#modules

1 messages · Page 387 of 1

urban elk
#

X-Files :)

tranquil wren
#

no, i'm pretty old lol

tame wave
#

Authenticate to (ip:port) with user "admin" and password "admin"

  • 2 The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search, and use cURL to search for 'flag' and obtain the flag.
#

Is there something I can do to resolve the error?

#

Bug bounty path module 1 "http methods, GET"

acoustic owl
rain mountain
#

X files

#

Oh was already said..

tame wave
wild sage
#

Are you doing Web Requests?

tame wave
wild sage
#

That isn't a module name

#

Upper left hand corner should have the module name

tame wave
tame wave
lunar flicker
#

CWEE - Whitebox Attacks - Skills Assesment

Hi guys, someone manage to find how to get the hash merged with the salt for the user Larry?

If anyone can give me a hint I'd really appreciate it.

Thanks everyone.

wild sage
tame wave
#

Thanks

frigid bay
#

Please dont forget me

fathom pendant
#

don't reveal information about a skill assessment environment

misty current
#

What's the section link?

frigid bay
fathom pendant
#

consider anything you find for a skill assessment as a potential spoiler, since you had to dig for the upload file location, it's a spoiler

#

also consider that the web server is basically in the UK, so adjust for timezones

misty current
#

I remember seeing it, but I can't find it now

frigid bay
fathom pendant
#

just practice on the pivoting module sections with different tools

misty current
#

^

fathom pendant
#

i practiced double hops with ligolo-ng on the socksoverrdp section

#

the environment/module doesn't really care what tool you use

misty current
#

Also, try to find some blogs about pivoting, double pivoting as keywords.

fathom pendant
#

so long as you successfully do it

sick oxide
#

Hello guys sorry to cut you short I'm running through a problem and I can't seem to fix it,I'm new to this.
When I run
Nc -lnvp 9001 and open browser nothing happens and I'm connected to the VPN , I don't know what I'm missing or need to do please help

frigid bay
#

Nice guys

sick oxide
#

Alert

novel matrix
sick oxide
#

It's saying I don't have access

lusty thicket
sick oxide
#

I'm a noob to this things

#

Just looking for help

lusty thicket
sick oxide
#

Okay on it

lusty thicket
#

awesome!

sick oxide
upper ruin
#

Attacking enterprise networks
Lateral movement

#

apparently the domains are different, INLANEFREIGHT Administrator has access, however my domain is: ACADEMY-AEN-MS01

fathom pendant
upper ruin
#

my bad

upper ruin
#

Nevermind

upper ruin
#

I tried that

fathom pendant
#

no as in log out and then log back in

upper ruin
#

I will read around forums, been stuck for about an hour already, tried interaction with UAC and ways to bypass it

#

Ahh okay will do

fathom pendant
#

closing rdp != logging out

upper ruin
#

Well, I typed logoff in cmd and then logged back in.

#

No result whatsoever, will read around forums and will get back.

#

Trying with gpupdate

potent kelp
#

to open up a new terminal

#

and see if ur permissions work in the new session

upper ruin
#

Will do, ty.

#

Well, it did spawn me in windows/system32, alas access is denied.

potent kelp
#

DMs

upper ruin
#

Some guy in the forum wrote that gpupdate

#

Alrighty.

fickle sparrow
#

Nmap. Why is showing this error in every ip???

waxen totem
#

Probably because of connection issues, try swapping VPN to TCP

wooden perch
#

Hi all, I'm stuck for about 2 hours on this one - Windows Privilege Escalation on 'Other Files'. Sticky Notes it's not showing anything. Not able to find anything with 'bob_adm' string

#

OMG, just resolved.. was logged in as another user

#

this lab it's misleading haha

long hazel
#

Does anyone have problems with proxying nmap through burp

safe star
#

Why…

long hazel
safe star
long hazel
safe star
#

Did you set the proxy up correctly?

long hazel
#

Yea, it works with curl and metasploit but not with nmap

wooden perch
#

reload burp

long hazel
#

Still not working, I've been on this for about an hour, just gonna skip it

fathom pendant
lusty thicket
fathom pendant
#

But it'd really only work if you used http scripts

lusty thicket
#

nse scripts that support them

jaunty swallow
#

anyone managed to use ligolo for AD skillsassement 2?

my current network is as such
kali -> attack box -> foothold

attackbox runs ligolo client while kali runs ligolo server. I have trouble transfering huge files via http like sharphound to foothold.
I was looking into using smb server to do it but i cant seem to configure ligolo server to add a listener on attack box port 445 to my kali 445

fathom pendant
long hazel
fathom pendant
#

cleared with @jolly cradle
Looking to get help with understanding and moving forward with the Pentester path and need help with things here and there? I'm offering a paid program to assist with getting through the course, no guarantees of passing the cert exam.
As a brief note - this mentor/tutor program is about learning so:

  • No direct answers
  • More direct hints and help with solutions so that you can understand it better
  • scheduling 1on1 sessions via vc
    for info DM me
jolly cradle
#

Can confirm

fathom pendant
tired olive
#

typo in linux fundamentals - service and process management?

tired olive
#

oh thanks

#

sorry didnt know what erratum meant

fathom pendant
tired olive
#

yea i see now

lusty thicket
pseudo kiln
#

hey guys if I am already on silver anual can I still get a monthly platinum sub ?

#

or do I have to let it run out first ?

#

because I do not see any option on the academy platform to subscribe to monthly platinum

storm elk
#

You can only subscribe to one plan at a time

spiral sapphire
#

Good morning, I've been enjoying learning the fundamentals on the academy so far. Do I need to also learn programming for the more advanced modules?

waxen totem
#

If you follow a path it's got all you need

spiral sapphire
#

Okay, so it's not required? I have just been doing the basic modules so far.

pseudo kiln
#

The module authors always encourage you to go deeper and research on your own on topics,

pseudo kiln
fathom pendant
#

programming can help you build your own basic tools

spiral sapphire
#

Good to know, thanks. If I decided to learn basics is it Python?

fathom pendant
#

python is an easy one to learn

#

¯_(ツ)_/¯

spiral sapphire
#

Yes I figured, Python is mentioned time to time on the basic modules. That's why I asked. Thank you!

glass mirage
#

Hello guys I have a very specific question if anyone knows his business please dm me

fathom pendant
#

?

#

love the vagueness dude

storm elk
#

Crystal ball broken @fathom pendant ?

fathom pendant
storm elk
#

damn, mine is shattered to 1000000 pieces

fathom pendant
#

my orb has been pondered too long, need to go put it in one of those bowling ball cleaners

storm elk
fathom pendant
#

considering my recent project getting things set up; the pondering has been too long

storm elk
#

I'm sure you will be alright 🍀

fathom pendant
#

now i just wait prayge

simple sky
#

Hello, I'm reading "Windows Privilege Escalation Skills Assessment - Part I" "Find the password for the ldapadmin account somewhere on the system." need help with this question nothing seems to work i have tried "RoguePotate.exe, PrintSpoofer64.exe,LaZagne.exe, JuicyPotato.exe" all of them but no user with "SYSTEM" rights via "nc"

honest crane
autumn pilot
#

In the module another way (method) of taking advantage of that privilege was shown, if the potatoes don't work, try the other one

waxen totem
autumn pilot
#

Can't recall, but I assume it is due to just finding it humorous, probably following the same naming approach with the DirtyCow exploits etc

urban elk
#

hahah, I asked chatgpt the same thing the other day. I thought it had something to do with plugging glasses and mustaches on Mr Potatohead, given the "impersonation" angle. The bot thought I was cute for thinking that

spiral sapphire
#

Hey! I think something went wrong with my target? It's the "getting started" module and "nibbles" section. I was able to get the reverse shell from my target but when I tried again It's not happening. If I try to execute the php script by opening the URL on browser it will not open it's loading the page forever and nothing happens using curl?? Help

#

It worked before, not anymore.

young ore
#

And make sure nc is listening

spiral sapphire
#

Already did that

fathom pendant
#

With revshells it will be stuck loading

#

As it's connected to your system to execute the payload

#

Did you check your listener to see if it connected?

#

Do you have multiple vpns running?
Are you running the vpn and pwnbox?

spiral sapphire
#

Well, it's fine. I couldn't make it work so I just reset the target and pwnbox.

fathom pendant
#

¯_(ツ)_/¯

honest crane
#

This has to be the most stupid exercise in the path. What's the point of a brute-forcing exercise if you're gonna trottle me to death?

fathom pendant
#

Likely your networking settings throttling you

#

for some reason bridged networking bottlenecks you, NAT doesn't

pseudo kiln
blissful elm
#

i think this make modules much easier coz at first tiem it was nightmare for me to solve this module "information gatherring"

burnt hill
fathom pendant
blissful elm
#

it don't matter these flags are expired

fathom pendant
#

But yes information gathering module updated, so the flags don't match up in some sections

blissful elm
#

now question won't accept these flags

#

even if someone want to use them

fathom pendant
#

Also where are you getting the flags from? Since it's a tier 2 module

#

If it's the official writeup included with an annual sub, reach out to support

#

If it's some medium blog, then that's breaking ToS

blissful elm
#

no one in the world use light mode for htb except me

spare fossil
#

something is not adding up on the module Security Monitoring & SIEM Fundamentals/SIEM Visualization Example 4 , like a mistake, who do i report it to ?

fathom pendant
#

You can't change/update answers to sections you've already completed even if the answers no longer line up

blissful elm
spare fossil
blissful elm
#

so i only happen to information modules or with every modules

fathom pendant
fathom pendant
north frigate
#

Cheers everyone 🙂 Very quick question: I just enrolled for the Pen-Tester path and got the welcome-mail. That mail says, the path and certification are meant to bring you from beginner to intermediate Pentester. Did I miss something or is there also a path + certification for BEGINNER pentester? 😄

blissful elm
#

even after 1.5 year or some u still active here

fathom pendant
north frigate
fathom pendant
#

If you have 0 infosec knowledge, the information Security Foundations path is the pre-requisite

north frigate
fathom pendant
#

It goes through

  • networking
  • os basics (windows, linux)
  • command line basics
north frigate
#

(just no beginner cert then)

fathom pendant
#

While the info is dense: there are practical labs to help reinforce the reading

north frigate
blissful elm
fathom pendant
north frigate
fathom pendant
#

It's a multiple choice theory based exam

blissful elm
fathom pendant
blissful elm
#

hmm , i thought u meant u have to be a full dev first

north frigate
# fathom pendant CompTIA Security+

Thanks! 🙂 I took a look at that one, but just theory / multiple choice did really feel a LOT less valueable. Hmm. Looks like the OffSec OSCC is the only practical beginner cert currently. Maybe due to a reason ^^"

Okay, I'll continue the pentester path then 🙂 I just thought I'm skipping something here. Thank you all!

fathom pendant
#

I mean being a full dev wouldn't hurt

fathom pendant
#

It's why methodologies like footprinting are early on in the path

blissful elm
fathom pendant
#

*typically

#

But I'm not saying you have to, a knowledge of the code framework in use, like php, can be just as useful

blissful elm
#

you still learning or working now

fathom pendant
north frigate
# fathom pendant Trust me, the path teaches you from the bare minimum.

Thanks again 🙂 The courses looked very "beginner-ish" thats why I was confused about the mail telling me the path is "for getting from beginner to intermediate". I'm not working in this field, but I still want to build some good understanding and (ideally) some proof. Regarding the understanding, I'm convinced, HTB has the best content to get there. As for the proof I'm not sure whether CPTS cert is the right for me or whether it's "taking things too far" for someone who wants to widen his horizon 😅

wild sage
#

As someone who went through the CBBH path with no prior experience in web testing. I learned a lot

fathom pendant
glacial minnow
#

Hello i need help with attacking common applications module, section Discovering and enumerating WordPress, Im trying tyo find the plugin 3 worded) but i've gathered 3 that did not work, i've enumerated using curl, all the different pages, done wpscan with agressive mode but still nothing, tried loggin in the admin panel to retrieve the plugins from there, still nothing, can someone help me please? this lab is not properly working

#

if even the admin panel is not showing the plugin in question then this lab might not be setup correctly or has stopped working as intended

glossy cloak
#

loosing my mind here... cant enable selinux. its installed properly, changed the config file (enforcing, default/targeted), the grub file is also configured (quiet splash selinux=1 security=selinux) and more... tried in VM and pwnbox

wide wagon
#

question regarding .rhosts File:
The internet says it has to be like <hostname> <username> but the academy says its the other way around <username> <ip address> is this a mistake in the academy?

#

screen from academy

acoustic torrent
#

Can someone give me a clue on what the operating system is in the IDS/IPS evasion lab - easy, I believe I have found the answer, but no matter what format I put my answer in, it's giving an error message.

gray yacht
acoustic torrent
fathom pendant
sick meteor
#

Hello. I'm stuck on the 'Footprinting Lab - Medium' skills assessment. I've made it onto the target box with the RDP client and am attempting to open the mssql server management studio as administrator (based on the hint, right click run as admin) and its asking for admin credentials to do so. have i forgotten / missed something?

acoustic owl
fathom pendant
sick meteor
fathom pendant
#

you figured out the outside the box thinking huh

sick meteor
#

hahaha yeah. part of doing the modules is trying to foster a new mindset. will get there - one facepalm at a time

acoustic owl
#

Well, users are lazy. They like to use the same passwords everywhere 😉

sick meteor
#

and then some

fathom pendant
prisma flume
#

What this server for ?

#

Can anyone explain me

fathom pendant
prisma flume
#

I have a question can I ask in dms

fathom pendant
prisma flume
prisma flume
fathom pendant
#

<@&861185840277487616>

prisma flume
#

About how I can protect my account from hackers

fathom pendant
#

we cannot/will not hack a discord account/server for you

fathom pendant
#

basic rules of the internet

urban sage
fathom pendant
#

if a server has you go to a third-party website trust it with a grain of salt

sweet venture
#

I am lost brothers need help

fathom pendant
acoustic owl
sick meteor
fathom pendant
#

do you need a map and a compass?

sweet venture
fathom pendant
#

that's not something we can really help with lmao

#

pick something that interests you, and study it

#

¯_(ツ)_/¯

#

it's how i stumbled onto HTB

#

i was interested in hacking, and found HTB

acoustic owl
sick meteor
fathom pendant
#

now i've completed the pentester path and am offering (paid) services to help others through the path

sweet venture
prisma flume
urban sage
tiny frigate
#

not sure if this is the best place to ask, but I'm currently working through the Windows "Finding Evil" module, and learned about how to detect DLL hijacking using Sysmond with the calc.exe example.
What I don't get; how on earth would an Analyst (Blue Team) ever get the idea to look for Event ID 7, and specifically the calc.exe and one instance of an unusual because unsigned and oddly located (malicious) dll file?

In this scenario, would we assume that a user reported the odd behaviour of the calculator app at least?

prisma flume
#

How to stop that

#

I put passkey also

#

Please help

#

What I need to do

lusty thicket
#

nobody's going through sysmon logs for fun

urban sage
# prisma flume How to stop that

Don't let an attacker have access to your email. And if they have that, that's your first priority to get that out of. It's also not really on topic for this channel. You can send me a DM if you wish. ¯_(ツ)_/¯

tiny frigate
# lusty thicket nobody's going through sysmon logs for fun

lol, ok, thanks! Yeah I mean, I'm super slow anyway as a beginner, but it still seems oddly specific, not something I see anyone checking frequently.
So like "hey, whenever I open the calculator, I get this weird popup / my computer starts smoking", something like that?

prisma flume
#

@urban sage sir can I dm you please

chilly echo
#

.\SharpHound.exe -c All --zipfilename ILFREIGHT 2025-02-11T10:17:38.5109835-08:00|INFORMATION|Resolved Collection Methods: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote 2025-02-11T10:17:38.5266107-08:00|INFORMATION|Initializing SharpHound at 10:17 AM on 2/11/2025 2025-02-11T10:18:02.6047472-08:00|ERROR|Unable to connect to LDAP, verify your credentials
Module:Ad-Enum-Attacks , section:Privileged Access

lusty thicket
tiny frigate
lusty thicket
#

i gues you would be looking for known indicators then rather than randomly scrolling in hopes of divine inspiration

ocean night
#

@prisma flume reset password, enable 2FA, sign out others on the services. Check the service documentation.

lusty thicket
ocean night
#

This is a channel for discussion of Hack The Box Academy Modules

#

Please move to a more appropriate channel @prisma flume

prisma flume
chilly echo
ocean night
chilly echo
#

its seems there is a issue with ldap

lusty thicket
simple sky
# honest crane Try a Metasploit module (search for "Juicy"). Also, you need to figure out a va...

`msf6 exploit(windows/local/ms16_075_reflection_juicy) > exploit
[] Started reverse TCP handler on 10.10.xx.xxx:4444
[+] Target appears to be vulnerable (Windows Server 2016)
[
] Launching notepad to host the exploit...
[+] Process 2376 launched.
[] Reflectively injecting the exploit DLL into 2376...
[
] Injecting exploit into 2376...
[] Exploit injected. Injecting exploit configuration into 2376...
[
] Configuration injected. Executing exploit...
[+] Exploit finished, wait for (hopefully privileged) payload execution to complete.
[] Exploit completed, but no session was created.
msf6 exploit(windows/local/ms16_075_reflection_juicy) > sessions -i 1
[
] Starting interaction with 1...

meterpreter > getuid
Server username: IIS APPPOOL\DefaultAppPool`

I found the CLSID but it still failed pls help broSad_Squidward_Pepe

chilly echo
glacial minnow
gray yacht
glacial minnow
#

OK will do

glacial minnow
#

was i on something

#

but i swear they were getting flagged as incorrect

ocean elk
#

Hi am new here

brave prawn
#

Hey, any fix for [('SSL routines', '', 'no protocols available')] when relaying SMB over MSSQL? --no-http-server does not work for me. UPD: Fixed, just run as root with sudo su -

quartz jacinth
#

Hello im in the foot printing module for pop 3 and imap , when i connect using open ssl i dont get any response from server to my VM but the pwn box is working fine , any help?

fathom pendant
#

you also need to log in in order to issue commands

quartz jacinth
#

no not at the same time , when i saw it hang i used pwn box

#

how am i to login without connecting first?

#

login where exactly

fathom pendant
#

when it connects

#

1 login user pass

quartz jacinth
#

no resp to that sadly

fathom pendant
#

in another terminal ip a and see if you have multiple tun devices, or look in your openvpn log that should be running and see if it created a tunN device greater than 0

#

if so then you have multiple vpns running causing a conflict

#

otherwise i'd reach out to support

compact patrolBOT
rustic sage
#

I need to Send my ip ?

quartz jacinth
#

i am running express vpn on my windows machine because openvpn is banned in my country

fathom pendant
#

¯_(ツ)_/¯

fathom pendant
rustic sage
fathom pendant
#

clarity on your statement?

#

no one said to send your ip for anything?

#

<@&861185840277487616>

rustic sage
fathom pendant
#

this isn't a hacker4hire server

fathom pendant
elfin folio
rustic sage
fathom pendant
#

i'm just trying to figure out what you're on about

#

because your message literally came from nowhere about sending ip

#

lol

rustic sage
#

Accept me then

fathom pendant
#

?

rustic sage
fathom pendant
#

??

#

bro

rustic sage
fathom pendant
#

if you mean you can't chat in #general there's instructions in #welcome on how to do that

rustic sage
#

Say that then

fathom pendant
#

be less vague next time

#

ffs

#

how was i supposed to glean that you need help accessing general from "bro i'm not sending my ip"

pure jolt
#

Did you ever get an answer to this?

#

Did you ever get assistance with this question?

quartz jacinth
rain mountain
gaunt forge
#

any idea why bloodhound ce is so much worse than bloodhound legacy? I'm trying to use ce but the same built in queries return different results for no reason

still edge
#

hi guys im doing teh Metasploit framework module and i'm wondering in the module section if you found way to get the flag. i've got it with type and powershell Get-Content.

#

like were you able to find other way that those I tried to uploaded it with raven but didnt work well

fathom pendant
#

You likely missed something but I suggest avoiding spoiling the module as it's above t0

mighty drift
#

if someone know what's wrong

#

basically im able to have a normal session (so i can act, open shell etc...)

#

btw im trying this on a VM

fathom pendant
#

Weird that it's setting the listener to 0.0.0.0 but that's whatever

#

What module is this for?

mighty drift
fathom pendant
#

What academy module, do you mean the windows privilege escalation module?

mighty drift
#

oh yes im sorry

mighty drift
#

i used many like uabhelper

fathom pendant
#

Deleted your message as WPE is above tier 0

mighty drift
#

but many doesnt seems to work even if local_exploit_suggester told my it can work

#

wich is weird

fathom pendant
#

¯_(ツ)_/¯

#

No session typically means that it couldn't connect to your listener

#

Try specifying lhost as your tun0 ip

mighty drift
#

im running on nat so i better just use publlic ip

#

instead of interface cause tun0 will sepcify local ip

gaunt forge
lusty thicket
gaunt forge
#

thank you

acoustic owl
gaunt forge
# acoustic owl

whats that on the left? i just cant access it with firefox

gaunt forge
#

thanks g0blin

ocean night
#

no worries nathans

#

😅

gaunt forge
#

really explained it all well yk lmao

acoustic owl
#

For all pages that you do not want to open in your browser

ocean night
#

Noice

burnt hill
upper ruin
quartz lagoon
upper ruin
#

Thanks guys

#

1 thing left to do...

silk anchor
wooden perch
rugged bolt
rugged bolt
#

I'm currently working through the last question on /module/112/section/1069 which is find the FQDN of the host with the last octet of x.x.x.203

I've ran DNSenum and found several domains hosted on other hosts but can't find the x.x.x.203 host. the hint was to use other word lists, I have tried several of the lists located in /opt/useful/seclists/Discovery/DNS folder, as well as rockyou.txt. I'm assuming I'm overcomplicating and passing over something simple, can anyone offer a hint if they've recently done the same module?

Worth mentioning I've also done zone transfers to reveal IPs but x.x.x.203 isn't one of them.

silk anchor
rugged bolt
#

Okay this is in the footprinting module/DNS section

silk anchor
rugged bolt
#

I appreciate it I did try with that list, returned some results but not the host im looking for. however I will triple check to be sure. thanks!

silk anchor
#

I'm looking at my notes and that is what I used. Maybe the rest of the command is wrong.

#

What domain name are you running it against?

rugged bolt
silk anchor
#

Do a dns zone transfer with dig against the main domain then run dns enum against the results. There is one that is more interesting than the others.

rugged bolt
fickle crystal
quasi wave
#

which is a better tool for cracking FTP: medusa or hydra?

#

I need a recommendation because I am doing the Easy Lab for the Attacking Common Services Module and tried playing around with medusa and it isn't working.

wild sage
#

Medusa and Hydra are pretty much the same tool

rugged bolt
#

I haven't been through that module yet, however I usually use hydra for brute forcing.

quasi wave
#

why did medusa not work for me? I set it to try every username and password in the username and password list provided in resources and it gets to like the 79th password of the first user and then it throws a 550 error and quits

#

will hydra work better potentially?

#

was it an issue with the server?

#

I need to log into the server and get the flag and have found via nmap that FTP port is open and it is vulnerable to FTP attacks

lusty thicket
#

it's vulnerable to ftp attacks

earnest pasture
wild sage
#

I've personally only used (known) about Hydra

quasi wave
#

the module introduce me to both

wild sage
#

Until Login Brute Force module

rugged bolt
#

I think there's also a nmap script ftp-brute you can also use.

wild sage
#

There is, but Hydra is a lot more powerful

feral adder
#

is the module from cbbh if completed are also credited to the percentage of cpts?

dark hedge
#

completing overlapping modules will count progress toward their associated paths

#

so completing Login Brute Forcing will count progress toward Penetration Tester, Bug Bounty Hunter, Basic Toolset, etc. paths

old bolt
#

Super stuck on http attacks assessment. Could anyone help with a nudge? I have bypassed waf via the hint, however I can't get a payload to work.

merry crescent
#

How do I use cURL to obtain the source code of a website and then filter all unique paths of the domain?

real delta
merry crescent
#

Yes, I am stuck on the Linux Fundamentals Module. I wasn't sure which channel to post on for help.

real delta
waxen totem
#

Oh yah thats a tricky one

#

Using the filters mentioned:
curl https://www.inlanefreight.com > temp.txt && cat temp.txt | tr " " "\n" | cut -d"'" -f2 | cut -d'"' -f2 | grep www.inlanefreight.com | sort -u | wc -l

there's an easier way to do this but REGEX is the next module so...

said regex:

curl https://www.inlanefreight.com | grep -Eo "www.inlanefreight.com[^'\"]* | sort -u | wc -l"

fathom pendant
#

but people don't like to use the search feature

waxen totem
#

Yeah I just looked for my prev message regarding it

#

Istg this question should be made easier somehow seeing as its in a fundamentals module

fathom pendant
#

it should be placed after regex imho

waxen totem
fathom pendant
#

they simplified/clarified the question, at least

waxen totem
#

Hekkin love regex golf though

merry crescent
waxen totem
#

just wait for it

merry crescent
#

I got this error:
curl: (28) Failed to connect to www.inlanefreight.com port 443 after 132769 ms: Couldn't connect to server

waxen totem
#

do it from pwnbox

#

or with academy vpn active

feral adder
#

hello guys is there a way to encode the base64 into ascii hex code? its kinda hard to use zaproxy because the encoder is not complete

lusty thicket
fathom pendant
uneven lichen
#

Has anyone done the "Using CrackMapExec" module recently? I'm finding that most of the sections dealing with proxychains seem broken. I'm finding that certain applications (particularly python scripts) don't work over proxychains while other applications have no problem and I can pivot using them without issue.

waxen totem
#

Crackmapexec is outdated I'd recommend looking at the equivalent commands for netexec

uneven lichen
#

Yea I had to use the latest nxc to fix one of my issues

#

Python script just fails to connect, I've tried several different scripts

waxen totem
#

Is the dc01 host in your hosts file under its internal ip add?

wooden perch
#

thank you, was stuck here too. this helped a lot

autumn pilot
#

Try running proxychains with sudo

uneven lichen
uneven lichen
#

I've been banging my head for 4 hours on this

waxen totem
#

Prolly some port open shennanigans

fathom pendant
#

also cme > t0 so spoiler

#

if you really wanna know; sudo strace <command> shows you the raw instructions

upper ruin
upper ruin
fathom pendant
feral adder
#

Anyone can nudge me I'm having a little bit of hard time in skills assestment of web proxy I'm stuck in cookie bruteforcing

upper ruin
fathom pendant
upper ruin
#

Also a a part of the web exploitation

fathom pendant
#

only one was something not taught

upper ruin
#

Infogathering did myself as well

upper ruin
fathom pendant
#

?

feral adder
fathom pendant
upper ruin
#

Oh

#

Well idk what wasn't

fathom pendant
#

one of the web related ones

upper ruin
#

Lemme see real quick

feral adder
fathom pendant
sinful narwhal
#

anyone help me on - Linux Privilege Escalation > Miscellaneous Techniques

Error: ./shell: ./shell: cannot execute binary file

feral adder
upper ruin
feral adder
#

I put the 0 - Z on a payload together with the 31 characters then I select the cookie and then bruteforce after the result the flag still not showing

fathom pendant
#

the process is the same, run the wordlist; re-encode in reverse order ¯_(ツ)_/¯

#

you also need to set the prefix to the decoded value

#

and you replace the WHOLE cookie

fathom pendant
#

chill you just asked

sinful narwhal
#

i'm in lab

feral adder
#

Is it okay to send a picture of payload here together with the processor option?

fathom pendant
#

@upper ruin said they'll dm
my dms are currently only open to field clients that want to pay for tutoring/mentoring services for the pentester path

upper ruin
#

Well

#

I have every module documented with screenshots on solutions.

fathom pendant
#

same

upper ruin
#
  • writeup for each skills assessment in the path
fathom pendant
#

i'm offering tutoring because why do for free what i can get paid for

upper ruin
#

Just gotta do AEN writeup.

fathom pendant
#

no

upper ruin
#

Ok

fathom pendant
#

i've already completed the path

#

i don't need someone else's notes and writeups

upper ruin
#

Sounds good

fathom pendant
#

my stuff is organized in a way that works for me

upper ruin
#

Ah, fair.

#

I just realised my .zip Htb folder is about 600 megabytes

fathom pendant
#

i just use obsidian to organize my stuff

upper ruin
#

1 sec

upper ruin
#

Just search a bit around the /var/nfs/general directory 👀

honest crane
upper ruin
#

Same

sinful narwhal
upper ruin
#

Oh.

fathom pendant
upper ruin
#

^

fathom pendant
#

examples aren't always instructions

upper ruin
#

Especially in these few sections.

sinful narwhal
#

got it

upper ruin
#

Tbh I'd say they are a way of persistence.

sinful narwhal
#

it didn't worked as planned

dusk yarrow
#

Any hint for the fuzzing module, recursive fuzzing flag.

fathom pendant
dusk yarrow
#

I set it to 10.

upper ruin
#

You have about 5 seconds to get the flag, so you gotta have script prepared.

sinful narwhal
dusk yarrow
#

I'm gonna change it now

#

To 5

fathom pendant
#

just make sure you start from the right endpoint iirc it gives you an endpoint to start at

dusk yarrow
#

It just keeps on scanning, i scanned it for like 15 minutes.

lusty thicket
dusk yarrow
honest crane
autumn sun
#

hi

#

@autumn pilot hello im sorry to bother you can i ask you for assistance?

fathom pendant
autumn sun
#

not too much thought i wanted to know more about cyber sec

acoustic owl
autumn sun
#

i have done like 3 box

fathom pendant
autumn sun
#

okay sorry

#

what is a module in this context?

fathom pendant
autumn sun
#

i tried to do my thing it did not work

fathom pendant
#
  • Path: a curated collection of modules that serve the overall goal of the path name
  • Module: A set of labs and reading with the overall goal of understanding the module name
  • Section: the individual pages/parts of a module with the goal of teaching a small part of the overall Module topic
autumn sun
#

i know it is not technically secure but if u want to hack my htb aacc go ahead

#

i mean link to discord

#

its okay

#

i know what i did

fathom pendant
#

not smart to leak your account token dude

autumn sun
#

why

urban elk
#

it's ok, he knows what he did

autumn sun
#

they will take my account of nothing

#

i cant even use it

fathom pendant
#

it's just general internet safety

autumn sun
#

they can if i cant im nice

fathom pendant
#

and you can use it you're likely being dumb

autumn sun
#

LMAO

#

maybe

fathom pendant
autumn sun
#

yeah

#

i think what ghappend was i was muted 3 years ago

#

because i said something against the guidelines

fathom pendant
#

/verify has the bot dm you
/identify <account identifier> runs it in the server

pseudo kiln
#

Question regarding hydra and virtual hosts. Is hydra "smart" enough to understand and attack a vhost when you point it to one, or do I need some extra syntax ?

for example

hydra -f -L users.txt -P passwords.txt support.example.com -s 80 http-post-form '/login.php:username=^USER^&password=^PASS^:F=Invalid'
fathom pendant
autumn sun
#

brute

#

fake

#

i will try

lusty thicket
fathom pendant
#

anyway; this channel is for module content not troubleshooting user error for not getting your account identifier working

pseudo kiln
lusty thicket
fathom pendant
autumn sun
#

WHAT MODULE

#

what of what

fathom pendant
# autumn sun WHAT MODULE

i'm not repeating what i stated earlier, i suggest reaching out to a moderator (shield icon) in dms

autumn sun
#

my bad u must be busy

fathom pendant
#

i'm not a moderator

#

so i cannot help you with that

autumn sun
#

im asking u as a human

fathom pendant
#

bud

#

i explained what academy modules are

#

if you were; then that's not my problem

#

nor is it anyone in the server's problem

autumn sun
#

im okay im just saying

#

im trying to get my general chat to work

fathom pendant
#

sorry that happened to you, but being serious it's not anyone's business

autumn sun
#

okay?

#

im just giving u context so u can have a chance to understand

fathom pendant
#

@pseudo kiln if you replied you may have gotten caught up in the cleanup; sorry

pseudo kiln
#

aha yea seems to be, this was the reply anyway
login bruteforcing module. I am doing ||AEN blind||, there are many vhosts and I was wondering if hydra can understand a vhost when you point it to one, and as you said it seems to be handling it fine, thank you 🙏

fathom pendant
#

ah, yeah

#

hydra sends the request with the header as specified (also if it's on default port 80, you don't even need to specify the port)

#

the http-post-form and stuff implies http

spiral sapphire
#

Hello! I've got a problem with the Windows Fundamentals module. I'm testing the connectivity from the Pwnbox terminal using smbclient, as instructed. I will get the following error message: "do_connect: Connection to 10.129.130.130 failed (Error NT_STATUS_IO_TIMEOUT)" Does someone know how to get it to work?

autumn sun
#

lots of censorship

#

what have u tried to do ?

#

hmm why did it timeout?

fathom pendant
spiral sapphire
#

I copied this command from the module: "smbclient -L SERVER_IP -U htb-student"

fathom pendant
#

and assuming the 10.129.130.130 is the spawned target IP

spiral sapphire
#

Correct

autumn sun
#

did u add the thing to ur dns list

fathom pendant
#

try:

  • respawning target
  • changing vpn region
  • changing pwnbox region
fathom pendant
#

any 1 or combination of those

real delta
fathom pendant
#

make sure you're also not running the vpn on your own system

autumn sun
#

idc about general anymore

lusty thicket
#

you never cared about general 😭🙏

spiral sapphire
#

Could you teach me the timeout flag,? I will try that, thanks.

autumn sun
#

bro acting like she didnt click to view the message

real delta
#

it's what I use for smb stuff instead of smbclient unless I need to use smbclient

fathom pendant
real delta
spiral sapphire
real delta
#

smb://ip

fathom pendant
slate zinc
#

on some shells u need to escape the /

fathom pendant
fathom pendant
spiral sapphire
#

Guys, I'm getting even more confused. 😄

slate zinc
#

after all these years still mess up \/

spiral sapphire
#

I guess it's just broken.

fathom pendant
#

also make sure you're not running the vpn on your own system while using pwnbox

spiral sapphire
#

I'll try to respawn the target. Not running the vpn on my own system currently.

fathom pendant
#

just wanted to make sure because that is a common issue people have with connectivity

spiral sapphire
#

Got it, I only have the vpn file on my VM if I'm running that. Since I'm running Pwnbox I don't have my VM launched.

fathom pendant
#

👍

spiral sapphire
#

Again, with a new target!! "do_connect: Connection to 10.129.96.27 failed (Error NT_STATUS_IO_TIMEOUT)"

autumn sun
#

okay bro

#

maybe u should uninstall

#

u ever suck at something ?

fading olive
#

Hello I'm doing the section: Attacking Common Applications > PRTG Network Monitor.
I've managed to create the notification which created a user prtgadm1 with password Password123 and when I run the command:
nxc smb 10.129.201.50 -u 'prtgadm1' -p 'Password123'
It returns:
SMB 10.129.201.50 445 APP03 [+] APP03\prtgadm1:Password123
Which is a sign that the user has indeed been created. Now the section says to use psexec, wmiexec or evil-winrm, and I've tried each of them and they all seem to authenticate successfully, but don't yield a shell:
psexec.py prtgadm1@10.129.201.50
Impacket v0.11.0 - Copyright 2023 Fortra
Password:
[*] Requesting shares on 10.129.201.50.....
[-] share 'ADMIN$' is not writable.
[-] share 'C$' is not writable.
Am I not running the wmiexec, psexec or evil-winrm commands correctly?

sinful narwhal
#

help me on - Linux Privilege Escalation > Shared Libraries

issue is i'm getting this file - /usr/bin/openssl and payload not working with it

urban elk
spiral sapphire
real delta
urban elk
#

missing something there

autumn sun
#

try it fr

fading olive
real delta
autumn sun
#

why do u care

#

do u have a box to root?

#

or something

acoustic owl
# autumn sun why do u care

Last warning!
Stop harassing other users. If you need help verifying your account, contact a mod of your choice via DM

urban elk
#

starting to think we can get notifications of scammer bots by the use of capitalised "Mate"

#

do not open that "guide", @sinful narwhal

sinful narwhal
#

just ignored

fading olive
# urban elk missing something there

I tried again with the correct command and yet I still can't connect.
I get the same behavior, where the command succeeds in authenticating but doesn't give me a shell.

urban elk
#

does netexec now show "(Pwnd!)" next to your user account ?

fading olive
urban elk
#

ok, that means it still isn't a local admin. Something must still be off with your payload

#

the content is not crystal clear on this. Make sure you have the payload as described, and nothing more

jolly widget
jolly widget
#

it is right channel to talk about modules right..?

waxen totem
#

It's the right channel yep

silk anchor
sinful narwhal
#

help me

jolly widget
fathom pendant
silk anchor
jolly widget
#

no

fathom pendant
sinful narwhal
fathom pendant
silk anchor
# jolly widget no

You need to be logged in, Read the start of the footprinting section again.

fathom pendant
sinful narwhal
fathom pendant
#

🤔

sinful narwhal
#

yes

fathom pendant
#

Ah ok, not shell

sinful narwhal
#

i men i compiled it and

fathom pendant
#

I don't remember compiling a so file

sinful narwhal
#

no it was a C file

fathom pendant
#

Well yes, you compile it into .so, it's been a hot minute

#

I just utilized gtfobins method instead of preload

fathom pendant
sinful narwhal
fathom pendant
#

i didn't use LD_Preload

#

instead i used the in-built load library option

tropic ether
#

Welp guys Idk what am I doing in CTF 😭

fathom pendant
tropic ether
#

Ok 👍

daring cliff
#

Introduction To Splunk & SPL

Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.

i think have a correct request spl but i have no results

modest lichen
#

hey guys , am stuck at the intro to digital forensics skills assessment , question 1 , I've used the Windows.System.VAD and tried to search in the results file for the process but it dind't seem to work. any hints please

worldly badger
#

Guys how can i use EyeWitness with list of vhosts???

#

Is it possible?

hoary moat
stray pilot
#

{ HTTP ATTACKS -> HTTP RESPONSE SPLITTING }
Heyy friends, I figured out xss part and i try to send to /?admin but everytime i send it, it returns me the request for /?admin with empty log, really could use some help here T_T

pseudo kiln
#
mysql -h <host> -u <user> -p'<pass>'  --skip-ssl-verify-server-cert                            
ERROR 2013 (HY000): Lost connection to server at 'handshake: reading initial communication packet', system error: 11

any idea what to do about this error ? It's through ligolo, typically the --skip flag solves it but not this time.... And the target does not have mysql binary installed so I can only check through the pivot

gray yacht
young ore
modest lichen
pseudo kiln
young ore
modest lichen
sleek grove
#

Hello, are there any French people to help me?

#

Mp me

gray leaf
torn cairn
#

Hello!
I'm currently finishing this module, however on the Skilss Assessment I get stuck. I know where to try my injection, however I can't get any injection to work. I tried multiples but none worked.
If someone can help me?
Thanks a lot!

grim basin
zinc mantle
#

does any know of a module that can be used to map a network?

glossy cloak
fathom pendant
#

I haven't messed with SElinux

fathom pendant
glossy cloak
fathom pendant
#

It's not required

#

So i didn't mess with it

glossy cloak
#

Yeah, you dont get cubes, its an exercise… i dont know how much is selinux used “IRL”

fathom pendant
#

It can be used quite a bit, it's just not necessary to set up

glossy cloak
#

Then I want to practice. To begin with practice, I have to enable it first, right? Lol

dusk yarrow
#

Hey

sleek grove
#

Hello , are there any french guy to speak or explain me something

near raven
#

Regarding what?

urban elk
#

<@&861185840277487616>

gray yacht
#

lol

fathom pendant
torn cairn
#

Hello!
I'm currently finishing the Whitebox Pentesting 101: Command Injection, however on the Skilss Assessment I get stuck. I know where to try my injection, however I can't get any injection to work. I tried multiples but none worked.
If someone can help me?
Thanks a lot!

storm elk
torn cairn
storm elk
#

Feel free to dm me

#

Tell me everything you tried

fathom pendant
#

Glyph cache, refresh the page

quartz lagoon
sleek grove
fathom pendant
#

Lots of research and practicing

pseudo kiln
#

has anyone ever had issues with getting a reverse shell through docker container ? like bind shells work, but not reverse shells

acoustic owl
#

Docker containers may not have access to other networks. This means that a reverse shell is not possible either.

lusty thicket
#

run as root

#

or manually forward ports

pseudo kiln
pseudo kiln
lusty thicket
#

you don't have to be root to get a revshell

#

you haven't set up networking properly

pseudo kiln
#

I did, I did this a million times, but this time when I do it through docker it does not work

lusty thicket
#

prove it's not a network issue

#

and try to ping your machine from this container

pseudo kiln
#

sadly all machines have ping disabled

#

the container does not even have ping lmao

lusty thicket
#

use netcat or curl instead

pseudo kiln
#

yeah curl works, is how I downloaded ligolo agent

acoustic owl
#

But then a reverse shell should also be possible.

pseudo kiln
#

from the container yes, not from the target near the container

#

however bind shell was possible on the target near the container

#

on ligolo I did listner -add 0.0.0.0:9002 --to 0.0.0.0:9002 --tcp which typically always works for me

lusty thicket
fading olive
feral patrol
#

Could someone help me please. I'm stuck on the Wi-Fi penetration testing basics: Airdecap-ng

paper gust
#

What was your command?

#

token length exception would seem to indicate that you've selected the wrong mode or the hash is formatted wrong

#

sure, but what's your hashcat command

burnt hill
#

sudo hashcat -m 170 found-hash.txt /usr/share/wordlists/metasploit/ipmi_passwords.txt

#

I tried different password files

fathom pendant
#

@burnt hill don't paste hashes; spoilers

fathom pendant
#

170 is sha1 with utf16 little endian encoding

burnt hill
#

so, ipmi has its own type of hash?

fathom pendant
#

correct the module i believe mentions the correct mode to use as well

#

yep did a quick search of the reading, and it is mentioned

burnt hill
#

in the module when using metaesploit gets the user and the password in plain text, but when I run the ipmi_dumphashes I get the user in plain text and a hashed password

#

I tried to crack it whith hashcat and John, but no success

fathom pendant
#

Flow should be
Given wordlist->rockyou

burnt hill
#

I used this one as well, but as you told me before, my mistake should be that I used 170 for sha1 instead of the ipmi on, but I don't know how to guess the number for ipmi

fathom pendant
#

1; the module reading gave you the correct mode
2; example hashes on the hashcat wiki is your friend

burnt hill
#

I am gonna re-read the module and check the hashcat wiki

#

thanks

remote fulcrum
#

Question about the module "Password Attacks", Section "Credential Hunting in Linux", at the Question, do they expect me to somehow "hack my way in" again? I mean they do not give creds.

burnt hill
remote fulcrum
woeful lake
#

Hi, i have no clue how to continue on Ad module skill assesstment 2 Q4, use a common method to obtain a weak credential...
I try everything i know but not working

woeful lake
#

I need to have a list of user rigth? to do that

earnest pasture
woeful lake
#

Now i get it, i miss something important

#

ty thoug

remote fulcrum
#

Shameles bump: Question about the module "Password Attacks", Section "Credential Hunting in Linux", at the Question, do they expect me to somehow "hack my way in" again? I mean they do not give creds. The htb-student creds also dont work.

fathom pendant
#

ftp is better to brute

remote fulcrum
#

Thank you for the feedback/hint.

fathom pendant
#

though if you wanna speed up; the hint can help a lot

remote fulcrum
sinful lava
#

The windows event logging basics. Trying to find another way to gain access to the event viewer logs without Windows 10 Pro. Anyone have a work around?

lusty thicket
#

or just rip those logs out of the filesystem

ocean night
#

Please read the channel subject before sharing anything pertaining to modules.

rustic sage
#

I didn't even mention the module name 😢

#

that came off like more of a general ques

#

resolved!

naive cedar
tribal beacon
#

Not seeing where I can view my favorite modules list...I must be going blind? 🙂

waxen totem
#

You should see it at the bottom of your dashboard, if you have a path enrolment active it'll be below that

tribal beacon
#

got it. thanks!

dusk yarrow
#

Hey

#

I've added a academy.htb in the hosts file.

drowsy raptor
#

Which module is this?

dusk yarrow
#

Web Fuzzing

#

Now I've fuzzed a sub domain which is admin

#

So it's admin.academy.htb

safe star
#

Why didn’t you just say that to begin with

dusk yarrow
#

But the thing is if you ping academy.htb it works. But if you ping admin.academy.Htb

#

No packet send or receive.

safe star
dusk yarrow
lusty thicket
dusk yarrow
dusk yarrow
safe star
#

Did you add it to your hosts file?

real delta
safe star
#

It’s not a dns record

dusk yarrow
dusk yarrow
#

😳.

safe star
dusk yarrow
#

Yes there's a vhost section

dusk yarrow
safe star
dusk yarrow
#

What would be the IP of it?

#

Same ip?

dusk yarrow
#

But that doesn't make sense. 😑

safe star
#

did you read the second line of that section?

dusk yarrow
#

Isn't it?

#

😑

dusk yarrow
#

Which second line

safe star
#

im actually confused tho, how did you do the vhost section?

tight seal
#

Hiiii

dusk yarrow
#

I'm confused too. But I was able to find the flag though.

safe star
dusk yarrow
#

Web fuzzing is a critical technique that every penetration tester should master. Unlike traditional methods that rely on predictable inputs, fuzzing systematically explores the vast input space to uncover hidden vulnerabilities, often revealing weaknesses that would otherwise remain unnoticed.

#

second line from above?

safe star
#

?

#

the section i mentioned

tight seal
#

I am stuck at the alert machine of htb and don't know what to do further can anyone help me

tight seal
#

It would be a great help

safe star
#

Virtual hosting enables multiple websites or domains to be served from a single server or IP address.

tight seal
#

I don't have access

dusk yarrow
#

Huh 😑

lusty thicket
dusk yarrow
#

But but but 🥲

real delta
safe star
#

stop skipping

tight seal
#

Still no access buddy

dusk yarrow
#

Even I was discussing about even on a voice room with some one here.

#

I was confused about vhost

#

That person explained.

#

Explained well.

#

But I forgot or something.

waxen totem
dusk yarrow
#

I'm gonna hack you 😈

lusty thicket
safe star
#

fuzz his subdomains

lusty thicket
dusk yarrow
#

💀Btw command still not working for some reason.

safe star
#

did add it to your hosts file?

dusk yarrow
#

Yeah.

waxen totem
#

show hosts file

dusk yarrow
#

Wait let me check.

#

" GNU nano 7.2 /etc/hosts

/etc/hosts: static lookup table for host names

#<ip-address> <hostname.domain.org> <hostname>
127.0.0.1 localhost.localdomain localhost
::1 localhost.localdomain localhost
127.0.1.1 blackarch.localdomain blackarch
83.136.253.28 academy.htb
83.136.253.28 admin.academy.htb

End of file"

#

here it is

waxen totem
#

you can add em on the same line separated by a space

#
83.136.253.28   academy.htb admin.academy.htb
dusk yarrow
#

How do you make that box? In text?

#

How

waxen totem
#

god damn it

waxen totem
#

discord XD

#

using back ticks

dusk yarrow
#

Okay

#

Hey my thing still not working 😭

#
  GNU nano 7.2                                                  /etc/hosts                                                             
#
# /etc/hosts: static lookup table for host names
#
#<ip-address>   <hostname.domain.org>   <hostname>
127.0.0.1 localhost.localdomain localhost
::1                 localhost.localdomain       localhost
127.0.1.1 blackarch.localdomain blackarch
83.136.253.28   academy.htb admin.academy.htb
# End of file
#

It's Workin

drowsy raptor
#

why does it matter lol

#

we can still see the content

dusk yarrow
#

It looks good 🙂.

safe star
dusk yarrow
#
>>> ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://admin.academy.htb:58405/admin/admin.php?FUZZ=key
zsh: no matches found: http://admin.academy.htb:58405/admin/admin.php?FUZZ=key
#

Look at this.

#
ffuf -w /opt/useful/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://admin.academy.htb:PORT/admin/admin.php?FUZZ=key

actual command in module 😄

drowsy raptor
#

it should be in one line

dusk yarrow
#

It is in one line.

drowsy raptor
#

doesn't look like it, zsh is trying to interpret the target as a command

waxen totem
#

put le url and le wordlist directory in le single quotes: '

dusk yarrow
waxen totem
#

Your terminal is attempting to parse what it thinks is bash or zsh language or something

acoustic owl
#

the modules are often structured in such a way that you cannot replay them 1:1, but the modules show you the way and you then have to adapt the commands to the lab

lusty thicket
autumn pilot
#

Try using single or double quotes around your parameters

dusk yarrow
#

So what's the solution?

lusty thicket
#

switch to bash

dusk yarrow
autumn pilot
#

apart from not using arch you can

Try using single or double quotes around your parameters

safe star
#

zsh4life

drowsy raptor
#

ffuf -w "/opt/useful/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ" -u "http://admin.academy.htb:PORT/admin/admin.php?FUZZ=key"

dusk yarrow
#

Hey yoooo This is not my file location btw.

drowsy raptor
#

then adjust it

safe star
#

please change the file location for him

dusk yarrow
#

No, I did it myself

#

Btw the command ran. But 🥲🥲🥲🥲🥲

#

It didn't find anything.

safe star
#

you have errors

bright coral
#

you need to replace PORT with the actual port

dusk yarrow
#

Ayooo 😅😅😅 bruh. Nice one though.

#

Okay it's scanning.

#

Thanks y'all so much.

#

I Appreciate it.

#

❤️

lusty thicket
#

yeah, you're welcome buddy

safe star
#

Awesome

lusty thicket
#

awesome stuff

storm elk
#

Don't threaten people @dusk yarrow

dusk yarrow
#

I was kidding. 🙂 I'm a noob what do you mean ?

#

I barely can fuzz 😅.

storm elk
#

Fuzz harder kek

dusk yarrow
#

Deeper also

storm elk
#

Behave

#

Don't act like a 10 yo

dusk yarrow
#

Alright.

#

I'm gonna go study now.

storm elk
#

have fun

dusk yarrow
#

Personality development?

rustic sage
#

No, i deleted!

#

soz

dusk yarrow
#

Nice 🙂👍

lunar flicker
#

Good morning guys, can anyone give me a hand with CWEE - Advanced deserialization XML and Binary?

storm elk
#

I was gonna say

#

open your eyes kek

waxen totem
#

I should really wear my glasses

storm elk
#

😎

lunar flicker
lunar flicker
#

But not working

#

Okay, thanks!

#

And open your eyes @waxen totem hahhahah

#

joking!

storm elk
heady estuary
#

I believe I am successfully connecting to the VPN using openvpn. I am using a linux desktop. but I can't ping anything. I'm not closing the terminal window running the VPN connection, I am opening a new one.

I don't have any other VPN or process running but after "initialization sequence completed" I have 3 more lines. they are:
1)" Data Channel: cipher 'AES-256-CBC', auth 'SHA256', peer-id: 1, compression: 'lzo'"
2) Timers: ping 10, ping-restart 120
and 3) Timers: ping 10, ping-restart 120

bronze wind
#

I need a help with the flag on bugbounty course, web requests topic. The question is "The exercise above seems to be broken, as it returns incorrect results. Use the browser devtools to see what is the request it is sending when we search and use curl to search for flag and obtain the flag". Anyone who has worked on this please help

heady estuary
#

I had to manually enable ipv6

brisk ingot
#

is there a reason the xfreeedp machines are so slow? when i try to xfreerdp they crash

waxen totem
#

Have you tried swappng to TCP vpn?

brisk ingot
#

Is there a general problem with HTB machines?

waxen totem
#

Not that I've experienced, aside from slow-ish spawn times they run pretty well. Also target machines have timers, they terminate after 90m iirc, there's an option to extend that time once the target is spawned.

brisk ingot