#modules

1 messages · Page 402 of 1

cloud urchin
#

it says the location in the question itself

primal rover
#

There's no flags though

#

I have full access to the site, but i can't find anything with resembling a flag

dusky valve
#

im doing the Understanding Log Sources & Investigating with Splunk module and i just realized that the logs time and the one in the screenshots of the module differs,

should i be concerned about this :O unlike the module before that uses elastic, we can change the timezone there but for splunk, should i do the same if possible and where can i change it

cloud urchin
primal rover
#

I used the shell to list all the users in /etc/passwd

#

no flag

#

😅

unique spruce
#

im in the ftp server now and idk im using ls and it keeps saying transfer complete i tried switching to passive and tracing but the ls is doing shit nothing

primal rover
#

Keep having to rebuild the VMs because time runs out because i can't understand the vague. not fun

tranquil crystal
primal rover
#

I have obtained the shell, but what is the question asking for?

cloud urchin
#

that's not the last question of the skill assessment in the wordpress module lol

tranquil crystal
#

Does it not give a hint about directory/location?

primal rover
primal rover
#

but what am i looking for?

#

it just says "a file"

fathom pendant
primal rover
tranquil crystal
#

Is it the last question? The question tells you where to look

fathom pendant
#

if you have a shell and upgrade it
(typically linux revshell you can do python3 -c 'import pty; pty.spawn("/bin/sh")') then just utilize the find command or grep -r iirc

primal rover
#

no it's this question "Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download."

tranquil crystal
#

What is the wpscan output?

primal rover
#

it's very long

tranquil crystal
#

Use a pastebin. Then I can take a look

#

I think you maybe overlooking something?

fathom pendant
#

take this to private

tranquil crystal
#

Ok

fathom pendant
#

since the module is above tier 0

primal rover
#

ok i need to setup the vms again so it might take a bit

tranquil crystal
#

Ah

fathom pendant
#

sharing a pastebin of output would be spoiling

tranquil crystal
#

Feel free to DM me

unique spruce
#

can someone please help local: .cache remote: .cache
ftp: Can't access .cache': Permission denied ftp> get . local: . remote: . ftp: Can't access .': Permission denied
ftp> get ..
local: .. remote: ..
ftp: Can't access ..': Permission denied ftp> get ... local: ... remote: ... ftp: Can't access ...': Permission denied
ftp> get aura
local: aura remote: aura
ftp: Can't access aura': Permission denied ftp> mget . ftp> mget .profile mget .profile [anpqy?]? ftp: Can't access .profile': Permission denied
ftp> mget .cache
ftp: Unable to determine real path of .cache': No such file or directory Skipping non-relative filename .cache/motd.legal-displayed'
ftp> mget .ssh
ftp: Unable to determine real path of .ssh': No such file or directory Skipping non-relative filename .ssh/id_rsa'
ftp: Unable to determine real path of .ssh': No such file or directory Skipping non-relative filename .ssh/authorized_keys'
ftp: Unable to determine real path of .ssh': No such file or directory Skipping non-relative filename .ssh/id_rsa.pub'
ftp> exit
221 Goodbye.
┌─[us-academy-2]─[10.10.14.179]─[htb-ac-1794577@htb-wtlvwk0t9e]─[/home]
└──╼ [★]$ ls
debian htb htb-ac-1794577
┌─[us-academy-2]─[10.10.14.179]─[htb-ac-1794577@htb-wtlvwk0t9e]─[/home]
└──╼ [★]$

#

i got this on the ftp server and i need the stupid ssh key but i cant get the file so i have no clue what to do

#

anyone able to help please

unique spruce
#

i did bro

fathom pendant
unique spruce
#

why did u delete my message mane

#

yes thats how im even logged in

fathom pendant
#

module is above tier 0

#

that's why

unique spruce
#

bro its from my cli

fathom pendant
#

ok and? the information is from a skill assessment from a module that's above tier 0

unique spruce
#

and i did ls -la

#

and nothing wants to be fucking getted or mgeted

fathom pendant
#

chill

tranquil crystal
#

your output showed an .ssh directory

unique spruce
#

yeah i cant get in there for some reason

fathom pendant
#

you know you can cd within ftp

#

but if you can't cd or are getting permission denied i'd be making sure i connected to the right port as well as logged in properly

#

all else fails reset the lab, give it a few minutes, try again

elder thistle
#

Hello I'm new here what's the module category about

fathom pendant
#

or change vpn regions and try again

unique spruce
#

i cded into the ssh file

unique spruce
#

and i cant get ANYTHING

fathom pendant
#

if youread #welcome it explains the layout of the server

unique spruce
#

like every single file is permission denied

#

ftp: Can't access id_rsa': Permission denied ftp> get authorized_keys local: authorized_keys remote: authorized_keys ftp: Can't access authorized_keys': Permission denied
ftp> get id_rsa.pub
local: id_rsa.pub remote: id_rsa.pub
ftp: Can't access `id_rsa.pub': Permission denied
ftp>

#

permission diened permission denied permission denied permission denied like my hod

fathom pendant
#

chill for a sec

#

take a minute

#

step back

unique spruce
#

dude its 3am

fathom pendant
#

and come back with a clear head

unique spruce
#

id rather js solve this im not even clouded in the head i js dont know what to do

fathom pendant
#

frustration will only compound on itself

tranquil crystal
#

Take a break for now

fathom pendant
#

it's not about being clouded in the head

#

it's about compounding frustration

unique spruce
#

it is 3am and i have work in 3 hours bro 😭

fathom pendant
#

then you should be sleeping

#

and not doing htb

tranquil crystal
#

Mind doesn' work optimally when frustrated. You need a break. It's okay to take a break

unique spruce
#

is there any hint i can get to like get these denied keys?

fathom pendant
#

the module will still be there after work

tranquil crystal
#

Don't try to force yoruself to do it right now

elder thistle
#

OK read everything thank you

fathom pendant
unique spruce
#

bro i just want to get this one over with

#

let me try one second

#

yeah im on the right port

#

idk im in the ssh direcotry and i see the restricted keys i lowk dont know where to go here or how to privlege escalate from here ig

fathom pendant
#

you're on the right track, your frustration is just getting the better of you

unique spruce
#

im not mad anymore bro 😭 atp being called frustrated is whats making me mad

#

idk im looking through my notes and the actual module and idk rly where to go

fathom pendant
#

you're frustrated because:

  • you're assumedly doing the right thing
  • it's not working
#

frustrated != mad

barren crystal
#

is there a way to filter owned modules so i only see the ones i havnt finished yet?

fathom pendant
barren crystal
fathom pendant
#

ah ye

#

forgot about that tab

barren crystal
#

yeah me to kek

#

i usually have education sub, but waiting to see how my banks looking after this week haha

fathom pendant
#

try specifying port with -P to be sure

unique spruce
#

im 100% sure because i tried 21 and i didnt have the same files at all

fathom pendant
#

i just did it myself and it worked just fine ¯_(ツ)_/¯

#

try changing vpn regions [you'll need to respawn pwnbox and target]

#

it's on the alt port

#

i told you

#

alt port == not default btw

#

also removing your question because it's a spoiler since you have to scan for info

#

ffs

unique spruce
#

ok im on the alt port

#

hold on look

#

150 Opening ASCII mode data connection for file list
-rw------- 1 ceil ceil 738 Nov 10 2021 authorized_keys
-rw------- 1 ceil ceil 3381 Nov 10 2021 id_rsa
-rw-r--r-- 1 ceil ceil 738 Nov 10 2021 id_rsa.pub
226 Transfer complete
ftp> exit
221 Goodbye.

#

this is how mine looks

fathom pendant
#

you typed exit

unique spruce
#

yeah

fathom pendant
#

also the !ls <-- is to run a local command

#

prefixing any command in ftp with ! runs the command on your local machine

#

allows you to check stuff without needing to leave the comfort of the ftp shell

unique spruce
#

oh ok

#

ok but my issue is like i cant acess the ssh file

#

idk why thats why im stuck as of rn

fathom pendant
#

you shouldn't be having issues; normally i wouldn't do this but dm me the exact string you used to connect

#

simple PEBKAC error

primal rover
#

i'm on hour 11 now. this questions is killing me

#

I even found a flag that is for something else?

#

🥲

safe star
primal rover
#

Yes. I have found the vuln and have an active shell. I can view the whole file system. Only problem is the question doesn’t say which file it wants me submit.

safe star
primal rover
#

I know, i skipped ahead and brute forced a user got admin access then added the code and can do RCE. Ive been scanning the whole server for hours and found a fag in the uploads folder but it wasn’t accepted

#

I have all the other solutions already i just need #5 to finish the module

safe star
#

the module gives you a command to search them

primal rover
#

I found the cvs and git the command to read files using the vuln, but now what? What file do i read to get the flag code?

primal rover
safe star
primal rover
#

Exploit-db is the one i used. Im not using metasploit

safe star
#

dm the one youre using

waxen totem
#

Ok am gonna need a sanity check on Password Attacks: Password Mutations cos hydra has gone through ~90,000 entries and still isn't done...

#
  • yes Im using a mutated list
  • yes I grabbed the original password list and am using the custom rules provided
  • yes Im not directly targeting ssh but the other service instead
  • im on TCP vpn
  • 48 tasks
#
  • total of mutated list of ~180,000(am thinking this is the culprit YGGC_eyesShaking )
limber river
#

iirc it took me 4hours to found one answer

waxen totem
#
[STATUS] 639.77 tries/min, 91487 tries in 02:23h, 96282 to do in 02:31h, 48 active

I hate this

bright coral
fathom pendant
#

looks like it may contain dupes, you don't want that

rustic sage
#

thanks @fathom pendant

flint palm
#

Guys hello. When you have a shell with PowerShell is it possible to switch to cmd.exe?

fathom pendant
#

cmd <-

#

why you'd want to drop down to cmd is beyond me

#

but you do what you want

fast arrow
#

https://academy.hackthebox.com/module/41/section/442

I spent close to an hour trying to get this flag - it only worked after I skipped ahead and went back later. I swear I'm not going crazy and pasted the exact same string that got denied (I had it sitting in a notepad). It's a really obvious flag and tried all the white space combinations including the standard format without any white space

#

exact same string I tried many times only worked after I skipped ahead and went back

fathom pendant
#

sometimes refreshing the page lets you submit the flag

#

it's weird

fast arrow
#

damn first time I've encuotered this, thanks

acoustic owl
tawny flint
#

Hi, in the "Web Attacks" Module, in IDOR section -> "Bypassing Encoded References"
https://academy.hackthebox.com/module/134/section/1187

I can´t download any contract, I am getting a 403. I found how the server is encoding but I am not able even download my own contract, so the one with uid=1, should be like that o something is wrong?

spark hinge
#

i run this code import requests
import re
from bs4 import BeautifulSoup

PAGE_URL = 'http://94.237.59.30:50280'

def get_html_of(url):
resp = requests.get(url)
if resp.status_code != 200:
print(f'HTTP status code of {resp.status_code} returned, but 200 was expected. Exiting...')
exit(1)
return resp.content.decode()

html = get_html_of(PAGE_URL)
soup = BeautifulSoup(html, 'html.parser')
raw_text = soup.get_text()
all_words = re.findall(r'\w+', raw_text)

word_count = {}
for word in all_words:
word = word.lower() # Convert to lowercase to ensure case-insensitive counting
if word not in word_count:
word_count[word] = 1
else:
word_count[word] += 1

top_words = sorted(word_count.items(), key=lambda item: item[1], reverse=True)

Print the top 10 words with their frequencies

for i in range(10):
print(f'{i+1}: {top_words[i][0]} ({top_words[i][1]} times)')

Output the 3rd most used word

third_most_used_word = top_words[2][0]
print(f'The 3rd most used word is: {third_most_used_word}')

fathom pendant
#

as the example url you'd have to change

spark hinge
#

it s the same

#

what can i do?

#

i can find...

fathom pendant
#

@spark hinge don't dm users for help without asking

spark hinge
#

ok

dense tree
#

I believe I'm answering this question correctly in the Linux fundamental mod, "Which kernel release is installed on the system? (Format: 1.22.3)"

#

I did provide the X.XX.X format based on the uname -a cmd

#

but it's not accepting

#

is it better I ask inside the academy chat?

dark hedge
shut vapor
#

Me trying to compile juicy potato.
Visual Studio: "Hey, check it out, you can use XBox Live Pass.....!"
Me: No, go away... <click.. click.. compile..>
Clippy: "I see you're trying to compile malware! I've taken the liberty of deleting that new binary!"
Me: Arrrgh.

shut vapor
#

Will do, next up. :^) edit: oh yea, that's going in the notes

dense tree
dark hedge
#

i believe you aren't SSHed into the target

#

you have to SSH first then you can start answering the questions

dense tree
#

no wonder why it's taken me about 4 hours do get through this part

nimble scroll
#

Hi , can anyone help me with this ? Authentication Bypass via Parameter Modification , Module , Broken Authentication

#

?

simple shuttle
#

Hi, I've been following some HTB modules the last couple of weeks. I love the platform, but a lot of the content could be improved significantly in terms of writing style and clarity. Is there someone here I can get in touch with to suggest improvements? Right now I keep submitting new content tickets, but that's getting cumbersome at this scale and I'd like to do some proposals.

acoustic owl
flint palm
#

guys can anyone give a link to normally working JuicyPotato?

#

.exe

sand rose
#

Hello (again). I'm trying to brute force vhosts on Vhost section of the information gathering-web edition. I've tried gobuster numerous times, and it is giving me back nothing. The command I'm running for reference is:
gobuster vhost -u http://83.136.251.19:43946 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain

Each time I run it, I never get any results. Is there something I missed? I keep looking in the module, and I'm not noticing anything I may have overlooked.

nimble scroll
#

solved

opaque cosmos
#

I am trying to use foxyproxy after connecting to it i am unable to access any website

rustic sage
opaque cosmos
#

Setting ip 121.0.0.1 and 8080

sand rose
#

Are FoxyProxy and Burp (assuming youre using burp), on the same port?

opaque cosmos
#

Yes zap

#

Justing unable to access any website after connecting to it

sand rose
#

Is intercept on? I know with burp you need to forward the packets or turn it off if so.

opaque cosmos
#

Zap it off

sand rose
#

I use Burp, so I'm not really able to help much more beyond that... my apologies.

opaque cosmos
#

I am not asking about zap just help me how to use foxyproxy

acoustic owl
rustic sage
#

My Citrix RDP session literally running at 1 FPS NotLikeThis

opaque cosmos
#

If i am using zap in build bowser which opens a firefox window then there is no need for foxyproxy because it has inbuilt proxy ?

acoustic owl
#

You need Foxyproxy to tell the browser which proxy to use.

proud pine
sand rose
fathom pendant
#

@unique spruce moving the convo here since i know you're working on an academy lab

unique spruce
#

It’s cat: ‘adam2/*’: Input/Output error

fathom pendant
#

well... the mount dir you said was adam1

#

so

unique spruce
#

there’s 2

fathom pendant
#

?

unique spruce
#

Cus I tried multiple permissions

#

There’s adam1 and adam2

fathom pendant
#

well there's your problem

unique spruce
#

They both have the same error

fathom pendant
#

sudo umount adam2

#

gotta unmount one

unique spruce
#

Still the same error

#

I did unmount it though

opaque cosmos
#

i am doing this flag Try intercepting the ping request on the server shown above, and change the post data similarly to what we did in this section. Change the command to read 'flag.txt' using command 'cat flag.txt' for getting the flag while intersepting is on using zap getting response but but no flag

fathom pendant
#

unmount both then and remount

fathom pendant
unique spruce
#

I remounted but it’s the same error

fathom pendant
#

change vpn regions; reset the lab; try again

unique spruce
#

that actually makes a difference?

opaque cosmos
#

intercepting web requests web proxy module

fathom pendant
#

cause I/O error isn't a standard error

unique spruce
#

It’s not my fault u mean?

opaque cosmos
fathom pendant
fathom pendant
fathom pendant
opaque cosmos
#

yes

#

HTTP/1.1 200 OK
X-Powered-By: Express
Date: Sat, 22 Mar 2025 15:01:37 GMT
Connection: keep-alive
content-length: 0

#

but no flag

#

got the flag

#

i was using ' in place of ;

#

stupid me 😅

fathom pendant
#

oof

unique spruce
#

@fathom pendant im still getting the same error

fathom pendant
#

try using ls to look at the directory

unique spruce
#

I alr saw the directory

#

The only way I’ve been able to cat files is one by one

fathom pendant
#

grep -E ".*"

unique spruce
#

huh

fathom pendant
#

regex

unique spruce
#

Whats rhe follow command

#

Full*

fathom pendant
#

grep -E ".*" mount/*

unique spruce
#

Same error

lusty thicket
fathom pendant
#

weird you can't sudo cd into it

unique spruce
#

Yeah lemme show u hold on

fathom pendant
#

did you try changing vpn regions and respawning?

unique spruce
#

Yeah I alr did that

fathom pendant
#

weird

unique spruce
#

am I cooked??

#

Im lowk js gonna use the credentials from the walkthrough i found at the end of the day its ab the knowledge ykwim?

proud pine
fathom pendant
#

ah

unique spruce
#

yeah that!

fathom pendant
#

just sudo su

proud pine
#

cd is just meant to change your pwd, but since none of your actual access rights would change, it wouldn't be possible to do it via sudo.

fathom pendant
#

no

unique spruce
#

the password on the walkthroguh doesn’t work so I think I’m cooked

fathom pendant
#

?

#

wdym

unique spruce
#

I FIDNIT

#

sudo su worked

fathom pendant
#

now you can cd to your targetNFS/

unique spruce
#

Im in the directory now how can I cat all the files now

fathom pendant
#

and hopefully this resolves the I/O errors too

#

cat *

unique spruce
#

uh I did that it’s just a blank line now

fathom pendant
#

give it a sec

#

also "blank line" isn't helpful

#

screenshot?

unique spruce
fathom pendant
unique spruce
#

yess it worked

lusty thicket
unique spruce
#

I found the credentials

fathom pendant
#

yep just had to be patient kid

#

as you're not reading a local file, you're reading a mounted file, which is prone to network issues, likely why I/O error - delay and such

#

also $(pwd) returns
/example/dir

#

that's why grep gave you the error

#

you needed to add a / before the * to get it

proud pine
#

but there's no reason to use pwd like that, when you can ./

fathom pendant
#

also that

unique spruce
#

yo

#

i had to do sum but im back my credentials aren’t working for some reason on smb client

#

It’s saying session setup failed?

pearl furnace
#

is anyone else having trouble connecting to their target machines? I keep timing out for some reason

#

have refreshed the target a few times too btw

karmic raptor
#

Has anyone ever had a problem with an incorrect password when connecting to the “Internal Password Spraying - from Windows” RDP to 10.129.66.155 (ACADEMY-EA-MS01) with user “htb-student” and password “Academy_student_AD!” challenge?

hushed rivet
#

😛

unique spruce
#

The way I talk or my approach?

#

@hushed rivet

hushed rivet
#

the way you type

#

and the way you take screenshots haha

unique spruce
#

I am 15 man 🤷‍♂️

languid imp
#

Module: Introduction to Windows Evasion Techniques
Section: Process Injection

Is anyone else experiencing issues with this section?
I'm trying to complete the module using micro_shell, and I'm following the guide step by step exactly as described, but for some reason, I can't get the expected results.

Is there anyone who can help?

ocean night
#

There's no guide to solve the interactive section for that module, as it's over Tier 0. If you're following what's in the module / section, it could be you need to look at the commands you are using, and related options

#

Sometimes you need to research a little to find the solution.

gray yacht
rough nimbus
#

Hello guys !

On the module Protected Files from password attacks

They ask "Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer."

What is the cracked password ?..

languid imp
gray yacht
languid imp
# gray yacht `msfvenom` prolly worked.

I will try, but I don’t think it will work.
Because when I read on HTB, I saw that shellcodes like msfvenom are well-known signatures and are quickly detected by Defender.
That’s why micro_shell is used by HTB

quartz sundial
#

The 'Password Attacks' module… is "brilliant"! All the material is well-written and understandable, except for two pages: 'Pass the Ticket (PtT) from Windows' and 'Pass the Ticket (PtT) from Linux'. It’s like learning how to work with Python's requests library and suddenly being thrown into C++/C memory management coding halfway through the course. Seriously. They could have moved it to a separate module or placed it under the Active Directory section.

I'm reading and reading, but I don’t understand... Some crazy magic is going on — playing with keys, tokens, tickets… Where do these keys even come from? Why are they being passed around? Maybe for those who have worked extensively with Active Directory before, these pages aren't that difficult. But if you're taking CPTS as a course without any prior AD experience, these topics are next-level stuff.

Ugh, this is frustrating. Time to keep digging into this magic....

I've been trying to understand what's going on in these pages for two days. Maybe on the third day I'll understand😂

proud pine
proud pine
rough nimbus
gray yacht
quartz sundial
rough nimbus
#

The question on the module Protected files say ' Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer."

But i don't have the kira password ...

quartz sundial
rough nimbus
quartz sundial
languid imp
proud pine
rough nimbus
safe star
ocean night
#

It's ok @safe star.

#

Form signed etc etc

unique spruce
#

i have parent consental form done please dont banish me again 💔

quartz sundial
proud pine
unique spruce
#

┌──(kaifux㉿kali)-[~/Downloads]
└─$ nmap -sCV 10.129.146.33
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-03-22 14:01 CDT
Stats: 0:00:29 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 0.00% done
Stats: 0:01:01 elapsed; 0 hosts completed (1 up), 1 undergoing Service Scan
Service scan Timing: About 100.00% done; ETC: 14:02 (0:00:00 remaining)
Stats: 0:01:01 elapsed; 0 hosts completed (1 up), 1 undergoing Script Scan
NSE Timing: About 0.00% done
Stats: 0:01:02 elapsed; 0 hosts completed (1 up), 1 undergoing Script Scan
NSE Timing: About 96.89% done; ETC: 14:02 (0:00:00 remaining)
Stats: 0:02:01 elapsed; 0 hosts completed (1 up), 1 undergoing Script Scan
NSE Timing: About 98.21% done; ETC: 14:03 (0:00:01 remaining)

how did it go backwards 😭

safe star
#

It’s just the way bro used that as an excuse for the screenshot😂

unique spruce
#

oh no thats cus i was at work

#

im a lifeguard aswell so the account i was on didn't let me access discord so i had to take pictures on my phone

rough nimbus
gray yacht
cloud urchin
rustic sage
#

i am really stuck at CPTS : Double Pivots

cloud urchin
rustic sage
#

i am already connected to vpn

cloud urchin
#

the page i linked provides methods to make the vpn connection more stable, if you don't think it's on your end then you can try another server or region

rustic sage
#

It finds everything, when i press yes there then after a while it disconnects me

rustic sage
cloud urchin
#

at that point probably best to reach out to support on the website then

rustic sage
#

hell yes

#

now i will start with AD 😄

lost pumice
#

I'm new to the HTB world and I want to make sure I'm utilizing my Kali VM properly within the HTB Academy. I'm in the Getting Started/Basic Tools Section and wanted to know how to connect to the target through my VM? Do I need to use openvpn for this module or....?

cloud urchin
#

If you're going to use your own VM, use the VPN

tired atlas
#

I'm on Attacking Common Services RDP, I'm trying to disable restrictedadminmode and basically, my first thought was to use evil-winrm to do the job, but its essentially not loading a shell.

unique spruce
#

what the actual fuck

#

im on the medium lab still i literally got it and i logged into windows and i was on the bullshit mssm and it just crashed

#

and then i tried to reconnect and it wouldnt let and then i reset the target and pwnbox still the same actual bullshit

safe star
#

why not just do it from the rdp session

unique spruce
#

this is in footprinting btw

tired atlas
#

I've done this before in the Password Attacks Module, but it was using evil-winrm

ocean night
#

No need for that kind of language @unique spruce - if you believe there's an issue, please reach out to support. If something that was working for you previously is now not working, please redeploy again - sometimes things do come up in an unhealthy state unfortunately.

unique spruce
#

ok, ive redeployed like 5 times and i have no clue what to do atp

ocean night
#

@tender nimbus please do not provide potential spoilers for modules over Tier 0

tender nimbus
#

Ow euh yeah sorry so If someone can help in private for a SSI problem ^^

rich salmon
#

Hi guys i'm having some problems with the module Login brute forcing - skills assessment 1. Every time i use hydra it can't find the password. I've redownloaded the 2 text files from the current github repository but still nothing. Can someone help?

tender nimbus
rich salmon
tender nimbus
#

Let me check

rich salmon
#

ok

ocean night
#

Hm, broken link @rich salmon ?

rich salmon
#

???

ocean night
#

The links provided, could you download them ok, or was there a broken link?

rich salmon
#

no it wasn't

ocean night
#

If you have both lists and are following the section, then the information / creds you need are there

#

That's all I can say I'm afraid

rich salmon
#

ok

#

I will try to reset the target.. let's see

rich salmon
#

When i've downloaded the 2023 most used passwords it said the file is empty

tender nimbus
#

But when you do it with the link I did what did you get?

#

@rich salmon

#

Maybe you tried to clone the repo but you gave the full file path?

tender nimbus
#

Yeah but if you do git clone with this link it will not work because you only can clone "directories" and not directly files thats why

rich salmon
#

no i used wget

pine dune
#

Hi

#

Im using this command to test for ssrf vulnerability

rich salmon
#

now it worked thanks

#

@tender nimbus

pine dune
#

each time I run it it gives different ports open

#

gives it like this

#

anyone have any ideas why its doing that?

tender nimbus
#

Mb didn't saw it

pine dune
#

no worries, if you have any ideas pls lmk

#

idk why it keeps giving diffeent ports

#

and why its giving in that output

tender nimbus
#

Its about you filtering

pine dune
#

I did fs 8285 and mc 200

tender nimbus
#

also 127.0.0.1:FUZZ

pine dune
#

because I needed to filter the size and made sure I only get 200

#

ahh cant believe i didnt see that lol

#

let me try tht

tender nimbus
#

You trying to identyfi blind ports?

pine dune
#

do u know how I can hide the progress?

#

im trying to identify open ports

tender nimbus
#

Is the fs not Something went wrong?

pine dune
#

i dont think so?

#

fs should be a number?

tender nimbus
#

No You use strings to

#

You talking about these right?

pine dune
#

also do u know how I can get rid of all these lines and just give output

#

nah

#

identifying ssrf

#

f man this timer is so annoying

pine dune
tender nimbus
#

Let me look quickly I will do it again

pine dune
#

okay thanks

#

happened today morning too, idk why it keeps giving me different ports all the time

tired atlas
#

its just permanently loading

safe star
tired atlas
safe star
#

Then it’s not gonna work

tired atlas
#

yes i know

pine dune
tender nimbus
#

@pine dune for me it is just a bug

#

somethimes when you have that just do ctrl c and run again

pine dune
#

also Im still having the issue, Im still getting random ports opened all the time, its not consistent

tender nimbus
#

I’m not sure about that ^^ tbh i don’t know I just do it’like the module tu be sure its correct

#

With m’y command i just received the open ports

pine dune
#

my command

ocean night
#

If a module is over tier 0, do not share spoilers. Repeated posts will result in more than just a post deletion

#

..or maybe should just add a bot to say "no t0 spoiler" every other post

#

😅

pine dune
#

anyone know why Im getting this error? I dont have credentials for this

pine dune
safe star
#

externally?

pine dune
#

yea i believe so

#

it came up as an open port in the ssrf identification

safe star
#

and you fuzzed for 127.0.0.1 right?

pine dune
#

yea

safe star
#

thats not external

ocean night
#

Yours is fine tbh

#

It was another

safe star
#

you can only access that on localhost

pine dune
ocean night
#

NFI which module you're working on RE that

#

and it just shows trying to connect to a mysql server

pine dune
#

identifying ssrf

safe star
pine dune
#

let me try that

ocean night
#

Uhhhm, yeah,.. was gonna say, not sure you';r eon the right path

#

But that's a Tier 2 module, so don't give anything that could be considered a spoiler away please.

#

ty

pine dune
ocean night
#

I so gotta train an AI to do this

safe star
pine dune
#

let me see

#

also just a suggestion can we please get rid of the 5 second time limit in this channel 😅

ocean night
#

"Ok subservient intelligence, detect content that potentially spoils any content relating to <insert path to academy writeups>, and respond accordingly"

#

Well, that's my evening project for tomorrow

pine dune
#

im struggling wit this

pine dune
#

so it has 3 ports open and I was certain it was the sql one. When I tried connecting to it its refusing

ocean night
#

Not something you should advertise @tired atlas

pine dune
#

and thats what they show in the example so what the heck

tired atlas
#

it aint my fault google shows other search results

#

I was offering to give them to you so you can get them taken down

ocean night
#

Yeah, but.. just don't use writeups with content meant to be completed without using writeups, and have an impact upon completion of a certification

#

Thanks 👍

#

We do our best to fight against such postings

#

but it's a game of continuous cat and mouse

#

We catch cheaters daily also unfortunately, on all sides.

tired atlas
#

i mean look, they can exist but they're not gonna help you complete the exam

pine dune
safe star
#

pretty much the same with curl

ocean night
#

But.. comes with the terriritory, and it's not unique to HTB

#

If there's a test of skill, cheaters gonna cheat

tired atlas
#

even in a daily convo you have with a friend

ocean night
#

There still are leaks though

#

and certs are revoked, as with us, and other providers we speak with

#

End of the day, cheaters are hurting themselves more than providers

tired atlas
#

even if you cheat and get the exam i guess, you'll get fired or on a PIP when you pen test poorly

ocean night
#

and it's a shame

lusty thicket
#

how would they know

proud pine
tired atlas
ocean night
pine dune
tired atlas
#

like for my first soc job i got, the most they asked me was "what's the difference between threat intelligence and a SOC"

pine dune
pine dune
#

Im just confused on why port 3306 isnt working

tired atlas
#

also because of AI people are graduating with whole degrees while knowing next to nothing

pine dune
#

even though the ssrf scan found it open

tired atlas
#

its a damn shame

ocean night
# lusty thicket how would they know

Some can learn the skills required on the job without needing to learn beforehand. That is impressive, and they may well get away with it, but it doesn't detract from the massive ego thinking they can cheat in to a role over someone who has spent time learning and building. It just makes me angry and quite sad to think of

tired atlas
ocean night
#

Majority who fake their way in will just waste both their time, and the employers time, and get a black mark

#

Well, technically in the UK you can't be given a bad reference

#

But still.. you would know yourself

tired atlas
#

OMG wait you're from the UK?

ocean night
#

Aye

tired atlas
#

I'm Australian, my bf is from the UK, I'm literally doing this cert just to get a job in the UK

ocean night
ocean night
lusty thicket
tired atlas
#

Yeah ofc theres this company thats on hackthebox job search that recognizes cpts that is housed right where my bf lives, about 10 minutes away

ocean night
#

Last two jobs, I didn't know the main programming language the company used, but picked it up as I went

#

Just presented myself and my prior knowledge and eagerness to learn

tired atlas
ocean night
#

You get used to it

#

The worst for me was Ruby on Rails.. thankfully I only had to do a couple of small patches

tired atlas
#

My brother can pick up a textbook and within a day know how to code that language, prodigy

ocean night
#

but that shit just confused me for some reason

tired atlas
ocean night
#

If you have a good amount of experience in any general high level language, how basic logic works, scoping etc, moving to another language isn't too bad

#

but it's certainly a skill that takes time to pick up

#

I don't mind Java, but it's certainly got some aspects that are quite different to other languages.. in some cases for the better, and some.. not so

tired atlas
#

Im bad at coding in general, like it just looks like hodge podge to me, even though I have a maths background, i just can't....read it

ocean night
#

😅 maths background, you should have seen me going through a crypto course ages ago with discrete mathematics and syntax

#

I wasn't just a fish out of water, I was a fish that had been desiccated for a week and thrown in to a vat of salt

tired atlas
#

after this i want to take the AI red teaming course, looking forward to all the linear algebra

ocean night
#

..but it was fun to learn

#

That's the key too.. finding joy in learning

tired atlas
#

Yeah I'm pretty gucci at maths but even python for me, like I just can't learn beyond a basic program which is fine i guess for pen testing where you only need to write small automating scripts

#

but the big boys, they write all those tools and I"m like WOWWOOWOWWOW

ocean night
#

😄 Yeah, for pentesting having enough to write your own little automation scripts and tooling is definitely a massive bonus, and you can go as simple as automation as in chaining some pre-existing tooling together to writing your own toolset that does more advanced analysis and reporting, but at the end of the day so long as you can research the tools that exist and understand how they work to an extent from a theoretical perspective, you'll be fine

#

Using other peoples tools doesn't make you a skid imho, so long as you take the time to understand how it's working

#

Understanding how something works doesn't mean you should be able to turn around and build something better

tired atlas
#

for the first few modules of this course, I was feeling like a skid, but I'm so glad a lot of these questions are not directly taught in the module and you need to do a little bit of research

#

it builds those skills, with TryHackMe, the answers were quite literally taught

ocean night
tired atlas
#

Like I'm stuck right now, there's only an RDP port open, and I'm trying to perform a PtH but restrictedadmin is enabled, and I'm quite unsure how to do it

safe star
ocean night
#

What?

safe star
#

look how ffuf is sending the request

tired atlas
pine dune
ocean night
#

Getting that phenom is so rare

tired atlas
ocean night
#

I'd prefer to have someone who can grow than spending a year looking for that diamond

ocean night
safe star
#

not just requesting the target ip

tired atlas
pine dune
#

so we should change it to a GET request?

safe star
#

no

#

thats not how ffuf found it

ocean night
#

Not sure I can fairly comment much, as hiring was pretty different when I finally got in to the field after working in a supermarket for 6 years

safe star
#

ffuf is just automating something you can do manually

ocean night
#

I've been very lucky in my journey, never turned down, took many years to grow up to where I am.. but again

#

It was a different time when I got in

#

Now people do really have unrealistic expectations of what "entry level" is

#

"NEED 5 YEARS EXPERIENCE IN LANGUAGE THAT WAS RELEASED LAST YEAR"

tired atlas
tired atlas
ocean night
#

Well I hope that you managed to get a foot in the door when you're ready 🙂

#

When you feel ready*

#

When you go for it*

#

If we waited until we thought we were ready, we'd never do anything

#

I've never been ready for anything my entire life, apart from picking up a pint

tired atlas
ocean night
#

I lived in a town full of alcoholics, with more pubs than houses

pine dune
ocean night
#

I was well trained

#

(ok, more pubs than houses is a stretch..)

safe star
tired atlas
ocean night
#

🙈

#

Not the place for it @signal cloud

tired atlas
ocean night
#

Get out of my head

#

..and doctors notes

#

(not really)

tired atlas
#

I'd rather die than get sick in the Uk tbh

#

NHS is abhorrent

#

anywho

ocean night
#

It really is bad

tired atlas
#

general chat things in modules

ocean night
#

I had AF for like.. 6 months until they finally got me in for a 15 minute appointment to shock me

#

Maybe even 9

#

Ah crap, we're in modules, oops

tender nimbus
#

@pine dune still stuck?

#

You have to use burpsuite

#

And make a request to the port you found as date server parameter

pine dune
#

makes a lot more sense now

tender nimbus
#

Take notes to of Every new topic/tool you use for the futer @pine dune

fading skiff
#

hi guys

#

i need little help

#

btw why i cant type in general ?

real delta
quartz lagoon
unique spruce
#

yo im on the footprinting hard lab any tiny tiny hint i enumerated services but so far i have nothing and im not sure if im gonna have to brute force

quartz lagoon
#

btw i think there's a command to disable restrictadminmode in the module section iirc so you can PtH

fading skiff
#

hello any help ?

young ore
unique spruce
#

oh smart people here let me check

fading skiff
#

i think my problem is a type error

unique spruce
#

is a udp scan supposed to take 15 minutes?

fading skiff
ocean night
#

Don't freakin paste flags

fading skiff
#

okey

unique spruce
#

goblin

fading skiff
unique spruce
#

is a udp scan supposed to be 5-20 minutes?

ocean night
#

UDP scans are slow

#

and very rarely required at HTB

neon wadi
unique spruce
#

but in this case it might be?

ocean night
#

I don't know, I can't comment sorry

unique spruce
#

alright

#

im doing the footprinting hard lab

#

so yeah

safe star
fading skiff
#

nevermind im gonna open a ticket

neon wadi
unique spruce
#

right now or after im done w footprinting

ocean night
unique spruce
#

is footprinting a really really long unit

#

cus it rly does feel like it

ocean night
#

If UDP is required, interaction with it will be mentioned through the module somewhere no doubt

unique spruce
#

this is a lab they dont mention anything they js give u a username in this instance being HTB

unique spruce
ocean night
#

I can't comment

#

It's a Tier 2 module

unique spruce
#

the length is public dude

#

im just saying comparison to other modules on the cpts path is it considered long or are they all like this in length

ocean night
#

Honestly, I do not know

safe star
#

but theres a lot longer ones

unique spruce
#

maybe it felt like this cus school been taking away all my time

ocean night
#

It's not the longest module, but it's larger than many

unique spruce
#

oh ok thanks!

proud pine
unique spruce
#

ur lowk right ill try to adapt to the stuck mentality rather than js giving up

neon wadi
unique spruce
#

yeah 2 days took me one week but i wasnt rly doing it full time and i was taking comprehensive notes

proud pine
#

If it takes a week, but you fully understood the material, then it doesn't matter. The only bad thing you can do is to try to jump ahead of the content, and to disregard something as beneath your time. The exam won't care how quickly you complete things - only if you understood it properly.

ocean night
#

The smallest brick can cause a house to fall

#

(total bs statement, just felt like saying it)

#

..but it kinda made sense at the time

fair plinth
#

On the password cracking module in cpts, how many tries/min is normal and should any attempt take longer than 30 mins of cracking?

ocean night
#

Any specific piece of knowledge skipped over or discarded as just "part of the content" could be the difference between achieving a goal, or failing entirely

proud pine
ocean night
#

You can expect many expletives at that time, I think

proud pine
ocean night
tired atlas
ocean night
#

fudge it's nearly 1am now, oops.. one day "I'm going to bed" will actually mean "I'm going to bed"

tired atlas
#

GO TO BED

quartz lagoon
ocean night
#

🫡

proud pine
ocean night
#

nn all

#

I've been told

tired atlas
quartz lagoon
#

cause if you can /pth: will allow you to pth

quartz lagoon
proud pine
tired atlas
#

no I tried that but there wasn't an option within \Control\Lsa to disable it

quartz lagoon
#

i just did the module and i think they give you the cmd command (i couldnt be bothered to go to the registry file thing)

tired atlas
proud pine
#

Do not post module content.

quartz lagoon
#

does this work?

tired atlas
quartz lagoon
#

oh even the command isn't allowed?

#

i guess it does spoil, mb

tired atlas
#

I get there's a command, I read it, but without winrm port being open you can't even open a winrm shell to do it

indigo fulcrum
#

Having some issues with https://academy.hackthebox.com/module/25/section/149
How can I get a foothold, please? with the provided list, I have tried null session with SMB, tried crackmapexec but nothing is giving...should I use kerbrute and spray? I need some creds to begin with...but I am struggling with getting started with the provided list after enumerated two servers running on the subnet. One which is a DC and another which is just another server.

quartz lagoon
#

they should've given you a username and password

proud pine
tired atlas
proud pine
tired atlas
tired atlas
quartz lagoon
tired atlas
quartz lagoon
#

i'd just restart the target if i were you

tired atlas
#

its been 5 targets later

#

i've waited even before using the target for a few minutes

quartz lagoon
#

good luck then lmao i'm not too familiar with windows registries so i can't help any more

ocean night
#

You've more methods to go through over what you have already tried, you got this!

tired atlas
#

Youre in bed on your phone, blue lightttttttt, really bad for your sleep pattern, but I'm a hypocrite as I sleep hugging my laptop everynight

ocean night
#

💯

#

I'm my own worst enemy.. closely followed by my phone

indigo fulcrum
#

@ocean night you know...i have tried it all so far...i know my htb-student account doesnt auth to DC so I think I am stuffed untless the lab is messged up 😦

ocean night
#

It's not supposed to. Read the description where you start the exercise.

unique spruce
#

which genius told me to scan udp ports

ocean night
#

Implement the methods you have learned through the module.

indigo fulcrum
#

kool, kool...thanks man. will circle my method list again...

ocean night
#

mmhm, you have used what you need before.

#

Won't say any more, as phone is getting chucked down the side of the bed

#

..and I can't spoil, and please be mindful of what you post so as not to spoil a module that is over Tier 0

indigo fulcrum
#

staring at all these sections now again

safe star
#

you dont need admin to disable here

safe star
#

you can copy and paste the command straight from the module

tired atlas
#

I'm good now

#

also this module was weird, its stuff we've already done before but the new things explained in the module haven't been tested. Pass the Hash was taught in Password Attacks

#

session hijacking would've been nice to practice

quartz lagoon
#

maybe we'll see that in more details further down the line

unique spruce
#

i took the advice of my goat rat but im stuck, i managed to get the ssh key log in as the the user in the service but im in ssh now and ive hit a brick wall

#

ive looked for some many AV's but eveything came up short and i have 0 sudo privileges so im js stuck i feel

#

@fathom pendant can u help 💔

crisp solstice
#

Hey! So i am currently workign on Active Directory Enumeration and Attacks section 2.

I am on question 7: Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host.

I attempted to manually escelate my privileges using PrintSpoofer, GodPotato and JuicyPotato and it just didnt work, didnt even give me errors, it did nothing!

So i logged in to the mssql instance with metasploit, used getsystem and it worked. Does anyone have advice on how to try again manually?

cosmic plaza
#

Modules: Getting Started
Section: Nibbles
Sub-Section: Nibbles - Web Footprinting

Use VPN.
The /nibblelog/ shows a 404 error. What is it that goes wrong that I cannot see the /nibblelog/ page?

Both web browser and curl show 404 error.


└──╼ $curl http://10.129.41.215/nibblelog
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /nibblelog was not found on this server.</p>
<hr>
<address>Apache/2.4.18 (Ubuntu) Server at 10.129.41.215 Port 80</address>
</body></html>
┌─[parrot@parrot]─[~/Shares/Shared/lab/starting_point/nibbles]
└──╼ $curl http://10.129.41.215/nibblelog/
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /nibblelog/ was not found on this server.</p>
<hr>
<address>Apache/2.4.18 (Ubuntu) Server at 10.129.41.215 Port 80</address>
</body></html>

safe star
#

I think it blog not log

cosmic plaza
final hill
#

hi i need some help. currently on SQLmap essentials - Skills assessment. Currently am stuck on running sqlmap with the POST page, found the exploitable sql type, and (i think) the correct tamper (based on the search on this chat).

however i am still coming up empty on the database names, numbers, users, etc.

tired atlas
digital jolt
#

anyone experience the noriben.py unable to generate a CSV file report in Dynamic Analysis malware analysis modules?

tired atlas
#

Imagine spending months making a tool only to name it juicy potato

ocean night
#

Hahah

#

There's gotta be some lore to it surely

#

A sugared version of rotten potato

#

Ok, so why rotten potato

#

From hot potato

#

Curiouser and curiouser

#
Hot Potato
Rotten Potato
Lonely Potato
Juicy Potato
Rogue Potato
Sweet Potato
Generic Potato
#

Hot Potato was the first potato and was the code name of a Windows privilege escalation technique discovered by Stephen Breen

#

Ok so I assume it's about the payload and subsequent paylods making a number of to's and fro's before finally hitting the NTLM Relay

#

Kinda makes sense

jagged beacon
#

Run ZAP Scanner on the target above to identify directories and potential vulnerabilities. Once you find the high-level vulnerability, try to use it to read the flag at '/flag.txt'

HTB: using web proxies cube question.

I got the high-level vulnerability. But how to get into the next step?

ocean night
#

Research?

#

When you hit a wall, think about it as you would a totally blind pentest. You have something. What can you do with the thing?

keen belfry
#

Hi, does somebody know where I can get the source of ./followthegreencube.sh script from the first page of the Shells & Payloads Module? I couldn't find it on GitHub

acoustic owl
#

This is just one example. You cannot download this script.

keen belfry
acoustic owl
keen belfry
last ermine
#

Once i finish a module and im in the target machine, what is the fastest way of finding the flag.txt? "locate" doesnt work and i usually have to manually check dev/root/usr and custom file names to find the flag.txt. Im not sure if this is done on purpose and "there is no fast way"

ocean night
#

Oh, well.. for modules

#

The flag path is sometimes specified in the module / section exercise

#

Otherwise it should be obvious once you have completed the assessment step, as the step asks a question

#

Your goal is generally to answer that question to provide the answer.

last ermine
turbid echo
#

Hey,

Any nudge in Advanced SQL Injection Module? I got the two users and their emails. How ever the reset code is always wrong. I don't get it. What am I missing?

fickle gale
#

Need help
rdate: Could not connect socket: Connection timed out

acoustic owl
#

Which module, which section and for which question?
Without this information, it should be really difficult to get help

frank stirrup
#

Please , i need some help at CPTS Footprinting Lab - Medium
I have connected with success to the rpd session , and have found creds for the sa users , but when but login in with the creds keep failing , i also tried Adminstrator.

acoustic owl
frank stirrup
acoustic owl
fast arrow
#

Hi this problem still exists, I've rebooted the VM's several times and always get this error with the command provided in the walk-through

ocean night
#

That is a Tier 2 module, please do not share specifics pertaining to the solution.

#

Reach out to support if you believe the module is in fault.

fast arrow
#

noted thanks

outer tendon
#

i cant seem to connect to htb-student with ssh in linux fundamentals

fast arrow
ocean night
#

Please feel free to feed back to us in #1234357888114364508 - this goes direct to the team 🙂 Glad you found out the problem

sour silo
#

What credentials does Bob use with WinSCP to connect to the file server? (Format: username:password, Case-Sensitive)

wild oriole
#

Hey guys,
Is anyone facing an issue with the Transferring files module? The Windows section / the assessment server is not up, I tried to change to different VPN locations, restarting/terminating/ all with same results,

From 10.10.14.1 icmp_seq=3 Destination Host Unreachable

acoustic owl
#

Not every host responds to a ping

prisma basin
#

Hi

I am on the footprinting module and in the Oraclt TNS part. I am trying sqlplus on the parrot in the browser. But somehow its giving me some library issue. Anyone got it running ???

Here is the error

┌─[us-academy-4]─[10.10.15.63]─[htb-ac-1314953@htb-cthadzwjwo]─[/tmp/instantclient_23_7]
└──╼ [★]$ ./sqlplus 
./sqlplus: error while loading shared libraries: libsqlplus.so: cannot open shared object file: No such file or directory
┌─[us-academy-4]─[10.10.15.63]─[htb-ac-1314953@htb-cthadzwjwo]─[/tmp/instantclient_23_7]
└──╼ [★]$ export LD_LIBRARY_PATH=($pwd):$LD_LIBRARY_PATH
┌─[us-academy-4]─[10.10.15.63]─[htb-ac-1314953@htb-cthadzwjwo]─[/tmp/instantclient_23_7]
└──╼ [★]$ ./sqlplus 
./sqlplus: error while loading shared libraries: libclntsh.so.23.1: cannot open shared object file: No such file or directory
┌─[us-academy-4]─[10.10.15.63]─[htb-ac-1314953@htb-cthadzwjwo]─[/tmp/instantclient_23_7]
└──╼ [★]$ ```
pliant sage
#

Hello I am currently trying to tackle the injection attacks path. In the XPath part, blind injection I'm trying to do the assessment. I'm trying to automate the exfiltration process, however the string that lets us know whether the injection was successful or not is in script tags and for some reason doesn't appear when I issue the request via curl/python requests. I don't really understand how to fix this problem and I was wondering if anyone might be able to help em out with this

wooden canopy
#

Hello,
I'm currently doing the Pass the ticket on Linux inside the Password Attack Module. I,M stuck on the svc_workstations method. I found the kt file transfert into Rubeus to get a kirbi file then ticketConverter to ger a ccache file but can't use it to logged with it because it ask me a Password... could a get help pls

opaque cosmos
#

83.136.251.141:59272 Try using request repeating to be able to quickly test commands. With that, try looking for the other flag.
It's not in the same directory! using zap proxy after ;ls; HTTP/1.1 200 OK
X-Powered-By: Express
Date: Sun, 23 Mar 2025 12:35:28 GMT
Connection: keep-alive
content-length: 68 flag.txt
index.html
node_modules
package-lock.json
public
server.js unable to get the flag the flag.txt is the flag already got but where is the other flag i am confused (module using web proxies , repeating requests )

terse sage
#

stuck at the same point, even the db user is unclear for me. Contents of the user.txt, this one i got.

astral egret
#

can anyone help with this shit

#

the commands are executed but i don't get no response

wild oriole
astral egret
#

and when i used invoke-SMBExec

#

it said success but i didnt get a reverce shell

acoustic owl
wild oriole
fathom pendant
tender trellis
#

Hello! I am unable to make pgtunnel-ng work in the pivoting module of CPTS. The traffict doesnt seem to arrive to the final machine (172.. DC) may i get some help? I could make it work with chisel but i wonder if the pgtunnle tool is simply not working properly or it was me

ocean night
#

@astral egret that is a Tier 1 module, please do not post specifics for modules over Tier 0

#

Ask in a way that does not involve specifics, but states which module / section you are in, and the trouble you are having.

quiet trout
ocean night
#

No need to use that language. Read up, and see how others ask.

astral egret
#

didnt really help

ocean night
#

Which module, which section, which question, ask if someone can give you a nudge

#

That's how you do it

astral egret
#

Password Attacks - Pass the Hash (PtH)

  • Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt. give me a nudge
cloud urchin
#

what are you stuck on

astral egret
#

i have no idea how to explain it to you wihtout screen shots

#

but im stuck and dont know how to access the shared directory or file

#

when i execute a command it executes sucessfully but does not give me an answer it just excutes

cloud urchin
#

you pass david's hash, with it you should have the right access to read the david.txt file

astral egret
#

no shit man

#

im asking how

#

cuz i tried the module way idk what im doing wrong

cloud urchin
#

you've essentially simply said you're stuck on the question but you didn't provide info on what part you're stuck on, for all i know you're stuck on establishing an RDP connection to the target

hardy sundial
#

anyone knows in "introduction to windows command line" "Skill Assestment part 3" what kind of flag should i find, it says only "If you search and find the name of this host, you will find the flag for user2."But ive tried "hostname" "systeminfo" "Get-ComputerInfo" and i dont see anytging related with a flag. Even the hint just say ||systeminfo||
https://academy.hackthebox.com/module/167/section/1633

ocean night
#

If anyone can help give them some advice in DM, that'd be great.

#

But yeah.. trying to keep things to the rules RE spoilers.

cloud urchin
dim bloom
#

Hello everyone, I'm working on the AD Enumeration & Attacks module, and I'm currently on the Privileged Access section.
To answer the questions, I need to connect from the MS01 machine using SSH to a Linux host. I used the provided credentials, but nothing seems to work (I just can't access it).

fathom pendant
#

it's not formatted like HTB{}

naive parrot
#

and I'm putting the same nmap command but on my machine using the vpn I don't get the banner but on the web instance I do

#

anyone knows why ?

fathom pendant
#

also try using a udp scan to check it

naive parrot
#

I think I'm using the recommended one so the udp

fathom pendant
#

nmap -sU <target>

#

generally you don't wanna throw -p- with -sU

naive parrot
#

yeah trust me I went to the forum

#

tried every possible options on the nmap

#

got no banner and first try using the web instance got so much stuff

#

but it's fine as long it's not me being wrong and it's the machine I'm happy

compact vessel
#

Hey guys, I wonder if there is a path or module towards IoT. I found a few references in the search, but no real modules.

sand rose
#

Hello guys, I hope all of ou guys are well. I'm having issues with Information Gathering: Web Edition.

For the vhost enumeration, gobuster keeps coming up empty. The command I use is the following (which I hope it ok to share the command since it's not working for me anyway):
gobuster vhost -u <ip>:port -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain

This comes up with nothing found. Am I missing something?

safe star
#

youre not supposed to use the ip

sand rose
#

I get an error when I try the vhost given (the same error is there with my /etc/hosts file updated or not)

safe star
#

did you add the port

fathom pendant
#

without specifying a domain, append-domain doesn't know what you want the domain to be, even if it's in your hosts file, it's assuming the domain is in the -u

raven scarab
#

Anyone in here know bin reverse engineering? I have an .exe I am debugging with Olly. Its set to listen on a port and then take an input, but I am not very experienced in this realm and am not sure how to trigger a connection event when running the exe locally

raven scarab
#

Oh perfect, thank you!

sand rose
fathom pendant
#

the hosts file should not contain the port; only ip vhost

sand rose
#

the host file only contains the ip.

fathom pendant
#

also the reason it says url not set is because it's taking -u as the argument for --domain

#

--domain requires an input to work properly

sand rose
#

Without the -u it still says url not found... do i still need -u and the ip address?

compact vessel
#

I just tried to replicate the task. when you have only the ip adress in your /etc/hosts file, the only thing you need to do is swap the port in your command with the port you get when spawning the target. Otherwise you can copy paste the command as it is given.

sand rose
#

did you need the vhost name?

fathom pendant
#

and --domain you should have inlanefreight.htb after it

#

directly after it

sand rose
compact vessel
fathom pendant
fathom pendant
#

most of the labs aren't running https

compact vessel
#

muscle memory

sand rose
#

Ah ok. I just had to step away from my computer so I'll try that when I get back home here in 10. Thank you guys!

tender trellis
#

Anyone i can ask about the pivoting module? got couple cuestions.. thx

safe star
#

just ask them

sand rose
#

@fathom pendant @compact vessel I got it working properly. Thank you.

fair cove
#

Hey peeps. Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt. On Password Attacks , pash the hash. I cant do it with anything. It tells me It cant find it or I have the wrong creds

cloud urchin
tender trellis
#

In the socksoverRDP section, why wasnt i able to log as jason? in the hint it says its a local account. Any explanation about this please?

#

after couple times i could log as jason but i dont understand the reason of this at all

fair cove
fair cove
cloud urchin
#

You can DM me if you want

sly sorrel
#

is htb a science of cryptography?

burnt hill
#

Hi everybody, I am on Infiltrating Windows section on Shells & Payloads module "https://academy.hackthebox.com/module/115/section/1109" I am on the last question "Gain a shell on the vulnerable target, then submit the contents of the flag.txt file that can be found in C:". Everything indicates that I need to use Eternalblue to gain a shell, but every time I run the exploit with msf it doesn't creates the session, can anyone tell me if I am doing something wrong or maybe I am not on the correct path to find the solution?

indigo fulcrum
#

Anyone avaialble to help me with an issue with a section

#

seems to be some dns related problems when using a box...

burnt hill
burnt hill
indigo fulcrum
#

👍

lusty thicket
indigo fulcrum
#

Figured it out, which is kinda crazy as I used this method before and it didnt work 😦 anyhow - circled back and iot worked.

cloud urchin
gilded radish
#

How to do triple proxy with chisel, do somebody know an article maybe?

#

Attacker -> Pivot 1 -> Pivot 2 -> Target

#

I really don't understand the logic with chisel

proud pine
gilded radish
rustic sage
#

the same is also possible with ligolo

#

automatic port forwarding

#

use what ever you want its personal preference

waxen totem
#

but yeah I get what you're going at

#

Still use Chisel to be able to do it manually

waxen mesa
#

Hey does anyone know the format for this answer on pentest in a nutshell module

gilded radish
#

yeah, I managed to forward it with chisel

gilded radish
waxen mesa
#

I already have the file open

#

I copied and paste but it says it’s incorrect maybe I should try again perhaps?

vast creek
#

Can HTML smuggling be used to inject a reverse shell into the server using Burp Suite? I’m currently working on solving Season 7 HTB (code), but I’m considering dropping the HTML smuggling approach since it’s client-side and focusing on other findings instead.

fair plinth
#

Im working on the password cracking module, and got the NTDS.dit, but I cant figure out the next step to dumping the hashes from it. So i used netexec for the dump through smg with the --ntds tag. What step am i missing for just dumping it through the NTDS.dit file?

waxen mesa
#

I already have the file it’s just i can’t get the answer correct when I paste it

waxen totem
waxen mesa
#

Sorry man

unique spruce
#

hey im on the information gathering module and im on the subdomain bruteforcing secton and theres like a bunch of subdomains so which one am i supposed to use?

unique spruce
#

bro what

waxen totem
#

You need to filter out your scan

unique spruce
#

do its a dnsenum

waxen totem
#

Oh that one

unique spruce
#

yes bro

waxen totem
#

yeah just try em one by one

unique spruce
#

i did none of them work

#

do i need the www infront of it for it to work?

waxen totem
#

no...

#

www IS a subdomain

#

they listed out which ones to exclude

unique spruce
#

theres only like 2 that arent them and they both dont work

#

the only ones being my does not work

waxen mesa
#

Why do I keep getting this incorrect tho???

waxen totem
unique spruce
#

the only one i dont see, and i tried the rest

fair plinth
#

What subdomain is it asking for? Also you may need to find the subdomain of a subdomain

waxen mesa
#

Here is the log file contents

waxen totem
#

Ok yeah that should be the right answer

#

try refreshing your cache kek

unique spruce
#

bro how tf am i getting it wrong 😭

waxen mesa
#

Who him or me ?

unique spruce
#

how bro 😭

waxen totem
#

ohh

#

the . at the end

#

💀

unique spruce
#

oh my god

waxen mesa
#

Lmao 😂

unique spruce
#

it literally lists the answer in the question w a dot at the end

waxen totem
#

It's the end of the sentence

unique spruce
#

oh

waxen totem
#

go post in #1234357888114364508 that it should probably be (www.inlanefreight.com) as to remove confusion (with the parenthesis around)

uneven niche
#

Would someone mind telling me how to submit module feedback?

uneven niche
#

lol it's right above my message mb

ocean night
#

Generally that is for corrections, but feedback I imagine would also be accepted there

#

Yeah

#

😄

uneven niche
#

Thank you!

fickle sparrow
#

need some tips on session security... if someone can send me a msg plz on private

fickle sparrow
#

i am about to shoot my pc with this skill assessment...

cloud sinew
#

I'm doing RDP and SOCKS Tunneling with SocksOverRDP module in the Pivoting, Tunneling, and Port forwarding course. I'm following all directions according to this module, but the issue is that I can't run C:\Users\htb-student\Desktop\SocksOverRDP-x64> regsvr32.exe SocksOverRDP-Plugin.dll Because the dll keeps deleting itself off the system within a few seconds. I've already gone into the Windows Security Settings and disabled what I could. Any tips would be appreciated because after dealing with the ptunnel module where the ubuntu host glibc was outdated and I just had to use Chisel to get the flag, this is incredibly frustrating.

cloud urchin
cloud sinew
cloud urchin
#

yeah defender

cloud sinew
#

Everything I'm seeing shows everything turned off

#

I'm under Virus and Threat Protection in Windows Security Settings

cloud urchin
#

yeah go to Manage settings under Virus & threat protection settings