#modules

1 messages · Page 378 of 1

fathom pendant
#

You'll find a niche you like and dig into it

cloud urchin
#

you literally said 'i'm a kid' earlier

solid rivet
cloud urchin
#

it's not a problem

fathom pendant
#

You can likely encourage your parents to help you by helping them

cloud urchin
#

you need consent from your parents though

solid rivet
#

Because I'm a teen

fathom pendant
#

Still a kid

solid rivet
solid rivet
fathom pendant
#

If person.age < 18:
Response = "ok kid"
print(Response)

solid rivet
#

OK call me whatever you want

solid rivet
#

I don't care

long kestrel
#

you could say ur 21 and you'd still be a kid to some of us old folks

fathom pendant
#

True

#

If person.age < self.age
response = "kid"

solid rivet
#
print("Hello marcielee!")
fathom pendant
#

Anyway

#

Instructions are in #welcome how to link the account

fathom pendant
#

Just keeping the chat on topic of academy modules

#

It's not complaining, it's literally steering the conversation back on topic

#

Since you can't/don't want to do academy, this conversation is just further going off topic

solid rivet
#

Are you blaming me

fathom pendant
#

No

solid rivet
#

I'm taken aback

fathom pendant
#

I'm not caring

#

Lol

solid rivet
#

Mmmm

#

OK you continue with your topic then I'll not distract you

#

Or text

#

Hey you there

#

So guess im leaving the server good bye

fathom pendant
solid rivet
#

Bye

#

I'm not wanted here

fathom pendant
#

No one said you're not wanted here

#

I was literally guiding you to a more appropriate place for off-topic conversations

solid rivet
#

Its not your fault

#

You're a good persons

fathom pendant
#

🙄

solid rivet
#

Mm

#

Just kidding

fathom pendant
#

I need to get back to modules at some point

solid rivet
#

Yeah

long kestrel
#

are you working towards a cert?

solid rivet
#

But this server is for tertiary level I will join it again when I'm in university

#

So see you in a few years

#

Bye👋

#

👍

fathom pendant
solid rivet
#

Yeah I noticed

#

But he is older than me

fathom pendant
#

Don't need to be in uni to learn hacking, you do need to be able to think though

#

Ok and? Plenty of the old heads in the server started learning at an earlier age

solid rivet
#

Well I gotta go to sleep so good night

twilit zenith
#

Hey did someone solve this on the module "Introduction to Bash Scripting - Conditional Execution" ? I tried different ways and also got results but apparently wrong lol. feel free to dm if u can help me 🤯

long kestrel
#

have you checked if you're off by one char? that was my mistake on it

twilit zenith
#

Ye lol

#

Thank you

#

Do you know why its +1?

fathom pendant
#

It's counting new-line char

terse sedge
#

lol sorry, didn't mean to thumbs down that

twilit zenith
#

maybe stupid question but \n would be new line right wouldnt make that +2 ? or are there also other new line elements with only one char im not yet aware of

long kestrel
twilit zenith
#

ah okay thank you good to know. if id put \n as a string it would be counted as 2 right

long kestrel
errant pivot
long kestrel
errant pivot
#

Oh thats a good idea thank you I have had many that are quirky about which input they take and I got a little sidetracked kek

terse sedge
#

In the Footprinting section of the Penetration tester path, I don't understand something. In some modules, why does a Vhost have to be added to your hosts file in order to be seen? If it exists on an IP, why can't it be discovered by scanning through something like gobuster? And then after adding it to the hosts file, it still can't be discovered by gobuster.

fathom pendant
#

Also you wouldn't add the port to the hosts file

#

You make the request in gobuster with the port as http://domain:port/

somber whale
#

If you start from the beginner modules will you eventually learn how to play the hacking games without any issues?

errant pivot
#

They are pretty solid so far I am a few weeks in and it’s helpful.

#

OS fundamentals and info sec fundamentals we’re good

somber whale
#

Those were good

#

Or is it better to learn from specific books and such ? I want to be able to get through the hacking games with ease

fathom pendant
#

Wdym "the hacking games"

#

Is that like a competition or something?

#

If it's a ctf competition learning broad web techniques and such will be valuable

#

As a fair bit of ctfs have web or web adjacent challenges

edgy ember
#

Hey guys I just finished the crackmapexec module skill assignment. Everything good with it but I just want to ask a question regarding the mssql_priv module.

Why does it show both users ||Juliette and Atul|| as sysadmins when none of these users have this privilege?

||MSSQL_PRIV 172.16.15.15 1433 SQL01 [+] INLANEFREIGHT\Juliette is sysadmin||

fathom pendant
#

They can likely impersonate sysadm

#

I'm assuming you're using cme and not nxc?

#

Nxc is a better version of cme

edgy ember
#

Yeah it is nxe

#

And no they can't impersonate

fathom pendant
#

¯_(ツ)_/¯

#

Also the pages of a module are called "sections"

edgy ember
#

At least for this assignment, the user that can impersonate was different

somber whale
fathom pendant
#

You don't need to do the modules to take part in ctfs

somber whale
fathom pendant
#

Ctfs are standalone challenges

#

You can do one challenge in a category without it having any impact on you doing another challenge

somber whale
#

Ok. Let me ask you this… the level of hacking I would like to learn is to be able to go through the CTFS and pro labs, etc type of knowledge. I’m not looking for a job in cybersecurity or anything. I just want to learn how to utilize Linux and go through CTFS and such

fathom pendant
#

You can also research old ctfs and writeups and learn from them

#

Prolabs are networked machines

somber whale
#

I just didn’t know how to proceed with doing a standalone CTFS challenge

fathom pendant
#

Research

#

Google the shit out of everything you find

somber whale
#

Oh yeah? Should I go that route?

fathom pendant
#

That's just one method

somber whale
#

Or should I just go through the modules? I’m just trying to find a clear path to learn

fathom pendant
#

The tier0-2 modules scratch the surface of what you'd find in ctfs

#

And lots of challenges have a gimmick or trick associated with them that often makes them a bit easier

#

Modules are good if you want a broad understanding

somber whale
#

I would rather go through the modules I will need to be able to go through the CTFS challenges and not learn all about cybersecurity for a job

fathom pendant
#

Again the knowledge isn't centered around being "for a job"

worldly dirge
#

Me too, see the thing is with labs you don’t need to pay

worldly dirge
#

No, unless your out of printer ink lol

#

This is the most important advise lol, don’t get it filled and admit it? One day you wake up banned kek

knotty gust
#

If you're doing a penetration test and have not been given a user account within the network, how would someone go about active directory user enumeration? Kerbrute and CrackMapExec?

worldly dirge
knotty gust
heavy solar
#

Linux Fundamentals.

#

Does anyone know the exact command for this problem!

fathom pendant
#

Or on pwnbox

hard matrix
#

I don't have any questions but i do just want to say that the attacking thick client applications module is hot garbage and needs to be rewritten for clarity

fathom pendant
#

But otherwise, heavily agree

#

It just doesn't belong. And even faced heavy criticism when it was released

fathom pendant
#

And believe it or not, it used to be worse

hard matrix
#

Just feels completely out of place and following the section 1:1 doesn't actually help you. I ended up having to read the fatty walkthrough by 0xdf to get anywhere.

fathom pendant
#

The biggest hint/suggestion people gave was to use a walkthrough of fatty

#

That's how hot garbage it is

hard matrix
unique ether
#

Breh

#

I had the creds yesturday dint work with xfreerdp today I tried it worked

fathom pendant
#

Mood

unique ether
#

💀

fathom pendant
#

[It was resetting the vm that did the trick]

#

Classic turn it off and turn it back on

unique ether
#

Kill me pls bro yesterday and today morning I was doing other enumeration resulted nothing

inland oak
#

anyone stuck at Nmap module? question is to find system name without giving us ip address??. help

fathom pendant
orchid furnace
#

Hi other than the module Introduction to networking is there any other more advanced module about networking please ?

fathom pendant
fathom pendant
inland oak
orchid furnace
fathom pendant
#

It's directly referring to the SENT and RCVD lines

fathom pendant
#

Cbbh job role path is decent, the buffer overflow modules

fathom pendant
#

Ctfs have a wide scope of challenges

orchid furnace
#

are there modules I should not do in that path in order to not waste time?

fathom pendant
#

Cbbh is all about web stuff and is well worth doing regardless

#

It's not a waste of time to learn things

#

There's no paths that are specific to getting better at ctfs

unique ether
#

What a relief finally finished AD enumeration module

safe star
#

type shi

unique ether
#

Fr fr

surreal urchin
#

Someone please gudide me on : nibbles privalage Escalation

fathom pendant
#

The module is a guide

#

One big thing is full filepath

steel snow
#

excuse me, can someone help me?

#

i mean i have solved the question but i want to understand something i tried to google, and i will keep doing so but i want to ask it here as well so

#

when i am connecting to ftp, when i am listing using ls

#

i am getting:

29 Entering Extended Passive Mode (|||51387|)
150 Opening ASCII mode data connection for file list
226 Transfer complete

#

and no listing is happening, although i can wget the whole thing

#

why? what is happening? how can i wget it it but not list?

mellow lava
#

try asking on chatgpt, explain ur problem and ask for possible reasons

steel snow
#

maybe that's a configuration to block listing but allows downloading?

steel snow
#

but i don't have a confirmation to anything said

visual umbra
spare condor
acoustic owl
solid rivet
#

Hi

honest crane
#

Hi, I'm currently doing the skill assesment of the Shells & Payloads module.

Am I supposed to figure out the IP address of blog.inlanefreight.local by myself or is it given somewhere that I missed?

Edit: Nvm, figured it out.

spiral sinew
tiny wedge
#

when i try to use the free rdp comand and have entered everything correctly i keep getting the error messages :[05:30:58:839] [14277:14277] [ERROR][com.freerdp.client.x11] - failed to open display: [05:30:58:840] [14277:14277] [ERROR][com.freerdp.client.x11] - Please check that the $DISPLAY environment variable is properly set.

unreal hill
#

Can someone help me with this

honest crane
stark lark
#

Is there anyone who has completed AEN who I may ask a question in DM?

fickle thicket
#

hi, correct me if i am wrong but there seems to be some discrepancy regarding PMKID topic in Attacking WPA/WPA2 Wi-Fi Networks module. first statement state PMKID allows you to skip full EAP handshake, second statement state PMKID allows you to skip EAPOL 4 way handshake. third picture show EAPOl 4 way handshake still occuring even after PMKID is sent. any help to clarify my doubts?

wintry cosmos
heavy solar
gray yacht
prime scarab
#

Did you manage to solve it?

glass locust
#

Anyone I can chat about WEP Attacks - Korek Chop Chop attack ?

winter schooner
prime scarab
# winter schooner I moved on from that one and still didnt come back to it, i'm on the Attacking C...

You were almost there.. just try to read the upload.php using XXE with the SVG payload but with a little change in the content header (so that it accepts SVG files and XML content) and no need to add any MIMEs

After that you should be able to understand the rest.

Another issue I faced when trying to solve this was that my burp wasn't working properly and I got timeout errors but managed to solve it using the pwn box. So you might want to try using the pwn box if you haven't done it already.

tribal plinth
# fickle thicket hi, correct me if i am wrong but there seems to be some discrepancy regarding PM...

Hello, what's written in the module is correct. The second screenshot you've shown is for WPA Personal (PSK) while the first and third screenshots are for WPA Enterprise (MGT).

Authentication processes for both WPA Personal and Enterprise are different since in WPA Enterprise, each user is authenticated with their own unique username and password which are verified by the RADIUS server.

When it comes to WPA Enterprise networks, we are more interested in the actual EAP handshake which happens between the Supplicant (Client), Authenticator (AP) and Authentication server (RADIUS), since each user has their own unique credentials configured.

While the EAPOL-Key handshake happens between the supplicant (Client) and authenticator (AP) but only after the EAP-Success (RADIUS accepts the auth).

The following blog post should help you to understand the EAP-PEAP auth process for WPA Enterprise in detail.

https://mrncciew.com/2014/08/25/cwsp-eap-peap/

EAP-PEAP (Protected Extensible Authentication Protocol), creates an encrypted TLS tunnel withing which the supplicant’s inner identity is validated. Sometime it is referred as EAP within EAP.…

median gale
#

CME module, Pass Spray section, question Is there any other local MSSQL account created with the same username and password as the corresponding Active Directory account? Keep getting these errors The login is from an untrusted domain and cannot be used with Integrated authentication.

#

Altough i guess, i shouldnt?

glass locust
glass locust
median gale
glass locust
median gale
#

thanks for the help mate ❤️

zenith token
#

203

leaden island
#

hi im getting this error in wireshark while doing TLS decrypting for RDP

#

network traffic anaylsys module

safe star
leaden island
#

oooo i figured it all out

#

thanks mate

cinder marten
#

Hello guys i was trying to solve meow level 0 when i check from youtube or offical writeup, when they nmap they find port 23 is open so it is about telnet but when i do nmap i got port 22 is open so it is ssh i need help

median gale
#

In cme, mssql there is a -x option to execute commands on the system using the xp_cmdshell function. Does this automatically apply the reconfigurations needed for xp_cmdshell to work, or does that fall on us to do?

fathom pendant
#

I believe it requires it to be configured, could be wrong though

median gale
#

thank you ❤️

carmine delta
#

can someone help me with hydra i try to attack rdp: but i got this error:

fathom pendant
#

I think i used nxc instead for rdp

leaden island
#

yo guys from the network analysis module

#

last module rdp decrypting

#

wheres the resources for the question ?

#

i rdp to the machine and its empty

#

also captured some traffic on the ens224 but no rdp traffic

fathom pendant
#

Did you check -> resources or next to the question?

leaden island
#

there is

#

for the module itself not the question

carmine delta
fathom pendant
leaden island
#

ive searched everywhere

#

no resources linked to the question

#

its the last question in the whole module

visual umbra
#

Hello im in the Web proxy module in basic tool set and i have using burp before a little but now when oi was installing it and running it i cant intercept and proxy the traffic . I have installed the cerificate in Firefox and did set up the proxy in Foxyproxy but this is all i get when trying to proxy tarfic from any site...

leaden island
visual umbra
fathom pendant
#

Continue clicking it

solid rivet
#

Hi

visual umbra
fathom pendant
#

¯_(ツ)_/¯

visual umbra
#

it is not proxy the trafic at all, just from firefox... some one know wwhar problem can be?

fathom pendant
#

Well... yeah it will only proxy traffic via firefox

solid rivet
visual umbra
fathom pendant
#

i suggest looking up on stack overflow or reddit ¯_(ツ)_/¯

visual umbra
fathom pendant
#

But this issue isn't necessarily an htb issue, it's a burp issue

visual umbra
fathom pendant
#

Because maybe we don't know how to resolve your issue on the discord lol

#

Also Google searching may be useful to find articles/posts that report similar issues

visual umbra
#

google... hm.. more likly chat gpt can help ;D i know some one in discord can help me out:D

#

i think it can be a Arch problem, Burp told me at first start it is not tested at Arch.. But it did work before new install..

fathom pendant
undone abyss
#

Windows Attack and defence
PKI-ESC1
I am able to do all the steps till converting it into PFX format.
After that when I go to WS001 to authenticate the certificate it says
“failed to find certificate for cert.pfx”

Can someone please reply if there is another step in between or how to fix this failed to find certificate thing.

Thanks In advance

rustic sage
#

Could you tell me what you mean by dot

acoustic owl
rustic sage
#

Yes I know but…but

#

Sigh

#

Ok I will

acoustic owl
#

Burp Comparer can help

rustic sage
#

Oh I see now

#

Well fuck

#

That’s wild

#

Blind the only difference is a wiff of a fart

#

Got it

#

Sadistic

acoustic owl
rustic sage
#

Ugh don’t remind me

acoustic owl
#

I haven't tried it yet and don't know what's coming, but if it's already coming in the modules, the exam will be even harder.

median gale
#

Is veil the same as using msfvenom with encoded payload ?

rustic sage
#

Damn username be trippinnnnn

#

I smell it

median gale
crystal notch
#

I am working actually on Windows Privilege Escalation and doing Pillaging part. When i am pasting hash into answer it says its wrong. I have obtained Administrator hash, and i dont know what i am doing wrong

cloud urchin
#

i've seen a couple more lately, my guess is it's around 40 people who have it now give or take some.

#

i could also be totally off

crystal notch
acoustic owl
acoustic owl
rustic sage
gray yacht
acoustic owl
gray yacht
crystal notch
#

i dumpted hash from SAM and SYSTEM

median gale
acoustic owl
#

These users do not get badges. Therefore these numbers are unknown

median gale
acoustic owl
median gale
acoustic owl
rustic sage
#

Login

#

I know the dot is dotting but having trouble getting decent things to happen

median gale
rustic sage
#

Winky wink

#

😝

#

Put me to sleep jk

#

Whoops sorry

fathom pendant
#

Don't be weird

river jetty
#

I am doing the sqlmap introduction and this code doesnt seem to be working with the current module. Any Hints

sqlmap -u 'http://94.237.54.231:54163/case3.php' --cookie='Cookie:id=1' --batch --dump
rustic sage
#

I have no friends all I have are these modules

#

My skin singes when I go outside

safe star
#

real

still ibex
#

Dear Dalian, I would like to ask a question. What are the injection methods for game cheats and how can I check for traces

unique ether
rustic sage
#

🥹

winter shard
#

How do cubes work? I am on the CPTS path and on footprinting module and SMB section. I am answering questions that show a cube beside it but all show +0 cubes. Why am I not earning cubes anymore?

fathom pendant
rustic sage
#

Do better modules for money

cloud urchin
fathom pendant
#

By the end of the module you'll have earned back %20 of the module cost

winter shard
winter shard
fathom pendant
rustic sage
fathom pendant
#

If you're working on a module, it helps to provide a module name and section name

#

If you're just repeating the question from a module, I suggest reading the section again

rustic sage
#

With your help and a prayer to Saint chat of gpt I got it

hasty rock
#

why can't i send images to this forum?

acoustic owl
hasty rock
#

but still can't send pictures

lyric spade
#

hey Guys, can someone help ?
I need help in one of the ⁠modules and according to the answers the Event 7 is not showing up in Sysmon.

fathom pendant
acoustic owl
hasty rock
#

oke wait

analog pebble
#

DCSync module:
Cant complete the exercise for "What is this user's cleartext password? " as the reversible-encryption passwords are grabbed by secretsdump.py toward the end of the dump and the connection keeps getting reset / error thrown after about 10 seconds of hash dumping

#

mimikatz also throws an error when trying to elevate perms when using runas.exe so i cant use lsadump::dcsync

gray yacht
hasty rock
#

Network Enumeration with Nmap
Firewall and IDS/IPS Evasion - Medium Lab

In this medium lab I tried to enter the command "nmap -T4 -A -v 10.129.67.225 -D RND:5 --stats-every=5s" after I waited for the command nmap on ip 10.129.115.20 instead an error occurred
Initiating OS detection (try #1) against 10.129.115.20 (10.129.115.20)
Retrying OS detection (try #2) against 10.129.115.20 (10.129.115.20)
Retrying OS detection (try #3) against 10.129.115.20 (10.129.115.20)
Retrying OS detection (try #4) against 10.129.115.20 (10.129.115.20)
Retrying OS detection (try #5) against 10.129.115.20 (10.129.115.20)
Initiating Traceroute at 22:55
Unknown address family 0 in build_packet.
QUITTING!

Please help me

analog pebble
gray yacht
analog pebble
#

true.. will do

hasty rock
#

Network Enumeration with Nmap
Firewall and IDS/IPS Evasion - Medium Lab

In this medium lab I tried to enter the command "nmap -T4 -A -v 10.129.67.225 -D RND:5 --stats-every=5s" after I waited for the command nmap on ip 10.129.115.20 instead an error occurred
Initiating OS detection (try #1) against 10.129.115.20 (10.129.115.20)
Retrying OS detection (try #2) against 10.129.115.20 (10.129.115.20)
Retrying OS detection (try #3) against 10.129.115.20 (10.129.115.20)
Retrying OS detection (try #4) against 10.129.115.20 (10.129.115.20)
Retrying OS detection (try #5) against 10.129.115.20 (10.129.115.20)
Initiating Traceroute at 22:55
Unknown address family 0 in build_packet.
QUITTING!

Please help me

#

guys

fathom pendant
#

Also assuming you are connected to the vpn

#

If there is an ids/ips running you'd be tripping it

#

There's no need for RND

hasty rock
#

what is the solution I should do?

fathom pendant
hasty rock
fathom pendant
#

No

#

There's a vpn connection pack that you can download to attack targets from your own machine

#

If you're using the pwnbox it's not a problem

hasty rock
#

If I try to use pwn, will the same error occur as before?

fathom pendant
#

¯_(ツ)_/¯

#

You'll have to make sure the vpn isn't running on your machine first

hasty rock
#

after that

#

iam beginner,sory

#

please give me some guidance, experts

hasty rock
#

@fathom pendant

ocean night
#

Describe your issue clearly, check connectivity to the lab (e.g. ping your target or VPN gateway), see if you get a response.

hasty rock
#

I have successfully connected to the target VPN and can ping the target IP, but why does the problem above still occur?

#

please help me

#

😫

unique ether
#

😿

ocean night
#

What version of nmap are you running?

#

Stop spamming

unique ether
#

Why are u running decoy

ocean night
#

What do you think we're trying to do?

#

mmm

hasty rock
#

I'm not spamming, I'm just trying to explain my problem earlier

ocean night
#

You keep posting the same block of text, that's spamming. We're trying to help, you don't need to keep posting it

unique ether
#

Try udp scan see what happens

hasty rock
#

wait

unique ether
#

I think ur trying evasion but y u running T5

ocean night
#

That RND option is not mentioned in that module anywhere, does it work without it? Good spot Phil.

unique ether
#

Which module is he doing

ocean night
#
Network Enumeration with Nmap
Firewall and IDS/IPS Evasion
#

Tier 1, so please keep specifics to DMs, not here

unique ether
#

Oh hmm

unique ether
hasty rock
#

yes

unique ether
#

Hmm did u try other types of scans

#

Agressive scan is not really good if ur tryna evade

ocean night
#

Just stick to what the modules / sections are guiding you

#

That option involves spoofing traffic etc, which is certainly not required

unique ether
#

^

hasty rock
#

okay, so what should I do? to solve the problem like that?

unique ether
ocean night
#

Go through the section again, look at how they guide you to use the tool

#

No idea where you got that RND option from

hasty rock
unique ether
#

I do that too sometimes

unique ether
ocean night
#

Well you are taught everything you need to pass the module / section within the content provided in the module / section @hasty rock

#

I'd again say go and re-read over the content 🙂

hasty rock
#

okay, I will try to see the module again. thank you for your sharing that helped me

hasty rock
unique ether
fathom pendant
#

Imo the biggest section that requires evasion is the hard lab

ocean night
fathom pendant
#

There's only like one or two sections that's useful for stuff like academy

#

At least within that specific reading portion

#

The medium lab doesn't require too much evasion and thought

ocean night
#

Does that specific decoy require it to be run as sudo I wonder

#

raw sockets etc

fathom pendant
#

Probably

chilly girder
#

hello

#

i'm having trouble with using xfreerdp to connect to a box

#

anyone free to help?

fathom pendant
#

What's the error you get?

chilly girder
#

at first it said the certificate mismatched

#

so i added /cert:ignore

fathom pendant
#

That's a non-issue

chilly girder
#

then i get [03:40:37:988] [84661:84663] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[03:40:37:988] [84661:84663] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[03:40:37:988] [84661:84663] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[03:40:37:988] [84661:84663] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1***

fathom pendant
#

Is the password correct?

chilly girder
#

yeah

fathom pendant
#

status_logon_failure

chilly girder
#

i copied and paste it

fathom pendant
#

Wrap the password in single quotes

chilly girder
#

same result

fathom pendant
#

Are you sure the username is correct then?

chilly girder
#

yeah

#

htb-student

fathom pendant
#

What module and section?

#

Sometimes the username is htb-studentadm

#

Or something silly

chilly girder
#

windows fundamentals

#

the first module

chilly girder
fathom pendant
#

What's the section name?

chilly girder
#

introduction to windows

fathom pendant
#

Try resetting your vm and trying again

chilly girder
#

guess i'll reboot

fathom pendant
#

main host
You mean the in-browser vm?

chilly girder
fathom pendant
#

Ah

#

You mean your host system

chilly girder
#

yeah

fathom pendant
#

Pentesting on your host system isn't generally wise as you're opening and closing ports

#

If only instructions existed somewhere people may be #welcome

chilly girder
#

thx for your time

fathom pendant
#

idk what your setup is looking like to try and rdp ¯_(ツ)_/¯

chilly girder
#

it's probably going to turn out to be some stupid thing like typing htp instead of htb

#

or something

#

now it tells me :
BIO_should_retry returned a system error 32: Broken pipe

#

instead of logon failure

fathom pendant
#

Sounds like connection issue

#

Use the tcp vpn instead of usp

#

Udp*

chilly girder
#

used both unfortunely

fathom pendant
#

Well make sure to only be running one

chilly girder
#

why would i run them both at the same time

fathom pendant
#

Well sometimes processes get stuck when quitting

chilly girder
#

didn't think of that actually

#

i'll just try later in the day hopefully the connection gets better

rustic sage
#

dehşet purno

fathom pendant
#

Redact the hashes

hidden trellis
fathom pendant
#

Read the channel description

hidden trellis
#

?

#

no

fathom pendant
#

No begging, i suggest you read #rules

fathom pendant
#

How about you not

rustic sage
#

yes

fathom pendant
#

We don't cater to leeches

rustic sage
fathom pendant
#

If you want a c2 just build your own or use something like mythic or sliver

fathom pendant
#

Ok and?

#

This conversation isn't related to htb academy or modules

#

I don't give a shit

#

With this treasure I summon <@&861185840277487616>

#

Keep the chat on topic

cloud urchin
#

<@&861185840277487616>

safe star
#

ggs

#

i fr thought u were a bot 😭

#

the bio convinced me

rustic sage
#

Ok I’m suffering on nosql injection 2. I am very close but I’m still off can anyone help me sorry

#

I’ll dm

fathom pendant
#

Fuck off

fathom pendant
rustic sage
#

Ummm

fathom pendant
#

What

#

They weren't legit looking to help you in the module

rustic sage
#

Bro scamming

fathom pendant
#

It's one of the scam bots that look for the term "help" and "support" and replies to the message using discord's built in bullshit

rustic sage
#

lol

rough comet
#

I just finished the Hard Assessment for CPTS - Attacking Common Services. And I love it!

#

Very cool twist at the end, lol ...

safe star
#

easy felt the hardest

rough comet
#

Yeah, the hard was the easiest for me

#

But I've also used nxc a lot

#

Bye guys. Netflix time...

weary marsh
#

ITS MY FIRST time lesrning or want to lear cybersecuirty, im Aldo learning to code HTML JS AND CSS, should i start with HTB as a begginer?

cloud urchin
#

<@&861185840277487616>

weary marsh
#

?

rustic sage
#

Every time I come back to this chat, I always miss the serious rule break 😦

#

I always miss out what they said

#

Shucks

cloud urchin
#

it was just a bot trying to get people to join their scam discord server

weary marsh
#

@rustic sage ? For lesrning as a begginer you think is good?

safe star
#

@rustic sage thought?

rustic sage
weary marsh
#

Dont laugh hahah just asking i need motivation

novel matrix
#

hmmm

rustic sage
#

Skills injection 2

cloud urchin
rustic sage
#

Anyone pleaseee😭

#

I’m hopelessly lost

safe star
rustic sage
#

Dm?

hidden trellis
#

Active Directory Trust Attacks - GoldenGMSA Attack

Can I please get help regarding why I am getting this error, cheers

safe star
#

are the creds correct?

hidden trellis
marsh echo
safe star
safe star
marsh echo
warped locust
#

Can I get some help on the linux module

#

For some reason I can't type in Htb-student's password.

safe star
warped locust
#

Yes.

safe star
#

thats a security feature

#

best to just copy and paste it

warped locust
#

Ok.

warped locust
#

@safe star For some reason I can't paste it in.

safe star
#

i said copy so your less likely to mess up

warped locust
#

It worked.

#

Thank you!

#

/home/htb-ac-1327532
Is this a home directory path?

safe star
warped locust
#

okay

vast plover
#

Alrighty thanks ❤️

rustic sage
#

Spammer

#

Man you work fast

#

Spammer

#

Mods don’t sleep

vast plover
#

Dang 😭

#

I feel for that ggs. Lemme go through the rules again if what I've said is aight

unique ether
sweet jewel
#

could u dm me ur full command, including the hash ill take a look at my notes

safe star
#

This bot lasting pretty long😭

novel matrix
naive compass
#

Help

novel matrix
spring forum
#

If anyone is familiar with binary exploitation, regarding the phrase "If we see that the program crashed because our input overwrote the EIP register, we likely have a stack-based buffer overflow vulnerability" they are referring to the position on the stack which is popped back into the eip / rip when the function call ends on a return, right

finite abyss
#

The patch provided in the Patching - Validation Logic Disparity section of Parameter Logic bugs just check if date is not set which is already checked by updateReq.
We can book any valid date still like next year same date.
Could someone explain what does it fix actually?
https://academy.hackthebox.com/module/239/section/2594

Edit:
Got it, this avoid two users scheduling the exam on same date.
Thanks

empty trout
#

when we extract keytab file we get ntlm hash and aes256 and aes128 hased by cracking we get the password but it does not mean that the ad password and local account password will be same as shown in the section pass the ticket from linux

#

any body know this ......

brazen gorge
#

I am new

fathom pendant
empty trout
#

i dont get it

fathom pendant
#

not everything you see will be the same as the screenshots or output from the examples in the reading

#

HTB either has you go after a different account, or intentionally omits (leaves out) information from output that you'll discover

mint solstice
#

Can anyone give me a hint for the fourth question on Sliver's skill assessment?

brazen saffron
#

?

#

What's the module?

mint solstice
#

Intro to c2 operations with sliver

brazen saffron
#

I have not access to it personnally but if you have no answer from anyone else try to see on the forum.

noble jackal
#

Can anyone help me, I'm stuck!? I'm booting a machine but it's stuck on "joining instance" and I've also turned off the vpn but it's still there

solemn fractal
#

Is hackthebox start point great field to start

storm elk
#

Yes, and also have a look at the academy

#

there's great tier 0 modules to get started

meager bluff
#

can someone help me with linkvortex? I feel so dumb

storm elk
#

@meager bluff #boxes - read and follow instructions in the last post of #welcome to gain access

solemn fractal
meager bluff
#

my badprayge

meager bluff
#

So about that linkvortex anyone could help a brother out

storm elk
#

@meager bluff - as I said - post in #boxes please

solemn fractal
#

@storm elk are you doing pen testing too and how do maintain consistency and discipline to hack the box Academy and labs

storm elk
#

I don't do pentesting as my job is just web development

solemn fractal
#

I’m about to start with hack the box pro labs is it worth it spending more money on time on it if you have a experience before

#

Why can I ask a question in general I don’t have write permission what is wrong?

storm elk
solemn fractal
#

OK, thank you

polar latch
#

Where do we get help for technical issues with target systems not spawning in modules?

compact patrolBOT
storm elk
#

does it keep spinning?

polar latch
#

no, it tries and gives up

#

goes back to 'Click to spawn the target system'

#

I have refreshed the page etc..

#

have not logged out/cleared cache yet though

storm elk
#

Maybe try that first 🙂 or switching regions sometimes helps

#

if not - I suggest to contact support

polar latch
#

cheers

#

all good

storm elk
#

awesome @polar latch - glad it worked

flint solar
#

Im about to start my HTB journey - absolutely loved doing the starting point machines, shall i get vip+ ?

unique ether
#

Why cant we extend the machine again it again?

#

Especially pwnbox

tranquil topaz
tepid horizon
#

Module: Detecting Windows Attacks with Splunk

Detecting Pass-the-Hash

Submitting the answer as ||DC01.corp.local|| which will be shown as incorrect... What is the question about? I am submitting the ComputerName... but it won't solve...

ocean crescent
storm elk
#

no

#

@ocean crescent you sure you're not a bot?

dapper moth
ripe verge
#

Hi,
Can someone help me with the module: Wired Equivalent Privacy (WEP) Attacks?
I'm in the section "Finding the Initialization Vector with Wireshark" and am trying to solve the task, but the issue is that the file needed ( /opt/IV-Wireshark.pcap) doesn't exist on the virtual machine. I've looked through the directory and tried the Find command in linux searching for pcap files, but none matched the one in the task.
Anyone know what the issue could be?

prime stump
#

Look if there's another users creds..you can ssh to

void kayak
#

For people who spent more and 1 hour to get through module 177 exercise 1763: Oracle Design of the Time-based SQLI, it is not specified in the question section where the target is: do not use port 80, use port 8080 like it is in the example. Port 80 is for the previous section, the donut shop. It would be great if there was some vhost or just a reminder to use port 8080.

tepid horizon
undone abyss
#

Windows Attack and defence
PKI-ESC1
I am able to do all the steps till converting it into PFX format.
After that when I go to WS001 to authenticate the certificate it says
“failed to find certificate for cert.pfx”

Can someone please reply if there is another step in between or how to fix this failed to find certificate thing.

Thanks In advance
Any one please help me with this

timber relic
#

Guys can anyone give me hints on backfire season machine on rooting

wary plover
delicate light
#

3 days on fatty module and few more i think 🥲 the goal of this module is only java ?

shut vapor
#

The goal is a little bit of understanding java applications, but more so the notion that these applications interact with underlying data through another server and how manipulating the client can give us room to subvert the server.

#

I've seen a lot of complaints about that section of that module specifically. I thought it was good but they very much could have designed a simpler scenario to get the point across IMO. There really wasn't enough explanation on Java to understand the whole process and I understand that module wasn't the place for it, but it made that section rather frustrating.

delicate light
shut vapor
#

you got it. it took me 2 or 3 days and probably 5 or 8 do-overs but it works.

delicate light
delicate light
primal coral
#

hi

#

some one help me about it session setup failed: NT_STATUS_LOGON_FAILURE ı get this error smbclient -U bob \\10.129.12.197\users
Password for [WORKGROUP\bob]:
session setup failed: NT_STATUS_LOGON_FAILURE

fathom pendant
fathom pendant
primal coral
#

I dont have any pass ı try to ls command

#

wıth help command

fathom pendant
#

you can't interact with the smb server without actually connecting to SMB

primal coral
#

ı do every thing step by step

fathom pendant
#

also you do have bob's password

#

check the reading carefully

#

you're given user:password

primal coral
#

ok ı wıll ı check one more tıme

#

ıf ı dont fınd probably ı eat my Pc

fathom pendant
#

the example doesn't show the password because when you're asked to provide a password for most secure applications it doesn't show in terminal as you type, this is intended

primal coral
#

ık

#

ıt dıdnt show

fathom pendant
#

"let us try again using credentials for the user (bob:...)" [i didn't put the password in here, but that's where it is in the reading, just above where it shows in the example connecting to bob]

flint solar
fathom pendant
#

this isn't the proper channel to discuss this, read and follow #welcome to access more channels

slow osprey
#

any hints on this?

fathom pendant
#

there's a command in the cheatsheet

slow osprey
#

oh

#

I guess I should start saving those cheatsheets huh

hazy quail
#

Hi, a question related to oscp, i noticed some of the machines in tj null that are AD requires attack related to ADCS, which wasn’t explained in the course , does this mean they are out of scope ?

fathom pendant
#

no idea about OSCP this is HTB not offsec

vocal wind
#

Hi

#

I want hack Instagram

fathom pendant
vocal wind
#

Ohh sorry

#

Then what do in here server

urban elk
#

Knitting

fathom pendant
#

if only there was a channel that explained what the server was about

delicate light
fathom pendant
#

that'd be crazy if a server had a #welcome channel wouldn't it

delicate light
#

idk maybe

vocal wind
#

Ohh

#

Yhen what

#

Here stupid question

fathom pendant
#

christ

#

that'll explain what this server is about

#

if you don't wanna know what this server is about, you can just leave

delicate light
vocal wind
#

I will destroy this fucking server

fathom pendant
#

no one is keeping you here; but if you want to interact with this server in a meaningful way

gray yacht
fathom pendant
vocal wind
#

Myra

tired atlas
#

Has anyone done Footprinting Medium Lab?

fathom pendant
tired atlas
fathom pendant
tired atlas
fathom pendant
#

but consider this; what if the password you discovered is reused

tired atlas
tired atlas
fathom pendant
tired atlas
#

This is so dumb

fathom pendant
#

one of the basic things to check for is password reuse

tired atlas
fathom pendant
#

but you're asking in a channel where a lot of people likely have

tired atlas
#

All I asked was has anyone done it, like in this moment

fathom pendant
#

¯_(ツ)_/¯

#

no need to ask if anyone has done it

tired atlas
#

I will, sorry, that's how my parents raised me

fathom pendant
#

just asking your question is gonna be more effective

tranquil topaz
fathom pendant
#

because waiting for someone to respond to "has anyone done this section" could have also been time waiting for someone to actually answer your underlying question

tired atlas
#

It's manners

#

I rather be polite, than "efficient"

fathom pendant
#

different etiquette for cybersec forums

tired atlas
#

ok???? cybersec doesnt have a framework for manners, and that's a random website

fathom pendant
#

¯_(ツ)_/¯

tired atlas
#

some people are just rude to be rude tbh, anywho thank you for the unnecessary conflict, I'll just find the answer myself. Toodalooz ❤️

fathom pendant
#

for most people it's more annoying to go through the back and forth of hi/hello, have you done x?/sure what's up?

fathom pendant
bright shore
#

Current stuck on Password Attacks Lab - Hard and I'm trying to move a file using the command: "move Backup.vhd //10.10.15.128/CompData" to a hosted share on my pwnbox .This is what I learned in the previous module questions but it doesnt seem to work due to an authorization error. Are there any other ways to move files without causing an unathorized error?

tired atlas
fathom pendant
#

i'm not mad lol

#

and you can do things however you want, i'm just stating it's faster/typically better to just ask your question, especially in a channel dedicated to helping people with modules

#

this channel is specifically for ask/answer; no need for preliminary questions -- you can include the module and section name in your question

#

and you'll get an answer

fathom pendant
#

xfreerdp has the /drive: option

#

which allows you to mount a share

tired atlas
outer urchin
#

Linux Fundamentals Networking Services has me installing nfs-kernel-server but I keep coming up with an error. This is on a Virtural Box VM with Parrot OS installed. Is this an issue with my machine or the nfs-kernel? I tried looking up the issue online but did not come across any solutions. I tried Sudo apt update, sudo apt insall -f and with the --fix-missing as well.

Not seeing a way to upload a screenshot.

fathom pendant
fathom pendant
bright shore
#

@fathom pendant If I specify on the pwnbox that it requires authentication and I use "net use \10.129.124.124\CompData /user:david gRzX7YbeTcDG7" something like that on my windows machine does that fix the issue? Also, I used this method in to get one of the module flags which is weird but maybe it was because I was admin. Also I tried rdp'ing to david's account and the only way I could access his directory was through the cmd.exe using runas command.

#

But I would have mounted my pwnbox drive using rdp if I could

fathom pendant
#

/drive:name,/path/to/directory/ with xfreerdp command

bright shore
#

Yes I did that

fathom pendant
#

should show up under ts-client

#

and you can move things to 'name'

#

iirc it's just the //name/ or //ts-client/name it's been a minute

bright shore
#

I used this command with the first user I found creds with "johanna"" and it worked fine

#

maybe its because zfreedrdp can't run two at a time and I already have a connection established with johanna's machine?

#

nvm that doesn't work either

#

Is this by default

tired atlas
#

What does password reuse mean, what else do I use??? There's nothing else to enumerate

tranquil axle
#

the host you are attacking has this specific folder mapped to that share, you are just mounting the share to one of your folders

potent sandal
#

hey guys how u doin hope all fine... I have a problem with the data file extraction he alsways shoe me this error can somebody help please... \Users\htb-student> move C:\Users\htb-student\AppData\Local\Temp\lsass.DMP \10.10.15.123\share
move : The file exists.
At line:1 char:1

  • move C:\Users\htb-student\AppData\Local\Temp\lsass.DMP
    \10.10.15.123 ...
    + CategoryInfo          : WriteError: (C:\Users\htb-st...\Temp\l
   sass.DMP:FileInfo) [Move-Item], IOException
    + FullyQualifiedErrorId : MoveFileInfoItemIOError,Microsoft.Powe
   rShell.Commands.MoveItemCommand-----------------------------------------------------
 sudo smbserver.py share . -smb2support
Impacket v0.13.0.dev0+20240916.171021.65b774d - Copyright Fortra, LLC and its affiliated companies 

[*] Config file parsed
[*] Callback added for UUID 4B324FC8-1670-01D3-1278-5A47BF6EE188 V:3.0
[*] Callback added for UUID 6BFFD098-A112-3610-9833-46C3F87E345A V:1.0
[*] Config file parsed
[*] Config file parsed
[*] Incoming connection (10.129.202.149,49678)
[*] AUTHENTICATE_MESSAGE (FS01\htb-student,FS01)
[*] User FS01\htb-student authenticated successfully
[*] htb-student::FS01:aaaaaaaaaaaaaaaa:f581668fd9302eefbd0a6c49f476f194:0101000000000000002156065d6bdb017337bc5b8f6c886f00000000010010006a006f0043004f004100550053004700030010006a006f0043004f0041005500530047000200100048004b00500075004500710044007a000400100048004b00500075004500710044007a0007000800002156065d6bdb0106000400020000000800300030000000000000000100000000200000dc08c34ef1da0f3b1c25e860312d1b26ffec971f7b35cd4ce89152122352b1840a001000000000000000000000000000000000000900220063006900660073002f00310030002e00310030002e00310035002e003100320033000000000000000000
[*] Connecting Share(1:IPC$)
[*] Connecting Share(2:share)
[*] Disconnecting Share(1:IPC$)
[*] Disconnecting Share(2:share)
[*] Closing down connection (10.129.202.149,49678)
[*] Remaining connections []
peak light
#

In module ; Web Request(CRUD) , a Exercise is given in which i have to add a new city through the browser devtools. but i am unable to do it and been struck for like 30 min now. Anyone Know any way pls share

bright shore
tranquil axle
#

in windows you can type "net share" and it should show you the available shares and what folder they are mapped to

rough violet
#

reading the VLAN section in networking fundamentals like I know what the actual heck

#

VXLAN, 16 million segments.. fr fr, yup 24 bits can give 16 million unique numbers

outer urchin
slow osprey
#

how do I get a file from exploit-db into metasploit

#

this is rough 🤦‍♂️

icy cove
#

Im doing the 'RDP and SOCKS Tunneling with SocksOverRDP' but when i try to load the .dll with 'regsvr32.exe SocksOverRDP-Plugin.dll' like in the example, i get that error.

#

Failed Virus detected

fathom pendant
#

@bright shore please don't reveal passwords

fathom pendant
icy cove
#

k

#

just turned it off and still the same error

fathom pendant
#

did you reupload the .dll

icy cove
#

Yes

#

added exclusions, etc

fathom pendant
#

No need to add exclusions

#

Just disable real-time protection (which is different from defender)

tired atlas
#

@fathom pendant What did you mean by password resuse

#

I know what it means, but what else can I try

fathom pendant
#

Unless I'm misremembering this one.

tired atlas
#

I tried remmina with sa as the username and whatever that password is, did not work

fathom pendant
#

Think of default user accounts on windows install

tired atlas
#

I tried right clicking run as admin for mssql, and using that password which everyone else on the internet did, did not work

fathom pendant
#

It's why i suggest logging in, since the UAC doesn't allow copy/paste

tired atlas
#

logging in through parrot?

#

I tried that too, got an error saying can't connect to host

slow osprey
#

anyone know why I'd be getting this error? on the exploit for host 2 for the shells & payloads final assessment

#

I just downloaded it from exploit-db and entered in the options and ran it

fathom pendant
somber whale
#

Is there a mentor option with HTB?

fathom pendant
somber whale
#

Thank you

#

I need help

slow osprey
storm elk
slow osprey
tired atlas
fathom pendant
fathom pendant
tired atlas
#

administrator doesnt work either

#

nor admin

fathom pendant
#

Are you sure you copied the pw correctly? Respawn target and double check

slow osprey
storm elk
#

You can easily get it from there if you really want but t

tired atlas
#

i'm just using the 87... part

fathom pendant
#

Don't share password

tired atlas
#

okie

fathom pendant
#

Ffs i don't have it on me to verify

#

But respawn target, regrab the important.txt. but that looks right

slow osprey
#

ty

#

I never wanna get hints but I think it'll just make things easier in the long run if I just ask for help sooner

#

instead of trying random things aimlessly

storm elk
#

Yeah 🙂 no worries

zenith token
#

has anyone solved the questions in the smtp Module of the academy?

"Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer."

I used the command sudo nmap <ip> --script smtp-enum-users. With this I get a proper list of usernames. But it seems that none of the usernames is working as a solution. Does anyone know why?

tired atlas
#

because they look so similar

shut vapor
zenith token
shut vapor
zenith token
#

Yes exactly! And I finally got it. First proper hint would have been to check the ressources -> Provided already a list to enumerate from. Then I had to play around with the configs of smtp-user-enum. 🎆

fathom pendant
fathom pendant
#

nmap script stuff is just tedious

zenith token
# fathom pendant smtp-user-enum script >>> nmap --script smtp-user-enum

No actually it was not an nmap thing here :P. When using nmap there is the smtp-enum-users script you can use.... buut there exists an cli too called smtp-user-enum you can use. I solved it with this -> Link to the kali site here: https://www.kali.org/tools/smtp-user-enum/

fathom pendant
#

I believe it's the same script, just ported to nmap

zenith token
#

Ah gotcha! But if this was ported to nmap... would you know how to actually execute this nmap script with a list to enumerate over? Never did a NSE with arguments before 🌚

#

Nevermind -> ChatGPT for the win: nmap -p 25 --script smtp-enum-users --script-args smtp-enum-users.userdb=userlist.txt <target> happy_ping

fathom pendant
#

¯_(ツ)_/¯

zenith token
#

hmmmm... tried to do it with the nmap scan, but I am not able to get the same result as with the script.
The command I glued together would be nmap -p 25 --script smtp-enum-users --script-args userdb=/home/htb-ac-326403/Documents/footprinting-wordlist.txt,smtp.timeout=30,smtp-enum-users.methods={VRFY} <ip> -v

Based on the nmap documentation: https://nmap.org/nsedoc/scripts/smtp-enum-users.html

fathom pendant
#

i genuinely wouldn't bother ¯_(ツ)_/¯

safe star
#

Least confusing nmap script command 😭

zenith token
#

Going wild with the command to get no result fingerguns . Hell yeah

zenith token
# fathom pendant wrap the args with []

This is not an issue. The command works fine. If I use for example RCPT as method, I get some results. Its just that it is not able to do it properly with the VRFY command.
Nevermind, I guess I stay with the cli tool sadglas

neat sail
#

Yo

#

I wanna learn how to hack

#

I need to learn quickly bc I need to get some revenge rq

#

I'm on laptop

storm elk
#

That’s not what this server is for

neat sail
#

Yh I'm jk

storm elk
#

Suuuure

neat sail
#

But like how do i learn it it is so cool man

compact patrolBOT
neat sail
#

Thanks

#

You helped and the moderator didn't what a shame

fathom pendant
#

accessing devices you don't own without permission is illegal, and can land you in some serious trouble

fathom pendant
neat sail
#

Right, ik I'm not stupid

fathom pendant
#

sure Jan

#

either way there's no crash course zero to hero 24 hour learn hacking cheat code

#

lots of time, effort, and spelling mistakes along the way

neat sail
#

It takes time, is that what you tryina say here

#

Oh alr yhyh

fathom pendant
#

yes

storm elk
#

Rome wasn’t built in a day. There’s great content on academy site

fathom pendant
storm elk
hard matrix
rough comet
#

I am getting this error when running subbrute.py : permute_filter = re.compile("^[a-zA-Z0-9]{" + str(self.permute_len) + "}\.")

#

Even though it worked, gave me what I need. The error is kind of annoying. Any ideas of what can be or how to resolve?

#

Thanks i advance.

unique ether
compact patrolBOT
dark hedge
unique ether
shut ice
#

Can anyone give a hint on the last question in Kerberos SA?

lusty hearth
#

Can some one help me with
Secure Coding 101: Javascript skills assessment?, Question 2: "Access '/Static/static.js', and try to statically calculate the flag returned by the 'sendFlag' function".

lusty hearth
potent sandal
#

why is it that nobody really helps here really for what is this module then. I see here always only one person and 1000 question

#

i need to say that htb need to improve when is about discord and community

dark hedge
urban python
#

Whoever needs help with hacking DM me!

potent sandal
#

i know i didnt expect 24/7 but at least answer one of my questions... i feel really not nice when i am stucked and asked some times and never get a reply

potent sandal
rough violet
dark hedge
potent sandal
#

advanced sadglas i wish i would be advanced

potent sandal
# dark hedge with what specifically?

i dont know if u guys have also problems with the walktrough and then suddenly comes some error. I get the answer many times to refresh the machine but still always same error

rough violet
potent sandal
#

have it with many exercises

#

hahahahahahahahah

urban python
potent sandal
#

which color have your bugattii losser

urban python
dark hedge
rough violet
potent sandal
#

Like in Password attacks / Attacking LSASS / lik in exfiltrating the lsass.dmp data but could not do it because of an error

dapper moth
potent sandal
#

same with attacking with SAM

dark hedge
dapper moth
#

Still without posting your question or problem, will be hard to figure

#

Which module and section?

potent sandal
#

Like in Password attacks / Attacking LSASS / lik in exfiltrating the lsass.dmp data but could not do it because of an error

dark hedge
#

did you read the error? "The file exists"

potent sandal
#

yes but u cant see it

#

i will try it tommorow again and will come back

dark hedge
#

i can't see what

potent sandal
#

and will also try the forum guys but still thanks

#

the fillleeeee

dapper moth
#

I mean... The only problem you are facing is with file transfer

potent sandal
#

no this is only a example

dapper moth
#

Why not transferring via explorer in the RDP session you have

#

give it a /drive flag in the xfreerdp command

potent sandal
#

i tried it with scp also

dark hedge
#

that's because you're trying to move a file to another place where a file with the same name already exists

potent sandal
#

but he showed me time outs

potent sandal
dark hedge
#

look at your command again and you'll see what i'm talking about

#

that could be the issue

dapper moth
#

You also don't need to parse it with pypykatz
You can use mimikatz locally

potent sandal
#

i have to move the file from the windows machine to my machine and when i tried to sen it via ssh or scp he always showed me timeouts

#

try to connect with ssh i mean

dapper moth
potent sandal
#

i will make tommorow a picture

#

and come back i need go guys but thanks have a good night

dark hedge
dapper moth
#

Could've just copied and pasted the file in the directory with RDP

urban python
fathom pendant
#

sir this is a wendy's

#

htb academy is already a place to help people learn hacking

#

and this channel spefically is to help people with the learning modules

novel matrix
#

Read #rules and #welcome

Please keep this channel on topic related to modules. Anything but modules, will just be deleted.

unique ether
#

well well well

fathom pendant
#

i also suggest in future when you enter a server to read the rules and welcome messages channels of the server

crude meadow
#

Huh

#

What did I do wrong

cloud urchin
valid viper
#

Has anyone done the Blind XPath Injection section of the Injections module.

#

I can't get either the bool or time-based method to work with pulling letters.

languid falcon
#

Hey guys, stuck on the phishing module for XSS for CBBH. When you send the malicious url you get the creds back via netcat right? The problem says you’ll get them back immediately after sending the url

fathom pendant
#

phishing section of the XSS module*

#

and did you send it to the /phishing endpoint?

#

iirc there's a test one and the actual phishing one to send the url to

#

been a hot minute

languid falcon
crude meadow
#

How do I get in general chat

fathom pendant
novel matrix
cloud urchin
languid falcon
fathom pendant
#

i would have ensured it works properly on the test endpoint first tbh

languid falcon
fathom pendant
#

yep; utilizing your payload on the test side you can ensure that the payload does what you want to first

fathom pendant
#

no

#

i haven't touched like any t3 modules

#

been too busy not having a room kek

valid viper
#

Oh no...I hope you're okay.

fathom pendant
#

i'm fine

#

life stuff that's slowly shaking out

valid viper
#

I understand. Things are ugly everywhere.

valid viper
#

If it's any consolation, I'm staying in BFE literally for another month.

fathom pendant
#

anyway gl with your learning

valid viper
#

Thanks. I just can't get the chars to exfil.

rough comet
#

Any ideas why I’m getting that error ?

icy cove
#

Done!

fierce wagon
#

Hey how do u get Administrator NT hash ? Thanks

safe star
unique ether
#

i slacked off again man

fierce wagon
south radish
#

Does academy machines change passwords for their services on every boot or password is always the same? I tried brute force ftp with first 50% password and now after another boot should I start again or can continue with another 50%?

fathom pendant
#

nope

#

the only thing that has a randomized login is the pwnbox; every practice lab on academy has their designated/expected pws

fathom pendant
outer urchin
#

Linux Fundamentals Networking Services has me installing nfs-kernel-server but I keep coming up with an error. This is on a Virtural Box VM with Parrot OS installed. Is this an issue with my machine or the nfs-kernel? I tried looking up the issue online but did not come across any solutions. I tried Sudo apt update, sudo apt insall -f and with the --fix-missing as well. Has anyone else see this error before?

fathom pendant
#

you don't need to install it

#

that's if you want to run an nfs server, but it's not required to download and install

#

don't think of the examples as something you HAVE to do

#

also did you try first with sudo apt update

#

to make sure that your apt repo is updated

outer urchin
#

Oh ok, I'll continue with the module then. Not used to Linux, I am learning why people like it over Windows.

I did try with Sudo apt update.

fathom pendant
#

make sure your system is also up to date with sudo parrot-upgrade

#

but as i said; it's not required to move forward

fathom pendant
#

@outer urchin worked fine on my end after running apt update [mind you this is browser pwnbox, not my own parrot vm]

#

out of curiosity what's the output of uname -a @outer urchin

ocean night
#

The keys need to be updated for now

#

The images will be updated I believe

fathom pendant
#

that doesn't look like a gpg key error g0b

#

lol