#modules

1 messages ยท Page 399 of 1

fathom pendant
#

Can't wait for fucking Monday and fiber is back online

waxen totem
fathom pendant
#

Curious about your "non-standard" way you got the answer btw

#

Missed that part

#

Also sometimes: resetting the lab gets it to work properly

spare river
#

sry

fathom pendant
#

@spare river deleting the references due to it spoiling the answer, basically

#

If you reset the lab and can recreate the issue: #1234357888114364508 is the place to post with module name, section, and issue

spare river
#

no problemos

fathom pendant
#

Otherwise consider it a one-off error.

spare river
#

just wanted to help other people who might be stuck lol

#

even though they probably are doing it right

fathom pendant
#

These things happen, labs don't spawn properly/startup scripts don't run

spare river
#

understandable

#

have a nice day

fathom pendant
#

Suggestion for future troubleshooting:

  • reset lab
  • change vpn regions [respawn of lab will be required]
spare river
#

I assume the problem is not resolved

solar junco
#

hello i started hbt yesterday and iam about to finish the network foundations but iam running into a problem when i try to use the nmap command , iam using a vitrualbox and connected to htb vpn but when i run the command it is just stuck here i restarted multiple times and tried to connect to different servers on the vpn but i still have the same issue

solar junco
#

ive been trying for like an hour

waxen totem
solar junco
#

it says scan about 99.99% done and that 0 time remaining

waxen totem
#

you can use the flags -T and --min-rate to increase the speed, there's also --stats-every flag to get updated every <insert time here>

waxen totem
solar junco
#

ys

#

yes

waxen totem
#

I'd re-run the nmap command with the flags I've mentioned

solar junco
#

ok i will try it thank you

cloud urchin
#

you can also add -vv to show status along the way instead of waiting for it to finish

solar junco
#

it worked thank u but now i have the netcat thing it shows nc command not found

cloud urchin
#

perform some basic troubleshooting, make sure it's installed.

fathom pendant
#

sudo apt install netcat ?

broken furnace
#

Hey guys I need any hent at alert machine in htb , just give me a hint to get to the root or flag like : focus in the page source , use gobuster to find a directories and like that , thank you

#

I did used gobuster and viewed the page source and these basics but I didnโ€™t get to something valuable

fathom pendant
devout hazel
#

guys

#

can help me?

cloud urchin
#

with what?

devout hazel
#

my telegram is a hack

cloud urchin
#

No one here can help you, you'd have to reach out to Telegram.

devout hazel
#

okay tq

shut slate
#

Hey, Iโ€™m new here, is anyone looking for a team?

#

I just joined

waxen totem
fervent lantern
#

I've read it like 70 times and I still don't understand "Get a session cookie via a valid login and then use the cookie with cURL to search for the flag via a JSON POST request to '/search.php'"

#

I did everything they showed in the module but nothing at all.

swift dove
#

Hi Guys so I'm doing the Getting Started module and in the Service Scanning section the only reason I know the user is because they give it to me but is there a way of getting that user and password? am I going to see that later one?monkaEyes

fervent lantern
swift dove
waxen totem
swift dove
waxen totem
deep bay
# fervent lantern web request

when you open up a Web Developer Tools from your browser, nevigate to "network" tab & you could edit the cookie on the right hand side

fervent lantern
#

It tells me to validate the cookie but I already did it dx

#

I must have done something wrong

deep bay
#

might be the session cookie expired

fervent lantern
#

I did it because he wouldn't let me have this other cookie that I gave

fathom pendant
#

@fervent lantern @deep bay please don't post direct solutions and spoilers. if you're willing take this to dms

#

also you don't need to meddle with the cookie at all

fervent lantern
#

my bad

fathom pendant
#

read what the question wants carefully; it wants you to do a search for flag using a valid session cookie (which you'd get via logging in with the user:pass); not mess with the cookie

#

the reason for using curl is that the section is set up to only respond properly to the curl User-Agent

waxen totem
#

Do it from the pivot host via ssh

cloud urchin
#

@dry falcon please make sure not to post content from the modules.

waxen totem
#

hoddon, I forgot which module and section is this?

waxen totem
#

Ohh I thought it was something else, nvm haven't done that module

cloud urchin
#

@dry falcon it came up instantly for me, make sure to read the note section under the ping commands. if that's not it, try another server or region.

dry falcon
#

wow i reset machine and it work ban

fervent lantern
#

First, try renaming any city to "flag." Then, delete it. Once that's done, search for a city named "flag" to get the flag. WTF? I did that and it didn't give me the answer. lol

waxen totem
fervent lantern
#

XD

#

But that's what I asked for

#

lol

fervent lantern
fathom pendant
#

try deleting other cities

storm elk
#

Developer would say; itโ€™s not a bug, itโ€™s a feature

fervent lantern
#

Why do I get: bash: jq: command not found?

storm elk
#

jq might not be installed

fervent lantern
#

apt install jq?

#

sudo apt install jq

#

xd

#

Finally I solve a question myself ๐Ÿฅฒ

waxen totem
fervent lantern
#

because I get this error Unknown column '' in 'field list'

sterile solstice
#

has anyone done the C2 Sliver module?

safe star
sterile solstice
# safe star yeah

https://academy.hackthebox.com/module/241/section/2637

Question: "Assess further the web applicaiton and submit the name of the database user"

Was this meant to be using any particular command within sliver? I answered the other questions but after trawling through a few folders related to the app I couldnt find a db user. Wondering if I'm missing something simple.

safe star
sterile solstice
#

I already got the implant uploaded, and working. and able to use sliver commands. just wondering where this question is coming from. it does seem kinda random

safe star
#

just straight web ๐Ÿ˜‚

sterile solstice
#

cool. that was part ofmy original question. whether it was just snooping around or if it was sliver command related.

fervent lantern
#

Complete the web application form now which form do you recommend I take?

fervent lantern
#

Because it won't let me connect to Firefox, I get this Check that Firefox has permission to access the web (you might be connected but behind a firewall)

urban stratus
#

Hi , for some reason I can't send message in public chat , can i ask here ?

fickle thicket
#

Anyone done blind sql injection module, out of band dns section? Does interactsh or burp collaborator works because lab uses an internal ip.

cloud urchin
urban stratus
#

Bruh im turning my pc off

#

It just questions about certs

waxen totem
#

Which cert? Theres channels for each of them, am pretty sure you have access to message there

urban stratus
#

It's about great ine offer or taking cpts

cloud urchin
#

cpts no question about it

urban stratus
#

Any 3 certs + 1 yr premium subscription from ine or cpts

#

That shi is sooo hard

#

Ine offer cost 350 btw

cloud urchin
#

You can ask in #cpts if anyone has taken both and has takes, but you can see from Googling ine isn't really held in high regard. HTB has the best content I've seen for learning.

fervent lantern
#

help me please

waxen totem
fervent lantern
waxen totem
fervent lantern
#

I get this look

#

Hmm. Weโ€™re having trouble finding that site.

We canโ€™t connect to the server at start.parrotsec.org.

If you entered the right address, you can:

Try again later
Check your network connection
Check that Firefox has permission to access the web (you might be connected but behind a firewall)
#

I don't know what to squeeze

waxen totem
#

What module and section is this from?

fervent lantern
#

I asked for help because I don't know what to press on my virtual machine.

#

That's why I ask here on this channel

waxen totem
#

Is this a part of an academy module?

fervent lantern
#

no why

waxen totem
#

then this is the wrong channel to ask

urban ore
#

Hi, I have no idea where to ask but where do I start hacking? Ive been wanting to learn for a while now but Iโ€™m not sure where to start.

compact patrolBOT
urban ore
analog dock
vital moat
#

Hello @cloud urchin i need some help on this, please. I that the j**** user belongs to the right group to approve the cert but i am missing another permisison that is required

cloud urchin
#

always best to say the module and section you're on

vital moat
cloud urchin
#

Make sure to check all the permissions all of the users you have credentials for

acoustic owl
#

Why shouldn't you be able to use your PC?
But you're probably better off in the #homelab-sysadm channel, as it has nothing to do with the Academy modules.

silk swan
#

oups sorry

acoustic owl
#

But you probably have a better chance of getting a good answer there than you do here.

silk swan
prisma plaza
#

Can I ask here for a solution for the skill assessment machines found in the end of the modules?

waxen totem
#

exact solution? no, hints yes, try your best not to spoil the content especially the answers, it's usually better to take it to DMs

silk swan
fathom pendant
#

it's meant to run as a docker container

lavish ember
#

I need help in KERBEROS ATTACKS - Unconstrained Delegation - Users
I'm supposed to use krbrelayx.py but it give me errors the module told me to remove the impacket version I have and install a new one from the soure now I have this problem

Traceback (most recent call last):
 File "/home/anan/HackTheBox/Academy/Kerberos/krbrelayx/krbrelayx.py", line 45, in <module>
   from impacket.examples import logger
ModuleNotFoundError: No module named 'impacket'```
fathom pendant
#

try not calling it with python?

silk flicker
#

Hi! I'm stuck at upload files attack skill assessment

lavish ember
silk flicker
#

I've done all the steps and uploaded the file

lavish ember
#

like ./krbrelayx?

silk flicker
#

Now I want to know the url to see the uploaded file

fathom pendant
#

i genuinely wouldn't recommend uninstalling unless you were running into dependency errors

fathom pendant
#

figure out how to leak that info

lavish ember
silk flicker
#

yes I leaked it and I know the directory /user_...

lavish ember
#

what I'm I supposed to do

fathom pendant
#

i mean you can also install sudo pip3 install impacket the no module found error means that it's not in your python installation

#

check the function in the upload.php

#

run it locally with php -r

#

find out what the function is doing to your filename

lavish ember
#

I still get the error ```โ””โ”€$ sudo python krbrelayx.py -p 'C@lluMDIXON'
[] Protocol Client SMB loaded..
[
] Protocol Client HTTPS loaded..
[] Protocol Client HTTP loaded..
[
] Protocol Client LDAPS loaded..
[] Protocol Client LDAP loaded..
[
] Running in export mode (all tickets will be saved to disk). Works with unconstrained delegation attack only.
[] Running in unconstrained delegation abuse mode using the specified credentials.
[
] Setting up SMB Server
[] Setting up HTTP Server on port 80
[
] Setting up DNS Server

[*] Servers started, waiting for connections
[-] Could not start DNS server. Address is already in use. To fix this error, specify the interface IP to listen on with --interface-ip
Exception in thread Thread-3:
Traceback (most recent call last):
File "/usr/lib/python3.12/threading.py", line 1075, in _bootstrap_inner
self.run()
File "/home/anan/HackTheBox/Academy/Kerberos/krbrelayx/lib/servers/dnsrelayserver.py", line 107, in run
self.server = self.DNSServer((self.config.interfaceIp, 53), self.DnsReqHandler, self.config)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/anan/HackTheBox/Academy/Kerberos/krbrelayx/lib/servers/dnsrelayserver.py", line 34, in init
raise e
File "/home/anan/HackTheBox/Academy/Kerberos/krbrelayx/lib/servers/dnsrelayserver.py", line 28, in init
TCPServer.init(self, server_address, request_handler_class)
File "/usr/lib/python3.12/socketserver.py", line 457, in init
self.server_bind()
File "/usr/lib/python3.12/socketserver.py", line 473, in server_bind
self.socket.bind(self.server_address)
OSError: [Errno 98] Address already in use```

acoustic owl
lavish ember
#

well I noticed that lol

#

Oh it worked!

#

that's mb lol

elder matrix
#

can i use cewl on multiple sites in one command or do i have to do one site per command?

silk swan
manic bison
#

Hello, can someone have ideas to fix the RECCURENT black screen issues when using RDP ?

#

i tried specifying dynamic resolution, gfx, changing vpn, restarting the machine, using remina

#

nothing works all the time

#

it's either i'm lucky or i won't be able to fire that machine for the whole day

#

it's not even working from the attack box sometimes

#

The Shell & Payloads assessment is undoable rn, it keeps crashing when you scan ports, go on webpages or other small interactions

#

i was on the attack box

fathom pendant
fathom pendant
#

you're practically told where to go for the assessment

fathom pendant
#

make sure you're not running the pwnbox and your own vm at the same time

manic bison
#

even if i could try it by hand since it's a common one

manic bison
fathom pendant
#

shells and payloads gives you a jump host to start from; then 3 targets, i don't recall needing to do any special scanning as the info was given in the brief unless i'm forgetting something

flint palm
#

Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer. Windows privilege escalation

#

can someone help me with this?

fathom pendant
#

did you try restoring the directory? i believe some useful stuff is on the desktop of that machine

fathom pendant
#

well host 3 maybe

#

but that's about it

silk swan
fathom pendant
#

docker compose is a docker plugin that allows you to use yml files and such to orchestrate setting stuff up; it literally gives you the docker commands to stop/start and such

flint palm
#

I restored the directory but I have to find administrators hash somehow

fathom pendant
#

well look at what you restored and how it may be useful;

#

gotta exercise some level of thinking to figure it out

flint palm
#

The best advice of my life)

fathom pendant
#

i believe there's multiple backups you can restore

lapis sky
#

im working on shells & payloads - the live engagement, when i connected to the rdp, and gathered a few information, i didn't find a browser in the rdp, which kinda confused me i need help

paper lodge
#

Hi guys, did anyone solve this question from the windows priv esc module 'Using the techniques shown in this section, find the cleartext password for the bob_adm user on the target system'

manic bison
#

Hey, i'm on the Sessions part from the metasploit framework module, the machine has port 80 opened, but i can't manage to browse it or even curl it

acoustic owl
manic bison
#

do someone have an explaination ?

#

(i can nmap -p80 and it's open)

paper lodge
acoustic owl
paper lodge
#

Is that the right way to do it, or i am doing it wrong

#

Found some passwords too, and none of them are for bob_adm

acoustic owl
spare fossil
#

Intro to C2 Operations with Sliver / initial access - Assess further the web application and submit the name of the database user ... i dont get it, tried all users found on there, any hint ?

acoustic owl
gray yacht
vital moat
severe lagoon
#

Hi, did anyone do Hacking WordPress from hackthebox academy, I need some help related to the skill assessment

quiet trout
severe lagoon
#

Skill assessment....

quiet trout
#

a link so i dont have to go search for it?

severe lagoon
#

ok

quiet trout
#

thats usually how we format questiosn here

severe lagoon
quiet trout
quiet trout
severe lagoon
#

Sorry I couldn't understand this one....

#

Please help me out for the skill assessment, I am having trouble with the enumeration

#

The above is the section

quiet trout
#

ok so assuming you've done no enum on the target at this point what have you tried? have you ran a wpscan?

severe lagoon
#

its saying that its not a wpwebsite by wpscan....

quiet trout
#

did you get your hosts and all that good stuff set up?

#

your /etc/hosts set with the target IP and hostname

severe lagoon
#

I did the inlanefreight.htb and logistic.htb setup... in the hosts

quiet trout
#

have you done vhost boxes yet?

#

do you know how vhosts work and all that good stuff?

#

launching the lab so i can see how you got to where you did some stuff doesnt /seem/ right, at glance tho

#

ok so you're at http://inlanefreight.local right? does this look like a wp blog? if it just looks like a regular page that would explain why you're getting the results from wpscan, browse around on the site, what link might reveal/redirect to the wp blog?

flint palm
#

Guys if someone has done Windows Privilege Escalation all that backup stuff pls contact me need your help

quiet trout
#

@severe lagoon ^

severe lagoon
#

Yeah trying

quiet trout
#

cool cool just checking. dont over think it. this requires some manual enumeration of the page to find the wp blog then adding the url you discover it located at to hosts

#

aka "clicking around"

paper lodge
flint palm
#

Hello Guys ones again if there is someone who has done Windows Privilege please help me with the last question how did you find administrators hash

paper lodge
lapis sky
dark hedge
#

try bloodhound-python -u user@domain_b.com -ns <dc01.domain_a.com/ip> -d domain_a.com -c all

stark rock
#

can someone explain the time element to modules please, do you need to complete the module within the time stated (4 hours for example) im only asking so i can better prepare for taking a module. Thanks in advance

solar junco
#

can someone help when iam running this command from NETWORK FOUNDATION (nc -v <target ip> <dynamic port>) it is saying connection refused but in the example on the website it says open

#

i tried to change target ip couple of times and rerun everything and it still says refused

quiet trout
deep raptor
#

I need help

#

Can someone tell me how to filter a specific persons name on wireshark

quiet trout
#

the ascii output or whatever its called?

quiet trout
#

frame contains "username" i think will work

#

thats a very broad search tho, you'd want to shrink it to something more specific to your use case like http contains 'username'

pliant sluice
#

I'm in the Info Sec Foundations path on the the VPS setup module. I setup the VPS on Vultr. I'm trying to ssh to it. I'm unable to. When I ping I get network is unreachable. I've changed the network settings to have a bridged adapter on my VM. That did not fix it. Should the VPS (100.68.x.x) be on the same network as my VM (192.168.x.x) on Virtual Box? they are on different networks right now. If so how do I do that? Or is the solution something completely different?

deep raptor
elder matrix
#

im trying enumerate imap. When i try to log in, i get this: Plaintext authentication disallowed on non-secure (SSL/TLS).
if i were to brute force with hydra, would this works?

hydra imaps://ipaddr:993 -l usernameifound -P passlist.txt

do i need more information in order for hydra to do its magic?

quiet trout
#

does anyone know a AI proompt that doesnt do this?

elder matrix
#

its just that some place mentions using some kind of ipv6

#

lemme fetch what i mean

#

hydra -C defaults.txt -6 pop3s://[fe80::2c:31ff:fe12:ac11]:143/TLS:DIGEST-MD5

#

where do i get that? LOL is my command enough or do i have to add that fluff in there?

#

i know thats for pops

#

its still ssl/tls like imaps

cloud urchin
severe lagoon
#

wpscan --url http://Blogurl -U users.txt -P /usr/share/wordlists/rockyou.txt
Am I on the right track??? I need to put a reverse shell for this I am first doing a bruteforce???

#

I have found the users and the password

#

This is for the Hacking Wordpress skill assessment

elder matrix
cloud urchin
#

well AEN is just a walkthrough.. you could just look there

elder matrix
#

imaps and pops

cloud urchin
#

you could man hydra

elder matrix
deep raptor
#

Sorry, Iโ€™m working in Linux basic room. I type the command to find the number of lines dpkg -l | wc -l โ€ฆโ€ฆI get the count but it says Iโ€™m wrong

quiet trout
quiet trout
#

use chatgpt and copy it real quick you'll see the subtle diff. this could be wrong of course, but good as a sanity check if you're not getting the results you'd expect

severe lagoon
quiet trout
#

good deal. glad you got it sorted

elder matrix
#

i found out that using somethign like pop3://ip:110 -m TLS and imap://ip:143 -m TLS works. i did "man hydra" like supernuts told me LOL

deep raptor
#

How do I find the number of packages on the target system? I put all the commands I know .

quiet trout
#

the number of installed packages according to the package manager?

#

it would be something like apt-cache search --installed

#

ok thats slightly wrong syntax dpkg list works

#

apt list --installed

frosty tree
#

Hello guys, I go through Intro to Assembly Language, Part "Debugging with GDB" where I need to download asm file and debug it. Task is "Download the attached file, and find the hex value in 'rax' when we reach the instruction at <_start+16>?" but when I make a breakpoint on "_start" and run the debugging there is no "<_start+16>" and when I do two steps, I get "0x401013 โ†’ add BYTE PTR [rax], al" and then "Program terminated with signal SIGSEGV, Segmentation fault.
The program no longer exists."

#

could you please help me with this? I dont know what Im doing wrong

lusty thicket
#

break at _start+16

frosty tree
#

but there is no start+16

#

0x401000 <_start+0000> movabs rax, 0x21796d6564616341
0x40100a <_start+000a> xor rax, 0x21449
0x401010 <_start+0010> xor rax, rax
0x401013 add BYTE PTR [rax], al
0x401015 add BYTE PTR [rax], al
0x401017 add BYTE PTR [rax], al

#

gefโžค b _start+16
Function "_start+16" not defined.

lusty thicket
lusty thicket
#

b *0x401010

frosty tree
#

You have typed the same address for _start and for _start+16 aswell

frosty tree
#

but next to that address there is "<_start+0010>" not the "start+16". I dont get it mate

lusty thicket
#

16 in decimal is the same as 0x10 in hex

frosty tree
#

I dont see anywhere in this module where is stated that I need to convert it. But you are right, RAX on this breakpoint is 0x21796d6564637708 and thats the right answer

#

or better said, why there is "<_start+16>" in the task, when in reality you see "<_start+0010>" in debugger?

lusty thicket
#

because everybody counts in decimals even if they're writing an assembly task

frosty tree
#

hmm I think I need to get use to it..anyway, thank you very much, because I stuck here for hours -_-

runic fern
#

hello

#

im on network enumeration with nmap and im on the ids ips evasion easy lab and i think i got the right os system but its sayig its wrong idk

#

Our client wants to know if we can identify which operating system their provided machine is running on. Submit the OS name as the answer.

#

this is the prompt

#

i put in linux as my result and its saying its wrong

#

idk what to put atp

cloud urchin
runic fern
#

soryr

#

are you able to help though?

#

nevermind

cloud urchin
#

Try reviewing the host discovery section

scarlet garnet
#

Hi everyone, I need a hint in CRLF http attacks log injection, It gives php injection into the logs

cloud urchin
scarlet garnet
#

Ohk thanks SuperNuts, I will try harder, and if I cant I will get back to you. thanks

#

wow you are great thank you SuperNuts

runic fern
#

im on a nmap module and im really struggling to get anything from nmap, ive tried ack, syn, quiet performance, and everything it feels any recommendations?

#

like EVERYTHING is showing up as filetered

quiet trout
#

the assesment? the firewall one?

runic fern
#

its nmap firewall evasion ids hard level

quiet trout
#

just a sec i just reviewed that whole module earlier today

runic fern
#

thank you

quiet trout
#

DM me what you've tried if you'd like

#

this one is a little difficult and the scenario is vague

severe inlet
unkempt palm
#

anyone here online

cloud urchin
#

a lot of people

unkempt palm
#

anyone here have complete Login Brute Forcing Skills Assessment Part 2

#

please help me.anyone who did this module

#

i am stuck at this much time

unkempt palm
#

i need youre help.๐Ÿซถ

cloud urchin
#

@Ulq please don't post content from modules above t0

severe inlet
#

Oh really sorry

sharp river
unkempt palm
severe inlet
#

Regarding the question tho

if i have a form

the form has the following attributes
id=ulqa and name=ulqw

if i want to brute force using hydra
what are the parameters is it for the id or name?
since in the module they were identical so i couldn't tell

severe inlet
cloud urchin
sharp river
#

Yeah, simple plugin for wordpress

unkempt palm
#

@severe inletbro dm me

cloud urchin
unkempt palm
#

@cloud urchin did you completed Login Brute Forcing module.

sharp river
#

Ok thx

cloud urchin
unkempt palm
#

ok bro

sharp river
cloud urchin
solid epoch
#

Why was attacking common services (medium) much easier than easy lol

#

in easy you needed to look some things up

bronze tapir
#

ip link
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: ens3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP mode DEFAULT group default qlen 1000
link/ether a6:ba:3b:08:59:d4 brd ff:ff:ff:ff:ff:ff
altname enp0s3
3: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN mode DEFAULT group default qlen 500
link/none What is the name of the network interface that MTU is set to 1500? Shouldn't this be either ens3 or tun0? Neither are working.

acoustic thorn
#

Genuinely can't understand a single thing in the thick clients section after obtaining a foothold ๐Ÿ˜ญ . I can't see how this section genuinely makes any sense in the broader scope of cpts

#

Does anyone have a better resource for digging into thick clients? It's something I'd like to understand albeit after cpts

feral latch
#

hello I just started and in the three lesson I turn on the virtual machine and try a scan with nmap and I get this Starting Nmap 7.94SVN ( https://nmap.org/ ) at 2025-03-15 21:07 UTC
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.10 seconds

acoustic thorn
#

Maybe try a different scan or ping. Could also just restart the machine if you suspect it's bugged

sharp river
cloud urchin
sharp river
flint palm
#

guys hello can anybody teach me how to restore sam database?

safe star
gray stratus
#

Has anyone completed the challenge? CPTS > Module: Attacking Web Applications with Ffuf. > Section: Parameter Fuzzing - GET

Question: Using what you learned in this section, run a parameter fuzzing scan on this page. what is the parameter accepted by this webpage?

I tried this command but it return a lot of keywords & errors which is not really helpful

ffuf -w /opt/useful/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ -u http://admin.academy.htb:47558/admin/admin.php?FUZZ=key -fs 900


I also Optimized Command (Extract Keywords Only) still dead end

If you want to extract only the parameter names that yield valid results:

ffuf -w /opt/useful/seclists/Discovery/Web-Content/burp-parameter-names.txt:FUZZ \ -u http://admin.academy.htb:47558/admin/admin.php?FUZZ=key \ -mc 200-299,301,302,307,401,403,405,500 \ -fs 900 -t 40 -v 2>/dev/null | grep -oP "(?<=\* FUZZ: ).*" | sort -u

I extracted the keywords into a txt file and used burpsuite, still no way.

solid epoch
bronze tapir
flint palm
#

Guys if there is someone very clever and has restored SAM database from Pillaging in Windows Privilege Escalation pls DM me

#

I have restored many folders but all of them are empty

#

pls share how you did it if you did

sharp river
waxen totem
#

Find one that can maybe help you find what you're looking for

sharp river
#

Thx

#

I achieved ๐Ÿ™‚

#

Hard for me

plush agate
#

Hello, following the "ADCS attacks" module, in the "ESC9" section, i wanted to perform a shadow credentials attack from a windows host instead of changing user2's password, any ideas on how to do that ?
so far i tried whisker.exe to get a TGT as user2, opened a new terminal using Rubeus's createnetonly, imported user2's TGT, Certify.exe request didn't work

severe inlet
vocal vortex
#

hi All, maybe is dumm but how to i remove bad character from a address for example 0x00EEFB70, and let's say 00 is a bad character how do i remove it from address ? this is related to skills assesment for windows based buffer overflowx86

fathom pendant
#

0x00EEFB70 wouldn't necessarily be a bad address

#

it's just padded in that case to meet the full length

#

but the module would teach you everything you need to know to complete the skill assessment

vocal vortex
#

i figure it out, thanks @fathom pendant

stiff aurora
#

hello I'm in the module "ICMP Tunneling with SOCKS", I'm using Chisel in this module because I got a lot issue with ptunnel-ng but I'm stuck creating the proxychains with RDP but i get connection error I can't figureout why is the issue

#

proxychains xfreerdp /v:172.16.5.19 /u:victor /p:pass@123
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] Strict chain ... 127.0.0.1:1080 ... timeout
[00:44:14:799] [22413:22415] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[00:44:14:799] [22413:22415] [ERROR][com.freerdp.core] - failed to connect to 172.16.5.19

stiff aurora
#

the same

fathom pendant
#

use ligolo-ng instead gigaChad

stiff aurora
stiff aurora
#

nothing

#

I'm so tired of this module in the PCTS

#

westing time a lot big frustration

storm elk
#

Have you tried switching to tcp vpn?

fathom pendant
#

are you sure you have it set up properly?

severe inlet
heady vault
#

Hello, I am new here. Needs help for Cracking Into HTB - GET module. I am stucked there. Any ideas to obtain the flag?

warped dagger
#

Hey guys, I'm on Skills Assessment - Web Fuzzing module, on this question:
"One of the pages you will identify should say 'You don't have access!'. What is the full page URL?"

I write the answer, but it's not accepting it. I even checked with online solutions.

#

I should write "academy.htb:PORT" instead of the real port, I think maybe this can bug?

brazen spoke
#

Is it only me, or does the question ask from THB is beyond the material they provided? Like, I just completed a section and can't understand how to solve the question, and when I googled, I saw people using different commands that HTB never mentioned, so I had to use those commands to get the solution without understanding what I was doing. Does every module have this problem?

acoustic owl
#

Sometimes there are several ways to achieve a goal

waxen totem
#

There's no world in which you learn every aspect of every service, protocol, and vulnerability, which is where research comes in, it's the most important thing that the modules are trying to teach.

brazen spoke
acoustic owl
brazen spoke
brazen spoke
#

I used some advance concepts of gret and netstat which weren't touched in the section

waxen totem
#

Yeah that module notorious for having some quite hard sections

acoustic owl
brazen spoke
acoustic owl
#

netstat is also mentioned in the module

brazen spoke
brazen spoke
#

Might have missed my eye then

acoustic owl
brazen spoke
acoustic owl
gray stratus
neat crest
#

Module/77/section/843, I have found the exploit for the plugin in .txt, renamed it to a .py file but I cant seem to use it I tried python exploit.py --target <ip-adres>

#

nvm, I used metasploit

tired atlas
#

1 of 1 target successfully completed, 1 valid password found

I'm on password attacks, easy lab, and I finished the hydra, took 2 hours lol, and it says 1 valid password found, but I can't really find it, it's not really indicating to me, what the valid pair is

shut ice
#

Can anyone give a hint on LPE for the first question on AD trust attacks skills assessment? Not sure if I should be looking outside the module as I thought all the attacks require compromising the DC first

onyx dust
acoustic owl
onyx dust
#

thanks. it connects when adding the port.

#

the javascript on the site does not implement it though big_think

acoustic owl
#

Look on the page in the module. All ports are specified there

onyx dust
#

thanks. i missed that!

analog basin
#

@acoustic owl

acoustic owl
keen walrus
#

hey could someone assist me with this? : Try to use what you learned in this section to fuzz the '/blog' directory and find all pages. One of them should contain a flag. What is the flag?
in the cbbh path , this is the command ive tried :

||i tried this but it didnt worked : ffuf -w clean_wordlist.txt:FUZZ -u http://83.136.254.23:34766/blog/indexFUZZ||

shut ice
#

@tranquil axle Can I DM you about Q1 on Trust Attacks? I think I have the right path but I'm getting access denied and can't figure out why

paper lodge
#

Hi Guys, i am stuck on Pillaging moudule of windows priv sec, last question "Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer" i was able to restore the C:\Windows\sytem32 using password on the jeff's desktop , but there is config folder in that, guys how did you solve it, give me some hints

#

@acoustic owl did you solve this question?

shut ice
#

What is the question @paper lodge

paper lodge
#

Restore the directory containing the files needed to obtain the password hashes for local users. Submit the Administrator hash as the answer

shut ice
#

Restore the folder? and you've restored it?

paper lodge
#

this is the question, its from Pillaging moudule of windows priv sec

fathom pendant
shut ice
#

Look at secretsdump

fathom pendant
#

@shut ice please don't give direct answers/spoilers

paper lodge
#

the config folder is missing

shut ice
#

My bad, research into where local account hashes are stored

fathom pendant
#

I believe there's multiple backups; so if one doesn't contain it try others

languid socket
#

guys why the sqlite db from cat is giving me a wierd error when i try to dump the database

can someone help what is the best arg to use with sqlmap?

pearl walrus
#

Anyone able to help with the section in the SQL injection section "Using Comments"?

The question is to login with the user with the id 5 to get the flag.

I'm trying with multiple variations of the following as the username: or where id=5);

paper lodge
#

do i need to get the admins password to do the backup?

fathom pendant
#

You have the info you need to restore and search the proper backup

paper lodge
#

I am getting access denied

fathom pendant
#

Did you set the restic password environment variable?

paper lodge
#

yes, the one i found on the jeffs desktop

#

its for restic

fathom pendant
#

After you restore it's mostly just exfiltrating the data to use

paper lodge
#

there is no config file in it

fathom pendant
#

Why are you looking specifically for config files?

paper lodge
#

in the config folder

#

there is no config folder

fathom pendant
#

If you've done the password attacks module: consider the ways that windows saves login information

#

Again; why are you looking for that

paper lodge
#

to dump the hashes using secretsdump

fathom pendant
#

And what files does secretsdump need, exercise some logical conclusions

fathom pendant
#

Who said they'd be in a config folder

#

pika_sip so make logical leaps and conclusions from that

#

I'm not holding your hand through every step, as

  1. it'd be a spoiler
  2. You're not paying me to
paper lodge
#

๐Ÿ™‚

flint palm
#

If we newbies were all that clever we wouldn't come here and asks questions)))

fathom pendant
#

You've been given enough information and know what to look for

#

You're just trying to find a solution in x when you can just look through y

paper lodge
#

okay thanks @fathom pendant

mossy marten
#

Hello, I am stuck at this assesment. I bruteforced the ssh and got a username (or more like real name) and passwords.txt. The task says : What is the username of the ftp user you find via brute-forcing? The problem is there are no open ftp ports and i brute forced every open port i could including an SQL-Database but nothing leads anywhere. What do i do?

fathom pendant
#

If I'm paid to im more than happy to provide more pointed guidance privately. It seems AJU knows the core concept but is banging their head against a brick wall when the door is 2 feet to the left

fathom pendant
#

Public_ip:port means you're limited in scope to what you're given

#

Other ports are off limits

keen walrus
#

hey could someone assist me with this? : Try to use what you learned in this section to fuzz the '/blog' directory and find all pages. One of them should contain a flag. What is the flag?
in the cbbh path , this is the command ive tried :|| i tried this but it didnt worked : ffuf -w clean_wordlist.txt:FUZZ -u http://83.136.254.23:34766/blog/indexFUZZ ||

fathom pendant
#

Take a close look at your url

#

And where you're inserting the fuzz keyword

keen walrus
#

noted

paper lodge
fathom pendant
#

If all else fails reset the lab

paper lodge
#

okay

fathom pendant
#

Ls, dir, tree, whatever you need to look for files that are juicy

#

Don't just look right at the surface

paper lodge
#

okay @fathom pendant

keen walrus
fathom pendant
#

Doesn't the section contain an example?

keen walrus
#

it is i even tried using the exact command

#

but no results

fathom pendant
#

/blog/FUZZ, not /blog:FUZZ

#

:)

keen walrus
#

ok thx brb trying to fuzz it

languid socket
keen walrus
#

did that command but no results

fathom pendant
#

Is that the list they wanted you to use? :p generally you can use the same list as referenced in the examples

keen walrus
#

yea it is

fathom pendant
#

Is that server actually up/what's given to you?

#

:)

keen walrus
#

yeah it is the machine has an ip running for at least more 80 min

languid socket
keen walrus
#

ok

fathom pendant
languid socket
fathom pendant
# keen walrus ok

Are you receiving any errors while it's running? It shouldn't be executing that quickly

fathom pendant
keen walrus
#

yeah i get :

#

name or service unknown

fathom pendant
#

For two, that's unnecessary

keen walrus
fathom pendant
inland grove
#

Anyone else having problems with https://academy.hackthebox.com/module/details/291 - Wi-Fi Evil Twin Attacks with the Using EAPHammer section question?

With the ESSID stripping assignement? I can't force client to authenticate to my SSID ๐Ÿค” Deauthentication gets picked up; the packet loss is growing when I'm checking with airodump-ng but can't seem to get the client to connect to me ๐Ÿค”

fathom pendant
#

You'd just ping the ip

#

Does the section give you a vhost?

keen walrus
#

yeah it gives

#

no vpn to connect to tho

surreal urchin
#

Hello worlds! I have problem in my HTB acadmey modules whenever i create a challenge it gave me "IP" AND Not Port. While accesing the challenge throw ip don't gave me response! please someone help me

fathom pendant
fathom pendant
keen walrus
#

ok

fathom pendant
keen walrus
#

i tried on the pwnbox tho

languid socket
#

i dont think that ffuf would be able to fuzz the vhost like what he did..

keen walrus
# fathom pendant Not all labs give ip and port; if it gives a 10.129.x.x ip you need to be connec...

||ffuf -w /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ -u http://94.237.56.224:30483/blog/FUZZ.php

    /'___\  /'___\           /'___\       
   /\ \__/ /\ \__/  __  __  /\ \__/       
   \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
    \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
     \ \_\   \ \_\  \ \____/  \ \_\       
      \/_/    \/_/   \/___/    \/_/       

   v2.1.0-dev

:: Method : GET
:: URL : http://94.237.56.224:30483/blog/FUZZ.php
:: Wordlist : FUZZ: /opt/useful/seclists/Discovery/Web-Content/directory-list-2.3-small.txt
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500


:: Progress: [87664/87664] :: Job [1/1] :: 6451 req/sec :: Duration: [0:00:14] :: Errors: 87664 ::
โ”Œโ”€[eu-academy-5]โ”€[10.10.15.10]โ”€[htb-ac-1577141@htb-gyp0pzvubw]โ”€[~]
โ””โ”€โ”€โ•ผ [โ˜…]$
||

fathom pendant
keen walrus
#

thats the ffuf output sorry for long msg

surreal urchin
#

Yep i have conted the openvpn throw my CMD terminal but still not accesing the challenge!! Also there is a problem for downloading openVpn appliction new update makeing problem to me

keen walrus
#

thought it was normal since no extensions were found

languid socket
fathom pendant
keen walrus
#

noted ๐Ÿ™‚

fathom pendant
keen walrus
#

damn bro

languid socket
lusty thicket
#

user error

keen walrus
#

he says the issue is me

fathom pendant
# keen walrus noted ๐Ÿ™‚

The question gives you a vhost, the lab is likely designed to not respond to http queries to the ip, but instead the vhost

languid socket
#

ohhh yeah haha

fathom pendant
#

You need to interact with the target using the given vhost

fathom pendant
#

I already told you how earlier, but you ignored that

languid socket
fathom pendant
#

I'm not staff, I just yap and I (kinda) know things

languid socket
fathom pendant
#

Keep this channel on topic to htb academy modules :)

languid socket
fathom pendant
#

I haven't done it, so no

languid socket
fathom pendant
#

But also there's a channel to ask for help with machines on the htb labs site, which is pointed you to

keen walrus
#

||ffuf -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt:FUZZ
-u http://94.237.59.30:57416/FUZZ \
-H "Host: 94.237.59.30:57416"
-mc 200,204,301,302,307,401,403||

#

i got it

shut ice
#

Has anyone done question 1 on AD Trust Attacks? I've got the path from Bloodhound but getting access denied trying to auth, gone back through the module twice and can't see what I'm doing wrong ๐Ÿ˜ข

fathom pendant
#

Thats an unconventional vhost you pointed to with the host header, typically a host is a.example.com or something like that

#
  • vhosts required
    ^ thats the text you're looking for for the vhost
#

Vhost != ip

keen walrus
#

gotchu gotchu

mossy marten
keen walrus
#

much appreciated the memes rlly gives motivation to ask q's here again

fathom pendant
#

This is 101 type shit you should know before you even touch fuzzing

keen walrus
#

ok men

#

thx for helping

fathom pendant
#

Writing things down helps you remember them

keen walrus
#

i do i write all down in remnotes

#

just the vhost thing

#

didnt wrote facepalm

lusty thicket
fathom pendant
keen walrus
#

yeah yeah

fathom pendant
#

Time for another 2 hour nap bc fucked sleep schedule

solar bloom
#

Getting Started Module> Priv Escalation hands on lab. In the learning module they talk about copying id_RSA, but in the answer we use netstat. They want us to look at the active connections but why would I know to use this over nmap? Nmap doesn't show port 80 evven open.

candid juniper
#

When going through modules and solving x or y through exploits, do y'all find it useful to try and run through the actions of said exploit manually?
For example, looking at the exploit's code and attempting the actions it does manually to potentially understand the design of an exploit better.

Or would this only really help you understand this specific exploit?

Possibly a very person-to-person answer but I'm just wondering, as I've been told most public exploits usually are detected easier, where I think understanding each step better could help understanding the exploitation process better.

lusty thicket
fathom pendant
shut ice
#

Depends, there are that many exploits IMO it wouldn't be possible to 'understand' how they all work

#

But understanding the common ones (which is probably what the modules shows) would be worth it

balmy nova
#

@solar bloom How ya doing.

lusty thicket
candid juniper
#

Thanks for the quick input

elder matrix
elder matrix
#

trying to find out all info i can get... stuck on foothold for almost a week (aen blindly)

acoustic owl
acoustic owl
elder matrix
#

cant do that during the exam

#

unless the foothold is easier on the exam ๐Ÿคฃ

acoustic owl
cloud sedge
#

Hello, please tell me! If I buy a monthly "gold" or "platinum" subscription, will I have access to modules such as "ADCS Attacks", "Active Directory LDAP"?

shut ice
#

Think you have to buy ADCS Attacks, depends on the tier of module

tranquil axle
tranquil axle
cloud sedge
#

I take it it's better to buy cubes?

shut ice
#

No better to buy membership you save about 30% on cubes, but you are limited to only unlock so many modules a month (until you get your next cubes), guess it depends how fast you plan on doing each module

#

Then if you get it yearly, you get all the tier 1-3 modules I think? (depending on silver/gold)

cloud sedge
#

I want to go through all the modules for the path 'CAPE'. But I don't have the opportunity to pay for everything at once, so I'm thinking about how to go through them with payment once a month.

proud pine
pearl walrus
quiet trout
proud pine
quiet trout
#

i dont follow the first part, best use of plat/gold? is that there new like uh... rewards hours or something for buying cubes?

#

last time i checked in there was just cubes and paypal or w/e to buy them with?

#

(back in like july of last year?)

proud pine
quiet trout
#

OH, no kidding?

#

Noted, thanks thats super important info.

proud pine
#

For the first tier courses, the monthly subs are generally the best option, because you will take longer than a month to finish all the modules that one month of sub unlocks. For higher tier certs, one month sub might only unlock a single module at a time.

spiral sapphire
#

Do you guys spar on app.hackthebox after finishing modules?

proud pine
#

For CPTS, for example, you need 1 month of platinum, and 1 month of gold.

quiet trout
#

i find myself getting frustrated on an easy/med box, i go back to the academy

#

yes easy boxes still whip me sometimes, rank is just rank.

#

im not too proud to admit.

spiral sapphire
#

I'd love to get the CPTS certificate one day. I've been grinding modules for a couple of months now and sparred for the first time today on app.hackthebox, but... even the easy machines are too difficult to finish without peeking at the walkthroughs. I feel like I "waste" the machines if I continue doing them. Should I finish the whole path on academy first?

quiet trout
#

thats the conclusion ive come to from the same trial and error.

#

i guess theres nothign wrong with it if you're "learning" but i just prefer to learn differently.

#

making an attempt to total frustration is not my ideal learning manner, at least not until i have "read the book" or "completed the path"

#

then i feel like i should be ready to exert the mental effort to total frustration and go back to drawing board (notes)

spiral sapphire
#

But wouldn't you also like to keep practicing what you've learned on a module? Then you do ten more modules and forget what you learned previously ๐Ÿ˜„

vapid prawn
#

Sup, guys. How are ya?

Using Web Proxies - third final question of the module, how is it expecting to be the input of the answer? Input format

spiral sapphire
#

I get what you mean tho, the boxes require wider knowledge than just one or two modules.

spiral sapphire
quiet trout
# spiral sapphire How far are you on your path anyways?

i did the bbh so it seems like the web portion of cpts is clear i just started in earnest a few weeks ago and have only been doing a few hours here and there. but im gonna need to re go thru bbh as it changed with the graphql stuff since i last went thru it

#

so to answer your question "im not sure" but im also gonna redo everything and make sure my notes are a thousand percent solid.

#

im currently on footprinting -> nfs

quiet trout
#

after moving on for a few. not like uh, finishign it then doing it again a day later while its still muscle memory

spiral sapphire
quiet trout
#

yeah i asked about that early on. i think there aware of the request for this.

vapid prawn
quiet trout
#

i dont believe we're the only ones who have suggested this.

spiral sapphire
#

So, do you plan to start sparring on boxes only after you've finished the whole cpts path?

quiet trout
#

ive done a few boxes and im familiar with the overall process so at the moment im just focusing on acad. i dont have vip tho so i cant do retired boxes and i dont wanna mess with the live boxes right now and like uh... aggravate myself out of being motivated to learn. to be totally honest. but thats just me.

#

who knows maybe that will change in a day or two

nimble scroll
#

hi

#

can anyone help me on skill assesments , File Upload Attacks , I am stuck by 5 days and did not find any solution :/

cloud urchin
#

You can DM me

quiet trout
#

same fuzzing your did in the module, just slow it down a bit and comb those errors carefully.

main ridge
#

I have just finished the skills assessment for the pivoting, tunneling and port forwarding module. But I have a question: It confused me a lot that both """subnets""" had the same mask /16 (172.16.5.35 and 172.16.6.35) so technically they were in the same network and all packets were sent over the .5 . Is this correct from a networking point of view? shouldn't these two subnets be in different network segments with /24 masks?

scarlet creek
#

heyoo

cloud urchin
#

Did you poison the log already?

nimble scroll
cloud urchin
#

@brave scroll It's fine to post from this module but I'm deleting your comment as it shows the flag's filename which you normally have to enumerate yourself in this skill assessment.

quiet trout
#

i believe i could NOT do the second method myself reviewing my notes and checking the assessment

#

@nimble scroll please DM me that so i can compare my outcome?

brave scroll
onyx cave
#

i am new to hack the box , i have 70 cubes and just finished academy . What should i buy with these and how can i get more cubes for free?

cloud urchin
#

cubes cost money

onyx cave
#

what is a good purchase to do with my 70 cubes?

cloud urchin
#

whatever looks interesting to you really

brave scroll
#

@cloud urchin i have used double quotes php shell code in burp repeater.. it didn't work even when inserting single quote code it works..

  • when enter double quote access.log file stop accessing.
cloud urchin
brave scroll
cloud urchin
#

you can test it like this

quasi wave
#

hi I need to ask. So tell me if I'm getting this right. I did the reverse/remote port forwarding with SSH mysql several days ago and I want to make sure I understand the concept. So we have attack host, and public IP target and private IP target. In order to reach the private IP target, the attack host listens on a port such as HTTP/HTTPS port 8000 or 8080 but with HTTP/HTTPS protocol to get a reverse shell script onto the public IP target's machine in order to establish an SSH connection with the machine and listens for that machine to connect. Upon establishing an SSH connection with the publicly available web server, it then must use that server to connect via 8000 or 8080 or some other port to the private IP server on the remote network that would not otherwise be reachable. Then, the attacker must transfer the attack script again from public IP server to private IP server on remote network not that they have access to a device that can reach the private server. But the command to transfer it has to trick the internal server into running that script so that the attack box outside the network has the traffic forwarded back from the private server to the threat actor via the public server.

I solved all the questions from that section. Do I understand the material well enough to go to next section?

cloud urchin
#

as long as you have that as your user agent header, you should be able to curl the log

onyx cave
#

how can i speak to the general chat btw?

cloud urchin
brave scroll
#

means give commands in agent-header?

cloud urchin
quasi wave
#

@cloud urchin hi I see your busy but if you could just let me know if I understand the section well enough or not that would be great.

#

see above

brave scroll
cloud urchin
quasi wave
#

its the reverse/remote port forwarding with ssh section in pivoting, tunneling, and port forwarding module

#

I did all the questions correctly

#

I just want to make sure I understand the concept see the paragraph above

brave scroll
#

@cloud urchin here you can see.

cloud urchin
cloud urchin
quasi wave
#

if not its fine I'll ask someone else

#

but I just want to make sure I understand the concept before moving forward

cloud urchin
#

essentially, you're forwarding a local port on the victim server through the pivot host to your computer

quasi wave
#

but I want to know based on my paragraph if I have a good enough understanding of the process and the different steps to move onto next section

#

because your one sentence is you know a short sentence but the full process has several steps and substeps and I just want to make sure I understand the details well enough.

#

then after that I will go onto next section as I already have done the questions

cloud urchin
#

well you're not transferring http traffic

quasi wave
#

but using HTTP/HTTPS ports so ssh over HTTP/HTTPS

cloud urchin
#

technically no

#

a port is just a port

#

just because it's port 80 doesn't mean it's http traffic

quasi wave
#

but using different port because port 80 is allowed

#

and SSH isn't so the change in port is to disguise traffic right?

#

so that its not recognized as SSH traffic and then blocked

cloud urchin
#

the port doesn't matter

#

you can use whatever port you want

#

the only port that would matter is ensuring you're connecting to the correct port the service is running on in the private network/server

quasi wave
#

ok got it I see now

cloud urchin
#

you just need to open up a port to listen on from the pivot host, just like you do on your attacker

#

that way it forwards from that port to your attacker machine, all the way from the private server

quasi wave
waxen totem
#

Just think of it like using the public ip target as a bridge to the private ip target.

quasi wave
#

ok so its a similar process on pivot host as attack machine

cloud urchin
#

yeah if you don't open the port on the pivot host then the traffic will just get blocked

quasi wave
#

so do I get it well-enough to move onto next section?

#

or is my understanding too impaired?

cloud urchin
#

i think so...

quasi wave
#

ok will go to next section then just wanted to make sure

#

thank you

cloud urchin
#

this module can be a mind bender

quasi wave
#

ok peace out. I'm gonna do the next module now.

flint palm
#

Guys I want to ask you one question. How many of you use AppleMacbook in your cybersecurity work?

lusty thicket
#

for writing reports

flint palm
#

8 GB basic model is really useless \

silk flicker
#

Hi! I'm still struggling with upload file attack skill assessment

#

how to access the url of the uploaded image ?

cloud urchin
#

Please don't post spoilers from modules above t0, especially skill assessments.

#

Know your target, HTB is not an American company.

silk flicker
#

Sorry!

#

Any hints please!

cloud urchin
tiny sentinel
#

Hi all, just started the "Setting up" module today and I'm a complete n00b. Any tips on which basics to start with so it might be smoother working through modules and gaining better understanding in general? I feel like I might be overreaching here without knowing any coding etc., I managed to get Parrot OS on a VM, but that's about it for now lol, I got stuck on permanently changing the bash prompt, so I thought it might be best if I worked on some basics first.

Any knowledge you might have on building my base knowledge would be greatly appreciated honestly.

waxen totem
tender spire
#

Has anyone completed Web Attacks module ?

#

need help with the XML External Entity (XXE) Injection onwards

tiny sentinel
waxen totem
tiny sentinel
ocean coyote
#

guys, a query regarding HTB Academy - if i purchase Silver monthly plan - do i get access to all the modules ? or do i still need cubes to view the modules/paths?

proud pine
#

Except for the student monthly. That one gives access directly.

ocean coyote
#

thanks for the clarification@proud pine

shut ice
#

Can anyone give a hint on the last question in AD trust attacks SA?

gloomy garnet
#

I have the username from part 1 but no idea what I have to do after that

#

My understanding about brute forcing and the different part of that topic are well known now

#

but the question or the task is just poorly written... I made a medium couse few hours ago and that was much easier then this

gray yacht
fickle sparrow
#

any recomendation for someone that has done the cbbh to do some boxes related to web api attacks pd: i already know htb has a feature for that!, but i want someone opinion in which box is a go to

ocean night
#

If you're having issue with a specific module, mention the module / section here @fickle sparrow

#

Someone may be willing to give you a nudge in DM

fickle sparrow
#

thanks thanks

ocean night
ocean night
#

Both HTB team members, and both have searchable writeups for retired content

gloomy garnet
gloomy garnet
#

bad thing, it doesnt accept passwords

vivid hinge
#

Hi everyone, I'm facing an issue with a question in HTB Academy.

I'm working on the question that asks for the number of services listening on all interfaces in the linux fundamentals module/filter contents sections ,but I'm getting inconsistent results.

Hereโ€™s what Iโ€™ve tried:

ss -tulnp | grep -v "127.0.0.1" | wc -l: Getting different results each time.
netstat -tulnp | grep -v "127.0.0.1" | wc -l: Same thing, the results are inconsistent.
Using sudo when possible for more visibility, but I canโ€™t see all the services.
I get different numbers with each attempt (e.g., 18, 21, 29) and Iโ€™m not sure which one is the correct answer. Is there something Iโ€™m missing in how I'm filtering the interfaces or any specific services I should be focusing on?

If anyone can clarify or explain why the results are different, Iโ€™d really appreciate it.

Thanks in advance!

waxen totem
vivid hinge
#

yes i do

wicked temple
#

yo

waxen totem
# vivid hinge yes i do

have you tried restarting the target or swapping VPNs? that's really odd behaviour from the target

wicked temple
#

i'm Supposed to be a Developper i wanna learn CyberSecurity

compact patrolBOT
vivid hinge
#

is it necessary to be in root mode ?

waxen totem
#

I did it without sudo

vivid hinge
#

thanks @waxen totem ^^

wicked temple
#

#problรฉmes 4 budget = 50 Water = 10 Chips = 3 chocolat = 1.5 #total total = Water + Chips + chocolat print(total) #Reste Reste = budget - total print(reste)

#

written in Python

wicked temple
#

question mathemathic

waxen totem
#

@wicked temple this is not the channel for random programming problems, go to ---> #programming

If you don't have access please get verified, instructions ---> #welcome

wicked temple
#

i have not acces

real delta
safe star
gloomy garnet
gray yacht
gloomy garnet
#

but I dont get acess, even I have the password and username for the ssh

#

also I didnt get any results, cause the target IP didnt work really, had to refresh it

gray yacht
gloomy garnet
#

i target the assigned one

gray yacht
gloomy garnet
#

im in ssh now

#

i dont know why it works now, I didnt change something at all

severe inlet
#

https://academy.hackthebox.com/module/33/section/518

I am in SQLi Skills assessment

i was able to bypass the login
i was able to find a directory to write in
However i don't know how to access the file since its not in /var/www/html like the section of the module

how can i access it?

willow estuary
#

Hey ๐Ÿ‘‹ there ๐Ÿ™‚

cloud urchin
#

hi

stiff aurora
stiff aurora
stiff aurora
severe inlet
waxen totem
severe inlet
#

The problem in the section when they uploaded the file
they uploaded in /var/www/html/shell.php which then they can access from http://<ip>:port/shell.php

But for me i couldn't write it their since i don't have permission i was able to write it somewhere else but i can't seem to find the file

severe inlet
#

I just solved it
I hate my self so much LOL i dont know why the overcomplication

but i guess im glad i did it without help

gloomy garnet
#

I just need the password for the second user then im also done

#

Is the pw in the list or do I have to create a pw list with cupp?

severe inlet
#

Login brute forcing?

gloomy garnet
#

Yes

#

But now I have the feeling I made an error

#

The second user I wrote the first letter in caps

severe inlet
#

You should apply the skills taught in the Custom Wordlist section

gloomy garnet
#

Cupp -i then

severe inlet
#

You learned 2 things there

tender spire
#

if you have complete the web attacks module can you dm me plz!

gloomy garnet
#

I create the list with the full name and then use hydra with the new username

severe inlet
#

You are on the right path

cloud urchin
gloomy garnet
#

Perfect

#

Sleep then continue, ty everyone! โค๏ธ

blissful terrace
#

can some one help if tried intro to whitebox module ?

tender spire
tender spire
#

my script wont work to download the contents i need for this one task, im not sure where to go from here i tried multiple ways/options, thats why if anyone completed Web attacks module youll be a great help rn

cloud urchin
#

the Mass IDOR Enumeration section?

tender spire
#

yes

#

bypassing encoded refrences im stuck on

cloud urchin
# tender spire yes

They provide a working script I believe, you just need to modify the server and port.

tender spire
#

yeah i tried that it doesnโ€™t work so i tried using another script for this but no luck

cloud urchin
#

do you get an error or something

blissful terrace
regal ruin
#

how to open .docx file in kali linux ....????

cloud urchin
#

open office?

low seal
#

Hi guys, I am on File Upload module, to be specific this section : https://academy.hackthebox.com/module/24/section/160, I am trying the WebDav upload. But seems like the share is not reachable from windows, i have tried spinning actual SMB server (using impacket-smbserver) to verify but in this case the host is infact reachable.

Has anyone else has faced this issue? Basically the whole "SMB Uploads" section is not working.

swift dove
#

is it normal for nmap to take so GAD DAM LONG!...sorry Ive been trying to scan a target it its been for ever...

waxen totem
sonic linden
#

hello

in the wordpress hacking skill assessment i dont find any worpress related stuff ? i scan the ip i get 3 open ports but still no seervice runing wordpress and the qst is what is the worpress version ?

autumn pilot
#

enumerate the application

timid oar
#

hmmm
what's the point of a module providing a pws.list if all but one of the labs require rockyou.txt instead =/

waxen totem
regal sigil
#

Hi I have a very simple question, not related to HTB academy. So when I ran this ffuf scan
ffuf -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt:FUZZ -e php -r -u http://192.168.180.10/FUZZ
I am expecting the scan to also search for php extension files like login.php (which I know exists)
But ffuf did not return any files, but only directories. What am I doing wrong here?

fathom pendant
#

let me throw an 8GB wordlist at the wall and wait 5 hours because the sysadmin limited the amount of concurrent connection threads to 2 :)

fathom pendant
#

also i forget with ffuf if you need to use .php instead of just the php name

#

oh wait you said not related to htb academy

regal sigil
fathom pendant
#

this channel is for htb academy questions, best to ask in #web instead since this is unrelated

regal sigil
timid oar
sonic linden
autumn pilot
#

Enumeration can be done with other means and not only with automated tools

sonic linden
#

okey i ll work on it more thank you

timid oar
fathom pendant
#

i don't recall using rockyou for too much in that module but it's been a minute

gloomy garnet
#

never forget one important point

#

hydra is case sensitive :'D

#

I worked yesterday 2 hours on that and didnt saw that

round stream
#

Where to report typos in academy modules?

waxen totem
#

@glad tusk not the server for that kind of stuff

glad tusk
#

Can you refer me to the message

#

Cos Iโ€™m confused honestly

karmic vapor
#

I don't know, I'm new

waxen totem
fathom pendant
grizzled schooner
#

Hey guys! Still a bit stuck on "Password Reuse / Default Passwords"

I ran nmap, there's a couple of services open, but the previous creds don't work, not sure what I'm missing but a nudge would be great. The last one I got was to see if those worked for any external services. I can't find any that these would work for, but I may be missing something. Please @ with a response, thanks in advance!

jade trail
#

hey, im very new to HTB and HTB Academy and i feel super dumb but i dont know if what im doing is right. Im currently learning cURL and the module is asking me to download a file. should i be using cURL to look at the target ip it gives me or the url in the examples above?

storm elk
#

The URL from the examples are from when the lab was created. They won't work

#

You should ALWAYS use the target that is provided for you

jade trail
#

ok that is what i thought but cURL doesnt like it as a URL am i just not formatting it correctly

fathom pendant
#

Or http://ip:port/rest/of/url

fathom pendant
#

I believe the question prompts you to use the login you discovered from the last section

grizzled schooner
#

Hmm, interesting I may have to mutate a password or something then... I got 3 services in tcp, and udp ran for 10 minutes before I had to clock in to work

fathom pendant
grizzled schooner
#

Maybe it just needed a restart then, I'll try that again when I can, but that login didn't work the first time around

fathom pendant
#

Should work for ssh

#

ยฏ_(ใƒ„)_/ยฏ

grizzled schooner
#

Alright cool thanks!

jade trail
fathom pendant
#

And there's no logic to downgrade the request to http

jade trail
#

gotcha

stuck flame
#

Hello i am on "Using Web Proxies" I already searched in chat but not find an answer, Can you please help me understand what i missing on this exercise ?
"Try using request repeating to be able to quickly test commands. With that, try looking for the other flag."

What can be other flag ?
I read already flag.txt but its not that, i not realy understund what i need to looking?
Any help appreciate. Thanks.

mossy marten
#

For the skill assesment part 2 of Login Brute Forcing: i brute forced the ssh connection and am connected. I have a username file created with a first and last name and in the ssh home directionary there is a passwords.txt file. Brute forcing the ftp from within with these 2 has been unsucessfull. Do i need to use another password file i created on my own?

sand sedge
#

theres more flags there

#

but you have to search

stuck flame
#

Ieah I finaly got the Answer and i understund need searc more extra from what you academi teach you to find correct answer from questions.

tired atlas
#

Hi so I'm on the infamous password attacks hard lab, and I just can't download the .vhd file, I've tried, smb, http-server, netcat isn't installed on windows and the box has no internet access, ftp isn't working either, can anyone please help me ๐Ÿฅน

neon wadi
mossy marten
neon wadi
mossy marten
#

but there is only 2 txt files and the username-anarchy directionary, is it supposed to be in the username anarchy .

neon wadi
mossy marten
#

that is in the home diectionary after i brute force and logged into the SSH connection

hybrid elbow
#

Hello

#

Can any one crack a password for me please

neon wadi
mossy marten
#

i have a password.txt file and an "Incidentreport.txt" that gives me a firstname and a Surename. I used username-anarchy(directionary given) to create a username.txt file based on given first and surename. i can connect to ftp manually with : ftp ::1. but the matching hydra command does not find a combination

#

satwossh@ng-1215477-loginbfsatwo-kr8td-84d4f74bfb-9sqt9:~$ netstat -tuln | grep 21
tcp6 0 0 :::21 :::* LISTEN
satwossh@ng-1215477-loginbfsatwo-kr8td-84d4f74bfb-9sqt9:~$

acoustic owl
mossy marten
#

satwossh@ng-1215477-loginbfsatwo-kr8td-84d4f74bfb-9sqt9:~$ ls
IncidentReport.txt passwords.txt username-anarchy

neon wadi
# mossy marten satwossh@ng-1215477-loginbfsatwo-kr8td-84d4f74bfb-9sqt9:~$ ls IncidentReport.txt...

Sometimes you just have to enumerate further and think outside the box. That applies everywhere in this course. In this case, the enumerating further means looking for more information on a system once you gain access, like looking in /etc/passwd to get a list of usernames on the system. Thinking outside the box might mean not using the given username AND password list, but maybe there's another way to get a username (list users on system), or password (maybe stored in file somewhere).

mossy marten
#

ok thank you for your help will do that

safe star
#

Are you able to mount a drive with rdp?

tired atlas
#

smbclient isn't working, and ftp has no changing directory rights

safe star
#

Smbserver or smbclient?

tired atlas
neon wadi
#

If you have the right host, username, and password, then smbclient syntax should be: smbclient //HOST/USER -U 'USER%PASSWORD' Once in, the get command should be able to download a file.

tired atlas
#

give me a sec

neon wadi
#

I meant 'SHARE' instead of 'USER' in the first part

mossy marten
west arrow
#

Hey, Im trying to use iptables as firewall to block port 8080 connection of my apache2 server but it isn't blocking it. This is my code: sudo iptables -A INPUT -p tcp --dport 8080 -j BLOCK

west arrow
#

It still persists, thanks for the reply though

tired atlas
acoustic owl
tired atlas
#

yeah i am

tired atlas
#

been a while

acoustic owl
#
xfreerdp ..... /drive:share,"/home/user/share"
safe star
# tired atlas

The file is big so you will have to set a bigger timeout to download it

safe star
#

But yeah you should probably use the rdp drive if you have access

#

Think I used ftp there though

west arrow
#

Does anybody know why this firewall iptables isn't working and the page apache page remains?

mossy marten
nimble scroll
#

hi , I got stuck on this module , Server-side Attacks
Identifying SSRF , I get Error (3): when I try to get a response

#

can anyone help ?

scarlet garnet
#

Hey, someone has done "MODERN WEB EXPLOITATION TECHNIQUES - SSRF Basic Filter Bypasses"

#

I need help

acoustic owl
outer tendon
#

i cant find the VM ware 16 workstation player thats free for windows on vmware like the Setting up Module is showing

neon wadi
outer tendon
#

thanks, do u need a broadway acc? even tho i want to install on window

neon wadi
# outer tendon thanks, do u need a broadway acc? even tho i want to install on window

Yes, VMWare was purchased by Broadcom. You need a Broadcom account to download VMWare Workstation Pro. You don't need to give them a credit card or anything sensitive, just an email address I believe. And it takes a few steps to navigate through their portal to the downloads section to get the product installed. Not very intuitive I recall, but after you get it set up it works great. Much superior to the old free Workstation Player, which could only handle a single VM at a time.

#

I'm running it on Windows. I have Kali and Windows VMs running. Works great.

outer tendon
#

ahh thx alot so its free and only got to give a email and great as a VM

#

OKay great il do it

neon wadi
# west arrow

Are you actually seeing traffic going through port 8080: sudo tcpdump -i eth0 -n -t port 8080

digital pendant
#

Is a block by AV expected every time? just on shells & payloads module in CPTS (tier 1 module) reverse shells section -

What happened when we hit enter in command prompt?

Well ... I got the reverse shell instead of the 'expected reply from the environment'

This script contains malicious content and has been blocked by your antivirus software.

&&

Using PowerShell instead of CMD for this part of the module was hell, 8+ errors with no real way to fix, CMD works (as seen above)

Thoughts?

nimble scroll
#

Exploit a SSRF vulnerability to identify an internal web application. Access the internal application to obtain the flag. Did anyone solve this ?

neon wadi
flint moth
#

Can somebody help me in HTTP Response Splitting Assessment? I have the payload working but can't get the admin cookie part

Solved

DM if you need help

neon wadi
#

I see. That's not what iptables is for. It blocks traffic coming into the host from an external network interface. It doesn't block traffic coming from localhost.

neon wadi
ocean night
#

I mean, technically you can use iptables to block off local ports

#

I imagine it has uses for multi-tenant systems, but that being said I don't honestly know if you can do such things as blocking based upon things like process owner

#

There are modules and such which allow for this kind of customisation apparently

#

This channel is for discussion of modules

west arrow
nimble scroll
#

I still cannot get it connected to get the flag

#

I don t understand the lesson :/

fathom tide
#

ffuf isnt doing dns enumeration

nimble scroll
#

HTTP/1.1 200 OK
Date: Mon, 17 Mar 2025 18:12:32 GMT
Server: Apache/2.4.59 (Debian)
Content-Length: 45
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8

Error (1): Received HTTP/0.9 when not allowed

supple dragon
tired atlas
#

I'm trying to crack the .vhd file in password attacks hard lab and its TAKING FOREVER like its been like 1.5 hours

#

and its at 40%

nimble scroll
#

I can t figure out on Identifying SSRF :/

#

I managed to find the port but doesn t give me any hint what should I do next

inner shell
#

Can someone help me with the module 77, under the pentester route. The host/nibbleblog components aren't working and I'm getting these errors:

#

I can't view the host/nibbleblog page in a browser either, but I can view the host page