#modules

1 messages · Page 397 of 1

tired bough
#

connection timed out

#

let me try one more thing one sec

#

yeah nothing connection timed out

#

i should be using my tun0 ip correct?

waxen totem
#

what command are you using to serve the webserver?

tired bough
#

nc -lvnp 1234

#

and im specifying that port in curl

waxen totem
#

show curl command

tired bough
#

curl 10.10.16.46:1234

waxen totem
#

show ip a output on attacker machine

tired bough
#

9: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
link/none
inet 10.10.16.46/23 scope global tun0
valid_lft forever preferred_lft forever
inet6 dead:beef:4::102c/64 scope global
valid_lft forever preferred_lft forever
inet6 fe80::6420:4b64:366e:c522/64 scope link stable-privacy proto kernel_ll
valid_lft forever preferred_lft forever

waxen totem
#

you able to ping the target?

#

also is that the only tun IP?

tired bough
#

one sec

waxen totem
#

seems like you have 9 network interfaces sus

tired bough
#

O_o

#

here ill send you the full output taking out my local ip

#

woundering if its docker maybe

#

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host noprefixroute
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether 00:0c:29:84:9b:8c brd ff:ff:ff:ff:ff:ff
inet ###.###.###.###/24 brd #.#.#.255 scope global dynamic noprefixroute eth0
valid_lft 72396sec preferred_lft 72396sec
inet6 2604:3d08:6478:eed0::5fc0/128 scope global dynamic noprefixroute
valid_lft 95484sec preferred_lft 95484sec
inet6 fe80::6db3:531:224:ff77/64 scope link noprefixroute
valid_lft forever preferred_lft forever
3: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
link/ether 02:42:39:4e:8f:fe brd ff:ff:ff:ff:ff:ff
inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
valid_lft forever preferred_lft forever
9: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
link/none
inet 10.10.16.46/23 scope global tun0
valid_lft forever preferred_lft forever
inet6 dead:beef:4::102c/64 scope global
valid_lft forever preferred_lft forever
inet6 fe80::6420:4b64:366e:c522/64 scope link stable-privacy proto kernel_ll
valid_lft forever preferred_lft forever

#

let me try the ping

waxen totem
#

can you do: sudo killall openvpn and then start up a new academy VPN?

#

The fact that it's interface 9 is sus

tired bough
#

i cant seem to ping the ip address intresting. but i can access it in my web browser?

#

lemme try telnet

waxen totem
#

Well now we know it's blocking SOME requests

tired bough
#

telnet wont work either lol

#

k one sec let me try that

#

O_o

#

now its 10

#

10: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
link/none
inet 10.10.16.46/23 scope global tun0
valid_lft forever preferred_lft forever
inet6 dead:beef:4::102c/64 scope global
valid_lft forever preferred_lft forever
inet6 fe80::8f77:51b5:4d03:f3c6/64 scope link stable-privacy proto kernel_ll
valid_lft forever preferred_lft forever

waxen totem
#

maybe that's intended idk

#

I'd restart the attacker machine

tired bough
#

resetting it

#

brb

tired bough
#

yeah still nothing

#

its like the vpn just wont accept incoming connections its super weird

cloud urchin
#

you can try changing servers, regions, or mtu

idle sundial
#

In advanced sql injection at skills assessment
When I execute the injection, the injection is correct, but the log gives me false and Extracted SQL state class '42' from value '42601'? any hints?

tired bough
#

so strange

high stream
#

I'm in login brut forcing module skill assessment 1 the command and worlist are fine, but i'm not able to get the correct user name and password and also it give me this error" [ERROR] all children were disabled due too many connection errors"

unique patrol
#

did the reconspider.py from the info gathering module work for you guys? (for the skills assessment 2 last questions)

honest crane
#

Hi, guys. I recently finished AEN, and had some questions. So there's a domain account that can WinRM into MS01, but it doesn't show up in BloodHound, under the Execution Privileges section. Is this expected behavior?

safe star
honest crane
safe star
idle sundial
#

I have been trying for weeks to solve the first question of Advanced SQL Injections in Skills Assessment and I did not reach a satisfactory result. I added the log in application_properties to know my mistakes and I did not reach any solution and all the problems I face in the distance. Any hint please

cloud urchin
#

Ask in #hacker-lounge, this channel is for discussion of the modules on Academy. You may need to follow the instructions in #welcome to gain access to other channels.

sharp wren
#

thanks for the link! I did learn a couple of new things from there, so will keep in mind if I need it again. So far it's working for me tonight, fingers crossed!

lavish lily
fathom pendant
karmic oyster
#

yo cani anyone plz get me started

#

im new:(

#

i dont even know where to ask questions 😦

compact patrolBOT
karmic oyster
#

thank you hackster

rustic sage
#

In the password attacks module, the network services section, one of the question asks me to find the valid credentials and I use hydra and the wordlists provided by the section but my scan has taken more than 1 hour is it normal, or is there some issue?

cloud urchin
#

no nothing really takes more than 30m.. is it the RDP question?

rustic sage
#

yup

cloud urchin
#

try crowbar maybe, i had luck with that

rustic sage
#

ok

rustic sage
sweet jewel
#

there was an academy module in the CAPE (?) path that had a large lab with a ton of ACLs, anyone remember which it is?

#

there was a table of all the ACLs too

#

nvm found it, it was in the bloodhound module

glacial sparrow
#

i'm just getting to the end of AEN atm, and i'm trying to run the domain passwords through hashcat, and it's finishing super quick without cracking anything. am i doing something wrong? i would have though running rockyou against every domain user would take longer than 30 seconds

#

here's the command that i'm using: hashcat -m 1000 ntds.txt /usr/share/wordlists/rockyou.txt --username

#

or are these users just super onto their password security 😂

waxen totem
safe star
#

most of them could just be the same password

glacial sparrow
glacial sparrow
waxen totem
glacial sparrow
#

LM is on the left pretty sure

waxen totem
#

Then yeah I've seen credentials with same LMs but still different passwords

glacial sparrow
#

i was also wondering if perhaps my ntds file wasn't formatted properly and hashcat wasn't telling me, but i've got it formatted like domain.com\username:RID:LM:NT::: which i think is correct

waxen totem
#

apparently if it's AAD3B435B51404EEAAD3B435B51404EE exactly then LM hashing is disabled

safe star
#

Yeah that’s not the format

waxen totem
#

probably why I've seen duplicates

safe star
#

I usually just grab the second part only

glacial sparrow
#

yeah i was checking there earlier. i also tried chopping the ntds file so it was just NT hashes and using mode 1000 on them

#

i might try applying some mutations to the wordlist and see if i can find anything that way

proud pine
#

This same kind of thing will lead you astray in the real thing.

glacial sparrow
#

i haven't tried many other wordlists. i'll see if i have any success with something from seclists

proud pine
glacial sparrow
#

right ok, good to know. i am kinda out of ideas though lol. feels like i'm bumping around in the dark atm

daring tundra
#

Hi, I'm trying to open the sample reports under resources, but it is password protected.. am I suppose to find the password through the lab?

daring tundra
#

Ohh right

#

Thank you

olive slate
#

Anyone can give some pointers on Abusing HTTP Misconfiguration > Bypassing Flawed Validation?

fathom pendant
#

if LM hash caching is disabled (Forget the actual name of it) then they'll be a default null, unnassocaiated with the NT portion

#

it's why you typically use the NT portion of the hash in PTH techniques [ LM:NT ]

glacial sparrow
#

yeah i haven't really been messing with the LM hashes at all

fathom pendant
#

i typically ignore the LM portion

#

because it's ultimately meaningless

#

as even if it were enabled it's a far more limited keyspace with lowercase characters

glacial sparrow
#

i'm still feeling confused about putting the NTDS hashes through hashcat. i've created a text file with only the NT hashes and am running hashcat on mode 1000, but it's finishing the entire thing almost instantly which feels way too quick

fathom pendant
#

is it [exhausted] or?

#

if they've already been cracked then --show will show whatever's been cracked

glacial sparrow
#

it's showing exhausted after about 30 seconds, and running --show only shows the few that i was able to crack while i was working through compromising AD

#

my assumption is that i should be able to crack at least a few more since surely there are a few domain users that are using bad passwords

fathom pendant
fathom pendant
robust marsh
#

Hi guys,I have doubt in splunk, while analyzing logs and got results on what I'm looking for. Then, I don't know what to do. Could someone help me?

fathom pendant
brave field
#

Hi@fathom pendant may I DM you? I have a question regarding some module question that I want to discuss. Thanks.

fathom pendant
#

and which section

fathom pendant
glacial sparrow
#

well except for all the domain creds that i found lol

brave field
robust marsh
fathom pendant
brave field
#

the bleeding edge vulnerabilities section

fathom pendant
#

@robust marsh My DMs aren't open for random conversation

#

you can ask your question here

#

if you're not sure what the module and section name are: read the top part of the section

<Name of module>:heart:
-------
Section Name
acoustic owl
rustic sage
#

Hello, any tips for resolving this error when trying to RDP to WS001 machine from the Kali machine. I am doing the Windows Attach & Defence PKI - ESC1 Module (Question 1). Thanks

final shale
#

The penelope shell handler makes life so much easier.

nimble scroll
#

On module Command Injections , lesson, Advanced Command Obfuscation , I got this question and I can t figure out how should I put the command , Find the output of the following command using one of the techniques you learned in this section: find /usr/share/ | grep root | grep mysql | tail -n 1

#

can anyone help me ?

gray yacht
#

You need to enumerate again, as what you need isn't hidden.

rustic sage
gray yacht
#

Well maybe the flag is on another machine.

potent sandal
#

hey guys where i can ask question about the labs Machines ?

gray yacht
#

<@&861185840277487616>

#

In CAPE too

lavish ember
#

Hey everyone,

I'm having some issues running Responder through a Ligolo pivot.

Here's the situation:

I'm using Ligolo to pivot into a network.
I tried running Responder on my attacker machine through the Ligolo tunnel, but it’s not capturing anything.
However, when I ran Responder directly on the target machine (which is a Linux box), it did capture some traffic successfully.

I'm not sure what I'm missing — maybe a routing issue or something else.

Has anyone faced this before or knows how to fix it? Any help would be appreciated!

Thanks in advance! 😊

nimble scroll
#

can anyone help me on Command Injections
Skills Assessment ?

#

I tried to do the request and fails to get the flag :/

shut wraith
#

Hello

#

For the evasion module how do I transfer the exploits to the target

#

theres no WinRM and theres no SSH

#

Theres only rdp

nimble scroll
#

there is no one to help me on command injections ? :((

next trail
#

Sup guys, I was doing attacking common services module and I cracked mssqlsvc hash and I started to wonder, what can I do with that hash? Can I use it to evil-winrm with it if winrm port was exposed?

nimble scroll
#

I tried to do this request and still failed to get the flag, can anyone help?

stone elk
#

What the hell is that is that hackthebox?

nimble scroll
#

yup... skill assessments

#

command injections, I am trying to figure this out by 1 hour and nothing

nimble scroll
#

I could not copy

#

ok

gray yacht
shut wraith
#

Should my shellcode be indented

lusty thicket
trim pelican
#

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)
can i get some help with that?
its part of module Skills Assessment - Using Web Proxies
and its 3rd exercise, i have cookie but how to do this?

bronze bobcat
#

hello

cloud urchin
bronze bobcat
#

I am new here and I was wondering if anyone could help me with a question about Network Enumeration With nmap Lab3.

rustic sage
#

Introduction to C2 Operations With Sliver > Domain Reconnaissance

Implant Timeout every time I try to execute-assembly or use alias

Getting Session via new-beacon.exe in RDP session

[server] sliver (new-beacon) > use db3b78ba-5127-4fdd-982b-a61183129bad

[*] Active beacon new-beacon (db3b78ba-5127-4fdd-982b-a61183129bad)

[server] sliver (new-beacon) > interactive

[*] Using beacon's active C2 endpoint: https://10.10.14.223:9002
[*] Tasked beacon new-beacon (d4d00ec5)

[*] Session f161143e new-beacon - 10.129.100.89:50263 (web01) - windows/amd64 - Sun, 09 Mar 2025 13:07:53 EDT

execute-assembly

[server] sliver (new-beacon) > execute-assembly /home/p1erce/SharpView.exe "get-netuser -PreauthNotRequired" -t 240 -i -E -M

[!] rpc error: code = Unknown desc = implant timeout

rubeus alias

[server] sliver (new-beacon) > sharpview -- "get-netuser -PreauthNotRequired" -t 240 -i -E -M

[!] rpc error: code = Unknown desc = implant timeout
trim pelican
hot perch
#

hi

#

sorry i have a questin off topic

#

does anyone have a great ressource to learn php

#

either videos docs books...

inner wadi
#

Hi, can anyone help with running SharpHound to complete the first task in Sliver skill assessments? I've tried everything but I can't figure out what the problem is

shut wraith
#

Why doesnt the flag get spawned its been 5 minutes no detection

hybrid temple
#

Hi, I am stuck at the same point. The module says ```Permissions

Not every user can create functions in PostgreSQL. To do so, a user must be either a superuser, or have the CREATE privilege granted on the public schema. Additionally, C must have been added as a trusted language, since it is untrusted by default for all (non-super) users.

For reference check out the PSQL Documentation and this answer on StackOverflow.``` but I can't find any solution

vague yoke
#

I am stuck at Login Brute Forcing - Skills Assessment Part 1. Can someone please give me a hand? Here is the hydra command I am using: hydra -L top-usernames-shortlist.txt -P 2023-200_most_used_passwords.txt 83.136.249.46 http-get / -s 54017

no luck getting the creds for the basic auth login

sand sedge
#

hi guys im on XSS PHISHING SECTION iam trying to get the credential of a user and when trigger the link by mine and enter my credentials in appears in the listener but when sending the link to send.php it does not give me any credentials how i can do this ??

#

btw im using 127.0.0.1:8

fathom pendant
#

127.0.0.1 is localhost meaning only your system

sand sedge
#

i tryd on 0.0.0.0:8080

#

but still not work

sand sedge
fathom pendant
#

because you're calling it from your browser

sand sedge
#

can i use any ip

fathom pendant
#

so your browser is calling your localhost

#

no

#

use the tun0 ip :)

#

the one that allows you to connect to the target; 10.129.x.x

sand sedge
#

is the one that when i do ip a appear the first

#

when i use it and the port it tells it is used with other things than web

fathom pendant
#

it's literally labeled tun0 in the ip list

sand sedge
#

yeah i use it but didn't work

fathom pendant
#

if using pwnbox, port 80 is already used up

#

i suggest using a different port

sand sedge
#

i can use it with any port

#

thanks for helping me

#

i got it

fathom pendant
#

you'd just adjust your payload to specify the port

sand sedge
#

where can i know somethings like this

fathom pendant
#

it's called adaptive thinking

sand sedge
#

bc i didn't know anything about web

fathom pendant
#

you need to adapt your thinking to be more flexible

sand sedge
#

no not about thinking

#

about know the ports and ips

fathom pendant
sand sedge
#

yeah and more like this

fathom pendant
#

it's a simple thing of understanding that services can run on non-default ports

#

¯_(ツ)_/¯

sand sedge
#

kk i wil search about this

#

thanks in advice

boreal fern
#

does someone know how to get access to the htb faq forum? Because its only on invite and i'd like to know if its possible to get access there

vague yoke
#

I am stuck at Login Brute Forcing - Skills Assessment Part 1. Can someone please give me a hand? Here is the hydra command I am using: hydra -L top-usernames-shortlist.txt -P 2023-200_most_used_passwords.txt 83.136.249.46 http-get / -s 54017

no luck getting the creds for the basic auth login

median gale
#

Got the 3rd one, and the handshake for the 1st one but dont think we are meant to break it or so. I dont think we have to set up apache the module states that this is not it purpose

rustic sage
#

Hello 👋🏻

storm elk
#

Hi

rustic sage
storm elk
median gale
storm elk
median gale
#

It ok thanx though

main ridge
median gale
main ridge
vague yoke
#

I am stuck at Login Brute Forcing - Skills Assessment Part 1. Can someone please give me a hand? Here is the hydra command I am using: hydra -L top-usernames-shortlist.txt -P 2023-200_most_used_passwords.txt 83.136.249.46 http-get / -s 54017

no luck getting the creds for the basic auth login

gray yacht
vague yoke
#

yes... I am using those wordlists as they are the recommended ones in the question.

vague yoke
#

yes, a couple of times already.

gray yacht
vague yoke
#

yes, the new ip and port are: 83.136.249.46:43769

#

first question in there.

gray yacht
#

I just ran it and got it.

#

Are you on pwnbox or your own VM?

vague yoke
#

pwnbox

gray yacht
#

Can you send me a DM?

vague yoke
#

did you run hydra -L top-usernames-shortlist.txt -P 2023-200_most_used_passwords.txt 83.136.249.46 http-get / -s 43769 ?

#

this exact command? did you use the same wordlists?

#

yes, I will DM you

shut wraith
#

When running the program, we get a interactive PowerShell session and we didn't get blocked by Microsoft Defender Antivirus, because we didn't use anything known to be malicious. Even if it decides to do a memory scan of our process when powershell.exe is spawned as a child process, nothing should be detected since we won't be matching any known signatures. Is this fake news because dynamic analysis by Defender doesnt care about signatures it just looks at the behaviour. And we are spawning a PS shell remotely so that is malicious ...

cloud urchin
boreal fern
cloud urchin
fathom pendant
#

i believe staff have said they're keeping it ReadOnly but they're not allowing new posts afaik

#

while it sucks; discord being an async platform that most people utilize anyway allows for better/faster resolution and searching for solutions

boreal fern
#

Yeah, really like the simple way and its clearness

muted jacinth
#

Hi everyone, can someone give me a hint about the MSSQL, Exchange, and SCCM Attacks SA? I feel pretty stuck after the exchange parts. I can't seem to find any way into the mssql server

fringe hollow
#

Good day everyone,
I have been working through the Penetration Tester Pathway, and decided to direct my focus on specific modules such as XSS. I have found myself at a loss, confused as to why the session hijacking and assessment target web servers are blank. Even after running an nmap scan to identify additional pages, there are no pages accessable for an online form with input fields. I have read in HTB Forums that these fields should be shown. Am I overlooking something obvious?

median gale
#

Any hint for the second one?

main ridge
median gale
main ridge
quick goblet
#

Nmap have any limits on windows ? I want to start and every time i use nmap in termianal i got error . Should i use linux / kali linux instead ?

shut vapor
#

In Windows Privesc > Weak Service Permissions but my question is generic PowerShell. I'm having a weird time filtering for double quotes with findstr. Typically you can escape a character with a backtick or if you need a double quote use single quote encapsulation... but with findstr neither of these is working.

PS C:\> echo "this is a `" test"
this is a " test
PS C:\> echo "this is a `" test" |findstr "a"
this is a " test
PS C:\> echo "this is a `" test" |findstr "x"
PS C:\> echo "this is a `" test" |findstr "`""
FINDSTR: No search strings
PS C:\> echo "this is a `" test" |findstr '"'
FINDSTR: No search strings
median gale
main ridge
shut vapor
#

quirky

gray yacht
#

Maybe a different internet protocol version?

shut wraith
modest briar
#

hi

pliant jewel
#

Hi guys. Im doing the "Getting Started" module and now im learning about "msfconsole" and "searchsploit". I have this IP: 94.237.55.96:55521 . With nmap i got the port 55521 is open with http and the version is Apache httpd 2.4.41 ((Ubuntu)). Im trying everything that comes to mind, but I cannot find a "public exploit" to gain the flag.

Thanks everyone

pliant jewel
#

Public Exploits

waxen totem
pliant jewel
#

ye

waxen totem
#

Literally the first thing when you visit kek

solid epoch
#

look for the source code of the page to identify what its using

#

also, get the directories with dirbuster, everything can help you

#

then searchsploit <name>

pliant jewel
#

this is the web xd

solid epoch
#

when you see WordPress somewhere,

#

the site is asking : Hack me

waxen totem
solid epoch
#

search for wordpress backup plugin

#

when you find an exploit for it, try to understand the code and see why it is working in the first place and what its doing

lavish gale
#

Currently I'm working on Firewall and IDS/IPS Evasion - Hard Lab section from the "Network enumeration with Nmap" module, and I'm completely stuck on trying to obtain the flag. Utilizing the --source-port and using port 53 allows me to see additional info from port 50000 on the target host, and I assumed just like the sectiosn in the module suggested that I can try to netcat and use port 53 to connect to port 50000. However, I keep recieving this error. I've attempted to take away the -p 53 and I still got nothing. If anyone could give me hints that would be greatly APPRECIATED!

gaunt forge
#

so if your running nc end that

solid epoch
gaunt forge
#

this command should show what service is running netstat -tulnp | grep :53

pliant jewel
solid epoch
pliant jewel
gaunt forge
#

I'm stuck on sqlmap essentials, case 6. I got the flag just fine with the hint telling me that the prefix is '`)', but i would have never gotten it without that hint. any idea how I can figure out what the prefix is

#

without a hint

lavish gale
cloud urchin
barren karma
#

yo guys, can someone help me the module PIVOTING, im specifically at RDP and SOCKS Tunneling with SocksOverRDP, i have been stuck in this module for 2 days, becase it keeps giving me the same error when i try to execute the Remote Desktop Connection.

The error says:

Remote Desktop can't connect to the remote computer for one of these reasons:
Remote access to the server is not enabled
The remote computer is turned off
The remote computer is not available on the network
Make sure the remote computer is turned on and connected to the network, and that remote access is enabled.

gaunt forge
cloud urchin
gaunt forge
cloud urchin
#

nah i don't know, you'd have to search i guess

#

or just read about how queries are constructed

#

i'm sure it depends on what type of db etc too

gaunt forge
#

i guess i'll just try some of the prefixes i would try from sql injection essentials

#

still it feels like i could get completly lost on a skill assesment if I miss the right prefix then

dull heron
cloud urchin
#

the hint explains what to do

#

you can also review the encoding/decoding section

safe star
dull heron
solid epoch
#

i have a small question :

in IMAP, when I do : 1 SELECT <directory>,
and when there says : 4 EXISTS, how can i fetch this ?
1 FETCH 4 all ?

dull heron
#

Am I supposed to decode md5 after this?

#

Sorry I am struggling here...kinda at beginner stage...

cloud urchin
#

it's a web proxy module, do it in a web proxy and see the results when you have the correct cookie

dull heron
#

ohk i think i got it

#

lets see

cloud urchin
#

also please be careful not to post spoilers from modules, especially skill assessments

fringe hollow
dull heron
cloud urchin
cloud urchin
# barren karma ?

That's a very generic error indicating network issues, check your network connection through to the target.

#

and verify you're using the right IP or hostname.

barren karma
#

i just did a ping, but it does not reach

cloud urchin
#

is this the initial target?

#

if so, shut down the target. re-download the VPN if you are using the VPN. shut down the pwnbox. press ctrl+shift+r on the page, respawn the target and reconnect to the VPN or spawn the pwnbox. do not use the pwnbox and the VPN at the same time as that causes connectivity issues. this should clear up any network problems connecting to the target, unless you've had your computer/vm on for a long time then you may need to restart to reset the networks stack.

barren karma
#

any other machine in the module works perfectly, its just that machine.

I have tried everything I have found, and know, however nothing works.

cloud urchin
#

okay but is this the initial target or something else

#

you are leaving out critical detials

barren karma
#

so, im connecting to the pivoting host, throught xfreerdp, and then i need to use the tool SocksOverRDP, to do pivoting to the ip 172.16.6.155 , however when i connect throught xfreerdp to the pivoting machine and i try to do a ping to 172.16.6.155 , it does not even reach.

shut wraith
#

Hey @cloud urchin i tried all methods in lab and no "user" runs my shells and my sliver listener is empty for hours

supple gorge
#

Is it usual to get a server not feeling well when downloading cheat sheet for Process Injection Attacks and Detection?

shut wraith
#

I just need a point to the right direction please

cloud urchin
cloud urchin
shut wraith
cloud urchin
shut wraith
#

Btw I ran the shells by myself and non of them work for my own user ...

shut wraith
#

Did u build it on your user host or a VM ?

cloud urchin
barren karma
cloud urchin
#

the error you provided is straight up a network connectivity error so somewhere along the chain something is not configured correctly

waxen totem
#

👀

#

Was bout to ask em how many rs in the word strawberry kek

neat pelican
#

anyone here know how to compile the Inveigh C# into an exe?

cloud urchin
#

otherwise clone the repository and compile it from there

neat pelican
#

I read that it needs the Visual Studio Solution to compile it but I only have VSCode (the blue one)

safe star
#

get VS

shut wraith
#

In the Tools directory of any module VM there will be these

solid epoch
#

how am i supposed to know what the unusual process is :)))))))

shut wraith
solid epoch
#

now whats the unusal process 🤣

#

im on SNMP btw, and is SNMP usually always that unstable ?

#

I mean when i want to get the running processes for example, it always gives me different ones

waxen totem
#

UDP doesn't do any connection checking, or acknowledgement if packets are received

solid epoch
#

i see

waxen totem
#

Which module you on?

solid epoch
#

footprinting, SNMP

#

stuck on last question

waxen totem
#

Ohhh... you'll definitely know it when you see it

solid epoch
#

okay thank you

#

and btw : how can i know the snmp version ?

#

if i need to use v1 or v2c

waxen totem
#

did you try to use the other enumeration tools highlighted in the section?

solid epoch
#

when i do this, only TCP ports are checked

#

however, in autorecon i can see that udp port 162 is open

waxen totem
solid epoch
#

afterwards

#

i should revisit it hah?

waxen totem
#

So you should know how to scan UDP ports sus

solid epoch
#

yeah i skipped maybe things
because i know that i can also scan with autorecon UDP ports

#

but idk how to get banner with autorecon Lets see

#

omggggg

#

i found it

#

it took so long because i didn't look at ||the long output||
I think i should > save.txt it next time :D

waxen totem
solid epoch
#

Yes
I just thought that the flag is in the running processes

lament fossil
#

Hello friends

waxen totem
#

Deletin that cos that was a spoiler

solid epoch
lament fossil
#

I'm new here and I want to learn please 🙏🏻

compact patrolBOT
opaque geyser
#

There is a lot to learn

solid epoch
#

I have read :
Windows MIB values
And OIDs

its the same right ?

lament fossil
#

Ok

waxen totem
thick steppe
#

doesnot this seem advance enough

waxen totem
#

Please don't post about THM stuff here, this is a channel for HTB modules

thick steppe
#

please dont complain I know I am not supposed to post here

#

I was not able to post in general so I did here, will delete it in few minutes

#

THis seems to be as good as cpts

solid epoch
#

man after knowing cpts course i am never comin back to THM 🤣

lament fossil
#

These links are not opening

solid epoch
waxen totem
solid epoch
#

i just bypassed the check 🤷🏾‍♂️

#

now im in 😎

waxen totem
#

I mean it's just the difference between using HTTP and HTTPS

#

it's just a security layer through SSL but since your client doesn't like that the server signed its own cert you can just tell it to ignore it

shut wraith
#

hey @waxen totem did u do the process injection new module yet ?

waxen totem
#

Am only at File Transfers in PT kek

faint wagon
#

Hello

solemn patrol
shut wraith
velvet jay
#

Hey guys

faint wagon
waxen totem
#

@faint wagon @velvet jay @solemn patrol this ain't #general chat, please get Verified (instructions here --->#welcome) so you can chat in #general

sharp torrent
#

doing attacking common applications assessment 1, having a hard time finding the vulnerable application on port 8080. Can someone suggest a wordlist to use please ? thanks in advance.

tender cliff
sharp torrent
tender cliff
#

Use hydra or something else bro.

tender cliff
#

I think is firewall or rate limit or captcha.

sharp torrent
tender cliff
#

Not laugh it is great ai to help us and do legal work for us

safe star
#

bro just talking

cloud urchin
tender cliff
tender cliff
#

Again I sure to legal activities only .

#

Bro that is easy

tranquil zealot
#

Hi, on the Network Foundations module Introduction to Networks section, 2nd question, for some reason I cannot answer
In network terminology, what is the term for individual devices connected to a network? with Nodes, is this like an error because everything in the page suggests this to be the answer and I have refreshed the session as well

#

All other questions worked fine except for this

#

Nvm it was seriously caps sensitive this whole time

#

Thanks though

thick steppe
#

I am at the ReGex section, I have this question

Search for all lines beginning with Password and containing yes.

what exactly would you google to get the answer, if possible can you show me like how would you approach this question in googling it, I googled few things but can't get the answer

#

I am trying to learn how to google right thing, so far I am only getting weird answers for my searches for - regex line begenning word, don't know what else to google in this case

lapis burrow
#

Hello, i'm new here, how do I contact the support in this discord server? I'm having issues with billing.

thick steppe
thick steppe
lapis burrow
thick steppe
#

linux fundamentals

#

just after the filter contents section

thick steppe
#

I got the answers from yt but there is no relevent cheatcheet

fathom pendant
#

plenty of them to go around

thick steppe
#

I already tried looking at those

fathom pendant
thick steppe
#

evem tried the one you have told before

fathom pendant
thick steppe
#

yes this one

fathom pendant
#

it explains all the regex expressions

#

"^<text>"
outside of [], "^" is an anchor much like "$"

thick steppe
#

too much data, can know where to go and what to do

fathom pendant
#

you're looking for "starts with"

#

"start of string" or "start of line"

#

if you think a cheatsheet that's fairly explanatory on what each function is is "too much data" i have bad news for your friend

thick steppe
#

is regex used very often in CPTS

fathom pendant
#

for instance you're searching a list for lines that ONLY contain "abc" but not if there's a symbol or space in front or behind

#

"^abc$" will get you all lines that start with, and terminate at abc

thick steppe
fathom pendant
#

that's really not that complex

#

that's on the simpler side of regex, and regex can save you loads of time

thick steppe
#

LInux fundamentals

fathom pendant
#

i barely knew regex when i started, so i can tell you for sure, that this is on the simpler end of regex

thick steppe
fathom pendant
#

some can get extremely complex

thick steppe
fathom pendant
#

^.*{6,} <-- this is a bit more complex
start, match any, minimum 6 characters

#

it's used in a couple modules for shortening wordlists, login bruteforcing iirc goes over it a bit, though a shame they replaced that portion with chained grep over using sed

#

but regex is super useful overall to learn

thick steppe
#

Seems like this is enough for today, I need to sleep, will ask for help tomorrow if I need it, I try not to ask for help unless stuck for hours which did happen

light yarrow
#

Wasgood

#

L4 sent me

fathom pendant
#

no idea who that is but either way this isn't #general i suggest reading and following #welcome to access

tepid ridge
#

Hello, just started hack the box academy and I am on the linix fundamentals module. All of the challenge questions are targeted for htb-student and when I enter whoami, I get htb-random numbers. How would I be able to change my user to htb-student

safe star
tepid ridge
light yarrow
#

Plz send the bots when I get the money we do stream raids

#

etc

light yarrow
#

Lmfaoo duhh

noble raft
#

HTTP Response Splitting anyone? I got the xss, figured out everything but the way I make the admin press my amazing payload, anyone solved it and can give me nudge on what I am missing?

#

Were you able to solve it? the XSS works for me, I just dont know how to deliver it to the admin..

hazy comet
#

Good morning, I'm looking for help with the Advanced CSRF & XSS module - XSS bypass flag. Managed to bypass the filter with object tag with encoded payload. Can't seem to get a call back with the exfil payload. If someone could share the solution please

storm elk
willow furnace
#

i just wanna say im a big hater of AD Enumeration & Attacks - Skills Assessment Part II

#

and everyone who also hates it , is my friend

proud pine
willow furnace
#

im in the middle and cant see the end

#

dont get me wrong, i have mad respect for person behind it

#

but there is so much to try and its so time consuming that demotivates

old wren
#

yeah AD enum was more difficult than some other modules in the same difficulty range

#

but worthwhile!

tranquil zealot
#

Hi, for the final chapter of Network Foundations, I am unable login as anonymous user despite copy and pasting the commands into the terminal on my VM instance

gray yacht
#

You can DM.

vagrant gust
#

Hi this might seem a bit stupid but for the intermediate network traffic analysis skills assesment i wouldve thought that 52 bytes was reasonable as the lesson said 48 bytes is a normal amount

#

im not really articulating this well but i wrote off tunnelling for that reason

#

sorry if im putting spoilers

#

and also how would you know which ip is the host with the pcap files

waxen totem
#

idk the correct answer but have you tried just drupal ?

trail mulch
brave scroll
#

Module : SQL Injection Fundamentals
Section : SQL Injection -> Subvertiing Query Logic

SELECT * FROM logins WHERE username='tom' AND password = 'some' or '1' = '1';
T F-------->T<-----T
|------>T<--------------------|

SELECT * FROM logins WHERE username='tom or '1' = '1' AND password = 'some' or '1' = '1';
T F-------->T<-----T
|------>T<--------------------|

SELECT * FROM logins WHERE username='tom or '1' = '1' AND password = '1234';
T T------>F<--------F
|-----> T <-------|

1 and 2 give me answer of successfully login as "admin"
but why logic no 3 only give me flag.. and show successfully login as "tom"

spiral jungle
#

hello people, im in the ai red teamer path - applications of ai in infosec module, in the skills assessment when i upload my .joblib file it gives me Your model accuracy is 0.0. Please improve it to at least 90% to receive the flag. which i saw someone mention it earlier but didn't find any solution to this issue, does anyone know what must i do

Update: I checked the python libraries i used in my model, which had one that wasn't included in the module's material, used the one in the module and got the flag, hope this helps

#

also in the validation feedback, the confusion matrix shows that 12 positives were predicted positive, and 13 negative were predicted negative, sooooo...

opaque geyser
#

Can someone help me in Module : windows attacks and defense; Coercing Attacks and Unconstrained delegation?

I am having a hard time figuring out what to connect to and I lost my previous progress from other attacks. I can’t seem to connect to WS001 with bob. Now we have brought in the Kali machine 🤷‍♂️

tired atlas
#

So I have a question regarding Password Attacks: Pass the Hash

Why does Julio not have permission to access SMB folder \\DC01 when you RDP as Julio, however, when you use the Mimikatz command, you can suddenly access the shared SMB drive to get to his folder, essentially how the flag is found. How does that work

#

What does Mimikatz execution have that logging in as Julio via RDP doesn't have

#

Does it escalate his privileges or something, I dont get it

errant tiger
#

im having a problem with Network Foundations last last question. im using htb web based Pwnbox. does anyone have the same problem or a solution?

inland oak
#

hi'

rustic sage
#

hey guys, I need help in the password attacks module network services section. The question is about finding the credentials of RDP. I have tried using both hydra and crowbar using the provided wordlists but still cant find it. Can someone give me a nudge in the right direction? Thanks.

lusty thicket
#

it uses kerberos (if available) or some other method, which prevents his credentials from being forwarded to another system like DC01

#

and since you don't have julio's ntlm hash, you cannot authenticate to smb using ntlm

hazy comet
#

Good morning, I'm looking for help with the Advanced CSRF & XSS module - XSS bypass flag. Managed to bypass the filter with object tag with encoded payload. Can't seem to get a call back with the exfil payload. If someone could share the solution please

tired atlas
#

thats why i asked

keen walrus
#

please
[16:24]
help me i need help with this module
[16:24]

  • 2 The directory we found above sets the cookie to the md5 hash of the username, as we can see the md5 cookie in the request for the (guest) user. Visit '/skills/' to get a request with a cookie, then try to use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag. Use the "top-usernames-shortlist.txt" wordlist from Seclists.
    (edited)
    [16:25]
    got the request with the cookie than fuzzed with the requested wordlist but found nothing
spice star
#

Hi in NFS module, I'm experiencing an error message each time I'm trying to mount the module.
I'm using Exegol, so hacking from a Docker container.
Do you know why?

$ sudo mount -v -t nfs -o nolock 10.129.202.5:/var/nfs ./nfs
mount.nfs: timeout set for Mon Mar 10 13:41:16 2025
mount.nfs: trying text-based options 'nolock,vers=4.2,addr=10.129.202.5,clientaddr=10.10.16.43'
mount.nfs: mount(2): Operation not permitted
mount.nfs: trying text-based options 'nolock,addr=10.129.202.5'
mount.nfs: prog 100003, trying vers=3, prot=6
mount.nfs: portmap query retrying: RPC: Timed out
mount.nfs: prog 100003, trying vers=3, prot=17
mount.nfs: portmap query failed: RPC: Timed out
mount.nfs: Operation not permitted
shut wraith
#

Hello for:

Evasion Module

Dynamic Evasion

I replicated exactly how the lab does Option 3 and it still doesnt work...

Do I need ot convert it to shell code and obfuscate it ?

If so how do I convert it to shell code ???

spice star
spice star
keen walrus
#

wait

#

try mounting from the pwnbox

#

start with this command

#

sudo nmap --script nfs* 10.129.14.128 -sV -p111,2049

#

showmount -e 10.129.14.128

#

havent done this module in a while so thats my best 🙂

#

cause i switched to cbbh path mid cpts

spice star
keen walrus
#

i mean

spice star
keen walrus
spice star
keen walrus
#

networking and windows pentesting was fire

keen walrus
keen walrus
spice star
keen walrus
#

im on 30% soon wish me luck lol

spice star
keen walrus
#

😂 XD

spice star
#

it worked smoothly from the pwnbox...
Will the pwnbox be available during the exam?

shut wraith
#
[03/10/2025 07:52:08] C:\Alpha\Dynamic\day2.exe - OK - Starting process...
[03/10/2025 07:52:53] C:\Alpha\Dynamic\day2.exe - OK - Timeout reached, killing process```
Anyone can help with the evasion module
shut wraith
#

its in the cape path

spice star
gray yacht
keen walrus
#

anyonecan help with fuzzing ?

shut wraith
gray yacht
keen walrus
#

guys i rlly need help

#

you need to set your processors to md5 hashes and then in the fuzzers tab all will appear with 200 and just resend to the browser to view the flag

keen walrus
gray yacht
keen walrus
#

can u help me bro ?

keen walrus
#

using web proxies zap fuzzer - question : + 2 The directory we found above sets the cookie to the md5 hash of the username, as we can see the md5 cookie in the request for the (guest) user. Visit '/skills/' to get a request with a cookie, then try to use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag. Use the "top-usernames-shortlist.txt" wordlist from Seclists.

cobalt aspen
#

Does someone has the same problem as me today, machines in CAPE modules are so unstable today, it is not even possible to do the module normally?

#

Like, 2min machine is available, then 5min not

desert quail
#

Can someone help me, i can´t find a way to get this answear right

https://academy.hackthebox.com/module/229/section/2446

Question: Inspect the ARP_Poison.pcapng file, part of this module's resources, and submit the total count of ARP requests (opcode 1) that originated from the address 08:00:27:53:0c:ba as your answer.

in the ARP_Poison.pcanpng when in wireshark, and using this filter: arp.opcode == 1 && eth.src == 08:00:27:53:0c:ba , i get nothing as an answear. What im i doing wrong?

shut wraith
spice star
# keen walrus sure men

in case you are using Exegol (advanced kali via Docker) my probleme was a container network config issue whic is solved by granting more (Sys) privileged 🙂

keen walrus
#

u solved it at the end right ?

#

btw idk if u do that but i personally take notes of every module , u should also write notes to urself on the module as well to have it ready in case u forget something . i personally recommend remnotes its really good

#

@spice star

vagrant gust
#

double check youre using the right file

spice star
vale ingot
#

Anyone here in the field of OSINT?

spice star
desert quail
vagrant gust
desert quail
vale ingot
#

Would you help?

granite rivet
#

Is kali still better than most distros? Or is parrot htb better now?

#

Im new to the Parrot OS but I wanna get the certificates, So should i just get rid of kali and hard focus parrot?

lusty thicket
#

they both work

shut wraith
lusty thicket
languid imp
#

did u use micr0_shel?

honest crane
#

I'm reviewing the Sample Report given in the Documentation & Reporting module, and in Appendix E there's a section for most common passwords with passwords in plaintext. Should I follow this example in the exam report? Because I've seen some people say passwords and hashes should always be redacted.

shut wraith
# languid imp did u use micr0_shel?

I wasnt able to build that because my Commando VM had some incompatibility.

But someone else said that using the powershell script (option 3) is the solution.

For me personally I am going to go through other resources and master shellcodes before I come back

https://tryhackme.com/room/avevasionshellcode

TryHackMe

TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!

gray yacht
old wren
old wren
languid imp
rustic sage
old wren
#

you can try increasing the thread count in Hydra (-t flag)

#

sorry I don't remember more details - but I do remember that some of the hydra attempts took a long time

#

you should take advantage of Hydra's session saving feature, that way you don't have to repeat stuff

vital apex
#

Hi there! I've encountered a challenging scenario in the Dante ProLab. After successfully double pivoting to a host in the 172.16.x.x range, I discovered another IP in the same subnet through a ping sweep. Despite having my tunneling properly configured, I can't get ping responses from this new target, which means I can't even use nmap or msfconsole to determine what ports might be open. Is there something i have missed? A nudge in the right direction would be greatly appreciated 🙂

mystic narwhal
#

Hi all! I'm stuck on the windows evasion techniques module in the open-source software section, can anyone help me? I tried using bypass which patches amsi.dll, but I still can't run the .ps1 file

old wren
fringe hollow
#

May someone please take the time to view my issue with the module: Windows Priv Esc: SeImpersonate and SeAssignPrimaryToken (Module 67 Section 607)

My question was posted in the Community Help Channel. Thank you in advance!
#1348722231781621790 message

gray yacht
mystic narwhal
old wren
#

so if you copy/paste the command from the module, and then remember "oh wait, my machine has a different IP", and then fix the IP/port to the one you're using, and run Juicy Potato again - it won't work

#

simply log out, re-establish the mssqlclient connection, enable xp_cmdshell, and re-run the command (literally just copy paste) - but run it once, with the correct IP/port

shut wraith
shut wraith
fringe hollow
# old wren simply log out, re-establish the mssqlclient connection, enable xp_cmdshell, and...

Thank you for the assist, this does make sense.

Unfortunately, after quitting the mssqlclient connection and re-establishing the connection, running the required cmds leading up to the cmd to reverse shell (Setting up a listening port first on my local htb vm) I still do not receive a reverse shell back. The IP I enter within the cmd is in fact supposed to be my local htb vm IP right?

spiral sapphire
#

Hey guys! I'm doing the web fuzzing module with ffuf and requests/second is extremely slow right now. Yesterday I got 1k requests / second and now I only get 100 requests / second. Is this common?

old wren
vital apex
old wren
spiral sapphire
mystic narwhal
old wren
#

If you got that, but can't get a revshell back to your HTB VM, I'd first try resetting both the attack VM and the target VM - it's likely there's some mud in the pipes, and you can't establish a connection

old wren
fringe hollow
# old wren I assume you at least got a better output in the SQL machine? Meaning this:

Thank you again, I agree this was strange. I did reset both again and specified a different listening port "12345". This worked just as your screenshot shows. I assume I may have needed to verify there was not still a process running "8443", then kill the process running the listening port "8443" on my local htb vm before attempting to use this port again.

Strange either way but it works now. Thank you!

patent crow
#

I can't text in general
Anyone know why?

proven valley
#

Hello there, I’ve been trying to figure this out for the past hour, but I still can't get the correct answer.
Network Foundations
The question: What type of cable is used to connect components within a local area network for high-speed data transfer?

old wren
solid epoch
#

i think i have it

nimble scroll
#

can anyone help me with this ? The above exercise contains an upload functionality that should be secure against arbitrary file uploads. Try to exploit it using one of the attacks shown in this section to read "/flag.txt"

#

File upload attacks , lesson Limited File Uploads

#

I don t understand how to proceed to get the flag, I get errors while uploading...

gray yacht
blissful harbor
#

Quick question regarding fuzzing using Burps' intruder. If I'm setting the directory to finding a certain type of file and I'm getting a 400 or 403 status message; does that mean I'm skipping a step?

fathom pendant
proven valley
fathom pendant
#

it's not looking for any type of 'cat'

solid epoch
#

man i got it now but dude, this is not possible without knowledge about certain softwares

#

i thought i can || the spoilers sorry @fathom pendant

#

and how can i use strg+alt+Q in kali linux? :D

fathom pendant
#

anyone can click on it

proven valley
solid epoch
fathom pendant
proven valley
#

ohh i see ok

fathom pendant
fathom pendant
#

but everything needed to enumerate was 100% taught by the module

nimble scroll
valid zinc
#

Hello, My name is Erik Heijne. Can I talk to someone who works at Hack the Box in Athens?

real delta
valid zinc
real delta
#

you should contact support

compact patrolBOT
verbal stump
#

Hi, I study in HTB_academy and I trying to run .exe on the windows server 172.16.5.19 in module Pivoting, Tunneling, and Port Forwarding in Remote/Reverse Port Forwarding with SSH in Penetration tester path but I always getting error
I need help (изменено) sadglas

valid zinc
proud pine
valid zinc
proud pine
valid zinc
#

Alright I will try that way then. Thank you

real delta
nimble scroll
#

can anyone help me with some tips ?

#

The above exercise contains an upload functionality that should be secure against arbitrary file uploads. Try to exploit it using one of the attacks shown in this section to read "/flag.txt" , I don t find any clue to get the flag

cyan nacelle
#

this is not in a module per say but does any know how to a listener to lingolo for a third pivot

#

is it the same as

listener_add --addr 0.0.0.0:11601 --to 127.0.0.1:11601 --tcp
deep bay
heady pier
#

Hey, got stuck with Nmap-hard, i'm using the scan nmap with source 53. And geting the open 50000
PORT STATE SERVICE REASON VERSION
50000/tcp open tcpwrapped syn-ack ttl 63

but not sure, where to dig further, nc or ncat cannot connect in any way.

waxen totem
real delta
heady pier
nimble scroll
deep bay
nimble scroll
#

<svg xmlns="http://www.w3.org/2000/svg" width="100" height="100">
<rect width="100" height="100" fill="red"/>
<text x="10" y="20">&xxe;</text>
<text x="10" y="40">XXE Test</text>
</svg>

#

curl http://94.237.57.237:38154/uploads/proc_cmdline.svg
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL was not found on this server.</p>
<hr>
<address>Apache/2.4.41 (Ubuntu) Server at 94.237.57.237 Port 38154</address>
</body></html>

deep bay
nimble scroll
#

still didn t get a way for the flag

deep bay
#

all you need is uploading a svg file with XXE code in it.

nimble scroll
#

it says success but could not make it to do the command

deep bay
#

have you try viewing the website source code after upload? like ctrl + i

nimble scroll
#

I did and still doesn t help me

#

invalid input

#

I still don t get how to get the flag :/

#

HTTP/1.1 200 OK
Date: Mon, 10 Mar 2025 20:56:36 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 26
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8

File successfully uploaded

#

when I enter on the file it says not found ... wtf

#

welp, solved in the end :\

sinful mulch
#

I'm having trouble on the information gathering web edition vhosts module and I can't figure out why I can't get it to work can anyone give me a hint on what I might be doing wrong?

deep bay
sinful mulch
#

i think i may be entering the answers incorrectly or I'm not sure exactly what it's asking me to find when I scan vhosts it gives me the entire list

#

nvm i'm dumb

#

it was an issue of ports

safe star
fathom pendant
#

also be mindful of spoilers

deep bay
#

that was quick

fathom pendant
#

no

sudden galleon
#

Anyone who has done the WiFi-EvilTwin Attacks module? I have some questions about skill assessment, I would like to compare results

plain raven
#

hi

devout spruce
#

Hi can someone help me with the question

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

for pass the ticket from Linux in the Password Attacks module? I've been stuck on this for about 3 hours.

fathom pendant
#

are you unable to use the ccache? NEI to properly help you

#

you just repeated the question without stating what you've tried [redacting spoiler info like full filenames]

devout spruce
#

So far I've tried following what it says in the section for importing the ccache file into the current session. I've found two ccache files for the user julio and tried exporting both of them individually. When I check afterwards with the klist command though it just gives me "No credentials cache found".

fathom pendant
#

you're setting KRB5CCACHE=<filename>?

devout spruce
#

Yes I am

fathom pendant
#

well = /path/to/filename

#

it's generally best to use the full filepath

devout spruce
#

Omg... yep, that was it. Should have seen that lol. Thank you.

viral lotus
#

Can someone give me a nudge or help on the Linux priv esc logrotate - I have logrotten compiled, made a payload one was just to read the flag from root and the other was a reverse shell like given in the module example. Neither worked. Any help appreciated

cloud urchin
#

I believe I also found it really only works once, so if you got it to work you need to restart the target. I could be misremembering but I think this was the case.

viral lotus
#

Ahh okay so I could’ve done it just not been quick enough I just spent 4 hours pulling my hair out. I’ll try it again in a few hours. I think you are right.

I did check the forum. The log file goes from flag.txt to another log.1 or .2 very quick

#

I’ll try restarting the target too. Thanks

neat pelican
#

Anyone here who is finished with Internal Password Spraying - from Linux | Active Directory I can't seem to do passwordspray using kerbrute using the found usernames from the previous section. It always says KDC_ERR_ETYPE_NOSUPP

cloud urchin
#

did you allow it to continue? i got that error but it still worked

neat pelican
#

Yeah, unfortunately it was finished. Says 21 out of 50+ usernames tested with 0 successful

#

I also tried cme but still no luck

neat pelican
#

nevermind, I just have to filter out/remove those usernames that would cause errors

long kestrel
#

I am trying to answer the first question on the Introduction to Binary Fuzzing section Glee with Klee, but it is not recognizing the LLVM bytecode when I am following the commands in the section. I installed KLEE with snap on the pwnbox to do this because I cannot pull the docker image for Klee to try it that way because the pwnbox doesn't have enough storage for it.
Question: Based on the contents of test000002.ptr.err, which line of the intermediate language (IL) file assembly.ll does the vulnerability appear on? Provide only an integer, eg 123.

languid imp
# shut wraith Yes okay please share it with me and share how u made it work

Hello,

Sorry for the late reply.

Since I don’t know C#, I just gave the code to ChatGPT and asked it to modify it so that it sends the reverse shell to my own IP and port.

There was no need for any obfuscation—HTB explained the reason in the module.

If you don’t mind modifying the code yourself, please let me know. I’ll be at my computer in about 1.5 hours and can share the code then.

shut wraith
#

(U just paste it)

languid imp
shut wraith
#

Thanks gonna try it in the morning 👋

cloud urchin
#

@languid imp please don't post content from any modules above t0.

languid imp
verbal stump
brave field
#

Hi. I am using attackbox and I get an error while getting TGT using gettgtpkinit.py. Any suggestions? Thanks.

gleaming tundra
#

Hi

#

I wanna learn hacking so where do I start

compact patrolBOT
waxen totem
#

@gleaming tundra ^

neat pelican
#

First time using bloodhound tool. It says in the academy to do sudo neo4j start says it's already running (pid 2703). Typed bloodhound says No database found at bolt://localhost:7687, I tried http://localhost:7474 still nothing.

waxen totem
neat pelican
#

No output, but here's the output when starting neo4j

┌─[✗]─[htb-student@ea-attack01]─[~]
└──╼ $sudo neo4j start
WARNING! You are using an unsupported Java runtime. 
* Please use Oracle(R) Java(TM) 11, OpenJDK(TM) 11 to run Neo4j.
* Please see https://neo4j.com/docs/ for Neo4j installation instructions.
Directories in use:
  home:         /usr/share/neo4j
  config:       /usr/share/neo4j/conf
  logs:         /usr/share/neo4j/logs
  plugins:      /usr/share/neo4j/plugins
  import:       /usr/share/neo4j/import
  data:         /usr/share/neo4j/data
  certificates: /usr/share/neo4j/certificates
  run:          /usr/share/neo4j/run
Neo4j is already running (pid 2703).

waxen totem
neat pelican
autumn pilot
#

If you are starting the neo4j service on the target machine and you use the workstation (yours or academy's) to visit the above port it won't work, unless you do port-forwarding

neat pelican
#

yeah for some reason, neo4j is started by default when spawning the target. Even sudo kill can't stop this thing

waxen totem
#

Is it maybe running the daemon as a service? sudo systemctl status neo4j

neat pelican
#

Tried that also but it says not found. Also neo4j.service

waxen totem
neat pelican
#

I can't finish this section also I wonder how others did it

waxen totem
#

Run bloodhound locally in a docker like everyone else

neat pelican
#

Maybe if I'll run bloodhound on my own machine then just transfer the files from the target to mine

neat pelican
#

So bloodhound's ouput is just based on the imported files (results) right?

waxen totem
#

If you can gather bloodhound data technically you can also ldap dump as an alternative

#

but then no graph pepehands

neat pelican
#

Wdym with no graph?

fathom pendant
#

@hasty trellis please don't spoil skill assessment info :)

brave field
hazy comet
#

Good morning, I'm looking for help with the Advanced CSRF & XSS module - XSS bypass flag. Managed to bypass the filter with object tag with encoded payload. Can't seem to get a call back with the exfil payload. If someone could share the solution please

marsh isle
#

how did you make it worked? I got the same issue

waxen totem
hazy comet
supple dragon
hazy comet
waxen totem
#

Please don't share content on skill assessments, deleted

worldly vortex
#

ok well without going into specifics I have given the IIS user write access to the DB file as described in the module but for some reason am still getting an error that it can't write to the DB, I've also double checked that my web.config file has the correct path specified for the DB

#

Anyone available to DM about the skill assessment for the Advanced deserialization attacks module?

#

I just gave the IIS user write access on the entire app folder and it worked

warped hawk
#

Hello! Could anyone give me any hint on Q3 of the ntlm relay attacks's skills assement? I am kinda hardstuck

fading olive
#

Hello, I am working on Windows Privilege Escalation > Skills Assessment Part II and I have found the password for the iamtheadministrator user which was the first question. I am now supposed to answer question 2: Escalate privileges to SYSTEM and submit the contents of the flag.txt file on the Administrator Desktop However I can't seem to be able to authenticate anywhere as the iamtheadministrator user. I tried with rdp, with evil-winrm, with the runas command on windows command line but everything fails. What should I do? Are you not supposed to authenticate as that user?

deep bay
fading olive
deep bay
#

msfvenom -f .msi ?

fading olive
deep bay
#

just try a simple reverse shell payload.

fading olive
west arrow
#

Hello im a newcommer to cybersecurity and im starting with the "Information security foundations" course from the academy. The thing is it starts with setting up linux, some bash scripting, setting up windows and a VPS server before covering the "introduction to linux" and "introduction to bash scripting". Im not sure if im meant to do as they say and copy everything they do even though i don't understand the bash scripting and other things or if it is that im missing some foundations.

fathom pendant
#

you don't have to do all of that

#

it's more of a rough guide than full step-by-step instructions

west arrow
fading olive
fathom pendant
fading olive
fathom pendant
#

maybe take a step back and evaluate your surroundings then. or just take a break and come back fresh minded

loud tapir
#

@fathom pendant any idea on the issue I got?

fathom pendant
signal hound
#

Hi just to make sure i understood correctly
In RDP over socks section in the pivoting module
I have 4 machines

  1. My host
  2. The first pivot host (10.129.x.x)
  3. A second pivot host (172.16.5.19)
  4. The target which is 172.16.6.155
    ?
elder matrix
#

is it me or is nmap faster when using --open? if so, is there any downside of using that parameter?

lusty thicket
#

i guess, context loss

#

also if you're testing firewall rules, network segmentation or maybe just being through, --open is basically self sabotage

signal hound
elder matrix
#

i dont understand both of your answers 🤣

elder matrix
elder matrix
fathom pendant
#

aka it's nothing but you're coping that it is faster

elder matrix
#

should i use --open or am i better off without it

fathom pendant
#

you don't generally need it

elder matrix
#

ill just continue not using it...

#

thanks

shut wraith
elder matrix
#

im doing a report of my blind AEN run using the sysreptor template for CPTS.. i have this really tedious section here.

#

do i have to write down every machine and every open port here?

fathom pendant
# elder matrix

you should, it's just a markdown table so it's not that fancy to add rows/columns a lot can just be copy/paste new rows

fathom pendant
#

it's meant to be professional :)

#

and professionals wouldn't skip details

elder matrix
#

im taking that reporting seriously. failing the exam because i can't get the flags is okay, but failing because of the report would kill me

dry falcon
#

task 1

elder matrix
#

everything looks good otherwise.. pretty weird

#

why is the date 2024?

fathom pendant
#

living in the past type shit

dry falcon
solid epoch
#

dont underestimate the cpts exam
Theres a reason why you get 10 days

dry falcon
rustic sage
#

What do you mean? You're a bit unclear but it all depends is what Penetration Tester pathway teaches

fathom pendant
#

Thats illegal

#

"For educational purposes" isn't the bandaid you think it is

#

We see through the bullshit of it

solid epoch
#

yes it was also very clear to me that "its not for educational purposes only"

#

a person who has good intentions would never say that in this sentence

fathom pendant
fathom pendant
solid epoch
#

yea you can actually test how much timeout you need by enumerating manually, but just to be safe 10 s is enough

vagrant gust
#

Got a quick question i was doing the fingerprinting module on information gathering web edition

#

for the cms wappalyzer wasnt showing anything

#

is my wappalyzer broken or did i have to use another tool

deep bay
vagrant gust
deep bay
#

I think its wappalyzer issue. From the top left hand side, you could see that the icon of app.inlanefreight.local is refer to a CMS application called Joomla. @vagrant gust

shut wraith
#
(PWSH Rev Shell Used)"
2. convert to shellcode
3. XOR Shellcode
4. Xor Loader
5.Convert Loader to Shellcode
5. Compile stager
6. Start HTTPS Server
7. Start Listener
8. Deliver stager```
Target successfully retreived my staged payload but i did not receive a call back.

Can anyone help?

Is there a problem with embedding multiple shellcodes each other?
vagrant gust
#

didnt recognise the logo guess thatll come with more experience

#

thanks

lusty thicket
#

if the execution flow isn't properly managed your second stage shellcode might never even execute

shut wraith
main ridge
#

Hi. I'm doing Passwords Attack's hard lab

I got ||Johanna's password to connect via RDP||, but I'm having trouble keeping the RDP session stablished. It only stays for a few minutes then it finishes with the error

[10:23:26:407] [775255:775256] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[10:23:26:407] [775255:775256] [INFO][com.freerdp.client.common] - Network disconnect!

I have already tried with three different VPN servers. Is this part of the assignment or just a problem with the lab?

shut wraith
lusty thicket
#

my c# is non existent 😭🙏

shut wraith
#

I think there is some conceptual confusion about this

lusty thicket
#

i think you're nesting execution layers for no reason

#

donut already generates pic that loads and executes a payload in memory

#

there's no need for another loader unless you're modifying execution flow

shut wraith
#

But the rev shell is not yet XOR before using DONUT ...

lusty thicket
#

if you really need an xor stage, you should modify the ps script directly not the donut shellcode

barren valve
#

Does anyone have any resources I can use to better understand and be able to spot attacks any really injections stuff like that I’m working on the SOC analyst path I can’t post this anywhere else it might not be the right spot to post this

shut wraith
silk swan
#

Hello all I’m a new comer
Quick question what’s more relevant silver annual sub or student monthly
What’s the main differences ?

safe stream
#

if u are new to the academy then defentlly get the student one

silk swan
#

Need a student status proof ?

lusty thicket
#

<@&861185840277487616>

burnt hill
#

Hi, doing the OpenVAS skills assestment "https://academy.hackthebox.com/module/108/section/1516" I got stuck with this questions "What type of FTP vulnerability is on the Linux host? (Case Sensitive, four words)". I really think I have the right answer, but the form says Incorrect. Any help is very welcome

deep bay
burnt hill
#

yes

stiff aurora
#

Hello guys I'm stuck in this part " SOCKS5 Tunneling with Chisel " I'm getting error for when I trying to run "Running the Chisel Server on the Pivot Host"

burnt hill
stiff aurora
#

ubuntu@WEB01:~/chisel$ ./chisel server -v -p 1234 --socks5
./chisel: error while loading shared libraries: libgo.so.23: cannot open shared object file: No such file or directory

signal hound
#

Hi im doing skills assesment in pivoting
Im stuck on question #3
"Enumerate the internal network and discover another active host"
I tried performing ping sweep on the subnet
But received an error "name or service unkown"
I try to ssh into the the server using webadmin/administrator and the other user i found on the system with password i found but i cant log in
Edit: solved

fresh wedge
#

can anyone help with Windows Priv Esc skill assessment part 1?

#

i have initial foothold but cant finda anying on thie ldapadmin creds

safe star
fresh wedge
#

no i thought i needed to find the creds to escalate

#

thats the second question

safe star
#

You to escalate first

fresh wedge
#

its deff not juicypotato

cloud urchin
stiff aurora
deep bay
solid epoch
#

in file transfer module, creating smb server with and without password is demonstrated. i researched a bit and smb server without password is not supported on some windows pc's
Is that true ? if so, i only need to note the "with password" command right?

balmy kraken
#

☕️

fathom pendant
solid epoch
#

thank you both!

quasi wave
#

hi I'm trying to solve the first question of the 4th section of Pivoting, Tunneling, and Port Forwarding. However, the protocol I'm supposed to log into pivot from with is not connecting successfully.

#

my VPN is saying network is unreachable

fathom pendant
quasi wave
#

the issue had to do with the VPN I was using on the host OS

fathom pendant
#

👍

#

yeah host vpns can sometimes mess with traffic flow

safe star
#

-c

stiff aurora
quasi wave
#

ok I completed question one several minutes ago. now I'm having trouble with the second question. the next step is to run a command on the target host after pivoting from the other host. but it doesn't give me the IP of the actual target host only the pivot. I tried sshing into the same target host as last time and the connection was refused.

#

can you help me out with this?

sly ivy
#

Hi who is the admin of this group

quasi wave
#

the section is the reverse port forwarding section

#

wait solved

#

never mind I got it. it was very simple. It just had to marinate a little bit. I'm onto the next section.

fresh wedge
#

Csn anyone help with windows priv esc skill assesment part 1.

#

can not get the priv to work

#

tried a few things now

safe star
fathom pendant
#

if you need site support then

compact patrolBOT
fathom pendant
#

that's illegal, so no

sly ivy
#

Ok

#

Thankyou

vapid prawn
#

Does anyone know the answer format for the first question in the final section of the module "Attacking Web Applications With ffuf"?

vapid prawn
fathom pendant
fathom pendant
vapid prawn
#

I'm just curious

vapid prawn
#

Thanks

fathom pendant
#

no commas

vapid prawn
#

That's it!

solid epoch
#

is it normal that FreeRDP inside client lags a bit ? or is it cus of my vmware

inner shell
#

hi. new here. what do I do when nmap shows tcpwrapper under service for a given port? should I make an assumption based on the port?

inner shell
vapid prawn
fathom pendant
#

second verse same as the first my guy

#

.ext .ext .ext

vapid prawn
#

Nevermind, got it

#

Thanks

fathom pendant
#

@green shuttle don't paste content from modules above tier 0

rustic sage
#

hey guys, i was wondering if using the VPN i can also access the pwnbox

#

or do i have to then attack from my own VM on my machine

autumn pilot
#

It is best to use one or the other, e.g., if you want you can use the workstation (pwnbox) which is already connected to the VPN. If you decide to use a local VM, then you must download the VPN file and connect.

rustic sage
#

i love the pwnbox but the web interface is a bit slow

#

if i could ssh into it or something it would be great

#

but i guess no option like that

#

thank you

fathom pendant
#

There's a public facing ip

quick cedar
#

Hiii

severe inlet
#

in Active Directory Enumeration & Attacks
Section ACL Enumeration

The question

What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word)

I was able to find the user forend in bloodhound and found 2 edges between the user and the GPO group

however none of those edges gave me the answer am i doing something wrong?

quick cedar
#

It looks like you're on the right track by using BloodHound to analyze the relationships between the user "forend" and the GPO Management group. However, if you're not seeing the correct ObjectAceType, here are a few things you might want to check.

severe inlet
fathom pendant
#

you really didn't state your issue or what you needed help with

quick cedar
fathom pendant
quick cedar
#

how to access general

fathom pendant
#

see previous statement

severe inlet
#

I dont know where the best chat to send this question to
but after finishing the whole CPTS path
will i be able to finish Dante and Zephyr Prolabs?
like will i have the skills to do them?

fathom pendant
#

there will be things in them that go beyond what the path teaches

cloud urchin
cloud urchin
old wren
#

in Windows PrivEsc > Windows group privileges > DnsAdmins.

I successfully manage to add my account (netadm) into the Domain Admins group. When I run net group "Domain Admins" /dom, I can see myself there, alongside the Administrator. But I cannot get to the Administrator's Desktop. Shouldn't I be able to, as a Domain Admin?

severe inlet
#

Thank you everyone

frigid plaza
#

Thanks for yout guidance, but i've tried with all headers and dont can'r execute code, also i tried with expect header but don't works 😦

cloud urchin
tranquil axle
old wren
vagrant gust
#

is the wayback machine always buggy

#

doing my head in trying to do its module on information gathering

rustic sage
deep bay
#

@fathom pendant it's off topic, I think

fathom pendant
#

@broken furnace 1) what you're asking for and how you're phrasing is illegal; 2) you were already informed of this earlier

fathom pendant
#

read #rules bud; we don't cater to illegal requests

broken furnace
#

My bad

fathom pendant
#

"for educational purposes" is a bullshit argument, you and i both know that. If you want access to the rest of the server you'll need to read #welcome as your question also wasn't on topic of the channel

severe inlet
fathom pendant
fathom pendant
severe inlet
waxen totem
#

In my experience RDPing into target machines is a nightmare though. Wanna just be able to remote into the cli

#

Just yesterday had issues with a windows target being so slow I couldnt even start powershell 💀

severe inlet
#

You had the TCP vpn aswell?

waxen totem
#

Yep

fathom pendant
#

reminder: vpn region also dictates the target spawn so maybe shifting around regions can improve performance (even if it's just cope)

gusty ivy
#

Hello how can I get my account idetifier

waxen totem
waxen totem
fathom pendant
#

the vpn regions only show relative availability/traffic