#modules

1 messages · Page 395 of 1

fathom pendant
#

you might be used to 3 octets for permissions rwx

digital steeple
#

ah

fathom pendant
#

owner/group/others

#

but there's a hidden 4th

waxen totem
#

SUID bit ftw

fathom pendant
#

special/owner/group/others

#

SUID -rwsr-xr-x
SGID -rwxrwsrwx
STICKY/restricted deletion rwxrwxrwt

digital steeple
#

Thanks for the advise, I did a whole section with no help.

fathom pendant
#

you won't really need to worry too much about SUID/SGID/STICKY for a while

digital steeple
#

I have a quick question

fathom pendant
digital steeple
#

I ran apt list --installed | wc -l and it said its not a stable CLI interface, but when I did apt list --installed 2>/dev/null | grep -v "^Listing" | c - l it did work. Howcome?

fathom pendant
#

and you'll see exactly why

fathom pendant
digital steeple
#

Wait, nvm.

fathom pendant
#

apt list --installed | head

#

that'll output the first like 10 lines

#

if you compare the two you get off by one

#

told you to be mindful of extra outputs

waxen totem
#

you also don't need the ^ in your grep

fathom pendant
#

also 2>/dev/null really didn't suppress anything

#

as | only pipes stdout

#

not stderr

#

or stdinfo

digital steeple
#

but why do we use 2>/dev/null in the first place

fathom pendant
#

2>/dev/null sends stderr (file descriptor 2) to the shadow realm

waxen totem
#

for find any time we don't have permissions on a file/directory it will output an error in stderr

fathom pendant
#

suppressing errors

fathom pendant
digital steeple
#

Thanks guys

waxen totem
#

go 30 mins without asking for help now 👀

fathom pendant
#

i don't recommend relying on it as sometimes you want errors to tell you why something broke

#

i.e. you typod

#

chomd instead of chmod Kappa

fathom pendant
#

haschat instead of hashcat

digital steeple
#

well, imma take a break, ive been at machines and stuff for 18 hours.

fathom pendant
#

you've been at academy for 18 hours

#

machines and labs are a different beast entirely

#

you don't get a rundown of what to expect for it

waxen totem
#

You don't know what it's like to be at a machine for 18 hours *ehem* darkcorp *ehem*

fathom pendant
#

just a vague hint based off the name

digital steeple
#

I swapped

waxen totem
fathom pendant
#

bold strategy doing machines first then realizing how lost you are

digital steeple
waxen totem
fathom pendant
#

HTB easy is other platform med/hard

#

unlike THM HTB says, here's a box -- goodluck

#

and you really gotta do research if you're green to the field

ocean night
#

That's the fun part 😄

fathom pendant
#

ye

#

i learned about an interesting service thanks to it

ocean night
#

Not for everyone, but certainly a way to get started and learn

waxen totem
fathom pendant
#

also learned some simple js commands

waxen totem
#

I like that I learned something from the newest box but... it is still just a shameless plug by the creator 💀

ocean night
#

So long as you learned something.. sellers gotta sell, and if the content team saw it as ok, hey ho 😉

fathom pendant
#
fetch(https://hackthebox.com/all_Flags).then(response => response.json).then(data => console.log(data))
waxen totem
#

Maybe I should do that

fathom pendant
#

speaking of i haven't plugged my tutoring in a hot minute

ocean night
#

I honestly know nothing about it

#

(the most recent machine)

#

I just trust our content team

waxen totem
#

but it has a tendency to confuse everyone which path is intended as there seems to be so many branches that all lead to user & root

ocean night
#

🤣

fathom pendant
#

no place like 127.0.0.1

ocean night
#

I know, I know.. we all gone off topic

waxen totem
#

Put the box in a module, problem solved kek

#

We can talk about nibbles here cos it's in the getting started module kek

fathom pendant
#

by a sharp technicality

#

i'm sure there's plenty of retired machines floating around the modules; i mean the Common Apps thick client is based off Fatty

#

well "based off"

waxen totem
feral abyss
#

hey for this question i got r*****32.exe but it doesnt say correct when i submit it did it fwork for you

prisma turtle
#

I have been stuck here for a while

ocean night
#

That's not a question - include the module, section. Do not post spoilers for content above T0. Read the channel subject @prisma turtle

prisma turtle
#

in module 19 section 101 I need help finding os I have looked for like 30 min

waxen totem
#

Yeah... need the names not the numbers

prisma turtle
#

network enumeration with nmap

waxen totem
prisma turtle
#

oh ok ty

spring charm
#

So, how much hacking and IT knowledge do I need to have to start the academy?

spring charm
#

Good to know, thanks!

compact patrolBOT
waxen totem
#

You could also start with the : Information Security Foundations path

spring charm
#

Thanks!

unique ether
#

Hi sql map module page bypassing waf question 3 ik I have to use random agent but when I checked the traffic I dint get error codes 500 but I got 200 with connection close

#

I checked the solution they just gave the command that's it

#

No explanation on why they used this

#

Based on traffic

#

Someone explain why

cloud urchin
#

some wafs silently filter instead of blocking, that could be why

unique ether
#

Nuts help

compact patrolBOT
wild rapids
#

Nvm

#

Dark web on phone is hard

compact patrolBOT
wild rapids
#

@cloud urchin how was my name offensive?

#

My name was Dokno

#

@cloud urchin

foggy monolith
#

Encountering multiple issues with trying to RDP to an IPv6 address in the Windows Lateral Movement Skills Assessment:

  1. xfreerdp thinks the IPv6 address dead:beef:df::3 is a hostname (it isn't)
  2. The /port:43389 switch is ignored by the xfreerdp command whenever an IPv6 address is specified

How does one get xfreerdp to recognize the IPv6 address as the IPv6 address that it is? What command line options do I need to pass?

wild rapids
#

@ocean night

foggy monolith
wild rapids
#

@fathom pendant

unique ether
wild rapids
wild rapids
foggy monolith
# safe star what about wrapping it in brackets

The full command used here:

xfreerdp /6 /d:inlanefreight.local /u:Arturo /p:'<REDACTED>' /w:2880 /h:1620 /dynamic-resolution/cert-ignore /drive:'backup',$PWD /port:43389 /v:[dead:beef:df::3]:43389 /timeout:99999

The command is ignoring the port flag and trying to connect on port 0 despite my explicit mention of the port number twice. Why?

cloud urchin
#

please don't ping random people

wild rapids
foggy monolith
cloud urchin
#

considering the vpn is only ipv4 how are you connecting to ipv6? is that even covered in the module?

fickle crystal
storm elk
#

I’d reply, but I’m not a girl

fickle crystal
storm elk
#

What’s the problem?

fickle crystal
#

ummm

#

so i run sqlmap

#

for flag6 and i still cant get any good results from honeslty ive beating eating my 100$ nails so

#

ive been running this is there anything wrong with it

storm elk
#

You can dm me 🙂

#

So to not spoil content for others

unique ether
safe star
unique ether
#

But in description it said connection closed

safe star
#

Just compare it to a normal request

hot perch
#

hi im so lost in the website

storm elk
#

Have you tried using the search function? 🙈

hot perch
#

hmmm

storm elk
#

It does help to mention what you’re lost on

hot perch
#

i just dont know if the things are free or no and does the intro toacademy count as a course a bit lost

storm elk
#

That should answer your questions

unique ether
#

This skill assessments I'm stuck since 3 hrs haven progressed at all

foggy sandal
#

I am facing the same issue, have you found a solution?

wild rapids
high citrus
#

Guys, i have a questions about the modules, i m doing the CPTS learning path as a Student, the modules i complete will remail available after i end the subscription?

unique ether
#

Yuh

inland grove
hardy spire
inland grove
#

I need a learn partner

hardy spire
high citrus
#

@inland grove Are u also interested in CPTS?

inland grove
#

Also doing the overthewire challenge

high citrus
#

Cisco is a great company for certificates, i did the cisco CCNA

nimble scroll
#

hi, I got this question and I don t understand what it is asking me , Try running a VHost fuzzing scan on 'academy.htb', and see what other VHosts you get. What other VHosts did you get?

#

I did to find vhosts in the scan but I don t know what to submit, every answear is incorrect and I don t know where to look

nimble scroll
#

Attacking Web Applications with Ffuf

#

Filtering results

fickle crystal
#

specially cisco packet tracer is the best tool to work and set up networks and learn about them

waxen totem
nimble scroll
#

yes

#

and I get at every 200 code

#

but when I submit, it is not the right answear

waxen totem
#

provide your command please

nimble scroll
waxen totem
#

am assuming it's in your host file, correct?

nimble scroll
#

correct

waxen totem
#

What happens if you don't filter out s 900?

nimble scroll
#

I still get code 200

waxen totem
#

show output real quick

nimble scroll
waxen totem
#

Ohh, gotta be more specific with your filter size kek

nimble scroll
#

that I don t know how to do :/

waxen totem
#

What's the exact size that every vhost seems to give you?

#

Visiting the vhost might give a clue as to what's happening, why it's returning 200s
remember to add the vhost to your host before you visit it

nimble scroll
#

I did add the vhost and also the ip

waxen totem
#

did you try to visit any of the vhosts in your browser? what's the result look like?

inland grove
#

This feels crazy
Can’t learn to be a higher hacker

nimble scroll
#

We can’t connect to the server at www.academy.htb.

#

the weird thing is that I added vhost and ip with sudo

waxen totem
nimble scroll
waxen totem
waxen totem
# nimble scroll

you need to add the vhost's subdomain as well e.g:

94.237.53.147 academy.htb www.academy.htb
nimble scroll
#

ohh..

waxen totem
#

after which try to visit www.academy.htb and see what's what

#

You'll know why they're all 200s

nimble scroll
#

connection time out

#

still did not understood what did I miss

waxen totem
#

did you add the port at the end? when you visited?

nimble scroll
#

yes

waxen totem
#

the target still up? kek

nimble scroll
#

yes, I get reply from 94.237.53.146

waxen totem
#

did you copy paste my thing? cos I think I misspelled the ip

#

double check the hosts file

nimble scroll
#

Unable to connect

Firefox can’t establish a connection to the server at www.academy.htb:38540.

waxen totem
nimble scroll
#

now it is working

#

ip was ip

waxen totem
#

knew it

inland grove
#

Guys I wanna learn 😭

nimble scroll
#

but still not the right answear

#

:/

compact patrolBOT
nimble scroll
#

so I still don t know where to look for the right answear

waxen totem
nimble scroll
#

welcome to my htb academy "

lilac cradle
#

Hey Guys!
Im stuck on this module, which is code analysis from Malware Analysis https://academy.hackthebox.com/module/227/section/2499
Can someone please tell me how to connect with the xfreerdp command? im using this command from the solutions, i have also approached support team in hack the box. they are not able to help. If someone has passed this module, please let me know how to debug this issue.
└──╼ [★]$ xfreerdp /v:10.129.33.33 /u:htb-student /p:HTB_@cademy_stdnt! /dynamic-resolution /drive:share,/home/htb-ac-594497

waxen totem
nimble scroll
#

allright

#

worked like charm

waxen totem
waxen totem
nimble scroll
#

I used to filter

#

right ?

waxen totem
nimble scroll
#

to filter the size 🙂

#

ffuz skips the response also

#

and skips response of 986

#

now I understood

waxen totem
#

Yeah so essentially we notice that almost every response has a size of 986, which could indicate some redirection shennanigans (probably what we have here) or a custom 404 page(you might see in other labs), which is why we filter it out

nimble scroll
#

thanks for clarifications now it makes sense to me

noble raft
#

Was someone here able to pass the Common Session Variables (Account Takeover) lab? I was able to change the admin's password but got stuck on what to do with the MFA part.. would really appreciate some help

urban elk
#

is anyone up for a DM about AEN? I've been stuck for too long now, starting to think there's something I don't understand fundamentally. I don't want to get spoiled by the walkthrough

inland grove
bold wagon
#

hii

fading olive
#

Hi, I'm working on Windows Privilege Escalation > Further Credential Theft
I found the answer to the first question which was the password for the sa user, I have no clue what to do from there. I tried every tool from the C:\Tools directory, I tried connecting with the credentials I found to no avail, I see no mention anywhere of the WEB01.inlanefreight.local domain. May I get a hint on what to try?

green shuttle
#

Hi i am advanced sql injection module reading and writing section , if anyone here can give a hand i would appreciate that...

signal hound
#

Hi i have a question about dns subdomains and Vhosts.
i wonder whats the difference between bruteforcing Vhosts and bruteforcing subdomains because the result will be the same
For the domain example.com both will try to bruteforce it for example dev.example.com
So whats the difference between the two enumeration methods?

stray heart
#

Hi everyone, I tried searching but wasn't having much luck. In the intro to malware analysis module, has anyone had issues with Noriben?

full wagon
#

Doing attacking common applications: WordPress - Discovery & Enumeration
There are three questions, 2-3 are about the plugins. I found that and answered the questions. Question 1 says "Enumerate the host and find a flag.txt flag in an accessible directory." --> Accessible, for me = something I can enumerate and browse to without exploiting the application (otherwise, it's not Accessible). Am I right?? Am I supposed to browse around and look for the flag file, or how am I supposed to address this? I am not looking for a solution, just someone who can explain what they ask about. If I need to get access to the authenticated part, please just let me know because I'm confused. Thank you!
Btw, the sections is somewhat unstable/buggy.

tranquil axle
# signal hound Hi i have a question about dns subdomains and Vhosts. i wonder whats the differe...

dns subdomain bruteforcing is only possible if there exists a dns server that you can ask.The DNS server would know that example.com belongs to ip A and dev.example.com belongs to ip B. In development environments (and pretty much any htb box) there is no DNS server available that knows of all the subdomains. So in these cases subdomain enumeration via DNS is simply not possible.

With Vhost enum you already know/assume that all subdomains/vhosts are on the same ip address. The one webserver running on that ip uses the host header to determine if it should show you example.com or dev.example.com. You enumerate by just sending every possible subdomain and see if the webserver responds differently. There is no need for a DNS server here, because you can tell by the response of the webserver if you got the right subdomain.

Whats important is, even if there is a DNS server available and it lists you 10 subdomains, that does not mean that there aren't another 5 vhosts also available. Especially in development environments there can be webapps running on the webserver that are not yet linked to the DNS server.

What you should do: if you see a dns server available, try to perform a zone transfer to get all the subdomains the dns server knows of. But even then, still perform a vhost enumeration to see if there are any other subdomains available

tranquil axle
full wagon
tranquil axle
#

I'd think the section taught you a way to enumerate wordpress specific folders

#

and probably some plugin folder is accessible and has the flag or something

full wagon
unreal fractal
#

hello guys, does anyone else has been experiencing issues with the vpn of the academy or the connection ,I have 2 days all my hosts are down when I try to work on them and I have change numerous vpn and restarted the machines, can someone tell me how could I fix this please ?

mild oyster
#

hello sir i am new to HTB and starting my journey but when i try to answer it got incorrect answer please help me answer this question it’s from Components of a Network module from network foundation

What type of network cable is used to transmit data over long distances with minimal signal loss?

fathom pendant
#

It's given in the reading

mild oyster
fathom pendant
#

also fiber not fibre

mild oyster
wild rapids
#

IPv4 is easier than IPv6 ?

fathom pendant
#

Wdym "easier"

#

And what module is this in relation to?

wild rapids
#

Nvm

fathom pendant
#

Sounds illegal

#

I suggest not talking about illegal activities :) #rules

wild rapids
#

It’s not illegal

#

Since I had his approval

fathom pendant
#

Sure and I have permission to slap the King of England, he said so

wild rapids
#

You a funny guy

fathom pendant
#

Either way, it's unrelated to academy modules, I suggest reading #rules and #welcome

wild rapids
wild rapids
fathom pendant
#

If only one of those tells you how to access more channels

#

"Think twice before typing anything stupid"

wild rapids
#

Ik how but I can’t remember my password

#

And I don’t have access to a computer rn

fathom pendant
#

Then suffer

#

¯_(ツ)_/¯

#

It's doable on mobile

wild rapids
#

Well well well

hardy cloak
#

Why are my nmap scans getting this reponse ? "Host seems down. If it is really up, but blocking our ping probes, try -Pn". I am doing a routine scan on the target machine.

nimble scroll
#

hello

dark hedge
nimble scroll
#

Before you run your page fuzzing scan, you should first run an extension fuzzing scan. What are the different extensions accepted by the domains? at the module web aplications , I got this and ran out of wordlists, what should I use to get the right answear?

dark hedge
#

Windows machines will usually block ICMP ping, resulting in that message. other machines may be configured to do the same

nimble scroll
#

I tried this wordlist and every result it gets me 403, I tried a different wordlist and same result, any sugestion ? 😦

fathom pendant
#

Not sure with gobuster but ffuf has -ac to autocalibrate the scan as it runs

neon remnant
#

hi i want a help with ARP Spoofing & Abnormality Detection in the academy. Can anyone help me ?

nimble scroll
#

ttacking Web Applications with Ffuf

neon remnant
#

Intermediate Network Traffic Analysis

nimble scroll
#

what should I change at the command ?

fathom pendant
#

The username list has that username, and the mutated password list has the password

#

Also spoilers for module content above tier 0

neon remnant
lucid wolf
fathom pendant
#

I forget if there's a linux host before that but they reuse the windows and linux hosts in that module a fair bit

lucid wolf
#

i am attacking ssh i think

fathom pendant
#

😉

#

Don't assume the question is giving you the direct first step

nimble scroll
#

I tried and no results :/

#

any advice ? :*)

#

every results is with 403

#

also on web estensions or raft

fathom pendant
#

The 48 threads advice was directed towards the one asking for help with password attacks

fathom pendant
nimble scroll
#

ohh..

fathom pendant
#

I'm not sure what the gobuster output is telling you

nimble scroll
#

I solved with ffuf

lucid wolf
median gale
#

Evil-Tweans module Skill Assessment anyone to ask a thing or two?

covert crag
#

Why I m not able to msg in general chat ?

fathom pendant
honest spoke
#

https://academy.hackthebox.com/module/57/section/3209
-I'm having an issue getting a username, nothing seems to work and hydra is giving "[ERROR] Child with pid 178413 terminating, cannot connect" and stopping the search. this is a newly added section so checking if its messed up or am I missing something?

fallow kernel
#

I am currently doing the AD enum skill assessment and I was wondering if there is an easy way to write nxc output to a file?

#

I used to just copy it to vim and then search and replace a lot but there has to be an easier way right?

old bramble
#

Hey everyone, having some trouble on Password Attacks - Network Services. I was able to get everything except RDP. I was able to find the user with some recon via powershell, but tested out the password.list file (with and without the computer domain) and got nada. I've used hydra, crowdbar, and tried crackmapexec and it errored out before even starting. Also tested changing VPN connect, just in case. Is there something I'm not getting?

cloud urchin
frigid plaza
#

Hello everyone, I'm working on the HTTP Attacks module and trying to get RCE via log poisoning, but my payload isn't executing.

I sent a POST request to /contact.php with the following payload:

Host: 83.136.248.16:32509  
Content-Type: application/x-www-form-urlencoded  

name=testuser&email=testuser%40test.htb&phone=123&message=<?php+echo+'pwned';+?> 

When I check /log.php, I can see my payload in the log, but it doesn’t execute. It seems like some characters might be getting filtered. Am I missing something? Do I need to encode it differently, or should I try another approach? Any hints would be appreciated. Thanks in advance!

fallow kernel
worthy inlet
#

any one woking on Attacking Applications Connecting to Services ?

cloud urchin
earnest pasture
fallow kernel
#

I tried it on nxc and cme

#

I also use the redirector but I always strugle to find the correct find and replace commands in vim

#

so I thought there maybe is an easier way

honest spoke
fathom pendant
#

yeah

#

or you can use mine i'll dm it to you (fresh spawned box and should be reachable, literally got it in .5 seconds)

honest spoke
# fathom pendant yeah

yes please dm me, cuz my new one, i ran the same command its saying itll take 4500 hours lol

fathom pendant
#

shouldn't take long

#

also i dislike how they changed this section

#

previously they used sed to do the editing and not a mess of grep chains 🤮

honest spoke
fathom pendant
#

previously no lab for this section, only the http-get section

leaden flax
#

im stuck at the Password Mutations model,

Ive tried BF FTP and SSH, FTP had 0 results and SSH says its going to take 6 hours...

what am I doing wrong?

I followed this exactly,

Take password.list and custom.rule to create a mutation file hashcat --force password.list -r custom.rule --stdout | sort -u > mut_password.list
Bruteforce FTP hydra -l sam -P ./7000mut_password.list ftp://10.129.202.64 -t 64

safe star
#

Or you can use nxcdb

#

Actually I’m just thinking about creds here

#

I also just copy the other output to obsidian

fathom pendant
fallow kernel
#

Maybe someone can create a pull request for an output argument 🙂

fathom pendant
#

module is the overarching thing, sections are the pages in the module

#

nxc has an output argument

leaden flax
#

got it, but yeah stuck at that section

fallow kernel
fathom pendant
#

you can use --log

#

some modules within nxc may also have their own separate output things

fathom pendant
#

also 64 may be too many threads try dropping to between 48 and 52

#

that seems to be a sweet spot for this module and services

#

saying "you're stuck" isn't particularly helpful as that can mean a multitude of different things going wrong

leaden flax
#

ill try 48 but i let FTP run and had 0 results, SSH runs longer then the box lives for

fathom pendant
#

ssh is unbearably slow to bruteforce

frank panther
#

What is the main channel in here?

fathom pendant
frank panther
#

Ok

#

Still not letting me join💔

fathom pendant
#

because there's instructions that you need to follow it's not just click the "done reading, go here" button

#

literally the last thing in #welcome is instructions how to verify/link your account

frank panther
#

Im not tryna do all that twin

fathom pendant
#

well this server ain't about that life

#

since it's clear you don't know what hackthebox even is

leaden flax
fathom pendant
#

just gotta have patience

leaden flax
#

👍

old bramble
glossy cloak
#

Help please...
nc 10.129.233.197 21
220 Microsoft FTP Service
USER anonymous^M
331 Anonymous access allowed, send identity (e-mail name) as password.
PASS anything^M
230 User logged in.
PASV^M
227 Entering Passive Mode (10,129,233,197,194,13).
LIST^M
150 Opening ASCII mode data connection.
550 Data channel timed out.

fathom pendant
glossy cloak
#

its an exercise in network fundamentals, going step by step for some cubes 🙂

glossy cloak
fathom pendant
#

imo just use ftp anonymous@ip

#

but it doesn't hurt to know alt methods

glossy cloak
fathom pendant
glossy cloak
#

passive mode is running and I calculated the port number

fathom pendant
#

¯_(ツ)_/¯

#

just a bit silly to use nc here

glossy cloak
#

sigh, ok i will try alternative

fathom pendant
#

also

waxen totem
#

NC is supposed to be the alternative kek

fathom pendant
#

^

#

don't know why they decided to go through the convoluted mess of using nc for this

waxen totem
#

Looks like parrot's PS1 var logic also a bit broken, weird ahh coloring

fathom pendant
waxen totem
#

I mean I use kali and a custom PS1 variable without all the colors

#

it's either that or I dive deep into oh my posh again kek

glossy cloak
glossy cloak
#

You think kali is better

#

?

waxen totem
#

I only use Kali cos I'm wayy too lazy to fix Parrot's weird ahh VM image issues

glossy cloak
#

I have to try Kali then lol

#

tommorow, GN

#

and thanks

#

ok, my stubbornness killed the tiredness! I just changed to extended passive mode (EPSV)

dawn totem
#

Hey

unique ether
#

Ya?

dawn totem
#

Guys give me your personal favorite tools for network sniffing

serene ingot
#

web attacks module, mass idor section

safe star
dawn totem
unique ether
#

💀

fathom pendant
wild rapids
thin parrot
#

Anyone able to provide assistance on the last flag for IMAP/POP3 in footprinting?

#

I've gone through a big list of IMAP commands and cannot for the love of god find this supposed flag. The mailbox that is supposed to have it has no messages.. there is nothing to intercept unless I'm doing something wrong

thin parrot
#

Vidal BTC is trying to nab my account in dms :/

#

@waxen totem ^ lmao

waxen totem
waxen totem
thin parrot
waxen totem
thin parrot
#

it just says search completed with nothing showing

#

let me check that i didnt accidentally signout

waxen totem
thin parrot
waxen totem
#

have you tried using FETCH instead?

#

When selecting an inbox it'll tell you how many mails are in that inbox

fathom pendant
#

When you select the inbox, do you get a message regarding how many mail entities exist?

#

Also search requires a bit of syntax to properly utilize

#

Yeah search only works in the currently selected folder

thin parrot
#

oh ok that makes sense

#

says 0 exists lol

molten ibex
#

if im new

#

what do i start with

fathom pendant
fathom pendant
molten ibex
#

and after that

fathom pendant
#

Whatever interests you more

molten ibex
#

ima try and do everything

thin parrot
fathom pendant
#

You generally wanna start with one focus then spread from there

waxen totem
unique ether
wild rapids
waxen totem
#

@unique ether @wild rapids this ain't #general go get verified (Instructions --> #welcome ) and take it there if it ain't module related

wild rapids
waxen totem
unique ether
waxen totem
waxen totem
thin parrot
#

can someone just tell me how to use FETCH im going according to documentation and still getting invalid results there is 1 stored message in the current folder im in and nothing is letting me pull it out

#

nvm

#

what the hell was that solution

waxen totem
#

In case you were wondering

#

Yes it's a pain kek

waxen totem
thin parrot
#

i dont think i never want to access an email through imap commands ever again

waxen totem
thin parrot
#

that honestly sounds preferable

#

i just feel a bit fried after blazing through everything except the last question which took about 3 times as long as reading the whole page and doing the other questions

#

i cant wait till the day that most of this makes sense and im not confused about half of everything

waxen totem
#

I mean tbf they don't really dive deep into the commands in the section so it is understandable

thin parrot
#

well i did digging and found a site full of them

#

and i did find fetch but i just dont get why that command gets me the result im after

#

ehh ill gpt it

waxen totem
#

The fetch command IS in the module though

thin parrot
#

yes

#

the many paramaters, no

#

because i couldnt get the result referncing the single id in that mailbox

waxen totem
#

tbf this and a second fetch command is all you need kek

thin parrot
#

well i got it i just dont want to post it to avoid spoiling for others

waxen totem
#

Think about how I felt when I missed the creds when doing that section last week kek

thin parrot
#

LOL

waxen totem
#

I went knee deep into unauth imaps exploits

thin parrot
#

oh man thats actually horrible

waxen totem
#

I went back and read the module and went:

thin parrot
waxen totem
#

btw get verified sus (instructions here --> #welcome )

fathom pendant
#

all is a shitty fetch class

#

use body[] instead

#

and yes the [] are necessary

thin parrot
#

i used body[] to pull the contents of the message.. i think

fathom pendant
#

body[] pulls everything

#

and doesn't leave you with the weird NULL nonsense

waxen totem
fathom pendant
#

i forget the upper bounds of it

waxen totem
waxen totem
fathom pendant
#

yep

fathom pendant
waxen totem
#

what I don't understand is why ALL doesn't include BODY[TEXT] 💀

fathom pendant
waxen totem
#

yeah... that's stupid kek all should be all

fathom pendant
#

it's more like all [metadata]

waxen totem
fathom pendant
#

Calm down Bob

#

also: it's FLAGS INTERNALDATE RFC822.SIZE ENVELOPE

waxen totem
#

That's why clients exist IG kek

fathom pendant
#

but yeah ALL basically grabs the metadata of a message
Flags set
Date
Size
Structure

#

if you wanna be sneaky: body.peek[] doesn't set the \SEEN flag if it was previously \Unseen

unique ether
#

sql map skill assessment every form has form action as #

#

not post and i dont see any get variables as well

#

am i blind

cloud urchin
#

Whenever dealing with web apps I'd suggest using a web proxy, clicking on every single link on every single page, and inspecting what's happening through the web proxy.

nocturne wyvern
#

Does anyone know if I can access htb without a GUI/browser? I have a Linux machine that I’m SSH into with my phone, using Tailscale and Termius, which I want to use to access htb, but it doesn’t seem like there’s a way to use without a browser. I was thinking one workaround would be to download the .ovpn file on my laptop then just scp it to my Linux machine, and connect there, but I still have to interact with htb through the browser to activate the individual machines I’m trying to attack and get the ip.. anyone know a workaround?

cloud urchin
#

you probably "can" but it would be tedious and difficult..

#

if you can curl the site you should be able to log in etc but you'd have to figure out a lot of stuff

fathom pendant
alpine ingot
#

Security Monitoring & SIEM Fundamentals - SIEM Visualization Example 1: Failed Logon Attempts (All Users)
I keep getting SSL errors on this box. Anyone know how to fix this?

#

Genuinely, immediately after sending that message i was like "wait a minute, i didnt try http..."
I fixed it...

novel matrix
cloud urchin
#

@brave field please try to ask your questions without spoiling anything from the modules. That said, "not working" isn't a great description either, is there an error you're getting for example?

brave field
cloud urchin
#

ok

safe star
#

bro trynna drag me too 😭

unique ether
fathom pendant
#

let's keep the convo related to academy modules =_=

unique ether
#

anw i finished sqlmap essentials is there anw i can practice more of this one

#

i feel like i just tried bunch of options and got the flag with trial and error

#

kinda want to know when to use which option

storm elk
opaque geyser
#

Can someone help me with the Windows Attacks and Defense module for Kerberoasting ?!

#

I have gotten the first answer, however when I spawn the windows 🪟 for the given Ip (using the first windows machine to use RDC to open another windows machine(with New given IP and login) I cannot find the webservice and it’s service pid

echo geyser
#

Hi I am a beginner and needed some help with the linux fundamentals quiz:
I am using the exact same parameters, the ip is also the same, so why is it giving permission denied

fathom pendant
fathom pendant
#

target == thing you're attacking
instance == in-browser vm

echo geyser
#

So how to get the target's ip

echo geyser
#

nvm, got it, thanks

echo geyser
#

What am I doing wrong here, it's mail, why is this a wrong ans

waxen totem
#

that's the system mail

#

try checking the env variable

echo geyser
worldly vortex
#

Anyone able to chat about the skill assessment for the Intro to Whitebox Pentesting module? the challenge description says there's two ways to obtain RCE. I have managed to exploit it in one way and I believe I can spot the second way but I can't figure out how to get my input into the sink, when I try to send a request to this function the local app errors

waxen totem
true urchin
#

Hi i am new here

waxen totem
novel matrix
#

is this something to wtih hackthebox challenges?

coarse terrace
waxen totem
coarse terrace
#

Ah, so now as Im verified, can I ask about my issue when solving one of the cahllenges?

waxen totem
#

@coarse terrace use the channel linked above for your question please

terse magnet
#

Need python resources ¿

fallow kernel
#

Yooo guys I am doing the AD Enumeration & Attacks - Skills Assessment Part II and I try using bloodhound. I run into a problem when trying to upload the json files collected with SharpHound.exe into my bloodhound on the pwnbox. It just doesn't seem to upload, it's just stuck at 0%. Anyone knows how to fix this?

rustic sage
#

as an alternative use bloodhound-python and specify the ns and --dns-tcp

fallow kernel
compact seal
#

Hi, I'm having trouble with a module in Introduction to Windows Evasion Techniques -> Static Analysis.
I compiled the binary, put it in the static directory and I'm waiting for the flag to be generated. In the logfile it states "OK - Undetected by Microsoft Defender Antivirus". I have waited for quite long + I tried to reset the machine without any luck. Anyone who have experienced this?

proud pine
#

The checks it does are very specific.

compact seal
wild forge
#

i only see a vbs script on the SRV09 in Intro to C2 Operations with Sliver module, I still don't find a ps file on it

weary pewter
#

Hi, I'm working on ffuf module, "skills assesment" and I don't know what to think about the hint in third question : "Use 'PORT' instead of the port shown above".

dapper moth
jagged arrow
#

I am currently going through the File Inclusion module skill assessment. I am attempting source code disclosure. However, using the base64 encode filter on any existing source simply waits on the response and times out. I would much appreciate a pointer in case you have one 🙂

jagged arrow
signal hound
#

Hi im in the middle of attacking common services > email services
And im unable to dig the MX server from the domain "inlanfreight.htb"
any ideas why?

rustic sage
#

can any1 spot the error here? can't get it output any commands

rapid fog
#

Hi fellow hackers,
I currently stuck in Whitebox Attacks module Data Exfiltration via Response Timing of CWEE
The code I used is

import requests
url = "http://83.136.255.47:42674/filecheck"
wordlist= "/usr/share/wordlists/seclists/Usernames/xato-net-10-million-usernames-dup.txt"
THRESHOLD_S = 0.15
cookies = {"session":"eyJsb2dnZWRfaW4iOnRydWUsInVzZXIiOiJodGItc3RkbnQifQ.Z8XR4w.5EP3X7dklt-a7w32tocrTkviZCo"}

proxy = {'http':'http://127.0.0.1:8080','https':'http://127.0.0.1:8080'}

with open(wordlist, 'r') as file:
    for usernames in file:
        usernames = usernames.strip()

        res = requests.get(url,params={"filepath":f"/home/{usernames}/"},cookies=cookies)
        if res.elapsed.total_seconds() > THRESHOLD_S:
            print(f"valid username in the file system is: {usernames}")

and no matter how much threshold_s I modify it keep give me the false positive system's username.
Note: I can make it work on local testing but not the real lab. (also tried wiith pwnbox just in case it has issue with network connectivity).
Appreciate for any help! (already tried email to supporter for help but he asked me for guidence here instead)

rustic sage
#

@jagged arrow

jagged arrow
rustic sage
young ore
#

There is a zip file you need to download, from the Resource

alpine summit
#

Can anyone tell me about the skill assessment of Active Directory Trusts? I'm stuck on question 2. PM me

compact halo
#

Having some issues with the module VMs not loading. Is this known? Stuck on fetching status

true urchin
#

keyboard is not working in instance

rustic sage
rustic sage
#

@true urchin

wanton estuary
#

Can I DM anyone about abusing http misconfigurations - hard skill assessment?

For others struggling with the first part. You can find an unkeyed parameter by clicking about the site.

split minnow
#

Hi, could someone please on Windows Lateral Movement - Skills Assessment - Question 5 What is the password for VNC?

I've tried everything like in the writeup, but i don't get a reverse shell connection
Also the WSUS update is stuck at 50 (sometimes 0) Install (2/2)
How much should i wait? > 5 mins?

I've tried restarting the lab and doing it again - didn't help

Update: for those struggling in the future - it took me like 10-15 mins to receive connection. After receiving connection, it's still 50% Install (2/2). But as it was written in the course - status can have a delay

bronze turtle
#

Hi could someone help me with Q8 of the AD Enumeration & Attacks skills assessment II? I have admin access on SQL01 and have to get admin access on MS01. I have read some past messages and have tried to ||dump hashes with secretsdump.py from the SAM, SYSTEM and SECURITY hives. But when I try the hash of the Administrator user using evil-winrm, I don't get logged in||. Could anyone give me a hint?

bronze turtle
gray yacht
urban elk
#

<@&861185840277487616>

winter schooner
#

Hello, I am on Windows Privilege Escalation module, Skills Assessment 1

I saw the user has|| SeImpersonate|| privileges, and I used, ||RoguePotato,JuicyPotato,Printspoofer,Meterpreter getsystem||, nothing worked. Can anyone help me??

urban elk
#

@acoustic owl they're back...

quiet heart
#

<@&861185840277487616>

winter schooner
winter schooner
candid spire
#

anyone available for a hint on dacl attacks ii - skill assessment q3? i've been stuck on this for days and feel like i've tried everything

#

i found the rights i have over 2 objects with the t* user, but i'm not seeing how to leverage that to compromise the DC

tranquil wren
#

Hello, i am on https://academy.hackthebox.com/module/147/section/1327 and am running crackmapexec winrm and selecting different lists, it doesn't look like the lists have the correct usernames or passwords in it. did i miss something in this module that tells us what list to use for target ip?

rustic sage
rustic sage
#

Wifi*

tranquil wren
#

i do not know wifi hacking, i do infact know wife hacking though.

lusty thicket
#

same

rustic sage
late swan
#

i have a general question, is the SOC path the unit that covers tablets, cell phones , social media and the like

tranquil wren
#

man is winning at life and tryng to hack wifi

rustic sage
tranquil wren
#

no, only wife

rustic sage
rustic sage
#

What happened @proud pine

proud pine
# rustic sage Do u know

You've been told about this already. Verify your account, read the #rules and #welcome, and you can access the rest of the server. This channel is for discussion of modules, so stop spamming people.

late swan
#

or does SOC cover something totally different

dark hedge
clear shell
#

Hi, I do have a question about the module "Security Monitoring & SIEM Fundamentals" section of Skills Assessment. I have completed this section but I want a better understanding or a overview of bassicaly why these answers are correct and how you are supposed to see that with in Kibana. I know that the annual subscribers will have step by step solutions but money is kinda tight and is there any other way to get a better understanding as to why my answers are correct?

viral lotus
#

hi Linux Priv Esc module - Cron Job Abuse. I completely forgot to check if it had access out to the web because I couldn't see the pspy on the box but it was running. were we supposed to get the binary across and execute it that way? some of the lab boxes don't allow you to access outside, thanks.

digital zealot
#

Hlo guys . Does that tool named saphyra still works ,??

viral lotus
#

or should I have downloaded it to my VM that is connected on the vpn then copy it across that way? thanks

safe star
#

wdym -l is taking longer?

viral lotus
#

I think that one takes a while

proud pine
#

SSH is not the best service to try to bruteforce.

dark hedge
#

because you're brute forcing SSH, which only likes 4 connections at a time

viral lotus
#

increasing attempts with -t speeds it up too

#

you have to add a value

#

try it multiple ways I have done the module, literally looking at my notes lol

#

can someone help with my brain fart question above ^? I couldn't get pspy to run so I don't want to move on to LXD until I have it done... many thanks

viral lotus
#

took me 15 minutes on hydra so it can take time

wispy rapids
#

Does anyone have a recommendation on what modules to start with

#

I do know a bit but still need to learn a bit

viral lotus
#

I can't give spoilers but you are close and you are thinking the right way.

compact patrolBOT
viral lotus
#

ok so if 2/3 don't work...? also investigate the -t flag with hydra youll thank me later lol

#

dm me if you want

proud pine
#

smb isn't the fastest service to try to bruteforce.

#

😉

lucid wolf
#

dam , i was looking for an exploit for like 2 hours haha

open yacht
#

Hi HTB Team, I'm a uni student and I have an HTB academy account with my personal email is there a way to have both my personal email and my uni email on the platform ?

worn matrix
#

the last module,its for maldev?

heavy forum
#

Daer all

#

i need help for this HTB Academy model

#

Info to assembly language

#

Download the attached file, and find the hex value in 'rax' when we reach the instruction at <_start+16>?

fathom pendant
heavy forum
#

i got your point

#

however i am not good at Assebly Language

#

hence assistance for the task

fathom pendant
fathom pendant
heavy forum
#

ohh noted with thank you

#

if possible some can help

candid spire
#

anyone available for a hint on dacl attacks ii - skill assessment q3? i've been stuck on this for days and feel like i've tried everything. i found the rights i have over 2 objects with the t* user, but i'm not seeing how to leverage that to compromise the DC.

solid epoch
#

oh you are here as well. :) Which module did you do here?

safe star
#

you should be able to jump to that _start+16 instruction and just check the rax register

lusty thicket
humble aspen
#

hello guys, my name is Yousef I'm from Saudi Arabia and it is a pleasure to be here among you.
if you don't mind me asking, i just started Linux Fund and i got stuck to initiate VPN connection between HTB and my VM kali. i got everything as mentioned in the guides and i can ping the target buuuuut, i can't use ssh htb-student@ip adress.

if anyone faced this issue and give me any pointers it will be highly appreciated.

ocean night
fresh canyon
#

hi i have a probleme with a module network foundation please

ocean night
#

With the Linux Fundamentals you should indeed have SSH access.. so what IP are you trying to SSH in to?

#

...and if it's a VPN issue you should include any logs, although if you can ping it, you should be able to connect to its services

#

..and include any output from the SSH command if it gives an error

#

@humble aspen

fair fulcrum
#

Hey guys,
need help on Pillaging, I want to share a screenshot but I don't understand this Tier 0 rule

ocean night
rustic sage
#

Hello

fair fulcrum
#

Its CPTS Windows Privilege Escalation - Pillaging.
Extracting the cookie with Firefox works but does not work with Chrome, Command runs but no extracted cookie shows up

ocean night
#

Not done that one I'm afraid, and can't discuss further here, hopefully someone can give you a nudge in private 🙂

#

@humble aspen .. did you want help, or no?

humble aspen
#

yas please, sorry for the delay

fair fulcrum
#

Yes, I need to understand why its not working

fair fulcrum
humble aspen
#

this is the generated ip ( 10.129.219.236 (ACADEMY-NIXFUND) )

#

i installed the VPN and i get Initialization Sequence Completed

ocean night
#

Ok, and what happens when you try to SSH in to it?

humble aspen
#

i can ping the IP adress but when i try to SSH to it is sayes connection closed ( ip ) port 22

ocean night
#

What hostname is in your ovpn file, the one you're using to connect to Academy?

humble aspen
#

sorry i did not get that ?

ocean night
#

Ok, let's make it easier, re-download your OpenVPN config file from HTB Academy and try again

fresh canyon
#

help for module network foundation please

ocean night
#

(I was asking what was in your ovpn file, a line like this remote edge-eu-academy-5.hackthebox.eu 1337)

humble aspen
ocean night
#

Ok, what server are you connected to currently then please?

humble aspen
#

EU Academy 2 UDP 1337

#

the file name academy-regular.ovpn

ocean night
#

Sorry @humble aspen, experiencing iso issues ATM.

#

You may be better raising the issue with the support team

humble aspen
#

@ocean night no worry at all, thank you for taking the time and help me out 😄

ocean night
#

Do you see the port open with nc -v <ip> 22 ?

humble aspen
#

10.129.219.236: inverse host lookup failed: Unknown host
(UNKNOWN) [10.129.219.236] 22 (ssh) open
SSH-2.0-OpenSSH_7.6p1 Ubuntu-4ubuntu0.3

ocean night
#

Ok, so what happens when you ssh in? Any output?

humble aspen
#

Connection closed by 10.129.219.236 port 22

ocean night
#

Weird, I'm able to access it fine from the same VPN

humble aspen
#

ssh htb-student@10.129.219.236 this should give me access and asked for password

ocean night
#

Yes, it should

humble aspen
#

i have been trying for hourse now xD

ocean night
#

Maybe force password authentication?

#

ssh -o PubkeyAuthentication=no -o PreferredAuthentications=password htb-student@10.129.219.236

humble aspen
#

ok i'll try it

zealous rune
#

hello. working through the end of module exercise for the Local File Inclusion module. A little stuck. So far I have:

  1. found two parameters to investigate
  2. tried to use a file with a list of payloads with the two parameters to identify an LFI
  3. tried to find other parameters that may contain LFI vulnerabilities
    However so far all I've managed to do is to identify two parameters
#

I think i know which parameter will contain the LFI

humble aspen
#

did not work

ocean night
#

The error you are getting doesn't say much I'm afraid

humble aspen
#

i think it is better to use Pwnbox to avoid this issue

ocean night
#

Anything of interest running it in verbose mode? ssh -v htb-student@IP ?

#

The instance is working fine, I've confirmed

mighty olive
ocean night
#

No @mighty olive - helping with SSH access to an Academy module target.

mighty olive
ocean night
#

Not sure I follow you, sorry

humble aspen
mighty olive
humble aspen
#

Connection closed by 10.129.219.236 port 22

waxen totem
#

How long of a delay is there before it closes the connection?

humble aspen
#

it take some time almost 20 to 30 sec

#

sometimes more

ocean night
#

Any other output after the last line?

#

Because that last expecting output is weird to be the last

humble aspen
#

@ocean night this is the last line

#

Connection closed by 10.129.219.236 port 22

ocean night
#

I meant the line before that, the last line in the output you shared, is that expecting... ?

humble aspen
#

debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
Connection closed by 10.129.219.236 port 22

ocean night
#

hm

humble aspen
#

i got it like this

waxen totem
#

Idk if this is a thing but it looks like its looking for if your machine trusts cert but not prompting you if you wanna trust it

Try typing yes and enter during the delay?

ocean night
#

That sounds possible, but weird yeah

humble aspen
#

ok i'll do that

ocean night
#

or add -o 'StrictHostKeyChecking no' to your SSH command

zealous rune
ocean night
#

What about the option I mentioned?

humble aspen
#

it will be like this ( ssh -o 'StrictHostKeyChecking no' htb-student@10.129.219.236 )

ocean night
#

That said, if it's not prompting for the key, maybe it wouldn't prompt for the pass. Have you tried opening a fresh terminal session, or running reset in your existing terminal?

#

Yes, that's right @humble aspen

humble aspen
#

nothing happened

ocean night
#

You mean nothing changed with the SSH command, or nothing happened with the reset command?

humble aspen
#

both i tried and got the same result

ocean night
#

That delay definitely suggests an issue with the client promoting you, never seen that before..

#

Do you see different output with both the above option flag and the -v flag?

#

Prompting rather, not promoting

humble aspen
#

i'm using a virtual box kali version, could this cause an issue

ocean night
#

Sorry typing by phone lol

#

No it shouldn't

#

( ssh -o 'StrictHostKeyChecking no' -v htb-student@10.129.219.236 )

#

As in different from the previous output with -v

humble aspen
#

no diffrent there is a delay

#

after sometime connection closed

ocean night
#

You're sure the output was exactly the same withg the -v flag?

#

That tells the client to output verbose logs

humble aspen
#

i'll copy the outpot

#

Connection closed by 10.129.219.236 port 22

ocean night
#

Ok.. last thing.. try ssh -v -o KexAlgorithms=ecdh-sha2-nistp521 htb-student@10.129.219.236

humble aspen
#

ok

zealous rune
#

the client version is 9.9p2

humble aspen
ocean night
#

Honestly I've no idea then

#

Random StackOverflow post says maybe -o MACs=hmac-sha2-256

#

But this is really weird. If that doesn't work, I'd suggest reaching out to support for assistance

compact patrolBOT
zealous rune
#

you could perhaps also try installing a different ssh client version

humble aspen
#

@ocean night no worry, thank you so much for the amazing support

humble aspen
ocean night
#

Some other posts mention MTU on the NIC causing issues

#

...but unsure on that one, outside of my knowledge as to why that would impact

#

Ok, well sorry I couldn't help. Good luck! Support will hopefully be able to help further

humble aspen
#

If it gave me to much issue I’ll just use pwnd I think it is more convenient

zealous rune
#

I'm doin the end of chapter exercise on the Local File Inclusion module. A little stuck. Can anyone provide a gentle hint?

humble aspen
#

@ocean night i got to work as you sayed it is related to MTU

ocean night
#

Ah nice one

humble aspen
#

i used sudo ip li set mtu 1200 dev tun0

#

tun0 it the vpn connection

#

thank you so much you have been a great help

ocean night
#

Odd that it's not mentioned in the help articles, honestly likely a rare occurance

#

No worries, enjoy!

humble aspen
#

at least now we know if someone else faced the same issue

ocean night
#

Yep! Also mentioned in our internal support channel, so we can update our help articles

gray yacht
zealous rune
#

yes r1icky

gray yacht
#

You can just DM

digital steeple
#

Tip: Take 10 minutes to do it by yourself no rush, it helps

zealous rune
#

@safe star gave me some good hints. it's the skills assessment. I'm workin thru the hints of @safe star thanks guys

nocturne ridge
#

did you try password mutations

heavy forum
#

Download the attached file, and find the hex value in 'rax' when we reach the instruction at <_start+16>?

long flint
#

hi guys seeking help on the skill assessment for whitebox attacks. im on the second part where there is potentially a race condition with type juggling, however i can't think of a race condition that could be malicious to even start. i've been reading the add_user() and delete_user() functions all day QQ

My is idea is to get the ($user_data['role'] != 0) by influencing the fetch_user_data(), if a user exist, it will return False, but then you still can't login as the user with admin priv

heavy forum
heavy forum
#

in connected seesion what command i have to givve

#

i have download the file and kept on pwnbox

#

post that what i have to do

#

as i am new to assembly language

#

not able to sense it

ocean night
#

@heavy forum the module and section will have the information you need

fathom pendant
#

the module teaches you what to do

#

the only thing i've noticed is that sometimes gdb is loaded in x16 (hex) mode so you'd need to translate decimal (+16) to hex (+10)

tired bough
#

iv had issues with reverse shells going to my kali vm on the vpn

lusty thicket
hidden trellis
#

can anyone please help me with Kerberos Attacks final question on skills assessment, THank you 😀

#

?

lavish fulcrum
#

Hi

#

What is about this group

#

Are you hear me

#

Well it’s okay

glacial minnow
#

im having a problem with SeImpersonate section from the WIndows privilege escalation module, when i rdp, i get this error message

#

Connection reset by peer, i have tried connecting from my box and through pwnbox with different VPNs but nothing worked..

proud pine
glacial minnow
#

are you able to rdp? if not then i've tried everything

worn pilot
#

hey

compact oriole
#

ive been on the filter contents section of the linux fundementals module for a while now trying to do the first question and ive tried alot of netstat and ss commands but with no success

lusty thicket
#

whats the first question

compact oriole
#

How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)

waxen totem
compact oriole
compact oriole
uneven niche
#

getting rick rolled by an HTB module in 2025 is crazy work

lusty thicket
#

trust no machine

uneven niche
#

😂

robust quartz
#

I’m currently working on improving my reporting skills by creating a report based on the AEN module. When writing the "internal network compromise walkthrough" section, should I also include the exploitation details of the DMZ server? Or should I start directly from the point where I obtained a shell on the DMZ server?

proud pine
fresh canyon
#

Hi , help me for a network foundation module please , I'm locked for the last question of skills assessment please 😭😭

noble raft
#

Someone who did the abusing-http-misconfigurations-hard-skill-assements-lab and can assist?

heady blaze
#

hey , im doing pass the ticket in linux,

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.
i got the flag but it tells me that my submission is wrong

dawn mountain
#

hi, i have a problem with this question :
Which kernel release is installed on the system? (Format: 1.22.3)
i use the command "uname -r"
the return "6.11.5+parrot-adm64"
i answer "6.11.5"
and it's wrong...
i do something wrong or is it not the right answer for real?

dawn mountain
#

CDSA - Linux fondamantals - System Information

waxen totem
#

Ensure you're ssh'd into the target and not just on the parrot vm.

#

ssh htb-student@<IP OF TARGET>

dawn mountain
#

I use the web terminal
I'll try that! thanks

old wren
fresh canyon
#

Help please I'm locked 3 days

old wren
#

cool - what did you try, what didn't work?

fresh canyon
#

I try a very but I don't a response

old wren
#

I don't understand what that means. If you want us to help you, you have to be much more specific about the nature of your problem, everything you tried, and so on.

naive sluice
#

i am stuck at this question from the module Password Attacks :Password Reuse / Default Passwords. could someone help?
Use the user's credentials we found in the previous section and find out the credentials for MySQL. Submit the credentials as the answer. (Format: <username>:<password>)

fresh canyon
solar arch
#

is academy reevaluating modules and their tier from time to time? im kinda sure some of these modules have been tier4 before?

#

like - these are the only tier4 currently?

dapper moth
solar arch
#

yeah, im kinda sure sliver was tier4 too

#

thx 🙂 so i guess when they release a new path they downgrade the modules in it to tier 3 for annual gold members to be able to access?

dapper moth
#

I hadn’t though of it that way
But makes sense

old wren
old wren
fresh canyon
#

All , I modify the request post , get ,put , trace, the content length, the path by burpsuite

burnt hill
#

Hi, I am doing the skills assestment section of the Information gathering - web edition Module "https://academy.hackthebox.com/module/144/section/1311" I found the subdomain webxxx and now I want to curl the robots.txt but it tells me that can't resolve the host, I added the subdomain to /etc/hosts, but I am doing something wrong, I am able to open robots.txt through the browser, using the url, any hint about what I am doing wrong?

old wren
#

what's your curl command?

#

you can anonymize the full path

burnt hill
#

what do you mean with anonymize the full path?

old wren
#

sorry - I thought "webxxx" was anonymized, that "xxx" stood for something else. my bad.
the curl command looks ok, though you're only fetching headers with the -I flag.

#

if that exact URL is reachable using the browser, it should be reachable using curl - curl is just another "browser"

burnt hill
#

now it's working, I don't think I did something different, but I just tried and it's giving the results

#

thanks for the help

fresh canyon
#

and me please ?

silver fable
#

can someone dm me if you have completed Hacking WordPress Section?

tired atlas
#

Hi so I'm on the Password Mutations section of Password Attacks, and I'm using the right command and such which is

hydra -l sam -P mut_passwordlist -t 48 -V ftp://<targetIP>

it runs the attack for a while, and then it just stops saying, 0 passwords found, I tried running it with sudo, same issue, I'm not really sure on what I could try next

frigid plaza
#

Hi, I’m stuck on the HTTP Response Splitting lab (https://academy.hackthebox.com/module/191/section/2056). I’m trying to steal the admin’s cookie with a payload like <script>fetch('/cookie=' + encodeURIComponent(document.cookie))</script>, but I’m unsure about the multiple URL encoding needed due to the firewall restrictions. I’ve tried single and double encoding, but I can’t find the cookie in the logs. Can someone clarify the correct encoding and where to look for the cookie? Thanks!

tranquil axle
jolly raptor
#

how does everyone write notes on their modules? i’ve found myself just re-writing the whole page in notion…

tranquil axle
jolly raptor
#

Content type header?

tranquil axle
#

Wow sorry, I pinged the wrong person

#

This was meant for @frigid plaza

old wren
tired atlas
#

it stops early, before not even 200 passwords are tried

old wren
old wren
fresh canyon
#

the screen say bad requests header or content- length required

old wren
fresh canyon
#

So how do I get around HTTP filtering??

old wren
#

Well what does your request look like? What do you think is being filtered? It seems to me that the content-length value is wrong - or that there's another header that should be present, and isn't. Not sure though.

fresh canyon
#

in the questions say bypass filter http

old wren
#

HTTP filtering can take many forms. From content type, to specific headers, to length, to HTTP methods...

fresh canyon
#

they don't say how to do it but they say the flag and in the htmll body

kind socket
#

I am very green so I apologize in advance. I am having trouble in the Linux Fundamentals." What is the path to the htb-student's mail?" I have tried find command, uname command and other commamnds but I cant seem to find the answer. Could I get some direction please?

dark hedge
solar arch
tranquil axle
#

I think in one of the early cpts modules it is said that tier is only related to how special the knowledge is and not how hard or how long it takes

dark hedge
#

i believe Intro to Academy explains the tiers in more depth

storm elk
#

Yes

spiral sapphire
#

Hello, I'm doing intro to network traffic analysis module and can't log-in to xfreerdp computer

#

I try to type the htb academy student password and it prompts me for wrong password

#

The username is also wrong I think it should be htb-student and not mr bean?

fathom pendant
#

whatever username and pass is given to you

spiral sapphire
#

Yeah, username: htb-student

#

I type in " xfreerdp /v:IP /u:htb-student /p:HTB_@cademy_stdnt! " and I get an authentication required from MrB3n. The password given doesn't work.

fathom pendant
#

reset the lab, reach out to support

compact patrolBOT
spiral sapphire
#

Alright, so it is an error? Thanks

fathom pendant
#

i haven't done it in a min, support will confirm if it's broken

#

just don't select "content guidance" option

digital sun
#

Hello pretty new here i will probably get the subscription but i dont know where to start and what paths to follow my ideal goal is to be a penetration tester some day

fathom pendant
#

Information Security Foundations path

urban elk
digital sun
fathom pendant
#

you should be alright to go for the Penteseter Path after that, the Information Security Foundations path is considered the pre-requisite to the Penteseter Job Role Path

digital sun
#

Appreciate it a lot

tired atlas
#

hi so in the password reuse section of password attacks, how do i run the hydra command on the target machine, would I need to smb the password wordlist to target machine and then go from there?

#

(i hate file transfers)

fathom pendant
#

you don't need to

#

iirc the pw reuse section is also the default password section yeah?

#

use that as your hint, it's a small enough list to test on

tired atlas
#

yeah I already have the password from the section before

#

i just need to figure out the username??

fathom pendant
#

there's a default-cred-cheetsheet in the reading

#

and that tool has an install you can do

tired atlas
#

yeah i got the usernames from there

fathom pendant
#

there's username and password combinations

#

not just usernames

tired atlas
#

yeah I know

#

but i deleted the passwords cuz i thought sam would've resused the password

fathom pendant
#

default

#

:))))

#

don't make assumptions, rule options out

tired atlas
#

it wouldve been too MUCH effort to remove the first column

fathom pendant
tired atlas
#

oh really, I dont know how github works

#

so i didn't know that

fathom pendant
#

and in the tool itself you can download (referenced in the README) you can search for the service

#

looks like you're looking at the raw list

tired atlas
fathom pendant
#

yep

#

but the regular page allows searching as well

#

via a search field

#

but i also urge to just install the tool

tired atlas
#

yeah i got it thanks

#

so to reiterate

#

just go through that list

#

and it should work??

fathom pendant
#

yes

#

no need to rotate user/pass

tired atlas
#

yeah thanks that did the trick

#

thank the lord, its 4am in the morning when I was removing services from the :: lines, i didn't check to think to just go through the mysql ones

#

brain doesnt work properly at that time, i rawdog life and dont ingest caffeine

pale atlas
#

Hello

candid night
#

Hey Tanay.

Question. Is it okay If I'd share my test report on the reporting and documentation lab here? I would want to get some feedback if it's a good report or not as I don't yet have a feeling for it

dark hedge
candid night
#

Alright, thank you for letting me know

#

Also, for Attacking Enterprise Networks - I know it's best to go blind into it, but should I avoid reading anything inside of the module and just start the machine until I get a total AD control? Is there some time range that would tell me if I was too slow?

#

I'm on the last straight so I want to be sure

dark hedge
#

you can read up to the start of the engagement. after, you can do the lab blind

worn sonnet
dark hedge
#

i think the section the walkthrough starts is called Initial Enumeration