#modules
1 messages Β· Page 407 of 1
I am not permitted to ask in the off topic section so that's why I asked here
I am in a ctf challange need help
What CTF?
pentathon
If it's active, then don't ask here. We don't help people cheat with CTFs
Kπ
Sent!
Thanks!
And if we did... it would defeat the purpose of the challenge and undermine the learning experience.
Also wouldn't be fair to others who are putting in the effort.
This is my first time posting, do I just wait for someone to hit me up?
yep; patience. in the meantime keep cracking at it
no sense in staring at the screen waiting on a reply
sounds good
you can utilize the search feature; this question has been asked and answered a lot
short answer: you need to work in reverse of how you decoded the cookie
actually the question hint basically spells it out for you
literally gives you the step by step
Ok, so turns out it was an error on the lab side. did the exact same attack today and got the hash.
Yeah I did that and even checked a few of the final ones backwards manually to ensure they didn't break. I'm just not seeing anything standout in the output
are you sure you're doing it properly then?
you replace the whole cookie, not just a part of it
the prefix handles the important bit
I've checked my work a couple times and if I am not doing it properly, I can't see where. I do have a prefix.
cookie=<section symbol>randomtext<section symbol> then you do the payload processing
remember you're encoding the reverse order you decode
decode order
a -> b -> c
encode order
c -> b -> a
Looks like Error Code 522 is back to haunt me again.
You're a certified gangster! Thank you so much! I had the encoding setup right but I was mistakenly doing the sections at the end. I didn't accont for the prefix. Thanks again!
We are still investigating, apologies. It's a weird one for sure.
No worries, thanks for looking into it. Let me know if you need any info from my side.
Hello everyone, please help me. Please help me find the answer to this question in the HTB lab Broken Authentication Brute-Forcing Password Reset Tokens On what do password recovery functionalities provided by web applications typically rely to allow users to recover their accounts?
Hello everyone
I'm sorry if this isn't the right channel for my problem
Guys, has anyone ran into this problem recently? I can't load the academy, and my account is not even showing my gold subscription status. It throws me the following message
It looks like it's an issue on HTB side, but I didn't found anyone having this same issue. Any advice? Thanks!
it's being investigated rn [tagging @ocean night ]
thanks! I just read the previous messages
don't know if it helps, but the dashboard is also with this strange behavior showing me the option to open the academy as if I have never opened it before:
see prev; i'm not staff so i can't offer insights. but it's being handled high-prio afaik
We are still investigating the issue, we've eliminated a lot of potential causes, and are going up the chain to our providers now
"everything is green" apparently does not mean "everything is green"
Spent a lot of time trying to correlate the errors being reported in CloudFlare and from users to the backend services, with no lucky.. so yeah, next step is size 14's up the providers arses
Apologies for the inconvenience @uneven dock - we're on it
Hello, I have a doubt with Ligolo-ng's double pivoting. I have access to the Network B Windows 10 machine and have agent.exe on it. However, to perform double pivoting, I can't get the agent.exe to connect back to my attacker machine and even pinging my attacker machine from Network B fails - provided, single pivot works flawless. I have tried port 80 on Ligolo too, but that didn't help.
TLDR: I can interact with Network B machine, Network B machine can't interact with me.
Even pinging 8.8.8.8 fails through Network B. So, is a double pivot through Ligolo a no-go approach for this?
well pinging 8.8.8.8 from the internal networks would be fruitless anyway afaik
but you need to port forward for a double pivot
set up a forward that forwards from victim A -> you; then from victim B call to victim A on that special forward that sends back to you
Oh yes, that is making sense, there needs to be a link to get back to me.
However, the article that I studied ligolo from misses all this vital info on double pivot https://www.hackingarticles.in/a-detailed-guide-on-ligolo-ng/
directly from that same guide
yeah this setup is kinda odd tbh
though @rustic sage newer veresions of ligolo do a lot of that stuff without the need to do route adding outside
Yeah, but they are adding that listener in session 2 console. Session 2 is this double pivot session
Yeah, I got that idea and it makes complete sense
not to mention their diagram doesn't make sense
at least under some sections (mislabeled) but this is beyond modules and we're going off-topic
Right, thanks for the help, Marc. Very useful.
I'll just read another article for double pivot and modify my notes. Atleast their single pivot is fine
yeah according to everything i know and understand, their lab setup is flawed in some way
100%
Hi everyone, I have a networking-related question. I have noticed this in the Pivoting module as well, but I'll use an example from the first lab assessment of the AD enumeration module.
running ipconfig inside the WEB01 box, returns:
IPv4 Address. . . . . . . . . . . : 172.16.6.100 Subnet Mask . . . . . . . . . . . : 255.255.0.0 Default Gateway . . . . . . . . . : 172.16.6.1
The solution states:
Students need to use WEB01 as a pivot host into the 172.16.6.0/24
Why is this described as the172.16.6.0/24network and not the172.16.0.0/16network as the Subnet Mask would suggest?
Yeah I too had the same concerns. I'd assume there's some actual proper VLAN (layer 2) implementation of the proper subnet masks and these masks are just slightly misconfigured since although the host has that mask configured it actually cant reach the entirety of the network that the mask would pertain to.
Cant actually make a definitive statement btw just providing my own insights and assumptions
Hi in
Introduction to Windows Evasion Techniques
Static Analysis
i put the exe in \alpha\static
in log files it says C:\Alpha\Static\htb.exe - OK - Undetected by Microsoft Defender Antivirus
but doesn't show the flag
did you make sure to create a .net framework and not normal .net project? You want your build process to give you a single .exe without .dll
hi guys
I am trying to enter academy but when I hit academy it waits waits and after that gives 522 error does anyone experience the same problem?
They working on it bro
I thought there is a problem from my side somehow...
@bronze lodge @main ridge could you both try again please if you're available?
If there is bug in webpage with dom base attack so you need to inject this in url or in input feeld and see what happens
Which CTF you are solving give me link i will solve latter
Guys, can someone help me with this? I've tried a lot of things and can't find the flag.
Giving more details will help to find π give me link
It got the job as IT admin in my city top international schoolπΊ
it's not a ctf it's a module
Oo I don't have token π
@tawdry wren this neeed some token π
What are you on about @rustic sage ?
Nice one!
@frosty ferry it needs 10 token π apology i don't have.. but try what I say it will work π
Do not spoil
Okay
Even if it's free, flat out spoiling is crap.
@ocean night i want frand π₯² good friend
No, get out
π π π
Shadow (1320243791252426822) has been banned until 2035-04-03 14:38:33 (UTC).
I uhh.. I can't see the ban..
User #1320243791252426822 has been unbanned.
There
Do you want me to invite him back to server?
Please.. I can't seem to be able to
What is going on these past days..
Why the hell can't I invite them back
He's back i invited him
I think I need to close Discord.
You need sleep too
You've been online from long hours
Thanks broπ₯²
No problem it's just my stupid luck πI am use to it
You can find a team in #1318239802931286066
Oh, verify yourself then you can access
@frosty ferry ok.. let me see how that works π¦
Why I can't message in "general " ? Just read
Do I have to do chmod +w general π
Good morning yall. I got the correct answer but dont understand why for a question in the Wi-Fi Penetration Testing Basics Module. The question was 'How many interface modes are available? (Answer in digit format: e.g., 3)'. I tried the number of supported interface types shown by iw list, but that was incorrect. Could anyone give insight into why? Does type != mode?
Interface is number of wifi AP you have and mode is about those WiFi state like 1 moniter mode 2 . Manage mode , 3master mode
Interface ex. Wlan0, wlan1, etho, lo etc @hollow tapir
@hollow tapir and its night here π
lol, good evening then. Thank you, but I am still confused.
The number supported interfaces are too many, and the interface types on each band doesnt add up to the amount of modes either
Could you provide a hint on how to get the correct information?
(if allowed)
I just figured it out
crazy work
It works!! Thank you
Awesome, glad to hear it π
You need to verify yourself
Lol
is using google to solve a question inside a lesson considered cheating?
i mean ik i wont know everything from the start, but i feels too easy just googling it
Hi
I have a question regarding the Optional Exercise in "Cracking Common Hashes" in the module "Cracking passwords with hashcat".
I revealed the answer but i don't understand how i can get to this answer myself.
Can someone explain me, how ||the NTLM hash of user pfalcon|| can help me leverage the NTLMv2 hash of adconnectsvc with the help of hashcat to authenticate as the user adconnectsvc to the domain?
I still can't figure this shit out π
Hey you almost got it right,
Ignore the original text in the page because it's already there
The payload that they gave you, what text does it produce on the page?
it says "click me"
it redirects me to the htb page
It's an anchor tag so it will redirect you based on what you put in the href attribute
The text between the tags can be changed to anything
Have you tried to grab the blue text alone?
yes no spaces
This is weird ;-;
so the answer is "Click me"?
I believe though, I can't remember it well but logically it should be
i am stuck at such a simple question lmao
Hi do anyone of you know hacking?
nope, its Introduction to Web Applications
no
Oh okay ππ»
@cyan bladeif you have done this module could you just check for the answer and let me know
May I DM?
sure
Okay π
For everyone struggling with the same question:
After asking, i found an answer to the question for the Optional Exercise in "Cracking Common Hashes" in the module "Cracking passwords with hashcat".
||You can use the NTML hash of a password to generate a NTLMv2 hash. And as you can use a NTLM hash for a "pass the hash" attack, if you can find a NTLM hash that correspond to a NTLMv2 hash, you can use this hash to authenticate as the corresponding user (see https://stackoverflow.com/questions/32272615/is-it-possible-to-convert-netmtlmv2-hash-to-ntlm-hash for how to check, if NTLM hash corresponds to NTLMv2 hash).||
when i do curl request .
curl -i -X OPTIONS http://94.237.61.28:56767
HTTP/1.1 200 OK
Date: Sat, 05 Apr 2025 17:29:56 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 1108
Content-Type: text/html; charset=UTF-8```
why their is no Allow: header ? π
https://academy.hackthebox.com/module/134/section/1175
One of the guys on my team made a pretty cool plugin. Essentually he wanted to revisit modules that he completed, but did not want some of the flags to give away the hints. So he created a way to obfuscate the flags in the browser.
https://github.com/sudoheader/htb-academy-answer-hider
The sparkling milk is not apart of the plug in lol. That was just him trolling one of our other co-workers that was trolling another co-worker about creating sparkling milk, like actual sparking milk, but the video shows what the plugin does.
apache server might not always be configured to handle OPTIONS requests explicitly
depends what you mean by that
do you mean googling "X module htb academy Y section" => if the module is above tier 0 --> yes
if you mean googling how to perform a task in general then no
but in module they tell use -X options .
no, they use it as an example
examples aren't necessarily the "use exactly this"
sometimes they are an 'hey sometimes you can do this'
witout it we can' t solve lab
sure you can
yesh but have to check one by one each
in this case: assume the basic options exist
thanks for helping me out , sleep is kicking in
that's part of what separates hackers from the rest.
You need to be able to take incomplete data, with what you know, and figure it out
if you wanna suggest it then #1234357888114364508 and /feedback :) @dry falcon
is this msg meant for me or?
i edited to @ the person i was referring to
:)))))
learn2read

ye, but guess what i have a excuse
"Sleep is kicking in"
Guys hello if there is anybody who has done Cracking Passwords with HashCat what is the format of correct answer in Identifying Hashes?
just the type name
put me to sleep
i.e.
MD5; SHA1; etc
wait am i gonna die?
ouch
hashid identified is as drupal but it tells me that incorrect answer...
there's more
you need the whole thing
the whole line is the hashtype
Lol three times after inserting the same was telling me incorrect on the fourth it is correct....
Hello. I am on Pitoting, tunneling and Port Forwarding module, in ICMP Tunneling section, I can't seem to solve this error while building the ptunnel-ng tool in the pivot host. my attack host ptunnel-ng is OK. but the pivot host is causing issues, it seems like its searching for a program "autoheader", the host has no internet, so i can't install the program. any suggestions
You need to statically compile it from what I recall
thanks, though the module should've mention it like it did with all other things(errors).
learned new things obviously with this.
Hey guys, I'm currently working on the Android Fundamentals module, and it asks me to create a virtual Android phone. Does anyone know how to do this or where to do it?
hi all im stuck here
Module : AD Attack adn ENum
Section: Skill Assestment Part1
I'm doing pivoting here, but my command doesn't work
my kali : 10.10.14.245
web0 my connect machine(windows):10.10.14.245
and i want to connect machine :172.16.6.50
i use netsh.exe but dont work
dude is anyone doing the evil twin attacks new module on wpa2 and spa3? Im in the skills assessment and it seems like it is flipping impossible.
Hey. Information from some modules don't load on smartphones. Tried both Android and iOS. Chrome and Firefox. Deleted cookies as well. For example https://academy.hackthebox.com/course/preview/web-attacks
Hi,
To be able to use evinwinrm into a machine we need to have PSRemoting right with our account + the WinRM port should be open ?
I'm seeing that I can evilwinrm into a machine however on bloodhound my account doesn't have the PSRemote edge to this machine. Does someone now why ?
Hackthebox isn't really meant to be viewed on mobile devices
Memu, Genymotion, android studio emulator
which users can PSRemote is something Bloodhound can only obtain from the Host itself. Your standard Bloodhound data is done against the DC and does usually not contain this PSRemote information. So unless you already have a user that can access the host to obtain this information, you will have to manually check every new user you get if they can PSRemote somewhere
ok thank you
I'm doing the Active Directory Enumeration & Attacks module. I can spawn the Linux attack box but the windows doesn't work
It says that the password is incorrect ERRCONNECT_LOGON_FAILURE.
Is something wrong with the VM?
which password you using? cos there's 2 different ones for those
I mean I can't do the windows exercises because of this issue
htb-stdent:Academy_student_AD!
I tried using the linux password as well, cuz I didn't have anything else to try xD
make sure that the username and password are in singlequotes because the ! character does something in bash
If you get a locked out error just restart the attack box
π€¦π»
Never thought I need to use quotes for the username, I used it for the password tho π
Actually that also didn't solve the problem
I used rdesktop to make sure I'm typing the credentials in windows's login screen
Yet I'm getting (the username or password is incorrect)
maybe try using xfreerdp ?
It just spawns a black screen for some reason
press enter
I feel stupid man π
Thank you very much, it worked
Still no idea why rdesktop didn't work
Hey can someone help me I started a new account since I wasn't using this for a long time and I found and outdated tool that is no longer used I tried reporting it but I can't find a contact email anywhere
I donβt think anybody here can help you to start with a new account
If you want to use the old one you can email HTB.
Curious what the "Error detecting the version of libcrypto" error in PKINITtools is about. Anyone?
Reach out to support online, but retrieving an old account may be tricky, unless you have evidence of ownership
Need some help? Learn how to reach the support team on Academy.
Update: figured it out. Needed to install a more up-to-date fork of oscrypto in the Impacket venv.
Just started the nmap module, have a follow up question to some content. The module says:
If we disable port scan (-sn), Nmap automatically ping scan with ICMP Echo Requests (-PE). Once such a request is sent, we usually expect an ICMP reply if the pinging host is alive. The more interesting fact is that our previous scans did not do that because before Nmap could send an ICMP echo request, it would send an ARP ping resulting in an ARP reply. We can confirm this with the "--packet-trace" option. To ensure that ICMP echo requests are sent, we also define the option (-PE) for this.
My questions is when/why would I choose to use ARP vs ICMP to determine if a host is "alive"?
Windows firewall actually blocks ICMP by default
Gotcha, that makes sense π and presumably ICMP can give me a bit more than just "here have a mac address" which is my understanding of what arp would give me, so if it is there it's nice to have? Sorry new to networking beyond the basics required for programming.
ARP can get you ip addresses indirectly iirc
Thanks π
I need some assistance and I'm not sure where to start
Assistance with what exactly?
Then reach out to the authorities, no one here can help you with that, we aren't the police.
if it's not relevant, then it doesn't belong here
Who can I verify myself here?
what's this server for please someone tell me
You can see how to verify your HTB account in #welcome
For discussion related to HackTheBox products and platforms.
thanks
it tells about hacking?
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
I'm a noob and I'm looking for a partner to code with anybody hmu on my discord can start today n I'm serious if u can help me out that's all I'm looking for
@silent kayak i want someone who can play ctfs
steps are in #welcome
im getting id error
telling me to contact mods
dm me
done
For the Shells and Payloads live engagement, is there a way to find the user/password for host1 without looking at the hint?
@quiet halo please don't post content from modules above tier 0
here, no need to post content from the module though.
You just explain it without revealing the content
if i set ip 10.10.10.10 to status.company.com on /etc/hosts, it should take me to the same page whether I visit 10.10.10.10 or status.compnay.com, no?
there
depends on how the server is setup
there are various methods to block direct ip access and require a hostname
Hello guys in "Using Web Proxies" module in question "Use Burp Intruder to fuzz for '.html' files under the /admin directory, to find a file containing the flag" should i try more than 10 millions probability ?
Hello,
in the Working with IDS/IPS module, i got the answer for the Suricata skills assessment by getting a hint here and analyzing the pcap with wireshark, i also read through the link that is provided in the section but i still dont understand why its the correct answer.
There is a file named pipekatposhc2.pcap in the /home/htb-student/pcaps directory, which contains network traffic related to WMI execution. Add yet another content keyword right after the msg part of the rule with sid 2024233 within the local.rules file so that an alert is triggered and enter the specified payload as your answer. Answer format: C____e
if someone could explain it, i would really appreciate it.
mmm but let's assume I can visit the IP, it should still give me the same page as hostname since that's what the IP is mapped to, no?
or idk myabe im consufed
nope
how though
virtual hosts
There are various ways to configure a web server on how to respond when accessing it directly by IP. I can't really list them all because I don't know them all, and there are different ways for nginx, apache, and other web server software.
anyone compleded the wifi evil twin attacks skill assessment?
Hello there team! I have an issue or think is an issue in module pentest in a nutshell (Windows Pillaging) I can't see the file mention the .csv just want to validate if its only me? I already did privesc with user John by the way π₯²π
Hi everyone,
Iβve been stuck for about 4 hours on the Introduction to NoSQL Injection: Skills Assessment II.
Iβve already identified the valid username, and|| Iβve also triggered the reset functionality.||
However, when I try to use|| a time-based injection to enumerate the reset token||, it doesnβt seem to work anymore β I get the|| same response time ||regardless of the input.
If anyone could give me a hint or point me in the right direction, Iβd really appreciate it!
You can DM me
i need help for cbbh or cpts dm me if u willing to help
Server-side Attacks and broken authentication probally need some help
Yeah ask your specific questions here, just remember don't spoil content from modules above tier 0 (which those both are)
dm me directly thx
@formal prairie please don't post content from the modules that are above tier 0, like the pics, the username/pass etc.
Module Injection Attacks, section Exploitation of PDF Generation Vulnerabilities. How do you properly enumerate the internal web application? The payloads in the section mostly show errors for me
Sorry Wont happened again Apologies π
You can DM me
Would you be able to help me with my issue ?
Exploit a SSRF vulnerability to identify an internal web application. Access the internal application to obtain the flag?
dm me thx
i can't troubleshoot it right now sorry, sometimes you have to wait like 3-5 mins before a windows environment is fully up and running though
It weird I was not able to RDP in to any of the machine do you think I have to change my MTU ? Machine is running for more than 30 min
Hey guys, I recently start getting into βhackingβ I was wondering, how does one get access to a websites code, Not just by inspecting it but actually being able to change stuff about it. sorry if itβs a dumb question. Iβm not into taking credit card info or anything like that i just find it cool lol
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
anyone finish broken authentication and server side template injection
txt me thx
from cbbh
Imao, broken auth and ssti?
y'all makin progress or just staring at errors?
Hi, I am taking the Information Gathering - Web Edition, Skills Assessment module. When I add the correct vhosts in etc/hosts, I still can't get to the site. Can you tell me what the problem might be?
btw I'm not sure if this is the right or wrong place to ask questions about the modules.
When you update your hosts file make suire first to not add the port, second when you visit the host through a browser do not forget to add the port
i know
in hosts I wrote like this
94.237.50.202 inlanefreight.htb
then i tried
http://inlanefreight.htb:35350
God damn its slow as hell, will HTB servers ever be in SEA ??? π¦
nmap -Pn -A 10.10.11.62
Starting Nmap 7.95 ( https://nmap.org ) at 2025-04-06 04:34 EDT
Nmap scan report for 10.10.11.62
Host is up.
All 1000 scanned ports on 10.10.11.62 are in ignored states.
Not shown: 1000 filtered tcp ports (no-response)
Too many fingerprints match this host to give specific OS details
TRACEROUTE (using proto 1/icmp)
HOP RTT ADDRESS
1 102.55 ms 10.10.14.1
2 ... 30
What should I do next ?
Nmap Free Security Scanner, Port Scanner, & Network Exploration Tool. Download open source software for Linux, Windows, UNIX, FreeBSD, etc.
Thanks for your support!!
do you solved it?
can i dm you?
Feel free to DM
Some modules render properly though. And not meaning for HTB to be used on mobile. But just to check the content of modules for example.
Need help with payload and shell module "The Live Engagement". im not sure if i can post anything related to it here since its more than tier 0
Happy Sunday Peeps! Just touching in to see if i could get some advisement on:
https://academy.hackthebox.com/module/232/section/2578
Its a bit of a tricky situation...I am yet again in a situation - where I can do some interesting stuff...I got some sensitive deets, but not for the NPORTs and wondered if it might be related to an environmental issue?
I was able to enum as another user where I got sensitive deets for...but not as per user in the final question. Any helpers?
Can anyone help me with this questions:
Try to exploit the upload form to read the flag found at the root directory "/".
Has anyone did the 'Android Fundamentals' module --> 'Android Debug Bridge' section --> ' After launching the application as instructed in question 1, use ADB to read the content of the file /data/data/com.hackthebox.myapp/files/flag.txt.' for a little help please?
i can help, dm
i hope i can help π
we both have the same "permission denied" problem on this question
I have a question for this module:https://academy.hackthebox.com/module/292/section/3312 ,when I use module on my PC can get 86.84 accuracy,but when I upload this is output{ "accuracy": 0.0, "metrics": null, "misclassified": [] }
bro do you finished this?
do you finished?
me too,how dou you solved this?
can I dm you?
hello
i am doing pentest module and i am on footprinting smtp i run command it seems correct but it does not return answer can anyone help?
idk if we can ask for help here but ive been stuck on Module 39, Section 407 for an hour now
which is that
yea their wordlist was missing the correct user i searched the questions answer added to wordlist and it worked
strange
Hey,
Do you know who I can talk to about correcting a problem with my Academy account?
Hi π
Need some help? Learn how to reach the support team on Academy.
see above link
thanks
hey guys i have been having trouble on openvpn and i dont understand whats wrong
idk if this is the right channel
I solved this when who need help please dm me
reach out to support
Need some help? Learn how to reach the support team on Academy.
anyone know this?
desktop
huh
wow
yeah
@tulip jasper please don't spoil information from scans from a lab from the module, yes it's tier 0 but still try not to share the specific scans
I understand, sorry about that.
as a note @tulip jasper you got errors in your ffuf output; so there may be more going on that's causing issues
Thank you! I appreciate it. I have no idea what is the issue right now. I will try to find more info.
well the errors may indicate that there's some connection issue or something simplistic going wrong
my best guess is you're using http:// and not https://
@left needle module is above tier 0 please don't spoil things :)
sorry sir but was how can I solve that question ?
I have tried with https and I managed to get a 200 response code but when I use it as an answer it's still an error.
try refreshing the page, making sure you don't have extra spaces/0-width characters
thank you I will try this
the answer it's looking for is x.inlanefreight.com
there will be multiple 200 responses
the hint as to what it could be is in the question
Thank you! It worked but I don't know why fuff returned 301 for it.
Do you remember how you got the first answer for PulseGrid-INT?
hy any hint for it https://academy.hackthebox.com/module/134/section/1219
what i done :
i able to take over other user account but i don't see any admin user
when i go to flag.php it give 404 error . any hint to solve . thz in advance . π
301 => redirect
what? how? i have same problem
haven't done the module just utilized reading comprehension
Hi people
After several trials I couldnβt find the right answer for ( Penetration Testing Process; Page 9; Vulnerability Assessment):
βWhat type of analysis can be used to predict future probabilities?β.
I think it should be something like βPredictive Analysisβ, I tried prescriptive analysis as well
But I couldnβt manage to find the exact answer. Could someone assist me, please?It would be a great help
anyone ?
try taking out "analysis"
tried..it doesn't work
link to the page?
worked finally..thanks
ah ok nvm then 
Anyone know if theres an arm VM?
did you try different attack methods?
also the admin may not be a "username"
yes
A HTB specific one? I had a look and couldn't find it, do you have a link?
it helps to be specific in your initial question then
there's no "htb specific" vm
there's the "HTB edition" of the ParrotOS
looks like the live HTB edition isn't updated for ARM
Thanks
there is the architect edition
i use kali linux, both are great
btw theres even ippsec's version of it
you can use that too
somewhere in his vids he explains it
they were asking specifically about an ARM vm
:)
Hi! I am currently doing the Active Directory Attacks series and have difficulties connecting the the windows machines through RDP. I Downloaded the VPN config file after spawning machine. It once worked briefly, but I cannot get a stable connection. What am I missing?
you forgot the quote for the password ''
hello guys i'm stuck on this question on the active directory module :Perform the ExtraSids attack to compromise the parent domain. Submit the contents of the flag.txt file located in the c:\ExtraSids folder on the ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL domain controller in the parent domain."
can someone help me ... ?
i have this error with mimikatz ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)
don't use pwnbox and vpn at the same time
did you privilege::debug?
yes i have this error ERROR kuhl_m_privilege_simple ; RtlAdjustPrivilege (20) c0000061
i forgot how i navigated this, not at my notes atm but i don't recall many issues with this Β―_(γ)_/Β―
wifi evil twin attack skill assessment, anyone else working on this?
Dear all, I hope one can hel me: I am stuck withe final question in the Module "Network FOundation" that says: "Bypass the request filtering found on the target machine's HTTP service, and submit the flag found in the response. The flag will be in the format: HTB{...}"
THe flag says: "<!-- HTB{REDACTED} -->" but its still wrong...?
the flag part is just HTB{REDACTED}
it doesn't include the HTML comment
so exclude the <!-- -->
mh..still not working π
even copy pasted your answer
maybe i try and restart - thank you MarcieLee
well obviously i'm not giving the actual flag
but the flag is just the HTB{..}
as noted by the format
will try again thank you MarcieLee
I'm doing the "Information Security Foundations" path and am starging the "Setting Up" module. However this module says "A firm grasp of the following modules can be considered prerequisites for successful completion of this Module: Linux Fundamentals, Windows Fundamentals" But those are ordered later in the path. What is the deal with that? Makes the order in which to complete these confusing.
Setting up is the basics of getting a VM/VPS/etc up and running
you don't need to follow it step by step you can use it as a rough guide
there should be a wordlist included in the > resources < section
smtp-user-enum is also helpful
(not the nmap script, as that's garbage)
it can
Hello, like many others I am also stuck on this question in the module Password Attacks PtH: Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.
I am connected to the windows machine but when I try launching the attack the reverse shell conection is never initiated. Any help would be great.
This module introduces fundamental concepts of the Android environment, focusing on the operating system, its security features, and the structure of applications. It provides students with details about the different styles of application development and familiarizes them with their development environment. This module also explains how apps co...
dance !
Hey guys, do you know anything about computers?
||SSL||
is it possible for someone to explain me that question on the active directory module it's been 4 hours that i'm stuck ..
Perform the ExtraSids attack to compromise the parent domain. Submit the contents of the flag.txt file located in the c:\ExtraSids folder on the ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL domain controller in the parent domain.

preciate it, yeah finally got that one. Didn't realize I needed to get two clients to connect instead of just one. I got the third question as well. Can you offer any insight to the second question. I think I'm supposed to combine the wifiphisher section with another to crack into PulseGrid. Can you nudge me in the right direction?
Most likely, I did not close this question.
what you mean? You haven't been able to get the answer to question 2 either?
Yes, the module did not pass
Gotcha, well question 3 is covered directly in the eapham section if you haven't gotten that one, and I'm pretty sure question 2 is a combination of evil twin attack on wpa3 + the wifiphisher section
you're trying to download the file to a location you don't have write access to
also you can't chmod within ftp
not to mention module is above tier 0; and skill assessment so avoid spoiling things like username and general info about the environment
ok but im pretty sure the location isnt a problem so now you deleted the message i will remake it
ftp> ls
229 Entering Extended Passive Mode (|||35821|)
150 Here comes the directory listing.
-rw-rw-r-- 1 1000 1000 554 Feb 09 2022 authorized_keys
-rw------- 1 1000 1000 2546 Feb 09 2022 xfile
-rw-r--r-- 1 1000 1000 570 Feb 09 2022 x.pub
226 Directory send OK.
ftp> chmod 644 xfile
500 Unknown SITE command.
ftp> get xfile
local: xfile remote: xfile
ftp: Can't access `xfile': Permission denied
ftp>
Guys im struggling in the password-attack-easy-lab i cant download a file
i'm pretty sure it is; cd to a directory like /tmp then connect to the instance
Now that's interesting
the directory i created maybe days was root
drwxr-xr-x 2 root root 4.0K Apr 3 12:40 Confuzing
Thank You Marcie
this is why you don't run around as root
New module captive portals-bypass Client Hijacking through Interception. Anyone has problem connecting to the enterprise network with the already correct found password? What am i mssing?
hey yeah i solved it. it wasnt that hard thank you
i have seen many wifi moduels.Will be any cert about this?
One message removed from a suspended account.
Doesnt it only allow directories?
One message removed from a suspended account.
Evening all. I'm still stuck on the SMB-Footprinting: Connect to the discovered share and find the flag.txt file. Submit the contents as the answer.
I found A flag but its the wrong one? i did run a -Sv -sC to find this...i'm just stuck and could use some guidance
To start a share and have meaning the share has it, shares are directories
The key here is in the question: connect to the share
This module uses the same lab for several sections
if i'm understanding correctly im looking for logins and pws to be able to connect if anon is not present?
Correct also as a note, bc somehow this trips people up: -L lists shares and exits
Also "anon" in smb is guest logon
Easily testable with -U "" -N
am i doing too much by using -p-? clearly i'm not accessing the correct service
It's the smb section...
The answer isn't on some obscure port or anything
yes, of course and i have to access that to find the flag. i was just wondering if i'm doing too much by using -p-
One message removed from a suspended account.
The section tells you what ports to look at/for
You don't need to -p-
The windows machines on the modules have a huge latency for me, my VM is running 4 cpus and 8 Gigs of ram but man it's painful. Is the latency on Windows machines normal or can i improve it somehow
If I think there is some mistake in the solution, can I ask about it?
Module: Parameter Logic Bugs
Section: PoC and Patching - Unexpected Input
Hi, does after my annual subscription ended the step-by-step solution will be disabled?
My guess would be yes, but reach out to support on the site for an answer they will know for sure. I believe you need the active subscription to show the solutions.
Ok, thank you
Is it allowed to share details regarding solution?
yes
module above tier 0: no
if you think the solution is bugged/incorrect: #1234357888114364508 with the #walkthrough tag (obviously keep things spoilered/redacted) but more leniency is put there so that staff know what you're having issues with
does anyone know how to make the exploit work on Host3 of Shells and Payloads live engagement? I check LHOST, LPORT, RHOSTS, RPORT and everything seems correct, yet I get "Exploit completed, but no session was created".
Are you sure it's correct? Remember: you're on an internal network
Which IP π cos it's gonna have more than one
Your LHOST should be the device you're listening on, highly doubt it's the target IP you spawned
yeah the IP above, no?
Issue is 172.16.1.13 and 10.129.240.35 are NOT on the same subnet,
oh
However the foothold host CAN connect to them so it does have an IP in teh SAME subnet, e.g. 172.16.x.x
that's the LHOST you want
I change my LHOST to 172.16.1.5, same error
show ip a output on foothold host
deleted it cos it showed which exploit you were using 
oh myh bad
show options WITHOUT payload&exploit 
Looks good to me, can you try the check command?
idk what was wrong with the last exploit I used
They're different methods of establishing a shell
The one you're currently using is more reliable but also less stealthy as it involves adding files onto the admin share
yeah well it sucks
my mess up was not looking at the IPs
and not think about subnets
You'll get more used to it when you do the pivoting module
Anyone available to assist with payload construction on nosql skills part 2?
After discovering a username, Iβve discovered the endpoint to inject into but canβt ascertain a true/false from response text
@fringe gust This isn't the place for political discussions.
I need help
with what
File Upload Attacks
Type Filters
https://academy.hackthebox.com/module/136/section/1290
I can't seem to find my resource on the server
I finally finished "Introduction to Malware Analysis - Debugging" it only took me 9 hours.
Get Started with the HTB Beginners Bible: https://www.hackthebox.com/blog/learn-to-hack-beginners-bible
How I do this
How do you do what? I just linked how to get started with HTB.
Hey guys im having trouble with this module: SQLMAP ESSENTIALS - Attack Tuning
What's the contents of table flag5? (Case #5)
I can find the flag but it doesnt actually work. I heard of people having similar issues
tried refreshing the instance but no luck
What do you mean? You can't find uploaded file? Should be under /profile_images/test.jpg......
So you find and dumped it with [redacted]?
Not sure then, double-check that there is no [space] in the beginning and in the end of your input in SA section
Don't spoil commands for modules above tier 0
yeah I double checked that π¦
Removed.
Thank you.
@trail grove if you're certain you have the correct answer, and it is still not being accepted, I'd advise reaching out to support.
Starting to think we need to add a notification stating that whenever someone submits an incorrect flag, not sharing spoiling content I mean
Hi! I saw you completed the Android Fundamentals module, and I wanted to ask you something about the assessment.
In the instructions, it says: Install myapp.apk by dragging and dropping it into the emulator. Then, open the embedded terminal in Android Studio and run adb root && adb shell ls -l /installed/apps/. Replace /installed/apps/ with the correct path to find the appβs home directory.
Could you help me understand what the actual question is in this module?. I think the question is ambiguous. This is the last question I need to complete the module.
Thanks for the feedback @split cliff - agreed this module could be much clearer, and I'll feed this back to the team. This is certainly, at least from my experience of modules when providing support an exception. Apologies for the inconvenience and confusion.
As for the actual question, it seems you are expected to provide the path for the data directory of the installed APK.
Can dm me
Also @ripe pulsar, see above
Already answered @vivid mantle ;P
But thanks for offering all the same
π
I could have been less of an ass. Iβm sorry I let a bad day give me an excuse. I could have been a lot more professional, and I wasnβt. I figured it out, and it really wasnβt that big of a deal. Thank you for considering it despite my approach.
It's fine, can understand the frustration
Know that feeling of a bad day marring the rest of it
Question: Why does DLL Injection section of Windows Privilege Escalation module not have an exercise section? Looking at the whole lot of content, I feel like, I could grasp the concepts better, if I was doing hands on.
because DLL injection is definitely a bit more advanced than the other topics
as it would require either crafting an msfvenom payload or writing the malicious DLL yourself
Does this mean that I can expect CPTS exam would not require me to do "advanced" DLL injection?
Generally speaking, if the subject is not covered in the course material, it is unlikely to be included in the exam, but past that statement we can't provide details regarding the exam environment @eager ledge
Is there someone who I can send a DM for 'Skills Assessments Advanced XSS and CSRF Exploitation' and share my word doc for steps I tried to do xss on file upload function and help to promote the user?
Has anyone been having issues with xfreerdp at all? Everytime I get on hackthebox and this has been happening for about a month now, it will work for a section or two, then when I go to start the target IP again, wait the recommend 5 minutes, I either can't connect or I just get a black box. I've switched VPN servers, I've already checked everything on my end, I don't really have these issues to this extent with other platforms. I'm on the Active directory enumeration module now, but this issue has been prevalant since I started the Attacking Common Services module.
uses the tcp vpn download
I did that as well and it's pretty much the same result. It works for like two sections then I either get failure logon or I get a blackbox.
blackbox -> hit enter
Yeah that didn't do anything
I tried that before but I'll try that again. I checked my interfaces before and tun0 was the only vpn running
i also suggest reaching out to support
Need some help? Learn how to reach the support team on Academy.
I think previously some mentioned changing the MTU value on the VPN connection
All you need to know about the VPN Connection for Academy
I'll look into this and thank you for your help
The question has now been updated in order to provide more clarity π
anyone done with the API Attacks module? Got stuck in the 2nd question on Broken Object Property Level Authorization so need to do some sanity check https://academy.hackthebox.com/module/268/section/3063
Please I need help with this, have answered all most likely Ans but it's still said wrong answer
What does the acronym Linux PAM stand for ?π
@jagged vault Pluggable Authentication Modules
Anyone for SA advanced XSS and CSRF availible?
try using the /dynamic-resolution flag, and as suggested, click the black windows that appears and hit enter
anybody know what i'm doing wrong here? i can't interpret the error message mimikatz is giving me meaningfully
PS C:\Tools\mimikatz\x64> klist
Current LogonId is 0:0x59a94
Cached Tickets: (1)
#0> Client: hacker @ inlanefreight.local
Server: krbtgt/inlanefreight.local @ inlanefreight.local
KerbTicket Encryption Type: RSADSI RC4-HMAC(NT)
Ticket Flags 0x40e00000 -> forwardable renewable initial pre_authent
Start Time: 4/7/2025 3:30:24 (local)
End Time: 4/5/2035 3:30:24 (local)
Renew Time: 4/5/2035 3:30:24 (local)
Session Key Type: RSADSI RC4-HMAC(NT)
Cache Flags: 0x1 -> PRIMARY
Kdc Called:
PS C:\Tools\mimikatz\x64> .\mimikatz.exe "lsadump::dcsync /user:inlanefreight\lab_adm /domain:inlanefreight.local" exit
.#####. mimikatz 2.2.0 (x64) #19041 Aug 10 2021 02:01:23
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > https://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > https://pingcastle.com / https://mysmartlogon.com ***/
mimikatz(commandline) # lsadump::dcsync /user:inlanefreight\lab_adm /domain:inlanefreight.local
[DC] 'inlanefreight.local' will be the domain
[DC] 'ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL' will be the DC server
[DC] 'inlanefreight\lab_adm' will be the user account
[rpc] Service : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)
ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)
mimikatz(commandline) # exit
Bye!
ah, the /domain argument was wrong when creating the golden ticket - should have been logistics.inlanefreight.local
Hello, Im having some trouble on a question on Linux Fundamentals modul, hwere I should ask for help? π
here
So its not necessary to create a post at erratum?
Server-side Attacks
Identifying SSRF
There is like no guidance for this module, I think it login to a service or start a shell
https://academy.hackthebox.com/module/145/section/1295
as the name suggests, erratum is for errors spotted in the courses
If anyone could help me with this question, I'm doing a curl on the box, but its not returning anything.
I tried not to use chatpgt and alredy checked: man curl, but did not find anything
got it thank you
does the pwnbox have internet access? can you curl https://example.com from the pwnbox? are you able to access www.inlanefreight.com from a browser in the pwnbox?
I can ping google.com
but there is some problem on the connection
reboot the pwnbox
https://academy.hackthebox.com/module/134/section/1207
hy i was trying https://github.com/enjoiz/XXEinjector.git
that told in module but it not woking ? did i something working.
File Upload Attacks
Skills Assessment
Can't find the resource on the server?
https://academy.hackthebox.com/module/136/section/1310
Still the same problem after reboot
odd, did you terminate then start again? i don't use the pwnbox so not well-versed in the issues they tend to face.
Yes I did π , but this question aks for the use of the pwnbox, I also dont use, I have a VMWARE with ParrotOS
yeah just use that, nothing special about the pwnbox necessary for this question.
Ok, thank you for the help!
which resource?
the shell upload
how are you determining where the shell is uploaded?
i have the uploads folder but I can't find the file on the server
ok, so the name of the file you uploaded doesn't seem to match what is written to disk on the server. if you could list the directory contents, you could easily see the name the file is written as. if not, are you able to figure out how the filename is written?
Content-Disposition: form-data; name="uploadFile"; filename="SVG-XXE-Injection.svg"
Content-Type: image/svg+xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=index.php"> ]>
<svg>&xxe;</svg>
------WebKitFormBoundarynnv9uucKfWdyGev9--```
this give u source code if site then u get to know where file is uploaded.
yeah you are supposed to date the file after upload, but I still don't find the file on the server. But you are saying list the directory. I didnt try that but is it command injection at the URL?
Yeah I got this and and decoded it for a uploads folder, and like a naming scheme, but I don't seem to locate the file so I can list the directory
may be giving wrong path
hmm ok. what's the exact filename you're looking for?
i named it shell.phar.jpg but I have to find it on the server as 260704_shell.phar.jpg
did you run the php you saw in the source code to get that filename?
i didn't see it in the source code it gave me only images error
i don't know what you mean by that, but by the looks of it you're pretty close to getting the right name - although even without looking at the source code i can tell you definitely have that filename wrong based on the name you posted above
the file name doesn't show in the source code, it shows a Only Images Allowed message instead. but it would of shown as a base64 encoded path. I think i have to get the upload right anyways. You are supposed to fine your file on the server directly from the browser url
hang on, the base64 thing isn't a path, it's base64-encoded data. the url scheme is data://.
ok, so specifically why do you think you should be looking for a file named 260704_shell.phar.jpg
No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.
i think the server renames the file after upload
correct, and why would it be 260704_shell.phar.jpg
ohhh I have to name it that before uploading
// rename before storing
$fileName = date('ymd') . '_' . basename($_FILES["uploadFile"]["name"]);
$target_file = $target_dir . $fileName;
no, the comment describes what the code is doing
so shel.phar.jpg would of gotten name 260704_shell.phar.jpg on the server
the 4th of july 2026?
i cant list the directory anyways, im like sniping it at this point
oh its 260407_. But your are supposed to find the file like from the url and I get a 404
what year is it?
hello, question on android fundamentals. I'm currently in Android Emulator section and I'm stuck with the question number 2 asking for build number. I followed the instructions but it keeps prompt ing incorrect answer.
you can dm me
should be GET not a POST, but i would still expect that to not 404 if you uploaded the shell successfully
yeah, ill try that, I think its just the upload. ill probably try a php injection for jpegs from github
you have access to the source code to inspect the upload filtering logic, you shouldn't need to defer to random payloads
yeah I tried that, I think it was delete a function and add your extension to the list.
i swear they patched this thing
it is a +7 cube question, so it is quite demanding
You are supposed to be able to find/preview the file on the server by using the browser, but its not there.
How to get access to general
Can some help me in what is the issue in this case?
I am trying to use ligolo-ng SSL certificate for my connection but it is giving errors.
I am testing it on Pivoting, Tunneling and Port Forwarding Module Skill assessment.
Read and follow #welcome
hello i am a problem with
YARA & Sigma for SOC Analysts
Use Chainsaw with the "C:\Tools\chainsaw\sigma\rules\windows\powershell\powershell_script\posh_ps_susp_win32_shadowcopy.yml" Sigma rule to hunt for shadow volume deletion inside "C:\Events\YARASigma\lab_events_6.evtx". Enter the identified ScriptBlock ID as your answer.
its possible explain what i have to do
nice regards
Review # Hunting Evil with Sigma (Chainsaw Edition) section again
For modules you don't need to set up cert. -ignore-cert and run proxy without autocert
But answering your question, the problem is that you're connection (in simple terms) without valid cert to your proxy
Guys I switched to Kali Linux as Main OS from Windows. From that time I am facing a issue in charging. The battery percent suddenly shoots up and down. From 100 to 81 normal then suddenly 0. This happens in 3-4 minutes. Similar during charging.
What should I do . Other than switching to different OS
2025-04-07 19:02:15 status=Discharging percent=82
2025-04-07 19:02:16 status=Discharging percent=82
2025-04-07 19:02:17 status=Discharging percent=82
2025-04-07 19:02:18 status=Discharging percent=82
2025-04-07 19:02:19 status=Discharging percent=82
2025-04-07 19:02:20 status=Discharging percent=0
2025-04-07 19:02:21 status=Discharging percent=0
2025-04-07 19:02:22 status=Discharging percent=0
2025-04-07 19:02:23 status=Discharging percent=0
2025-04-07 19:02:24 status=Discharging percent=0
2025-04-07 19:02:25 status=Discharging percent=0
2025-04-07 19:02:26 status=Discharging percent=0
2025-04-07 19:02:27 status=Discharging percent=0
2025-04-07 19:02:28 status=Discharging percent=0
2025-04-07 19:02:29 status=Discharging percent=0
okok
ty
Yes, i can do it with self certificate but i want to use let's encrypt certificate.
I want to use letsencrypt certs to learn how to use those in real environment.
Have you done yet? I stuck with 2nd question too
i might have to skip it cause i feel some info is missing or was not explained
real
To create a Lets Encrypt certificate, you must own the domain to which the certificate is to be issued.
then what is the use case of this in ligolo-ng?
Have written it but it's wrong answer
Then why it shows, let's encrypt acmme autocert?
how can we use let's encrypt certificate to encrypt our current ligolo session.
@jagged vault Try then Privileged access management (PAM) that is the only two i know
@thin citrus thank you sooo much, I've got it
lol
I think if you have your own domain, you can make an SSL certificate over it and encrypt the connection that way
Yeah you can DM what you know, have tried, etc.
You can DM what you know and have tried too.
thanks
Hey, before I leave it running all day, is the brute force attack in password mutations supposed to take more than an hour or did I mess up an earlier step
Hi guys, can someone help me? Iβm new to pen testing and have a dumb questionβ¦
Iβm doing appointment module on htb, how do I know where something downloads to after doing git clone (url) command?
Also it would be a big help if someone could tell me how to access general chat
Been trying to figure out the general chat thing as well.
I wanted to thumbs up your message but I canβt do that. It makes me worry about my potential in being in pen testing lol
Ohhh thank you I got it
In the meanwhile, does anyone know the answer to my question about git clone?
Thats a #starting-point machine; read and follow #welcome to access
You likely missed a step; as a note you can adjust threads
DACL Attacks II Β§ sAMAccountName Spoofing
Getting a KDC_ERR_PREAUTH_FAILED on attempt to use the TGS retrieved using the spoofed account, and curious as to why. Any /etc/hosts modifications necessary?
Um thereβs no account identifier on my profile
Iβm in user settings of hack the box
Are you looking at https://app.hackthebox.com/profile/settings ?
Server-side Attacks
Identifying SSRF
I can't seem to find any guidance as far as attacking any services
https://academy.hackthebox.com/module/145/section/1295
Yeah it says I need a computer to be able to view the page
But Iβve only got discord mobile
Update: that's exactly what I had to do. Working now that I've added a hosts file entry
Thank you but Itβs locked.
This is hurting my heart so much right now
Can you really not help me with my question until I do this verification?
No
I don't like diverting channels off-topic
Can you dm me then?
You can use the web version of discord if you can't/don't want to download desktop
No
Yeah kerberos is picky when it comes to hosts stuff
Okay you guys seem a bit stuck up and Iβd rather not have ur help then
Bye
No Marcie
I just don't do help with starting-point stuff
I haven't touched it in ages
So i wouldn't be of much help
Yeah but the way I ask for help and youβre just like βnoβ
Just cos you donβt know me, have some manners
Because you asked a yes/no question
So you just follow rules your whole life?
And i might be busy
Either way we're diverting off-topic; i gave you ways to solve the issue of getting your account ID so that you can verify and get help in proper channels
I get you may be frustrated with the lab, so I'm not taking your frustration personally. I used to work helpdesk, so par for the course
If you really want #1024429874246590575 , but other mods may tell you the same info
So I have one question and the way to get ONE answer I have to download discord on computer, find my details for discord, wait for email verification for discord, do the account verification thing, ask my question again, wait for a response ?
All because you donβt want to spend 3 minutes
Thats the way this server operates, yes
Thatβs the way you choose to operate it though
Not to mention verification unlocks a whole host of other channels
Because youβd rather just not help me in dm
It's the way HTB chooses to operate
As i told you; haven't touched starting-point in ages
And i don't have notes on it
So it'd be pointless
But u do know about git clone if ur beyond starting point and if its basic?
Yeah exactly so my question wasnβt anything youβd need notes on
It was literally how do I know where it goes after doing that command?
It tells you where it downloads to
Cloned to <directory name>
Usually directory name is the same as the repo name
This is also stuff you can quickly and easily Google, instead of getting riled up over it.
First result on google
I see, its on me for listening to the hydra warning
Iβm not riled up over looking it up, I get annoyed that everything is made so complicated because people have egos
Thank you for explaining it to me
I don't have an ego
Thatβs literally all I needed
An ego would be me telling you "skill issue, read the docs"
So if u needed help and I said βnoβ and that was it
Youβd be like such a nice lady?
Yeah because you like rules though
Not sure where you're getting at with this
I just think you're reading too much into it
I don't dm regarding most things
Only dms are open for:
- server related issues bc mod
- business reasons
Thats it
Why are you on here if not to help people with htb?
It's not solely bc "rules" it's because in my experience; people tend to ask questions in dms that extend way past their original question i agreed to
I do help; but it just depends on the topic
If it's a module I've done? Sure I'll give a nudge or two
Most things beyond that, if it's not to do with moderating the server - i tend to stay in my own lane
Your profile literally says offering mentorship and tutoring but okay idm that but I was asking for something so easy for u, it shouldnβt have been so hard to get it
Yes, regarding the cpts path
I don't do much mentor/tutor outside that, and it's not free
Hey! Anyone completed Android fundamentals? I'm bit stuck for question that asks for build number when there is need to create avd - Pixel 3a API 34 Google APIs, build number is the one from settings, right?
Btw Marcie Appointment Write-Up has wrong instructions
I donβt know if they updated it
I'm not staff. You can feel free to message support
Need to speak to a person? Learn how to reach our support via HTB Labs.
The labs and such are several years old, and the writeups by extension are as well
Tools update, syntax changes, life moves on
How long did it take you to learn pen testing Marcie?
Well it would have been faster but a bit over a year
Ohh so you did it during a time when there wasnβt hack the box?
No
Or did u learn from hack the box?
Oh sorry
It seems like itβs better now though?
Also did u have background in learning this stuff before hackthebox or were u completely new?
Didn't even know what nmap was
@thin citrus please I'm stuck with another question
The question says Find out the machine hardware name and submit it
Have tried but not getting it
Linux fundamentals module? Are you connected to the target machine?
@fathom pendant no
- Instead of @ someone; the reply feature exists
- What module and section then?
Ok, thank you
Current path on Information Foundation
System information
So linux fundamentals module: system information?
I have a question if anyone is available?
Yes
Android Fundamentals - Android Emulators - Q2 ? Anyone, this is misleading, tried to check from shell getprop and sort everything that has build name and none of the answers is correct
Spawn target, ssh to the target with the given creds, use the command
Have spam it but I don't know way forward from there
Gonna assume (sorry if not) English isn't first language?
How I'm I going to use the command
When you connect to the target, you run the uname command
I believe the section gives you info on how to ssh
No, I'm not getting it
Different sections of the uname -a are for Different things
I believe the section goes over this
Can I do it without having Linux on my pc
Because I have issues with installing Linux on my pc
There's a target you can connect to; you get 1 use of the in-browser vm per day you can use to do the labs
(On free account)
Im on the skill check part of the linux local priv esc and i cannot get flag4. I'm pretty sure its something to do with mysql but i cant get the login.
@jagged vault look at uname -h for options
It's also shown in the section
I'm cooked π¦
Take a step back and re-evaluate your situation. Try everything that was taught, even things like default passwords or history
π¦ if its a default password im going to probably think about it for the next 3 days.
thank god its not but im still stuck. I will msg back if im still stuck in like 10 minutes
yeah still nothing.
+1
I've tried all its not accepting anything anyone know what is it?
I've tried -
MAC
MAC address
Hardware address
Ethernet address
Physical address
helps to say the module and section name
name is slightly more helpful for other users in the future if they run into the same issues
Intro to Network Traffic Analysis -Networking Primer - Layers 1-4
word-word
it's in that format several times in the section
Appreciate the help Marcie! Honestly though, they really should mention the format requirement in the question itself. Spent way too long trying every valid term-wouldβve been so much easier if it just said 'use word-word format' upfront
well; tbf it's written that way in several spaces in the section
3/5 times that "MAC" appears, it appears with the hyphenated spelling
the only time it's not is when they define what MAC is (Media Access Control) or with the separation (IP and MAC)
If a question is about technical accuracy, the format shouldnβt be a guessing game.
- Can't access #general ?
- read and follow #welcome, there are instructions at the bottom of that channel for connecting your HTB labs account to gain access.
- The "Finished Reading Go to <channel>" is a byproduct of Discord, it's not something that HTB can control, it's just how the Read Only channels work.
- Want to post images/embed so it's easier to explain your issue?
- see above, in order to prevent trolls and spammers we limit the embed perms in the academy channels to verified/linked users only
- Having a technical issue with a module?
- If you believe it to be an issue with the module itself, and not with your methods -- #1234357888114364508 with the module and section name (I.E. Getting Started - Introduction) that way the staff that handles it can check and update accordingly, even if it's just a typo.
- If it's not an issue with the module itself, ask here and provide the module and section name -- plenty of people in the community willing to help, if you need to reveal syntax redact things like subdomains, usernames, and passwords, spoiler tags don't really do much, since anyone can click on them.
- common redaction format for usernames and passwords is first character followed by an asterisk * w* (for example for a username like will);
- common redaction method for subdomains/domains would be like x.example.local, or sub.do.main
- If you're unsure of the module/section name you can look at the top left of the page (scroll to the top) the module name will be at the top with a β€οΈ next to it, the section name is just below that.
- Curious how the cube system works and the subscriptions?
- https://help.hackthebox.com/en/articles/5272936-introduction-to-htb-academy
- https://help.hackthebox.com/en/articles/5720974-academy-subscriptions
- Your question is unrelated to academy?
- see point 1, linking your account grants access to a lot more of the server.
Just saying... if the answer is technically correct but still wrong because I didnβt match their secret hyphen club formatting - thatβs not assessment, thatβs trivia night π
technically speaking, the hyphenated format is more correct
but if you think it should accept both; /feedback and #1234357888114364508
Can someone help me with the third flag in the Active Directory Trust Attacks β Skill Assessment module?
Weird that it's trying to connect to mit for the proxy
Hello hello,
Quick question on Lateral Movement (Windows).
On the WSUS part, I followed all the instructions, user now is part of Admin group. Yet...
Somehow flag isn't where it should be according to the question. What did I miss?
Yea , not sure why it's doing that
Did you log out and log back in?
Wait; misread
Ignore me
Login Brute Forcing
Custom Wordlists
I can't seem to find a username to start my custom wordlist
https://academy.hackthebox.com/module/57/section/3209
Use the example data
alright its just like a random Jane Smith and really long custom wordlist
Yep. And they tell you how to shorten the list
I'm finally done with all the module of the CPTS course (outside the reporting one I keep for few days before the exam).
I wanted to try to do a prolabs to keep working on my methodology & enumeration skills but I don't know which one to take between P.O.O, Zephyr & Dante. Do you have any advice please ?
am i supposed to use pwnbox or am i allowed to use my own openvpn+vm setup, for doing exercises on the modules
i accidentally closed my pwnbox so i went w ovpn+vm, but some commands are funky
for example, ls does not work (shows no input), and i tried sudo'ing it but it was a nono
Not sure how you are attempting to get the flag, but you can DM if you are having issues.
i believe i do not have read permissions, but i did follow the steps to connect properly
open kali running on vm > openvpn > ssh
you can use your own vm
on the final part of SMB Footprinting. The question is: What is the full system path of that specific share? (format: "/directory/names")
I feel like i've used the right cmd but i'm getting C:\ and the hint states linux doesn't use C:\ what am i missing?
APTLabs
Bruh, if I were able to do the APTLabs, I wouldn't be worried about the CPTS exam
Better go with Zephyr then haha
Ok thanks !
Hi! In short, C:\ is the root directory in Windows. Linux uses a different file system structureβits root directory is simply /, not C:. To find the answer to your question you could google "Linux File Hierarchy Structure".
e.g. for users folder
Windows C:\ Users\john
Linux: /home/john
thanks for replying! Shamhus helped me out with the hint being very misleading and me trying to learn linux and pentesting i've made this a bit more difficult on myself!
π
@wet arrow please be sure not to reveal content from modules above tier 0, including commands, IP addresses you need to find, etc.
Can anyone help me setup the introduction to malware analysis debugging lab. I'm using the pwnbox for INetSim but its saying failed when I try and run it
@small willow Please do not reveal content from modules above tier 0
what's the difference between LSA and LSASS?
the password attacks module pretty much explainst it to be the same
yeah I found that when I googled it
to me, it's seems like it the same thing
also, i'm so confused on what the diff between LSASS and Kerberos is. I keep seeing that LSASS is still used to authenticates users even when the computer is domain joined. I thought that's what Kerberos is for.
my undertanding is that LSASS is used on non-domain computers
and Kerberos for domain-joined computers
Kerberos is a network authentication protocol used in domain environments that identifies securely using tickets. LSASS is a Windows process that enforces security policies and manages authentication, including Kerberos and NTLM. Basically Kerberos is an authentication protocol while LSASS is a process/service that implements and manages authentication methods.
No. Not what this discord is for.
This server is for discussion about HackTheBox's various platforms, it's not a hacker for hire server.
There are two directories that I want to list the contents of. I've done it with public and it worked. However, I'm unable to do the same on Anonymous Share. I've shared the error below.
rsync --list-only [IP]::Anonymous Share
@ERROR: Unknown module 'Anonymous'
rsync error: error starting client-server protocol (code 5) at main.c(1863) [Receiver=3.2.7]
(Note: I do not actually need to access Anonymous Share to complete the module but I just want to try stuff)
Which module is this for?
@late jungle you may want to go to the #starting-point channel
This channel is for Academy modules
Were you about to make progress here? Same place as you
Hello Everyone, I would like your opinion regarding HTB Academy,
I'm doing the Bug Bounty Hunter program,
Currently on Using Web Proxies. On step 3 out of 4 it asked me to Fuzz the last character of the 31-characters to submit the completed md5 hashed cookie.
I felt the Academy didn't go into much detail of encoding chains. I found myself doing research outside of the Academy. [Being in IT for 8+ years, I'm aware a lot of troubleshooting/learning is researching.]
For those who have used HTB Academy, do you find it informative and straight forward or do you find yourself still researching to understand your objectives more clearly?
I got a special code from hack the sphere (the April fools event). Where do I use it and what does it do?
That event finished last week, it just did something on Discord
Thx
A lot of the tasks are designed to get you to research cos thats what most of cyber is
Yeah I had a feeling.
Anyone can help me?
I get this error when I followed steps as is.
Start-Dnscat2EncInit : Failed to negotiate encryption. Ensure your dnscat2 server is set up correctly.
At C:\Users\htb-student\Desktop\dnscat2-powershell\dnscat2.ps1:1462 char:20
-
$Session = Start-Dnscat2EncInit $Session $False -
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~- CategoryInfo : NotSpecified: (:) [Write-Error], WriteErrorException
- FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,Start-Dnscat2EncInit
what about it?
whats the output when you run the server?
https://academy.hackthebox.com/module/57/section/3209
Login Brute Forcing
Custom Wordlists
I can't tell where to start on usernames and making a custom wordlist. Text shows how to make long wordlist for specific names?
Server doesn't respond after setup
are you positive that it's running?
can the client machine reach the server machine on port 53? (you can use nc.exe to confirm this)
Sry, I got this
dnscat2> window
0 :: main [active]
crypto-debug :: Debug window for crypto stuff []
dns1 :: DNS Driver running on 10.10.14.183:53 domains = inlanefreight.local []
dnscat2> /home/a/dnscat2/server/libs/swindow.rb:381: [BUG] Segmentation fault at 0xffffffffffffffff
ruby 3.1.2p20 (2022-04-12 revision 4491bb740a) [x86_64-linux-gnu]
-- Control frame information -----------------------------------------------
c:0004 p:---- s:0019 e:000018 CFUNC :join
c:0003 p:0005 s:0015 e:000014 METHOD /home/a/dnscat2/server/libs/swindow.rb:381
c:0002 p:0867 s:0011 E:000bd8 EVAL dnscat2.rb:217 [FINISH]
c:0001 p:0000 s:0003 E:001180 (none) [FINISH]
-- Ruby level backtrace information ----------------------------------------
dnscat2.rb:217:in <main>' /home/a/dnscat2/server/libs/swindow.rb:381:in wait'
/home/a/dnscat2/server/libs/swindow.rb:381:in `join'
-- Machine register context ------------------------------------------------
RIP: 0xffffffffffffffff RBP: 0x000055580ac55320 RSP: 0x00007ffe86c415b8
RAX: 0x0000000000000000 RBX: 0x000055580ac59308 RCX: 0x00007efe3211b316
RDX: 0x00007ffe86c415c0 RDI: 0x000000000000001c RSI: 0x00007ffe86c416f0
R8: 0x0000000000000008 R9: 0x0000000000000000 R10: 0x0000000000000000
R11: 0x0000000000000293 R12: 0x0000000000000000 R13: 0x00007efe325ae220
R14: 0x0000000000000000 R15: 0x00007efe31fc3f50 EFL: 0x0000000000010293
Looks like the dnscat server is crachingdue to a buffer overflow/misalignment
how do I resolve this?
You doing this on the pwnbox or your own vm?
use the pwnbox to get through the section for now, I recommend uninstalling dns cat on your main machine for now
I assume it's a ruby version mismatch but it's hard to say
I'll try that tomorrow morning after a sleep. thanks for the tip
Anyone for SA advanced XSS and CSRF availible?
You can send me a DM.
With the amount of issues I'm having with trying to connect to their Window machines, I'm beginning to get really put off by the platform. Some of their Attacking Common Services sections are outdated as well. I'm all for researching and troubleshooting a problem, but when I'm paying for it, I can't help but feel slighted.
Anyone else having ovpn file issues. Can't connect to anything.
Contact support to solve the connection problems.
I did that. Couldn't email them directly as it wouldn't let me put my email in the sender message, so I had to use the chatbot and then put my email in there when prompted for the option.
ok now it's working I have no idea
You can also send an email directly.
Need some help? Learn how to reach the support team on Academy.
Thanks
For Broken Authenticaion - Brute-Forcing Passwords
in the grep command; i first gunzip .gz txt file, then it after I run the command gives me a binary file matches, after I used grep -a and still the same. Am I tripping??
The one in Passwords/Leaked-Databases/ didn't work.
grep: /usr/share/wordlists//rockyou.txt: binary file matches
grep: (standard input): binary file matches
Hey there, I'm having a silly issue on The Anatomy of a Shell, https://academy.hackthebox.com/module/115/section/1103
The task is really simple and just asks for the version of Powershell. However, tried running $PSversiontable and inputting the version in any variation I can think of (7.5.0, PowerShell 7.5.0, PS 7.5.0) and much more. I've also tried manually brute forcing every major version of PowerShell down to 7.0.0, like "7.4.6", "7.4.5", "7.4.4" etc.
I've also tried all the other numbers listed there, like 2.3, 1.1.0.1 etc.
I keep getting "Error Incorrect Answer". It doesn't much matter as it's kind of a silly task, but I do want that checkbox and it does bother me, lol.
Do I really have the wrong answers (or wrong format) or is this a bug (perhaps the Pwnbox PS version was updated since this module was made)?
read the question again
Silly me... Got it now. I could have sworn I already tried that in various variations, but obviously Imust have missed the very basic one. Thanks.
Is anyone having an issue with target web pages taking 5+ minutes to load?
Trying to pull up a web page in portswigger and it.. just isnt
On my pwnbox, through firefox, it took minutes
This one is still going 5+ minutes later
Also very frustrating that we're suddenly expected to know how to use burpsuite when it still hasn't been introduced in the pen testing line π
nvm.. think i have it figured out finally
oh man thats incredible you can literally STEP between each request???? Why has this not been introduced already god I love this
Did somebody solve the exercise "PEAP Relay Attack" in the "Attacking WPA/WPA2 Wi-Fi Networks" module (https://academy.hackthebox.com/module/282/section/3176)? The wpa_sycophant script cannot be started:
wifi@HTB-Corp:~$ sudo /opt/wpa_sycophant/wpa_sycophant.sh -c wpa_sycophant.config -i wlan2 SYCOPHANT : RUNNING "./wpa_supplicant/wpa_supplicant -i wlan2 -c wpa_sycophant.config" SYCOPHANT : RUNNING "dhclient wlan2" /opt/wpa_sycophant/wpa_sycophant.sh: line 61: ./wpa_supplicant/wpa_supplicant: No such file or directory
I fixed line 10 to
supplicant="/usr/sbin/wpa_supplicant"
then the script starts but doesn't show the ASCII art and will fail EAP authentication:
wlan2: CTRL-EVENT-EAP-FAILURE EAP authentication failed wlan2: CTRL-EVENT-DISCONNECTED bssid=dc:4b:03:39:bd:7a reason=23 wlan2: CTRL-EVENT-SSID-TEMP-DISABLED id=0 ssid="HTB-Corp" auth_failures=2 duration=39 reason=AUTH_FAILED
Can anybody help?
Shells & Payloads assessment seems to be impossible
Referencing "The Live Engagement"
You're required to do everything through the parrot vm that you connect to through XfreeRDP. However this VM is unequipped with any sort of internet browser which the literal second question requires you to utilize taking the reverse shell route.
I've been here for an hour trying to figure a way around this but have found no resolutions. I'm going to bed but please ping me with a fix or whatever I'm doing wrong please.
I'm still struggling to figure out how you're supposed to know to use a ||stageless attack|| and as to which ||payload to use, in this case I'm seeing people using java_jsp shell.war|| I'm pretty lost as to how to approach any of this and I'm feeling too overwhelmed to even think straight. The lack of resources to cover these topics directly is exhausting.
you can launch browsers from the terminal
Iβll figure that out in the morning then. Iβm still not sure how the fuck im supposed to know which specific war payload to use. Everywhere online only shows answers no methodology or explanation of logic behind it.
Hey guys does anyone know how to convert a ntds.dit dump file in a hashcat format for cracking?
Yes, the fact that I paid for the course, I was expecting to be presented with some in-depth concepts that would be difficult to obtain elsewhere. It looks like the content that we are paying for isnβt necessarily a hand-holding class. Itβs more like weβre simply paying for the environment (infrastructure) that they had configured to test our skills. With just enough context and concepts to get you thinking.
Whatβs your issue with connecting?
I have an issue here either my scans are not giving me the right service or HTB needs to review,
i am working on Pentest In A NutShell >> Linux Pillaging >> Which version of vsftpd is installed on the target system? (Format: x.y.z)
PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 63
| fingerprint-strings:
| GenericLines:
| 220 ProFTPD Server (Debian) [10.129.233.210]
| Invalid command: try being more creative
|_ Invalid command: try being more creative
22/tcp open ssh syn-ack ttl 63 OpenSSH 8.9p1 Ubuntu 3ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 3e:ea:45:4b:c5:d1:6d:6f:e2:d4:d1:3b:0a:3d:a9:4f (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBJ+m7rYl1vRtnm789pH3IRhxI4CNCANVj+N5kovboNzcw9vHsBwvPX3KYA3cxGbKiA0VqbKRpOHnpsMuHEXEVJc=
| 256 64:cc:75:de:4a:e6:a5:b4:73:eb:3f:1b:cf:b4:e3:94 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOtuEdoYxTohG80Bo6YCqSzUY9+qbnAFnhsk4yAZNqhM
There is proftpd no vsftpd
which nmap flags did you use?
did you try -p- --min-rate=1000
-sVC -vvv -Pn
no
I'm new here so my questions might be dumb
Nah no dumb questions
maybe vsftpd is on a port higher than the default 1000
but default seems to be 21 so..
Hello everyone... I just got access to a box and I discover a sub-domain that is not reachable from the outside. The web server running behind it is nginx. I can reach the root domain soccer.htb but not soc-player.soccer.htb. I've already updated my /etc/hosts. Every time I try to navigate to soc-player.soccer.htb, I get a 502 error. Can anyone help me solve this problem?
Can I DM someone on module "Introduction to Crackmapexec" skill assessment?
@junior roost , it may be the flag your using. Iβve had some issues where I know a service is on the machine but couldnβt get nmap to detect it until I had the correct flag in.
Please can I have an idea here ?
Yes π
Have not done this module but maybe try to connect via ftp/nc to see if it may give you additional output
I had this issue and switching VPN regions fixed it for me. I don't know the cause or even what's happening to break it, but it's worth a try if you haven't.
Alright. Thanks. I will try.
Thanks a lot @shadow grove . It worked for me.
hey there, lately I'v been struggling a lot to complete my rooms because of poor performence of htb servers, I keep getting timed out while bruteforcing, connecting to any service etc... this is slowing me down to crazy extents. Is there any way to fix that ? I tried switching servers, vpn protocol (udp/tcp) etc... but yeah nothing seems to work my connection to the target is always bad, (from my own machine throught vpn or from the pwnbox)
reach out to support via the website and the green bubble
tried that but the chatbot keeps telling me that I should look for support somewhere else
Don't ask to ask, just ask.
change the context of the support inquiry and deliberately ask to contact a human
Content Guidance
You asked for something different than you intended
well on the first module Enviroment Enumiration any ideas or give me directions on what to look for
yep my bad tried again answering differently and it seems like it is redirecting mle to support
Hunt for bash scripts
yea so flag should conatin HTB{ ....... smth()} as far as we know and i just bash script for potential flag files right?
seems fun ):: i hate linux priv esc
yeah smth like that
simple find / grep should work as long as you filtering by a filename
yea thanks!!!
Assume you don't know the format
yea that would be hard okay time to research thanks guys
Hi, is there a way to copy the entire config (appearance, menus, terminal, etc.) from the Pwnbox to my local Parrot OS vm (HTB)?
I mean you can just install the htb version of parrot
It'll be close enough
But you'd have to dig through configs and .bashrc to mirror it exactly
I did, but there's still quite a big difference. The matemenu is also designed differently (the VPN indicator, etc.). I was thinking maybe there's a way to apply it automatically to every VM. Thanks for the quick reply! π I guess I'll dig through the configs then.
it took a while but i had to configure a lot manually. it's not exact but it's close enough
you can steal the .bashrc to get the bash prompt
the MATE terminal colors you can also steal if you go to the settings
ohhh, thats awesome @dark hedge ! so, just the .bashrc and terminal colours etc. trough the interface? thanks for helping out! π
yea. you'll also have to configure the MATE bar or whatever it's called
okay, thanks alot!
My bad
this command is right but it does not return anything
maybe the server is down or smth do any of you have any idea?
Why not connect via openssl
According to google you need to provide -X 'imap command'
Thats your first mistake
Also i believe the section shows some curl commands, could be wrong though
with K