#modules

1 messages · Page 372 of 1

dapper moth
#

Totally forgot of it. May have used only a couple of times

severe inlet
fathom pendant
#

Why are you including the number in front?

#

It's asking for the fqdn

severe inlet
#

yeah sorry even without the number its incorrect

alpine ingot
#

marcielee, the amount of people you help every day must hammer these modules into your head irreversibly.

waxen totem
alpine ingot
#

dude thats what im saying, i feel like i should do this once im done with the modules so i can remember it better.
no better way to learn than teaching in my opinion

severe inlet
#

even this question when i saw it i thought it will be easy but idk nothing works maybe its bugged

feral nimbus
#

Hi I was on the command injection module where we have to bypass a filter for \ character I'm encountering something weird. i'll let the picture do the explaining:

#

The var with tr command essentially become \ character however when combined with the rest of command id the terminal outputs an error

#

But when I type i\d manually it works

#

Not sure what's happening here

I tried to change my shell to bash

and add an additional \ as well

#

But both didn't work

rotund sphinx
#

hi,
i am working on smb part of attacking common services
trying to bruteforce the password of a particular user
i have managed to get the answer but i am a bit confused about why my attempts with NetExec failed while metasploit got it immediately with the same password list, has anyone else ran into issues with different bruteforce tools giving different results? or am i doing something wrong with NetExec

plush mist
#

Hi, I'm looking at the Active Directory Trusts module and I can read this:
Just like in an Intra-Forest environment, where Active Directory trusts exist within the same forest, Unconstrained Delegation can also be performed in Cross-Forest also known as Inter-Forest scenarios where trusts exist between different Active Directory forests
And also:
Even with default, modern configurations for Active Directory forests, the Unconstrained Delegation attack remains viable, particularly when a two-way forest trust exists.
Isn't that sentence false ?
By default you cannot abuse unconstrained delegation between 2 different forests no ?

topaz willow
#

Hey everyone, someone know if it’s possible to audit with hydra a website with dinamic token

lusty thicket
#

so maybe it downgraded or switched strategies mid bruteforce

fathom pendant
#

My best guess --local-auth

obsidian kayak
obsidian kayak
alpine ingot
#

finally

#

I dont think i did it how i was supposed to but hey, i got the flag

rotund sphinx
rotund sphinx
lusty thicket
#

tip; if you need hydra for smb, use auxilliary tools like smbclient first to verify the protocol version

rotund sphinx
#

idk why i still go to hydra first for smb :p it never works for me

#

but i was confused why metasploit was able to find the password that nxc said gave a login failure, but it seems to have been that local auth flag so i will need to try and remember that

proper lodge
#

Please am new here

molten summit
#

can someone please help me install parrot. i followed exactly as mentioned in the 'setting up' module.

for some reason im getting this error although ive entered the correct password

fathom pendant
molten summit
#

thanks for helping!

stable tapir
#

Anyone have issues with InstallDate value for SRV02. Question2 on WMI. I got the value using 3 different methods all with the same output but did not accept as answer.

dapper moth
rotund remnant
# plush mist Hi, I'm looking at the Active Directory Trusts module and I can read this: `Just...

Hey Will, after doing some reading, the course content is aligned with MS. Sorry, I haven't had a moment to test this scenario, but I recommend spinning up some AD boxes and trying various scenarios. It's worth noting that you'll need to tweak the trust configuration due to MS locking down this feature. Ref - https://support.microsoft.com/en-gb/topic/updates-to-tgt-delegation-across-incoming-trusts-in-windows-server-1a6632ac-1599-0a7c-550a-a754796c291e#:~:text=The trusted forest can authenticate,on behalf of the user.

molten summit
plush mist
hybrid temple
#

Hello, can someone give me hints for Intro to whitebox pentesting skills assessment2? I get "Patch test failed. Please try again.", but the code seems to work and I cannot make it crash. You can DM me, and I can provide more information. Thanks a lot!

wanton estuary
#

Anyone free to talk about the HTTP Attacks Skill Assessment? I think I understand what to do but im struggling to craft the correct payload

eager siren
#

hello guyz, i am on the skill assesemnt 2 of Login Buteforcing i obtained from skill assesment 1 the username that i have to use on skill assesment 2, from the username its not clear to me what i should do next, i mean i cant derive a first and last name from it, so i can use the tools from custom wordlist part. I have a suspect first and last name but it does not have a date of birt since it is a psedonym

#

can someone help me

sturdy laurel
#

Can anyone start their pwnbox while solving module?

#

my pwnbox is not starting

#

Error
There are no available instances. Please try again later.

#

I am getting this error even though i am having student sub

#

Am i only the one having the problem or others are also having?

fathom pendant
compact patrolBOT
sturdy laurel
sturdy laurel
frigid carbon
#

anyone who could help me out on dns footprinting?

#

have been stuck for hours now

steel owl
#

Can anyone tell me how to practice hping3 ? Like a dummy website or some activities?

worn matrix
#

.

wanton estuary
#

@fathom pendant have you completed HTTP Attacks skill Assessment?

soft reef
#

On DACL Attacks II - SPN Jacking I got the flag from Windows. I'm trying to do it from Linux as well but I can't get it to work. Has anyone done this from Linux?

sonic ridge
#

I'm doing the file inclusion php wrappers module and I got all the other modules to work but can't seem to get the expect wrapper to work. It says its enabled in the ini file when I read that but I tried curl -s "http://<SERVER_IP>:<PORT>/index.php?language=expect://id" and i just get back the html page with no command executed

craggy steppe
#

Hello, i need help with the windows pivesc module :
I'm not able to play the SeTakeOwnershipPrivilege part.
All i get is access denied error.
And i can't see the SeTakeOwnershipPrivilege in the whoami /priv with htp-student.

soft reef
cloud urchin
#

i remember struggling with the manual way

#

i did re-do it and get it done the manual way too though

soft reef
#

Okay yes I did a reset and manual seems to work now.

soft reef
cloud urchin
#

sure

indigo swallow
fathom pendant
#

Also the article is from 4 years ago

cloud urchin
#

sounds like you're out of.. luks.. kek

fathom pendant
#

It's not kernel issues, its the way the installer handles it

#

Aka its being the big dumb

unborn heron
#

Hey who needs help with hacking?

real hearth
#

Hello, i am currently following a pentester role path on HTB academy.
During one my enumeration with nmap i find out that the option -sA (for a ACK-scan) isn't working and do a SYN-scan instead.
I tried to troubleshoot via wireshark and i am indeed sending SYN flags instead of ACK flags...
Isn't the ACK-scan supposed to send ACK request only ?
Did you encounter this behaviour with nmap ? How did you fix it ?

Thanks in advance 🙂

fathom pendant
wild sage
#

@fathom pendant do you know the correct | for crud api? I'm trying to follow the section for notes and doing it in my Parrot VM. Doesn't seem | jq works, do I need to install anything?

#

Module is Web Requests

fathom pendant
#

Bro i did this so long ago at this point and didn't even take notes

#

| jq is just to read the jq response from the server in a neater manner

#

Otherwise it's all returned on one line

craggy steppe
obsidian kayak
#

how to ctrl + v in Pwnbox

cloud urchin
#

in the lower right there's an icon you can click on to open a box, this box is the clipboard of the pwnbox so you can copy/paste from it

fathom pendant
fading bough
#

Hello

feral zodiac
#

is it just me or is the information security path actually pretty hard and difficult for a complete begginer to understand?

cloud urchin
#

Keep in mind it's geared toward beginners in infosec, not beginners in IT in general.

#

so it really depends on your starting point

cloud urchin
#

on snap new module dropped

#

hell yeah it includes hcxdumptools, finally

real hearth
inland reef
#

Hey guys, how are you doing?

I'm not sure if this is the right place to ask this, I hope it is.
I'm currently working on the Cross-Site Scripting (XSS) module. In the Phishing section, at the questions I have the following challenge:

"Try to find a working XSS payload for the image URL form found at '/phishing' on the above server, and then use what you learned in this section to prepare a malicious URL that injects a malicious login form. Then visit '/phishing/send.php' to send the URL to the victim, and they will log into the malicious login form. If you have done everything correctly, you should get the victim's login credentials, which you can use to login to '/phishing/login.php' and get the flag.

I was able to build a working payload with the malicious login form that sends the submitted data to my local netcat server. I was able to reproduce it successfully by myself (entering the malicious url and sending test credentials), but when I go to /send.php url to send the malicious url, it returns a message that says "Issue in sending URL!

For clarification, I'm doing this connected to the VPN (I've never had issues before), and I've tried using netcat for recieving the credentials, and also tried with a local php server (both cases are explained in this module section). I also tried "url encoding" the payload. In each case I get the same response.

I can share the payload I built if needed. I don't want to post it directly as it might be considered a "spoiler" for someone who hasn't reached this section yet.

Has this happened to anyone before? It's very strange to me that I'm able to replicate it, but I get this error when I try to solve the challenge.

Thank you very much!

obsidian kayak
# cloud urchin so it really depends on your starting point

Let me ask you what you need to do to become a real security officer who is suited to both offense (including pentest) and defense
I want to understand if it is worth to seek a huge amount of knowledge or to deepen only in my field (I am interested in cyber security in general)

#

Introduction to Web Applications
Public Vulnerabilities

"What is the CVSS score" -> What is the CVSS Version 2.0 score
I think such a change should be made so as not to confuse people

cloud urchin
# obsidian kayak Let me ask you what you need to do to become a real security officer who is suit...

I'm probably not the best person to ask, maybe check reddit/youtube for this. but IMO what you need to do is have a strong passion for it. You need to be self motivated. You need to learn the basics of how computers and networks operate. You need to learn the fundamentals of network and security protocols, etc. Once you have a strong foundational knowledge you can move on to learning red/blue team stuff which can make you feel like you don't know anything all over again.

cloud urchin
slow osprey
#

what are your guys go to wordlists when using gobuster or similar for directory/subdomain bruteforcing?

#

it's frustrating when I'm often doing the right thing, just using the wrong wordlists and getting no results

dapper moth
#

raft or directory-list in Sectlists

weak seal
#

Anyone run into any issues on the Footprinting IMAP/POP3 module where after connecting and logging in there are 0 messages? I am logging into imap with the creds on the page and I connected to the mailbox I believe I need and it shows "0 EXISTS" for messages

slow osprey
weak seal
slow osprey
#

No problem 🙂

obsidian kayak
#

what to do if you can't paste with ctrl + shift + v

cloud urchin
cloud urchin
#

that's it. now that you have "test" in the clipboard you can go back into the pwnbox and paste it with the hotkey combo (ctrl + shift + v)

#

when you ctrl + shift + c in the pwnbox, it will show up in that clipboard as well

fair yacht
#

@fathom pendant do u think if cbbh is easier than cpts? I mean it has much less modules and it was the first cert if Im right on htb

fathom pendant
obsidian kayak
#

If I pass the pathway, is there a fee to take the exam?

cloud urchin
#

yes if you want to get the certification you'd need to purchase an exam voucher which is good for 2 attempts

obsidian kayak
#

So assuming a student subscription - I should take the modules for basic vulnerability hunting, try to find something and try to pass the exam?

cloud urchin
#

you should do whatever your end goal is. you don't need to take the exam or get certified. you can unlock modules just to learn stuff. if you go for the exam, there are paths you need to complete before you can take the exam. look at the job role paths and you can see which modules are required for the various paths, then you can buy an exam voucher for whatever path you complete, if you want to.

crisp raft
#

What ColdFusion protocol runs on port 5500? i tried everything i didnt know

cloud urchin
#

it says in the module

#

look under 'coldfusion - discovery & enumeration'

acoustic owl
#

Need help on the critical flight ctf

steel snow
#

excuse me...

#

i am unable to receive any ping from any server US one

frank hearth
frank hearth
dark hedge
#

please tell us the module name, section name, what you have tried, ...

frank hearth
#

module: Network Enumeration with Nmap section : service enumeration

rustic cargo
#

Hello

olive horizon
#

Hey guys, anyone having trouble spawning a target machine in their modules?

#

I'm on the pentester path on one of the module and it's "Targets are spawning" forever. I switched to another previous section within the same module but spawned target without problem

cloud urchin
#

on the page press ctrl+shift+r and try again

obsidian scroll
#

I am on the footprinting lab easy one, I am lost again.
There are 3 services opened, DNS, SSH and FTP.
I can connect to the server using FTP and given credentials but cannot create the ".ssh" directory to authenticate my ssh key.
Neither can i use the given credentials for ssh connection, it shows public key error.
I used the "sudoedit" command to change permissions within the ssh.config file too but that has been of no use again.
the hint shows that i should change some permissions for ssh keys but I can't find the keys as well.

How should i proceed ?
I am on the Footprinting Easy Lab in Pentester Role

civic steeple
#

hell, i'm in Pivoting, Tunneling, and Port Forwarding, Page 3, Dynamic Port Forwarding with SSH and SOCKS Tunneling
the walkthrough for the second question specifies using proxychain but its not installed on the target machine and i cannot install it

#

the walkthrough doesn't mention having to install it and seems to skip to just using it. i also tried using xfreerdp, not installed and cannot install

#

also the question is confusing because it specifies pivoting to 172.16.5.19 but the ifconfig from the target shows 172.16.5.129. i'm happy to try either but cant get to that point

cloud urchin
safe star
civic steeple
waxen totem
cloud urchin
civic steeple
#

i get that the targets don't ever match but it's odd that within the question they actually specify the ip to target with the target machine. i think it's a typ because they say .19 but the module when you read through and the scan doing it live show .129

cloud urchin
civic steeple
cloud urchin
civic steeple
#

it's 1am here lol, thank you

#

now it all makes sense, you're specifying proxychain to attack the new target but using the port thats been forwarded, or something like that lol

cloud urchin
#

you are pivoting through the target. the target itself has a NIC that has access to the internal network

#

so you're using the connection to the target machine, from your machine, with proxychains which uses the target machine to route traffic through it to network that's inaccessible from your machine

frank sun
safe star
#

—no-cast or —dump 🤷‍♂️

frank sun
#

not working

#

I reset the target as well multiple times, no luck

cloud urchin
frank sun
#

all the parameters? bit overwhelming to determine. I chose what can be passed and it worked but not fully to dump the content

#

i also gave risk and level to max

cloud urchin
#

you can combine parameters

#

also if you're able to enumerate more information about the tables you can make it go faster, the section explains how

frank sun
#

I am lost, can't decide what to try

#

can I text you the commands which I have tried?

cloud urchin
#

can you see how many columns are on the page?

frank sun
#

yes

cloud urchin
#

ok.. so did you tune the attack with the combined parameters about the knowledge you have, plus what tlattice said?

#

re-read the section, see how granular you can get with the info you have, provide as much info as you can to sqlmap

frank sun
#

yes

#

I provided -
technique to use
cols
database
table
--no-cast or --hex
max - risk and level
--dbms

cloud urchin
#

well you probably don't need everything but if it works it works

#

also some of those flags aren't on that section at all

#

focus on what's in the section, its all you need

frank sun
#

When I tried prefix say -111 OR it does not reflect on the payloads

frank sun
cloud urchin
#

hard for me to say more without straight up giving the answer, i kinda handed you what you need to do already. feed it the knowledge you know, tlattice gave some good advice on other flags, you can combine flags.

frank sun
#

if you don't mind, can you try once see if the target is working as expected?

unreal crescent
#

On the Introduction to Bash Scripting Module I am having trouble with the question that needs me to script an If-Else statement that requires the variable to contain the value and be longer than 113,450 characters. I think I have everything right, but I am not getting any output from the script

Edit: Contains not Equals lol. Note to others Surrounding the value in * makes it contains instead of equal to.

cloud urchin
frank sun
cloud urchin
#

just try some of the parameters provided in the section, did you try what tlattuce said?

frank sun
#

yes

frank sun
obsidian scroll
safe star
wraith oyster
#

Hey everyone. I need help with proxies module. Nmap -proxies. It’s for CBBH learning path.

I can't seem to get Burp to intercept traffic when I use nmaj as described in the "Proxying Tools" section of the "Using Web Proxies" module.
I have ascertained that Burp is listening on 127.0.0.1:8080, and that intercept is "on" This is further tested by using curl with proxychains.
I do get intercepts that way.
I use the following command to scan with Nmap:
proxychains map --proxy http://127.0.0.1:8080
-Pn -sC-p 53756 94.237.51.209
the scan works, but nothing is intercepted by Burp. Nothing in the intercept window, or the hitp history.
Also, Using a proxy in metasploit (as shown in the section example) does the same thing. The scan seems to work, but Burp doesn't react.
PS: i tried to test it with cURL and Burp reacts and intercept the request normally.

obsidian scroll
soft reef
#

Anyone I can DM about DACL Attacks II - SPN jacking, doing it from Linux?

noble haven
#

Hey guys hope youre doing well , i had a question currently im in footprinting module in PENETRSTION TESTING JOB ROLE path ithink its way long to complete it , can i get some advices about how to do it faster and effectively

cloud urchin
#

imo your goal should be to absorb the material and understand everything in it. doesn't matter how long it takes. i'd suggest first reading the module. then following along with the module and writing notes down as you go. then do it again but only using your notes.

#

focus on really understanding why you're doing what you're doing and what the commands are doing. again doesn't matter how much time it takes for this.

mighty sierra
#

Anyine who have completed the final question on Kerberos attacks \DC01\Secret Share\flag.txt>

rough violet
#

so the first line is always filled with * * *? just to demarcate the start or something?

ancient niche
#

Good Morning I'm trying to get the flag at the module attacking web applications with ffuz in Value Fuzzing but i can't doing. Does anyone know why i can't geit it?

opal nexus
#

In the module 'Intro to Network Traffic Analysis' -> section 'Interrogating Network Traffic With Capture and Display Filters' -> first question 'What are the client and server port numbers used in first full TCP three-way handshake? (low number first then high number)'

what format should be the answer? ports seperated by comma? space? something else?

tranquil axle
#

space

snow quartz
#

Hi. I'm working on the SQLMap Essentials module, on the section Skills Assessment. I'd like to ask some questions regarding to the commands that I ran with SQLMap. So, is there anyone that I can reach out to DM at this time? Much appreciated

I think i finally figured it out why. I'm calling this off, thanks 😄

fickle thicket
#

Anyone already done advanced xss and csrf exploitation skills assessment? Any clue on what to do after becoming moderator

ancient niche
silent bolt
#

.

#

verify

#

@ancient niche

ancient niche
#

i have verify

silent bolt
silent bolt
#

@versed zealot

#

@fickle compass

smoky dagger
#

Hi

I am new to HTB and I was trying HTB Challenge - Pentest Notes..?
But I'm stuck..
Can someone Please guide me and help me with this.

silent bolt
#

@low girder

loud socket
#

Stop pinging everyone

silent bolt
loud socket
languid pike
slate zinc
#

this is ur ssh ip

languid pike
#

Er

#

Operation not permitted

slate zinc
#

ss?

shadow latch
#

i have a question about ssh command. When I am pivoting and I execute this command: ssh -D 9050 ubuntu@10.129.202.64, I can use socks5 instead of socks4?

languid pike
waxen totem
#

Sudo

slate zinc
#

try with sudo

languid pike
#

Okay done

#

I entered my pass and no response

slate zinc
#

now connect the vpn academy one

languid pike
slate zinc
languid pike
restive mango
#

Type yes

slate zinc
#

yes

#

and then it will ask for password
you will type it but for security reasons it wont show up
so just type and enter

#

you should see a new shell as in your prompt will change

languid pike
#

Alright give me a moment i tried to copy and paste then it closed the connection

restive mango
languid pike
#

I got the elcome to Ubuntu 18.04.5 LTS (GNU/Linux 4.15.0-123-generic x86_64)

languid pike
slate zinc
#

yeah ur in

restive crater
#

Guys Simple Question

I'm working on the Advanced Deserialization Attacks module, specifically in the Identifying Vulnerable Functions section
I'm trying to answer a question but keep getting it marked incorrect

The question is as follows:

There’s another instance of deserialization in the assembly that’s not included in the screenshot provided above. Identify it and submit the name of the serializer used.

After decompiling the code, I ran this command:

$ Select-String -Pattern "\.Deserialize.*\(" -Path "*/*" -Include "*.cs"

Here are the results I found:

TeeTrove\MvcApplication.cs:44:                  session = (Session)bf.Deserialize(ms);
+TeeTrove.Authentication\RememberMeUtil.cs:28:                   RememberMe rememberMe = (RememberMe)JsonConvert.DeserializeObject(cookie, new JsonSerializerSettings
TeeTrove.Controllers\TeesController.cs:83:                              Tee tee = (Tee)xs.Deserialize(new XmlTextReader(new StringReader(xml)));

I tried submitting the following answers:

  • RememberMe
  • rememberMe
  • JsonConvert
  • JsonSerializerSettings

However, none of these worked. Could anyone help identify the correct answer or explain why my submissions might be wrong?

languid pike
#

Yay, after so long it's done, thanks guys

#

Uh but theres no command prompt

restive mango
#

Good luck man!

languid pike
languid pike
slate zinc
#

it should appear after a few seconds if not press enter

languid pike
#

Oh okay it popped up after pressing enter

#

Thanks

dapper moth
ancient niche
#

someone can help me?

#

pls

frank vine
#

Hi, not sure where to report this but there is a broken link on the login brute force module (skill assessment 1). The link should be .../Passwords/Common-Credentials... , thanks

fathom pendant
frank vine
#

thanks

frigid carbon
#

Anyone here who could help me on DNS footprinting?

#

Am stuck for a while now

acoustic owl
ancient niche
#

i can't find the flag 😦

fathom pendant
ancient niche
#

probably but i'm tryied all

fathom pendant
#

Well without knowing what you're working on it's hard for anyone here to help you

ancient niche
#

oke one moment pls

fathom pendant
#

Is admin.academy.htb in your hosts file?

#

Your screenshot contains a flag

ancient niche
#

but ist error

tulip hearth
#

helloo need help. Exploit failed: NameError uninitialized constant Msf::Modules::Exploit__Linux__Http__Rconfig_vendors_auth_file_upload_rce::MetasploitModule::RHOST
i keep getting this error in msf

fathom pendant
fathom pendant
#

Also make sure all your options are set properly

ancient niche
fathom pendant
ancient niche
#

but i don't know to doing

fathom pendant
#

Every system has a hosts file

#

/etc/hosts

tulip hearth
#

where should i put login.php

#

in uri or targeturi

fathom pendant
#

You shouldn't need to change anything like that

tulip hearth
#

msf6 exploit(linux/http/rconfig_vendors_auth_file_upload_rce) > set RHOSTS 10.129.201.101
RHOSTS => 10.129.201.101
msf6 exploit(linux/http/rconfig_vendors_auth_file_upload_rce) > set LHOST 10.10.14.117
LHOST => 10.10.14.117
msf6 exploit(linux/http/rconfig_vendors_auth_file_upload_rce) > run
[] Started reverse TCP handler on 10.10.14.117:4444
[
] Running automatic check ("set AutoCheck false" to disable)
[-] Exploit aborted due to failure: unknown: Cannot reliably check exploitability. Can't access the rConfig web interface ! "set ForceExploit true" to override check result.
[*] Exploit completed, but no session was created.

#

previously before i restarted msf, i set ForceExploit to true

civic steeple
#

hello, i'm in Pivoting, Tunneling, and Port Forwarding, Page 3, Dynamic Port Forwarding with SSH and SOCKS Tunneling
i've completed the module using the proposed methods but for shirts and giggles i wanted to try ligolo-ng. It's having quite a time and won't seem to work, even after connecting from the attack machine to the host machine, it's as if the target has no internet access. is this just due to the configuration/limitations of the target in this module or SHOULD it work

fathom pendant
#

The only network access they have is internal

#

You'll need to transfer files

tulip hearth
#

im stuck in this modulee for a while now i dont get the miconfigs

#

i used rconfig, changed the rhosts and the lhost

#

can get a reverse conn

civic steeple
# fathom pendant You'll need to transfer files

i've transfered the zip file from the attack to the target successfully, got the machines to connect to eachother. are there other files i need to transfer? this is my first time using ligolo so i'm not exactly sure what the end result looks like yet

ancient niche
fathom pendant
ancient niche
#

the flag

fathom pendant
#

Make sure no whitespace in front or back of flag

dim hound
#

It should be a different flag than that...

ancient niche
#

probably but

#

i'm trying all

dim hound
#

I am sure 😁

#

Did you try to fuzz id at the admin page?

civic steeple
dim hound
# ancient niche

Well you see, the error .. proberly your hosts file isn't correct

ancient niche
#

mmm how can i put in good?

dim hound
#

dm me

#

Wrong channel mate

spring pelican
#

Sorry

dim hound
molten summit
nimble salmon
#

I am new to Hackthebox but have managed to capture some flags in the starting point labs and like what I see from the company as a whole.

My question is where should I go after capturing all the different flags in the beginner, intermediate, and advanced modules in starting point? I currently have the vip+ membership. 🙂

dark hedge
#

HTB Academy to fill in the gaps that Starting Point glossed over

#

or if you're already familiar with pentesting, you can move to doing the active easy machines

#

make sure to verify your account to get access to most channels -> #welcome

ancient niche
#

i can't doing

#

😦

frozen coyote
#

yo im in academy on the infosec fundementals path and the setting up module is killing me. im on mac and none of the instructions on VMware, parrot, or anything is downloading right or looking the same

#

this gonna affect me moving through the path properly?

#

seems like this is a home lab set up and if thats the case i should just be able spawn in browser machines

agile mauve
#

Hey, sorry for being a bother, but can anyone tell me what im doing wrong with my find command?

fathom pendant
#

I mean if you actually post it

agile mauve
#

sorry my snip and scetch is bugging out

fathom pendant
#

To get image perms you need to read and follow #welcome

#

Just copy/paste the command here

agile mauve
#

oh

fathom pendant
#

And wrap it in backticks (`)

agile mauve
#

thanks

#

find / -type f -name *.conf -size +25k -size -28k -newermt 2020-03-03 -exec la -al {}\; 2>/dev/null

hasty mauve
agile mauve
#

oh

fathom pendant
#

la is an aliased command iirc

storm elk
hasty mauve
fathom pendant
agile mauve
#

yes, i've made that mistake before

fathom pendant
agile mauve
#

hmmm

#

still not showing any results

#

find / -type f -name *.conf -size +25k -size -28k -newermt 2020-03-03 -exec ls -al {}\; 2>/dev/null

fathom pendant
#

Again are you sure you're running it on the target

agile mauve
#

yes

dawn bloom
#

like "*.conf"

agile mauve
#

ok

agile mauve
storm elk
#

What for?

fathom pendant
#

There's a whole module on XSS in htb academy

storm elk
#

So not a module 🙂 this channel is for help with modules. Might wanna post in #web

#

Or check out the modules like Marcie said

fathom pendant
#

Are you meaning rce and not xss?

acoustic owl
storm elk
#

#web is the place to be if not a module

#

It’s XSS either way

dawn bloom
#

You will have to research on google, the xss module I believe they are talking is very basic (The one that is on the cbbh path)

storm elk
#

The filename is printed and not escaped properly, that’s a simple XSS. But often overlooked

#

@rustic sage , this channel is for module help only. Please continue your question in #web If you can’t access that channel, read and follow instructions in #welcome

arctic fjord
#

wyo

storm elk
civic steeple
#

hello currently in Pivoting, Tunneling, and Port Forwarding, Page 4, Remote/Reverse Port Forwarding with SSH. Though the questions don't have you go through what you learned in the module, I am currently trying to perform a reverse port forward for practice purposes. The issue i'm running into is, after sending the backupscript.exe to the spawned target and starting the python3 webserver on the pivot host (spawned target), the module then shows running a command in PowerShell but never walks you through how you gained access to that windows machine in the first place, what am i missing?

cloud urchin
#

if you have creds there are a lot of ways. rdp, pssession, winrim

civic steeple
#

ok i considered rdp but totally blew off the creds i started with, let me try them

civic steeple
#

they wouldn't expect you to use creds from a previous page in the module would they?, tried them too, nothing

fervent cypress
#

W

cloud urchin
civic steeple
cloud urchin
#

ahh not sure then i'd have to re-read the module/section

civic steeple
#

i've even downloaded xfreerdp and rdesktop to the attack machine, sent them to the target machine but then the target machine needs some dependencies i can't find in order for those to work and i'm just not sure its meant to be this difficult at this stage lol

fervent cypress
#

How can I text in the general chat ?

fervent cypress
#

I did

#

It Brings me here

cloud urchin
#

and did you follow the instructions that tells you how to access other channels?

#

you need to mcverify your account

fervent cypress
cloud urchin
#

did you get your identifier from your settings on the website?

cloud urchin
#

well that's why... read the instructions again

fervent cypress
civic steeple
fervent cypress
#

I can text now

cloud urchin
#

oh wait

#

it is there, it's the creds from the previous section, username is victor

#

worked for me i just tried it

pale reef
#

I have been stuck for hours on the Abusing HTTP Misconfigurations -> Skills Assessment -Easy. I saw a forum discussion where someone seemed to hint they solved it without burpsuite, but I've tried with and without. I've tried all combinations of switching back and forth between the sign-in forms but to no luck. Has someone figured this one out?

#

Oh it was even simpler than the tutorial, but more tricky to find.

civic steeple
#

maybe i missed one

cloud urchin
autumn valve
#

hello everyone, i have troubles answering the second question of the "Print Spooler & NTLM Relaying" section from the Windows Attack and Deffense Module (SOC path). this is the question "After performing the previous attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and make the appropriate change to the registry to prevent the PrinterBug attack. Then, restart DC1 and try the same attack again. What is the error message seen when running dementor.py?", first, i dont know what it refers by "restart DC1" like restarting it like a normal pc?. and also, it seems to me that this question requires to have both the windows ws01 and the kali linux target active, which does not seem to work for me because only 1 works at a time

civic steeple
quasi wave
#

hi I am on the hard lab for password attacks module. I am having some trouble logging in as a user I found via SMB. Can someone help me out with this? because I'm scared I might spoil stuff I feel like DMing is good. I have a specific command and I think there's a syntax error. I log in using the password I found but it doesn't give me a connection it just authenticates and then leaves me same shell as before.

#

I don't want to spoil anything. Is anyone available to discuss one on one?

fathom pendant
tranquil axle
autumn valve
weak seal
#

Evening all! Anyone on that could take a peek at what I am doing wrong for Footprinting Lab - Easy?

analog dock
weak seal
#

Basically I am getting access denied when trying to use the commands from the cheat sheet to get the files I need.

gray yacht
# civic steeple hello currently in Pivoting, Tunneling, and Port Forwarding, Page 4, Remote/Reve...

Eh it's because the section doesn't really tell you that you need to actually move the backupscript.exe to another host on the internal network (or maybe it does). You can definitely figure it out, based on the payload created and other stuff, but yeah you have to do some other things that aren't super difficult to work through the example in the section. If you want help to work through it, you can DM me.

lean saddle
#

Hi

weak seal
#

I am able to successfully authenticate and view the files no problem but either trying to get the files while directly logged into the ftp server or via the mentioned wget command I keep getting access denied.

lean saddle
#

How can I help you?

ocean night
cloud urchin
weak seal
ocean night
dapper moth
quasi wave
#

hi guys I solved hard lab for password attacks

#

now I'm gonna do next module starting tomorrow

#

attacking common services module is gonna be great

signal pike
#

Hi, I'm doing the web proxies module and I like to do in my own VM when possible, the native burpsuite was giving me errors, so I reinstalled, but I want to call it and open thru the terminal too, how can I add it to the path and open with the 'burp' or 'burpsuit' keyword?

long kestrel
#

In one of the early CPTS modules I remember there being a section where they recommend a tool for capturing GIFs for including in reports, but I have not been able to find it again. Does anyone remember which one this is? I imagine it might be touched on again in the reporting module but I haven't gotten to that one yet

cloud urchin
#

there are a few. i like sharex. there's also greenshot.

long kestrel
#

thanks, ill check them out

cloud urchin
#

not sure you'd want to use gifs though

long kestrel
#

I was more wanting to use it for my notes than an official report, but iirc it was mentioned in the module for showing something in a report

#

I just can't find it again

ocean night
#

Yeah, GIFs in PDF.. does that even work?

cloud urchin
#

from the reader's perspective i'd imagine that's annoying. like if the just want to capture the command or one frame of the gif it can be difficult to get it.

#

i can't speak for how they'd handle it in a report but i'd avoid it personally

signal pike
ocean night
#

Have you reset your bash / whatever session?

signal pike
#

Yes

signal pike
ripe wadi
#

on the server side attacks module in the exploiting ssrf it says to uncoiver another endpoint

#

by endpoint we mean on the same web server roght?

cloud urchin
#

in the context of web stuff, an endpoint is just the full path to the resource accessed. so this: https://example.com/products/shoes is an endpoint. it's a specific url on a server that applications use to send or receive data. for an api, same idea, ```https://api.example.com/products/shoes

long kestrel
#

Oh my mistake, it was about note taking, not reporting. I found it in the Setting Up module. The tool they mentioned is Peek

river jetty
#

currently doing the SQL Injections fundamentals Assessment and I'm having trouble with the final part. When I write code into using
' union select "",'<?php system({Code}); ?>', "", "","" into outfile '{Path}'--
It gives me the error code of 500. Why is that?

weak seal
#

Anyone have issues being able to pull files from the FTP server on Footprinting Lab - Easy? I can connect directly on the "other" port and see the files I want to download and I have tried the other method via the cheat sheet but I still get access denied.

ripe wadi
fallow terrace
#

Hello! For the File Uploads Skills Assessment, does this request look correct or should there be a POST request as well?

frozen coyote
#

if i buy the annual subscription for the academy does that carry over to my plan type on htb proper at all? im using the same account

fathom pendant
#

They are separate platforms

pastel lotus
#

BROO

#

CTRL+SHIFT+V Into pwd

#

And it still says its wrong 😭

normal plover
# pastel lotus

Type the password 1 letter at a time. It still could be you're typing the wrong password

#

I've not used pwnbox for a long time but are you entering the username correctly?

frank robin
# pastel lotus

copy the password, paste it into a notepad, check for leading/trailing spaces, copy it from the notepad and paste it from there.

normal plover
#

Try ssh htb-student@10.x.x.x

pastel lotus
#

I'm legit practicing typing in the pwd 😭

frank robin
#

Restart the instance

normal plover
pastel lotus
#

OOOOOOOOOOOO I USED A UNDERSCORE

#

😭

normal plover
#

See

pastel lotus
#

When I typed the correct username the first time this what I did 😭

normal plover
lucid mortar
#

anyone run into trouble with using PassTheCert? I keep getting ssl errors 😦

rustic sage
#

Has command injections module been changed recently?

waxen totem
#

ehem <@&861185840277487616>

dark hedge
#

no, contact TikTok support

thin mantle
thin mantle
#

i’ll try tho thx

rustic sage
#

No one here for sure

#

U sound sketchy af

thin mantle
#

how do i sound sketchy if i was willing to give a stranger MY information for MY acc😂

#

but it’s alright

#

preciate the honesty

dark hedge
thin mantle
#

thanks for lmk tho

fathom pendant
#

Use ssh instead of telnet. Likely closed because insecure connection protocol

polar raven
#

My question is more why my nmap scan is not showing anything. Despite the port being open.
Was it on purpose ?

fathom pendant
#

I also suggest deleting references to internal machines because of the fact that you have to scan for hosts on the network

#

So you're spoiling content

polar raven
#

Yeah, I know but It just for understading

fathom pendant
#

🙄 likely filtered due to windows trust shenanigans

#

Filtered often just means that there wasn't a negative reply back

#

Not that there's an actual filter in place

#

So packet dropping, and things of that nature

polar raven
#

Actually after doinf the assessment, if found a review with someone doing proxychains ith meterpreter and the scan was clearly producing results and mine under SSH not ...

safe star
fathom pendant
#

Anyway, deleted your message since it's heavy with spoilers

safe star
#

sudo proxychains

polar raven
#

ah

polar raven
fathom pendant
#

I'm gonna keep whacking your messages

#

Lol

polar raven
fathom pendant
#

If you had to enumerate for it: redact it

#

No guarantee of a speedy reply

polar raven
#

I know but there are plenty more on the internet ... But Okay no problem I would redact next time.

fathom pendant
#

🙄

#

Pivoting is a t2 module

#

Utilizing a walkthrough for any module above t0 [that isn't the official one that comes with the annual subs] is cheating

night crypt
#

anyone having issues getting targets to spawn on the US regions?

#

have tried swapping between a few diff VPN servers but constantly stuck trying to spawn the machine

steel snow
#

yeah

#

i am @night crypt

#

hmmmmm it worked now tho

night crypt
#

mine just fired up in the last 30 seconds too

steel snow
#

it's been annoying me

#

the service been so slow lately

#

probably because how most people are in holiday

vague stag
#

guys

#

I need help with module 49, section 454,

#

it's Windows Essentials guys

#

sorry for saying it like some religious freak would, basically I need to enter the builder number which I've taken care of, no matter how I input the NT Version (which is 10.0.19041) it doesn't work

#

even if I put 10.0

#

\

storm elk
#

Read the question properly. 90% of the answer is already written in the question

fathom pendant
#

Windows 98, 99, 2000

#

Etc...

pastel lotus
#

Im struggling with linux fundamentals

#

navigation, cant find that hidden files

waxen totem
safe star
pastel lotus
pastel lotus
waxen totem
misty trench
#

why can i only type here?

safe star
waxen totem
storm elk
weak seal
#

Still having some issues on Footprinting Lab - Easy. I don't want to post any output here so I don't share any spoilers but I am able to connect with the credentials that were given on a certain port successfully but when I am trying to download the files from the FTP server I am getting permission denied. I check permissions of the files I am wanting to download and the owner is the same user I am logged in as. Anyone willing to help point me in the right direction?

vague stag
#

that's helpful, I looked it up and it always said do thse cmds

#

and gave me OS Versions

#

I thought that was right but I was failing to understand so I give you my grattitude for heping me succeeedd

cloud urchin
#

<@&861185840277487616>

dire lark
#

almost a year later and I still tried to enter "previous flag" as the password 🤣

devout garden
#

Quick question, in the "Setting Up" of Information Security Foundations, did you follow this step here and created a "Broadcom" account?

obsidian scroll
#

What is this error ?

waxen totem
#

Use single quotes, bash is tryna execute an expression

waxen totem
devout garden
fathom pendant
devout garden
fathom pendant
#

You can still install on vbox

#

Your mind has to be flexible, and Google is an arms reach away

devout garden
waxen totem
#

Half the time you just remote onto academy targets

pine dune
#

Hi

#

on the command injection module and doing the "Identifying filters" question, its not giving the right answer when I input it if im doing it correctly

#

am I allowed to share what Im doing to make it clearer? I dont want to give any spoilers away 😅

quick abyss
#

Hello
I'm trying to use metasploit on some easy boxes like nibbles,lame,blue and getting the same error "Exploit completed, but no session created". I have tried the following fixes but still no issues. Can anyone help me with resolve? - thank you!

Tried
Checked my settings
Followed walk throughs using Metasploit method
Updating metasploit
Checked db_status (shows connected)
Reset DB (deleting db, init, restart postgresql - still same issue)

hollow badge
#

Yo

lean saddle
#

Hi 👋

hollow badge
#

Why can't I chat in general

ocean night
hollow badge
ocean night
#

Read #welcome again and follow the instructions

hollow badge
#

Thanks

ocean night
#

No worries 🙂

pine dune
ocean night
#

What is it about?

ocean night
#

Read the title of the channel

#

If it's above Tier 0, do not post anything that would spoil the content

pine dune
#

which is why Id like to DM someone from htb because I genuinely think the website is wrong or something

ocean night
#

Then I'd advise leaving a message stating vaguely where you are having trouble, and perhaps someone will give you a nudge in DM

#

If you think there is something wrong on our (HTB) side, raise a support ticket

pine dune
#

ok how can I raise a ticket pls?

#

oh no worriess i found it thanks

ocean night
#

👍

devout garden
#

I followed all the steps written here, the VM restarted as it says, but instead of seeing window that asks us for our passphrase to unlock the system it is asking me to Install again, I restarted it a few times and it is the same thing, should I again follow all the installation process? Something got messed up?

#

I selected Try / Install again and I am in the home screen again, so I assume I should re-do the installation

unreal crescent
#

Just finished my Intro to Networking Module and to be completely honest, most of it was a refresher from College, but some of it I don't feel we covered very well in the classes lol

tranquil axle
devout garden
fathom pendant
#

Or mess with boot order

devout garden
#

My bad, I'll do it again

fathom pendant
fathom pendant
#

GPT will fuck you over

#

More often than not

devout garden
#

Hahaha

fathom pendant
#

I'm assuming the 'solution' you tried was GPT

devout garden
#

No no I played with the boot order but it didn't work, then I got stuck in a terminal tried to get out but something else got selected, not sure, I do it all over again, no problem

real burrow
#

Hello, who have worked on nformation Gathering - Web Edition - DNS Zone Transfers questions. I put nameserver to /etc/hosts, but I still can't run nslookup

acoustic owl
real burrow
#

ah ok

fathom pendant
#

Maybe you're misunderstanding the output

real burrow
lean saddle
#

Yeah I can do that 🙂

real burrow
#

I should see subdomains

fathom pendant
acoustic owl
# real burrow

.htb is not an official top level domain and therefore cannot be resolved by the root servers. Use the IP as a nameserver

ocean night
#

@pastel lotus right here

granite path
#

good day, I'm new here
glad to be here

acoustic owl
slate slate
#

I'm stuck at the same part can I dm you aswell?

real burrow
#

thanks, I understood

granite path
devout garden
# fathom pendant Dismount the iso

I dismounted it, I entered the key correctly, and then chose the first option: Parrot OS 6 GNU/Linux
Then I had the following 2 screens for a few minutes, which they make no sense as the passkey was correct.

#

Now it's stuck here

fathom pendant
#

Current iso version has an issue with the LUKS encryption mechanism

devout garden
#

I just followed the steps on the academy

fathom pendant
#

You don't need to encrypt unless you're a paranoid schizo

devout garden
waxen totem
#

They should really update the windows section cos ain't nobody getting their hands on that windows dev iso anymore

devout garden
#

Oh I didn't know, it seems pretty recent 🤣

fathom pendant
#

Always bet on the documentation on the OS website being accurate, and their own discord

#

If you popped into the parrotsec discord for even a minute you'd know this is an issue

ocean night
#

Right here @pastel lotus - show us

waxen totem
ocean night
#

0917

fathom pendant
#

G0blin sleeps?

ocean night
#

We don't talk about sleep

fathom pendant
#

(I know, ironic coming from me)

pastel lotus
fathom pendant
#

Are you sure that's what it has, or just what your data can contain

#

Unless you can have it pull specifics, calling bs

slate slate
#

I've tried a lot and I'm stuck on module 57, section 516 Skill Assessment Part 2. I'm also pretty sure I discovered something that should not be possible and will lead anyone down a rabbit hole (cusswords in a working login).

I read the entire page, tried bruteforcing with and without the username from skill assessment 1 and not sure what to do.

If someone could reach out to me, I would really appreciate it

fathom pendant
slate slate
fathom pendant
#

It's a second order attack. Iirc the assessment is on a public ip and port

slate slate
fathom pendant
slate slate
astral tundra
#

Hello guys, i am new here, currently i am doing HTB Prolabs and i have already completed Dante and i am working on Zephyr.. Actually i am kinda stuck at the pivoting part, I tried using Ligolo and Chisel but it is not working… Can someone plz help me out…Thank you

fathom pendant
devout garden
fathom pendant
devout garden
#

Should I still follow the rest of the steps in Setting Up or half of the stuff will not work since it's old?

fathom pendant
devout garden
slate slate
fathom pendant
#

The password isn't gonna contain cursewords

#

Also make sure you specify the port

slate slate
upper haven
#

Hi everyone, I just pushed a major update to all labs in the Advanced XSS and CSRF Exploitation module that removes any port-related issues. This should enable significantly easier debugging and testing of payloads, removing unnecessary complexity and potential for frustration. I apologize for any frustration caused by the previous lab setup. Let me know if anyone identifies issues introduced in the update 🙂

sonic seal
#

Kerberos Attack Module - Unconstrained Delegation - Users

Does anyone get the same error and doesn't get the ticket?

chrome hawk
sonic seal
tranquil axle
chrome hawk
#

Better try the time sync though, it seems like people have solved the same error by syncing time 😅

tranquil axle
#

Or just reset lab heh

coral surge
#

hello i have a problem at the first module of tier 1 i cann ot connect to the site where i have to do the sql injection

#

i use openvpn and not the virtual machine or pwnbox

#

please help me

coral surge
#

Learn the basics
of Penetration Testing on this on

#

the tier 1 and the exercise appointment

waxen totem
coral surge
#

ok sorry but it s written that i don't have access at this server

fathom pendant
slate slate
fathom pendant
slate slate
fathom pendant
sonic seal
ancient niche
#

Good Morning someone can say me why have i so error here?

ember fern
ancient niche
#

and how can i doing that?

ember fern
#

remove the -fs option

#

which filters by size

#

make sure you understand what the command is doing

chrome hawk
# sonic seal I didn't solve it syncing

Time is yet another can of worms. Your virtualization solution (VMWare, Virtualbox etc) tries to actively sync time of your VM to that of the host, and it is not desirable (we want to sync time with the target). That auto sync feature of VMWare etc needs to be disabled

ancient niche
#

i removed and the same

sonic seal
chrome hawk
sonic seal
#

This was my settings. I think I already had disabled. Thanks! I didn't know this

chrome hawk
#

That's nice

chrome hawk
fathom pendant
fathom pendant
#

My other thing would be making sure the target is still alive

sonic seal
ancient niche
chrome hawk
dapper moth
sonic seal
ancient niche
#

i still have an error

versed eagle
#

Currently doing the Lab Warmup for Advanced CSRF & XSS Exploitation, but can't seem to access the csrf.labintro.htb site on both the Pwnbox as well as via the VPN.

Hosts file is configure correctly, and I am able to successfully access the xss.labintro.htb and exploitserver.htb sites.

Anyone else having issues with this? The server for csrf is not responding, and burp browser says:

Error

Failed to connect to csrf.labintro.htb:443

storm elk
#

Have you tried respawning?

#

Make sure you didn’t make a typo in your hosts file. I accidentally wrote crsf

versed eagle
#

This is the entry in my hosts file:

10.129.129.102 exploitserver.htb
10.129.129.102 xss.labintro.htb
10.129.129.102 csrf.labintro.htb

I did try respawning as well, but no luck

storm elk
#

Which region? I’m on EU academy 3.

versed eagle
#

For the Pwnbox I used UK and for the VPN I'm on EU Academy 1

#

Just tried EU Academy 5 as well, and also doesn't work there

storm elk
#

Working fine here on my end

versed eagle
#

Hmm, strange. The fact that I can access xss and exploitserver confuses me

storm elk
#

Yeah. Try remove your record and put it in the same line as the XSS one. Maybe theres an ambiguous character somewhere

versed eagle
#

Hmm yeah now it suddenly works lol. Thanks!

storm elk
#

Awesome 🤩

versed eagle
#

Now I can't access my exploit server 😂 . I will just come back to it later. Chances are it will suddenly work again hahaha

storm elk
#

Try to put the exploit server in the same line too

#

There’s no point in having 3 lines for the same ip 😅

#

Then you need to update just 1 ip if you respawn doge_finger_guns

versed eagle
#

Will do! Indeed, idk why I put it on 3 lines 😅

autumn valve
#

hello everyone, i have troubles answering the first question of the PKI-ESC1 section from the Windows Attack and Deffense module (SOC path). this is the question "Connect to the Kali host first, then RDP to WS001 as 'bob:Slavi123' and practice the techniques shown in this section. What is the flag value located at \dc1\c$\scripts? ". the problem is that, after using the PS command ".\Certify.exe request /ca:PKI.eagle.local\eagle-PKI-CA /template:UserCert /altname:Administrator" as described in the section, this error shows up "[X] Error sending the certificate request: System.Runtime.InteropServices.COMException (0x800706BA): CCertRequest::Submit: The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)
at CERTCLILib.ICertRequest3.Submit(Int32 Flags, String strRequest, String strAttributes, String strConfig)
at Certify.Cert.SendCertificateRequest(String CA, String message)
at Certify.Cert.RequestCert(String CA, Boolean machineContext, String templateName, String subject, String altName, Boolean install)", i really dont know why that is happening or how to fix it, and the steps are clear and easy enough to know that i am not doing anything wrong, but idk

ancient niche
#

Someone can help me pls?

acoustic owl
ancient niche
fathom pendant
#

The question doesn't deal with subdomain fuzzing

vale stag
#

Hi

ancient niche
#

i don't know because i cannot get the flag

storm elk
vale stag
storm elk
vale stag
#

Thanks

acoustic owl
fathom pendant
#

Iirc

acoustic owl
ancient niche
#

mmmm

#

oh my good

prisma scroll
#

L

#

Wwwwww

ocean nymph
#

guys pls help what should i do here

#

pls help

#

@ocean night

acoustic owl
ocean nymph
#

i dont know

#

@acoustic owl

harsh gorge
#

Good luck!

acoustic owl
ocean nymph
sturdy laurel
#

Hello guys, I am stuck on this Skill assessment section of sqlmap esssential i don't see any potential attack vectors

dire solar
#

Who can recover my hacked account?

analog dock
ocean night
wooden trail
#

I have a question regarding module Linux Privesc, exercise Environment Enumeration, "Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer.".

Which is the expected approach? Being honest I just grepped for the expected HTB flag structure, but that doesn't look like I was expected to do so.

ancient niche
#

I cannot get the flag oh my good

wooden trail
ancient niche
wooden trail
#

module and section?

#

okay, found it

ancient niche
#

attaking web applications with ffuf

wooden trail
#

why are you bruteforcing vhosts?

ancient niche
#

i don't know

wooden trail
#

try to understand what you are really doing, what is that custom wordlist? why would you use it?

#

why would you be bruteforcing subdomains like 1.academy.htb, 2.academy.htb... 100.academy.htb...?

ancient niche
#

basically i don't know i am a noob

ocean night
#

Sometimes you just gotta throw a hail mary

#

Just to be sure

#

😄

wooden trail
#

section is telling you that sometimes there is some data that can be bruteforced contained in POST requests

#

if a POST request is requiring an "id" parameter and you have just created some "ids.txt" wordlist, it seems like you need to fuzz id parameter with it

ancient niche
#

but i don't know because i cannot get the flag

ocean nymph
#

yo

lean saddle
#

Yeah I can do that 🙂

wooden trail
ancient niche
#

then what i do

wooden trail
# ancient niche then what i do

I have already given you an enormous hint (pretty much the solution hahahaha)

Cant provide you with the exact command. Would recommend re-reading.

ancient niche
ocean night
#

I advise you go back over the module / section content carefully

#

Keep in mind the advise you have been given here

wooden trail
ocean night
#

snap

ancient niche
devout garden
wooden trail
clear zephyr
#

any modules related to AI prompt testing?

ancient niche
#

Thank you guys i love so much

wooden trail
wooden trail
devout garden
#

Tell us the secrets

rustic sage
#

hi

#

why I cant message in general

devout garden
rustic sage
devout garden
rustic sage
#

oh alright

devout garden
#

I had the same in the beginning 😄

rustic sage
#

thanks for the help

devout garden
#

No worries

ancient niche
#

I got itttttttttttttttttttttttttttttttttttttttttttttttttttttt let'ssssssss goooooooooooooooooooooooooooooooooooooooo

#

uffffffffffffffffff

#

this is very hard xD

wooden trail
ancient niche
#

the funny thing was that i didn't do it xDDDDD

pale reef
#

I am very close to having finished the Abusing HTTP Misconfigurations -> Skills Assessment - Hard. I already have the xss payload working succesfully, as when I enter the page the xss executes. automatically. However, it seems like the admin is sleeping and never executes my xss. I tried various values for the Host field since the admin might not be using the public ip address but nothing changed. I would have expected the admin to use the vhosts given in the skills assessment instructions. I used the vulnerability from the module to make sure other keyed fields were not triggered and so when I just open the page normally it executes the xss immediately without me changing any header values. Does someone have a clue why the xss is never triggered by the admin?

ripe wadi
#

on the server side attacks skills assesement sshould i be doing a blind jinja injection

ocean night
#

Read the module / section, you will find it there.

sonic plume
ripe wadi
#

i was trying the wrong payloads

pale reef
#

Did you figure out the assessment? I can dm you if you still haven't poisoned the web cache since I did get that far.

ripe wadi
#

for a different template engine

pale reef
#

What is the mention limit? There were 6 users who had unanswered questions on the Abusing HTTP Misconfigurations hard skills assessment, and I wanted to mention them all to see if they could help me or I could help them.

pale reef
storm elk
#

Dm me what you got

dapper moth
wet osprey
#

Excuse me,

i was stuck at the question on Learning Progress.

The question is : What is the difference between the two numbers of the learning progress mentioned above?

I understood the question, is something about 1% of our performance but where i write this, that tell me is the wrong answer :/

mint lark
#

Does anyone know which character can bypass the space to make the following command work correctly in the Bash terminal? %09, ;, and %0a don't seem to work:
bash<<<$(rev<<<'dwssap/cte/ tac')

heavy tapir
#

Hello. I am a little stupid. Can anyone teach me how to hack stuff ?

tepid holly
#

Bruh

compact patrolBOT
mint lark
safe star
#

Just base64 at that point 😭

#

Why not just cat+space+flag?

mint lark
harsh gorge
mint lark
ancient niche
#

I only have one section left to complete the module. Thank you all for your help.

wooden trail
#

in case u didnt know

#

you'll get access to ton of them

ancient niche
autumn valve
fresh stone
#

Sorry if its not the right place to ask but has anyone been experiencing connection issues with the vpn or the pwnbox. For example i keep losing connection to the vpn i have to manually restart it every 2m, if i use the pwnbox and have an ssh connection it randomly freezes and I cannot do anything

autumn pilot
#

Check if you have multiple tun interfaces created by the VPN, if you do - terminate them

cloud urchin
olive fiber
#

Anyone has solved the section Reconnaissance and Bruteforce of the WPA/WPA2 module? I have completed all other section included skills assessment but cannot get the pin for that secrtion

fresh stone
fathom pendant
fathom pendant
#

Also iirc rev doesn't flip bracket directions

harsh gorge
fathom pendant
#

Sorry wrong reply lol

#

Thought I replied to the other guy

next sleet
#

hi all. I was just doing "Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows" section (https://academy.hackthebox.com/module/143/section/1487) and I found something that I believe is a bug (correct me if I'm wrong, please)

The task at the bottom of the sections says you need to obtain the TGS for the mssqlsvc user, and we I did it using Rubeus, I got a string starting with $krb5tgs$23$*mssqlsvc$FREIGHTLOGISTICS.LOCAL$MSSQLsvc/sql01.freightlogstics:1433@FREIGHTLOGISTICS.LOCAL*$. I tried to crack it with john, but it couldn't recognize the hash format. So I extracted TGS ticket for a different user and I managed to crack it.

In the end, I modified the ticket of mssqlsvc user to start with $krb5tgs$23$*mssqlsvc$FREIGHTLOGISTICS.LOCAL$MSSQLsvc/sql01.FREIGHTLOGISTICS.LOCAL@FREIGHTLOGISTICS.LOCAL*$ and then I could finally crack it using john.

safe star
#

Hashcat at never failed me 🤷‍♂️

next sleet
#

I haven't tried with Hashcat, but still, this part freightlogstics:1433 did look weird to me

fathom pendant
#

Not that weird

#

Look at what port mssql runs on

next sleet
#

I meant the missing i typo

fathom pendant
bright coral
dapper moth
next sleet
#

no, actually I just tried it with GetUserSPNs.py from linux, and it gave me the correct hash for mssqlsvc user. I guess the problem is with Rubeus

pastel lotus
dapper moth
#

I’m going through the module again can check if Rubeus will mistype the SPN

next sleet
#

ok, if you need any screenshots or anything, I can provide them to you

dapper moth
#

That’s ok

pastel lotus
#

OOO i figured it out

pale reef
#

I got the http misconfigurations module solved (with some help). If anyone else has questions I can try to give some clues.

weak crescent
#

Howdy! I'm currently starting out with HackTheBox, doing the Nibbles - Privilege Escalation and I'm pretty sure I require to download the script LinEnum.sh from GitHub, but the pwnbox doesn't allow me to access github.com... Is this an issue or misunderstanding on my part?
-# (I Ctrl-C'd because it didn't go anywhere and on Firefox it returns the Timed Out connection error)

real delta
#

Also all of the boxes don't have Internet access. You'd have to transfer it from your machine to the box

weak crescent
real delta
weak crescent
#

Well, yeah but what I understood from the module description was that I served this file through the pwnbox and download it from the reverse shell in the penetrated machine

#

is that not the case?

bright coral
weak crescent
#

I can't find the file in the filesystem of the pwnbox, so I thought I had to download it from github

torn sable
#

pm_211 yur blez hak

fathom pendant
torn sable
#

delat

#

plez

ocean night
torn sable
#

hello

bright coral
#

github should be fine though

weak crescent
fathom pendant
real delta
weak crescent
dark hedge
#

it's called linenum, for enumeration.

thin owl
#

people are still confused about linpeas and auto exploit lol

dark hedge
thin owl
#

it failed a few people a while ago (2021) because in order to validate one of the sudo priv esc it actually performed it and was classified as auto exploitation - the author fixed this so it wouldnt do that anymore, but people still ask if linpeas is allowed in the oscp

ocean night
#

They really limit automated tools quite a bit don't they

thin owl
#

yeah

ocean night
#

I think they allow one use of metasploit?

#

or did when I took it

thin owl
#

yeah thats right

#

same with meterpreter payloads

ocean night
#

but unsure on the rest, I did everything else by hand

weak crescent
ocean night
#

yeah

#

Like you couldn't just go grab all the exploits and pwnpwnpwn

thin owl
#

they want to drive peoples ability to do stuff themselves

ocean night
#

It was rough, I won't lie

#

but seeing that sweet 100% and physical OSCP card (when they still did them - sorry, total brag)

thin owl
#

it helps a lot when youre in real engagements and need to explain to clients and technical teams how attacks work

ocean night
#

Gooood feels

thin owl
#

I loved the wallet cards

ocean night
#

Yeah 😄

thin owl
#

I like physical copies of stuff, its tangible 😄

ocean night
#

Flip it out, sorry maaam, OSCP, I need a quick word

#

(joking)

thin owl
#

you mean THIS

ocean night
#

Hah, get right up in there

#

Short sighted? Your fault. I'm here!

thin owl
#

sorry to everyone for spamming modules 😄

ocean night
#

Whoops

fathom pendant
thin owl
#

I am all for efficiency irl though, but during courses, the primitive is to learn how they work before you pew pew

fathom pendant
#

Honestly I've only used msfconsole when I cbf to find a working exploit or the exploit is py2 and I cbf to refactor to py3

thin owl
#

thats fair, ms08-017 is fussy with pythhon but works pretty reliably in metasploit

fathom pendant
#

Refactoring py2 code to py3 is actually good practice though

thin owl
#

yeah, I like to do that too

fathom pendant
#

I used 2to3 then Google fu the remaining errors

thin owl
#

especially since 80% of exploitdb is py2.x

fathom pendant
#

Cause 2to3 does like 3.7 iirc and 3.9+ is just different enough KEK

thin owl
#

recently theres been an issue in 3.12 where they reworked and renamed imp so heaps of stuff is broken now

dapper moth
#

But it's not a problem for Rubeus

#

It's in the SPN of the Service Account

#

It's misspelled

#

If you try to retrieve it via PowerView it still shows the misspelling

#

And it won't retrieve the krb5tgs hash via PowerView

#

In the Module content it is also misspelled

#

Nevertheless it's cracked successfully with Hashcat

next sleet
#

ok, good to know

#

thanks for checking

potent sandal
#

hey guys hope everbody doing shell feelsamazingman
guys one question after mkdir NFS i wanted to do
sudo mount -t nfs 10.129.194.101:/TechSupport ./NFS
when i wanna open the NFS directorie he tell me that i dont have the permission

#

┌─[us-academy-4]─[10.10.14.6]─[htb-ac-1660468@htb-ahrrqjuuk7]─[~/Documents]
└──╼ [★]$ sudo mount -t nfs 10.129.194.101:/TechSupport ./NFS
┌─[us-academy-4]─[10.10.14.6]─[htb-ac-1660468@htb-ahrrqjuuk7]─[~/Documents]
└──╼ [★]$ cd NFS
bash: cd: NFS: Permission denied

#

drwx------ 2 nobody nogroup 65536 Nov 10 2021 NFS

civic steeple
#

is this the right channel for VPN assistance?

dark hedge
#

you may want to ask support on the website

civic steeple
#

is the VPN typically much slower than connecting to the target with the pwn box?

safe star
#

in my experience yes

wild sage
#

Is there anyone I can dm about the skill assessment for Server Side Attacks?

#

Having some difficulty figuring out the payload

cloud urchin
#

<@&861185840277487616>

ocean night
#

wtf lol

upper ruin
#

Windows Privilege Escalation.

Other files - section

Using the techniques shown in this section, find the cleartext password for the bob_adm user on the target system.

I did search the entire packages folder, where in the module it's said to contain passwords ( uers likely store them there). Yet, I have found nothing. Any hints?

upper ruin
#

By any chance, are you on Linux PrivEsc? I have seen that before.

gray yacht
fathom pendant
#

Just mounting a share

pure finch
#

can someone help me figure out how to find the path to the student directory?

wild sage
upper ruin
#

unless I am doing a mistake

fathom pendant
upper ruin
#

Oki

fathom pendant
#

There's a list of handy commands given, I suggest trying and looking into those

pure finch
upper ruin
fathom pendant
#

Like right at the top

ancient wigeon
#

hypertext module, first module, I'm looking for the flag after i put the s and 0 and everything

acoustic sparrow
#

marcie
do you anything about
skillassesment kerberos attacks

fathom pendant
#

No

acoustic sparrow
#

❤️

fathom pendant
#

I haven't done any of the t3 modules

acoustic sparrow
#

gottcha

upper ruin
pure finch
ancient wigeon
#

if anyone knows what I'm looking for in the noob module and can help me lmk lol

upper ruin
compact patrolBOT
tulip hearth
#

idk why but shells and payloads live engagement takes forever to load the target

rustic sage
#

I wonder if HTB will release a module about WPA3

safe star
tulip hearth