#modules

1 messages · Page 404 of 1

nova knot
#

idp/ids section skill assessment

#

at the end of nmap module

last ermine
#

ah yeah that one is hard

nova knot
#

from what i can see, i should either use the ssh to do something

#

or toy with apache settings

#

or am i lost completely?

last ermine
#

DM me ur current command, ill give u hints

peak bear
#

how are you checking it's installed?

weak current
quick rover
#

im doing the MacOS Fundamentals part of the operating systems fundamentals path, im stuck at how i should access the MacOS machine, is there even one? theres a question where i need to find the version running on my machine and submit it as the answer

#

where do i access the machine?

potent yoke
#

guys anybody know about this? i already do the steps like iwlist wlan0 scan with some grep. and i found the ESSID but it still wrong

#

i will delete this later

quick rover
storm elk
#

yep

potent yoke
storm elk
potent yoke
#

np thanks bro

#

i think there is an error on the module

#

just restart the module and its fine, just some bug

neat dock
peak bear
#

how would you normally check a package is installed on debian-like systems?

neat dock
#

dpkg?

peak bear
#

yep

neat dock
#

Alr. I'll try that thx

#

worked out, thx again

peak bear
#

cool

peak bear
scarlet jacinth
#

The target server is still deploying for about 10 mins...

weak current
peak bear
#

are you able to find a working payload for the first? (case #2)

scarlet jacinth
weak current
peak bear
signal hound
#

Hi Im rying to pivot to a network using Chisel,

  1. i transfered the .exe file to the windows host
    2.Started a reverse server on my host
  2. Tried to connect the windows machine using chisel client.
    But i cant get a connection back to my machine
    Any ideas what could be the problem?
weak current
signal hound
peak bear
#

once sqlmap has identified an injection point you can use the hint to find how to start reading data from the DB

weak current
peak bear
#

i think you have misread it - you can PUT data with --data 'id=0' --method PUT, but that's not the goal in case #2

burnt knot
night jackal
#

Hello,
I'm doing the Windows Privilege Escalation Skills Assessment - Part I and I'm totally stuck
I tried to get the credentials of the "ldapadmin account" by using the credential theft method ==> didn't find anything
Moved on and tried to escalated my privileges by using JuicyPotato and RoguePotato but I always endup with this error ==> COM -> recv failed with error: 10038
Do you have some advice ? Looking for some wisdom 🥲

peak bear
night jackal
chilly finch
#

Anyone else getting the "no instances available" error?

burnt knot
#

yes I had to use one over in DN

balmy wigeon
#

The CME section in Active Directory Enumeration & Attacks Module Page 14- Credentialed Enumeration - From Linux says

Make sure you preface all commands with **sudo**.
sudo crackmapexec smb 172.16.5.5 ...... --users

But why? what would CME / NXC do that would need su rights?

fathom pendant
peak bear
lapis sky
#

Attacking Common Services -> Attacking DNS

im receiving issues either with the pwnbox or the lab it self, when i try to enumerate the subdomains nothing works, used tools but nothing works, tried to see if the subdomain even exist, didn't exist, should i switch from the pwnbox or what?

#

yeah i did add the ip and the domain on /etc/hosts

safe mango
lapis sky
#

no, i didn't add the port

#

tried some things, got 3 subdomains but when i try to use dig nothing useful

#

it keep saying it couldn't get address

fathom pendant
#

when enumerating subdomains sometimes it's useful to point the tool in the right direction; @nameserver/ip for digging

night jackal
peak bear
gray yacht
night jackal
night jackal
rich salmon
#

I have a quick question. Will i still be able to access the modules that i have finished after my gold membership expires and i choose not to renew it?

nova pivot
#

Hello again, I have a basic AD question : In the academy course, a security principal is defined as anything that the operating system can authenticate and a security principle as a domain object being able to manage access to other resources within the domain.

That being said, when digging a bit to further understand the concept, I found that security principals are what the HTB course says, and security principles are general security principles, not especially linked to AD.

Could anyone help me clarify this ?

rich salmon
lusty thicket
#

security principles are, you know general security guidelines, least privilege, separation of duties, defense in depth etc

nova pivot
nova pivot
harsh gorge
#

can someone help with the pioviting part in this question ‘Submit the contents of the flag.txt file on the Administrator desktop on MS01 skill assesment 1 in AD module’

#

I’ve tried finding the route or ip by scanning internally but all nmap shows is tcpwrapped

west salmon
#

Broken instance???? Hi all! Is anyone familiar with the Wi-Fi modules?

#

This one in particular: https://academy.hackthebox.com/module/186/section/1958
When I go through the "step-by-step solutions for all questions" it says to start the instance and do an iwconfig. Should be easy enough. However, there are no wlan interfaces in the instance. scratching my head on this. Am I missing something extremely obvious or is there a problem with the instance itself? Just wondering if you had any guidance

dark hedge
#

you can DM me if you still need a nudge

calm swan
#

Could someone help me?
Should I, in the Firewall and IDS/IPS Evasion - Hard Lab, focus on the same port we were investigating in the Easy and Medium Labs?
Cuz we were told that we should identify the version of service our client was talking about so I assumed we should scan the same port as before.
But even tho im getting its version the flag is not showing up...

gray yacht
harsh gorge
#

yes

calm swan
gray yacht
vital apex
#

Anyone who did offshore, can you dm me?:)

sage quest
#

Hey, Anyone did "Applications of AI in InfoSec" module? I need a little help in the skill assesment. For those who know or did it, I am stuck with the model, i tried multiple models but all came out to be zero percent accurate idk how to proceed with this can anyone help me?

limpid crypt
harsh gorge
#

@gray yacht

fathom pendant
#

@rugged bolt don't reveal info for modules above tier 0

rugged bolt
#

thought i asked not revealed

rugged bolt
fathom pendant
rugged bolt
#

stuck on Password Attacks Pass the Hash last question for a couple days now: use Julio’s hash to get a reverse shell from DC01 to MS01 and read the flag. On MS01 (172.16.1.5) as admin via RDP. Tried Invoke-SMBExec/WMIExec with Julio’s hash, Base64 payloads to 172.16.1.5 (ports 8001, 443, 445), nc.exe listening. Also shared Invoke-TheHash.ps1 and ran it on DC01 via WMI. No output, no shell. Anybody have a hint?

gray yacht
desert quail
#

Hey, im having trouble recreating the debugging to get the answer for the following question : Reproduce all the debugging procedures mentioned in this section and provide the hidden shellcode-related hex values from the final screenshot as your answer. Remove all spaces.

https://academy.hackthebox.com/module/227/section/2496

Malware Analysis -> Debugging

meager otter
#

Has anybody completed the Process Injection - Attacks and Detections? Stuck on a question for almost 2 days. need a nudge. Thank you.

lunar flicker
#

Hi, can someone give me a hand with "INTRO TO WHITEBOX ATTACKS SKILL ASSESMENTS 1 CWEE" please?

I'm in the last part but I cannot exploit the function ||ping|| because of scaping characters..

Thanks very much!

hidden harness
#

hi everyone, i am doing the login brute forcing module, and i can't use medusa because the command can't be found?

meager otter
hidden harness
#

no, not even medusa -h or the full command is working, it seems as if it's not even installed on the machine

hidden harness
#

Login Brute Forcing

meager otter
#

What exactly

hidden harness
#

well, i spawn a machine and target in the academy, i want to use medusa and the command is not found

meager otter
#

what question are you on??

hidden harness
#

respawned many machines already

#

Medusa Web Services

lean crest
#

hey guys, I'm having trouble with Password Attacks > Pass the Ticket (PtT) from Windows. after trying to connect to the target with xfreerdp I get this error:

#

I've tried using both the vpn and pwnbox

meager otter
hidden harness
#

omg 🤦‍♀️

#

didn't bother trying any sudo commands on the machines, thought it came with the machine since it's usually pre-installed

#

thanks a lot, works fine now

meager otter
#

Small rant, but my goal is to help the next person who comes across this.

The Module:

https://academy.hackthebox.com/module/266/section/3461

Question:
Explore the reflective loader to find the hardcoded hash for the LoadLibraryA() function. Submit the hash as the answer.

You are NOT looking at reflective_dll.x64.dll nor are you using CFF Explorer. I was told to do both by HTB Support. That is incorrect. There is a link to the source code in the module. All you will need to do is go to the link and find the answer there.

This question is horribly worded and misleading especially after what is covered in the content. Please consider changing it accordingly. Hope this helps someone.

vague yoke
#

I am doing a curl -i -X OPTIONS http://IP:PORT and not getting the allowed verbs back.

#

anyone know why?

rustic sage
#

i don't know what is wrong but:
Module: "Introduction to Bash Scripting"
Exercise: "Flow Control - Loops"

i am trying to find the flag for exercise. but stuck with openssl error:
*** WARNING : deprecated key derivation used. Using -iter or -pbkdf2 would be better. bad decrypt 80BB9CC9F8760000:error:1C800064:Provider routines:ossl_cipher_unpadblock:bad decrypt:providers/implementations/ciphers/ciphercommon_block.c:107:

vague yoke
#

I tried changing the verb to head and post and they still require authentication.

#

got it to work with HEAD, but I am not sure why I can’t get the curl command to result in a list of allowed verbs. any ideas?

nimble scroll
#

hi , can anyone help me on Skills Assessment - WordPress?

#

I edited /etc/hosts but could not figure out an aproach to find the answear for , Identify the WordPress version number.

#

Scan Aborted: The remote website is up, but does not seem to be running WordPress.

#

I changed also target , also the machine and no succes

alpine ingot
#

I'm having some issues on the linux privilege escalation - enviornment enumeration section.
I have ran every command in the section including running linpeas.sh and nothing stuck out for me.
I ran all of the environment commands and every "juicy" folder i find is completely empty.
I found the ncdu with sudo -l but i dont think im supposed to get root with this particular challenge.

gray yacht
alpine ingot
fading skiff
#
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
_apt:x:100:65534::/nonexistent:/usr/sbin/nologin
mysql:x:101:102:MySQL Server,,,:/nonexistent:/bin/false
systemd-timesync:x:102:103:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin
systemd-network:x:103:105:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin
systemd-resolve:x:104:106:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin
messagebus:x:105:107::/nonexistent:/usr/sbin/nologin
sshd:x:106:65534::/run/sshd:/usr/sbin/nologin```
what should i focus on this output ( i try to reach a file in a web server)
alpine ingot
#

theres a lot to focus on with this, might need to do some more enumeration until its blaringly obvious what to focus on.
my mind goes to the mysql

cloud urchin
#

Yeah hard to say with no context. What module and section?

gray yacht
#

Generally from HTB{Whatever is in here to this end} just be sure you don't accidentally copy any leading and trailing space.

cloud urchin
#

@jade trail please don't post flags

#

it's probably a flag for a different question

jade trail
#

alright got it thank you, i thought i had entered it and yea ill delete

#

o someone got it

#

understood

zenith pagoda
#

Hello Everyone

#

Stuck on linux fundementals system information

#

I have to make SSH connection to the hackthebox but whenever I tried to type the password it says access denied

#

or permission denied

unique spruce
#

hey im using scrapy and i keep getting like 0 results like none

#

same w finalrecon im supposed to see a hidden admin directory but nun popping up

waxen totem
unique spruce
#

anyone have an idea what im doing wrong and i also cant find emails i lowk have no clue what to do

umbral ether
#

how do i open the general chat ?

cloud urchin
unique spruce
#

anyone??

waxen totem
unique spruce
#

information gathering web edition skills assessment

waxen totem
#

have you ever thought about the hidden directory being in a different subdomain? 👀

unique spruce
#

nx domain??

#

and yes i have the ip address with the domain in my etc/hosts

#

its a vhost so im gonna use ffuff

#

i got nothing wtf do i do

#

wtf do i do ┌──(kaifux㉿kali)-[~]
└─$ gobuster vhost -u http://inlanefreight.htb:56053 -w /home/kaifux/SecLists/Discovery/DNS/subdomains-top1million-20000.txt -t 50 --append-domain -H "Host: inlanefreight.htb"

===============================================================
Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)

[+] Url: http://inlanefreight.htb:56053
[+] Method: GET
[+] Threads: 50
[+] Wordlist: /home/kaifux/SecLists/Discovery/DNS/subdomains-top1million-20000.txt
[+] User Agent: gobuster/3.6
[+] Timeout: 10s
[+] Append Domain: true

Starting gobuster in VHOST enumeration mode

Progress: 19966 / 19967 (99.99%)

Finished

┌──(kaifux㉿kali)-[~]
└─$

#

like whattt

#

nvm i found something but gobuster dir isnt working

waxen totem
#

no clue, I use ffuf kek

fickle crystal
waxen totem
#

but yeah feroxbuster and ffuf's where it's at

unique spruce
#

uh i found the admin key but now i cant find the email

#

i tried using reconspider but i dont think its going past the first page and im getting 0 emails

waxen totem
unique spruce
#

theres 1 subdomain

#

bro im actually so confused why tf am i getting no results from anything

#

i js need this stupid email and where theyre gonna store new api results

zenith pagoda
# waxen totem Show your ssh command here please

I have fixed it but faced another problem when I try to connect the vpn to my own virtual machines it gives me this error Options error: Unrecognized option or missing or extra parameter(s) in my_vpn_file.ovpn:12: data-ciphers-fallback (2.4.12)

#

tried to fic it but nothing helps

waxen totem
#

there's an issue with the one you downloaded

zenith pagoda
#

which one should I download

waxen totem
#

Any one of them, just pick a new region, preferrably one that says Recommended

zenith pagoda
#

Alright I will try agein

#

Thx for the help

waxen totem
#

also be sure to run openvpn with sudo

unique spruce
#

@waxen totem please help

waxen totem
unique spruce
#

yes bro i ran fucking gobuster and ffuff and dnesnum like 30 times and i got 1 subdomai

waxen totem
#

have you tried: recursive subdomain?

dense tree
#

regarding package mgmt both the 'APT' & 'Git' sections in linux fundamentals:

I'm a little confused if I should be cloning this from Firefox inside the PwnBox? Also should I be ssh? Will this be useful for later? I don't have a current Linux box, yet...

waxen totem
unique spruce
#

subdomain within a subdomain

cinder thorn
#

.

unique spruce
#

smart guy here

dense tree
waxen totem
#

not even sure that's an actual domain but it's usually what they would look like

zenith pagoda
unique spruce
#

im done thank god

#

thank u for reminding of recursive domains thats like all i needed

waxen totem
zenith pagoda
unique spruce
#

but the main reason i was stuck was liek the initial subdomainign and it wasnt popping up on my kali linux for some reason but it worked fine on pwnbox i dont know 🤷‍♂️

waxen totem
zenith pagoda
compact patrolBOT
waxen totem
#

but otherwise it's really good

zenith pagoda
#

maybe I will just stick to it

proud pine
waxen totem
zenith pagoda
#

still in Linux fundementals

thick parcel
#

hi guys need help module 18 sections 72 and 71 ??

waxen totem
thick parcel
#

@uneven forum @astral elm

waxen totem
thick parcel
waxen totem
#

Just wait for someone to help you, like I'm about to, it just takes time for me to load up academy to see exactly what you need

#

Have you tried using the commands provided in the module?:

systemctl list-...

you can even use the concepts you've learned in the filter section of the module:

systemctl list-... | grep "Load App...
thick parcel
#

can i do call with u and share with u me screen and ask u ?

waxen totem
thick parcel
#

there is no guy can do that with me ?

waxen totem
thick parcel
#

this path that i send it to u is me first path i started with on this HTB

waxen totem
#

if you're still having trouble after that then keep asking questions but I will not go into a call

thick parcel
#

so whene i am studying every section from this modules i meet a lot of diffuclt to understand a lo of things for exemple in the section network services he talk about commun services but i dont understand how realy averyone f them work exactly this is normal to do nt understand everyting ?

#

i already do it broo

waxen totem
thick parcel
#

don t work

#

can i screen and send to u or something ?

waxen totem
thick parcel
#

sudo openvpn --config academy-regular.ovpn
[sudo] password for howami:
Sorry, try again.
[sudo] password for howami:
2025-03-27 05:33:17 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2025-03-27 05:33:17 Note: --data-cipher-fallback with cipher 'AES-128-CBC' disables data channel offload.
2025-03-27 05:33:17 OpenVPN 2.6.3 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2025-03-27 05:33:17 library versions: OpenSSL 3.0.15 3 Sep 2024, LZO 2.10
2025-03-27 05:33:17 DCO version: N/A
2025-03-27 05:33:17 TCP/UDP: Preserving recently used remote address: [AF_INET]38.46.226.34:1337
2025-03-27 05:33:17 Socket Buffers: R=[212992->212992] S=[212992->212992]
2025-03-27 05:33:17 UDPv4 link local: (not bound)
2025-03-27 05:33:17 UDPv4 link remote: [AF_INET]38.46.226.34:1337
2025-03-27 05:33:17 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
2025-03-27 05:33:19 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=1

why they refuse me connectio nto the vpn in the exercice ? ouffffffffffffffff

waxen totem
#

Remove --config

thick parcel
#

sudo openvpn academy-regular.ovpn
2025-03-27 05:35:27 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2025-03-27 05:35:27 Note: --data-cipher-fallback with cipher 'AES-128-CBC' disables data channel offload.
2025-03-27 05:35:27 OpenVPN 2.6.3 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2025-03-27 05:35:27 library versions: OpenSSL 3.0.15 3 Sep 2024, LZO 2.10
2025-03-27 05:35:27 DCO version: N/A
2025-03-27 05:35:28 TCP/UDP: Preserving recently used remote address: [AF_INET]38.46.226.34:1337
2025-03-27 05:35:28 Socket Buffers: R=[212992->212992] S=[212992->212992]
2025-03-27 05:35:28 UDPv4 link local: (not bound)
2025-03-27 05:35:28 UDPv4 link remote: [AF_INET]38.46.226.34:1337
2025-03-27 05:35:28 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
2025-03-27 05:35:30 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
still the probleme exist

waxen totem
#

Have you tried downloading a different vpn file? From a different region?

thick parcel
#

bro i feel that i will explose nothing work like the course i m crying and i dont understand a lot of things

thick parcel
waxen totem
#

Tech is hard kek

waxen totem
thick parcel
#

look i ndms i seen y screen i thin ku dont understand me

#

i cant send u on dms ouffffffffffffff
u see this :
Questions
Answer the question(s) below to complete this Section and earn cubes!

Target(s): Click here to spawn the target system!

SSH to with user "htb-student" and password "HTB_@cademy_stdnt!"

  • 1 Use the "systemctl" command to list all units of services and submit the unit name with the description "Load AppArmor profiles managed internally by snapd" as the answer.
proud pine
thick parcel
#

sorry i didnt read rules i have already too mush things to read and i m crying now and typing nothing works

waxen totem
#

Look for where to download the VPN, above it there's a box that says which region you currently have, click on that box and choose a different one and download the vpn again

thick parcel
#

Next to the exercise, there is a button called Download VPN File. When I click on it, I download it, then put it in the virtual system, then put it in the command line.

thick parcel
waxen totem
#

Like above the exercises theres a bigger button for vpns

dense tree
#

Ox- I'm a little confused how I installed Git by using the apt command with installing impact scripts in the VM... I understood how I made the directories and how I cloned them from the web, but still confused how the impact scripts had anything to do with installing the Git onto the VM...

i.e. sudo apt install impacket-scripts -y

thick parcel
#

yeah ok ok i will try it

waxen totem
waxen totem
thick parcel
# waxen totem

howami@parrot]─[~]
└──╼ $cd Desktop
┌─[howami@parrot]─[~/Desktop]
└──╼ $sudo openvpn academy-regular.ovpn
[sudo] password for howami:
2025-03-27 05:43:56 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2025-03-27 05:43:56 Note: --data-cipher-fallback with cipher 'AES-128-CBC' disables data channel offload.
2025-03-27 05:43:56 OpenVPN 2.6.3 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] [DCO]
2025-03-27 05:43:56 library versions: OpenSSL 3.0.15 3 Sep 2024, LZO 2.10
2025-03-27 05:43:56 DCO version: N/A
2025-03-27 05:43:56 TCP/UDP: Preserving recently used remote address: [AF_INET]38.46.226.32:1337
2025-03-27 05:43:56 Socket Buffers: R=[212992->212992] S=[212992->212992]
2025-03-27 05:43:56 UDPv4 link local: (not bound)
2025-03-27 05:43:56 UDPv4 link remote: [AF_INET]38.46.226.32:1337
2025-03-27 05:43:56 read UDPv4 [ECONNREFUSED]: Connection refused (fd=3,code=111)
2025-03-27 05:43:58 read UDPv4 [ECONNREFUSE

#

yeah i do it doesn t work

thick parcel
#

03-27 05:46:03 net_route_v6_best_gw query: dst ::
2025-03-27 05:46:03 sitnl_send: rtnl: generic error (-101): Network is unreachable
2025-03-27 05:46:03 ROUTE6: default_gateway=UNDEF
2025-03-27 05:46:03 TUN/TAP device tun0 opened
2025-03-27 05:46:03 net_iface_mtu_set: mtu 1500 for tun0
2025-03-27 05:46:03 net_iface_up: set tun0 up
2025-03-27 05:46:03 net_addr_v4_add: 10.10.16.16/23 dev tun0
2025-03-27 05:46:03 net_iface_mtu_set: mtu 1500 for tun0
2025-03-27 05:46:03 net_iface_up: set tun0 up
2025-03-27 05:46:03 net_addr_v6_add: dead:beef:4::100e/64 dev tun0
2025-03-27 05:46:03 sitnl_send: rtnl: generic error (-13): Permission denied
2025-03-27 05:46:03 Linux can't add IPv6 to interface tun0
2025-03-27 05:46:03 Exiting due to fatal error

permission denied ?

dense tree
thick parcel
#

look i will try to work with the free 1 hour on pownbox that htb give me per day

waxen totem
#

bro you been using pwnbox? No need for vpn then

#

Pwnbox is already connected to the network by default

thick parcel
waxen totem
#

Something about not having a default gateway

thick parcel
#

on the pownbox i use the commande taht u send it to me above and whene he filtred he dont show nothing i told u i tried it already before doesn t work

waxen totem
#

That means complete it yourself

thick parcel
#

yes i do it i m not stupid

#

but nothing shows

waxen totem
#

Are you ssh'd onto the target?

thick parcel
#

okwy wait i will copied it and past it to see

waxen totem
#

Please dont share module answers, check for leading and trailing spaces

thick parcel
#

also i stunk on it i use chat gpt and i tryd all the ensers

#

ansers

#

systemctl show dconf.service --property=UnitType

waxen totem
#

Honestly cant remember the command for that one kek

thick parcel
#

i m in section task schedchul

waxen totem
#

Yeah I cant remember that mate kek

thick parcel
waxen totem
#

Try removing Unit in the command chatgpt gave big_think

deft plank
#

I'm unable to solve Question #1 in Pentest in a Nutshell in Linux information gathering section

#

$ ftp 10.129.233.210 21
Connected to 10.129.233.210.
220 ProFTPD Server (Debian) [10.129.233.210]
Name (10.129.233.210:hannzo): ls
331 Password required for ls
Password:
530 Login incorrect.
ftp: Login failed
ftp> ls
530 Please login with USER and PASS
530 Please login with USER and PASS
ftp: Can't bind for data connection: Address already in use
ftp>

#

i tried using password PASS and the other one in the section but nothing seems to work

young ore
#

Try to run the application as a different user

golden plume
waxen totem
golden plume
waxen totem
harsh gorge
#

Imagine that

fickle crystal
#

It’s just bunch of authentication protocols u need to know

#

Relax ur horses

#

U acting like AD is god and we can’t reach out to it like so easily

#

Calm down Paul 🤣

waxen totem
untold ore
#

Module: Password Attacks; Pass the Hash (PtH); Question 6.
I can't really invest anymore time into this alone
Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01).
on MS01 as julio:



VERBOSE: [+] inlanefreight.htb\julio successfully authenticated on
DC01
VERBOSE: inlanefreight.htb\julio has Service Control Manager write
privilege on DC01
VERBOSE: Service LMHODRPBPMCEJBSNSDSD created on DC01
VERBOSE: [*] Trying to execute command on DC01
[+] Command executed with service LMHODRPBPMCEJBSNSDSD on DC01
VERBOSE: Service LMHODRPBPMCEJBSNSDSD deleted on DC01
PS C:\tools\Invoke-TheHash>```
#

srry for the bulky msg

#

last question in the module

waxen totem
golden plume
waxen totem
untold ore
#

yes, it's all over RDP to MS01, nc listener running on 9999, and actively listening

waxen totem
untold ore
#

that's a good one. i'll give it a shot real quick

harsh gorge
#

I would try Invoke-WMIExec as well

#

@untold ore

untold ore
#

oop. my environment reset 🙂

waxen totem
#

Use a container

#

Anything but pwnbox

harsh gorge
untold ore
#

i only used the pwnbox, cause it wasn't working on my vm sadglas

harsh gorge
#

Had a friend do that once

untold ore
#

how'd it turn out for him

harsh gorge
#

It was pretty funny

waxen totem
#

Bye bye impacket script compatability

untold ore
#

alright, let me log this process to this john

#

> reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0
x0 /f

> exit

xfreerdp3 /v:10.129.79.85 /u:julio /pth:[redacted]

term1:
cd \tools
.\nc.exe -nvlp 9999

term2:
> powershell -ep bypass
> Import-Module .\Invoke-TheHash.psd1
> Invoke-WMIExec -Target DC01 -Domain inlanefreight.htb -Username julio -Hash [redacted] -Command "[payload]"
##Successful ## no shell
> Invoke-WMIExec -Target DC01 -Domain inlanefreight.htb -Username julio -Hash [redacted] -Command "[payload]"
##Successful ## no shell
waxen totem
untold ore
#

nah, can't get it to run 🙂

#

i'm so bad with windows smh

wooden seal
waxen totem
untold ore
#

sorry, it's like 5am and my baby is still up

untold ore
waxen totem
untold ore
#

yeah, just to test out the base64 script

#

IPs are accurate, .5 and .10

thin parrot
#

The file transfer module is very confusing

#

I can't connect to my share via the DavWWWRoot directory

#

its hosted against my eth0 interface but I'm assuming that should work?

#

How the hell do I know what direction I'm going here?

#

I'm assuming I'm supposed to, through Linux, upload a the specified file to the windows vm

#

However we're also instructed to RDP so why the hell would I not just RDP then download the file from the link? So am I supposed to attempt to shoot it over to the pwnbox instance?

nimble scroll
#

can anyone help me with this task?

thin parrot
#

The forums are full of people stuck on the same issue so I have no idea what we're expected to do.

nimble scroll
#

Identify the WordPress version number.

#

when I try to scan the website it says this , Scan Aborted: The remote website is up, but does not seem to be running WordPress.

thin parrot
#

How are you running the scan?

nimble scroll
#

same issue

#

I even edited /etc/hosts but nothing changed

thin parrot
#

ok no you're ahead of me sorry, I haven't used wpscan. I was thinking it was an earlier module involving nmap scripts

nimble scroll
#

:((

young ore
# untold ore IPs are accurate, .5 and .10

.5 is IPv4 whilst .10 is for DNS server, using the IPv4 address should get you connected if you set up the listener on the terminal that performed the pth on user julio

nimble scroll
#

there isn t anyone to help me with Skills Assessment - WordPress ? :((

waxen totem
#

Or even nmap script/banner scan?

nimble scroll
#

yes, no hints

harsh gorge
#

@waxen totem You wouldnt have happened to do the skills assement for AD Attacks would you?

waxen totem
#

Please tell me it doesnt involve kerberos in linux systems kek

thin parrot
#

Someone explain what I'm missing here 🤦‍♂️ This module doesn't really explain anything conceptually

nimble scroll
#

this is what I find , 22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
443/tcp open http Apache httpd 2.4.29
Service Info: Host: 127.0.1.1; OS: Linux; CPE: cpe:/o:linux:linux_kernel

waxen totem
#

\\10...

thin parrot
#

Is that it because I'm still getting "The system cannot find the path specified" on cmd

waxen totem
#

Also is that the entire command? You need a destination

#

Its copy <source> <destination>

real delta
waxen totem
#

Just ESCs

real delta
waxen totem
thin parrot
nimble scroll
#

nmap -sV -p- 10.129.227.99
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-03-27 03:49 CDT
Nmap scan report for blog.inlanefreight.local (10.129.227.99)
Host is up (0.0086s latency).
Not shown: 65532 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
443/tcp open http Apache httpd 2.4.29
Service Info: Host: 127.0.1.1; OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 14.63 seconds
┌─[eu-academy-5]─[10.10.15.151]─[htb-ac-555305@htb-eywryyclte]─[~]
└──╼ [★]$ nmap --script http-wordpress-enum --script-args basepath=/ -p 80 10.129.227.99
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-03-27 03:49 CDT
Nmap scan report for blog.inlanefreight.local (10.129.227.99)
Host is up (0.0082s latency).

PORT STATE SERVICE
80/tcp open http
| http-wordpress-enum:
| Search limited to top 100 themes/plugins
| themes
| twentysixteen 1.9
| twentyseventeen 2.1
| plugins
| akismet
| the-events-calendar 5.1.2.1
|_ duplicator 1.3.34

Nmap done: 1 IP address (1 host up) scanned in 0.79 seconds

waxen totem
real delta
nimble scroll
#

:/

waxen totem
real delta
#

Tbf I copied a bunch of code from certipy for delta2 and even use the python module

harsh gorge
#

Seriously do I have to remind you that you did that

waxen totem
#

Anyways lets keep this channel back on topic

waxen totem
#

This aint scp

harsh gorge
#

Second

#

Look at the plugins and themes

thin parrot
#

now to figure out where the default path for copy is...

nimble scroll
#

I managed to solve in the end 🙂

#

2 questions answered 🙂

thin parrot
#

and christ I cant find the zip anywhere on the system...

#

I really should not be doing this while dealing with nerve pain, unncessary layer of difficulty lol

waxen totem
signal hound
#

Im doing AD enum and attacks skills assessment II
the question is
"Use a common method to obtain weak creds for another user"
I have been trying for a few hours now
Can i get a little nudge

oblique matrix
#

Hi, anyone had the same problem in with ICMP Tunneling with SOCKS? I can tunnel via ssh, however cannot reach destination server via nmap proxychains nmap -sV -sT 172.16.5.19 -p3389 I got: proxychains nmap -sV -sT 172.16.5.19 -p3389 [proxychains] config file found: /etc/proxychains.conf [proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4 Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-03-27 06:37 CDT Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn Nmap done: 1 IP address (0 hosts up) scanned in 3.15 seconds

gray yacht
waxen totem
#

use Ligolo

#

or run nmap from the compromised host

near temple
#

Hello, could someone help me with the knowledge check challenge machine in the getting started module (htb academy)? I already did the reconnaissance and have the data to bypass certain part (no spoiler) but I don't know what to do with that... I'm trying to do it without metasploit to learn more… (I read some htb forums post about it, but I can not wrap my head around it… Maybe I lack some specific knowledge) All help is appreciated. thx so much

gray yacht
severe inlet
#

I don't know why but everytime i ask for help here regarding a skills assessment i find the solution 5 mins later
Even tho ive been stuck at it for 2 hours

severe inlet
#

Sadly won't be able to abuse the rubber duck method during the exam 🥲

fathom pendant
#

buy a rubber duck, talk to it while you hack, ggez

tired atlas
#

so I'm on attacking common services easy, and I've managed to execute the select outfile command to get a webshell, but when I go to that directory on the domain, it returns an empty page, I feel like I'm doing something wrong, but can't really seem to get it

safe star
#

and it should be a empty page

tired atlas
#

i used the directory thats in the txt file

tired atlas
safe star
tired atlas
tired atlas
safe star
#

yeah it should be blank

#

try another command

#

@tired atlas can you dm the directory you wrote to

prisma wing
#

Hi all, i'm stuck on the first question in the Linux Privilege Escalation module. I couldn't solve it using the info in the section, so looked online and apparently i need to escalate privileges to user lab_adm, which is where the flag is stored. It does not state anywhere in the section on how to escalate privileges, so how am i supposed to answer the question?

prisma wing
safe star
#

you can use a find command or use grep

#

no escalation is needed

prisma wing
elfin roost
#

Thank you @fathom pendant ! I had the same issue today. Changing the region helped.

prisma wing
prisma wing
safe star
#

That’s the flag format

prisma wing
#

Ah! no i was just searching for flag

safe star
#

It’s not in a common place

prisma wing
#

Okay noted, thanks again. I'll give it another crack

safe star
#

It can also be inside the file not just the name

prisma wing
#

it's still saying permission denied, i know where the flag is now it's in either .cache or .viminfo but i just can't access them due to permissions. How am i meant to extract/read the info considering this?

#

the obvious answer is escalate privileges but i'm a noob and do not know how to and the section does not explain how to either

heady tusk
#

I'm working through the NTLM Relaying Module and am currently fiddling around with Coercer. Does anyone know whether it is possible to make HTTP authentication work with the latest version? The module mentions it's broken but I was hoping it has been fixed since the module was made. If anyone happens to have fiddled around with that too, feel free to shoot me a DM

safe star
#

Have you searched the whole file system?

fathom pendant
#

don't forget to throw errors to the void

prisma wing
# safe star It’s not

$ grep -r "HTB" /home/lab_adm/
grep: /home/lab_adm/.viminfo: Permission denied
grep: /home/lab_adm/.cache: Permission denied

$ grep -r "flag" /home/lab_adm/
grep: /home/lab_adm/.viminfo: Permission denied
grep: /home/lab_adm/.cache: Permission denied

dense tree
#

I'm working on the Linux Fund Modd: Sec section, specifically the "Working with Web Services" question about starting a simple HTTP server using npm on port 8080 (with the short argument).

I’ve tried a bunch of variations, ran it with and without SSH, even closed the terminal to make sure nothing else (like Apache) was still using port 8080. The second question worked fine for me, but this one’s got me stuck.

Could use a hint or clarification. I know I am not supposed to put answers here...

prisma wing
fathom pendant
#

you're not looking at the full system

#

just a single user

prisma wing
#

Okay noted, i'll enumerate further

fathom pendant
#

also to avoid flooding your screen 2> /dev/null

prisma wing
#

thank you

fathom pendant
#

send errors to the void

prisma wing
#

lol noted thanks again

signal hound
#

Hi im doing AD enumeration and attacks
Im trying to connect to SQL01 host via enter-PSsession using the creds i found but i get username/password is incorrect error
But they are correct
What could be the issue?

dark moss
#

Hello, I am playing with bloodhound in the AD odule ('Credentialed Enumeration - from Linux'). After running bloodhound.py on the ACADEMY-EA-ATTACK01 towards the DC, I get the three json files. All is good sofar. But, when starting neo4j and typing 'bloodhound' as database, it cannot find it. I am overlooking something. Any clues? Thx in advance!

prisma wing
dense tree
# safe star Google and man page?

I have tried so many stupid noob variations lol... and yes, even ai... I give up and finally came here to ask... I don't bother you guys unless it's been an hour...

lean crest
#

hello people

fathom pendant
#

^

#

that's what i did when i first did that module

dense tree
#

sudo systemctl start npm lol
npm http-....
npx http.s...
npx http-s... -p...

#

the list is long....

lean crest
#

I'm having trouble with Password Attacks > Pass the Ticket (PtT) from Windows. after trying to connect to the target with xfreerdp I get this error:

#

anyone know the fix?

safe star
lean crest
#

xfreerdp has worked in all other modules

fathom pendant
#

it's asking what the command is to start it

lean crest
#

just this one isn't working

fathom pendant
dense tree
#

"Find a way to start a simple HTTP server inside Pwnbox or your local VM using "npm". Submit the command that starts the web server on port 8080 (use the short argument to specify the port number)."

fathom pendant
#

submit the command that starts the web server on port 8080

#

you don't have to start the web server

dense tree
gray yacht
gray yacht
slim otter
#

On the password attacks module, currently doing the ntds.dit questions, was wondering how do I actually extract the hashes from the ntds.dit file? Some further research said I also need the system hive, is this correct?

Additionally, would I be using secretsdump.py to extract hashes once I obtain both files?

severe inlet
normal sand
normal sand
#

Sorry, kinda sleepy, didn't read your question properly at first 😅

fathom pendant
#

i used pypykatz to dump NTDS.dit

slim otter
#

No worries, not sure why that's not explicitly mentioned in the ntds.dit chapter

#

And you need the system.hive file for that or nah?

normal sand
#

I believe you can dump NTDS.dit without system.save.

slim otter
#

okay sweet cheers mate

normal sand
#

I'd recommend testing it out to be sure tho.

#

But iirc it isn't needed.

slim otter
#

Looks like I needed to grab the system.save file aswell and then use impacket-secretsdump to dump the hashes

#

from what I can see pypykatz doesn't support ntds

#

unless I am using the wrong option

safe star
#

yes system is needed

fathom pendant
#

system is needed

#

my b pypy is for lsass

slim otter
#

No problem, guess it will stick more now I had to struggle a little lol

#

looks like with crackmapexec, dumping ntds remotely will sort the system file for you

indigo cargo
#

I have a question about the password mutations part of the password attacks module.

#

I have understood the lesson, but is it really necesarry that we then have to wait 1-2hours for the password to crack?

fathom pendant
#

that's far too long

#

should only take ~30-40 minutes

#

unless, of course, you were attacking ssh and not one of the other open ports

indigo cargo
#

Ah well yeah, it says 1h51 for the list to complete but i obviously dont know where in the list it will complete

fathom pendant
#

the mutated list should be ~93k words long

indigo cargo
#

yeah thats it

#

but still, isnt 30-40 minutes a bit too long? Isnt the essence to get the lesson isntead of waiting for 30 minutes?

fathom pendant
#

nope

#

the essence of the lesson (and the module as a whole) is patience

#

even with the 'right' wordlist, bruteforcing can still take a while

#

also yes, it's bruteforcing, not cracking

indigo cargo
#

allright, i guess i can continue with other lessons whilest its bruteforcing

fathom pendant
#

cracking == taking an existing hash and trying to find something that creates the same hash (due to the nature of hashing algorithms, the same input should always result in the same output)

warped falcon
#

Hey guys could anyone suggest me a vedio or anything so that I can dual boot my computer

fathom pendant
#

Google. plenty of guides online on how to set that up

indigo cargo
#

daimn, my pwnbox reset due to timeout

fresh wedge
#

can anyone assist with Password attacks protected files module? it says to log in as kira using the cracked password 1234....this doesnot work when using ssh kira@x.x.x.x

fathom pendant
rustic sage
#

Hi

fathom pendant
fresh wedge
#

i didnt save it

fathom pendant
fresh wedge
#

ok that works

true wing
#

Hello I have some questions regarding challenge creation for HTB (catagory specific)

#

So I want to make a web challenge which will have two targets 1 internal and 1 external and the attackers have to figure out a way to exploit the external target and reach the internal target. But according to rules If a challenge contains a dockerized component, it shall not include multiple containers but just one. This rule kind of forbids me from creating such challenge can anyone explain this rule to me in detail and if it will contradict with my idea. My challenge will have both the hosts on the localhost just on different ports both ports will not be exposed just one of them. Both will be http and there will be a bot too.

#

I will apologize if this is not the right channel to ask about this, for some reason I can't access other channels so I am sending this here.

fathom pendant
fathom pendant
keen juniper
#

hi peoples

deep spire
#

I've just started with Intro to Digital Forensics, i'm in the topic Evidence acquisition techniques and tools. For some reason I just can't seem to figure out how to start with the challenge where it asks you to connect to "https://127.0.0.1:8889/app/index.html#/search/all". I don't get it, am I supposed to use the VPN file and visit the target system or am I supposed to visit this localhost file, or do I have to open Velociraptor and input this as target. Can someone help me get started please

near temple
stark rock
#

Code: shell
USER anonymous[Ctrl+V][Enter][Enter]
PASS anything[Ctrl+V][Enter][Enter]
PASV[Ctrl+V][Enter][Enter]

How do i run this command for Network Foundations???

I have tried a few times and it keeps saying bash: USER command not found

safe yoke
#

Hi guys! Did anyone do this module?
Module: Active Directory Trust Attacks
Section: Unconstrained Delegation
Link: https://academy.hackthebox.com/module/253/section/2803
Question: Abuse Unconstrained Delegation to get the TGT of DC01$ and submit the flag located at \DC01\UCD_flag\flag.txt

I reproduced the attack as explained in the module, but it seems that either Spoolsample isn’t functioning properly or something’s off, because no TGTs are showing up.

fathom pendant
signal hound
#

AD enum and attacks II question 7
"Sumbit the flag on the admjn desktop on SQL01"
Got to the SQL01 using mssqlclient
Got a reverse shell back to my host using xp_cmdshell
Tried to dump the registry hives using reg add, specified the location of C:\sam.save
But i dont see it after listing files in this directory.
I then tried uploading mimikatz to the host but i do not have the rights to do so
I also tried dumping the SAM using CME but with no success
Any hints what else i can try?

signal hound
#

I did not

deep spire
fathom pendant
#

¯_(ツ)_/¯

dim shard
#

Hi guys, if i dont have the money to pay for the cubes are there any other ways to generate them?

waxen totem
#

Theres also referrals and very rarely giveaways

near temple
acoustic owl
near temple
#

Ye, I was referring to that should have been more specific facepalm

harsh sundial
#

hey everyone i am currently tryin to establish a reverse shell connection but for some reason it won't connect on my vm but it does on the pawnbox does anybody have a clue why this is ?

dim shard
#

Just not realistic for people who aren't students

#

Ah well

#

Thanks tho

harsh sundial
mental otter
#

@acoustic owl first I want to make an account hm

dense tree
#

linux fund: dockers: are these the safe environments "containers/ dockers" that CISO & GRC can certify for A/B testing and keep from harming any live environments?

#

okay - looks like I'm getting ahead of myself...

waxen totem
fathom pendant
harsh sundial
fathom pendant
harsh sundial
#

stupid mistake of me sorry for bothering y'all

dense tree
rustic sage
#

it won't locate something in the seclist even though it's in there

#

how am I supposed to get help if ur just gonna delete my question

fathom pendant
#

@rustic sage please refrain from spoiling content from the module

rustic sage
#

ok wait

fathom pendant
#

spoiler tags don't do anything

#

as anyone can still click them

wispy aspen
rustic sage
#

at their own peril?

fathom pendant
#

i suggest not limiting the depth

#

even then, not allowed

rustic sage
#

yes but it's under the directory /x/

fathom pendant
#

redacting info is the smartest way to do it

rustic sage
#

ok

fathom pendant
#

since your question and the way you phrased it initially revealed way too much about where the answer would be

rustic sage
#

ffuf -u http://X.X.htb:40040/FUZZ -w Desktop/Seclists/directory-list-2.3-small.txt:FUZZ -recursion -recursion-depth 1 -e X -ic

it's under the first directory

fathom pendant
#

but try not limiting the recursion depth

rustic sage
#

oh

fathom pendant
#

or setting the depth to 2 instead

rustic sage
#

ok ill try that thanks

sage quest
#

hey

#

can anyone help me with "Applications of AI in InfoSec" module? its tier zero I am stuck at the skill assessment of it

rustic sage
#

even though I have the extension set right and x is in the seclist

fathom pendant
#

^

rustic sage
#

the . ?

safe star
#

i think youre running FUZZphp7 instead of FUZZ.php7

rustic sage
#

i thought it automatically adds the .

#

interesting

#

ok fixed thanks

waxen totem
vast wind
#

Hey guys I’m stuck on figuring out bob’s password for the smb share on the Service Scanning section of Getting Started. Can anyone explain how they figured it out

safe star
#

@upbeat fulcrum they show it in the section

vast wind
#

Nvm I figured it out

fresh wedge
fathom pendant
#

It's the same target

#

You can adjust threads btw

fresh wedge
#

Lol i checked to see if. it was any on the Pass* option in the mutated list so i guess its not any of those 258 words.

fathom pendant
#

kira's password doesn't start with [pP]ass

fresh wedge
#

im running full list now all 94043 of them

fathom pendant
#

that's your main issue, don't know where you got the idea it was

fresh wedge
fathom pendant
#

don't make assumptions, that's a big pitfall

safe mango
proud pine
safe mango
#

I have done the module, I don't remember it violating this rule

proud pine
fathom pendant
#

in which case it doesn't

#

but the modules tend to break that pattern a bit

#

with the modules if it's taking greater than 1h then you def are doing something wrong

#

30-45 minutes tends to be the average

safe mango
#

I would say 20 min max in case of server a overhead or bad vpn

#

Ironically this is similar to real life pen testing. Where most of the time things that you need to do your job break. Might as well embrace it

fresh wedge
#

LOL been. over 20 min runing this mutated list...still runnng. already extended the time for server

#

4500 passwords out of 94000

fathom pendant
#

Doesn't overload or give errors from what I've seen on that section

fresh wedge
#

i am using medusa, shoud i cancel and start over with hydra?

lusty thicket
fathom pendant
#

and can lead to missing the password from one of those threads

#

rather have no workers die off

lusty thicket
fathom pendant
lusty thicket
#

and in the rare case that it does, hydra doesn't just forget the password

fathom pendant
#

point is rather not rerun the command 5 times just to get the password

lusty thicket
#

the attempt won't get counted as successful or unsuccessful

fathom pendant
#

correct: the point being made is rather not have to re-run a command and wait longer when it would have taken like a marginal amount more time with less threads

lusty thicket
#

if -t 64 finishes faster, even with occasional reruns

#

it's worth it

fathom pendant
#

except with less threads that don't require re-runs, the speed won't make a meaningful difference

fresh wedge
#

1hr down -t 48

fathom pendant
#

and yes, it matters

fresh wedge
#

yes i used lowercase kira

fathom pendant
#

let's not use "gay" as a descriptor for things especially if the connotation is negative

fresh wedge
#

sorry, my appologies

untold ore
weak current
#

haa yeah im silver this season....

storm dome
storm dome
waxen totem
storm dome
mystic echo
#

Hello guys 😄

wooden seal
#

Using crackmapexec {Bloodhound Integration}
Using my own vm configured the bloodhound part of cme.conf but when i try to run the bloodhound module commands it gives error bloodhound isnt running on bolt://localhost:xxxx so how do i configure it to run on http://localhost instead of bolt

grim plaza
#

What is the best path on htb academy that will to become security researcher and in exploit development???

bleak kiln
#

What should I do as a junior in HS hoping to major in cybersecurity

#

any extracurriculars, internships or anything type of websites

#

Looked at a isc 2 membership thing, what’s the membership due for

untold ore
#

big thanks 2 @cloud urchin . My guy helped me out with a smile, and went out of his way to test the environment himself. Showed tons of knowledge and professionalism

For future purposes, if anyone is looking for the question:
Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

Try using a different source for your payload

vast wind
#

Hello everyone, I am stuck on figuring out how to successfully do web enumeration on the target. Every time I try to enumerate it no matter what tool, it will tell me that the host cannot be found at the ip on port 80 or port 443. What I did was the command with
http:// targetip/

vast wind
#

Getting Started. Web Enumeration

vast wind
deft veldt
#

Hello everyone, I am currently stuck on Attacking Authentication Mechanisms skill assessment, I understand the vulnerability however when trying to exploit it, does not get what I needed

waxen totem
#

Gotta specify it if it isnt one of the default ports(80/443)

wooden seal
deft veldt
#

anyone can give me a nudge on the skill assessment: Attacking AUthentication Mechanisms?

wooden seal
vast wind
waxen totem
wooden seal
waxen totem
#

<IP>:<PORT>

vast wind
#

I see

waxen totem
vast wind
#

So it should be for example whatweb http:// targetip:port/ ?

vast wind
#

Thanks.

deft veldt
wooden seal
#

reconfingured the port to 4747 but its taking bolt:// schema instead of http:// one

cloud urchin
# wooden seal yups

ok.. so neo4j is the graph dbs management system and bloodhound runs the website that reads from the neo4j instance

wooden seal
#

and config file has nothing in it to specify the schema

#

yes you are right

cloud urchin
#

you're supposed to connect bh to neo4j's bolt protocol not http

#

i mean i think it's the same thing really

#

you should also be able to access the neo4j console directly with that ip it runs on

wooden seal
#

wait i will run the tools again and will send screenshot in a while so you get better idea about the issue

cloud urchin
wooden seal
wooden seal
#

Module - Using crackmapexec {Vulnerability Scan Modules}
trying running this command : crackmapexec smb 10.129.x.x-u Administrator -p 'IpreferanewP@$$' --put-file ./chisel.exe \Windows\Temp\chisel.exe --local-auth
Getting this error : [-] Error writing file to share C$: Unexpected answer from server: Got 47, Expected like this
SMB 10.129.x.x 445 WS01 [*] Windows Server 2016 Standard 14393 x64 (name:WS01) (domain:WS01) (signing:False) (SMBv1:True) SMB 10.129.x.x 445 WS01 [+] WS01\x:x (Pwn3d!) SMB 10.129.x.x 445 WS01 [*] Copying ./chisel.exe to \Windows\Temp\chisel.exe SMB 10.129.x.x 445 WS01 [-] Error writing file to share C$: Unexpected answer from server: Got 47, Expected 4

harsh gorge
#

It’s late

waxen totem
harsh gorge
#

We got a box to prep for

dusky valve
#

just wanted to ask if anyone has high latency on pwnbox at all... using my own machine and use the vpn file is also quite high on latency T-T

dense tree
#
Quick setup question for the pros here:

I’m working through HTB Academy and prepping for certs (HTB + CISSP). My system runs Windows 11 on C:, but I’ve got 750GB free on D:. I’m considering setting up a dedicated Kali or VirtualBox VM on D: for lab work, note-taking, and more flexibility.

But for now, would it make sense to just stick to the browser-based labs until later, and build out my local lab as I get deeper into the paths?

Curious if anyone here started the same way—Windows as host, Linux VMs on a second drive—and gradually built out their setup over time.

Appreciate any insights—trying to stay efficient but also future-proof my workflow.

dusky valve
#

i tried switching vpn servers, it did worked once but it went back to high after i came back lol

wooden seal
#

its always higher for me too no matter the reigon

verbal phoenix
#

Hi, can anyone help with Hacking WordPress module ?

green shuttle
#

with advanced sql injection module does anyone know why it always gives 400 error when sending requests with script

storm elk
acoustic owl
dense tree
#

Hey — while we’re waiting for him, I’ve got a quick question about the workspace. I just finished the AppArmor portion under the Network Config section of Linux Fundamentals. That was a beast — I had two terminals open to test enforced profiles and behavior.

If I close those terminals now, is there any risk it could mess something up in the workspace? I’m about to move on to the TCP Wrapper section and want to start with a clean environment.

#

I did take notes

#

Do i have to close the sessions?

dense tree
#

Would like to still know for future ref...

#

on what the staff pref is.

proper umbra
#

Hi, anyone have an issue on the new xfreerdp3, where you cant copy paste from windows -> kali, but the other way works

So i cant complete htb ad path because i need to copy hash from inveigh powershell

Maybe someone here have encountered similar problem

verbal phoenix
dry falcon
dry falcon
#

First, navigate the website to find potential attack vectors.
that i don't found

storm elk
#

Surely must have found something that it does/sends?

#

Did you click around? See what the website does?

#

Feel free to dm me to avoid further spoilers

dry falcon
#

their are some forms which don't even send filled data.

dry falcon
serene drum
#

So I'm currently doing the sql injection module and I'm having trouble wrapping my head around operators. I'm still getting familar with sql, does anyone have a suggestion as to better understand the module?

dense tree
#

So I was fighting tonight! I wanted to get my hands around the NSA tool 🤣 I was trying so hard to figure it out.

serene drum
#

haha

dense tree
#

Thought you would like a good Friday laugh... I'm looking forward to that next chapter, which definitely excites me to that configuration

serene drum
#

sounds like it

dense tree
#

oh- and you know I also tried to hunt for the files as well once my memory started kicking back in on how to navigate Linux again 🤣 - then the light stuck 💡 ahhh... that's whats sudo is for..

grand gate
#

Hi, just a small question related to student subscription for htb academy
Is it possible to add my university email along with my main email? So that if I ever lose access to my student inbox I can shift back to my main account 🤔

slender totem
#

Good morning community, I'm following the Network Foundations module of the academy at Tier 0 and in the chapter Components of a Network arrived at the questions I can't solve the first one which is this:

What type of network tables is used to transmit data over long distances with minimal signal loss?

I think it's obvious that we're talking about fiber but whatever nomenclature I put it always gives me an error; can someone help me?

waxen totem
#

also please don't share the answer(or similar) in your query

grand gate
#

One question, can I keep my real mail as primary, but add my university mail as 2ndary and still get access to hackthebox student ?

waxen totem
grand gate
#

Ah crap I can't change till april 🤔

#

Bcs I just added my main email as secondary and made my university one as primary

serene drum
#

So I'm currently doing the sql injection module and I'm having trouble wrapping my head around operators. I'm still getting familar with sql, does anyone have a suggestion as to better understand the module?

I'm not looking for someone to give me the answer. Just help understanding how to get the answer.

thin citrus
#

Dear HTB people, I am working on Attacking Authentication Mechanisms - Forging JWT tokens. I have followed the steps it showed, but still I get invalid token. the Section of Verify Signature is not clear. In the figure of jwt.io Verify Signature states 'secret based64 encoded'. Does this means that the cracked secret from hashcat needs to be based64 encoded? Tried also with the dot '.' at the end of the token. No luck either.

waxen totem
#

just the type, don't have to put cables

#

@slender totem will be deleting your message cos it contains an answer(close enough at least) to a module question

slender totem
grand gate
grand gate
#

Ah F I'm on a 14 day cool down to shift my email back

serene drum
#

ima take it I asked a dumb question haha

grand gate
#

I wonder if there are any mods here who can disable the cooldown

storm elk
#

only support can help you @grand gate

#

mods dont have access to the platform

grand gate
#

ah ok

compact patrolBOT
thin citrus
#

it is this image in the course:

storm elk
#

you having fun with attacking authentication mechanisms @thin citrus ?

dense tree
#

ok- so it's fundamental Remote Desktop; I get it.. But umm RDP, VNC.. no c2 stuff?

serene drum
#

Im stumped

dense tree
#

Silver

#

Colbalt

#

anything of this era lol

#

or does that come much later

safe star
serene drum
dense tree
# safe star What’s the context

Hi Latice, this is the quote from the mod "For these VNC connections, many different tools are used. Among them are for example:

  • TigerVNC
  • TightVNC
  • RealVNC
  • UltraVNC
    The most used tools for such kinds of connections are UltraVNC and RealVNC because of their encryption and higher security.

In this example, we set up a TigerVNC server, and for this, we need, among other things, also the XFCE4 desktop manager since VNC connections with GNOME are somewhat unstable. Therefore we need to install the necessary packages and create a password for the VNC connection."

#

then we have to Pivoting, Tunneling, and Port Forwarding

safe star
#

Wym no c2 stuff

foggy slate
#

Cyber hacking Instagram link can you available

shut ice
#

@dense tree if you are talking about setting up your own VM to connect to the labs, if you use a Kali VM 90% of the tools will be installed

dense tree
#

I meant in comparison to the more advanced tools that are out today. i.e. Colbalt Strike, Silver Framework, Brutal Ratal, and BeyondTrust (way overkill)

safe star
#

Wait what are you comparing here

shut ice
#

They are not tools, they are C2 frameworks that have tools built in

dense tree
shut ice
#

If you've setup a Kali VM to connect to the labs yet, I wouldn't look into C2 frameworks just yet

dense tree
#

lol

shut ice
#

Yeah exactly, start with setting up a Kali VM and running through labs. C2 stuff is way way beyond that 🙂

dense tree
#

Well - it's a pleasure to meet you guys 🙂

shut ice
#

There are modules for Sliver (an open source C2) on HTB (I'm doing it now) but it's a Tier 3 hard module

dense tree
#

🔥

shut ice
#

On that note, can anyone help with this error with Sliver? I've set the beacon timeout to 180 but can't run any PowerView commands

[!] rpc error: code = Unknown desc = implant timeout

safe star
#

Some machines it works great and others it doesn’t at all

#

Are you using sharpsh or sharpview

shut ice
#

Ah okay thanks, just sharpsh at the moment, going to try with Sharpview now

green shuttle
shut ice
#

Same thing with SharpView 🤦‍♂️ I've got an RDP session and just ran both manually from the host, just won't run through the beacon...

opaque walrus
#

Hi I am on Login Bruteforce section using Hydra, In the final lab we just need to bruteforce a login page. I have initiated it with hydra but will it take 7hrs ? as per sc

shut ice
#

@opaque walrus can you not enumerate a user somehow? Then you just need to brute-force the password?

opaque walrus
#

@shut ice i have following the module with this process. How do i get which username is correct?

thin parrot
#

Sorry but is it not impossible (from my current skillset) to upload to the user without ssh to to the user to download the file from the webserver??

opaque walrus
shut ice
waxen totem
#

See File Transfers Module for more info

thin parrot
#

I just found the question confusing because it seems to imply that you're expected to make the initial steps without SSHing to the target

waxen totem
#

can't recall the exact order in which copy methods were introduced, also it's still technically sshing into the target

thin parrot
#

Oh yeah SCP was mentioned let me look back on that

#

I was going to do it through a webserver but I guess I should try and dabble into something I haven't done yet

waxen totem
#

during that module I was like: man when am I ever gonna need all these methods
did a box... specifically needed one of the methods kek

thin parrot
#

This method seems a lot simpler lol

#

Theres a reason I brutaly document every which way to do a singular task

#

I know someday it will be worth it

waxen totem
thin parrot
#

I do, I also read over them every few days or so to memorize them over time, and include descriptions for flags or anything I may forget the purpose of

waxen totem
#

but revision is still a must, human brains are designed to forget things that aren't deemed important

thin parrot
#

Will do, its a bit rough though I've never had to memorize so much on a particular subject.. or sub..subjects of a subject

sterile bane
#

U

thin parrot
#

its a lot to say the least

#

...the host does not have unzip

#

and the user is not in the sudoers file

#

either I screwed up or this has a secondary exercise nested in it 😭

#

I screwed up.

mental otter
#

@everyone i make an account in hack box then what can I do? Pls help me

#

Bro

#

Brother where I can get some role

storm elk
#

@mental otter - why make an account on a platform you don't know what you could do there?

storm elk
#

I know everything

shut ice
#

Bot commands @mental otter

storm elk
#

this isn't general chat, this is a chat for helping with modules

mental otter
#

Brother I want to learn

#

@storm elk

storm elk
storm elk
#

Please read and follow instructions in #welcome - it's three steps.

mental otter
#

@storm elk where I find account Identity

storm elk
#

There's a link in the steps

mental otter
storm elk
#

click it

mental otter
storm elk
autumn pilot
#

please let's keep the channel on topic

shut ice
#

Can anyone help with this? Or know if I should report it as a bug?

Module: Intro to C2 Operations with Sliver

When running any domain query commands via

-SharpView via execute-assembly
OR
-PowerView via sharpsh

I get the error

[!] rpc error: code = Unknown desc = implant timeout

I can run local commands such as 'Get-NetLocalUser', however any domain queries I get a timeout.

I can also RDP onto the VM and run the commands manually with Powerview/SharpView and both work querying the domain, this is just when executing via the session.

I've set the beacon timeout to 180 when generating, and also using -t 240 when running execute-assembly.

cedar yew
#

hi all
Module : AD attack enum
Section : ACL abuse tactics

my problem -> I get Access Denied error when creating a fake spn

fathom pendant
#

@cedar yew module is above tier 0 please refrain from posting info regarding it.

cedar yew
#

sorry

shut ice
#

@cedar yew I would open a new Powershell session and go through steps again

cedar yew
prisma wing
#

Hi all, i'm currently doing the pen tester path, i'm 80% done. I want to do a hard module after, what hard labs would you recommend for pen testers?

desert marlin
acoustic owl
unborn dagger
#

Hloo Guys I Am New To This Server

#

I Need Some Help

grave oasis
#

Hello lads, I've been trying to do the "Attacking Authentication Mechanism" skill assessment and I'm having issues in understanding what I'm missing.|| I've been trying to forge a new JWT with a new RSA key following the "Exploiting jwk" steps, but it seems like it doesn't work even if I don't change the payload, like it's not how it's supposed to be exploited. I'm also having issues running the script which gives me the error "AttributeError: module 'jwt' has no attribute 'encode'", and I've had to uninstall and reinstall pyjwt for it to work for some reason, but I'm still unsure if it could be an issue. Anyone would care enough to help me out with the reasoning to help me out a little? I've already tried each method explained in the JWT sections, if that could help in any way.||

late orbit
#

hey guys im struggling with the "Deobfuscation" in CBBH Path in The Question "Using what you learned in this section, try to deobfuscate 'secret.js' in order to get the content of the flag. What is the flag?", i've done everything correctly and got the flag but it shows incorrect answer any help ?

acoustic owl
unborn dagger
#

@acoustic owl

acoustic owl
unborn dagger
#

Yes Brother Itz About HTB Server Can I Please Speak With You @acoustic owl

fathom pendant
prisma wing
fathom pendant
prisma wing
supple dragon
grave oasis
glass egret
#

Hello guys, sorry to ask but im getting a problem on the last section of the 'Attacking Enterprise Networks ' module of the Penetration Tester Path in Hack The Box Academy. I've entered the commands as it says in the section, tried different methods like using ligolo and chisel. But when i try to use peoxychains to nmap the target, it always comes out as filtered ports. Just wondering if someone who's already done it can maybe help me. I've been stuck on this for 3 days and it's super frustrating.

sharp torrent
#

I’m currently in the password attack assessment for the hard lab. I’m having a hard time mounting the vhd file. Can someone provide help please ? Thanks in advance.

acoustic owl
#

The easiest way is to mount the drive in a Windows VM

glass egret
fathom pendant
#

you don't need proxychains if you're using ligolo btw

glass egret
#

yeah i know, i'll try again later tonight

round sail
#

Hey, I have a question regarding Kerberoasting - from Linux section on AD enumeration and attacks... In the section I get access to user and I need to answer question 'What powerful local group on the Domain Controller is the SAPService user a member of?' but I cannot figure out how to look at user by only being authenticated to linux and without access to windows 😦 Can someone tell me what tool can I use to get information about the current user from the linux host? Thanks a lot 😊

fathom pendant
#

the tool is mentioned in the section

fresh wedge
#

good day all, need help with the Password Attack Lab Medium. I found and retrived a documentnt via one of the open ports. However when trying to crack using john --wordlist=/usr/share/wordlists/rockyou.txt --format=pkzip clean.hash i am not get anything. I have even tried using the Password.list file also with no luck. can i get some help as i have already cleand the hash to use john and pkzip format

safe star
#

Have you tried the mutated list?

#

I don’t think the format is needed if you already used zip2john

fresh wedge
gray yacht
#

I don't recall if that is the flag or not, but you shouldn't post flags. If it isn't working, I would verify there aren't any leading or trailing space and input HTB{STUFF} as the flag.

brave prawn
#

Hey, I am doing Skills Assessment from Introduction to Sliver C2 module.

Is there any way to bypass uac for ||felipe|| via sliver? I can do it from rdp, but sliver tells "Access Denied" when running getsystem

west arrow
west arrow
#

Is it the guided-rdp?

proven skiff
#

anyone got stuck with chisel in password attack ( Pass the Ticket (PtT) from Linux )

follow the every step still same can't ping the 172.16.1.5 windows machine

acoustic owl
#

I don't know, maybe it's one of the other files. But resources are often overlooked.

#

But I think it is, because you also need a key, which is also included in the file.
but I'm not at the Computer and can't test it

median lion
#

Hola buen día , soy nueva en esta comunidad . 😎🌟 Y bueno estoy a qui para aprender muchas gracias .

acoustic owl
median lion
proven skiff
fiery berry
proven skiff
fiery berry
brave prawn
proven skiff
winged gate
#

hello guys, i'm acutally working trhough the penetration tester path.

i'm on the active directory module, when i'm trying to connect with the rdp session with htb credential the rdp doesnt work. is there any problem with the lab academy ? ty for your response

safe star
#

Sstimap is not needed to exploit

hexed oyster
hexed oyster
safe star
#

Just go with basic testing that they taught

hexed oyster
#

k

#

but it is the ssti?

simple vine
#

Hello! I am very new to all of this and I want to learn how to hack. I know it has a steep learning curve but I am willing to stick with it. I just think I need some direction on what to learn and how. I am currently a little under half way through the linux fundamentals module and I watched network chucks entire series over it but I still struggle to understand what the questions are really asking and how to get the answer. Should I just keep going and try to understand more and more as I complete more modules, or should I start somewhere else?

proud vector
#

You definitely want to know the fundamentals before you continue delving into any path, but once you do learn the cyber fundamentals, stick to a job path or cert path, which most likely woukd require you to get a subscription but it is worth it if you’re serious about getting into cyber security.

simple vine
#

i currently have the student subscription. the issue now I think is i dont even really know what the fundamentals are

dark hedge
#

the fundamentals can be found within the Information Security Foundations skill path

worldly badger
gray yacht
strange pivot
#

How can I search using an xpath injection? I can return all rows for the injection attacks skill assessment but Cant seem to find the row the flags on?

lapis sky
#

what's wrong with attack common services medium lab?

fossil jacinth
#

Sometimes for RDP I get black screen and have to press 'enter' or 'space'.
Also if I remember correctly there was some sub-module there where you had to use different credentials than the ones provided @winged gate

winged gate
fossil jacinth
#

Ah glad it's sorted out then 😉

stark rock
#

Can some one help me out here please? I am stuck on the question, Which network interface allows us to interact with the target machines in the HTB lab environment. This is from the Networks Foundations. I just can not figure it out lol

fathom pendant
stark rock
#

im runing the command nc TARGET IP 21 I have entered the FTP details and logged in, i have done the last 2 digits pt1 x 256 and the + pt2. I have then run the command nc -v 10.129.121.161 49676 and it has told me that connection is refused.... I got stuck on this bit yesterday and still it will not work, any suggestions as to what im doing wrong?

#

This is also Network Foundations

stark rock
#

I have done it multiple times now and still nothing, I even asked ChatGPT if there was anything wrong with the way i was doing it and the only thing it suggested was try ftp instead of nc and that just came back as log in to root so that was no help. I really dont see whats going on but this is seriously frustrating haha.

pale hull
#

anyone recall on Credential Hunting in Linux Module I remember sam password, but Kira I never got, just craked her notes password.

#

I should of saved all the creds I worked on 😦

fervent vessel
#

Someone is making "Abusing HTTP misconfiguration" module? I have problems solving Password reset poisoning, im not sure if the lab is broken or something

hexed oyster
#

@safe star I got it! Thank you, very much for your nudge.

coral summit
#

Can anyone help me with the skills assessment 2 for the login brute forcing? I have found the username of the ftp user, I have tried using username-anarchy and the passwords.txt with hydra and I don't get an answer, and medusa doesn't seem to want to work either

indigo fulcrum
#

Seems i got all th right ingredients to pull it off but for some reason nothing comes back after some coersion

#

wondering if its infrastructure related issues thats creating this behaviour...

gray yacht
serene drum
#

So I'm currently on the second to last section of sqlmap essentials. I've gained access to the system through os-shell, but am at a loss as to finding the other flag. It doesnt appear like I can CD so I am confused

#

Like I cant cd out of the directory it appears, the hint makes me think its a certain file but when I attempt to cat or edit the file nothing happens

#

If anyone could provide insight i would appreciate it

fathom pendant
fathom pendant
serene drum
#

I'm stumped

weak current
serene drum
#

I just dont know what I am missing

wide river
weak current
serene drum
#

Would anyone be willing to suggest what I might be missing

weak current
acoustic owl
#

@grim plaza Please read and follow #welcome to find better channels for your question

rocky spade
#

Hey guys, I'm having a problem with password attacks when attacking Active Directory on the machine.

When I try to create a shadow copy of the C: file, it creates it correctly, but after copying the NTDS.dit file, I get an error.

#

Could someone help me?

grim plaza
acoustic owl
grim plaza
acoustic owl
#

Yes, for web-based vulnerabilities

grim plaza
#

Ok thanks

rocky spade
#

Can someone please help me?

wide river
wide river
serene drum
#

Oh wow i figured it out

waxen totem
#

Feel like I'm going crazy, anybody else think that for Attacking Common Services that the Medium SA was easier than the Easy SA?

#

the easy one being rather difficult made me question my judgement a lot on the medium one

tame turtle
#

Hey guys, im doing the privesc on windows, in section SeDebugPrivilege, it states as follows "(though we can get SYSTEM access with just the machine NTLM hash, but that's outside the scope of this module)" in the last paragraph. I tried sekurlsa::logonpasswords, but the machine ntlm hash is empty, how do I go about getting it? (Yes its out of scope of the module, but I want to try it out anyway)

waxen totem
#

I only remembered cos I saw it in the cheetsheat

cloud urchin
tame turtle
cloud urchin
cloud urchin
#

This channel is for discussion of Hack The Box's various modules on the Academy platform, not tech support. Probably a better question for #1024429874246590575 and if you can't access that you'll need to verify your account by following the instructions in #welcome.

coral summit
slim otter
#

Just want to double check, the Password Attacks module doesn't teach us how to dump hashes with mimikatz for the Pass-the-Hash questions right?

#

We need to go and figure that out ourselves?

arctic spire
#

hi , i have an issue to apply this misson Nibbles - Initial Foothold
i have applied all the steps correctly but the listner is not workin in my case

full wagon
#

Windows privilege escalation module:
Hey guys, just feel I need to comment. I am following the "Pentester Job Role Path" and it is over all very good, extensive and I learn a lot, even after taking the PEN-200.
However, the Windows priv esc would really need some additional work. It's sometimes a bit poorly explained. To the degree that I need to slam the text into GPT and just ask it to explain what the author means. And sometimes it feels like one author wrote one part and another wrote antother and they never ever coordinated.
Well, no offense, but to get 5 stars for the course, this module needs to be updated. Cheers 🙂

steady pelican
#

Hello,
I am solving Nmap modules and stuck on Firewall and IDS/IPS evasion - Easy lab.
As learned in the module, and as it easy, I begin the scan by disabling the ping, arp ping and dns resolution. Along with -A option to identify the OS. Still the --packet-trace options shows that it is sending ICMP request. Can somebody tell me the reason.

cyan arch
#

curl command just doesnt seem to work for me on the linux fundamentals module

#

doesnt seem to be connecting to the website, i have tried loading the website in pwnbox and that also doesnt seem to load either?

fathom pendant
fathom pendant
steady pelican
#

||I have used this command -> sudo nmap (target-ip) -p80 -n -Pn -sA -A --disable-arp-ping --packet-trace||

cyan arch
steady pelican
#

Still it did not give me accurate result.

steady pelican
fathom pendant
#

You don't need -sA, don't assume the firewall exists/is properly configured

steady pelican
fathom pendant
#

Try a simple version scan instead of throwing darts at the wall