#modules

1 messages · Page 403 of 1

cloud sinew
#

Yeah it's turned off

#

should I try resetting the target IP?

#

Wait I just did it the command through PowerShell to disable it and now it's not being removed. But it showed that it was already turned off when I checked it a bit ago. That's odd.

wise birch
#

Holy hell

#

Has anyone done the nmap

#

Pentesting route

#

On attacking services

#

I’ve been stuck in question 3 for an hour

#

I though you just
smbclient -L -N \\<myIP>

#

Just keep getting an error

#

How am I supposed to know bobs password wtf

#

Bruh the password is given in the beginning the module

#

I thought I was supposed to find it

#

An hour down the drain

lusty thicket
wise birch
#

How come when I type it in it doesn’t do anything

wise birch
#

Just says login failure when I type th password

bright pivot
#

lyze the event with ID 4624, that took place on 8/3/2022 at 10:23:25. Conduct a similar investigation as outlined in this section and provide the name of the executable responsible for the modification of the auditing settings as your answer. Answer format: T_W_____.exe
after i found the event is services.exe the answer?

#

Windows Event Logs & Finding Evil mini-module badge

unique spruce
#

hey im on the information gathering web edition virtual hosts but im stuck i ran the following command gobuster -u http://<IP>(i am confused because should i be using the target ip or the inlanefreight.htb but nontheless i tried both and the latter gave me and error) -w /opt/useful/seclists/Discovery/DNS/subdomains-top1million.txt --apend-domain

#

did not work and i spent 10 minutes waiting getting a blank result

#

anyone got any tips?

lusty thicket
wise birch
#

Holy hell something is wrong with that virtual machine 😭😭

#

I had to put in the password 5 times before it worked

#

Then I restarted it to see if it was me

#

And it took 5 errors again

#

Then I tried it again and same thing

#

Fix that shit mods

waxen totem
wise birch
#

It took me 3 hours to figure out I had to spam tf out of the password

#

Bruh I should of just moved on

waxen totem
wise birch
#

Yeah I was

#

Should I do tcp?

waxen totem
#

Yeah might've been dropping packets

waxen totem
#

But is more reliable

wise birch
#

Oh

#

Ohhhhhh

#

I’ll give it a try next time

#

Or maybe a different server

#

Thanks bro

waxen totem
#

Also discord mods or Community contribs arent staff so no access to the modules

wise birch
#

I know to try that next time 😭

#

Oooh

#

Welp thanks bro

unique spruce
#

I did bro

waxen totem
unique spruce
#

Too late I gave up and I’m doing to bed 😭

wise birch
#

Never give up

#

Never surrender

fading skiff
#

xD

storm elk
#

In the settings section? 🤣

fading skiff
#

lol

#

i have to create a exploit but i dont know how i mean i just learned for windows not for web

#

can someone explain to me pls

storm elk
#

Use msfconsole

fading skiff
#

i know i have to use msfconsole

#

but idk how to set config

storm elk
#

show options will show you all the available settings to configure

#

The flag is at the location mentioned in the question

fading skiff
#

yeah but i have to go useless school for learning german

#

byee

storm elk
#

See you later 🙂

warped dagger
#

OMG, dude thanks a lot for this! Can someone from HTB team please fix this?

cloud urchin
#

It's just a windows thing, but you can make a post in #1234357888114364508 if you think something needs to be fixed.

plain cosmos
#

Hi anyone willing to help/disccuss with me for - dacl attack 2 - skill assessment question 1
i know what attack to perform, but after all the process i still cannot access the flag, i'm doing it in windows machine provided.

Update
Manage to get it with linux, but still curious why failed using windows, if someone able to perform from windows could we have discussion, thanks.

keen fiber
#

Hi all, I'm on the "Shells & Payloads" module. I have a question to the "Bind Shell" section. In the command to initiate the bind shell on the target machine, the IP of the target is used in the nc call: "rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc -l 10.129.41.200 7777 > /tmp/f" . Why is this needed or beneficial? I tried in the section with and without the IP and both works. Any insight would be highly appreciated!

waxen totem
#

you can specify an ip to listen on a specific interface

keen fiber
digital jolt
#

anyone good at reverse engineering? i have question.

fathom pendant
fickle sparrow
#

i got it, with the pwnbox. i guess the vpn is ass

faint wagon
#

hey guys, I was connecting to victim machine using chisel as said in the pivoting, tunneling module

#

I am facing this error when I try to connect client pivot host to server attacker machine

#

./chisel: /lib/x86_64-linux-gnu/libc.so.6: version GLIBC_2.32' not found (required by ./chisel)

fathom pendant
tender nimbus
#

Hey guys who has the same problem on the AI path?

gray yacht
vapid prawn
#

Is it possible to pass the first question of the "Attack Tuning" section from "sqlmap Essentials" without creating a tamper?

#

I tried hard to get it without the tamper, but I couldn't

slate palm
#

Please help me 😦 I am so stuck on this Skills Assessment of Information Gathering - Web Edition.
Description: What is the API key in the hidden admin directory that you have discovered on the target system?
Steps:
I have been facing "Error: error on running gobuster: bufio.Scanner: token too long" from the subdomains-top1million-110000.txt but I might have solve it with awk 'length($0) < 64000' subdomains-top1million-110000.txt > filtered_wordlist.txt
but then I just cant find the Status: 200 OK after doing the scanning 😦
p/s: I did add the ip in /etc/hosts and I am connecting to the htb vpn too. Despite working on a Kali Linux virtual machine, I think the open vpn is still working fine.

proud pine
slate palm
#

this is my second attemps with no 200 OK found 😦

dry falcon
#

what are the rewards specified in last line?

proud pine
slate palm
slate palm
shut vapor
acoustic owl
alpine ingot
#

Is the "Footprinting Lab - Hard" skill assessment supposed to take hours to scan? i lowered the type of scan to something less comprehensive, am using the -A aggressive nmap flag, and its still taking forever.

undone mesa
#

Footprinting IPMI module - Im using pwnbox and i wanna know if its normal that hashcat take so long for a simple module exercice ?

fading olive
fading olive
undone mesa
fading olive
undone mesa
alpine ingot
# undone mesa it was way faster ty brother 😅

its the standard for CTF challenges to take like less than 10 minutes with the rockyou.txt wordlist when bruteforcing anything. If it takes longer, brute forcing is probably not the way to go.

wet glen
#

Guys can someone help me, i was doing the "Protected FIles" module of "Password Attacks" and the question asks: "Use the cracked password of the user Kira and log in to the host and crack the "id_rsa" SSH key. Then, submit the password for the SSH key as the answer."

But where should I get the password for Kira? Like do i need to bruteforce ftp or ssh with rockyou? (passoword.list don't have it)

gray yacht
inner sand
#

Guys I am helping cybersecurity student to get into cybersecurity, I gave them this advice, and everytime I do, I feel like they become repulsive off me, is there anything wrong with my advice ?

First of all, your entire journey is going to be based on a question mentality

Secondly, for technicals, your curiosity in understanding a specific topic would highlight u between your colleagues, whether in uni or work inshallah, start with these three

  1. Python : Explore the syntax thru the documentation + do codeceafters and learn how to automate network requests and file i/o, then finish the first 5 to 10 projects here : https://github.com/kurogai/100-redteam-projects
  2. Learn linux thru practice, learn about wsl and Linux basic administration, and how can you adapt only a cli environment, but it would be better if you can install it alongside windows, and for 1 hour a day experiment with it and try to do all various tasks, youtube and hackthebox academy have pretty good resources
  3. Last thing, a good field you can start in is web security, go to portswigger, It contains labs and verbal explanations in all various topics in web security / attacks ( with uni account, u can have an 8 dollars subscription on htb academy, I do really recommend it, the penetration tester path is verrryyyyy educative )

The last message is that researching Google is going to be your friend along the way, in everything, and question everything you face and try to understand the "why" and the "how"

Htb academy : https://academy.hackthebox.com/

Portswigger : https://portswigger.net/web-security

Install wsl on your windows before u start in Linux: https://youtu.be/AfVH54edAHU?si=RvW9cUe1ktvwKu-U

For linux, this guy is very beginner friendly : https://youtube.com/playlist?list=PLIhvC56v63IJIujb5cyE13oLuyORZpdkL&si=vQyrUnmvjJv-MDSA

lusty thicket
tender nimbus
#

Hey guys I have this problem with the skills assesment of the prompt injection modeule, can anyone help?

#

It's on the pwnbox btw

icy grotto
#

Hello! Currently in password attacks shadow passwd and opasswd section. I transfered the .bak files then combined then into a tmp/unshadow file and unshadowed them i think using the command in the module. I've been trying to use john and hashcat to crack them with the mutated_password. But hashcat gives a token exception 55/55 and john gives a wrong password. I was trying formatting md5 but that didn't work either. Don't know how else to go about it. Besides maybe a wrong file download

lusty thicket
#

and the title says "urgent: your future depends on this" 😭🙏

gray yacht
analog wolf
#

Anyone here did the Cat room, kinda stuck in the last step

gray yacht
icy grotto
#

I figured it out. I wasn't paying attention and just copying commands not realized for some reason when I tried to unshadow the pass hash would dissappear but it showed up if I sudo and John the downloaded .bak file Luckily I was able to be allowed to crack that file instead. But I don't know why that works I assumed I'd have to unshadow them both.

lusty thicket
#

that makes sense as the shadow file is only readable by root

fresh wedge
#

Pass the Ticket (PtT) from Linux Which group can connect to LINUX01? When i david@inlanefreight.htb@linux01:~$ id
uid=647401107(david@inlanefreight.htb) gid=647400513(domain users@inlanefreight.htb) groups=647400513(domain users@inlanefreight.htb)

i enger the goup name for the question and its not working. Can someone help?

gray yacht
fresh wedge
#

found it same proces different user group was found

acoustic thorn
#

Experiencing difficulty continuing with logrotate section of linux priv esc. Repeatedly encountering a resource dependency error: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./logrotten.1). Is there a way to still execute the payload without sudo to install the missing dependency?

fathom pendant
#

you have to bear in mind that the GLIBC version on a machine may differ from what you have on your own machine

acoustic thorn
#

For whatever reason I get a whole slew of unexpected errors attempting to compile on the target. I should also add that I compiled on the pwnbox which I figured would have a similar configuration to the target

fathom pendant
#

why would it have similar config to a target? it's an up-to-date attack vm

#

the pwnbox is just a hosted parrot VM that you can use instead of your own

acoustic thorn
#

Regardless if I cannot compile on the target or modify the packages is there alterative course of action?

fathom pendant
#

statically compile

#

gcc has the --static flag

acoustic thorn
#

I will try that thanks

#

What is the technical difference between static comp and the 'regular' method

fathom pendant
#

static compilation basically packages the required libraries with it

#

instead of relying on the library to be on the machine

acoustic thorn
#

Ah that's good to know, will probably save me more than a few headaches in the future. Ill give it a go

acoustic thorn
fathom pendant
#

is the id_rsa formatted properly?

#

it requires the ---BEGIN and ---END lines

#

always make sure with stuff like md5sum and stuff like that to make sure the checksums work out

#

it also helps to provide the module and section name

#

also: it's -p for port

#

not -P

dim wedge
#

hello, can anyone help me with the last question What is the flag contained within flag.txt in the skill assessment of login brute forcing module? i found out the name is T... but i dont know how i go from there

gray yacht
dim wedge
#

i build custom wordlists with cuppy and username ananrchy but i dont know even what the service is

#

ssh doenst rquire password so it doenst work and there is no ftp server?

gray yacht
dim wedge
gray yacht
nova geyser
#

Hello all. I am having problems with Active Directory Enumeration & Attacks Room, specifically with DCSync Lab. The lab keeps disconnecting seconds after I succesfully RDP. I don't know what it could be, I switched VPN file, I restarted lab uncountable times. This is getting my nerves and I am thinking on cancelling my subscription because of this problem.

#

I've even tried with HTB VM, but the same problem, after few seconds or minutes it keeps disconnecting RDP with errors

#

So I think it's a problem with the lab.

balmy steeple
#

in the gettin started final of the pentest path where you test your knowledge there is a upload file option in the admin portal which doesnt work when i press this. is it supposed to not work and i need to find another way or is it a glitch?

leaden island
#

yo guys

#

im stuck on IPMI enum

round parrot
#

I got problems with using proxychains and chisel. It's the crackmapexec lab. After chaing the proxychains.conf to socks5 1080. Then setting up the reverse server on pwnbox and client on the ws01 they connect. But using proxychains crackmapexec smb 172.16.1.10 -u - p --shares and looking at the verbose output it says no route to host and failes. I can't figure out the problem. I have used proxychains and chisel before and I'm doing exactly as I use to (i think)

leaden island
#

im doing the hashing correctly but my pc is bad (using 5th gen i5 to crack the hash)

#

can someone dm me the hash to move on

#

the plain text*

vapid prawn
safe star
proud pine
leaden island
#

I forgot that option

#

When pwnbox is faster than my actual laptop...

fossil jacinth
#

@round parrot make sure that the IP you are specifying in your command is actually reachable and smb is open there

round parrot
fossil jacinth
#

proxychains evil-winrm works ?

leaden island
#

How can i copy my hash to pwnbox ?

#

direct copy and paste not working

fossil jacinth
#

echo 'HashValueHere' > hash.txt

round parrot
#

Nope, I can reach ws without proxychains, so I used evilwinrm and from ws01 I could use net view on dc01

leaden island
#

Also cant connect to it directly from my host to send something

round parrot
#

And see the share

paper basalt
#

Any Skills Assessment - File Upload Attacks chads? Can't even access flower.jpg (I have leaked upload.php using XXE and gotten the directory and naming scheme)

proud pine
fossil jacinth
#

Something might be wrong with your proxychains/chisel setup there @round parrot

round parrot
#

Yep but even following the exempel it doesn't work. I got the connected on chisel. Changed the proxuconf to socks5 and 1080. So I can't really figure out what it is

paper basalt
#

okay curl instead of burp worked

leaden island
#

Pwnbox hashes 2.5x times faster than my laptop (using linux as a main, not vm)...

fossil jacinth
#

Granted I haven't done that module just yet. Did you comment out the socks4 in the conf ?

indigo mirage
#

hi could you help me with this question :

round parrot
#

Yep, even changed the 4 to 5.. still... I guess it's a reset somewhere

fossil jacinth
#

Hmm

nova geyser
#

Changing the Browser to a chromium based, and using Pwnbox I'm able to keep working on DCSync. The only solution I found...

fair cove
#

Can anyone help me with Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt. Password attacks, pash the hash

fossil jacinth
#

@fair cove isn't that attack explained in detail in the module itself ?

fair cove
fossil jacinth
#

DM if you wanna talk specifics

leaden island
#

I double checked the hash format on hashcat examples and everything is right

#

Ok my bad

still mica
leaden island
#

I mistakely copied the one from hashcat examples into hashcat

#

Braaah

#

Its taking a lot of time too

eternal current
#

Can someone help me solve this question from the Footprinting module on the DNS page:
What is the FQDN of the host where the last octet ends with "x.x.x.203"?

fossil jacinth
#

You need some subdomain enumeration if I remember correctly @eternal current

safe star
leaden island
#

I blindly followed the module and chose to crack it with

#

Computational power ?

#

I mean hashing lol

eternal current
fossil jacinth
#

What does dig any 'Target' @'IP' give you ? @eternal current

#

What about the zone transfer - axfr ... Go from there

#

Maybe try different wordlists too.

cyan arch
#

is there any way to connect to the terminal using my own when doing modules? Using the built in one slows me down quite a bit?
im on mac tho idk if thats an issu

quiet trout
#

yes use the vpn from your kali or whatever

#

no problem there install openssh (it might be on there already) download the vpn file and connect

cyan arch
#

Okay, so if I use openssh I can connect from that?

#

How come normal ssh doesn’t work?

quiet trout
#

"yes" but you need to connect from your testing environment

#

connecting from a mac box without like... any tooling is not gonna get you where you wanna be. prob best to setup a kali environment

#

kali vm i mean... same thing

cyan arch
#

So I need to use a vm tool for that?

#

To create a kali vm then openssh from that into the environment?

#

Basically what I’m trying to get at is that currently it’s really annoying having to read all the text etc and be scrolling up and down to answer the questions

#

To be able to see the instance

#

Idk if there’s some way to pop out the instance maybe?

proud pine
cyan arch
#

Okay I see, let’s say for example I was running my PC on a Linux OS, could I just do everything on my own pc then?

proud pine
cyan arch
#

Ahh okay I see

cyan arch
#

From the HTB instance

proud pine
cyan arch
#

Like currently the only way to access onto that instance is to be scrolling up and down until I see the box for it

#

So like go have it in a new window on another monitor

#

Whilst being able to scroll up and down the read the questions and text

proud pine
cyan arch
#

Oh okay I’ll have a look next time I’m on it thanks

#

In the real world do people use VMs for their pentesting?

#

Like they will never use their own machine?

proud pine
# cyan arch Like they will never use their own machine?

Pentesting distros are not safe to use baremetal. They are not built for stability, they have to include tons of outdated packages (as some old tools require them), and using it as a daily driver would be dangerous, due to all the tools that would be available, if the machine was compromised at all.

#

VMs also make it easy to take snapshots, so you can have an environment that is always the same for reproduction.

cyan arch
#

Okay I see

rustic sage
#

i need help at: Kerberoasting - from Linux
Ad enumeration and attacks

https://academy.hackthebox.com/module/143/section/1274

i use this command : GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend

and just give the pass (known from one part of previous part) || Klmcargo2 || which is not even a spoiler its mentioned somewhere in the module. But it says incorrect credentials. how to solve this now

dark hedge
#

just a little tip, you can put the password in your command
GetUserSPNs.py -dc-ip 172.16.5.5 inlanefreight.local/forend:password

gleaming bobcat
#

can I get some help with https://academy.hackthebox.com/module/296/section/3394, I cannot seem to download wpscan on kali linux, and even when using the instance and the exact command used earlier in the demonstration, wpscan -e p --url https://10.129.12.10 --disable-tls-checks --no-banner --plugins-detection passive -t 100 (the ip address changed to the target) the instance terminal gets stuck with the message [i] Updating the Database ... until it eventually times out

cloud urchin
#

wpscan comes with kali

gleaming bobcat
cloud urchin
#

weird, did you download the smaller version? they do have different versions with various tools. it sounds like you have it because you say the command updates the database

gleaming bobcat
cloud urchin
#

that's parrotos, not kali

gleaming bobcat
#

I've been trying it with an openvpn connection using kali, and with the daily instance

cloud urchin
#

make sure you can get online then wpscan should be able to update

gleaming bobcat
#

what do you mean by get online?

cloud urchin
#

make sure your kali box is connected to the internet

#

if wpscan is timing out updating the database i assume it can't reach the servers, so it's some kind of network issue

gleaming bobcat
#

well, the updating database error occurs when I use the parrot terminal on htb, I'm pretty sure the command is right, on kali sudo apt install wpscan results in tons of errors that seem like failures to install the necessary dependencies

#

here is the parrot terminal error after timeout

cloud urchin
#

the pwnbox has limited Internet connectivity unless you have made a purchase i think

gleaming bobcat
cloud urchin
#

your original statement said kali, which is not the pwnbox

gleaming bobcat
#

my bad, I started with kali then said the instance in place of parrot

cloud urchin
#

have you spent money on the site?

gleaming bobcat
#

no

cloud urchin
#

that's why. the pwnbox is limited

#

try --no-update as an argument maybe that'll work

#

Just ask your question here if it's about modules

gleaming bobcat
#

Scan Aborted: Update required, you can not run a scan if a database file is missing.

cloud urchin
gleaming bobcat
#

that might be the issue, I used the instance because openvpn was failing

cloud urchin
#

they share the same IP so you can only use one at a time

gleaming bobcat
#

got it, seems my openvpn has been off so that can't be the issue

cloud urchin
#

well you know why the pwnbox is failing, so you'd have to switch to your kali box on vpn

#

or spend money on the site

#

I have no idea you'd have to reach out to support on the website

gleaming bobcat
novel hinge
#

anyone have issues installing sqlcmd?

im on Attacking SQL Databases module

#

tried sudo apt install sqlcmd as well :()

cloud urchin
#

sqlcmd is a Windows command

novel hinge
#

omg im so out of it thank you

devout spruce
#

Hi is there anyone that can help me with the RDP and SOCKS Tunneling with SocksOverRDP section in the Pivoting, Tunneling, and Port Forwarding module? I've gotten to the point where I needed to connect to the Windows server at 172.16.6.155 with jasons credentials as instructed in the question, but whenever I try to connect through Remote Desktop it immediately closes my connection, saying it was lost due to network connectivity problems. I've already loaded SocksOverRDP.dll and configured Proxifier properly. I've also restarted the box as well incase that was the issue but it wasn't. Any help would be greatly appreciated.

cloud urchin
devout spruce
#

Ah nvm, figured out the issue. Had to set the performance to modem in the experience tab. Didn't think about that lol. Thanks for the help though.

fervent lantern
#

Hello, do you know that in the JavaScript deobfuscation module, the source code section already has the flag, but it doesn't accept it as valid?

#

I already solved it xD

fathom pendant
rustic sage
#

but why ?

dark hedge
#

maybe because you were inputting the password incorrectly

rustic sage
stoic fern
#

Hi I want some newbiees fir my teams 0 experience member for my ctf team those who want participate join my team

Htb ctf

dark hedge
#

you can also paste the password when it prompts for it

rustic sage
#

Thank you !

stoic fern
#

Ok

#

Hi I got one more problems

#

I can't type msg general and # no access

dark hedge
signal pike
#

How much would a bloodhound scan differ when we gather the data from a user with default privileges vs a user with more privileges, like an admin.

novel hinge
#

anyone know why impacket-smbserver isnt pulling netntlmv2 hash?

stoic fern
cloud urchin
fathom pendant
#

:)

novel hinge
#

omg

#

thank you! i took like a 4month hiatus from this and its not clicking yet. thank you for the push 🙂

signal pike
lusty thicket
signal pike
#

No

#

I'm doing cape path and kerberos module

#

I was just curious

lusty thicket
#

you'll see users, groups and a few machines on a low priv user, but none of the juicy stuff like who's logged in where or what acls you can abuse

#

you migh scrape together a kerberoast target if you're lucky

signal pike
#

Hmm I get it, thanks a lot man

thin parrot
#

The wayback machine section seems softlocked

#

The archives for the questions no longer exist

#

Literally the only accessible archive left is Feb 10 2020 which displays nothing

#

The wayback machine shows entries but literally none can be pulled up

#

The records must have been erased during that whole incident a few months ago :/

cloud urchin
#

module section and question?

thin parrot
#

Information Gathering - Web Edition -> Web Archives

#

" How many Pen Testing Labs did HackTheBox have on the 8th August 2018? Answer with an integer, eg 1234."

And related

#

I'm seeing a 302 redirect that seems to loop indefinitely

cloud urchin
#

it seems to me working for me

#

always know your target, htb is not an american company

thin parrot
#

I have no idea what you're doing but every archive for "hackthebox.com" is not pulling up for me

waxen totem
#

works for me too

native crow
#

anyone else having massive lag issus, Active directory skillls assessment is not doable, all connections keep timing out, on several vpns now

cloud urchin
#

Try changing regions, or read the VPN guide which has some great tips

native crow
#

they all have medium load too , even the less used one, yeh I have i've trtied them all

thin parrot
#

Is the specific date August 8 2018 working because recent archives are showing up for me, just not the ones needed for the question.

waxen totem
#

Just realized there's even a hint of it in the module

#

@thin parrot

#

look at the images

thin parrot
#

oh nvm

calm swan
#

hello,
can someone help me with a task in module network enumeration with nmap -> service enumeration.
I have a problem with the question: Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.

what I did:
I used service fast scan to get all open ports and their service versions:

Host is up (0.0089s latency).
Not shown: 94 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
110/tcp open pop3 Dovecot pop3d
139/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
143/tcp open imap Dovecot imapd (Ubuntu)
445/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
Service Info: Host: NIX-NMAP-DEFAULT; OS: Linux; CPE: cpe:/o:linux:linux_kernel

then I used the method described in the module:
sudo tcpdump -i tun0 host <local_ip> and <target_ip>
then
nc -nv <target_ip> <port>

then Im trying to get smth chaning the ports in nc but I cant get anything from it

can someone tell me what am I doing wrong or maybe I'm not look at the right place?

thin parrot
#

I think I may know which lab this was as I struggled on this one but without giving too much information (assuming I have this right) perhaps take a further look at what may relate to whats hosted on port 80?

waxen totem
#

1 by 1

calm swan
#

yes... am I blind or smth? haha

waxen totem
#

gimme 1 moment I can't remember exactly what I did to get this

#

have you tried enumerating ALL ports?

calm swan
#

gonna do it again

waxen totem
#

what's your nmap command looking like?

calm swan
#

sudo nmap -sV -Pn -p- -T4 <target_ip>

#

okay, nvm

#

I got the flag...

waxen totem
#

got it? kek

calm swan
#

I had to wait more like BRUUUUH

waxen totem
#

yeah I knew it was on an off beat port

calm swan
#

I mean, as I was talking here it was going and after 2 min it worked haha

#

but thx ❤️

waxen totem
#

yeah I usually do a fast port sweep scan then a script scan of all those ports

calm swan
#

btw @waxen totem, do you remember doing those Labs (SS)?
Is Hard Lab like H-A-R-D or "human level"?

waxen totem
#

IIRC it was human level FOR ME

#

only cos I put off academy for a while and actually was doing boxes kek

#

the only one I was stuck on was the medium lab cos my scan gave me false data sadge

calm swan
#

im wondering when should I start doing boxes

waxen totem
#

mate you hacker you already been doing boxes kek

calm swan
#

It was a year ago... forgot most of the things haha

native crow
#

Does anybody know if chisel works on Windows Server 2019? I tried the latest version and it was incompatible

waxen totem
proud pine
native crow
proud pine
waxen totem
#

Maybe its already on the machine in C:\tools

native crow
native crow
proud pine
#

Are you using the version from the pivoting module?

native crow
native crow
proud pine
#

Shouldn't have any issues like that, unless maybe there was corruption when you copied it over. Either way, the script I linked is just better than chisel in every way.

native crow
proud pine
proud pine
#

SSH for linux socks, and the script for windows

wooden seal
#

module (using crackmapexec) submodule {Searching for Accounts in Group Policy Objects}
whenever i try to do the practical questions getting this error
The NETBIOS connection with the remote host timed out.
tried restarting target machine

cloud urchin
wooden seal
dense tree
#

been struggling to connect via ssh in terminal. keep timing out.. just trying to do the linux fundamental mod

cloud urchin
#

can you ping the target

dense tree
#

seemed to be timing out as well

#

oi - just caught my mistake

outer osprey
#

hello can i please get some help with starting point meow task 6 (What service do we identify on port 23/tcp during our scans? ) thanks so much

dense tree
#

I was off by a digit

#

now we are on a roll - that held me up the whole time 🙂

unique ether
#

file inclusion assessment someone give me hint

#

ik the parameter is page

outer osprey
#

hello can i please get some help with starting point meow task 6 (What service do we identify on port 23/tcp during our scans? ) thanks so much

unique ether
#

ye

outer osprey
#

i was thinking port scan but it ends with t

unique ether
#

what

outer osprey
#

yeah

calm swan
outer osprey
calm swan
#

@outer osprey do you know what tool to use to scan ports?

unique ether
#

bro just service scan and see what results you get and remove the version number

outer osprey
#

n mapp is what i use

calm swan
unique ether
#

specify the port so its faster

calm swan
unique ether
#

yea thats why i dint tell him the options itself

#

lol

calm swan
#

@outer osprey got it?

unique ether
#

someone help me tho

outer osprey
#

tbh no

cloud urchin
#

You may need to follow the instructions in #welcome to access it

unique ether
#

file inclusion assessment i am stuck

#

i used directory methods and mixed with url encode

#

still i would get invalid input

#

i am guessing its filtering out ...// even after url encode i tried using php wrappers still dint work

cloud urchin
#

@outer osprey please don't spoil answers. also starting point discussion is in #starting-point , this channel is for modules on the Academy platform.

calm swan
#

@cloud urchin can I give him the command? he got the answer

cloud urchin
#

I'm sorry, what?

calm swan
cloud urchin
#

he needs to ask in the channel dedicated to starting point, but he got the answer already he said

cloud urchin
unique ether
#

is tlattice here bro need ur help fr im actually dying here

#

yea you can rdp from windows machine to other one

#

there is a windows pivot rdp method

tulip copper
#

but how would I know if rdp is allowed there in the first place?

unique ether
#

hmmm your asking if the other machines rdp service is open?

thin parrot
#

Could I get a bit of a hint on Information Gathering - Web Edition -> Skills Assesment -> "What is the API key in the hidden admin directory that you have discovered on the target system?"

I found the hidden admin directory, trying to access it returns permanent redirect. Not sure what to do from here

cloud urchin
#

@tulip copper please don't spoil content, you're revealing addresses and such of a skill assessment that people need to find.

unique ether
#

@tulip copper there is metasploit module using a pivot so scan the targets and find the target info

#

i cant recall properly but i remember doing something like this

tulip copper
#

I have to get meterpreter first on that windows_1 (first machine) and autoroute traffic through SOCKS

unique ether
#

yea now i remeber most likely when u try nmap through proxychains it will not give you a proper output you can use metasploit auxilary modules to find about the other machines on the network

tulip copper
#

I know that this skill assessment want you to get the port directly but I wanted to expand and run a scan from attacker host, I know I need to double pivot but how its my issue :/

unique ether
#

are u rdpd into windows 1?

tulip copper
#

yes and can reach windows_2

unique ether
#

did u rdp into windows 2

tulip copper
#

no

unique ether
#

do u have creds?

tulip copper
#

yes

unique ether
#

try rdp then

tulip copper
#

I got all the flags

thin parrot
#

Anyone..?

tulip copper
#

my concern is that in real engagement you wont be trying port by port

#

if I run commands from my box to the network of windows_2 it would be convient

unique ether
#

oh so instead of having windows 1 as ur pivot u want windows 2 as ur pivot?

#

well thats not possible

#

cause u need windows 1 to reach 2

waxen totem
#

You could do it actually through pivot

tulip copper
#

not really, now my pivot is linux machine, I want windows_1 to be pivot

waxen totem
#

Use ligolo or chisel to start a tunnel or a socks proxy

#

If you're using chisel you'll need proxychains setup

#

Also proxychains only works with TCP iirc

#

So using ligolo is much more preferred

tulip copper
#

from linux machine to windows_1?

waxen totem
#

Yeah setup ligolo and create a tunnel interface

#

Its almost like having a vpn

tulip copper
#

ohh ok I have to get familiaer with ligolo

unique ether
#

i got confused

#

mb

tulip copper
#

sorry no, I have the linux machine a spivot to get into network of windows_1

tulip copper
# unique ether breh i thought you had windows 1 as pivot cause u said this

I was thinking about using 2 dynamic port forwarding with ssh , dynamic port forwarding from my box to foothold linux machine. and access to that linux machine and use again dynamic port forwarding inside linux host (since windows_1 have ssh open) to access windows_2 network. But my issue is that linux machine doesnt have proxychains

unique ether
#

the page

unique ether
#

well you could copy over proxychains

#

using scp

tulip copper
#

I have to try this

unique ether
#

idk i havent done that

#

tho

tulip copper
#

I see double pivoting is not covered in this module nor ligolo

unique ether
#

yea

#

thats y i told u to rdp

#

from ur linux

#

after u scan the services and find the creds

tulip copper
#

are you talking about first creds?

unique ether
#

no im talking about the creds to rdp to windows

#

u prob need to find those

tulip copper
#

yes to lateral movement

unique ether
#

yes

tulip copper
#

thanks bro for assistance

thin parrot
#

Now ReconSpider is not working

#

Man they really need to make a second modules channel

waxen totem
#

what for?

thin parrot
#

I gave up and looked up a guide online and I think something is wrong with HTBs end now which is pissing me off

harsh gorge
#

ReconSpider?

thin parrot
#

The web crawler

harsh gorge
#

This is just some outdated OSINT tool

thin parrot
unique ether
thin parrot
#

And for some reasons targets last 30 minutes less now which makes the time crunch much worse when you get stuck

thin parrot
unique ether
#

ok

#

did u curl the page to get api

#

key

thin parrot
#

i already passed that as well

unique ether
#

ok so what are u trying now

thin parrot
#

I'm trying to get the email from another subdomain that was hidden based off of another subdomain found in the prior step

#

And to do that I'm trying to use reconspider which can pull information such as email addresses and a bunch of other pages/their contents etc

harsh gorge
#

This is from the cbbh path yes?

thin parrot
#

However dev.web1337.inlanefreight.htb:ip yields nothing there is nothing under this domain according to the web crawler

#

There are no index pages that supposedly exist

#

Penetration Tester path

waxen totem
#

that domain looks wrong

#

web is the lowest subdomain under dev

harsh gorge
thin parrot
#

it is literally what gobuster shot out to me

unique ether
waxen totem
thin parrot
#

I did rthe results.json is empty

waxen totem
#

reinstalling mine now kek

unique ether
#

waht

harsh gorge
waxen totem
thin parrot
#

I just ran gobuster again
dev.web1337.inlanefreight.htb:port

harsh gorge
#

Wait wait

thin parrot
#

I cant send screenshots yet

#

so I cant show you that it is a literal result

harsh gorge
#

You’re using gobuster

waxen totem
thin parrot
#

yes im using gobuster

unique ether
thin parrot
#

Should be let me check

#

oh

unique ether
#

remove the port before u add

waxen totem
#

and I swear if you added it in with the port I'mma stab you

thin parrot
#

oh yeah that'll do it 🤦‍♂️

unique ether
#

breh

thin parrot
#

Oh no dont worry I didnt even add it

unique ether
#

ok do everything again

#

aight can anyone help me now

thin parrot
#

Ok ReconSpider is still not returning anything

unique ether
#

delete the folder and rerun it

#

i think ur looking at the same result

#

in the command add the port

thin parrot
#

i did add the port

#

i feel like giving up these labs are such curveballs i dont get it

#

but no i have to pay annually to get step-by-step help

waxen totem
#

they're designed to force you to research and think logically

thin parrot
#

I have 6 minutes till I literally have to restart this entire process

waxen totem
#

and find your own mistakes of course

waxen totem
#

you can get 6 hours of target time

thin parrot
#

There is no + on my end :/

#

I literally have a gun to my head to finish this entire path by mid april so I dont have time to spend 4 hours on one fucking question because god forbid somebody posts useful instructions I can actually learn from

simple goblet
#

i now learn the CBBH path what is ur problem specifically may i can help u

unique ether
thin parrot
#

I might just have no other choice

#

to restart this

unique ether
#

show me ur command

thin parrot
#

oh well

unique ether
#

copy paste here

thin parrot
#

Oh my fucking god its because I didnt give it permission to create results.json

#

Thats why its not working

unique ether
#

assessment

simple goblet
#

i solved already

unique ether
#

i found parameter page

#

but i tried all the methods dint work

#

i mixed with url encoding still

#

dint work i tried automated that dint work

#

give a pointer

thin parrot
#

Oh my god it fucking ended on me
You know fuck HTB I'm charging back this whole fucking bullshit on my card, this platform SUCKS.

simple goblet
waxen totem
simple goblet
#

may its help us to solved

unique ether
#

oh i dint use burp

#

hmm let me see

simple goblet
#

lol

#

GL

unique ether
#

yea the page would just show invalid input validation thats it

#

i checked for session poisoning too

#

no cookies to poison

#

havent tried server log poison

#

lemme see

storm elk
#

Then /identify TOKENHERE

thin parrot
#

Well I finally got to that.

#

I'm still not sure why ReconSpider is not working

#

All the vhosts are added

storm elk
#

If the IP is an external one, yes (not 10.x.x.x), but without the port in your hosts file.

thin parrot
#

I mean I am literally following the steps of what someone did and the only difference is that they are getting results in results.json
Whereas I am getting absolutely nothing

waxen totem
#

are you tryna spider the subdomain or the base site?

thin parrot
#

That specific subdomain not the base site

storm elk
#

I’m on my phone so can’t check atm. Gotta bring my kids to school and daycare in a few min too

waxen totem
#

😉

thin parrot
#

I actually finally got the results
Something must have been funky with the last session I had

#

I really need to set up a vm and download the vpn from now on

#

I have no idea what went wrong though because I entered it with http:// as I did before, only difference now is that its giving me results

I know I caught myself accidentally doing resuls.txt instead of .json but I caught that before the new session...

This is genuinely more frustrating than software engineering, I hope it wont always be like this 😓

waxen totem
waxen totem
unique ether
#

cs job market is even worse

waxen totem
#

not for blue team

unique ether
#

its cooked for recent grads

thin parrot
#

I want to get some experience with Kali see which I prefer over the other

Also I wont be scared away, Softare engineering was one of the most soulless mindless tasks once you get the general bearings down. At least it was for the field I worked in. Same issues every time. Same code. Same crap. I wasn't creating or inventing something or coming up with creative solutions. So I'm sticking this through no matter what. Its way more enjoyable, but also way more difficult and frustrating

#

and yes it took me 800+ applications and 5 interviews to finally get a job as a Software Engineer

#

and I've been told entry level is also very rough for cybersec

#

But despite the stress I actually wake up looking forward to this, for the most part sadglas

unique ether
#

can some one please give me pointer
like im still stuck since 5 hrs

storm elk
#

what're you stuck on @unique ether ?

#

If its a CBBH/CWEE module feel free to dm me to avoid spoilers 🙂

native crow
#

Hey guys , having some wierd trouble proxychains is working, but for some reason cmb does not want to, it managed to get through once but connection dropped. is there a timeout setting or has someone had similar issues , This is for skills assessment 1 of Active directory enumeration and attacks

#

sudo proxychains crackmapexec smb 172.16.6.50 -u svc_sql -p xxxxx

#

[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.50:445 ... OK
[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.50:445 ... OK
[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.50:135 ... OK
SMB 172.16.6.50 445 NONE [*] x64 (name:) (domain:) (signing:False) (SMBv1:False)
[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.50:445 ... OK
[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.50:445 ... OK
SMB 172.16.6.50 445 NONE [-] Connection Error: Error while reading from remote

red shuttle
#

Hi everyone
linux file transfer module task1
Download the file flag.txt from the web root using Python from the Pwnbox. Submit the contents of the file as your answer.
should i use request lib to download (passed with wget itself) however cant get requirements of task

native crow
#

othertimes all i get is sudo proxychains crackmapexec smb 172.16.6.50 -u svc_sql -p 'xxxxx'
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.50:445 ... OK
[proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.50:445 ... OK
then it dies

sick oxide
#

How do fix this error

storm elk
#

Perhaps nothing is running locally on 8080?

hot crypt
#

Hello guys, I'm stuck on Tier 1 of the "Learn the basics of Penetration Testing" - Responder... I can't run the Responder.py bc the port 80 is already running the python from the PWNBox.. if I kill the process the Pwnbox close itself.

unique ether
#

For hint I feel ashamed

#

I'm beyond cooked

nimble scroll
#

hello

#

I am struggle to solve Advanced File Disclosure

#

module Web Attacks, can anyone help me ?

fathom pendant
#

Lowercase p for port

nimble scroll
#

can anyone help me ? HTTP/1.1 200 OK
Date: Tue, 25 Mar 2025 11:21:24 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 44
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8

Check your email for further instructions.

grizzled schooner
#

Password Reuse / Default Passwords

Found a zipped folder on the host, does this require cracking? Not sure if I'm running down a rabbit hole or not - please @ with any responses thanks

nimble scroll
#

can anyone help me with the request on burp suit to get the flag ?

calm swan
limpid oracle
#

Has anyone finished the prompt injection attacks module ?

#

i need help

nimble scroll
#

HTTP/1.1 200 OK
Date: Tue, 25 Mar 2025 12:33:12 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 1141
Connection: close
Content-Type: text/html; charset=UTF-8

<br />
<b>Warning</b>: DOMDocument::loadXML(): internal error: xmlParseInternalSubset: error detected in Markup declaration in file:///etc/passwd, line: 1 in <b>/var/www/html/error/submitDetails.php</b> on line <b>11</b><br />
<br />
<b>Warning</b>: DOMDocument::loadXML(): Entity 'file' not defined in Entity, line: 5 in <b>/var/www/html/error/submitDetails.php</b> on line <b>11</b><br />
<br />
<b>Warning</b>: simplexml_import_dom(): Invalid Nodetype to import in <b>/var/www/html/error/submitDetails.php</b> on line <b>12</b><br />
<br />
<b>Notice</b>: Trying to get property 'name' of non-object in <b>/var/www/html/error/submitDetails.php</b> on line <b>13</b><br />
<br />
<b>Notice</b>: Trying to get property 'tel' of non-object in <b>/var/www/html/error/submitDetails.php</b> on line <b>14</b><br />
<br />
<b>Notice</b>: Trying to get property 'email' of non-object in <b>/var/www/html/error/submitDetails.php</b> on line <b>15</b><br />
<br />
<b>Notice</b>: Trying to get property 'message' of non-object in <b>/var/www/html/error/submitDetails.php</b> on line <b>16</b><br />
Check your email for further instructions.

#

I am still stuck here , there isn t anyone to help?

waxen totem
storm elk
#

@nimble scroll feel free to dm me what you got

undone dock
#

is it okay if i use chatgpt to explain the displayed information i get from the nmap scan? like what these means:
Service scan sending probe DNSVersionBindReq to 10.129.2.48:53 (udp)
NSOCK INFO [2.2950s] nsock_write(): Write request for 30 bytes to IOD #1 EID 19 [10.129.2.48:53]
NSOCK INFO [2.2950s] nsock_read(): Read request from IOD #1 [10.129.2.48:53] (timeout: 5000ms) EID 26

rustic sage
#

Yes, its allowed

#

atleast for CPTS

cunning lark
#

I may just be being rrly dumb here. I've just started, and am on linux fundamentals.

#

Q: "What is the index number of the "sudoers" file in the "/etc" directory?" I put in the command ls -i /etc/, and found the sudoers file, put in the number next to it, it's saying it's wrong

cunning lark
#

right, yep, i was being dumb, thankyou!

fathom pendant
cobalt aspen
#

Module: ADCS Attacks
Section: PKINIT

When i obtain administrator certificate by exploiting esc1, extracting public key from certificate gives me an empty .crt file, but extracting private key works fine.

fathom pendant
cobalt aspen
#

Sorry, didnt know that my screenshot can be a spoiler 😄

fathom pendant
fathom pendant
cobalt aspen
cobalt aspen
fathom pendant
plain cosmos
gray yacht
rustic sage
#

Can anyone give me a work
I need to earn

fathom pendant
rustic sage
#

Ok

#

Sis

full acorn
#
  • How many Pen Testing Labs did HackTheBox have on the 8th August 2018? Answer with an integer, eg 1234.
  • How many members did HackTheBox have on the 10th June 2017? Answer with an integer, eg 1234.
    please help me on this , waybackmachine deosen't work !
    Module: Information Gathering - Web Edition
acoustic owl
full acorn
acoustic owl
acoustic owl
#

Read my hint again. ||com is not correct.||

full acorn
fathom pendant
acoustic owl
full acorn
#

i solve it, thanks very much

spiral sapphire
#

Hey guys! I'm doing the web attacks module. CURL is not working for me. When I run "curl -i -X OPTIONS http://SERVER_IP:PORT/" it should print me the allowed methods like in the guide. However, it doesn't work for me for some reason...? Does anyone know how to fix this issuea?

#

First picture is what I get,

The second is what should happen:

fathom pendant
nova pivot
#

Quick question : during assessments, is it common to look into the /opt/scripts directory ?

fathom pendant
#

i mean if it exists it's not a bad place to look

fathom pendant
#

@signal hound your screenshot contains spoilers for a password redact it and reupload the image

signal hound
#

Hi im doing AD enumeration and attacks
I am trying to rdp to MS01
I tried using metasploit
And netsh to portforward but i get errors when im trying to rdp
When i use /cert-ignore i get "timeout waiting for activation"

nova pivot
tranquil axle
strange pivot
strange pivot
strange pivot
nova pivot
meager otter
#

Anyone available for a hand on the RDLL Injection - Implementation Question 2 (Process Injection Attacks and Detection). Been stuck on this for most of the day. Cant figure out where im going wrong. Thank you.

vapid prawn
#

Hi, guys. I can't understand why any search bar or form of the final skill assessment of the sqlmap module is sending a request to the web app's back-end

calm swan
#

Hi,
I'm trying to get the OS name from the target in Firewall and IDS/IPS Evasion - Easy Lab, here's what I did:

sudo nmap <target_ip>/24 -sn -oA host -PE --reason to get the neighbors IPs
then
sudo nmap <target_ip> -p<port> -n -Pn -O -S <ip_from_the_above> -e tun0
and here I get the error:

setup_target: failed to determine route to 10.129.2.80
WARNING: No targets were specified, so 0 hosts scanned.
Nmap done: 0 IP addresses (0 hosts up) scanned in 0.09 seconds

am I doing smth wrong?

strange pivot
strange pivot
# calm swan OS

See if this works :D. ping -c 1 <target-ip>, if you can get the ttl (time to live) if its 128 its likely windows, if its 64 its linux

calm swan
#

cannot do haha 0 received

#

my ip is blocked then or?

strange pivot
#

so your blocked from sending icmp (pings)

fathom pendant
strange pivot
#

try scanning with -Pn

calm swan
#

sudo nmap 10.129.2.80 -p80 -sS -O -Pn -n --disable-arp-ping -source port 53 did this too

fathom pendant
#

-S also doesn't do what I think you think it's doing.

calm swan
#

but the answer is incorret

fathom pendant
#

Also i believe it's just asking the base OS not full flavor

calm swan
calm swan
#

can I send the SS in priv? cuz I guess I can't send it here cuz its the result of a scan

#

@fathom pendant

strange pivot
#

try -T 0? 😄 and ss is a syn scan

fathom pendant
fathom pendant
#

Normally I wouldn't but if i find it in your screenshot you owe me a beer

calm swan
fathom pendant
#

There's reading surrounding the examples that give them more context

strange pivot
#

--dns-server <ns> try specify their dns, just spit balling ideas

strange pivot
strange pivot
fathom pendant
#

the module this is from doesn't touch on half of what you put there

strange pivot
#

try SECLISTS http-request-methods.txt and just run through each one in intruder

waxen totem
strange pivot
#

if you've not got burp pro, id just use ffuf

west salmon
#

Hey, guys. I'm brand new to HTB but not to wi-fi hacking. I'm doing the WPS Reconnaissance module. When I open up the target system, there is no wlan0 interface. Any advice would be appreciated.

#

cant go too far with wi-fi hacking without a wlan interface 😉

fathom pendant
#

by "open up" do you mean ssh or rdp in? because the pwnbox != the target;
Spawn Instance != Spawn Target

west salmon
#

I can spawn the instance and have access to the environment.

fathom pendant
#

Spawning instance spawns the pwnbox, not the target that would have the wlan0 interface

#

:)

west salmon
#

ya, im brand new...thanks

fathom pendant
#

there should be instructions above the question that state <ssh|rdp> to <ip> with username "something" and password "something"

west salmon
#

but I have been performing wi-fi pen test for 6 years

fathom pendant
#

ok?

west salmon
#

checking...

fathom pendant
#

i'm telling you how the targets and questions work on htb academy

west salmon
#

yes. thank you

fathom pendant
#

spawn target spawns the actual lab that would have the required stuff to do

#

since you can utilize your own machine/vm to connect to the labs

meager otter
#

Just rechecking in seeing if anyone would be available for a hand with Refelcted DLL IMplentation, question 2. I have located the LoadLibraryA() in both IDA and x64dbg. cannot find the hash to save my life. Could use a nudge.

west salmon
fathom pendant
#

you can't share images because your account isn't linked

west salmon
fathom pendant
#

a lot of it is explained in the INtro to Academy module 😉

west salmon
#

yaa...lol I'll do that (the Intro to Academy Module). thank you

fathom pendant
#

should have been the first thing loaded up when you created your academy account

restive trellis
#

cannot login with provided credentials on https://academy.hackthebox.com/module/147/section/1639

xfreerdp /v:10.129.175.164 /u:Administrator /p:AnotherC0mpl3xP4$$

[18:03:43:170] [6235:6236] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[18:03:43:170] [6235:6236] [WARN][com.freerdp.crypto] - CN = MS01.inlanefreight.htb
[18:03:43:371] [6235:6236] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[18:03:43:371] [6235:6236] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[18:03:43:371] [6235:6236] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - 

proud pine
fathom pendant
#

if you're curious why echo AnotherC0mpl3xp4$$ and see what it outputs, that's what bash is seeing as the pw

restive trellis
#

Thank you @fathom pendant , i also needed to add the /sec:tls that was throwing the error

fathom pendant
#

well the main issue here is > STATUS_LOGON_FAILURE

#

meaning that no matter what it's not logging in with invalid creds

restive trellis
#

if you have invalid creds you get a RDP session and it shows the error on the new screen saying invalid credentials if you got the IP and username right. In this case the second screen did not open at all, and yes it needed to be inside single quotes

restive trellis
#

can i upload images here?

fathom pendant
#

xfreerdp throws the error without setting up the rdp session with invalid creds

#

maybe rdesktop or other tools do that

restive trellis
#

could i share pictures here?

fathom pendant
#

yes

restive trellis
#

okay

fathom pendant
#

since it wouldn't contain a spoiler

#

literally as long as it doesn't spoil the module (contain creds that you had to hunt for or other things you had to search for) you're fine

restive trellis
#

no it shows only the provided creds

fathom pendant
#

weird

#

but eh as long as the password works and logs you in; you're fine

restive trellis
#

yeah, thank you for the response ❤️

fathom pendant
#

i don't think i've ever used the /sec:tls option

#

also you don't wrap '/p:password' it's just /p:'password'

#

just as a standard use

restive trellis
#

it works both ways

fathom pendant
#

i'm aware

#

just informing standard use case just in case the tool gets an update and that no longer becomes valid syntax

astral egret
#

hello lads can anyone help im doing the right thing maybe im using the wrong list

#

??

fathom pendant
astral egret
#

not kira the zip file homie

fathom pendant
astral egret
#

same didnt work

waxen totem
#

try the provided word lists

fathom pendant
#

Make sure the 2john tool didn't output an empty line/string

waxen totem
#

this is the only thing I hate about this module (actively doing hard lab rn), is that it is mostly guessing and waiting

astral egret
waxen totem
astral egret
#

you just said rockyou tho

waxen totem
#

ohh you mean for the zip file? yeah I used rockyou, I thought you mean for the hard lab

waxen totem
#

[STATUS] 63.33 tries/min, 190 tries in 00:03h, 93856 to do in 24:42h, 2 active
long wait to go catscream

astral egret
#

can i send you an ss and tell me what im doing wrong??

waxen totem
#

cos I do have a few different versions of rockyou

#

~~made a mutated one just for the fun of it kek ~~

astral egret
#

did you transfer the zipped file to your machine?

#

or did you unhash it on kira @waxen totem

waxen totem
astral egret
#

same

#

can you send me the wordlist you used please

#

you would be a fucking champ man

fathom pendant
#

they said they used rockyou

#

lol

astral egret
#

I DID FAM

waxen totem
#

try the other wordlists

astral egret
#

I DID

waxen totem
#

if it ain't working don't force it

#

shouldn't take more than 1 min to crack ngl

#

took mine 2 seconds

astral egret
#

im using my own machine

fathom pendant
#

is the hashfile empty?

astral egret
#

a long way to do this on pwn

astral egret
fathom pendant
#

no

astral egret
#

lol

fathom pendant
#

i've already done my free DM help for the day

#

:)

astral egret
#

fair enough

waxen totem
#

have you tried the mutated wordlist?

astral egret
#

i just did thank you

waxen totem
#

Yoo quick question about the Password Attacks Hard Lab, I found a massive file, am I supposed to transfer this over to my machine? catscream

fathom pendant
#

depends on the file but typically: yes

pale hull
#

question when using hydra for ftp attacks, I swear I read -t 48 was recommended for speeding up the process

#

that was like the max

#

or maybe 46

#

ahh yea has to 46 I see the time short now

#

nvm

fair plinth
#

Some protocols might be faster also

lusty thicket
pale hull
#

[STATUS] 256.00 tries/min, 256 tries in 00:01h, 93788 to do in 06:07h, 16 active

fair plinth
#

How do I keep the windows machines from blowing up on me in the password section. I tried opening a notepad file and the RDP blew up and i gotta restart the server

pale hull
#

so that is the default I guess 16

fair plinth
#

Yeah default is 16

pale hull
#

[SATUS] 864.00 tries/min, 864 tries in 00:01h, 93194 to do in 01:48h, 50 active

#

nice so I set it to 64 I guess it went to 50

#

other wise this module is going to take 5 hours lol

waxen totem
silk lagoon
#

For Case6 on Attack tuning - SQLMap essentials; is the command supposed to take a long time?

Can I post the command I’m using?

fair plinth
#

sigh went from my rdp constantly crashing on the windows machines to just Destination Host Unreachable - switching from UDP vpn to TCP solved my RDP issues

cloud urchin
#

@fleet moth no spoilers from modules please

fleet moth
#

How am I supposed to share my concerns@cloud urchin ? Besides I haven't mentioned anything that is not to be found on the HTB forum.

cloud urchin
#

You can simply ask without posting content from the module as it's above tier 0

#

if you need to go deeper with info then you can ask if someone will DM

silk lagoon
#

Lul

twilit mantle
#

hi guys

#

I asked in general where to ask for help in my linux lab question problem and i was referred to this chat

#

anyway

#

Im in linux lab and idk why is this answer wrong, i even tried losing the / at the beginning and still wrong, i double checked with "echo $HOME" and "cat /etc/passwd | grep home" to double check my home dir and idk why its still wrong, tried diff browser, refreshing and still nothing, any help?

twilit mantle
#

if by that you mean im using the virtual machine web thingy that they offer then yes

#

forgive my ignorace, im new

twilit mantle
waxen totem
twilit mantle
waxen totem
#

Look just slightly above the question

cloud urchin
#

Please don't post answers for the challenges guys

twilit mantle
#

oh

waxen totem
#

Yeah mb didn't realize there was one of the answers in it kek

twilit mantle
#

the ssh thing wasnt covered

waxen totem
#

Yeah which is why I sent a link to ssh cheatsheet

twilit mantle
#

do i spawn my virtual box kali and use its terminal ?

#

or use it from whithin the web one that htb offers

#

omg, is that like connecting as a different user ???

waxen totem
twilit mantle
#

they offered some vpn file to download, but again im kind of skeptical and also ignorant when it comes to this, idk why they didnt cover it first

#

I'll read it

waxen totem
#

Heck it's preferred to use the vpn

twilit mantle
#

alright I'll read it for now and use the cheatsheet u provided

waxen totem
#

A VPN is essentially a network with your computer and the target in it

twilit mantle
#

thanks so much @waxen totem

waxen totem
#

No ping ples noping

twilit mantle
#

hey there, to ssh, i need to know the name@ip, they only provided me with a name and password

waxen totem
#

It will give you an ip

twilit mantle
#

i feel so stupid lol

#

thanks man, already done this and im in and solved it

#

but there is this question

#

i used ls in my home dir and there was nothing, kept spoofing around and this was the only mail thing i found, im confused

unique spruce
#

hello

#

im on the information gathering web edition and im on the way back machine think but for some reason this keeps popping up when i check htb 2018 aug 8

waxen totem
unique spruce
#

what i do

waxen totem
unique spruce
#

oh what was it

waxen totem
#

know your target 👀

waxen totem
tulip copper
#

Hi, I have a question I was practicing with ligolo and I established a connection with double pivot but when I try to start second tunnel it showed me this error:
error: a tunnel is already using this interface name. Please use a different name using the --tun option

If anyone could help me with why and how to resolve this issuer. Much appreciated

tulip copper
shut quest
tulip copper
#

oh okaay, so this tool doesnt support like dns or icmp tunneling?

shut quest
#

You can treat it like a normal network route.

tulip copper
#

if internal network is monitored, what protocol is used by ligolo's inbound traffic?

waxen totem
#

Although generally works as if its an actual interface

#

Similar to virtual interfaces on your vm

tulip copper
#

niiice its stealthy by design I like it

waxen totem
tulip copper
#

in this context yeah

#

thank you guys for assistance

ripe thunder
#

Im doing network foundations course and im stuck on the last questions. I dont want the answer i want to be pointed in the correct direction. The question is "Bypass the request filtering found on the target machine's HTTP service, and submit the flag found in the response. ". So when I use nmap to search for the ports of the target ip it gives me port 21 and 80 but they are both closed. I then try and use netcat to create a connection but it says connection refused. How do I get around this ? Please assist, been on this for the last few days.

opaque geyser
#

For Windows Attack and Defense : Skills Assessment, I had finished the Attack, however when I am in Bob in a windows machine, I cannot find the 4886 and 4887 events in event viewer am I missing something

final fog
#

[Skill Assessment - Pivoting | SSH usepam error] Hello everyone! When I attempt to perform a ssh dynamic port forwarding on the server, I get ssh_config usepam and unsupported error. I have review the Solution and also check the forums, but it seems like no one has encountered this error before. Thank you in advance for your help!
Command: ssh -D 9050 -i id_rsa webadmin@10.129.59.85
Response:
<badmin$ ssh -D 9050 -i id_rsa webadmin@10.129.59.85
/etc/ssh/ssh_config: line 25: Bad configuration option: usepam
/etc/ssh/ssh_config line 27: Unsupported option "rsaauthentication"
/etc/ssh/ssh_config: terminating, 1 bad configuration options

solar grove
#

Try to use what you learned in this section to obtain RCE via log poisoning and submit the flag. You can access the log at /log.php I'm stuck on this question at http attakcs

final fog
autumn pilot
#

@ancient idol not the place and not the server, please familiarize yourself with the #rules

fervent iris
#

is there a way to search for information\keywords in the owned modules like a search engine? if not, is it possible to be implemented if i requested it from HTB Academy?

solar grove
#

I'm stuck on the first question in the http attacks module “ Try to use what you learned in this section to obtain RCE via log poisoning and submit the flag. You can access the log at /log.php” how to pass the filtering.
help pls

native turtle
#

cwee and cape courses will be in the future included in students billing?🥺

fathom pendant
#

no

#

as those are advanced certs

#

you get a hell of a deal with access to the basic certs/t2 and below modules

autumn pilot
#

@rustic sage feel free to dm

narrow wasp
#

Kerberos Attacks Skill assessment last question, could use some help...

dry falcon
fathom pendant
#

yes

last ermine
#

why does eternal blue never work, any time it comes up in a module the payload works but shell never gets completed

#

This is for the shells & payloads module for the pentester pathway

fathom pendant
#

what module; did you set the options properly

#

for a shell you need to set the lhost to tun0

last ermine
#

ive just restarted my VM, i will try again

dry falcon
#

should i install htb parrot os edition as defaut os no problem ?

last ermine
fathom pendant
#

after it loads up i adjust the size a bit

#

also /dynamic-resolution is what i use not -Dynamic-resolution

#

oh

#

you're on the skill assessment

#

yeah no you need to set it to the interface that matches the target subnet

last ermine
#

yeah i had the foothold IP used originally

fathom pendant
#

also failed to bind

#

seems like something may have been using that port

#

is that the tiny window in the academy page? not the fullscreen page?

last ermine
fathom pendant
#

meh i prefer still using the fullscreen option for pwnbox when i use it

#

but yeah the foothold doesn't have dynamic resolution

last ermine
#

ill set the LHOST correctly

signal hound
#

Hi quick question
When interacting with active directory
do i have to specify the name of the domain?
For example for a user when i RDP into a computer
'Xfreerdp /v:IP /u:DOMAIN/USER'
Or runas /DOMAIN\user
Or i can use these commands without the domain name?

fathom pendant
fathom pendant
#

if it's a domain user and not local user

last ermine
last ermine
#

ive tried ctrl + alt + delete and all the other alternatives

last ermine
#

all other modules seemed fine

fathom pendant
#

ctrl-alt-enter

last ermine
#

its all good, i dont think future labs will have the same issue

fathom pendant
#

but i've genuinely never had issues with not seeing what i'm typing on this module/section

#

failed to bind

#

try a different lport?

last ermine
#

Yeah, but the port is not being used

fathom pendant
#

or try running msfconsole with sudo if you weren't already?

signal hound
fathom pendant
#

it can yes

last ermine
#

Im trying port 1234 now,

#

ok same issue, ill try sudo metasploit. but all other exploits work fine. I think eternalbue just hates me

fathom pendant
#

(i'd also make sure that's the right ip)

#

deleting screenshots as module is above tier 0 btw

#

:p

last ermine
#

yeah no worries, IPs are correct as i checked "show solution" and they used the same IP

fathom pendant
#

all else fails change vpn region

#

and respawn target

#

and pwnbox

last ermine
#

yeah it is always "failed to bind", Ill try another vpn region

#

for the exam, do people use the pwnbox or their own vm? or is it like a split

narrow wasp
neat dock
#

in the Pentest in a Nutshell module there is a question where we have to retrieve the version of vsftpd but vsftpd isn't installed on the target... Am I missing something?

last ermine
#

rip EU, im moving to NA

#

not sure if anyone else gets the error with eternal blue in the future. If ur using this region. Change it to US

#

Not sure if i should contact support about why my EU region is broken

nova knot
#

stuck on nmap idp/ids hard assessment

last ermine
#

u have to mess with alot of the settings

nova knot
#

the question's asking the version of service running and all i see is apache and openssh

#

knowing that it's a hard one

last ermine
#

dont feel scared to use walkthrough or chatgpt

nova knot
#

but the question/hint at top says the administrator held a session or smtg for all and smtg....smtg...

nova knot
#

nmap module