#modules

1 messages · Page 412 of 1

uneven solstice
#

soo the case here is
there is no "admin" existin on it anymore

waxen totem
viral lance
#

Where do we reach out about billing problems related to Academy?

compact patrolBOT
tall iron
#

Please how can I learn to track

winged steeple
#

has anyone done the advanced xss & csrf skills assessment? that can help please?

acoustic owl
limpid void
#

ohhh i see thank you!

tall iron
tall iron
acoustic owl
fathom pendant
#

you're asking for something illegal my guy

#

i suggest stopping there

#

stop. asking.

acoustic owl
#

@tall iron if things have been stolen, contact the local police

nova knot
#

Resuming my CPTS path (end of footprinting module), if anyone's interested to learn our way together DM me!! i don't mind if you're ahead or still at the start!!

waxen totem
#

What module is this even for?

spiral jungle
#

its a private ctf...
im not supposed to ask here aren't i?

waxen totem
#

That would be cheating

spiral jungle
#

understood🫡

mellow lantern
#

Guys

#

How to Change a Microsoft account password with Password and Email

#

No Code or gmail

#

@astral vault @bitter needle

#

Please help

bitter needle
#

do u know ur current password or?

mellow lantern
#

Yeah I know the current password but m not logged in to gmail

waxen totem
mellow lantern
#

Can someone do it for me

bitter needle
#

its fishy the fact that u dont have access to ur gmail acc

mellow lantern
#

If I give u the email and The current password can u change the password for me

mellow lantern
bitter needle
#

havent given any recovery email?

mellow lantern
#

I'll try

#

Nope

bitter needle
#

no trusted device?

burnt talon
#

Hello,

My name is Moksh and I'm a cybersecurity aspirant. I am in my early days of learning cybersecurity and I would love to know more about the cybersecurity space and the path to being an expert in this industry. I would love to pivot to cybersecurity. Any guidance(certifications or courses) towards my career path would be highly appreciated.

Thank you

compact patrolBOT
burnt talon
#

Thank you for your response.

I’m genuinely interested in the offensive side of cybersecurity—particularly areas like penetration testing and ethical hacking. To build a strong foundation, I’ve been watching Professor Messer’s videos on YouTube covering CompTIA A+, Network+, and Security+, and I feel confident that I now have a solid grasp of the basics.

As I’m in the final year of my web development degree, I’ve been thinking that it would be highly beneficial to earn a recognized cybersecurity certification before graduating. Having a strong certification on my CV would not only validate my skills but also improve my chances of securing opportunities in the field after graduation.

It would be great if you could suggest any certifications that align with my interests and current level of experience.

digital pendant
#

Probs not best place for this @burnt talon this is for modules in the HTB academy...

burnt talon
#

I am really sorry for that

Okay I'll do that.

Thank you

digital pendant
#

no harm done 🙂

distant gate
#

Hello group, hope you all are doing well! I am doing the exercises on the Attacking COmmon Services - Medium. I got stuck at a point so I checked the sollutions and in the solutions it says to add the subdomain int-ftp.inlanefreight.gtb to hosts and then NMAP it. and it shows on their solution nmap that there is an FTP on port 30021 . But its closed on my VM, I assume maybe the service didnt power on correctly and would require a restart of the VM but just was curious if someone had the same experience or am I missing something

digital pendant
#

its not first time ive seen that on few modules, not done the attacking common one yet but if restarting the VM doesn't help, its most likely a bug -- report in #1234357888114364508

#

others can comment on it then if they think of a reason it could be happening... best way to get feedback I found

distant gate
#

Yea will do it now, probably a one time thing, i dont assume no one reported it if it wasn't . THis would def suck if happened on the exam, it took me an hour of enumeration until i gave up and saw that it was something outside of my control haha

winged steeple
#

Has anybody done the xss and csrf module, Im struggling to get my sqli payload to work on the last endpoint any help would be much appreciated!

waxen totem
distant gate
winged steeple
lone cobalt
#

Hey, are cURL requests anonymous ?

storm elk
digital sigil
#

What do you mean by anonymous

storm elk
#

why'd you even think that

waxen totem
lone cobalt
#

Can they be traced by the server?

winged steeple
#

yes

lone cobalt
#

oh alr

#

ty

distant gate
#

ohh someone has been curling something that they shouldn't have 😉 hahah

lone cobalt
#

just asking 😳

waxen totem
storm elk
#

Either way. Please keep it on topic. This is the channel for module support.

winged steeple
storm elk
#

I'm not able to help with modules at this time

winged steeple
#

ok

lone cobalt
digital sigil
#

All requests that arrive to the server can be logged. This will include the ip that it arrived from/is going to

winged steeple
lone cobalt
#

oh ok thanks

dense crane
#

hi

#

is this the right channel if i have technical problems with my module?

digital sigil
#

@storm elk

dense crane
dense crane
storm elk
#

@prisma wing if you are applying for a job and got a task assigned, don’t lie and do the task yourself.

prisma wing
#

Asking for help isn't lying, how fuckin rude

storm elk
#

Well; it’s your task

#

We are not here to help you solve a task for a job interview. That would be cheating.

prisma wing
#

I understand your point, but asking for help isn't the same as cheating. Sometimes, discussing a problem or getting clarification on specific aspects of a task can help me approach it more effectively. It's about learning and improving, not bypassing the challenge.

storm elk
#

Well, it’s your task for a job interview. You should be able to do it yourself. Check out the Wordpress module on Academy. Either way, this channel is not the channel for your question. If you want access to general chat, read and follow instructions of #welcome

#

It’s 3 steps.

dense crane
#

I'm doing the pentesting in a nutshell module and I tried to wget linpeas from github on the virtual machine on my hackthebox account, but everytime i try to do that the connection times out.

prisma wing
#

Not currnetly as i have not be taught how to. Thank you, i will have a look at the wordpress module. So can i ask the same question in general then?

storm elk
#

People will more than likely tell you the same as I did.

prisma wing
#

Okay noted, I'll try thanks again

jagged lotus
#

Hey

rustic sage
#

Help me I can’t stop listening to early 2000 dad rock someone please save me

digital sigil
#

This isn't the place for that

fleet jay
#

whgere is the place for thag

sacred dome
#

Hi

carmine wadi
#

having some trouble with
Introduction to NoSQL Injection
Skills Assessment II. Anyone around for a pointer?

digital sigil
#

dm me

rustic sage
#

Windows lateral movement windows management instrumentation question three. Use WMI to get a reverse shell on SRV02. Helen is not even a admin with WMI permissions. Wondering if I should fuzz her password against the list of users and go that way. Not sure why the lab showed an example of somebody without those permissions to begin with.

dapper moth
rustic sage
#

Netexec for .52 just went and did nothing from what I remember . Sorry I walked away

weak mirage
#

did you find the anwser ?

dapper moth
rustic sage
#

Taking a lunch break, but I’ll try again

weak mirage
#

please help me i have read 3 time the module and i don't find the aswer :module/80/section/837 broken authentification What is one prominent issue with passwords?

dapper moth
true oak
#

I am in trouble with the target of the "Packet Inception, Dissecting Network Traffic With Wireshark". I can connect to the machine with xfreerdp but it shows nothing, I mean it displays only a black screen. I searched about it in old log and found I should press a space key in the black screen but it does not work for me. Could you give me some advise?

Please ignore this post, I realized that the blackscreen is a wallpaper of a linux VM. I misunderstood it was a Windows VM.

pseudo forge
#

Anyone working on the Penetration Tester module and want to learn together DM me!!

cloud urchin
#

@rustic sage This channel is for discussion of the various modules on HTB, take it to #general please. Follow the instructions in #welcome to access the channel.

harsh gorge
#

Thank you W1ld

wraith thunder
#

Hi. Someone knows if there's any kind of issue with 'inlanefreight.com'?; I cant access it

viral slate
#

Module: whitebox attacks
Section: client side prototype pollution

Hello everyone!
Got stuck for a week around on this task.
Can I have some help?

acoustic owl
hoary whale
#

I’m having trouble Copy>Copy after I authenticate in the GET exercise in web request in order to find the flag

hoary whale
#

DM?

#

No answer

hoary whale
#

Web request module in Bug Bounty path

hoary whale
#

Is anyone working on Bug bounty

slate zinc
#

tell us what issue are you facing

spiral sapphire
#

I'm having trouble installing some tools. It's the attacking common applications module. The guide teaches "sudo pip3 install droopescan" and I get an error "error: externally-managed-environment" . There are other tools also, I cannot install pip3 tools for some reason. git clone doesn't work either btw, I cannot install the "requirements.txt" and the tool won't run at all.

slate zinc
#

i havent done the module but i have fixed pip erros before
there are usually 2 ways to do it
using pipx (this is global)
and using venv (using this you will need to go inside a python venv everytime and activate it)

#

for now intsall pipx and then try to install droopscan

spiral sapphire
slate zinc
#

did you try to install the missing modules 🤔

spiral sapphire
#

When I used "sudo pipx install droopescan" I couldn't even use the tool as it installed itself in the ROOT directory. When I used "pipx install droopescan" I try to use the tool but some modules are missing. When I try to install said modules, it won't let me I think it just gave me errors

slate zinc
#

wait here i guess someone may know :)

spiral sapphire
#

That's too bad, I say the course material should be re-evaluated :/ Do you happen to know any other Joomla scanner I could install with apt ?

slate zinc
spiral sapphire
#

Alright, thanks a lot, man!

slate zinc
#

venv doesnt work either

#

🪦

spiral sapphire
#

So it's the tool itself that is broken?

#

That's a shame :/ I've been banging my head trying to get it to work. If you happen to know any alternatives, please tell me 😄 And the material needs urgent updating.

lavish jay
#

Hello,
I have completed all but 2 of the questions for Android Fundamentals. (1) question 2 for Android Emulators: Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test).
and also
(2) question 2 for the Android Skills Assessment: Find the UID of the application com.android.settings. Use the command adb shell ls -l /full/path/ to inspect the file permissions and identify the application's UID from the output.

request assistance.

lavish jay
trail grove
#

hey I'm having trouble with:
"command injections - bypassing blacklisted commands" https://academy.hackthebox.com/module/109/section/1038
"Use what you learned in this section find the content of flag.txt in the home folder of the user you previously found."

(also not really sure how much I'm allowed to share of my progress for means of getting help with this?)

#

I am able to read the files in the home folder but nothing comes back for flag.txt

shadow latch
#

you can list the flag.txt?

#

some times, in command injection, you can use *, so instead of execute cat flag.txt you can execute cat flag*

shadow latch
fathom pendant
#

😉

arctic wyvern
fathom pendant
#

@shadow grove don't spoil the module content

fathom pendant
#

It's there to show you can use the ip in the query, not just a domain name

shadow grove
fathom pendant
#

The target you can access is the 10.129.x.x spawned target above the question

dapper moth
#

Are we getting "missions" on Academy now!?

fathom pendant
dapper moth
#

I'll never be able to finish the whole content 🤦‍♂️

solar bloom
#

Footprinting Module> Oracle TNS Challenge/Skills. When running the .SH provided to download/install SQL Plus, it doesn't appear to install it, the tool itself despite I can see the xcript working. I woud like to finish the lab but I know this tool is needed.

fathom pendant
#

run the script line by line instead of as a script

#

i've had issues where the tools/dependencies don't properly install

lavish socket
#

I'm working on the last part of the Advanced XSS & CSRF module's skill assessment.|| I can query the API but I cannot get a working injection other than a "something went wrong"||. Could someone help me on that?

fathom pendant
#

@round parrot please refrain from spoiling info on labs from modules above tier 1; your screenshot contained passwords and such.

neon frost
#

.

#

guys how can i have access to active machines channels please

fathom pendant
#

read and follow the #welcome instructions

round parrot
#

ok this then

#

a lot of broken modules or not updated for a while

#

still for some reason i can connect with ldapsearch with the creds but not with following the tutorial. it fails..

fathom pendant
#

You're running with sudo yeah?

round parrot
#

yes, tried it with and without

cloud urchin
round parrot
#

lol. yes it does. quite clear. module Unconstrained Delegation - Users Kerb Attacks. But it shouldnt. since i get connection with ldapsearch. maybe the twist is that i cant add a record with that user..

polar raven
#

Was looking at 'Python Library Hijachking'.
https://academy.hackthebox.com/module/51/section/1640

I think there is a mistake. It is said, if the SUID/SGID is assigned to a python script than we can do what we want (Wrong write permissions section)

But it's not the case, suid are ignored on scripts and in the box itself. If you changed permisions and put a SUID on the python scirpt it doesn't work.

Even having a SUID on the python interpreter isn't working

The real and only method is having sudo permissions on the script

dark hedge
#

sudo

polar raven
dark hedge
mortal linden
#

Good evening. Working on Shells and Payloads - the live engagement. Within the first box you have to rdp to, i have minimized terminals that are running commands. I cannot figure out how to get them to be visible again. I've tried Super +W but my laptop tries to respond, and the vm does not. i swear i only show up with dumb problems.

waxen totem
mortal linden
#

Thanks. The top Taskbar isn't showing any of the things I minimized, and alt tab just tries to switch windows on my laptop. 😦

waxen totem
plain spear
#

Hint: think about what UID stands for and you should get the answer from that.

uneven solstice
#

need help w dis in windows fundamentals module

#

i tried dir c:, tree c:, but im not sure wt im supposed to actually do

#

whats "non-standard" supposed to mean

#

can any1 help?

waxen totem
uneven solstice
waxen totem
uneven solstice
#

dir c: gives directory for c drive right??

waxen totem
#

dir c:\

uneven solstice
#

.
right

uneven solstice
#

in c

#

@waxen totem

waxen totem
uneven solstice
#

im trying 😭

waxen totem
uneven solstice
#

i need the file contents of a directory

waxen totem
uneven solstice
#

i got the directory im lookin for
its academy
but i need contents of da flag file stored in it

waxen totem
#

just use the command bro why you making modifications?

uneven solstice
#

thats the one i need

#

i tried everythin in section

waxen totem
#

have you tried: using the file explorer?

uneven solstice
#

apparently the ps command for dat was dis....i did smth similar but i think i missed smth

#

n then yes file explorer

quick rover
#

hey, need some help with the OnlyHacks lab

#

is this the correct place?

fathom pendant
#

no

#

read and follow #welcome to access more of the server

zinc swift
#

i thought i saw where approximately how much time each module took. where can i find this information again so i can plan out my days in advance?

edit: i found it in modules if anyone else was wondering

vague sage
#

broo in linux privilege escalation/logrotate how do you ||force logrotate||?

#

i tried using -f
permission denied (obviously)

im not sure what else to try

#

ive tried a few other ways i saw on google but nothing worked

waxen totem
#

there are modules rated for 8 hours that I finished in 2, while there are modules rated for 10 days that I finished in 20 kek

zinc swift
#

i'm just setting aside a few hours per day during/after work

#

but i have a goal in mind for when i want to finish the pentester path

vague sage
nova knot
#

hey in Foot printing module I'm having trouble cracking the hash

#

in IPMI section

waxen totem
#

you can remove admin: or add the -username flag (might need two -s)

nova knot
#

yea got it changed to 7300

proud notch
#

Module: Understanding Log Sources & Investigating with Splunk Section: Skills Assessment "Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through SPL searches against all data the process that started the infection. Answer format: _.exe" I was able to get the answer but can someone DM for a quick sanity check regarding the question and possible ways of finding the solution easier? 🙏🏿 🙏🏿 🙏🏿 🙏🏿

flint palm
#

Hi Guys has anyone completed hard lab of Enumerating Network with Nmap?

flint palm
#

figured it out never mind)

lavish socket
# lavish socket I'm working on the last part of the Advanced XSS & CSRF module's skill assessmen...

I'm still looking for help in the last phase of Advanced XSS & CSRF module's Skill assessment. I got a tip from a helpful user but I'm not sure I'm still doing it correctly. Is the last phase supposed to be ||boolean-based||? I'm trying to be methodological in my approach but at this point I think I'm misunderstanding something, because my current approach is testing other skills to what the actual module is about.

chilly cosmos
#

No.

stark hull
#

<@&861185840277487616>

hexed oyster
#

I have the original short link they sent

quick temple
#

Guys I started Tier 0 Meow and completed it, but can someone explain, what are open ports? What is 'nmap'? I felt like I got thrown in without some background.

#

It was fun but just trying to understand the inner workings

dark hedge
quick temple
#

Ty

safe mango
uneven obsidian
#

hey I am on the Pivoting, Tunneling, and Port Forwarding module,

I am trying to utilize a reverse shell with ligolo-ng,
I managed to move the reverse shell to the internal server but I cannot manage to gain a reverse shell from the windows host through the ubuntu server to my attacker host

#

I am a bit confused, is someone availabe for a little help 🙂

ancient niche
#

ey guys Good Afternoon, I need bit help here. Has anyone arrived here?

#

this is the last exercise of AI

golden gate
#

hello guys
im doing the introduction to windows command line
and im facing some stupid issue

#

options in powershell have a colour similar to the terminal background ||at first i thought that options were invicible lol||

how to change the colour of the terminal backgroud

#

so the options become easy to read

fathom pendant
#

It's been a minute

#

It's mostly due to jumping to ps from another session which is causing some issues

ancient niche
fathom pendant
#

Who's marciello?

ancient niche
#

you xD

fathom pendant
#

Thats not my name? No "o" in sight

barren apex
#

Module: AD attacks & Enumeration
Section: Skill Assessment 1

Question: submit cleartext password for t***** user.
I compromised the domain admin and got the final flag, but can't get cleartext password for that specific user, anyone available for a hint?

dim hound
barren apex
#

Can I dm you?

dim hound
tame latch
#

Hello everyone,
I just finished learning all about networking, but now I’m not sure what to move on to next. I’m new to the cybersecurity space and don't know anyone in the field yet.
Can someone please guide me through the process and suggest what my next steps should be?

compact patrolBOT
golden gate
ancient niche
#

almost

safe torrent
#

hi everyone! I've got one question - currently i'm at pivoting & tunneling module. How exactly rpivot works? is it only forwarding webserver to my attacking host (kali)? or can i even rdp to this victim server which contains webserver?

lavish socket
# chilly cosmos No.

I kind of thought that it shouldn't. Would you mind if I DM you about this (are you familiar with the assessment?)?

uneven obsidian
#

Hey, i am on PIVOTING, TUNNELING, AND PORT FORWARDING - Remote/Reverse Port Forwarding with SSH section

I am trying to use ligolo-ng in order to get a reverse shell on the windows machine of the user victor (172.16.5.19) is not connected to the internet and there is no open port within it
this windows host is connected to the web01 ubuntu jump host

In the module they're doing it with ssh -R <InternalIPofPivotHost>:8080:0.0.0.0:8000 ubuntu@<ipAddressofTarget> -vN
But I am wondering how to utilize it with ligolo

If someone can please assist me I will share screenshots to be more clear.
Thanks 🙂

#

yesssss omg I manage to do it after 5 hours

#

I guess typing my thoughs helps

zinc drum
#

can the flag be a word/sentence? as in:
HTB{word1_word2}? I'm new here ^-^

uneven obsidian
#

the flag is the whole HTB{word1_word2}

zinc drum
uneven obsidian
#

yes 🙂

dapper bough
#

hi, i need help with (Attacking Thick Client Applications)

uneven obsidian
#

a flag could be also like
Em0r!4L!_G00d_LUCK 🙂

zinc drum
#

Thanks! ^-^

gusty mortar
#

Hi, can anyone help with skills assessment on injection attacks? I found how to execute js code and read files, but I have problems at the xpath injection stage.

ancient niche
#

ey guys how long have you been hacking?

terse sedge
#

I am on Shells & Payloads - The Live engagement, question 5. The remote host install of Metasploit does not contain the exploit, and there is no internet connection to get it from exploit-db. Am I missing something?

cloud urchin
quasi wave
#

hi I'm trying to make sure I understand this section. who can I talk to in order to understand it better? I think if I explain it to someone else I will understand the material better. I also have some questions about the material.

#

can I DM someone? I don't need help with the questions as of right now

#

I just need help understanding the section

quasi wave
#

I completed two questions of section doing third

#

gonna get flag and then reread section

#

hi the section is telling me to login to the server to transfer a file to it via a specific protocol but the server isn't listening on that protocol

cloud urchin
#

services don't always run on default ports

quasi wave
#

ok thanks

fathom pendant
quasi wave
cloud urchin
#

i have no idea what you need to do

fathom pendant
terse sedge
#

@fathom pendant That worked. Why would it be in there, but not come up in a search?

fathom pendant
#

But it does exist

terse sedge
quasi wave
#

And I mentioned it earlier

fathom pendant
#

That context was long lost

gray heath
#

Hi!! Guys
Can speak in spanish?

fathom pendant
gray heath
#

Srry. Muy bad

quasi wave
gray heath
#

I can't resolve my 1er lesson
[us-academy-3]-[10.10.14.169]-[htb-ac-uxkrp0utzq]-[~][*]$
Find IP:PORT

fathom pendant
#

well find isn't an ip/connection command

#

but what academy module is this for?

proven spindle
#

hey everyone , i need help i am doing cpts and now i am in chapter 2 topic public exploits in which i have been given question. but i am geeting this error using metasploit when i hit check:
" The service is running, but could not be validated. Authentication to Wordpress failed."
can anyone help me with that

cloud urchin
proven spindle
wicked kayak
#

hello I was thinking something from the Penetration Testing Process
Page 2
in Academy Modules Layout you have to do just the fundamental modules it suggests Before moving on right ?

proven spindle
#

spent my entire day still coudn't solve this sadglas

#

problem

proven spindle
wicked kayak
#

Ok so just read the page for now

#

Thought maybe it was asking the fundamentals, I guess I will do them somewhere in cpts path

cloud urchin
#

@desert plume No one is going to outright tell you the answer. You can ask for a nudge if you're really stuck but you need to explain without spoiling content from modules above tier 0.

desert plume
#

the answer is the flag lol im just asking how high the pin code is lol i dont want the flag

cloud urchin
#

still applies

#

And those go against the rules too, no posting content above tier 0.

desert plume
#

there hows that ? how that code look then

#

thats is they give you

sharp shadow
#

Hi. Im doing attacking enterprise network. when I try to upload zip from sharphound to bloodhound it just keep loading forever

cloud urchin
pearl reef
#

It can be a Malware or It might be a genuine family man. @viscid osprey Referring to your question in #cpts

cloud urchin
rustic sage
#

Try a legacy one

safe star
#

Try bloodhound-python or sharphound v1.1

sharp shadow
hexed oyster
#

OK. I'm working on the Final assessment for Broken Authentication. || I've gotten to the point where I have to brute force the 2fa pin. I know what information I need to filter out. I've generated the pins with 'seq'. However nothing is hitting for me. || Have I missed something?

#

I've used seq -w 0 9999 to generate the list of possible pins.

rustic sage
#

hi

cloud urchin
#

@rustic sage Hi. Read the #rules and follow the instructions in #welcome to gain access to most of the server. You can chat in #general after that.

sharp shadow
#

hi again. I tried with sharphound v1.1 it didnt work either. my bloodhound version is 4.3.1

#

when running with sudo stuck here.

harsh kindle
#

Hi there

rustic sage
sharp shadow
rustic sage
#

All gs

long flint
#

do you think using AI to help with learning, like reverse engineering code, is frowned upon?

nova knot
#

guys, I'm in footprinting medium assessment and stuck

#

at a point i've got the access to target and 2 required creds

#

unable to move forward from there

azure ocean
proven spindle
#

Hey everyone, i am on GETTING STARTED MODULE , Using PUBLIC EXPLOITS SECITION. I am stuck , when i exploit target host using msf it says " the service is running but cannot be validated" means plugin require authentication but i have done all the things to get username and password all in vain. can some body help me how should i get this done

wispy hill
#

Wireless network in network fundations. It’s not accepting 2.4GHz and I can’t close the module. Yes it’s tier0 and don’t know why it’s like this

acoustic owl
proven spindle
acoustic owl
proven spindle
#

thank you

nova knot
nova knot
wild oriole
#

Hello guys,
I'm practicing the last assessment in the password attacking module, when trying to download the backup.vhd file, I'm always getting a timeout, the ping to the server is OK, I've
checked the tutorial for this assessment, and it should work. any idea? I'm using my own attacking Kali VM

rustic sage
#

If persists, try a TCP VPN since that file is quite big

wild oriole
rustic sage
#

TCP is a safe bet, but someone who has attempted the exam can answer it better. I'm yet to sit the exam

frozen mesa
#

Active Directory PowerView --> Enumerating AD Users --> Find the second user with a password in the description field. Submit the password as the answer. -->||Get-DomainUser -Properties samaccountname,description | Where {$_.description -ne $null}|| but none of the output is accepted as an answer. What did i miss?

serene laurel
#

Is the VPN extremely spotty for anyone else, I can connect but get booted off after a few sec?

safe torrent
dark hedge
#

the flag is in your screenshot.

#

deleting due to spoilers

devout garden
#

Okay, thanks!

half geyser
#

Need some serious help... Firewall and IDS/IPS Evasion - Hard Lab. Struggling with this one a LOT. I assume I need to get to a point where the port is open as step one right?

fathom pendant
half geyser
# fathom pendant source ports are your friend

lol, I gathered that in the first two minutes, it's the next four days that has me struggling 😄 Thanks for the confirming that I am on the right track though 🙂 It is way to easy to overthink

fathom pendant
gusty zinc
#

Hi - in Active Directory LDAP module, LDAP Overview it disucsses how to enumerate using ldap queries for " This query searches the domain for all administratively disabled accounts."

My question is - does this query and its output have any significance or is it just for demonstration purposes? I cant understand why this output would be something you would have interest in.

fathom pendant
#

a disabled account can be interesting; but it's an example of what you can do

#

it also helps if, for example, you pilfered creds to ensure the user is active

gusty zinc
#

Thank you, helpful.

languid coral
#

I'm doing Linux Privilege Escalation - Logrotate and one of the preconditions for the exploit, logrotate running with elevated privileges, doesn't apply to the machine. The config file listed in the tutorial that sets the su for the process is not visible to the user I'm given. If somebody is familiar with this module: can I get a hint? ty

fathom pendant
#

i had 0 issues with using logrotate to copy the file

languid coral
#

I ran the logrotten exploit, it apparently did it's thing, the "logrotate -f" command I used to trigger the rotation returned a permission denied error and I didn't receive the reverse shell.

#

Am I missing a step?

fathom pendant
#

are you sure you're messing with the right file, first and foremost

frozen mesa
#

I found him but the found pass is not accepted as answer

languid coral
frozen mesa
#

was the most obvious of the two 🙂

languid coral
#

Thank you!

fathom pendant
#

i deleted the message previously for providing the direct hint; i suggest taking to dms for further help

fathom pendant
frozen mesa
#

i did retype it, copy/paste. Didnt work.

maiden kestrel
frozen mesa
#

Yes I did

maiden kestrel
# frozen mesa Yes I did

Then try refresh the page and enter the same answer. I found that if the page has been open for too long it will say the answer is incorrect.

frozen mesa
#

Thanks...kept me busy for more than a hour 🥲

fathom pendant
median gale
#

Shouldnt the uid be a f integer !?

calm abyss
#

hello i am also stuck with MODERN WEB EXPLOITATION TECHNIQUES - SSRF Basic Filter Bypasses

Can you help ?

half geyser
fathom pendant
#

it absolutely doesn't "just work on pwnbox" lmao

#

i've gotten the answer on my own vm plenty

#

sometimes it's also a bit of patience after you identify the right port

signal berry
#

I have a mundane problem... I'm often getting my solutions right, but not the expected end result, this is usually because I choose the wrong local IP's to connect to my target. Just now, I was working on the shells module with the live engagement, on the first host, i essentially did everything right, but i picked the wrong LHOST up to 3 times, which made me doubt what i was doing was the right thing. How validate I'm using the correct ip from ifconfig -a when connecting to my target?

fathom pendant
#

that's the most simplistic answer i can give

#

the live engagement has you attacking targets on a separate internal network that don't have access to the 10.129 range

signal berry
#

that's the answer i needed

#

I was trying to use the local ip, the ip i got from the assignment, another one, but i was doing it aimlessly. using the correct IP range is actually a reason why to pick A over B 🙂 Thank you Marcie! that helps me a bunch

half geyser
hearty fox
#

Got it: need to "sudo -s", then run wpa_sycophant.

livid solar
#

hey guys I am new here. anyone can help me get through Academy - DNS Zone Transfers? I found internal.inlanefreight.htb subdomain with DNS records. I tried every possible count they would want but without any success it always says incorrect answer. I tried 12, 11 you name it so if anyone knows how to get through this thingy I would be grateful.

odd scroll
#

Hi Where is the right room to ask help about labs ?

delicate zenith
#

quick question on htb academy. when you finish a section and you go to the next ?module? / ?section? where do you see how long htb thinks it will take to do that module / section?

acoustic owl
acoustic owl
delicate zenith
#

ahh ok. thanks!

acoustic owl
delicate zenith
#

how do you get access to speak in the htb off-topic general channel?

livid solar
odd scroll
#

Where I can see my account Identifier on HTB settings?

acoustic owl
odd scroll
#

I follow

livid solar
odd scroll
#

It say go to my setting my profile I dont see account Identifier

acoustic owl
#

on the right side

odd scroll
#

thanks!

twin bridge
#

Hey guys

cloud urchin
#

This channel is for discussion of the various modules on the HTB platform, not for help with school.

twin bridge
#

How do i get permission to post in general? @cloud urchin

cloud urchin
half geyser
wheat night
#

Hello, I'm doing the using web proxies module and the spawn a target of a submodule seems broken, I try to ping/curl into the ip and it doesn't seems to work

cloud urchin
inland oak
#

hi , anyone can help? I am stuck at footprinting IMAP/POP3. The question is to Find the admin email address..

wheat night
#

but I taget spawning work for you it means that is something on my pc

dim hound
wheat night
#

anyways I'll do it on the vm

wise galleon
#

Hi

inland oak
#

So confuse

cloud urchin
#

@inland oak Please take care not to post content from modules above tier 0

inland oak
#

😦

golden gate
#

helllo guys
why is this not working

PS C:\Users\ahmad> Get-Alias | Where-Object { $_.Name -like 'Get-Content' }
PS C:\Users\ahmad>
#

i mean i know the name here would be something like cat since its an alias
but

PS C:\Users\ahmad> Get-Alias | Where-Object { $_.Name -like 'cat' }

CommandType     Name                                               Version    Source
-----------     ----                                               -------    ------
Alias           cat -> Get-Content

PS C:\Users\ahmad>

here cat is the name but what is get-content
is it just a normal text

topaz vessel
#

Hii

cloud urchin
#

Are you looking for a Windows command that does what 'cat' does in Linux? If so just use type

topaz vessel
#

That's right 👍🏻

golden gate
golden gate
cloud urchin
daring sigil
#

Can someone help me get started?

#

I’m new and I’m trying to learn to code so help is appreciated

compact patrolBOT
shell ore
#

ehm hi in the Sliver module the error:
"rpc error: code = Unknown desc = implant timeout" happens a LOT i searched this channel a lot of people are facing it NO ONE suggested any solution, anything new? i cant execute binaries or aliases and this is annoying T_T

thin citrus
solar bloom
#

Footprining Module> Footprinting Lab-Medium. I'm trying to mount NFS share, but it just freezes and does this. I've made the directory on my attack machine.

#

Eventually times out with "connection refused". I can see there is an available share..

gray heath
#

Login & password de mrRobot plz ❤️

cloud urchin
maiden sigil
gray heath
#

Vulnhub mrRobot can't login

solar bloom
maiden sigil
#

IP should be target, just edited.

cloud urchin
# gray heath Vulnhub mrRobot can't login

This channel is for discussion of HackTheBox's modules, not vulnhub stuff. Maybe ask in #red-team or something. You'll need to verify your account by following the instructions in #welcome to access other channels more appropriate for questions like that.

gray heath
#

Srry my bad

acoustic owl
solar bloom
quasi wave
#

hi it doesn't give me an error but I cannot connect via ssh on the Web Server Pivoting with Rpivot section of the Pivoting, Tunneling, and Port Forwarding module. This is for the last question. I tried nmaping it but that failed too because it scans all 1000 ports and none of them are open. I want to scan all 65,535 ports but I'm scared it will take forever and I don't know if that's really the right way to go because it says to SSH into it. Do I need to do a fancier nmap scan like a FIN scan or something?

quasi wave
#

hopefully I'm not spoiling anything

west arrow
#

module link?

cloud urchin
high reef
#

Algorithm Confusion anyone around i can DM for help ?

#

when i input the pem key in cyberchef i get invalid token

fathom pendant
high reef
#

thats a section in the modules

fathom pendant
#

Whats the module name then?

high reef
#

Algorithm Confusion

#

in the Attacking Authentication Mechanisms

quasi wave
#

But good point. Thank you for the suggestion. I’ll try soon.

indigo fulcrum
#

hey peeps, I am having some issues with coercing in order to get the first RPC call resulting in the message '[+] (ERROR_BAD_NETPATH)' for the SMB named pipe '\PIPE\lsass'.

I am looking at module/232/section/2522. I know I am doing the correct command, but there seems to be some issues where lab env is concerned.

Command:
Coercer coerce -t 172.16.117.60 -l 172.16.117.30 -u 'htb-student' -p 'password' -d inlanefreight.local -v --always-continue --filter-pipe-name '\PIPE\lsass'

#

When I run my command, everything works fine, but no error shows in the form:

'[+] (ERROR_BAD_NETPATH)' for the SMB named pipe '\PIPE\lsass'.

vital ravine
#

Can someone help me with Firewall and IDS/IPS Evasion - Hard Lab? I've tried several types of scans, and I only ever find 2 ports, or the scans will take hours (The machine won't stay up long enough) I've tried adjusting the delay, max tries, etc. I have enumerated the http service I found with no luck. Been stuck on this for a while.

fathom pendant
vital ravine
#

Ill look into that, thanks

fathom pendant
#

Check the reading; it refers to source ports and reasons 😉

vital ravine
#

Nice, thanks 😎 I think I'm on the right track now

fathom pendant
#

@atomic moss this isn't a hacker4hire server; see #rules

atomic moss
#

Anyok

wheat night
#

I have to say sorry. Earlier, I was asking why I couldn't connect to the spawned target. I forgot that I had configured my firewall to drop everything except some ports. 😛

#

hehe

grizzled torrent
#

Hey guys I’m switching fields into cyber security from medicine and my old laptop has died on me. Are MacBook pros suitable as an entry level device in cyber?

fathom pendant
#

They're fine. But you may run into tool issues as most tools are built for amd x86_64 chips, and most recent mac pro chips are m1/2

grizzled torrent
#

Are there work arounds for this issue?

fathom pendant
#

I mean you'd just have to find comparable tools

#

As that's more of a cpu level thing than it is a distro level thing

#

Different instruction sets

grizzled torrent
#

Awesome. Thanks for your help

mortal linden
#

I'm restarting my spawned target for the umpteenth time now for the Common Services Attacking FTP module. I know this one gives everyone a problem. It took like 5 retries for me to get the first non-standard port, and then i exhausted the users lists and password lists. I can't connect to the one non-standard port I've found anonymously (i've tried...lots). Looking through other people's posts it seems like there should be a second non-standard port open. I've tried a lot to find the other non-standard port, including looking for some specific ones, and I can't get a box to spawn that has a second non-standard open. Has this lab been updated or do I really still need that second non-standard port open. feel free to DM me if this is getting too into the weeds!

#

I did find one of the users (that answered question 2) and suspect that there is a second user; I've tried the provided password list with both usernames and got no dice.

rustic sage
mortal linden
cunning meadow
inland oak
cunning meadow
#

that's the other thing.

#

I certainly didn't need this machine, but i like it a lot and the battery life is killer.

#

It's a nice computer objectively speaking. I'm sure someone will tell me Im wrong. But with Surface vs Macbook pro it's like a matter of preference imo

inland oak
#

I just want a system I can customize, that’s it. Some of my friends say MacBooks are hard to customize. Is that true?

cunning meadow
#

to an extent yeah, you're dealing with Apple's walled garden.

#

certainly not what you'd get using linux, but if you're doing HTB you probably wouldn't be connecting from your macbook. It's best to use a VM (I could be wrong) or the pwnbox with your web browser

#

What sort of customization are you thinking?

#

either way, if you're thinking you want to get into things deeply I'd look else where. Saves the money too.

acoustic torrent
#

Stuck on the last question of manipulating the model under introduction to red teaming. If anyone can give a hint on what to exactly look for that would be great

weak fractal
#

in Signature Wrapping Attack I've tried to inject my modified assertion in the original SAMl payload like in the module , but it didn't worked ,I didn't beautify the code, can anyone help me?

waxen totem
distant gate
#

Hey group, I am having an issue I cant figure out. On module Meterpreter Tunneling & Port Forwarding. Making a payload: msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.175 LPORT=8080 -f elf -o backupjob (running on the pivot host)
And running multi/handler on local msf, I am getting : The "stdapi" extension is not supported by this Meterpreter type (x64/linux) . I tried both meterpreter_reverse_tcp and meterpreter/reverse_tcp. The syntax of the msvenom is correct, and on the handler, I have set the payload the same. IT makes a connection but doesn't allow for command executions.

waxen totem
#

Nope that's illegal

barren crystal
#

so just wondering but whats the difference between the cbbh and cpts exams?

queen gull
#

hii can anyone help my friend recover her Instagram account??

waxen totem
distant gate
#

Would love some help with :https://academy.hackthebox.com/module/158/section/1428 . i cant get a Meterpreter session for some reason, getting ailed to load extension: The "stdapi" extension is not supported by this Meterpreter type (x64/linux)"" . I tried a bunch of different payloads, all are getting the same error. Tried linux/x64/meterpreter/reverse_tcp , linux/x64/meterpreter_reverse_tcp , linux/x64/meterpreter_reverse_https , all are getting the same error

smoky scroll
#

Hi! Quick question:

If I upgrade my subscription to Gold right now, will I immediately receive the 500 cubes, or will they only be credited after my next billing cycle starts?

acoustic owl
smoky scroll
#

Also, if I buy a Gold subscription, unlock a module using the 500 cubes, and then cancel the subscription afterward, will I still have permanent access to that module?

thorny kraken
#

Yes

#

Modules you unlock with cubes are permanent according to the FAQ

thorny kraken
#

Also modules you complete with the access based subscription are reviewable too and cubes you unlock for completing them are yours to use on whatever you like

#

So you could build up your cubes with access based then use them for the higher tier modules

cedar ruin
#

hey is anyone able to help me with Footprinting module, section MySQL, question 2. The email for the answer i have isnt showing up as correct. even if i check the walkthrough the same answer shows up as incorrect?

bronze lodge
#

504 Gateway Time-out

elder scaffold
lean bronze
#

I'm having 504 gateway timeout

cedar ruin
#

might explain why my answer wasnt submitting haha

bronze lodge
#

Where should we submit the ticket?

lean bronze
#

I guess we wait

bronze lodge
#

Looks like everything's back to normal now.

cedar ruin
#

yep

bronze lodge
#

Alright, back to the grind!

distant gate
#

Is it me or the pwnbox and the targets are having issues, lag, connectivity issues, freezes?

sinful lodge
#

robots.txtx

acoustic owl
barren apex
#

Anyone available for a hint on AD attacks & Enumeration skill assessment 2?

waxen totem
dense hearth
#

Hi, I am doing skills assessment regarding NTLM relay attacks and I am stuck on question 3. I got the hash of the machine from question 2, tried to coerce the sqlbox but no success. But I am lost what to do next to access SQL machine. Any direction is welcome

gray yacht
modest void
#

Bummer

median gale
#

Would like some help on NoSQL injection SA 2, is anyone available?

nova knot
#

guys, I'm doing info gathering web edition and on skill assessment, I was asked to crawl and submit the found mail, but the crawling showed ntg but index.html

fathom pendant
finite bramble
#

Can anyone help me with module 57 section 491. Have the username and password for both users yet I cannot log in to the ftp service to get the glad

#

Flag*. It isn’t connecting and this is driving me up the wall

nova knot
#

but all it has it counless random order indes-1-1000

fathom pendant
nova knot
#

prolly, and I tried dir busting the new sub.sub.domain and no leads

fathom pendant
nova knot
#

yea it's curntly running

#

it's taking a long time, is that it?

#

I'll try to restart and run this again if it's the way cuz I'm w8ng since 15 mins

finite bramble
#

I’ve been trying to ssh in and ftp in using the usernames and passwords that I acquired and nothing is working

#

I’m getting a constant “connection refused”

winged steeple
#

Construct a valid SSL 3.0 padding of the plaintext bytes "AABBCCDDEEFF". Use the byte 00 for any byte that can be an arbitrary value. Provide the padded plaintext without spaces. Assume the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA is used.

If there is 6 bytes in the string, would it mean there needs to be 10 bytes of padding? so 00000000000000000A, so why doesn't this answer work ?

quick grotto
#

Hi everyone hope you are doing well, ive one question! currently im doing attacking authentication module and currently on jwt algorithm confusion attack. im doing the same steps like mentioned but its throwing error. any help will be appreciated. python3 jwt_forgery.py eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VyIjoiaHRiLXN0ZG50IiwiaXNBZG1pbiI6ZmFsc2UsImV4cCI6MTc0NTg1ODI5MX0.<SNIP> ASIYNejb12GEuZjhVNZ0oyqgqUbVOtipqdiiZyZ02A7Zl24rOxiZCkD-iudtSSccWBKFZrzLwWHIegYAbmc1-qleXZ1UOGU4hDXq4iucdZfxnXQnlIFHZc7V0PMlUtjtvuecppcCyYQMlCJ-TYyU6dslJoiMsk7O0ITdMvUmMwtztukKfXvXZ6bUX4ZZsFYh1eRgb20l04LAMLWyVFsVEYOa-CH5eyFb5lqgZRoOGSeL-D--mecWVJkwGY4ogx8XSh2RVxkT1SlkdTZ6cQ4wns94zEpjAO4xvgk0-0jAgk1ME8-VfFAfgWEK6WIJXbI8dgBZSa14WqSyBj9nyFek9w<SNIP>

plain echo
#

Dann

rustic sage
#

What type of files do Android Runtime and Dalvik VM execute?

#

guys whats the andwer for this questions

#

@everyone

faint geode
#

Don't tag everyone....

snow gazelle
#

Hey I need a little help in bash scripting. So the module gave me this asks me to: Create an "If-Else" condition in the "For"-Loop that checks if the variable named "var" contains the contents of the variable named "value". Additionally, the variable "var" must contain more than 113,450 characters. If these conditions are met, the script must then print the last 20 characters of the variable "var". Submit these last 20 characters as the answer.

#

And my solution is this:

#

#!/bin/bash

var="8dm7KsjU28B7v621Jls"
value="ERmFRMVZ0U2paTlJYTkxDZz09Cg"

for i in {1..40}
do
var=$(echo $var | base64)
if [[ "$var" == "$value" && ${#var} -gt 113450 ]]; then
echo "Last 20 character: ${var: -20}"
exit 0
fi
done

#

but the answer isn't right. (NVM SOLVED IT)

storm elk
#

Do not click that link. It’s fake

snow gazelle
#

i need a mod

snow gazelle
storm elk
snow gazelle
storm elk
#

Ahh okay! Thanks 😄

#

Next time, just ping [at]serious rule break

snow gazelle
#

okay

storm elk
#

Thanks 🙏

snow gazelle
#

can you give more context

fathom pendant
#

In order to ssh in you need to specify the port

#

Ftp is running internally on that container

snow gazelle
#

also make sure that on that port there is an ssh service

fathom pendant
#

If I'm recalling the exercise correctly: there's an ssh service running on that port that you connect to to then attack the internal ftp service

median gale
#

Would like help on Blind SQL inj module, anyone?

#

Been stuck here too, how did you manage this ?

#

Keep getting this error no matter the payload

lavish jay
#

Any one have any success with question 2 of the the Android Emulators section of Android Fundamentals?

zinc swift
#

hi team
https://academy.hackthebox.com/module/112/section/1067
for the SMB part of Footprinting, i'm not able to get the version of the SMB server. it says to submit the entire banner but whatever i submit it's not taking. i've done all the other questions on the module but for some reason it's not accepting my answer for the version

near orchid
#

hmm

acoustic thorn
#

Without giving it away I believe the format is <suite> <daemon> <version>

#

<samba> <daemon> <x.x.x>

zinc swift
acoustic thorn
#

I've identified a vulnerability in one the modules that requires "make" to compile. In the case of this particular module, the "make" command is not available on the target. Does anyone know of a method similar to gcc --static that would allow me to compile the exploit on the attackbox and still execute it on the target?

lavish jay
#

Any one have any success with question 2 of the the skill assessment section of Android Fundamentals?

barren apex
#

Would like some help on AD attacks & enum skill assessment 2.

#

I'm at the final stage of the assessment, just need a little push

pine phoenix
#

File Upload Attacks -Blacklist Filters module target instance wont spawn

#

Ofc right after I send the message it wants to work

#

Disregard lol

median gale
#

Does anyone know why cyberchef's url encode produces different output from burp's ctrl+u url encode ?

barren apex
#

It's not different, burpsuite encodes spaces as +, cyberchef uses %20 instead

median gale
barren apex
#

Ye, didn't notice that first, I usually do encoding in custom scripts using safeurl encoding

median gale
#

Then again when i try to hex decode it gets only half part correct

quick eagle
#

Hey everyone. What is a good channel for the questions regarding active boxes?

fathom pendant
quasi wave
#

hi for the last question of the Web Server Pivoting with Rpivot section of Pivoting, Tunneling, and Port Forwarding module I got the connection to the server so now it can't load the web page to get the flag. it says "page not found" or whatever. can someone help me? I'm following the instructions exactly

#

I got the connection to the pivot box

#

but the target server on the remote network won't connect for some reason

gray yacht
quasi wave
#

and it does nothing either way

gray yacht
#

You can DM your command if you'd like.

quasi wave
#

ok I will DM you

quasi wave
#

hi if I run a server on 0.0.0.0 is that an issue if that's the IP the instructions use?

#

or do I use the IP of my attack box?

fathom pendant
quasi wave
fathom pendant
#

¯_(ツ)_/¯

quasi wave
#

ok

#

well, that's not my issue then

fathom pendant
#

Thats just what 0.0.0.0 does

quasi wave
#

@gray yacht is helping me with this particular section when he gets home in 30 or less now

#

so I'm gonna wait for him

#

I'll get it working

#

I'm sure I'm generally doing the section right

#

its probably an issue with the section this time and not my fault

#

but we'll see what the issue turns out to be. I'm fairly confident this will be resolved by the end of the day.

#

So I'm not worried. Anyway, I think I'm starting to get it a little more when it comes to the section

quasi wave
#

I got the flag

#

section completed. I knew I was gonna have it finished by the end of the day.

wild rover
#

Hi, I am doing the Pentest in a nutshell module and im stuck on a question if someone can help, its in the windows system enumeration section, its the question that says what OS version doe winpeas report, however the systeminfo.exe is access denied and all the versions ive tried are the wrong answer? can someone point me in the right direction.

mortal linden
#

In password attacks AD module, I created a shadow volume but it seems not to contain the dit. My user is a domain admin. anyone able to point me in the right direction, because for whatever reason it seems like I don't have writers here. Contents of shadow copy set ID: {6170bacc-f91b-4daf-8a41-0315f21f9cb9}
Contained 1 shadow copies at creation time: 4/28/2025 3:15:22 PM
Shadow Copy ID: {cae793b6-cd5c-43fd-b859-aa85df4d53db}
Original Volume: (C:)\?\Volume{da2aad9f-e76b-4d77-a2ee-d53dd4c3c8a1}
Shadow Copy Volume: \?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1
Originating Machine: ILF-DC01.ILF.local
Service Machine: ILF-DC01.ILF.local
Provider: 'Microsoft Software Shadow Copy provider 1.0'
Type: ClientAccessible
Attributes: Persistent, Client-accessible, No auto release, No writers, Differential

zinc swift
dapper moth
waxen totem
zinc swift
#

the command used

dig axrp <FQDN> @<target_IP>

waxen totem
#

axrp ?

zinc swift
#

the FQDN used is the one given on the first question

#

i also did dig any

#

fqdn @ target

waxen totem
#

I don't know what axrp is did you mean axfr ?

zinc swift
#

sorry yes axfr

waxen totem
#

try all the subdomains you find 👀

zinc swift
#

how long does it usually take for the wordlist in the same module to give me the answer?

#

i'm brute forcing with the same wordlist in SecLists

#

dnsenum --dnsserver <target_IP> --enum -p 0 -s 0 -o subdomains.txt -f <list_here> <FQDN>

#

okay so i did it with all of the subdomains but i wasn't able to get the final answer

fathom pendant
#

also; a more fierce list

zinc swift
#

and that doesn't give me the .203 thing

#

i think?

fathom pendant
#

using the right wordlist might help

#

:p

zinc swift
#

i used the same one in the module

fathom pendant
#

use a different one

zinc swift
#

unless i should be using something else?

fathom pendant
zinc swift
#

isn't the 110000 the most fierce one

#

i'll try the 5000 and 20000 one!

fathom pendant
zinc swift
fathom pendant
zinc swift
#

i aint that smart man

fathom pendant
#

😉

zinc swift
#

the service and you winking has me hollering

#

ty friend

topaz ruin
#

I have an extremely basic question that feels dumb, which is I'm on the Windows CLI module and specifically in User and Group management and I can't get the commands to work

Every Active Directory command yields:

Get-ADUser : The server has rejected the client credentials.
At line:1 char:1
+ Get-ADUser -Filter *
+ ~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : SecurityError: (:) [Get-ADUser], AuthenticationException
    + FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.Security.Authentication.AuthenticationException,Microsoft.ActiveDirectory.Management.Commands.GetADUser

Even an initial Import-Module ActiveDirectory ends up with

WARNING: Error initializing default drive: 'The server has rejected the client credentials.'.

I don't think this is intended because the solution sheet just says to do Import-Module followed by Get-ADUser. I tried a bunch of things like start-process powershell –verb runAs and searching, but everything I can find online is like "right click and run as administrator on the client computer then connect to that" (and this module neither covers RDP nor does RDP appear to even be functional on this particular box).

The htb-student user is definitely in the Administrators group. And I even tried scuttling and remaking the box.

fathom pendant
#

windows and even linux CLI handle things in a specific way; as the user shell you are only permitted to do things within a basic user context, not an administrative context

outer mirage
fathom pendant
#

it's why if you want to run around in an adminstrative context; windows requires the shell to be run as admin

topaz ruin
#

how would i accomplish this via SSH? it's why I tried runAs and some Enter-PSSession stuff

fathom pendant
#

as far as RDP not working, that'd be odd but i don't recall having that permission issue when i was running that module

#

the problem with stuff like runas; is that it will attempt to run an interactive window shell with the process

topaz ruin
#

... i figured it out and my error was very stupid
the question was very subtly using mtanaka as the user instead of the usual htb-student but i didnt notice because the password was the same as always and every other step was as htb-student. actually using the correct username fixed the issue lol

hexed oyster
#

Working on the Final Assessment of the Broken Authentication Module. || I enumerated the users and brute forced the password. I'm having problems brute forcing the 2fa pin. Am I on the right track? ||

cloud urchin
#

If brute force doesn't work, think about other things you can try.

calm geode
#

Hi guys,I wanted to try out some modules from cwee and the mobile static analysis course.

Would you guys recommend me buying the platinum or gold sub?

storm elk
#

If you just want to try out a few modules, monthly might be better. Can always switch to yearly.

quiet halo
#

i'm guessing it's becuase it's a service account and not a user account?

quiet halo
#

wow i'm blind

#

one other thing, how can I run an admin cmd prompt if I'm not part of any admin group

waxen totem
#

I think you have SEImpersonatePrivilege iirc

quiet halo
#

even with a admin prompt I dont have that priv

waxen totem
quiet halo
#

maybe the box is setup to where SeTakeOwnershipPrivilege gives me an admin prompt?

waxen totem
#

check whoami /all

#

?

quiet halo
#

I remember seeing a blog saying that even it the priv is disabled, you still have it regardless if it's enabled or disabled

#

idk though, never verified it

waxen totem
safe star
#

they cover how to enable them

waxen totem
cloud urchin
#

which module is this?

#

privesc?

safe star
#

i think you can limit privileges on local accounts

fathom pendant
#

Windows Local Privilege Escalation if i had to guess from the machine name

cloud urchin
#

yeah i think so

#

that's above tier 0 so unfortunately @quiet halo you can't post content from modules above tier 0

quiet halo
safe star
#

i just tested using the Local Security Policy app and a low level user i just made

quiet halo
#

so it's sort of like app locker where it gives you access to specific things?

quiet halo
safe star
safe star
cloud urchin
#

@quiet halo Please stop posting content from modules above tier 0.

safe star
#

@quiet halo the last one

quiet halo
cloud urchin
#

alright

harsh gorge
#

kinda having problems on shells and payloads as eternal blue isnt working for both variants

#

nvm

#

we good

wooden seal
#

Web Attacks {Blind Data Exfiltration}
Not getting the flag even if i did follow the walkthrough (filename & url and my ip is configured correctly)

worldly vortex
#

Anyone know of an easy way to install an older version of PHP in Kali, preferably without having to build from source? working through the type juggling exercises and the PHP versions that come stock with Kali and Pwnbox are too new to work with setting up a debug environment for these exercises

pure seal
#

spray

nova knot
#

hey guys, while I'm trying to submit the plugin ID for "What is the plugin ID of the highest criticality vulnerability for the Windows authenticated scan? " in Vuln assessment - Nessus skill assesment, It's giving me wrong answer

#

i found only 1 high criticality vulberability in the report mentioned but, it didn't work out, I ALSO had to try other plugin ID's but nothing worked

#

also for MODS, "What is the name of the vulnerability with plugin ID 26925 from the Windows authenticated scan? (Case sensitive) " question in the same module should be changed to "Windows basic scan instead of windows authentic scan"

wooden seal
wooden seal
nova knot
#

target IP

wooden seal
# nova knot target IP

i heard people say that some vulns come in when they ran the scan on their own try it maybe

nova knot
#

okay

#

thanks!!

worldly vortex
little terrace
#

Hi, Im starting out the penetration tester job path and was wondering how important is the "penetration testing process" to the final CPTS exam? I understand it provides industry experience on how an actual pen test happens IRL regarding laws, assessments and documents but how applicable is it to the final report? am i suppose to produce every single document?

tranquil axle
potent sandal
#

hey guys whats up i have trouble with Skills Assessment - File Upload Attacks. When i start Burpsuite and sen the POST request to the Intruder and set all Payloads he doesnt give me anything back. I tried it many times. CAn someone help. MY steps which i do is 1. CLearing the Payloasds 2. Marking the §.jpeg§ 3. Copy the Extensions List 4. Removing the URL ENCODE then starting the attack

smoky scroll
#

I have a question regarding the payment of the subscription...is it possible to include a VAT number in the invoice for tax purposes?

acoustic owl
#

@supple star please read #rules

smoky scroll
compact patrolBOT
median gale
#

Could use a nudge for Blind SQL SA, cant seem to find it. Tryied the cookie fileds and the post data on login.php and index.php

distant gate
#

Hey group, does anyone know what could cause meterpreter reverse_tcp error "Failed to load extension: The "stdapi" extension is not supported by this Meterpreter type (x64/linux)" . It works fine when i do it from the PWNBOX but when I do it from my VM with VPN i get the error. THe parrot and msf are both the same version as the ones in the PWNBOX.

opal nexus
#

has anyone managed in ADCS attacks module, to exploit esc7 from windows for a question?

(basically how to run this command:
Get-CertificationAuthority LAB-DC.LAB.LOCAL | Get-CertificationAuthorityAcl | Add-CertificationAuthorityAcl -Identity "blwasp" -AccessType Allow -AccessMask "ManageCertificates" | Set-CertificationAuthorityAcl -RestartCA
where it required elevated powershell (which in the section we do not have)

grim zealot
#

can anyone help me, please, with Nocturnal.htb, what should I do?

median gale
#

manually found tracking id but cant do with sqlmap

winged steeple
#

Is there a good resource anywhere that explains how this algorithm does padding? TLS_RSA_WITH_AES_128_CBC_SHA you'd think if you had 6bytes and you padded with 10 it would be the answer

acoustic owl
median gale
acoustic owl
thorny kraken
#

Hello, i am doing the Network Enumeration module where i have to map a company network without getting blocked which i track with the statuspage. Upon checking the page, i have 50 alerts already and i havent ran any enumeration yet. Is this normal?

median gale
#

Sure did on all the other exercises throughout the module and did exploit the fact that it did to avoid doing everything manually

waxen totem
flint palm
#

Hi Guys I have some kind a technical problem. I am doing Attacking Common Services and I found out that I can't scan their targets from my kali. It shows me that host is down and appears up only using -Pn flag in nmap. More, when doing attacking FTP I guessed the port but I can't connect to the server. I tried out it on their pwnbox and in pwnbox it works fine but not in my kali? What can be the problem?

flint palm
#

no

#

I am working from virtual machine but vpn is their

#

their vpn file

potent sandal
#

It happend to me also manytime so i installed Parrot OS direct and since then no problem more. But manytimes i had this sameissue from the VM and needed to reset the machine and set new VPNS and after a time was it working

#

and take care which VPN is connected sometime i start the lab_machine instead the academy 😄

flint palm
#

No I am sure that this is academy vpn but possibly yes I will kill kali and download parrot os

jolly raptor
#

In the information gathering module, i’m in the skills assessment trying to use go buster for vhost enumeration however it gets like 40% through the wordlist, spits out an error then my network stops working

wanton wharf
#

(Attacking Common Services) Just to point out, providing a resource with a username and password list, but not including the correct password needed for the skill assessment, is honestly crazy kek

dense hearth
#

Hi guys, is Anyone available for a sanity check regarding on MSSQL, Exchange & SCCM skills assessment? I managed to get a reverse shell from DB02. I would like to confirm if I am on the right track. Thanks

fathom pendant
#

don't reveal info for modules above tier 0 @fading olive

#

also: if a user/account is an administrator, they'd have access to administrative commands.

fading olive
fathom pendant
#

since anyone can click on them and reveal it anyway

fading olive
fathom pendant
#

the administrative group that the account you have is a part of has specific access to certain tools; it's intentional access to those tools

fading olive
#

ok ok

#

Also, I had another question which, I hope, won't reveal too much. In the next part which is AEN > Post-Exploitation Persistence, you're supposed to escalate privileges again and you find yourself being able to run a certain GTFOBin as sudo. This GTFOBin is supposed to be able to grant you a reverse shell as root if done properly as per the doc at http://gtfobins.github.io and I haven't managed to do it and I assume that it's impossible since that's not what the module does either, and I wanted to know how you're supposed to find out that you can't use this method? Trying it and seeing that it doesn't work? Or have I just not done it properly?

delicate zenith
#

Have a general question regarding modules. Since I am newish to python / pip/ pip3 /pipx / python3 -m venv.
when kali is a major version some people use and Kali pip install is externally managed, why is there not a walk through as part of the module that shows how to setup the venv or pipx so we can get a "correct process" to work from in the future when we have the "externally managed" issue? for some reason I can't get my head around the venv vs pipx install process

lofty marsh
#

hello guys i was doing a module from tier 0 and got myself stuck in a simple question can you please help me with that

fathom pendant
#

Module - section
Issue

lofty marsh
#

Pentesting in nutshell - windows target- here i was supposed to do a nmap scan of the given target machine, and answer few question and i did but the one question that got me stuck is it asks how many tcp port are open in the given target and as according to the nmap scan there are 9 and on 1 service nmap couldn't detect it really, which makes the answer either 9 or 10 ig but none of that helped me

fathom pendant
#

Did you scan all -p- orts

lofty marsh
#

yep, did exactly as same as given command

#

in the module

delicate zenith
#

is this the correct channel to post questions regarding a specific module in the cpts path? #cpts

fathom pendant
delicate zenith
#

ok thanks. I am having an issue with the oracle tns listener footprinting. I keep getting this error when running odat.py then after this error if I nmap 1521 I get filtered.

fathom pendant
#

I don't see an error here

delicate zenith
#

I tried so should I stop or continue without asking?

fathom pendant
#

Continue without asking

delicate zenith
#

ok thanks

lofty marsh
delicate zenith
fathom pendant
delicate zenith
#

ahh ok thanks

bronze wharf
#

hello guys i need help in this question , i have got the backup.vhd file how to access it ? Examine the third target and submit the contents of flag.txt in C:\Users\Administrator\Desktop\ as the answer. , attack password , hard lab

flint palm
#

Hello Guys I have a question in Attacking Common Services I discovered FTP username but medusa doesn't want to discover a password from the list provided

#

no match

#

what can be the problem>

#

??

#

this is attacking ftp section

harsh gorge
#

Perhaps?

flint palm
#

trying hydra now

flint palm
#

no even the hydra doesn't help

digital pendant
#

am I doing something wrong, clicking spawn target and simply waiting for 20 minutes doesn't feel right. happened the other day and now today

#

anyway to purge existing spawn?

flint palm
#

reload the page and try again possibly the problem is with your connection internet is slow or something but yes their targets are spawning quite slow

#

but if you are waiting for long can be internet connection problem

quartz sundial
#

https://academy.hackthebox.com/module/163/section/1549

Hi everyone!

Could you please help me with this module? I escalated the privileges of the ilfserveradm user to Administrator. Then I tried to run Mimikatz and execute the privilege::debug command, but I got the error:
"ERROR kuhl_m_privilege_simple ; RtlAdjustPrivilege (20) c0000061".
I'm not sure what I need to do next…

tall dome
#

on linux fundamental module kernel release name . I used uname -r command. in my case kernel release is 6.11+parrot-amd64. I submitted following the format specified in the question but still says incorrect. could anybody help me out?

fathom pendant
tall dome
#

okay.Thanks

quartz sundial
quasi wave
#

hi I solved the Port Forwarding with Windows Netsh section of Pivoting, Tunneling, and Port Forwarding on my own. I want to talk to someone and see if my way of solving it was the intended way. Who can I talk to and when?

#

I don't want to spoil the answer if the way I did it was the right way.

quartz sundial
mortal linden
#

And i used vssadmin.exe to create the shadow, which it says it accomplished, but when i try to access the ntds.dit portion, it says objectnot found.

#

but the shadow copy is there : Shadow Copy Storage association
For volume: (C:)\?\Volume{da2aad9f-e76b-4d77-a2ee-d53dd4c3c8a1}
Shadow Copy Storage volume: (C:)\?\Volume{da2aad9f-e76b-4d77-a2ee-d53dd4c3c8a1}
Used Shadow Copy Storage space: 3.44 MB (0%)
Allocated Shadow Copy Storage space: 320 MB (1%)
Maximum Shadow Copy Storage space: 2.33 GB (10%)

mortal linden
#

Meh. I'm giving up on that method. I got it another way, but i'd like to figure out how to do it this way, using the actual utils; seems useful.

digital pendant
#

@fathom pendant

#

re: above... think they slipped through the cracks

fossil shoal
#

Hello. I am stuck on the windows fondamental module. Specificaly, I am not able to setup the SMB share properly.

To do a short story, I just created and share the folder Company Data on the target pc. But when I try to connect to it using smbclient, I get a Timeout error. I tryed using both pwnbox and the vpn with a kali VM same result.

Even weirder, When I try to ping the target machine, I do not get a reply.

When I look online for a solution, I just got the famous "just turn off Client Firewall" answer. I don't think this is a good solution so I wonder what is a better way to solve the lab?

flint palm
#

Hi Guys! Has anyone done Footprinting? What module is focused on? Is it focused on credentials hunting for rdp ftp and other connecting services?

runic plover
#

• Linux to Linux: Use rsync over SSH — it’s fast, secure, and robust.
• Windows to Linux: Use WinSCP for manual GUI use, or rsync with cwRsync/pscp for scripts.

#

Is what I use personally

flint palm
runic plover
#

It’s glorified looking around with ttp’s

#

Anyone looking for a hacking duo of sorts? Possibly doing some labs or pro labs👀

fathom pendant
fathom pendant
#

Thats old news

runic plover
#

Dayum fr? I haven’t been in here in a while. Last time I was you were not mod

flint palm
#

Yeah Marcie I know what footprint is generally just was interested what it means in the module.

runic plover
#

If you have academy do it

fathom pendant
#

I.e. anonymous login for ftp isn't really attacking ftp, it's just seeing what's available to anyone with a network connection to the service

cunning berry
#

hi. i have a file transfer through proxy question. i'm doing RDP and SOCKS Tunneling with SocksOverRDP. i am using openvpn, not pwnbox. once i am inside the internal network, specifically, 172.16.5.19 as victor i am unable to see the files i want to transfer. i initially connected with xfreerdp /drive:tunnel,/home/kali.... option. once i get in the internal machine, i am no longer able to connect to the tscclient, it says the file is empty. when i set up a python3 server on kali to hosts the files and attempt wget or curl, it says it can't connect to remote server. i realize this is a proxy issue, but i'm a little lost. i tried wget 127.0.0.1:1080 and other thing like that. what should i do so i can transfer SocksOverRDP-Server.exe to the internal network?

fathom pendant
exotic rapids
#

Guys I have questions

fathom pendant
#

Also 127.0.0.1 is gonna be localhost

runic plover
runic plover
#

Hello

#

May I say hello Kappa

exotic rapids
exotic rapids
fathom pendant
#

Read and follow #welcome to access more of the server: but you're not gonna get help for active ctfs

#

As a general rule: you're only meant to get help from your team/others participating

cunning berry
compact patrolBOT
#

No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.

exotic rapids
fathom pendant
compact patrolBOT
#

No hints are allowed for the duration of the event. Once the event is over, feel free to share solutions.

exotic rapids
fathom pendant
#

Anyway. It's not on topic for this, or any channel :)) unless I missed a memo and there is a channel for it.

fathom pendant
#

Victor is machine 1 yeah?

#

Iirc this lab is set up;
Attacker -> a -> b -> c

#

Where a is the 10.129 ip

cunning berry
fathom pendant
#

It'd be your tun0 ip

cunning berry
#

yes yes, i know, my point is that i used tun0 and localhost, just in case.

#

tun0 is what i expected to work, but didn't.

fathom pendant
#

If it's the first machine you connect to: it'll have a connection to your host

#

Did you specify port, did you run the python server from the same directory the .exe is in

#

Default python http.server serves it on port 8000

cunning berry
#

its the first internal machine, so victor:pass@123 to connect to 172.16.5.19

#

after using mstsc.exe to connect

fathom pendant
#

Then you'll need to do port forwarding if you want to wget; or do some mstcsc shenanigans to share files

#

Iirc it's under advanced options

cunning berry
#

yes, i tried multiple ports from 80, 8080, 8000 and i always run from the directory the file i need

fathom pendant
#

Port forwarding == telling another (ip) and port to push traffic to another ip and port

cunning berry
#

ok, that's what i was thinking... perhaps some form of port forwarding maybe, it was not able to connect to my computer. was not sure really what i needed to do.

fathom pendant
#

Not dictating what port a service uses

cunning berry
#

port forward through ssh?

fathom pendant
#

Thats possible with -L iirc

cunning berry
#

ok, thanks. i found a really bizarre way to solve this machine without using server tools or any further tools from here. i guess that's all that matters, but i still wanted to try these tools because they are new to me.

fathom pendant
#

most people here with some experience will just tell you to use Ligolo-ng instead ¯_(ツ)_/¯

#

It heavily simplifies a lot of the stuff, and bonus: no dll shenanigans

fathom pendant
#

@solar hedge please don't reveal info from modules above tier 0

solar hedge
#

Apologies. The only thing I had typed out was direction that was included in the module itself, I had thought only indicating solutions was not allowed. What's the best forum to obtain assistance?

fathom pendant
#

You should be doing it blind tbh, learn how to unstick yourself

fossil shoal
mortal linden
solar hedge
fathom pendant
#

If resetting the lab doesn't work then idk what to tell you

#

As a general principle I don't help with that module

solar hedge
#

Did that a few times as well. Will try a fresh look at it tomorrow perhaps, hopefully in overlooking something minor

fossil shoal
fathom pendant
quasi wave
#

hi I solved a section from the Pivoting Tunneling and Port Forwarding module today and I want to make sure I solved it the way its meant to be solved. I checked with @gray yacht but I want to DM one other person to confirm I solved it correctly. Anyone available tonight?

#

or now?

#

this is for the Port Forwarding with Netsh section of Pivoting, Tunneling, and Port Forwarding Module that I did earlier today

vernal tapir
#

Let me check if I have notes with it, give me a minute.

cloud urchin
#

Sometimes there are multiple ways to complete the challenges and there isn't really "one way it should be done"

quasi wave
vernal tapir
#

I agree with that for sure, who knows we could've done it differently, but we can compare 🙂

vernal tapir
#

👍

quasi wave
#

ok so I dmed @vernal tapir how about you @cloud urchin can I DM you?

#

I want to check with a mod possibly. Matthew seems to think I am good.

#

ok matthew solved it the way I did that's good enough for me

#

onto the next section then

vernal tapir
#

He is just fine 👍 (I don't think the mods want to be DMed) but I took care of ya 😄 Carry on with your journey sir, be confident in yourself don't second doubt. If you got it right, doesn't matter which way, it's right!

quiet halo
#

does anyone know the powershell version of this accesschk.exe /accepteula \\.\Pipe\lsass -v

#

I asked deep seek and it gavme the wrong command

gleaming summit
#

I need help please it is bugging me but where can I find the answer to the first question on Components of a Network that reads "What type of network cable is used to transmit data over long distances with minimal signal loss?" because I thought it would be fiber optic cable but apparently that is incorrect and keeps coming up as such so if someone can point out my mistake or point me in the right direction i would greatly appreciate it.

fathom pendant
quasi wave
#

thank you for taking care of me. I think that it would be smart for me to do more work tomorrow on the next section. either way, it looks like I am moving more quickly now for whatever reason.

narrow plover
#

Is there where I'm supposed to ask for help?

fathom pendant
#

for academy modules: yes

#

you can also utilize the search feature in the upper right to see if someone else asked a similar question and had it answered

narrow plover
#

Can anyone point me in the right direction in the Payloads and Shells module - Infiltrating Unix/LINUX, I was able to get a TTY UNIX Shell however I've been unable to find the hostname of the router in the devicedetails directory at the root of the file system. Am i right to assume that I need credentials to be able to access this directory since its the root of the file system? I've also tried other solutions as to trying to find a txt file using $type or $find commands however that came to no avail. Can anyone give me any advice?

fathom pendant
#

you are incorrect in assuming this

narrow plover
#

Can you elaborate please?

fathom pendant
#

also $type and $find aren't commands

#

$ in linux denotes a variable call

#

type isn't a linux command either

fathom pendant
#

when you get a shell you're dropped in as the service account the service is running under

narrow plover
#

I may be wrong in assuming that I can't access it then, I only assumed cause i also can't seem to find the directory. I thought it would be easily seen with ls or dir

fathom pendant
#

with find, if you're searching the root of the file system you will need to redirect the error output to /dev/null

#

as even root will not be able to access certain files

narrow plover
fathom pendant
#

remember the directory you land in when a shell pops isn't going to be the root directory

#

remember with unix systems, / is the filesystem root

narrow plover
#

ohhhhhh that makes so much sense

#

thank you! I just naturally assumed the directory i landed in was automatically the root directory

fossil shoal
fathom pendant
#

also with smbclient on linux you have to do \\\\ip\\share or //ip/share

fathom pendant
#

since in bash, \ is an escape character; so for it to see the \ as \ you need to double up

#

\\ <- this is 4 \

#

escape characters "escape" the shell to do meta-functions, you often see new-line as \n <-- the \ isn't interpreted literally, rather it "escapes" the parsing and does whatever n is designed to do

#

in this case -> new-line (CRLF on windows)

#

and is why \n is counted as "1 character" because it doesn't count the \ as a character

fossil shoal
#

Wait so wen I try to do the lab I need to put 4 \ instead of just 2? why then on the lab they only show 2?

fathom pendant
#

In computing and telecommunications, an escape character is a character that invokes an alternative interpretation on the following characters in a character sequence. An escape character is a particular case of metacharacters. Generally, the judgement of whether something is an escape character or not depends on the context.
In the telecommunic...

#

there is a difference between \ and /; one is an escape character, the other is not

#

they are fundamentally, not the same

#

ah i see the confusion