#modules

1 messages · Page 385 of 1

narrow meadow
#

thank!

pine dune
#

@waxen totem I got an obsidian plugin u may find useuful. It's called "reminder" but for some reason it doesn't work for me, but it may for you. It seems super helpful tho

wanton topaz
#

Hi everyone, I'm doing the AD enumeration and attack module, currently on the kerberoastong part but I cannot find creds for a valid domain user on the page. I'm probably missing it but I tried the basic htb-student creds, forend user (but i don't see the pass ?) And tried with sqldev creds that they retrieved during the explanation

fathom pendant
wanton topaz
#

I guess, I will go back and see the other creds. I just needed to be sure that it's not me tweaking lmao

mild jungle
#

did you set your payload in the multi handler

wanton topaz
#

Thanks !

quick abyss
pine dune
#

Hi guys, is anyone else having trouble connecting to the vpn?

still edge
#

hi guys i'm using kerbrute userenum -d domain.local --dc x.x.x.x wordlist.txt -o valid_user but the result in valid_user is empty like the output give nothing. even if kerbrute say there is 56 valid user

#

so i don't understand why the output file is empty

fathom pendant
#

i think that kerbrute version is bugged

crude wind
#

Hello! I'm still working on Linux tasks, but I can't figure out what I'm doing wrong when calculating the number of installed packages. The question is: How many total packages are installed on the target system?
I'm entering the command:
apt list --installed | wc -l
but the number I get is not the correct answer.
What am I doing wrong? (I'm running the command on the target machine.)

urban elk
#

have you checked for any extra lines at start or end ?

#

(I haven't done the module)

crude wind
urban elk
regal wedge
#

hey, could anyone lead me on a path here?
bug bounty hunter, Information Gathering - Web Edition / Skill assesment.

What is the API key in the hidden admin directory that you have discovered on the target system?

i used gobuster and FFUF, but i only seem to get a /index.html dir.

reef dragon
#

i ned help with a question What is the name of the hidden "history" file in the htb-user's home directory? this one ive ran the command ls -la i tied opening .bash_history but it output was "exit" what shuld i do

odd horizon
#

He

#

Doe you jus hachs

crude wind
reef dragon
crude wind
#

You probably just don't have permission to read it.

reef dragon
#

ohh i must have missunderstood the as

#

aassignment

#

thanks

#

am new to this shit so dont know so much

crude wind
reef dragon
regal wedge
#

Finishing something hard feels like a reward, keep up the works!

crude wind
halcyon cliff
#

Is this the place to ask questions if we are havin issues with a module? Sorry new to this channel

regal wedge
#

yes it is

halcyon cliff
#

I'm on the Pivoting section of module 'Intro to C2 Operations with Sliver'. I'm having issues running the cmd: 'make windowsdll_64'. For some reason it keeps throwing errors:

make windowsdll_64
env CGO_ENABLED=1 GOOS=windows GOARCH=amd64 CC=x86_64-w64-mingw32-gcc-win32 go build -buildmode=c-shared -trimpath -ldflags "-s -w " -o chisel.x64.dll .
go build: when using gccgo toolchain, please pass linker flags using -gccgoflags, not -ldflags

golang.org/x/sys/windows

/home/htb/go/pkg/mod/golang.org/x/sys@v0.0.0-20220908164124-27713097b956/windows/dll_windows.go:182:32: error: reference to undefined identifier ‘syscall.Syscall9’
182 | return syscall.Syscall9(p.Addr(), uintptr(len(a)), a[0], a[1], a[2], a[3], a[4], a[5], a[6], 0, 0)

pine dune
#

Will there be any ctfs or htb events held in London this year?

dull barn
#

Hello

cold pilot
#

hey im currently finishing up the Pivoting, Tunneling, and Port Forwarding module and im stuck on the SSH for Windows plink.exe page.
I am connected to the VPN in my Windows VM and can ping the target machine correctly and see open ports 22,80. What credentials am I supposed to use to connect to it with plink.exe? I tried the same credentials for the ubuntu user that are given in the other pages but that fails from my VM. It somehow works from the HTB Pwnbox though 🤔 Is there some kind of restriction not allowing me to connect from my Windows VM? I get the SSH prompt and 100% sure I enter the correct password but impossible to connect... I have also tried using the basic ssh client on windows and I get the same errors... Permission denied (publickey,password) any ideas on what's going on here 😂 ?
turns out i just had to redownload a VPN file...

potent sandal
#

hey guys whats up ... why i cant do normal nmap scans ? (sau) machine. i wanna do nmap -sC -sV x.x.x.x have the lab vpn on but still problems

#

then i did a sT scan he show me the ports but could not secify with sV

warped cedar
#

hi , in the pentester path, module 'Getting Started ' it reads :
'Another option is VMware Workstation, which requires a paid license but offers many more features than the free options.'
isnt this misleading ? I mean like, this software is not paid provided one uses it non-professionally, right, or what ?

#

it also might be that it is not paid since recently, but this suggets the HTB materials are not updated regularly ☹️, what do you think ?

dark hedge
quick mica
#

So I’m in Linux fundamentals modules of the section system information.

I couldn’t find the answer to “what is the path to htb-students home directory”

Idk isn’t it supposed the answer to be “ /hoem/htb-ac-1733123??????

safe star
#

you spelled home wrong + you're supposed to ssh into a machine

hallow kiln
#

Only thing I did differently in my notes is import Powerview first, but that literally shouldn't make a difference, what if you do Get-DomainUser -Identity damundsen

quick mica
safe star
cedar dagger
#

In the ACL enumeration for AD enumeration & attack this question : What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)

Im using bloodhound but cant seem to find anything ? Like I've found 2 ObjectAceType for the forend user over GPO management group but nothing is two word ? Any tips on how to discover the answer using bloodhound cause the powerview command been going for 20 min and I still got nothing?

safe star
old wren
quick mica
#

So I do ssh htb-student [ip address]?

#

Into the pwnbox

cedar dagger
old wren
# quick mica So I do ssh htb-student [ip address]?

I assume that you can spawn a machine at the end (usually modules work like that). If that's the case, it should tell you "ssh into <machine> as <user> using <password>" (or something to that effect).
If you need help around ssh syntax, google it or run man ssh.

#

I am guessing (not sure) that the user that you're running PowerView with isn't joined to the domain? That would explain why you're not finding damundsen.

I seem to remember that I right-clicked PS, ran it as wley, and just did your last three lines (import PowerView, set new password for damundsen). Didn't even create separate credentials for wley.

old wren
potent sandal
#

ich wanna do a nmap scan with nmap -sC -sV 10.10.11.224 -p- / But he dont scan and break up with 50 %

old wren
potent sandal
#

└──╼ [★]$ nmap 10.10.11.224
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-02-04 21:03 CET
Nmap scan report for 10.10.11.224
Host is up (0.050s latency).
Not shown: 997 closed tcp ports (conn-refused)
PORT STATE SERVICE
22/tcp open ssh
80/tcp filtered http
55555/tcp open unknown

Nmap done: 1 IP address (1 host up) scanned in 1.97 seconds

└──╼ [★]$ sudo nmap -sC -sV 10.10.11.224
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-02-04 21:03 CET
Stats: 0:00:47 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 50.00% done; ETC: 21:05 (0:00:45 remaining)

old wren
#

running scripts and doing version probing takes time; your nmap scans should first cast a wide net, and you should run your scripts and more aggressive probes on things (ports) you know have something behind them

potent sandal
#

yeah but in the walktrough they do exactly the same and they give some thing back

#

when i let them run i get nothing back

quick mica
#

Nvm it turned out I typed it in a wrong way

#

Thx guys

#

Finally got my first cube lol

thin parrot
#

Anyone able to help with Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

This is in the "Getting Started" module for pentesting

#

I found an exploit but I literally cannot find it in searchsploit or metasploit

#

||Port 22 is open for ssh, OpenSSH is running on debian 12/bookworm, there is a known exploit for the exact version of OpenSSH (9.2) on deb12u3 which is what the target has.||

rustic sage
thin parrot
#

I've been googling it but I can't find what the name of the exploit.. actually is??? It doesn't help that in the prior pages it does not mention how to actually find the exploit it just mentions eternalblue out of nowhere like we're supposed to fucking know that it exists for no reason

cloud urchin
thin parrot
cloud urchin
rustic sage
#

Hey guys, was wondering if anyone could help me through the API attacks.

I’m on the 1st module and have been able to retrieve the reports, but I cannot for the life of me find the flag.

cloud urchin
thin parrot
#

i thought we were supposed to scan through all the ports and look at open ones or the ones potentially hosting webservers etc

urban elk
#

when that's the case, you will only be given an IP. Like SuperNuts said, when you get IP:PORT, you just use that port

thin parrot
#

gotcha, thank you

mental fossil
#

ls /roorman ls

frigid bay
#

Hi there, I am doing the ICMP Tunneling with SOCKS section. I have troubles understanding this command: sudo ./ptunnel-ng -p10.129.202.64 -l2222 -r10.129.202.64 -R22. How come the proxy and remote address are the same? Shouln't be the attack box address be the proxy? Please help

wraith oyster
#

Hi everyone, i’m doing the AI fundamentals and i’m stuck at question 5 no matter i answer is always wrong. If someone can please help me with it

umbral blaze
#

@fresh stone hi brother

rugged kernel
#

Go

umbral blaze
#

Has anyone completed Dante?

umbral blaze
#

no answer

cloud urchin
#

this channel is for discussion of the Academy modules

umbral blaze
#

dm

crimson dew
fathom pendant
#

I did it blind. So not sure what the module itself says. But I suggest figuring it out on your own using notes from the relevant module

#

If you're absolutely sure it should work, restart the environment. Or reach out to support

muted pulsar
fathom pendant
#

Also spoiling content for a module above t0

muted pulsar
#

yeah I ended up spending a bit of time on the sql inj one and reviewing those modules, it was helpful.

fathom pendant
#

I suggest continuing the module blind and only refer to the reading if you're truly stuck

muted pulsar
#

ok

fathom pendant
# muted pulsar ok

it's mostly because doign AEN blind is a test of methodology and shows how good (or bad) your methodology and notes are

late moth
#

the winodws privesc module is taking forever lol

craggy summit
#

Guys I got a question, just started HTB, I need to awnser "What does the acronym Linux PAM stand for" I tried "PLUGGABLE AUTHENTIFICATION MODULES" and many other things but can´t get the awnser wright. can anybody help me?

fathom pendant
#

did you add linux in front of it also the module and section name is super helpful for us helping you

#

also wouldn't be authentification, just authentication

#

authentify isn't a word

#

well

#

at least in this context

weak token
#

Sometimes I see this out of the corner of my eye and get excited I found a flag 😮‍💨

royal hemlock
#

Anyone would help to do Skill assesment of Information Gethering - Web Edition in last two Question

fathom pendant
small maple
waxen totem
#

Gotta be more specific mate...

fathom pendant
#

i used the given command with the wordlist and it worked fine for me

#

you're likely overlooking the answer

#

as it's not something that's crazy

#

don't reveal answers 😉

#

overthinking the problem

honest crane
#

Linux Local Privilege Escalation - Skills Assessment

Could someone give me a nudge on the ssh-less foothold? So far, I've the webpage (static), Tomcat, and the subdomain, and what looks like a mysql port, but I can't make sense of it.

bright ridge
fathom pendant
#

Simple question, simple answer

digital pendant
#

(was being stupid have removed :P)

honest crane
urban elk
#

sure

floral jewel
#

Inquiry about the annual subscription to HTB. My question is about the step by step feature. I want to take a look before buying. Is it explained somewhere?

wooden seal
#

can some help me with (Remote/Reverse Port Forwarding with SSH > Remote/Reverse Port Forwarding with SSH) practical part. As i cant do it nor i have any clue whats going on even after reading material lol

fathom pendant
floral jewel
fathom pendant
#

It's literally just solutions to the content lol

digital pendant
#

its also against the rules to post pictures of the solutions Faza

floral jewel
#

Because I will take the CWEE test and study the entire content.

digital pendant
#

So cant even show xd

floral jewel
pseudo kiln
digital pendant
#

This ^ but also if you've exhausted all options of your methodology and still the answer alludes you, at least then you can learn something either new or sanity check how your approach is wrong

fathom pendant
#

the steps are assuming you read the content and just hit a wall

pseudo kiln
#

well the person was asking about the feature, so I answered the person's question about the feature

pseudo kiln
#

has anyone ever had this issue with bloodhound ? Yesterday uploading a zip file worked, now the same zip file no longers works

#

it gets stuck in Waiting for upload forever

waxen totem
#

Is your neo4j db running?

pseudo kiln
#

yes, typically when I forget about that one bloodhound will not even login for me

#

ok I rebooted my machine and now it works, very strange

urban elk
#

what was your expectation

#

I guess the 10-second tiktok format doesn't really lend itself to learning complex skills

fathom pendant
#

it helps when you didn't grow up on AI and instant gratification responses

misty current
visual umbra
#

Well.
Is at the end of the Web proxies module.
Am on proxychains but facing some problem: : proxychains nmap --proxies http://127.0.0.1:8080/ 94.237.61.111 -p 50193 -Pn -sC
and then I get that work but I only get what is caught in my terminal and not in burp which is the actual sentence. If I tx run proxychains curl http://sida.se/ it is captured in burp as it should be.

waxen totem
#

You only take an hour on a section? I typically re-read and internalize everything which can take more than an hour per section

#

(part of the reason I take so long is cos of distractions like discord 👀 )

smoky oracle
waxen totem
urban elk
#

one or the other

visual umbra
waxen totem
waxen totem
#

Yeah I think it's a too many proxies in use issue like facsimilae said...

visual umbra
#

it do proxy [proxychains] Strict chain ... 127.0.0.1:8080 ... 94.237.61.111:50193 ... OK
but not into Burp

waxen totem
#

Might be the ports interfering

visual umbra
#

But if i do proxychhains curl it wors..

waxen totem
#

you mean you can see the curl request in burp?

visual umbra
#

yes

waxen totem
#

what's your proxychains.conf looking like?

urban elk
#

I meant try
proxychains nmap 94.237.61.111 -p 50193 -Pn -sC
or
nmap --proxies http://127.0.0.1:8080 94.237.61.111 -p 50193 -Pn -sC

visual umbra
waxen totem
#

if you have proxychains set up this way you shouldn't have to tell nmap to use the proxy...

#

try removing the scripts, some of them may not work through the proxy

pseudo kiln
urban elk
visual umbra
urban elk
visual umbra
urban elk
#

alright, then I don't know

visual umbra
#

Ok. Thanx for trying

pseudo kiln
#

did you uncomment quiet mode ? if you cat /etc/proxychains4.conf| grep -v '#' | grep -v '^[[:space:]]*$' how is the config looking ?

visual umbra
pseudo kiln
#

if you do proxychains curl -i https://example.com -k does it send it through burp ?

pseudo kiln
#

ok so it's failing for specific commands then

visual umbra
#

exactly

#

As I said, it is caught in the termianl but not forwarded to burp, precisely when it comes to nmap

pseudo kiln
#

then I have no more ideas, I am sorry chief 🤷‍♂️

visual umbra
#

I suspect that it may have something to do with the fact that I connect via VPN, I will test the same thing via pwnbox

visual umbra
#

It must be me doing something wrong here, I tested via pwnbox and couldn't get it to work there either.
Hmm.....

#

well, i will fix it some time:D

gray yacht
waxen totem
#

Was bout to say: looks like a public ip, you don't need a VPN

visual umbra
#

but i seems so..

strong wyvern
#

Hello guys I'm alvino new to cyber security and i have a small plan to do simple very simple tbh so if you can guide me i it would be wholesome

compact patrolBOT
visual umbra
#

did try without VPN, same problem...

gray yacht
visual umbra
#

I can't figure this out...

#

But i will:D

waxen totem
#

Yah am tryna figure it out too, having the same results using caido

strong wyvern
#

Anyone who can explain me some of nmap

waxen totem
#

No one's gonna hold your hand. I'd recommend reading the Network Enumeration with NMAP module

visual umbra
strong wyvern
#

Where to get modules

visual umbra
strong wyvern
#

Is it free??

visual umbra
#

join the Academy

visual umbra
#

you ern and buy cubes

grim basin
waxen totem
grim basin
#

yeah openvpn is running

#

that part should be good considering it did give me some output

#

i just dont get the virtual hosts part i guess, i did append them to /etc/hosts/

waxen totem
#

please don't post flags, even with spoiler tags

trail flicker
#

oh i though it was fine because it was wrong

grim basin
#

so i dunno what else i should be doin

waxen totem
grim basin
#

oh dang

visual umbra
grim basin
#

i got it now

strong wyvern
grim basin
#

needed the ip in front of it

#

nother lesson learned

strong wyvern
#

Someone help me in nmap pls

waxen totem
#

@strong wyvern no one is going to help you unless you have a legitimate question.
If you want to learn how to use nmap there's a module on: https://academy.hackthebox.com
however, I suggest starting with the beginner's bible:

compact patrolBOT
visual umbra
#

As I said, I don't know about proxycains, now tested with msfconcole as the lab says, and it works, it seems only when I run with nmap it goes wrong!

strong wyvern
#

Bro my dought is how to use nmap pls

visual umbra
strong wyvern
#

Ok bro

craggy summit
waxen totem
#

@visual umbra can you try proxychains nmap 94.237.61.111 -p 50193 -Pn -sT -sC?

heavy thorn
#

Hello, I am trying Nibbles. I am very new to kali/linux. The instructions are very unclear for me. Do I use Parrot Terminal? None of the commands I am doing are working. Is the IP address they provide in the instruction the same one I am supposed to use? I tried watching a video as well and their version of linux looks nothing like mine so I am at a loss

delicate light
#

are you on the pwnbox ? @heavy thorn

heavy thorn
#

is that the linux VM they provide? then yes I am

warped cedar
delicate light
heavy thorn
# delicate light yes the online vm ?

Yes I am, I figured out my problem but I am sure I will have more, the command was right but I didn't know which IP address to use.

I had to hit "show target" or something towards the bottom for them to provide me with an IP address. That was my issue.

visual umbra
strong wyvern
#

It's telling host seems down when I'm nmaping

candid lily
#

whats wrong with htb ssh, keep getting stuck

spark fox
#

helloo everyone

#

currently doing file inclusion and ive reached the file inclusion prevention section

#

i have modified the php.ini file as you can see

#

disable_functions = pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,pcntl_unshare,system

#

i added system to the disabled functions

#

when i run the following i dont get the error message : sudo tail -n 20 /var/log/apache2/error.log
[Wed Feb 05 14:55:12.773536 2025] [mpm_prefork:notice] [pid 929] AH00163: Apache/2.4.41 (Ubuntu) configured -- resuming normal operations
[Wed Feb 05 14:55:12.773582 2025] [core:notice] [pid 929] AH00094: Command line: '/usr/sbin/apache2'
[Wed Feb 05 16:10:13.482041 2025] [mpm_prefork:notice] [pid 929] AH00169: caught SIGTERM, shutting down
[Wed Feb 05 16:10:13.545133 2025] [mpm_prefork:notice] [pid 3455] AH00163: Apache/2.4.41 (Ubuntu) configured -- resuming normal operations
[Wed Feb 05 16:10:13.545164 2025] [core:notice] [pid 3455] AH00094: Command line: '/usr/sbin/apache2'
[Wed Feb 05 16:21:56.749425 2025] [mpm_prefork:notice] [pid 3455] AH00169: caught SIGTERM, shutting down
[Wed Feb 05 16:21:56.811869 2025] [mpm_prefork:notice] [pid 3799] AH00163: Apache/2.4.41 (Ubuntu) configured -- resuming normal operations
[Wed Feb 05 16:21:56.811896 2025] [core:notice] [pid 3799] AH00094: Command line: '/usr/sbin/apache2'

#

any help?

grim basin
#

doesnt say anything special after update file is pressed. any ideas?

spark fox
#

i found the answer to my problem. i had to add a php shell to var/www/html and execute it to trigger the error

safe star
grim basin
#

ill try that later thank u for the idea

white junco
#

Hello guys, I would appreciate a nudge in the right direction on the Penetration Testing path. I'm in the Privileges Escalation module and can't figure out
how am I supposed to echo the public key into remote server's /root/.ssh/authorized_keys file without having root access. I've spent 2 days on this.

white junco
#

I don't want a complete solution. Just a hint. The hint provided isn't very helpful. It just says "Review the page".

loud socket
white junco
loud socket
#

okay lets phrase this differently

#

what user are you currently on?

white junco
#

user1 on the remote server.

loud socket
#

so you need to get access to the account "user2" before being able to privesc to root

white junco
loud socket
#

np 😄

grim basin
ancient niche
#

Good Afternoon people someone can help me? i cannot find flag here. The module is stack-based Bufffer overflows on linux x86

minor eagle
#

Hello, can someone please give me a push in the right direction. Im on Information Gathering - Web Edition skills assessment I found the hidden directory but when i try and go to the hidden directory to find the api key it gives me a 301 moved permanently.

strong stone
#

i am stuck in answer and dont know whats the problem anyone ?

ocean night
strong stone
#

Learn the basics
of Penetration Testing

ocean night
#

You're just asking for the answer to the question

#

Right, ok

strong stone
#

Fawn

ocean night
#

Oh, Fawn

strong stone
#

no the answer is ftp -h

#

and its not working .

ocean night
#

It's not though

strong stone
#

okay

ocean night
vast swan
#

hi, pleas i stuck in the introduction to windows command line (the skill assessment) user2 i realy anser the question ,but when i try to login to the user2 , the password dosen't work , pleas any help

digital pendant
#

do you guys take updates to solution requests/feedback here? seen a T2 module solution just have slightly wrong numbers being referenced in part of the solution. Not a big deal just thought id mention it

hardy sand
#

does anyone else have severe issues accessing the platform ever since the CTF announcement? I've been unable to access anything :/

#

alright, I am back in. Maybe it was a cookie issue or something.

granite osprey
#

Hello, I've been stuck for hours on question 3 of 'pivoting, tunneling, and port forwarding' skills assessment. I've been scanning the internal network of the target, but Nmap takes forever, without a single output. I don't understand what I'm doing wrong, as I am using TCP connect scans and configured proxychains as advised in the course. Please, give me a hint.

safe star
#

Did you use sudo?

#

Also add -v so your not wasting your time

granite osprey
lone locust
#

Hello guys! How many machines I need to complete to get "Hacker" Rank?? sadglas

cloud urchin
#

not what this discord is about

cloud urchin
#

careful not to spoil content from anything above tier 0 modules

grim basin
#

mb i thought the pw not being there was enough one sec

#

that alright? hope thats good

safe star
#

You’re listening on localhost

#

It gives you a warning

grim basin
#

yea i was trying that cus none of the addresses assigned to me are working atm

#

just double checked them just in case

#

but ive tried all the adresses from here

cloud urchin
#

i use 0.0.0.0 or tun0

#

you can see it's failing to upload the payload though

safe star
#

you could always do the other option they showed

grim basin
#

yeah this aint working for me for whatever reason

#

ill give the other options a whirl

cloud urchin
#

that's how i did it

grim basin
#

i tried 0.0.0.0 and i double checked if i set up the exploit correctly so im just gonna blame technology and move on

#

damn did i post a spoiler again or am i good

ocean night
#

There was information specific to the module and completion, and if it's the same one (e.g. above tier 0), then yeah.. I removed out of abundance of caution.

grim basin
#

my bad ill try to cut down on as much info as possible next time

ocean night
#

Thanks!

errant bane
#

anyone around for a nudge on the Login Brute Forcing / Web Services (Medusa) module?

waxen totem
#

Dont ask if anyone arround, just ask the question

#

Not that kind of server mate

#

If you wanna learn hacking ETHICALLY

compact patrolBOT
waxen totem
#

Nope, we're ethical hackers

serene phoenix
#

.

waxen totem
#

We don't do things that are illegal or to cause harm

waxen totem
#

For learning ethical hacking.

cloud urchin
#

This server isn't for you then. This server is to talk about the various HackTheBox platforms, this channel specifically is for modules on the Academy platform.

fathom pendant
#

Wtf is the deep discord

mortal spindle
fathom pendant
#

Is it like some skid version of the deep web

waxen totem
cloud urchin
#

master hacker shit

fathom pendant
waxen totem
mortal spindle
fathom pendant
#

If you wanna learn ethical hacking

compact patrolBOT
stable sandal
fathom pendant
waxen totem
mortal spindle
ocean night
#

Think you're in the wrong server then, sorry

mortal spindle
compact patrolBOT
fathom pendant
#

Thats just skid tricks, and not worth the time to learn illegal things

stable sandal
viral lotus
#

is there a problem on the servers? have been trying to spawn a windows box for ad enum &n attacks - Additional AD Auditing Techniques but multiple IPs are unreachable and now I have a spinning circle of doom for 5 minutes. I know sometimes windows boxes can take longer but this time seems off. tried terminating and rebooting a few times. changed to a tcp connection as well. it worked briefly maybe an hour ago

fathom pendant
#

Typically windows boxes don't reply to icmp echo requests

cloud urchin
viral lotus
#

its randomly spawned, I will give it 5 minutes and see as its still saying broken pipe as error

fathom pendant
#

there's likely more to the error than "broken pipe"

errant bane
#

First question of the lab on Login Brute Forcing / Web Services (Medusa) module asks for the passwd for the ftp user but the service on that port is SSH. I tried to use the SSH module with it but it yielded no results. If I use the ftp module I receive an error for failed regex pattern match. Any advice?

fathom pendant
#

i.e. an NT_STATUS_ error

viral lotus
fathom pendant
#

it starts with bruteforcing sshuser
then bruteforce ftpuser from within ssh

viral lotus
fathom pendant
errant bane
fathom pendant
#

no?

#

lol

#

i was able to log in just fine

viral lotus
fathom pendant
#

it's a public IP

#

worked fine for me

errant bane
#

ok

fathom pendant
#

is it -p and not -P for ssh?

errant bane
fathom pendant
#

:P

viral lotus
#

its only a P.O.C thing, I changed VPNs so it could be that and restarted the machine, I will just give it another whirl in the morning. I got the AD explorer snapshot. No big deal

#

Thanks anyway

terse sedge
#

I've been trying the Information Gathering - Web Edition- Skills Assessment. I can't find any subdomains or Vhosts. I've tried with gobuster, ffuf, etc. Is it just a matter of picking the right wordlist, or am I doing something wrong?

fathom pendant
#

With ffuf you need the host header, with gobuster you need to append the domain with --append-domain --domain [domain name]

terse sedge
#

I didn't use --append-domain this time, but I have in the past. Anyway, this is the command I used: gobuster dir -u http://94.237.50.46:34186 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt

#

And ffuf: ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -u http://94.237.50.46:34186 -H FUZZ:inlanefreight.htb

#

finalrecon found an ||index|| nothing else

fathom pendant
#

Sounds like you didn't fuzz for subdomains

#

Also host header would be -H "HOST: FUZZ.inlanefreight.htb"

#

dir is <directory> searching in gobuster btw

stray gust
#

As a Texas resident and user of your services, I am writing to exercise my rights under the Texas Data Privacy and Security Act (TDPSA) and Texas Business and Commerce Code Section 521.053 regarding the recent data breach affecting your company.

I hereby request the following information:
Confirmation of whether my personal data was affected by the breach
If affected, a detailed description of the specific information compromised
If affected, a copy of the exact information that was accessible

As mandated by the TDPSA, you are required to respond to this request within 45 days. Please provide a written acknowledgment of receipt of this request and confirm that you are processing it in accordance with the law.

Additionally, I would like to remind you of your obligation under Texas Business and Commerce Code Section 521.053 to notify affected individuals "without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred". Failure to do so may result in penalties as outlined in the statute.

cloud urchin
stray gust
#

Nah this works

#

They can read it

cloud urchin
#

No it doesn't as staff doesn't monitor this for that kind of stuff.

stray gust
#

Ummm you read it?

#

They can to

fathom pendant
cloud urchin
#

They don't. You'd have to open a ticket on the site or do what marcielee said.

fathom pendant
#

Posting on here is like farting in the wind, and you'd be told to make an official request via official communication methods

stray gust
#

Hmmm i don't think it works like that

fathom pendant
#

It does work like that

cloud urchin
#

it does, we're telling you it does lol

stray gust
#

If it's in the wind, it will eventually get to a moderator

fathom pendant
#

As this isn't an official way to get in touch with the right people

cloud urchin
#

you need to go through the proper channels just like anything else

fathom pendant
#

???

stray gust
#

You read what I said

fathom pendant
#

<@&861185840277487616>

cloud urchin
#

For the purposes of the data protection legislation Hack The Box, is the controller of your personal data. Our Contact details are:

Hack The Box LTD
email: info@hackthebox.com
postal address: 38, Walton Road, Folkestone, Kent, UK, CT19 5QS

If you have any concerns about the way in which we handle your Personal Data, you can contact privacy@hackthebox.com. You have the right to make a complaint at any time at the Hellenic Data Protection Authority Postal Address: Data Protection Authority Offices: Kifissias 1-3, 115 23 Athens, Greece, Call Centre: +30-2106475600 Fax: +30-2106475628 E-mail: contact@dpa.gr

The use of our web pages and the services provided requires your agreement with the Privacy Policy of this site. Therefore, you must carefully read the contents of this page before using the services of our Website. If you do not agree, you must leave this website and not make use of its services or content.

#

no

fathom pendant
#

No

#

You can read

gray yacht
cloud urchin
#

sounds like you don't really give a shit if you're not even willing to submit your request through the proper channels

fathom pendant
#

^

#

Then following up with "i want to abuse an smtp port" kek

ocean night
#

@stray gust reach out to us. You will need to delete your own account.

fathom pendant
#

I doubt they're actually serious g0b but appreciate you treating it as such

ocean night
#

We do not remove accounts purely on an email, users are able to remove their accounts u sing their own credentials, and this is in order to avoid data loss by account loss or misuse. Reach out to the details above if you need to, and don't ask for SMTP servers.

#

Yeah

#

I'll do you a favour though

#

I'll delete some data for you

fathom pendant
#

And g0blin told you what we've been telling you

#

Reach out to appropriate channels

cloud urchin
#

what a weirdo

fathom pendant
#

Skids coming in hot and heavy on a Wednesday

gray yacht
#

It is hump day

fathom pendant
#

They're already gone

ruby shadow
#

whew!

ocean night
#

Appreciate it also @ruby shadow, but the address is being updated 🙂

#

It's still valid

#

Just.. if anyone visits, they'd find an angry scott with a bat by the door

#

(I get the mail, but I don't live there any more)

#

Hopefully this is the year we finally get the address updated properly to an office 😆

gentle herald
#

in sliver c2 module, i am unable to get shell on srv01. psexec stuck on this like forever. any help please?

rustic sage
#

Does anyone wanna get into a group call and carry each other in this ‘game’ until we complete all modules that are free?

cloud urchin
#

doesn't that defeat the purpose of learning?

gentle herald
rustic sage
cloud urchin
rustic sage
#

We can test first hand if it’s helpful for learning to do so together, and find out later if it advantages us or disadvantages us.
As for ctf stuff, like I said, I’m new, so new that I’m not familiar with this server or acronyms, but my main point is learning and doing whatever hack related together for more learning.

waxen totem
rustic sage
#

Well, it’s up to what you want.
I’m not serious about the most efficient way to get through the content, because so long as I get through the content in the end do I learn what’s in it.
I want to do it with others, even if it has the potential to have what is considered to be distraction within the context of purely learning.

#

How do I access general btw?

#

It just says check modules (this)

waxen totem
cloud urchin
#

best to ask in the appropriate channel, like i said this channel is for HTB's Academy platform. Try asking in #1336347627452629033

rustic sage
#

I’m saying that it applies to academy stuff as well, I only mentioned the cyber apocalypse thing as an inspiration.

rustic sage
#

Thank you 🙏 🙂‍↕️

frigid bay
#

I am working on RDP and SOCKS Tunneling with SocksOverRDP. I have done everything correctly. I don't know what is not working. I even edited the proxychains.conf file (socks5 127.0.0.1 1080) on my kali. Can somone give me a nudge?

cloud urchin
#

i would wager it's not actually setup correctly.. can't really tell where, but i would just comb over everything again and make sure each piece/setting is in place. also disable real time protection when registering the .dll

cloud urchin
#

this isn't a hacker for hire server, this server is about the HTB platforms

cloud urchin
frigid bay
cloud urchin
#

as i said, this isn't the place for that. this isn't some hacker for hire discord. only the service provider can assist you, reach out to whoever provides the service.

nova igloo
#

has anyone completed the network enumeration with nmap mod

cloud urchin
#

Many have

nova igloo
#

im a beginner and stuck on the labs at the end

lusty thicket
nova igloo
#

the first lab is trying to bypass the firewall to detect os

#

i've used -sS -O and decoys

#

it cant determine the os still

fathom pendant
#

You don't have to specify the port from the example

fathom pendant
fathom pendant
nova igloo
#

but i will review the proxy section regardless

fathom pendant
#

O nvm you said first lab

#

I'm used to people getting stuck on the last one

nova igloo
#

stuck there now lol

fathom pendant
#

Well, what i said applies there lol

nova igloo
#

thank u

fathom pendant
#

Also fun fact -g is the shorthand for --source-port

nova igloo
#

that's handy

cunning plinth
#

hi guys, need help with cpts getting started module, knowledge check.. i already got the user.txt via metasploit

#

now, how can i get root.txt via meterpeter?

#

cant seem to find a way to root haha been hours already

fathom pendant
#

GTFObins is a great website

cunning plinth
fathom pendant
#

:p

zenith obsidian
#

sup npcs

novel matrix
cunning plinth
#

thanks guys im starting to get hings now lollllll

#

now my next prob haha

novel matrix
#

Linenum is always something you upload to the machine… otherwise, youll be enumerating your own machine

lusty thicket
cunning plinth
cunning plinth
#

oh sorry hahahah got too excited

#

woohoooooooo proudest achievement lol

dark hedge
#

can the astronaut see out of that helmet

cunning plinth
#

all he can see are boxes he needs to hack

lusty thicket
cunning plinth
#

always thought i'll be in the blue team lol, since i tried htb, i prefer being in the red team now lolll

safe star
#

Awesome sauce

silk flicker
ocean night
#

Part of the learning process 0_0

#

Amount of times I've been in that exact same position, not just in security

#

You either work through it, put it down to come back to later, or drop it

#

Whether you work through it alone or with others, really it's a personal decision, but HTB is better suited to those that can research and investigate under their own steam, take the knowledge they've learned realise how it could be used in various situations, and then of course there's the persistent inquisitiveness. Rarely does anything of value come easy, and if you do not find it easy, then it just means you've got more to learn 🙂

#

There's never a day when there is not something to learn, regardless of experience, of position or public image

silk flicker
#

I recently started academy doing some path like cracking into HTB, basic tool set but anytime I try some labs in the main platform I see that the knowledge I have is not enough to do the whole thing and with the academy x HTB I found the modules covering each retired machine. I wanted to ask if it would be better to focus solely on the academy for the time being since there are practical labs in most modules or if I should continue balancing things like suggested in the getting started module.

quick mica
#

Hey quick question can I run ssh on my own terminal not the website?

dark hedge
#

if you mean interacting with the targets on your own machine, you will need to download the VPN file

quick mica
#

Yep that is what I meant

dark hedge
#

yea, download the VPN file and connect to the VPN with it

quick mica
spark fox
#

Helloo everyone. Any idea what i gotta do to be able to chat in #general?

long kestrel
#

guess time to cut on a movie lol (doing password attacks)

fathom pendant
#

looks like you're using the rockyou wordlist for some reason kek or some other wordlist

long kestrel
#

the mutated password list provided

fathom pendant
#

the mutated list is only 94k long

#

the cheatsheet is missing the pipe to | sort -u

long kestrel
fathom pendant
#

ah

#

ye

#

combos and stuff

#

also you can use like 48 threads instead of 30

#

48 has been the most consistently reliable/fastest

long kestrel
#

im gonna cancel that one and try it with the non mutated list first actually. could save a lot of time if its in there

glacial sparrow
#

i'm a bit confused about the documentation and reporting practice lab. i've got the credentials for a bunch of users and am attempting to perform DCSync using one of them since bloodhound says that they have the permissions, but secretsdump is giving me errors stating that they don't have permission. has anyone else encountered that?

thorn walrus
#

Guys, I am taking the NTLM relay module and have a theoretical question.

Is putting .lnk files to assesible shares an authentication coercing method?

#

Or is it another method of pre relay like coercing and name resolution poisoning?

bright ridge
#

Verify with powershell «dsacls "CN=Configuration,DC=domain,DC=com"
dsacls "DC=domain,DC=com"»

#

you could also try to dump it with mimikatz

gray field
#

I have question in Web attacks. In Bypassing Basic Authentication the scripts said that use OPTIONS Method to see what HTTP method are accepted. But when I use options method using curl I can't find an Allow headers.
Can anyone know why this cause?

bright ridge
#

if it is, try to restart the target

gray field
#

I restart the target but It is same..

gray field
autumn pilot
#

The exercise can differ with what is written in the section

bright ridge
#

that's all im saying

gray field
bright ridge
#

submit it, try

gray field
bright ridge
#

issue is likely that php is not handling OPTIONS request properly

#

not returning allow headers

gray field
rustic sage
#

hi guys, ive a question. Ffuf didn't discover the dirs that gobuster did. Why such happens? I can provide the outputs

waxen totem
#

Did you use the same wordlists?

rustic sage
#

gobuster dir -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt -u http://xyz.htb/index.php/

This found a directory named admin
But
ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u "http://xyz.htb/index.php/FUZZ"

#

this ffuf didn't

#

I can provide whole outputs in DM so as to not spoil anything

#

I usually prefer ffuf because of speed, but this was really deceiving

bright ridge
#

could be filtrering or response codes, is ffuf actually finding anything at all?

rustic sage
#

nothing at all

#

gobuster spotted some status 302 directories

#

i can try ffuf with -mc 302

waxen totem
#

try and remove :FUZZ from the wordlist

#

it should automatically look for it anyway

urban elk
#

which module and section is it ? I'd like to try

rustic sage
#

It's a box, I can dm the outputs.
Tried removing FUZZ and adding matching case, nothing useful

bright ridge
waxen totem
#

that'll do it ^

bright ridge
#

ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u "http://xyz.htb/FUZZ"

urban elk
#

yeah, my best guess is something to do with that. Or the quotes. Still curious how gobuster handles it in a way that makes that work

#

you could send it through burp to see what's going on

waxen totem
#

you can also add -recursion flag in ffuf in case it is in a subdirectory

rustic sage
#

tried running ffuf on http://xyz.htb/FUZZ but it still didn't catch admin directory. Even tried -recursion flag.

#

Can I DM someone?

waxen totem
#

Probably a resp code then

urban elk
#

would be super surprised but can you remove the quotes from the url ? If you haven't already

#

in that issue, double quotes work though... maybe it's a shell shenanigan

onyx kite
#

Hi I need a nudge on AD assessment 2,
Q: Obtain credentials for a user who has GenericAll rights over the Domain Admins group. What's this user's account name?

I ran ||sharphound ||but I keep encountering errors related to machine cant connect to ldap

The error below shows both on ||MS01 ||and ||SQL01||:
||
|ERROR|Unable to connect to LDAP, verify your credentials
||

Running powerview tool
||
Error in retrieving forest schema path from Get-Forest
||

little shadow
#

Hi,

I followed all the steps in the provided solution to complete the task: ||"Use the concepts taught in this section to pivot to the Windows server at 172.16.6.155 (jason:WellConnected123!). Submit the contents of Flag.txt on Jason's Desktop."|| in the section ||"RDP and SOCKS Tunneling with SocksOverRDP"||.

However, when I attempt to connect to the internal host ||172.16.6.155||, I receive the following pop-up message:

Remote Desktop can't connect to the remote computer for one of these reasons:

1) Remote access to the server is not enabled
2) The remote computer is turned off
3) The remote computer is not available on the network

Any ideas on what might be causing this issue? prayge

little shadow
rancid spindle
#

hello there can any one help me with windows attack and defense module section PKI ESC1 when connect to WS001 it says there is trust issue with domain controller

rancid spindle
#

troubleshooting these labs takes longer than the lab it self most sections of windows attack and defense module have some sort of a problem

rough tree
#

Someone who maanged to pass the skill assestment lab on the WPA2 module?
I would need some help on the second flag

chrome maple
#

Anyone has done AI Red teamer skill assessment? I trained the model but it says Invalid model file even tho I uploaded .joblib model

#

Tried with .pth yet invalid

wide wagon
#

Hi all, I am currently doing the nmap module and can´t get the flag for the NSE part. Could need a small hint

fathom pendant
#

common port; as a note for some reason it seems some nmap installations may not properly have the enum script

wide wagon
#

nvm. got it

#

I was expecting the nmap nse output to contain the flag, not "digging deeper"

fathom pendant
#

yup

tiny zodiac
#

Working on the Wifi-WPA/WPA2 module and I'm at the start of the WPS PIN cracking. I'm not able to crack the WPS, I restarted the lab VM twice, I also turned on verbosity and I'm seeing lots of timeouts to the SSID. Is there a chance there is an issue with this lab?

delicate light
#

hello ! if i have a question about the box cat where can i ask ?

delicate light
#

i don't have access

cloud urchin
delicate light
#

ok thank you

tiny zodiac
#

Third reboot of LAB VM did it

ancient niche
#

good afternoon people someone can help me with this? i cannot find it the flag

vocal dust
#

🇪🇸

ancient niche
urban elk
vocal dust
spark fox
cloud urchin
#

in linux? openvpn <vpn file name> &

spark fox
#

go to where you downloaded the vpn configuration file

#

most likely in your downloads folder

#

then do sudo openvpn <your conf file name>

#

it should work

#

in kali you should see a small ip on the top right

#

something like 10.10.32.123

#

that usually means you are connected

dark hedge
#

you need to verify your account in order to send pictures -> #welcome

spark fox
#

you need to verify your acc

arctic cipher
loud socket
#

In terminal run

spark fox
#

cd /downloads

loud socket
#

sudo openvpn path/to/vpn_file

#

sudo apt install openvpn

cloud urchin
#

you're using archlinux, it's notorious to be difficult to setup and requires a lot of customization. since you seem new, i would recommend using kali or parrotos as they both come preinstalled with the tools you need to get started.

loud socket
#

Oh arch uses pacman I believe

cloud urchin
#

all of them are

wide wagon
#

just found the solution to nmap hard module - not sure how I could have done it with nmap I did it with ncat

rain mountain
#

-S

calm tapir
#

Need some help. Attacking Thick Client Applications: Trying to retrieve the hard coded credentials. I ||Disabled the autodelete from the temp folder and modified the .bat file so that the other files won't get deleted. Now I get an error that the restart-service.exe doesn't exist so I cannot move forward.|| I restarted the machine and still get the same error anyone else experience this?

wide wagon
rain mountain
#

That was for pacman, not you

wide wagon
#

ah

rain mountain
#

A long time since I did that module, and not at pc atm

wide wagon
#

ohh wait... it says to use ncat in the academy as well.. must have skipped it

cloud urchin
#

This isn't the channel for support.. try asking in #1024429874246590575 . As I mentioned before, you're going to struggle really hard on Arch because it appears as if this is all very new to you. I'd suggest again to use Kali or ParrotOS. Maybe take some of the fundamental modules so you can get a feel for how to operate Linux too.

wild sage
# spark fox

sometimes you have to send the request twice in order for it to work

slender delta
# spark fox

If I remember correctly, there was a small detail I missed as well and it took me hours to manage to do it. Something with the way I inputted the UA

dark hedge
wide wagon
#

Was there a possibility to solve only with nmap?

dark hedge
#

no.. for some reason, pwnbox will give you the answer without requiring anything besides nmap

wide wagon
#

Hmm… interesting

dark hedge
#

and it's only through pwnbox

#

so if you do it through vpn, you'll never get the flag unless you use something like nc

wide wagon
#

Ncat gave me the flag through vpn

dark hedge
#

yea. nc, ncat, netcat,

wide wagon
#

Wait. Is there a way to specify source port connection in nc/netcat? seems that ncat is unique for it

cloud urchin
#

yes

wide wagon
#

Whats the flag?

cloud urchin
#

you just put the port after the ip

#

oh the source port? yeah, --source-port

wide wagon
cloud urchin
#

i used ncat

dark hedge
#

i believe i used nc

wide wagon
#

Yeah thats the only tool that it worked with

late moth
#

on the Windows PrivEsc skill assessment part 1 question: " Find the password for the ldapadmin account somewhere on the system." Any hints? I'm struggling with it. I have a shell on the systme just cant find any creds. Tried running inveigh through a rev shell and its not working out so well

steel snow
#

Excuse me, this is very important!

#

now, do i need to always use a virtualenv to use PIP?

#

because it's annoyingg to keep activating the tool before i would be able to use it, i mean any tool i installed using pip

grim basin
#

the last method i tried im not sure how to describe without it potentially being a spoiler, but it involves netcat listener and that isnt working either

lime lake
#

Hi! How would I ever find out the answer to this module here?

https://academy.hackthebox.com/module/77/section/847

I revealed the answer already, but how in the world would I ever get to that result? I tried to ssh into the target machine on port 22 and 37072

But how would I know that the answer is/would be:
(warning - answer revealer)
||SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.1||

valid nest
#

so glad that you were there before me. and there goes my three hours of hate me time

grim basin
drifting salmon
#

Anyone can help me get my acc back ?!

dark hedge
drifting salmon
#

Tik tok

dark hedge
#

contact TikTok support

drifting salmon
#

I did many times nothing

dark hedge
#

anyone offering account recovery services is trying to scam you. the only way to get support for your account is through the service provider

dark hedge
#

none of us can help you

#

that's what i'm saying

#

contact TikTok support.

drifting salmon
#

I thought someone can hack so I can get it back

dark hedge
#

if they can't help then you're out of luck

dark hedge
drifting salmon
#

Alr

dark hedge
#

we also are not a hacker for hire server

drifting salmon
#

Ok

glossy cloak
#

I get 404 not found when trying to instal NFS

tranquil wren
glossy cloak
gray yacht
tranquil wren
gray yacht
void kayak
steel snow
#

Excuse me, anyone knows why pip install pyftpdlib doesn't work and gives externally-managed error EVEN tho, i used and activated myself in a virtual environment using virtualenv and source?

tranquil wren
#

i have to rdp into the foothold, to access the other targets

#

that foot hold doesn't seem to have firefox

steel snow
#

i can't install it at all unless i use --break-system-pack

gray yacht
tranquil wren
#

yes

gray yacht
gray yacht
tranquil wren
#

jeez yeah thanks

bright coral
gray yacht
lofty whale
#

stuck on file uploads attack skills assessment. I have found the source code for up*****,php and know the naming convention but still cant get to the file. any thoughts

slow ruin
#

Anyone here for a quick chat on the skills assessment for application of ai in infosec?

lethal dawn
#

Hi everyone Im looking for a services I need

safe star
#

Maybe you’re in a different time zone?

lofty whale
#

2 digit month and date or one, time zone?

gray yacht
lethal dawn
#

Somebody know how to find the delivery address from a tracking number

glossy cloak
#

Please help

real delta
glossy cloak
#

every command starts with sudo... no?

real delta
urban elk
#

and appache typo on second command

glossy cloak
#

oh... right

glossy cloak
slow ruin
#

Curious on the skills assessment for the applications of ai in infosec. Looks like the training data label is the inverse of what the submitted model is looking for... wondering if that is intended?

nvm, got it

fathom pendant
# glossy cloak

It's likely because default port is 80 and that's in use by pwnbox

glossy cloak
#

no more errors

#

but, now nothing happens... it should open a browser with apache page?

lofty whale
#

@safe star What do you mean by different time zone?

safe star
#

seen that before

fathom pendant
glossy cloak
#

ok, I am done with pwnbox, I ll use virtual machine

#

if its ok with you lol

late moth
#

In the Windows Priv Esc module Part 1. I’m trying to go from the web service user to SYSTEM.

I see I have the impersonate privilege . I have tried all the potato attacks and printnightmare but no luck. I can’t find any other escalation path.

Any hints?

fathom pendant
glossy cloak
fathom pendant
#

¯_(ツ)_/¯

#

Use your own vm then

#

Do you have to run apache, or is it just being shown.

terse sedge
#

Correct me if I'm wrong, but Vhosts & subdomains look the same to a user. The technology behind them may be different, but they both look like: something.inlanefreight.htb. If I use gobuster in fuzz, dir, or vhost mode, aren''t they all going to try to append a word from the wordlist? What would be the difference?

acoustic owl
#

A subdomain is a second level domain and therefore part of an address.
A vHost is a technology that allows a web server to be operated with a single IP, but is still capable of hosting multiple websites.
For example, it can display different websites for www.example.com and web.example.com.

#

This way you can also run example.com and inlanefreight.htb on the same web server.

terse sedge
light yarrow
#

Anyone know the uber eats method ?

dark hedge
rustic sage
acoustic owl
pine dune
#

Hi guys, in the whilelist extension section for file upload attacks when I fuzz the extensions I either get "only images are allowed" or "extension not allowed"

#

could anyone please give me some tips?

#

okay so it seems like the "extension not allowed" was for php only, however the wordlist I used had a few php extensions in them which is a bit bias if you ask me

#

I keep getting a 404 not found when I upload and try to go to the extensions

fathom pendant
#

I think they provide a php list in the reading

pine dune
#

the php extensions have been accepted but when I try go to them it gives a 404

fathom pendant
#

Are you accessing the right endpoint?

pine dune
#

I believe I am?

#

in the browser \ gets converted to /

fathom pendant
#

Nope, \ is an escape character in the upload

#

[Also not needed]

pine dune
#

okay well can u pls give me some tips? do u know why all of the endpoints are returning 404 😅

fathom pendant
#

¯_(ツ)_/¯

#

Well if it's giving certain errors like x only allowed, then it's likely not uploading and is getting blocked

pine dune
#

nah its getting uploaded cos im doing it through repeater in burp and its saying "file uploaded successfully"

rustic sage
#

Can I DM someone for an issue where gobuster and ffuf outputs for directory search don't match?

#

I have no clue whats really causing this difference

#

I have tried ffuf matching filters, recursion, and what not

#

I don't know if at this point I should even use ffuf over gobuster..

#

I'll try to paste here with hidden details

#

||This is a spoiler test!||

fathom pendant
#

Spoiler text does nothing

#

Anyone can click on it or disable it from their end

rustic sage
#

man, i've been stuck on this since yesterday. Just doesn't feel right when the tools you trust the most do sh like this

fathom pendant
#

that's why you learn multiple tools for the job ¯_(ツ)_/¯

waxen totem
#

If one tool doesnt work try it again, if it still doesnt work, try another tool

#

Thats my rule

rustic sage
#

The thing is- I won't even think of running long directory scans from different tools. I would usually just use one on different URLs to figure out and would trust the outputs. Using two tools seems out of scope

#

How would i differentiate if it isn't working or no directories exist at all?

waxen totem
#

Using more than 1 tool is usual, like I'd never just try to crack a hash with john, if it doesnt work I'll use hashcat or crackstation

rustic sage
#

ok, so this is a general practice. RIghto

#

any tweaks for gobuster? I find it way too slow than ffuf

rustic sage
#

its a box

gray yacht
waxen totem
#

Welp, time to delete spoilerss

rustic sage
#

yeah i was avoiding the name

#

theres no spoilers

waxen totem
#

All good, now we've got something to test off of

rustic sage
#

i've hidden the urls

waxen totem
rustic sage
#

um, righto

waxen totem
#

Now we can help test at least

terse sedge
waxen totem
#

But dont do 127.0.0.1 its your localhost address

terse sedge
fathom pendant
fathom pendant
#

Just spaces between

long kestrel
waxen totem
vapid thistle
gusty edge
#

I cant talk in generak

#

general

cloud urchin
bright ridge
#

@steel snow solved or not?

steel snow
steel snow
#

for pyftpdlib it did, probably because earlier i used --break-system-packages to install it globally

#

now i am trying to install --break-system-packages.

#

and nope, not a chance to install it

#

Even tho other files are installable, but this and some others didn't work

#

i am trying to use this command now

#

"sudo pip3 install wsgidav cheroot", and i am absolutely sourcing /bin/activate of a virtual env

bright ridge
#

which python
which pip
python --version

#

tell me the results

steel snow
#

3.12.8 for python

#

pip 24.2

bright ridge
#

hm weird

#

not sure honestly

steel snow
#

i am using kali-linux if that's some input to this issue

#

i tried to install odat before, same issue

bright ridge
#

odat should be easy to install

steel snow
#

nope, it crushed my soul to install it and i failed in ALL ways

bright ridge
#

sudo apt update && sudo apt install odat

steel snow
#

hmmmm well maybe i didn't know that but i used the github ones

#

i followed multiple paths

bright ridge
#

kalis system python is tightly managed

steel snow
#

so it's really risky to --break-system-packages?

bright ridge
#

can be

waxen totem
#

Well it's risky because some packages use different versions of libraries, which is why it's best to use separate virtual environments for each tool

steel snow
#

what is better?

waxen totem
#

~~that being said... no one uses a different one for each tool we all just use 1 venv laugh_cry ~~

steel snow
#

hahahaha I was actually using one for each tool

waxen totem
#

That is best practice

steel snow
#

and i thought i was stupid so i switched to one for all TwT

waxen totem
#

But... it's annoying to keep switching

steel snow
#

Exactly

#

that's why i switched to one for all

#

just today i did that

waxen totem
#

or you know... just let pipx do the work for you

steel snow
bright ridge
#

kali relies on specific versions of python packages. overwriting them with pip might break built-in tools

steel snow
#

and my interpreter recognized it yet

bright ridge
#

also conflict is a big issue

steel snow
#

it's saying it didn't recognize the commands

waxen totem
#

Did ya restart the terminal?

steel snow
#

yes

#

i did

#

and i checked the PATH variable

#

the /root/.local/bin and the other one

waxen totem
#

did ya do ensurepath ?

steel snow
#

both

waxen totem
#

dang... no clue then 😅

steel snow
#

my kali-linux is stubborn hahahaha, i wonder who it's like (pointing at me)

#

it's okay i will break its head one day

waxen totem
#

Yeah... had a lot of issues with kali so now I just run exegol (just kali but in a fancy docker container)

steel snow
#

is it no longer the best linux for this topic?

#

distribution

#

maybe it wasn't even? because when i was young i got the impression that it was

waxen totem
#

I mean it has some issues, but all systems have issues, just up to you to choose whether or not to fix it or to use something else

steel snow
#

now if i used pipx, would i need to go to any virtual env?

#

or no longer needed

steel snow
#

so when i use sudo the system doesn't use the local bin but use /root path, i didn't know that

bright ridge
steel snow
#

Okay i know my problem with pipx

#

when i install 2 things that are separate i have to inject them

steel snow
#

anyone is having an issue spawning a machine?

gentle herald
#

any help on escalating to domain admin in sliverc2 skills assessment module ? i tried the dumping password hashes using mimikatz and disabling ppl protection too with vulnerable driver but still got error. any help please

honest crane
gentle herald
safe star
#

You don’t need a driver there

gentle herald
#

i am getting error, because of openprocess being failed. i will try again

steel snow
#

guys anyone of you is suffering from the network

#

i am connecting to machine and the machine keeps dying like

#

the connection dies, no ping responses

#

then it comes backthen it dies

#

i am sure it's not 2 conflicting instances of openvpn

storm elk
#

If you’re not using them at the same time, try switching to tcp

steel snow
#

ooooooooo that's true?

#

i didn't know that

#

Thank you very much!

#

i thought this issue only can be caused by 2 instances one a zombie process or something

#

but i restarted my VM

#

this is one of the questions!

  • 3 Download the file flag.txt from the web root using wget from the Pwnbox. Submit the contents of the file as your answer.
#

i don't understand the question tho

#

like from where do i download it? where is the file?

#

does the machine possibly have flag.txt somewhere?

#

Ahhh i got it but i don't understand why

#

is it because webroot is basically http://<machine_ip>?

storm elk
#

Yes

steel snow
#

i see i see thank you!

#

that term confused me a bit

dusty aspen
#

Hello! I'm currently doing the skills assessment for Information Gathering -Web Recon. I have added all of the subdomains to the host file, but I am not able to navigate to the admin directory. When I curl the complete address, I get a Redirect message; then, when I curl the redirect message, I get an error. The question is 3. I have been able to find the answers to 4 and 5 in addition to 1 and 2. It seems like I should be able to navigate to the address, but it's not working. I have already restarted the target and the PBox.

steel snow
# storm elk Yes

excuse me, why would there be an issue when both pwnbox and mine are separate machines

#

why would the existence of both ruin the connection?

#

i mean i understand if it was 2 openvpn processes in the same device

cloud urchin
#

pwnbox uses the same vpn

steel snow
#

i mean so is many devices no?

cloud urchin
#

it shares the same ip address as your vpn file

steel snow
#

otherwise we wouldn't be able to access it

#

ohhhhh

cloud urchin
#

2 devices with the same ip is going to cause problems

steel snow
#

reallyy, okay okay

#

thank you! i mean probably

#

that's probably closer so it will steal all the data?

#

is that correct kinda? or something

cloud urchin
#

traffic can only be sent to one ip, and you have 2 devices competing for the connection

#

that's where your connectivity issues come in

steel snow
#

interesting, thank you! i didn't know that my pwnbox uses the same ip

spark fox
safe star
#

It does

safe star
hybrid shuttle
#

Hey, I just got into the server. Actually I was seeking some help/guidance for the last segment of the Introduction to Assembly Language module. I am hard stuck solving a task. Am I allowed to showcase any pictures related to the content?

waxen totem
#

Any content above Tier0 shouldn't be posted, since Intro to Assembly Language is Tier 2, probably don't post anything showcasing the content, you can however ask questions

onyx kite
hybrid shuttle
# waxen totem Any content above Tier0 shouldn't be posted, since `Intro to Assembly Language` ...

Okay, understood.

So I was trying to solve the task where they ask you to decode the stack by xoring with the key kept in rbx register. I tried to follow the hint, arranged the code in the following way:

decode:
xor [rsp], rbx
mov rdx, [rsp]
add rdx, 8
loop decode

while executing its shellcode, it give a shell and immedietly exit after pressing enter. Well can't obtain the flag, in other words.

Can anyone help me with this, please?

waxen totem
hybrid shuttle
safe star
onyx kite
safe star
#

Yeah that’s probably why

#

Try getting a new tgt or make a pscredential

onyx kite
sinful narwhal
#

anyone please help me with this:

compile the ClientGuiTest.Java file in Exploiting Web Vulnerabilities in Thick-Client Applications
getting error

dry falcon
onyx kite
safe star
onyx kite
#

Thanks alot

magic anvil
#

@west canopy hey for the osint module theres 3 questions im stuck on. idk if u can help or anyone else?

novel galleon
#

#modules

Hello I've got problem with Module DCL ATTACKS II --> Spoofing --> SPN Jacking --> Last task - (Abuse Gabriel's rights <skip>)

I think that I've done everything properly.
I am able to list some of the directories from web01 but I can't see the flag on Desktop (Desktop is an empty directory).

Wham am I doing wrong, or maybe flag isn't there anymore?
Can anyone help me?

Screen below:
https://ibb.co/VY3kqSCW

magic anvil
#

hey can i dm u abt this?

storm elk
#

might help to tell people what module and section @fickle crystal

urban elk
#
  1. Don't spoil others.
  2. If it says it's incorrect, I guess it is incorrect.
  3. We have no idea which exercise you're talking about.
magic anvil
#

need help with OSINT: Corporate Recon
Cloud Storage: Investigate the website and find the bucket name of AWS that the company used and submit it as the answer. (Format: sub.domain.tld) Email addresses: What is the email address of the CEO?
Internal Leaks: Investigate the website www.inlanefreight.com and try to find any additional information that a file might contain and submit the found flag as the answer.

lime lake
ebon panther
#

I need help w understanding AI Red Team skill assess

chrome maple
ebon panther
#

can I dm u to tell u what I tried?

chrome maple
empty trout
#

hey i completed the password attack module but in the section password reuse /default password i skipped that bcz there was an issue with the vpn at that time and to answer that que i need to bruteforce creds of sam from privious section and now i see hydra need to be compiles again with libssh . then i tried medusa again i need to compile it with ssh module . so can someone dm me and give me the answer to the que

hot matrix
#

Hello guys I was doing one hack the box academy module I can't it's giving this error

autumn venture
#

Hello, I'm currently on module Kerberos Attacks -> Unconstrained Delegation - Users. I'm cloning the krbrelayx github repo to PwnBox then I run dnstool.py to add a fake DNS record "roguecomputer" pointing to PwnBox. (for whatever reason, I'm unable to retrieve the DNS record via nslookup). I also tried adding both hosts manually to /etc/hosts, <TARGET_IP> INLANEFREIGHT.LOCAL dc01.inlanefreight.local & <PwnBox_IP> INLANEFREIGHT.LOCAL roguecomputer.inlanefreight.local...I'm also able to successfully modify the SPN via addspn.py but when trying to run krbrelayx.py, the content of the module provides a hash to run it with, however, it's the hash of the "sqldev" account, while I think I should be adding the NTLM hash of the user that has Unconstrained Delegation, callum.dixon. Could anyone assist? Thank you!

empty trout
#

I solved that and i am facing issue solving that again so wanna need some help

#

Kind of truee btw

prisma cape
zinc mantle
#

Did you even get any further information on this? I am getting the same error

#

Hello All, I am currently working on NTLM Relay Attack: NTLM Cross-Protocol Relay Attacks.

Question: Use impacket's SOCKS server to hold NPORT's relayed connections and abuse them to access the MSSQL service at 172.16.117.60; query the 'flag' table within the 'development01' database and submit the flag.

However, I am getting the following error: [*] SMBD-Thread-128: Received connection from 172.16.117.50, attacking target mssql://172.16.117.60 [-] Connection against target mssql://172.16.117.60 FAILED: [('SSL routines', '', 'no protocols available')].

I have been struggling for over two days and would love some help.

I am running the command 'sudo ntlmrelayx.py -t mssql://172.16.117.60 -smb2support -socks --no-http-server' as sudo su - (Root). And then I have running sudo python3 Responder.py -I ens192/ ******************************* Please ignore sorted myself ****************** HINT be SUPERMAN

ebon panther
#

@twin sand

rustic sage
#

I was told to ask in here regarding a flag not working

#

Is anyone available to help me, I have verified I am submitting the string properly

#

Can someone on HTB Staff help me please.

dry falcon
rustic sage
#

@twin sand Can someone please help me with the platform not accepting a flag? I have 45 mins left on this target before I have to start again

zinc mantle
#

save the flag on your local machine. (Your VM machine)

#

and then check the formatting mate

rustic sage
#

I did

#

What now

#

Why was I told to ask in here when it appears there is no support available?

urban elk
quartz lagoon
#

and look at the stack for yourself, step by step

rustic sage
quartz lagoon
#

iirc you were taught to execute instructions one at a time in the debugger, right?

urban elk
#

but assuming that you got the previous sections already, it's probably not, since it's in the same format

rustic sage
#

Yeah I was on a roll

grim basin
#

I'm stuck on https://academy.hackthebox.com/module/113/section/1209
Drupalgeddon2 doesn't work on drupal-dev.inlanefreight.local; I get no command line output when I try to call to the .php page it creates
I also don't know how to get a login from drupal-dev so I can't do Drupalgeddon3
And on Leveraging the PHP Filter Module the PHP Code option does not pop up despite the module being on

#

So basically I can't answer the question of finding the flag despite all the methods that it gives to me

#

Nothing but drupalgeddon 1 worked but that only works on drupal-qa

#

I really hate whoever made this module guides that assume everything goes perfectly are so annoying

urban elk
#

I did that last week so I can tell you it's answerable. I didn't take notes though

cloud urchin
grim basin
#

No I do not

cloud urchin
#

i'd suggest re-reading the section then

grim basin
#

I do not think that's the issue

#

The issue is I do not know any other methods because I'm trying to learn