#modules

1 messages ยท Page 406 of 1

indigo fulcrum
#

I figured it out now though

#

Thanks for responding ๐Ÿ™‚

hollow knoll
#

hi, is answering questions in short form a bug or intended

#

like answer was p2p i can use peer-2-peer

hollow knoll
fathom pendant
#

i'm not staff though so idk

hollow knoll
#

i was just doing new andriod module same thing happened

fathom pendant
hollow knoll
#

it just feels like i didnt read the module correctly but then i realize i was right

polar iris
#

Am I at the right place to ask for advice regarding penetration tester job role path module?

hollow knoll
#

hide the answer

polar iris
#

Thank you

#

I already tried using Hydra and metasploit did not receive any valid credentials not sure how to proceed.

fathom pendant
#

each service has a unique user; perhaps c:/users can help narrow things down

polar iris
#

passwords for them should be bruetforced as well?

fathom pendant
#

yes

polar iris
#

I'm probably brain dead, I found the user list earlier all of them are in the username list but I still can't bruteforce the rdp or smb services. Maybe you can give me one more hint?

fathom pendant
#

you absolutely can brute rdp and smb

#

nxc works better for smb

fair mural
#

Been stuck on the Detecting RDP Brute Force Attacks in the Detecting Windows Attacks with Splunk module for the last 24hrs because every time I go to access the splunk application I get an error stating the server reset the connection. Basically hard stuck since no matter how many times I reset the target IP it still doesn't work and I've been waiting since 10am to speak to HTB support agent...

polar iris
outer tendon
#

guys where did the general chat go

peak bear
#

in powershell, what's the difference between the following?

... | ? {$_SecurityIdentifier -eq $sid}
... | ? {$_.SecurityIdentifier -eq  $sid}

one of the solutions to a question in the ad enumeration module relied on the first, which omits the dot

#

the second is accessing the SecurityIdentifier property of the object that's piped to it, but how is that first one interpreted?

#

to answer my question: i'm overthinking it, it's just a typo in the solution

gray yacht
#

Did you run Seatbelt and the Seatbelt module AMSIProviders?

desert fractal
#

chek ls

full drum
#

Hi there, i'm doing the NoSQL injection module. I'm on the In-Band Data Extraction page, and struggling to find a valid payload for a GET request. Any help would be much appreciated.

Edit: Ignore - got it.

deep pier
#

hi all I'm watching HTB yt channel on basic cybersecurity test would it be more beneficial to do the Linux fundamentals or to start the module itself

lime cosmos
#

Hey , anyway did getting started module in the last section there is a box .. here the link of the box : https://academy.hackthebox.com/module/77/section/721

I root the box (using sudo -l ) but they say there is 2 ways to gain root .. any hints I try search for the mothd 2 buy no luck..๐Ÿ˜€

lime cosmos
#

Yes

fathom pendant
#

there's no lab for this section

lime cosmos
fathom pendant
#

that's not a box btw; that's an academy section

#

module: Getting Started
Section: Infosec Overview

lime cosmos
#

It small challenge machine

#

To pwn

fathom pendant
#

where LOL this section doesn't have a machine or challenge

#

there's nothing to spawn here

lime cosmos
#

Ok let me check the link

#

we can't send pictures her right?

fathom pendant
#

not without linking your htb account per #welcome instructions

lime cosmos
#

Ok

#

sorry i made mistake i send the wrong link

fathom pendant
#

foothold means entry

#

one via metasploit and one manually

#

afaik only one way to actually get root from that

lavish ember
#

Guys I need help in Kerberos Attacks - Pass The Ticket:

When in use the .\Rubeus.exe triage I dont see any tickets available:

PS C:\tools> .\Rubeus.exe triage

   ______        _
  (_____ \      | |
   _____) )_   _| |__  _____ _   _  ___
  |  __  /| | | |  _ \| ___ | | | |/___)
  | |  \ \| |_| | |_) ) ____| |_| |___ |
  |_|   |_|____/|____/|_____)____/(___/

  v2.2.2


Action: Triage Kerberos Tickets (Current User)

[*] Current LUID    : 0x49898

 ---------------------------------------
 | LUID | UserName | Service | EndTime |
 ---------------------------------------
 ---------------------------------------
lime cosmos
#

ii yes the foothold i did it using metasploit (easy + no need to the authentication ) + Manuel already did it

fathom pendant
#

as it states:
Two ways to gain FOOTHOLD

#

so you've been chasing a rabbit hole

cloud urchin
fathom pendant
#

ah nvm it does mention two root vectors

lime cosmos
fathom pendant
#

but imo it's not really all that important @lime cosmos

lime cosmos
#

"There are two ways to escalate privileges to root on the target after obtaining a foothold."

fathom pendant
#

i suggest moving on with your life and moving forward and coming back to challenge a different way once you have more experience with other modules

lime cosmos
fathom pendant
#

if you're doing the cpts path; the linux privesc module is way down the line

lime cosmos
#

yes am doing cpts path

fathom pendant
#

imo getting the manual foothold is better than finding another root vector

cloud urchin
#

@lavish ember no need to post content from the module. Remember it's against the rules for anything above tier 0.

fathom pendant
#

shows that you don't need to rely on too many tools to get the way forward

lime cosmos
#

yes i get it

#

thanks ๐Ÿ˜‰

lavish ember
#

I feel like it's glitched

cloud urchin
lavish ember
#

I tried both

lime cosmos
#

rebeus lol i see this tool on mr robot serie

cloud urchin
#

well the command prompt wouldn't have any. it's been a really long time since I did this module but there should be some in the powershell session. first thing i'd try is restarting the target i guess. it could also be you haven't waited enough time.

lavish ember
#

So am I stuck there forever? haha

cloud urchin
#

I'll try, give me a sec

lavish ember
#

okay tyt

cloud urchin
#

Alright, works for me. Sometimes you need to execute commands under another context.

lavish ember
#

so the box is fine I just need to think of another approach with the command you mean>

cloud urchin
#

yeah the command works fine

#

i was able to replicate pulling the tickets and also what you did pulling no tickets

lavish ember
#

I think I get it

#

It shows to me what the current user have only

#

not all users right?

cloud urchin
#

Think elevated context.

lavish ember
#

okay it worked lol

#

Thanks for the help! โค๏ธ

rose stratus
#

Stuck on Attacking Common Services - Easy Question " You are targeting the inlanefreight.htb domain. Assess the target server and obtain the contents of the flag.txt file. Submit it as the answer." Found user but unable to bruteforce password using rockyou against smtp. Advice?

cloud urchin
rose stratus
#

yea didn't work as well

cloud urchin
#

oh ok. i actually didn't take notes for the easy lab so i can't help much.

rose stratus
#

nvm, got it. stupid port 25 closed on me. had to revert box

restive olive
#

Hello guys,
Iโ€™m stuck for two evenings on XSS module skill assessment, made everything but still the request is not reaching my myip:port/script.js. Any advice?

gilded thorn
#

@runic rampart I was able to find the flag. I had to basically do a Mana attack that was shown in the WPA3 section (mac.conf), and then make sure your MAC address matches the target AP. That will jam the target AP, which will disconnect the client. Then, you can do the Wifiphisher plugin attack. That worked for me.

nova knot
#

stuck on the final question in the Footprinting module, DNS Section (What is the FQDN of the host where the last octet ends with "x.x.x.203"? )

nova knot
#

so i gotta "dig" deep?

waxen totem
#

yep ๐Ÿ˜‰

nova knot
#

mhmm, ig i tried, lemme give another shot

waxen totem
#

maybe you only tried the surface level, remember, dig deep

#

What do you mean? Reading and doing all that IS the module...

nova knot
#

going through the info first and continue with modules

nova knot
waxen totem
#

Do the modules in order, that's very important because the modules depend on information you gathered from previous modules

#

Nahh, it's a module, keep following it

#

There are no info boards on academy

nova knot
#

fine, then go through it tmrw, if u wanna do smtg practical rn

#

but I highly recommend doing it in the order, a lesson I learnt in my early days ๐Ÿ˜…

#

u dunno which command and/or information could help you during assessments

#

it's info about how the actuat pentesting cycle works

nova knot
#

i've fount a 201 and few other FQDN's but nothing for x.x.x.203

spring trail
#

if you saw a web app page that can modify the user info, and upload image profile, what you gonna think of to try and play around with?

nova knot
#

the hint under question says, "Remember that different wordlists do not always have the same entries." when I used dnsrecon to brute force, it took forever

nova knot
lean prism
#

Hello, good evening, do you help people with computer virus problems?

nova knot
lean prism
#

yep

spring trail
lean prism
#

I was infected

nova knot
#

ig the server's not directed in what you're looking for, personally i'd suggest you to contact someone trustworthy in person, or fall back to trusted antivirus softwares.

#

if you want a suggestion you can DM me, about the specifics

lean prism
# twilit gust Yes I can help you

A few hours ago I installed a file directly from discord and since then the cmd suddenly started appearing on my screen running users\public\microsoftedg and below some lines talking about RegAsm

twilit gust
#

Let me dm you okay?

lean prism
#

ok

waxen totem
cobalt acorn
#

what is the password here ? i believe their is no password in this right ? if yes then when its asking for password and i am just pressing enter its showing wrong password , so is their really password which i am missing ?

#

btw this is Skills Assessment section of Introduction to Windows Command Line

#

please do guide me on this asap :-))

waxen totem
red steppe
#

Has anyone done the module Active Directory TRust Attacks: Attacking Cross Forest Trust

I cant seem to authenticate using rdp, has anyone experienced this issue before?

signal hound
#

Hi am doing web proxies module ZAP fuzzer
I need to brutrforce the user cookie after encoding with md5 hash
But in the request there is no a user parameter or similiar in order to mark as a location

peak bear
peak bear
signal hound
peak bear
signal hound
#

Mind if DM u?

peak bear
#

yeah sure

nova knot
#

anyone have idea where i could find footprinting-wordlist

waxen totem
#

Anyone up to discuss the Pivoting Skills Assessment? I just have a quick question about the network addresses and masks/CIDRs that I've noticed.

waxen totem
nova knot
#

when i try to brute force using the given wordlist under resources the username didn't turn up in the results? am i missin smtg

#

smtp-user-enum -M VRFY -U u.txt -t 10.129.42.195

#

this is teh cmnd i'm using

waxen totem
nova knot
#

EXPN,RCPT also gave the same o/p and this time the target is running, i'm currently running the same cmd with -w 60 to increase timeout gotta see if i'd get the result

#

yup -w 60 worked

gray yacht
waxen totem
grizzled schooner
#

Attacking SAM

I have the registry files, but when I run the secretsdump.py nothing's happening, not sure if I'm missing something or maybe something whacky is happening with my kali?

grizzled schooner
#

Yes I have all 3

#

``โ””โ”€$ python3 /usr/share/doc/python3-impacket/examples/secretsdump.py -sam sam.save -security security.save -system - system.save
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[-] RemoteOperations failed: [Errno Connection error (system.save:445)] [Errno -2] Name or service not known
[*] Cleaning up...``

rustic sage
#

python3 /usr/local/bin/secretsdump.py -sam sam -system system LOCAL

peak bear
#

you need a target

rustic sage
#

local as in the domain

grizzled schooner
#

at first I did - LOCAL like it was in the module, same thing happened

#

``โ””โ”€$ python3 /usr/share/doc/python3-impacket/examples/secretsdump.py -sam sam.save -security security.save -system - system.save -LOCAL
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

usage: secretsdump.py [-h] [-ts] [-debug] [-system SYSTEM] [-bootkey BOOTKEY] [-security SECURITY] [-sam SAM]
[-ntds NTDS] [-resumefile RESUMEFILE] [-skip-sam] [-skip-security]
[-outputfile OUTPUTFILE] [-use-vss] [-rodcNo RODCNO] [-rodcKey RODCKEY] [-use-keylist]
[-exec-method [{smbexec,wmiexec,mmcexec}]] [-use-remoteSSMethod]
[-remoteSS-remote-volume REMOTESS_REMOTE_VOLUME]
[-remoteSS-local-path REMOTESS_LOCAL_PATH] [-just-dc-user USERNAME]
[-ldapfilter LDAPFILTER] [-just-dc] [-just-dc-ntlm] [-skip-user SKIP_USER] [-pwd-last-set]
[-user-status] [-history] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key]
[-keytab KEYTAB] [-dc-ip ip address] [-target-ip ip address]
target
secretsdump.py: error: unrecognized arguments: -LOCAL
``

peak bear
rustic sage
#

check the size of the sam and system files - do they match the target file's size

grizzled schooner
#

got rid of that dash "-" kept local, same thing happened

peak bear
#

secretsdump.py -sam sam.save -security security.save -system system.save LOCAL

rustic sage
#

they're big files - sometimes they don't transfer over entirely and it's something to check

waxen totem
grizzled schooner
waxen totem
peak bear
#

can you post the command again that you're running

rustic sage
grizzled schooner
#

``python3 /usr/share/doc/python3-impacket/examples/secretsdump.py -sam sam.save -security security.save -system system.save -LOCAL
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

usage: secretsdump.py [-h] [-ts] [-debug] [-system SYSTEM] [-bootkey BOOTKEY] [-security SECURITY] [-sam SAM]
[-ntds NTDS] [-resumefile RESUMEFILE] [-skip-sam] [-skip-security]
[-outputfile OUTPUTFILE] [-use-vss] [-rodcNo RODCNO] [-rodcKey RODCKEY] [-use-keylist]
[-exec-method [{smbexec,wmiexec,mmcexec}]] [-use-remoteSSMethod]
[-remoteSS-remote-volume REMOTESS_REMOTE_VOLUME]
[-remoteSS-local-path REMOTESS_LOCAL_PATH] [-just-dc-user USERNAME]
[-ldapfilter LDAPFILTER] [-just-dc] [-just-dc-ntlm] [-skip-user SKIP_USER] [-pwd-last-set]
[-user-status] [-history] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key]
[-keytab KEYTAB] [-dc-ip ip address] [-target-ip ip address]
target
secretsdump.py: error: the following arguments are required: target
``

peak bear
waxen totem
#

LOCAL is your target cos you got the registry files downloaded on your LOCAL machine

rustic sage
#

so you need specify the target somehow - could try the ip

grizzled schooner
waxen totem
peak bear
grizzled schooner
# waxen totem show again please

sorry, not same error - different one:

``โ””โ”€$ python3 /usr/share/doc/python3-impacket/examples/secretsdump.py -sam sam.save -security security.save -system system.save LOCAL
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[-] [Errno 2] No such file or directory: 'system.save'
[*] Cleaning up...
``

waxen totem
grizzled schooner
#

yeah I just double checked on my desktop to make sure that's what it's named

rustic sage
#

remove the .save - make sure those system, sam, security are all in the directory you're running the script from

waxen totem
#

what directory are you running the command in?

grizzled schooner
#

desktop

waxen totem
#

can you ls -lash

grizzled schooner
#

I'm just going to re-download them

#

yeah one sec

waxen totem
grizzled schooner
#

... 65 kb?

rustic sage
#

In AD Enumeration & Attacks - Skills Assessment Part II - Question 6 - I could never get creds from winpeas, snaffler, or seatbelt - has anyone else recently done this?

#

the netdb user

peak bear
waxen totem
peak bear
prime magnet
#

Hi , " you already have an active machine" how can i fix that ?

#

I can't start it

waxen totem
peak bear
grizzled schooner
#

it seems to have worked just re-downloading them

rustic sage
waxen totem
#

@prime magnet

grizzled schooner
#

not sure what happened before?

rustic sage
prime magnet
#

Thank you guys

waxen totem
#

btw @prime magnet @peak bear please get verified!
instructions ---> #welcome

prime magnet
#

ok

#

why I got 'Noob' In my profile FeelsBadMan

rustic sage
#

you've been exposed that's all kek

waxen totem
gray yacht
warm drift
fathom pendant
true wing
#

I did email at that email but didn't got any reply yet does it usually take that long??

true wing
#

Any estimated time I can expect??

fathom pendant
#

no idea i'm not staff

true wing
#

Okay thanks for the reply

acoustic owl
fleet rose
#

Hey guys. Been lurking for a while, figured I'll jump in now that I'm going to school for cybersecurity and doing modules as well

fathom pendant
fleet rose
#

I enjoy a good Ole search button. It's been my friend while I lurk

near orchid
#

hey, atm i am doing the "Getting Started" module page "service scanning"

#

i am required to enter bob's password which is given in the module but bash will not allow me to enter any text here

#

anyone has any idea why bash will not allow me to input bob's password

autumn pilot
#

you will not see typing the characters (e.g., the *****), type the password and press enter

fathom pendant
#

with bash it's a security feature to not show the password or even masking characters as you're typing

#

this is also to prevent shoulder surfing as someone may see how many characters a password is

near orchid
#

thanks for the help

#

didnt know that

warm drift
fossil jacinth
#

Anyone did Ffuf module from CPTS as of late ?

ruby yoke
#

guys can someone give me a hint in the skill assessment of advanced sqli

fathom tide
#

what am i doing wrong?

fathom pendant
#

errors 372
is your hosts file correct?

fathom tide
#

seems so

#

the machine reset now so its a different port

hushed socket
fathom tide
#

cause the machine has a port

hushed socket
#

But you want to find subdomains, the port is to request for the specific service under this port

#

Can you try once without the port?

fathom tide
#

yea i tried that before still got errors

fathom pendant
#

and the web service is specifically running on that port that he has to attack

#

so it's not on default 80

acoustic owl
hushed socket
#

Got it

fathom tide
#

so all domains are linked to that port

fathom pendant
fathom pendant
fathom tide
#

what am i doing wrong then

#

guess i should try gobuster

fathom pendant
#

could be some weird issue with your router killing the traffic, assuming on a vm try switching from bridged -> NAT or the other way around

signal hound
#

Hello
Doing web proxies assessment question 3
I modified the cookie as was needed and i got the flag
But i dont understand why all cookies that were modified in the list give the flag?

fathom pendant
#

but a good handful; this is mostly by design of the lab to avoid spending a lot of time waiting on the attack to finish

signal hound
#

Oh ok thanks

hushed socket
#

I have started Documentation & Reporting Practice Assessment. As I prefer working from my kali machine, I am trying to use Dynamic port forwarding through ssh so that I can enumarate from my machine. But It is not working. When using nmap from the parrot machine I get results from the target host (let's say 172.16.5.200) but I get timeout from my machine. I have also tried with chisel but I again I don't get results. Any idea why?

fathom pendant
#

using sudo?

#

i used ligolo for my proxy needs ยฏ_(ใƒ„)_/ยฏ

#

so i never bothered with pf stuff

hushed socket
#

No without sudo. I have tried though with sudo as well but didn't work either

fathom pendant
#

i assume with nmap you're using the -Pn flag?

hushed socket
#

yes

fathom pendant
#

icmp traffic isn't a fan of some proxy/pf types

hushed socket
#

So it might not always work?

fathom pendant
#

i don't have much notes on this module or using ssh port forwarding/chisel

uneven crater
#

Hello i have a problem with the linux module, i need to get the last modified file in the /var/backups directory. my input command is $ls -la -l -lt /etc/ which would give me the latest modified hidden file but it doesnt seem to work

#

i have connected to the ssh

fathom pendant
#

-la is the same as -l -a

#

Same with -lt, -l -t

fathom pendant
#

Also the path

uneven crater
#

i put the path behind it

acoustic owl
#

Yes, but you want to look at a different path than the one you specify in the command.

uneven crater
fathom pendant
#

Read the question, then the command you put

fathom pendant
#

Note: not all tools allow for squished flags

#

My favorite udp scan though is nmap -sUV

uneven crater
#

got it ๐Ÿ™‚

#

guess samba wasnt a file xd

fathom tide
fathom pendant
#

Though getting pedantic: everything is a file in linux

thin cradle
#

Hello @fathom pendant Im doing SCCM module. 'Connect to the shared folder \LAB-DC\SCCMShare\PUSH using the PUSH account and read the content of the flag.txt.' However the creds do not work. Can you help me with this?

timber shell
#

hey guys do you also face with difficulties with Academy targets, most of the time the server wont respond. I was doing "Advanced SQL Injections" skill assessment but the generated target stalls every 1-2 minutes I tried to reset it but still works soo bad

hollow knoll
#

in this questions this happened again *in new android fundamentals module

#

CoolName is correct answer but coolname is not

#

like its not programing question

#

or there should be hint saying 'case sensitive'

dense tree
#

after 2hrs and about 70 cmds. I would like someone to please tell me which "CMD" line is to be used (not PS).

Introduction to WIN CMD LINE> Finding Files & Directories> 2nd Question. aka find Waldo.txt

rich salmon
#

Hi guys i'm at the Information Gathering-Web Edition module and Fingerprinting section and i can't access app.inlanefreight.local thus can't answer the 2nd question. Can anybody help?

safe star
#

Did you add it to your /etc/hosts file?

winter schooner
winter schooner
fathom pendant
balmy apex
#

What is the best place to ask for help on intro to bash comparison exercise?

#

I am stuck

rustic sage
#

Ahoy y'all! I am working on the SIEM Visualization Example 2 module from the SOC analyst path, and I am totally stuck on the last question. It asks what should follow user.name in the KQL query in order to filter by admin users only. I feel like the obvious answer would be ||admin* or administrator||, but I have not been able to figure out an answer that the answer box will accept. Am I thinking about this right?

fathom pendant
#

think of all scenarios

undone mesa
#

Hello, Im stuck in the credential hunting in Windows i found everything execpt the WinSCP password.
To do so i mv Lazagne to the Windows but it says password not found is it normal ?

fathom pendant
#

@pale silo your post also is spoiling an active machine, for active boxes you need to ask for nudges for steps and not spoil directly what you've found

pale silo
#

ok, thx. I'm now registered

pale silo
#

anyway, what should i do? maybe some advice?

fathom pendant
#

:)

dull carbon
#

Hello can someone give a bit of advice on the burp intruder module

The question is Use Burp Intruder to fuzz for '.html' files under the /admin directory, to find a file containing the flag.

Using the common.txt word list, with burp suite throttle this is probably going to take 12 hours, am I on the right track

waxen totem
#

Probably better to just use another fuzzer

dull carbon
#

I cant extend the machine either ๐Ÿ˜–

#

66 minutes left

waxen totem
#

Also missing a slash after admin

dull carbon
#

ahhh thank you of course ๐Ÿคฆ

#

Ill try Caido or ZAP, thanks for the info

fathom pendant
#

i don't recall issues with intruder on this taking too long

#

i just monitored the results

dull carbon
#

Im on 274/4734 on the wordlist with only 59 minutes left on the machine and no option to extend the machine

#

Im wondering if there is a smaller wordlist Im suppsoed to use

fathom pendant
#

yeah the public IP won't get extended

rough comet
#

Hi folks

#

I am on INTRODUCTION TO WINDOWS EVASION TECHNIQUES .

#

But I am a bit lost

#

Where do we suppose to compile the shellcode? on victim?

#

The shellcode itself.... should I use NotMalware ? the c# code? but insert the msfvenom line based on our IP address?

fathom pendant
#

does the module not give you a dev machine to mess with?

dull carbon
#

FFuF found the directory for it in 20 seconds, ty @fathom pendant & @waxen totem for the pointers. So much for it being a learning module for burp suite ๐Ÿ˜‚

severe inlet
barren apex
#

Hey guys, sorry for the irrelevant question, where can I ask for nudges regarding traditional machines?

dull carbon
#

@severe inlet thanks, I did and it worked a treat, I really think any fuzzing modules concerning Burp suite should have a word list supplied, I dont mind waiting an hour or so but the throttling just makes the learning process paingful\

severe inlet
#

You just need to understand how to use the intruder after that feel free to use ffuf or something else

dull carbon
#

Indeed, I have Caido installed but have yet to get my head around it, Once I break up from University I'll dedicate some time to learning it

waxen totem
uneven crater
#

can someone explain why if i count installed packages with $ apt list installed | wc -l it counts 738 and if i use the | grep -c installed* it counts 737?

full drum
#

Hi! I'm on the Skills Assessment 2 page of the NoSQL Injection module. I have a good idea of what i'm supposed to do, but I'm struggling with a valid payload to trigger some kind of a different response. I have a valid username, and understand where the injection point should be, but can't seem to trigger it in any way, can someone please help me out?

uneven crater
#

it worked on conf files before tho

#

not sure why it doesnt work on installed packages

waxen totem
uneven crater
#

okay thanks!

fathom pendant
lime cosmos
#

hey

waxen totem
lime cosmos
#

i can't try them all (--script All ) it will take long time

waxen totem
#

So just try specific ones based on the services you've found

lime cosmos
#

ok

rough comet
#

Is the code in that Dev box ? How can I obtain that IP so I can RDP and do the required work ?

fathom pendant
gray yacht
# rough comet Is the code in that Dev box ? How can I obtain that IP so I can RDP and do the r...

Essentially you can have the introductory section open in one tab of your browser for spawning your DEV instance and in another tab work through the sections that contain your TARGET instances. I recommend building a few different payloads out, just in case, but follow along with the section, use what is provided and you should be good. Make sure you pay attention to detail when you are building things out. You'll have to terminate your DEV instance to start your TARGET instances. Hopefully that isn't too confusing.

full drum
#

How often can i re-ask the same question for help if I don't get any response?

fathom pendant
#

@rustic sage this isn't a hacker4hire server

full drum
fathom pendant
rough comet
fathom pendant
#

But I'd also advocate for working on the problem while waiting on someone to answer

#

Rubber duck debugging is a real thing, you ask your question and immediately see the solution

#

Without a reply from anyone

waxen totem
full drum
fathom pendant
waxen totem
fathom pendant
#

Ah right, buried

#

But yeah things like that get moved to dms because the module is above tier 0

#

So to avoid spoilers; it gets shifted to dm :)

full drum
fathom pendant
#

I've seen cases where someone replies to a message a while later asking if still need help sometimes days, sometimes months

#

But either way deleting it really doesn't help your case

full drum
# fathom pendant You don't have to delete

If anyone does what I do and use the "In: [hashtag]Modules" search function, they might just see my non-answered result several times, rather than something that can help them. It seems better to delete a question that hasn't been responded to.

rough comet
lime cosmos
#

hey

#

still nothing find

#

i try many nmap script tom find the flag as they say + 1 Use NSE and its scripts to find the flag that one of the services contain and submit it as the answer.

fathom pendant
#

-sC should show an interesting file on the server: it may not enumerate the page

lime cosmos
#

i try it before and i did not get anything

#

i will try again -sC

fathom pendant
#

If you're given ip:port, specify port

lime cosmos
#

no port given

fathom pendant
#

Then sC should get it

#

Note: you may need to manually enumerate past the script

lime cosmos
#

waiting the results of -sC . hope so get the flag

lime cosmos
fathom pendant
#

There will be a .txt file that's revealed

lime cosmos
#

where ?

fathom pendant
#

The -sC should find it

lime cosmos
#

ok

lime cosmos
glacial remnant
#

working through the footprinting module now and there have been a few times ive gotten an answer but not so sure that was the intended way to get there. is there ever a resource that shows the other ways i could have skinned the cat? (or maybe a less barbaric analogy saying other ways to get the same solution)

silent kayak
#

Who won the partner up with me or be my mentor and teach me python

fathom pendant
#

Try http specific scripts

fathom pendant
lime cosmos
#

Yes I try --script 'http*'

fathom pendant
fathom pendant
#

Maybe try just the http scripts mentioned by the examples

lime cosmos
#

I try them... All lol

fathom pendant
#

ยฏ_(ใƒ„)_/ยฏ

lime cosmos
#

I can't access the exam if I don't answer all the modules questions/laps ?

fathom pendant
#

you need to complete the path 100%

spring sluice
#

hi MarcieLee, I could ask you a question via DM

magic mango
#

where do i post about issues with a module? like i'm struggling and need answeres

fathom pendant
burnt knot
#

I am stuck on question 1 in the WordPress skills assessment. I have run every thing I can think of and the site say's it not a WP site. It's run on Apache 2.4 but I cannot seem to get to see the verison.

cloud urchin
burnt knot
#

I will look again but the source code all looks the same

rustic sage
#

I mistakenly closed the cmd console when I rdp'ed into internal network in AEN. Is there any coming back from this without having to restart the target?

cloud urchin
#

can you not simply re-open the terminal?

rustic sage
#

The session was just a console session

cloud urchin
#

press the space bar

rustic sage
#

Its not a full RDP session, but just a cmd console session

#

which I closed lol

cloud urchin
#

ahh ok. i don't know.

fathom pendant
vast wind
#

Hey I am on Getting Started in Privilege Escalation, Iโ€™ve sshโ€™d into the machine but I canโ€™t figure out how to escalate privileges.

fathom pendant
#

i forget is that the one where you have to get to user2 then root?

#

always check what your user can sudo;
always check for files that you shouldn't have read access to

vast wind
#

Yes

#

Okay

fathom pendant
#

those are separate bits of info btw ๐Ÿ˜‰

#

sudo can be thought of as the linux equivalent to runas

#

man sudo or sudo --help iirc should get you more info what sudo can do

vast wind
#

Iโ€™ve check sudo Iโ€™ve tried looking for etc/shadow, and ssh keys but I canโ€™t find anything

fathom pendant
#

if so: there is something hiding in the roots ๐Ÿ˜‰

silk shard
#

m

tawdry pasture
#

Hi, who can help me with the command to know how many services are listening on the target system on all interfaces? (Not only on localhost and IPv4) I am stuck

dense tree
#

can i get help from a pro hacker pls... I found an issue and I think this may need to be reviewed...

#

this wasted a lot of time of mine... and I just want to make sure I understand the instruction correctly.

#

@west canopy are you able to assist me please?

#

after 2hrs and about 70 cmds. I would like someone to please tell me which "CMD" line is to be used (not PowerShell command, since the module is only about CMD host enumeration).

Module: Introduction to WIN CMD LINE> Section: Finding Files & Directories> 2nd Question. "Waldo.txt"

#

I can tell you - that yes, a PS cmd worked, but the questions explicitly states, only using commands that we have learned up until this point, which was all CMD CLI... So, was there a package that was needed to be installed again once I ssh'd back into the instance and opened up the terminal for for the sudo PS / sudo CMD interface? because barely and commands worked

storm elk
waxen totem
waxen totem
storm elk
#

The solution is funny though

#

Solution uses PS sus

dense tree
waxen totem
#

Maybe try find waldo.txt C:/

storm elk
#

Iโ€™ll have a look when I get on my pc

waxen totem
#

Same, am on phone rn

dense tree
#

and any command that was taught did not work

#

nope..

#

tried it

waxen totem
dense tree
#

work on it when you get back.... ๐Ÿ™‚

#

now you know why i pinged a staff member

waxen totem
#

No need to ever ping staff

dense tree
waxen totem
#

@dense tree figured it out, if you can see PS in the prompt its a powershell prompt and where is aliased to where-object which has a different syntax

To fix: run cmd to enter cmd context then run the where command

dense tree
#

issue I had is that I overlooked; although I knew how to access cmd & PS through the xfreerdp >WIN VM.
I didn't know that I had to use the CMD prompt inside the PS CLI that that I ssh'd into... But you taught me something new about this VM instance. Thank you very much.

eager ledge
#

Hi

Module: Windows Privilege Escalation
Section: Kernel Exploits
Section link: https://academy.hackthebox.com/module/67/section/627

To exploit CVE-2020-0668, the text says:

we can also look for any third-party software, which can be leveraged, such as the Mozilla Maintenance Service. This service runs in the context of SYSTEM and is startable by unprivileged users.
What if "Mozilla Maintenance Service" is not present in the system. How can we find the third-party services that runs in the context of SYSTEM and is startable by unprivileged users?

autumn pilot
#

In this case you will have to enumerate the system and take stock of what is installed, and, subsequently, you will perform a research to find if any of the found services can be used to escalate your privileges. In the future, when you advance and hone your skills, you may find something that hasn't been uncovered yet.

teal sparrow
#

Wordpress module skill assesment find the vulnerable plugin with unauthenticated file download but i have no idea how to use the poc

thin citrus
#

Course says: 'An attacker can employ various methods to force a null origin on a cross-origin request, which is subsequently trusted, resulting in a Same-Origin policy exception.' this can be done by using 'sandboxed iframe'. But it did not work either:

acoustic owl
thin citrus
#

Others did that too, but sorry

acoustic owl
thin parrot
#

Man I was about to grind out shells and payloads then the internet went out sadglas

uneven crater
#

Good morning, when i put in this command curl https://inlanefreight.com | grep -oE 'https?://inlanefreight.com[^"#]+ i stays stuck at >

hushed rivet
#

i think i found an unintended solution in web service & api attacks on the section of "Information Disclosure (with a twist of SQLi)"

uneven crater
empty badge
#

is the target machine also available for just 2 hours to free users? if im using openvpn n my own machine?

#

or thats just for pwnbox

hushed rivet
#

pwnbox

#

afaik

acoustic owl
hushed rivet
#

where can u report unintended solutions

lime lake
#

Could anyone help me in module 77 section 843? Please DM me
I am inside of "Getting Started" and at "Public Exploits"

sturdy ivy
#

Okie dokie, another 'Print Spooler & NTLM Relaying section.' question.

I have successfully rdp'd from kali to DC1 and changed the registry value to 1 and restarted DC1.

Back on the kali machine I've run ./dementor.py 172.16.18.20 172.16.18.3 -u bob -d eagle.local -p Slavi123 and impacket-ntlmrelayx -t dcsync://172.16.18.4 -smb2support

I have received two error messages:
||[-] exception RPRN SessionError: code: 0x6ab - RPC_S_INVALID_NET_ADDR - The network address is invalid.||

||[-] exception RPRN SessionError: code: 0x6ab - RPC_S_INVALID_NET_ADDR - The network address is invalid.||

Both don't answer the question. Unfortunately, being in Aus RDP is snail slow and makes the whole process pretty frustrating. Would love a hint in the right direction, Thank you!

hushed rivet
#

reported it thanks @acoustic owl

plain charm
#

hello. I am at Pivoting,Tunneling & port Forwarding Module where we have to use meterpreter for port forwarding, my question is: the module is not seting the active meterpreter session into the socks_proxy module of metasploit. so How will it route the traffic through the pivot?

#

I think there is a option to set session like we set other parameters, but HTB didn't use it, dont know why?

waxen totem
safe star
plain charm
waxen totem
#

The socks proxy allows our attacker machine to interface with msf's network structure through proxychains, msf itself creates routes towards the target through an active session using autoroute

plain charm
#

okay, so the scenario is this: first we created the socks proxy to route all traffic from msf network structure, then we used autoroute to add a route to that network structure binding the session to it. so we can use proxychains to route through msf network and use the routes created by autoroute!

#

is this correct?

waxen totem
#

kinda lost me there but essentially:

  • route/autoroute: creates iptable route to route traffic towards the networks in the active meterpreter session
  • socks_proxy: runs a server on the local machine to route any traffic given to it through metasploit's ip route table
  • proxychains: runs a command through the socks proxy
plain charm
#

Yeah. I got it, Also sorry that my question was confusing.

waxen totem
analog kiln
#

Ok

waxen totem
#

@analog kiln I will now delete your messages as it violates rules of the server to ask for such.

analog kiln
#

Ok

fallen plaza
#

Hello, has anyone completed the Spookifier challenge? I already have the flag, but I'm trying a reverse shell, and it doesn't work. Am I the only one trying to do this?

waxen totem
golden gate
#

hello guys
im doing a simple task in one of the sections in introduction to windows command line

to do the task i need where but it's just not there
is there any alternative commands you can suggest

golden gate
#

ty
i didn't realize im in power-shell not cmd

waxen totem
fathom pendant
waxen totem
golden gate
pulsar needle
#

Where do I ask questions about a lab in a module?

#

I am stuck on Linux Priv Esc Environment Enumeration lab

dark hedge
#

you can ask in this channel

pulsar needle
#

Guys I am on the second user on the machine but I don't know where to go from next.

#

I did the sudo with the binary as another user.

#

I don't see anything useful in the second user's home directory

#

module/51/section/1592

#

Uhhh never mind guys i just found it, was in a place I never expected it to be at

#

It is just confusing because it said this module is for linux environment but the lab got nothing to do with that at all. It is totally irrelevant.

lime lake
#

Could anyone help me in module 77 section 843? Please DM me
I am inside of "Getting Started" and at "Public Exploits"

brave prawn
#

Can I DM someone on LOLBAS: Rundll32.exe section in Windows Evasion Techniques module?

pulsar needle
#

Guys how do I link my hackthebox with discord? and also why i cannot chat in #general ?

pulsar needle
#

Thanks

regal sigil
#

Hi can someone help me, I do not understand what is wrong with my powerview. I cannot get the Get-DomainUser function to work

Get-netuser works fine

plain charm
#

it clearly stats that the first cmdlet is not recognised, its powerview i guess. make sure you use the correct version of it of re-check the syntax

#

also try re-loading the module

regal sigil
plain charm
prime magnet
#

guys what should I do if all the ports closed ?

rustic sage
prime magnet
#

-sU and -sS yes

plain charm
prime magnet
#

and -A

rustic sage
#

is this by any chance part of the Footprinting module?

#

can you ping the target?

tawdry pasture
prime magnet
rustic sage
distant ibex
#

i can't find flag it doesn't exist

#

SPN Jacking

ruby yoke
#

Has anyone done Question 2 in skill assessment in advanced SQLi?

timber shell
#

Hey guys, has anyone completed "Advanced SQL injection" if so then could you please help me with final RCE skill assessment?

inner wadi
#

Hi, as funny as this may sound, can someone give a hint where to go for solution 6 - the last question in Windows Lateral Movement SA? I have the VNC password

gray yacht
dense tree
#

lol - I ran "Get-ChildItem -Path HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion -Recurse" on my local....

#

not recommended

fathom pendant
#

i mean, not like it breaks anything

dense tree
full wagon
#

Citrix Breakout, Windows Privilege escalation, question 2, admin flag.
I could || spawn cmd || and read the first flag. Looked for easy paths to escalate. Found none. So. Now I want some tools. So I tried mounting a SMB share, failed. So checked connectivity. When I ping my Kali and the IP I could first RDP into, there is no connection. Pinged localhost just to verify that ping worked. It did. Is this expected? Should I find a route without needing anything uploaded? Not sure how to upload anything. Also tried alter the network settings in the VDI I'm in, but got denied. Any hint on how to move forward?

And btw, it is indeed extremely laggy the instance, but I guess you already know that. cheers

fathom pendant
rustic sage
full wagon
rustic sage
fathom pendant
#

@midnight vigil i don't do private dms unless either;

  • I already know you
  • it's for business
split cliff
#

Question about a specific situation in the "Linux Fundamentals," course. I've completed it. I've run into a problem in the "Task Scheduling" unit. There is a single question in it. I made an honest mistake in my answer. I provided x-xxxxxxxxxx (obviously this is not the correct length answer, I don't want to give any hints). The answer was what I provided, but without the hyphen (again, I'm hiding even the answer length). I tried the answer without the hyphen, and it was accepted. It still shows as the answer. But I can not, for the life of me, do anything to get the green checkmark to complete the "Task Scheduling" unit in "linux Fundamentals." What am I doing wrong? And yes, I hit Mark Complete & Next at the bottom.

#

Figured it out, I had another tab open.

#

Naturally I had to ask before I could figure it out.

inner wadi
glossy cloak
#

help plz... I am at user3 of skill assessment section of windows command line module.
the flag from user2 is not the password for user3?

fathom pendant
#

try putting the password in single quotes 'like-this'

fathom pendant
#

i haven't done that module in a hot minute ยฏ_(ใƒ„)_/ยฏ

#

but i'll let you in on a secret; most stuff can be done with other users so if you're stuck try using a different user

glossy cloak
#

i found the flag with "whoami" command... it worked as the answer for the previous task

#

but not as a password for the next one

fathom pendant
#

like i said it's been a minute ยฏ_(ใƒ„)_/ยฏ

glossy cloak
#

argh... CAPITAL LETTERS

rough comet
#

Hi folks, can I please get some help with "Intro To Windows Evasion - Static Analysis"

#

I connected to DEV box. Copy/paste the 1st C# code. Added the msfvenom shellcode, using Kali's IP and port 4444. Then build ... no problems.

#

The instructions say "add the executable to C:\Tools\Alpha\Static"

#

I did. But after almost 10 min I see no flag. As a matter of fact, I run the .exe and I get no shell.

#

All this was done on DEV. Can I someone please DM me or maybe give me a nudge? what am I missing?

mighty aspen
#

Was this also done on DEV ?

add the executable to C:\Tools\Alpha\Static

rough comet
#

By the way. My executable was created at || C:\Tools\exercise\ConsoleApp1\ConsoleApp1\bin\x64\Release\net8.0\ || which is klind of weird. I do not see any || net8.0 || in the screenshots.

rough comet
#

Do I have to move to TARGET?

mighty aspen
#

A few things here

  • The question wants you to place it inside "C:\Alpha\Static", you placed it inside C:\Tools\Alpha\Static
  • The file should be placed inside the machine associated with the question, which is the the TARGET machine
  • You didn't mention whether ThreatCheck found known bytes
  • I would recommend targeting .NET framework 4.7 instead of 8
  • You can get the flag as long as there is no detected bytes on your .exe but you mentioned that you didn't get a reverse shell, i would recommend spending more time on the DEV machine until you are able to get a shell from DEV
rough comet
rough comet
mighty aspen
#

Go back and make sure to select the indicated project template

rough comet
#

Yeah, found it in VS

#

not a programmer.... VS is not something I am using regularly, lol ... I know that's about to change though ๐Ÿ™‚

mighty aspen
#

It's just a matter or time :) By the end of the module you will be more familiar with it

rough comet
#

Thanks again and for the patience , lol โ€ฆ

tribal plinth
#

The checker script (which gives you the flag) tries to check if it's a .NET framework binary which includes Cryptography (for the AES) and InteropServices. If you really follow the section step-by-step, it should give you the flag.

brave prawn
#

Nvm, solved it, thanks

lapis sky
#

Pivoting, Tunneling, and Port Forwarding -> RDP and SOCKS Tunneling with SocksOverRDP

wtf is this issue? its stressing the hell out of me. It happens every time I try to run the command or even just extract the files. i've reset my machine twice and Iโ€™m still getting the same problem

fluid river
#

Hi all, am struggling with the HTB academy module "Information gathering - web edition". The skills assessment part. Getting confused with the vHostd bit

pulsar needle
fluid river
#

3rd question: what is the API key in the hidden admin directory....before thst it gives the target IP and port....then says vhost needed for questions....am assuming need to add that to hosts file for enumeration to work but added it s few different ways without success...so just looking for start point really to be able to put into practice what learnt from module...did nmsp scan and that port it specifies isn't listed

pulsar needle
fathom pendant
fluid river
#

Ah well that's one thing did wrong

fathom pendant
#

to access the host with ffuf or any http type protocol; you do http://hostname:port

#

to fuzz a subdomain you'd add -H "HOST: FUZZ.hostname" in ffuf

fluid river
#

Ok let me try that

fathom pendant
#

all this stuff you should have encountered in the module

fluid river
#

Did but may have to revisit parts

fathom pendant
fathom pendant
#

that way if you take a break it's not jarring to come back and mess up a fundamental thing

fluid river
#

Yeah hit nail on the head there that's exactly what's happened

timber marlin
#

Ngl I'm just on here to be friends with hackers close age I'm high school age Btw so please don't be weird

fathom pendant
timber marlin
#

Oh thank you sorry

magic mango
#

for the SMB module, am i to change the smb.config file to further gain access?

#

or to make the txt file show?

fathom pendant
#

wdym smb module
did you mean: Footprinting module, SMB section
Attacking Common Services module, SMB section

#

also, no modification is needed to smb.config

magic mango
#

yes

fathom pendant
#

yes
motherfucker i asked a or b

#

this isn't a ternary question with a hidden third option

magic mango
#

footprinting

fathom pendant
#

no modification is needed

severe inlet
severe inlet
magic mango
fathom pendant
#

you need to link your account to share screenshots; though i believe that module is above tier 0 so screenshots would be spoiling content

#

#welcome <-- instructions on linking here

severe inlet
#

You can dm screenshots if its above 0

fathom pendant
#

so long as the screenshot isn't revealing content and is just basically errors with stuff like passwords and such redacted

#

the section though gives you all the info you need to get the answers

magic mango
severe inlet
fathom pendant
#

note you may not just be enumerating SMB, i believe the section also talks about enumerating via RPC

#

something that catches people off as well, at least with the filepath, is look closely at the filepath and think: does that look like <redacted> OS structure?

#

i.e. why would a windows machine have C:\Home ๐Ÿ˜‰

magic mango
severe inlet
#

Which question are you stuck on?

magic mango
#

connecting to the discovered shared to find the flag

severe inlet
#

First you need to find the Share that you can access
After that you should use something taught in the section to find the flag

magic mango
#

im feeling like i'm using the correct cmd but not getting the comfimation of login with the anonymous login

severe inlet
#

For me i broke it down into
Which share can i access?
What tool can i use to access this share?
Find the flag

fathom pendant
magic mango
#

i did

fathom pendant
#

to connect via smbclient you need to specify a share
smbclient -U <some username> //(ip or hostname)/sharename

#

if the sharename contains spaces you'll need to wrap it in quotes

#

then you can just dir and navigate through that

#

cd as well

magic mango
#

run the -N -L [Target IP] is not enough then?

fathom pendant
magic mango
#

oh!

#

see that i did not know or missed that in the reading

severe inlet
fathom pendant
#

man smbclient or smbclient --help

#

:) man is your best friend

#

(except when a tool doesn't have a manpage)

magic mango
#

oof, learning this and linux at the same time should have been a better thought out plan ThinkNoose

fathom pendant
#

now you know, and hope you put it in your notes for future use ยฏ_(ใƒ„)_/ยฏ

split cliff
#

I've been banging my head on the table for 20 mins... I can't figure out the format that your system demands for the answer, even though the webpage calls out what I am providing as the answer... How do I be more specific, I don't want to give anything away?

#

I'm doing the Android Fundamentals.

#

Here's the question: What is the name of the function that returns the string inside the cpp file? (Format: FunctionName()). The web page literally states the answer followed by a colon...

#

Having to post more nonsense because there's a damned ad in the way in Discord

fathom pendant
#

Also you can dismiss the ad

split cliff
#

THANK YOU!

#

The problem I'm having is I have provided... wait...

spring trail
#

hey guys, i have a question to ask about iframe vulnerability, since i scanned the web with nessus i found iframe is vulnerable to clickjacking, but itโ€™s worked through burp request only. Is there any way to inject and affect to all users?

fathom pendant
#

The question literally tells you the format: no : after means no : in your response

fathom pendant
split cliff
lost turret
#

Hi

fathom pendant
#

We can't help you with that

lost turret
#

Does anyone know how to do that

lost turret
fathom pendant
charred sky
fathom pendant
icy grotto
#

I was doing the PTT from Linux and on the last 2 questions whenever I try to Smb with the cp and export for the current key it just says no cache found. And then lists the key I exported

polar raven
#

Hi, i did the assesment File Upload but I don't understand why my upload get interpreted and executed. I don't find anywhere a special config allowing those type of files to be executed.

icy grotto
#

So I figured it out but the flag.txt file is saying its a wrong answer

fathom pendant
acoustic ginkgo
#

(It makes the page view on the nibbles task take quite awhile to load up in a browser)

fathom pendant
#

the problem isn't the vpn, it's the lab itself

#

because of how things get processed

#

if it wasn't split tunnel you wouldn't be able to access the regular web while connected to it

acoustic ginkgo
#

So just do what I did (basically just blacklisted the googleapis domain for now so it's 'quick')?

fathom pendant
#

typically adding in the domain nibbles.htb or whatever box it may be fixes some of the fonting issues, at least when the lab is based off a retired box

acoustic ginkgo
#

I can't access regular web while connected to it; that's why I assumed it wasn't split tunneled

fathom pendant
#

well it works on my machine, i take it you're using kali?

acoustic ginkgo
#

ya

#

maybe funky DNS stuff on local network causing issues?

fathom pendant
#

is your openvpn up-to-date?

acoustic ginkgo
#

yup

#

just did a apt upgrade about 45m ago

fathom pendant
#

google is your friend

#

there's also network preferences tab <

#

my google query :)

acoustic ginkgo
#

ty for help

fathom pendant
#

๐Ÿ‘ next time though:

compact patrolBOT
dense tree
fathom pendant
#

run powershell elevated, first off

dense tree
fathom pendant
#

but also your system wouldn't be registered to an ad set even with it installed

#

and setting up a general purpose AD lab for your local daily drives would suck

dense tree
#

Indeed, I'm just playing with it at the moment with making a scipting module for this section for pratice. I'll eventually have a server instance and a VM soon as I continue with the academy.

#

This system is pretty decent

polar raven
sour roost
#

guys I have a question in pintesting In a nutshell or it's more like a trouble shoot I already have the answer but it's not working can I dm someone

dense tree
#

@sour roost I hear you.. This channel is for us who are in the academy and learning about all that info as you dive deep into it

noble temple
#

๐Ÿ”ฅ

sour roost
#

so state the question here?

dense tree
#

Don't ping / DM staff .. always ask permission from mods.. Read the rules closely... If you are going through a module in the academy, this is a good channel. Otherwise they may point toward a channel with the answer your looking for... But Shoot it

sour roost
#

ok I'll revisit the rules section thanks ๐Ÿ‘๐Ÿผ

thin citrus
#

I am working on 'XSS Filter Bypasses in the 'Advanced XSS and CSRF Exploitation' 'https://academy.hackthebox.com/module/235/section/2677'.
I am able to execute javascript that popups the standard XSS box and also able to connect to my python webserver.
But when I use the basic xhr payload to extract data from '/admin.php' I get no response. I tried to host the exploit file on my python webserver and updated the xss to point at my https://kali_vpn_ip:4443/exploit" I see:
10.129.233.62 - - [04/Apr/2025 12:14:16] "GET /exploit HTTP/1.1" 200 -

So he can access the file but it's never executed. Can someone help me with this?

acoustic owl
#

As the name of the section suggests, it's about XSS filter bypasses. This means you have to find out what is being filtered and then adjust your payload accordingly.

thin citrus
#

The strange thing is that I am able to access my webserver got 'code 404, message File not found' but the xhr payload does not execute. Tried also with src instead off fetch(). And with fetch() I used also '.then(r => r.text()).then(code => eval(code));' to execute the payload. No luck either.

lethal crow
#

Hey, im busy with nmap service enumeration 'https://academy.hackthebox.com/module/19/section/103'
and need to give a flag, i scanned ports, then activated tcpdump, then used nc on all the ports, after this i got the same flag on every port. Can someone help me?

acoustic owl
thin citrus
acoustic owl
#

The payload you insert on the page.

thin citrus
#

@acoustic owl Got the flag

fathom pendant
#

[status code] [text]

narrow wasp
#

can anyone help with the last question for dacl1 SA. i have 2 users ntlm hash...

split cliff
#

How poorly written is the material in the hack the box?
I have an empty box that says "Submit your answer here".
Above it are two statements, and no questions.
Install myapp.apk by dragging and dropping it into the emulator. Then, open the embedded terminal in Android Studio and run adb root && adb shell ls -l /installed/apps/. Replace /installed/apps/ with the correct path to find the appโ€™s home directory.
In English, sentences that are meant to be questions end with, "?," a question mark.
Your last sentence should say, "What path do you replace /installed/apps/with to find the apps home directory?" if that is what you want answered. I ASSUME that's what you want, but in 40 years of doing this I've learned InfoSec is NEVER about assumptions.

But what's great about this? The next box with a "Submit your answer here" has only statements above it too, with no question anywhere to be seen. I'm sure someone is just going to read these to me again... because that'll solve the problem. It'll make question marks suddenly appear.

Since you're charging for this product, could you at least achieve the minimum standard and have questions where you expect answers?

EDIT: Turns out "What path do you replace /installed/apps/with to find the apps home directory?" Isn't the question. So how do I find out what the question is in the Android Fundamentals module skills assessment? I found a flag.txt, but that value isn't accepted.

What is the actual question?

short orbit
#

Hi there, I've been stuck on a question for 5 days (yes, I enjoy bashing my head against walls), but I finally gave up and started looking online for the answer. Turns out I was actually doing the right thing all along. It's part of the XSS module, specifically in the "Session Hijacking" section. Here's the question: "Try to repeat what you learned in this section to identify the vulnerable input field and find a working XSS payload, and then use the 'Session Hijacking' scripts to grab the Admin's cookie and use it in 'login.php' to get the flag." I set up my PHP server on ports 8000, 8080, and 4444 on the following environments: my host machine, Kali VM, and the HTB Pawnbox. When I manually visit the IP:PORT of my PHP server, I can see the requests hitting my console. I used the payloads from the module and the one I found online , but whenever I try to insert the payload into any field (except the email field), nothing seems to happen. Can you help me out? Iโ€™m kinda desperate at this point.

tribal glade
#

I could use some help with the box: Administrator I was able to get to michael and thought I changed the password for Benjamin but it only shows that it was changed for SMB and not WINRM. Even smbexec is not working so Im wondering if I messed something up. Thoughts?

fathom pendant
split cliff
#

I've put that in.

#

Not accepted.Matched the format

#

Checked capitalization

fathom pendant
#

also reach out to support

compact patrolBOT
fathom pendant
short orbit
#

dude somehow i just got it

#

didnt edit anything just restarted the target

fathom pendant
#

also module is above tier 0; i suggest removing the payload used

short orbit
#

yup sry for that

fathom pendant
#

there shouldn't be a payload/guide online but people violate ToS a lot and it's hard for staff to keep up sometimes

short orbit
#

yeah i keep finding some article that just does the entire exercices and doesn't give answer but give every step to get there

short orbit
#

Yes i know you need the url or something ?

fathom pendant
short orbit
#

i gave you the url in mp if you need it

fathom pendant
short orbit
#

done thx for the help anyway

light siren
#

intro to windows command line... so im supposed to use the previous flag as the password to ssh into the current user for flag but ive tried everything i can think of and none of these are relevant even tried to forum related answers and still a no go

scarlet garnet
#

hi everyone I need help regarding HTTP Response Splitting

#

will anyone help please

fathom pendant
#

@light siren please don't share the answers :)))

#

so the answer is NO, don't be a dumbass

#

@light siren make sure the output that gave you that answer doesn't have capital letters in it; since it's a password -- casing will matter

light siren
#

what... the output is exactly what im typing i havent changed casing...

#

ive been trying this for like a hour now, its redundant... it should be ac....11

#

for the windows fundamentals skills assessment does anyone actually know what the pw is to ssh intoo user 3 here, SSH to 10.129.204.9 (ACADEMY-ICL-SKILLS11) with user "user3" and password ""

  • 1 How many hidden files exist on user3's Desktop?

ive tried all the passwords it should be, none of them are working, and ive used exact casing

fathom pendant
light siren
#

let me try mine is all lowercase when i used hostname and who am i

fathom pendant
#

systeminfo?

#

:)

light siren
#

yeah that one is all caps, weird huh well anyways tyvm, i tried verifying with hostname, netip, and whoami

#

i even tried searching for missing flags maybe lol

Get-ChildItem -Path "C:\Users\user2" -Filter "flag.*" -Recurse -ErrorAction SilentlyContinue

fathom pendant
#

it was right there

fathom pendant
#

i also checked with systeminfo; and i got the answer as expected

scarlet garnet
#

hi everyone I need help regarding HTTP Response Splitting

#

please help

full wagon
#

Windows privilege escalation - interacting with users:
I found the right path, tried different flags for catching, but I never get anything back on Kali.
Why is this not working?
|| I tried .lnk .url .scf to no avail ||

rough comet
#

hello folks

#

so I am still working on INTRO TO WIN EVASION TECNIQUES - STATIC ANALYSIS

#

I manage to get a reverse shell after building the c# code. That's good

#

But my understanding is that I need to put that on TARGET. c:\alpha\static , which is other other VM.

#

The problem is ... I cannot have both VMs working at the same time.

#

Do we have to compile , develop, etc on DEV. Export to Kali. Start TARGET, upload to get the flag? seems a very convoluted process. Maybe I am missing something. I do not see Visual Studio Code in TARGET

tawdry wren
#

Guys, I'm currently on Applications of AI in InfoSec, Model Evaluation (Malware Image Classification). I got this far, but never get a flag. Can anyone suggest where I'm going wrong?

scarlet garnet
#

anyone please help me with http response splitting

gray yacht
rough comet
#

I have VS code in Kali

#

can I build the solution there?

#

Or it must be a Windows box?

gray yacht
rough comet
#

ok

supple dragon
rough comet
#

let me make more cofffee.... this is gonna be a long module, lol

full wagon
gray yacht
full wagon
acoustic owl
fathom pendant
dapper moth
rough comet
#

Good point

#

I may have to spin a Windows VM. Do not really want to pass all that to my actual Windows host. I will have to create an exclusion, etc.

rough comet
# rough comet

Still not getting a flag. I did transfer the malicious executable without any obfuscation. So my question now is ... the file we need to move to get the flag, is the one generated using the AES encryption?

#

1st version gets immediatly deleted (obiously)

proven crane
#

did anyone ever solve this? Im getting the same thing

#

i think something my have broken? The results im getting to not match the walkthroughs I checked it against

#

||the NTLM hash for the local admin account of SQL01 no longer matches the NTLM hash of the local admin account of MS01||

#

I don't see any way around that at the moment

rough comet
pallid granite
#

resubbed, time to demystify windows more

rough comet
proven crane
#

I've moved on to the next steps, I'll have to go back and confirm it

vivid mantle
#

@hollow knoll can i DM you for an question ?

rough comet
#

jesus christ ...

vivid mantle
#

can somebody help me with the "android fundamentals"
i test already all functions from the provided code, is this a content error ?

dense mesa
#

Having fun with the Footprint Hard Lab at the moment. I used some alternative flag with nmap already, but when i try to connect my finding, which is said to be open, i donยดt receive anything. I always end up with an timeout and i am not sure if I am on the wrong path :/ I restarted the target already, as I thought i broke something.

Got it. God damn, i hate it sometimes. Still not coming much further, but atleast i know the services is answering, something.

rare vessel
#

Hii

gray yacht
dense tree
#

If I had my own VM Parrot OS, and I vpn'd and ssh'd per academy instructions. Would my sessions still time out?

fathom pendant
#

They shouldn't

#

ยฏ_(ใƒ„)_/ยฏ

dense tree
#

Thank you!!

dense tree
#

@fathom pendant okay - this is the 5th time, I have tried this... I need help pls... may I DM you on this only...

#

This is a lengthy code..

#

regarding user10 intro CLI: skill assessment

#

been at this now for about 20hrs..

fathom pendant
#

Im busy with other stuff

dense tree
#

that's ok ๐Ÿ™‚ can you recommend another support pls?

fathom pendant
#

Make sure you're connected to the DC. A separate machine in the targets internal subnet

slim plaza
#

On what do password recovery functionalities provided by web applications typically rely to allow users to recover their accounts?

dense tree
#

@fathom pendant I can't thank you enough... I was banging my head for over 8 hours...

rustic sage
#

Hi guys...

frank stirrup
#

Hi there guys , have a little issue with the "Using Splunk Applications" , the first question on "net view" stuff. I did remove the extra space but got no results. Please am i missing something?

dense mesa
serene drum
#

Hey this might be the wrong place to ask, but anyone know how to actually have request and response side by side on burp suite

fathom pendant
pallid granite
#

this format makes more sense

fathom pendant
#

Because in bash (and most things) \ is an escape character

pallid granite
#

Nvm im blind , right below the smbclient example talks about firewall blocking

fathom pendant
#

Go ahead type 4 \ in discord and see how it's interpreted when you hit enter :)

pallid granite
serene drum
#

yeah I figured it out thank you anyway

pallid granite
#

The organization is doomed

blazing loom
#

What is the difference between the amound of estimated hours and the % complete of the path. What are they measuring because they are definely not measuring the same thing. I am doing the "Information Security Foundations" which has an estimated time of 10 days (each module's estimate added up to 39.5 hours so that adds up). However I'm halfway through the second module. The first module had a 30minute estitmate and the second one has an estimate of 3 hours. However they % completed says I've complete over 10% of the module..... but by time estimate it is less than 5%. So that leads me to ask why are these figures so different?

ivory pecan
#

Hi @ocean night ๐Ÿซถ๐Ÿฝ

fathom pendant
ocean night
fathom pendant
#

% completion is based on the sections completed and questions answered

#

For a path as a whole it's as a total number of sections/questions completed

blazing loom
#

Ah gotcha. So in my case, it seems that the sections I have complete are less time-consuming sections thus requiring less time but each one still bumps the completion %. Soon I'll get to more time-consuming sections. Makes sense.

fathom pendant
#

Focus on understanding the content over getting through it quickly

pallid granite
#

ive found that unlike a lot of services, htb's acad time for completion is pretty accurate

blazing loom
fathom pendant
#

Some people find certain things easier than others, so long as you understand the module you're good either way

fathom pendant
blazing loom
#

Lol, fair enough. I'll prepare myself mentally for that ๐Ÿ™‚

#

I saw I was 10% of the way through and thought "Sweet, I'll finish this in half the time I thought it was going to take me".... but then I looked at the time estimates and realized that might not be true.

fathom pendant
#

Just don't put too much stock into it

#

It's ok for a guideline

#

It's more there as an "if you have 0 issues and don't take notes" thing

blazing loom
#

๐Ÿ‘ Sounds good. Probably better to not plan or look ahead much then. Just set a timebox and study. I'll get done when I get done.

fathom pendant
#

Yup

#

If you pass an expectation; great! If not, oh well you got tripped up

mossy sable
#

wouldnt this be the total packages installed on the target system??

#

dpkg -l | grep '^ii' | wc -l FeelsGoodMan

slender kindle
#

can anyone help me with: Skills Assessment - File Upload Attacks

acoustic ginkgo
#

Is it normal for the modules to have multiple different flags?

#

(e.g. have 1 valid and 1 invalid flag)

waxen totem
#

Its possible to find flags for subsequent sections because a lot of sections share the same target image

#

You might've found a flag from a later section

main ridge
#

๐Ÿ˜ฆ

ocean night
main ridge
#

The error still remains, but I can connect to the VPN. In fact, the VM I was attacking is still up

ocean night
#

Did you edit the RAY_ID there?

#

Or is that how it appearead

main ridge
#

Tried reloading a few times with CTRL SHIFT R but nothing

storm elk
#

Yeah thatโ€™s how the ray id appears. Had the same on April fools with the ctf platform. Doesnโ€™t show a ray id

main ridge
#

If you need anything else or if there's something I can try just let me know

ocean night
#

Still looking in to it

#

Anyone else experiencing issues with Academy at the moment?

fickle crystal
#

yo the LFI module pisses me off rn

#

im inject the payload in with the language parameter but my page just shows no connection error

#

i did this task before

#

never seeen this befo

ocean night
#

@main ridge could you try again please?

fickle crystal
#

how are you

ocean night
#

Fine, trying to get to the bottom of the error from gr4f3n at the moment.

#

I can't comment on module content I'm afraid.

ocean night
#

?

fickle crystal
#

i tried using the pwnbox

#

and it works ,,, something wrong with my kali proxy settings in the browser

ocean night
#

Please reach out to support on the site.

#

Sorry, but I'm not support, and am trying to figure out another issue, as I said.

compact patrolBOT
main ridge
ocean night
#

Damn, ok.. sorry for the inconvenience. I'll continue digging.

main ridge
main ridge
#

If you need more info (location, screenshot) feel free to DM

ocean night
#

Thank you

#

Okkk, one more go please @main ridge? Last one I'll ask from you, mitigated an ongoing attack.

#

That may well have been impacting the service you were hitting

main ridge
ocean night
#

Arrrrrrgh

#

Ok bringing in someone else. Sec involved, and we mitigated an ongoing attack, but apparently this has had an impact elsewhere.

#

I'll update you once it is resolve. Again, apologies

main ridge
#

No problem! Good luck with that

ocean night
#

Don't like handling PII over Discord if I can help it ๐Ÿ˜…

bronze lodge
ocean night
#

Thank you!

#

Weird, managing to submit solutions, and I'm seeing others submit them also.

#

Could you provide the exact module/section/question URL / name you are having issues submitting to please? You too if possible please @bronze lodge

#

Not even seeing your submission requests hitting CloudFlare to be honest @main ridge

#

What on earth is going on

#

I see some regions being re-routed in CloudFlare

#

..but no major incidents that'd impact us

bronze lodge
#

I'm experiencing this issue intermittently. There are times when I can access the module without any problems, but other times it becomes inaccessible.

ocean night
#

Thank you

bronze lodge
#

Everything seems fine now. I'll let you know if it happens again.

main ridge
bronze lodge
main ridge
ocean night
#

All I can suggest is to keep retrying now and again. We're looking in to it, but as a sporadic issue it's a pretty hard problem to pin down. We're on it

main ridge
bronze lodge
#

๐Ÿ˜‚

ocean night
#

Modules do not handle flags differently on submission

#

So just a big coincidence there hahah

main ridge
#

Here are some requests that are being made after the error. It looks as if we are being blocked by the WAF

ocean night
#

@bronze lodge I don't suppose you could email your IP to me as well please? Wanna see if it's a regional thing

#

We have blocked a few IPs that were hammering services pretty hard..

#

Lemme check CF logs for your IP again

#

@frail tinsel please read the subject to the channel, and the terms of service

#

Sharing information like that of modules above tier 0 is not permitted.

#

Please ask for assistance without pasting such information.

frail tinsel
#

No problem, I'm looking for assistance on the Skills Assessment - Using Web Proxies question number 3.