#modules

1 messages · Page 381 of 1

fathom pendant
#

:)

cyan lark
#

What? am I wrong?

slow osprey
#

yes but that's different from subdomain

fathom pendant
potent yoke
#

and i already do the ssh -D

fathom pendant
cyan lark
#

Wait guys am I wrong?

fathom pendant
#

it's impossible to differentiate a subdomain from a vhost by glancing at it, while used interchangeably colloquially they are different things

fathom pendant
potent yoke
fathom pendant
#

you don't go straight from the first machine to the last machine

#

there's a machine in the middle, this is the pivoting module yeah? where it describes using socks over rdp?

#

unless i'm reading wrong, bc you didn't provide the section name

slow osprey
fathom pendant
#

(this is why it's important to provide the section name alongside the module, to prevent confusion from those that are attempting to help you)

potent yoke
#

owh my bad, im in ICMP Tunneling with SOCKS. and i try to connect with tdp but it can't connect. is the machine in the middle is the ip that the module give us? like 10.129.

#

because of the ptunnel-ng is doesn't run so i try to use other tools. but it still didn't run aswell

fathom pendant
#

10.129 is the first machine

#

do me a favor when you connect to the first target: check the ip info

cyan lark
#

I am getting an SSL error when trying to browse into the hidden admin page? @fathom pendant

potent yoke
#

172.16.5.129

fathom pendant
#

ah i was thinking you were on the next section which is a common section for people to get messed up on

fathom pendant
#

not https

cyan lark
#

ssl error when I'm trying to use http ... that's actually embarrassing

fathom pendant
#

make sure you comment out the other socks config line

#

that tends to mess with it a fair bit

potent yoke
#

okay marcieleee

#

so this is the ip of the middle machine?

fathom pendant
#

as you can see your proxychains is trying to use 127.0.0.1:1080 and because it's in strict mode, it's failing and not trying 9050

fathom pendant
#

i was thinking you were on the next section

potent yoke
#

owh okay2

cyan lark
#

Appreciate the help 🙏 @fathom pendant
just got done with the module

potent yoke
fathom pendant
#

and comment out the socks4 line

potent yoke
#

okay already

fathom pendant
#

this is why i don't mess with proxychains stuff, too much headache

potent yoke
#

yap, before when i still in some module i can read so much documentation to learn about it. but when it comes to pivot, port forward, and tunnel. my head feels blow up

#

it's like a totally new field again for me, but it feels challenging

iron plaza
#

Anyone around to explain the question at the end of the Introduction to Malware Analysis - Debugging module (/module/227/section/2496)? I am unable to find the process for the notepad as it does not pop up on the list. Thanks in advance.

potent yoke
#

i still can't do the rdp and ssh -D 9050 into the server. is that anything that im wrong? @fathom pendant

fathom pendant
#

no idea

#

chat with support

#

¯_(ツ)_/¯

potent yoke
#

T_T

fathom pendant
#

i'm assuming you also did the ptunnel-ng steps

potent yoke
#

but thanks for the help marcielee

fathom pendant
#

as those seem to be important for this

#

also try running proxychains with sudo

potent yoke
#

owhh icic

fathom pendant
#

sometimes it's weird like that

potent yoke
#

okay2 i will reset my machine

#

thanks marcieleeeee

long kestrel
#

The sanitizers section of intro to binary fuzzing was fun. I wish it would have went over other sanitizers with examples as well rather than just address sanitizer though

cyan lark
#

Hey, I'm on the Hacking WordPress module.

At the Directory Indexing section.

I received a simple WordPress website, and was asked to manually enumerate the target for any directories whose contents can be listed, and locate a flag with the file name flag.txt.
Problem is I crawled every file in /wp-content/uploads/ and /wp-includes/ and the /wp-content/plugins/photo-gallery (a plugin that I found)
/wp-config.php returns a blank page

I can't find flag.txt.

storm elk
#

Enumerate some more 🙂

cyan lark
#

What am I missing? I went over all of the files mentioned in the WordPress Structure section.

storm elk
#

There’s more plugins

cyan lark
#

Are there..

#

You're right

storm elk
#

Good luck 🤞

cyan lark
#

Got it, thank you @storm elk

storm elk
foggy tusk
#

Hey guys got a question about the footprinting module the DNS section

This is the question to the challenge
What is the FQDN of the host where the last octet ends with "x.x.x.203"?
I have found the domain for 203, but when I try to query for the SOA, it return nothing to me
I tried to query any and it only give me the A DNS records

cyan lark
foggy tusk
#

Wait I got the screenshot but can't send picture

#

Do I need to verify first to send pic?

storm elk
foggy tusk
#

Identified, I blur the domain name just in case for spoiler

cyan lark
#

did you try to dig specifically for soa?

foggy tusk
#

You mean dig SOA @$IP [domain_name]?

cyan lark
#

yes

storm elk
#

Damn @foggy tusk your pfp making me hungry

cyan lark
#

lmao

foggy tusk
#

Yeh done it return nothing as well, I'll send a pic

foggy tusk
cyan lark
#

Why are you trying to get the SOA?

empty trout
#

Which group can connect to LINUX01? how can i find this i cant think of anything module = password attacks , section passthe ticket with linux

foggy tusk
#

I just tried submitting the domain name and it is a correct answer, idk why

cyan lark
#

See that's in your mind

#

Yeah I just read the question again and I was like what is he talking about SOA for lol

foggy tusk
#

So FQDN means the domain name itself?

cyan lark
#

Fully qualified domain name

foggy tusk
#

I really need to reread the theory

cyan lark
#

Well I didn't do the module I just googled it

foggy tusk
#

Okay, thank you for the answer I'll do more research again

cyan lark
#

of course

unborn summit
# foggy tusk Hey guys got a question about the footprinting module the DNS section This is t...

https://superuser.com/questions/1021869/using-sub-subdomains-with-bind

This might be interesting to read. Apparently there is only one SOA per zone, so that would imply that all the subdomains are managed by the same zone which challenged my understanding of dns

foggy tusk
#

I'm reading about it and trying my best to process the info rn, I have become the loading cat

empty trout
#

have anyone noticed in the module = password attacks , section = pass the ticket with linux the ccache of julio is changing

fathom pendant
empty trout
#

but is there a script running to keep the ccache valid from time to tome

fathom pendant
#

no; there's a script running that should generate a valid one

empty trout
#

yeah same thing

fathom pendant
#

no

empty trout
#

but the date of creation of those files are same

fathom pendant
#

you said from time to time

empty trout
#

ok i am wrong you wins

fathom pendant
#

since the targets aren't on 24/7; there isn't one

#

both ccache are generated at target spawn, but only one is actually valid

empty trout
#

yeah

fathom pendant
#

one is generated from a script that spawns one with a certain set of info, one that is generated from actually querying the DC

empty trout
#

let me find that script i am root btw

fluid lantern
#

https://stackoverflow.com/questions/32762773/use-php-exec-to-launch-a-linux-command-with-brace-expansion

I've come to share knowledge (no one asked for it, but incase someone is curious and sees my question in the future), it is because possibly

"the 'outer' shell you are implicitly using to call your shell script using shell_exec() is probably not Bash in your case. This way, brace expansion never takes place because there is no shell capable of expanding the expression before calling your program (as it would be in an interactive Bash session)."

That's why i wasn't able to recreate the bash shell even in a similar deb env.

fathom pendant
#

i wouldn't concern yourself too much with trying to figure it out

empty trout
#

i am not hoping to ..

fathom pendant
#

also try not to spoil module info

#

:))))))

empty trout
#

yeah

fathom pendant
#

(screenshots from the target about specific environment bits is spoiling)

#

don't be weird

empty trout
#

gr8 i know you know more

fathom pendant
#

i'm pointing out that the module is tier 1; and the rules of this channel specifically say don't spoil above tier 0

fathom pendant
empty trout
#

ok it will not happen again

fluid lantern
fathom pendant
fluid lantern
#

ohhh I didn't see the channel title "but do not spoil module content over Tier 0" , is there a place to discuss Tier 2 or higher module content?

fathom pendant
#

generally speaking, outright giving/providing a solution is spoiling as someone can just copy what you did without actually putting in the work themselves

fathom pendant
#

you can ask for helps and hints to nudge forward

#

but you can't share direct solutions or commands

#

it's why i do my best with my nudges to be general enough, but make sense in the context of doing the material

#

if a conversation about how to move forward with a t1+ module you're stuck on needs to happen, it can be taken to dms so as to 1: not flood and 2: not spoil since in DMs things can be a bit more direct

fluid lantern
#

sounds good! I was just curious on why the command works in the module env and not in a normal deb env moreso and wanted to share exceptions in env! otherwise noted on everything mentioned, I'll try not to spoil in the future 👍🏾

fathom pendant
#

if anyone is curious as to nudging instead of direct answering:
Nudging encourages the person asking the question to apply critical thinking; if i were to just tell you to do x instead of well what about <hint that makes 0 sense out of context> for instance with one of the modules one of the hints is 🤖 to encourage the person asking to consider one of the most common files on a web server: robots.txt

#

or sometimes engaging in the 'why' method, asking 'why' someone is doing something has them think and rationalize that either "i'm overcomplicating" or "i'm doing something wrong"

#

happens a lot where you're trying to overthink the problem; your first focus in any of the modules should be to follow the instructions (changing a thing here or there to get the flag) and then tinkering around with other potential methods

wide lynx
#

hi

storm elk
signal rain
#

When it comes to the Target(s) in the modules if the time runs out and I refresh the target, will any of the previous actions that I did to the previous target stay or be affected?

Like let's say I was using intruder to fuzz for something and the targets life limit expires.

fathom pendant
#

if it times out while using intruder (assuming you used intruder near the start of its lifetime) you're doing something wrong

signal rain
#

Gotcha, thanks for the answer

hearty wolf
#

I’m neweeeew

fathom pendant
#

this isn't a gen chat; read and follow #welcome to access #general (as well as to see what this server is about)

stone gorge
#

In the CAPE training, Kerberos Attacks module, under Kerberoasting from Linux, when I run GetUserSPNs.py, I get an error - [-] [Errno 2] No such file or directory: 'DC01$.ccache'

#

Has anybody ever experienced this?

hasty mauve
#

are there modules in the academy that can prepare me for HTB challenges?
It has many stuff like Crypto, Reverse, etc. but I'm not well taught in these stuff.

fathom pendant
#

there's some binex stuff and some game reversing but as far as crypto there's nothing (at this moment) regarding that

hasty mauve
fathom pendant
#

google ¯_(ツ)_/¯

stone gorge
#

I am inputting the command exactly per the coursework.

compact patrolBOT
fathom pendant
#

i guess

#

otherwise i suggest resetting the target, changing vpn region, praying ¯_(ツ)_/¯

stone gorge
#

nevermind.... I still had KRB5CCNAME environment variable set from attacking a different box in the lab.

fathom pendant
#

silly artifacts

stone gorge
#

Yet, another forehead slapper...

rustic socket
#

May I know that is it because of the location make the network so slow? cause I am stuck at the first pwnbox section

fathom pendant
#

?

#

it helps to provide the module name and section name

rustic socket
#

the intro to academy page 4

#

which ask me to paste a command

fathom pendant
#

page 4

#

that's not the section name

#

section name may be something like "interacting with targets"

#

you don't need to paste the command either

#

you can just type the command in

#

but if you're having issues pasting, there's a clipboard on the bottom right (if you fullscreen)

rustic socket
#

the section name is 'section', it is part of the intro to academy

rustic socket
fathom pendant
#

otherwise you can just type in the pwnbox terminal cat /etc/issue

#

if you link your htb account via #welcome instructions you can paste screenshots

fathom pendant
#

if you're experiencing delays when typing in; you can change the pwnbox region, but i don't recommend that if you're a free user as you only get one spawn per day

surreal urchin
#

Hello Confues in the ffuf skill assesment : Question 3

fathom pendant
#

i'm assuming you already fuzzed and found what they asked for

surreal urchin
#

Yas i found the /admin dir but there is the login page : try many things f=but there is no api key

earnest pasture
flat sequoia
#

Hiii every one
Where can i find hint about Alert(Machine) Easy
Thks

fathom pendant
fathom pendant
surreal urchin
fathom pendant
#

yeah that's information gathering: web edition

#

not the ffuf module (attacking web applications with ffuf)

fathom pendant
mighty magnet
#

hi

storm elk
fair yacht
fathom pendant
#

you don't need to have CPTS to start CAPE

empty trout
#

if the ccache is updated does the old one expires

#

i know KVNO but i dont have info about KVNO of a keytab

regal oxide
#

may i know which module teach about mimikatz? thanks

fathom pendant
#

there's a few that utilize mimikatz but none that strictly teach it

regal oxide
#

ok can point out which modules touch on mimikatz thanks

fathom pendant
#

AD Enumeration and attacks, I think Password attacks for one of the things uh not sure, don't have my notes or anything off the top of my head

#

i know the t3+ AD modules utilize mimikatz a fair bit

regal oxide
#

ok no problem thanks for point it out hard to search on hackthebox site, this is really helpful enough

#

thanks

fathom pendant
#

unless it's a module or section title the higher tier and/or newer modules that mention mimikatz take precedence

regal oxide
#

ya really hard to find

#

if really no other choice will google for it

fathom pendant
fathom pendant
#

but tbh if you do the pentester path you're gonna run into mimikatz a bit

#

¯_(ツ)_/¯

#

if they do make a mimikatz dedicated module it'd likely be t2 at least

#

maybe t1

regal oxide
fathom pendant
#

the modules teaches you the info you need regarding mimikatz and what they want you to do

#

if you really wanna learn mimikatz just RTFM

regal oxide
#

i will be subscribing up to t3 cause some t1 and t2 doesn't have what I want to know, not that i am very good it is just need to cherry pick

fathom pendant
regal oxide
#

mimikatz is just one of the must know tools I bump into understanding issue while attacking AD

regal oxide
#

cause when i use mimikatz to do part of the AD attack or enumeration i get the results butr seems like don't get certain part of it as in don't quite understand how i get the result

fathom pendant
#

can't help ya there ¯_(ツ)_/¯

regal oxide
fathom pendant
#

generally the type::tool is self explanatory

regal oxide
#

mimikatz have 5 techniques of attacks i trying to see what it does

honest crane
rustic sage
#

i’m brand new to cybersecurity and need help on htb. is there a step by step guide . i’m on a student account, do i need to up my account to get step by step guidance or is there anything like that on hack the box

regal oxide
vast creek
#

Gives you

#

A guided mode

rustic sage
#

ok thank you

vast creek
#

And also you can go with Academy htb also

fathom pendant
fathom pendant
#

but they're referring specifically to being new on academy, referring to the student plan

#

I answered earlier but someone deleted it

oak girder
#

hello

rustic sage
fathom pendant
#

watching someone else do something only goes so far; the benefit of academy is you being able to do it yourself

#

you can read and perform actions

oak girder
#

I can't connect to RDP, does anyone know how to fix it?

fathom pendant
#

i suggest the information security fundamentals course to get your bearings

fathom pendant
#

but as far as that, no videos exist for academy content (aside from tier 0)

regal oxide
oak girder
#

The screen will go black, and then it will exit

fathom pendant
#

the annual plan guides aren't really great for learning from either as they don't necessarily teach you anything

fathom pendant
#

you don't need to blur the IP btw, no one can connect to the 10.129.x.x machines aside from you

oak girder
#

Okay, thank you, but I still can't connect

fathom pendant
#

aside from that i'd say tinker with different vpn regions or the classic just turn it off and turn it back on

oak girder
#

ok I'll give it a try

regal oxide
fathom pendant
#

and the other obvious don't run the vpn on your host machine while using pwnbox

#

just give it a few minutes

oak girder
#

I am trying

fathom pendant
#

as the AD enum labs are networked machines

#

you didn't blur the answer in that image

#

btw

oak girder
#

ok Sufficient patience is required for debugging, thank you

fathom pendant
#

also i always suggest adding the /dynamic-resolution option to xfreerdp, so that you can resize the window

oak girder
#

ok this is really cool

fast kettle
#

Can someone pls help me

#

i dont have the 'permissions' to text on the general chat

fathom pendant
fast kettle
#

i dont have permission to send there either

honest crane
#

Password Attacks - SA - Hard Lab

I managed to move the ||Backup.vhd|| file to an accessable directory by ||Johanna||, but mounting it requires Admin privileges. What am I missing here?

fast kettle
#

what do i do

fathom pendant
#

engage in critical thinking activities

edgy schooner
#

Good morning all. I am trying to do the Knowledge Check for Getting Started Module. So far I was able to find credentials and get to the point where I need to add a php reverse shell to somewhere either in existing code or upload a new file.

Does anyone have a good article or piece of advice on where to place the rev shell in the code or if I am on the right track? Again, trying to do without a walk through, but I have been here for quite some time.

I have a listener setup, tun0, 9443, etc., but can't seem to curl and get anything to connect.

fathom pendant
edgy schooner
#

Sorry to interupt above convo.

fathom pendant
#

there is no convo, don't apologize

#

this channel exists to help people with modules, you asking for help isn't interrupting anything

fathom pendant
#

also not much of a convo, more like a brick wall

edgy schooner
fathom pendant
#

i haven't touched this in a minute, this has ||themes|| enabled yeah?

edgy schooner
#

Yes!

fast kettle
fathom pendant
#

just put the code into one of those, then go to the directory specified (it'll tell you where it updated iirc) and magic

edgy schooner
#

Ohhhhhh... I had the bash one liner inside of it from previous.... I think I get it

honest crane
fathom pendant
#

i'll tell you this this is basically the last step

edgy schooner
stone gorge
#

I cannot grab a hash in CAPE - Kerberos module - Unconstrained User...

#

kbrelayx is receiving the hits and Printerbug seems to be working fine, but it's not writing hashes to the disk...

empty trout
#

i cannot ping the dc with the config setup by chisel and proxychains first its very confusing and second i dont now how they both communicate with each other proxychains and chisel . i am on module password attacks and section pass the ticket with linux on optional que Transfer Julio's ccache file from LINUX01 to your attack host. Follow the example to use chisel and proxychains to connect via evil-winrm from your attack host to MS01 and DC01. Mark DONE when finished.

#

when i use the command proxychains python3 wmiexec -k dc01

#

and the dns 4.2.2.2 ????

hasty mauve
empty trout
#

yes

fathom pendant
#

Try running proxychains with sudo

empty trout
#

i did nmap scan

fathom pendant
#

I believe the module as well talks about how to add a domain to the search/configuration in resolv.conf

empty trout
#

they tell about /etc/host

fathom pendant
#

Also, I'm assuming you put the dc01 in your hosts file?

empty trout
#

yeah but not about resolv.conf i did add the entry of the ip of domain in there but no luck

fathom pendant
#

You need to put DC01.inlanefreight.htb AND DC01

empty trout
#

in hosts?

hasty mauve
fathom pendant
fathom pendant
# hasty mauve yes

I forget i feel like there's one more you gotta add to that hosts line

empty trout
#

yeah i have the entry just like in the module

hasty mauve
fathom pendant
#

Probably?

#

Kerberos is quirky

empty trout
#

nmap resolvs the ip to the domain by default and it is doing that so i think there is no problem in the /etc/hosts file

hasty mauve
# empty trout

can you show your proxychains config file + your chisel setup?

empty trout
#

ok

hasty mauve
# empty trout

since you have socks5 in your proxychains config file, I think you need --socks5 in the reverse chisel server command.

empty trout
#

ok i will try

naive cedar
#

happy lunar new year ^^

empty trout
#

thanks i think the issue is resolved but got another one

fathom pendant
#

Also try with psexec

empty trout
#

why psexec worked

fathom pendant
#

Different coding

empty trout
#

@fathom pendant you have every answer

fathom pendant
#

While they're similar in nature, they do functionally different things to achieve the shell

empty trout
#

yeah agree

fathom pendant
#

wmiexec uses windows management instrumentation, psexec uses process injection i believe

empty trout
#

yeah via smb

#

IPC interprocesscommunication

dark hedge
#

iirc psexec creates a service

hasty mauve
# empty trout

welp, I know that psexec works with SMB, but what does wmiexec work on?

empty trout
#

wmi

#

windows management instrumentation

dark hedge
fathom pendant
hasty mauve
empty trout
#

yeah smb3

fathom pendant
empty trout
#

smb3 dialiect

fathom pendant
#

Ot at least that only plays a small portion

empty trout
#

yeah

fathom pendant
#

It communicates with 445 and 88, smb and ldap respectively at least iirc 88 is ldap

hasty mauve
dark hedge
#

88 is Kerberos

fathom pendant
#

Ah 88 is kerb auth

#

Been a minute

hasty mauve
#

guess I'll need to have a little bit more exposure with impacket utilities lol, not just use the tools that always work for me.

fathom pendant
#

Since a lot of this is interplay

dark hedge
#

psexec doesn't need Kerb auth

frank sierra
#

Hey guys, can I help you? 😄

dark hedge
#

works just fine on a regular Windows host

#

but if domain joined obv it will query the DC

empty trout
#

hell i dont get it

frank sierra
#

wmiexec uses Win32_Procecss object in WMI for command execution (RPC over DCOM) and puts the output in a file. then it uses SMB to read output. in recent versions of wmiexec.py you can use -nooutput to disable smb (so you don't have access to output directly)

dark hedge
#

you can get a very high-level overview if you check the script on the impacket repo

fathom pendant
hasty mauve
empty trout
#

ok lets move on

hasty mauve
dark hedge
#
Optiv

Consultants often upload and execute a binary payload to a remote system during penetration tests for the purpose of footprinting the target, gathering information, and leveraging that information to compromise additional hosts. When the scope of the engagement calls for the consultant to remain stealthy and undetected throughout the assessment,...

#

this is for smbexec, similar to wmiexec

hasty mauve
empty trout
#

what is happing today

#

whats the difference in dc01 and dc01.inlanefreight.htb

#

why it reached to winrm afterwards

fathom pendant
#

some services only accept either IP or fqdn, and when interacting with kerberos; fqdn is preferred

#

but looking back over your screenshot it's also about hostname

#

the hostname of the DC isn't DC01.inlanefreight.htb it's just DC01

#

and you're interacting with the domain of inlanefreight.htb

#

i wonder if you can just do -i DC01.inlanefreight.htb and not worry about -r

empty trout
#

yeah u are right but i am confused about having the same ip over these two names

#

virtual host thing is on web

fathom pendant
#

because you're not dealing with things over the web (fully)

#

you're dealing with silly kerberos things

#

vhosts and stuff like that are exclusive web terminology

harsh swan
#

Hey there!, I'm really stuck on the module API Attacks in section Broken Authentication, I managed to get the account info but all options tu reset password are OTP needed, and I can't manage to get rid of that OTP because they are sent to the saved user email and phone number... any enlightment?, I've been trying for two days but my practice time ends and still have no Idea about how to solve this...

empty trout
#

at first i think there was a problem on krb5.conf file then i enter the correct entry . but then i got frustrated over this que i am moving on

gray yacht
harsh swan
# gray yacht Have you tried to brute force it?

yes, I used ffuf following the example on the lecture, but there are no OTP wordlists locally and when I try to download an external wordlist seems the practice machine is nos allowed to download anything, tried by curl, and directly on the website that hosts the wordlist, but always responser with a connection error.

gray yacht
harsh swan
#

I'll do that, thanks wish me luck 🙂

gray yacht
harsh swan
#

Thank you I really apretiate

bright ridge
#

The name of the container is "Deleted Objects" not Tombstone

#

this should be corrected

#

tombstone is the state of the object

vagrant cargo
#

Hey guys, in the "Using Crackmapexec - MSSQL Enumeration and Attacks" we are told we can run commands using on the server via "-x" flag, during the exercise i notice it doesnt work and wonder if i need to enable xp_cmdshell first yet i didnt find any module/option to do so with nxc. After enabling xp_cmdshell with impackets mssqlclient.py, running commands with nxc was working.

Is there a way to enable xp_cmdshell with nxc? because it seems the module forgets to mention that

fathom pendant
#

don't share answers to modules, if you feel it needs correction please post in #1234357888114364508 with the module and section name

snow quartz
#

Hi. I'm working on the File Upload Attacks module, in the section Limited File Uploads. After I'm trying to exploit the SVG file upload, it seems that I encountered the issue where the web app lost the upload button, which shows the SVG image is blank, as well as the source code. Is there something that I missed during the exploit?

fathom pendant
snow quartz
vagrant cargo
#

and no module to do either

fathom pendant
#

¯_(ツ)_/¯

fathom pendant
#

er not smb

#

sql

vagrant cargo
#

idk, i figured the entire idea is to enable it through interaction with mssql

fathom pendant
#

-q you can send a 'query' string

#

so maybe you can pass through the enable xp_cmdshell commands

vagrant cargo
#

just tried it again to make sure, didnt work for some reason, still its wierd nxc doesnt do it automatically if u use -x to run a local command, or atleast have an option to enable it

fathom pendant
#

like printnightmare and shit

gray yacht
simple zephyr
#

CAPE module help.

Anyone finished this part from RBCD from linux

Compromise the domain without creating a machine account. Use DONE as the answer when finished.

simple zephyr
#

I know that, but that doesn’t help me ensure I know how to do it, if it’s on the exam

fair yacht
#

my bad, thought u were asking for the flag lmao

fathom pendant
#

it's optional as in it's an additional way to do things

#

you'll likely be able to create a machine account (if it comes to it)

simple zephyr
#

🤞🤞

fathom pendant
#

imo finish the module then go back and do the optional bits

bitter ridge
#

MacOS Fundamentals, no targets, and my workstation (pwnbox) is still parrot.os

simple zephyr
#

Nice, I’m taking my time because I’m building obsidian templates for each section. It’s nice with the templates it auto fills all your findings.

fathom pendant
bitter ridge
#

See I had a feeling that was the case but I didnt look at the overview just at the intro etc. Thank you

storm elk
#

Marcie is 🔥

bitter ridge
#

Thanks BOTH o f you lol

toxic ingot
#

question about HTF do i have to remember everything i read. or will it all connect at the end because i started Pen test path

cloud urchin
#

I'd say you'll want to have a solid understanding of the material taught, yes. You'll need strong foundational knowledge to understand how the underlying systems are really working and apply what you learned to new situations that you haven't seen before based on that fundamental understanding and knowledge.

lusty thicket
#

context and repetition

toxic ingot
lusty thicket
fathom pendant
#

Yeah but until it clicks, it saves the time of loading webpages if you already have notes of what to try

lusty thicket
#

the knowledge needs to be relevant and applied to the specific situation

errant pivot
pine dune
#

Good evening all

#

thats a cool kali, how did u get it to look like that?

cloud urchin
#

Careful not to post spoilers for the module

#

I would recommend reading over the section again and make sure you're using the right commands

simple zephyr
#

It really wasn’t a spoiler, since you can click done and what I was doing wasn’t working. It was also a direct copy paste from the module.

cloud urchin
#

well yeah.. posting content from the module isn't allowed unless it's a tier 0 module

simple zephyr
#

you can with spoiler tags though right?

cloud urchin
#

no

simple zephyr
#

This isnt me trying to argue, just ensuring that I understand correctly, but isn't the erratum section covered in screenshots of items not working correctly from modules, and for the past two years I have seen people that have trouble with syntax post screenshots or syntax snips from the modules of what did not work.

dapper moth
#

Anyone for a quick chat on the "Applications of AI in InfoSec" Module?

cloud urchin
simple zephyr
# pine dune thats a cool kali, how did u get it to look like that?

To answer your question, I use starship with zsh plugins. The terminal is windows terminal that I ssh into my kali box and I us ligolo from my windows machine to kali, so i can use tools like burp, firefox, rdp and etc to target machines on tun0. Just started with workflow last week, so we will see how well it works.

Here is a shot of the terminal since my last post was in violation and should have been posted, for those that are curious. I am more than happy to share dot files or help people establish a solid or riced out shell. My starship was taken from typcrafts dotfiles, but my color scheme for everything is dracula

dapper moth
calm tapir
#

Working on Web Attacks: Chaining IDOR Vulnerabilities and I am working in the following question:
Try to change the admin's email to 'flag@idor.htb', and you should get the flag on the 'edit profile' page.
I changed the email but the flag isn't generating.

pine dune
fair yacht
simple zephyr
#

Yup I’m using VMware workstation for my Kali. I just SSH into it.

oblique flume
#

can anyone help me with “virtual hosts” in “information gathering-web edition” module

#

my gobuster is coming up empty every time

cloud urchin
#

when i did the module it was using ffuf, did that change with the update of the module?

oblique flume
#

i’m using this command gobuster vhost -u http://94.237.59.180:40296 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain -o vhosts.txt

#

yes , it’s gobuster now

cloud urchin
#

looks to me the issue is related to your -u value, that should be a hostname not an ip address.

cloud urchin
#

actually i could be wrong not sure i didn't do the updated module, but they give 2 commands one using the hostname instead

hearty wolf
#

How do I start 🫡

compact patrolBOT
river gale
#

Guys, I need help, Because I am really stuck here. and don't know why it isn't working at the last point, I did everything the same what every showed on the modules, but still not working.

Use the concepts taught in this section to pivot to the Windows server at 172.16.6.155 (jason:WellConnected123!). Submit the contents of Flag.txt on Jason's Desktop.

fathom pendant
fathom pendant
river gale
calm tapir
#

Can anyone help with Web Attacks: Chaining IDOR Vulnerabilities and I am working in the following question:
Try to change the admin's email to 'flag@idor.htb', and you should get the flag on the 'edit profile' page.
I changed the email but the flag isn't generating under the admin edit profile page.

fathom pendant
river gale
fathom pendant
#

Make sure everything you do looks like what's done in the examples, same messages and all

#

If you wanna send images here read and follow #welcome

oblique flume
cyan lark
#

Is there a module speaking about CGI?

fathom pendant
#

It's touched on in a couple modules but nothing in depth beyond "hey cgi bins can be vulnerable, try this"

cyan lark
fathom pendant
cyan lark
#

CGI, not cgi-bin

#

Or is it the same?

dull carbon
#

If possible, can someone help me understand why I get varied results using SMTP-user-enum, I have the answer because I used Metasploit but I want to understand where I went wrong. (this is for the Pentest job role, footprinting, SMTP) The question wants me to find the username. With the default query timeout I dont get any responses, I increase it to 6, I get 6 usernames that exist, when i check these with VRFY none of them exist, If I increase to 7 for query timeout I got a lot more resullts, the correct ansnwer is in there but finding it would mean me taking most of the provided wordlist and using the VRFY command on each which kinda defeats the object of using the tool

#

thanks in advance

lusty thicket
#

the more time you give it, the more the server can screw tihh you and provide you with false positives

#

VRFY can be unreliable, so you might have to use another technique to confirm these usernames

cedar dagger
#

For the Attacking Common services modules in the FTP section is it normal that I get disconnected from the ftp port it closes ? I managed to get the files with the anonymous users but now I cant even reconnect to it ?? dunno if its a bug or the way its intended , cant even bruteforce the user and pass with hydra or netexec or medusa as i keep getting dc ? Dunno if im doing something wrong or its the intended way??

winter schooner
cedar dagger
#

I tried that a couple of time xD I'll wait a hour or so before trying again then thanks for the tips

dull carbon
#

I’ll have to do a bit of research on this tool

lusty thicket
#

yes, please do a bit of research

dapper moth
#

Really nice Module! The Introduction one was heavy on theory, but this one was really nice!

https://academy.hackthebox.com/achievement/799850/292

next current
#

hello, How do I access this IP from my virtual machine?

#

module: getting started

fathom pendant
next current
#

thankS!

earnest pasture
#

Guys I have a question in the Skills Assment File Upload, when I got using burpsuite to intercept the request and see how the image was being sent, after fuzzing and knowing what extensions are allowed and so on, when I sent it to the intruder the image was uploaded but if I sent it manually from the Repeater, it kept telling me “Only images are allowed” but from the Intruder the image was uploaded, can anyone know why this is happening? Or is it a machine error?

cloud urchin
#

sounds like there's some filter in place or you changed something which made it think it's not an image. try bypassing the filter.

earnest pasture
cloud urchin
#

There is no "better." Infosec is as wide as it is deep, pick the niche you want to learn and go for that one.

lusty thicket
#

yeah, cbbh

fathom pendant
#

Linking on the website doesn't actually do anything (yet)

next kite
#

more odd that I can't message there and had to here since it's a bit off topic. Should have someone fix that lol

novel matrix
gray yacht
naive cedar
next kite
fathom pendant
#

And yeah, it's an official server relating to a product/service, of course you need an account

#

But it's not like you need to pay for the account

next kite
#

Yes but that also requires an account. can't even come to ask questions about the service you might be interested in. Doesn't make much sense so.

fathom pendant
cloud urchin
next kite
#

no but community members could

cloud urchin
#

and they do here

fathom pendant
pine dune
#

Hi

next kite
#

anyways I don't want to just be ranting when I was just trying to inquire so I'll be on my way then since it's not welcomed.

fathom pendant
#

You should be able to pose your question there

pine dune
#

I have a small question regarding php

fathom pendant
#

Since you're so adamant about not creating an account (which is 100% free to create)

pine dune
#
echo gethostname(); // may output e.g,: sandie
?>
```  this command does get/executes the system to get hostname right?
fathom pendant
#

gethostname() seems like a built in php function

#

Since it's not doing system (command)

pine dune
#

ah I see, I needed to execute the hostname on one of the file upload attack module and it said to execute hostname. I searhced how to get hostname from php on google and this was one of the top results

#

when I uploaded this file it gave some error

fathom pendant
fathom pendant
#

More than one way to perform desired actions

pine dune
fossil jacinth
#

So I just did the Footprinting Lab - Medium and I have a question, trying to understand some things. Anyone up for a chat ?

pine dune
cedar dagger
#

Anyone else having issue with Attacking Common Services - FTP/SMB machine ?? Ports for the service works and after a few minute they not working anymore I restarted the machine a few time and sometime it work 1 time sometime 2 times but most of the time it dont even work on machine spawn

fathom pendant
fathom pendant
#

could be a config that disallows that function

pine dune
fathom pendant
#

not that weird

pine dune
#

it did say it wasnt validating the file uploads 🤔

fathom pendant
#

if you were running a php server you'd wanna mitigate attacks no?

#

¯_(ツ)_/¯

pine dune
fathom pendant
#

doesn't mean there can't be stuff that prevents execution

#

also did you try without the echo?

pine dune
#

ok seem there was apparently an error with what I was doing or the website, well I refreshed the target and it worked now 🙂

earnest pasture
gray yacht
earnest pasture
cedar dagger
#

Someone can give me tips for the Attacking commons service SQL part?

#

I connected to the mssql server using impacket-mssqlclient

#

afterward I run responder on my attack host

#

execute this command on the mssql server : EXEC master..xp_dirtree '\10.10.17.28\share\

#

Receive an NTLM hash on the attack host

#

But tried to crack it with the ressource wordlist and the one found into the ftp/smb server but no hits

#

am I missing something?

safe star
#

Did you copy the whole hash?

#

Wait you did crack it?

cedar dagger
#

no it cant crack it

hasty mauve
safe star
#

Did you use 5600?

cedar dagger
#

I used 1000

#

is 5600 the right for ntml?

safe star
#

That’s ntlm not ntlmV2

#

Yes use 5600

cedar dagger
#

oh right

#

that might be it

#

Right I thinks thats it -> 5600 NetNTLMv2

#

It worked thanks

#

How do you guys know what hash type to use is there a way to dectect or a program to autodetec hash ?

hasty mauve
cedar dagger
#

Very nice thanks ill add this to my notes

late parrot
#

I need to reach an admin please?

calm tapir
#

Web Attacks Skills Assessment I am stuck on changing the admin password. I've tried using ||uid + token + new password on reset.php|| but to no avail. Any guidance?

calm tapir
quiet ember
cinder warren
#

I am in the HTB academy path and in the Working with Files and Directories module. Why do I keep getting command not found when the command ls does work and when I pull up the manual page, it shows the flags I can use

#

I am trying to get the inode for it

#

-i is the command for inode but it isn't working

#

is the flag for ls

#

I didn't misspell it

naive cedar
#

shadow.bak, not shadow.bk

#

prayge .

cinder warren
#

that's what I did, shadow.bak

safe star
#

without the pipe?

cinder warren
#

ohhhhhh, ok

naive cedar
cinder warren
#

I will try that

#

You're right, I did it without the pipe and it worked

#

And you are right, shadow.bak is not a command, lol

#

I should have been using grep shadow.bak if I was going to use the pipe

#

all the little stuff to remember, it can be exhausting at times lol

#

True. I am in the learning phase for the basics. I am still very new to thsi.

#

this

#

I am going to try that right now

#

how do I exit out of this

#

exit worked

#

I think it might have been but I am not sure

#

I just tried what you suggested and it didn't work

#

but this worked, I get what you mean now

#

LOL, oh man! The little things are going to kill me

#

At least I am a little older and wiser so I won't want to throw my computer out the door, 🤣

#

When I get frustrated that is

#

Well I can't afford a new one every week, 🤣
I have calmed down as I've gotten older, thank God. I can just walk away from the computer now and get a little exercise to calm down.

cloud urchin
#

read and follow the instructions in #welcome to gain access

wind spruce
#

hihi i was wondering how you resolved this :X thank you... or if anybody would know, for citrix breakout, how does one switch from the citrix environment back to the local desktop?

fathom pendant
earnest pasture
fathom pendant
#

1; don't spoil assessments
2; read the evasion section again, there's something important in there relating to connecting 😉

lusty ridge
cinder warren
fathom pendant
cinder warren
#

I just have to get into the habit of doing it right away ALL the time.

jagged tartan
#

I have a question on the Windows Security section from Windows Fundamentals, particularly the "What 3rd party security application is disabled at startup for the current user?" question. ||I can't figure out where exactly NordVPN gets disabled, seeing as it is in the current user's Run key and therefore should be running. Is there something in Windows that can override what's set in the Run key?||

fathom pendant
#

¯_(ツ)_/¯

#

as you can see one-drive is also disabled AND in the runkey

jagged tartan
jagged tartan
#

Alright, thank you

granite osprey
#

Hello everybody ! In section https://academy.hackthebox.com/module/158/section/1427, I would like to practice the technique presented as advised in the conclusion. The problem is that we are supposed to have RDP access to the target, but no credentials are given. How to get around this problem ?

fathom pendant
#

you don't need to practice rdp or anything; plenty of the other sections deal with tat

#

this section is part of laying the groundwork for understanding the tools

granite osprey
#

Ok, thanks

stone gorge
#

I need some help ... Kerberos-Constrained Delegation from Linux. Nothing in this section works on anything -PwnBox, Parrot, nor Kali... reset machines about five times now. This is really a downer.

#

I get the ST with getST.py just fine and it saves. Export to KRB5CCNAME. Then psexec does not work on anything.

jolly yacht
#

is there an update to the Linux Fundamental Module?

#

I mean how can I know which section in the Module have been updated ? Because every section in the Module has a green checkmark like I have been completed.

storm elk
#

Progress won’t be reset

stuck shard
#

Hi everyone! I have started the Penetration Tester job role path and now I am having some hard time with the section "Pass the Hash" of Password Attacks module. More specifically in the question "Connect via RDP and use Mimikatz located in c:\tools to extract the hashes presented in the current session. What is the NTLM/RC4 hash of David's account?", even though I can successfully PtH the administrator's account through impacket, I cannot RDP to the same host using PtH and I am getting an (wrong username or password). I have modified the DisableRestricteAdmin registry key value under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa as well as the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy to 1, to allow local accounts perform remote administration. The xfreerdp command I am issuing is: xfreerdp /v:10.129.2.65 /u:Administrator /pth:30B3783CE2ABF1AF70F77D0660CF3453 /cert-ignore /timeout:6000
[06:31:18:280] [68675:68676] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[06:31:18:282] [68675:68675] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

A hint or some help will be more that welcomed. Thank you in advance.

#

└─$ xfreerdp /v:10.129.2.65 /u:Administrator /pth:30B3783CE2ABF1AF70F77D0660CF3453 /cert-ignore /timeout:6000 +sec-nla
[06:39:53:938] [72901:72902] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[06:39:53:940] [72901:72901] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

chilly echo
#

Module: AD Enum & Attacks
For past few days xfreerdp doesnt seem to work , but rdesktop works (VPN: US)
Command used : xfreerdp /v:10.129.243.216 /u:htb-student /p:"Academy_student_AD!" /d:inlanefreight.local /cert:ignore +clipboard /dynamic-resolution

jolly yacht
# storm elk Progress won’t be reset

ohh got confused because some youtuber mentioned that even though he completed the Bug Bounty Hunter Path, his path towards completion becomes 98 % percent or something because there's been a update on some Modules. So I though maybe the new updated section in the module becames to non completion.

lusty thicket
#

lol

silent kayak
#

@lusty thicket I'm for real I know basics but I need to know more about languages and how to read binary and write binary and I need to find out how to use Python and Linux cuz right now it's confusing me

foggy sierra
#

anyone able to point me in the right direction for 2nd question in** NTLM relay** skills assessment? - BACKUP01 =>|| i was able to create a machine account and coerce to get BACKUP01$ ntlmv2 hash and relay it too for q3|| , update: done , only last flag now :))

jolly yacht
silent kayak
#

@jolly yacht thank u what's that and where do I find it

#

Looking it up now thank u so much

full patio
#

Hi all. I'm just working on https://academy.hackthebox.com/module/116/section/1466 - Module: [Attacking Common Services - Easy]

Aside from the fact that the intro offers some insight into the server having SMTP - are we also supposed to be able to tell from our NMAP scans? Because, no matter how I've scanned, SMTP doesn't seem to be showing up. 🤷‍♂️

`sudo nmap -Pn -p- 10.129.203.7
Starting Nmap 7.95 ( https://nmap.org ) at 2025-01-26 15:57 GMT
Nmap scan report for inlanefreight.htb (10.129.203.7)
Host is up (0.031s latency).
Not shown: 65530 filtered tcp ports (no-response)
PORT STATE SERVICE
21/tcp open ftp
80/tcp open http
443/tcp open https
3306/tcp open mysql
3389/tcp open ms-wbt-server

Nmap done: 1 IP address (1 host up) scanned in 156.38 seconds`

gray yacht
full patio
gray yacht
torn edge
#

Hello! Sorry if this is not the right place but where should I ask for help with a retired machine? Thanks!

next current
#

I can't connect from my vm , i have activated my tun0 openvpn

calm tapir
shell ore
#

hey in Windows Attacks & Defense am I the only that cant connect to PKI at 172.16.18.15 via RDP?

#

It's not up at all

elder pond
#

Information Gathering - Web Edition -Skill Assessment question no. 3:
"After crawling the inlanefreight.htb domain on the target system, what is the email address you have found? Respond with the full email, e.g., mail@inlanefreight.htb."
I am not getting any results when doing crawling neither inlanefreight.htb not the subdomain I have found. Used reconspider and finalrecon on both targets and did not get any email. Any hints very apprecuated!

acoustic owl
#

Enumerate everything. Apply all the techniques in the module to everything you have found.

chrome maple
#

Hello I am doing a module but I cannot seem to get the flag

Command Injections: Advanced Command Obfuscation
Just to be clear we need to run the command: find /usr/share/ | grep root | grep mysql | tail -n 1
RIght?

elder pond
cloud urchin
acoustic owl
cloud urchin
#

well, i doubt the first two commands would execute correctly due to the parenthesis being missing, i'm going to delete that message though because it kind of reveals a lot

chrome maple
#

So there is a typo or some? What about the third one if you were able to see it

cloud urchin
#

you have an opening parenthesis but not closing

calm tapir
chrome maple
cloud urchin
chrome maple
#

Ohhh mb it was typo I was supposed to send the rev one there

cloud urchin
#

just remember the command is going to run on the system as you input it, so if you're reversing the command it's like you typing the command in reverse in the terminal, ie. it won't work. so if you reverse it make sure you reverse the code too

fathom pendant
chrome maple
#

So { would not be }
It still would be {

#

Got it thank you!

cloud urchin
fathom pendant
#

This is just to add on, meant to untag you lol

chrome maple
#

Ig using reverse string was a bad idea lol

gray yacht
fathom pendant
chrome maple
cloud urchin
#

yeah like if you type 'ls' into the console, reverse it'd be 'sl'

fathom pendant
#

Like going backwards through an array

elder pond
quiet ember
brittle eagle
#

Does anybody know how can I connect to an instance in the challenges, because when I try to using netcat or ssh it says couldnt resolve host

fathom pendant
modern talon
#

whats up with this ldap part: What non-default privilege does the htb-student user have?

#

there are no privileges that ur non-default

cloud urchin
modern talon
cloud urchin
#

that doesn't show all the privs

modern talon
#

what does?

#

I don't know any other commands?

cloud urchin
#

this is one of those things where context matters

modern talon
#

UAC?

#

or what

bright ridge
#

whoami /groups

#

user might inherit non-default privileges through group membership

#

also might be smart to do "whoami /priv" from an elevated shell

#

never done this module myself

modern talon
#

nah it was bug in the machine, had to restart it, it didn't gave me elevated shell

wooden perch
#

Hi all, I'm working on the 'Attacking GitLab' for some hours now. I cannot get the 1st question right "Find another valid user on the target GitLab instance.". I've run the python script with the usernames list under /usr/share/seclists/Usernames/Names (the longest one) and found exactly the same users in the lesson. The field doesn't accept the answer. Puzzled now, can I get any help on this?

fathom pendant
#

try using hydra instead

#

medusa is a bit finicky and touchy

#

also don't reveal info for modules above tier 0

whole vale
#

i was thinking that ngl i liked hydra cause it was easier(sorry btw about leaking info i tried to hide it but yeah can spoil it for yourself)

whole vale
# fathom pendant try using hydra instead

just a small question inside the module i am loging in from inside the thing using ssh, which has medusa installed and its specific password thing, but no curl or sudo.... weird ik, so i cant get hydra on the server so do i do it from a seperate box or somthing

fathom pendant
#

oh

#

which section are you specifically doing

whole vale
#

medusa- webservices

#

in login brute forcing

bright ridge
fathom pendant
wooden perch
#

I'm running the other wordlist now, and I already see uppercase ones.. weird

whole vale
fathom pendant
#

password reuse; consider that

#

consider the subsection <retrieving the flag> in the reading

fathom pendant
whole vale
#

yep so when ur in the ssh, but the password that got me into ssh isnt geting me into ftp

wooden perch
whole vale
fathom pendant
#

:)

#

(you don't have to bruteforce ftp to get q1 btw)

#

(ftpuser exists as a user in /home/ ... draw conclusions from there)

whole vale
#

nope i havent gotten there lol, i am in using ssh and i looked around a bit cause i have access to cd so i went to the home directory, but i havent gotten into ftp user

bright ridge
wooden perch
#

thanks will try out

fathom pendant
whole vale
#

so should i brute force using hydra from the outside........ cause the password given earlier in the module doesnt get me in

fathom pendant
#

not ftpuser

#

utilize some braincells to connect dots

whole vale
#

yep i am in sshuser

whole vale
fathom pendant
fathom pendant
fathom pendant
#

so it can absolutely be done from within the ssh session with sshuser

whole vale
#

yeah i dont know why i got that other thing the other time, i got the real one now thanks

fathom pendant
#

the 1... entry is for bruteforcing the sshuser... which is their password

#

make sure you put the right username kek

bright ridge
fathom pendant
#

i find it a minor oversight that they allow you to bruteforce the ftpuser and bypass even looking for sshuser :: eta dropped a post in #1234357888114364508 to maybe see if this is intentional or unavoidable

whole vale
wooden perch
tender nimbus
#

Hey guys, i'm stuck since a few days on the Windows Event Logs & Finding Evil skilss assessment, on the first question on the DLLhijacked, i did a lot of things but cant find nothing, first thing that i dont understand is why is there no ID EVENT 7 in the logs?

whole vale
#

sorry i am back but just a quick question after looking through login brute forcing-custom wordlist, am i suppsed to follow the example to get in, and if so how to i obtain usernames.txt(thats why i am wondering this is a example), or do i just brute force like earlier and use hydra and break in

fathom pendant
fallow kernel
#

Yo guys can someone help me with this one:

From the Pivoting module
The Web Server Pivoting with Rpivot section
Using the concepts taught in this section, connect to the web server on the internal network. Submit the flag presented on the home page as the answer.

Using firefox with proxychains the page does not load so I tried using curl, but the flag I see does not get accepted. Could someone check if I have the correct flag or if I am doing something wrong? The flag contains I_L0v3....... I have no spaces in front or after it

fathom pendant
#

try refreshing the page

fallow kernel
#

I tried but the firefox browser does not seem to want to connect

fathom pendant
fathom pendant
fallow kernel
#

Oooh well that also did not work and I have a different hash value

fathom pendant
#

then you didn't copy it fully or you missed something

#

dm me the flag you retrieved

wooden perch
#

@bright ridge am I on the right path using /usr/share/seclists/Passwords/Leaked-Databases/rockyou-70.txt to brute force? it's taking a while :/

fathom pendant
wooden perch
#

I'v tried others like the ones in /usr/share/seclists/Passwords/Common-Credentials/

#

the weak passwords mentioned on the section are found on the rockyou-70.txt, that's why I used

fathom pendant
#

if rockyou is meant then it'd be near the top of the file

wooden perch
#

hmm

fathom pendant
#

the examples won't always match what you expect

#

vaz gave you a wordlist to try from seclists btw

wooden perch
#

that one worked to find the user

fathom pendant
#

which should work

wooden perch
#

but know I need to break the pwd

fathom pendant
#

wait that's for user

wooden perch
#

hmm ok

fathom pendant
#

i know it was a basic list i don't recall which list though

#

for password

wooden perch
#

kk, will keep looking thanks

fathom pendant
#

read the last section again that last sentence seems like it could be interesting to try

#

However, if we encounter...

fathom pendant
fathom pendant
wooden perch
#

ok, I'm exploring the project but don't see any clue, might need to run nmap to find out something else

fathom pendant
#

nope

#

you're missing the important bit at the end of the last paragraph

#

something about being able to create your own account 😉

#

and depending on the version, you may be able to do some funny stuff 😉

wooden perch
#

yeah, I created an account on the 1st minute.. will explore the other project I see it available

#

ohhhhhhhhhhhhhhhhhhhhhhhh

#

I was so biased about the question 1 user account that I missed the basics

#

got the RCE working now!

#

I thinked too much and missed the obvious thing

wooden perch
honest crane
#

I'm about to start the Pivoting module, and I've been using Ligolo for some time now. I also know the module doesn't cover Ligolo but instead uses a combination of other tools.

My question is: would I miss anything if I didn't practice those tools and continued using Ligolo throughout the module? For example, is there a feature Ligolo lacks that might be critical in some edge cases?

wooden perch
#

Renata Sorrah

wooden perch
dark hedge
#

and that other method will usually involve proxychains

unique ether
#

Any idea why my zap proxy doesnt show hud when its turned on

#

Like when I request it doesnt give me the alert box to step and continue

unique ether
#

Any idea?

lusty thicket
unique ether
true breach
#

💀

safe star
#

💀

lone dagger
#

I can't complete Web Requests>GET it says:

The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search, and use cURL to search for 'flag' and obtain the flag

I'm using curl 'http://<IP><PORT>/search.php?search=flag' but nothing

cloud urchin
fathom pendant
#

yep browser devtools is the first step

cloud urchin
#

ugh nevermind i was thinknig about a different section

fathom pendant
#

even still i think this one is a bit interesting i'd have to pull it up to be sure though

fathom pendant
cloud urchin
#

actually yeah i got it just now

fathom pendant
#

same

#

used shitty wincurl

#

but i got it

#

:)

cloud urchin
#

lmao i used windows too

fathom pendant
#

wincurl, it's a pain if you're gonna do json requests

cloud urchin
fathom pendant
#

it's even above the question to authenticate, there's even syntax given in the section how to :)

lone dagger
#

First I did it with devbrowser, later with curl but I didn't get an answer bc I got a "failed to connect"

fathom pendant
#

and even a syntax for an auth bearer token

#

failed to connect
did it tell you anything about why it failed to connect?

lone dagger
#

curl: (7) Failed to connect to x port x after 271 ms: Could not connect to server

fathom pendant
#

ah

#

resetting the target tends to fix those issues

lone dagger
#

I did it 2 times... devbrow should give me a header auth?

fathom pendant
#

"Authorization: B64stringhere="

#

when you view the request

lone dagger
#

Can I send you ss? Again failed to connect

fathom pendant
#

is that ip and port up?

#

i'm assuming you're not literally typing IP:PORT into curl

lone dagger
#

Yes, I'm using an active target

#

Done

#

I was using my VM without the OpenVPN

#

Sorry for bothering

snow quartz
#

Hi. I'm working on the File Upload Attacks module, in the Skills Assessment section. Is there any person/user that I can DM to discuss here?

fathom pendant
#

It's a public ip:port, hence why I did it on winders

lone dagger
#

the same comand\

gloomy spindle
#

Hi, I am stuck in Windows Lateral Movement => Windows Remote Management (WinRM) => Question 3 (getting to DC01), could anyone give me some help? DM me please

mighty sierra
#

Hello Guys Someone available to ask about ADCS skill assessment ?

earnest pasture
swift anchor
#

Hey who can help me reset my Android phone i forgot my Password

urban elk
#

I hear putting it on rice helps

swift anchor
#

I'm new into these

snow quartz
fathom pendant
swift anchor
fathom pendant
#

Like how do you forget your own phone password

#

Besides it's off topic of this chat

swift anchor
fathom pendant
swift anchor
fathom pendant
storm elk
#

we can't help you @swift anchor

swift anchor
#

Yea alright guys thanks

fathom pendant
#

??? Random racism?

bright ridge
#

someone should just ban this guy

fathom pendant
#

I'm American btw

#

Dumb shit

swift anchor
fathom pendant
#

By assuming what I'm saying and assigning it to a locale for what I can only assume are racially charged reasons

swift anchor
fathom pendant
#

Nah, not offended, more confused than anything

urban elk
#

I hope that legitimate question that went deleted was deleted by the author, and not by mistake with all this noise

fathom pendant
#

There was no legit question asked yet

urban elk
#

splunk module question a minute ago

fathom pendant
fathom pendant
#

¯_(ツ)_/¯

#

Like I said you can't see shit, go fuck yourself with the fake scare bullshit

coral cedar
#

Hi, I am working on a question in the Hunting Evil with Sigma (Splunk Edition), but the generated query does not seem to show any results. Has anyone faced this problem?

fathom pendant
#

<@&861185840277487616> failing terribly at trying to scare me, it's not even funny

fathom pendant
urban elk
#

hey @fathom pendant can I DM ?

fathom pendant
#

No

lone dagger
urban elk
# fathom pendant Dumb shit

ok, I'll say it in public then. I don't think this (what I'm replying to) helps. It's not the first time either. As much as I don't appreciate these people either, I don't think it's necessary to go down to that level, and I don't see how that's not against the rules either. Especially with that badge. I'm not the police, but I'll give feedback about it, just wanted to tell you first.

fathom pendant
#

What level was i stooping to? Most I did was call it as I see it, them being a dumb shit.

#

They turned around and for whatever reason tried to push a race on me? Which mostly confused me

fathom pendant
#

But if it's a random "can I DM" without prior conversational context, it's a no

urban elk
#

that's fair enough. Could have also asked, but I get it

ocean night
#

The message was deleted by the user who posted it.

#

Also, what on earth happened, I'd read back.. but meetings starting NotLikeThis

mossy marsh
#

👍

novel matrix
#

👀

fathom pendant
#

Just another day

ocean night
#

Aha ok, lovely..

#

Sorry that happened :/ That's crap.

fathom pendant
#

it mostly confused me ¯_(ツ)_/¯

#

Like even if i was, why would it matter?

ocean night
#

Well yeah wasn't focusing on the race part, that's just.. what

#

More the webcam thing, but yeah. Inappropriate all the way. Thanks for pinging

fathom pendant
#

Yeah ❤️

fathom pendant
#

Sql comments require a space after iirc

cyan lark
#

Wait sorry now I haven’t used two dashes

fathom pendant
#

I don't think it can be directly attached to the value

cyan lark
fathom pendant
#

Instead of 6- 6 -

urban elk
#

check that your input is not being transformed. When I use your copy-paste it's clear that the two dashes became a... long dash, however that's called. I thought it was discord but I get the same error you're getting if I copy paste, and it works with double dashes as expected

crisp shadow
#

hi i need help with sumk machine (chemistry)

storm elk
urban elk
#

nothing wrong with either of those queries, but I'd re-read the question :)

cyan lark
fathom pendant
#

Deleting bc spoilers iirc sql is t1

cyan lark
fathom pendant
#

Ah yeah, mb

#

I may have been thinking sqlmap

cyan lark
dry falcon
#

why it now working in CLI?

pine dune
fathom pendant
#

Context specific my guy lol

#

So much shit happens in a day

cyan lark
#

Hey. I'm in the SQL Injection Fundamentals module at the Skills Assessment module.

Well I achieved sql injection in every kind of way, I found that I am on user root which is a superuser, I need to get a shell and locate a flag in the root directory.

However, when trying to write files in order to get reverse shell, I get an error that I have no permissions to write
" Can't create/write to file '/var/www/html/proof.txt' (Errcode: 13 "Permission denied")"

fathom pendant
#

Maybe write to the directory you're in

cyan lark
#

oh

cyan lark
urban elk
#

if by "I am on user root which is a superuser" you mean you are root@localhost on the db, note that those are not necessarily the same thing. That might be what you found

#

the SQLMap module notes this at some point, you'll see it soon

cyan lark
pine dune
# fathom pendant Context specific my guy lol

it was just about going through your journey basically and how you got to where you are. What are the best steps for me and how can I improve/replicate? basically a back and fourth on that 😅

fathom pendant
pine dune
ember copper
#

I wanted just to let it registered more or less how is the session that im stuck, is on the CWEE path, Header Attack,

The lab says I can only access admin "localy" and i need to spoof the Host header, the session list 10 improbable values to be on a blacklist that are also interpreted as 127.0.0.1, like 127.1 or ::1. Even using all the payloads I cant still solve the challange.

Please person of the future who sees this, help me lol (free to dm)

[EDIT POS SOLVING]: Try to think different things than the list provided, the session is really misleading, is much simpler then the ideias os the session

ember copper
storm elk
#

section?

ember copper
storm elk
#

dm me

ember copper
#

SOLVED! thanks to this really nice person

storm elk
#

I'll send a 🍐 to this nice person

#

eats pear

formal turret
#

Who do you contact regarding inconsistencies with the modules?

I'm having a few issues after following the module and i'm always coming to here and everyone seems to have the same problems

storm elk
ember copper
formal turret
# ember copper just by curiosity, what kind of inconsistencies?

Currently working through the 'Pivoting, Tunneling, and Port Forwarding' module, followed everything and some things didn't show up on a scan compared to the screenshots provided.

Previously I was stuck on a bitlocker task which i was unsure on mounting through linux, nothing was in the module. Once complete the next module then told you how to do it.

There's an entire page on SQL and the lab at the end involves an entire different command to what was shown

#

I understand that it's a learning curve, but when the course material doesn't help it kind of defeats the point.

hushed rivet
#

it also requires out of the box thinking

#

and own research

autumn pilot
#

If you are scanning a specific host (subnet) through a socks proxy within the workstation, try adding sudo before the proxychains command

formal turret
formal turret
#

without just doing proxychains xfreerdp

real burrow
#

Hello, I have a question on Login-BruteForcing - Web, Services, when I am trying to nmap the target, there is no FTP service, but I need to find the password of ftpuser - What was the password for the ftpuser??

dark hedge
dark hedge
#

some things will not work as shown and it is a real part of pentesting. you have to do some externel research in order to get what you want

#

no. please leave the server if you are here for less than ethical purposes

empty trout
#

hey i am stuck or dont bcz i dont even have access just bruteforcing ftp and ssh on skillassessment of password attacks Examine the first target and submit the root password as the answer. can i get a hint bcz its been 3h

gray yacht
# real burrow

You are given a specific port with your target IP address that you are supposed to use. Services can be hosted on ports that are not the default port for that service.

real burrow
gray yacht
honest crane
#

I'm doing the Pivoting module, first ever lab, and proxychains is not working.
ssh -D 9050 ubuntu@10.129.61.160

socks4 127.0.0.1 9050```
```ubuntu@WEB01:~$ ping 172.16.5.19
PING 172.16.5.19 (172.16.5.19) 56(84) bytes of data.
64 bytes from 172.16.5.19: icmp_seq=1 ttl=128 time=0.720 ms```
```proxychains nmap -Pn -sT -p 3389 172.16.5.19
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-27 07:50 CST
Nmap scan report for 172.16.5.19
Host is up.

PORT     STATE    SERVICE
3389/tcp filtered ms-wbt-server```
fathom pendant
#

Looks fine to me?

honest crane
#

Well I couldn't reach the port from my Pwnbox. I tried the nmap scan with sudo, and it shows open:```➜ ~ sudo proxychains nmap -Pn -sT -p 3389 172.16.5.19
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-27 08:01 CST
[proxychains] Strict chain ... 127.0.0.1:9050 ... 172.16.5.19:3389 ... OK
Nmap scan report for 172.16.5.19
Host is up (0.010s latency).

PORT STATE SERVICE
3389/tcp open ms-wbt-server```

formal turret
real burrow
gray yacht
real burrow
#

ok

gray yacht
queen magnet
#

Yo

paper sage
#

@everyone hello I am stuck in JavaScript Deobfucation module in Http request part . I got an answer but that is incorrect. I also verified the answer walkthrough.

sonic plume
#

Hi Could I dm someone for a sanity check for Api Attacks, Skill Assessment?

potent sandal
#

Attacking Common Services - Easy
hello folks whats up ... can somebody tell me if they have also this issue sometimes with some machineswhy i can not scan the ports ?nmap -sC -sV 10.129.11.127
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-27 09:42 EST
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.47 seconds

┌──(kali㉿kali)-[~/Vpn]
└─$ nmap -sT 10.129.11.127
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-27 09:43 EST
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.16 seconds

┌──(kali㉿kali)-[~/Vpn]
└─$ nmap -sT 10.129.11.127 -Pn
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-27 09:43 EST
Stats: 0:02:29 elapsed; 0 hosts completed (1 up), 1 undergoing Connect Scan
Connect Scan Timing: About 67.50% done; ETC: 09:47 (0:01:06 remaining)
Nmap scan report for 10.129.11.127
Host is up.
All 1000 scanned ports on 10.129.11.127 are in ignored states.
Not shown: 1000 filtered tcp ports (no-response)

Nmap done: 1 IP address (1 host up) scanned in 215.03 seconds

fathom pendant
#

Gonna sound dumb but are you connected to the vpn or have multiple connections open?

potent sandal
#

i have my own vpn which iam connected always to the internet and then from the VM the vpn from htb

#

i have this issue more often

fathom pendant
#

well considering your setup not sure how to help with that ¯_(ツ)_/¯

real burrow
# gray yacht What port did it give your target IP?

there are many 5 numbers ports - like 54854/tcp open http Apache httpd 2.4.41 ((Ubuntu))
55047/tcp open http Apache httpd 2.4.41 ((Ubuntu))
55208/tcp open http nginx 1.19.2
55249/tcp open http nginx 1.19.2
55424/tcp open http Apache httpd 2.4.41 ((Ubuntu))

zenith hill
#

Hello; I got such an error like NameError: name 'smb_share_name' is not defined while I was running crackmapexec ldap 10.129.191.62 -u grace -p Inlanefreight01! --asreproast asreproast.out ; Do you know what could be the reason?

Fixed!: I run nxc ldap 10.129.191.62 -u grace -p Inlanefreight01! --asreproast output.txt and it worked successfully

fathom pendant
gray yacht
#

The target port is the only port you need to target.

real burrow
gray yacht
#

Earlier when I mentioned banner grab, you can figure out the service with netcat or telnet

#

marcielee, if that is too revealing, go ahead and remove it.