#modules

1 messages · Page 389 of 1

candid juniper
#

Yo, thanks a lot for your help. Eventually, swapping locations, downloading a new config file & refreshing the browser got it to work!

empty trout
#

in module attacking common services in attacking smb . in solving the questions we have null session and we can read id_rsa of a user in a smb share when i was downloading the private key it failed and when i did with a user credential it downloaded i was thinking maybe null session only have read access on the private key that was the reason but the user i logged in only have read permisson on private key so didnt get it why it happend

harsh swan
#

Please help with Module: API Attacks / Section: Broken Authentication, I'm stuck on it... I managed to get the password changed and logged using the new credentials, then I tried to retrieve the information that is needed to get the flag and I got "Unauthorized" as response...

fathom pendant
empty trout
#

but it downloaded

fathom pendant
#

¯_(ツ)_/¯

#

could also be disallowed for guest users

#

or some other reason

empty trout
#

yeah thats the only possibility

#

they said in the section that if no shares are writable we can use smbexec but smbexec also need a way to write the payload

red shuttle
#

Hi!
having strange problem from recent days
connecting to labs using vpn as usual (tcp, udp is banned in my country) but cant ping or connect to ssh (ip route is fine) anyone else having this?

p.s. 1 month ago it was fine

compact patrolBOT
red shuttle
ancient niche
#

guys i cannot find it nothing of AI in google omg

tired olive
#

What country are you in that has that banned? That’s so interesting

gray yacht
primal coral
#

how to ı can do thıs shıt modules

#

ıts embarresing me

wooden trail
#

hi guys, on AEN (don't exactly know which part as I'm doing it blind), I have set up a responder and I'm poissoning LLMNR and MDNS, anyways I'm not getting any hashes, I can assume it means that only kerberos authentication is carried, but I might be wrong. The output would be:

[*] [MDNS] Poisoned answer sent to 172.16.8.20     for name xxxxx-DEV.local
[*] [MDNS] Poisoned answer sent to 172.16.8.20     for name xxxxx-DEV.local
[*] [LLMNR]  Poisoned answer sent to fe80::fdc4:5f07:f1ba:b737 for name xxxxx-DEV
[*] [MDNS] Poisoned answer sent to fe80::fdc4:5f07:f1ba:b737 for name xxxxx-DEV.local
[*] [MDNS] Poisoned answer sent to fe80::fdc4:5f07:f1ba:b737 for name xxxxx-DEV.local
[*] [LLMNR]  Poisoned answer sent to fe80::fdc4:5f07:f1ba:b737 for name xxxxx-DEV
[*] [LLMNR]  Poisoned answer sent to 172.16.8.20 for name xxxxx-DEV
[*] [LLMNR]  Poisoned answer sent to 172.16.8.20 for name xxxxx-DEV
earnest pasture
harsh swan
# gray yacht Did you reauthenticate as that user?

yes sir!... I did... then I tried the payment options endpoint that is the one needed to solve the test, and I got "Unauthorized", then tried relogin as the main user and got the same result... that's why I want to meet someone who solved so I can know it's not a bug...

gray yacht
ruby badger
#

can someone help me check if an exe file is malicious?

cloud urchin
#

No that's not what this discord or channel is about

ruby badger
#

where can I check

#

do u know any community that can help

cloud urchin
#

no

ruby badger
#

alright

ruby badger
fathom pendant
#

You'll just either need to sandbox or upload to a site like any.run

ruby badger
#

but the thing is idk how to analyse if its a malware

fathom pendant
#

But that's as far as anyone here can help you in this chat

ruby badger
#

and i think my antivirus is giving me a false positive

#

so i want to make sure that its a false positive and not a malware

fathom pendant
ruby badger
#

it says no access

#

idk whats that channel

fathom pendant
#

2 parts to my statement

#

Read and follow #welcome

  • this grants access to more of the server
    #binex-rev is a channel you'll be able to see after you do the first part
ruby badger
#

alr alr

fathom pendant
#

It deals with binary exploitation and reversing

ruby badger
#

yeah ik

fathom pendant
#

I'm explaining the channel you don't have access to yet

rustic sage
fathom pendant
#

Thats mostly because you're proxying traffic

gray yacht
fathom pendant
#

I mean if they're downloading a cracked exe (assumptions) then 9/10 times you get a free virus

small basin
fathom pendant
#

You can do -sV to get version info and --script banner to verify

small basin
#

I'm not looking for the banner. nmap should tell me that the port is open

fathom pendant
#

Filtered doesn't mean much

#

Just means that you didn't receive a reply back, as opposed to a reply saying "not open"

small basin
fathom pendant
ancient niche
#

ey guys look at this

fathom pendant
#

Intro to Assembly is a t2 module please refrain from spoiling

hybrid shuttle
#

Sorry for the inconvenience @fathom pendant, I was just thinking how I can bring it to some insight for getting suggestions. 😅

fathom pendant
#

you can just state you're having an issue with getting it below the 40 bytes, someone that's done it can ask to dm and take it from there

hybrid shuttle
#

Alright, noted and thanks

#

Thanks, just letting to know that I just solved it!

vital moat
#

hey guys i need help on “Windows Lateral Movement
\ Skills Assessment”: ‘What is the password for VNC?’. I have successfully RDP to the backup server as rossy but unfornately is not admin on the server so i can not get the VNC password? Any hint after getting a shell on backup?

#

I checked and rossy was added in the local administrator group but it's weird i am not able to execute any command as admin
SOLVED

unique patrol
#

bruh do your full port scans correctly

#

didnt do it and stayed for hours figuring out how to solve the easy lab(footprinting) XD

waxen totem
cedar marsh
#

hey someone wanna help me i am new to the game

compact patrolBOT
lusty thicket
#

<@&861185840277487616>

safe star
#

Alr Hudson

fickle crystal
safe star
short sentinel
#

I am following along with academy for "Using sysmon application" and used archive app for "sysmon app for splunk" , but the result is not generated by the application as in the academy is teaching? Also, app is showing "This dashboard version is missing. Update the dashboard version in source". Is version missing is causing any issue

lusty thicket
#

you're right lol

short sentinel
short sentinel
fickle crystal
short sentinel
drowsy raptor
#

If you can't help, don't say anything at all, simple

short sentinel
cyan hornet
#

Hey

safe star
#

its goku

orchid furnace
#

Hi guys, I tried using burpsuite on the Academy HTB instance pwn box and when I turn intercept on it doesn t do like my home burp suite community, instead when I turn intercept on the request is immediatly intercepted and I cannot see a list or choose from the list of request that the browser is trying to do, I would like to know if this behaviour is normal and wether it is or not how do I see the list of http request without having to go to HTTP History please

lilac breach
#

Does anybody have any advice? I just finished Introduction to networking and I’ve started on Linux fundamentals but is there anything you guys specifically recommend for after introduction to networking?

orchid furnace
drowsy raptor
drowsy raptor
#

the main three for fundamental knowledge is linux/networking/python

lilac breach
#

Thanks man I appreciate it

sinful narwhal
#

anyone help me on Windows Privilege Escalation > Credential Hunting module

rustic sage
#

Try asking

ember ibex
#

Anyone else struggle with ReGex?

undone solstice
#

Hello, why i cant submit root flag at meow?

#

i use open vpn

ivory finch
#

hi guys, did any of you exp this while taking the sqlmap essentials module on CBBH

Every sqlmap command on my Kali machine doesn't work. For example, sqlmap -r case2.txt --dump -T flag2 --batch doesn't work on my kali machine, but when i run it on the HTB machine, it works perfectly fine.

fathom pendant
#

I didn't run into any sqlmap issues

lusty thicket
fathom pendant
old echo
ember ibex
lusty thicket
#

looks like something a cat typed by walking across the keyboard

ember ibex
#

i was looking at some of the regex codes and was like... How in the hell do people understand that ahahahah

lusty thicket
fathom pendant
#

you eventually learn the things you use commonly

cold cloak
#

rdp

fathom pendant
#

is a common windows service found on port 3389; what about it?

waxen totem
fathom pendant
fathom pendant
#

that's LDAPS

#

LDAP over TLS

waxen totem
#

oh...right... secure mode ldap

fathom pendant
#

636, or 389 (389 is unencrypted)

waxen totem
#

so there's 3 ports 👀

fathom pendant
#

also 88 is KDC not LDAP

waxen totem
#

damn ldap

fathom pendant
#

mb

waxen totem
#

oic

fathom pendant
#

(some of this is quick google sanity checks)

waxen totem
#

Yeah you'd think with all these nmap scans I've done I'd remember which port is which

fathom pendant
#

i just do basic nmap scans in most instances and go off the common port#s

waxen totem
#

same, but if it's sus I'll chuck in a udp scan

fathom pendant
#

but i also have a brain like a sponge even in my advancing age

sinful tide
#

Hi so I am a bit stuck on the broken authentication module
Section: brute-forcing password reset tokens

Question 1 : on what do passwords recovery functionalities provided by web applications typically rely to allow users to recover their accounts.

On the course it says that it's a token I tried token in different forms and reset tokens and it still says that it's wrong I need help with that

drowsy raptor
#

most important one Kappa

thin parrot
#

I broke one of the modules and have no idea what to do now

#

Getting Started -> Nibbles, the image plugin cannot upload more than a single file

#

i didnt upload the reverse shell one liner and now.. cant upload shit

waxen totem
#

You should be able to upload another image

#

I'd restart the box seems broken

thin parrot
#

Nevermind I was smoking crack and misunderstood the plugins functionality

waxen totem
sinful tide
unkempt palm
#

hi friends i am in the skills Assessment Part 2 in Login Brute Forcing.i am stuck at finding the flag.i have access to ssh account satwossh and cant find the flag.txt

shut ice
#

Anyone had an issue with Xfreerdp disconnecting when you click on a mapped drive? I've mapped the drive using /Linux: and as soon as I open it on the Windows VM the RDP session closes

lusty thicket
#

and the slightest issue can cause the entire session to collapse

shut ice
#

Going to try it with another VM

hallow elbow
#

Damn hacking is just too interesting if I tell you what I just did to windows someone will put a bullet through my head 😂🤣😂

hallow elbow
#

Yeah sounds like a good idea. Thanks @waxen totem

waxen totem
#

Lmao was doing Host & Port Scanning | Network Enumeration with Nmap and found a flag for a future lab by accident laugh_cry

potent yoke
#

hello guys, did anybody have a clue about this exploting SSTI - Twig?

worldly badger
#

Module Attacking Enterprise Networks, Section Internal Information Gathering. when i am doing ping sweep for the internal network i can only see 3 hosts: 172.16.8.3; 172.16.8.50, 172.16.8.120. But in the section there is also internal host 172.16.8.20. It is not shown for me and i cannot interact with that host to complete the module. What should i do?

fickle trellis
#

Hi, Did anyone had problems with windows machines in Shells & Payloads module?. They sometimes dont even respond, the supposed to work msf exploits do not work, nmap scans are also way off etc.

lusty thicket
fickle trellis
#

Been forcing myself now from past 3 daysss🤧

worldly badger
vapid hull
#

hi did anyone have any trouble working with the skills assesment portion of the AD enumeration & Attacks. The server is not responding despite me waiting for an hour and after multiple refreshes of the server. For Skills Assesment Part I, I am unable to run any command on the webshell and the web browser is constantly loading while part II, I am not able to ssh or rdp into the attack host

visual umbra
#

Hello, im in Skillassement for Web Proxies and the first q is: The /lucky.php page has a button that appears to be disabled. Try to enable the button, and then click it to get the flag.
Iv been trying with add a post requset so it is getflag=true but the response is the same, i was look at some write-up for it and it says my method is correct . What i do wrong?

shut ice
#

Can anyone give a hint on DACL SA 2? Been stuck on the first question for a long time, I've got the NT hash for a non existing PC account that has constrained delegation to another PC that doesn't exist.

tranquil axle
shut ice
visual umbra
# visual umbra Hello, im in Skillassement for Web Proxies and the first q is: The /lucky.php pa...

My request looks like this: POST /lucky.php?getflag=true HTTP/1.1
`Host: 94.237.55.157:36040
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:135.0) Gecko/20100101 Firefox/135.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,/;q=0.8
Accept-Language: sv-SE,sv;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate, br
Content-Type: application/x-www-form-urlencoded
Content-Length: 16
Origin: http://94.237.55.157:36040
Connection: close
Referer: http://94.237.55.157:36040/lucky.php?getflag=true
Upgrade-Insecure-Requests: 1

getflag=true
`

Dont get what im doing wrong.. Can some one help me out? Iv been trying difrent reqsuets but no luck. I did read a wrirte-up cuz i did not get it, a was on track, but nothing i do works.

#

The server reject my request..

steady sigil
#

Hi , I want unlock the Module (FootPrinting) but i can't , anyOne here can help me ?

visual umbra
#

Going to take a walk outside and try again later

steady sigil
#

How

visual umbra
#

Earn or Pay

steady sigil
visual umbra
#

Or earn cubes by do modules

steady sigil
#

which one is better

visual umbra
#

Earn cubes take alot timme..

unkempt palm
#

hi friends i am in the skills Assessment Part 2 in Login Brute Forcing.i am stuck at finding the flag.i have access to ssh account satwossh and cant find the flag.txt

#

please help me anyone

#

😩

coarse stone
#

Attacking Enterprise Networks , Post exploitation Need Help with this module . Can anyone help me with this ?

normal sand
#

Try not to disclose too much here though since it's a Tier 2 module. Also, I'd recommend struggling some more and looking back on relevant modules since the AEN module is a capstone module for the CPTS.

shut ice
coarse stone
fading olive
dreamy osprey
#

hey man can i dm you please?

dreamy osprey
vagrant pewter
#

I was wondering if you need a bash script payload for a RCE?

Sorry, if stupid question.

storm elk
dreamy osprey
#

okay

fathom pendant
dreamy osprey
fathom pendant
#

haven't done that

#

and literally just said the only reason my dms are open atm kek

dreamy osprey
fathom pendant
#

¯_(ツ)_/¯

#

what you need is patience; my guy

dreamy osprey
#

i think i have had it for over 3 weeks now to be fair , even trying harder.. i finally cracked it solved it

#

two days later repaeting the same thing and its not working how does that work

#

it doesnt the make the patience any easier you know

fathom pendant
#

take a step back; frustration is the enemy of progress

#

frustration leads to mistakes
mistakes lead to anger
anger leads to the dark side

normal sand
fathom pendant
#

also generally i suggest using the fully qualified IPs

dreamy osprey
fading olive
#

Hello, I'm working on Attacking Common Applications - Skills Assessment I and I found a url which allows me to run the command dir on several directories even, but I can't figure out how to run anything else, like the type command or the whoami command. I found the latter in C:\Windows\System32 but I couldn't execute it. I'd be happy to get a hint as to how to proceed and/or what to try.

fathom pendant
#

not the wildcard 0.0.0.0

#

that way you can clearly see/know where the traffic should go

coarse stone
ancient niche
#

Good Afternoon guys look at this

thick steppe
#

Hey guys, a quick question, I have this question in the filter content section which is completely unrelated to this section which I said yesterday as well,

Determine what user the ProFTPd server is running under. Submit the username as the answer.

Now how do I approach this kind of questions, if I google this one I get answer but don't learn anything, if I try to solve it myself I dont have enough knowledge to do it so will end up wasting lots of hours for a single question which is useless. So how would you approach this kind of question when googling it will give you answer and you wont learn anything. I am just confused I am not learning anything, what am I doing wrong, is it just my problem.

normal sand
#

I don't know if it's possible to double pivot with another port other than 11601. You will have to refer to the docs.

fathom pendant
normal sand
#

I don't know how you went about setting up your pivoting. You might already have the listener set @coarse stone

#

Because I had no issues pivoting with ligolo on AEN.

coarse stone
normal sand
coarse stone
normal sand
#

Or just send the steps here. Whatever works for you.

unreal fractal
#

hey guys quick question, what's your take on the CPTS cert , is it worth taking or is best to prepare directly for OSCP instead ?

fathom pendant
#

it's worth for knowledge

thick steppe
#

Its very frustrating and demotivting when things do not work the way I want and I have to waste lots of hours and still have nothing in hand, maybe its a me problem

unkempt palm
thick steppe
#

no am stuck at the linux fundamentals in infosec prerequisite pathway

#

for like forever

fathom pendant
#

GPT is ok for some things

#

as it's ingested a bunch of different documentation

#

@keen drift this isn't an advertisement server read #rules [7]

thick steppe
#

how can somebody stay motivated when things are just not working, wasting lots of hours is painful when I get nothing in return, maybe I dont know the basics or something.

fathom pendant
#

taking breaks is healthy

thick steppe
#

I end up talking longer breraks than sessions

fathom pendant
#

i take a few minutes go get something to snack on, and let my brain do the processing in the background

#

then realize i made a simple typo

thick steppe
#

you cna process things when you know those things, I just lack the knowledge

fathom pendant
#

things "just not working" 9 times outta 10 is a user issue

fathom pendant
#

your brain processing info doesn't necessarily mean you already know something

#

sometimes it pops the question in your head of "did I look up xyz?"

thick steppe
fathom pendant
#

"how to <do thing> in <Linux/Windows Powershell/Windows CMD>" is a common query in my google searches

#

"how to find out what user started a process in Linux" is something you'd ask google (or GPT) to get an answer

unkempt palm
fathom pendant
#

a while ago

unkempt palm
#

i need a help from you

fathom pendant
#

but it's best to just ask your question (avoiding spoilers) instead of asking "Did you complete <module>"

unkempt palm
#

ok

fathom pendant
fathom pendant
#

one of the sections teaches you something you can do; not to mention there's some important documentation given on the server

calm pewter
#

Hello good people! I am stuck in "Active Directory Enumeration & Attacks" in the part "Attacking Domain Trusts - Cross forest trust abuse - from Windows"

After identifying a cross forest user and having bidirectional trust, how to determine the computer name to attempt Enter-PSSession? klist does provide some hints, but how to be sure what is the computer name of this user in another domain?

In this case we are currently in ACADEMY-EA-MS01 and the foreign user is in ACADEMY-EA-DC03 according to the script they use next, but I couldn't find how they knew for sure

unkempt palm
#

i found every where without root folder.am i right path.or flag is in another where

#

for Login Brute Forcing Skills Assessment Part 2

green shuttle
#

Hi can anyone give me a hand in http misconfiguraition module i am stuck with hard skill assessment

earnest pasture
# calm pewter Hello good people! I am stuck in "Active Directory Enumeration & Attacks" in the...

I think it depends on your previous enumeration, if it is another DC perhaps you should have already seen it in a network scan of the internal network where it can show you several hosts that may be in another domain or hosts that have another network interface with a different subnet where you have to scan IP's to identify other hosts that may belong to another domain or also from bloodhound, since you are in the last modules everything is based on the previous enumeration that you did during the tour with bloodhound or PowerView.

golden prawn
#

Can someone give me a nudge on titanic? I have user flag but am having a hard time getting a shell

empty trout
#

when logging into mssql with linux by sqsh we need to specify either hostname or domain name to use windows authentication . what does .\username means we can also use that too . i dont get it

#

we can use .\username when targettting local account .

strong hollow
#

Hey guys I’m new lol

#

How do I get started

compact patrolBOT
fathom pendant
#

I.e. local user

#

[Domain\]user

#

. Is local

empty trout
fathom pendant
#

On a standard windows install [not domain joined] .\ is implied

calm pewter
fathom pendant
#

On domain joined you'd use .\ to log in a local account, i.e. IT logging into localadmin account for administrative purposes

empty trout
#

so it is required that mssql server should be running in that computer and we are using the local account on that computer

fathom pendant
#

It can be set up a myriad of different ways

empty trout
#

yeah i get it

fathom pendant
#

You can use a local account on another machine if you specify the ip/fqdn

strong hollow
#

How do I get access to general?

fathom pendant
empty trout
#

@fathom pendant after i complete cpts path can i also be a community contributor

fathom pendant
#

community contributer isn't linked to completing any paths

#

it's just someone who's active and helps out in the community

empty trout
#

yeah but to contribute i need knowledge

fathom pendant
#

¯_(ツ)_/¯

thick steppe
#

I am not able to find answer to this in any way, all I can find needs sudo provelages which I cannot get on htb

Determine what user the ProFTPd server is running under. Submit the username as the answer.

fathom pendant
#

i became a contributer well before i finished the pentester path

empty trout
#

😅

fathom pendant
thick steppe
#

this is gettinf more and more frustraing

fathom pendant
#

google is your friend

thick steppe
#

I did that

fathom pendant
#

and even gpt can help

empty trout
#

assigned for discord

fathom pendant
#

"how can I find out what user started a process like ProFTPd?" <-- what i asked to chatGPT

#

no

#

i just tab in and out

empty trout
#

dont you feel distracted

fathom pendant
#

nah

restive spoke
#

Does anyone have the answer for the fourth question in the information gathering - web edition module. in the web archives section? I think I have the right answer but I'm not getting credit.

fathom pendant
#

it's asking for the full thing without the ™️

#

2 words, remove the TM

restive spoke
#

I did. I swear its bugged.

fathom pendant
#

copy/paste? (in the answer bit)

#

make sure no extra spaces and whatnot

restive spoke
#

Got it... Thanks for the help. I'm embarrassed. I thought I tried that..

thick steppe
#

their is only one way to know it, by looking at its config file in
/etc/proftpd/proftpd.conf. which is kindo wierd, who would have thouht that this can be the answer

#

just got it from reddit, such a waste of time

thick steppe
#

well not exactly weird but still not the way anyone would think to get the answer

fathom pendant
#

that's not the only way to know it

thick steppe
#

you need sudo privileges to know the otherways

fathom pendant
#

nope

thick steppe
#

ok then, tell me one other way, I would like to see one that works, I tried a lot of things and everything needs priviliges

fathom pendant
#

google and gpt both netted results to find a user of a process, didn't require sudo perms

thick steppe
#

idk how thats even possible, if someone wants to know a details about processs then the user mush be sudo to get that

fathom pendant
#

ps

#

that's the command, there's additional options to pass through

#

but that'll require some extra research on your end

thick steppe
#

cant even open man page of ps by ps -h

#

let me try

fathom pendant
#

man ps or ps --help

thick steppe
# fathom pendant nope

ps aux to see all the processes and checking for proftpd is one way to do it. THANKS ALOT

#

I need to learn to search things, in different ways

fathom pendant
#

the man page for ps i believe gives you a brief overview of common options

unkempt palm
fathom pendant
#

About?

twilit roost
#

Hey :)
I'm on the Broken Authentication -Brute-Forcing Password Reset Tokens

Any idea why this command :
ffuf -w ./tokens.txt -u http://http://94.237.54.109:39810/reset_password.php?token=FUZZ -fr "The provided token is invalid"
is so slow ?
It's been 10 minutes and its only at token 4000 :/
Im running a python script rn but i wanna know why it is so slow

green shuttle
#

Hi anyone can help me with abusing http misconfiguraition module stuck in hard skill assessment

hybrid dew
#

Hello I have question about Attacking Common Applications on the Attacking Thick client Application, can someone help me.

twilit roost
zealous rune
#

Hi. I'm working on the File Inclusion module in CPTS path. I am having difficultly completing the exercise in the log poisoning section. Specifically when trying to do an LFI for the apache logs as follows: index.php?language=/var/log/apache2/access.log I find that I get the access.log file successfully initially then subsequent attempts fail, especially after atempting to poison the logs

#

am I missing something and this is expected behaviour? or i should keep resetting the machine?

acoustic owl
zealous rune
#

thanks for the tip.... I'll try different payloads and see if i can identify characters that interfere

acoustic owl
lunar flicker
#

Hi, anyone can give me a hint in "Advanced Deserialization Attacks S.A"? [CWEE] I've found some potencial vulnerable functions but I cannot bypass some filter, I don't know if I'm in the right path..

Thanks!

empty trout
thick steppe
#

I saw on reddit that linux module is found diffult even by experienced linux users and some even suggest switching to tryhackme before htb saying htb academy isnt for begenieers. What do you guys think of switching to thm for a bit and then comming back, is it worth it.

#

Or is it something a begenner should do

fathom pendant
#

Thm holds your hand a lot

#

And if that's something you prefer, up2you

#

But a bit of the linux module sections are solved by simple Google queries

#

Or reading the man pages

thick steppe
#

what does handholding even mean, they are not going to give you like answers very easily right. I mean aren't they supposed to teach me something and ask questions from that

fathom pendant
#

it means that they are VERY much step-by-step instead of theory+practice

empty trout
#

i havent tried thm but i like htb bcz i got the dopamine hit when the simple problems become hard . and then you solve it . its like awwww man i am stupid ....

#

yeah i it is frustrating you will likely bruteforce credential and not get it upto 3 day (my max )

silk dome
#

Hi all.

I'm doing the Firewall and IDS/IPS Evasion - Hard Lab and I'm struggling to get flag.
I've tried what is detail in the Firewall and IDS/IPS Evasion to no avail. Anyone able to give me a clue as to what I could be missing ?

fathom pendant
rapid zenith
#

Hi all, i'll try to compleate windows foundation , but can't decide servisec & process section... who can help me pls?
Identify one of the non-standard update services running on the host. Submit the full name of the service executable (not the DisplayName) as your answer.

fathom pendant
#

Non-standard == not built in

#

So not windows or anything like that

rapid zenith
#

But how i should know about it? i reviewed all proccess, but didn't look for anything

#

I look tutorial at youtube, but don't understand, why she write this command Get-Service | Where-Object {$.Name -like "reader"}
In this section has example
Get-Service | ? {$
.Status -eq "Running"} | select -First 2 |fl
But how i must to know right way?

fathom pendant
#

The module should have shown you how to get running service info

#

Also use backticks (`) to wrap commands

#

_ _ is markdown italicizing

rustic sage
#

Im lost 🤔

#

Oh thank you I figure out

pure osprey
#

Man these channels really should be locked to verified/academy users only.

I haven't read this channel consistently for a long time - has this been discussed?

fathom pendant
fathom pendant
#

They're getting held up on the academy verification thing

teal sparrow
#

im stuck on the file upload attack skill assesment i tried many file signatures and extensions and Content-Types but i still get Only images allowed error even when trying to upload no payload and no php extension?

zealous rune
sly citrus
#

Guys someone here termux user?

hallow elbow
#

Does anyone know how to use discord server for a reverse shell?

fathom pendant
teal sparrow
#

really stuck on file upload attacks assessment ive been on it for a month now i finally managed to upload the file when i visit the directory its supposed to be in (wont mention for spoilers) i get apache not found ?!?!?!?! honestly this lab is driving me insane does anyone mind dming to help?

glossy cloak
#

Hi @fathom pendant, did U miss me? LOL
I have a problem with SMB, its enabled but...
do_connect: Connection to 10.129.201.57 failed (Error NT_STATUS_IO_TIMEOUT)

#

is the server ip the target ip?

ember ibex
#

noob question: are we able to use this chat as a check to see if I am doing some of the practice questions correct?

fathom pendant
fathom pendant
#

Modules above t0 you have to be mindful of spoilers

ember ibex
#

so like for this question

#

would it be ||grep -v "#" /etc/ssh/sshd_config||

#

#practice spoilers

rustic tree
#

hey guys, i have a problem. i'm on the knowledge check on HTB academy CPTS, after gettting Nibbles done. I have the admin credentials, and now i know that i must load a payload on the site, but dont understand how, can anyone help ?

ocean night
#

What do you mean knowledge check for CPTS? Which module are you on @rustic tree ?

rustic tree
#

About the getting started sorry 🥲

#

I have scanned the IP, this and apache server. I have the admin credentials

#

I there is a lot of directories but I don't know where to look to do RCE to gain access to

#

It seems familiar to Nibbles but I can't find any exploit right now

lunar flicker
#

Hi, anyone can give me a hint in "Advanced Deserialization Attacks S.A"? [CWEE] I've found some potencial vulnerable functions but I cannot bypass some filter, I don't know if I'm in the right path..

Thanks!

ocean night
rustic tree
#

OK I will continue searching then ! Thx for the response 😇

safe star
waxen totem
rustic tree
waxen totem
#

~~I love how I shameless plug my writeup any time this module is mentioned laugh_cry ~~

lusty thicket
#

i just checked it out

#

feels rushed

waxen totem
lusty thicket
#

🕵️

lusty thicket
ebon shoal
#

I’m new to this server, I’m guessing it’s about tips on hacking?

woeful lake
#

This channel is for modules of htb academy

nova pivot
# rustic tree OK I will continue searching then ! Thx for the response 😇

Hey there, not sure if you found it already, but just in case : for nibbles there are two ways to get a foothold, one "manual" and one more..."assisted" : If you went the "assisted" route for nibbles, you might want to go back and try to do it manually 😉
If you do and you understand what you are doing, you will find how to exploit the knowledge check easily

#

@restive spoke Don't know if you found your answer, but sometimes what you read isn't what's really there

thin parrot
#

Any reasons why python3 -c 'import pty; pty.spawn("/bin/bash")’ Would cause the shell to freeze up without fail?

#

I seriously cannot figure out why this is happening I'm assuming its HTBs end freezing up

#

I cancelled out of the reverse shell, re-established the connection by refreshing the page (a script is ran everytime that does this in which I added the reverse shell connection one-liner)

#

Successfully establish a connection

#

Them bam, can't upgrade the shell anymore

rustic sage
#

Mm, I've had a few terminal freeze ups too, and they got fixed when I shifted to TCP version of the VPN

lusty thicket
thin parrot
#

I can still fully interact though I don't understand, I can use ls with no issue or anything else

rustic sage
#

you could try TCP version, if you are not on one already. I used to have file transfers getting stuck, terminal freeze ups on opening large files, etc.

thin parrot
#

I'm not sure if I am or not I've always done everything through the terminal on academy

#

I'm just going to start fresh this is taking up too much time

#

Oh yeah I see the TCP/UDP option for the VPN, I'll use TCP from now on

rustic sage
#

Yea, try that one and tell if that resolves anything

inner sand
#

Hey everyone !, I am a cybersecurity engineering major as my somphore year and I have already some Linux and some hacking tools experience, but I need an actual computers architecture + networking + cybersecurity + malware + telecommunications experience, any could help ?

inner sand
#

"#no-acess"

lusty thicket
thin parrot
#

Christ you're kidding me its still not fucking working

#

I literally cannot complete this because vi has a stroke everytime I try putting the elevated shell script in the no password sudo directory

#

It will not register 'esc'

#

so I cant actually save anything I write

lusty thicket
#

it's not the end of the world buddy

#

there're other ways

thin parrot
#

yeah I'm just tired of spending an hour on one page when I'm expected to finish HTB within the next month

#

Not sure why it is not working with the TCP vpn

lusty thicket
#

you can use echo

slow osprey
#

hi friends, in the SQL injection skills assessment, I found the username and password from the database. Am I supposed to be able to login with these credentials? I wasn't able to so I also tried authenticating via mysql on terminal with no luck. Is the method to create a webshell directly with these credentials instead?

thin parrot
#

Cant send a screenshot but sudo -l is showing "User root may run blah blah blah: ALL : ALL

rustic sage
#

Make a valid SQL injection request, and you'll be able to get in

#

Try think of possible scenarios (hint: commenting out stuff might help you)

safe star
slow osprey
severe iron
#

Did you ever figure this out? I'm getting the same error even though the model file works.

cloud urchin
#

can you guys take it to dm please, you're talking about a skill assessment here

ocean night
#

Listen to SuperNuts, take it to dm.

#

However, you should not be spoiling it for each other at all to be honest.

#

Totally negates the purpose of a skill assessment.

rustic sage
#

You’re right. Soz. I thought that was a silly hint

#

You can dm me dude if you want

slow osprey
#

my b

#

I got it, I was stuck on a silly error

#

ty all

rustic sage
#

Well done

sturdy ivy
#

Heya gang,
I'm attempting to solve the fourth SIEM visualization through the intended way, and not through brute-forcing the dates.
Could someone please inform me what I am doing wrong with @timestamp to still be getting only the 'week of event', as opposed to the day of event.
Much appreciated!

spark fox
#

Hey guys. Currently doing attacking web applications with fuff final assessment

#

Im trying to submit my answer for the question which asks which extensions are accepted by the domains

#

I fuzzed all the vhosts and it is using. .. I dont know if i missed an extention or if there is a certain format i should use when submitting my answer

rustic sage
#

Hi Avesh, probably not the perfect wordlist. You are missing an extension likely

#

And edit your message, I reckon thats a spoiler

spark fox
nocturne current
#

Hi everyone. I'm having an issue with the password on page 6 in the linux fundamentals module. I returns "Permission denied, please try again". Today is the third day as I can only spawn a terminal once a day. Can anyone help here before my timer runs out? Otherwise I'll have to wait until tomorrow. 😦

spark fox
#

Also, install a vm so you can practice as much as you want without having to rely on the pawnbox

#

Or get a subscription if you can for unlimited access

nocturne current
#

@spark fox - Will WSL with ubuntu also work?

#

subscription is not viable at the moment. 😦

thin parrot
#

Hey uhh how long does nmap on all ports take yall

#

I've been here for about 12 minutes waiting for a response and it still shows nothing beyond starting the scan

sturdy ivy
rustic sage
sturdy ivy
sonic plume
#

Could i get a sanity check for "Wi-Fi Penetration Testing Basics - Skills Assessment" last question?

thin parrot
#

its literally just nmap (ip) -p-

thin parrot
fathom pendant
#

don't take your frustration out on the author

fathom pendant
#

nmap has a ton of great documentation

waxen totem
#

You know HTB academy does put those links to the documentation for a reason, it's because it's not like they can explain everything in a single section or module

#

Also you're gonna have to do a lot of research when pentesting anyway, so it's good to practice

thin parrot
#

What I'm actively looking up I just wish the questions were centered around the modules it feels a bit offputting when what you just spent 20 minutes reading about applies to nothing you're being questioned on

#

Doesn't make much sense its like teaching someone how to operate an automatic transmission vehicle then asking them how stick shift works

rustic sage
#

I think its meant to be that way. They want us to do some extra research work and think outside the box which is essentially a skill in itself too

spark fox
waxen totem
#

It's not that they're teaching you how the tool works, they're teaching you how to learn more about it and discover things for yourself. The point is that they give you a base to build knowledge from

potent yoke
#

did anybody have a clue about SSRF module the SSTI question?

lusty thicket
#

if i wanted to teach myself, i wouldn't need you 😭🙏

ocean night
#

Being able to absorb, reuse and research based upon what you have learned is such an important skill. That is what the modules try to teach, the ability to improvise and build upon the knowledge gained through the sections.

#

If the answers to the modules were just laid out in front of you within the module, there really would be no point IMHO. There's got to be a degree of challenge, and in any learning environment you will never be given the exact answers to what will be on the "exam".

#

Of course, we are always open to /feedback, but know that the above is the nature of the HTB Academy, and is intended. It's not for everyone, but ultimately I believe if you stick with it with the approach of learn, research, apply, you will get much more value than just following a guide showing you exactly how to complete the final question. We give you everything you need - some times you just have to apply that knowledge with some innovative thinking.

waxen totem
#

Sometimes though the challenge is a massive leap from the module itself *ehem* Linux Fundamentals Filtering Section Curl Question *ehem*

ocean night
#

Also true

#

And again, feedback is a gift 😄

#

I'm nothing directly to do with content, but I do pass on this kind of feedback to the team

#

Also, any feedback provided with the /feedback command also goes directly to the team.

waxen totem
#

btw @ocean night saw the change in sharing active season machine pwns, It's noice!

ocean night
#

Oh sweet, that shipped 😄

lusty thicket
#

just saying some skill assessments right after a module don't always align with what was covered

thin parrot
#

Like at least this one stems off of nmap

#

Spend a few minutes looking at documentation and I got my answer lol

ocean night
#

Sorry if it came across differently

potent yoke
#

did anybody have a clue about this?

lusty thicket
#

quite a few of us, actually

nocturne current
#

Hi. Does anyone have an idea what the password is here (linux fundamentals page 6)?
The given password HTB_@cademy_stdnt! is apparently not correct. I have respawned the machine 3 times already. Always the same error... 🤔

autumn pilot
#

You have the wrong IP address

#

The target's IP address starts within the subnet of 10.129.x.x

orchid furnace
#

should I provide screenshots ?

drowsy raptor
nocturne current
fathom pendant
#

pwnbox is the attack box vm
"click here to spawn target" above the questions

#

that IP is the tun0/VPN ip of the pwnbox to use for reverse shells (and other exploits) to connect to the attack box

nocturne current
#

I did. This is the box that spawned.

fathom pendant
#

nope

#

you clicked the "spawn instance" button

#

"spawn instance" and "spawn target" are two different things

nocturne current
#

w8 1 plz. trying again

#

Wil 2 machines run at the same time?

#

If not, I'll have to wait until tomrow to try this solution.

fathom pendant
#

the target spawn has no bearing on the pwnbox

#

you can have the target and pwnbox running at the same time

rustic sage
#

In simple terms, when you spawn instance, you are spawning the machine you are going to work on to perform the task at hand. When you spawn the target, you deploy the machine you are attacking

fathom pendant
#

^

nocturne current
#

Either way, thanks for the assistance. 😄

fathom pendant
#

layer 8 issue fr

potent yoke
#

did anybody have a clue about SSTI twig?

nocturne current
#

Perfect! Thx everyone. 🙂

lusty thicket
orchid furnace
# drowsy raptor yes please

the second one being the one being the one at hackthebox academy, I don t know why it doens t show a list like the first one

#

whenever a request happens to be intercepted it shows it directly allowing me not to see all the intercepted request

autumn pilot
#

What's the reason of intercepting the request to the vnc session of the workstation?

#

Additionally, you are intercepting websocket requests and not HTTP

orchid furnace
orchid furnace
autumn pilot
#

There is a Type column in your first screenshot

autumn pilot
orchid furnace
orchid furnace
covert pine
#

https://academy.hackthebox.com/module/211/section/2273

Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Discover". Then, click on the calendar icon, specify "last 15 years", and click on "Apply". Finally, choose the "windows*" index pattern. Now, execute the KQL query that is mentioned in the "Comparison Operators" part of this section and enter the username of the disabled account as your answer. Just the username; no need to account for the domain.

I open up the VM and put it in firefox with the target IP and nothing comes up? Kibana doesnt load by iteself either. Is there something im doing wrong, what should i do?

#

Please @ me when you respond

nova knot
#

I'm working on getting started module and have to exploit apache httpd 2.4.41 ((unix)) any idea? i tried msf and search sploit but didn't find any matching exploits

#

for "public exploits section"

autumn pilot
#

Explore the service on the running port, something might stand out

waxen totem
#

attempt to use the service as it's meant to be used... you might see sometehing interesting

polar cliff
#

What is the basic things I need for a bug bounty hacking

nova knot
#

is it smtg related to this?

autumn pilot
#

read what is written there and look it up if it is vulnerable

covert pine
#

@autumn pilot can you help me aswell

fallen glen
#

Hi everyone! I'm currently working on the Network Foundations module and I'm stuck on finding the flag. I've tried several approaches, but I'm hitting a wall. Could anyone provide some hints or guide me in the right direction? I'd really appreciate any help!

full grail
shut ice
#

Can anyone give a hint on the DACL II skills assessment question 2. I have the SDE01 server admin and found Angel creds but not sure on the path from here to RD09. I have found I can modify a GPO but believe I need to compromise another user to link it to the RD09 box.

autumn pilot
full grail
sinful narwhal
#

anyone help me on this: Windows Privilege Escalation > Interacting with Users

Using the techniques in this section obtain the cleartext credentials for the SCCM_SVC user.

tired atlas
#

So I'm on Shells and Payloads, automating payloads with metasploit, and I just had a question regarding how to find the correct exploit to use, I've used the ones the module suggested but I cant get a shell session to start, so i enumerated using nmap and Im currently trying to find another suitable exploit

limpid eagle
#

Hi, I am not sure if you were able to get the answer right but i tried all possible ways and there were no extra spaces! tcpdump -rX /tmp/capture.pcap, -rX /tmp/capture.pcap, tcpdump -r /tmp/capture.pcap -X

All these are working in the command line, i tried with real tcp dump. Can you advise me please ! @fathom pendant

fathom pendant
#

spoiler tags don't do anything

#

also the question says winrm, not rdp; so of course you can't use j* creds for rdp :) each service has a unique user

grizzled schooner
#

Oh alright sorry, thought they may help to give some context, but I'll keep looking then

covert pine
#

https://academy.hackthebox.com/module/211/section/2273

Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Discover". Then, click on the calendar icon, specify "last 15 years", and click on "Apply". Finally, choose the "windows*" index pattern. Now, execute the KQL query that is mentioned in the "Comparison Operators" part of this section and enter the username of the disabled account as your answer. Just the username; no need to account for the domain.

I open up the VM and put it in firefox with the target IP and nothing comes up? Kibana doesnt load by iteself either. Is there something im doing wrong, what should i do?

grizzled schooner
tired atlas
#

you could answer it in 3 hours, 7, 2 days or never

fathom pendant
#

Been doing this for a long time. Typically people expect immediate answers when they @ someone

#

Also, when someone @'s another user, other people are less likely to help

tired atlas
fathom pendant
#

I get where you're coming from: but please don't try and police how I respond to people

covert pine
#

CAn someone help me

tired atlas
fathom pendant
#

I'd appreciate if you don't try and dictate how I interact with people

fathom pendant
tired atlas
#

You're just being mean!!, its like if i was being mean and told you dont tell me how to talk to people

fathom pendant
#

Ah scrolled up

#

Setting a boundary != being mean

crisp solstice
#

Hey! Im on ACL Enumeration of the module Active Directory Enumeration & Attacks, Im struggling with the final question:

What is the ObjectAceType of the first right that the forend user has over the GPO Management group?

I'm using the command as seen in the image, and its been running for about 20 minutes. Just not sure if its meant to run more than that!

Any help would be much appreciated.

fathom pendant
#

I haven't done that module @covert pine wish you luck

fathom pendant
#

Or using forend identity

#

Consider the question gives you specific info

crisp solstice
fathom pendant
#

If you take a look at the object (output) you'll see a lot of info you can use to search

covert pine
weak kindle
#

Has anyone here completed the ADCS module? Reply to this msg please!~

fathom pendant
sinful trout
#

Okay

weak kindle
pine dune
#

Hi guys

#

Im having trouble on "Type Filters" for file upload attacks, any hints would be appreciated!

pine dune
#

"phpextenshionhere" was replaced with the valid php extension but thats the error its giving

fathom pendant
#

type filter
fuzzing extensions

pine dune
#

hi @fathom pendant I managed to upload the file but it comes up with the actual image and not the web shell

#

any ideas?

old echo
pine dune
pseudo kiln
#

What do they mean by briefing here ? Like a power point presentation ? End of AEN module

sinful narwhal
#

anyone help me on this: Windows Privilege Escalation > Interacting with Users

pine dune
fleet spear
#

i have a dissagreement about pwntools and the use of xor that in my eyes gives kind an odd and not replicateable if you want to use other tools for xoring that it in the middle of the hexstring have \n and ^ tucked in with the code you should insert to get the right answer

nova pivot
lusty thicket
fleet spear
#

well the problem is that it expects \n ^to be in the hexcode that you should submit as answer...

#

since when is \n and ^ valid hexcodes...

rustic sage
#

I remember there was a script that you modified to fit the allowed extension in, and that generated every combination of extensions attempted at escaping blacklisting and whitelisting.

fallen oasis
#

Hello, so I am working on the intermediate network analysis module and have been stuck on the first question for a while... Is the ARP_Poison.pcapng file supposed to already be installed on my PWNBOX or do I make it or what? If so where would i find it

tawny coral
#

Anyone else unable to click 'modules' from the other academy tabs (Dashboard, exam, etc.)? For me, the button is just a Javascript void

#

Same with the 'paths' page

minor sonnet
#

hello everyone , i want to ask if dante is a good start on pro labs or there's a better choice ?

pure gazelle
#

Hi,

I'm basicly stuck on those two questions (What is the admin email address? | Try to access the emails on the IMAP server and submit the flag) in HTB Footprinting module. I've tried every possible command but I think none of them gave me proper answer. For second question I tried Evolution but I couldn't grasp it's capabilities.

Any help - suggestions what should I try or where to start looking?

waxen totem
tawny coral
#

Nothing is dropping down, though :/

patent ravine
#

Hello, could I DM someone to help me with the XSS module? I can't seem to figure it out what I am doing wrong and I already figured out which input field is vulnerable to XSS

errant sapphire
pure gazelle
#

also made it to aquiring devops email address but it shows it's not the one

#

i've managed to connect to imaps using credentials but LSUB "" * command returns nothing whatever inbox i use

#

I GOT IT - FETCH !

light siren
#

hiya, how do i find the walkthroughs on the academy

pure gazelle
light siren
#

not for me man, their asking questions i have no idea even how to find the answer for

#

luckily i found a answer sheet online for my module and im like learning backwards kinda deal

#

but hey im learning

pure gazelle
#

yea me too

#

but still what module are you participating ?

light siren
#

im very new to this stuff, started with a 20 hour youtube video on cli and just kinda went from there

#

😦

#

linux fundamentals i know haha point finger

pure gazelle
#

nothing to be pointed finger at - hey we all started somewhere

light siren
#

years ago i used to just find like backdoors so easily and all didnt know any networking stuffs much or nothing

#

not quite like that anymore

#

ethically on my phone ofc

pure gazelle
#

hey - let's chat on DM's, we wouldn't want to spam this tag 🙂

light siren
#

usually where ive forgotten passwords and the alike, locked out of myspace hmm ill find a way in its my acct no harm no foul

pure gazelle
patent ravine
#

Am currently working on XSS skills assessment and I figured out which input field is vulnerable to XSS but when I try to grab the cookie using script.js I get 200 response but no cookie. I could use some help I've been working on this since yesterday

rustic sage
signal hound
#

Hi, doing right now the password attacks module, PTT on linux section.
But Im not sure whats the difference between tabkeys and ccache files ?

patent ravine
rustic sage
#

Sure

fathom pendant
patent ravine
pine dune
rustic sage
pine dune
rustic sage
#

Its under Whitelisting iirc

high reef
#

can i get help with Introduction to NoSQL

pine dune
high reef
#

I dumped the internal with user name and password, but i dont see any username and password for for answer i need

fathom pendant
#

Because you're looking for a specific length of strings

#

You're given the info of a first/last name

hexed atlas
#

Does anyone know what the reason could be for not being able to connect Parrot to VM? I keep getting error messages about the file either being corrupt or invalid. Is this likely a system issue? (Very new to this)

fathom pendant
#

Wdym "connect parrot to vm" you mean vpn?

hexed atlas
#

The Virtual Machine platform

#

I am just in the setup module

waxen totem
#

Do you mean install parrot in a vm?

hexed atlas
#

In the setup module of Info Security Foundations I have to virtual workstaion and connect it with a guest operating system, however, I am having a lot of trouble doing this and honestly, do not know enough to diagnose it. I have tried a few different things, but it has been dead-end.

high reef
#

but i kept getting error

waxen totem
hexed atlas
#

Yes

waxen totem
#

Could you send a screenshot of the error?

fathom pendant
covert pine
#

https://academy.hackthebox.com/module/211/section/2273

Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Discover". Then, click on the calendar icon, specify "last 15 years", and click on "Apply". Finally, choose the "windows*" index pattern. Now, execute the KQL query that is mentioned in the "Comparison Operators" part of this section and enter the username of the disabled account as your answer. Just the username; no need to account for the domain.

I open up the VM and put it in firefox with the target IP and nothing comes up? Kibana doesnt load by iteself either. Is there something im doing wrong, what should i do?

velvet belfry
#

Hey everyone new to this group I wanted to start cybersecurity from health professionals backgrounds so need some study plan and step by step support please help me.wanted to do Comptia A+ exam to know little bit about it then will start for 1st line job if that’s possible what else do i need like to get in to the job role ,any other courses needed like Microsoft 900 Az or please sort this out

pine dune
covert pine
fathom pendant
ember ibex
#

@pure gazelle @light siren YAY im not the only beginner bwahahahaha

light siren
#

@ember ibex not at all i have spent hours researching for one question man but learning, sometimes i just wanna smash my head into a wall the verbage on the manpage can be harder then the question haha

ember ibex
light siren
#

omg yes @ember ibex ❤️ went thrugh this one yesterday with a curl command, and then filter result

waxen totem
light siren
#

explain shell couldnt even tell me

#

@waxen totem yeah i take advantage of the kali forum, r/linux, kali linux, stack overflow, explain shell

waxen totem
light siren
#

all good for finding stuff usually have to use all four for the tough ones

fathom pendant
ember ibex
light siren
#

the regex wasnt so bad, took awhile to find a good result and figuring the correct way to use "^(This|First)' but found it

waxen totem
fathom pendant
light siren
#

yeah the one on fund it was almost a two line syntax

fathom pendant
#

I'm sure there's a neater command

#

But i stuck with the one that gave a verbose answer

light siren
#

idk i just found the answer, used it in the pwnbox then reverse engineered it, put each part one by one with different terminals open to compare, and plugged in the step by step into shell... the parts shell couldnt tell me i used web to search for

fathom pendant
#

make sure no extra spaces

#

also i beleive that module is > t0 so be careful just spoiling/giving potential answers

vagrant flax
fathom pendant
#

i haven't done that module plan to soon.tm but haven't gotten around to it

rustic sage
fathom pendant
#

just gotta read sadglas

grim basin
#

looking it up says people are talking about an otp token which i cant figure out how to make a ffuf command for it

granite halo
#

Hello, I am trying to attend a wedding otherwise I would go through more official channels, but the problem is as follows:

https://enterprise.hackthebox.com/academy-lab/35638/11395/modules/143/1420

".\Inveigh.exe" will not load into an interactive state. I understand that I am looking for a hash, and how to use that hash once it is found but the tools are not working appropriately. Is there someone that has the hash on hand so that I may move forward?

fathom pendant
#

no one is just gonna hand you the hash as that's actually against ToS

#

you gotta figure out how to make it work

#

i'd say enjoy the wedding and chat support when you're done

#

¯_(ツ)_/¯

granite halo
#

@fathom pendant
Active Directory Enumeration & Attacks > LLMNR/NBT-NS Poisoning - from Windows
The mod and section. Good to know that it is against terms of service.
All of my searching hasn't shown someone else to have the problem yet. The command executes, it just seems to exit before ever starting the interactive portion.

fathom pendant
#

the interactive bit of inveigh is just pressing a key while it's running iirc enter should work

#

could also need admin rights, been a minute so i'm rusty on that module

granite halo
#

@fathom pendant @lusty thicket Thank you, ill make it happen.

lusty thicket
#

awesome

quasi wave
#

what is the alternative to hydra for brute forcing ssh?

#

I heard someone on here mentioned there was a better optoin

#

I'm doing the medium lab for the Attacking Common Services module

#

I am trying out hydra but isn't there an alternative in case it doesn't work?

#

I know nmap shows ssh port 22 as open

#

also is the username and password list in the resources suffice?

#

or should I be using rockyou.txt?

rustic sage
#

Medusa is an alternative

quasi wave
#

I think I see what to do

#

I'm trying to brute force just the username of the server in the medium lab for Attacking Common Services. I am trying this and its not working:

                                                                                                                                                                                            
┌──(kali㉿kali)-[~/Desktop]
└─$ hydra -L users.list -e ssh://10.129.232.82 -T 32
Hydra v9.5 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

[ERROR] unknown mode h for option -e, only supporting "n", "s" and "r"
                                                                                                                                                                                            
┌──(kali㉿kali)-[~/Desktop]
└─$ 
                                                                                                                                                                                            
┌──(kali㉿kali)-[~/Desktop]
└─$ hydra -L users.list -en ssh://10.129.232.82 -T 32
Hydra v9.5 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2025-02-18 23:37:34
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 16 tasks per 1 server, overall 16 tasks, 79 login tries (l:79/p:1), ~5 tries per task
[DATA] attacking ssh://10.129.232.82:22/
1 of 1 target completed, 0 valid password found
[WARNING] Writing restore file because 1 final worker threads did not complete until end.
[ERROR] 1 target did not resolve or could not be connected
[ERROR] 0 target did not complete
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2025-02-18 23:37:49

┌──(kali㉿kali)-[~/Desktop]
└─$ hydra -L users.list -p password ssh://10.129.232.82 -T 32
Hydra v9.5 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2025-02-18 23:34:24
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore
[DATA] max 16 tasks per 1 server, overall 16 tasks, 79 login tries (l:79/p:1), ~5 tries per task
[DATA] attacking ssh://10.129.232.82:22/
1 of 1 target completed, 0 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2025-02-18 23:35:15
#

can someone point me in the right direction?

#

do I need to use a brutespray list from /usr/share/wordlists?

#

because I cat that list out and it doesn't look like it will work

cloud urchin
#

if that's not working, have you enumerated anything else?

quasi wave
#

I am also trying to enumerate ftp:

┌──(kali㉿kali)-[~]
└─$ perl ftp-user-enum.pl -M sol -U users.list -t 10.129.101.73
Starting ftp-user-enum v1.0 ( http://pentestmonkey.net/tools/ftp-user-enum )

 ----------------------------------------------------------
|                   Scan Information                       |
 ----------------------------------------------------------

Mode ..................... sol
Worker Processes ......... 5
Usernames file ........... users.list
Target count ............. 1
Username count ........... 79
Target TCP port .......... 21
Query timeout ............ 15 secs

######## Scan started at Wed Feb 19 00:00:08 2025 #########
######## Scan completed at Wed Feb 19 00:00:15 2025 #########
0 results.

79 queries in 7 seconds (11.3 queries / sec)
#

I could try different userlist for ftp

#

but beyond that I don't know what to do

#

wait ftp port is not open

#

gonna look for a tool to enumerate ssh users

#

I think it looks like it can be done in metasploit I will read up on that later

cloud urchin
#

you don't need anything outside of the module

quasi wave
#

ok

#

well, I will keep looking then

cloud urchin
#

just make sure to enumerate everything and then investigate it all

quasi wave
#

ok thanks will do

modern spear
#

Hey guys i'm on HTTPS/TLS attack module, at the Bleichenbacher & Drown session, the question at the end of the session demand perform the bleichenbacher attack on a target system and provide a traffic.pcap file, i do extract the premaster_share_key in the TLS client key exchange and use it to perform the attack with -connect but it seems to run nonstop until the target system expire. Is that just becuz the attack take times or i'm doing something wrong?!

deft burrow
#

Hello!
Could i get a small nudge in the correct direction
Module: Footprinting
Section: Footprinting Lab - Hard

My Nmap scan shows an open port for 22 imap and pop3.

no credentials have been able to be retrieved.
Ive tested some basic usernames and they return with a +ok in POP3 but the passwords do not allow for auth.
I did see that 993 had ubuntu on it but when i attempted to view it as a web link Firefox blocked it.

Is there something i should go read on or review? I reviewed the IMAP/POP3 module and i have the same commands in my notes with no luck of another lead on direction

fathom pendant
#

btw ubuntu is an OS not a web service

#

993 would be IMAPS or POP3S i forget which

lusty thicket
#

either that or you didn't specify the right parameters

deft burrow
fathom pendant
#

nope

#

just giving some general info so you're not wasting too much time

#

not all services are tcp

deft burrow
#

🤦‍♂️ i see. I shall go dig further and report back with an updated status

#

Thank you

fathom pendant
modern spear
fathom pendant
#

that module is above t0 so it would be spoiling module content

modern spear
#

wow in that case maybe i try to digging further

#

anyways, thanks guys

deft burrow
half trail
#

guys i need some one to teach me

#

if there is any one he can dm me

waxen totem
#

No one's going to teach you personally unless you pay them to. That being said, start here:

compact patrolBOT
fickle crystal
#

i need help

#

i found a flag but no matter how many times i insert it in the box it says its incorrect

waxen totem
#

Restart the target, re-gather the flag and try again.

foggy seal
#

leading or trailing spaces? 😄

#

did you copy it or type it

#

does the input field ask for the flag or something else?

fickle crystal
#

stop smiling like i copied from ur notes bruh relax

foggy seal
#

alright!

fickle crystal
#

can i send a photo

waxen totem
#

Don't send photos of flags or flags themselves

fickle crystal
#

yeah i know

#

i hide it

#

after i get the carlos.txt to my linux machine

#

ok

waxen totem
#

Which module is this even?

fickle crystal
#

password attacks

#

Pass the Ticket (PtT) from Linux

#

if u do it now the way flag comes up its all weird

#

i tried doing it again

#

edit : that was a flag for another challenge lol !

rose escarp
#

Hey can u help me with targeted individual issue?

storm elk
rose escarp
#

Cybercrime organized stalking

#

Wrong place sorry i ll send in general chat

storm elk
#

You're in the wrong server

#

That's illegal

#

If you are targeted, contact law enforcement. Nobody here can help you. If they claim they do and ask you money for it, they are also wanting to scam you.

tawny coral
#

Regarding the issue I had with the modules dropdown yesterday: It seems it's an issue with using Firefox. Does anyone know where I can report the error? I've tried updating my Firefox, but it's still causing issues. Works perfectly fine in Chrome, though, but I don't really want to use Chrome

storm elk
#

You can report it via /feedback

loud nova
#

Hey there I have a question regarding the end of Attacking Enterprise Networks (I'm not stuck but wondering why one way worked while another did not) can I DM someone as to not spoil the fun for everybody else ?

sinful narwhal
#

python2.7 not working any help or suggestions ?

loud nova
#

Guess you'll have to be a bit more specific in your question 😉

sinful narwhal
#

Im running this command in module: Windows Privilege Escalation > Windows Desktop Versions

sudo python2.7 setup.py install

loud nova
#

Okay for what tool ? which version of it ? what is the error message you get ?

sinful narwhal
#

and other with python2.7

#

i also tried with python but no luck

loud nova
#

Okay what is the error message you get ?

sinful narwhal
#

SyntaxError: multiple exception types must be parenthesized

loud nova
#

can you provide the full error ?

sinful narwhal
#

File "/home/htb-ac-1306913/windows-exploit-suggester.py", line 390
except IOError, e:
^^^^^^^^^^
SyntaxError: multiple exception types must be parenthesized

#

/home/htb-ac-1306913/setuptools-2.0/setup.py:12: DeprecationWarning: The distutils package is deprecated and slated for removal in Python 3.12. Use setuptools or check PEP 632 for potential alternatives
from distutils.util import convert_path
Traceback (most recent call last):
File "/home/htb-ac-1306913/setuptools-2.0/setup.py", line 17, in <module>
exec(init_file.read(), command_ns)
File "<string>", line 8, in <module>
File "/home/htb-ac-1306913/setuptools-2.0/setuptools/init.py", line 11, in <module>
from setuptools.extension import Extension
File "/home/htb-ac-1306913/setuptools-2.0/setuptools/extension.py", line 5, in <module>
from setuptools.dist import _get_unpatched
File "/home/htb-ac-1306913/setuptools-2.0/setuptools/dist.py", line 16, in <module>
import pkg_resources
File "/home/htb-ac-1306913/setuptools-2.0/pkg_resources.py", line 1426, in <module>
register_loader_type(importlib_bootstrap.SourceFileLoader, DefaultProvider)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
AttributeError: module 'importlib._bootstrap' has no attribute 'SourceFileLoader'

loud nova
loud nova
#

I'd suggest trying to find an alternative that's a bit more recent or trying to update the python code yourself. I personnaly haven't tried using it

sinful narwhal
#

any suggestions

loud nova
#

updated 5 days ago 😁

wooden seal
#

almost lost access to internet while using proxifier for this modulesadglas (SSH for Windows: plink.exe) be carfeul lads

sinful narwhal
primal eagle
#

why do my request responses look like its encrypted

storm elk
#

got it

primal eagle
#

no problem

storm elk
#

thank you

primal eagle
#

i feel like something is wrong with tls/ssl

#

but when using https it results in unsupported or unrecognized SSL message

#

ill restart the machine.

urban elk
#

it's not just gzipped ?

#

see Content-Encoding header

primal eagle
#

but why does my chrome show it all in response, while burp encrypts it

#

removed the gzip

#

now it shows...... thats so strange, why does it show the gzip

urban elk
#

dunno, you have gzip in Accept-Encoding request header, do you see that in chrome ?

primal eagle
#

yup

#

in firefox too

lusty thicket
primal eagle
#

it is installed and trusted

#

:/

lusty thicket
#

strange

visual umbra
#

Serve again.
I am sitting with Skill Assessment for the Webproxies module and am a bit stuck on the question: Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload) .

I have decoded the cookie and as I said, one character is missing to get an MD5 HASH, I fuzz in Burp, but only one result of the attack stands out from the others so I test with that character without success. I've tried a few different other characters found in the attack, but the same thing there.

And one thing I don't really understand is: Once I find the right character, should I decode the MD5 HASH and then just replace the cookie with the decoded HASH to get the flag?

lusty thicket
#

iirc there should be an automatic decompression option in burps options

#

might be wrong

primal eagle
#

is already checked tho

lusty thicket
primal eagle
#

ooooo found it, it was disabled in repeater

lusty thicket
#

awesome

visual umbra
#

My problem is what to do with the cookie after fuzzing, i try to change the cookie to the one iv fuzzed, but no one works..

lusty thicket
#

alright

#

no you don't decode the hash after fuzzing

#

fix the cookie with the complete hash and resend the request

visual umbra
lusty thicket
#

if you're trying to do it, then why're you still stuck?

visual umbra
#

Am I probably the one explaining poorly...

#

I have fuzz and tested the ones I get as a result in the attack, but none of them work. I've sneak peeked in a writeup so I know it's the correct HASH for the cookie I'm using etc...

#

So somewhere I'm simply making a mistake..

lusty thicket
#

yeah

fathom pendant
#

@modest fossil what do you mean by collaborator, that's very vague, i also suggest reading #rules

dim crater
#

Guys in the Password Attacks modules, about the PtH attack, there is the method using RDP, which could show an error for Restricted Admin Mode. The module suggests disabling it from the registry entry..etc And I don't understand the logic of it, if we already got access to the target, in which case i would use this method? Is it only too get the GUI ? or some kind of local priv esc? What benefits does it come with? thank you !

rustic sage
#

By default, RDP does not allow authentication via hashes. It expects cleartext credentials.
When you add the key, this enables Pass-the-Hash (PtH) attacks over RDP without knowing the plaintext password.
Since this module is regarding PtH, the module is teaching you that if you have command execution on a target system (but not full credentials), you can enable Restricted Admin Mode to allow Pass-the-Hash (PtH) attacks over RDP.

#

You'll find lots of command execution vulns

austere heart
storm elk
#

Don't cheat @coral saffron

#

This is not the server to help you cheat at a quiz.

coral saffron
#

sorry

visual island
#

Hey guys, I need help on the path AI Red Teamer in the exercise "Applications of AI in InfoSec Page 25 Skills Assessment" whatever I try, it turns out that "Your model accuracy is 0.0. Please improve it to at least 90% to receive the flag."

rustic sage
hushed rivet
#

Question: if you cancel your annual subscription before the next payment occurs, do you immediatly lose access or can you just keep using it before the next payment.
like gold academy for example.

steady spade
#

Hi man did you success to finish the module because i'm stuck too

fickle thicket
#

yup i did finish it

steady spade
#

did you have certificate problem ?

#

because i try to create a rogue AP for the StarLight ssid but i have an certificate error (because it's autosigned i think)

signal hound
#

Hi im doing password attacks PtT on linux.
Could someone explain to me why would i need chisel for tunneling if i have RDP acces to ms01? What am i trying to achieve with it?

steady spade
fickle thicket
#

you at qns 1?

steady spade
#

no the second

fickle thicket
#

did u use /opt/wordlist.txt

rustic sage
steady spade
#

nop i used the rockyou

fickle thicket
#

then use /opt/wordlist.txt

steady spade
#

ok thks i'll try 😉

fickle thicket
#

EAPOl handshake

burnt hill
#

Hi everybody, I am really stuck with the Footprinting medium lab (https://academy.hackthebox.com/module/112/section/1079), I found the credentials mounting the NFS folder, then I found the credentials in the important document, then I connect vida RDP using the first credentials, but when I am trying to log in SQL server I get an error, any hint in what I am doing wrong?

cedar void
#

Did anyone else think that the "ATTACKING enterprise networks" was one of the easiest modules in the Pentesting Path?

vast kiln
#

Could someone assist me on the lateral movement section of attacking enterprise networks? For some reason PowerView does not want to properly import, tried it both ways where I connect my directory with RDP connection or upload it through DNN, but in both cases the cmdlet isn't recognized

pseudo kiln
pseudo kiln
pseudo kiln
burnt hill
vast kiln
pseudo kiln
sinful narwhal
vast kiln
pseudo kiln
#

powerview is one way, there are multiple ways to achieve it

velvet belfry
pine dune
#

u mean the link marcie gave? I believe you have to connect your htb account to the discord

autumn crypt
#

I'm doing the network foundation module. But I can't pass this question. What advanced feature does a Next-Generation Firewall include beyond stateful inspection?

pure jolt
#

Hey muralikurva, did you ever solve this? I'm running into the same issue as you - as far as I can tell, my hash file looks good and even re-mutated my passwrd list with cutom.rule, as well as tried rockyou.

grim basin
vague geode
#

u could dm me

latent glen
#

what can I do to get rid of this error. In the ntlm relay module

vague geode
#

or ping me

grim basin
#

I'll dm so I can share the command with you

latent glen
#

there is a connection coming in from HTTP but I cannot relay it

#

nevermind

grim basin
#

In short, I got the OTPs requested, but my FFUF commands dont seem like theyre turning up anything.

#

The requests are succesful, but I can't find the right thing

gray yacht
rustic sage
#

Guys how to open a pdf with password, I forget my password, can anyone help plsss

analog dock
#

🧍🏼

fathom pendant
#

pdf2john and pray your pw is in a wordlist

rustic sage
fathom pendant
#

no

#

it's not related to an academy module, and i'm not in the business of resolving personal skill issues unrelated to my tutoring program (which is for academy)

tired atlas
#

hiiii so I'm on shells and payloads laudanum web shells, and I'm having a 404 server error come back to me when I do status.inlanefreight.local//files/demo.aspx

I've modified the /etc/hosts file with the vhost
I've added the IP in the aspx allowedIP string
I've restarted the machine, respawned target

Anyone have any other ideas on what I could try?

fathom pendant
tired atlas
#

hm no i didn't actually

#

what a dumb move

#

yeah that worked

#

thanks

shut ice
#

NTLM Relay Attacks- Skill Assessment, Q3: Submit the password of the SQL user 'sqlftp'.

Can anyone help with this? I've compromised BACKUP01 but not found any more creds. I've trying to stick to the techniques covered so don't think I need to run mimikatz to grab more creds from memory?

I've seen the clear-text SQL pass via Responder but that doesn't give me access to any shares on Backup01 or SQL03? (I've tried dropping a .lnk file in the share on Backup01 but no further auth requests have come through)

edit: Think I've solved this, remember machine accounts may have access

latent glen
#

Hello everyone. I am doing the ntlm relay assessment, I have a computer account that I created via ldap. I got an smb shell on BACKUP01 but I don't really know how to proceed. Id love a hint towards compromising BACKUP01

shut ice
#

^ I've just done this but stuck on next step. With the computer account you've created try Coercing a machine/enumerating ADCS and use one of the techniques to access it @latent glen

latent glen
#

I am trying petitpotam but it doesnt seem to work

#

lemme try coerce

shut ice
latent glen
#

aight

zealous rune
#

hi i'm still stuck on log poisoning section of the LFI module

#

I've attampted to poison the log file with a php shell

#

however this causes the log to become unavailable

#

due to payload bunny's hint i've identified characters in the payload that may be causing the issue

#

i'm unsure how to proceed further

fathom pendant
#

module is above t0 i suggest taking to DMs if you're gonna troubleshoot further

latent glen
#

aight

shut ice
zealous rune
#

As far as i can tell my log poisoning attempt causes the access.log file to "disappear" i.e. i cant retrieve it using the LFI vulnerabilitiy but i can retrieve other files

fathom pendant
#

' and " are different entities

zealous rune
#

true

fathom pendant
#

also if you break the file you gotta reset the target

zealous rune
#

yh i've been resetting the target a bunch hahah

#

i realised one thing tho. <> don't get rendered in the browser which is expected behaviour

#

" get's escaped

#

grrr keep breaking this file

winged gate
#

Hello All ! i'm new on this server.

I'm actually working on penetration tester path on the module Attacking common services, i'm at this question : What port is the FTP service running on?

this is so frusting .. i feel like dumb because i don't find any thing.. is there any problem with this module or i'm doing something wrong ? thank you

fathom pendant
winged gate
#

Okay thank you ! I’ll try it then .. hope it going to work ! 😁

pastel tinsel
#

New to htb. Got stuck briefly on a box b/c I didn't realize the naming convention used here for flags (was accustomed to "flag.txt"). Is there a readme for simple stuff like that? Curious if there are similar naming conventions for ssh keys apart from the typical "id_rsa" or other gotchas that might trip me.

fathom pendant
#

Typically they'll be id_rsa

#

User.txt and root.txt are the common ones on boxes

#

Read and follow #welcome to access more channels

winged gate
pastel tinsel
true kestrel
#

I’m working on JS Deobfuscation:Source Code, it seems pretty straightforward and I see the flag, but it isn’t accepted. Any thoughts?

fathom pendant
#

The answer is in the website source code

true kestrel
fathom pendant
#

this module heavily catches you on working ahead