#modules

1 messages · Page 363 of 1

unborn summit
#

wdym the password list? dont we have to try every username and password combination

safe star
harsh gorge
#

Feel slightly embarrassed asking this but I could use some help with the file upload modules

harsh gorge
# safe star which part

The whole file upload part, I uploaded my file and got past all the defenses but I’m not sure where my file landed

#

I checked the path I got from the source code but no dice

harsh gorge
#

Sorry for not being more specific

safe star
#

oh i see

#

try checking the response with burp

harsh gorge
#

See that’s what I did.

#

But no dice on the whole checking the response and the file getting renamed thing

#

So I suspect the file may be getting renamed

knotty anvil
safe star
#

been a while

harsh gorge
long flint
#

anyone i could DM for Advanced XSS and CSRF Exploitation XSS Filter Bypasses?

Bypassed the XSS filter, but can't retrieve any data... tried with and without ports... tested with ports to XSS myself and aren't hitting CORS errors.. not sure what else I can do if I can't even XSS myself lol

I can use the vulnerablesite.htb to send a request to exfiltrate.htb, but exploit.htb doesn't do anything

Is it not vulnerablesite.htb calls exploitserver.htb which then calls exfiltrate.htb?

safe star
#

have you tried a real image yet?

harsh gorge
#

Yeah I just get an image thumbnail

safe star
harsh gorge
safe star
#

yeah alr

crisp remnant
#

Is there someone that have completed the ADCS module section ESC5, i am having troubles with the last step, no matter how many times i revert the lab its always the same

~ # proxychains4 -q certipy auth -pfx administrator.pfx -dc-ip 172.16.19.3 -ns 172.16.19.3 -dns-tcp -domain lab.local
Certipy v4.8.2 - by Oliver Lyak (ly4k)

[*] Using principal: administrator@lab.local
[*] Trying to get TGT...
[-] Got error while trying to request TGT: Kerberos SessionError: KDC_ERR_PADATA_TYPE_NOSUPP(KDC has no support for padata type)
~ # 

As far as i understand this is yet another buggy lab... the support team is less than helpful, so can someone at least share the flag for this section... i really want to wrap up this module and move to the next one...

dim hound
#

I am stuck on the Nmap Hard lab, I am able to see the state of port 50000 now open.. but now able to retrieve the banner. Would someone like to point me into to right direction? sudo nmap -sS -Pn -f --mtu 16 -D RND:10 -T1 -p 50000 --source-port 53 -sV --version-intensity 0 --data-length 32 --randomize-hosts 10.129.38.221

long flint
#

Seeking help with Advanced XSS and CSRF Exploitation - XSS Filter Bypasses

gray yacht
brisk ferry
#

guys with a little hint i was able to solve xss/csrf skill ass final step
Honestly i still cant imagine the query it's running in backend

#

is it clear for anyone? or ask the source code is running behind to fully undesrand? i spent days for this skill ass, and i'd like to fully undestand

#

"advanced xss and csrf" for cwee

barren chasm
#

Hi all, I have just submitted my CPTS exam with report..

I am little bit confused. there was just a button to upload your report. I clicked on it and browsed my report and uploaded. and it showed my report name on the button,

the confusion is that, is there any other place where my report will be shown that i have uploaded it????

or just we to browse it from the system and submit the exam

ancient niche
#

Good afternoon people i'm writing in burpsuite the direction web but, i can't lesen the direction web

#

the page remains blank in history containers 😦

storm elk
#

But I’m sure it went fine 👌

barren chasm
storm elk
barren chasm
#

yes….

ancient niche
#

hello?

storm elk
ancient niche
#

someone can help me?

storm elk
#

With what?

ancient niche
#

with burpsuite

analog dock
#

They have a discord

ancient niche
#

i can't put in php wrapers 😦

#

just i have history

storm elk
#

Maybe go over the burp module

ancient niche
#

what

storm elk
analog dock
#

Or just go to their discord…

ancient niche
#

the program oh my goof

#

good

storm elk
#

Look at the module I wrote above. It’ll teach you the basics 🙂

wind ruin
humble mirage
#

i need some help.. i was able to authenticate to the ACADEMY-EA-DB01 host (172.16.5.150). Submit the contents of the flag at C:\Users\damundsen\Desktop\flag.txt using mssclient.py. But i tried it with the PowerUpSQL and couldnt do it. Can anyone help pleasee?

fathom pendant
#

Did you import it?

humble mirage
#

Yes

#

Get-SQLQuery -Verbose -Instance "172.16.5.150,1433" -username "inlanefreight\damundsen" -password "SQL1234!" -query 'Select @@version' this command works

#

I read the git hub cheatsheet but couldnt find a command to get the flag

#

I mean... i found the commands but none of them worked

quiet trout
#

is tree a ParrotOS native cmd or something? I see it used in a lot of acad modules but the cmd doesnt exist oob on my ubuntu or kali installs... and no apt suggestion is thrown to install it...

cloud urchin
#

tree isn't installed by default on Debian derivatives. apt install tree

#

no idea about parrot

fathom pendant
#

It's there default I think

quiet trout
#

thanks, im unsure i actually /need/ it but every time i see it mentioned or pictured on modules i tend to open my term and "try" it... just to see

cloud urchin
#

it's a nice command

quiet trout
#

it does seem helpful. i think i have an alias that does something similar

#

altho less useful, as ls does not (to my knowledge) have a way of listing just dirs (if that is what tree does)

lusty thicket
indigo topaz
#

hello, hack the box don´t have a comunity for spanish speakers?

fathom pendant
#

Not on the discord, no

indigo topaz
#

uh, and in other site?

fathom pendant
#

Not sure about other places

#

And go to their communities

indigo topaz
#

ohhh

#

okay

fathom pendant
#

But there's no official Spanish community

indigo topaz
#

okay I understandt

#

thank you

lime oyster
#

Hello
I need a small hint with this question: “Examine the target and find out the password of the user Will. Then, submit the password as the answer.” I already found Kira’s password; I checked the .mozilla folder and found 2 files but no one contain the login.json files ||" wx------ 2 kira kira 4096 Feb 9 2022 lktd9y8y.default
drwx------ 7 kira kira 4096 Feb 9 2022 ytb95ytb.default-release||
" i saw a lot of people talking about cracking users hashes but i couldn`t find it , any help ?

fathom pendant
#

Read and follow #welcome for more access to the server

fathom pendant
lime oyster
fathom pendant
#

It is mentioned and showcased in the section

lime oyster
fathom pendant
#

laZagne should work. No root required

lime oyster
#

are u sure ?

fathom pendant
#

You might have to specify python3 instead of just python

#

But I don't recall any issues extracting info

lime oyster
fathom pendant
#

Nah

lime oyster
# fathom pendant Nah

everytime i get this error Traceback (most recent call last):
File "laZagne.py", line 17, in <module>
from lazagne.config.write_output import write_in_file, StandardOutput
ModuleNotFoundError: No module named 'lazagne'

fathom pendant
fathom pendant
#

Otherwise you can try and copy over the .Mozilla file and try and get lazagne to hit that

#

But I recommend pulling over all the files, or if there's a releases section, using that

gray yacht
harsh gorge
#

So Im doing the server side attacks skills assement and I got the ssrf vuln working but port scans revealed nothing and so was fuzzing the dirs

wild sage
cloud urchin
#

you selling these?

#

<@&861185840277487616>

#

sorry you can't scam here

harsh gorge
#

can i uhh get a little help here

ocean night
#

Thanks @cloud urchin

gray yacht
harsh gorge
#

tried that nothing

harsh gorge
#

i am geuninely tweaking

#
http://truckapi.htb/?id%3D{{var_dump(['id']|escape('system','system'))}}
I managed to do this but still no luck```
gray yacht
harsh gorge
#

cant read that

gray yacht
whole vale
#

yo i am on the using web proxies, zap scanner part, and when i am trying to use zap to spider the target it says out of scope which is ok but it says to start and that waht the module says to do, but nothing happens...

long flint
#

Looking to DM someone for help with Advanced XSS and CSRF Exploitation XSS Filtration Bypass

whole vale
unborn summit
#

i had the same problem lmao, its the answer to question 3 in the LLMNR/NBT-NS poisoning From linux section

#

no worries

#

it was always a little frustrating to have to go back and find the passwords but I guess they don't want to allow cheating or something

broken hollow
#

Is this the right channel to ask questions about specific modules?

#

I'm on my second day trying to get through Web enumeration, total noob. I just get server time outs when I try to gobuster the target. When I ping it it shows up no packet loss. try to connect to site through mozilla same thing just times out. Any advice?

#

*Pentesting basics-Web enumeration

fathom pendant
#

And if there's subdomain fuzzing you'll need to --append-domain --domain inlanefreight.htb or whatever domain they give you

broken hollow
#

🤦‍♂️

#

Okay.. that solves that issue..

#

gobuster dir -u {target-IP:port} -w usr/share/dirb/wordlists/common.txt Now it says this file doesn't exist. confirmed it's the correct file path. Did I type this out wrong?

thin owl
#

/usr/share

fathom pendant
broken hollow
#

sorry, I did type that in correctly in parrot..

#

/usr/share/dirb/wordlists/common.txt

fathom pendant
#

Pwnbox doesn't have dirbuster installed so that wordlist isn't there

#

The seclists common.txt is similar with like a few more words, but it'll work

broken hollow
#

That's weird, I can navigate to that exact file path. Click Parrot on desktop- File System - filepath.

thin owl
#

screenshots are probably necessary at this stage

fathom pendant
#

Can't share screenshots unless they link their account [ #welcome ]

thin owl
#

ah I thought modules allowed it

#

or used too

broken hollow
#

I thought I linked my account already but maybe not:/

fathom pendant
#

Gotta follow the welcome instructions to do it properly

broken hollow
#

Testing.. just showing file path.

lusty thicket
broken hollow
#

This is the error I get, or file path doesn't exist.

#

However, I was just able to connect to the web page on mozilla so maybe its my network shrugs

harsh gorge
#

So is the Server-Side Attacks Skills Assessment broken still

whole vale
broken hollow
safe star
#

Awesome sauce

lusty thicket
#

awesome stuff

keen torrent
#

attacking SQL Databases I need help I've been using my main system with vpn and now attacking Sql db its not working can log in and am I suppose to use htbdbuser or mssqlsvc??

fathom pendant
acoustic thorn
#

Encountering a weird issue with an lsass dump, anyone know what the deal is? Running the cmd as admin btw

keen torrent
harsh gorge
fathom pendant
harsh gorge
fathom pendant
#

No idea I don't think I did that module

#

¯_(ツ)_/¯

harsh gorge
#

How...convient

safe star
cerulean hinge
acoustic thorn
sweet jewel
acoustic thorn
hollow charm
#

I opend RDP session to window machine but start menu not shown. how can i access it?

fathom pendant
cerulean hinge
hollow charm
whole vale
#

Yo is there anything wrong with zap, I am in the web fuzziness module on zap scanner and zap's hud is tweaking and I can't access and I set it up 5 tines restarting the instance and updating it.

whole vale
lusty thicket
storm elk
#

What module is this for? If not a module, we can’t help.

grim grove
#

@storm elk ok no problem. I was only asking a general query.

storm elk
#

This channel is for help with Academy modules.

empty trout
#

yesterday there was a problem of not connecting via rdp now its this ..

#

and in the module shells and payload there is no other way to use this foothold to exploit other machines on the network ...

cloud urchin
#

which section

empty trout
#

yeah remmina is working

faint sedge
#

My partner near Christmas and Happy New year

empty trout
#

but now its working

robust quartz
#

Why should we crack the password on a user's ticket? We can simply pass the ticket and gain access to the resources without the hassle of cracking the ticket's password.

safe star
#

What section?

tranquil axle
cunning frigate
#

Hey were you able to solve it?

west canopy
safe star
polar raven
cunning frigate
#

had the same problem in zephyr

keen minnow
#

Anyone completed "MSSQL, Exchange, and SCCM Attacks"? in section "SCCM Auditing", just wondering why SCCMHunter doesn't populate all the SCCM information in the lab like it does in the walkthrough?

keen minnow
#

Logged a ticket, just incase its a content issue.

round marten
cunning frigate
#

I just finished the module (spent 2 hours on a typo)

round marten
#

haha, thanks i'll pm you.

tranquil axle
dawn topaz
#

keeps changing

keen minnow
keen minnow
long flint
#

need some advice on Advanced XSS and CSRF Exploitation Skill Assessment, I can't even do the first part lmao

tacit monolith
#

I'm doing this exercise but I've been stuck for two days and I'm not making any progress. Can someone help me?

What is the IP address of the eth0 interface under the ServerStatus -> Ipconfig tab in the fatty-client application?

rustic sage
#

Detecting Windows Attacks with Splunk > Detecting RDP Brute Force Attacks (But this applies to the entire Leveraging Zeek Logs section)

When I try to access the splunk server on port 8000, I get an error. I checked the running processes and it says that splunk is running. Did anyone else encounter this?

htb-student@ubuntu:~$ ps aux | grep splunk
root        1311  4.5  3.2 539108 129580 ?       Sl   03:19   0:14 splunkd -p 8089 start
root        1339  0.0  0.3 100972 14300 ?        Ss   03:19   0:00 [splunkd pid=1311] splunkd -p 8089 start [process-runner]
root        1707  0.6  1.3 1490192 55008 ?       Sl   03:19   0:01 /opt/splunk/bin/python3.7 -O /opt/splunk/lib/python3.7/site-packages/splunk/appserver/mrsparkle/root.py --proxied=127.0.0.1,8065,8000
root        1709  0.2  1.3 187036 51992 ?        Sl   03:19   0:00 /opt/splunk/bin/splunkd instrument-resource-usage -p 8089 --with-kvstore
root        1779  0.0  0.0   4140   860 ?        S    03:19   0:00 /bin/sh -c /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py
root        1780  0.3  1.4  77824 56140 ?        S    03:19   0:01 /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py
htb-stu+    2492  0.0  0.0  17672   664 pts/0    R+   03:24   0:00 grep --color=auto splunk

Even doing it via RDP connection on the server browser didn't work

clever topaz
#

Module: RDP and SOCKS Tunneling with SocksOverRDP
i cant connect to the last machine 172.16.6.155 with the given creds jason:HTB_@cademy_stdnt!

visual umbra
#

Im in Module for NTA i sektion : Interrogating Network Traffic With Capture and Display Filters .. I don't figure out ware to find the file TCPDump-lab-2.zip is no link etc, i been look at the pwn box 2 without finding it. or It is the file from previous labs?

visual umbra
clever topaz
#

ya its pwnbox.....

visual umbra
#

ok

long flint
#

anyone who has completed advanced xss and csrf? need a nudge

fading iron
#

heey i have a question about this payload

http://truckapi.htb/?id%3D{{['ls']|filter('system')}}

server side attacks skill assessment, where i found the ssti vulnerability but can't encode some space to go to the home dir whatever i do to add some space it pops an error

#

found it

for yall who don't know and stuck on this, double encode and leave the spaces as it is

azure turtle
#

Run ZAP Scanner on the target above to identify directories and potential vulnerabilities. Once you find the high-level vulnerability, try to use it to read the flag at '/flag.txt'

The ZAP HUD doesn't work for me

burnt spruce
#

Web Attacks Advanced File Disclosure
Hi guys, can someone give some hints?

Using Blind Data Exfiltration on the '/blind' page to read the content of '/327a6c4304ad5938eaf0efb6cc3e53dc.php' and get the flag.

my req.txt

POST /blind/submitDetails.php HTTP/1.1
Host: 10.129.200.254
Content-Length: 160
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.122 Safari/537.36
Content-Type: text/plain;charset=UTF-8
Accept: */*
Origin: http://10.129.200.254
Referer: http://10.129.200.254/blind/
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
XXEINJECT

gray yacht
azure turtle
#

i clicked on the automated scan in the thing and put the IP in but its taking way too long so idk im doing something wrong

gray yacht
#

Can you DM a screenshot? I'll let you know if it looks like an issue or if you just need to wait.

azure turtle
#

i found the flag

#

but it doesn't accept it

#

someone had the exact same problem

gray yacht
azure turtle
#

my brain just committed die

sharp torrent
#

I'm doing the lab for double-pivots. I've changed the performance to modem and my connection is still unstable. Any suggestions ?

dusty steppe
#

Hello, I need help with Attacking Authentication Mechanisms Skills Assessment.
I have tried the module provided script, jwt_tools and now i have written my own script.
Made my own private and public keys and also x5c certificate, none of these have worked so far.
Have not modified the payload, only played with the header, to see if i can forge tokens.
Also, verified that my signed jwt's are correct. Have read the forum and other posts here but they haven't made any sense to me.

burnt spruce
#

Web Attacks Advanced File Disclosure
Hi guys, can someone give some hints?

Using Blind Data Exfiltration on the '/blind' page to read the content of '/327a6c4304ad5938eaf0efb6cc3e53dc.php' and get the flag.

my req.txt

POST /blind/submitDetails.php HTTP/1.1
Host: 10.129.200.254
Content-Length: 160
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.122 Safari/537.36
Content-Type: text/plain;charset=UTF-8
Accept: */*
Origin: http://10.129.200.254
Referer: http://10.129.200.254/blind/
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
XXEINJECT

misty current
sweet jewel
#

Trust Attacks -> ADCS
anyone know how to add the vulnerable ESC1 certificate without having to do it over RDP? (i.e. certipy, certify, cli, etc.)

proven loom
#

This might be a 'works for all': CVE-2024-49019

upbeat zinc
#

certipy auth -pfx administrator.pfx -username administrator -domain lab.local -dc-ip 10.129.205.199

Certipy v4.8.2 - by Oliver Lyak (ly4k)

[] Using principal: administrator@lab.local
[
] Trying to get TGT...
[] Got TGT
[
] Saved credential cache to 'administrator.ccache'
[] Trying to retrieve NT hash for 'administrator'
[
] Got hash for 'administrator@lab.local': aad3b435b51404eeaad3b435b51404ee:<SNIP>

#

KRB5CCNAME=administrator.ccache wmiexec.py -k -no-pass LAB-DC.LAB.LOCAL

Impacket v0.11.0 - Copyright 2023 Fortra

[*] SMBv3.0 dialect used
[!] Launching semi-interactive shell - Careful what you execute
[!] Press help for extra shell commands
C:>whoami
lab\administrator

opal nexus
#

How do I claim my reward?

rustic sage
cyan lark
#

We need to see how you configured it. Whether you configured it correctly or not. Saying "I configured it" doesn't make it easy for people to see where you went wrong.

pastel geyser
gray yacht
#

Probably because you should be able to identify some open ports in that sections assessment?

rustic sage
#

remove your --min-rate

gray yacht
rustic sage
#

I'll do it in a second

cyan lark
gray yacht
cyan lark
rustic sage
#

he means is that the only scan you've done

cyan lark
#

Oh, I've also done a general scan but same result

rustic sage
#

yeah try and remove --min-rate

long flint
#

anyone.. please... for the skill assessment of Advanced XSS and CSRF Exploitation im already moderator...should i be focusing XSS on the task management or upload? i've yet to get passed CSP...

rustic sage
#

or increase it

cyan lark
#

Remove it or increase it? Do you understand what --min-rate does?

rustic sage
#

Adjusting rate of packets sent

#

But this option is mainly used when you know the network bandwidth stats

#

Nmap will do its best to send packets as fast as or faster than the given rate.

cyan lark
#

I disagree since this scan would take hours if I would remove the option

rustic sage
#

testing rn

gray yacht
# cyan lark It's the first question, I don't understand what you are asking

Like did you start with that are you scan or did you start with something less busy, i.e., less options to see if you got any results? For instance, you would simply start with just nmap -Pn IP or even hit all of the ports to see if you even get any results and then start adding in more options to tweak your scan if necessary. It might be more difficult for you to troubleshoot something like that if you come out the gate with a scan query like that.

primal eagle
#

Am i allowed to use the courseware of hackthebox academy, to write some writeup on?

cyan lark
#

What does the filtered state of a port on an nmap scan mean?

rustic sage
#

Nmap cannot correctly identify whether the scanned port is open or closed because either no response is returned from the target for the port or we get an error code from the target.

gray yacht
# cyan lark

So with your initial scan query, it is fine, you just needed to move some things around. In this screenshot, you still had the output filename without the output switch.

gray yacht
cyan lark
#

Any clue what am I supposed to do in this question?
Enumerate the hostname of your target and submit it as the answer. (case-sensitive)

signal glen
#

Currently on this module:

https://academy.hackthebox.com/module/109/section/1038

There is a little exercise outside of the regular flag at the end of the module that goes like this:

who$@ami
w\ho\am\i

Exercise: Try the above two examples in your payload, and see if they work in bypassing the command filter. If they do not, this may indicate that you may have used a filtered character. Would you be able to bypass that as well, using the techniques we learned in the previous section?

--

wh$@mi works just fine, w\ho\am\i doesn't, so it says to utilize techniques from the previous section to make it work. The previous section mentions this:

Character Shifting
There are other techniques to produce the required characters without using them, like shifting characters. For example, the following Linux command shifts the character we pass by 1. So, all we have to do is find the character in the ASCII table that is just before our needed character (we can get it with man ascii), then add it instead of [ in the below example. This way, the last printed character would be the one we need:

CPTmevius@htb[/htb]$ man ascii # \ is on 92, before it is [ on 91
CPTmevius@htb[/htb]$ echo $(tr '!-}' '"-~'<<<[)

\

--

I've tried a few ways to use this but I can not figure out how to do it in burp, does anyone else know how to do this?

cyan lark
gray yacht
cyan lark
rustic sage
#

Probably a NETBIOS output which will reveal the hostname

long flint
#

where do i go for module help if this chat is unable to help?

rustic sage
#

htb forums

cyan lark
long flint
#

trying to be unclear to not spoil it lol

#

just more of a directional thing

cyan lark
#

Got it man @rustic sage
Got it through the smb-os-discovery script

signal glen
# opal nexus How do I claim my reward?

you have a streak of 30 weeks, the 30 streak points you refer to are divided by 10 each for every answer you correctly answer of every chapter inside a module you finish.

rustic sage
cyan lark
#

Yeah could have also just selected the ports I found to save time but we're good

rustic sage
#

absolutely, glad to help

clever topaz
#

In Pivoting, Tunneling, and Port Forwarding Skill Assessment, i got the creds for mlefay and vfrank already, but i cant rdp in either alive host ||.25|| and|| .45||

#

any hint for that

rustic sage
#

ssh?

clever topaz
#

i doubt that

fathom pendant
#

Read the nmap docs to understand the commands and options/flags

clever topaz
iron plaza
clever topaz
#

the last question of Pivoting, Tunneling, and Port Forwarding: Skill Assessment
Submit the contents of C:\Flag.txt located on the Domain Controller.

i solved it simply by ||accessing the share, is this the right way?||

clever topaz
#

okay thanks

fathom pendant
#

I confirmed it way back when I did it with Tejas or someone to make sure it wasn't an error

pastel geyser
#

I figured it out. I forgot to set the TARGETURI and Traversal depth from the show options command. In case it helps anyone.

kindred acorn
#

I do not know why i cannot download

#

┌──(root㉿kali)-[~/Downloads]
└─# wget -m --no-passive ftp://anonymous:anonymous@10.129.186.239:2121
--2024-12-16 11:14:25-- ftp://anonymous:*password*@10.129.186.239:2121/
=> ‘10.129.186.239:2121/.listing’
Connecting to 10.129.186.239:2121... connected.
Logging in as anonymous ... Logged in!
==> SYST ... done. ==> PWD ... done.
==> TYPE I ... done. ==> CWD not needed.
==> PORT ... done. ==> LIST ... done.

10.129.186.239:2121/.listing [ <=> ] 255 --.-KB/s in 0s

2024-12-16 11:14:34 (30.7 MB/s) - ‘10.129.186.239:2121/.listing’ saved [255]

--2024-12-16 11:14:34-- ftp://anonymous:*password*@10.129.186.239:2121/passwords.list
=> ‘10.129.186.239:2121/passwords.list’
==> CWD not required.
==> PORT ... done. ==> RETR passwords.list ... done.
Length: 1959 (1.9K)

10.129.186.239:2121/passwords.list 0%[ ] 0 --.-KB/s

short relic
#

Hei

kindred acorn
#

can anyone help me why i cannot download?

#

hi

short relic
#

I wanna to join Advent of Cyber 2024 now can i?. Can I learn it from it's first...

rustic sage
#

** Detecting Windows Attacks with Splunk > Detecting Golden Tickets/Silver Tickets**
For which "service" did the user named Barbi generate a silver ticket?
I've tried using the mentioned silver-ticket SPL queries mentioned in the section, but modifying it and extracting service_names has proved fruitless. Any tips?

short relic
#

@kindred acorn try with sudo. what is it?

kindred acorn
#

Attacking Common Services - Attacking FTP

rustic sage
#

Send the contents of the flag.txt file to the administrator's desktop in MS01

Active Directory Enumeration & Attacks Module
In this case you could import inveigh.ps1 to poll the network and scan other hosts on the network

fathom pendant
kindred acorn
kindred acorn
# fathom pendant Instead of wget just login ftp normally

┌──(root㉿kali)-[~/Downloads/10.129.186.239:2121]
└─# ftp 10.129.186.239 2121
Connected to 10.129.186.239.
220 ProFTPD Server (InlaneFTP) [10.129.186.239]
Name (10.129.186.239:root): anonymous
331 Anonymous login ok, send your complete email address as your password
Password:
230 Anonymous access granted, restrictions apply
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||63690|)
150 Opening ASCII mode data connection for file list
-rw-r--r-- 1 ftp ftp 1959 Apr 19 2022 passwords.list
-rw-rw-r-- 1 ftp ftp 72 Apr 19 2022 users.list
226 Transfer complete
ftp> get passwords.list
local: passwords.list remote: passwords.list
229 Entering Extended Passive Mode (|||60110|)
150 Opening BINARY mode data connection for passwords.list (1959 bytes)
0 0.00 KiB/s

rustic sage
warped gull
#

i am totally fresher in this feild...and i enrolled by the module learning process...because i am absolutely in 0 level...anyone here who can guide me properly?

scarlet agate
#

I am working on the AD Bloodhound module. The question is asking what rights the user Sarah has over the user Nicole. I can see the edge in Bloodhound, but That answer is not being accepted. Has anyone done this that can give me a hint please?

solid quarry
solid quarry
compact matrix
#

anyone know why I dont have the templates in here

viral lotus
#

is there a way of making RDP into windows environments in modules more stable? having issues where the connection will drop out

fathom pendant
manic bramble
#

i'm having trouble using tmux logging; where should my .tmux.conf file be located?

next osprey
manic bramble
#

error connecting to /tmp/tmux-1000/default (No such file or directory) ; i'm getting this error when running # tmux source .tmux.conf

proven swift
#

Could i DM someone for http misconfigurations Common Session Variables (Account Takeover) tried everything taught in the module but no luck.

cyan lark
#

Hey. I'm on the NMAP module, the hard lab in the IPS/IDS evasion section/

What would a result for a simple scan like this mean?

"919 filtered tcp ports (no-response), 81 filtered tcp ports (host-unreach)

harsh gorge
#

On the broken Auth module is the correct command to generate the password policy wordlist this?
cat rockyou.txt | grep '[[:upper:]]' | grep '[[:lower:]]' | grep '[[:digit:]]' | grep -E '.{12}' > custom_wordlist2.txt

#

i got gladys but i dont know what to do next since my passwords arent working

lime oyster
#

any help ?

#

okay i just found out that i cracked the hashes lol

#

i need a brake maybe

harsh gorge
#

never mind lel\

fathom pendant
harsh gorge
#

stuck on the otp and i figute i need to perform some kind of auth bypass since i dont know the length of the token. But changing the reponse to 302 does nothing and using IDOR doesnt seem to be the right answer

#

Wait, should I 302 to profile?

stark lark
#

Linux Privilege Escalation
Kernel Exploits

What is up with this? I am root but don't have access to the flag

Escalate privileges using a different Kernel exploit. Submit the contents of the flag.txt file in the /root/kernel_exploit directory.

harsh gorge
#

okay 302 to profile doesnt work

bold niche
compact matrix
#

didnt realise I have to click create a project and select the design

harsh gorge
#

never mind had to do the funny 302 to 200 trick

cyan lark
#

NMAP, IPS/IDS Evasion
Module: https://academy.hackthebox.com/module/19/section/119
Well I got this but I don't know what to put as the answer in the question
"Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer."

I tried:

Apache 2.4.29
httpd 2.4.29
2.4.29
OpenSSH
OpenSSH 7.6p1
Ubuntu
Ubuntu 4
4
Ubuntu Linux
Linux
ubuntu0.7
0.7
spare tendon
#

Hello everyone,
I am on the Web Attacks module and on the Mass IDOR Enumeration chapter. I managed to find the file but I have a problem on the Flag.
I don't know if it is related to the form or it is something else. Could someone give me a clue?

#

I see that the content of the file is HTML but without anything interesting

#

What else should I do when I find the file?

cyan lark
manic bramble
#

I could be mistaken but I think I used --source-port for this

fathom pendant
#

Without -p- it just tries the top/most used 1000 ports

quasi moth
#

I think I have catched some weird bug, wanted to check my answers but they are definitely wrong, as example the word vagrant shown as the answer, where question was expecting numberkek

twin cape
#

hello guys one question about linux :
"Which option needs to be set to create a home directory for a new user using "useradd" command? "
my first answer is = sudo useradd -m
second : sudo eseradd -b

cyan lark
twin cape
#

but all the submitted answers are incorrect , google also says -m

cyan lark
#

I got this port but still can't identify the version.

#

Any help guys?

dark hedge
twin cape
#

yes

tranquil axle
# cyan lark Any help guys?

have you tried doing from the pwnbox instead of from kali? I remember there being 2 instances where the flag was supposed to be in the nmap output and nmap would give a different output on the pwnbox from my vm

twin cape
#

the second and third question/task require the longer version

dark hedge
#

which module and section?

twin cape
dark hedge
#

check your answer for any whitespaces

twin cape
#

it doesn't seem to work : "sudo useradd -m"
"useradd -m"

dark hedge
#

i asked if you were answering with just the flag

cyan lark
#

I tried from kali but on the vpn

tranquil axle
dark hedge
#

but that answer contains the command too

#

answer with only the flag

twin cape
#

ok

#

thank you it worked

#

have a nice day/night @dark hedge

fathom pendant
#

Try everything from the sections at least once

#

There's something about a --source-port in the reading

cyan lark
fathom pendant
#

everything you need is in the reading ¯_(ツ)_/¯

safe star
hot bane
#

Am new here

storm elk
fathom pendant
cyan lark
fathom pendant
#

Yes

bold niche
safe star
cyan lark
# fathom pendant Yes

You're right now I see that I need to be using a port that the administrator might have misconfigured to not function well with the IPS/IDS

fathom pendant
high gorge
#

My aplogies! I will ask it there

cyan lark
#

Does a source-port of 80 make sense in my case? @safe star @fathom pendant

fathom pendant
#

Nope

#

The reading gives you an idea what port to use

cyan lark
#

I mean in the section they use port 53

fathom pendant
#

Do you know why 53? :)

cyan lark
#

Yes because it's where they might be running DNS

fathom pendant
#

Well yes and no

#

The source port tells nmap that you're using that port on your machine for callbacks, instead of an arbitrary port

zealous rune
#

hi guys, i'm getting to the end of the Attacking AD module in the CPTS path. Just wondering if anyone has a kind of flowchart, diagram or checklist to share that can serve as an aid when attacking AD. I did see something like this a while back but not sure where- curious if ppl find this useful. It seems useful to me to have a bit of a checklist for different stages of what paths we can take, i.e. i have no credentials i need to enumerate, i have basic creds, i have admin etc.

fathom pendant
#

Typical misconfiguration broadly allows incoming traffic from 53

frail jay
#

Hey where is the channel for operation tincel trace?

lusty thicket
fathom pendant
cyan lark
#

My inputted source port refers to the port on my end right?

cyan lark
#

Yesss I got another port

fathom pendant
#

The reading explains it

lusty thicket
#

some applications only accept responses from port 53

cyan lark
#

I got another port when I ran it with source port 53

safe star
#

Should be on github

zealous rune
#

perfect exactly what i was looking for

cyan lark
#

Let's go thank you so much guys I just got the flag @fathom pendant @safe star 🙏

quiet trout
#

does anyone know why nmap expects a single port like -p21 but a range or interval like -p 0-99 or -p 10000 (or however the syntax goes) i think its very strange that we must "remember" to not include a space for a single port scan

hard phoenix
quiet trout
# fathom pendant You can have a space

ok THANK YOU, i ALWAYS see it with the space omitted and never seen an explanation or w/e to say why we do or dont do that, and never thought to question whether it was even necessary

fathom pendant
#

Just laziness

#

The way it's coded it doesn't matter

silk cedar
#

i've been working on generating shellcode academy module. the stack has some extra values, 0xc2, not shown in the academy module- 0xffffcffe: 0x55 0x55 0xc2 0x90 0xc2 0x90 0xc2 0x90
0xffffd006: 0xc2 0x90 0xc2 0x90 0xc2 0x90 0xc2 0x90

quiet trout
# fathom pendant Just laziness

ok cuz i do know some util switches DO require an absent space and will fail without one, and i start making erroneous connections about other instances where you see that kinda stuff, ya feel me?

#

tho i cannot think of anny off top

fathom pendant
#

Looks to be a non-breaking space

quiet trout
#

hey @fathom pendant if you'll humor me a "silly" question, i have two "small" 22(24?" screens, but they're just wide enough to make glancing over at academy modules and back to pwnbox instance annoying... should i have any apprehension to using the integrated terminal? i used it once before but always default to pwnbox for some reason

zealous rune
quiet trout
#

just realized im complaining about having to tilt my head... technology man... its so over.

fathom pendant
#

I've used it maybe once or twice, have always had issues with it freezing/getting stuck

sturdy stone
#

@sterile hawk Can you please check your DMs? I have a problem: I can't verify my Discord account with my HTB account.

dim ridge
civic steeple
#

i'm in the Meterpreter section of the Metasploit module and this section i have a question about:

**"We have our Meterpreter shell. However, take a close look at the output above. We can see a .asp file named metasploit28857905 exists on the target system at this very moment. Once the Meterpreter shell is obtained, as mentioned before, it will reside within memory. Therefore, the file is not needed, and removal was attempted by msfconsole, which failed due to access permissions. Leaving traces like these is not beneficial to the attacker and creates a huge liability.

From the sysadmin's perspective, finding files that match this name type or slight variations of it can prove beneficial to stopping an attack in the middle of its tracks. Targeting regex matches against filenames or signatures as above will not even allow an attacker to spawn a Meterpreter shell before being cut down by the correctly configured security measures.

We proceed further with our exploits. Upon attempting to see which user we are running on, we get an access denied message. We should try migrating our process to a user with more privilege."
**
Does it makes sense to/can we, manually delete the file if the meterpreter attempt to delete it failed?

dim ridge
civic steeple
# dim ridge i guess it depends on why it failed no. It shows 403 forbidden in this example. ...

yes which leads me to my next question lol, in the next section they steal_token, but don't explain why they chose that token nor do they explain why they went into the c:\Inetpub>dir in the section after that. Maybe i'm lost there because I dont have prior experience with these tools before enrolling in the course or maybe i'll learn more later in the modules

meterpreter > steal_token 1836

Stolen token with username: NT AUTHORITY\NETWORK SERVICE

i guess you could steal any token with "NT AUTHORITY\NETWORK SERVICE"?

tacit bay
#

Not sure where I'm going wrong with this - on the AD trust attacks SA, running bloodhound-python is giving me DNS errors:
└─$ apt bloodhound-python -u htb-student -p 'HTB_@cademy_stdnt' --dns-timeout 15 -d 'child.inlanefreight.ad' -dc 'CHILD-DC.child.inlanefreight.ad' -ns 10.129.229.201 --dns-tcp

But, when running it with a "." at the end of the domain as suggested here - https://github.com/dirkjanm/BloodHound.py/pull/196 - it works? /etc/hosts has the correct info there
└─$ bloodhound-python -u htb-student -p 'HTB_@cademy_stdnt' --dns-timeout 15 -d 'child.inlanefreight.ad.' -dc 'CHILD-DC.child.inlanefreight.ad' -ns 10.129.229.201 --dns-tcp INFO: Found AD domain: child.inlanefreight.ad WARNING: Could not find a global catalog server, assuming the primary DC has this role If this gives errors, either specify a hostname with -gc or disable gc resolution with --disable-autogc INFO: Getting TGT for user INFO: Connecting to LDAP server: CHILD-DC.child.inlanefreight.ad INFO: Found 1 domains

GitHub

I faced some issue when using a BloodHound in a environment with a different DNS sufix.
Error sample 1
bloodhound-python -c All -ns 192.168.30.230 -d alunos.sec4us.local -u 'aluno.0&#39...

dim ridge
#

"We should try migrating our process to a user with more privilege."

#

worth testing it to be 100%

civic steeple
dim ridge
#

hehe password attacks is fun too

#

it steps up a level when you get to pivoting tho at least it did for me

civic steeple
civic steeple
dim ridge
#

It didn't go into ligolo yet for me but i think you can use it as an alternative, it takes you through quite a few different pivoting tools and methods, chisel is one it recommends but i hear ligolo is better

civic steeple
#

i'm a 44yo construction worker with an IT degree from 2002 lol, this pentesters course is wild for existing, so thankful

dim ridge
#

nice!!! yeah same! super fun and useful

delicate steeple
#

hey guys i am a little stuck here

i am on

-Password Attacks
Credential Hunting in Linux

#Examine the target and find out the password of the user Will. Then, submit the password as the answer.

I am logged in as kira on ssh (got the pw)

i see the json file on kira her machine i copy paste the text it to my own machine to crack it does not work
i was trying to copy over files with sftp does not work (need sudo for alot)

i am really stuck if someone could help yes please

civic steeple
civic steeple
dim ridge
#

Thank you you too!!

fathom pendant
fathom pendant
#

Ligolo blows other tools out of the water

silk cedar
# fathom pendant Looks to be a non-breaking space

the extra character is getting inserted after the string concatenations. i thought i could set sep='', but then nothing is written into the stack. thx for any help... i'm stumped. here's the shellcode: run $(python -c 'print("\x55" * (1040 - 124 - 95 - 4) + "\x90" * 124 + "\xbf\x54\x81\x18\x93 <snip> \x67\xa8\x70\xc2\x24\x23\x97\x52\xc1\xfe\xd8" + "\x66" * 4)')

fathom pendant
civic steeple
fathom pendant
civic steeple
#

thank you

proven swift
#

could i get some help on http misconfigurations skills assessment easy

bright coral
delicate steeple
fathom pendant
quiet trout
regal shore
#

hey I have a question, im doing pentesting basics and theres an optional exercise that says get the banner of the above server (94.237.55.109:40760) but whenever I use SSH w/ it, it says Permission denied (publickey) and im not sure what to do about that

silk cedar
gray yacht
silk cedar
regal shore
fathom pendant
#

You're given a public ip:port, that's your only scope

#

Ssh defaults to 22 if you don't specify the port

regal shore
#

correct, I was just typing
"ssh 94.237.55.109:40760"

fathom pendant
#

Also are you sure ssh is the way?

#

:)

regal shore
#

it does say optional so idk if it just didnt teach me this yet or if I missed something

fathom pendant
#

It just says "get the banner" it doesn't specify ssh

#

:)

regal shore
#

true I just assumed bc under "Using netcat" it says "As we can see, port 22 sent us its banner, stating that SSH is running on it. This technique is called Banner Grabbing, and can help identify what service is running on a particular port."

Cant send images so I have to copy paste lol

#

Oh it does say netcat I was using nmap

gray yacht
fathom pendant
#

netcat ip port is the basic syntax

whole vale
#

yo i am having a small hud problem, for zap i start running zap and open fire fox but none of the buttons appear and when they do it dosent scan and when i check the hud error scanner it gives me this 01:15:51 GMT+0000 (Coordinated Universal Time) ERROR errorHandler: TypeError: right-hand side of 'in' should be an object, got null @https: https://zap//zapCallBackUrl/-8015504834334403353/file/tools/commonAlerts.js 94:: {} idk if its just a me problem cause i have restarted the instance and refreshed the page and open and closed zap but its always the same result, it doesnt scan at all like no minor flags at all.

fathom pendant
regal shore
#

Can I type it as "94.237.54.116:50998" or do I need to do it as "94.237.54.116 50998"

#

sorry for the rudimentary questions lol

fathom pendant
regal shore
#

ur right mb

zenith zealot
#

Hello, I've got a quick question. Has any one had any issues with the Windows Fundamentals module spawning a target machine?

fathom pendant
#

Try changing vpn regions or reaching out to support

zenith zealot
#

Alright. Ill try that. Thanks you, I have tried everything else I could think of.

gray yacht
fathom pendant
#

I have vague recollection of modules I've done.

civic steeple
#

holy christ, how important is being able to write metasploit modules?

cloud urchin
#

depends on what you're doing.. if your job is writing metasploit modules probably pretty important

civic steeple
cloud urchin
#

the CPTS path teaches all you need to know, so if it doesn't dive deep into metasploit module writing I wouldn't worry about it too much personally

civic steeple
#

i'm stressing as if the test is literally going to expect you to know how to do everything mentioned lol

#

which is maybe a good thing but def overwhelming

cloud urchin
#

my understanding is the exam does not deviate from the contents of the path, so essentially you won't need to go off-site to learn about things you'll need for the exam

civic steeple
#

gotcha, i'm still early in the path but worried i may not recognize i need to do X rather than Y at some point. probably natural to feel that way at this point

cloud urchin
#

my advice would be to just go through all of the material and absorb as much as you can. make sure you don't just do it to do it, but make sure you actually understand the concepts they teach. then after finishing the whole path go back and touch on subjects you feel weak on.

civic steeple
cloud urchin
#

yeah i understand how you feel, i haven't taken the exam yet and i feel the same way. not looking forward to having to do password attacks for example lol.

civic steeple
cloud urchin
#

have fun with that lol

civic steeple
#

haha thanks

indigo granite
#

Hello!

Having some issues with "Attacking Common Services" -> "Attacking SMB."

Question 1: Used enum4linux-ng to list shares
Question 2: brute forced for user ||jason|| with provided wordlist, got password
Question 3: I logged into the share ||GGJ|| and downloaded ||id_rsa|| but the file is 0 bytes and ssh doesn't work for some reason. Command I'm using for SSH: ||ssh jason@10.129.xx.xx -i id_rsa||

I keep getting "Connection closed by..." error on the ssh command. the share has read permissions, which means downloading ||id_rsa|| should be fine, but I feel like the issue is with the file downloading.

glad smelt
#

Anyone know how long this is supposed to take?

cloud urchin
#

if you did it successfully it would be immediately after the "OK - Undetected" part

glad smelt
#

any idea why it wouldn't generate a flag? I did this:

  • Generate msfvenom shellcode
  • truncate all the \n
  • pasted the shellcode with no new lines into the recipe provided
  • made sure my C# code has the correct key, iv, and cyberchef encrypted shellcode
  • published release and copied over the exe
  • check ran ok - undetected
cloud urchin
#

when you created the project what did you choose?

glad smelt
#

.NET console app

rich galleon
#

still waiting on htb cpts report review going on 14 days now, biting my nails lol

regal shore
#

Im trying to use smbclient -U bob \\\\10.129.78.176\\users and its not letting type when it prompts for the password for some reason so I cant progress

storm elk
rich galleon
storm elk
#

Fingers crossed

rich galleon
dark hedge
#

patience friend

rich galleon
dark hedge
#

i think HTB can benefit from having some kind of notification of when your report gets reviewed or when it's planned to be reviewed

storm elk
#

Get your CBBH role if you passed, will get you more access

  • Use /verifycertifcation with your Cert ID & The name on the certification
regal shore
dark hedge
#

because sometimes the wait is agonizing.. also transparency

gloomy compass
#

I wanna report a broken link (and the new one) in one of the Academy's modules. What is the right channel to do that?

storm elk
hybrid pilot
#

X-Post from #cwes .. I'm a little lost on Login Forms from Login Brute Forcing. I got the hydra command up and running but it seems like I cannot get any valid username+password combination out of it. Am I not supposed to use the shown wordlists and find my own?

compact matrix
#

What does your command look like

hybrid pilot
#
hydra -I -L top-usernames-shortlist.txt -P 2023-200_most_used_passwords.txt 94.237.50.242 -s 33067 http-post-form "/:username=^USER^&password=^PASS^:Invalid credentials"
#

For what its worth here is the output:

DATA] attacking http-post-form://94.237.50.242:33067/:username=^USER^&password=^PASS^:Invalid credentials
[STATUS] 282.00 tries/min, 282 tries in 00:01h, 3120 to do in 00:12h, 14 active
[STATUS] 245.00 tries/min, 735 tries in 00:03h, 2667 to do in 00:11h, 14 active
[STATUS] 241.29 tries/min, 1689 tries in 00:07h, 1713 to do in 00:08h, 14 active
[STATUS] 246.58 tries/min, 2959 tries in 00:12h, 443 to do in 00:02h, 14 active
[STATUS] 245.92 tries/min, 3197 tries in 00:13h, 205 to do in 00:01h, 14 active
[STATUS] 240.07 tries/min, 3361 tries in 00:14h, 41 to do in 00:01h, 14 active
1 of 1 target completed, 0 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2024-12-17 05:12:53

Tried tweaking the command a little but the wait-time is a little annoying.

compact matrix
#

Can you send a ss of what question you on?

hybrid pilot
#

CBBH -> Login Brute Forcing -> Login forms

  • 2 After successfully brute-forcing, and then logging into the target, what is the full flag you find?
compact matrix
#

I will dm you to avoid spoilers

hybrid pilot
#

nvm got it

bright coral
viral slate
#

ABUSING HTTP MISCONFIGURATIONS : Skills Assessment - Hard

Hey guys!
Currently working on hard skills assessment, but unfortunately couldn’t find any solution at the moment.
Can I DM someone for a nudge please?

simple harness
#

Does anyone have good notes for SOC Analyst path

turbid sundial
#

why cant i send messages in general?

acoustic owl
turbid sundial
#

just saw it, sorry

dusty steppe
#

Hello, I need help with Attacking Authentication Mechanisms Skills Assessment.
I have tried the module provided script, jwt_tools and now i have written my own script.
Made my own private and public keys and also x5c certificate, none of these have worked so far.
Have not modified the payload, only played with the header, to see if i can forge tokens.
Also, verified that my signed jwt's are correct. Have read the forum and other posts here but they haven't made any sense to me.

analog dock
#

There’s a lot of tampered ones to try, but there’s one that works

#

And don’t forget the newline

dark hedge
willow sand
#

Intro to C2 Operations with Sliver > Skills Assessment. Not really sure what to get from that. Any other tips?
||You can try within the context of MSSQL$EXPRESS||

tranquil axle
#

I think it’s trying to say that you don’t need to privex for this step? It’s the question about taking over the 2nd dc right?

willow sand
#

yeah, 2nd DC

tranquil axle
#

It’s a pretty standard attack from child dc to parent dc

willow sand
#

isn't there a SID filtering in place?

tranquil axle
#

I don’t think so, at least in my notes I just wrote down “-519”

willow sand
#

||kerberos::golden /user:h4x /domain:sde.inlanefreight.local /sid:S-1-5-21-2027674183-2520992429-4195948650 /krbtgt:4dd3c61f97e887bb596c62b08b6c3def /sids:S-1-5-21-1091722548-1143476209-2285759316-519 /ptt||

tranquil axle
#

Try with Administrator user instead of h4x, I know there was a windows update in 2023 that made it so that the parent domain checks if the provided user/id exists in the child domain. Maybe it doesn’t like your made up account name

willow sand
#

works with Administrator

#

thanks

tranquil axle
primal patrol
#

network fundamentals >Netwrk Typologies>>>Tree 1)The tree topology is an extended star topology that more extensive local networks have in this structure.?

#

2)There are both logical tree structures according to the spanning tree and physical ones.?

#

anyone elaborate these two statement(bold)s in simple terms ?? I appreciate your response !!!!

analog dock
golden scroll
#

thanks

safe star
delicate light
#

hey guys i am stuck at an assessment on the AD part 2 can i ask for some info here or just in the forum ?

delicate light
#

Okay thank you

ruby pier
#

hello guys , i apparently solve the pass-the-hash section of the password attack module but stuck to resole some of my questions , an i tried to login theough pth by xfreedrp to david account then i am not ableto access \\dc01\david , but when i tried with mimikatz i can read that particular file , any explanation ...

coral hinge
#

What's protocol for when a task answer doesn't register the correct answer/it gets locked up? I've tried re-logging & re-starting browsers and it doesn't let me get back into answering tasks.

#

What is the command we need to run in order to display the 'ftp' client help menu? the prompt is *** -? and I'm familiar with man pages/help through the cli and have submitted ftp -h, but apparently i'm not smart enough for this one.

rugged linden
#

Hello, I am currently on the the Information Security Foundations learning path. For the setting up module, am I supposed to follow the website and spawn an instance and follow along? For example right now I am on the Organisation page, and they are going through toolsets for us to refer to in future. However, when I spawned an instance I couldnt find the .bashrc file in my folder as shown in the instructions

narrow oriole
#

hello guys i just started out with my academy via student subscription, im having trouble with this question for "Enumerate the hostname of your target and submit it as the answer. (case-sensitive)"

do you mind me asking where can i find help? this is from basic toolset course btw

long flint
#

hey guys, where can we see how many people have completed a module. in the badges section?

#

for future students, if you ever need help on the skill assessment for Advanced XSS and CSRF Exploitation, send me a PM anytime...

fading olive
narrow oriole
# fading olive The same command should give you the answer for both questions

┌─[eu-academy-2]─[10.10.15.91]─[htb-ac-1155776@htb-hj9mnlegq2]─[~]
└──╼ [★]$ nmap -sS -R 10.129.159.95
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-12-17 08:07 CST
Nmap scan report for 10.129.159.95
Host is up (0.18s latency).
Not shown: 993 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
110/tcp open pop3
139/tcp open netbios-ssn
143/tcp open imap
445/tcp open microsoft-ds
31337/tcp open Elite

Nmap done: 1 IP address (1 host up) scanned in 2.61 seconds

this is the scan result of what i did which solved problem one but i cant fight the "hostname" in it

fading olive
narrow oriole
fading olive
fading olive
glad smelt
cedar zinc
#

Module "Getting Started" > "Basic tool"... The answer is "SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.1" but how ?? the nmap result is showing "OpenSSH 9.2p1 Debian 2+deb12u3" Everything like nmap script & advance scan is showing "OpenSSH 9.2p1 Debian 2+deb12u3"... what am I doing wrong ??

fathom pendant
#

pay more attention to what's taught, not what's directly given in the example

cedar zinc
#

I have added the IP to the hosts file, even the ping is coming back

fathom pendant
#

you don't need to add anything to the hosts file

fathom pendant
#

there is the --script banner

glad smelt
fathom pendant
#

netcat is a good tool to grab banners as well, nc ip port

cedar zinc
urban elk
#

make sure you include the target port

cedar zinc
glad smelt
fathom pendant
#

:)

#

as @glad smelt stated the target you're given a PUBLIC_IP and port

#

meaning that there may be other services running on the target beyond the port given by htb

fervent hull
#

What can i do when the sublist3r give me back this errors
Virustotal probably now is blocking our requests
Google probably now is blocking our requests

fathom pendant
flat patrol
#

Same problem. I killed the process on port 80 and killed my session too, did you ever resolve this?

fathom pendant
#

80 is what's serving you the pwnbox in-browser

flat patrol
#

like nc -lvnp 8080?

fervent hull
fathom pendant
#

No idea why VT would be blocking sublist3r

fathom pendant
#

And php -S [tun0ip]:8080

#

If you're using the pwnbox, best practice is to learn how to bind services to an interface

#

This is due to the pwnbox having a public facing interface, so you'd be getting random requests from automated scanners

marble whale
#

module : password attacks
section : Network Services
hydra is not working to to crack the password for rdp, it is taking toooo long. I've also tried many more tools to do it but can't see the results. using the resources given by hack the box. Can anyone please help me in that or it will be very kind if someone please tell me the login of rd protocol please!!!

fathom pendant
#

Adjusting threads can also help

marble whale
#

yup i did like everything but it is not working

#

is there anyother tool you can recommend that can crack the rdp password

gray yacht
fathom pendant
#

If i spin it up and crack it in under an hour you owe me $50

marble whale
fathom pendant
#

@marble whale

#

resources used:

  • username.list
  • password.list
marble whale
#

which tool do you used ??

fathom pendant
#

hydra

marble whale
#

but mine is taking too long...almost 2 hours

fathom pendant
#

hydra -L username.list -P password.list rdp://ip -t 16 (it dropped it back down to 4

fathom pendant
#

i used the user/pass list from the Password-Attacks.zip from the [ Resources ] Button

fathom pendant
#

anyway you owe me $50 Kapp

marble whale
#

i am doing this using the openvpn connection file, does this even make some problem

fathom pendant
#

nope as long as you're not running the pwnbox at the same time you're connected to vpn it should be fine, i'd also make sure you only have one vpn connection

#

i'd have to use a shitty OS in-built to the Chromebook VM (Penguin)

#

but i can test it from there in a bit

marble whale
fathom pendant
#

also when running the command i got some hits that gave this info message: the valid one will be highlighted without that info

marble whale
#

i am getting this message on every attempts 😩

fathom pendant
#

you'll get a few hits like that 😉 (those combos may be valid for other services) but not all the hits will be that info

#

you can dm me, i'm stepping away for a minute but i'll sanity check when i'm back

wild sage
#

Is this password attacks?

bright coral
#

yes

fathom pendant
ancient niche
#

Good Afternoon

#

Someone can help me?

#

with wrappers in Burpsuite

#

i think burpsuite is not working well for me

delicate steeple
#

Hey guys could someone help me out

i am at Password Attacks
Pass the Hash (PtH)

Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.

i am at the part where i need to read the \DC01\david but when using the dir command i get the error The network path was not found. am i doing someting wrong?

gray yacht
ancient niche
#

Helloo?

cold star
#

Hey Guys, Is there a way to fully transfer my hackthebox attackbox network into my main attack machine so That I can ping dc and run attacks from my kali without needing to do ssh everytime. I have tried dynamic port forwarding but it didnt work for me

gray yacht
cold star
crude quiver
#

HI

#

AM IN NEED OF HOW TO CONNECT TO MY TARGET MACHINE USING SHELL

crude quiver
#

BUT ALL ACCOUNTS IN THE WRITEOUT ARE SECURED

cold star
safe star
#

Did you nmap it?

thorn urchin
#

I mean DCs dont normally respond to ping for one, and for two pings are icmp and dont get tunneled by proxies

crude quiver
#

YEAH

safe star
#

I sometimes test with nxc

crude quiver
safe star
storm elk
cold star
crude quiver
safe star
cold star
safe star
#

Because it’s not mapped to a real machine

safe star
cold star
safe star
#

Do you know the ip of the dc?

cold star
safe star
#

Try proxychains nxc smb <IP>

cold star
safe star
#

Also add -q after proxychains for quiet mode to remove all the output

safe star
cold star
# safe star It’s up

Ohkay But Why Can't I Ping the dc? When I run the petitpotam attack it runs succesfully But i dont get my blob on the listner side

thorn urchin
#

I already said why

safe star
#

The dc is probably blocking pings and it can’t connect back to you unless you make a port forward

thorn urchin
#

you cant port forward icmp either

cold star
safe star
thorn urchin
#

why petitpotam doesnt work is a different question that why ping doesnt work

#

if youre asking the second hoping to get an answer for the first youll get wrong advice

cold star
safe star
#

Yeah I put both answers in one message 😅

cold star
#

So I have to make a port forward?

safe star
thorn urchin
#

if petitpotam requires a callback(idr off the top of my head) then yeah youd need a port forward to catch the shell

cold star
safe star
#

You can get a callback but I don’t think u can do anything after

cold star
#

Not gotten any response

safe star
safe star
cold star
safe star
#

Can you do nxc ldap <IP> -M adcs

#

I don’t recall the dc having adcs on it

#

If it doesn’t, then the attack won’t work

cold star
#

just a sec

#

the images are uploading

safe star
#

Yeah there’s another dc you gotta test it on

#

Check the /etc/hosts file

cold star
cold star
safe star
#

No on attack machine

#

They have 4 different DCs

cold star
safe star
#

Attack the CA one

cold star
#

lemme try attack on 172.16.5.120

#

Nope it's not working with the ca dc either

safe star
#

It will be a lot easier to just ssh

cold star
safe star
#

your targeting the wrong one

#

Use .5.5

#

@pseudo kiln Apparently you can do it💀

cold star
safe star
#

Run ntlmrelay on the attack machine

cold star
#

ah leave it, I will stick to simple ssh only for this module

safe star
#

You got the base64?

cold star
#

it shows attack sucessfull not I havent got any base64

#

but in the attack machine witb simple ssh i get base64

safe star
#

Yeah it would be a ton of extra work to get ntlmrelay working through a pivot

cold star
safe star
#

Yeah that’s what I did

cold star
delicate steeple
#

Hey all i could use some help please

i am at Password Attacks

Pass the Hash (PtH)

the question is

Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

i setup the listener op 8001
do the command Invoke-WMIExec or Invoke-SMBExe cant get the listener to get through

fathom pendant
#

You used the payload generated from the revshell site?

#

Iirc thats what I did it's been a minute

delicate steeple
#

i did yes

fathom pendant
#

Did you encode it in base64? (Might need to select advanced) iirc sometimes it extra encodes the payload from expected

delicate steeple
#

yesss

fathom pendant
#

I mean is the option at the bottom "encoding" say "none" or "base 64"

#

It should be "none"

delicate steeple
#

its of sh and encoding is none

acoustic sparrow
#

i need help on the first question on the skill assesment (USING CME) ... pls nugget

fathom pendant
#

[ms01]

delicate steeple
#

i did yes nc in a separate cmd > ip is 172.16.1.5

void hemlock
#

Can I ping someone for Advanced Deserialization Attacks - Skills Assessment

fathom pendant
delicate steeple
#

i just got it

well i redid everything
it was in the reverse shell generator

i did something wrong there

i saved the codes in my notepad that i used and then copy all of them and checked if they were the same they were not

this new one worked

#

thanks

fathom pendant
#

👍

delicate steeple
#

and i did everything in powershell

azure dust
#

I think I found a broken activity in Academy

fathom pendant
#

9/10 times though it's user error

mortal locust
#

Hello

I'm doing a php filters module in File Inclusion.

I am able to get the configure endpoint using ffuf, and I'm also able to get the source code using the command provide, but I'm not able to exploit the LFI initially.

I have tried bypassing the filters as well.

Can anyone help me?

#

Like as per the workflow of LFI, we usually get /etc/passwd file to know if the webapp is vulnerable or not!!

I am not able to exploit it!!

quiet trout
#

does MSF work with these vhost demo walkthrus on htb academy? im doing a module discussing msf fundamentals and they're doing an eternal blue attack, but they specify an ip without a port... im unsure if this will work or if theres extra options or syntax that must be used?

fathom pendant
#

Also the target given may not be vulnerable to Eblue

quiet trout
#

Sure, I realize its just a demo and im trying to follow along and all that

fathom pendant
#

Rule 0: never assume anything

#

You won't always be able to follow along 1::1

#

As sometimes the point is just to showcase a thought process

quiet trout
#

but maybe the disconnect im struggling with is if this ip is serving multiple vhosts or containers or however its doing it, how will it detect 94.237.254.254:42065 vs :42069

#

assuming it was possible in the first place (which i wont do here but just for the examples sake)

fathom pendant
#

It's usually serving mylt

#

Multiple

#

And your only scope is the given port

quiet trout
#

I think I understand that but not enough about how services are "served" on setups like this

fathom pendant
#

They are on containers

quiet trout
#

how does 94.237.254.254:445 serve MY target vs another target with the same ip and diff prot?

#

assumign that that demo did work on the target

fathom pendant
#

Dude

quiet trout
#

is what im asking make sense, i know theres a lack of technical understanding here, if you'll humor me

fathom pendant
#

I'm only going to say this one more time: do NOT attack ports other than what's given

#

Don't worry about what other ports are doing

quiet trout
#

gosh gosh gosh

fathom pendant
#

As the ONLY in-scope thing to attack is the port given

quiet trout
#

I may not be explaining this correctly

fathom pendant
#

They are running a service running on that port for the exercise

#

It's nothing overly complex

quiet trout
#

thats http i want to say, this is a general section of the module that goes thru different demos gobuster, curl, msf, etc

fathom pendant
#

It doesn't have to decide any logic

fathom pendant
#

Any service can be running in any port

quiet trout
#

Yes, i understand that. Look this may be a better way to phrase the question... setting aside the academy module and the target box... if i had a lab env with 3 machines containerized or w/e with the same IP and diff ports, and they were all running smb on all containers they would need diff ports for smb on each container they couldnt all use 445 right?

fathom pendant
#

The main thing when you're given an ip:port is that you're not expecting to run a callback exploit i.e. xss

fathom pendant
quiet trout
#

and if not they must have diff ports?

fathom pendant
#

Yes

quiet trout
#

ok thanks thats what i was asking.

fathom pendant
#

A service cannot run on a port in use

#

This is very very basic knowledge, I fear

quiet trout
#

no i get that

#

its just that i have very literal familiarity with containers and was under the impression that they were isolated and you could, for example, serve the same sevices on the same ports within one device with multiple containers... and it would be routed via some other means (perhaps?)

#

kinda like how one writes routes in node or w/e some type of special logic to handle that

fathom pendant
#

No

#

You're talking about port forwarding shenanigans, you'd need to set it up for that but that requires some other circumstances

#

Like subdomains and things like that

#

But you can't just start a service on a busy port

quiet trout
#

ok thanks thats helpful

fathom pendant
#

Web server stuff is much different though

quiet trout
#

Ok if you'll humor me maybe another silly questions just so i understand this fully... when we're on just for examples sake, a module doing enum and it says run a ffuf on this ip:port , then login to the ftp on port 22 with anonymous access... we're scanning a container on a port, but the ftp on port 22 is the same ftp that myself and anyone accessing the same target ip (but diff port) would have access to?

fathom pendant
#

Ftp would be 21 by default

quiet trout
#

yeah my bad, i meant 21

fathom pendant
#

You're not gonna be given a scan of pub_ip:port then told to log in to a service on default port, the service would be on that pub_ip:port

#

Anyone can access any of the open ports on the public server

quiet trout
#

oh, right, ok i think im just seeing something that isnt really there about the way htb serves up these target machines

fathom pendant
#

The containers have the default ports heavily locked down

quiet trout
#

it might have to do with my lack of familiarity with containers or however these are served and other things

fathom pendant
#

Well with the public ip you're not meant to get reverse shells or call backs

#

Everything is done clientside or server side without the need to have it run reverse_shell.php [because it can't reach out to you]

quiet trout
#

i think i get it now

#

i guess im still just scratching my head why it would deliver a target with ip:port, when maybe the module or activity doesnt require it, perhaps due to simplicity of the target vm logic?

fathom pendant
#

You're overthinking the examples

#

It's that simple. Don't look to the examples as a pure "just do this lol"

#

And actually understand the context to them

quiet trout
#

Im with you, i just like to follow along with the walk thrus/demos when i can

fathom pendant
#

Unless you start the target on your own, get out of that habit

#

Some modules you can, some modules you can't. Identifying the thought process behind why they used an exploit is more important than the actual exploit itself

quiet trout
#

do you have any simple suggestions for how to go about exploring some of these topics like the eternal blue (that are not researchable on the target, in the module) that might be a little less hassle than setting up a lab environment specifically vuln to the attack?

fathom pendant
quiet trout
#

is there maybe some outside resources or like a vm repo that have pre-configured vms or environments that would for example be able to be quickly downloaded and spuin up for resarch?

fathom pendant
#

Vulnlab comes to mind, GOAD

quiet trout
#

Whats GOAD? "GO and discover"?

fathom pendant
#

But it seems you're kinda missing the point

quiet trout
#

No im with you 100% im just trying to square my expectations and how to go about making the most of the info

fathom pendant
#

If it's important the section itself will teach you about it

#

Iirc one of the modules in the cpts path has a section purely for Eternal Blue

quiet trout
#

i see

fathom pendant
#

Also GOAD == Game of Active Directory

#

The biggest thing about learning from the modules is understanding what it's trying to teach you. And not missing the forest for the trees

quiet trout
#

thank you that github looks helpful

fathom pendant
#

It's why reading the info surrounding the examples is far more important

#

Often the reading explains the process of discovering, searching, exploiting

quiet trout
#

im with you

fathom pendant
#

And the questions are applying that reading to a slightly different scenario

#

Engaging in critical thinking to link the process to the practice

rustic sage
#

can someone help me

dark hedge
#

with?

rustic sage
dark hedge
#

nope

#

ask here please

rustic sage
#

how do i make a webhook

dark hedge
#

for what

rustic sage
#

for things

dark hedge
#

like?

rustic sage
#

why do u needa know

dark hedge
#

i don't see the need to be secretive about it. but your question is off-topic anyway, this channel is for HTB Academy module discussion

rustic sage
#

if you knew you'd have a few things to say

wary plover
#

so its obviously with malicious intent lmao

rustic sage
#

nobody said that

dark hedge
#

yea.. most likely for malicious purposes

#

so we're not gonna help you with that

rustic sage
#

how is a webhook associated with malicious intent

dark hedge
#

if you don't want to tell us then clearly there's something to hide, even though this server is for learning hacking

harsh gorge
#

It’s a simple ass question

dark hedge
#

if you don't want to tell us, then we're just gonna have to assume it's for malicious purposes

rustic sage
#

if it's associated with hacking how is malicious intent wrong in this group?

harsh gorge
#

Are…you fucking stupid

dark hedge
#

because this server is dedicated to learning ethical hacking

#

anyway, convo ends here, you won't find what you're looking for here

rustic sage
#

hacking is hacking at the end of the day malicious or not if ur not gunna help then js say that tf

wary plover
#

we already said we weren't lol

#

lol

#

@dark hedge you can show him the door lol

rustic sage
#

"can you show him the door" 👆🤓

lusty thicket
harsh gorge
#

he got banned

stark grail
#

I need urgent help

dark hedge
wary plover
#

calc kek

#

remove this lol

dark hedge
#

woops, forgot to remove that, thanks

wary plover
#

all good

stark grail
#

Sorry, I was in the wrong section. I would like to know if anyone knows how to get Gmail passwords. I forgot and I need it urgently.

dark hedge
#

click "Forgot password" maybe

#

this isn't gmail support

wary plover
#

only way to recover your account is so contact google

glad smelt
stark grail
#

I can't reset it so I'm asking for help.

dark hedge
#

we cannot help, as we aren't Google. please contact Google

stark grail
#

any brute force program?

dark hedge
#

NO. contact Google for help

gray yacht
glad smelt
viral snow
#

Halp! I'm in Kerberos Attacks-RBCD Overview & Attacking from Windows.

I'm using Get-DomainComputer, but I'm getting a message stating it's not recognized as the name of a cmdlet, function, script file or operable program.

What do? How do I fix this?

safe star
#

Did you import powerview correctly?

viral snow
safe star
#

what about get-netcomputer?

viral snow
#

I've noticed that AD is very unstable.

minor locust
#

Bro

#

did I read tha right thank god he got banned..

#

that*

#

Bro what has been these interactions someone who didn't realize unethical hacking is bad and not accepted, then we have someone looking for password reset in a hacking server. Sounds like a setup glad he's gone

#

@harsh gorge how do i use general i have no perms sorry to link ur name

#

😦 back to depressing code until I get chat access

#

been here a few

cloud urchin
#

chat access is immediate

minor locust
#

Look at the top sorry just got back

ocean night
#

What a clear answer, thanks

#

🤦‍♂️

#

Welcome back

minor locust
#

You can simply read it it's like a second of scrolling

ocean night
#

Forget it

harsh gorge
minor locust
#

I just got back my backs in extreme pain idkw aht u expect

#

I'm sorry im not helpful for real

ocean night
#

nah it's fine

minor locust
#

how did u get that

#

the icon next to name

ocean night
#

webhooks, ok

minor locust
#

the other thought it was google support

ocean night
#

they asked in a strange way, but maybe they thought they were something they are not 🤷‍♂️

minor locust
#

I am talking to the air about to icons here. I'm confused but maybe it's something that nitro buys

#

idk never done that

ocean night
#

Check #welcome - to chat in other channels, you need to link your HTB account

harsh gorge
#

Yep

ocean night
#

You do not need Nitro

minor locust
#

Ok sweet I do appreciate that I owe you for that one I was interested seen a few of them earlier

ocean night
#

Ok

minor locust
#

Hack the box has certs?

ocean night
minor locust
#

I joined this not that long ago really I have used the site tryhackme i think it is. I have to look into it

#

You'd say its better thancodecademy?

#

Because I'd be down to get those certs next

ocean night
#

I'm biased

harsh gorge
cloud urchin
#

as far as i know code academy is for programming. the htb certs are geared toward blue/red teaming stuff

minor locust
#

True man I wanted to get offsec courses but I saw prices yikes

#

Ok bet bro Ima look into that

cloud urchin
#

you can do a google search and find answers, but i'd say htb has the best content by far out of all of the vendors

minor locust
#

Cool that is 3 who vouch for it

harsh gorge
harsh gorge
#

I’ll take another look but I don’t think they have any

minor locust
#

How much hours are some of the courses to see a comparison? Easily over 100 I'd hope.

#

If it's more than codecademy that'd be dope

harsh gorge
#

I think the bug bounty path is roughly above 400 hours

minor locust
#

I'm definitely in now

#

Easily more hours

cloud urchin
minor locust
#

I have sped run Python and web dev on codecademy in 20 days

lusty thicket
minor locust
#

I would love to participate in that this is dope

lusty thicket
minor locust
#

I've went through a rough patch being hurt by significant others and past 4-5 months I have spent analyzing code. I am excited to get this all started tomorrow I may check pricing

#

my backs been in extreme pain a week since i broke up a fight

cloud urchin
#

if your interest is coding code academy may be better for you, i don't know much about code academy but i know htb isn't really geared toward programming, it's more offensive/defensive computer security

minor locust
#

Im interested in cyber sec as well sadly

#

... Lol I like tryhackme i did that one before but never the paid side of it

ocean night
#

Aye got that

#

Well HTB has lots of free content

#

both on Academy and the Labs

#

Give it a go if you want 🙂

minor locust
#

Cool I am here for Cyber Security lol sorry i made a weird impression lmao

ocean night
#

It's all good honestly

minor locust
#

I just was asking if the certs are maybe worth more

#

I been doing codecademy for like 20 days but i didnt look into all options

#

I thought it would teach that as well it's code basically

ocean night
#

You in college or anything?

minor locust
#

No I dropped out of high school i dont have a ged im 26

ocean night
#

Ah ok, was just asking due to plans we have for students

long kestrel
#

Hello, I am on the nmap hard lab and found ||port 5000 ibm-db2|| is open but I am unable to connect with ncat to find the version, and I have not been able to get the version with any nmap scripts I have tried so far

minor locust
#

i been programming foor 10 years self taught just never took it serious until recently after i was hurt by an ex well ex now

#

I started speed running codecademy lmao did exams before some courses in stuff I knew

ocean night
minor locust
#

I don't know if software engineer or Cyber Sec I am trapped in a cycle of asking which do i do

ocean night
#

The module, and sections should provide all you need to solve the assessments.

fathom pendant
#

Security Engineer kappa