#modules

1 messages · Page 373 of 1

tulip hearth
#

btw, what broser did u guys use for the live engagement? just the tor browser?

ocean night
#

You'd never use Tor for a live engagement I don't think

#

Slow, traffic potentially intercepted, and what's the point if you're on a live engagement that you have permission for?

tulip hearth
#

im currently doing it now and im confused to what browser to use hahah

rustic sage
ashen brook
#

Hi everyone
What's cooking

rustic sage
#

wsg

safe star
tulip hearth
rustic sage
misty current
#

I don't think so, he's genuinely just asking for a doubt I guess

storm elk
#

No. That’s one of the commands in the module

pine dune
#

Ok cool, just wanted to make sure. Thanks guys

dry folio
#

Wait why can't i talk in general?

ocean night
#

@eager ledge please read the subject of this channel.

#

That was a tier 2 module.

eager ledge
#

How do I ask question then?

#

@ocean night

ocean night
#

Without pasting the content and attempted answer

#

Describe which module and section you're on, and a bit about how you're stuck

#

Someone may nudge you here, or in DMs

ocean night
#

Did you follow the instructions?

eager ledge
#

Module: Linux Privilege Escalation
Section: LogRotate
Section link: https://academy.hackthebox.com/module/51/section/1589

I have compiled the binary and ran the exploit against the log file that we have write access to. The payload I am using is the reverse shell. I am triggering the log rotate by appending to the log file. However, I don't get reverse shell. Why?

ocean night
#

Thank you @eager ledge - appreciated

daring tundra
eager ledge
ocean night
#

I'm afraid I am unable to help with queries on content, sorry zombiiieee 😦

eager ledge
#

I was actually asking @safe star

ocean night
hallow cobalt
#

Start hacking with me

fathom pendant
hallow cobalt
#

Ok

#

@eager ledge yes sure

safe star
#

😭

gloomy basin
#

Hello

hallow cobalt
#

@gloomy basin @gloomy basin hi

gloomy basin
#

I’m new in crypto currency’s
I need help

storm elk
#

This is not the server for it @gloomy basin

#

This server is not about crypto.

hallow cobalt
#

This the server is about hacking @gloomy basin

gloomy basin
#

Ok teach me hacking

compact patrolBOT
storm elk
#

Read the guide above.

hidden urchin
#

hey i am on the skill assessment section of information gathering i have found till the dev subdomain and i have added it to the hosts file i have crawl dev and web both i am not able to find answer for the last 2 question what approach should i follow to do so

rustic sage
#

sup, anyone know any odat tool analog?

sonic seal
#

How can I solve this?

autumn pilot
#

Focus on how you authenticate

boreal basalt
#

Hi i'm on the Login Brute Forcing Module with this topic "the what is the password for the basic auth login?" on the skills assesments.

i dont want any help just clarification about this :

#

Why am i getting no http server is this normal bc on the forums they talk about the http server no the smpt, or ssh (i already try it)

primal drift
#

here we go

boreal basalt
#

wow

soft reef
coarse panther
viral lotus
#

in the ad enumeration & attacks module for question in living off the land: Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer. is the intended route to use wmic like in the chapter above I tried it initially it took ages, so I used Get-ADUser. In the end I got it with a wmic query was just a cog spinning question. thanks

pine dune
#

Hi

#

I need help with "Bypassing Other Blacklisted Characters" in command injection. heres what Ive tried

#

${PATH:0:1}${IFS}home

#

${PATH:0:1}home

ancient niche
#

Goog Morning people i need some help. I'm stuck here

opal nexus
#

The weekly streak is still faulty - It jumped for me from 32 to 39 (now 40 after i made some module progress)

frigid carbon
#

Anyone who could help me with cracking an IPMI hash?

#

from the ipmi footprinting module

opal nexus
frigid carbon
#

Yeah nvm i got it, i did it by exporting the hash in metasploit instead of just copy pasting it from the terminal haha

#

i think the formatting was a bit fucked. Thanks though

opal nexus
pine dune
#

I tried adding an ls before those paths too

opal nexus
boreal basalt
ocean nymph
#

guys can anyone help me with this

#

helppp

olive fiber
#

Yes,that one

narrow oriole
#

quick question, how do i minimize the font size

#

another question how do i clear terminal action history, i wanna type it out all the time even though its long for me to familirize, seeing it makes it hard to familiarize knowing you have something to copy

ocean nymph
hasty mauve
narrow oriole
hasty mauve
ancient niche
#

pls someone can help me with this?

gray merlin
#

Here is how I built NimExec for both Linux and Windows. Clone it into /opt/NimExec then use Docker:

FROM nimlang/nim:1.6.12-ubuntu
WORKDIR /usr/src/app

# Install required system packages
RUN apt update && apt install -y \
    mingw-w64 && \
    apt clean && rm -rf /var/lib/apt/lists/*

# Install required Nim packages. Not 100% version 0.2.0 of ptr_math is necessary.
RUN nimble install -y nimcrypto hostname && \
    nimble install -y ptr_math@0.2.0

COPY . /usr/src/app
CMD ["bash", "-c", "nim c -d:release --gc:markAndSweep -o:NimExec Main.nim && nim c --cpu:amd64 --os:windows -d:release --cc:gcc --gcc.exe=x86_64-w64-mingw32-gcc --gcc.linkerexe=x86_64-w64-mingw32-gcc --passL='-static-libgcc -static-libstdc++ -lws2_32' -o:NimExec.exe Main.nim"]
docker build -t nimexec-builder .
docker run --rm -v /opt/NimExec:/usr/src/app nimexec-builder
boreal basalt
# boreal basalt i have something thanks !

sorry to bother you but i don't understand what's happening,

when i refresh the page they are always different sites on the same box, and there isn't a login (for the module login brute forcing)

all this weekend i've been refreshing ip.
Am i doing a thing wrong ? like doesn't understand topic

Thank again for your help
@soft reef

ancient niche
#

i find stuck here someone can help me?

fathom pendant
ancient niche
#

but where ist that?

fathom pendant
ancient niche
#

is

fathom pendant
#

Google, ffuf --help pick your poison

ancient niche
#

oke oke thanks

fathom pendant
ancient niche
#

in google?

fathom pendant
#

Or in the terminal

#

man <command>, <command> --help are common ways to figure out command options

versed mantle
#

Is this serer teaching how to be a hacker?

fathom pendant
compact patrolBOT
fathom pendant
#

Some commands as well may not have man pages

ancient niche
#

then?

fathom pendant
#

Most commands have a -h or --help flag

ancient niche
#

this ist very difficult oh my good xD

gray yacht
#

What does the error displayed tell you?

ancient niche
#

i don't know xD

analog dock
# gray yacht

That you don’t have that file in your home directory

ancient niche
#

ahhahahahah😅 😅 😅 😅 😭 .

gray yacht
# ancient niche i don't know xD

Well 0x56 hooked you up with the answer, but I highly recommend you take the time to troubleshoot and research errors you receive. Most things you can easily Google and others might take some Google Fu, which IMO in the end will help you out as being able to troubleshoot is just as important as everything else.

hollow charm
#

in "sqlmap essential" module "Attack tuning" session, i am finding flag6
i used the following sqlmap option but the 'col' parameter is not injectable.

||sqlmap -r req.txt --batch --dump -T flag6 --prefix="')" --suffix=" -- -" --level=3 --risk=3||

how can i resolve it?

ancient niche
potent sandal
#

NOPE was my fail ... as a root i had acceess

#

Yes was because of using the normal user. Had to switch as root user

ancient niche
#

I still can't find it,how clumsy I am, my goodness.😅

bright coral
fathom pendant
ancient niche
fathom pendant
#

Match regex, you already know what to match

#

That's gonna be the option under ffuf --help

ancient niche
fathom pendant
#

I believe you also should know which file extensions to use

ancient niche
#

haha i think that's the problem xD

fathom pendant
#

The questions build on each other

#

Also when you go to submit the answer use PORT and not the actual given port

ancient niche
#

but the port gives error

fathom pendant
#

when you go to submit the answer

#

Not while you're fuzzing

fathom tide
fathom pendant
ancient niche
fathom tide
#

my antivirus blocked it when i tried to login i put it in exception the same issue persists

wooden moss
boreal basalt
#

@soft reef
i retried and i have this :

#

no http server, am i doing something wrong ?

fathom pendant
#

Public ip and port means you're given a specific scope

#

It's a docker container

olive fiber
devout garden
#

I feel sorry for @fathom pendant , trying to help everyone😂🙌

boreal basalt
eternal blade
#

Hey, can someone help me in the SQLMap skills assessment?

fathom pendant
#

Open the network tab, and click around until something pops up

eternal blade
fathom pendant
eternal blade
#

in source page appear id:1, but i use this command

#

can i send the command here?

fathom pendant
#

That'd be spoiling things. Consider just saving the request, as shown by the module

eternal blade
#

ok, i will try here

#

if i have another question can i ask in this channel? or have any channel for ask questions about the academy?

fathom pendant
#

Nothing you'll be required to do hasn't been shown by the module

rough comet
#

hello folks... quick question about Password Attacks - Credential Hunting in Linux .

I've found two ways to resolve this. The 1st one is based on || history || and what we found there. The 2nd one, we use a tool. Is this intended? I'm just curious .

fathom pendant
#

Yes

rough comet
#

Interesting

#

so... two ways to do it I guess?

fathom pendant
#

More than one way to cook an egg

rough comet
#

Indeed. Thanks!

#

Cool module. I gotta write some notes.

misty elk
#

**CWEE path: CSRF Exploitation > CORS Misconfigurations ** Can I DM someone? Not sure why my code isn't working...

rustic sage
#

has anyone gone through the AD module Active Directory Enumeration & Attacks recently?

#

in the section for Kerberoasting from Windows its suggesting hashcat mode 19700 for TGS with AES128 encryption but I cannot get this to work

#

nevermind its working now

eternal blade
rustic sage
#

hi,does hackthebox teach frameworks

real delta
rustic sage
real delta
#

There are tons of technologies that HTB teaches.

rustic sage
real delta
rustic sage
#

yeah something like that

acoustic owl
#

Look at the CBBH path. It's all about such vulnerabilities.

rustic sage
late depot
#

Hello brethren

tiny eagle
#

hello

pine phoenix
#

This academy module for mutations seems like such a mega powertrip. Could easily teach the same principles without having to waste so much of the users time brute forcing a massive list. Genuinely disappointing.

icy cove
rustic sage
#

This got me too

hexed oyster
#

I'm working on the final assessment of the Insecure File Upload module. I've exfiltrated the files, I've bypassed the allow and deny list, I know theoretically where the files are uploaded to, but I'm constantly receiving 404 errors when I try to navigate to them on the server. I've checked it with burp repeater and I'm at least in the correct subdirectory, but for whatever reason I can't find the file. Does anyone have any suggestions on what I need to re-read to figure this out?

gray yacht
glass locust
#

Windows lateral movement - skills assessment - second question. I have IPv6 address and required password. I established pivoting with Ligolo. Still I can't see any open ports on that IPv6 address. Tried with nmap -sT -Pn and all other methods. Tried Chisel / proxychains, no result too. Any nudge?

dapper moth
#

There a couple of ways to perform that IPv6 Port Scan and they are all locally

#

The stuff in the txt

#

The Ports are methodologically configured to non-default ones

#

So if you Port Scan a Host, you will know what the Ports are

glass locust
#

Make senses. I saw it's locked and I have read the hint. But what I can't understand is how to quickly identify how to move and to which service (rdp/winrm/ssh etc)?

dapper moth
#

Try the different services

glass locust
#

So the full portscan using PowerShell from first host is the way to go? I thought it's waste of time

dapper moth
#

Forget about Port Scanning

#

Try the different services

#

But you can try the ones you have already enumerated with the Test-Connection

glass locust
#

not sure I understand you. first you say "if you port scan the host..." then "forget about portscan" 🙂 I tried winrm/rdp/ssh as well as other things but I assume the port is random

dapper moth
#

Forget about Port Scanning IPv6 enabled interface 😂

#

Haven’t you Port scanned the first Host already?

glass locust
dapper moth
dapper moth
#

If you already scanned one Host, you know what the Ports are

#

You can try the services on that ports

#

Or if you are stubborn (like I was and spent a day just to be able to perform it), you can either use Test-Connection on those specific numbers or there is a standalone scanner for Windows from a company, but it will also take forever if you are scanning all 65535 ports

glass locust
#

yes, thats what I thought. too much time. but I can't understand how open ports on Support host can help me move to IPv6 WSUS host. you mean if (for example) port 8920 would be RDP on Support it will mean it's also the same for WSUS? not sure I follow the path rn

dapper moth
#

It’s the same values…. It basically limits to a handful of non-default ports
You can use PowerShell to do it

dapper moth
#

I wouldn’t trust the txt, but the answer I got from HTB is that they were not configured randomly in each Host

#

They followed a method

#

Like all Hosts having RDP running on the same non-default port

#

Or WinRM

#

If you get yourself stuck on that SA, you can DM @glass locust

glass locust
#

nah idk why but all 65535 are filtered. I'll dm @dapper moth, fine ?

dapper moth
#

Ok

long kestrel
peak cipher
#

To get the flag, start the above exercise, then use cURL to download the file returned by '/download.php' in the server shown above. How do u do this i did curl -0 then http ip then hit ls and it says index.html how do i open it

cloud urchin
#

the syntax is -o <file name>

peak cipher
cloud urchin
#

curl <link> -o <output file>

#

you can type man curl to see the manual (works for other commands too)

waxen totem
#

the -O also works to download the file with the same name that it has on the web root directory

cloud urchin
#

it worked, but before you asked about -0 which won't work. it's -o or -O

peak cipher
cloud urchin
#

i don't know.. no idea which module you're on.. i was just answering your question on how to use curl

peak cipher
cloud urchin
#

try opening the downloaded file

peak cipher
#

i think

cloud urchin
#

well yeah you weren't in the download directory when you downloaded it

#

you can see the Downloads folder right there in your screen shot

peak cipher
#

yes?

#

do i click it

#

do i go to documents?

safe star
#

where did you download the file?

peak cipher
safe star
#

.

#

looks like you do

peak cipher
#

i think i found it

cloud urchin
# peak cipher do i go to documents?

you can type pwd to print working directory and see where you're working out of, then navigate there and double click on the file. if it doesn't open in your browser that way you can just open your browser and do open file.

peak cipher
lilac sorrel
#

How do I get my hacker rank The Box?

long kestrel
#

maybe you should do the IT Fundamentals modules to learn how to use a terminal

peak cipher
#

i just clicked my home and there was this index.html file there

lilac sorrel
#

I've completed 4 exercises, I'm just getting started on this

peak cipher
#

but ill do that next

safe star
long kestrel
#

it looked like he downloaded it to his home directory and just needs to output the contents of the file to see the flag

safe star
#

should def go back to linux fundamentals first

#

yeah he downloaded "download.php" right there

peak cipher
long kestrel
#

oh he actually has the flag in his screenshot already too

cloud urchin
cloud urchin
#

the hint says you see it when you open the file

peak cipher
long kestrel
#

that isnt the file you downloaded

peak cipher
#

found it

#

it worked lets go

cloud urchin
#

please don't post flags

peak cipher
#

oh sorry

#

I thought that varied based on the ip they gave you

fathom pendant
sinful lava
#

is anyone around? I have a quick one that I have been stuck on for a few days and I believe that I am just overthinking it

#

Specifically, the priviledge escalation module

safe star
#

ask the question

sinful lava
#

is this task asking you to generate an SSH key for the user2 and then sign in as them?

safe star
#

i dont know that part ur talking about

sinful lava
#

It's the first objective

#

Just can't upload a SS here apparently

shut quest
sinful lava
#

SSH into the server above with the provided credentials, and use the '-p xxxxxx' to specify the port shown above. Once you login, try to find a way to move to 'user2', to get the flag in '/home/user2/flag.txt'.

wooden seal
#

Password attacks [attacking lsass] excercise (que 2)
lsass.dmp file not getting created in c:\ for some reason i have no idea why please help
thank you

sinful lava
shut quest
wooden seal
fathom pendant
fathom pendant
shut quest
#

Eh that's what I get for coming in and assuming, thanks msrcie

eager ledge
autumn pilot
#

Try to move the flag to a destination that you can access, instead of attempting to establish a reverse shell connection

#

Additionally, look in a directory that you have access (read and write) which may have the necessary file(s) for you to rotate the log

pale reef
#

I'm a little lost on the Linux Privilege Escalation -> sudo section. Both of the options from the tutorial on what to do don't work. sudo -l does not list anything, and the code they gave to run does not run. I tried to find a docker image of an older version of linux so i could compile the code there but couldn't find it and didn't know if they were expecting us to go to such a length.

autumn pilot
#

Elevate from sh shell to bash and then list the binaries/commands available to be run in the context of root

pale reef
#

when i look for binaries with setid set, i don't see any important ones. when i use sudo -l -U root, it prompts for my password.

icy dagger
#

Hello guys, is it normal that I get a 10.129.xxx.xx (ACADEMY-XXX-LAB) and no port when firing up a module instance? It's the first time I get this IP with no port.

autumn pilot
#

Yes, the 10.129.0.0 is the range that can be accessible by the VPN

icy dagger
#

Right, so probably I am having some issues with the VPN if I see no port in the output

waxen totem
#

wdym by no port in the output? like in a scan?

icy dagger
#

No, I mean in the HTB dashboard. I spawn the target system and I get the IP address like above, but no port for the connection.

fathom pendant
#

The 10.129.x.x don't provide a port, and unless otherwise specified or by scanning, defaults can be assumed

#

So if, for instance, it's a web module you can assume default port 80

#

And you don't need to specify anything special in your commands to enumerate

icy dagger
#

Alright! thank you for the clarification ❤️ it is the first time I see this kind of IP for the modules.

coarse merlin
#

is subscription required for downloading vpn configurations ?

waxen totem
coarse merlin
#

i mean for academy modules

waxen totem
#

still applies

coarse merlin
#

i can't see the download vpn config button

#

but they mentioned it will below cheat sheet

waxen totem
#

Some modules don't show it cos they don't need you to use the VPN

harsh summit
#

is there anyone who finished the Zephyr pro lab ? DM me please

storm elk
#

if you can't access it, read and follow #welcome to get your account verified

barren wharf
#

guys is the "getting started" module good to start off or do i choose another one?

waxen totem
#

Yep, also check out the Information Security Foundations Path

brave kayak
#

Hi guys!

I have a problem with the Cross-Site Scripting (XSS) Phishing task, where I am unable to connect to the website. This happens both in the HackTheBox virtual environment and in my external WSL environment. I tried pinging the IP address; sometimes it worked, but in the end, it didn't. I also added the IPs to the /etc/hosts file and updated my OpenVPN connection. Unfortunately, I have no other ideas, so I turned to you for help. Could you please let me know what the issue might be? Unfortunately, without being able to connect, I can't proceed. The previous IP addresses worked, and I was able to connect to the website.

Has anyone encountered this before? Do you know a solution? I was able to connect in the previous tasks.

waxen totem
#

Did ya restart the target?

brave kayak
#

Yes, about 15 times

waxen totem
#

wdym by updating OpenVPN connection? just download a new file or did you change regions as well?

brave kayak
#

But it doesn't work in the Pwnbox either

waxen totem
#

O, yah that's strange

#

stumped Shruge

brave kayak
brave kayak
little spade
#

hello I need help According to the task, you need to find the name of the bird, but the system shows that this file does not exist what to do?

fathom pendant
#

What module and section?

little spade
#

Information Security Foundations ( Intro to Academy )

#

maybe I'm doing something wrong, but I even tried to go through the options

fathom pendant
#

What section

#

That's the skill path and module

#

It should be on the pwnbox, if not it shouldn't be too hard to discover

narrow oriole
#

quick question, where do i find the /etc/hosts in my machine why does it say not a directory

acoustic owl
#

hosts is a file, not a folder

fathom pendant
#

^

narrow oriole
#

how do i look for it sir

acoustic owl
#

cat /etc/hosts

fathom pendant
#

The error tells you: not a directory

narrow oriole
#

oh sweet

#

found it thank you so much!

narrow oriole
#

how do i delete a line inside hosts btw

fathom pendant
#

You'll need to use a text editor with sudo to edit

fathom pendant
little spade
# fathom pendant What section

Interactive Sections ( Start your workstation, then use the integrated terminal to find the Linux OS flavor by running the following command: cat /etc/issue )

fathom pendant
#

If that file doesn't exist on the pwnbox, then some googling may do good

little spade
#

That's the problem. Google didn't help me.

#

I wouldn’t have come here if Google and a simple search of options had helped me

fathom pendant
#

It's xOS but drop the OS

#

Also not sure what you're meaning by options

floral pelican
#

ChatGPT my guy

regal wedge
#

Hey, could anyone help with the bug bounty? been stuck on Repeating Requests for like 2 hours now and i cant find the second flag haha

storm elk
#

what module are you talking about @regal wedge

regal wedge
#

bug bounty>Using Web Proxies>Repeating Requests

#

i found the first flag, but as i understand the other flag is not in the same directory, i searched all directories by commands but it just gives me the same flag @storm elk

winter schooner
#

One sec let me check

fathom pendant
#

What's the grep for?... you're grepping for nothing

regal wedge
#

i used "HTB" and "flag"

fathom pendant
#

Not all flags will be HTB

#

And grep doesn't read the filename

regal wedge
fathom pendant
#

Maybe try listing files first :p

smoky stream
#

does some1 knows when the CBBH changes of modules (like GraphQL replacing the Session Security) happens?

fathom pendant
regal wedge
fathom pendant
#

I prefer not giving direct solutions

#

Lead a horse to water and whatnot

winter schooner
fathom pendant
#

Give them a push in the right direction without outright telling them "hey do this full command"

regal wedge
fathom pendant
regal wedge
#

i liked zap more than burp haha

fathom pendant
#

Much easier to work with

onyx igloo
#

here any one help to connect with mosh server client showing udp port secure with firewall

winter schooner
#

Can anyone can help me on Login bruteforcing skills assessment 1. I'm trying to brute force the basic login page, and hydra is going through the wordlists provided and not finding a valid pair of credentials.

fathom pendant
onyx igloo
#

underpass machine , how to get root acess

fathom pendant
onyx igloo
#

if have no access

regal wedge
#

@winter schooner @fathom pendant thanks guys, with your help, learned some new interesting things

fathom pendant
winter schooner
fathom pendant
#

Just user as the username

#

Also make sure your user and pass variables are correct iirc this is a post request

winter schooner
#

This is the login page I'm getting

torn skiff
#

how to do htb after my pwn box ended

winter schooner
torn skiff
winter schooner
torn skiff
#

i want to do something with the htb machines

#

to complete them

gray yacht
haughty tree
#

Hey quick question, I am attempting to generate a list of usernames in a domain, kerbrute does find usernames but does not output them to the file I specified, it does create a file of that name but its contents are empty despite it finding users, here is the command I am using
kerbrute userenum -d INLANEFREIGHT.LOCAL --dc 172.16.7.3 --output write_the_output_pls /opt/jsmith.txt

winter schooner
gray yacht
haughty tree
torn skiff
torn skiff
#

how to make sure kali runs on vm

pale reef
#

I'm still stuck on the linux privilege escalation -> sudo module. I was able to use a docker container for an old version of ubuntu so I could get the sudomakemeasandwich binary compatible with the target, but then when i run the file it asks me for a password and then says i don't have sudo permissions. this is circular logic since the point is to get sudo. it looks like in the past, when people did this module, sudo -l showed some exploitable binaries but it no longer shows any.

gray yacht
jolly yacht
#

In Web Requests/GET section, it was stated that the web application's search function is communicating with some remote source to obtain the search results so we can see the network tab to see any request made by that web app as we searching anything in the search function. But it does not sending any request or there is no get request is showing up in the browser dev tool's network tab. Any help please to figure this out?

pale reef
gray yacht
pale reef
#

only the password for htb-student

gray yacht
manic bramble
#

anyone help me with Attacking Enterprise module - Web Enumeration & Exploitation. The second question verb tampering?

#

I dont get the results when altering the request

pale reef
#

Oh that was it.

sonic ridge
#

I need some help in the file inclusion prevention module. I changed php.ini to disable the system function but when I curl the web shell which uses the system function it still works so I can't generate the error log needed for the flag.

#

nevermind I needed to restart the apache service

wild meteor
#

Hi, I need help with Linux Privilege Escalation: Special Permissions. In the question " Find a file with the setuid bit set that was not shown in the section command output (full path to the binary)." I found a file called ipu...s, but it doesn't accept its path. Can I get a hint? Is this the right file?

pale reef
gray yacht
manic bramble
next sleet
#

I'm doing AD Enumeration & Attacks - Skills Assessment Part I, and there is a task to execute DCSync attack with the user I just found credentials for. Now I want to list this user's ACLs and find out if he has necessary privileges to execute DCSync. My question is: can I do it using tools on my attack machine (ldapsearch maybe?), or can it be done using built-in tools on windows host? (I don't want to use PowerView)? Any tips?

gray yacht
next sleet
#

I already have, no problem there, but I want to know how and if I can enumerate ACLs from my machine?

gray yacht
next sleet
#

no, just PV and Bloodhound

clever lotus
#

greetings, on module Wired Equivalent Privacy (WEP) Attacks:
section: ARP Request Replay Attack:

when I attempt to crack key for BSSID I get this:

sudo aircrack-ng -b D8:D6:3D:EB:29:D5 replay_arp-0107-173902.cap
Reading packets, please wait...
Opening replay_arp-0107-173902.cap
Read 8 packets.

1 potential targets Got 8 out of 0 IVsStarting PTW attack with 8 ivs.
Segmentation fault

can somebody give some tips why this is happening?

gray yacht
fathom pendant
next sleet
#

I'm always trying to take LOTL approach in order to learn more before going for automated tools

gray yacht
hasty mauve
torn skiff
fathom pendant
#

The tool doesn't make the man

#

Or another adage, a poor carpenter blames his tools

elder lily
#

i was a kali guy but then i went to parrot and loved it more but now is hard to download kismet i went back to kali

fathom pendant
#

Imo i value that parrot is a more lightweight install

torn skiff
fathom pendant
#

¯_(ツ)_/¯

torn skiff
#

i mean a vm inside my laptop

fathom pendant
torn skiff
#

but my ram and gpu wont work maybe

fathom pendant
#

If parrot won't work in a vm, kali sure as hell won't

elder lily
#

parrot has a better firefox browser

torn skiff
#

rtx gpu

fathom pendant
torn skiff
slate quartz
#

Hello, i am currently doing the starting point labs but i have got to the task called "Three" and i am left with this message and unable to complete it. I have had it say this for nearly 3 days now.

"Please wait for a few minutes until all machine related services are up and running.
Expect to see {"status":"running"} when visiting s3.thetoppers.htb"

fathom pendant
#

If you have less than 8 GB of RAM good luck getting any vm working

elder lily
#

kali-undercover is so underated

fathom pendant
fathom pendant
#

Then you're fine

elder lily
#

it saved me ones

fathom pendant
#

It's all just personal preference really

torn skiff
#

wsl?

fathom pendant
#

i prefer parrot because it's lightweight and they opt for stable branches ¯_(ツ)_/¯

fathom pendant
#

Yeah, and you can install pretty much the same tools

#

As i said previously the tool doesn't make the man

#

Running just a random tool because you were told to is different than running a tool because you know what its doing

torn skiff
#

so i just sudo rm -rf /tool?

fathom pendant
#

Funny guy

#

Know the basics before worrying about needing all the bells and whistles

torn skiff
torn skiff
fathom pendant
#

Yeah

torn skiff
#

/* at end

#

for all tools

fathom pendant
#

Do you know what rm does?

torn skiff
#

it might stand for remove

fathom pendant
#

Correct

torn skiff
#

but star is just harmless

fathom pendant
torn skiff
#

for sure or it just deletes folder called *

fathom pendant
#

Nope

#

* is a special character

torn skiff
#

whats so special about it

fathom pendant
#

It's the everything operator

torn skiff
#

so it will delete like

fathom pendant
#

Say you have 10 files called file1.txt file2.txt.... file10.txt

torn skiff
#

C:/ but only / and leave C:

#

so its all /

fathom pendant
#

You can do rm file1 down to file10

stoic ice
#

Someone know how to solve this?
Detecting Windows Attacks with Splunk ->
Detecting Golden Tickets/Silver Tickets

fathom pendant
#

Or do rm file*.txt

torn skiff
fathom pendant
torn skiff
fathom pendant
#

/ is the filesystem root, like C:/ in windows

torn skiff
#

so it technically wipes entire hard drive?

fathom pendant
#

It bricks your system, yes

torn skiff
#

so if i did del C:/ then it did same as rm -rf ?

#

but windows is smart and it doesnt let

fathom pendant
#

Eh smart enough, so is linux

#

But I wouldn't run random commands someone gives you

torn skiff
#

if there were rm -rf but for entire programs in windows

#

so i would delete that weird red shield

#

called mc caffe

fathom pendant
#

Locked behind admin/system on windows and root on linux

fathom pendant
torn skiff
fathom pendant
#

And can cause some weird errors

fathom pendant
torn skiff
fathom pendant
#

Yes lmao

#

That's 101

#

Anyway were veering way off-topic here

torn skiff
#

once after restarting i forgot about a program (vmware) and few years in future i found it again as folder

fathom pendant
fathom pendant
#

There's an nmap module in the pentester path

torn skiff
#

i want nmap

fathom pendant
#

But like I said, basics will build you up

torn skiff
#

hascat (something like this name)

#

uhhhh wireshark

fathom pendant
#

I'm not a search engine or fetcher for you

torn skiff
#

metasplot

#

do i get them in linux shell?

fathom pendant
#

Yes

torn skiff
#

sudo install nmap

fathom pendant
#

Parrot and kali have nmap installed by default

torn skiff
#

term sudo not recognized

#

sudo : The term 'sudo' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the
spelling of the name, or if a path was included, verify that the path is correct and try again.
At line:1 char:1

  • sudo install nmap
  •   + CategoryInfo          : ObjectNotFound: (sudo:String) [], CommandNotFoundException
      + FullyQualifiedErrorId : CommandNotFoundException
#

tomorrow will fix

fathom pendant
#

Are you sure one isn't an admin?

#

I also suggest not stating which specific exploit you utilized to get started on it

#

As that can be considered a spoiler

covert wyvern
fathom pendant
covert wyvern
fathom pendant
#

😉 shouldn't take much longer from here

#

You can adjust passwords btw via this type of vulnerability

covert wyvern
#

yes, already done that, I just didn't know who to impersonate to elevate privs 🙂

#

I had it there all the time, I guess I spent too much time in front of the screen haha

fathom pendant
#

Forest for the trees

molten summit
#

can someone pls help me for some reason im not getting any response when trying to use ssh

fathom pendant
molten summit
#

yes

fathom pendant
#

ip a run that in a new terminal

molten summit
fathom pendant
#

Do you have multiple tun devices?

molten summit
#

im not sure what that is
tun

zealous rune
#

Hi. Module Attacking Web Applications with Ffuf. End of module skills assessment. I am trying to submit the answer for the following question
One of the pages you will identify should say 'You don't have access!'. What is the full page URL?
I am as certain as I can be that I have identified the correct page. However the URL is not being accepted. What am I missing?

fathom pendant
fathom pendant
zealous rune
#

ah ok thank you so much

#

perfect accepted

fathom pendant
#

You're not the first to ask that question here

molten summit
fathom pendant
molten summit
#

i downloaded the file and ran this command
'sudo openvpn academy-regular.ovpn'

fathom pendant
#

Kill the vpn, and run the command again

molten summit
#

still no response. it stays like that for a while and later says:
Connection closed by 10.129.255.221 port 22

fathom pendant
#

Reset target?

molten summit
#

again same thing. should i just use pwnbox

fathom pendant
#

Try changing vpn regions

#

And terminate -> spawn target

stoic ice
#

Detecting Windows Attacks with Splunk → Detecting Golden Tickets/Silver Tickets

Can someone help me? I'm trying to answer the question in this module, but I can't find the answer anywhere. I've used all the commands provided in the module without any success.

molten summit
stoic ice
#

some one know how can I create a post on htb-forums?

vital marlin
#

i'm doing the Malware Analysis module and Noriben keeps hitting error 7 "could not create CSV file" when attempting to save. because the CSV doesn't generate, the TXT report necessary to complete the exercise fails to generate also

#
C:\Tools\Noriben-master>python .\Noriben.py

--===[ Noriben v1.8.8
[*] Using filter file: ProcmonConfiguration.PMC
[*] Using procmon EXE: C:\ProgramData\chocolatey\bin\procmon.exe
[*] Procmon session saved to: Noriben_07_Jan_25__12_12_898349.pml
[*] Launching Procmon ...
[*] Procmon is running. Run your executable now.
[*] When runtime is complete, press CTRL+C to stop logging.

[*] Termination of Procmon commencing... please wait
[*] Procmon terminated
[!] Error detected. Could not create CSV file: Noriben_07_Jan_25__12_12_898349.csv
[*] Exiting with error code: 7: Error creating CSV
stoic ice
#

run cmd as administrator bro

versed eagle
#

The advanced XSS and CSRF exploitation labs are again not accessible for me.

They work, sometimes. But then after a few seconds, I get this error again:

Error

Failed to connect to bypassing-csrftokens.htb:443

#

Was having the same issue yesterday and the day before

#

Is it possible that these machines do not have enough resources or something?

vital marlin
#

okay, it's an issue with the default Noriben python script. it references procmon.exe when there is only 64-bit procmon present.

#

works fine if i change noriben.py (changing the name of prcomon64 to just 'procmon' would also work)

stoic ice
#

theres the .txt?

vital marlin
#

just submitted a ticket for the module to be corrected

vital marlin
stoic ice
#

okey, respond the question, no?

wild sage
#

Is there someone I can DM about Broken Authentication Skill Assessment? I was able to find a user and their pass, but couldn't brute force the 2FA. (Which I guess you can't do in this exercise) I tried doing bypasses but I got stuck.

glad patio
#

Hello! Introduction to Digital Forensics module (https://academy.hackthebox.com/module/237/section/2610)

Examine the file "/home/htb-student/MemoryDumps/Win7-2515534d.vmem" with Volatility. Enter the Pid of the process that loaded zlib1.dll as your answer.

I used dlllist to find mentioned dll but it doesn't display any PIDs.

The output: 0x000000006b2b0000 0x22000 0xffff 2023-06-22 12:31:30 UTC+0000 C:\ProgramData\ggzstcat367\TaskData\Tor\zlib1.dll

I then used cmdline and looked for the this path, there was only one .exe within this path, so I concluded that it's the answer (and it was correct). However, I wonder If I found it in intended way, how do I see the connection between ||taskhvc.exe|| and the dll? Or how can I validate the answer?

dapper moth
#

Crazy seeing these erratum posts and realizing that there are people that goes through the Modules with a Bug Hunting drive chasing typos 😂

devout raptor
#

yooooo

#

can someone help me

#

can we be on a call is going to be more ezier

#

.

steel crypt
#

Yo

devout raptor
steel crypt
devout raptor
#

good you

rough comet
#

hi folks

#

Got a question about Password Attacks - passwd

#

why the module uses unshadow? I just copied the hash I found and used hashcat directly

#

As a matter of fact, I was getting errors if I try to use "unshadowed.hashes". Can someone please clarify?

#

here's the error I was getting

#

when I used || hashcat -m 1800 -a 0 unshadowed.hashes ./mut_password.list ||

chilly cosmos
#

@rough comet Hello, can i DM

rough comet
#

sure you can

chilly cosmos
#

@devout raptor Ask before DM Please

rough comet
devout raptor
rough comet
novel matrix
devout raptor
#

is just a question

#

ohhhh

#

ok sorry

#

my mad

novel matrix
#

If you have a question about a module, you can freely ask here and anyone online can help answer your question 🙂

rough comet
novel matrix
rough comet
#

Always read the rules of any Discord when joining! 😉

#

You are gonna be banned my friend, lol

devout raptor
#

why

rough comet
wary plover
#

bro is weird like that

novel matrix
#

User left

rough comet
pale reef
tender nimbus
#

Hey guys anyone that can help me with blueteaming?

pale reef
#

This one's tricky because a lot of the activity with golden/silver tickets happens outside of the purview of the domain controller and so does not get logged. I found the answer in a column that was not at all self-explanatory.

tender nimbus
#

I need to find the exe file that loaded a hijacked dll, i'm trying to filter on dll's that apears in writeble directories (so excluding system32 etc but the querys are invalid, quand someone help?

cunning frigate
#

this may lead you which dll has been hijacked so you can filter

tender nimbus
tender nimbus
#

@cunning frigate also with chainsaw i find nothing

cunning frigate
tender nimbus
ripe anchor
#

I can never go blue sorry

unborn summit
#

hi im doing Pass the Ticket (PtT) from Linux in the password attacks module and im stuck on the question Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio. the ticket is expired by 3 years 😂 and not sure what im supposed to do

unborn summit
safe star
#

have you noticed the user has 2 tickets?

unborn summit
fathom pendant
scenic geode
#

Hi guyz,

Can someone help me with some tips on NextPath Challenge machine ?

Web - Medium Difficulty?

scenic geode
storm elk
#

There’s a channel for everything and this is just for academy modules 🙂

scenic geode
#

Okay.

I am pretty new to discord and HTB.
Just got Annual Silver in academy subscription.
Would that suffice to get into those channel ?

fathom pendant
#

Nope, need to link via #welcome instructions

storm elk
#

There’s 3 steps at the bottom of #welcome - as you’re doing challenges, it should be easy to get the identifier token

hollow coral
#

For the SOC analyst module . I was given a question that wanted me to open elasticstack and kibana together. Does anybody know how to get through that ? I was having trouble finding it.

unique ether
#

any idea what the username and pass on bloodhound page

#

pwnbox

#

nvm

unreal crescent
#

In the Network Traffic Analysis Module, when it asks for the command for the TCPDump that gives Hex and ASCII while reading from a file, how does it want the Syntax. I have tried several variations of the command that work in the command line, but it won't accept it

safe star
unique ether
safe star
#

pretty sure you have to reset it on http:7474

#

oh alr

unique ether
#

thanks

unreal crescent
#

I've tried sudo tcpdump -Xr, sudo tcpdump -X -r, sudo tcpdump -r file -X

fathom pendant
#

Iirc

#

If not you do need to tell it what file to read

unreal crescent
#

Here is the question: Given the capture file at /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in Hex and ASCII? (Please use best practices when using switches)

safe star
#

they actually wanted the full command this time for some reason sadglas

safe star
unreal crescent
#

Unless they want the ethernet headers as well, which wasn't specified in the wuestion

unreal crescent
fathom pendant
#

Use the full filepath

safe star
#

thats not the file they asked

fathom pendant
#

^

#

Since when is ~ /tmp/ ?

unreal crescent
#

lol

#

changed it to /tmp still doesn't work

safe star
fathom pendant
unreal crescent
fathom pendant
#

Make sure no weird extra spaces

#

Otherwise try refreshing the page and putting it in again

unreal crescent
unreal crescent
hollow coral
#

For the pathway of SOC analyst in the "Security Monitoring & SIEM Fundamentals. How can I open elastic stack because it doesnt specify if it's an applicaton on VM or if I have to acess it through the web in the VM

fathom pendant
#

Elastic is typically a tool running on a web port

#

A quick Google tells me which port, and I'm sure the reading should also tell you

hollow coral
#

okay thanks !

unreal crescent
#

Lol I had to use Wireshark for the last bit of the TCPDUMP due to the resource being downloadable and not in the box. I am running Windows lol

rustic sage
#

How can I make friends?

unreal crescent
#

Not sure they have a Module on that

unreal crescent
#

Aw. My Pwnbox time limit ended while I was using Wireshark lol

mortal reef
#

Hi

waxen totem
verbal turtle
#

any hint for Introduction to Deserialization Attacks skill assessment 2 task 2

#

||i use phpggc for CodeIgniter 4.2.7 and it doesnt work !||

storm elk
#

feel free to dm me @verbal turtle

#

tell me which one you're using in dm

versed eagle
#

Advanced XSS and CSRF exploitation labs still not properly working. Can anyone have another look into this? First they work, then I can't access them anymore for 5 min, then they work again for 1 min, etc etc. It's super annoying

autumn pilot
#

reach out to support please

versed eagle
#

will do

upper haven
versed eagle
upper haven
versed eagle
#

I tried both VPN and Pwnbox. For VPN I'm currently on EU academy 5, don't remember what the previous one was I tried

#

Or could it be an issue that I'm using both Pwnbox and VPN at the same time or something? (I use Pwnbox for the http server and tools and such, but use my host + VPN for browser + burp

bright coral
storm elk
#

ah yes, you can't use both at the same time

versed eagle
#

ahh

#

okay got it. thanks!

warm turret
soft reef
#

In the NTLM Relay module what servers do I have to deactivate in the config file? Using SMB the module says to deactivate SMB in config file, but using MSSQL it doesnt say that. I assume any protocol I want to use with nltmrelay I would have to deactivate it in Responder?

shadow grove
jolly spire
#

atwossh@ng-1594780-loginbfsatwo-nqtu1-6778dfc78c-99258:~$ medusa -h 127.0.0.1 -u /username-anarchy/Thomas_smith_username.txt -P passwords.txt -M ftp -t 5

#

this list doesnot work with me module login brute ass2

#

is any one did it?

urban elk
#

I'm on the skills assessment part II of the AD Enumeration & Attacks module. I have accessed an SQL server and my user has SeImpersonatePrivilege. The relevant section in the module says "[this] can be leveraged in combination with a tool such as JuicyPotato, PrintSpoofer, or RoguePotato to escalate to SYSTEM level privileges (...) These methods are covered in the SeImpersonate and SeAssignPrimaryToken of the Windows Privilege Escalation module." I'm confused. Am I supposed to jump to that module to learn how to proceed in this skills assessment ?

shadow grove
urban elk
urban elk
#

Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.

primal adder
#

Is SELinux really necessary to learn and if so, where can I find a manual or a guide for it? The one I found seems to be bigger than the entirety of Linux Fundamentals module.

soft reef
urban elk
soft reef
tulip hearth
#

Hi guys! Need help in password attacks - attacking sam module in pentest path

#

└─$ python3 /usr/share/doc/python3-impacket/examples/secretsdump.py -sam sam.save -security security.save -system system.save LOCAL
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[-] read length must be non-negative or -1
[*] Cleaning up...

#

i dont understand the readlength, like, what parameter should i change for that

soft reef
tulip hearth
#

i can transfer 2 files then the third one (system.save) just says shutting down connection, unexpected network error.

#

it moves the file to my attack machine but the system.save and also the next activity which is lsass.dmp cant be transferred

#

although other files were moved through smb

soft reef
#

how are you transferring the files?

tulip hearth
#

move file \10.10.14.117\CompData

#

i think its the file size

#

sam.save and sec.save are lower than 100k

#

system.save and lssas.dmp are greater than 12 million

#

its being moved, but not completed

#

for some reason the connection closes after a while therefore leaving the lsass/system file corrupted

rich spoke
#

Footprinting module, Footprinting Lab - Easy.

I have a couple of questions regarding DNS Footprinting. I was able to get the flag, and everything was fine, but then I hit the "Show Solution" button, and I was not able to understand the purpose of the dig command or the next three commands/steps.

I would appreciate some help here.

vapid hull
#

does anyone know how the module got the ip address when editing the the host files in regards to the proxying of traffic via MS01 for the Pass-The-Ticket from Linux, Password Attacks Module, any helps/tips is appreciated 🙏

in relation to the first question of the optional exercise

cobalt osprey
#

can someone help me, i am trying to connet with xfreerdp to a windows host, but it gets stuck loading some files:
09:17:25:367] [5440:5441] [INFO][com.freerdp.channels.drdynvc.client] - Loading Dynamic Virtual Channel rdpgfx
and i get blocked from a black screen

storm elk
#

press the enter button @cobalt osprey

cobalt osprey
west scarab
#

How to enroll on a student plan i already connected my college id but I need to get to support how to do it

ancient niche
#

Good afternoon people i'm still haven't solved this problem

polar mural
#

hello im on network enumeration with nmap - nmap scripting engine
i scanned with nmap -sV --script safe and i found this banner on port 31337: || HTB{pr0F7pDv3r510nb4nn3r} || but when i try to submit that i get incorrect answer. i don't know what else in the output could be it

soft reef
shut vapor
wooden trail
# ancient niche

send the full command, we can not see it, but seems like a syntax error

#

oh, it clearly says "no such file or directory", you dont have that wordlist there

shut vapor
polar mural
shut vapor
gray yacht
# ancient niche

The issue was pointed out to you yesterday or the day before I believe.

shut vapor
#

Sometimes copy/paste gets messed up. Not usually out of a terminal, but on occasion with CTF's I've found typing the flag by hand fixed problems where copy/past gummed something up with unicode.

shut vapor
wooden trail
# gray yacht The issue was pointed out to you yesterday or the day before I believe.

@ancient niche as this m8 is telling you, and considering your last few questions, you need to take a closer look at the module's content, the errors you are shown... i'd suggest both "penetration testing process" and "getting started" modules at this point.

maybe you are running too much, most of the errors or problems you find are copy-pasting related.

take your time, read a bit more carefuly and try your best, not everyone starts at the same point 🙂

ancient niche
#

thanks guys but i'm not copy and pasting 🙂 i'm working hard

rustic sage
polar mural
shut vapor
polar mural
#

nse

wooden trail
shut vapor
#

I just popped every section and found a match.

polar mural
west scarab
vital zephyr
#

good evening to all friends, I have a question, related to the section attacking common applications -> prtg network monitor, in particular question 2: Attack the PRTG target and gain remote code execution. Submit the contents of the flag.txt file on the administrator Desktop.

following the way in which the module is developed, I noticed this thing that I would like to ask for clarifications. Going to compile the notification, if I call it test it does not work, while if I call it pwd instead it does, it allows me to use crackmap exec and eviwinrm, can you explain why? Can I also show the screens

#

I add that both were configured the same way

#

don't answer so many that I can't handle them all 😆

cobalt osprey
#

hi guys, i need a hint, i am triyng to do the Enumerating & Retrieving Password Policies truck in AD dEnumeration & Attack, i have to find he minPwdLength set to in the INLANEFREIGHT.LOCAL domain? (One number) and i think i have to use this command:
ldapsearch -h 127.0.0.1 -x -b "DC=INLANEFREIGHT,DC=LOCAL" -s sub "*" | grep -m 1 -B 10 minPwdLength
But i am getting errors

vital zephyr
#

marcieleee where are uuu, u are my mentor

spare condor
#

Injection Attacks - Skills Assessment, I just solved the skills assessment but I have a question regarding the payload. Why the payload doesn't work when we have <iframe src="http://127.0.0.1:port/index.php?q=test *[rest_of_payload]* and it only work as <iframe src="http://127.0.0.1:port/?q=test *[rest_of_payload]* (without specifying the index.php)???

analog dock
spare condor
fathom pendant
hasty mauve
# vital zephyr

The dots in the password field are not the same count, meaning the password is not the same in both pictures for prtgadmin account.

vital zephyr
chilly cosmos
#

writing a python script for IDOR Vulnerabilities

bright shore
#

hello guys this is a noob question but I'm stuck on Exploit the target and gain a shell session. Submit the name of the folder located in C:\Shares\ (Format: all lower case) Module SHELLS & PAYLOADS and I'm trying to figure out how to get to the tomcat website from the foothold machine but I can't even access the browser to upload the shell. Does anyone know where I can even upload the shell?

earnest pasture
bright shore
#

Do I have to configure the IP on /etc/hosts on the pwnbox?

fathom pendant
bright shore
#

Am i accessing this webpage via the foothold target browser?

night inlet
#

Yo i can dm someone for help on the module C2 sliver please ?

analog dock
#

Just ask your question

final elbow
#

hi, i dont know if this is the right place to ask, HTB didnt tell me to install ncat so i did it myself and i get this error, is my format wrong, i followed the exact format on the firewall evasion section

fathom pendant
#

You didn't define a source port to use

final elbow
#

so should i put the port number first then ip?

fathom pendant
#

Source port is the port youre using to connect, not the open port on the target

final elbow
#

ahh, i see

fathom pendant
#

Instead of an arbitrary port, source-port allows you to define the port you're using to connect to a service

final elbow
#

ah, that seems to have fixed it for now, thanks so much my dude :D

bright shore
fathom pendant
night inlet
#

Yo if someone have the time i dont find this one for the module C2 sliver i do some enum web but nothing so someone can give me a hint please 🙂 ( i must use sliver for find the answer ?)

bright shore
fathom pendant
#

Lowercase

#

My phone auto-capitalized

bright shore
#

huh lmao I feel soo stupid thank you

#

Never experienced this much pain with any course ever so thanks HTB Academy

safe star
#

Idek why that was added 😭

night inlet
night inlet
autumn pilot
#

Enumerate it, poke it a bit, and the word database can help you to find where you need to focus

quasi wave
#

I'm doing the Attacking Common Services module and I'm doing the Attacking FTP section. I'm on the second question which requires me to give username for FTP. I solved question 1 which requires me to enter the port number that FTP service is running on (which happens to be a different port than normal), so this is about the question after that. I am running an nmap scan with -sC and -sV flags on the target just like the section is saying to do. However, nmap scan never completes, even if I just run it on the FTP port specified.

Can someone help me out here?

safe star
#

you gotta keep restarting it in my experience

quasi wave
#

ok

safe star
#

you could easily guess what port it is tho

quasi wave
#

I solved that already. What I am scanning for is the username for the FTP login.

#

because the second question wants me to get the FTP username.

#

I know the port already and I already entered that. What I'm having trouble with is question #2

quasi wave
#

what flags should I run?

analog dock
#

Probably follow what the section teaches

quasi wave
#

the section said to run sC and sV no?

analog dock
#

Does that enumerate the users?

#

Just a reminder, there’s a user and password list in the resources

quasi wave
#

ok

quasi wave
#

how many logins should I configure brute forcing program to try at once? right now I'm doing 10 cred-combos at a time

safe star
#

10 cred combos?

#

Aren’t lists they give pretty small?

shadow sedge
#

Network enumeration with nmap module(host discovery). I didnt get the idea of using “-PE” without using “—disable-arp-ping” because with “-PE” alone nmap sends an ARP request

tender nimbus
peak cipher
#

On network fundamentals unit the intro to LAN course is required premium. is that room super duper important

fathom pendant
#

There's no "premium"

peak cipher
quasi wave
safe star
quasi wave
#

Medusa

#

That’s what section says to use

safe star
#

did you use the user and pass list at the same time?

quasi wave
#

Yes

#

Its taking forever

quasi wave
#

should I pass in a singular password at random and try to crack the username?

#

is hydra better than medusa at ftp login cracking?

fathom pendant
#

Are you using the right port?

quasi wave
#

yes

#

I know its not the traditional ftp port I already got that

#

found that with nmap prior

#

in fact the right port is needed to answer the previous question so I know I got the right port

safe star
#

its just slow at times

quasi wave
#

I'm sure it will get it eventually

fathom pendant
quasi wave
#

again, I'm using medusa to crack it

quasi wave
safe star
#

mine was slow at first too

fathom pendant
#

Password cracking and bruteforcing are different things

safe star
#

got faster after some time

quasi wave
safe star
#

yeah maybe wait for it a little

quasi wave
#

ok

safe star
#

or just restart

quasi wave
#

in that case I will wait until it tries every single username and password combination

#

that's fine I guess that's like the real world

#

it feels like brute forcing it would be cheating. @safe star your saying you used medusa too. Anyone here used a better tool for ftp cracking than medusa? is hydra any faster?

safe star
#

yes hydra did it faster

quasi wave
#

ok

#

well, I already have this going on cracking and its half way through

#

is there still a point in switching to hydra?

#

medusa is starting to speed up a little

safe star
#

faster but might overload the server

quasi wave
#

ok

safe star
#

if you catch the server at a good time then it will be quick

quasi wave
#

ok ya

#

gonna just wait out the medusa then

#

guess that's what I gotta do

quasi wave
#

I think I have to restart this instance. Its not gonna crack it in time. I'm gonna try hydra soon since that would be ideal.

#

I'm gonna wait until the servers are cleared up tho

#

so will try later tonight

prisma echo
#

Hi

limber ravine
#

hey, is it normal that some boxes wont allow you to connect to the website? has anyone else run into this issue before? I tried resolving the /etc/hosts file manually but was unable since I don't even know the hostname I'm trying to connect to - nmap works and curl returns an error... been a couple of boxes I've been unable to complete because of this

#

tried both chromium and firefox and still unable to access the site - all ports were up on the box too, I'm working on Unified in the starting point.

novel matrix
bitter ridge
#

Where can i suggest grammer fixes

rustic sage
reef marlin
#

hi, im in the privilege escalation on the first part of the pen tester path im stuck on question 2 i got the user 1 to user 2 by abusing privilege but im stuck on getting from user 2 to root the hint mention chmod but im not finding anything and there is no ssh key like tought in the module any hint any1?

fathom pendant
woeful lily
#

Hello. I am currently stuck on the login brute forcing module, the web services lesson. I get all the way to the flag in FTP, I do get flag.txt, it says it is downloaded. I exit, cat flag.txt, and it says it doesn't exist

#

Please help

mortal locust
#

Hi,

Doubt for, Password Attacks > Attacking Active Directory & NTDS.dit

I have some confusion regarding the output.

When I retrieved the admin hash from the ntds file, I was able to authenticate successfully with the Administrator account. This makes sense because the ntds file contains domain hashes, so I could successfully log in using the domain account's hash (which led to the "pwned" message).

The real issue arises when I use the --sam flag to extract the hash from the SAM file. This provides a different Administrator hash, which corresponds to the local administrator account since SAM works with local account hashes.

However, when I try to authenticate with the local administrator hash obtained from the SAM file, I am unable to log in. This happens whether I use the --local-auth flag or not.

restive grove
# mortal locust Hi, Doubt for, Password Attacks > Attacking Active Directory & NTDS.dit I have...

not certain if this is specific to your issue (its been a minute since I did the module) but as you say SAM is for local, but by default when you try to authenticate the system will prioritise domain authentication, hence you tried --local-auth, but in a lot domain environments it is often disabled (for exactly this reason) or controlled by group policy, so its unsurprising it didnt work.

TL;DR: Local accounts are often locked down in domain environments specifically to force users to authenticate with domain accounts. The --local-auth flag might fail due to restrictions or Group Policy settings.
||also from memory, you dont need to do any hash passing for that module, you should be able to brute force||

mortal locust
dapper moth
# restive grove not certain if this is specific to your issue (its been a minute since I did the...

Not Domain environment. Specifically in the Domain Controller.
You will be able to authenticate, with high level of access, to any other machine using its local Administrator NTLM hash which you can retrieve from the registry hives.
When referring to a DC, you will have to go for the NTDS file. The Domain Administrator account is the Domain Controller Administrator, hence you wont be able to auth using the hashes dumped from the registry.

viral snow
#

Were you able to complete this one? I kept getting error messages when I used the use_link command.

#

Were you able to complete this one? I could use some help with abusing sql server links.

peak cipher
#

which roles should i do in order to become good at cot or king of the hill

#

ctf i mean not cot

fathom pendant
rare temple
real delta
waxen totem
peak cipher
#

i keep doing that

peak cipher
fathom pendant
peak cipher
#

and even if u want to upgrade thm much cheaper

fathom pendant
#

Either way it's not related to htb

#

¯_(ツ)_/¯

rough violet
#

I'm struggling with the meaning of the highlighted sentence, "pivoting around" as in circumventing security measures and managing to get access to subnetworks, is not difficult,
but it is tough to do that silently and quickly (takes time to crack handshakes or something, your fake MAC or the cloned will get alarmed or something idk I'm just wondering),

is this the correct meaning of the sentence?

tranquil axle
#

if you have several subnets that can only be accessed by specific hosts then you as attacker have to hack several hosts "in order" to move through them. Imagine a vulnerable webserver that you manage to hack, if it is a flat network hierarchy then you might be able to access every other computer in the network directly from your one hacked host.

If the network however is segmented into smaller ones then a hacker needs to compromise more hosts to dive deeper and get access to sensitive data. And with every host you compromise there is a chance that you as a attacker do something that can be detected, maybe you drop a .exe file that gets detected by AV or Endpoint Protection and alerts the defenders.

rough violet
potent yoke
#

did somebody already passed the cpts test?

rough violet
#

I wanna understand, these CIDR notations are only for the purpose of education right?
but the Gateway that hosts all these subnets' gateways doesn't need to know about their subnets right?

#

I also don't understand why the pentester's ip (the last IP) has a subnet, is that to represent the scan he did? like he did a nmap -Sn 10.20.0.1/24 or something like that?

obsidian kayak
#

I don't get it at all....

acoustic owl
potent yoke
waxen totem
# rough violet I wanna understand, these CIDR notations are only for the purpose of education r...

CIDR notations are actually used by networking devices, more often in IPv6 scenarios though

Gateways DO need to know the subnet masks to put it in the correct network

Pentester's IP has a subnet of /24 which is NOT equal to the netmask used by the targets /25 which makes it the wrong network

Therefore:
an IP address is never complete without the subnet mask as it determines the network and host parts of the IP address, without it, we have no clue which bits are network bits, and which bits are host bits (barring IANA classes with default subnet masks)

acoustic owl
obsidian kayak
#

why isn't it issued to students?

rough violet
# waxen totem CIDR notations are actually used by networking devices, more often in IPv6 scena...
  • yee actually you're right, I'm unfamiliar with IPv6 technologies but
  • yes even in IPv4 forwarding: the ARP table has to contain the subnet mask to determine what the next hop is gonna be and where the Destination Target is, thanks for reminding me
    (Although I honestly don't know how that plays out with NAT, since all these sub networks share a range of host IPs, how will the Server Gateway be able to tell which network the host is in, NAT and subnet seem counter productive in this sense..)

I guess I need to understand that to follow along with your explanation

#

this is an example of a routing table

waxen totem
#

dw if it doesn't make sense this is the year of IPv6! laugh_cry

rough violet
waxen totem
#

the network bits must be different for different subnets

rough violet
waxen totem
rough violet
rough violet
waxen totem
#

eg:

Subnet Mask: /28
11111111.11111111.11111111.11110000

10.10.10.0/28
breakdown:
10.10.10.00000000
NN.NN.NN.11110000

is a different network from:

10.10.10.16/28
breakdown:
10.10.10.00010000
FF.FF.FF.11110000
rough violet
waxen totem
rough violet
waxen totem
#

just read through the subnet section of that module

waxen totem
#
128  64  32  16  8  4  2  1
0    0   0   1   H  H  H  H

where H = host bits
rough violet
waxen totem
waxen totem
# rough violet what is that based on

the network addresses are based on the subnet mask and network bits,

128  64  32  16  8  4  2  1
0    0   0   0   H  H  H  H
therefore 10.10.10.0 = network 1

128  64  32  16  8  4  2  1
0    0   0   1   H  H  H  H
therefore 10.10.10.16 = network 2

where H = host bits
#

seriously... just read the subnet section, it probably explains it better

rough violet
rough violet
#

so that i can feed it to AI and make people ask you questions or something,

waxen totem
rough violet
waxen totem
rough violet
# waxen totem nope, the cap is always gonna be the same increment as if you try to get a host ...

aha I think I've managed to process what you just said: if a network has subnet mask allowing only 16 hosts /28 and that network has some IP, the cap will be that IP + 16 right?
roughly speaking + 16, probably + 15, I'm not that precise with numbers

second thing:
gateway is a host address in the bigger gateway, the main, the one higher in the hierarchy, like the Server Gateway in the above example, a sub network's gateway is host address in it,
why does that address have to be 17? what drove you to that conclusion?

waxen totem
#

Increment will always be the last network bit

rough violet
waxen totem
#

Gateway doesn't have to be 17 but what everybody does is either first or last host in the network

waxen totem
#

If you had 11100000
Instead as the subnet mask it'd be 32

rough violet
rough violet
rough violet
#

and that's the cap for network 2

waxen totem
#

Yep so what'd be the next network after 10.10.10.16?

rough violet
#

10.10.10.32

waxen totem
#

Yep

rough violet
#

NAT seems pretty useless then..
why would you wanna determine each network's hosts using ranges like that

waxen totem
rough violet
rough violet
waxen totem
#

Eg:
172.0.0.2:42069----NAT--------> 10.10.10.18
(public router address+port)

waxen totem
rough violet
#

good to know that's what F is for xD

waxen totem
rough violet
rough violet
waxen totem