#modules

1 messages · Page 382 of 1

fathom pendant
#

I'm going back to my game

gray yacht
#

Google banner grabbing, but like I said follow the section and just include the assigned target port when working the external part of it.

real burrow
gray yacht
real burrow
fathom pendant
#

I find it disappointing you can bypass the whole point of the module section

#

You're meant to get sshuser, ssh in, then use Medusa internally

spark fox
#

hello :). i am currently doing the sql injections fundamentals module and cant authenticate to the mysql server. i am getting the following error:

#

ERROR 2002 (HY000): Can't connect to server on '94.237.49.130' (115)

#

any help?

fathom pendant
rustic sage
#

guys but I get an error when I try to use my token to log in,how do I solve it?

spark fox
rustic sage
#

ok

spark fox
#

mysql -u root -h ip(redacted) -p 57726 -ppassword

fathom pendant
#

-p [port] then -ppassword

#

Try with just -p port and see if it prompts a password input

spark fox
#

it did

#

same error when i type in the password

fathom pendant
#

Ah mysql is -P port

#

Quick Google of the man pages

spark fox
#

it worked(it asked for ssl but chatgpt gave me an answer to bypass that error)

#

thanks for the help @fathom pendant 😄

vapid perch
#

does anyone know how i can change the keyboard layout of remote windows machines for academy?

fathom pendant
#

Locale

vapid perch
#

thanks

real burrow
#

for skill assessment 1 Brute Forcing - is the hydra command really run that slow?

surreal hedge
#

Hi guys

surreal hedge
real burrow
#

I use suggested one

honest spoke
#

ACL Abuse Tactics:

Hey hey! So I've gotten adunn hash, but cant crack it (hashcat -m 13100 hash.txt /home/rockyou.txt). I've run the hash through hash-identifier and I think there's breaks in it, just need a quick refresher if I need to run (echo "<base64 blob>" | tr -d \n) or am I just being dumb and grabbing too much/not enough of the hash?

surreal hedge
#

Can you explain what assessment is that . I will tell my best

surreal hedge
#

hashcat -m 13100 hash.txt wordlist.txt -r rules/best64.rule
try this

real burrow
honest spoke
surreal hedge
honest spoke
surreal hedge
honest spoke
teal sparrow
gray yacht
honest spoke
hard matrix
#

I'm a bit lost on the Linux Privilege escalation - Service based priv esc - Logrotate section.
There's supposed to be a logrotate.conf file but it doesn't look like it's present on the system. Am i getting tripped up by one small detail?

#

it exists in /snap/lxd/ dir but i don't think thats helpful for this exercise

gray yacht
hard matrix
#

Right, if you're hinting at the b******** folder in /home and the .log files found within, i've gotten that far.
I am successfully triggering the exploit (Theoretically?) but no shell is being sent back to my listener.
Reason why i'm fixated on finding the .conf file is because the logrotten page and module exercise specifically asks you to determine if compress or create option is set in that file. https://github.com/whotwagner/logrotten

GitHub

Contribute to whotwagner/logrotten development by creating an account on GitHub.

gray yacht
rugged bolt
#

I'm having an issue with VIM in pwnbox, trying to use ESC or ctrl + [ to leave insert mode but I keep getting these keyboard interrupts on top left instead. I'm used to nano so I'm sure its probably my fault. wonder if anyone can point out what I might be doing wrong.

fathom pendant
#

I dropped a feedback on it, hopefully fixed soon.tm

rugged bolt
#

I accidentally hit the shortcut to Lock Screen when trying to figure out VIM. Any chance is there a default password for pwnbox? I tried the two htb IDs on screen

fathom pendant
#

But the password is random genned

rugged bolt
# fathom pendant Run it with sudo, they messed up the user configs

Really appreciate your input! Although, think I may be still stuck on this one until that is fixed/ I think of another method. This is for Getting started/Nibbles - privilege escalation. I can only sudo without password on the file I need to edit for a root reverse shell.

hard matrix
#

Can try echo 'revshell_here' >> monitor.sh

#

i don't remember exactly what this is, but depending on what monitor.sh actually does you could also echo 'chmod 4777 $(which bash)' >> monitor.sh and bash -p

#

just shots in the dark that might help

fathom pendant
fathom pendant
rugged bolt
cinder warren
#

Why is it not working?

rugged bolt
cinder warren
#

Linux Fundamentals

fathom pendant
#

Since you own it

cinder warren
safe star
lusty thicket
safe star
#

oh yeah

cinder warren
fathom pendant
cinder warren
#

doesnt' work in my own box either

safe star
#

i think only subs

fathom pendant
#

:)

#

no active sub rn and can still use pwnbox a la carte

cloud urchin
#

something like this applies to academy too

cinder warren
#

I just started the pwnbox

cloud urchin
#

imo you'll have a better experience with your own VM

rugged bolt
cinder warren
cloud urchin
#

i was able to visit it now without any problems

cinder warren
#

but I am not able to view in in my own machine

cloud urchin
#

if you haven't spent money then pwnbox won't reach out to the Internet so it won't be able to reach it

rugged bolt
cinder warren
rugged bolt
fathom pendant
calm tapir
#

Can I get some assistance on File Upload Attacks Skill Assessment:
I've ||determined the naming scheme of files and the directory where uploaded files are stored. I found an extension that bypasses the filters. But when I enter the command shell it no longer accepts the file.||

fathom pendant
#

Not on the target

hard matrix
rugged bolt
rugged bolt
hard matrix
cinder warren
#

I think something might be wrong with my browser

#

session is timing out on all the websites I type in

calm tapir
rugged bolt
rustic sage
#

Could self improvement videos allow me to unlock general chat?

cinder warren
#

so I think it's an issue with the browser

rugged bolt
hard matrix
#

theoretically you can doublecheck what mime type with file example.jpg

#

altho im not sure if file will give the exact same mime as php mime_content_type()

rugged bolt
viral lotus
cinder warren
#

I am new to this stuff so I am taking copious notes, LOL

viral lotus
#

From my help desk days turning on and off fixes a lot of problems 😂

cinder warren
#

It

#

It's amazing that it works but you're right!!! LOL

#

It's a good thing I am a little older and wiser otherwise I would be buying a computer every week, lol

simple zephyr
#

Anyone get this while working a lab? Specifically the Kerberos Attacks - Silver Ticket from Linux

When I have seen this previously it was a timing issue on the DC. My Kali box is set to the correct time, so I am guessing the DC might be off. I tried to RDP into the machine, but HTB Student cant RDP.

I am guessing I need to submit a support ticket unless anyone else knows an easy fix.

[-] SMB SessionError: code: 0xc0000016 - STATUS_MORE_PROCESSING_REQUIRED - {Still Busy} The specified I/O request packet (IRP) cannot be disposed of because the I/O operation is not complete.
oblique flax
#

Will there be an Intro to Terraform module ?

tiny frigate
#

Not sure if this is the right place, but I recently struggle a lot with various latency and lag errors in academy.
Sometimes starting an instance of pwnbox gives me "no instance available" errors, spawning the target systems takes minutes sometimes...is that just me?

#

When I try navigating, like scrolling up in the terminal, it takes several seconds to do anything...

rugged bolt
#

I had “no instances available” also earlier today. I restarted the web page, chose a different server location and I was good. I haven’t had lag issues you’re mentioning, but I just got VIP so maybe those machines have less latency. Spawning a target does take 1-3 minutes for me usually

tiny frigate
#

Switching the location seems to help here too. I feel like the targets used to be faster...
I got VIP too (I think, lol? Yeah, unlimited spawns, that's the one, right?)

rugged bolt
#

According to your role you actually have VIP+! Lol

tiny frigate
#

Haha, might as well, I think I treated myself last year with an annual, that's why I don't recall xD

Had these slow machines the last few days now, might just keep an eye on it

rugged bolt
#

Sounds good I’ll pay attention to mine over the next couple days and report back if I’m also having issues 🤙🏻

limber berry
#

I'd like to ask if the "Starting Point" tiers all count as 1 "achievement" that counts once towards the rank points

rugged bolt
#

None of the retired boxes counts toward rank

limber berry
#

ah got it

#

Although Im sure I finished an active one in tier 0 and didn't score a point

#

oh well will check out others in order

rugged bolt
#

There’s a webpage on htb that breaks down how to earn points it might be /introduction sorry don’t know it off the top of my head

limber berry
#

no you're good I appreciate it I should've browsed for it too

rugged bolt
karmic raptor
#

Hello everyone, I'm in the Skills Assessment of the pivoting module... I've sent the ligolo agent to the target machine and I've run all the right commands... but when I run xfreerdp I'm getting this error message, can anyone help me?

xfreerdp /v:172.16.5.35 /u:mlefay /p:'Plain Human work!' /cert:ignore   
[22:32:55:667] [69739:69740] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[22:32:55:672] [69739:69739] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]
lusty thicket
karmic raptor
#

Yes, it's okay

#

I used nmap and it worked normally for port scanning

lusty thicket
#

if you didn't forward port 3389 from target network through ligolo, then xfreerdp can't reach it

karmic raptor
#

ligolo needs to specify the forwarding port?

simple zephyr
#

Ligolo should still work, it’s only local host port ports you have to create a different route for targeting 240.0.0.1

#

Use nxc to see what you get back

lusty thicket
indigo mirage
#

anyone could help me with this question : What is the name of the utility that can be used to view logs made by a Windows system? (Format: 2 words, 1 space, not case sensitive)
is on the module Windows Fundamentals

gray yacht
rough comet
#

hello folks

hard matrix
calm tapir
#

Looking for help on the Command Injection Skill Assessment. I found the injection point and tested each operator specified in the module. Any hints

rough comet
#

I am working on the Windows Priv Esc module - weak permissions. I managed to add myself to the administrator group, but || takeown || fails

#

I suspect this is due UAC. Can I DM someone to get a hint here?

hard matrix
#

redirections pipes that kind of thing

gaunt forge
#

is anyone else unable to connect to any htb box right now? i cant even ping anything

#

just switched vpn servers too

calm tapir
hard matrix
hard matrix
#

throw ${IFS} and ignored characters into the mix

calm tapir
hard matrix
#

base64 -d <<< [base64enc string]

finite abyss
#

This part is taken from the Assessment Solution:
https://academy.hackthebox.com/module/239/section/2599

||With the id 651599407998f5c5ff061491 of the card attained, students need to exploit the unexpected input vulnerability and perform two purchases, one for 1000 cubes costing 100 and another for a subscription with a non-existent name also costing 100 (therefore, the total becomes 0)||

My query is:
How come 100 + 0 becomes 0
First one is 100$
second one due to type juggling becomes 0
So total should be 100$ right
In that case the user cannot purchase it as card balance is 5$. Still the lab is working. It require more explanation.

gaunt forge
hard matrix
rough comet
#

there must be away... I do not think the module show explain the same and omit that part ....

hard matrix
rough comet
#

I do not know how

hard matrix
#

if you suspect the issue is due to uac

rough comet
#

DM?

rough comet
hard matrix
#

in the passthehash windows module earlier this reg key is mentioned
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy

#

id start there and check if that is 0 or 1

#

im still going through linux privesc so i havent actually done your module yet

#

wouldnt hurt to google around or look at payloadallthethings for ways to enumerate UAC

rough comet
#

may I assume, that will disable the "enter your password" thing?

hard matrix
#

the exact description i have for the regkey is:
When is set to 0; built-in admin account is the only local account allowed to perform remote admin tasks. 1allows other local admins too.

#

so maybe im sending you down the wrong path

#

might not be related at all

rough comet
stark lark
#

Is there a LaZagne binary instead of python3 version?

rough comet
#

Yes

#

Download from HTB box

stark lark
rough comet
#

talking about Windows version

rough comet
stark lark
#

Yes I did

rough comet
#

move it ALL. Then run it from it

rough comet
gloomy stump
#

No

#

That's illegal

naive cedar
#

actually tools like SharpChrome, Lazagne, SessionGopher, or most other tools are captured by windows. i wonder if the real environment will rewrite such tools on its own?

errant sparrow
real delta
viral patrol
dark hedge
viral patrol
# dark hedge read the question very carefully

I've reread it multiple times. I've used the visualization that I made and the one that is made for you. Both of them are coming up with || 2023-02-27 || when I add the @timestamp, event.created, etc. to it. I don't even see a date that would match the 20XX-0X-0X format because the date for what I see is all double digits.

pine vault
#

Hello, I need a little nudge for the AD Enumeration & Attacks - Skills Assessment Part I of the Active Directory Enumeration & Attacks. I successfully compromised the domain but there still remains a question where I should find cleartext user password. I use his hash to comprise the domain but I'm not able to figure out cleartext password.
Can some one nudge me please?

silk flicker
pine vault
analog dock
#

If you did the exercises in order

pine vault
analog dock
#

Question number?

pine vault
analog dock
#

Did you answer question 5?

pine vault
#

yep

#

Tyied it with mimikatz without success (i got the ntlm hash thoiught)

analog dock
#

But I see a reference to DefaultPassword

pine vault
#

Thx didn't tried that

analog dock
tired atlas
#

So I'm on information gathering skills assessment and I'm currently on question 2

  • 1 What is the API key in the hidden admin directory that you have discovered on the target system?

So I have found the subdomain of the vhost using gobuster, found the robots.txt file that has the hidden admin directory, however when i go to curl it, the results are quite peculiar

It says it has moved permanetly.....

#

I've went through every single writeup I found online, and they all found the answer here 😭

#

Perhaps HTB has changed this exercise and I need to enumerate deeper

#

Which I'm doing, I'm running another Gobuster, but this time with this subdomain, however the subdomains of subdomains I have found, have no directories that I can see inside

safe star
#

Try adding a slash to the end

versed eagle
#

I believe the lab for Blind SQL injection > Oracle Design is broken. It appears that the target from the previous lab is spawning. As a result, the script does not work and the payload has to be injected somewhere else. I tried injecting it at the vulnerable location, but the fifth character from the database is incorrect for that question

#

Anyone that can confirm this?

storm elk
versed eagle
#

Ahh

versed eagle
empty trout
#

yesterday i was asking this que

#

and i am still there

waxen totem
#

which module?

empty trout
#

password attacks in skill assessment easy lab

#

did hydra -L username.list -P passl.list ip ftp -t 64

waxen totem
#

haven't done that module, sorry

tired atlas
surreal hedge
empty trout
surreal hedge
#

What is the name of lab you mentioned

empty trout
surreal hedge
empty trout
#

no

wheat lark
#

Hi @viral lotus were you able to get this working, I am stuck at the same last step where in I do not get teh shell instead msfconsole shows "command shell session closed"

empty trout
#

yeah they gave username password list and custom rule to mutate the password and did that

surreal hedge
empty trout
#

ssh ftp

surreal hedge
#

Ok

#

What is the question

#

Is the lab ask you to bruteforce

grizzled schooner
#

For shells and payloads skills assessment - host 2 (blog) can I get a hint / nudge? I found the ||50064.rb script || but I don't know if I'm supposed to edit that script to use or something else. I couldn't find any reference to that in metasploit even though that's what it is using. Little confused and lost and nudges / help would be greatly appreciated! Please @ with response!

gray yacht
patent totem
#

Hello
I'm at skill assessment of command injection and I can't find the vulnerable request I already spent hours on this the only thing that I found is a post request but I doubt it's the intended request

#

can anyone help?

wheat lark
gray yacht
dawn tiger
#

hi did anyone faced the connection closed during request sequence when using burpsuite for the labs?

tranquil wren
#

I am on the virtual hosts module of the DNS & Subdomains section for information gathering. Im not really stuck, but if someone could make the question more clear it would be helpful.

#

i understand that we are using gobuster vhost -u to specify the target url

waxen totem
#

fuzz for vhosts... find web...

tranquil wren
#

the question is tripping me up though when they are asking for vhosts ON the target system

#

for example am i running

waxen totem
#

add inlanefreight.htb to your /etc/hosts file with the target ip, here's the sytnax:
<target ip> <hostname>

tranquil wren
#

so -u http://<target-ip> inlanefreight.htb:80

waxen totem
#

and use the port provided in the target at the end of the url as well

waxen totem
tranquil wren
#

ohhh

#

so i have to edit the hosts file to reflect dns

#

did i miss something in that whole module?

#

and i can make that edit with the pwnbox

waxen totem
#

you can do that edit with the pwnbox you just need to use sudo

#

not sure if you missed anything in that module since I haven't done it 😅

tranquil wren
#

well i wasn'ts ure becuase it just said to brute force the vhosts on the target, so i wasn't sure where to put the target sstem IP

dark hedge
pine vault
gray yacht
# pine vault ?

That's a handy tool that can likely help you nxc = netexec. You could also do something else. If you're unable to sort this out, you can DM.

tranquil wren
#

or '94.237.59.180 inlanefreight.htb:54920' ?

#

i got it, thank you

pseudo kiln
#

hey guys one question regarding extracting creds from memory on Linux with mimipenguin

./mimipenguin-static 
[+] Searching: [SYSTEM - GNOME] (gnome-keyring-daemon)

that's all the output I get on all machines I have done so far, does anyone know the condition for it to actually work and extract the passwords like mimikatz does ? they don't go into much depth in the module about it, other than presenting it

jade lintel
#

Hi can someone help me with connecting to vpn on Kali Linux for a htb machine

#

I am trying to connect to it and it won’t work, every time I run the code with domain administrator.htb it says domain not found

surreal urchin
#

Hello plz someone help me stuck at : Section : Phishing Module : Cross site scripting

#

CBBH

warped warren
#

Hi all, wondering if anyone wanted to study together im from the UK 26 and just abit of a lazy bastard so hoping having someone to study with will motivate me more and be fun to bounce ideas off each other

naive cedar
#

happy happy

formal bough
novel parrot
#

Hi am trying to transfer a file via smb using http, for thr module file transfers but i am unable to do so using wsgidav. Here is the command I used for reference:

sudo -E /home/zack/.local/bin/wsgidav --host=10.10.15.232 --port=80 --root=/tmp --auth=anonymous

Here is the powershell error from my windows target:
PS C:\Users\htb-student> dir \10.10.15.232\tmp
dir : Cannot find path '\10.10.15.232\tmp' because it does not exist.
At line:1 char:1

  • dir \10.10.15.232\tmp
  •   + CategoryInfo          : ObjectNotFound: (\\10.10.15.232\:String) [Get-ChildItem], ItemNotFoundException
      + FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetChildItemCommand
unreal aspen
#

Sziasztok

#

@unreal aspenhi guys

novel parrot
# hard matrix `\\`
PS C:\Users\htb-student> dir \\10.10.15.232\tmp
dir : Cannot find path '\\10.10.15.232\tmp' because it does not exist.
At line:1 char:1
+ dir \\10.10.15.232\tmp
+ ~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : ObjectNotFound: (\\10.10.15.232\tmp:String) [Get-ChildItem], ItemNotFoundException
    + FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetChildItemCommand

Still no luck

trail flicker
#

need help with this question Debug the attached binary to find the flag being pushed to the stack - #solved it :3catHiss

novel parrot
# lusty thicket test through win exporer

It works on browser with just the url only i get an error if i go to tmp. Doing the same command on powershell/cmd without tmp also results in an error. Navigationg to the share on file explorer also gives me an error

lusty thicket
#

map the drive

hard matrix
lusty thicket
#

it's not a smb share

novel parrot
lusty thicket
#

webdav uses http, so to access it from windows, you'll need to map a network drive using the http url

hard matrix
#

Oh I see,
2 things from my notes:
Try using special keword DavWWWRoot
Try hosting with --host 0.0.0.0

naive cedar
#

happy happy lunar new year

safe star
#

Probably got it already tho

viral patrol
# dark hedge you can answer the question without adding any columns

Come at it with fresh eyes made me get the answer, but I have no clue why that is the answer. The question says 'when the events took place' but without manually changing the date to something other then the default, I can't tell when they happened. All I know is that they happened sometime within the last nearly two years. What am I missing?

tranquil wren
jade lintel
honest crane
clever topaz
#

anyone know other method to dump dpapi remotely? nxc wont work for me

dark hedge
lone dagger
#

I got stuck at Web Request>CRUD API, I upgrade the city, after I delete it and search, but I just get the country name (US) kek

viral patrol
# dark hedge don't post answers to questions. i dont have my notes atm so copy and paste the ...

Removed it, my apologies.

Security Monitoring & SIEM Fundamentals - SIEM Visualization Example 4

Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Extend the visualization we created or the "User added or removed from a local group" visualization, if it is available, and enter the common date on which all returned events took place as your answer. Answer format: 20XX-0X-0X

lone dagger
#

Anyone can help me with Web Requests>CRUD API?

dark hedge
viral patrol
dark hedge
#

it's not asking you for when the events occurred, it's asking for the date for which all the events are shown to you on the visualization. which is the date you set yourself

#

very weirdly worded but it's simple

viral patrol
#

Ahh. That explains it, and looking at the question with that in mind I can see what they mean. Thank you for taking time to explain it.

honest crane
#

RDP and SOCKS Tunneling with SocksOverRDP

I'm trying to use ligolo-ng for double pivoting. First pivot goes fine, and I can reach the victor's machine. Then, I add a listener on the ligolo proxy on Pwnbox, try to execute the agent on the second pivot box, but I'm getting this error:

time="2025-01-28T12:13:20-08:00" level=info msg="Connection established" addr="172.16.5.150:11601"
time="2025-01-28T12:13:20-08:00" level=error msg="Connection error: read tcp 172.16.5.19:55694->172.16.5.150:11601: wsarecv: An existing connection was forcibly closed by the remote host."
time="2025-01-28T12:13:20-08:00" level=fatal msg="read tcp 172.16.5.19:55694->172.16.5.150:11601: wsarecv: An existing connection was forcibly closed by the remote host."```
On the first pivot machine (172.16.5.150), I get the following message:
```time="2025-01-28T11:31:05-08:00" level=info msg="Connection established" addr="10.10.14.230:443"
time="2025-01-28T12:00:48-08:00" level=error msg="accept tcp [::]:11601: use of closed network connection"
time="2025-01-28T12:11:47-08:00" level=error msg="accept tcp 172.16.5.150:11601: use of closed network connection"
time="2025-01-28T12:13:04-08:00" level=error msg="accept tcp 172.16.5.150:11601: use of closed network connection"```
Finally, on the ligolo proxy (Pwnbox), I get the following error:
```ERRO[2551] dial tcp 10.129.30.50:11601: connect: connection refused```
It seems to me that the ligolo proxy doesn't actually listen for incoming connections. Because, if I do `nc -nvlp 11601` on the Pwnbox, I do get respone back on the Netcat listener.

**Edit**: Fixed by explicitly specifying LHOST and RHOST when adding a listener:
```listener_add --addr 172.16.5.150:11601 --to 10.10.14.230:11601 --tcp```
viral patrol
rustic sage
#

si

potent sandal
#

HELLO GUYS ... Attacking Common Services - Easy. This machine drives me crazy always when i am connecting he show me this error and dont she me the files from the ftp server.Connected to 10.129.203.7.
220 Core FTP Server Version 2.0, build 725, 64-bit Unregistered
Name (10.129.203.7:kali): fiona
331 password required for fiona
Password:
230-Logged on
230
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> dir
229 Entering Extended Passive Mode (|||24812|)
dir
ls
?
^C
receive aborted. Waiting for remote to finish abort.
ftp> bye
221-
221 Goodbye

#

somebody can help

fathom pendant
#

😉

potent sandal
#

what u mean ?

fathom pendant
#

man ls

potent sandal
#

he get blocked and do nothing anymore after he shows me the passive mode

fathom pendant
#

Maybe something ||hidden||

potent sandal
#

yes of course 😄

fathom pendant
#

Also could be a connection related issue

#

I seem to recall you saying you have some weird setup vpn then the academy vpn

#

I'm guessing due to region issues

potent sandal
#

he shows me since days and sometimes also i can not even scan the ports

#

i think i need to contact the support

#

i lose already so much time is really annoying

fathom pendant
#

That would be best

#

Considering your set up isn't normal/average set up

potent sandal
#

i use a vpn from my laptop and the the VM ORACLE and the vpn from the HTB thats it

#

i think thats pretty normal

fathom pendant
#

It's not

#

Lol

potent sandal
#

no?

fathom pendant
#

Most people don't use a vpn at all on their main host os

#

And just use the academy vpn

potent sandal
#

i like to be anonymously (BATMAAANNN)

fathom pendant
#

Vpns don't really make you anonymous

#

They just mask your traffic, but if you're using an authenticated service, the auth service knows who you are

potent sandal
#

why u said that. When u dont buy it from your credit card and use crypte which u also buy anonymoulsy then i think it do

fathom pendant
#

And that info has to get back to you somehow

potent sandal
#

yes true

fathom pendant
#

Crypto can still be tracked, in a way, they can know the wallet - maybe not the owner

#

No sense in being overly paranoid tbqh

#

Typical use cases for vpns is to get around region locks for websites and content

potent sandal
#

yes the wallet but of course is not attached to my name.... is not to be paranoid but i like privacy

fathom pendant
#

True Anonimity is really a myth

potent sandal
#

and they dont need so see which demon slay episode i am on

#

😄

potent sandal
fathom pendant
#

To be truly anonymous go be a farmer with no devices connected to the internet

#

There will always be someone somewhere that can trace something back to you

#

¯_(ツ)_/¯

potent sandal
#

i am a really paranoid person so ... i like my things not being controlled i also dont use social media

fathom pendant
#

That's just the truth of it

potent sandal
#

a little bit control u have ... but u need to know how to move

fathom pendant
#

I doubt you do

potent sandal
#

of course the internet at home is everything but not anonymously

compact patrolBOT
fathom pendant
#

Reach out to them though, maybe they can help you figure things out

#

But it just sounds like using a vpn in this case is shooting yourself in the foot

potent sandal
#

i will ask and see whtas the issue

frigid bay
#

Hi there. I am working onWeb Server Pivoting with Rpivot. I managed to get the flag using curl. But it doesn't work when I try to use firefox. I get a The connection has timed out error. What am I doing wrong?

topaz lantern
#

Do I leave the terminal I used to connect to openvpn open?

#

I'm confused how this works cause I've always used the Pwnbox

fathom pendant
topaz lantern
#

So open a separate one for anything else then? And that will allow me to move around within the HTB Network?

fathom pendant
#

Yes

topaz lantern
#

Okay thank you! 🙂

frigid bay
fathom pendant
#

Ah

#

I don't recall having many issues tbh

#

I just did proxychains firefox http://ip

violet prawn
#

I'm doing a linux fundamentals, and the question:

What is the Type of the service of the "dconf.service"?

came up.

So what I did was I ran systemctl | grep dconf.service

nothing came up.

So then i ran systemctl status dconf.service

and got the output:

Unit dconf.service could not be found

What am i doing wrong?

fathom pendant
violet prawn
#

ya i'm ssh'd in

#

I can see all the services, but that one isn't listed.

compact patrolBOT
dire prairie
#

doing the** Print Spooler & NTLM Relaying** in Windows Attacks & Defense and I get this when running the suggested command of 'mpacket-ntlmrelayx -t dcsync://172.16.18.4 -smb2support'

Impacket v0.13.0.dev0+20240916.171021.65b774d - Copyright Fortra, LLC and its affiliated companies

[] Protocol Client HTTPS loaded..
[
] Protocol Client HTTP loaded..
[] Protocol Client LDAP loaded..
[
] Protocol Client LDAPS loaded..
[] Protocol Client SMB loaded..
[
] Protocol Client MSSQL loaded..
[] Protocol Client SMTP loaded..
[
] Protocol Client DCSYNC loaded..
[] Protocol Client IMAPS loaded..
[
] Protocol Client IMAP loaded..
[] Protocol Client RPC loaded..
[
] Running in relay mode to single host
[] Setting up SMB Server on port 445
[
] Setting up HTTP Server on port 80
Exception in thread Thread-2:
Traceback (most recent call last):
File "/usr/lib/python3.11/threading.py", line 1038, in _bootstrap_inner
self.run()
File "/usr/local/lib/python3.11/dist-packages/impacket/examples/ntlmrelayx/servers/httprelayserver.py", line 572, in run
self.server = self.HTTPServer((self.config.interfaceIp, self.config.listeningPort), self.HTTPHandler, self.config)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.11/dist-packages/impacket/examples/ntlmrelayx/servers/httprelayserver.py", line 47, in init
socketserver.TCPServer.init(self,server_address, RequestHandlerClass)
File "/usr/lib/python3.11/socketserver.py", line 456, in init
self.server_bind()
File "/usr/lib/python3.11/socketserver.py", line 472, in server_bind
self.socket.bind(self.server_address)
OSError: [Errno 98] Address already in use

Anyone had this before?

fathom pendant
#

Address in use means that the port it's trying to bind to isn't available to bind to

#

You'd have to specify a different port

#

http server on 80

#

You're using pwnbox, pwnbox is running port 80 to serve you it in browser

honest crane
fathom pendant
#

Running ligolo with sudo helps

glossy cloak
#

hi Marci, remmember me lol?

#

@fathom pendant

glossy cloak
#

started linux tutorial as you politely asked me lol

glossy cloak
#

and my command prompt is wrong I guess... its not Robinjo@htb[/htb]$

#

this is ok, right?

fathom pendant
#

That's fine

glossy cloak
#

then I entered first command ssh htb-student@[IP address], where the IP address is target IP

#

and its asking me for the password

fathom pendant
#

Everything before the $ is just user@hostname[/filepath]

fathom pendant
#

The password is just above the question

#

You might benefit from the intro to academy module which teaches you how academy works

digital pendant
#

can I get some help with this? seems I slipped through cracks 😛

#

please*

#

cancel i was just being a noob with -L, wasnt needed 🙂

fathom pendant
#

Don't share screenshots of modules above t0

devout mirage
#

hey guys I am on the last question on skill assessment for fuzzing here is the problem though this doesn't work for some reason until now everything was so smooth but for some reason I can't make this work I found the flag from an online platform but I don't understand why it didn't work I have checked it multiple times and it looks totally fine to me can you help me maybe I am missing something

fathom pendant
devout mirage
#

oh sorry

fathom pendant
#

Considering you had to dig for the subdomain and file extension

devout mirage
#

yeah right

fathom pendant
#

My tips are: making sure you're fuzzing is filtering the right size

#

And making sure that you don't overthink

#

With parameter fuzzing you will always generally get a 200, so you need to filter via other means

devout mirage
#

I think my machine had a network problem in the middle of the assessment because I literally couldn't get any responses

fathom pendant
#

Then reset the machine

#

You'll need to update the ip in your hosts file

devout mirage
#

yeah I have done that

#

checked everything

fathom pendant
#

Also make sure you update your command with the right port

devout mirage
#

checked that as well I dunno I guess I'll go back to it again and see if I'm gonna be able to get the flag

#

maybe I had a temporary problem who knows

#

or I am missing something

fathom pendant
digital pendant
fathom pendant
digital pendant
#

cool, shall do so, ta

fathom pendant
#

Just did it myself and got it

rugged bolt
#

So I think the reason I might've been having issues navigating vim yesterday is because I'm using a 60% keyboard. I think some keyboard layouts are different by default.

fathom pendant
#

Ah yeah

fathom pendant
glossy cloak
#

somehow i dont have any files/directories in my home dir... trying ls command, no luck

devout mirage
#

soooo weird and stupid

fathom pendant
devout mirage
#

😄

fathom pendant
#

it loaded the page and displayed the flag

devout mirage
#

yeah in the middle of the assesment my pwnbox's time was up and I got a new machine I think I configured everything with no problems but who knows maybe I messed up something xD

fathom pendant
#

you probably did something slightly wrong

devout mirage
#

thanks for looking into it though

#

yeaah probably

fathom pendant
#

like typing application/x-www-urlform-encoded

devout mirage
glossy cloak
#

right?

kind wasp
#

(starting point - tier 0) "Fawn" -> task 7 does not accept my answer, i have controled it on official walkthrough but i can not solve it, anyone help please.

kind wasp
#

first i type in general chat they said type in modules now you said "ask in there" 😦

glossy cloak
#

you are asking about starting_point, its logical to ask in #starting_point 🙂

#

just trying to be helpful for a change, dont take my noob status here LOL

kind wasp
#

yes i know it is not problem, thanks, i just wanna solve the task 😄

oblique flume
#

can someone help me with starting nessus in the vulnerability assessment section ?

#

htb note says “Note: The VM provided at the Nessus Skills Assessment section has Nessus pre-installed and the targets running. You can go to that section and start the VM and use Nessus throughout the module, which can be accessed at https:// < IP >:8834. The Nessus credentials are: htb-student:HTB_@cademy_student!. You may also use these credentials to SSH into the target VM to configure Nessus.”

#

i tried to start it using sudo systemctl start nessusd.service but the service is not found

quasi wave
#

for the Attacking SQL DB section of Attacking Common Services, I'm authenticated into the DB server and I managed to list available users. Unfortunately, I am trying to use the command to switch to one of those two users and I don't have permission. I also don't see the user the first question wants me to authenticate as.

#

I can authenticate as the user I'm currently logged in as of course but not the other user

#

can someone give me a hint?

fathom pendant
#

pika_sip perhaps being a thief may help

quasi wave
#

ok

fathom pendant
#

it takes a few minutes to fully spin up as nessus is a bit beefy of a web service

quasi wave
#

I took a minute to scan with nmap. All SQL related ports mentioned in the section are open but only one of them works for logging into MSSQL

#

or they are not all open but two are filtered which suggests they are also possibly open. I tried them and get a banner but cannot log in

fathom pendant
native crow
#

Hi all , In Attack Common Services - Attacking SMB , What is the name of the shared folder with READ permissions? - The method taught does not work smbmap -H 10.129.70.227 - [] Detected 1 hosts serving SMB
[
] Established 1 SMB connections(s) and 0 authenticated session(s)
[*] Closed 1 connections

Looking at the forums people seem to have been able to solve this using the taight method. I have reset the machine 4 times. Does anyone know if im missing something?

native crow
fathom pendant
#

i think netexec has the --readonly flag? i could be wrong and it's -M readonly

earnest pasture
woeful lake
quasi wave
# fathom pendant maybe my previous hint about *STEALING* something wasn't clear

ok I stole the hash that was made clear. I'm trying to crack the hash and the password cracker is giving me issues. I think I have some syntax error. I tried using chatgpt to correct the file and my syntax. I'm 99% sure I'm on the right track and one little thing is off. I don't think I can explain my syntax problems in vague terms because its an issue that probably requires me to show specific syntax.

#

So I don't want to spoil it. Can someone DM me? This is just to fix an issue with hashcat.

#

I came close but even with ChatGPT I'm not entirely getting this to work.

fathom pendant
quasi wave
#

ChatGPT gives me a password result decrypted but it won't work on my machine? Here's the error:

┌─[us-academy-1]─[10.10.14.83]─[htb-ac-605555@htb-yqmvvms7mt]─[~]
└──╼ [★]$ hashcat -m 5600 -o cracked_pass.txt cracked.txt pws.list
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 3.1+debian  Linux, None+Asserts, RELOC, SPIR, LLVM 15.0.6, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
==================================================================================================================================================
* Device #1: pthread-haswell-AMD EPYC 7543 32-Core Processor, skipped

OpenCL API (OpenCL 2.1 LINUX) - Platform #2 [Intel(R) Corporation]
==================================================================
* Device #2: AMD EPYC 7543 32-Core Processor, 3919/7902 MB (987 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashfile 'cracked.txt' on line 1 (WIN-02...C1E5EC2FCC130655C06623227F44FD72): Separator unmatched
No hashes loaded.

Started: Tue Jan 28 18:02:31 2025
Stopped: Tue Jan 28 18:02:31 2025
#

I'm scared if I post further I will give a spoiler

fathom pendant
#

the hash itself starts at mssqlsvc

#

and it's a netntlmv2 hash

quasi wave
#

ok

fathom pendant
#

so right mode

quasi wave
#

ok

#

password cracked

fathom pendant
#

nice

quasi wave
#

ok now I have the password and its not letting me log into sql database as that user which is really weird so I'm trying to log into that user

#

the python script to log in as the cracked password for that user won't let me log in

#

what should I do?

opaque tree
#

What can I do so I can control a website?

quasi wave
#

I am looking through lesson I don't see anything that may work except the other script besides the .py one

quasi wave
opaque tree
#

Sarcastic response

quasi wave
#

ok

#

what I'm asking is why can't I log in now that I have username and password of the user?

opaque tree
#

What does it say?

quasi wave
#
┌─[us-academy-1]─[10.10.14.83]─[htb-ac-605555@htb-yqmvvms7mt]─[~]
└──╼ [★]$ mssqlclient.py -p 2433 mssqlsvc@10.129.203.12
Impacket v0.13.0.dev0+20240916.171021.65b774d - Copyright Fortra, LLC and its affiliated companies 

Password:

Then when I enter the cracked password I get no response.

#

or I do it on port 1433 instead

#

and same thing

opaque tree
#

Try the 1433 port

quasi wave
#

it does the same exact thing no matter what port I try it on

opaque tree
#

It js doesn’t say anything?

quasi wave
#

ya

opaque tree
#

Maybe the user has nothing

quasi wave
#

no sql prompt for me its really weird

opaque tree
#

😭😭

quasi wave
opaque tree
#

No it’s not rlly

quasi wave
#

ok

#

but I would at least get a prompt

#

like something that shows I am logged in

opaque tree
#

True

quasi wave
#

I'm not even gettingthat

opaque tree
#

Have u tried other username?

waxen totem
#

Looks like you need credentials 👀

quasi wave
#

yes, the default one it gives me to start that I had to log into the server as initially

mighty sierra
#

But I'm using the module provided me

waxen totem
quasi wave
#

I seriously don't get what my issue is

#

what do you recommend I do?

opaque tree
#

Try Redfin

#

Reddit

#

or ask ChatGPT why it does that

fathom pendant
quasi wave
#

ok I'm logged in as mssqlsvc. I am trying to enumerate contents of the database file. I selected the right database. I am googling how to list the contents of that database but not getting very good results.

fathom pendant
#

enumerating mssqldb sucks

quasi wave
#

ok

fathom pendant
#

so don't worry too much

#

you are given how to find a table name in the section

quasi wave
#

ok hold on

fathom pendant
#

😉 just gotta use some critical thinking to figure out which to switch out

#

(note you can do something similar for column_names)

quasi wave
#

ok got it

#

found the flag

fathom pendant
#

note how the result is returned; it's given as a byte string

quasi wave
#

I'm onto the next section, which I will do tomorrow

#

ya ok I will write this down

fathom pendant
#

always bear in mind how things are returned to you

quasi wave
#

ya I wrote it down

#

thank you

inland shuttle
#

I am doing the SQLMap essentials module, and I am up to the bypassing web application protection part, and it all makes sense, but how do you determine what to use in a real scenario? Tamper scripts for eg. what information would a web application give away in order for you to determine the right tamper scripts to use? Or would you just try everything until something works? Same with prefix and suffix?

fathom pendant
#

imo you'll get more clarity in the sql injections module; the prefix/suffix thing is how it injects the payload based on how the payload is processed on the backend

#

the sql injection module displays the query back to you so you can see where it's being thrown in

#

since sqlmap is mostly based on blind stuff; you're on a journey of fafo

inland shuttle
#

I’ve done the sql injections fundamentals if that’s what you mean. I just understood that it only shows the process and payload because it is a learning environment, not like any website out there would be showing you the back end. So in that case it is mostly a guessing game for what parameters you use in your injections?

fathom pendant
#

yep

#

that's how SQLi has always been

inland shuttle
#

Interesting. Do the guesses get easier to make over time?

fathom pendant
#

eh

#

it's why sqlmap exists, to take the tedium out of manual checking

inland shuttle
#

Yeah fair enough. Thanks for the help!

cold pilot
cloud urchin
#

not much HTB can do about some indian government site having errors

#

you may be able to google it if you'd like to find more

naive cedar
#

why logon fail??

fathom pendant
cold pilot
dapper moth
#

Please don't tell me there will be another cert!

fathom pendant
#

Can't wait to see what it's about

dapper moth
#

I actually finished the path already.
Academy won't even let me close the path since I finished the modules prior to launch.

hasty mauve
dapper moth
tired atlas
safe star
tired atlas
tired atlas
safe star
#

It said permanently moved so closing it usually works with those

safe star
tired atlas
#

I thought it meant the contents were moved to a different page, so started enumerating for more subdomains

safe star
#

I ran into it at one point too

tired atlas
#

how did you think of it

safe star
#

Just closed it🤷‍♂️

#

I also think the error says where it got moved but can’t remember what’s it looks like tbh

tired atlas
tired atlas
# tired atlas

the directory without the slash was probably a file, that says something got moved permanently

#

the slash told the web server i was accessing a directory

lusty thicket
tired atlas
chrome furnace
#

on Attacking common services - easy
Is the SMTP user exists on the provided user list? I already tried -w 5 up to 85 with increments of 5 but the results is always 0 exists.

chrome furnace
earnest pasture
chrome furnace
chrome furnace
earnest pasture
earnest pasture
chrome furnace
chrome furnace
earnest pasture
fathom pendant
#

Please take talk of the skill assessment to DMs as to not spoil

storm elk
#

@chrome furnace - you were told to take this discussion to DM. Please do so.

storm elk
#

This is not the server for this @snow arch

#

Hacking someone's WiFi is illegal

snow arch
#

@storm elk okay I have no money 😥

storm elk
#

That doesn't make it right to steal someone's WiFi.

fiery kindle
#

What’s your advice for a newbie ?

#

Like someone who just wants to start ?

compact patrolBOT
storm elk
#

👆

median gale
dapper moth
urban elk
#

surely there will be more modules guys

dapper moth
#

You finished the modules prior to the path launch, @median gale?

fathom pendant
#

Likely more to come alongside an announcement

dapper moth
#

Hoping that it wont be as heavy on theory and text as the "Fundamentals of AI"

fathom pendant
feral parrot
#

@fathom pendant you available for question.

naive cedar
#

hi

lusty thicket
#

buddy

feral parrot
#

@lusty thicket not sure what your getting at.

median gale
weak kindle
#

Has anyone completed the ADCS attacks modules? If yes, just reply to this msg and I will PM you!

small basin
#

Is it normal that Firefox takes a while until the Proxychains is working?
It looks like it first waits for all these requests to timeout and then finally sends the request to the IP I want to access.

[proxychains] Strict chain ... 127.0.0.1:9050 ... academy.hackthebox.com:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... firefox.settings.services.mozilla.com:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... push.services.mozilla.com:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... darkreader.org:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... push.services.mozilla.com:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... ublockorigin.pages.dev:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... push.services.mozilla.com:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... ublockorigin.github.io:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... cdn.jsdelivr.net:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... cdn.statically.io:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... ublockorigin.github.io:443 <--socket error or timeout! [proxychains] DLL init: proxychains-ng 4.16 [proxychains] Strict chain ... 127.0.0.1:9050 ... push.services.mozilla.com:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... ublockorigin.github.io:443 <--socket error or timeout! [proxychains] Strict chain ... 127.0.0.1:9050 ... 172.16.5.135:80 ... OK

Even after accessing the page one time when I refresh the page it first waits until one or two other requests timed out again and then it refreshes the page.

Is this related to using Proxychains? Can that only handle one request at a time?

naive cedar
#

i can't rdp to windows host..

fathom pendant
#

Have you tried not using powershell?

peak light
naive cedar
#

its logon fail

naive cedar
lusty thicket
#

firefox pre resolves domains and connects to mozilla services in the background and these requests are forced through proxychains so when it sends these requests at the same time each one must wait for the previous one to complete or timeout before proceeding

fathom pendant
fathom pendant
#

You have pwnbox running dude

naive cedar
#

yes

fathom pendant
#

You can't use pwnbox and vpn on your own machine at the same time

naive cedar
#

ah, i try vpn when not running pwnbox

#

FeelsBadMan .

fathom pendant
#

Well you can't have both running otherwise you get ~problems~

naive cedar
#

i tried with vpn first, it didn't work

#

and i try with pwnbox

fathom pendant
#

Make sure you're disconnected from the vpn before trying on pwnbox again

naive cedar
#

okay, i will try again

fathom pendant
#

If it works you owe me $20 and some melatonin

naive cedar
#

FeelsBadMan ..

small basin
lusty thicket
#

you can also isolate proxychains to specific cmds like curl

#

and if that doesn't work you can turn off proxy dns

#

doesn't the module cover the config file?

naive cedar
#

omg.

#

RPOGGERS ..

small basin
small basin
feral parrot
#

need help with a module, information gather Vhost, brute forcing vhost. i have ran gobuster everyway, used dig, created my own wordlist to narrow my search to the prefix of the answer. i have used the other tools in the sections, im not getting anywhere. any hint or tip would be grateful

small basin
# lusty thicket or random chain

random_chain has the same problem.
even if I disable proxy_dns.

The only thing that makes it less annoying is to reduce the timeout:

tcp_read_time_out 150 tcp_connect_time_out 80

But thanks for the explanation! 🙂

naive cedar
vapid perch
#

i just completed the windows fundamentals skill asessment but even after completing the steps like i should, it always says that the SID is wrong

fathom pendant
#

@opaque walrus don't post images that contain flags, should be common sense

#

shuffles back to sleep

storm elk
#

sings a lullaby

waxen totem
storm elk
waxen totem
#

papa sparkling fr fr

opaque walrus
#

Kind request for help.
.
I am on Nmap module, with Firewall evasion Lab - Medium.
Please check pic, my command is correct, Not sure why I am not getting the version for DNS

jagged tartan
opaque walrus
grizzled schooner
vocal thorn
#

Hi anyone alrealdy resolve this question

grizzled schooner
#

What question?

vocal thorn
#

Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

#

Is from Footiprint SMTP

fathom pendant
#

don't copy/paste about info on a machine

#

especially modules above tier 0

grizzled schooner
#

marcie, do you have any hints you can give about the question I was asking about the shells and payloads engagement?

fathom pendant
#

you don't need to do anything to the script beyond use it

#

then of course setting the options

#

using the vhost and such where applicable

grizzled schooner
#

how? I can't get 'sploit to recognize it / import it unless I'm missing something

fathom pendant
#

?

vocal thorn
fathom pendant
tranquil wren
#

i have a ticket in with support but did anyone have any issues running the command sudo apt-get install gvm && openvas on the getting started with OpenVAS module?

fathom pendant
vocal thorn
#

I already use exploit but continue not acept the user that I have found

grizzled schooner
#

exploit isn't in metasploit...? I don't know what I'm missing lol

fathom pendant
grizzled schooner
#

this is gonna piss me off soooo bad, that makes me think I'm staring at it lol

fathom pendant
#

literally don't do anything beyond use exploitname.rb you don't need to import it or anything

grizzled schooner
#

...

vocal thorn
#

Is not work

grizzled schooner
#

that was for me

vocal thorn
#

the user that i found continue to receive wrong answer

fathom pendant
#

you're not the only one asking for help

grizzled schooner
#

Here, I'll bounce with that info, I should be able to figure that out, thanks as always marcie o7

tranquil wren
#

lol

fathom pendant
vocal thorn
#

if we can share screen there is no fun

#

I try get some help

#

If i can show you... always we dont have how to get understand

fathom pendant
#

told you how to find the answer with the tool you're using

#

you're going to continue getting the "wrong answer"

#

just did it myself, told you how to adjust your usage

#

it seems the way it's set up is to always verify that whatever@inlanefreight.htb is correct regardless of if whatever exists or not

#

so you need to verify whatever

cedar dagger
#

is it normal in the module of pivot in the chisel part when executing chisel on the victim target I get this error ? :

ubuntu@WEB01:~$ ./chisel client -v 10.10.16.37:1234 R:socks
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./chisel) ./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.32' not found (required by ./chisel

#

nvm found this command online when building the binary sudo go build --ldflags '-linkmode external -extldflags "-static"' and it worked

zenith acorn
#

yay complrteed weba attacks

#

skill assesment was fun

shut ice
#

Can anyone give a hint on DACL II SA first question? I've got a PC account that has access to another PC account, but can't see the path to the target with the flag?

woeful lake
#

Oh, you allready solve it, my bad

cedar dagger
edgy crown
#

Um

#

Who you

cedar dagger
#

Dunno why tho since this morning every time I connect try to connect to rdp i get these error

[09:35:19:616] [22255:22256] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[09:35:19:617] [22255:22256] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[09:35:22:733] [22255:22256] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[09:35:22:733] [22255:22256] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[09:35:22:733] [22255:22256] [ERROR][com.freerdp.core] - freerdp_post_connect failed

edgy crown
#

You a hacker

#

Ooooo

woeful lake
brazen spoke
#

I am doing Information Security Foundations pathway , r there any htb machine to do , or the machines only start from penetration tester pathway

cyan lark
#

Hey, I'm on the Hacking WordPress module at the Skills Assessment.

I was asked to use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.
I have 3 vulnerable plugins, one allowing me LFI - I don't know where the flag file is.
One plugin allowing me to read private posts. (I'm not finding a private post)
And another plugin allowing me other kinds of things (not files related)

shut ice
#

Does anyone know if Q1 for DACL part 2 skills assessment require abusing constrained delegation? Not sure if it's a rabbit hole as that is covered in part 1?

zenith acorn
cedar dagger
cyan lark
zenith acorn
#

I have 3 vulnerable plugins, one allowing me LFI - I don't know where the flag file is.....

#

i completed this module but long time ago

#

dont remember sorry

cyan lark
edgy crown
#

I’m

#

Bye

zenith acorn
#

i think so i a

cyan lark
zenith acorn
#

that was the main objkective right

sour raptor
#

I am unable to start an attack box instance on my account. Anyone else having issues?

cyan lark
zenith acorn
#

what fucking flag?

#

the flag location is in the fucking quetion or am i missing something

#

i swear man blind fucking people

cyan lark
#

Calm the fuck down

zenith acorn
#

what flag u talking about?

cyan lark
#

I am talking about this question for the 100th time

zenith acorn
#

sorry my bad

cyan lark
#

I don't want your help @zenith acorn , I'll wait for someone else

zenith acorn
#

haha bro im sorry i am the blind one

#

accept my sincerfe apologies

narrow oriole
#

which is better use for enumeration gobuster or ffuf

hallow kiln
zenith acorn
#

but yeah if i want to help i needed to start up teh machine i guess

narrow oriole
zenith acorn
#

but bro if u want some advice

#

u know the vuln righr? then research it maybe look up a PoC and try it

#

should get u the flag

#

just look wpscan output and check some links

#

time to get some weed for me. sorry for many messages

valid nest
#

This drives me nuts. Working on Abusing HTTP Misconfigurations Password Reset Poisoning.

But I cannot access interactsh.local:Port/log. any insights?

cyan lark
bright ridge
valid nest
cyan lark
ancient haven
#

Hi HTB Community, I am new to the HTB world and am currently working through the Intro to Network Analysis Module, I am stuck at the Familiarity WIth Wireshark portion, I am using Pwnbox VM but do not see eth0 or wifi filters available in Wireshark, am I missing something obvious

valid nest
#

thanks thanks!!

lyric temple
#

HTB Community is there any way to know whether the discord user still uses their account without being in their friendlist?

#

Let me know for real

#

I want to msg my old friend but I don't know whether they still use their account

ancient haven
#

I am getting the following error when trying to capture on ANY of the devices listed:

acoustic owl
#

The error message tells you what you can do

gray yacht
cyan lark
#

Whether it's manually with the theme editor or using exploits on msfconsole.

gray yacht
gray yacht
zenith acorn
#

if you still stuck on the same question

#

do what it sais and it should get u flag

zenith acorn
#

im trying to help you:)

#

i feel bad

fathom pendant
gray yacht
zenith acorn
#

yseah sorry....

gray yacht
zenith acorn
#

bro is ignoring me

bright ridge
#

@zenith acorn move on

fathom pendant
#

It happens

zenith acorn
#

letting go is not my string suit

cyan lark
#

I just reached an API limit..

zenith acorn
#

you can us emy api token

#

so sorry am ior listen too what i say

fathom pendant
#

Btw (slightly off topic) hope you're doing better

fathom pendant
gray yacht
# cyan lark Yes

Then start researching the identified vulns. I wouldn't really read up the cve.mitre stuff, but rather blogs and other references. Look for something that correlates with what the question is asking. I'd also start at the top and work my way down.

cyan lark
#

I don't see the unauthorized file download with the mail vulnerabilities in the WP scan

zenith acorn
#

are we really living in a world we nobody can lose his or ehr temper anymore?

gray yacht
cyan lark
gray yacht
#

You have everything you need. Good luck

cyan lark
#

You don't have to help me if you don't want, you don't need to do it with an attitude

cyan lark
zenith acorn
#

wow youre the one wiith a attitude

fathom pendant
#

Wpscan is only one of the tools, look at the id'd plugins. And as ricky said research.

zenith acorn
#

those shitty people that cant take a joke

#

i hate them woke brokie

bright ridge
#

.. this chat sometimes lol

zenith acorn
#

is this with or without api token

fathom pendant
cyan lark
zenith acorn
#

hmm

cyan lark
#

Why was it deleted

zenith acorn
#

spoiler

cyan lark
#

That's not even a spoiler.. damnit

fathom pendant
# cyan lark With

Hacking WordPress is a t2 module, anything you reveal about it is a spoiler whether or not you think so

#

See the channel topic

cyan lark
#

So how am I gonna ask questions

#

I'm looking at the results of the scan, I'm showing you what I got and what I'm trying to find

zenith acorn
#

let me fire it up

cyan lark
#

Nevermind I found it, it was labled as "multiple issues"

fathom pendant
#

You can be slightly vague or reveal just enough info so that people who have done it would know.

#

But copy/pasting the output is spoiling

#

Since it gives exactly the environment in the assessment

cyan lark
#

Yeah I get it you're good @fathom pendant

#

I was just frustrated a little

fathom pendant
#

It's also why I say spoiler tags don't do anything because anyone can still click it

#

I think it hides it from discord search, but if you have enough surrounding info for it, it doesn't take a rocket scientist to figure it out

cyan lark
#

Yeah.

zenith acorn
#

nice bro

cyan lark
#

But now I'm still stuck at the shell part. I got access to an admin account but I can't upload shell php neither manually and neither with the msfconsole

cedar dagger
#

for RDP and SOCKS Tunneling with SocksOverRDP -> when I load the SocksOverRDP-Plugin.dll i get an error stating that there is an error is there a solution for it ? cause without this when connected with rdp I cannot run the .exe

#

on the 172.16.5.19 host

ancient haven
fathom pendant
cedar dagger
#

Ok thanks I'll try to find it

fathom pendant
#

Well your lhost is wrong I can tell ya that

dark hedge
#

new Tier IV module. insane

analog dock
#

Defensive 😭

fathom pendant
#

Don't believe you need to specify http protocol

cyan lark
cyan lark
fathom pendant
#

Also: spoilers

#

Ffs

cyan lark
#

What did I spoil????

#

I redacted everything, it's not even related to the module at this point

lusty thicket
last sentinel
#

Hello guys

#

Who’s active

lusty thicket
#

not me

sonic merlin
#

Hiya

storm elk
#

Not me

fathom pendant
rustic sage
lusty thicket
rustic sage
final shale
#

Well guys, maybe its a bit of off topic but i gotta share i got the KLCP. It was harder than you would think. 🙂

final shale
hasty mauve
final shale
hasty mauve
analog dock
hard matrix
#

Did anyone get a foothold from the tomcat server on the linux privesc skill assessment? Wondering if just bruteforcing the /manager login is the correct way or if its expecting me to find some CVE (doesnt look like it.)

next stone
#

anyone online who have finished Injection Attacks module Skills Assessment?

#

I need help with that

#

I have done the first part of it || SSRF || but couldn't complete the second || XPath || Injection| part

gray yacht
hard matrix
#

🤔

crisp solstice
#

Heyo! Im just doing the Actve Directory enumeration & attacks module, in the LLMNR/NBT-NS poisoning section.

Just curious, can responder capturing hashes be done through ligolo-ng or another tunnelling tool? As i tried it and cant seem to get it to work!

cyan lark
#

I’m still stuck on it

cyan lark
#

Do you have any clue why I get that error where I can’t upload a shell?

bright ridge
#

llmnr/nbt-ns poisoning relies on udp broadcasts

cloud urchin
bright ridge
#

my bad, it can handle udp traffic

#

but it doesen’t handle broadcast/multicast traffic properly

#

the packets will never reach ypur responder instance

fathom pendant
#

It can but you'd need to do a lot of port forwarding shenanigans

bright ridge
fathom pendant
#

¯_(ツ)_/¯

#

It's a pain in the ass to set up anyway. Best to just run it from the machine

opaque tree
#

What’s better your own virtual machine or starting point machine

fathom pendant
#

?

#

Your own vm is better 9 times outta 10

opaque tree
#

Oh thanks!

fathom pendant
#

Control, storage, flexibility

opaque tree
#

Yeah

fathom pendant
#

You're not relying on someone else's infrastructure not being FUBAR

opaque tree
#

Thanks

crisp solstice
cedar dagger
#

For the skill assesments for Pivot module, For your next hop enumerate the networks and then utilize a common remote access solution to pivot. Submit the C:\Flag.txt located on the workstation. I tried to lookup network but both nic are in the same subnet and I found the user/password for this question In previous pentests against Inlanefreight, we have seen that they have a bad habit of utilizing accounts with services in a way that exposes the users credentials and the network as a whole. What user is vulnerable? But now im a bit stuck idk in what direction should I go

woeful lake
#

Im at Acl part of the AD module, in the pass i use bloodhound, but now i have a better idea of what is happening, very insteresting so far

fathom pendant
#

Would defeat the point of 2 nics on the same net

cedar dagger
#

I mean if both have an /16 subnet

#

and both are 172.5.x.x

#

172.16*

fathom pendant
#

That's not really the case though

#

It's a bit of an oddity but they are separate

#

They are logically separated

cedar dagger
#

Sorry forgot to hide the ip

#

ok i see so one is in network 172.16.x.x and the other one in 172.16.x.x?

bright ridge
#

the last one has no default gateway

cedar dagger
#

right

#

so it cant even go outside of his lan

fathom pendant
zenith acorn
#

but spoikers are fun

fathom pendant
#

Except when it's against rules and ToS my guy

zenith acorn
#

still fun

#

....

fathom pendant
#

And you can have fun getting banned if you continuously post spoilers and/or post writeups to content above tier 0 (not saying that you do that, just stating consequences)

zenith acorn
#

yes i understand ma'm

fathom pendant
#

I do hope that you've gotten a lot of what was bugging you off your shoulder from a while back. Genuinely. But I'd suggest not being antagonistic towards others when they're trying to help.

zenith acorn
#

not my intent

fathom pendant
#

I couldn't care what your intent is. Impact over intent. The way that people receive what you say is independent of how you intended to say it.

lusty thicket
zenith acorn
#

sure, everything is relative'

#

you have strong and weak people

fathom pendant
#

Not about being strong or weak

cedar dagger
zenith acorn
#

okay haha

fathom pendant
#

I just hope that you're sober

#

Genuinely

zenith acorn
#

just sayingnot my purpose to be rude

#

world is a big place

#

different cultures

fathom pendant
#

Not about cultures

cedar dagger
#

its common sense lol

fathom pendant
#

Not here to debate you on this

zenith acorn
#

becaus eyou lose lady

fathom pendant
#

Just stating that the way you say things can counteract how you intend things

fathom pendant
zenith acorn
#

okay okay

cedar dagger
#

if a computer is joined to a domain the domain controler will always be the dns server ?

zenith acorn
#

you have a point, i double check my responses from now

fathom pendant
#

I'm genuinely trying to benefit of the doubt. Especially knowing your history

cedar dagger
#

or would it be possible that its another computer?

cedar dagger
#

ok so not always the domain controller

fathom pendant
#

Typically the DC(S) handle name resolution

#

But there could also be a dedicated name server that's separate in some instances

cedar dagger
#

han i see

fathom pendant
#

It all just depends on the environment and what the business needs and whatnot

cedar dagger
#

but lets say the domain name like hackthebox.local if i did an nslookup on that domain name given im joined in the domain it will give me the ip of the domain controller right?

native igloo
#

Anyone know where I can get usernames and passwords to try on hydra !!!

lusty thicket
native igloo
safe star
#

Obito pfp makes it so much funnier

zenith acorn
#

tnx

cedar dagger
#

Omg I feel so stupid for the last flag in Pivot Skill assesment ..... 😂 after 1 hour of trying to pivot it was so simple

cedar dagger
#

that was literally me lool

fathom pendant
#

I confirmed with support at one point btw that it is intentional

zenith acorn
#

well goodnight i am going to sleep

cedar dagger
#

Ligolo-ng worth learning ? Seems easier than the method shown in the course

fathom pendant
fallow kernel
#

Eyo Tonym did you do an nmap or something to get the port to which u need to connect to at the last two questions of the pivot skill assessment. Because I think I found the IP with cmd pingsweep on one server but I can not seem to connect to it. The IP i found is alive though since I can ping to it ofc

cedar dagger
#

like 😭

cedar dagger