#modules

1 messages · Page 409 of 1

lusty thicket
#

but from what i remember from that module you should be fine

#

just go back and skim the first cluster's or diagrams, don't do the labs again, just refresh core ideas

#

they usually label the good bits early

quasi wave
#

ok thanks I'll just pwnbox it then ya

#

until my lenovo gets out of shop

#

tomorrow is renaissance fair

safe star
#

should have a backup on github or something

quasi wave
#

ok thanks

quasi wave
#

I think they said five to ten days and I submitted the machine last Friday. However, its five to ten days after they get the part ordered or something.

#

because they are fixing it under warranty

#

so its an issue with my battery I think

#

I'm hoping I get it fixed by next Friday

#

I'm hoping it will get fixed soon

#

its a new lenovo laptop and there's a battery issue

tranquil axle
#

I remember there being a hint on the initial website (I think a comment on an order?) that tells you which port it is

hallow dust
#

Can anyone tell me how to apply for student subscription in HTB?

shadow grove
#

I've got a question with massive spoilers for the final skill assessment for the Active Directory module on the CPTS path. Is anyone who's done it open for a DM?

fading olive
#

Hello, I had a big issue with Attacking Enterprise Networks > Lateral Movement > Privilege Escalation on MS01. The lesson suggests to use the SysaxAutomation software which contains a vulnerability where it will run stuff as SYSTEM. I kept trying and I kept gettings errors (which strongly suggested an encoding problem). The way I fixed it is by saving the pwn.bat file with ANSI encoding, now it's executed correctly. I just hope this is useful for someone in the future because I feel like encoding problems aren't so obvious. Good Luck!

ancient niche
#

eyyy guys Good Morning i have this problem with jupyter lab. I cannot open it

cinder bolt
#

I think the Skill Assessment lab on AD Trust attacks is broken (specifically the last step). Anyone who’s done it around so that I can confirm?

rustic sage
languid barn
#

Can anyone help me? i'm am stuck for hours at the module "information gathering - web edition", i'm at the skills assement page, at " What is the API key in the hidden admin directory that you have discovered on the target system?" With gobuster i found the hidden vhost. On this vhost the robots.txt file gave away an admin page, but i can't reach it, not with curl, not with firefox. And i definitely correctly added the subdomain to the /etc/hosts file.
the sudo nano command is just me checking for the 100th time if i added it correctly

#

or without -L :

ancient niche
#

ey guys someone had this problem with jupyter lab?

daring fable
#

Quick Question. I am currently working on the Firewall and IDS/IPS Evasion. However, I feel like I was being even way too stealthy for the easy lab. How would you determine when it go really stealthy or not?

waxen totem
waxen totem
#

Or visiting it in the browser?

daring fable
#

For example when scanning for OS or whatever

languid barn
#

i visited already in the browser, but i know for sure this is the right directory, i checked some write ups because i went crazy. But from the write ups I was still no wiser

waxen totem
nimble scroll
#

hi

#

Security Monitoring & SIEM Fundamentals
Page 2
Introduction To The Elastic Stack
Introduction To The Elastic Stack , I cannot connect to the target, did anyone find this issue?

#

10.129.208.183 I spawned also another target, it is up but still cannot access

ancient niche
#

pls I need help with jupyter lab

nimble scroll
#

can anyone help me ?

#

I specified also in /etc/hosts but no success

safe mango
nimble scroll
#

now it works

#

now I don t find Comparison Operators :/

ancient niche
#

someone can help with this pls?

steady pelican
#

Hello, I am on Introduction to Active Directory module and stuck on AD Administration Guided Lab Part II.
The task is to add a new user computer to the domain INLANEFREIGHT.LOCAL. When I looged in to new user computer and run the command to add computer to domain it worked.
However, when I logged into DC and run the powershell with admin privilege and run the command to add computer. It returns with an error Access id Denied.
Please refer to the attached screenshot for reference. My question is with Admin priv on DC, we can add any computer to domain, then why we can't in this case.

safe mango
safe mango
ancient niche
safe mango
ancient niche
#

i don't know omg

#

yesterday i was worked it but today no:(

safe mango
ancient niche
#

but that has nothing to do with it

#

with the vpn friend

acoustic owl
spark adder
#

hello there, I am trying to do the finall assessment of XSS module. I am able to load my remote script. But after that I cannot proceed further. NEed help ty

ancient niche
acoustic owl
# ancient niche AI

And you need Jupyter Labs for that?
Doesn't the module explain how to install it?

ancient niche
#

this is not working

cinder bolt
#

Have you cleaned browser cache? Tried a different browser or private instance?

acoustic owl
ancient niche
acoustic owl
#

Is Jupyter needed for the Lab?
Is the installation explained in the module?

proven skiff
#

Hey @wet arrow

I tried with arp if we have access to the terminal we can run for discover host

arp -i <internal_network_interface_name>

It will response back if there are any host up

ancient niche
#

and i didn't nothing

acoustic owl
#

If it is required in the module, it should be installes on the PwnBox. Does it work there?

ancient niche
flint palm
#

Guys hello can you recommend some free password audit tools?

#

Preferably online tools if such exist

leaden island
#

im not sure if this looks like a powershell shell

#

module shells&payloads

ancient niche
#

someone had this problem with jupyter lab?

bright coral
leaden island
#

ahaaaaaaaaa

restive vortex
#

Footprinting module DNS host based enumeration

hey, I'm currently on this module but there seems to be alot of information on the page which is making it hard for me to memorize. Does anyone have key takeaways that I can remember instead of reading over the whole page numerous times?

quartz lagoon
#

i wonder if there's a windows equivalent of this command

vocal galleon
#

Hey everyone!
I'm currently working on the Active Directory Trust Attacks - Skills Assessment and I’m stuck on the last question.
I found the shadow credentials (password and KeyCredential link), but the exploitation isn’t working as expected.
Has anyone here completed this part and could share any hints or point me in the right direction?
Thanks in advance!

proven skiff
gray yacht
acoustic owl
#

Have you tried it from the PwnBox?

ancient niche
#

the problem is I cannot work if I don't have this programm

odd stirrup
#

hi, i don't know if its the right place, i'm trying to scan a target for the Public Exploit module through mu VM which is connected with the ovpn file to the lab, i can ping the targetm but if i run nmap -sC -sV it returns

Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-04-12 15:15 UTC
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.18 seconds

if i run again with -Pn i get only a partial scan, however when i run the scan without -Pn in the pwnbox it goes through without issues, can it be a misconfiguration of the vpn my side?

ancient niche
#

the browser is in white

cinder bolt
acoustic owl
ancient niche
acoustic owl
ancient niche
acoustic owl
#

But now you know that your vm is broken and you have to look there. Probably no one here will be able to help you because no one knows exactly what you have installed/configured.

gray yacht
cinder bolt
#

I’ve been resetting the box since yesterday, must’ve been at least 10 times by now. Let me DM you to figure if I’m just massively unlucky or missing something

acoustic owl
#

you can post this picture 100 times. It won't do any good.
No one can help you on your own vm. It works in the PwnBox

vernal coyote
#

I need help. I’m at the AD Enumeration & Attacks. I’m completing the DCSync assessment. When I try to rdp to the second IP (academy-EA-attack01), it gives me a login failed for display0. Can someone put me to the right direction?

smoky arrow
#

Hi guys I'm stuck at the skill assessment of File Upload attack.
Try to exploit the upload form to read the flag found at the root directory "/".
Someone can help me in DM?

proven skiff
median gale
#

Would love to see the wireless series move to some bluetooth attacks as well

proper umbra
proper umbra
gray yacht
topaz inlet
#

thank you a lot fingerguns

hexed oyster
#

Can someone take a look at this script and tell me if I'm on the right track? I'm working on "broken auth - brute forcing weak tokens". The script runs, but it's not returning anything.

hoary glen
#

hi

iron zephyr
#

Hello colleagues! I need some help. In the Information Gathering - Web Edition module in Skills Assessment (question number 3). I find the only available vhost/subdomain with the dictionary subdomains-top1million-110000.txt. I then set out to look at the robots.txt file and there is no way to find it. I looked at a couple of write ups to check that I was doing it right and it was all correct. Does anyone know if the module is broken? I still have 3/5 questions to answer and I would like to finish the module without having to lose more hair.xD
Thanks in advance to all!
PS1: I just need to know what I am doing wrong or if the module is broken.
PS2: The /etc/hosts file is updated with the correct IP and name.

if this is not applicable here please tell me where and excuse me.

fathom pendant
fathom pendant
spark charm
#

i need help

fathom pendant
spark charm
# fathom pendant with?

i don't know why the academy machines so slow when i connect them via rdp or ssh there are a lot of lag

fathom pendant
#

use tcp vpn; try changing vpn regions

#

you read the page; take notes; do the question (if there is one) then click "complete and continue" or w/e the wording is on the button

spark charm
fathom pendant
compact patrolBOT
fathom pendant
#

they do work on the weekends

#

just have patience

spark charm
#

the problem is that even my ms latency is 80-100 ms

fathom pendant
#

they aren't paid, however, to monitor the discord and assist

#

that may just be due to distance

#

there's not much that can be done about that

spark charm
#

ok thnx

iron zephyr
#

maybe /etc/resolv.conf is bad?

fathom pendant
#

why would you mess with /etc/resolv.conf?

indigo cobalt
#

hello guys

#

i have a question if someone can help me

#

am currently in the secuirty monitoring & siem fundementals module doing the SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe)

#

Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Extend the visualization we created or the "User added or removed from a local group" visualization, if it is available, and enter the common date on which all returned events took place as your answer. Answer format: 20XX-0X-0X

#

this is the question and i followed the steps of the lesson and did everything as should be

fathom pendant
indigo cobalt
#

the result is 3 events all with the timestamp of 2023-02-27

fathom pendant
#

or the other way around

#

can't recall how to adjust it

fathom pendant
#

you can change the range at which the data is displayed

indigo cobalt
fathom pendant
#

that's not what i meant

#

the data visualization can be showing 'week of' instead of 'this day'

indigo cobalt
#

uhm i still dont get it

fathom pendant
#

the date you mentioned falls under the week of the 27th as it's a Monday -> Sunday week

indigo cobalt
#

so?

#

how does that come in to play

fathom pendant
#

so... change the way it's displaying that

#

:)

#

instead of week of, you want the day of

indigo cobalt
#

i feel like a total idiot but isnt 27th a day?!

#

how can it be a week

fathom pendant
#

so anything in that week is classified under that same date

indigo cobalt
#

so do i just filter through the days of that week?

#

like 28th, 29th,...

fathom pendant
#

well there's a way when setting up the visualization to do that instead of manually doing it

#

but i haven't touched it in so long i couldn't tell you

#

also module is above tier 0 so don't reveal answers :) (i already deleted the message that contained the answer)

indigo cobalt
#

i got the answer after manually doing so but i still havent understood how to reach it

fathom pendant
#

just need to adjust the visualization a bit

indigo cobalt
#

could u tell me how i dms?

#

i really want to understand this

fathom pendant
#

like i said it's been a minute since i've done that so i couldn't tell you

#

but i recall there being a way to do it

indigo cobalt
#

well either way thnx for your help man, very appreciated

#

ill go search it up

fossil jacinth
#

Are some of the modules on the CPTS path supposed to be creating instances which can be accessed outside of the vpn ?

vivid whale
#

Hello

#

I am new to ethical hacking

acoustic owl
vivid whale
#

Can anyone help me

#

I know how to use kali and termux

#

And zphisher

acoustic owl
vivid whale
#

Where I can start

#

What to learn

compact patrolBOT
vivid whale
#

What to look into

#

My name changed what?

acoustic owl
vivid whale
#

Ok

#

And?

acoustic owl
#

Read it and you will know why the name was changed

lime cosmos
#

hey , i have problem in Footprinting mysql
i can't connect to the database

#

i test the connection using netcat and it fine

acoustic owl
#

Do you get an error message? You cancel the command in each case

high hearth
# lime cosmos

I had same connectivity issue when I got to that assessement, I don't know what happened but it eventually worked out so I will say keep trying.

lime cosmos
#

Ok

lime cosmos
sleek reef
#

is there a channel for box discussions ?

#

new to the discord

cloud urchin
acoustic owl
mossy sable
#

on linux fundamentals - curl with same options to endpoint returns different count on my machine than in pwnbox

lime cosmos
#

Same problem

languid barn
#

@iron zephyr Add me, i just finished the module, i was also stuck at question 3 (:

fossil jacinth
#

And if you don't pass the password directly in the line, just use -p ?

lime cosmos
#

same problem

acoustic owl
rotund rose
#

Hi, I am doing the Burp Intruder section in the Using Web Proxies module currently and I looked up the answer online to see how long I should wait for Burp Community edition to fuzz the flag, it iterated over the answer and return an error, can someone tell me what the problem is with this setup because I really don't get it.
I can send a screenshot in dms since its disabled here.

ocean night
#

For anyone facing issues with Parrot OS in certain regions regarding certificates, this is the advice I'd give until the core issue is resolved.

This is a known issue with Parrot infrastructure serving up the incorrect certificate. The only solution right now is to force to use the UK mirror IP, or another working region, by adding this to your hosts file.

178.79.175.35 parrotsec.org www.parrotsec.org deb.parrot.sh

The Parrot team have been informed, and will make the required changes as soon as possible, hopefully over the weekend, but possibly not until Monday. Apologies fore the inconvenience.
#

(this impacts certain Pwnbox regions as well, not just personal installs)

fading ridge
#

Hi anybody done the AEN? I have issues with running bloodhound-python ldap error anyone else did have this issue?

odd stirrup
elder bear
#

hi fellas, i'm on the information gathering - web edition module and currently going through the skills assessment and i'm stuck. for the question thats asking for the API key in the hidden admin directory, i go into the hidden directory and there's nothing in there (just a message that says 301 moved permanently). so my question is where do i go from here kek any help/hints appreciated. this is the only question i have left

white sonnet
#

Hi i hear alot of ppl using ligolo-ng for the exam. Is it true that ligolo-ng is sufficient for pivoting? And not the other techniques teached in the tunneling module?

gray yacht
alpine ingot
#

Question about the sqlmap essentials skill assessment.
I know it requires a tamper, but i didnt know which one. So i started going through every one and found it. My question is, how can i do this more efficiently?
Theres no way i did that correctly, i essentially just brute forced the correct sqlmap tamper.

odd stirrup
ocean night
terse sedge
#

Hello, I'm in Shells & Payloads, PHP Web shells section. First of all, isn't the FoxyProxy extension supposed to change your browser settings for you? I have to go into settings and do it manually. Anyway, each time I try to upload the php file, I get an error page: "Peer’s certificate has an invalid signature." While this is happening, I have Burpsuite running, and it doesn't capture anything. When I check the Burpsuite log, it says the same thing: Bad certificate error. Any help is appreciated.

fossil jacinth
#

You need to install the Burp certificate in your browser @terse sedge

terse sedge
#

I have the portswigger cert installed

fathom pendant
#

You have to configure foxyproxy for 127.0.0.1:8080

tulip jasper
#

Hello! I am trying to finish the File Inclusion module and I'm a bit stuck at the Skills Assessment. I am close to getting an RCE but I can't figure out what I'm doing wrong. There is even a video on youtube where someone is solving it and when I try it I don't get the expected results. Would anyone be willing to help me a bit? I just want to understand what I'm doing wrong.
Update: nevermind, solved it! 🙂

verbal grove
#

hello, i having a hard time trying to dump the lsa hashes in the attacking sam module

#

this is the last question of the lab

#

im using this command
netexec smb 10.129.232.77 --local-auth -u Bob -p HTB_@cademy_stdnt! --lsa

#

but i dont get any output, not even errors. im in the vpn and the target host is up

#

i also used different credentials to see if those worked, but i did not gget anything back

stray pilot
#

Yo

fathom pendant
verbal grove
fathom pendant
#

timed out

#

Connection issue in that case

#

I forget the timeout flag for nxc

verbal grove
#

it's --timeout

#

but, by default it is set to None

fathom pendant
#

--timeout 9000

verbal grove
#

nope, now i don't get any output

fathom pendant
#

Because it's waiting to timeout

#

🙃

#

9000 -> 9s

verbal grove
stray pilot
#

How do I hack

verbal grove
compact patrolBOT
fathom pendant
verbal grove
#

I execute the command and it does not wait 9 seconds, it instantly prints no output

fathom pendant
#

Reset target and try again? Try a different vpn region?

verbal grove
#

I just reseated the target, this is a new machine, but i still got no output

#

But I will try to switch regions and reset it again

#

Thanks, tho

fathom pendant
#

if the issue persists

#

contact support

compact patrolBOT
weak basalt
#

May I DM anyone about "Advanced SQL Injections - Error-Based SQL Injection"?
Need a sanity check. Not sure why my answer is wrong.

spiral sapphire
#

Hey! Am I missing something? I'm doing the File Upload Attacks module and just cannot get a reverse shell tho I'm doing exactly as the guide tells me to. I'll just get this warning msg displayed "WARNING: Failed to daemonise. This is quite common and not fatal. Connection timed out (110) "

#

Web Shell I can get, no probs! It's the reverse shell that's the problem

fathom pendant
#

if the target is a public_ip:port -> the goal isn't a revshell

spiral sapphire
#

Oh, so it was just an example?

smoky arrow
fathom pendant
#

the public ips don't have a route to the internal network of 10.10.0.0/16 10.129.0.0/16

novel valve
#

Can i reset the Modules when i have already done it ?

eager ledge
#

I managed to transfer the powershell script. But when I try to import the module, I get execution of scripts is disabled error. Then, I transferred Windows executable. When I try to execute it, I get error saying I first need to install .NET framework 😦

Any nudge on how to proceed forward is highly appreciated. Thank you.

rustic sage
cloud urchin
thin citrus
#

The http://interactsh.local:59651/log does not contain any password reset request, revert many times, one have an idea to solve this?

$ cat /etc/hosts
127.0.0.1 localhost
127.0.1.1 kali

83.136.252.66 interactsh.local

::1 localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

If I do 83.136.252.66:59651 interactsh.local in the /etc/hosts file and access the interactsh.local in browser its been automatic redirect to HTTPS and cannot find the virtual host.

long flint
#

for advanced sql injections skill assessment, am i supposed to have access to live remote debugging? or am i supposed to run it locally?

thin citrus
#

Password Reset Poisoning

acoustic owl
#

Try to reset the lab

thin citrus
#

did many times

gusty ravine
#

hello, i have started the into to networking module and i dont understand one thing. It says that printers should be on their own network but how do you do it?, or will it explain later in the module?

waxen totem
fallow ibex
#

Hi guys

fresh stone
#

When i run netexec with a blank password i get an error. Is there a workaround for this? I also tried with single quotes

netexec smb 10.10.11.236 -u guest -p "" --rid-brute
nxc smb: error: argument -p/--password: expected at least one argument

tranquil axle
full wagon
#

Attacking Enterprise Networks
Hi guys! Have gone through the pentester job role path and am now about to start the enterprise module. To get the most of it, I just want to ask a few things:
When people recommend to do it 'blindly' would that suggest just ignoring the section questions and just start enumerating and attacking 'freely' and based on my own methodology OR would it imply still following the questions but 'ignoring' the text sections? (In that sense, I figure maybe just trying to figure out the way to gain a foothold and then just keep going from there and eventually going back to tick the questions?)
I guess It's like the other sections that when picking up the next day, the target will be reset and you will have to redo any steps to gain foothold, so no persistence techniques would persist?

Any other recommendation related to get the most practice out of the module?
Thank you in advance!

gray yacht
# full wagon Attacking Enterprise Networks Hi guys! Have gone through the pentester job role ...

When I went through it, I just used the information provided by the Scenario & Kickoff section that I needed to begin and just started my process. I documented my process in my notes, so when I came back to it later, I was able to refresh myself with the information I knew and could essentially just pick things up again. If I came across flags along the way, I just documented them in my notes and when I was done, answered the questions where they applied. I used just my notes and if I got stuck, would only rely on what I could research via Google. I recommend if you can't move forward after referencing your notes or Google, to then reference that part in the walkthrough. Add that information to your notes, as that is obviously a gap, then push again blindly. I also wasn't wrapped up in rooting everything if it wasn't absolutely necessary to progress, although I made the effort to root everything. I also wasn't in a rush to just finish it. I probably worked on this for about a week, on and off, as I really wanted to test my enumeration, thought process, identify gaps, etc. When I was done, I then went through the walkthrough and compared it against my notes and my own walkthrough. I added parts I missed or expanded my notes a bit if they were just lacking. Hope that helps.

full wagon
rigid heath
#

Is anyone doing burp suite these days community edition

#

Am having a bad time starting with it

dark hedge
#

you can get acquainted with Burp Suite in the Using Web Proxies module

frank sun
#

Hey guys!

I'm trying to work on this module - https://academy.hackthebox.com/module/23/section/622

but I can't ssh. getting this error Connection closed by 10.129.xx.xxx port 22

  • tried resetting the machine
  • tried to confirm ssh service is running or not. I can see port 22 open with ssh
  • got a vpn file with different region

Any other suggestions?

rigid heath
#

But how

dark hedge
rigid heath
dusky valve
#

just to double check, for intro to malware analysis for setting up inetsim, the ip use should be our own virtual machine ip right?

long flint
#

hi guys for advanced sql injection skill assessment, are we supposed to be able to live debug or check logs of our payloads?

acoustic owl
marsh echo
long flint
#

for advanced sql injections skill assessment 1, i can't seem to get anything to evaluate properly. the only thing that is working for me is || admin'/**/aNd/**/'1'='1'--n which returns true|| and || admin'/**/aNd/**/'1'='2'--n which returns false||

once i combine it with the source code while simutaneously bypassing the filters trying to enumerate the database using other sql functions, i'd assume it'd all work, but seems not

things like this query just dont work and i dont understand why || admin'/**/aNd/**/sUbStRiNg((sElEcT/**/cUrReNt_dAtAbAsE()),1,1)='p'--n||

wheat jacinth
#

Heya

Can I get some help from anyone? Is there a voice channel? Unable to solve the final question on this one.

SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe)

wheat jacinth
#

can I have access to the general chat , please? #

wheat jacinth
#

hey guys,
I'm currently working on the CDSA path, more specifically the Security Monitoring & SIEM Fundamentals bit

I'm stuck on this one.
SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe)

I have been so far unable to answer the final question on this. Can someone push me gently on this by giving some guidance? Spent hours on it.

click on the side navigation toggle, and click on "Dashboard". Extend the visualization we created or the "User added or removed from a local group" visualization, if it is available, and enter the common date on which all returned events took place as your answer. Answer format: 20XX-0X-0X

thaanks

vernal coyote
#

Got it figured out!! Thank you!

marsh echo
wheat jacinth
#

What am I doing wrong here, please? I can't pass the module due to not being able to find the right answer here. 😦

fickle widget
#

Hello, I just started HTB as a total new comer
Shall I start with Linux fundamentals cuz cyber security requires Linux and python yea

Or shall I go for information security fundamentals

Which path shall I choose?

grizzled needle
#

I have the same problem.
I've used both Kira's passwds the one from the begining and the one which was discovered in the id_rsa file, and john isn't cracking thye zip password.

In time,
I've created the mutated list using the custom rule with both dicovered passwds, but I have this as result:

➜ Protectd-Files hashcat --force kira_pass.lst -r custom.rule --stdout |sort -u > mut_kirapass.lst
➜ Protectd-Files head -n 5 mut_kirapass.lst
L0veme
L0veme!
L0veme01
L0veme01!
L0veme02
➜ Protectd-Files john --wordlist=mut_kirapass.lst kira_notes.hash
Using default input encoding: UTF-8
Loaded 1 password hash (PKZIP [32/64])
Will run 8 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
0g 0:00:00:00 DONE (2025-04-13 16:37) 0g/s 19700p/s 19700c/s 19700C/s L0veme..LoveYou199!
Session completed.
➜ Protectd-Files john kira_notes.hash --show
0 password hashes cracked, 1 left

I'm stuck...can yopu help me?

dark hedge
vale crescent
#

Guys i need help

I am currently doing HTB shell and payloads in academy

I have complete the module and im in my last live engagement

Here i have to connect into parrot OS VM using "FREERDP"

I have connected to the VM but there is no any network connection

I cant even ping

Do you guys know hoe to fix this issue ?

barren kayak
#

Sorry to be a bother ya'll. I'm currently chasing for my CDSA cert and I'm going through the Linux fundamentals, but I'm totally stuck here.

#

Which kernel release is installed on the system? (Format: 1.22.3)

#

The final answer I got it 6.11.5 but it dings it as incorrect no matter what. I'm not sure what I'm doing wrong I pulled the kernel version and everything.

shut wraith
#

Hey @fathom pendant I'll trade u CPTS tutoring for Cloud pentesting tutoring (any CSP)

shut wraith
fathom pendant
#

I'm just not in a position for that

shut wraith
fathom pendant
shut wraith
gray leaf
#

I'm having trouble with the linux privesc skills assessment. I'm getting kicked out of my ssh session within 30 seconds every time. Is this an intended part of the challenge, is something wrong, or am I doing something wrong? 😄

fathom pendant
gray leaf
#

Error:

htb-student@nix03:~$ Read from remote host 10.129.91.247: Connection reset by peer
Connection to 10.129.91.247 closed.
client_loop: send disconnect: Broken pipe

#

I've reset the target and reconnected my VPN but nothing has changed.

fathom pendant
#

Or tcp vpn

gray leaf
#

Ah, tcp vpn fixed it. Thanks!!

barren kayak
fathom pendant
#

Start instance != spawn target

#

Start instance starts the in-browser attack box (pwnbox)

#

Thats not the same as the target

barren kayak
fathom pendant
#

Again: the pwnbox isn't the target, just above the questions should be a "spawn target" text to click

#

The module should tell you ssh syntax to connect, and gives you creds

barren kayak
#

OOOOH!

#

I’m a moron.

#

I got it.

rustic sage
#

Guys is joining hiddenwiki from chrome normal

#

I just joined it to check out didn't click on any links inside it

wheat jacinth
fathom pendant
rustic sage
fathom pendant
fathom pendant
wheat jacinth
#

Not made any progress

#

so how do I get dates?

cloud urchin
minor rampart
#

Hello, everyone.
I'm new to cybersecurity, and I want to become a cybersecurity professional. Can anyone give me some advice?
#general #modules
Do we have any experts here?

wheat jacinth
#

could someone chat with me on discord, I'm going nuts, spent the afternoon with this, gentle push woundlnt hurt I dont see the woods from the trees

compact patrolBOT
wheat jacinth
#

please help

#

I got it but dont understand how 😄

#

can I chat to someone from the stuff about this question?

tender nimbus
#

Hey guys little question about a seciton in the hacking wordpress module. I launched wpscan and it gives me 0 plugins, but the LFI that I need to exploid is via the masta (said in the exercice) plugin, is it because of the passive enumeration?

safe mango
tender nimbus
#

not really no the only tool that is shown in the section is wpscan if i'm not wrong

#

@safe mango

#

oh no my bad there is enum with curl to

#

I will try it now

safe mango
tender nimbus
#

got it ^^

lime cosmos
#

how can we confirm that we have the priv to connect as sysdba ?

#

module footprinting Oracle TNS

tender nimbus
safe mango
tender nimbus
#

don't look the first question it was mine ^^

lime cosmos
#

ok

#

so we can't confirm we just try to connect

tulip jasper
#

Hello! While doing the module "Using Web Proxies", in the chapter called "Burp Intruder", I was trying to do the exercise for that chapter and I managed to get the flag using Burp Suite but when I tried the same thing with ffuf, it doesn't detect the page with the flag. Does anyone know why? I am using the same wordlist for both Burp and ffuf.

serene drum
#

Hello everyone. It seems I am a little stuck on the bypassing security filters section of Web attacks. each method I have tried provide me with the flag from the previous section, which obviously does not work.
Im not sure what I am doing wrong. Some help would be appreciated

safe mango
tulip jasper
# safe mango Do you mind showing the ffuf command?

I actually managed to find it. I think the reason I didn't find it in the first place was because I didn't add any header params in the ffuf command.
First I ran a basic: ffuf -w common.txt -u http://83.136.249.199:32060/admin/FUZZ -e html
This didn't find it.

After doing some research I ran: ffuf -w common.txt -u http://83.136.249.199:32060/admin/FUZZ.html
-H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
-H "Accept: text/html,application/xhtml+xml"
-H "Accept-Encoding: gzip"
-H "Accept-Language: en-US,en;q=0.9"

It was able to find it with this. I didn't know these can make a difference.
When I did the module "Attacking Web Applications with ffuf" I didn't always use these header params.

fathom pendant
tulip jasper
fathom pendant
#

extension

#

It requires the .ext

tulip jasper
#

yes, I added it without the . initially 🙂

safe mango
serene drum
ancient eagle
#

Hi

safe mango
rustic sage
#

Yo wsp yall

fathom pendant
rustic sage
#

I can't type there

safe mango
serene drum
#

I should DM?

safe mango
#

yes, I have solved this lab so don't worry about spoilers

safe mango
#

Are we going to get any more modules about mobile hacking? A whole path maybe?

pallid granite
#

Can I skip intro to ad and go for ad enum & attacks?

fathom pendant
fathom pendant
cloud urchin
fathom pendant
#

It helps some underlying concepts

cloud urchin
#

Yeah if you don't know what AD is it may help to take the intro module.

fathom pendant
pallid granite
#

i guess I'll start intro soon, thank you. I'm just new to studying like this

#

I've been reading up tons on ad stuff while doing boxes but it would help with foundation yeah

fathom pendant
#

It helps to take notes

pallid granite
#

I've been trying. not that good at dissecting important details though. need to practice

fossil jacinth
#

And actually test what you read

proud notch
#

Looking through some of the previous messages here, I'm working on Stuxbot: Introduction to Threat Hunting for the following question "Some PowerShell code has been loaded into memory that scans/targets network shares. Leverage the available PowerShell logs to identify from which popular hacking tool this code derives. Answer format (one word): P____V___" I believe that I'm searching for the correct event.id but when I apply filters for the date and powershell.file.script_text it's showing 421 logs to sort through. Does anyone know if I'm searching too broadly or if we are supposed to look through 400 logs manually?

fathom pendant
#

There's some text within some of the logs that'll point you to the tool

proud notch
fathom pendant
proud notch
fathom pendant
#

I haven't done the module myself, but you can look through some to see the commands used

#

The commands are part of a tool suite

woeful spoke
#

Where i can learn the reverse engeenering

woeful spoke
#

thx

mystic fjord
#

Module: Active Directory Enumeration & Attacks
Skill Assessment II
[+] Use a common method to obtain weak credentials for another user. Submit the username for the user whose credentials you obtain.

Any help with this one?

#

Back then somebody told me to try password spraying, but the only password i fond at this point is wea*** but dosent work with other users

wooden seal
#

File Upload Attacks
Upload Exploitation
Made a php reverse shell witf msfvenom but not getting reverse shell ;v (tried netcat(nc) & msfconsole too)

wooden seal
#

not sure but try it

mystic fjord
#

nah i already try it with Rubeus and mimikatz, dont work pal 😦

wooden seal
#

i dont remember then :v

mystic fjord
#

hehe dont worry

safe star
#

the examples they used?

mystic fjord
mystic fjord
safe star
ember crest
#

@fathom pendant you online? Just need to DM you about something.

iron zephyr
hearty pelican
#

guys what do you guys rank at globally?

#

just need to get a reality check drop in your global ranks

#

i am at 928

elfin dew
#

BUMP. I still need a little help with "Detecting Attacker Behavior With Splunk Based On Analytics" if anyone can offer it? I do have the correct answer but not through the correct method. I really want to work out why my query does not show the answer as an outlier asit suggests I should be able to.

acoustic owl
wooden seal
#

File Upload Attacks
Upload Exploitation
Made a php reverse shell witf msfvenom but not getting reverse shell ;v (tried netcat(nc) & msfconsole too)

cosmic plaza
#

I am doing Information Gathering - Web Edition - Skills Assessment.

I am stuck at this question: What is the API key in the hidden admin directory that you have discovered on the target system?

I have put in the IP Hostname in /etc/hosts:

└──╼ $cat /etc/hosts
# Others#
83.136.252.66 inlanefreight.htb

I use the following to enumerate the vhosts.

I use gobuster vhost with the following: There is no result.

gobuster vhost --append-domain --domain inlanefreight.htb -u http://83.136.255.10:37047 -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt

Then, I tried with ffuf. I get results like Status: 200 for everything, which is obviously wrong.

ffuf -u http://83.136.252.66:30528 -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt -H "HOST:FUZZ.inlanefreight.htb"

...
alpha                   [Status: 200, Size: 120, Words: 4, Lines: 2, Duration: 303ms]
ww2                     [Status: 200, Size: 120, Words: 4, Lines: 2, Duration: 303ms]
marketing               [Status: 200, Size: 120, Words: 4, Lines: 2, Duration: 302ms]
job                     [Status: 200, Size: 120, Words: 4, Lines: 2, Duration: 303ms]
...

Could anyone give a hint on where I went wrong with my vhost enumeration?

wooden seal
cosmic plaza
#

Can anyone explain why ffuf gives all status code 200, even though the vhost or subdomains do not exist.

Is there anything wrong with my ffuf command?

ffuf -u http://83.136.252.66:30528 -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-20000.txt -H "HOST:FUZZ.inlanefreight.htb"

...
alpha                   [Status: 200, Size: 120, Words: 4, Lines: 2, Duration: 303ms]
ww2                     [Status: 200, Size: 120, Words: 4, Lines: 2, Duration: 303ms]
marketing               [Status: 200, Size: 120, Words: 4, Lines: 2, Duration: 302ms]
job                     [Status: 200, Size: 120, Words: 4, Lines: 2, Duration: 303ms]
...
wooden seal
#

try using -fs (response size) to filter the 120 response size@cosmic plaza

calm swan
#

in module Shells & Payloads - Bind Shells is says:
"we can test bind shell with other academy student".
I have 2 accounts so I opened up 2 workstations (yes, the same VPN server) but those 2 instances doesn't "see" each other.
any ideas why is that?
both are 10.10.14.x

fathom pendant
calm swan
#

so how to make it work?

tender nimbus
#

Hey guys I'm doing the skills assesements from the hacking wordpress module, can someone tell me why when I'm trying to scan it it says that it don't use wordpress?

autumn pilot
#

manually enumerate the website before using any tools

shut ice
#

Has anyone done the Introduction to Windows Evasion Techniques > Open-source Software?

It goes through 3 AMSI bypasses and asks you to use 1 to solve the challenge, however the bypasses themselves now look to be getting detected by Defender?

Is patching amsiScanBuffer not really relevant anymore?

round stream
#

Can anyone tell me why this particular section is named "Web Services" in the "Login Brute Forcing" module ?

#

Cause we did not exploit any kind of "Web" Service. We just exploited normal services like SSH and FTP.

#

nothing of web. I think it should be renamed as just "Services".

spare condor
#

Hello! I'm on "Advanced XSS and CSRF Exploitation" "Exploiting internal Web Applications II".

I solved the question on the assessment. But I want to ask something regarding the lines returned with the command injection. I am able to see only one line of the output of the command. Why this is happening? Is there a way to see all the output of the command?

grizzled schooner
#

PW Attacks
Attacking Active Directory & NTDS.dit

Got credentials for an account using CME, verified that these creds worked by additionally using nxc - Try to log in and get denied... Any nudges / help?

tender nimbus
autumn pilot
#

enumeration doesn't involve only using tools

round stream
woeful spoke
shut ice
tender nimbus
prisma wing
#

Hello all, I'm stuck on Linux Privilege Escalation Kernel Exploits. The hint suggests to use CVE-2021-3493, however when i run it on the target machine, i get the following error 'htb-student@NIX02:/tmp$ ./exploit
./exploit: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./exploit)' Do we defintely have to use CVE-2021-3493? or can we use another exploit?

grizzled schooner
autumn pilot
tender nimbus
dull brook
#

I can not get this question right, in android emulators. I opened and created the avd and got this build number UE1A.230829.036.A4 but it wont take it. Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test)

dull brook
#

how you solve this

autumn pilot
#

Aim at using the mentioned version of Android Studio, for some reason in a newer version the build number will differ for the same device

prisma wing
dull brook
fast jungle
dull brook
fast jungle
#

Its a string with a - in the middle

dull brook
gray yacht
dull brook
#

not sure where it it is i keep looking on the emulated devcie

fast jungle
prisma wing
dull brook
#

thought this was for help the forums dont work anymore

dense trail
#

hello

#

i need help on hackthebox DOG machine i dont know if i can write the question cuz its still active machine and please reply if i can do it

dense trail
#

it says that i dont have access to that chat

wooden seal
dense trail
#

yea thaanks

wooden seal
#

np

glacial sundial
#

HI im just wondering for Windows Privesc module, does anyone have an explanation to why even if the privileges are Disabled, i can still use them? Like the SeImpersonate and SeBackup

high ibex
#

Hi all
I have spent over an hour on an early enough module that I feel dumb now
I cannot figure out what exactly I am being asked to do
its in /module/77/section/843
Public Exploits
Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

opal jewel
high ibex
#

thank you.. I have scanned the ports..
Am I meant to rely just on the modules supplied information or am I meant to start googling all the possible exploits?

high ibex
#

ok.. thank you

mighty swan
#

please help me in ->
Network Enumeration with Nmap -> Firewall and IDS/IPS Evasion - Hard Lab
Which linux commands do I require ?!

fresh wedge
#

what is the correct channel to inquire about machines in the labs?

cloud urchin
uneven obsidian
#

Hey ! I am on Password Attacks, in Crendetial Hunting in Linux.
I solved the question with a bit of assistance from the module, on this section but I wanted to ask how I'd supposed to understand that i need to use python3.9 to run the script on the victim host ?
I ran before looking at the solution python --version and these were the outputs

kira@nix01:/tmp$ python3.9 --version
Python 3.9.5
kira@nix01:/tmp$ python3.8 --version
Python 3.8.10

#

python3.9 did work eventually, but I am trying to figure out how I'd supposed to understand it, if someone did this specific section without any help i'd love to know how : )

bronze wharf
#

hello guys , can anyone help me in this question , Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

dull brook
#

im still struggling with the answer for adv in android build figured it out needed use google api version

signal hound
#

Hi im doing sqlmap essentials skills assessment
Im stuck at finding a parameter to inject

uneven obsidian
glacial sundial
glacial sundial
tropic hearth
#

Uh.... sanity test that pentest in a nutshell doesn't have a container tool on the linux privesc?

cloud urchin
#

No. That's illegal. We don't do illegal stuff here.

tropic hearth
#

I grepped my way through the linpeas and nothing comes up. If I use docker cmd, it asks me to install. I'm sort of clueless as to where from here

tiny osprey
cloud urchin
fossil fossil
#

Hello, I'm working on the Practical Digital Forensics Scenario submodule within the Introduction to Digital Forensics course. I'm currently on the first question, which I solved by intuition. However, after analyzing the memory dump, I haven't been able to find any traces of the tool used, ||except for an encoded powershell payload which points to letsgohunt.site.|| Could anyone offer some guidance or point me in the right direction?

#

it should be john -w=path_to_rock hash.txt --format=something
But I'm not sure if ipmi format is supported

lime cosmos
#

No it not supposed

#

Hash(sha1):salte
So I think I split the first part hash(sha1) and crack it with --format=sha1

cobalt garnet
#

Hello, I'm working on the "Miscellaneous File Transfer Methods" of the "File transfers" module, I managed to mount a linux directory on the Windows machine with freerdp, I transferred nc64.exe and nc.exe from github to the pwnbox, and from the pwnbox to the windows machine, but when I try to run it to test the commands given in the course I get an error message saying "the program or feature cannot start or run due to incompatibility with 64-bit versions" for both the exe files. Am I doing something wrong ?

slim otter
#

Hi all, going through the pivoting, tunneling and port forwarding module. Just wondering if there is a simple way to remember when one would need to locally port forward, dynamically and reverse port forward?

quartz lagoon
#

locally is when you wanna have access to one specific service

#

dynamic is when you want to pretend you're part of the subnet (i.e. interact with it) (via your pivot)

#

and reverse is when you want your target inside the subnet to have access to you (through the pivot (iirc))

slim otter
#

Okay that helps, so local when I want access to an internal service that I can't access from my attack host. Dynamic when I want to interact with the deeper internal network potentially scanning the network. Reverse when I want the deeper internal host to have a route back to me for a potential reverse shell

quartz lagoon
#

exactly

#

i mean im no pro i just did the module a few weeks ago but i think thats it

slim otter
#

I think the confusion for the reverse port forward stems from the chapter already having RDP access to the target internal host, so I had a mental block thinking why would I need a reverse shell when I can get RDP access lol

#

but I assume I would discover an attack vector to upload a reverse shell or RCE on that internal host which I then would need a reverse port forward for

quartz lagoon
#

yeah same this kinda bugged my mind when i tried to create a meterpreter reverse shell thingy

slim otter
#

Cool, nice to know I'm not alone with that 😆

wanton estuary
#

I got stuck here too because the lab discusses the bypass within the console but we are sending the payload as JSON. Try {"constructor":{"prototype":{"deviceIP":"127.0.0.1; whoami"}}}

mossy marten
#

Hello, Skills Assessment - Using Web Proxies
3. Question: appended alphanum-case.txt the last letter encoded with base64 and ASCII HEX dont find anything. Also for this module in generall BURP intruder is a premium future can not be used anymore as free user.
where did i go wrong any hints?

fathom pendant
#

Use zap

open forum
mossy marten
#

I am/was did not work

fathom pendant
#

Intruder isn't premium btw

#

It's just really slow

mossy marten
#

if i try to use it it gives me pop up telling me its premium and if i click ok it closes intruder result

fathom pendant
#

Also you have to encode the whole cookie so cookie=§sometext§ > then prefix, and run the encoding in the reverse order you decoded in

#

So if you decoded a -> b -> c you encode c -> b -> a

alpine ingot
#

Im on the active directory skill assessment part 2 and i dumped credentials but i dont think the NTLM is correct for administrator.

cloud urchin
#

maybe you dumped the local admin?

alpine ingot
#

Yeah i did, am i was thinking of password reuse, am i not supposed to do that?

#

I think mine is broken..

worn matrix
#

any module for cloud is planned... ?

fathom pendant
shut ice
#

Can anyone help with the Windows Evasion SA 2? I have made two VBS scripts that get a shell when I run them manually on the target, but dropping them into the folder the target user get's a timeout? Seems like it's broken since it passes the AV checks and just timesout?

fathom pendant
shut ice
#

Isn't there already cloud labs that used to be Enterprise?

fathom pendant
#

Yes but the enterprise cost covered the overhead

shut ice
#

Isn't it just on Academy now?

fathom pendant
#

No?

#

I'm not in on the budgeting for htb but since each lab is meant to be able to be launched as individual instances, you have to factor that into overhead

#

And the cleanup/monitoring

#

And licensing

shut ice
#

Ah yeah can imagine it's expensive. I just thought it had moved to academy or pro labs but must have been dreaming

fathom pendant
#

No

gray yacht
fathom pendant
#

There's still the blacksky labs on EP, no big content like that is on academy

#

They shifted some prolab stuff around and there's some free prolabs now

fleet spear
#

footprinting lab medium the rdp dies very quickly and then you need to restart server

fathom pendant
#

Use tcp vpn

fleet spear
#

thanks 🙂

astral jackal
olive depot
#

So i wanna learn how to pentest webb apps etc, where should i start? I got some sections in portswigger Done 🙂

fathom pendant
#

There's a bunch of web modules, the cbbh path covers a bit of them

fleet spear
#

is there not a path that is called web pentesting?

fathom pendant
#

@small basin don't reveal any bit of answers for modules above t0, the module is expecting you to know your way around some credential harvesting/password attack techniques

small basin
fathom pendant
#

As i said it expects you to know some techniques not covered

olive depot
#

Hmm found some models about web! 🙂

fathom pendant
#

It's a tier 2 module covering something, it's not gonna teach you something related to password attack/cred harvesting

#

If you're doing the cpts path, I believe that the password attacks module is before pivoting

small basin
fathom pendant
#

Well if you look at the mimikatz mode used: you'll see the similarity to a technique used for dumping 😉

#

Also i wouldn't go to the walkthrough as a "this is the only way to do this"

#

Sometimes it's a matter of "this is one way to do this"

#

The author relies a lot on utilizing the msf shelling and pivoting methods in a lot of their stuff, for instance

#

But that's not the only way to achieve pivoting, as showcased by the module

#

I and many others will swear by "ligolo-ng," granted you understand the underlying structure behind pivoting

#

I also urge against using the walkthrough, as it's not sufficient in teaching you why

#

Asking for help here isn't taboo, just avoid spoilers

small basin
#

Yes, I found that one, that dumps it in the same way, but then uses another way to extract the pw.
I just expected it to be covered in that way as well in the course

I know that there are often multiple ways to archive something, I just usually check afterward how the walkthrough solved it to maybe learn another way. And it looks like this time it's something partially new.

I saw ligolo-ng mentioned a lot here on Discord. Will check that out sometime.

#

Thanks!

fathom pendant
#

This is a case of "you should already know this"

#

For the most part, the modules stick to their own topics

#

Higher tier modules expect more underlying knowledge

grim plaza
#

any one here solved whitebox attack module ?

#

i have a problem with a challenge so if any one here solved it

cloud urchin
#

plenty did, best to just ask your question. make sure not to spoil content from the module as it's above tier 0!

grim plaza
#

i know so i need someone who solved it to text him privetly!!

rough ginkgo
#

can someone help me with "Using Splunk Application" question 2?

cloud urchin
#

Please re-ask your question without spoilers from the assessment, may need to take it to private.

cloud urchin
#

No sorry I'm busy

heavy hearth
#

Intro to Whitebox Pentesting

Challenge: There are at least 2 different ways to obtain remote code execution on the target. So, once you are able to exploit one vulnerability, try to identify the other and exploit it as well.

The first RCE is obvious, not ez, but I got the flag. For the 2nd - can anyone tell me if the first RCE is required to "massage" some existing code prior to having an exploitable scenario?

ocean night
#

@summer crag Please do not share specifics of the path to solve modules above Tier 0. You may ask for guidance, but as far as requesting for guidance in private.

summer crag
#

@ocean night sorry about that. where should I go for private guidance?

ocean night
#

Ask for assistance here, state the module and section, and someone may reach out to help with a nudge

summer crag
#

got it, thanks!

dark bluff
#

Yo

azure saffron
#

Hey all Got stuck with burp intruder need help with it to complete exercise.

wooden seal
jaunty mica
#

Hey all, has anyone here completed the Intro to C2 with Sliver module that could provide some insight on the last step of the skills assessment? I have compromised the first DC, but am having issues pivoting to the parent domain

nocturne gulch
#

Hey everyone I got stuck on module using Crackmapexec Skills Assessment. I want to gain access to DEV01 but can't seem to find a way around.
Can anyone give me a nudge?

viral sierra
#

Has anyone gotten the flag for the Prompt Injection Attacks Skills Assessment? (not asking for the answer, genuinely curious if someone has gotten it since it gave me 2 flags that did not work)

frosty plank
#

I’m looking for someone who can help me with getting to hacking any tips or tricks will be welcomed🙏🏼

glass locust
glass locust
compact patrolBOT
fathom pendant
#

@frosty plank ^

glass locust
#

What helped me in that question is to run all Persistence Collections (main one)

misty current
#

Buffer Overflow in Windows (https://academy.hackthebox.com/module/89/section/946)
Do you guys actually use ERC --pattern c 5000 over msf-pattern_create? Because ERC gives the output in double quotes and I was wondering if there was any options built within to just get the patterned payload

long flint
#

could anyone help me check my script for RCE on adv sql injections skill assessment question 2?

faint terrace
#

Just I wanna write something?
Discode.

#

Wi-Fi penetration testing basic module, I will unlock it. Did you do it?

wild wolf
#

One message removed from a suspended account.

glass locust
proper umbra
#

Guys i wanna ask about dante prolab, idk if this spoiler or not, but is there buffer overflow on dante? I wanna try it but i have not learn about BO yet

glass locust
proper umbra
waxen totem
glass locust
wild wolf
#

One message removed from a suspended account.

glass locust
wild wolf
#

One message removed from a suspended account.

wild wolf
#

One message removed from a suspended account.

#

One message removed from a suspended account.

#

One message removed from a suspended account.

#

One message removed from a suspended account.

#

One message removed from a suspended account.

glass locust
#

Check Resources.

wild wolf
#

One message removed from a suspended account.

#

One message removed from a suspended account.

glass locust
#

Yeah I remember there is a wordlist somewhere in that section that you can use for all related attacks

#

wait, you need to get all users from AD

wild wolf
#

One message removed from a suspended account.

#

One message removed from a suspended account.

glass locust
wild wolf
#

One message removed from a suspended account.

#

One message removed from a suspended account.

#

One message removed from a suspended account.

#

One message removed from a suspended account.

#

One message removed from a suspended account.

glass locust
# wild wolf One message removed from a suspended account.

Being a while since I did that module so can't remember for now. I can however tell you that section "Enumerating & Retrieving Password Policies" contains what you need. Maybe someone else who recently completed this module will provide more details.

daring cliff
wild wolf
#

One message removed from a suspended account.

wispy hill
#

Hi guys, have a problem with last question. HTB Does not accept answers 2.4
The question is
„which frequency band is known for better wall penetration, but more prone to interference?”

acoustic owl
glass locust
#

We def need a Tier 0 module on "How to ask questions properly" xD

surreal arch
#

does anyone know why ? 5 years of ban

#

htb banned me

#

on htb academy

compact patrolBOT
novel matrix
surreal arch
#

ok how long they take to respond ?

novel matrix
surreal arch
#

ok

median relic
#

Hello, I'm not sure if im right here, but i try.

In the CPTS Path, Linux Priv Esc. -> Logrotate

The path is to escalate the privs with logrotten to root and then gain the flag.

Sadly logrotten needs DLIBC_2.34, on the target mashine is only 2.31 installed. And its not possible to run logrotten there. I tried an older branch but it's the same requirement to run logrotten. As htb-student access to the traget you also cant update libc6.

Is this a unwanted problem or I'm on the wrong path?

glass locust
median relic
#

yes, i did

#

but you cant run it with the old version.

fathom pendant
#

you need to compile it statically, you can also compile it on the target

median relic
#

Thanks for the input. I'll try,

wooden coyote
#

last time i asked this the answer was no, but I am wondering: is there a way to reset progress on a module? e.g. if i have one I want to re-do from two years ago for practice? Last time I used TamperMonkey to hide the answers but I was hoping there was like a reset option hidden somewhere.

tiny linden
#

Can someone tell me how ranking up to hacker works? I'm currently on script kiddie and solved active challenges. I see that I earned exp in activity but progress toward hacker stayed at 0%

#

Sorry if it's a bit off topic. I posted in general but can't anymore

shadow grove
#

You need to solve current boxes, not retired machines and not academy modules.

tiny linden
#

I solved active challenges. Is solving active machine the only way to progress once you get past noob?

shadow grove
#

I didn't know if those challenges give you points or not, but I guess you just confirmed they don't.

tiny linden
#

They do give exp, and I see that they do under my activity

#

When I ranked up from noob to script kiddie, I worked on active boxes and challenges.

#

But active challenges no longer seem to progress my rank

dark hedge
#

not related to Academy modules, so this should probably move to #general

tiny linden
#

I can't post in general anymore after my first message

dark hedge
tiny linden
#

Got it

pale reef
#

I've been stuck on Introduction to NoSQL Injection Skills Assessment II. I have the username. I have not been able to inject regex into the password since the post data is not in json, and changing the password parameter like the bypassing parameter section recommends throws an error of password parameter not set.

novel valve
#

Do i will get a complete Methodology in the Pentester Job Path ?

waxen totem
iron pike
#

I can't post in general…

waxen totem
iron pike
#

Tanks

minor sonnet
#

hello everyone

#

does anyone finish Signature Wrapping Attack??

obtuse verge
#

Hello all. Im doing the KERBEROS ATTACKS - Unconstrained Delegation - Users Module. Using the dnstool tool script, it is giving me this error... Can someone help me?

stray plover
#

Hey guys I was on shells and payloads live assessment connected via rdp but I can not find a browser to check out the website, there is only tor browser which does not open

nocturne gulch
glass locust
obtuse verge
#

i think the command its just fine

glass locust
obtuse verge
#

probably someconnection problem

glass locust
#

I can't remember the exact IPs, just a suggestion

#

Seems fine

#

In my notes:
10.129.205.* dc01.inlanefreight.local inlanefreight.local

obtuse verge
pliant mason
#

Hi all
I have spent over an hour on an early enough module that I feel dumb now
I cannot figure out what exactly I am being asked to do
its in /module/77/section/843
Public Exploits
Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)

obtuse verge
#

I will reset, to see if it resolves the problem

glass locust
pliant mason
#

yeah i did its just like im stupid i cant find anything

#

i did for an hr i only found 2 open port and googled them and theres nothing that i understand

pliant mason
#

huh is that the exploit?

glass locust
#

Open the IP:Port in your browser and see what's written there

pliant mason
#

i alrdy did that like i said i was trying for an hr

glass locust
pliant mason
#

alr

obtuse verge
glass locust
obtuse verge
#

let me run

#

pings are working

#

so It should be good

#

nmap as well

#

nmap also good

glass locust
keen flume
#

hey.. about the docker target
i keep trying to reset and put it on the browser but it always refuses to connect
anyone know why?

glass locust
obtuse verge
#

i though the -action add could be something random...

#

thank you for the help

keen flume
#

getting started, basic tools, optional exercise
but uhm i already got the answer but not from putting it on the browser which i thought it would like that

or maybe im dumb..

#

wait what 😭 so like the answer for it is SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.1 but I got SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u3 from terminal

#

i cant even open the docker target on the browser

#

94.237.55.234:34780
can anyone open this

glass locust
#

............................. 😵‍💫

rustic sage
#

I want to learn cyber security

west arrow
#

why are my nmap results totally different with the same command on my own vm vs the modules vm

#

never mind, i was using different vpn fileskek

novel valve
#

i was working on nmap medium lab for 2 hours... then i check that im doing it correctly but the vpn has manipulate my result and it just works with the pwnbox from htb 😄 this was frustrating ..

uneven crater
#

hello i have an error trying to start apache2 in the module linux fundamentals. it says failed because control process exited with error code. anyone know what to do in this case?

shut vapor
uneven crater
#

error 212 if i remember correctly

#

i did some troubleshooting earlier but couldnt figure it out

shut vapor
#

It's not ringing a bell, usually you get clearer output than that but seeing the full output might help. I'll see if I can fire up that lab and recreate. I haven't gone through that module.

uneven crater
#

great thank you!

shut vapor
# uneven crater great thank you!

What section are you in, "Working with webservers"? If so it isn't a lab, just on the pwnbox. The questions seems to suggest using something other than Apache.

thin citrus
#

I'm working on the HTTP Attacks module and trying to get RCE via log poisoning, but my payload isn't executing in the /log.php can someone help me with this.

uneven crater
#

im just trying to follow and recreate what the module is doing

nocturne gulch
#

Can anyone give me nudge for last flag on using crackmapexec module? I have svc_inlaneadm ccaches and i authenticated but i still don't have admin access

uneven crater
#

think i might have found the problem, thanks!

shut vapor
uneven crater
#

yeah seemed to be a port issue

shut vapor
#

my first thought was to kill the process running on port 80... but then my pwnbox fell over 🙃

uneven crater
#

yea i tried that to but didn't work haha

#

thank you for the help though linux can be tough ive figured out haha

shut vapor
#

Good deal. Hit #welcome and link your account sometime to get permission for sharing share screen shots

blazing loom
#

Is it just me or does taking notes significantly increase the time it takes to do these modules. I suppose it is good practice and helps learning. 🙂

signal hound
#

Hi im doing XSS module, session hijacking
Im trying to go through what i learned in the module
Im attempting to load the fields with a JS source file on my machine and i run php listener but i dont receive a connection to verify that the field is vulnerable

novel valve
lime cosmos
#
nobody@kali:/tmp$ ls -ln .


drwx------ 2 65534 65534 65536 Nov 11  2021 mount

nobody@kali:/tmp$ id
uid=65534(nobody) gid=65534(nogroup) groups=65534(nogroup)
nobody@kali:/tmp$ cd mount
bash: cd: mount: Permission denied
nobody@kali:/tmp$ 
#

i try with the root and it work i could access to the folder . but i want know why i can't access to the folder even i have the same uid uid of the file perm

dull brook
#

So i can not seem to get any answers out of this question on Introduction to Bash. I have attached screenshot of terminal output. Create a "For" loop that encodes the variable "var" 28 times in "base64". The number of characters in the 28th hash is the value that must be assigned to the "salt" variable.``` #!/bin/bash

Decrypt function

function decrypt {
# Apply all substitution rules
transformed=$(echo "$hash" | sed 's/988sn1/83unasa/g' |
sed 's/4d298d/9999/g' |
sed 's/3i8dqos82/873h4d/g' |
sed 's/4n9Ls/20X/g' |
sed 's/912oijs01/i7gg/g' |
sed 's/k32jx0aa/n391s/g' |
sed 's/nI72n/YzF1/g' |
sed 's/82ns71n/2d49/g' |
sed 's/JGcms1a/zIm12/g' |
sed 's/MS9/4SIs/g' |
sed 's/Ymxj00Ims/Uso18/g' |
sed 's/sSi8Lm/Mit/g' |
sed 's/9su2n/43n92ka/g' |
sed 's/ggf3iunds/dn3i8/g' |
sed 's/uBz/TT0K/g')

echo "[DEBUG] Transformed base64 hash: $transformed"
echo "[DEBUG] Decrypting with salt: $salt"

# Use OpenSSL with correct PBKDF2 and md
flag=$(echo "$transformed" | gbase64 -d 2>/dev/null | \
    /opt/homebrew/opt/openssl@3/bin/openssl enc -aes-128-cbc -pbkdf2 -md -md5 -d -salt -pass pass:"$salt" 2>/dev/null)

if [[ -z "$flag" ]]; then
    echo "[x] Decryption failed — trying fallback without pbkdf2"
    flag=$(echo "$transformed" | gbase64 -d 2>/dev/null | \
        /opt/homebrew/opt/openssl@3/bin/openssl enc -aes-128-cbc -md sha256 -d -salt -pass pass:"$salt" 2>/dev/null)
fi

}

Initial values

var="9M"
hash="VTJGc2RHVmtYMTl2ZnYyNTdUeERVRnBtQWVGNmFWWVUySG1wTXNmRi9rQT0K"

Encode 28 times with base64

for i in {1..28}; do
var=$(echo -n "$var" | gbase64)
done

Calculate salt as length of final base64 string

salt=$(echo -n "$var" | wc -c)
echo "[*] Salt determined from 28 encodes: $salt"

Run decrypt if salt is not empty

if [[ -n "$salt" ]]; then
decrypt
if [[ -n "$flag" ]]; then
echo "[✔] Flag: $flag"
else
echo "[✘] Still no flag. Check salt, OpenSSL version, or cipher mode."
fi
else
echo "[!] Salt not set."
exit 1
fi

[*] Salt determined from 28 encodes:    25223
[DEBUG] Transformed base64 hash: VTJGc2RHVmtYMTl2ZnYyNTdUeERVRnBtQWVGNmFWWVUySG1wTXNmRi9rQT0K
[DEBUG] Decrypting with salt:    25223
[x] Decryption failed — trying fallback without pbkdf2
[✘] Still no flag. Check salt, OpenSSL version, or cipher mode. instead of a flag
calm swan
#

can someone help me with the module Shells & Payloads - PHP Web Shells?
I have a problem with a Burp, it's not intercepting any events (proxy settings are all set); I tried using both local browser and burp browser but nth works. I noticed that there is an error [9] The client failed to negotiate a TLS connection to 10.129.201.101:443: Received fatal alert: bad_certificate. I remember the module said that sometimes we need to accept PortSwigger Certificate but I don't know where to do it.

#

I once more checked browser and burp proxy settings, checked certificate and all seem in place. idk what is wrong

idle bison
#

Hey everyone, i have a question for the people that finished in Network Enumeration with nmap the module Service enumeration, I have found the flag but I don't know how I have to put it in, maybe somebody can help me, I tried so much but I really dont know.
This is the task: Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.
I tried it with HTB{........} AND also only the flag text inside the clamp.

maiden sigil
pure gazelle
idle bison
#

I get the flag it was HTB{........}, of course it was not points inside, ist was a hash

pure gazelle
#

maybe you got the wrong one?

blazing loom
#

Working through the fundamental modules and they are a real slog. Does it get less sloggy after the fundamentals when flags start actually being used?

deep pier
#

whats the difference between HTB academy and HTB

blazing loom
#

Academy = learn to hack, currated content that teaches
HTB = vulnerable machines to hack. No teaching, just hacking.

deep pier
#

so as a beginner to cybersecurity Academy is better?

blazing loom
#

Probably. HTB is kind of like jumping in the deep end. You can try it and see if you sink or swim. If you sink, then Academy as a ton of good resources to learn.

deep pier
#

yeah i was sinking a lot tbf but the modules are confusing like the Linux fundamental where i have to find a student mail

#

i dont know how to

blazing loom
#

I just did that one. Check the env variables.

#

Also searching for hints on this discord server when you get stuck can be helpful. Typically there aren't too many spoilers just nudges to get you un-stuck

deep pier
#

ok thanks and would it best for me to learn Linux fundamentals or start another easy module

#

sorry to be pain but what does env mean?

blazing loom
#

Linux Fundamentals is a good start module. There is a path called "Information Security Foundations" which is a good starting place as well.

#

If you type env into the terminal if will print all the currently set environmental variables to STDOUT

#

No problem

deep pier
#

ok thank you so much for the help

meager otter
#

You ever get this sorted? Same issue for me. Seems like a whole lot of people are having this issue but i cant seem to find any solutions on it haha

devout spruce
#

Need help with this question in Using Web Proxies

The directory we found above sets the cookie to the md5 hash of the username, as we can see the md5 cookie in the request for the (guest) user. Visit '/skills/' to get a request with a cookie, then try to use ZAP Fuzzer to fuzz the cookie for different md5 hashed usernames to get the flag. Use the "top-usernames-shortlist.txt" wordlist from Seclists.

I've already fuzzed through all the usernames in the suggested wordlist in both Zap and Burpsuite and still can't manage to get the flag. Been stuck on this for a few hours. Any help would be greatly appreciated.

#

Nvm was able to figure it out. Was something simple I overlooked.

obtuse verge
#

Hello all, i have a doubt in the Kerberos - Silver Ticket Module. Can someone explain why, after performing a Silver Ticket attack, i cant do a PS Session?

marble ginkgo
obtuse verge
#

yeah, not the correct service, right?

safe star
#

pssession is http

obtuse verge
#

Thank you!!!!

safe star
#

yes, thats why you were able to list with dir

glacial remnant
#

hey all stuck on the information gathering - web edition module skills assesment. I got all the questions and just missing question 3. "What is the API key in the hidden admin directory that you have discovered on the target system?"

i believe i found what should be the path based off of subdomain enumeration and checking common web files. when trying to hit that path however i get a 301 redirect to a non-listening port on that same path. my /etc/hosts is correct as i can browse to the site to find the path and attempting that path on the naked domain/other found subdomain yeilds no results either.

kind of scratching my head what else i can find here

ashen crest
#

How can I get more spawns for "My workstation"

fathom pendant
fathom pendant
ashen crest
fathom pendant
#

Vip is main platform, not academy, but yes for main platform that'd be it

glacial remnant
fathom pendant
#

For academy it's buying any of the subs/any num of cubes

glacial remnant
#

oooof....well thanks...such a silly mistake

fathom pendant
#

It happened to me too, it's so touchy

glacial remnant
#

well TDIL that its common for nginx to rewrite a path appending the "/" however it doesnt preserve a nonstandard port. meaning i never ran into this until now

ashen crest
#

I'm on my dashboard how exactly do I close the "your chats" UI

teal ginkgo
#

good evening hackers, im looking for assistance completing the skills assessment on the introduction to windows command line module. im stuck on user7. is this the right place to ask for assistance, pls advise...

magic mango
#

for the last question for DNS footprinting. is the answer only found with brute force?

teal ginkgo
heavy hearth
#

Is there really 2 different methods to get RCE Q1 - Intro to Whitebox?? I don't think it is

cloud urchin
#

Not what this discord is about. Read the #rules.

wooden seal
sonic mountain
#

Hi

#

Is any body know that how can use wappalyzer in android phone ?😋 😋

cloud urchin
sonic mountain
#

By the way who are you ?

storm elk
sonic mountain
#

And you ?

storm elk
sonic mountain
#

Means ?

storm elk
#

You’re still posting in the wrong channel. Read and follow #welcome to get access to other channels, like #general

sonic mountain
#

You mean I am at a wrong place ?

storm elk
#

Read the channel description

teal ginkgo
pliant mason
#

wow

wooden seal
vivid wave
#

Hello all,
I've been stuck at the second flag of the Windows Lateral Movement Skill Assessment for several days.
I found the account password and was also able to access a filtered port, but I can't use this to access anything useful.
Can anyone give me a hint?

novel valve
#

do i learn netexec tool in the active directory module by pentester job path?

hardy spire
novel valve
tranquil axle
#

It does say in the beginning somewhere that you can also use netexec and all command should work the same

left dagger
#

hello, anyone have done the wordpress module?

hardy spire
tawdry wren
#

Guys, this question makes me crazy - Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test) .
I installed Android Studio, but the build number I put in HTB doesn't accept it. How to solve this problem?

jagged lotus
#

Hey wannna Know how hacking works

compact patrolBOT
jolly raptor
#

currently in the oracle TNS part of the footprinting module - but i can’t install odat, i’ve tried everything, installing packages, git cloning, anyone else have this issue?

crisp solstice
restive vortex
#

heya, slight bit stuck on FootPrinting SMTP last question
essentially, it wants us to enumerate the users on the SMTP server using a given wordlist. When I ran that wordlist through smtp-enum by pentestmonkey it didnt give me any results

im a bit lost now.


 ----------------------------------------------------------
|                   Scan Information                       |
 ----------------------------------------------------------

Mode ..................... VRFY
Worker Processes ......... 5
Usernames file ........... footprinting-wordlist.txt
Target count ............. 1
Username count ........... 101
Target TCP port .......... 25
Query timeout ............ 5 secs
Target domain ............ 

######## Scan started at Wed Apr 16 05:56:44 2025 #########
######## Scan completed at Wed Apr 16 05:58:29 2025 #########
0 results.```
command i tried was sudo ./smtp-user-enum-1.2/smtp-user-enum.pl -M VRFY -U footprinting-wordlist.txt -t <IP>
safe mango
acoustic owl
restive vortex
#

will do

high hearth
restive vortex
#

thank you payloadbunny

#

legend

glass locust
outer ruin
#

medusa -h 94.237.60.84 -n 21 -u ftpuser -P Downloads/2023-200_most_used_passwords.txt -M ftp -t 5

NOTICE: ftp.mod: failed to connect, port 21 was not open on 94.237.60.84

nmap localhost
Nmap scan report for localhost (127.0.0.1)
Other addresses for localhost (not scanned): ::1
Not shown: 998 closed ports
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh

#

what am i doing wrong here

#

(i am doing websevices in the bruteforce module)

#

i also tried using medusa from the ssh connection, but then i get: ERROR: Thread 5CCA3640: Host: 94.237.53.203 Cannot connect [unreachable], retrying (1 of 3 retries)
ERROR: Thread 5CCA3640: Host: 94.237.53.203 Cannot connect [unreachable], retrying (2 of 3 retries)
ERROR: Thread 5CCA3640: Host: 94.237.53.203 Cannot connect [unreachable], retrying (3 of 3 retries)

dark hedge
#

could be that FTP isn't exposed externally

obtuse verge
#

Hello all. Im doing the Kerberos Attacks - Skill Assessment, and I have Da... credential, but don't know to do with it, tried RDP but didn't work. Can someone give a small hint?

outer ruin
#

sshuser@ng-1642367-loginbfservice-id4yi-bb595f8b8-cdr9s:~$ medusa -h 94.237.53.203 -n 21 -u ftpuser -P 2020-200_most_used_passwords.txt -M ftp -v 5
Medusa v2.2 [http://www.foofus.net] (C) JoMo-Kun / Foofus Networks jmk@foofus.net

ERROR: Thread FDAEF640: Host: 94.237.53.203 Cannot connect [unreachable], retrying (1 of 3 retries)
ERROR: Thread FDAEF640: Host: 94.237.53.203 Cannot connect [unreachable], retrying (2 of 3 retries)

this gives me the same

glass locust
obtuse verge
glass locust
obtuse verge
#

RDP is not working with that User for every machine

glass locust
obtuse verge
#

yeah, i got it

#

I forgot about that common attack...

#

Thank you

rustic sage
#

Hi I want to open this file (file vpn ) in the key browser and be able to view it on my parrot machine “Try to find a working XSS payload for the form in the image URL found in ‘/phishing’ on the server above, and then use what you learned in this section to prepare a malicious URL to inject a malicious login form. Next, visit '/phishing/send.php' to send the URL to the victim, and the victim will connect to the malicious login form. If you did everything correctly, you should receive the victim's login credentials, which you can use to log into '/phishing/login.php' and get the flag.” --> Cross-Site Scripting (XSS) --> phishing module

jolly raptor
crisp solstice
jolly raptor
#

yes

dense belfry
#

Is there a recommended fundamentals module order before jumping into CBBH and/or CPTS studies? I've gone through "Intro to Academy", "Learning Process", "Network Foundations", and "Introduction to Information Security". Likely going to go with Intro Linux/Windows modules next, but I wasn't sure if there was consensus around an order to take the intro/foundation modules. Thanks for any help/guidance.

dark hedge
dense belfry
tawdry wren
shut ice
#

Did you ever find a fix for this?

prisma basin
#

Context: I am on the passwords modules
Part: Pass the Hash

I am having issue with the xfreerdp login with hash

#

Somehow not able to share the screenshot here

#

The error is: Account restrictons are preventing this user from signing in.

acoustic owl
shut ice
#

Looks like it's in protected users

#

so can't PtH I think?

shut vapor
#

am I misremembering that there's a location in the pwnbox for persistent storage?

#

like, across restarts

prisma basin
shut vapor
#

Are you sure you're supposed to /pth?

prisma basin
#

Yes, that's how you use pass the hash with xfreerdp

shut vapor
#

Are you sure that's a hash?

prisma basin
#

I tried this as password. That doesn't work

#

I tried this pth with evil-winrm. it works

shut vapor
#

hum, yeah, says password. I can see if I have any notes on that section.

prisma basin
#

so that's how i am sure it's the hash, not password

shut vapor
prisma basin
#

Actually, with evil-winrm. the mimikatz behaves stragely. it's just keeps going on like continuous entering of newlines. I tried with cme. but somehow the hashes were not working. So trying rdp as last option.

shut ice
#

Is it in a domain? Run cme smb IP and check the domain, you might need to add /d:domain to xfreerdp

#

The hash doesn't work with CME or xfreerdp but does with Evil-WinRM?

shut vapor
prisma basin
#

What I meant to say is I captured hashes using cme, but those didn't work as solution.

shut ice
#

you run -M lsassy?

#

Well there you go

shadow grove
#

The previous question tells you what to do, I believe. Unless you've already done that?

prisma basin
#

wow, Now I get the importance of reading documentation.

#

thanks

#

got it working. thanks man

prisma plaza
#

I want to send the image for a question but I can't

cloud urchin
prisma plaza
#

Here, in this question, after I have connected to the machine using xfreerdp, I found that there wasn't any browser I can use except Link 2, so, at first, I shocked, but got used to it, then I searched for the first host (Host -1) and found a default tomcat page, and that was after scanning the host using nmap and I got very valuable info such us the host name, but the main goal for this question was to gain a shell on the target which is windows server and I tried to search for any upload button on the web. After that I found a manager page which needs login credentials, and I tried to search for any creds after trieng default passwords but I can't get them. So, what can I do as a next step?

safe star
prisma plaza
north owl
#

I'm not sure where to put this but I need help with the "Windows Event Log & Finding Evil: Skill Assessment". I'm stuck on the fourth question which is asking me to find which .exe accessed lsass.exe. Here is my powershell command that I'm running:

Get-WinEvent -Path "C:\Logs\Dump* | Where-Object{$.ID -eq "10"} | Where-Object{$.Message -like "TargetImagelsass.exe"} | Select-Object --SNIP--

Here's the problem: I keep getting an error saying "Maximum number of replacements reached". I can't find a solution online or with AI. Can anyone explain what that error means or why my cmdlet is raising it?

safe star
safe star
#

I used Xpath for majority of the poweshell log filtering so not sure

north owl
#

It gets events for id 10 just fine

prisma plaza
west arrow
#

Hello I can't figure out this exercise, I've tried using nmap with the -smtp-open-relay and -smtp-enum-users scripts but i'm not getting anywhere, some tips would be appreciated.
Module link: https://academy.hackthebox.com/module/112/section/1072 SMTP (Footprinting)
Exercise Question: "Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer."

north owl
prisma plaza
west arrow
safe star
#

Smtp-enum

wispy hill
leaden island
leaden island
#

ah yes wait

#

I understood it wrong

queen nimbus
#

is subscribing and buying the HTB worth it?

dark hedge
#

most of us are biased, yes it is worth it

#

high quality information and lab exercises

lusty thicket
#

as for the information, it all can be found freely online

sturdy otter
#

Hi, somebody knows why the timestamp in elastic stays 30 days even if I set a custom timer interval? Is it just bugged? Thank you guys

leaden island
#

i hate timestamp settings on elastic

#

Btw im on payloads and shells, skill assesments

#

Im supposed to RDP to a machine which, is connected to the targets' network

sturdy otter
leaden island
#

The problem is, theres no browser on that machine

sturdy otter
leaden island
#

Inside the machine

#

I want to surfe throw the web application

#

Im supposed to find vulns i need a browser at least

sturdy otter
#

not sure if i get it, but you could forward the http port to your attack host f.e

leaden island
#

There should be an easier way Kappa

#

Until someone responds ill curl and view it on my pc

sturdy otter
#

most of the time there are multiple ways to solve a problem 😄

leaden island
#

Well it turns out to be an apache welcome page so yeah problem fized

sturdy otter
#

that would be the time I would start fuzzing on an assessment haha

harsh gorge
#

my bad

sturdy otter
# harsh gorge my bad

if you need relevant lists needed for the question they were on the top of the page to download

#

not sure if it got changed

harsh gorge
#

I just saw it right as i was looking at it

bright ridge
#

timestamp works fine for me on the stack

leaden island
#

Somebody help

#

I give up

#

Its late now and ive an exam tomorrow

harsh gorge
#

Yeah I’m not getting zilch whenever I use the wordlist from the module with smtp-user-enum

leaden island
#

I remember getting into the same thing

fathom pendant
devout spruce
#

Really needing help with the Zap Scanner section in the Using Web Proxies module. No matter what I do, the HUD doesn't seem to work. Tried it on my kali machine and on the pwnbox. Also can't run any other type of scans outside of Zap either so I'm clueless on what I should do. Even when I try running an active scan on Zap the high level vulnerability we're supposed to find isn't popping up. Any help would be appreciated.

cloud urchin
devout spruce
#

Well I'm currently trying to do the scan from the pwnbox. Don't have popup blockers or anything on either. Ran the scan multiple times without the HUD and I'm not getting the high level vulnerability we're supposed to find. Is there something else I'm missing?

devout spruce
#

Was able to figure out through Burp instead. Definitely not a fan of ZAP 😓

sturdy otter
#

I prefer burp, too. ZAP is a mess in my opinion

static aspen
#

Hi everyone. I would like to know up to which point is it 'legal' to share your own notes about htb modules? ofc it is not allowed to share the whole information, but what about publishing notes on github or something like that?

fluid ravine
#

Hello, I found that I can't successfully execute some payloads or make a requests via burp when I am connected to VPN from my local kali instance. When I am using pwnbox everything works fine. I think there is a VPN issue. Also I found that when I spawn a box, there is IP address assigned starting 83.xx.xx.xx or 94.xx.xx.xx instead of something like 10.10.xx.xx so maybe there is a routing issue. Can someone take a look on this and resolve this issue?

worn matrix
#

anyone knows why is this happening? [!] Unhandled Rubeus exception:

System.Security.Cryptography.CryptographicException: An error occurred during encode or decode operation.

livid pier
#

Anyone do skills assessment for Introduction to Dynamic Analysis with WinDbg?

fathom pendant
#

Some of the targets are on public docker containers with the given port as the target scope

#

This is explained in the intro to academy module

#

@neon ferry this isn't the server for that shit: reach out to telegram support.

neon ferry
#

I keep joining indian accs and shit

fathom pendant
#

Hacking telegram to get your account back is illegal

#

We don't help with illegal requests

neon ferry
fathom pendant
#

And this isn't a hacker4hire server

fathom pendant
neon ferry
#

K just nvm

fathom pendant
#

I'm not gonna sit here and break down how it's still Telegram's account, and you're just borrowing the namespace. Hacking an account is still hacking telegram, which is illegal

#

Something about reading the ToS of websites

fluid ravine
#

so what should I do in case that I can't normally do labs because something blocking by requests (reset by peer error)? Today I tried to finish file upload module and for example sending POST request with file read via SVG not working

fathom pendant
fluid ravine
#

only pwnbox works fine, but that's not how it should be....

fathom pendant
#

I've had 0 issues using my own machine and vpn

#

But you don't need the vpn to connect to the public ips

fluid ravine
#

yee I know

fathom pendant
#

Does the issue occur when you turn the vpn off?

#

:p

fluid ravine
#

so I normally got access to website

fathom pendant
#

I suggest reaching out to support