#modules

1 messages · Page 365 of 1

quasi wave
#

I forgot to write it down

#

is it previous one?

stone gorge
#

Yes... and rule #1... memo all credentials, always

quasi wave
stone gorge
#

just use module search. You'll find it.

quasi wave
#

ok

#

but its in the same module no?

#

kira is not the name of the modlue

iron oar
#

yes all the modules are independent of eachother

quasi wave
#

its the password attacks module I'm doing

#

so I don't quite understand

stone gorge
#

Same module, previous or same section... I'm fuzzy.

#

Been a couple weeks.

quasi wave
#

this section only has like one question

#

so I don't get how to solve this one

#

ok is anyone available tonight?

#

or like to DM?

iron oar
#

what section are you on?

#

its usually* as simple as going through the previous sections and ctrl + f for "kira" in this case

quasi wave
#

Password Attacks Module and the section is Protected Files

quasi wave
#

hold on someone DMed me never mind

stone gorge
#

My recollection is that in the material provided, they showed you Kira's PW. You need to use that to get her id_rsa file... pretty straightforward.

teal cape
#

So what ended up happening was I needed to comment out sock4 in config file since i ran socks5 in meterpreter, swear i did that hours ago and didnt work then but when i tried it again it worked afterwards lol

gilded rune
#

Bro, I'm still not getting it. I scanned for the right port and found a vulnerable service running (Apache 2.4.41) but there is no exploit for that

Pls how do I go about it now?

tranquil axle
#

Check the website itself

stone gorge
#

which is why I pointed out proxychains.conf update as well...

gilded rune
fathom pendant
quasi wave
#

I know I found it

#

never mind someone helped me get it

stone gorge
#

Same Empire error even happens in the web-based PwnBox hosted by HTB themselves.

#

Executing powershell-empire server
Traceback (most recent call last):
File "/usr/share/powershell-empire/empire.py", line 11, in <module>
import empire.server.server as server
File "/usr/share/powershell-empire/empire/server/server.py", line 14, in <module>
from empire.server.common import empire
File "/usr/share/powershell-empire/empire/server/common/empire.py", line 18, in <module>
from empire.server.core import hooks_internal
File "/usr/share/powershell-empire/empire/server/core/hooks_internal.py", line 5, in <module>
import jq as jq
ModuleNotFoundError: No module named 'jq'
┌─[root@htb-0klzeaiovo]─[~]

#

It lets you install jq, but then still gives the same error.... very frustrating. THIS is one tool that I loathe... it has never ever worked for about the eight years that I have tried to use it off and on...

#

tried that... that is starting it from the menu... you have to run as root.

#

Tried that...

#

Same thing on Kali

#

Exact same error

cloud urchin
#

i remember not being able to get it to work so i just moved on

stone gorge
#

It's a part of the CME module in the CAPE path, so not a move-on thing. It's something that HTB should provide a work-around for.

cloud urchin
#

the cme part is just to uploadi/install i think, you can do the same with sliver for example

stone gorge
#

There is a section specifically on this ... and better to fix things than just move on... down the road I know I will need C2

cloud urchin
#

yeah but it's a cme module, not a c2 module

stone gorge
#

Sliver is for port-forwarding. Not C2.

cloud urchin
#

no sliver is a c2

stone gorge
#

Okay... cool

tranquil axle
stone gorge
cloud urchin
stone gorge
#

Right... just seeing that. Always just used it as a port forwarder on a target.

#

I am sick and tired of Empire... every f (rea?)cking time! Never works!

cloud urchin
stone gorge
#

Did that... multiple times on everything... using their installation instructions.

#

Different module but same kind of error.

#

Debian, Kali, Parrot, Parrot-HTB version... nothing. I am doing what you did. Moving on. Reading Sliver C2 docs now to vent the frustration.

#

I know that sliver works because I use it all the time.

gilded rune
safe star
#

oh i see

naive cedar
#

is it allowed to share account with others to reduce cost for tier 3 modules?

naive cedar
#

oke

ocean night
#

You'll just end up not being able to work on the tasks anyway, as connections are limited to one per account.

naive cedar
ocean night
#

..and Thor would not be pleased

naive cedar
#

i hate thor, i love iron

storm elk
#

Hate is sucha strong word. But Ironman > Thor

waxen totem
#

I just started doing academy, what module does thor and ironman come in?

storm elk
#

The getting started on Discord

dark hedge
#

Cracking into HTB Discord skill path

livid pelican
#

Okay

finite abyss
#

Anyone unlocked Tier 4 module , could you confirm Show solution is available like it is present in Tier 3 modules for Gold annual subscribers.

acoustic owl
#

There is currently no annual subscription that includes Tier IV modules. Therefore no solutions are available.

spare tendon
#

Hello all,

I've been stuck on it for a few days now, on the Attacking Web Applications with Ffuf module, and on the Skills Assessment - Web Fuzzing chapter.
and on the question. Try fuzzing the parameters you identified for working values. One of them should return a flag. What is the content of the flag?

I would like to know the list of words you used.

acoustic ember
#

Hi there, I’m also stuck on the Attacking Web Applications with Ffuf module - skills assessment question 3

#

I clicked on the “show solution” button and the solution did not gave the correct output from the answer sheet

undone cypress
#

NoSQL Injection Skills Assessment II
Hi, I'm stuck on resetting the token, the script that I have can't generate a reset token in any way(
What am I doing wrong there?
Who managed to do this, maybe I'm missing something in my script?

acoustic ember
#

The -mr flag is failing for me, I copied the exact command and I get a “dquote”

#

Did hackthebox really vet through their own solution?

undone cypress
analog dock
acoustic ember
#

I followed the solution step by step but it did not worked for me

#

I’m getting a “dquote” from the exact command provided by hackthebox

undone cypress
undone cypress
acoustic ember
analog dock
#

Similar to what you’ve done in the ssji section

undone cypress
undone cypress
analog dock
acoustic ember
undone cypress
# analog dock I don’t know what you’re talking about

I understood it so that we need:
1 - to generate a password reset token.
2 - The script should generate it for us.
3 - Then I apply it on the "reset" page
4 - and change the password for the user.
5 - Then I enter under it.
In the second step, I have a problem)

undone cypress
analog dock
#

Yeah so you can see the difference in response size

#

Then you just dump the token with a payload similar to what you’ve done in the ssji

#

But you don’t need a this.username.match , this time you need this.token.match

glad patio
#

Hello, everyone! I can't understand why is the minimal offset in this EternalBlue rule ||is 4.||
https://academy.hackthebox.com/module/226/section/2415

In the /home/htb-student directory of this section's target, there is a file called local.rules. Within this file, there is a rule with sid 2024217, which is associated with the MS17-010 exploit. Additionally, there is a PCAP file named eternalblue.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to MS17-010. What is the minimum offset value that can be set to trigger an alert?

I have found a solution in the internet ||and 4 is the correct answer,|| but I don't understand why because none of the payload seem to match the content string from 4th byte... and I couldn't really find anything that would match from 9th byte too.
Suricata rule: content:"|ff|SMB|33 00 00 00 00 18 07 c0 00 00 00 00 00 00 00 00 00 00 00 00 08 ff fe 00 08|"

I changed this rule's offset to 4 and got alerts on the following ports (I didn't get alerts before changing), yet when examining the logs in Wireshark they don't seem to match the content (???).

glad patio
ornate smelt
#

hello guys

#

i finished all the seccions of pivoting module and i am stuck at "socks and rdp tunneling"

#

the questing is "Use the concepts taught in this section to pivot to the Windows server at 172.16.6.155 (jason:WellConnected123!). Submit the contents of Flag.txt on Jason's Desktop. "

#

when i rdp to the pivot host and i ping the internal given ip i get destination is unreachable

#

any idea

bright coral
ornate smelt
#

They r both on same subnet I tried to ping it but there is no reply

#

And I already did the steps fingerguns

sharp urchin
#

hello guys, did any1 try connecting the ovpn of hackthebox using windows wsl? its not working for some reason

bright coral
long kestrel
ornate smelt
#

The provided ip is connected to other NIC and that interface is 255.255.0.0

bright coral
tranquil axle
glad patio
dapper moth
#

I'm revisiting the Kerberos Attacks Module, anyone for a quick DM on the Unconstrained Delegation Section to check some of the commands in the exercise? I'm getting the auth but krbrelayx isn't extracting the TGT

long kestrel
#

I'm really impressed with the modules so far. I'm just doing stuff accessible from the student subscription and learning a lot that wasn't covered when I did GPEN

#

very good value getting this much info organized like this for $8/mo compared to the $9k SANS course

tranquil axle
#

It could be any of the yellow packets in your wire shark screenshot, you will see that they all in the payload section start with 4 random bytes, then it has the common header of 0xFF followed by “SMB” in ascii. The next hex value is the command, in your rule you are looking for 0x33 which apparently is “SMB_COM_TRANSACTION2_SECONDARY”. I can see in your screenshot that you have a few of those in the yellow lines

#

What’s important with the offset is that you don’t count the tcp header in it, it’s the offset starting at the content section of the packet

glad patio
granite osprey
#

Hello, I need a hint for module Password attacks - skills assessment - level 2.
I am logged as Jason on the target, and see another user who holds an ssh key. I have run hydra for more than an hour with that username (and the [mutated] password list given as a resource), but without success. I now want to steal his ssh key for offline cracking, but I need to escalate Jason's privileges, and I don't see how to do it...

opal nexus
granite osprey
#

I see ftp and ssh services only

#

sorry ssh and smb (ftp was for level 1)

opal nexus
fathom pendant
#

I don't recall needing to crack the second user password

granite osprey
fathom pendant
#

It was just there

opal nexus
gray yacht
granite osprey
opal nexus
gray yacht
granite osprey
signal pike
#

Does someone know if the gold annual subscription you pay all the price at once, or you can pay it over time, over the year

bright coral
uneven pecan
#

Hey, has anyone completed the final assessment on the advanced XSS and CSRF module? I feel I’m on the right track but have hit a road block and would love a nudge

tranquil axle
#

And you also see that there are 4 bytes before the ff, which is exactly the offset it was looking for. These 4 bytes are probably not deterministic and change with every request, but everything after stays the same for this specific attack

proper ravine
gray yacht
sly kelp
#

Is there going to be any Mobile Pentesting path ?

acoustic owl
#

So far, HTB has not announced anything like this. Also, there are currently no modules that could indicate such a path.

placid edge
#

So im kind of struggeling with the Whitebox attacks module on Remote Code Execution(https://academy.hackthebox.com/module/205/section/2343).

I have setup a localhost debugger and inspecting the Object values however sumitting my payload:

{"__proto__":{"deviceIP":"127.0.0.1; whoami"}} // Gets caugh in WAF

And

{"constructor.prototype":{"deviceIP":"127.0.0.1; whoami"}}

Bypasses the filter, however the object values just looks off to me, and i dont know if i am doing something wrong here:

{
  username: "test",
  id: 1,
  password: "a",
  deviceIP: "127.0.0.1",
  "constructor.prototype": {
    deviceIP: "127.0.0.1; whoami",
  },
}

The constructor.prototype gets stored as a object inside the User Object with its key and value pair.

#

i've never done prototype pollution before so i feel like i have 0 idea of what im trying to do

sick depot
#

For some reason i cant rdp into windows box on the living off the land section in pentester pathway a black screen comes up then it goes off

storm elk
#

Press enter

#

It’ll do magic

sick depot
#

🤣

#

Never had it do that before

storm elk
#

😄

quiet trout
#

@storm elk is this ok to post with my Q?

#

very basic nmap stuff i have a Q over

fathom pendant
#

Just ask your question

cloud urchin
quiet trout
fathom pendant
# sick depot 🤣

It can't draw the corporate AUP screen. It's an issue with xfreerdp, haven't seen it on remmina or rdesktop i don't think

quiet trout
#

the dialog suggests that forcing it with both switches is done to force both scans, but i only see the one

fathom pendant
#

-sn just disables port scanning

#

By default nmap does ARP scanning

quiet trout
#

i get that, but why are ICMP pings being forced but not returned in the output?

#

oh i guess i should just assume that in the output and not see teh ARP who/has as a red herring? or what?

#

maybe i need to traffic check in wireshark?

fathom pendant
#

It could be that the icmp request is being dropped

#

¯_(ツ)_/¯

#

Could also just be arp came back so it didn't send icmp

quiet trout
#

ok

#

ill have to check in wireshark i guess to confirm

#

ty @fathom pendant i certainly appreciate your help on the reg.

thorny pebble
#

Hello all! Is there anyone else having issues running the Windows VM on this module https://academy.hackthebox.com/module/87/section/885? Ive been able to install all tools, but when Im trying to install a linux distro I get this error:
Please enable the VIrtual Machine Platform Windows feature and ensure virtualization is enabled in the BIOS.
Ive got the Virtual Machine Platform Windows enabled and I tried enabling Virtualized AMD-V/RVI on VMWare but I get this error:
Virtualized AMD-V/RVI is not supported on this platform

Im a beginner, this is so hard to troubleshoot 😦
Ive followed these links without any success:
https://askubuntu.com/questions/1459065/virtual-machine-platform-windows-feature-and-virtualization-in-bios-is-enabled-b
https://www.reddit.com/r/vmware/comments/k7hd4z/virtualized_amdvrvi_is_not_supported_on_this/

Btw Im not completely sure if I just skip this part and keep going with the rest of the setting up section...

quiet trout
#

that may not be supported by your distro/hardware/whatever

#

if you have ubuntu on baremetal and you have a windows vm that you're using for testnig, then make a separate vm for kali, within the same hyper visor, not a nested hyper-v in windows vm

cerulean hinge
#

Hello, I have a question based on the Introduction to Active Directory module.
I'm trying to setup my own DC and to modify some stuff. I'm currently working on my audit policy however I observe that the audit policy I setup from the Group Policy Management is not the same as what I have on my DC if I run auditpol /get /category:*.

It seems that the GPO is overwritted but I don't know by what...

thorny pebble
quiet trout
#

ok, yeah, could be the iso dunno. but if you know how it should work and you've done it before prob best to move on

fathom pendant
#

You don't have to set up your own vm, also you'd need a windows server ISO to have it run as a DC iirc

quiet trout
#

gpresult /?

thorny pebble
# quiet trout ok, yeah, could be the iso dunno. but if you know how it should work and you've ...

Well, Im a super noob. Ive worked as dev for some years but I never needed VMs and stuff, so Im taking the modules step by step so I dont mess anything up. Im following the Information Security Foundations path and this is the third module of that path. It also mentions the idea of paying for a VPS (I also have 0 experience using it). I dont know if Im in the right path for a noob and if it makes sense to setup the windows vm or the VPS when I have 0 knowledge about any other cybersecurity concept

cloud urchin
#

vm better if you have a machine that can run a vm

quiet trout
fathom pendant
#

You don't need a vps

thorny pebble
#

Ive got a ParrotOS VM already up and running. Maybe I should jump directly to the next module (Linux Fundamentals) then?

#

Im running vmware

quiet trout
#

Does vmware give you type-1 and type-2 vms?

#

BIOS/UEFI? that might be the prob

#

just off top of my head

#

its really not worth digging into if you want to move on with the content (unless you're deadset hung up on resolving it, but itssomething config related, guaranteed) if your parrot vm works you're good to go, figure out the windows stuff later

cloud urchin
quiet trout
tacit bay
#

In the MSSQL, Exchange & SCCM attacks - Introduction to Privilege Escalation on MSSQL - when enumerating the webshop users & roles, it indicates that there is another db_owner - this is equal to NULL
"the name is left empty since our user does not have access to this information."

It then goes on to say "we discovered our login (ws_dev) can impersonate ws_user" - the previous screenshot only shows db_owner:NULL, how are we inferring / determining that ws_user has the db_owner role?

cloud urchin
#

for AMD it's called AMD-V and Intel it's called Intel-VT-x

rotund thicket
#

Attacking Web Applications with Ffuf Module's Skill Assessment Question 3 seems broken, even if i submit the correct answer it is showing as incorrect.

cloud urchin
rotund thicket
#

my bad should have seen it

quiet trout
rotund thicket
#

lol

tranquil axle
harsh gorge
#

my ass needs to do the skills assements for each module again

quiet trout
harsh gorge
#

the funny thing is i didnt take notes on them

#

so even i dont remember how I solved them

cinder tinsel
#

hey everyone,

i am doing skills assessment for crackmapexec module and i got stuck after getting the user N**** creds. i know i can access the share on dc ,but not able to download anything due to insufficient permission. i must be missing a step. any nudges please?;D

tranquil axle
cinder tinsel
#

funny it says permission denied

tranquil axle
#

Are you able to write in the folder on your drive?

cinder tinsel
#

yes

tranquil axle
#

Mb you don’t have permission to dl because you can’t write? lol

cinder tinsel
#

lol

tranquil axle
#

nick account right?

cinder tinsel
#

yeap

#

after HOURS. now worked....

#

thanks man! for some reaso now it worked

sudden spire
#

Has anyone done 'heal' on htb?

tranquil axle
mighty sierra
#

Hey guys Im Adrian

#

I have a problem with my silver

#

`sliver (FRIENDLY_GRAMMAR) > shell

? This action is bad OPSEC, are you an adult? Yes

[] Wait approximately 10 seconds after exit, and press <enter> to continue
[
] Opening shell tunnel (EOF to exit) ...

bash -p
id
/bin/bash
export TERM=xterm
ls
ls
id

`

#

I created a implat poiting to my host then I got a back connection but when I tried to create a interactive shell session it seems like the is stuck

#

sliver (FRIENDLY_GRAMMAR) > sessions

ID Name Transport Remote Address Hostname Username Operating System Locale Last Message Health
========== ================== =========== ====================== ========== ========== ================== ======== ======================================= =========
57bf091d FRIENDLY_GRAMMAR http(s) 10.129.229.147:45184 dmz01 root linux/amd64 en-US Sat Dec 21 21:31:30 PST 2024 (1s ago) [ALIVE]

sliver (FRIENDLY_GRAMMAR) >

#

sliver (FRIENDLY_GRAMMAR) > use

? Select a session or beacon: SESSION 57bf091d FRIENDLY_GRAMMAR 10.129.229.147:45184 dmz01 root linux/amd64
[*] Active session FRIENDLY_GRAMMAR (57bf091d-5553-4207-8e34-1b80ee632b29)

sliver (FRIENDLY_GRAMMAR) > shell

? This action is bad OPSEC, are you an adult? Yes

[] Wait approximately 10 seconds after exit, and press <enter> to continue
[
] Opening shell tunnel (EOF to exit) ...

shrewd remnant
#

hey

#

I need help

nocturne ridge
#

What is the API key in the hidden admin directory that you have discovered on the target system? def For_Future_Generation_of_Hackers(): print("Just follow the instruction. There is nothing like Enumeration. Hint: vhost, gobuster and dns. Once you guys found something, Start Enumeration again, Happy Hacking, Over and Out, TheUnknownPirate.") For_Future_Generation_of_Hackers()

cinder tinsel
#

hey,

any hint to get the last flag for crackmapexec skills assessment?

tranquil axle
#

If you got the ccache and know how to use it you are basically done. The user is pretty powerful

cinder tinsel
#

it does not run any command on dc tho

tranquil axle
#

It can dump secrets tho

cinder tinsel
#

hm.. ntds...

tender nimbus
#

Hey guys, i'm trying to do the python3 module but when i want to run my script i alwyas receive this error (from my own box and from the htb instance) cane someone help? I already tried to install uninstall BeautifulSoup it gives me an error and says the "new" one is beautifulsoup4, and this modul is already installed

cinder tinsel
carmine hill
#

uhmm,i couldnt find netcat package on chocolatey,what should i do?

safe star
#

get it off github or use linux

#

what module?

carmine hill
#

i'm new i'm doing setting up rn

safe star
#

oh yeah, then im not sure

#

but i highly suggest using your own linux vm or pwnbox for the academy, they have the tools pre-installed for you already

carmine hill
#

like...it has npcap and nmap ,so i dont know which one to install

#

i have a laptop for my kali linux,i'm just trying to setup for my window laptop

dark hedge
#

if youre setting up a windows vm, you don't really have to worry about it

#

for now, a linux vm will be sufficient

carmine hill
#

thanks u guys,i will try on VM

zealous rune
#

Hi I need a hint on skills assessment part 2 for Attacking Active Directory module. I am on this question : "Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain. ".

So far I have obtained a foothold in the domain, got a domain user and used that user to enumerate a list of users, groups, obtain bloodhound data. Also I have tried password spraying. Also searched for scripts in sysvol and gpos.

safe star
#

Use the passwords used in the example

proper ravine
#

Hi everyone! Anyone up for a quick brainstorming session on the "Injection" skill assessment? Feeling a bit stuck and could use some ideas

fathom pendant
proper ravine
fathom pendant
#

Well I'm not available to chat

zealous rune
proper ravine
fathom pendant
#

Also contemplating making DMs paid depending 🤔 but I'd need access to my computer before committing

zealous rune
safe star
#

Yes

zealous rune
#

ok spraying with one of the passwords i found in one of the module sections. thank you for the hint

#

damn kerbrute is fast

#

hmmm i tried two of the passwords used in the password spraying section, didn't get any hits against the user list i got by enumerating the domain users through ldap

zealous rune
#

no but maybe my user list is not good or something. I just checked the solution and it should have worked

#

I'm an idiot. I wasn't using the right file for the user list. I have two files named very similarly. user.list and user.lst. I needed to use user.lst

#

but now the instance died 🙂

#

time to start again

#

it's why kerbrute was coming back so quickly i guess

#

unblocked thank you for the hint

cunning frigate
#

Probably the hardest module Ihv completed so far

#

The skill assesment was incredible

sudden spire
#

I have done the identify. But requires admin for support.

#

Has anyone done heal though

cloud urchin
carmine hill
#

hmm Vultr charge me 17.5$/month. Does it normal?

sudden spire
cloud urchin
#

it's fully automated... do you have your account identifier?

carmine hill
#

do u guys have any options for VPS?

fathom pendant
#

you don't need to get a VPS

mortal locust
#

I m using this as a POST request

#

Does anyone knows why this is not working?

cloud urchin
#

are you sure it's vulnerable?

mortal locust
#

This worked

#

and i do get the base64 sourcecode!!

cloud urchin
#

ok those are two totally different php wrappers

#

the expect wrapper isn't enabled by default, how do you know it's vulnerable?

mortal locust
#

allow_url_include?

#

That shd be enabled? for this to work?

#

or is there any other way we can do it?

cloud urchin
#

do what?

mortal locust
mortal locust
cloud urchin
#

that module has a lot of sections, still not sure what you're trying to do.

mortal locust
#

Remote Code Execution with XXE

#

Web Attacks >Local File Disclosure

cloud urchin
#

do you mean the web attacks module?

mortal locust
#

I m able to read source code using filter wrapper

cloud urchin
#

pretty sure you need to do it like the module shows using a dtd not just executing commands directly

mortal locust
#

The other way also uses except

cloud urchin
#

ok, did you try it?

mortal locust
#

I got our point!!

#

The expect module is not enabled/installed by default on modern PHP servers, so this attack may not always work.

#

I m sorry for wasting your time!!

cloud urchin
#

you're not

#

but there's more to it

#

read the remote code execution with xxe section again

#

it says it you can't see the output you may need to execute the command in a more complicated way

mortal locust
#

I did try the other method as well though

cloud urchin
#

i would check all your stuff is setup correctly then

mortal locust
#

no request came on my python server

#

just wanted to know If you are aware that in the exercise, can we use expect wrapper? Is it enabled if you ahve some insight?

cloud urchin
#

worked when i did it

#

double check your stuff

fathom pendant
#

if you're going to embed a variable you should wrap it with {} ie ${VAR}

earnest pasture
#

If you add http://...:81, you don't get the request in your sv either?

cloud urchin
#

may just not be vulnerable

mortal locust
mortal locust
carmine hill
#

llike...i saw in the setting up module we regist a VPS

cloud urchin
#

may just not be vulnerable.

mortal locust
cloud urchin
#

then i went and looked at the actual challenge, it wants you to read a file not rce

ocean night
#

Could this go to DMs?

#

Tier 2 module..

#

ty

fathom pendant
carmine hill
#

thank you alot

long kestrel
#

I am on the footprinting hard and found ||mysql|| user with cat /etc/passwd after ssh'ing into the target as ||tom||. I then used
||cat /etc/mysql/mysql.conf.d/mysqld.cnf || to get the config for the service but it only lists the user and bind-address. I've searched for hints in this chat and saw that people were able to login to ||mysql|| but I am not sure what I am missing since I haven't been able to with default or empty passwords. A tip would be appreciated

safe star
rustic sage
#

Does anyone know how to get a girlfriend in 2025?

real delta
long kestrel
cloud urchin
ocean night
storm elk
#

Certified Boyfriend Brings Happiness

cloud urchin
#

you heard it here first, g0blin just leaked the next HTB path

ocean night
#

Hah oh no

viral patrol
#

I'm doing the Skills Assessment - Windows Fundamentals and can't figure out the answer to || "What is the name of the service associated with Windows Update?" || I am thinking that maybe prior knowledge is messing with me, because none of the answers I can find are the right one. If I could discuss it, I'd appreciate it

#

NM, reloading my webpage fixed it...

marble whale
thorn ingot
#

Is there a way to export/copy a list of payloads either by manual selection or filters (based on status code, length, etc) directly to a wordlist?

proven loom
#

I bruteforced the password using pwnbox and I got the flag

long linden
#

Hi, i've got a question in regard to Advanced SQL injection SA2 - i'm stuck at the last part, but what's funny is that I have gold annual subscription and there is a walkthrough that seems logical but the code does not work 🤣 there is no indication in the walkthrough that there should be some adjustments to the code (which I tried to tweek regardless to make it work but failed). Could somebody help or should i "speak to the manager" or some help center as it seems to be the case of wrong information on the site...?

nova ginkgo
#

The admin uses a firewall that prevents you from exfiltrating the cookie directly.

long linden
#

it is not about the cookie

fathom pendant
acoustic owl
nova ginkgo
#

pelase help

acoustic owl
#

Read the hint
The admin uses a firewall that prevents you from exfiltrating the cookie directly

nova ginkgo
acoustic owl
nova ginkgo
acoustic owl
nova ginkgo
#

not worked

acoustic owl
tender nimbus
long linden
#

but the problem seems to be at earlier steps, e.g. SQLi not working

#

(im doing it on PwnBox)

bright coral
tender nimbus
#

already did it

bright coral
tender nimbus
#

I tought to but i litterly cp the scirpt from the module

#

i'm gonna try in the evening i'm trying mastering python rn

bright coral
#

The script contents are alright, you just can't name the file html.py

shy cave
#

Hi there, I am stuck at the exercise in Authentication Bypass via Direct Access in Broken Authentication module. Can anyone please help me?

tender nimbus
tender nimbus
digital sigil
#

Likely there is an import importing html, and when you have that file name, it will chose that file instead of the library/external source that you actually want

bright coral
#

^ this, you can see it towards the end of the error message.
It’s trying to import html.entities from your file and there you have import bs4 in there. You’ll end up in an endless loop.
You can lookup the import search order

long linden
blissful fulcrum
#

hello there i was trying to solve a question from introduction to windows command line modue where question is (SSH to 10.129.255.206 (ACADEMY-ICL-WIN11) with user "htb-student" and password "HTB_@cademy_stdnt!" ) Access the target host and run the 'hostname' command. What is the hostname? i tried ||*~~raja@Raja:/mnt/c/Users/rajak$ ping 10.129.255.206 PING 10.129.255.206 (10.129.255.206) 56(84) bytes of data. 64 bytes from 10.129.255.206: icmp_seq=1 ttl=127 time=225 ms 64 bytes from 10.129.255.206: icmp_seq=2 ttl=127 time=221 ms ^C --- 10.129.255.206 ping statistics --- 3 packets transmitted, 2 received, 33.3333% packet loss, time 2001ms rtt min/avg/max/mdev = 221.329/223.131/224.934/1.802 ms~~*||

***||raja@Raja:/mnt/c/Users/rajak$ nmap -p 22 10.129.255.206
Starting Nmap 7.95 ( https://nmap.org ) at 2024-12-22 12:10 UTC
Nmap scan report for 10.129.255.206
Host is up (0.23s latency).

PORT STATE SERVICE
22/tcp open ssh

Nmap done: 1 IP address (1 host up) scanned in 0.65 seconds||***
raja@Raja:/mnt/c/Users/rajak$ ssh htb-student@10.129.255.206
Connection reset by 10.129.255.206 port 22
did anyone face the same issue ?

acoustic owl
long linden
acoustic owl
mint gale
#

Hi, can we make suggestions about modules?

digital sigil
mint gale
#

thanks

#

its about using ligolo-ng on Pivoting, Tunneling, and Port Forwarding module

waxen totem
mint gale
zealous rune
#

hi, i'm working on skill assessment 2 on Attacking AD. I have arrived at the question:
"Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host"

So far I have used mssqlclient.py to connect to the SQL01 host and ran a few commands to enumerate the directories, logins etc.

My thoughts are i should be able to run a cmd shell to then exfiltrate registry hives?

#

oh i have also tried using evil-winrm to try creds i have already. no luck

gray yacht
dapper moth
zealous rune
#

i've taken a sneak peek at the windows priv esc module and using the juicy potato technique in there

#

or trying to.... so far not working

earnest pasture
zealous rune
#

ok will take a look thx

wary plover
#

<@&861185840277487616>

cold star
#

I am working on HackTheBox Academy and currently connect to a provided machine via SSH to perform attacks. I would like to pivot the entire network of this machine into my own system, so I can run tools such as NTLMRelayX and PetitPotam directly from my machine and access the Domain Controller (DC).

I have tried using LigoLo and other tools but have not been successful. Any guidance on achieving this would be greatly appreciated.

tranquil axle
#

Did you try normal ligolo or ligolo-ng?

haughty karma
#

hey guys, Im currently working on the Windows Lateral Movement skills assesment and am having trouble with question 2. I got the credentials for Arturo and RDP into the machine with the necessay port but no flag on the desktop. I know I need to access wsus but am having trouble doing so. Would appreciate a nudge on this one

tranquil axle
vital creek
#

Hello guys nice to meet you all

I’m really passionate to learn hacking but i have no idea about this …… i’ve something before about networks our something like that so i use iPhone 8 and looking for a way to learn it by my phone and also i have a PC

#

So any advices ?

compact patrolBOT
fathom pendant
umbral badger
#

Hi there i am starting to learn hacker in my university's study group and I won a 1 month license to HTB Enterprise in this end year so I want to spend the most time I can Learning but from what i've seen it is more usefull for advance learners, since they usually recommend HTB Academy for starting out, I wonder if anyone wants to learn side by side along me, :b, and also may I ask what could i do If having a machien started and conneccted to the VPn it stills seems to not respond at all. Thank you very much. I do not know if it is the proper channel to ask or is it #1024429874246590575 where i also asked. Thank you all.

cold star
unreal sinew
#

Can anyone assist with 'Print Operators' modules for Windows PrivEsc? I don't understand how to utilize this UACMe's akagi64.exe in this lab. I've run the suggested keys from the github page and either nothing happens or I get a UAC prompt for creds. Any guides available for this?

cloud urchin
unreal sinew
safe star
unreal sinew
#

the repo shows akagi from run examples

cloud urchin
#

it walks you through the capcom driver, then shows you auomated eoploaddriver

unreal sinew
#

I ran into an an error on eoploaddriver, figured without the uac bypass I am going to get nowhere.

#

I'll try skipping the UACme stuff and seeing where I get.

cloud urchin
#

yeah this doesn't require anything outside of the material

cold star
safe star
#

petitpotam only sends a connection so that will work

cold star
safe star
arctic geyser
#

hey, I'm new to HTB and currently doing the IS foundations path, but i was wondering, they now announced the new module introduction to IS security, which is not in that path, which would be more useful to do first, the path or the module?

acoustic owl
#

I'd do the path first

fathom pendant
tranquil axle
fathom pendant
#

it looks potentially like that interface is EP; but that doesn't look like an academy lab; hence why i said something

#

:)

storm elk
#

It says EU VIP+ on the screenshot. Isn’t that main platform?

fathom pendant
#

yep

#

VIP isn't academy

storm elk
#

yeah. Marcie is right

#

As always

fathom pendant
#

i'd say reach out to support if you're facing connection issues

umbral badger
umbral badger
cold star
haughty karma
#

im still having trouble accessing wsus server on Windows Lateral movement skills assesment question 2. Anyone have a hint?

naive tangle
#

Anyone can help with Privesc in Windows? Defender and amsi giving me a headache. If so, plz dm

fathom pendant
#

in the WIndows Privesc module? i don't recall many issues with defender and amsi

fathom pendant
#

well then it sounds like it's either illegal or part of a ctf in which case outside help is cheating

#

but since it's not relevant to HTB academy, doesn't belong in this chat

naive tangle
#

Sounds good

fathom pendant
#

read and follow #welcome to gain access to more channels

teal cape
#

anyone have any advice when trying to RPD get error of "[ERROR][com.freerdp.client.x11] - failed to open display:
[ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set." I read some HTB forms and found this https://unix.stackexchange.com/questions/598924/display-environment-variable-not-set but that also didn't fix it

fathom pendant
teal cape
#

Im currently logged into the box with just the user creds given

fathom pendant
#

you can't rdp on an ssh session

#

it doesn't pass through the display

#

it helps if you supply the module and section name

teal cape
#

oop my apologies its the Active Directory Enumeration & Attacks, Skill assessment 2 question 3

fathom pendant
#

you need to pivot to use RDP

#

use whatever pivoting method you wish [my personal favorite is ligolo-ng]

teal cape
#

well it did work whenever i used evil-winRM was just wondering why that RDP error came up

fathom pendant
#

well evil-winrm isn't rdp

#

it's a different protocol entirely KEK

#

it's winrm - windows remote management, CLI

teal cape
#

ah okay im probs just messing up proper tool usage then

#

thank you!

fathom pendant
#

but again; one of the modules/methods you should know in order to be successful in AD enum&attacks is pivoting

cinder tinsel
#

Hey,

i am trying to responde the last question for crackmapexec module about vulnerability scanner. However, my proxy does not work as it seems the software is not compatible to windows version 'This version of C:\Windows\Temp\chisel.exe is not compatible with the version of Windows you're running. Check your computer's system information and then contact the software publisher'. Does anyone knows the right version or a way around this?

fathom pendant
#

knowing which one you're using helps

cinder tinsel
#

i believe was 32 =/. i was jsut following the module. i will download again . thanks for your prompt response

#

64 bits

stone gorge
#

I am in that same section of CME module now... using 64 bit

teal cape
#

thank you 🙂

cinder tinsel
stone gorge
#

I think it's a go program, so when you build, it will build for all platforms all at once.

cinder tinsel
#

thanks SysRisk i will give a try

#

yeah, i cannt make work at all

stone gorge
#

There is only linux and darwin in that releases folder... hmmm. I think I built it.

#

Ahhh... click on show all 85 assets

cinder tinsel
#

gotcha! thanks

dense axle
#

Hi, someone did the Introduction to Malware Analysis - Debugging section recently, it seems like its not working properly

#

like this guy apparently

fathom pendant
#

that was 2 months ago btw

dense axle
#

A guy already send a ticket to support in May and there was a bug

#

Yeah

fathom pendant
#

in order for people to help you it helps others to know what you've done/tried/errors

#

just saying "It's not working :(" isn't helpful

dense axle
#

Maybe a skill issue, i did all the x64dbg steps in order to bypass the Sandbox detection but it keeps detecting it at run.

#

I tried like 10 times

#

I saved the "modified" executable, still the same

plush lotus
#

ok i must ask. is it reallly worth the money for this site? i only ask becuase i was in the middle of a lesson and lost connection to VM and i can no longer complete the course do to the 1 a day ordeal.

tranquil axle
#

<@&861185840277487616>

#

Someone’s selfbot going haywire

cloud urchin
#

<@&861185840277487616>

tranquil axle
#

If you are running on a non sub then your time with the pwnbox is limited, but you’ll learn much more running your own vm anyway

plush lotus
fathom pendant
tranquil axle
#

You have to “connect via vpn”, download the academy vpn file and run “sudo openvpn <yourfile>”

fathom pendant
#

^

#

"spawn target" and "spawn instance" are different buttons

plush lotus
#

can i not run ssh

fathom pendant
#

in order to ssh into the target you need to be connected to the vpn

#

or if you want to ssh to the pwnbox, you need to well... launch the pwnbox

plush lotus
#

ok i understand what is being said. where do i find this vpn download

fathom pendant
#

but the htb targets are mostly on a separated internal network

#

if the module has a target spawn, above where it shows "spawn instance"

#

there will be a dropdown list you can select the vpn server from and protocol, then just click download

thorny vigil
#

Hi Chat, why cant i send a message in general chat?

plush lotus
fathom pendant
fathom pendant
#

there is no downloads folder in the root of your filesystem

#

there is one in your Home (~)

#

Downloads (capitalization matters)

#

here's a big tip for linux, if it's not popping up when you hit tab it likely isn't there

thorny vigil
plush lotus
fathom pendant
#

for instance if you open a terminal and do sudo openvpn Downloads/academy-regular.ovpn or sudo openvpn ~/Downloads/academy-regular.ovpn it should run

#

and once you see Initialization sequence complete (and maybe a few lines after) you're good to go open a new terminal and work off that

plush lotus
fathom pendant
#

no

#

the vpn is good for the whole of academy modules, you don't need to download a new one every time

#

it jut facilitates a connection to the HTB private internal servers where the targets are launched

#

allowing you to connect to the targets on the 10.129.x.x network

plush lotus
#

ok so then i ssh to target?

fathom pendant
#

if that's what the module asks you to do, yes

plush lotus
fathom pendant
#

it won't give you the target ip

#

by the questions there's "Target: 'Click here to spawn target system'"

#

that's what spawns and gives you the target, as stated, you don't need to redownload the vpn every time

plush lotus
#

ok so every lesson just run sudo openvp and then open new terminal and just go about the course

plush lotus
fathom pendant
#

nope you just need to run it once per session that you're working on academy

fathom pendant
#

you can go to another section, spawn a target, and you'll be able to connect to it

#

note: when you start a target it will end other targets running for your account, so you can't spawn 5 targets for a module

plush lotus
fathom pendant
#

the vpn you download isn't tied to the section you're working on, it's tied to your academy account as a whole, basically

plush lotus
fathom pendant
#

your system is; yes

cunning frigate
#

Hey did you figure out what's needed?

sweet jewel
#

don't remember exactly what I did, but i just did whatever they said to do in the module notes, previously i was trying my own custom loaders

cunning frigate
#

Did you have an actual listener on at the time?

fluid carbon
#

all right. i got the answer on my own by writing a super janky pwntools script and using the lists in the seclists directory; i didn't even know what they were referring to when they mentioned the "provided" wordlist.

can someone just tell/DM me what were supposed to be the intended ways to solve the second enumeration question, with the actual working commands? i'm guessing it was intended to be done with either of the network mapper script or the standalone CLI tool. but i can't for the life of me figure out what the syntax is to get the user to pop out of the results for either method.

i would love to know both ways and would appreciate if anyone would be kind enough to just let me know.. i spent days on this determined to get the flag on my own without looking up the support messages here and was able to prevail 🙏

cloud urchin
#

there's a "resources" link on the page that contains wordlists applicable to the various modules. just put the module and section names in your text, no one's going to bother typing the url in from your pic.

fluid carbon
#

right. i already see what they meant now.
anyway, module Footprinting, page SMTP

fluid carbon
#

if it's a better prompt to work with for feedback, i can provide some command history. (just want to reiterate, have already got the flag; just can't figure out what my syntaxing problems are here):

fathom pendant
#

Also that module has a provided wordlist or two in the resources button

fluid carbon
#

thank you for the hint 👌

tranquil axle
cunning frigate
#

I did aes only do I have to have both xor and aes?

rocky estuary
#

quick question if my subscription ended can i still run the machines in the modules i finished or only i can read them

#

i mean cpts path modules

cloud urchin
#

if you completed the module you can start the targets still

rocky estuary
cloud urchin
#

yes, if you completed the module before the subscription expired

rocky estuary
fathom pendant
rocky estuary
rustic sage
#

I need help with this quetion Windows PE + 0 Log in as Grace and find the cookies for the slacktestapp.com website. Use the cookie to log in into slacktestapp.com from a browser within the RDP session and submit the flag. i cannot update the slack cookie

haughty karma
#

anyone got a nudge for the final question of Windows Lateral Movement? I got the vnc password, stuck on getting dc connection

regal juniper
#

Hello!

Error after executing a kernel exploit CVE-2021-3493

When I try to implement the steps explained in the solution (https://academy.hackthebox.com/module/51/section/467) I have an error.
When I try to execute a compiled binary on the target machine, I receive an error which says that the glibc.so.6 is not the right version. Does someone have the same issue and how he/she fixed it?

Another issue is that if I have "root access" (output of the id command shows that I am root), I cannot read any root-related content. (have you seen this behavior?)
Thanks!

young linden
#

Currently I'm in double pivot in exploitation of cpts path, i did double pivot but in nmap results it is showing port state as a filtered anyone please help me

misty current
young linden
#

I'm used the method which shown in the module

#

Even i tried ligolo but i'm unble to ping the final machine

viral patrol
brittle arch
#

For the last question in Windows Lateral movement.. did anybody experience unbelievable slowness connecting to VNC? I am using proxychains, because when I used ligolo for pivot it didn't even seem to connect. Not sure how to get a better/faster connection

#

The window doesn't even seem to respond to mouse clicks

fading ingot
#

Hello

rustic sage
#

Who is now studying in Windows PE , if you there let’s review together?

south glen
#

can any one help me with active directory attack and enum module bleeding edge vulnerabilities PrintNightmare portion i am getting this error when running the command "sudo python3 CVE-2021-1675.py inlanefreight.local/forend:Klmcargo2@172.16.5.5 '\172.16.5.225\CompData\backupscript.dll'"

nova ginkgo
#

Help me please :Modern Web Exploitation Techniques

skills assesment : What is the flag value at the /flag endpoint of the PDF web application?

I tried dnsrebinding technique but not worked

zinc garden
#

Hello everyone I am new can anyone please tell me a good source to study bug bounty from 0 ?

storm elk
#

Follow the fundamentals path and CBBH path on Academy

opal nexus
#

Try 'smtp://<IP>'
Maybe it will work

soft reef
#

Have you tried just "fiona"?

rocky estuary
#

i got 500 points what module do u recommend i heared good stuff about the bloodhound and the crackmapexec module i'm planning to get the cpts will they help me ?

vocal pulsar
#

Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows

brave scroll
brave scroll
#

like when we do "ls" it just say "Passive mode" and no response.

soft reef
#

Have you tried turning passive mode off?

brave scroll
soft reef
#

Type passive, if I remember right

brave scroll
misty current
wet wyvern
#

Hello guys i'm new here i'm doing the password attacks module and im at the section network services i'm doing the smb one but i get an empty flag.txt does anyone have the same issue?

soft reef
brave scroll
wet wyvern
#

I cant upload dunno why

#

No its passsword attacks

brave scroll
wet wyvern
#

Network services

brave scroll
#

i got you, where you are stucked?

wet wyvern
#

smbclient -U cassie \\<ip>\CASSIE

#

Password:12345678910

#

ls

#

And get flag.txt

brave scroll
#

yeah, i had got same issue when i was doing this.

storm elk
swift anchor
#

Hey who can help me with how to connect to vpn on laptop using hackthebox im new to this

gray yacht
brave scroll
gray yacht
#

--skip-ssl

upbeat zinc
#

Anybody who can give me a hint for ADCS skill assessment, i tried to get a shell on DEV01 with printnightmare as I found $RPC, i tried to request a cert for DEV01, but it needs higher privilige than tom to actually issue the cert, i tried to capture hases, but there seems no activity... what technique/skill should i restudy ?

wet wyvern
#

I reset the target and it works noice

charred mason
#

Y'all know how to get my acc back?

dim hound
charred mason
#

Nahh bro said i can't get my acc back

orchid furnace
#

Hi i am currently in the learning process model , I tried finding some ressources about the ROQ relationship oriented question model to understand it better but I failed finding such, as any search result either video or google does not give ROQ like if it only exists in htb, I hardly understand how to apply ROQ in everyday life without further examples than the one used on htb which talks about the methods we can use to access windows remotely, please help

south glen
haughty karma
#

can someone please give me a nudge on the last question of windows lateral movement SA? I got the VNC password but cannot connect to domain controller

tranquil axle
#

You don’t use vnc to connect to the dc

earnest pasture
fathom pendant
#

smbclient works with // otherwise you need to \\\\

soft reef
brave scroll
#

Can anyone tell me when we have to use backslash & forward slash while using smbclient and how much time we have to use?

#

I always confused about this

fathom pendant
#

\ is an escape character in bash; and most languages \\ <-- this is 4 " \ " but will be interpreted as 2;

#

// has been accepted by smbclient for a while now and can replace the \\\\

#

but the UNC path needs to have 2 [interpreted] slashes to be a valid path

#

\\\\[IP/SERVER]\\Sharename is the same as //[IP/SERVER]/Sharename

#

if the share has any spaces in it you'll need to wrap it in quotes

haughty karma
hazy belfry
#

hi, can i ask questions about non retired machines anywhere here? Or is that not allowed? Upon logging in, the forum for machines is is invite only:) Just joined the server, and i didnt find where to ask

fathom pendant
fathom pendant
#

also you can't really discuss active machines without spoiling

#

you can ask for nudges

hazy belfry
hazy belfry
fathom pendant
soft reef
haughty karma
fathom pendant
shadow sedge
#

getting started module, types of shells. do i need to understand the shell commands for ex:

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc -lvp 1234 >/tmp/f

because it's not explained so that's y im asking

fathom pendant
#
  • if /tmp/f exists delete it
  • create a fifo named pipe /tmp/f
  • read the pipe; and send it to bash (include error and stdout redirect, 2>&1) pipe that to netcat
  • use netcat to listen [-l] on port x [-p x]
  • then redirect the netcat output to the named pipe (/tmp/f)
shadow sedge
#

got it

#

thank you

fathom pendant
#

/bin/bash -i runs bash in "interactive"

#

@lime cosmos moving the convo here; what section are you working on in Getting Started

idle sorrel
#

Hi is there an implementation for reseting a module progression ?

fathom pendant
#

no

idle sorrel
fathom pendant
# shadow sedge got it

google, man pages, and --help are gonna be your best friend, |,; are command separators so you can individually figure out each command

lime cosmos
#

List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file.

fathom pendant
#

giving the module and section name is more helpful

fathom pendant
lime cosmos
#

i send the link

fathom pendant
#

bob:password

#

ctrl-f for bob:

#

you don't need to bruteforce it at all

lime cosmos
#

what about the cpts exam ?

#

i mean when i will facing the same problem ?

fathom pendant
#

if it's meant to be bruteforced or sprayed it won't take a long time

lime cosmos
#

ok and i will use the rockyou list ?

fathom pendant
#

that's the general rule of thumb ~hour at most

fathom pendant
#

the modules teach you how to craft your own list and things of that nature

lime cosmos
#

ok thanks

fathom pendant
#

don't overthink the getting started module

#

it's not gonna have you do anything overly complex

shadow sedge
fathom pendant
shadow sedge
#

that is what im trying to avoid as much as possible i want to understand the roots of everything to build strong foundation

fathom pendant
#

it also helps to understand when digging is gonna lead you down a rabbithole. but reasonably understanding what a tool does allows you to understand similar tools.

shadow sedge
fathom pendant
shadow sedge
#

I’ll use for sure

fathom pendant
#

Rewriting in your own words is almost always more beneficial

#

The only person that needs to understand your notes is yourself

shadow sedge
shadow sedge
acoustic sparrow
#

need a nugget from cme skillassesment last question (DC01)

opal nexus
acoustic sparrow
#

using || nick ||

opal nexus
acoustic sparrow
#

ty i guess my nxc is broken again didnt got anything
time for smbclient

opal nexus
acoustic sparrow
tranquil axle
#

Did you end up finding a solution for this? I’m currently bruteforcing the offset but I feel like that can’t be it lol

mossy eagle
#

I’m stuck on abusing HTTP misconfigurations skill assessment - hard. I’m not sure where to start. Any chance someone could help me figure it out? I’d really appreciate any help.

carmine hill
#

i'm running a openvpn,but i get a "permission denied",can some one help me to fix this for me please?

dark hedge
#

sudo openvpn ...

carmine hill
#

when i trying to SSH to the machine by using htb-student@ip

#

and i got a permission denied erveytime even if i enter HTB_@cademy_stdnt!

dark hedge
#

can't send one since they're not verified

dim hound
#

aw damm, @carmine hill dm me ; )

fathom pendant
#

And I'm assuming you're replacing ip with the target 10.129 address

stone gorge
#

On the CME module skills assessment, the DNS server is not accepting queries...

#

That DC needs rebooting...

#

Even the solutions to the questions don't work!

dawn kite
#

‏ Hello , in broken authentication, brute-forcing passwords
‏The second question, I tried everything, even I tried the entire RockYou.txt without using grep (14344391 passwords)
‏And nothing worked with me, in the module they used rockyou.txt and they got the password but I think the password doesn’t exist in the rockyou.txt, Any tips?

stone gorge
#

I am surprised you got that far with the second question... mode 1300 and rockyou will definitely get the user pw.

#

Oh... different module! Sorry... broken auth!

keen goblet
#

who are you

analog dock
#

<@&861185840277487616>

stone gorge
#

Yes, go troll elsewhere...

fathom pendant
#

Get better opsec Omar, don't link your personal Spotify to your discord account

river jetty
#

I'm doing the Using Web Proxies Skill Assessment and I'm running Intruder to find the correct cookie. They all come back with 200 OK Code and Half of them allow you to login. What am I suppose to put as the Answer?

tranquil axle
#

200 ok doesn’t necessarily mean it did anything successful, can you actually log in with half of them?

river jetty
tranquil axle
#

Does the flag end on ninja?

river jetty
river jetty
tranquil axle
#

That’s the right flag, it starts with HTB and ends on }. Make sure you don’t accidentally copied any spaces

vivid sigil
#

hey

DACL Attacks I > Targeted Kerberoasting

when i try run this command

python3 targetedKerberoast.py -vv -d inlanefreight.local -u pedro -p SecuringAD01 --request-user Moly --dc-ip 10.129.205.81

[] Starting kerberoast attacks
[
] Attacking user (Moly)
[DEBUG] {'Moly': {'dn': 'CN=Moly,CN=Users,DC=INLANEFREIGHT,DC=LOCAL', 'spns': []}}
[!] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
Traceback (most recent call last):
File "/home/kali/Desktop/cpts/dacl1/targetedKerberoast/targetedKerberoast.py", line 597, in main
tgt, cipher, oldSessionKey, sessionKey = getKerberosTGT(clientName=userName, password=args.auth_password, domain=args.auth_domain, lmhash=None, nthash=auth_nt_hash,
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.11/dist-packages/impacket/krb5/kerberosv5.py", line 323, in getKerberosTGT
tgt = sendReceive(encoder.encode(asReq), domain, kdcHost)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.11/dist-packages/impacket/krb5/kerberosv5.py", line 93, in sendReceive
raise krbError
impacket.krb5.kerberosv5.KerberosError: Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

i did what they said on the note

sudo ntpdate 10.129.205.81

but still does not working

river jetty
vivid sigil
#

yup

pine dune
#

Hi guys, Im on the Sqlmap module and struggling to understand some of the "attack tuning" part of the module...could someone help me understand it a bit better? Im struggling to understand the prefixes and suffixes part

scenic plover
midnight galleon
pine dune
pine dune
midnight galleon
#

basically, the idea of suffix/prefix is that you use them to for the injection itself, it is the thing that triggers the injection

#

spoilers

pine dune
#

is that a spoiler? sorry

scenic plover
#

So basically the with the prefix you're attempting to end the first part of the query in a certain way. So maybe a small string and a certain special character (after you've done some fuzzing) that will terminate the original query. The suffix is what will be at the end of the query, so essentially comment syntax to make sure the rest of the original query, after your injection, is not included

pine dune
midnight galleon
#

for example, -- - is used to comment things out, you use it to bypass login for example, what comes after that, is the sqlmap shenanigans that exfiltrate database or read files or whatsoever

ocean night
#

Exactly.. let's you define what to "wrap" your injection payloads that sqlmap generates in

pine dune
ocean night
#

Sometimes sqlmap needs a little hand 😉

pine dune
midnight galleon
#

it is useful in whitebox when u can know what triggers the injection, and u just need to see how far can u go with it

ocean night
#

Queries are unique - their structure sometimes require very specific enclosures

scenic plover
#

Every query language(MSSQL vs MySQL) is different and if it's not working sometimes adding your own syntax helps

pine dune
ocean night
#

sqlmap does its best, but yeah, sometimes it can't infer or guess everything correctly

midnight galleon
pine dune
#

I need to get flag 5 and thinking of what to use 🤔

ocean night
#

The answer

#

(jk sorry)

pine dune
midnight galleon
pine dune
midnight galleon
#

good luck!

pine dune
#

what is the "--no cast" flag in sqlmap?

ocean night
#

It affects the usage of a mechanism in payload generation

#

Check manuals 🙂

rustic sage
#

Guys Im in login brute forcing skill assessment 2 , I found the other port with the webpage but theres no ftp port open or filtered and also ssh blocks me because i dont have the public key.
I tried to see if the public key is in the previous room but I'm having problems connecting to it as it responds to pings but I can't even see the login page

#

Cant enumerate anything with Medusa or hydra

dapper moth
#

Kerberos doesn't like unsynchronized clocks

#

You can sync your time to the DC with "sudo ntpdate [ip address]"

ocean night
#

Don't just flat out ask for how to get a flag.. asking for guidance, fine, discussing problems you're having, fine.. avoiding posting information directly pertaining to the content.

#

Just asking how to get the flag, come on

pine dune
#

let me try word that better

ocean night
#

Right..

#

Read back through the section

#

You have tried a command, it didn't succeed. Read the the section for options that can be used to help you

#

I can't help further, sorry - I'm gonna go chill for a while before bed, but yeah.. just dumping commands and output for questions which didn't work, asking for the answer.. it's the same thing

pine dune
#

Hi, when trying to use sqlmap to enumerate tables from a database, why doesn't it sometimes work even if there are tables in the database?

static stump
pine dune
wide river
static stump
#

see the error , is there any '>' error in the scan process?

pine dune
#

checked the hint

ocean night
#

Come on

pine dune
#

sorry

ocean night
#

Third time

pine dune
#

😅 😂

#

im sorry i need to get better at that

#

@ocean night may I please DM u?

ocean night
#

Ok

pine dune
#

thanks

rustic sage
#

I'm in login brute force assessment part 2 question 1
I'm reading on the forum that people are able to directly interact with ssh but Its telling me that I'm missing the public key. I nmapped the ip and found other 3 ports open and 2 filtered. It seems to me like all ports don't respond besides the one without service. Any clue?

main marsh
#

Hi guys, i'm in the footprinting lab (hard) I have an error when I try to log in with mysql -u tom -p

Error 2002 (HY000): Can't connect to local server through socket '/run/mysqld/mysqld.sock' (2)

ocean night
#

Re-read the section, you're missing something.

#

You're given a target.

ocean night
#

You do not need to nmap the target

rustic sage
#

I don't understand what you mean by "not the target for this module"

ocean night
#

module 57, section 516?

rustic sage
#

Pentester path, module login brute forcing, skills assessment part 2, question 1

cloud urchin
#

one thing to keep in mind, that module was recently updated so the forums you're reading may be wrong

ocean night
#

Sure.. read the question carefully

rustic sage
#

Ok

#

I still don't get it, I can't brute force anything because I can't interact with anything

#

What is the name of the ftp user you find via brute forcing?

#

Can't brute force anything

cloud urchin
#

read the entire page not just the question

ocean night
#

My bad about ssh, it is used here. Was looking at another module.

#

I'm too tired, and done. Night, cya later

#

But yeah.. the page does tell you what you need to know

#

Don't post dumps of info like that on modules over Tier 0 fml

rustic sage
ocean night
#

Ok no I go, for real. Can't deal

rustic sage
ocean night
#

The one that was deleted

rustic sage
#

Mmm aight

ocean night
#

Not you

rustic sage
#

Any clue on what I should do?

#

@cloud urchin can I dm u

cloud urchin
#

g0blin kinda told you exactly what to do

rustic sage
#

And also he was talking with the other guy who asked a question and got it deleted so I don't really know what messages are for me or the other guy

cloud urchin
#

yeah go ahead and dm me

south glen
south glen
drifting nebula
#

Hi. I am new to this and working through Linux Fundamental in academy. I am stuck on question asking what is path to htb-students home directory and path to mail. I thought I had it but it keeps telling me i am wrong. Can anyone help please??

cunning frigate
#

Can I dm someone about MSSQL, Exchange, and SCCM Attacks Skills Assessment?

tranquil axle
#

Are you asking if it’s normal to complete the last two flags in one go?

cunning frigate
#

Nope i am kinds lost on 3rd question

#

can i dm?

tranquil axle
fathom pendant
#

there's a list of common useful commands, one is to list things about the environment (env)

coarse merlin
#

hey guys

#

i need a help

cloud urchin
#

just ask your question

rustic sage
#

how do i fix this lol

coarse merlin
#

how to rank up ?

rustic sage
#

just do the machines, and link your profile

fathom pendant
# rustic sage how do i fix this lol

this has nothing to do with academy; but i'd assume hitting terminate should fix...something; also you can try hitting up support but it'll be barebones support considering the holidays

coarse merlin
tranquil axle
#

Machines give more points

#

Eventually you’ll need both if you want a high rank

cerulean grail
#

In the Linux File Transfer module it says "Download the file flag.txt from the web root using Python from the Pwnbox. Submit the contents of the file as your answer.". Am I expected to write a Python script that does this? This was never touched on in this or previous modules in the Penetration Tester Job Path.

tranquil axle
fathom pendant
#

because you're just meant to download /flag.txt from http://[spawned_ip]/

#

if i had silv/gold annual i'd check the guide and see if there's something not-so-obvious

#

i mean python does have a web requests thing you can import and use

#

but meh

rustic sage
#

my bad. But terminating doesn't terminate it 😦

fathom pendant
# rustic sage .

reach out to support, this channel isn't for help related to things outside of htb academy

#

¯_(ツ)_/¯

rustic sage
#

It is what it is man.
You tried your best to help me, but the rules stopped you somewhere. Godspeed

fathom pendant
#

It's moreso not flooding the chat with unrelated things

rustic sage
#

This is AD - Bleeding Edge Vulns section. I have the local internal network access via port forwarding (tried both ssh -D and now Chisel). However, I can't get to ping the internal network at 172.16.5.5 nor run nmap on it via proxychains. Any workarounds?

finite abyss
fathom pendant
#

AD enum and attacks?

#

There's multiple "AD" modules

rustic sage
#

AD Enum

rustic sage
fathom pendant
#

use 127.0.0.1 instead of localhost

rustic sage
#

And chisel connects as well

#

I meant 127.0.0.1

fathom pendant
#

i use ligolo for my proxying needs though

cerulean grail
fathom pendant
#

or using common windows ports; 445,3389,5985,5986

#

also make sure you use the correct subnet

#

but ligolo works much better and the bonus is no need to mess with proxychains

cerulean grail
fathom pendant
#

just use curl

#

or wget

safe star
fathom pendant
#

a webroot is just the base of the webserver

cerulean grail
#

They specifically asked us to use Python though which is why I'm just making sure

fathom pendant
#

and any files within that webroot directory on the host are considered in the webroot

rough violet
#

guys in the linux fundamentals module

#

what's the path to the htb-student mail?

fathom pendant
cerulean grail
rough violet
fathom pendant
#

run that command

#

on the target

rough violet
fathom pendant
#

you're given a list of potentially useful commands

rough violet
fathom pendant
#

it was

rough violet
rough violet
# fathom pendant it was

i was trying something different, in the previous page it was discussing the filesystem where it was mentioned how /var has the mail files, and so i was like locate mail | grep /var

#

why isn't listing contents of mail getting me htb-student, no one has tried contacting him?

fathom pendant
#

deleting because spoiler

glass egret
#

I just got on this website today for the first time. I am curious what's going on? I am 99% sure im getting the answer right but its giving me an error

fathom pendant
#

but an environment variable can be set without it being a valid file location

fathom pendant
#

or you're wrong

glass egret
#

refreshing the page worked

#

thanks

fathom pendant
#

cache issue then

#

also it seems your issue was related to #starting-point not an academy module

storm elk
#

My bad. I sent them here

ashen pollen
#

Anyone done the knowledge check at the end of Module 77

dire lily
#

Login Brute Forcing - Basic HTTP Authentication
File path changed, please refer to

404 not found
https://raw.githubusercontent.com/danielmiessler/SecLists/master/Passwords/2023-200_most_used_passwords.txt

moved 
https://raw.githubusercontent.com/danielmiessler/SecLists/refs/heads/master/Passwords/Common-Credentials/2023-200_most_used_passwords.txt
cunning frigate
ashen pollen
cunning frigate
#

what do you mean?

ashen pollen
safe star
cunning frigate
ashen pollen
dire lily
cunning frigate
#

CMS is stuff like wordpress, wix, joomla

ashen pollen
cunning frigate
#

find what CMS is on the website

ashen pollen
#

GetSimple

cunning frigate
#

yes google or searchsploit that

fathom pendant
ashen pollen
fathom pendant
#

well it helps others help you in a more useful way

ashen pollen
fathom pendant
#

module # means absolutely fuck all to me

ashen pollen
fathom pendant
#

the only reason i know that it's Getting Started is because people consistently link the endpoint /module/x/section/y

ashen pollen
fathom pendant
#

also the module search feature doesn't search module by # it searches keywords/title

rustic sage
#

I need help with windows prv esc skill assessment part 1 , stuck on getting reverse shell

fathom pendant
#

case sensitivity is quite the bitch though from what i recall

safe star
rustic sage
fathom pendant
#

yep

rustic sage
rustic sage
safe star
#

Wouldn’t revshell be easier?

fathom pendant
#

i don't recall if i did a revshell for this tbh

rustic sage
fathom pendant
#

but the hint specifies taking advantage of something

#

oh wait duh you can get a shell via a certain method

#

i forgor about that nightmare

rustic sage
hasty mauve
rustic sage
#

I do not know i will try what u said

fathom pendant
#

my last message was more of a direct hint

#

:)

safe star
hasty mauve
fathom pendant
#

:():

#

my purse appears empty

ashen pollen
cunning frigate
ashen pollen
#

How would i find the CMS version its running?

#

Is there a way to query it from the direct server or would i have to find it

fathom pendant
#

by looking around

cunning frigate
#

Think which ones would help you get the flag to eliminate most

fathom pendant
#

usually you have to login as an admin and figure it out via the admin page

#

also that ^