#modules

1 messages · Page 390 of 1

shut ice
#

Can anyone give a hint on the last question for the NTLM relay skills assessment?

zealous rune
#

is the in the ad module?

shut ice
#

It's "Compromise DC01 and submit the flag located at 'C:\Users\Administrator\Desktop\flag.txt'"

I've got the sqlftp password but can't find where to go using content from the module, the module is just called NTLM relay attacks I believe

fathom pendant
zealous rune
#

ok

#

i didn't know which module fantalemon was referring to

#

I'm still stuck on the log poisoining section of the LFI module in the CPTS path.

#

it doesn't break the file but it results in an empty string being logged

#

maybe i need to encode this

#

but i'm not sure that urlencoding these characters will really solve anything since i want the payload to be loaded

surreal chasm
#

Hey, I just finished Attacking DNS Under attacking common services

I think I understood why it worked but I want someone to verify it for me

when we found ||the subdomain hr.inlanefreight.htb|| it was vulnerable to ||zone transfer|| because it was an NS well?

full patio
#

Hi all, currently working on the Skills Assessment for SQLi - https://academy.hackthebox.com/module/33/section/518

I've so far found the SQLi and able to read certain files, like the ||/etc/apache2/apache2.conf||

I've read and re-read the 'writing files' section, but I ||can't find this web-root to write the shell to.|| ||The hint talks about reading files I know.|| Should I be looking elsewhere? 🤷‍♂️

zealous rune
#

what's the error you get

#

permission denied?

zealous rune
#

have you checked your path?

#

check the url

#

I think i figured something out with the log poisoning section in LFI module

#

certain chars are being stripped by apache so don't get logged

full patio
zealous rune
#

look at the url u r on

gray yacht
full patio
zealous rune
#

gl

#

i'm still struggling

#

keep breaking access.log

#

and having to reboot the box

gray yacht
zealous rune
#

thank u

grim basin
gray yacht
grim basin
#

i think my commands good and im trying a really big wordlist for directories but im not getting a result

gray yacht
#

Not sure what endpoint you are working on, but I'd try that one you were messing with earlier when we spoke.

#

You can DM if you aren't getting anywhere.

grim basin
#

mhm thats what im using as a target

#

ill try a couple more things

deep pier
#

Quick question how do I know which thing to connect to my pwnbox

fathom pendant
#

?

#

NEI (Not enough info)

deep pier
#

I'm on the first bit and it comes up with parrot

#

And README.licence and other things

pine dune
#

Hi guys

fathom pendant
pine dune
#

If anyone is currently doing cpts or cbbh path, please let me know so we can connect 🙂

deep pier
fathom pendant
deep pier
fathom pendant
#

Also you don't need to worry about license.txt

#

Intro to academy?

#

To rephrase; what are you trying to do

deep pier
#

I'm on the sections bit and it comes up with parrot and other bits and bob

#

Trying to connect to Pwnbox

fathom pendant
fathom pendant
#

Also if you read the link to the message it's not a warning or anything

pine dune
#

Oh sorry let me check it

#

I thought u were correcting me 😅

#

Holy shit thats a good offer

#

Can I dm you @fathom pendant

fathom pendant
#

Yeah

deep pier
#

Marcie

#

I've pressed start instance but I don't know where the terminal is located

#

Can u pls help

fathom pendant
#

There should be a full screen button. After that it's just looking around the screen to find it

deep pier
#

ok

#

Marcie I've found the terminal but why does it come up with bash thing when u try to put cat/etc/issue

fathom pendant
deep pier
fathom pendant
deep pier
fathom pendant
#

You did cat/etc/issue which made the prompt tell you it doesn't exist
cat /etc/issue

#

<command>[space]<options>

lusty thicket
deep pier
#

ohh i see marcie

deep pier
lusty thicket
#

you should

solemn fractal
#

Hey guys how is it going I am working on penetration tester module specifically Public Exploit section and fairly facing difficulties exploiting the system and want to know what exactly the exploit is for this task have tried in the screenshot but nothing seems working can someone please assist with this task thanks I really appreciate your support

safe star
#

its right in your face

solemn fractal
#

Yes cause I’m confused about the hint it says search for plugin and I don’t see anything exploit only that one for the plugin

lusty thicket
#

did you read the hint

#

maybe there's a clue

safe star
solemn fractal
#

This what I found because the server used simple backup but not working

lusty thicket
#

that's a nice laptop

fathom pendant
#

rce isn't going to work because it's a public docker container well to be more specific, a revshell isn't going to work

solemn fractal
#

Thanks now I search for plugin exploits but is a lot I don’t know a lot of help just need if someone did this before need the right exploit I already know the process @lusty thicket @fathom pendant @safe star

fathom pendant
#

it's in your screenshot the proper one to use

#

you're just using the wrong one

unreal lotus
#

Hi Mods!

fathom pendant
unreal lotus
#

Sorry, I'm unable to send a text in HTB: OFF-TOPIC

fathom pendant
unreal lotus
#

I'm trying to join HTB: Seasons >> find-a-team channel.

#

Thanks!

solemn fractal
#

I have used the same exploit but I just got this but what’s next step I cat the file but nothing in particular only showing /root/bin usr/bin and many others @fathom pendant @lusty thicket @unreal lotus

lusty thicket
#

find flag.txt

fathom pendant
#

look at the options and see what you can tinker with

#

the question tells you where to look

#

if you have any bit of linux knowledge you should know the file you pulled

waxen totem
#

I know that section focuses on using MSF for public exploits but I'd recommend actually looking at the vulnerability and trying to attempt it manually as well as understand any PoC you use before using it

fathom pendant
#

this as well

#

msf for the flag; manual for the knowledge

solemn fractal
#

Her what I tried but still getting same /root/bin and other things @fathom pendant @lusty thicket @waxen totem

fathom pendant
#

you're overlooking an option

#

it's nothing to do with the URI

unique ether
#

infinite load on target spawning

#

any idea what i shoukd di

lusty thicket
#

refresh

fathom pendant
unique ether
#

tells me to launch again

fathom pendant
#

that's intercepting the request and waiting for you to forward request

unique ether
#

so i dont have those tools instlalled

fathom pendant
#

? the pwnbox absolutely has those tools installed LOL

unique ether
#

no thats not what i mean

#

nvm it launched

waxen totem
#

Patience is a virtue... that being said: Yes the module targets sometimes take their sweet time in spawning

solemn fractal
#

Thanks guys for making me think deeper I got the flag eventually appreciate your help @waxen totem @fathom pendant @lusty thicket

lusty thicket
#

awesome

waxen totem
#

Seriously stop pinging us all

solemn fractal
#

Just wanted to appreciate nothing more not meant to hurt anyone

rich frost
#

Hello everyone just starting this journey and could use a little help.

compact patrolBOT
rich frost
#

What is the first step in the process of a web browsing session? (Format: two questions) this one has me stopped dead in my tracks. what am i not realizing here? Navigation, entering a URL in a browser is the first step. At least i think.

#

I don't get the format request.

fathom pendant
sturdy ivy
#

This might be a stupid question: I'm going through the Windows Event logs module, and the challenge isn't the module but how fkn slow the machine is. Is there a way to get the event logs from the rdp'd machine and browse them locally?

fathom pendant
#

use tcp vpn

#

tcp tends to be more reliable than the udp one, especially for RDP, a connection oriented protocol

sturdy ivy
hybrid shuttle
#

I have one unanswered question while doing the 'Take Control of the EIP' section of the 'Stack-Based Buffer Overflows on Linux x86' module.

I understood the concept what they have taught there, but I am not quite sure of the process. I mean, my question is, by seeing or judging what factor, I can tell that I can taken control of the EIP register? Is it the address of the EIP and EBP that has to be the same like,

ebp [Same Address] [Same Address]
...
eip [Same Address] [Same Address]

Well, I just want to make myself ensured that, how I have actually taken control over the EIP resgister?

rustic sage
#

Giys

storm elk
#

this is not hacker fire hire @rustic sage

lusty thicket
#

if execution lands where you intended and doesn't crash, then you own the flow

#

ebp has nothing to do with controlling eip

hybrid shuttle
pseudo kiln
#

anyone around for some help on Attacking Common Services - Medium ? I repeated the same commands in the solution on both personal VM and pwnbox and it still does not find the port

azure pond
#

In introduction in windows command line skills assessment I have successfully logged in as user0 and I only see an Alert! banner but it is not the correct answer. What am I doing wrong

spark summit
#

how can I start with htb as a beginner?
any youtube vd suggestion?

pseudo kiln
midnight ridge
#

can someone help me on Skill Assessment of Crackmapexec module in CAPE please?

#

it keeps showing me error:
ERROR NetBIOSError on target 172.16.15.3: Error while reading from remote

#

and this one:
ERROR NetBIOSTimeout on target 172.16.15.3: The NETBIOS connection with the remote host timed out

#

i want to enumerate share on DC, sometime it works, but most time it show me these errors

signal hound
#

Hi
Doing the first optional question on passwords attacks PtT on linux
Im trying to use chisel to connect to dc01
But when running wmi-exec impacket cant the find dc01

pseudo kiln
#

it should fix it

midnight ridge
rustic sage
#

hi, any idea why burp won't url encode injection characters like \n

#

Are these characters supposed to be looked up manually for their URL encoding?

vocal beacon
#

Anyone ever had this issue with Bloodhound where the json files just don't upload at all?

rustic sage
#

Yes, version mismatch

#

Try downgrading Bloodhound. It had to do something with it 100%

vocal beacon
#

Interesting, I never had this issue with bloodhound-python but now with SharpHound.exe

rustic sage
#

or

waxen totem
#

there's an area in bloodhound settings where you can download the appropriate ingestor for that version of bloodhound

rustic sage
#

Try legacy SharpHound

rustic sage
vocal beacon
#

"This version of SharpHound is compatible with the 5.0.0 Release of BloodHound"

My Bloodhound version is 4.3.1 so that might be the issue

rustic sage
#

Exactly

vocal beacon
# safe star Try bloodhound-python

INFO: Found AD domain: <redacted>
INFO: Getting TGT for user
WARNING: Failed to get Kerberos TGT. Falling back to NTLM authentication. Error: Kerberos SessionError: KDC_ERR_PREAUTH_FAILED(Pre-authentication information was invalid)
INFO: Connecting to LDAP server: <redacted>

Currently getting this when using bloodhound-python

shut ice
#

Can anyone help with NTLM Relay Attacks Q4? - Compromise DC01 and submit the flag located at 'C:\Users\Administrator\Desktop\flag.txt'

I've got the password from Q3 but can't find where to go using content from the module 😦

sand sedge
#

in dns modul i was trying to get subdomains of a vhost with gobuster this is the command ``` gobuster vhost -u http://94.237.55.238:46777 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain -o subs.txt -k

rustic sage
#

Maybe 0 matches?

sand sedge
#

if he has 0 matches then what wordlist will match

#

bc it is a vhost subdomain

#

Brute-force vhosts on the target system. What is the full subdomain that is prefixed with "web"? Answer using the full domain, e.g. "x.inlanefreight.htb"

rustic sage
#

Try to do it via DNS

#

They might be using uncommon naming conventions

sand sedge
#

this wordlist is in DNS

rustic sage
#

You can dump the whole subdomain list through DNS too eg. zone transfers

rustic sage
#

Yes

sand sedge
#

i will see

burnt hill
#

Hello again, still stuck with the footprinting medium lab #modules message
Any clue about what's happening?

#

I am getting this error

sand sedge
burnt hill
#

I tried different passwords I found, run as administrator, but nothing really works

sand sedge
#

trasfer failed

rustic sage
young ore
solemn fractal
#

Good morning everybody hope you’re all having an amazing day just starting digging around for penetration tester pathway anyway does anybody have done the path or currently working on it

young ore
sand sedge
#

yeah it is but why

sand sedge
young ore
#

Yea i’m not sure as well, but it’s requesting vhost so we need to put on the host domain i guess, not the host ip

sand sedge
#

it's like you search someon with it's internet name

young ore
#

Something to do with dns name mapping

#

Idk😵‍💫

storm elk
#

on it

nova forum
#

I ||reversed|| the labels but I have no good results...

winged gate
#

hello all !!

i'm actually on the attacks common service modules , at this question : Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

i did everything, but when i want to do dig axfr it doesnt work any advice ?

cloud urchin
winged gate
cloud urchin
#

well, there are only a couple other tools mentioned.. i would try each one

winged gate
#

i will then .. thank you

winged gate
foggy monolith
#

I did end up needing to use the abbreviated service name after all. Weird.

surreal chasm
#

Is HTB academy works for you?

#

Waiting like 10 min for the instance to spawn

cloud urchin
surreal chasm
#

I resetted both Target and HTB attack box and it worked

latent glen
#

Hello everyone, so I am in the Skills assessment for NTLM-relay Q4. I have Q3 and now would need a slight hint for Q4

shut ice
#

Do machine account passwords change on the modules? I've gone back to a lab today and the machine hash isn't working anymore

latent glen
#

yes when you turn the vm off you have to create the machine account again

shut ice
#

No I mean the lab VMs, not one I've made

fathom pendant
#

they shouldn't

shut ice
#

I'm sure the backup01$ hash has changed on the NTLM relay lab, we will see anyway

tranquil wren
latent glen
fathom pendant
#

i haven't done that module at all

#

haven't touched t3 modules

fathom pendant
tranquil wren
#

do you have any quick links on how to build it?

fathom pendant
#

make an edit to the log

fathom pendant
tranquil wren
#

i must have missed i will re-read it

fathom pendant
#

i rarely use msfconsole personally

#

so it's kinda pointless

#

and the times i do, having a db isn't really helpful

tranquil wren
#

hmmm okay, noted

fathom pendant
#

but if you use msfconsole a lot then nothing wrong with it

tranquil wren
#

i wish i knew enough to not use it for this module

#

lol

fathom pendant
#

well that module basically requires it

fading olive
fading olive
#

But I still don't get a shell though...

warped hawk
#

Hello! I am in the exact same situation. Does anyone have any hint on last DACL1 SA's last question, please?

fathom pendant
#

make sure you're using the right file as well

#

the one in the user's home is correct

fading olive
# fathom pendant why do you need a shell?

It's what's shown in the lesson but I guess I could go for a simple bash terminal spawn, the thing is if I don't get a reverse shell it means the payload isn't executed and I assume it won't be executed even if it's a bash terminal spawn that I do

fathom pendant
#

not everything will be 1::1

#

also sometimes it can take a minute for the payload to execute

fading olive
fathom pendant
#

yes

#

spoilers my guy, it's why i deleted your initial message

#

i suggest tinkering with it for a bit and having some level of patience

craggy flicker
#

Yo guys, I’m entering the field of cybersecurity, and I need to buy a laptop, do you guys recommend the MacBook Pro m4 chip?

tranquil wren
#

got it, thanks @fathom pendant , i just needed to start the database i was looking at building .xml files for nmap lol

fathom pendant
craggy flicker
fathom pendant
#

most vms require a minimum of 40Gb hard drive space and 4-6Gb of RAM; your host needs to have more than those to be able to smoothly run them

craggy flicker
#

Understood, the last thing I’ll say in this channel about this is I’ve been asking around for quite a while if macOS is good for cybersecurity and I’ve been getting mix opinions abt it, some say macOS is better but other say that windows is more suited

#

But thank you for your feedback

pseudo kiln
#

Guys I have question regarding Inveigh.exe. I cannot seem to be able to enter interractive mode when I press Esc key (it still poisons requests and captures NetNTLMv2 hashes), unless I am inside RDP. Reverse shells and and evil-winrm do not work. So I guess it simply needs a GUI like RDP for it to work in interactive mode with Esc key ?

silver tusk
#

In the module Cracking Passwords with Hashcat on the WPA/WPA2 I get corrupted .cap files. Is there a specific way i have to unzip the zip file or is there something wrong?

loud nova
#

Hey there I am trying to get bloodhound-python working on the Attacking Enterprise Network module (I did it once with sharphound without issues but I am trying the other way). Whatever I try I always get an error. I'm using Ligolo for proxy. Has anyone experienced such issue ? Thanks in advance

#

(note it worked in the AD module)

tranquil axle
loud nova
tranquil axle
#

What error are you getting?

loud nova
tranquil axle
#

Sure

tranquil wren
#

What is your go to nmap line, one that you run generally on every host, mine is currently nmap -sV -sC but i thought there may be something better

loud nova
grim basin
#

||ive tried it through api v1 products, but that fails for me, and uploading a photo tells me to contact the site admin||

upper delta
#

Can someone explain to me, why I cant copy targets (ip+port) and paste it into the Pwnbox? I have to type it manually. Browser is firefox on windows

young ore
hexed ferry
#

I followed the module exactly and I'm stumped

safe star
grim basin
#

can someone please help me?

fathom pendant
#

@hexed ferry avoid spoiling modules

safe star
#

only things that matters is the log tho

hexed ferry
fathom pendant
#

therefore info in it can be considered spoilers

dry prism
#

I'm working on the Modern Web Exploitation -> WebSocket Analysis in Burp module and I am not really understanding how it wants me to modify the info to grab the flag. The directions aren't super clear.

hexed ferry
fathom pendant
#

@lost nexus stop begging

hexed ferry
#

Can anyone give me a hint as to why this error is happening?
$ proxychains netexec smb 172.x.x.x -u <redacted> -p <redacted> [proxychains] config file found: /etc/proxychains4.conf [proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4 [proxychains] DLL init: proxychains-ng 4.17 [proxychains] Strict chain ... 127.0.0.1:8081 ... timeout [proxychains] Strict chain ... 127.0.0.1:8081 ... timeout
I double checked the proxychains.conf file and it's all good and even reset the machine several times.
I'm on the Attacking Enterprise Networks module

lusty leaf
#

Hi, Can I get some help with ARP Spoofing & Abnormality Detection module?
I'm basically reading off the packet number at the bottom right after applying the filter but not getting the correct answer.
The filter I'm applying is arp.code == 1 && eth.src == 08:00:27:53:0c:ba

fathom pendant
#

@rich frost my dms aren't open for module help

#

everything you need to know is on the section page of the module

rich frost
#

sorry. ill go through it again

white grove
#

hi, I'm struggling with the session hijacking section on the XSS module in CBBH.

I can get the XSS to fire and make a call to my script.js file, but i cannot seem to get the contents of that script.js to fire and then call to index.php.

I've tried the example in the solution but i can't seem to get it to work sadly.

shrewd tendon
#

Pivoting, Tunneling, and Port Forwarding module: RDP and SOCKS Tunneling with SocksOverRDP the host cannot connect to 172.16.5.19 no matter what i tried i cannot ping the server either it seems like its down any help΄?

thorny heath
#

Hello everyone, i'm doing the Introduction to Windows Evasion Techniques module. I'm stuck on the Static analysis section.

The question says:

Follow the steps of this section to recreate the shellcode injector (with your own shellcode), compile it, and place the EXE file inside "C:\Alpha\Static". After placing the file, wait up to a minute; if all checks pass, the file "C:\Alpha\Static\flag.txt" will be created, containing the flag.

I have followed the steps and placed the executable in "C:\Alpha\Static". But the flag does not appear. When i checked the log file ("C:\Alpha\Static\log.txt"), it indicated:

[02/20/2025 13:56:30] C:\Alpha\Static\ConsoleApp1.exe - OK - Undetected by Microsoft Defender Antivirus

It checks every minute.

Is it normal that the flag is not created ?

fathom pendant
#

A: target
B: middle host
C: question IP

#

middle host is provided by the reading

shrewd tendon
#

right now im : my system -> target host (with rdp) and trying to connect to middle host but seems down

#

cannot connect or ping the middle server

snow forge
#

hey, im on the Privilege Escalation section of the Get Started module, and I've managed to access the /root/.ssh/id_rsa file. I've copied and pasted it onto a local id_rsa file, did the chmod 600, and then I am trying to do ssh root@host -i id_rsa, but I'm getting a Permission denied. (i am very new to all of this, please bear with me)

fathom pendant
#

ping isn't necessarily a reliable thing with windows as an icmp echo request could be getting denied by default firewall rules

shrewd tendon
fathom pendant
#

@verbal phoenix you're spoiling information about the skill assessment; i suggest just asking for a nudge

fathom pendant
#

otherwise reach out to support

shrewd tendon
#

ok thanks

fathom pendant
#

consider anything you had to discover/find out as a spoiler

gray yacht
snow forge
fathom pendant
lusty thicket
#

@verbal phoenix the php code clearly slaps a date prefix onto your uploaded file

verbal phoenix
lusty thicket
#

and null byte injection has been dead since last decade

snow forge
fathom pendant
verbal phoenix
safe star
verbal phoenix
fathom pendant
#

if you do ls -la id_rsa do you see the owner and group as root root id_rsa

snow forge
snow forge
fathom pendant
#

@lusty thicket @verbal phoenix i suggest taking to dms

lusty thicket
#

i havent done that module

snow forge
#

i've done the chmod 600 id_rsa too, so I don't know what I could be doing wrong

lusty thicket
#

👍

fathom pendant
#

did you forget to specify port?

safe star
lusty thicket
snow forge
fathom pendant
#

-i doesn't do anything beyond tell ssh you're supplying an identity file

#

it still defaults to port 22

#

you still have to do as you did for the first question

safe star
snow forge
#

i did use -p for the first section, i didnt think i'd have to do it for the second section since the module didn't mention it

#

i'll try that

safe star
#

its the same server so the port wouldn't change

gray yacht
shrewd tendon
#

thanks @fathom pendant

#

it*

dreamy osprey
#

guys a little help here

fathom pendant
#

so the default ports are heavily locked down

dreamy osprey
#

for some reason htb academy is not logging me into my academy accout saying they dont have my account on records this is an account i have used over a year and even just yesterday?

compact patrolBOT
fathom pendant
#

reach out to support

fathom pendant
snow forge
dreamy osprey
fathom pendant
#

nothing we can do here on discord

white grove
lusty thicket
white grove
lusty thicket
#

yes, it triggers you already said this

verbal phoenix
white grove
#

the first script.js and then the index.php call is going to the same ip, which is my pwnbox ip, the .js works but the contents of the js doesn't, but if i put the contents of the js into dev console it runs,

its also word for word what the solution says to do, so i'm quite confused

verbal phoenix
#

when pasting script to js file have you removed semicolon(;) at the end ?

white grove
#

no its in there, is it supposed to be removed?

verbal phoenix
#

I was also stuck at this module for a day because this semicolon

verbal phoenix
white grove
#

oh! let me test

#

sadly still not firing,

#

I've removed everything after index.php just to see if the payload fires at all, and i can't seem to get it to run

verbal phoenix
#

hm, what about port of your php server ? it is 80 ?

white grove
#

8888, everywhere

fathom pendant
#

in your payload: are you specifying port

verbal phoenix
#

and you're including it in the script ?

fathom pendant
#

^

white grove
#

mhmm

#

i cant paste screenshots here it seems to show you sadly 😄

fathom pendant
#

that's because your account isn't linked also; spoilers

#

it seems like barrier is willing to help if y'all could take it to dms to troubleshoot the issues that'd be grand

white grove
#

sure ty, barrier are you happy to help?

verbal phoenix
#

why not of course

quartz lagoon
#

Hi, on the live engagement of the Shells & Payloads, when attacking the first host, are we meant to discover the credentials by ourselves or not? I've been trying for an hour and I can't find them so I'm starting to think we were meant to just use the hint

gray yacht
quartz lagoon
#

💀

#

thank you very much lmao i took the foothold for granted

quartz lagoon
#

kinda like a second attack box

leaden girder
#

Hi there, I'm breaking my head here on the Networking Fundementals...

The question is: What type of network cable is used to transmit data over long distances with minimal signal loss?
I know it must be Fiber or Fiber Optic Cable or in any way you would write it, but it's not taking it...
Am I too focused on Fiber?

fathom pendant
#

I believe this one is hyphenated

#

Bit of a PITA

lusty thicket
leaden girder
#

I feel like I've tried every type of way of typing it, hyphenating it...:(

fathom pendant
leaden girder
# fathom pendant Drop the word "cable"

I just got it the second before you send me that... now I feel stupid 🤣
I think the wording threw me off compared to the last answers I had to give which had you do multiple words, like the whole way of saying it

#

Thank you guys for the help 🙂

fathom pendant
leaden girder
#

I've got to say, it's a great module! This is basically the basics of my day job in support, it gives great understanding about networking 😄

fathom pendant
#

The important thing is you knew what it was talking about

white grove
# white grove sure ty, barrier are you happy to help?

just to keep you updated, Barrier confirmed everything was correct and tested it themselves, it worked, didn't work for me however. I ended up skipping it and taking the cookie from the solution page. Might be something weird with pwnbox or similar, i tried restarting them but it didn't fix it.

Ty to @verbal phoenix for their help.

white grove
#

I didn';t change the pwnbox region, no. I kept it to UK the whole time but did several restarts

#

It didn't occur to me to test a different region, just terminated/restarted pwnbox

cunning berry
#

hi there, i'm working on Network Enumeration with Nmap "saving the results" the nmap scan says its going to take 4 hours. ||sudo nmap 10.129.12.71 -p- -oA target|| in order for me to get the xml file. i downloaded a new vpn file and reverted the target. sudo is needed the for this command, is there something wrong i can do to fix this?

onyx quarry
#

so how does this work

#

@astral elm

fickle crystal
#

Why don’t you just scan the most common ports

#

-F

#

-p- means scan the whole 60k ports

cunning berry
waxen totem
#

I mean the point of that section is just to save results you can just scan the most common ports: -p22,21,80

fickle crystal
#

FTP , SSH , HTTP

cunning berry
#

ok, but when i did it with -F and used ||xsltproc target.xml -o target.html || i got these errors: Warning: program compiled against libxml 212 using older 209 and when i opened the html file it was flank.

#

nevermind, it works now. thanks!

#

unfortunately, it does appeaer it was looking for a higher port which i didn't get with that scan ||31337||

cunning berry
warped siren
#

Forgive me if this is a question often asked or if the answer is already obvious to most, but does HTB ever plan to add a feature to reset the modules? Redoing modules from scratch, especially ones that have been updated since you completed them previously, would be great.

reef marlin
#

sup sup in the pivot module, in the chisel chapter when u try to start chisel on pivot host is it normal that glib version is to old?ubuntu@WEB01:~$ ./chisel server -v -p 1234 --socks5
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.34' not found (required by ./chisel)
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.32' not found (required by ./chisel)

fathom pendant
#

Ctrl-f: "static compile" in this channel

rich frost
#

is there a reason HTB wouldn't recognize a correct answer? I've tried typing it out, using the abbreviation, and both together. I've refreshed the page as well as logging out and back in. still getting incorrect answer. example: What type of architecture allows nodes to act as both client and server? "Peer-to-Peer" tells me incorrect answer.

fickle crystal
fathom pendant
rich frost
#

tried that to.

rich frost
tulip hearth
#

sup guys! can anyone help me for the password attacks: passwd/shadow/opasswd

#

cant crack the hash been stuck for almost 2 hours now hahaha

cloud urchin
#

best to say which module/section you're on

#

if you've been cracking something for 30+ mins, you're probably doing something wrong. make sure you're using the resources in the resources section of the module or any specific lists it tells you like rockyou, etc

tulip hearth
#

module 137 secion 1319

tulip hearth
cloud urchin
#

idk what names of the module/section those numbers correlate to

tulip hearth
#

ohh sorry wait

#

im on the Password Attacks module of Pentester Job Path.

#

Passwd, Shadow & Opasswd section

cloud urchin
#

are you using the mutated list?

tulip hearth
#

the mutated list for kira right?

cloud urchin
#

the mutated password list

#

earlier in the module it had you mutate the password list from the resources

tulip hearth
#

yess i mutated it to bruteforce kira's ssh

#

when i use the mutated list, i get 2 passwords, none of em are correct tho..

cloud urchin
#

make sure your hash is formatted correctly, you can find examples here https://hashcat.net/wiki/doku.php?id=example_hashes, or using the hashcat command itself it can also show examples although i forget the parameters off the top of my head so you'd have to man hashcat. if you're using the mutated list you should get it.

tulip hearth
#

yeahh im getting 2 passwords everytime i hashcat the unshadowed, but none of the two are working..

cloud urchin
#

sent you a DM

fickle schooner
cloud urchin
#

yes it is normal, you cut off your command so i can't see if you're filtering by size, but you also need to make sure you're filtering by size so you basically filter out all the responses with the same size and only see the responses with different sizes

fathom pendant
cloud urchin
#

had no idea that was a thing

fathom pendant
#

-ac

#

but it can be tricksy

#

so don't rely on it

daring tundra
#

Hello, has anyone encountered this behaviour?

I mounted my shared folder on the target machine while RDP-ing, upon copying some files over from the Target to my Attack Machine, I immediately got kicked out / dc-ed from the Target and am unable to RDP back in.

I tried Terminating and respawning the machine but it is like perpetually loading

#

Nvm... It spawned right as I asked this question

fathom pendant
#

use the tcp vpn i also believe xfreerdp has an autoreconnect option

daring tundra
#

alright, thank you!

foggy monolith
#

Tried exactly that and it didn't work. Attempted Enter-PSSession DC01 and got "Access Denied" after RDPing with Leon's hash.

raven scarab
#

Maybe I am an idiot, but what is the problem with this regex?
grep "^Permit" /etc/ssh/ssh_config

#

If I do the above without the ^, it finds a result. The above line however, returns nothing

#

Ahh wait, I think I get it, nevermind

foggy monolith
#

Not sure what else there is here. Anyone else have any ideas?

cloud urchin
#

looks like you don't have permissions to do that

foggy monolith
cloud urchin
#

it doesn't say use enter-pssesssion it just says connect

foggy monolith
#

It's literally the WinRM section of the Lateral Movement module. If not WinRM, then why is it even there?

cloud urchin
#

you never said which module and section

foggy monolith
cloud urchin
#

i haven't done the windows lateral movement so i can't help with it

#

your error is pretty clear though, it says permission denied so it's a perm issue with your user and winrm

foggy monolith
#

Yeah, with the very user the question is asking about, which is why I'm asking what the problem is.

#

Tried using Evil-WinRM with the hash directly; it doesn't deny access but it does time out.

ocean night
#

Can we not paste module-specific info like that for modules over Tier 0 please?

#

As for the issue, I've not done this module, but some Googling does reveal some options based upon the error message

#

If one tool is working, and another is not, there's gotta be something different they are doing, right?

#

End of module questions sometimes require you to not only use what you have learned, but go a bit further using a bit of research. The answer is not always spelled out in the preceding content, although most of the time all or the majority of what you need is.

foggy monolith
#

Problem solved now. Just needed to look back a couple of times

wooden perch
#

the "Documentation & Reporting" skills assessment teaches ONLY 1 thing: if your colleague at work leave in the middle of an engagement, don't rely on their documented work so far. Start from SCRATCH. horrible skills assessment, full of rabbit holes

tulip hearth
#

man, rdp activities in the password attacks are kinda making me frustrated HAHAH disconnects me then doesnt let me reconnect anymore

ocean night
#

@agile imp please stop cross posting the same message across multiple channels

#

Ultimately the module contents should have the information you require, and given the tier of the module you should not be posting such detailed messages.

#

If you've spoken so someone "in the know", they can surely give you a nudge

#

..but rest assured, the information you need is within the module and sections preceding this question. You may not be given the exact answer through the sections, and you may need to do some reading or thinking regarding the techniques.

agile imp
#

Okay thank you! @ocean night

ocean night
#

Posting the same message repeatedly across various channels will not help though

agile imp
ocean night
#

Then dear, perhaps do not keep repeating them

#

If nobody has answered, perhaps nobody is able to assist

#

I'd advise going back and re-reading the module and sections, see if there's something you have missed

#

Take notes

undone mesa
#

Hey, in the network fundations module i dont understand what im supposed to enter there i tried so many things, may someone help me ?

lusty thicket
#

what does your browser do?

undone mesa
#

it still says its incorrect

fickle crystal
#

ur browser be be translating the name resolution

lusty thicket
fickle crystal
fickle crystal
undone mesa
#

my english is not realy good to be honest

lusty thicket
#

i'm not really sure though

fickle crystal
dry prism
fathom pendant
undone mesa
fathom pendant
#

it also helps to give the section name for others to help you

fading olive
#

Hello, I'm still struggling on the Linux Privilege Escalation > Logrotate section.
I upload the logrotten.c file to the target, compile it then run it against log files that I have found in my user's home directory with two different payloads: one that's supposed to copy the root flag to my directory and the other that's supposed to send me a reverse shell but none work (I modify the log file to trigger logrotate). I haven't found the /etc/logrotate.conf file so logrotate could be using the "create" function as well as the "compress", so to make sure I ran logrotten with both options for both payloads but still nothing. I would appreciate some guidance on what to try next.

surreal chasm
#

Hey, i'm right now in the Attacking Common Services - Easy and i'm not sure if i'm even in the right direction
I've found the user with the help of ||smtp-user-enum||
Right now I'm trying to gain the password
I tried bruteforcing the password with ||basic auth in the HTTPS service|| but doesn't seem to work finding the correct password.
Same with ||RDP||

glass terrace
#

hey i am stuck at this question in penetration testing process post exploitation section 2d question

fathom pendant
#

@surreal chasm spoiler tags do nothing can you please redact username?

fathom pendant
# surreal chasm is that better?

👍 anyone can click spoiler tags, while they are decent for short-term messages you plan to delete, long term messages that may be helpful for others in the future would be spoiling or even just allowing people to copy your answers without doing the work

#

consider everything you find (especially in a skill assessment) as spoiler, and asking for help redacting usernames and passwords with first initial/letter and *
i.e.
f*
j*
j*:p*

surreal chasm
#

sure, noted

fathom pendant
#

anyway, try without the @domain

#

consider the protocol in use and why it may be formatted that way

surreal chasm
#

yeah i understand that, i think i might need to brute force the other service i didnt try, i just was a little lazy because it doesnt allow multiple connections so it might take longer to get the password

#

How can I know when should I use the @domain on some services? like in the bruteforce in the ||HTTPS|| service

fathom pendant
#

also i don't believe you need to bruteforce that service

surreal chasm
#

I mean, it does have an auth mechanism, so i guess it all should be connected

fathom pendant
#

not all auth mechanisms are built the same

surreal chasm
#

you're right

surreal chasm
#

well rn i'm trying any lead i might have

surreal chasm
surreal chasm
#

I've tried bruteforcing each service, with the pws.list but doesn't seem to find any
And i've tried search for CVEs but nothing can help me RN

I'm not sure if my direction is not right and what in my thought process is wrong

fathom pendant
#

@heady pagoda stop asking for help with your hacking game issue

novel matrix
#

rule 9 mate

rustic sage
#

Dude.. just move on. She not worth it

silver tusk
#

What module should i do if i want to do a man in the middle attack

blissful tusk
#

do i still get cubes after completing pathway or modules with a student account

young summit
#

hey, can someone help?
I'm stuck on Tier 2 command injection module Skill assesemnt
https://academy.hackthebox.com/module/109/section/1042
I couldn't file the RCE by my own and after googling the tinyfilemanager 2.4.6 CVE I found a RCE cve but that requires file upload which I currently do not have with guest:guest

honest crane
young summit
#

I tried all of the features with RCE none of the matched

#

the closest I got was something "when moving file from directory to another" and it seems like i'm searching for SSRF more than RCE right now

#

@honest crane can you direct me on which feature i must look into?

hexed lintel
# young summit

Moving feature is vulnerable, re read the module if you are stuck.

honest crane
young summit
#

I finally got it. thanks

young summit
# young summit

for real i was searching for a way to send the file without RCE ")

flint palm
#

Guys who had a problem when logginig into account from usb running kali linux telling you that you are a bot and not allowing to log in? How did you solve this problem?

#

Sorry if writing in not appropriate place

white grove
compact patrolBOT
pseudo kiln
#

has anyone managed to get the foothold on the Linux Priv Esc skills assements without the provided creds ? I think I found the exploit, but not sure what to use it with

#

nvm, I think I figured it out

charred parcel
#

not sure if this was pointed out, i think the parts where it uses crackmapexec might need to be changed to netexec or psmapexec, i know it's all the same concept but it's good at least to put as note since crackmapexe is not maintained https://github.com/byt3bl33d3r/CrackMapExec

lavish socket
#

I'm looking for some help regarding the Academy module Injection Attacks, skill assessment. I've identified the first vuln and am now trying to construct the injection payload.

My issue is, I'm not sure how to identify a successful injection. If someone has completed it recently, I could run through what I've tried more specifically.

hexed ferry
#

Can anyone advise why I get this error when trying to use Mimikatz?
ERROR kuhl_m_privilege_simple ; RtlAdjustPrivilege (20) c0000061
I'm an Administrator so not sure what the issue is.

fathom pendant
#

did you run powershell/cmd as admin?

harsh gorge
#

Have you ran privilege::debug?

harsh gorge
hexed ferry
lavish cloak
#

Hlo

gray jay
#

I spent 40 minutes typing bash as the specified shell type on a module just to realize all it wanted me to do was /bin/bash

I think I might be a little stupid

#

So much time wasted

trim vessel
#

hey guys how are you ?

hexed ferry
trim vessel
#

i'm new in HTB , and i don't know wish module i should start with

fathom pendant
trim vessel
#

if you have any advices

fathom pendant
compact patrolBOT
fathom pendant
#

Closing rdp != logging out

cloud urchin
# trim vessel if you have any advices

IMO really depends on what you want to do. Like marcielee said, if you're totally new you need to learn the fundamentals first. After that, really just go down a path related to the cert you want or whatever interests you like blue/red teaming.

fathom pendant
#

Your question was relevant, just used to people going "hi" then asking a completely off-topic question

trim vessel
#

I can ask here in this room ?

cloud urchin
#

This channel is about modules on the Academy platform, so yeah, asking which module you think you should start with seems fine as a topic here because it's related to the modules.

fathom pendant
#

Lol

honest crane
river haven
#

Hi! I am trying to do the AD Administration module but can't manage to spawn the machine. Does someone else have the same problem?

cloud urchin
quasi wave
#

I could try smtp-user-enum on port 110 but I am unsure at this point if that's even reomtely realistic

#

I need to get the username for a user on the server to be able to crack the password

#

can someone help me out here?

cloud urchin
quasi wave
#

I didn’t mean too I was frustrated and hyperfocused on determining if I’m even on the right track

#

So does the fact that I accidentally spoiled something mean I got the right protocol?

cloud urchin
#

no

#

Make sure you enumerate everything before trying to attack services

solar bloom
cloud urchin
#

Yes

solar bloom
#

Also how do you know exactly when running netstat which target enviorment you shouudl be looking at? My host IP doesn't match with what I'm assuming is the target network range.

fathom pendant
solar bloom
#

Right, my pwnbox is 10.10.15.136, so I just assumed target would be on the same subnet.

fathom pendant
#

The target is a public ip and port, also it helps others help you if you give the module and section name

fathom pendant
tired olive
#

where do you find the recommended machines related to each module? i was told to complete the recommended machines after each module of the CPTS path

solar bloom
fathom pendant
tired olive
#

how do i see them

fathom pendant
#

Open module > last page > finish

fathom pendant
#

Should bring you to the completion page for the module

tired olive
fathom pendant
#

Or search the module name, click, and it'll bring you to it

#

There's also academyxlabs which lets you search module name

#

And shows all "related" content

solar bloom
#

I'm on Basic Tools, Optional Exercise. Pretty much the first one I can do under CPTS. Playing with TMUX. The objective is to grab the banner which I know is just a nc command. NMAP scan of the 10.129.0.0 network said 1 was up but didn't yield any open ports. Perhaps I have the wrong nmap input.

fathom pendant
#

But if you search "footprinting" and check, you'll see why I don't recommend

fathom pendant
tired olive
#

ill look

tired olive
solar bloom
tired olive
#

just wondering how i should be attacking these modules

fathom pendant
#

You're not gonna need to dig for any "hidden" things on the outside

fathom pendant
solar bloom
fathom pendant
#

Link?

#

Bc I'm not finding that module name

solar bloom
#

Optional exercise at the bottom.

fathom pendant
#

Getting Started
Thats the module name

solar bloom
#

I'm sorry 😦

fathom pendant
#

The answer starts with SSH

solar bloom
#

Is there a way I can look for this in the future that will be of more help? Again sorry!

fathom pendant
solar bloom
#

Oh jesus. Sorrrrry.

fathom pendant
solar bloom
#

I think I have the answer but I'm just missing something. I submit the flag but says its incorrect. I'll move on. I appreciate the help tho.

fathom pendant
solar bloom
#

Yeah I did send you a PM on it. I had the banner but the OS didn't match so it was incorrect as a flag. Not sure what I did wrong there, seems like a simple banner grab. I used the target machine with the public IP and port 22. sadglas

cloud urchin
fathom pendant
solar bloom
#

Welp.

#

Got it. My fault. Lessons learned. Thank you.

cloud urchin
#

believe it or not, straight to jail

light siren
#

i am here

#

i am on linux fundamentals module section containerization and am stuck on this docker command

#

idk what im supposed to do here from where it says install docker-engine

#

and dockerfile, can anyone maybe help-

waxen totem
#

Module: Network Enumeration with Nmap
Section: Firewall and IDS/IPS Evasion - Hard Lab
Question: Need a nudge on this lab... was able to get versions for every other service but the one they want question

NVM got it...
for those who need help, here's your nudge: 🦸 , 🛜 🐱

waxen totem
light siren
#

i guess where it says to install engine i have to create and run the script?

waxen totem
#

Docker Engine is build into docker desktop, yep you run the script

light siren
#

is that the same with this part then

#

man theres so much that this thing just does not tell or teach you

waxen totem
#

It's designed not to dive deep into that topic since the guides available are already very good

#

Just follow the guide mate, stop posting it here XD

light siren
#

i am

#

its not clear

waxen totem
#

How so? It goes step-by-step

light siren
#

yeah if your talking about the like full walkthrough thats only if you pay for the entire year im doing month to month

waxen totem
#

I meant the one on docker's website

light siren
#

ah

waxen totem
#

Like I said: that section isn't meant to go in depth since it's a really deep topic and there's already good documentation which is linked in the section

light siren
#

yeah i saw that

#

so 3hour module cant be done in 3 hours when your brand new

waxen totem
#

Haha no~ I wouldn't trust the estimated times

#

I spent 1 month on a 10 day path

light siren
#

im not, thatll be me i make notes and my own terms of definitions and all while im doing the module

#

they had to of highlighted in green what you need to know kinda deal and all

cloud urchin
#

don't worry about the time. take as much time as you need to really understand the material, that's the key is understanding it.

light siren
#

thats been my focus i want to know and understand

#

i dont just wanna like copy paste

cloud urchin
#

that's good, writing down your own notes will help solidify things into memory

light siren
#

and i am like brand new

raven brook
#

is there no vc's or am i just blind?

tired olive
waxen totem
tired olive
#

one... month..? 😔

waxen totem
cloud urchin
tired olive
#

praying i dont have the same experience

#

im ~50% done so far so

waxen totem
#

How many days you done it so far? keep in mind I was only allocating a few hours to it per day cos I got other stuff

tired olive
#

~4-5hr/day

waxen totem
#

I usually do like 1~2 hours, half of which is spent reviewing previous topics

tired olive
tired olive
light siren
#

[us-academy-6]─[10.10.15.158]─[htb-ac-1748002@htb-cshyyartu2]─[~]
└──╼ [★]$ sudo systemctl start apache2
┌─[us-academy-6]─[10.10.15.158]─[htb-ac-1748002@htb-cshyyartu2]

waxen totem
light siren
#

that means it started correctly im assuming no news is good news typical

tired olive
tired olive
light siren
#

ah thats what i was looking for haha i kept trying to verbose it

tired olive
light siren
#

tysm gentleman appreciated

#

i know man but idc

tired olive
#

🤝

waxen totem
#

Nahh I'mma speed it up

light siren
#

i spent 14 years fixing cars and all so nbd

tired olive
#

shittt not w midterms coming round

waxen totem
tired olive
waxen totem
#

Time to quit discord ig 💀

tired olive
#

mutual lock in

light siren
#

ty both

tired olive
#

👋

little bear
#

Hey guys, Working on Intro to Assembly and wanted to see if someone has a solid understanding of mov and lea.

If so, then I was additionally wondering how to appropriately word what's happening with:

Code: Assembly

global _start

section .text
_start:
  lea rax, [rsp+10]
  mov rax, [rsp+10]

Thanks in advance! I see what's happening in gdb, just not sure how to best explain it 🙂

waxen totem
lusty thicket
#

mov is context sensitive, this means it loads either a value or an address, depending on whether there's a dereference

#

they also do the same thing when used with static labels

fickle crystal
#

yo it says login as kira

#

and get the id_rsa

#

and crack it

#

but john aint even cracking nothing

lusty thicket
#

convert the key for john

fickle crystal
#

thats the issue

#

it dosent convert

lusty thicket
#

use the tool ssh2john

fickle crystal
#

i did loll

#

i did all that

#

use the cracked password for kira and log in to the host

#

a bit ehhhh

#

in my view its like two seperate things

#

get that girls password

lusty thicket
#

ssh2john id_rsa to a hash file?

fickle crystal
#

log into some random host

#

get the kira password
login to the host

lusty thicket
#

like three times now

fickle crystal
#

sorry

#

loll

lusty thicket
#

try with hashcat

little bear
fickle crystal
#

bruh i told u hashcat is for the hash not for the key

#

the process of conversion the issue

lusty thicket
fickle crystal
#

common sense says the password must be something related to the password we got now

#

but still

fickle crystal
lusty thicket
#

run again and this time redirect stdout to another file

fickle crystal
#

okay let me try again must be some silly issue

#

loll got it !!!

#

u know the was a dash missing at the end of the id_rsa key

lusty thicket
#

let me guess, you initially copied it manually

#

like a caveman

fickle crystal
#

what u want me to do use python3 server to send it

#

i cant be fucked doing all that

lusty thicket
#

b64 is a safe option

#

no missing dash

#

or just netcat it over

fickle crystal
#

yeah next time

#

it was only one question

lusty thicket
#

awesome

fickle crystal
lusty thicket
#

want a cookie? 😭🙏

fickle crystal
lusty thicket
#

finish the really hard labs first

fickle crystal
#

have u ever thought about u never solved a insane box before ?

safe star
ivory finch
#

Hi guys, any tips on resoslving a issue on flags? Im working on the sqlmap essentials assessment, and i found the flag, but for some reason it wont accept it.

ivory finch
#

i did all those things, i also tried to find if there are any flags, but so far this is the only one. 😭

#

i tried to type manually, still wont accept it.

waxen totem
ivory finch
#

hmm,let me try it on the HTB machine..

cloud urchin
#

sometimes sqlmap may retrieve data in an encoding different from the expected one, or the db may be performing automatic type casting.. you might need to tweak your command syntax to account for that kind of stuff

ivory finch
#

okay, so the difference from the flag that i got from my machine and the HTB machine is just a 1 f'n letter! whhat!?

#

i run the same commands, btw

unique ether
tranquil axle
# ivory finch okay, so the difference from the flag that i got from my machine and the HTB mac...

That can happen if you use sqlmap with a time based attack and then your connection to the vpn is a bit spotty. Sqlmap tries to extract data via Timing (if the first char is a “a” take 2 seconds to respond, otherwise respond immediately), and if your connection is bad for a bit the normal response time is the same as the “you found the right char” response. Sqlmap can’t tell the difference when using time based, so it ends up being wrong for a single char

#

Ideally you try to find non-timing based errors first

zealous sable
#

hey guys ,i am the new one

river wing
#

Hey I am a new one here

latent glen
#

did you manage to fix this, because I get the same error.

Error: rpc error: code = Unknown desc = exit status 1 - Please make sure Metasploit framework >= v6.2 is installed and msfvenom/msfconsole are in your PATH
In sliver I cannot use the generate function. And yes, although its just a wrapper around msfvenom, I would love to fix this. Anyone know where in the settings I could force sliver to use msfvenom to use the correct path

lusty thicket
#

check with msfconsole --version

latent glen
#

Hello everyone, anyone know hhow to fix this error?

When trying to execute: generate stager --lhost 10.10.14.62 --lport 4443 --format csharp --save staged.txt

[!] Error: rpc error: code = Unknown desc = exit status 1 - Please make sure Metasploit framework >= v6.2 is installed and msfvenom/msfconsole are in your PATH

In sliver

I know its just a wrapper but I still want it work

latent glen
lusty thicket
#

run in debug mode

latent glen
#

OOOOOOOOOOOOH I FIXED IT

#

Or rather... I bypassed it. What the issue there is, I still have no idea. All I can say is, to use the releases binaries instead of the script to install sliver

wow, okay. So the issue is the following. When I first tried accessing the armory yesterday I would constantly get a segmentation fault. Turns out that was just a rate limit issue from githup but when turning on a vpn, I was able to download all of the assets (not ideal but good enough). It took me a minute to find this out though. Initially I thought it had to do with installing via the script vs downloading the binary from the releases. The thing is that in the end it started working with the installed version via the script so I just left it at that. BUT now. it turns out the generate stager command DOES NOT work with the sliver server that's installed via the script but ONLY with the releases version.

Now my next question would be. How do I get rid of everything the install script did and only stick to the releases binary.. have some reversing to do

#

but at least for now, I fixed the main issue I had.

waxen totem
latent glen
#

Indeed, that much I have now learnt

latent glen
#

Did you end up solving this?

tranquil axle
latent glen
#

sweet thanks got it. Now I wonder where we were supposed to retrieve this

safe star
latent glen
#

in sliver?

safe star
#

No

latent glen
#

The question is to find out what the user of the deployed db is by "further assessing the website"

#

we are talking about sliver

#

we are not in mssql

safe star
#

I used sqlmap tho

latent glen
#

on the website?

safe star
#

That wasn’t the right way?

safe star
latent glen
#

oooh wow

#

maybe that was the right way

tranquil axle
#

I tried with manual sql injection and did not manage to get sa as result to any of my queries

latent glen
#

ooooh, right, yea there is clearly and sqli I just confirmed

#

I completely skipped manually trying to exploit the db. Okay this definitely sets the tone for how this module is going to be. Thanks for the help guys

latent glen
near night
#

Hello Everyone!
I am studying this Path : Penetration Testing Path >> this module Pivoting, Tunneling, and Port Forwarding >> this page : Dynamic Port Forwarding with SSH and SOCKS Tunneling
https://academy.hackthebox.com/module/158/section/1426

Question 2 : Apply the concepts taught in this section to pivot to the internal network and use RDP (credentials: victor:pass@123) to take control of the Windows target on 172.16.5.19. Submit the contents of Flag.txt located on the Desktop.
I am doing that : by confirming that first in our Pwnbox/PMVPN, the proxychains.conf file has the SOCKS4 127.0.0.1 9050 entry:

┌─[eu-academy-6]─[10.10.15.15]─[htb-ac-745983@htb-ejferdh1dn]─[~]
└──╼ [★]$ tail -4 /etc/proxychains.conf

meanwile

defaults set to "tor"

socks4 127.0.0.1 9050

Which it is

But then when I send this command :
proxychains xfreerdp /v:172.16.5.19 /u:victor /p:pass@123

Here what I got :

└──╼ [★]$ proxychains xfreerdp /v:172.16.5.19 /u:victor /p:pass@123
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.16
[proxychains] Strict chain ... 127.0.0.1:9050 ... timeout
[05:52:06:684] [57030:57032] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[05:52:06:684] [57030:57032] [ERROR][com.freerdp.core] - failed to connect to 172.16.5.19
┌─[eu-academy-6]─[10.10.15.15]─[htb-ac-745983@htb-ejferdh1dn]─[~]

Any Idea Why I am getting this error ?

#

or like why it does not finding my proxychains !

tranquil axle
#

it says nothing is listening on port 9050, did you set up the ssh connection to forward the connection?

near night
#

aaah
The ssh -D

#

Nope I didn't !
Thanks !

near night
#

Sry for not replying
I don't want to

#

A question regarding this
it is somehow hard to follow
when I did this : ssh -D 9050 ubuntu@10.129.145.59
it is the same as this : ssh ubuntu@10.129.145.59 (this we connect usual , using port 22)
but in the first one we used the port 22 to connect to 9050 and then connect ubuntu ? is that explanation correct ?

fleet spear
#

usally TOR i used for 9050 and 9080 should be used for socks

near night
#

Nope

lusty thicket
near night
#

@lusty thicket thanks

fickle crystal
#

No disrespect

#

In ur language

near night
#

aha
good to know
I am not Persian

#

I know my name is Milad

fickle crystal
#

Lolll

#

Too late buddy

analog dock
#

🤔

#

Cant find that anywhere

fickle crystal
analog dock
fickle crystal
#

Cmon bro u got all them certs u still don’t know what set up means

#

Skill issue lollll

analog dock
#

How is it a set up though

fleet spear
#

i would say it is just trolling

analog dock
#

You’re just lying about something and I ask a question, great set up fam

fickle crystal
#

It’s a set up like I was tryina see if he fall for it

analog dock
#

Amazing set up

fickle crystal
#

Some light

analog dock
#

Well done

fickle crystal
#

No disrespect

fleet spear
#

im noob at burpsuite but i cant really get it to be able to modify the response if i use match and replace i can change the javascript

lusty thicket
fleet spear
#

always work to say no disrespect but...

fickle crystal
winged knoll
#

Im stuck with htb pen tenting job role path and wanna ask something from 2nd module can i ask it here?

#

So im at last of 2nd module of htb pentesting job role path at knowledge check and task is to gain foothold, i gained access to admin portal and in there i found plugins, there was option to share anonymous data but it was not editable so by further research i found components.php in which i added payload and saved it but still there’s nothing to listen up through nc
Guide me that my approach is right or not or where am i missing things out?

feral nimbus
#

Hi is anyone else having difficulty spawning targets from HTB modules right now? I'm unable to spawn target machine in skill assessment section of Linux Privilege Escalation module.

winged knoll
#

I think it’s happening to every module because im also facing the same issue in getting started module

dark hedge
#

@feral nimbus @winged knoll if you are using the EU VPN, it's undergoing maintenance and you should switch to another VPN

sage oyster
#

hi all, someone have spwning target problems ?

dark hedge
#

@sage oyster if you are using the EU VPN, it's undergoing maintenance and you should switch to another VPN

#

feel like we're going to see a lot of questions about this so gotta get the clipboard ready

sage oyster
#

it's not that I can't connect, it just doesn't create the target from the academy

#

can it depend on the vpn?

dark hedge
#

the target depends on the VPN you use

#

try switching to the US VPN if you are using EU

sage oyster
#

ok thank you very much for your help

past stratus
#

Hello there. How do I start my hacking journey? Where do I start learning ? Any idea anyone?

compact patrolBOT
flint palm
#

Hi Guys if someone knows how to deal with the situation when you are told you are a bot during login?

zealous sable
#

Hey, can someone help me decide whether to choose penetration testing or cloud security?

dark hedge
flint palm
#

I am using Mozilla in Kali on usb

limber fog
#

Hi !
Am I the only one having issues with the PwnBox & Target machines ?
I understand that only the VPN is in maintenance this weekend.
I have the following error. I am not sure I am in the right channel though 😉
Thanks !

dark hedge
#

@zealous sable please don't spam your question

limber fog
#

I'm not using the VPN, I just want to use the in-browser PwnBox + the "Spawn The Target Machine" button

#

I still tried to change my region to US (currently i'm in Europe), but nothing changed

dark hedge
#

hm

limber fog
#

I can see this from the choices list

dark hedge
#

might be a separate issue then

#

get in touch with support

compact patrolBOT
flint palm
#

Got in touch with support but they told me to use private browser what is the private browser and how to use it on kali

#

or switch network

feral nimbus
dark hedge
flint palm
#

how to turn on incognito mode?

past stratus
#

Do you recommend using VPN With TOR or using bridges?

dark hedge
#

try googling your question

past stratus
#

Yeah I have heard various opinions but I wanted to know yours that's all

dark hedge
#

i recommend no VPN but that's a question for a different channel -> #general might entertain that question

past stratus
#

Sure. I'll try asking there too

flint palm
#

Found and it worked in incognito mode by the way

limber fog
dark hedge
#

the link i sent you should also have an email PoC

past stratus
#

How to check my rank and what is this ranking system on this server?

#

And yes how to type in #general I cannot type in it. Do I have to verify anything?

dark hedge
wanton panther
acoustic owl
blissful tusk
#

can a student account access retired boxes?

acoustic owl
blissful tusk
#

but the pentester modules makes reference to practicing 3 retired machines and 5 active ones

acoustic owl
#

This is additional training that is not required to pass the exam,

blissful tusk
#

ah ok, but reccommended?

acoustic owl
#

Additional knowledge never hurts

blissful tusk
#

so whats the absolute baseline, like mandatory training

acoustic owl
#

Just the path

unkempt wadi
#

i am stuck one this so, if anyone can help ?

spiral sapphire
#

Anyone else unable to spawn the pwnbox?

coarse marlin
#

Am I the only one who gets an error when starting pwnbox?

spiral sapphire
#

I'm getting it too

#

Staff aware of the issue?

median gale
#

Any hint for NoSQL SA 2 ?

acoustic owl
fathom pendant
#

@coarse marlin @spiral sapphire EU? if so the EU/UK servers are down for maintenance

unkempt wadi
unkempt wadi
coarse marlin
#

I tried US, DE

fathom pendant
#

then reach out to support, be patient

spiral sapphire
#

US not launching either

fathom pendant
#

also make sure your vpn isn't on EU

spiral sapphire
#

Thank you! This worked

spiral sapphire
fathom pendant
#

or slightly above the "connect to pwnbox" settings

spiral sapphire
fathom pendant
#

connect via vpn

#

or something like that

#

(only if vpn is required for that section)

#

if it's a public_ip:port then yes, settings

blissful tusk
foggy ravine
#

i am very new to cybersecurity and i am having a tough time figuring out the flag for this module https://academy.hackthebox.com/module/35/section/227 i have spent about an hour looking through what i can but i cant figure anything out. there doesnt seem to be any console errors nor network connections that hints towards where the citys could be stored. again this might be obvious to the seasoned users out there but as a new learner this is really confusing for me at the moment

fathom pendant
#

the module teaches you how to discover API endpoints and figure it out; also it gives you directly the api.php/city

foggy ravine
#

apologies, but this is all new to me. i had a feeling asking for help on such a low level question would be stupid lmao

fathom pendant
#

http://ip:port/api.php/city is given by the examples

foggy ravine
#

thank you, much appreciated

fathom pendant
#

literally reading the section explains exactly what to do/how to do it

foggy ravine
#

alright, my bad

fathom pendant
#

asking questions is fine, but make sure you read the content before being like "i'm lost"

ancient niche
#

ey guys good afternoon i'm still stuck in the module AI

#

someone has completed this?

urban elk
inland oak
#

im stuck at window privillage modules..
the question is " what non-default privillage does the htb-user have" ..

#

anyone can help me

gray yacht
glossy cloak
#

Hi, I cant start pwnbox at MacOS fundamentals module. I am in EU, so I am guessing thats the problem, the maintenance?
there is no vpn for VM like in other sections?

fathom pendant
glossy cloak
fathom pendant
#

The cost and overhead (and legality) of emulating a MacOSX device is too damn high

pine dune
#

Hi guys, on the file upload attacks skills assessment. Ive uploaded my image in the submission form, however Im a little confused on how to access this image directly on the site

#

In the previous sections they always told us that the image could be found at "upload_images" in the examples and never really gave us an opportunity to find the images by ourselves.

#

here is my link

fathom pendant
pine dune
fathom pendant
pine dune
fathom pendant
pine dune
fathom pendant
#

Go through each filter check

#

Walk back through the steps of checking extensions, content-type, etc

somber pagoda
#

gng how do i type in general chat

#

?

fathom pendant
winged gate
#

Hello everyone, i want to make some activities but i can spawn target or pwndoc, do you have some issues on the plateforme to ?

waxen totem
winged gate
ocean night
#

@surreal bear @hallow kettle @tame urchin the modules and content you shared are over Tier 0 - please read the subject of the channel, and be more mindful over what you share, and how you ask for help. Do not spoil content for modules over Tier 0.

#

Spoiler tags do not make sharing such content OK.

surreal bear
summer portal
#

how do i learn hacking

compact patrolBOT
ocean night
surreal bear
ocean night
#

If that's the case, feel free to reach out in #1234357888114364508 - we do make corrections if an issue is valid 🙂

surreal bear
#

Alright sweet, does that channel have any of the same restrictions around what I should be sharing?

heady belfry
#

Hokay so, just started here, still in Linux fundamentals, question is, why does the module state to use sudo when we are not allowed/need password for sudo?

cloud urchin
#

I haven't done that module myself, but you should specify the section too

acoustic vector
#

Hello, I'm having trouble with SQLMap Essentials Attack Tuning. I have a flag for What's the contents of table flag5? (Case #5) but it tells me the answer is incorrect. The hint suggests to run --no-cast and running the command a few times but I always end up with the same flag. Any help here is appreciated

craggy sinew
#

wtf

safe star
fleet spear
#

but i wonder if this zap scanner isent broken considering how many questions it is about it

acoustic vector
#

Never mind, my session was just returning the same exact value every time. After I cleared my session I got the correct flag

fleet spear
#

it seems sometimes the data get corrupted

#

funny that someone was reported my nick 🙂

acoustic vector
#

And for the next question flag6 can someone please explain to me how I would find the needed prefix without looking at the hint? I don't think I would have been able to figure that out on my own based on the course material

fathom pendant
#

long answer: Fuck Around Find Out

acoustic vector
#

I can appreciate that to an extent, as that's what this is all about. Up until now I haven't even needed to click the hint button, but for something I'm paying for I would expect to see a bit more guidance. As of right now I have no idea how this particular example even helps me if I'm unable to figure out what I'm supposed to be finding. Is there access to the server side code somehow?

fathom pendant
#

nope