use a vpn connection file? ot seems like some stuff wont work unless i connect my VM to the connection file

#

or am i understanding it wrong

midnight galleon
somber hawk
minor sonnet
somber hawk
#

how long does it take to connect using ssh, does it usually take very long?

proven loom
#

no

somber hawk
#

for some reason when i do it its just a blank line that i can type in, if i vput a command in there it does absolutely nothing

proven loom
#

that's intentional

#

type in the password

midnight galleon
somber hawk
proven loom
wanton vault
#

Sorry but relauch target! and wait 5 minutes. Always wait five

#

then Attempt

#

If you want to avoid problems

somber hawk
somber hawk
#

oh wait nvm

#

it worked, thanks!

near abyss
#

i have the same problem with Xorsearch and scdebug.exe in the skills assessment

cosmic mural
#

hello i have a problem in server side attack skill assessment anyone guide me plz this is the req POST / HTTP/1.1
Host: 83.136.251.210:32887
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
Accept: /
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: application/x-www-form-urlencoded
Content-Length: 45
Origin: http://83.136.251.210:32887
Connection: keep-alive
Referer: http://83.136.251.210:32887/

api=http://truckapi.htb/?id%3D

compact matrix
#

what are you trying to do

storm elk
#

Lets take it to dm to avoid spoilers please

cosmic mural
#

okzz

storm elk
#

Oh I meant you two. I’m unavailable atm (not at my pc, gonna be at least 2 hours)

cosmic mural
#

ohh okz

storm elk
#

Happy to help if you’re still stuck then 🙂

cosmic mural
#

i am stuck i dont know what to do i did many thing dint worked

#

pwd,ls,id this cmd works but cmd with space is not working like ls -al or ls /

compact matrix
#

have you looked at the forum/

#

for this question

cosmic mural
#

i did space encoding to

#

can you provide me forum link ?

compact matrix
#
cosmic mural
#

thankyou

pearl token
quaint belfry
#

In kali Linux
cd/usr/share/worldlist
Zsh : no such file or directory

How to solve this

compact matrix
#

what is your command

stray shard
#

In mobaXterm

#

nmap ip scaning blocked ping probe

#

dunno what to do

green minnow
#

I've tried putting the whole thing in a .txt file and it didn't work. I tried removing admin, didn't work, tried just the first part didn't work and tried just the second part didn't work

#

I don't see a password here

#

Non of these outputs is the correct answer

#

crackstation also doesn't recognise the hashtype

terse quiver
#

what's the module name?

green minnow
#

Ok apparently the syntax for john is totally different with IPMI?

You need to get matasploit to output a file for john. Then run `john --fork=8 --incremental:alpha --format=rakp <name of whatever metasploit output file>

#

This gets the password without even using a wordlist which is weird.

urban elk
#

check what "incremental" means

rustic sage
#
  • 0 What is the minPwdLength set to in the INLANEFREIGHT.LOCAL domain? (One number)

This is from AD.
I have tried ldapsearch, smb null logins, rpc null logins, and enum4linux, none gave me any info on Password Policy.
Any nudges?

urban elk
#

try resetting the lab, I'm pretty sure I got the info

upper haven
#

Now I know why people have been complaining that the module is too easy kek

rustic sage
compact matrix
sly kelp
#

Anyone who has done intro to purple team module. I need little help with Zabbix CVE section

viral mica
#

The Attacking Enterprises module for cpts is like a fever dream

fathom pendant
viral mica
#

I'm having trouble with it at the moment

#

I for some reason cant reach the page for the pivoted machine on firefox

#

firefox gives me the proxy server is not accepting requests message

#

OH

#

gotta use -D with ssh

#

there we go

glacial minnow
#

Can anyone confirm if the ssh is working ? Like the section after DCSync you're supposed to rdp into windows host and from there ssh to a Linux host

viral mica
# fathom pendant It's fun blind

well to be fair from what I've seen so far I don't feel that I need a blind run, it's just that I don't see how each attack fits the web attacks part. Like I wouldn't guess "AHA! XXE attack here!" in something.inlanefreight.local for instance

fathom pendant
rough comet
#

Morning / evening guys

tender nimbus
#

Hey guys little question about burpsuite (module web proxies) i'm doing the skills assigment and the question is that a button on the page is disabled, i need to enable it to see the flag so i did a matching rule disabled to enabled in the response body but it still stays on disabled any idea?

rough comet
#

Need an advice . I've been really frustrated with the AD modules . RDP is extremely laggy . Besides using the in browser Kali , any other suggestion ?

#

Maybe play with the MTU?

compact matrix
#

right click inspect and replace disabled with enabled then you can click on it

tender nimbus
#

i got the flag ones and tried again to understand what i did but idk i can't dso it again

#

and when i click on it after it refresh and set it again on disabled

#

@compact matrix a thing that i also don't understandis that in the response it is set to enabled but when i go check in the http history its set to disabled

queen birch
#

Hello Everyone

#

Can you help me with billing issue

#

Moderators please?

storm elk
#

Nobody on Discord can help @queen birch . Please contact support on the site. Discord isn't monitored by support

compact patrolBOT
queen birch
storm elk
#

There's an email customerops@hackthebox.com - best to e-mail them 🙂

#

@timber bluff - if you wanna run commands, go to #bot-commands please

tender nimbus
#

hey huys other question about burp so the thing thati want to do is to ad a char at the end of the cookie, end after it encode the whole cookie in first base64 and then hex, i now i'm doing something wrong

storm elk
#

remove the variable and add it again

tender nimbus
storm elk
#

yes

tender nimbus
#

i don't understand what you mean it gives me the same?

#

the thing is that the paylaod position is disabled i cant change it to

storm elk
#

payload position is a burp pro feature

tender nimbus
#

ow oke so i guess i need to use zap

storm elk
#

You should select the whole cookie

#

Add variable

#

then with payload processing

gray yacht
tender nimbus
#

that is the question in case Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

#

i understand the assigment and what i need to do this is my conf

tender nimbus
tender nimbus
gray yacht
# tender nimbus is it not suffix its the last char?

So if I add the given 31 character hash to Add Prefix, Burp Intruder, will build the payload using that prefix and the Payload within the Payload Settings, so essentially it is adding the 1,2,3,4 to end of the prefix, then Base64 encoding it, Encoding as ASCII Hex, then testing it against the selected parameter from the Payload Positions. Does that make sense?

#

I don't recall the tier of this module, but if you'd like to see an example you can DM.

tender nimbus
#

tricky one thanks i understand it now im gonna try it 🙂

tender nimbus
gray yacht
#

If you already got the flag you can DM.

zenith python
#

hi

#

im new

storm elk
zenith python
#

plss teach me somthin

full marlin
#

guess i'm not the only new one here lol

true mauve
#

Hello,

I am having trouble on page 9 of Security Monitoring & SIEM Fundamentals. It's not taking the date in Elastic. Am I reading this task wrong or could this be an error in the module?

glacial minnow
ancient niche
#

someone can say me what is that? <!-- partial:index.partial.html -->

#

this is of File inclusion part one

buoyant escarp
minor sonnet
#

hello , does anyone finished bloodhound module ? i have a question in the BloodHound for BlueTeams section

wild sage
#

Can anyone help me with the syntax for uploading lazagne.exe via xfreerdp for the Credential Hunting section in Password Attacks module. I'm having difficulty getting uploaded to the target host. Tried smb server and it didn't work

gray yacht
sonic plume
#

you can copy the file to clipboard and paste it in somewhere in the desktop on the rdp session

wild sage
wild sage
dawn topaz
#

mgr_brute.py

gray yacht
wild sage
#

Figured it all out thank you @gray yacht , @minor sonnet and @sonic plume

glass quail
#

Module: Active Directory enumeration and attacks
Section: LLMNR/NBT-NS poisoning - windows
I am having trouble connecting to the windows machine I keep getting error
"[12:14:35:029] [14037:14038] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[12:14:35:029] [14037:14038] [WARN][com.freerdp.crypto] - CN = ACADEMY-EA-MS01.INLANEFREIGHT.LOCAL
[12:14:44:044] [14037:14038] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[12:14:44:047] [14037:14037] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B"

midnight galleon
glass quail
glass quail
midnight galleon
#

prolly restting would help tho

glass quail
#

ok I will reset

glass quail
hasty mauve
#

I'm trying to access Splunk in Attacking Common Applications module but it keeps telling me Connection was reset

#

why am i not able to access it?

#

Here's the question

#

I did an nmap scan on the IP and it showed me that splunk is working at port 8089

gray yacht
hasty mauve
gray yacht
hasty mauve
gray yacht
hasty mauve
acoustic thorn
#

Hey guys, having some issues with the Start-Dnscat2 cmd. Having imported the ps1 module on the target successfully, the target is still unable to recognize the start cmdlet. I'm in the same directory and my dnscat2 server is properly configured on the attack box. Any ideas?

placid edge
#

anyone here done HTTPs/TLS Attacks that i can dm?

mild glade
#

Password Attacks -> Attacking LSASS
Apply the concepts taught in this section to obtain the password to the Vendor user account on the target. Submit the clear-text password as the answer. (Format: Case sensitive)

shouldn't the command netexec smb 10.129.166.200 --local-auth -u htb-student -p HTB_@cademy_stdnt! --lsa work beside the technique discussed above ?

fathom pendant
placid edge
#

anyone done intro to deserialization skills 2 that i can dm?

acoustic owl
woeful lake
#

Hi i have a question on the last question of skills-assessments from pivoting module, the shared you known, i have to have access to it if im in the last machine right?
If it is to much spoiler just tell my and i delete the message and ask private

woeful lake
#

Ok, ty

woeful lake
#

It just was that, now i understand ty

#

What a nice module i have to say

rustic sage
#

Hi everyone, I’m new here. I have a small issue where I can’t submit an answer for the /module/54/section/511 | Skills Assessment - Web Fuzzing | Q3 (question_id = 157). The question asks: 'One of the pages you will identify should say, "You don't have access!". What is the full page URL?' I have the answer after using ffuf, but it’s not being accepted and shows the error: 'Incorrect answer

I’m not sure how much I can post in the chat or what the rules are for providing answers. I’m just seeking some help as I might be missing something.

gray yacht
compact agate
#

Hi Guys, Who got the way? I have stuck for weeks.

delicate steeple
#

Hello everyone!

Could someone help with me
Shells & Payloads

I am stuck at Infiltrating Windows >

Gain a shell on the vulnerable target, then submit the contents of the flag.txt file that can be found in C:\

i have setup the Rhost Lhost SMBshare and used the ms17_010 when running the exploit is does not complete it

wild sage
#

make sure your using the correct exploit, I too got confused when doing that section

delicate steeple
green cypress
#

Module: SOCKS5 Tunneling with Chisel

Anyone know why this is occuring, using Kali Linux and it does not work

cloud urchin
delicate steeple
#

Shells & Payloads

Laudanum, One Webshell to Rule Them All

Establish a web shell session with the target using the concepts covered in this section. Submit the full path of the directory you land in. (Format: c:\path\you\land\in)

#

i did the etc file

can acces the site and upload a file

but cant acces with \files\file name i get a error

i think its in the aspx file wrong ip maybe ? does someone know

cloud urchin
#

so you uploaded shell.aspx ? did you modify the file to match your IP?

delicate steeple
hasty mauve
uneven tusk
#

Hi, I am stuck on the Documentation & Reporting Practice Lab module. can anyone help me with some hints?

fathom pendant
fathom pendant
uneven tusk
fathom pendant
#

Well you should have learned your enumeration strategies from the previous modules

#

Assuming you're doing the cpts path

#

The other thing is you're given an incomplete report in the resources

uneven tusk
#

I got some info from Nmap and reports from Obsidian but can't find my way to start

fathom pendant
#

Start with the basics, are there open shares, ftp, anything you can use to break in

#

By this point, if you're doing the cpts path, you should have a decent methodology-- or at least notes from the previous modules -- to try

uneven tusk
#

I will try with your hints. is it possible to ping you again if still stuck? thank you very much

fathom pendant
#

No. You should be well equipped to figure it out on your own tbh

uneven tusk
#

thank you

autumn valve
#

hello everyone, i am stuck in the third question of the "Credentials in Object Properties" section from the Windows Attack and Defense Module of the SOC Analyst path, i do everything required to the event with ID 4771 to appear but it does not show up, and the answer for that question is the TargetSid of an user, which should be present in the event

fathom pendant
autumn valve
fathom pendant
autumn valve
#

in the section it is refered as DC1, this is the exact question if it helps "Connect to DC1 as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the TargetSid of the bonni user?"

#

i am almost sure i am not doing anything wrong, but for some reason, the event with id 4771 that should be generated after the failed logon attempt does not show up in the Event viewer of the DC1

fathom pendant
#

Try resetting the target or changing vpn region

autumn valve
#

ok i am gonna try to change the vpn region, as i have already reset the target multiple times

autumn valve
cloud urchin
sly kelp
#

Anyone who has completed Intro to purple Team Modules Zabbix CVE exploitation section!

İ need little help about moving forward after getting shell as Zabbix

autumn valve
# cloud urchin where are you looking? i just did this and found it right away

Then sure there is something i am doing wrong --> Here is my steps again: Connect to the target using xfreerdp, then do the RDP logon to DC1 with the "bonni" username and a wrong password, then connect to DC1 with the provided correct credentials 'htb-student:HTB_@cademy_stdnt!', then opened the Event Viewer tool and filter for events with ID 4771. what can i be doing wrong?

cloud urchin
autumn valve
cloud urchin
#

should be there, maybe rdp with the wrong pass a couple times try different passwords

autumn valve
young ore
fathom pendant
young ore
#

That would then answer the question number 2: Using the password discovered in the previous question, try to authenticate to DC1 as the bonni user. Is the password valid?

young ore
autumn valve
#

i think there is a misunderstanding, the answer for the second question is just "No", because it is a wrong password, but then i need to connect to the DC1 using the credentials they are providing me (htb-student:HTB_@cademy_stdnt!) and then use the Event viewer to retrieve some information of the Event with ID 4771 that should have generate after performing the failed login to DC1 using the bonni username

fathom pendant
#

From the rdp session are you authenticating to the internal DC1 server, the host you're connecting to initially isn't DC1

fathom pendant
young ore
urban elk
#

I just went through the ExtraSids attack again (AD enum & attacks module, attacking domain trusts child->parent from windows), and I'm still struggling to understand the feature we are abusing. Can't trust chatgpt's explanation anymore after it hallucinated a bit trying to agree with me.

We are abusing the SID history attribute by adding the sid of a privileged group in the parent domain, and through that gain access to the parent domain after compromising the child domain. But I simply don't understand the design of the feature we are abusing. If I understand the content (and a few other sources I checked to see who was right) correctly,

  1. User 'dude' has SID X in child domain;
  2. We establish a trust between child domain and parent domain, and 'dude' in parent domain gets SID Y;
  3. Since we still need 'dude' to access things in child domain, we add SID X to dude's SID history, and child domain will check SID history henceforth.

So far so good. But when we abuse this we are abusing the parent domain. We add say Enterprise Admins' SID to SID history, and the parent domain says "Oh hey Enterprise Admin, come on in." Why is the parent domain checking SID history at all, if it's meant to preserve rights in child domain? Shouldn't it just check the "current" SID?

autumn valve
autumn valve
autumn valve
fathom pendant
autumn valve
autumn valve
urban elk
#

I don't doubt that I'm overcomplicating it, but how so ?

autumn valve
urban elk
#

"If a user in one domain is migrated to another domain, a new account is created in the second domain. The original user's SID will be added to the new user's SID history attribute, ensuring that the user can still access resources in the original domain." is precisely the scenario described in the content and every other resource I've found

fathom pendant
# urban elk I just went through the ExtraSids attack again (AD enum & attacks module, attack...
0xiN's Journey

Objective: To provide a comprehensive, step-by-step guide for executing the ExtraSids attack using Mimikatz, enabling learners to understand the concepts and techniques involved in compromising a parent domain from a compromised child domain.
Section...

urban elk
#

that in itself is not confusing. What is confusing to me is why the parent domain itself checks the sid history, if it's meant to preserve access on the child domain

winged egret
#

For any person who is well rounded in xpath syntax and conditionals:
In a xpath injection scenario, why cant we use > and < to search for the correct character at a particular index :
substring(name(/*[1]),1,1) > 'a' and '1'='1'] --> only = sign works here

urban elk
#

I'll re-read this carefully, thank you for taking the time. Just one note, I should generalise because indeed I don't think it matters that the trust here is parent-child

hasty flume
#

Hi there someone knows if is there any problem with the Vaccine lab in the tier 2 challenges? When running sqlmap as per the writeup the database which is supposed to be vulnerable to stacked queries for the --os-shell flag to work, is saying this: [CRITICAL] unable to prompt for an interactive operating system shell via the back-end DBMS because stacked queries SQL injection is not supported
Is this perhaps a misconfigurations on my side? I am trying to hack it by using metasploit but I need to crack the password which is md52d58e0637ec1e94cdfba3d1c26b67d01 but I had no luck cracking it 😅 ... Can anyone guide me trough please

hasty flume
storm elk
#

Sorry - I misdirected you @hasty flume

hasty flume
urban elk
#

I'm sorry, I still don't get why it's designed like this. I must be missing something fundamental. Maybe it's easier to explain what I'm struggling with with pseudocode. So what it sounds like a domain is doing when checking rights is:

checkRightsInThisDomain(object) {
   if (ACL.allows(object.SID) or ACL.allowsAnyIn(object.SIDHistory)
      OK
   else
      Permission denied
}

If I understand correctly, a SID is particular to a domain. Why isn't the check written like this instead (as in, why wouldn't that achieve the same requirements while being more secure):

checkRightsInThisDomain(object) {
   if (isInThisDomain(object.SID) and ACL.allows(object.SID))
      OK
   else
      for each SID in (object.SIDHistory)
          if (isInThisDomain(SID) and ACL.allows(object.SID))
              OK
   else
      Permission denied
}
#

if you guys think we're being too verbose I'm happy to dm

cerulean grail
#

In the "Linux File Transfer Methods" module it says "There are also situations such as binary exploitation and packet capture analysis, where we must upload files from our target machine onto our attack host". Shouldn't it be the other way around?

Isn't uploading taking a file from my attacking machine and uploading it to the target?

#

I'm specifically referring to the bit where it says "from our target machine onto our attack host" - shouldn't it read "from our attack host onto our target machine"?

young ore
#

And it had to be the first time

urban elk
#

I understand the attack (I think), and I think I could move on just like that, but I usually understand why something is designed the way it is and why it would need some kind of separate mitigation because a redesign would be costly. But in this case I don't see why it's not easy to patch, which tells me I am missing something about the feature itself

cerulean grail
#

Maybe I'm misunderstanding. I would appreciate any guidance or help here.

fathom pendant
urban elk
# urban elk I'm sorry, I still don't get why it's designed like this. I must be missing some...

It seems like SID filtering (https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-pac/55fc19f2-55ba-4251-8a6a-103dd7c66280) can do exactly this, so indeed I'm missing something about why we need a more generic design than that. That's ok, I can live with that. If anyone knows why though, I'd still be interested :)

A PAC from a cross-realm TGT needs to be parsed and analyzed. The type and stringency of the analysis is determined by the

autumn valve
cerulean grail
short topaz
#

Hi guys, Can anyone help in the module windows privilege escalation section 'SeTakeOwnership' lab? when I do the whoami /priv the htb-student user is a standard user without any privileges assigned and the user is only member of Remote desktop user. Can anyone tell me how the lab is done?

autumn valve
fathom pendant
young ore
placid edge
#

think that was it

wintry veldt
#

I'm stuck in "Advanced XSS and CSRF Exploitation
XSS Filter Bypasses", can anyone help? I am able to bypass xss filter and get logs as the admin, but cannot get it to work.

short topaz
# placid edge You can take over the ownership of the flag

yes..I have understand that; But in order take the ownership of the file, user have that privilege in right? but here the user only have "SeChangeNotifyPrivilege, & SeIncreaseWorkingSetPrivilege". And when I check the ownship of the file "cmd /c dir /q "C:\TakeOwn" , it is owned by a sccm service account. Also I have tried the " takeown " functionality, but the "action is denied", since on the privilege we donot have the SeTakeOwnership privilege for this user.

placid edge
short topaz
# placid edge does it actually say that the privledge is enabled?

No, but if it is disabled we can enable with the scripts given in the tools directory ("EnableAllTokens.ps1"). Here on the user privleges section there is quote of SeOwnershipPrivilege" PS C:\Users\htb-student> whoami /priv

PRIVILEGES INFORMATION

Privilege Name Description State
============================= ============================== ========
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
PS C:\Users\htb-student>

placid edge
#

icacls 'C:\Department Shares\Private\IT\cred.txt' /grant htb-student:F (example)

#

even tho you are owner you might not still be able to read the file unless that comand has been ran

#

you can also verify that the owner has changed with

Get-ChildItem -Path 'C:\Department Shares\Private\IT\cred.txt' | select name,directory, @{Name="Owner";Expression={(Get-ACL $_.Fullname).Owner}}
short topaz
placid edge
#

have you tried running cmd as administrator?

#

or powershell

#

just test it and see if it asks for a password

#

or try to supply your own

autumn valve
short topaz
placid edge
#

what does your takeown tell you?

#

can you show cmd and output please

compact matrix
#

@placid edge mind if I dm?

placid edge
#

go ahead

short topaz
# placid edge what does your takeown tell you?

Thanks bro...after restarting the machine. Now I tried running powershell as administrator and got the access. PS C:\Windows\system32> whoami
winlpe-srv01\htb-student
PS C:\Windows\system32> whoami /priv

PRIVILEGES INFORMATION

Privilege Name Description State
============================= ======================================== ========
SeTakeOwnershipPrivilege Take ownership of files or other objects Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
PS C:\Windows\system32> C:\tools\EnableAllTokenPrivs.ps1
PS C:\Windows\system32> whoami /priv

PRIVILEGES INFORMATION

Privilege Name Description State
============================= ======================================== =======
SeTakeOwnershipPrivilege Take ownership of files or other objects Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled

short topaz
iron patio
#

Is there any way to report to HTB that a particular module may be broken? I'm doing the FTP page in the footprinting module and the FTP server just doesn't seem to work. ls times out no matter what, and you can't get the flag by any method listed on the page. wget just times out as well, get flag.txt doesn't seem to do anything.

storm elk
young ore
autumn valve
young ore
safe star
autumn valve
young ore
autumn valve
rustic sage
#

kerbrute passwordspray -d inlanefreight.local --dc 172.16.5.5 justusers.txt Welcome1 -v

Im trying passwordspraying using a valid username list with 56 entries. However,

2024/12/13 06:20:16 > Done! Tested 25 logins (0 successes) in 0.031 seconds

its not really going through the whole list, and the number of attempts keep changing.

#

Its Active Directory

#

module

#

The username is present in the list, however, it won't iterate uptil that username and there's no errors in verbose too

fathom pendant
#

?

#

Also there's multiple AD modules

young ore
#

Was just trying to help with the details

rustic sage
wintry veldt
#

I'm stuck in "Advanced XSS and CSRF Exploitation
XSS Filter Bypasses", can anyone help?
I am able to bypass xss filter and get logs back, but I cannot fetch /home

primal adder
#

Good evening. It's not directly about modules, but I don't know where else to ask. My Parrot OS machine on VirtualBox isn't launching, it just loads infinitely without any animation or crashes instantly with "RPC_S_SERVER_UNAVAILABLE" and I don't know what that means and how to fix it. Hyper-V is disabled (if it actually affects anything). It was working fine before. I tried reinstalling it completely.

rustic sage
#

guys, this is not making sense to me:

┌─[htb-student@ea-attack01]─[~]
└──╼ $cat justusers.txt | grep sgage
sgage
┌─[htb-student@ea-attack01]─[~]
└──╼ $netexec
-bash: netexec: command not found
┌─[✗]─[htb-student@ea-attack01]─[~]
└──╼ $sudo crackmapexec smb 172.16.5.5 -u sgage -p Welcome1 | grep +
SMB         172.16.5.5      445    ACADEMY-EA-DC01  [+] INLANEFREIGHT.LOCAL\sgage:Welcome1 
┌─[htb-student@ea-attack01]─[~]
└──╼ $sudo crackmapexec smb 172.16.5.5 -u justusers.txt -p Welcome1 | grep +
SMB         172.16.5.5      445    ACADEMY-EA-DC01  [+] INLANEFREIGHT.LOCAL\tjohnson:Welcome1 

Does it stop on the first valid match?

bright coral
rustic sage
#

Amazing, thankyou!

icy dagger
#

Hello everybody, I am stuck in the Skills Assessment for the Attacking Authentication Mechanisms. Can I ping someone for a nudge? Thank you

cedar void
#

Trying to span the machine for HTB lab Dev and it saying that "Switch to VIP Server" , not sure how to do that . I spawn the open box and tried a bunch of different VPNs

cedar void
solar pecan
#

Does anyone having problem with file transfer with ligolo-ng?

gray yacht
solar pecan
solar pecan
gray yacht
#

Sure you can send a DM.

fading iron
#

heey, anyone finished the server side attack module after the update in 2024 ?? i have an issue with it can i get help ??

tacit monolith
#

Hi, I have a question.
I'm trying to do this exercise:
Perform an analysis of C:\Apps\Restart-OracleService.exe and identify the credentials hidden within its source code. Submit the answer using the format username:password.
But when I drag the .bin file on top of de4dot file I get this error. Can someone guide me?

gray yacht
#

Is this the "Working with Rules" section?

#

You can DM the command you are running.

green minnow
#

Ok this might be a dumb question, but is there any reason why the footprinting easy lab has you using up time running dig and dnsenum and finding an ftp dns to find an ftp server when you can just find it by using nmap on the main IP of the box in one step?

#

In fact the first thing it asks you to do in the walkthrough is run nmap. So you already have the info you need to get the flag. Why spend time enumerating the dns stuff?

placid edge
#

ligolo stuff ^

good watch

final kite
#

anyone know this one Find the output of the following command using one of the techniques you learned in this section: find /usr/share/ | grep root | grep mysql | tail -n 1

#

i made this command but it doesn't work 127.0.0.1%0abash<<<$(base64${IFS}-d<<<ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDE=)

#

Module Command INjections Advanced Command Obfuscation

vivid sigil
#

hi

when i trying to building the agent and proxy from ligolo-ng it gives me

zsh: illegal hardware instruction go build -o agent cmd/agent/main.go

placid edge
final kite
#

I figured it

#

Forgot to delete new line in burp

placid edge
#

ah

#

alr

fathom pendant
green minnow
#

Any reason my nfs nmap scripts just never complete?

#

How does more time get added to ETA that doesn't even make sense

fathom pendant
#

Timeout and readjusting

#

And if it gets stuck it just goes

pulsar berry
#

I am working on ADCS Attacks module. I have complete all sections except ESC5, ESC8, and ESC11. I can't complete them because on the last step of abuse I get the following error Got error while trying to request TGT: Kerberos SessionError: KDC_ERR_PADATA_TYPE_NOSUPP(KDC has no support for padata type). Does anyone know a workaround?

cinder mason
#

oh sorry wrong account i am burny with the burpsuite issue

#

i solved it ,

#

instead of removing the entire cookie then replacing it with the $$ stuff , you add the damn $cookie hash$ like this

#

which is sO dAmN dumb but it works i guess

wild sage
#

Does anyone have the command syntax to upload a directory for ssh? I'm trying to download LaZagne.py to kira's ssh in Cred Hunting in Linux and when I ran the script. It threw back "at line 17 you need..... this file"

#

tried using scp -r and wget on ssh

storm elk
#

Thanks @urban elk

urban elk
#

sure thing

glad patio
#

guys, could anyone please point out where the mistake is?

The question: Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII? (Please use best practices when using switches)(https://academy.hackthebox.com/module/81/section/774)
My answer: sudo tcpdump -Xr ~/tmp/capture.pcap

toxic apex
#

Has anyone succesfully used CME in "Using CrackMapExec" instead of just figuring something out with powershell without CME? It seems like for whatever reason chisel / pivoting just does not work on the target machine.

true sundial
#

Hello guys!! Recently I started the "Malicious Document Analysis" module, I am having big problems to complete the "Analysis of Malicious RTF Files" section, I have problems with the "XORSearch.exe -W c:\temp\agenttesla_rtf.sc" output command of the example

glad patio
true sundial
toxic apex
true sundial
#

so wierd, thank you very much

dim hound
#

Is there an option to reset job role path?

autumn valve
viral sundial
#

Do any of u know how to reverse an windows installation and retrieve back all the files?

iron patio
acoustic owl
iron patio
#

rip

harsh gorge
#

Anyone else having issues dumping the table from sqlmap essentials

#

because i sure as hell am

safe star
#

Use the —dump flag pepecoffee

harsh gorge
#

duh

#

I know to do that im not stupid

#

got it working

buoyant escarp
#

Just finished yesterday

atomic coyote
#

Second question, SMTP module, using the provided resource and nmap enumeration, I cannot find the existing user. Any assistance is appreciated.

fathom pendant
#

adjust the wait time

viral dawn
#

why

#

@jolly cradle @jolly cradle

#

@jolly cradle i want to rank up

jolly cradle
#

Why what?

viral dawn
#

i want to rank up

jolly cradle
#

So work on some of the active boxes and challenges to do that

viral dawn
#

ok

#

thanks

jolly cradle
#

You're welcome

atomic coyote
fathom pendant
atomic coyote
quasi wave
#

I'm having trouble with this question in the Pass the Ticket from Linux section of Password Attacks Module:

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \\DC01\julio.```

I get this far but I don't get further than this:

svc_workstations@inlanefreight.htb@linux01:/tmp$ sudo su
root@linux01:/tmp# cd ~
root@linux01:~# klist
Ticket cache: FILE:/tmp/krb5cc_647401109_ruz7E5
Default principal: svc_workstations@INLANEFREIGHT.HTB

Valid starting Expires Service principal
12/13/2024 22:41:16 12/14/2024 08:41:16 krbtgt/INLANEFREIGHT.HTB@INLANEFREIGHT.HTB
renew until 12/14/2024 22:41:16
root@linux01:~# cp /tmp/krb5cc_647401109_ruz7E5 .
root@linux01:~# export KRB5CCNAME=/tmp/krb5cc_647401109_ruz7E5
root@linux01:~# klist
Ticket cache: FILE:/tmp/krb5cc_647401109_ruz7E5
Default principal: svc_workstations@INLANEFREIGHT.HTB

Valid starting Expires Service principal
12/13/2024 22:41:16 12/14/2024 08:41:16 krbtgt/INLANEFREIGHT.HTB@INLANEFREIGHT.HTB
renew until 12/14/2024 22:41:16
root@linux01:~# smbclient //dc01/julio-k -c ls -no-pass
Enter svc_workstations@INLANEFREIGHT.HTB's password:
tree connect failed: NT_STATUS_BAD_NETWORK_NAME
root@linux01:~# smbclient //dc01/julio -k -c ls -no-pass
NT_STATUS_ACCESS_DENIED listing *
root@linux01:~# smbclient //dc01/julio.txt -k -c type -no-pass
tree connect failed: NT_STATUS_BAD_NETWORK_NAME
root@linux01:~# smbclient //dc01/juliot -k -c ls -no-pass
tree connect failed: NT_STATUS_BAD_NETWORK_NAME

#

can someone help em out?

fierce mortar
quasi wave
fierce mortar
jade fulcrum
#

hi

quasi wave
#

chatgpt doesn't work on this module

#

because its not free tier so chatgpt won't allow it

#

not tier 0 or 1 its tier 2

fierce mortar
quasi wave
#

Password Attacks

#

the section is Pass the Ticket from Linux

#

I managed to get an smbclient connection

jade fulcrum
#

why can't I type in general?

quasi wave
#

but I cannot get it to print julio.txt contents

fierce mortar
quasi wave
#
root@linux01:~# smbclient //dc01/julio/ -k -c
Try "help" to get a list of possible commands.
smb: \> help
?              allinfo        altname        archive        backup         
blocksize      cancel         case_sensitive cd             chmod          
chown          close          del            deltree        dir            
du             echo           exit           get            getfacl        
geteas         hardlink       help           history        iosize         
lcd            link           lock           lowercase      ls             
l              mask           md             mget           mkdir          
more           mput           newer          notify         open           
posix          posix_encrypt  posix_open     posix_mkdir    posix_rmdir    
posix_unlink   posix_whoami   print          prompt         put            
pwd            q              queue          quit           readlink       
rd             recurse        reget          rename         reput          
rm             rmdir          showacls       setea          setmode        
scopy          stat           symlink        tar            tarmode        
timeout        translate      unlock         volume         vuid           
wdel           logon          listconnect    showconnect    tcon           
tdis           tid            utimes         logoff         ..             
!              
smb: \> l
NT_STATUS_ACCESS_DENIED listing \*
smb: \> print julio.txt
NT_STATUS_ACCESS_DENIED opening remote file julio.txt
smb: \> ls
NT_STATUS_ACCESS_DENIED listing \*
smb: \> dir
NT_STATUS_ACCESS_DENIED listing \*
fierce mortar
jade fulcrum
fierce mortar
fierce mortar
civic steeple
#

currently in Shells & Payloads, Page 13, Laudanum, One Webshell to Rule Them All

i've uploaded the shell.aspx (or demo.aspx) file multiple times, even renaming and uploading with any changes made (not sure if uploading the same file name overwrites the initial file uploaded) at times, removing the ASCII art and comments from the file as suggested in the module as well as leaving them in. I've quadruple checked the IP addresses are all in the proper places but i keep getting the "Server Error in '/' Application."
thoughts?

fierce mortar
safe star
languid forum
#

Hello newish to connect the bot anyone able to assist me with a small problem with it?

#

I know it has something to do with no file or directory. But I don't know how to fix it if it is the problem

#

If someone is able to help plz just reach out. Ty

safe star
#

you didnt explain the problem

quasi wave
#

hold on

languid forum
#

Problem is I did not read the question for the thing.

#

So I'm dumb

harsh gorge
#

Im having some trouble with the command line injection module where I cant really figure out how to substiute the | any nudge or hint?
||```=127.0.0.1%0a'f'in'd'${IFS}${PATH:0:1}usr${PATH:0:1}share${PATH:0:1}${IFS}``||

languid forum
#

Long story short I thought it wanted me to put cat/ect/issue but I just did not read it well enough

harsh gorge
#

Advanced Command Obfuscation
oh and this is the section

languid forum
#

I'm extremely new so I wish I could help Vader

quasi wave
#

here the file is not showing up and the name of the file I know I'm supposed to read:

NT_STATUS_NO_SUCH_FILE listing \julio\julio.txt

I also go into julio.txt and find flag.txt. When I use more on flag.txt I get some sort of flag but when I enter the contents of flag.txt in as the answer HTBA says wrong answer.

#

I'm on this question

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \\DC01\julio.
#

this is for Pass the Ticket from Linux section of Password Attacks

#

if someone could help me with this that would be great

#

can someone help me with this?

harsh gorge
safe star
#

<<<

harsh gorge
#

so like this ||%0a%09{ta"i"l,-n,1}<<<$(g"re"p%09mysql)<<<$(g"re"p%09r"oo"t)<<<%09$(f"in"d%09${PATH:0:1}u"s"r${PATH:0:1}s"ha"re${PATH:0:1}||

safe star
#

hard to read but <<< can substitute as a pipe

#

they show it on the reverse commands part too

safe star
quasi wave
#

yes but I don't think that is issue anyways

harsh gorge
#

i see

quasi wave
#

anywho I'm gonna take a break until tonight

#

I have someone helping me in dm

safe star
quasi wave
#

ok cool that's good too

safe star
#

looking at your klist command it says that you are svc_workstations not julio

quasi wave
#

ok

#

so log in as julio and connect from there?

#

yes I can get to julio user on linux box

#

but when I smbclient into dc01 no matter who I connect as it won't work

safe star
#

you dont need be ssh logged in as julio

#

just import their ticket

quasi wave
#

ok

safe star
#

in the /tmp folder

quasi wave
safe star
#

its not a keytab file, so no need to extract anything

#

just set the KRB5CCNAME variable

harsh gorge
#

so input redirector aint working

quasi wave
#
julio@inlanefreight.htb@linux01:/home/svc_workstations@inlanefreight.htb$ klist
klist: Credentials cache permissions incorrect (filename: /tmp/krb5cc_647401109_VLi7AQ)
#

hold on

#

ok its still not working

#

wait a minute

#

where is the right cache file

safe star
#

way simpler

safe star
harsh gorge
#

127.0.0.1%0a'f'in'd'${IFS}${PATH:0:1}usr${PATH:0:1}share${PATH:0:1}${IFS}bash<<<$(base64-d<<<Z3JlcCByb290IHwgZ3JlcCAzMw==)

#

So like this?

#

actually

#

i have a better idea

harsh gorge
#

what if i just encoded it in base64 and feed it to bash

safe star
harsh gorge
#

I WAS OVERCOMPLICATING IT THE WHOLE TIME?

#

hey on the bright side I learned a lot

harsh gorge
#

and im stuck at the beginning of the skills assement

#

NEVER MIND WE GOOD

wild sage
#

I also got stuck on that when I did the module. Don't need to remove anything else

civic steeple
#

having an issue Shells & Payloads, Page 15, PHP Web Shells

i'm uploading the webshell.php with burp suite as my proxy, i change the content type the website expects to image/gif but every time i navigate to the file it opens the git page

thorn urchin
#

its just closing out a valid query

#

the cn part is unimportant

#

yeah because its closing out a valid query to filter out extra stuff

#

play around with the application without injecting it and see how its intended to work

cloud urchin
#

don't use sqli. don't enter anything into the search box and hit search. you'll see this returns all the results in the database. after that, you can see the port code column. try searching for one of those like "cn sha", itll then only bring up that entry. if you enter "cn" itll bring up any port code starting with "cn". madf0x is right, you're closing out a valid query and then injecting your own code afterwards. if you remove the cn and just input the injection it'll show you all the results and then your injection happens afterwards.

wild sage
civic steeple
wild sage
#

If you have issues with Land you can DM me

round marten
#

I was wondering if I could get a tip with the "Intro to C2 Operations with Sliver" module. I'm at the final question of the skills assessment. I had SYSTEM on DC02, I have earlier done the Active Directory module and I'm confident in how this should look but I cannot make it work. I've gotten to the point where I've ruled out a Sliver skills issue by using RDP as the Domain Admin to get on this server. I've noted that even commands like Get-DomainTrust when run as Domain Admin throw errors about servers not being operational, leaving me wondering if something deeper is going on. I've tried both methods in the "Whole forest takeover" section" without any luck.

pine dome
#

Any tip on how to bypass the filter to execute command on advanced deserialization attack SA?

fluid bobcat
#

Not sure

cloud urchin
#

<@&861185840277487616>

cloud urchin
#

<@&861185840277487616>

green minnow
#

How do I not have permission to access a folder I made on my own system and I'm using sudo?

#

footprinting medium lab, am I just barking up the wrong tree? Are you not meant to mount the NFS?

buoyant escarp
#

Show us the permissions of those

green minnow
#

apparently you can't cd as sudo

green minnow
buoyant escarp
#

Show permission of NFS

#

Ls -l

green minnow
#

drwx------ 2 nobody nobody 65536 Nov 11 2021 NFS

buoyant escarp
#

Where tf comes nobody from and why is it this weird file size

green minnow
#

Interesting that I can sudo ls -la /NFS but cannot cd NFS

midnight galleon
#

su root and go there

lusty thicket
#

i guess that means file permissions are not determined by your local machine

torn skiff
#

Asking again, in SOC Analyst Path, Windows attack and defense module. Where is the passwords.txt file used in the practicals located or does it even exist (there is no resources tab for this module)

tropic void
#

Are there any plans to add malware analysts to HTB Academy job paths?

tranquil axle
#

Nothing official but after cbbh and cpts got advanced CERTs people expect cdsa to be next. They already added two defensive modules for that recently, and one is about analyzing malicious documents (pdf,Word,etc.). I assume it is going to continue in that direction

broken trellis
#

hi in Server-side Attacks Skills Assessment i found ssrf but file:/// not working it says Error (1): Protocol "file" not supported or disabled in libcurl. But then i searched in chrome someone did samething what i did and it worked for him. Can u help me?

tropic void
tranquil axle
#

Yea I’m hyped for that too. Reversing is great fun imo

green minnow
#

Anyone know why zsh is erroring out like this?

zsh: event not found: mD
hexed lintel
green minnow
#

nice, thanks

pine dune
#

hi guyys

#

cant seem to connect to the mysql server

#

mysql -u root -h 94.237.49.127

#

mysql -u root -h 94.237.49.127:47899

#

even tried that

#

ahh got the correct command as follows if anyone also faces the same problem

#

mysql -u root -h 94.237.49.127 -P 47899 -p

upbeat zinc
lavish ember
#

Can someone help me with "Exploiting SSRF" exercise

compact matrix
#

what you need help with

lavish ember
#

Exploit the SSRF vulnerability to identify an additional endpoint. Access that endpoint to obtain the flag.
This is the question I tried enemurating ports and directories but didn't find anything useful

compact matrix
#

what does your command look like

lavish ember
#

For directory scanning
ffuf -w /opt/useful/secLists/Discovery/Web-Content/raft-small-words.txt -u http://10.129.176.152/index.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "dateserver=http://10.129.176.152/FUZZ.php&date=2024-01-01" -fr "Not Found"

#

For port scanning
ffuf -w ./ports.txt -u http://10.129.144.252/index.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "dateserver=http://127.0.0.1:FUZZ/&date=2024-01-01" -fr "Failed to connect to"

#

I also tried using gopherus as the port 3306 was open I used the admin username and show databses; query and didn't get anything

compact matrix
#

no thats not required in this

#

1 sec

lavish ember
lavish ember
upbeat zinc
#

In the ADCS module, I am stuck on an error KDC_ERR_PADATA_TYPE_NOSUPP for more than a week. Microsoft explanation is : "Smart card logon is being attempted and the proper certificate cannot be located. This problem can happen because the wrong certification authority (CA) is being queried or the proper CA cannot be contacted in order to get Domain Controller or Domain Controller Authentication certificates for the domain controller. It can also happen when a domain controller doesn't have a certificate installed for smart cards (Domain Controller or Domain Controller Authentication templates)." I see more people with the same problem, but nobody with a solution, can it be that the lab is broken ?

compact matrix
lavish ember
#

yeah

#

I tried enumarting all ports also

#

got two more ports at like the 40k but I couldn't reach them

compact matrix
lavish ember
sleek vale
#

Guys need an answers as for some reason I ma not allowed to post in the general chat channel - I am on question 1 of https://tryhackme.com/r/room/cyberkillchainzmt - the answers are correct, I checked them AFTER entering and even tested variants of the answers factoring in British and American English and swapping out & for 'and' in each variant......Anyone know why the room will not accept the answers?

dark hedge
#

this channel is for HTB Academy modules

sleek vale
#

Ah, sorry, wrong dept.

#

🤦‍♂️

winged egret
#

Hello anyone doing LDAP injections ?
Why does this payload work: username=*)(description=*&password=*
But this DOESNT : username=*)(d*=*&password=*
Specifically when I prepend the * with a pattern that I know exists like d* (description) , the applicaiton returns a negative result
Same goes for this payload:
This returns true : username=htb-stdnt&password=*
While this returns FALSE, when I know that the first letter of the password is A: username=htb-stdnt&password=A*

reef pecan
#

This CSS looks ugly, probably unintended? Its supposed to have a tickebox next to the text or somewhere inside the container, not below it.

shut vapor
#

I'm in AD Enum & Attacks > Assessment #2
When ||password spraying with kerbrute|| I get "Can't talk to KDC. Aborting..." but I consistently get that "error" upon discovering valid credentials. Is this a quirk of the situation or am I missing a flag or something?

gray yacht
safe stream
#

Something went wrong
Error Code: 520

Our engineers have been notified and are working to resolve the issue.

Ray ID: ::RAY_ID::

what is wrong guys

#

am I the only one with this issue?

placid edge
#

did you manage to figure it out?

#

or you ❤️

analog dock
placid edge
#

||DigestUtils.md5DigestAsHex(("" + user.getId() + ":" + user.getId() + ":" + user.getEmail()).getBytes());

isnt it id:id:email||

analog dock
#

Did you use jd-gui?

placid edge
#

ye

analog dock
green minnow
#

Bruh how the hell on the footprinting lab hard are you supposed to know there's a mySQL database running on the target? It doesn't show up on nmap and even the walkthough is literally like "Ok now connect to the mySQL database" having mentioned it zero times before then.

fast jungle
#

What is the name of the security standard for credit card payments that a company must adhere to? (Answer Format: acronym)

Does anyone know what the right answer for this is? I tried PCI and its incorrect.

fast jungle
#

Module : Penetration Testing Process
Section : Post-Exploitation

green minnow
# analog dock There’s a sql file

Where? And the walkthrough makes no mention of any file. It's literally like 1. Connect via SSH. 2. Connect to the mysql database. It doesn't say anything about finding a file.

analog dock
#

But you can also see it running if you run netstat -tulpen I assume

green minnow
#

I'm I misunderstanding what a walkthrough is supposed to be. I thought it's supposed to teach stuff. Instead it just provides the answers without showing any of the process or methadology.

analog dock
#

I don’t have access to walkthroughs so couldn’t tell you

placid edge
#

not sure what the issue is now

placid edge
analog dock
fast jungle
#

Nvm I got it

signal pike
#

When we need to scan udp ports, is there any method that can do it faster?

torn skiff
# dark hedge it should be on the kali host

Connection always gets refused when I attempt to ssh to the target ip "ssh kali@[target ip]" so I havent been able to connect to the kali host , idk if i am missing something important

knotty anvil
#

hi could i get a hint on kerberos attacks - skills assessment question 3, I cant find out a way to enumerate the user that has admin privileges on the machine that has unconstrained delegation, most solutions require rubeus, but i dont have access to a windows machine

calm abyss
#

hello
I am doing Using Crackmapexec module - Skill assessment

And i am stuck on a first question

I use

crackmapexec smb 10.129.199.120 -u '' -p '' --rid-brute
SMB 10.129.199.120 445 SQL01 [*] Windows 10 / Server 2019 Build 17763 x64 (name:SQL01) (domain:INLANEFREIGHT.LOCAL) (signing:False) (SMBv1:False)
SMB 10.129.199.120 445 SQL01 [-] INLANEFREIGHT.LOCAL: STATUS_ACCESS_DENIED
SMB 10.129.199.120 445 SQL01 [-] Error creating DCERPC connection: SMB SessionError: code: 0xc0000022 - STATUS_ACCESS_DENIED - {Access Denied} A process has requested access to an object but has not been granted those access rights.

I cant get usernames with --rid-brute

pine dune
#

Hi guys, Im stuck on this thing, its very basic but i keep messing up

#

cd+cat+flag.txt

calm abyss
pine dune
#

Im using a web shell and need to go back a directory and print the flag.txt

pine dune
# calm abyss yes no luck

sorry, I wasnt much help. Seems the pros are taking a break rn lol, hopefully someone will be with us soon

pine dune
calm abyss
shut vapor
gray yacht
harsh gorge
#

You can just use phpbash or just print the absolute path of the directory

harsh gorge
#

Dm me if you have any trouble

pine dune
surreal chasm
#

Hey, Just finished the skill assessment for the Shells & Payloads module and I dont understand
In host 1 and 2, how could we get the creds?
Got both creds from the hints..

knotty anvil
#

<@&861185840277487616>

dapper wigeon
#

he can/>?

knotty anvil
dapper wigeon
#

.

#

was that aginst the rule

knotty anvil
#

yes delete the msg

dapper wigeon
#

am sry

#

How do i learn whitehat hacking

dapper wigeon
#

ok i opened the link am hacked now?

#

it says error

knotty anvil
dapper wigeon
#

cant be reacherd

knotty anvil
#

idk why it doesnt work

#

go here

dapper wigeon
#

ty

#

@wooden mist am sorry for breaking the rule

#

ill make sure it wont happen again

loud socket
#

I wanted to ping seriousrulebreak

#

But I don't wanna be muted again

languid fjord
#

Taken care of

loud socket
#

🫡

gloomy bramble
#

Module (ACL Abuse Tactics) Anyone have a hint for me to get this working? Changing syntax, etc just is not working. I've checked that damundsen is in AD also. There is another password I tried for un w*** also, but nothing works. Even what i'm seeing in the suggestions in archives.

uneven pecan
#

Hi, I’ve been working through the skills assessment for the injection attacks module which is part of the senior web tester path, I was hoping someone could help me out. I don’t want to give too much away but I’m able to access the target system and have identified what the vulnerability is but can seem to get anything to work with exploiting it, I must had read the data exfil section about 5 times but the app just isn’t responding how I’m expecting. I’m happy to drop anyone a PM with more info etc

pine dune
#

Hi guys, Im on the SQLi skills assessment and could use some tips

fathom pendant
pine dune
#

for now

fathom pendant
pine dune
fathom pendant
pine dune
gloomy bramble
dark hedge
winged egret
#

Hello anyone doing LDAP injections ?
Why does this payload work: username=*)(description=*&password=*
But this DOESNT : username=*)(d*=*&password=*
Specifically when I prepend the * with a pattern that I know exists like d* (description) , the applicaiton returns a negative result
Same goes for this payload:
This returns true : username=htb-stdnt&password=*
While this returns FALSE, when I know that the first letter of the password is A: username=htb-stdnt&password=A*

fathom pendant
#

Also you can't partially wildcard

winged egret
# fathom pendant Because you can't wildcard a variable name

okay this makes sense, but what about the password ? In the module it is instructed : We can now brute-force the password character-by-character by injecting substring search filters. We can start with the first character by setting the password to a*

fathom pendant
#

A* and a* are different, case sensitivity

tranquil axle
#

Different fields can define how sub string search works on them or if it works on them at all

#

And yea I don’t think wildcard works on field names?

fathom pendant
#

It shouldn't afaik

winged egret
#

okay thx @fathom pendant @tranquil axle much appreciated

winged egret
#

and tried in manually aswell

tranquil axle
#

You sure the field is called password then? Sounds like you are doing the right thing

#

Is your & valid syntax?

winged egret
#

That's the payload from the module : (&(uid=htb-stdnt)(password=p@*)) there is no field required, its a direct injection into the password parameter

tranquil axle
#

I always see &(filter=1)(filter=2)

#

You out the & in the middle

winged egret
#

username=admin&password=a*

tranquil axle
#

Shouldn’t it be &(username=admin)(password=a*)?

winged egret
#

It's as simple as this, but its not working in my case, the password is given and tried it manually

tranquil axle
#

Ah, okay you pass it via url Parameters

winged egret
#

The problem is when I use an * alone it works, however when I prepend it with the first password characters it returns false . So I guess this will stay a mystery FeelsWeirdMan

static aspen
#

hi. im new on htb and im trying to get into a windows machine through the online htb parrot os machine. if i navigate to the link they provide i end up in the elastic web, how do i get the windows machine?

hasty mauve
#

in Attacking Common Applications - Skills Assessment I

this url works
/url/path/to/*somefile.some_extension*?&dir+C:\Users\Administrator\Desktop\flag.txt
and displays that the file exists, however if I simply change dir to type it doesn't display anything.

fathom pendant
static aspen
fathom pendant
#

Then you should start with fundamentals

stable bone
#

^^ preach sistah

fathom pendant
#

It's nothing to do with being "new on htb"

#

There's a windows fundamentals course on htb academy, maybe do that first

static aspen
#

i'll check it then

fathom pendant
#

There's also the "introduction to academy" module i believe

static aspen
#

my main pc is using linux, i assume that has nothing to do with rdp on the academy machine right?

fathom pendant
#

Correct

cedar yew
#

hi all
Modul - Using Web Proxies
Task - Intercepting Responses

My Problem -> I turned on the setting he mentioned through the application, but I cannot view the source code.

#

i cant see response page

formal turret
#

Hi guys, i'm curently on the 'Information Gathering - Web Edition'

I'm stuck on the question - Which domain is returned when querying the PTR record for 134.209.24.248?

When I use 'dig PTR <IP ADDRESS>' in the kali terminal and it doesn't show the domain that is returned. I've used a DNS query in a google search which has given me the answer I need. Has anyone had issues where the domain doesn't show in the terminal?

opal nexus
formal turret
#

so is dig PTR <IP> not the answer?

opal nexus
unreal tartan
#

Good evening, I wanted to know if someone can help me with the file transfer module, file transfer with Windows, I'm with the base64 part that explains examples and other things with the terminal, but I don't know if I have to download something or I don't know how to be able to execute and so on.

cloud urchin
lime oyster
#

On "Attacking Active Directory & NTDS.dit" with the question :
On an engagement you have gone on several social media sites and found the Inlanefreight employee names: John Marston IT Director, Carol Johnson Financial Controller and Jennifer Stapleton Logistics Manager. You decide to use these names to conduct your password attacks against the target domain controller. Submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive)

I have created a user.list using the provided firstname/lastname with the tool username-anarchy

i used ||crackmapexec smb 10.129.202.85 -u user.txt -p password.list||

and i got nothing, any help ?

polar raven
#

Hi, I'm on the File module of the CPTS(penetration path). Everything, is working correcty execpt or the WebDav part. It's rare, but I have a no clue why.

rustic sage
#

No port

#

on dir \\10.10.15.18\DavWWWRoot

cloud urchin
polar raven
opal nexus
rustic sage
#

Also try pip upgrading to see if an upgrade is available, unless you just installed it

polar raven
#

Yeah, i know I can access the webserver. Therefore, i don't see the problem.

rustic sage
#

🤷‍♂️

#

I would try googling at this point

#

honestly for RDP, do xfreerdp3 ... +drive:share,./

#

srry

cloud urchin
#

you can see it if you access the IP in a browser instead of using SMB

unreal tartan
cloud urchin
unreal tartan
# cloud urchin yes

In any case, is there anything to be installed or used in that module to keep in mind?

cloud urchin
#

you encode the file to base64, copy the base64 code into your clipboard, then paste it somewhere else, then decode it with base64 decoding

#

not really i believe both windows and kali/parrot have built-in commands that can decode/encode base64

unreal tartan
polar raven
upper ruin
#

Linux Privilege Escalation
Logrotate

So I did chmod on the logrotten and payload files, transferred them via scp and so on.
Problem came when I tried to run the logrotten and I got this error.

htb-student@ubuntu:~$ ./logrotten -p ./payload /tmp/tmp.log
./logrotten: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./logrotten)

I tried to transfer via scp an ubuntu libc package like: libc6_2.40-1ubuntu3_amd64.deb

Problem is that I cant dpkg it, as it requires superuser privs.

Any hints?

upper ruin
#

Sure will.

#

What if I use proxychains

cloud urchin
# polar raven So, I'm supposed to launch the server on port 445 ? I'm doing this, but still no...

well, the section explains that it will first attempt on the smb protocol and if that doesn't work it'll try over http, and webdav is running http. webdav won't work on smb, has to be http. i'm not really sure why it's not working (it doesn't work for me either), you'd probably have to open up wireshark and see if it's even attempting to connect over port 80 after smb fails. idk if the module is wrong or i just don't know enough about it to tell you why it doesn't work.

polar raven
cloud urchin
#

chatgpt says it doesn't inherently try http if smb fails, it must explicitly be set up. but idk if that's accurate at all.

carmine hill
#

hi,im new,i wanna ask how can i keep the data when i boot my vm on virtualbox,it keep losing so everytime that i reboot i can not setup

fathom pendant
cloud urchin
#

are you using a live version of kali?

carmine hill
#

yep

cloud urchin
#

that's why

midnight galleon
#

cuz from what I see, aspx shells doesn't work

carmine hill
fathom pendant
#

Also yes the install media in vm

carmine hill
fathom pendant
#

You said the "issue" was virtualbox so yes I'm referring to the vbox 'media' it's due to a boot issue order

carmine hill
#

ok,tks, i gonna try rn

midnight galleon
fathom pendant
#

It is

#

And asp webshells do exist lol

quasi wave
#

hi I'm on the last question of PTT from Linux section of Password Attacks Module

#

I ran linikatz

#

and tried exporting this file as KRB5CCNAME variable

fathom pendant
#

That's not a ccache

quasi wave
#

ok

#

is this cache better

fathom pendant
#

KRB5CCNAME; Kerberos 5 CCache Name

fathom pendant
quasi wave
#

ok

#

ok solved thanks

half pendant
#

I've been having trouble spawning targets throughout the AD enum & attacks academy module. I either click on it, it buffers and doesn't do anything, or says spawning targets... then snaps back to its original state saying 'click here'

civic steeple
#

Shells & Payloads, Page 16, The Live Engagement: I've spent a few hours trying to use credentials i found trying to gain a shell and answer question 2. I finally peaked at the walkthrough and it doesn't explain how i could've gotten the password, rather it refers to the hint that provided the username and pasword. My question is, could the password have been found/cracked without looking at the hint ever?

safe star
civic steeple
#

htb-student@skills-foothold]─[/home]
└──╼ $ls -ls
total 0
0 drwxr-xr-x 1 administrator administrator 462 Oct 28 2022 administrator
0 drwxr-xr-x 1 htb-student htb-student 796 Dec 14 19:00 htb-student

#

if you're asking about when i'm in smb using tomcat without a password, if i navigate to the Public or Default folders, there is no home folder

thin owl
#

/home is where all users main directories sit(where your pictures, documents, downloads, etc. live), tlattice was suggesting you check the one specifically for the user you're on the system as /home/htb-student, similar to when you're on windows and you want to check your home directory c:\users\jsp0511\

civic steeple
thin owl
#

no, youre looking at /home not /home/htb-student/

civic steeple
#

[htb-student@skills-foothold]─[~]
└──╼ $ls
combined_creds.txt Downloads Music thinclient_drives
core hydra_creds.txt Pictures usernames.txt
Desktop hydra.restore Public Videos
Documents hydra_results.txt Templates

#

none of those txt files were there when i started

#

i've been in this folder much of the time

safe star
#

the creds are def somewhere there

#

try "tree ."

fathom pendant
#

It's on the desktop

civic steeple
civic steeple
#

access-creds.txt

#

well, a very expensive lesson learned lol

fathom pendant
#

If you search the discord you'll see plenty of similar questions on it

#

Expensive??

#

Lol

civic steeple
#

yea just a lot of time wasted wow lol

fathom pendant
#

Lol ok

civic steeple
#

my brain can't decipher when the modules are going to go easy on me

#

thank you, i'm glad i asked i just couldn't fathom why the walkthrough would be like "yea so in the hint". there are no hints on the exam, i assume

fathom pendant
#

Nope

#

The walkthrough isn't really there to explain anything

#

It's just to show you a path to the goal

civic steeple
fathom pendant
#

It's assuming you read the hints from the section before you went to the walkthrough

civic steeple
#

i'm really trying not to read the hints lol

fathom pendant
#

Well... if you're digging into the walkthrough

midnight galleon
#

I tried it, but doesn't seem to work

fathom pendant
#

¯_(ツ)_/¯

midnight galleon
cloud urchin
#

i googled asp webshell and it was on the first hit

midnight galleon
#

core?

#

not framework?

#

not antak?

#

idk but does asp core even allow non registered views to be rendered? the thing doesn't even have a 404 error page lol

pine dune
#

Hi guys, Im trying to do an idor fuzz on the following website, is the following correct? As im always getting status 200 and same size

cloud urchin
#

doesn't look right, you're not iterating through different endpoints with your get request, i'm guessing that's what you want to do

real delta
#

@pine dune what module is that?

pine dune
pine dune
real delta
pine dune
#

ok ill ask there

half pendant
cloud urchin
#

press ctrl + shift + r and try again

half pendant
#

Same thing, I've refreshed the page numerous times

cloud urchin
#

you refreshed it the way i described?

half pendant
#

Yes

cloud urchin
#

try another browser or reach out to support on the site probably

half pendant
#

Even logged out and logged back on

#

Yeah I'll try chrome

half pendant
#

Not even chrome is working...

unborn summit
#

It appears to only affect the active directory enumeration and attacks module

half pendant
fathom pendant
#

Did you try a different vpn?

half pendant
dim cloak
#

The module is indeed down, so there's nothing else to do but wait.

cerulean hinge
#

Hello, I was doing the Command Injection Skill Assessment module and when I tried to inject a command I manage to arrive here (cf image).
Just wondering is that normal to be able to read the config.php file for this module ?

cloud urchin
#

apache can be configured to see directory listings, so yeah they probably set that option

civic steeple
#

also cannot re-set my target

swift plover
#

interestingly I can't get any windows VM to spawn, but linux seems to be working fine

next osprey
#

looks like module machines are down

#

guess this means i have no choice but to play vidya 😦

plush viper
#

I have started the "Introduction to Windows Evasion Techniques " module and the introduction talks about 2 VM evasion-dev and evasion target. I spun evasion-dev in the introduction section but when i spun the target on second or third section it closes the evasion-dev, is it how it is supposed to be? how can i run evasion-dev and evasion-target at the same time, starting one closes other.

clever topaz
#

oh everyone is having the same problem..

ocean night
#

Yes confirmed, I'm having a dig in to logs and we have alerted the team

gray yacht
hasty mauve
#

in the skills assessment 2 of attacking common applications, I got a reverse shell but cannot find a "flag.txt" file anywhere.
even when I run find / -type f -name "flag.txt" 2>/dev/null -exec cat {} \;

#

my shell is meterpreter so I even tried search -f "flag.txt" and still nothing.

hasty mauve
#

never mind found it.
I had to privesc which they did not mention anywhere lol.

rich yew
#

Hello, In the Skill Assessment of the SQLMap Essentials module, dumping any kind of data from the DB is quite slow. Is it something inherent to time-based sqli? Or is there a way to dump faster?

tranquil axle
#

That’s inherent to time based attacks and amplified by a slow/bad connection. Try to dump exactly what you need instead of dumping everything

rich yew
tranquil axle
#

I think another problem is that sqlmap searches for time based vulns before it does some of the others

#

So there might be a fast path but sqlmap gets stuck on the slow one

#

Idk if that applies to this case though

rich yew
torn skiff
dark hedge
#

what is the section name and question you are trying to answer?

torn skiff
#

Module: Windows Attack & Defense, Section: Kerberoasting, Question: Connect to the target and perform a Kerberoasting attack. What is the password for the svc-iam user? The walkthrough is simple enough the only issue I am having is the passwords.txt/rockyou.txt file not existing in the machine, So i am unable to crack the passwrod

dark hedge
#

probably will have to crack the hash on your own VM

#

no, just on your own VM since password cracking is offline

#

maybe you can RDP to kali from WS001

#

but easiest way is to copy the ticket and just crack it offline with hashcat on your own VM

finite abyss
#

Are there any compensation for annual gold subscription purchased recently before the offer announcement. Like a three month extension. It would be good if so.

midnight galleon
#

file upload - white list bypass

Each character has a specific use case that may trick the web application to misinterpret the file extension. For example, (shell.php%00.jpg) works with PHP servers with version 5.X or earlier, as it causes the PHP web server to end the file name after the (%00), and store it as (shell.php), while still passing the whitelist. The same may be used with web applications hosted on a Windows server by injecting a colon (:) before the allowed file extension (e.g. shell.aspx:.jpg), which should also write the file as (shell.aspx). Similarly, each of the other characters has a use case that may allow us to upload a PHP script while bypassing the type validation test.

tried the windows one, it saved it as .jpgblaze

acoustic owl
autumn valve
terse quiver
#

I’ve got this trying to do kerberosting :
[-] CCache file is not found. Skipping…
[-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

it’s like I cannot do kerberosting, I don’t understand.

acoustic owl
autumn valve
#

Do you spawned the Kali Linux Target from the "Coercing Attacks & Unconstrained Delegation" section from the same module to connect by RDP?

autumn valve
#

i understand, but the thing is, to be able to complete that section (and the next one i think) you need to access the Kali Linux Target too, aside from the WS01 Windows one, the problem is that in that section there is no option to spawn the kali linux target, only the windows one, so you need to spawned from that section

autumn valve
#

no problem, let me know how it went

#

great, most of the times i get stuck is for things like that, its annoying tbh

empty trout
#

facing this problem from yesterday . tried another vpn file . 3 times refreshed the target still ....

analog dock
#

And you don’t need sudo for rdp

clever topaz
#

am i the only one still facing machine problem?

empty trout
#

Still same issue@analog dock

analog dock
#

Gg

clever topaz
#

i manage to rdp in but disconnected after a sec

empty trout
#

its slow ....

unborn summit
#

I'm doing the network attacks section of the password attacks module, question about SMB. ive found the users for all of the other questions but crackmapexec has been running for ~ 2 hours now and its still not even half way to finishing, is there something different required for the last one? or do i just need to wait a few more hours

safe star
#

The password list shouldn’t take 2 hours

calm abyss
#

man did you solve the question, i am stuck at that