#modules

1 messages Β· Page 422 of 1

fathom pendant
#

@slender pendant not what this server is about, read #welcome and #rules

gray yacht
#

I have not

waxen totem
#

Yeah, not a good experience πŸ˜…

#

Gave up cos pwnbox was wonky with my bt keyboard and using touch

rugged bolt
#

anyone finished with active Directory Enumeration & Attacks/Kerberoasting - from Linux? in the example you are supposed to use the account forend with the users password to authenticate but there is no mention of the password anywhere?

waxen totem
rugged bolt
#

sure, that makes no difference now

fair harbor
#

Hello people

rugged bolt
spare imp
#

Done

wanton wraith
#

Hi I'm stuck on Web Proxies module -> more specifically the Skills Assessment - Using Web Proxies.

The second question asks: The /admin.php page uses a cookie that has been encoded multiple times. Try to decode the cookie until you get a value with 31-characters. Submit the value as the answer
hint: For the first value try multiple encoders until you get a clear text value.

I'm not understanding the hint properly. When I get the admin cookie why would I try multiple encoders? Shouldn't I just try to decode it? I've already tried multiple decoding styles like trying to decode the cookie into URL decode then using the output and decoding that with Base64 but at some point of doing that over and over, none of the decoders work.

#

I'm also using Zaproxys built in decoder for this task

waxen totem
wanton wraith
#

Im kind of too lazy to figure it out and I did spend a good amount of time on it lol

#

Do you happen to know the order by chance

finite idol
#

If anyone has time to teach me how to hack, send me a direct message!

tight gull
#

hey guys! i just started doing hackthebox and i was wondering how benefitial do you guys find it for someone who wants to work in the cybersecurity field. Is this something i can put as experience on my resume and stuff?

waxen totem
wanton wraith
opaque gulch
#

Hello there

#

in the module footprinting

#

smb

waxen totem
rustic sage
#

hey, did you solve it?

opaque gulch
#

i am asked to retrieve flag.txt

#

howeverm the value of flag.txt is different when viewed on the server then when viewed locally

#

why is that?

#

I can't share screenshots here either, it seems

waxen totem
#

@wanton wraith this might help you out:
Hexadecimal contains: 0-9,A-F
Base64 Contains: A-Z,a-z,0-9,+.=
Urlencoded: %00-%7E

wary wren
#

No

wanton wraith
wanton wraith
waxen totem
wary wren
#

can anyone help me in this As this user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?

wanton wraith
waxen totem
#

HuhNaruto but it gives the same output

#

you using the cookie cookie and not the PHPSESSID cookie?

foggy monolith
#

Is the jump box in the MSSQL, Exchange, and SCCM Attacks skills assessment supposed to straight-up crash every single time Invoke-PasswordSprayOWA is attempted?

wanton wraith
waxen totem
#

-# Unsolicited DM's Will be ignored

foggy monolith
stuck hollow
opaque gulch
#

sure

foggy monolith
#

Is this supposed to be happening every 5 requests? Anyone? @waxen totem ?

ERROR: 20:44:10 brute.go:193: An error occured in connection - Get "https://10.129.231.78/autodiscover/autodiscover.xml": Get "https://10.129.231.78/autodiscover/autodiscover.xml": net/http: request canceled
wary wren
#

i just needed fresh mind

foggy monolith
#

Yes.

foggy monolith
#

I'm still stuck on "What's the password for the account you were able to compromise?" because of how painfully slow the machine has been all day.

#

Also, none of the following password spray attempts work for the first question:

  • Logistics<year>
  • Freightlogistics<year>
  • L0gistics<year>
  • Welcome1

What else could there possibly be?

rustic sage
wary wren
#

xfreerdp /v:10.129.182.186 /u:Administrator /p:AnotherC0mpl3xP4$$ /dynamic-resolution

[23:46:24:506] [14361:14362] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[23:46:24:506] [14361:14362] [WARN][com.freerdp.crypto] - CN = MS01.inlanefreight.htb
[23:46:25:707] [14361:14362] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[23:46:25:707] [14361:14362] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[23:46:25:707] [14361:14362] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[23:46:25:707] [14361:14362] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1
#

why do i get this error

cloud urchin
#

My guess would be because you didn't wrap the password in quotes or didn't wait long enough for the box to spawn.

wary wren
#

oh ye might be

wary wren
vast crest
#

On web requests-POST. I'm not seeing any POST when doing the JSON part. All I get is GET.

cloud urchin
#

Looks like it's working to me, just didn't find any creds.

foggy monolith
cloud urchin
#

I don't know I haven't done that module

foggy snow
#

Are sections still being added within already existing Modules?

#

Pretty sure there are 2 new sections in Password Attacks, or I might just be going crazy

cloud urchin
foggy snow
#

my overall % went down for Penetration Tester path 😦 pain

cloud urchin
#

yay more content though? lol

quiet gust
native sundial
#

Also send the link of that module

quiet gust
foggy monolith
foggy snow
foggy snow
#

is ||1234 5678 9012 3456|| not the correct answer for question 1?

#

getting really confused

#

wait nvm

#

im dumb

quiet gust
#

Look it's in get request. So definitely some predefined data bloated with.

foggy snow
#

Was looking at the placeholder lmaooooo

quiet gust
foggy snow
#

Will the previous modules stay completed if new content is added?

waxen totem
#

@foggy monolith that an invitation to DM?

foggy monolith
charred ice
#

I cross checked the values and everything I have done seems to be working perfectly.

low seal
charred ice
#

I hope this is not the request length

low seal
#

did you check the content?

charred ice
#

Like content of all the responses? For all the 2XX responses I did.

low seal
#

yeah

#

I see

charred ice
#

I think there's nothing wrong here. All the responses looked the same to me. Maybe I making a mistake

low seal
#

yeah you are fuzzing incorrectly.

charred ice
#

oh

#

What's wrong then? I decoded a couple of requests and they matched with the format

crimson leaf
#

Hi all, I am on the HTTP/TLS attacks module and I am a little confused about what a question is asking in section TLS 1.3. Not sure if I am being dumb but it doesn't quite make sense to me.

low seal
#

right now you are fuzzing the encoded cookie.

#

not the value that you decoded from this.

charred ice
#

But if I fuzz the decoded cookie how will I be able to encode and send requests?

#

Because it only encodes the fuzzed part

low seal
#

you got it, you are to figure that out.

charred ice
#

I think I may have got it now. I'll retry

low seal
#

great

reef sonnet
#

is there a module related to JWT attacks?

crimson leaf
charred ice
# low seal great

Okay I finally understood the error. But I still don't know how to encode the entire cookie and not just the part which is being fuzzed.

low seal
#

the way you are doing it in burp is correct, using payload processing.

charred ice
#

Oh wait. I found another way.

foggy snow
#

Does anyone know how the days are calculated within modules / paths? for example the Penetration Tester path being 40 days, is that 40 x 24hr?

crimson leaf
#

Not sure how they estimated it but tbh, its probably not worth thinking about it too much. It's a really low end estimate giving the length of some of the materials

foggy snow
#

tbf not really basing anything on it but just curious

reef sonnet
lost canyon
charred ice
#

@low seal Thanks a lot for the help. Got it πŸ˜‰

#

I didn't know there was a prefix option in intruder

quiet gust
foggy snow
#

No, contact Instagram support for issues relating to lost accounts or passwords

waxen totem
rustic sage
#

Need help on the new module.
What is the password mcharles uses for OneDrive?
Section: Attacking Windows Credential Manager
Module: Password Attacks

#

Issue is, i transfered mimikatz but i cant get myself to administrator access

#

Hint: msconfig UAC bypass

foggy snow
#

Link: https://academy.hackthebox.com/module/147/section/1322
Module: Password Attacks
Section: Cracking Protected Files
I can't seem to crack any of the hashes I found I did ||office2john Confidential.xlsx|| but I'm uncertain of the format I did try crack those hashes but had no success

rustic sage
#

i cant connect to the machines

rustic sage
#

In password attacks, section: Pass the certificate, when i run printbug.py I get this error DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied

#

Here's the command I used: ||printerbug.py INLANEFREIGHT.LOCAL/wwhite:"package5shores_topher1"@10.129.234.174 10.129.234.172||

#

Ok maybe this isn't what i'm supposed to do

#

ok now winrm is killing me

#

fixed!!! woohoo

foggy snow
rustic sage
#

did you pipe the output to a file?

foggy snow
#

yea

rustic sage
#

what command are you using to crack the hash

#

yes this is correct

foggy snow
#

tried multiple with both john and hashcat

#

john --wordlist=/usr/share/wordlist/rockyou.txt conf.hash

#

hashcat -m 0 conf.hash /usr/share/wordlist/rockyou.txt

#

multiple different hash modes with hashcat aswell

rustic sage
#

john should crack that

#

do john --show conf.hash

foggy snow
#

It says DONE session completed but then when I do --show it says 0 cracked, 1 left

rustic sage
#

very weird

waxen totem
#

Please don't share hashes here πŸ˜…

waxen totem
#

both when cracking and when showing?

foggy snow
rustic sage
#

Ok, now i'm completely lost on how to get the certificate from DC01$, if anyone could point me to the right direction it would be appreciated

#

Nothing shows up on ntlmrelayx when doing the printerbug

foggy snow
foggy snow
devout saddle
#

Did anyone else have trouble with the SHA1 hash for Academy#2025 in the new CPTS Password Cracking module?

foggy snow
#

What do you mean trouble?

#

I just used cyberchef ngl

devout saddle
#

I have tried hashing it with sha1 in several different ways, but it keeps rejecting my answer

#

That is really weird. It worked flawlessly with Cyberchef, but not when i try it on my own VM or in the HTB provided VM

#

Thanks!

devout saddle
#

No i did not sadglas

quiet gust
quiet gust
foggy snow
compact matrix
#

anyone else have issues with Print Spooler & NTLM Relaying module

compact matrix
#

nice

#

on the first question?

waxen totem
compact matrix
#

this is what chatgpt said

waxen totem
compact matrix
#

It cant be when its the one that was given to me

#

Slavi123 in the module

rich pulsar
#

I am at a total loss here. I've been running ffuf scans multiple ways and multiple times to answer this question in the skills assessment. Following the hint provided and copy and pasting results I'm getting incorrect answer. Anyone else having this issue?

dark hedge
rich pulsar
#

Attacking Web Applications with FFUF // Skills Assessment -Web Fuzzing

young smelt
waxen totem
uneven obsidian
#

hey all, for the new section Credential Hunting in Network Traffic within the Password Attacks module I recommened you to use Network Miner as well. as someone who comes from the DFIR world i can tell you this would help you in network analysis

dense lava
#

could i get a nudge on nosql injection skills assessment 2? ive got the username but cant get anything from the token πŸ™‚

wicked nimbus
#

Hi everyone, I am in File Transfers module f in section Windows File TRansfer Method. I am unable to get around installing pyftpdlib, tried multiple methods, using pipx , pip3 etc. but end up getting this error , whereas i have installed it successfully

#

Has anyone able to progress beyond this

waxen totem
#

This is not a dating server... go look for a commitment IRL

buoyant torrent
#

i'm stuck at the last question of the pass the hash section, "Using Julio's hash, perform a Pass the Hash attack, launch a PowerShell console and import Invoke-TheHash to create a reverse shell to the machine you are connected via RDP (the target machine, DC01, can only connect to MS01). Use the tool nc.exe located in c:\tools to listen for the reverse shell. Once connected to the DC01, read the flag in C:\julio\flag.txt.". no matter what i did i can't get that damned reverse shell i followed the instruction of the section step by step to no avail. any hint will help and thanks

wicked nimbus
gray yacht
#

You can DM if you are having issues

wicked nimbus
#

Cool, i just had a glance of your screenshot, let me try

gray yacht
wicked nimbus
#

Medium is Tier 1 ?

gray yacht
#

All good

rustic sage
#

I cannot for the life of me get this ntlm relay attack to work

gray yacht
rustic sage
#

Password attack > Pass the certificate

golden saddle
#

apparently everyone is on password attacks rn lol

gray yacht
rustic sage
gray yacht
# rustic sage yessir

I haven't done it, but you can DM what you are trying and maybe something will stick out. Might be as simple as running something as root.

rustic sage
#

alright, will DM you

faint hamlet
#

I just want to ask, what was the point of providing Snaffler and PowerHuntShares in Credential Hunting in Network Shares in Password attacks? Or were they useful to someone else and I am the odd one?

rustic sage
#

I remember using powerhuntshares I think

#

but they weren't useful perse, just wanted to learn a new tool

signal hound
#

Hi im doing documentation and reporting module -> "how to write up a finding"
And im not sure what is my assignment

vital storm
#

Hello, guys

#

I am in the skills assesment module of the shells and payloads module, wh th rovided foothold machine doesnt have a browser ?

vital storm
gray yacht
fast torrent
#

very noob question but just been thru nibbles and curious to know if anyone found other ways to exploit it apart from ways mentioned in the walkthrough?

fathom pendant
#

nibbles is a retired box and you can ask in #boxes; i understand it's part of the getting started module -- but your question goes beyond the scope of the module

fast torrent
#

my bad - just started using the discord, will ask there

foggy monolith
#

How did you get MSSQL sysadmin? Domain user has no impersonation rights, all databases are owned by sa rendering the trustworthy databases method useless, attempting UNC path injection gives you the hash of a machine account, and attempting to relay the hash from one machine to the other causes an untrusted domain error.

signal hound
gray yacht
fathom pendant
#

imo the better writeup opportunity is in the AEN lab; doing it blind and performing a writeup

robust pecan
#

Good afternoon, guys. I'm on the Practice Lab of the Documentation and Reporting module. I'm enjoying this module a lot, however, I noticed it is painfully slow. I've tried connecting through Pwnbox and my own Kali VM. Is this normal? Is the CPTS exam equally slow?

gray yacht
reef sonnet
#

have anyone done command injection skills assessment? I would like to see how yall did the task, i tried to do it in both ways manually, but the second way(reversing the string) did not work.

vernal tapir
#

Hi, I'm on Windows Priv Esc Skills 1 and I've gained shell access as a low-priv user, my next question wants me to find a file that I've exhausted so many tools looking for. I'm not sure what to do (Should I skip enumerating and just attempt to escalate privileges then re-try after?)

gray yacht
vernal tapir
#

That started to really confuse me, knowing low-users won't find much at all

echo roost
#

Windows Lateral Movement Server Message Block (SMB) question #2 Use any tool to get a shell on SRV02 using the service Application Layer Gateway Service (ALG) and read the flag located at C:\Flags\serviceflag.txt: I am able to edit and ALG service with a payload but when I start it I get this error. I tested the payload on a dev machine and it work fine via smb guest access. It won't work when I start the service. Did anyone else have this issue?

#

The payload it there and works but it won't fire when I start the ALGservice.

#

Here is the annoying part I went a step further and just cracked the hash of the user the service was running as to login as that user and get the flag. That's not how it suppose to work but it worked. #hacking

echo roost
gray yacht
vernal tapir
grizzled atlas
#

I'm also witnessing some struggles with this question aswell. I am creating a wordlist with mark white information and trying different rules and etc.. Nothing seems to stick

stuck hollow
#

takes time

#

and patience... a lot XD

grizzled atlas
stuck hollow
#

if you want dm and we take a look what you are doing

grizzled atlas
sage void
#

I’m stuck on one of the new modules Attacking Windows Credential Manager . I’m not quite sure what the hint means but I’ve got mimikatz on there what step am I missing

#

I can’t get the Creds with mimikatz or lasagne

#

Lazagne

tacit ore
#

is there a way to check if my rev shell is correct? im following step by step yet i made a mistake im sure. i've been stuck for atleast 1 hour now.. im working on Nibbles, came as far as uploading my rev shell, i also set up NC to listen, HTB says: go to the URL to start the shell, wich i do, but i do not get any response on my listening port. anyone that could have a quick look or might know whats going on?

faint geode
thin citrus
#

When I ran the debugger from code_timing_users webapp I get the following error: **'from Helper import send_email' ** 'Whitebox Attacks - User Enumeration via Response Timing'. Is this normal for this application? Also the zip package does not contain 'instance/users.db'. So I cannot run the app locally.

tacit ore
crimson leaf
#

Has anyone done the HTTPs/TLS attacks module? I don't understand the last question within the TLS 1.3 section so I can't finish the section.

rustic sage
#

htb-student@nixfund:/var/mail$ cd /var/spool/mail/htb-student
-bash: cd: /var/spool/mail/htb-student: No such file or directory
htb-student@nixfund:/var/mail$

#

In operating systems

silver knoll
#

Doing Page 13 Attacking EAP-TLS Authentication of the Attacking WPA/WPA2 Wi-Fi Networks Module, in this section i am being asked to set up a wifi portal to capture credentials. the questions then ask what the password and username was but how the hell im i supposed to know that when I need to type in the credentials?

radiant abyss
# faint geode DM. EDIT: SORTED

Hey can you DM how you solved this? Is there a bug in this section? I cant use msconfig because I am not a local admin and also I cant manually back up because I cant press ctrl alt delete while rdp-ed

weary torrent
#

hey everyone, is there no browser in the shells&payloads live engagement skills foothold machine? Are we supposed to use only the command line?

crimson leaf
#

There should be a browser

wary lynx
#

Hi, Does anyone know if there is a module in the academy that talks about resource based constrained delegation ?

fathom pendant
#

Probably one of the higher tier ad modules in CAPE

paper marten
#

Can someone help me please

#

If you can dm me

fathom pendant
#

We can't help with what you want @paper marten what you want is illegal, read #rules

karmic aspen
#

Hello

weary torrent
hexed oyster
#

got it!

#

I definitely need to invest in the labs...

short vigil
short vigil
glacial remnant
#

looks like Password Attacks recently updated and Credential Hunting in Network Traffic has a question

"The packet capture contains cleartext credit card information. What is the number that was transmitted?"

im 99% sure I have what its looking for and tried the format in the pcap, putting in the digits only and adding hyphens however it still is giving me the red shakes. anyone get this one and able to tell me if its a format issue or maybe i did in fact miss it?

#

never mind have no idea what i did differently this time other then copy the field in wireshark as opposed to just highlighting the text.

fathom pendant
#

i.e. ssh 'david@inlanefreight.htb'@ip -p 2222

#

this is typically because on domain joined linux machines; the format is user@domain instead of the windows domain\user

short vigil
weary torrent
#

For the first question of the live engagement of shells&payloads, I have found the answer by browsing to the ip-port:8080 and used creds to log into admin page. There at the bottom was the hostname. Is this how we're supposed to find this answer? It felt off

fathom pendant
#

that's one way to get the answer

#

there's not always a singular method to achieving an answer

harsh latch
#

Hello fam,
I'm a newbie here in HTB and as I was doing Linux fundamentals. I'm seeing that those exercises at the end of the module are super tough. I wanted to know if there is some way to know the answers to those questions with explanations

weary torrent
fathom pendant
#

you can utilize google to format queries like
"How do you do X in linux"

harsh mauve
#

Can someone help me on **Active Directory Enumeration & Attacks ** - Privileged Access:

With question 1, I tried to run the query from foothold machine (ACADEMY-EA-MS01) and only got 1 result in return. I also ran sharphound and uploaded the ingest data into BloodHound, but the query provided didn't work. Am I supposed to be running the query from ACADEMY-EA-MS01 or am I missing something?

cloud urchin
harsh mauve
harsh mauve
#

Do I need to be running as another user? I'm just running under htb-student

weary torrent
# fathom pendant hint: war

can i dm you? I was able to solve both questions about host 1 but I need a nudge to find the hostname via msfconsole cuz I can't seem to make it work

grim frost
#

i want to learn to hack guys

compact patrolBOT
stiff sequoia
#

HEY I NEED HELP WITH SOEMTHING

weary torrent
#

don't ask for illegal stuff

grim frost
weary torrent
# grim frost wym

were you asking that question for charity purposes? what do you mean wym

rustic sage
weary torrent
stiff sequoia
#

Can some one help me out here ?

fathom pendant
fathom pendant
fathom pendant
rustic sage
#

thanks

split hound
#

Hi! im new to hackthebox, and im having trouble with one of the intro modules. (hope this is the right place for this)
the http module has an exercise where i demonstrate curl, and im successfully downloading the file i think? but all thats in it is an error message about it being moved permanently. not sure if i did it wrong, or if its something im supposed to trace further?

cloud urchin
split hound
#

module 35 section 219, according to the url

cloud urchin
#

better to name it no one's gonna find it that way

split hound
#

is it web requests for the name? or hyper text transfer protocol

#

or smth else?

cloud urchin
#

that's the web requests module, the hypertext transfer protocol section

#

what command did you use?

split hound
#

i also tried with https:// and :80 after .com

cloud urchin
#

the -O option tells it to save the file

split hound
#

ya

#

so i cat the download.php

#

and its just an html script that says it was moved permanently

cloud urchin
#

try without -O, also you don't want to target inlanefreight.com, you need to target the IP:Port provided when you spawned the target

split hound
#

ahhhh ok will try. i sadly killed the spawn since im still on the free trial, so ill have to try it tmr. thank you for your help

cloud urchin
#

not the pwnbox

#

the target at the bottom

waxen totem
fossil kestrel
#

Hello guys, Im new to this also. I seems to have a problem when I downloaded the parrot in Virtual box. It says " Command <i>/usr/sbin/bootloader-config</i> failed to finish in 600 seconds
There was no output from the command.

waxen totem
fossil kestrel
#

Oh sorry, Its part of the hack the box guide so I decided to ask here. and also I dont know where the discord link of that

dense lava
fossil kestrel
#

Thank you much

tall saffron
#

hi guys!! anyone who can check the lab for "HTTP Response Splitting" and can make a sanity check wether the admin visit the link because i have the payload working for me and i know how to write the admin cookie without an external server but get nothing back, i tried double and triple encoding, still didnt worked

drifting copper
#

hello guys i am leamring operating fundamnetals but i think it will not be enough if u have some video of it can u pls share

wary wren
#

can anyone say why i keep getting this error
smbclient //dc01/C$ -k -c ls -no-pass
when i try to access domain share

gensec_spnego_client_negTokenInit_step: gse_krb5: creating NEG_TOKEN_INIT for cifs/dc01 failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
session setup failed: NT_STATUS_INVALID_PARAMETER

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

strong vector
#

ik its dumb, but my english isnt good and i cant understand the "Firewall and IDS/IPS Evasion - Medium Lab" in the network enumeration with nmap, im really stuck and i need a hint, and also i dont want to google the answer

wary wren
strong vector
#

yeah

wary wren
#

what does dns port runs on

strong vector
#

53

wary wren
#

adn what it uses tcp or udp

strong vector
#

both

wary wren
#

most common

strong vector
#

can i dm u?

wary wren
#

sure

#

can anyone say why i keep getting this error
smbclient //dc01/C$ -k -c ls -no-pass
when i try to access domain share

gensec_spnego_client_negTokenInit_step: gse_krb5: creating NEG_TOKEN_INIT for cifs/dc01 failed (next[(null)]): NT_STATUS_INVALID_PARAMETER
session setup failed: NT_STATUS_INVALID_PARAMETER

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

hidden furnace
#

Hello, need help on Active Directory Enumeration & Attacks, ACL Abuse Tactics section. I keep on getting user/domain not available in powershell

native sundial
#

It's a good modules ,everyone should try it

wary wren
#

sure

west arrow
#

On the AD skill assessment 1, on the target IP there used to be port 3389 open and now doesn't matter how many times I spam the box It isn't open, any idea why ??

inland oak
#

hi..
I want to asking about module Information Gathering - Web Edition / Web Archives - the question is "How many members did HackTheBox have on the 10th June 2017? Answer with an integer, eg 1234." ..I tried using WayBackMachine , but the asnwer is not the. anyone can help ? maybe for hint . please

opal basalt
inland oak
inland oak
#

ok . i got it . hehe

dense lava
#

im still stuck on the skills assessment 2 for nosql injection if anyone can help, have the username and have found the second injection point but cant find a payload that works πŸ™‚

wary wren
#

Error detecting the version of libcrypto
I get this while running gettgtpkinit.py in pwnbox any help its from i also installed library oscrypto but still doesnt seem to work.
Its from pass the certificate section.

zinc halo
#

hi im doing the new credential hunting in network shares for password attacks, can i get some hints for the first question? not sure how i am able to just look for a credential in that huge output, thanks!

wary wren
#
└──╼ [β˜…]$  python3 gettgtpkinit.py 
Traceback (most recent call last):
  File "/home/htb-ac-1518820/PKINITtools/gettgtpkinit.py", line 19, in <module>
    from oscrypto.keys import parse_pkcs12, parse_certificate, parse_private
  File "/home/htb-ac-1518820/PKINITtools/.venv/lib/python3.11/site-packages/oscrypto/keys.py", line 5, in <module>
    from ._asymmetric import parse_certificate, parse_private, parse_public
  File "/home/htb-ac-1518820/PKINITtools/.venv/lib/python3.11/site-packages/oscrypto/_asymmetric.py", line 27, in <module>
    from .kdf import pbkdf1, pbkdf2, pkcs12_kdf
  File "/home/htb-ac-1518820/PKINITtools/.venv/lib/python3.11/site-packages/oscrypto/kdf.py", line 9, in <module>
    from .util import rand_bytes
  File "/home/htb-ac-1518820/PKINITtools/.venv/lib/python3.11/site-packages/oscrypto/util.py", line 14, in <module>
    from ._openssl.util import rand_bytes
  File "/home/htb-ac-1518820/PKINITtools/.venv/lib/python3.11/site-packages/oscrypto/_openssl/util.py", line 6, in <module>
    from ._libcrypto import libcrypto, libcrypto_version_info, handle_openssl_error
  File "/home/htb-ac-1518820/PKINITtools/.venv/lib/python3.11/site-packages/oscrypto/_openssl/_libcrypto.py", line 9, in <module>
    from ._libcrypto_cffi import (
  File "/home/htb-ac-1518820/PKINITtools/.venv/lib/python3.11/site-packages/oscrypto/_openssl/_libcrypto_cffi.py", line 44, in <module>
    raise LibraryNotFoundError('Error detecting the version of libcrypto')
oscrypto.errors.LibraryNotFoundError: Error detecting the version of libcrypto
(.venv) β”Œβ”€[eu-academy-1]─[10.10.14.71]─[htb-ac-1518820@htb-ks9ets2vuh]─[~/PKINITtools]

Hey can anyone help me in this

west arrow
#

Just found out that runas isn't really opening cmd as the target user, but i don't know why

tall saffron
#

hi guys!! anyone who can check the lab for "HTTP Response Splitting" and can make a sanity check wether the admin visit the link because i have the payload working for me and i know how to write the admin cookie without an external server but get nothing back, i tried double and triple encoding, still didnt worked

tall saffron
#

for local stuff you are limited by your user right

west arrow
#

well thats confusing because in the dssync module they do that

tall saffron
#

you can dcsync since it is remote auth

faint rampart
#

Hello, working on this module https://academy.hackthebox.com/module/22/section/157
one of the questions asks for users with unconstrained delegation enabled and is a protected account, I used this ldap filter: ||'(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=524288)(adminCount=1))'|| with windapsearch, also tried >=0 but it returns no output, excluding the adminCount for protected users returns 3 accounts. any reason why? or is this intended for the environment?

west arrow
fiery berry
faint rampart
# fiery berry Hi, `windapsearch` has some built in options you can use instead of ldap queries...

Heyy thank you! I tried this earlier just wanted to play with filters, so the issue is this doesnt find the answer, the source code of the tool basically doesnt treat protected users as privileged users because it adds a couple groups to an array and only finds users within
I pretty much just looked into the DN of protected users and crafted an ldap query to find users there who also have unconstrained deleg rather than guessing which of the 3 is

cold star
cold star
young smelt
#

Has anyone completed the new Skill Assessment in the Password Attack module? Can't jump from DMZ to internal network...

gray yacht
young smelt
gray yacht
bronze lodge
#

stuck here for an hour xD

gray yacht
wooden seal
#

Linux PrivESC skill assessment
getting this when trying to connect to target : Connection reset by 10.x.x.x port 22

thin citrus
#

Can someone help me with Whitebox Race condition. I dont get 10 redeem codes with the second function that should be vulnerable.

gray yacht
austere hound
rustic sage
#

.

maiden sigil
#

Any advice on OPTIONS verb tampering?
Both curl -i -X OPTIONS or burpsuite tampering don't seem to return an allow header. Working on AEN currently, but recall having the same issue in the tampering module.

fathom pendant
#

sometimes OPTIONS just isn't configured/allowed

maiden sigil
#

For sure, the writup says the dev sub should be responding to it. And I do get just the full page returned otherwise, not an error about using options.

fathom pendant
#

try without -i?

#

Β―_(ツ)_/Β―

#

i don't really recall too many issues with AEN tbh; but i also didn't really follow a walkthrough/guide

#

i just went through it blind - not answering the questions nor reading the content

maiden sigil
#

just get the html body alone without.

For sure, and I was going at it blind, but just ran against a wall. Finally looked to see it recommended there. And the verb tampering is supposed to lead to other disclosure. Idk, I remember having the same issue during the verb tampering module originally.

Ah, well. Keep playing with it. Appreciate it.

fathom pendant
#

OPTIONS isn't the only other verb

#

try other standard verbs Β―_(ツ)_/Β―

maiden sigil
#

For sure, and I had done a few of the others to no real effect. It's been driving me bonkers haha, why I ended up looking at the write up which says it should respond to options to get further.

tiny frigate
#

I'm having one of these days again where RDP is just infuriating. I'm working on the final exercise in "Shells&Payloads" where you connect to the target through a jump host. so PwnBox 'xfreerdp' --> jumphost (Parrot) --> target
My problem is that I just cannot find a good way to have that window that opens up for RDP in a usable size / resolution
I've tried dynamic-resolution, -gfx, anything to make the task bar of the jump host fit on my screen. Just can't get it to work

Usually, when it's a windows host, I make due with the windows key somehow, but here I'm not able to switch between windows on the jump host. Like, I minimzed Firefox while setting up the payload and the netcat listener, but now I just can't get them back πŸ˜…

fathom pendant
#

unfortunately the jump host doesn't have a dynamic resolution it's a static resolution

tiny frigate
#

alright, I'll try to find some other way to switch between windows there then. Or just gotta be reeeeally careful not to minimze anything that I might need again πŸ˜‰

onyx lion
#

hello guys , i finished a module and want to share it to linked but when clicking a share it pop up a window of my linked but without nothing .just the home

#

home mean feed

coarse leaf
#

Hi All, can you help me with Obtain the flag by getting the CEO banned from their own website- i dont see the flag

gloomy stump
#

Hello, can someone help me with File Upload Attacks - File Type filter? I found the extensions that seem to work, but the php shell doesn't work.

somber bison
#

Hey so, i was doing the enumerate all ports and service with a flag, and i found the flag yet i dont know what to copy

#

theres the long algorithm of letters and numbers but theres also htb and ||220||

somber bison
#

Do i still need to use tcpdump or is this it

safe star
#

Not sure what module your on

#

Was that the last question on the page?

somber bison
#

yeah im on nmap

hardy sandal
#

how do I get access to general. I don't have the HTB - Noob role

somber bison
hardy sandal
#

ah okay thanks

somber bison
storm elk
rustic burrow
#

Hello! I'm quite new to all of this and I'm trying the Getting Started Module, but I'm completely stuck on the Nibbles - Privilege Escalation. Anyone kind enough to give a hand that I can pester via DM?

crude halo
#

Anyone have any advice for 2nd question of credential hunting in network shares?

echo roost
#

Windows Lateral Movement Winrm - Connect to DC01 as Leonvqz and read the flag located at C:\Users\Leonvqz\Desktop\flag.txt I cannot get to DC01 using winrm anyone available to assist?

somber bison
#

I put the htb flag for Nmap Enumeration section Nmap Scripting Engine and well it told me im wrong

waxen mirage
#

Hello! I have problem with "Password Attacks / Introduction to John The Ripper", Question is: "Use wordlist-mode with rockyou.txt to crack the RIPEMD-128 password."

Which hash needs to be hacked? Is it the same one from r0lf or another one?

somber bison
#

2 minutes of life left.. its so over

crude halo
#

Anyone elses netexec smb for credential harvesting just stop working and error out? ive added timeouts but doesnt seem to fix it

outer plinth
#

Hello,
could someone help me out
its not accepting anyyy answerr?

fathom pendant
#

if it's not accepting "any" answer, have you considered your answer is incorrect

#

it also helps to provide the module and section name

outer plinth
#

yess i did soo i tried evryhting from 1 to 100 soo um yaa

fathom pendant
#

you shouldn't be guessing

#

try refreshing the page and inputting the answer if you believe you did it properly

outer plinth
#

i wasnt i tried using all commands i knew i was getting the ans to be 12

fathom pendant
#

it's definitely not 12

chrome cosmos
#

Has anyone completed the updated Password Attacks Skill assessment?

fathom pendant
#

read the question carefully; it's asking for the number for the entire system

#

not just within /etc/ as per the example

outer plinth
#

yuppp i did

fathom pendant
#

are you sure you're ssh and your terminal states htb-student@nixfund$ ?

#

because i just loaded up the lab and got the expected answer, and it's definitely not 12

#

they're talking to me not you regarding my questions of what they're doing
also don't spoil things

outer plinth
#

ill try disconecting and reconnecting again

fathom pendant
#

share the screenshot here

#

or share your command here

chrome cosmos
#

Opps my b

fathom pendant
#

if you need to specify help using a user, best practice is to do the Initial * method, I.E. B* R* (Bob Ross)

chrome cosmos
#

I see, thanks!

outer plinth
#

yes it workedd noww before ig it wasnt loading all of the .bin files or somin

chrome cosmos
#

Has anyone finished || Password attacks skill assessment (updated version)||. I’m currently on ||the dmz account for B* J*||

chrome cosmos
gray yacht
chrome cosmos
lethal atlas
#

ANyone online who have completed Windows Privilege Escalation? Im stuck on Citrix breakout. I am to the point where I am supposed to run PowerUp.ps1 but I get an error that it cant be loaded because execution of scripts has been disabled.

gray yacht
# onyx lion Anyone?

If that isn't working, maybe copy the sharable link and use it in a post on LinkedIn if that's what you are trying to do.

gray yacht
lethal atlas
gray yacht
crude halo
#

anyone have any issues running printerbug.py? and getting error lines with ntlmrelayx?

tired bough
#

reposting cuse posten in wrong chan

Hey! so I just noticed something.

I have been having a heck of a time trying to get reverse connections to work with HTB. I use a kali VM on my home computer and connect through Openvpn to htb. Whenever I have done modules that require a reverse connection (HTB target connecting to my machine) even though I use the IP address given to me by OpenVPN, it will not for the life of me work.

I cant even ping my own machine from the HTB target using the IP address given.

I just started the server side attacks module and am doing the SSTI lab. What i noticed was after putting in the payload into the simple test server, it gives my response, but i also noticed its showing me "Your IP" then an address.

I noticed that IP address is completely different then the one given to me by OpenVPN

Is your address not actully the one that OpenVPN lists under tun0? and if not, how do i find the correct one to use.

#

it works fine through the pwnbox but never works on my machine

#

it almost looks like the one on OpenVPN is the network address cuse it has never changed whenever i connect

cloud urchin
#

Revshells are going to connect to your HTB VPN IP, tun0. You can also just use 0.0.0.0 to listen on all interfaces, but the revshell will need to connect to your VPN IP.

tired bough
#

hmmm

#

cuse yeah iv tried that over and over and i cant get it to ping my tun0 address

#

its so weird

#

im thinking it might be vmware but im still trying to figure that out

#

threw me though when i saw a diff IP

cloud urchin
#

if you can reach the target it should be able to reach you.. don't see why not since it has to send packets back to your machine if you're successfully communicating with it.

tired bough
#

yeah i really dont get it

cloud urchin
#

could you be creating the revshell incorrectly maybe? or not doing a step right?

tired bough
#

iv got my own home lab and tested it on my local network and it worked fine. Same with when i tried the pwnbox

#

it seems whenever i VPN in i cant get it to function

gray yacht
tired bough
#

nope

#

i have vmware set to bridged

gray yacht
tired bough
#

ooo i havent tried that

cloud urchin
#

Yeah that's likely your issue

tired bough
#

k cool ill give that a shot and see what happens

#

was driving me nuts lol

chrome cosmos
#

Anyone else having issues accessing ||file01|| from ||dmz01|| ||(password attacks skill assessment||. I already have the creds for || H* W*|| but can’t access any other internal machines

gray yacht
chrome cosmos
uneven lava
#

can anyone ping at the machine of Windows Privilege Escalation Skills Assessment - Part I? it seems unreachable

magic mango
#

i need some help understanding the footprinting lab-hard.
with the services that are showing how would you know to try differnet ports, even looking at the top 100 for the open UDP ports? also, going off what information that's given back i dont see anything that would suggest community strings to use for enumeration? what am i missing? what am i doing wrong?

crude halo
#

Anyone run into this issue with impacket?

#

specifically the ntlm-relay

magic mango
#

anyone around to help Ben and I?

gray yacht
magic mango
#

I'll try again tomorrow, I know it's late for some

waxen totem
# magic mango i need some help understanding the footprinting lab-hard. with the services th...

If you cant find anything, cant hurt to scan UDP. I make it a point that if I dont find what I expect I scan UDP. For instance if I see a TTL of 127 which would indicate a windows target but find ssh... something is a bit iffy.

In the SNMP section of that module community strings is what is mentioned as the enumeration for SNMP. You can even UDP scan only port 161 (SNMP), an easy way to remember this is the One-sixty one tool whose name is based off the port. This and 53(DNS) are the two most common UDP ports so it makes sense to only scan these two ports if you're short on time

magic mango
waxen totem
# magic mango Greatly appreciated. Its not a short on time thing, it's more the experience and...

Enumeration is king, try to find as many avenues as possible before going down a route. That being said it can slow you down which is why for competitive situations like HTB seasons a lot of people for-go slow scans such as UDP. They can do this because of experience and knowledge. However in a real engagement you would try to find as many vulnerabilities as you can provided that you meet the client's evasion requirements and don't perform any enumeration that may break their systems(unlikely, you're more likely to break something while exploiting)

old lake
#

dm me if u can

cloud urchin
#

@old lake No. Not what this discord is about.

old lake
#

oh shit

#

mb i’m a bit of a idiot

#

sorry

rugged flax
#

Hi I've just started learning linux shell and I was wondering how I would connect with ssh to "htb-student" with the password like it says?
I tried ssh htb-student@127.0.0.1 which is the ipv4 address shown in the command ip addr but it says Connection refused.

#

Any help is appreciated

#

I'm a bit of an idiot I just started learning this stuff haha

cloud urchin
rugged flax
#

Oh wait by the way I'm using the parrot OS htb virtual machine maybe that's why

#

Am I like required to use the pwnbox for this?

cloud urchin
#

are you connected to the VPN?

rugged flax
cloud urchin
#

You use the command openvpn. openvpn <file you downloaded> then background it with & at the end and you can close the terminal, or just leave the terminal up.

rugged flax
#

How would I navigate to the file in the linux terminal for the <file you downloaded>? because I don't see it anything in downloads in the linux file explorer

#

Would it be somewhere else?

cloud urchin
#

wherever you downloaded it to

#

browsers usually have an 'open file location' feature

#

in kali it's usually ~/Downloads

rugged flax
#

I'm using parrot os

#

There's nothing in the vm file explorer that's in my actual computer's file explorer

cloud urchin
#

I don't use Parrot so I have no idea the folder structure

rugged flax
#

ah

cloud urchin
#

Do you have a GUI in your VM?

#

you should have the full desktop experience

rugged flax
#

Yeah I do

#

The file explorer looks pretty much the same as my normal windows one but without any of my files

cloud urchin
#

look in your browser's settings for the download location maybe

rugged flax
#

No like I know where I downloaded it to on my computer I can see it in my file explorer

#

It's just that my virtual machine doesn't have any of the files that are on my normal computer

#

Is it supposed to?

cloud urchin
rugged flax
#

OHH it worked I'm stupid

#

well now there's another problem I believe

#

oh nvm I think I fixed it I just had to write the command as root

storm elk
rugged flax
#

It is not letting me type anything did I do something wrong?

fathom pendant
cloud urchin
#

Your password isn't visible when you type

fathom pendant
#

it is taking your input, it's just not displaying

cloud urchin
#

Just believe and type

rugged flax
#

Ohhhhhh I see that's pretty cool lol thanks

fathom pendant
#

ctrl+shift+v

wooden seal
#

linux skill assessment keeps Connection reset is this a target sided problem?

cloud urchin
#

You can always try changing servers or regions and seeing if it's more stable

dense lava
#

I am once again asking for your help on nosql skill assessment ii, I have found the second injection point (I believe) however I cannot find a working payload

somber bison
#

I was on nmap enumeration NSE section and i got the flag yet it marked it as wrong it was HTB{and then a long hash}

cloud urchin
#

probably a flag for someting else or you have an extra space or something

woven valley
#

This is my medium account please follow and read my write ups

#

Need support

acoustic owl
#

@woven valley This is not the channel for advertising. Please read the rules

woven valley
#

Ok my bad

#

Sorry !..

dense lava
#

please anyone

rustic sage
#

Does anyone have video about " how to access dark or tor browser" ?

cloud urchin
waxen totem
# somber bison oh come on

That module reuses the same target for a few sections so you might find a few flags from following sections

crimson leaf
#

Hey folks, stuck on this HTTPs/TLS Attack module: https://enterprise.hackthebox.com/academy-lab/46638/11460/modules/184/1947

Trying to supply the encrypted_premaster_secret for the bleichenbacher attack from wireshark, however whenever I do, regardless of the format, I get a response that Certutils could not extract the public key. Am I doing something wrong or is the tool just kind of broken in my environment?

austere grail
#

in the skills assessment for the windows fundamentals module. my machines life ended and i had to open a new one

#

and now all SIDs I get are wrong

#

even though i am sure it is the right answer

#

what do i do?

leaden rampart
#

module/112/section/2117
The machine is not stable. Sometimes, it responds. Sometimes, it does not. I have reverted it multiple times.

stuck wolf
#

im having the same issue on module/77/section/726

#

keeps saying host is down, i've tried resetting it multiple times as well

leaden rampart
#

yeah. it has been happening for a few hours already. i have restarted my machine, reconnected the vpn. and tried everything. sometimes, the machine responses to Ping and sometimes it does not

stuck wolf
#

i think ill just wait for a while and try again later

storm elk
#

Please don’t just mention the module and section number. Nobody here is a phone book that remembers them

#

Say their names

quaint cliff
#

Hello. In the module "crackmapexec", I was trying to execute command from my exegol with netexec but didnt get any output. I put the output of the --debug option

#

it worked on the htb instance but not on my machine, despite resetting the vpn. and the --get-file didn't worked on either of them

rustic sage
#

Can anyone help me with account recovery I actually lost my friends valuable accounts (i can give my main account if you want and my chess.com account) I lost his account bye clicking to a link. Please help me he is not talking to me. I tried talking to other hackers but they need money and they didn’t help me { this may look fake but it’s the truth please help me)

crimson leaf
quaint cliff
kindred crystal
#

"Hey, I want to disable auto payment from my account and also remove my credit card details. How can I do that?"

thick ore
crimson leaf
shadow moon
#

Where can I ask for help about a module from the academy?

#

I'm currently working on the "Using a Web Proxy" module from Hack The Box, specifically the section involving Burp Suite Intruder. The objective is to discover a .html file under the /admin directory, but despite trying multiple payloads and common wordlists, I haven't been able to identify the correct file or get any valid responses.
I've used Burp Intruder with different file name variations like flag.html, index.html, admin.html, etc., and tested multiple positions and methods (GET requests, URL encoding, changing headers), but every attempt returns a 404 or no useful response.
Is there a specific technique, payload format, or Intruder configuration that I might be missing here? Any hints would be appreciated β€” I’ve been stuck on this for a while.

quaint cliff
#

from there you can walk backwards and find why it failed with Intruder

#

I would use big.txt from seclists/discovery/web-content/ to ensure the wordlist contains the right word

shadow moon
#

@quaint cliff thank you very much for your help!!!

sacred basin
#

I've found the flag.txt but it shows its incorrect

cerulean hinge
#

Check that you don't have a space before or after

sacred basin
#

tried everything nothing is working

quaint cliff
#

Wait no you need to download it first i think

#

isnt !cat to read local file flag.txt

#

i think you're reading a flag.txt on your machine, not the one in the share

sacred basin
quaint cliff
#

so ! in smb is to execute local commands, now you know

keen pewter
#

i'm doing html injection and it tells me to add <a href="http://www.hackthebox.com">Click Me</a> but when i check the page source theres no way for me to input

eager ledge
#

Hi,

Module: Documentation & Reporting
Section: Documentation & Reporting Practice Lab
Section Link: https://academy.hackthebox.com/module/162/section/1572

Question: After achieving Domain Admin, submit the NTLM hash of the KRBTGT account.

I have dumped the ntds.dit file and extracted the hash from it. But when I submit it, it says Incorrect Answer. Why?

keen pewter
#

how do i know what line to inject the html code when looking at the page source ?

quaint cliff
keen pewter
#

thank you c:

quaint cliff
#

it is the last part of the hash, without the :: , and check there is no space left

eager ledge
reef sonnet
sage void
#

I’m still having issues with the mounting bitlocker-encrypted drive Linux part of the cracking protected archives section

#

Any tips ?

#

Am I supposed to put the bitlocker mount file in a different directory then the one used in the module

quaint cliff
#

from a redditior, that helped me on another module with bitlocker encrypted drive

sage void
# quaint cliff

Can you send me the link to the Reddit I wanna know what the commands are for

quaint cliff
sage void
#

Thanks

leaden island
#

hello im on the new section on password attacks, attacking windows credentials manager

#

im supposed to use mimikatz but i cant get administrator

fathom pendant
fathom pendant
#

Otherwise you'll need to look into uac bypasses

leaden island
leaden island
fathom pendant
leaden island
#

bro im literally trying to get it to run but i couldnt

#

the python one ?

keen pewter
#

hello i did the mod that asked me to do What text would be displayed on the page if we use the following payload as our input: <a href="http://www.hackthebox.com">Click Me</a> and i have the words but i have tried Captials for the first letters and lower case but it says i am wrong :<

fathom pendant
leaden island
#

i cant find it

fathom pendant
leaden island
#

ah here it is πŸ™‚

#

i went transfering the whole repo lol

leaden island
gloomy stump
#

Hello, I'm doing File Upload Attacks, Type Filters, I found the extension and the content-filter and can upload it but it doesn't work 😦

fathom pendant
leaden island
#

without admin i guess i cant change any security setting

cloud urchin
leaden island
#

lemme check

fathom pendant
leaden island
#

do i need to run it from there ?

fathom pendant
#

well, yes, you're looking for mcharles' stored password

#

not sadams

leaden island
#

hmm makes sense

#

thats what taking a long time break gets me into

#

i forgot many things

fathom pendant
#

the section explicitly gives you that command for a reason

feral prawn
#

Bro I am new what to do?

#

I mean new on this server

compact patrolBOT
feral prawn
#

Thnx

flint palm
leaden island
#

turns out browser blocked the download for lazagne and it was 0 bytes size

flint palm
#

you are doing mcharles yes?

#

lazagne will not help you there mimikatz works

buoyant torrent
#

guys i'm stuck on passwords attacks module pass the certificate section, can y'all give me any hint to get the admin flag, please help

shy badger
#

hello i am on the Attacking WPA/WPA2 wifi networks skills assesments and i stuck on the "Connect to the StarLight Wi-Fi network and submit the flag.." (question 2) . I am sure this should be a EAP/TLS Auth attack but i got an error " SSL: SSL3 alert: read (remote end reported an error):fatal:unknown CA " . It means that the client validare the CA Authority before connection. I tried all the others attack (bruteforce, relay, downgrade , evil-tween...) i allways got this same error message. Could you tell me what i am doing wrong please ?

keen pewter
#

I keep entering Your Cyber Performance Center and it tells me i'm wrong i dont know what to do

crimson leaf
keen pewter
#

75 / 75

foggy snow
gloomy stump
crimson leaf
fathom pendant
keen pewter
#

introduction to web applications html injection

fathom pendant
#

if you use mimikatz you'll need to look into UAC bypass

foggy snow
#

yea but normally the tools are provided at C:\tools\

#

guessing I have to transfer them myself in this case

fathom pendant
fathom pendant
keen pewter
#

well damnit :<

crimson leaf
#

Re-read the question a bit, I think you may just be misunderstanding what is being asked

fathom pendant
#

the question is simply "what would be the text on the page if our payload is.."

#

it's a lot simpler than you may be thinking

prisma wing
#

do i need to be connected to a vpn to solve the modules?

crimson leaf
#

Some of them, yeah

cloud urchin
#

if you use a vm, for most of them, yes

#

you can use the built-in pwnbox and not use the vpn

crimson leaf
#

There are a pretty large number of web application ones that don't require a VPN or Pwnbox though which is interesting

keen pewter
#

i must be stupid because its deff not the Word that starts with C and the other word starts with M

fathom pendant
#

it's the full phrase

keen pewter
#

where do you see that

#

wait nrm

#

so its both phrase

quaint cliff
#

This will create a virtual interface with an IP that allows you to communicate with htb academy machines and labs

crimson leaf
prisma wing
#

I put the right line but it didnt worked

somber bison
#

now i’m lost

prisma wing
#

The parrot

prisma wing
cloud urchin
#

probably best to say which module/section/question you're on, what you've tried, error messages, etc.

#

you've provided no information

prisma wing
#

wait a minute

#

I m trying to do RDP in the module windows fundamentals

eager hare
fathom pendant
#

well .ova is specifically oracle virtual appliance, not sure if it would still work on vmware which typically uses vmdk files

#

they are different hypervisors, and as such use different virtual appliance specs

#

you can retry, as stated in the warning, and see if it still works

quaint cliff
#

or you own virtual machine in virtualbox

#

you should probably try the "getting started module that explains all of it"

quaint cliff
#

so you are connected to the vpn, it is set by htb when you create the pwnbox

#

now you can use xfreerdp to connect to the target

prisma wing
#

do i have to download the vpn conection file?

eager hare
prisma wing
#

or the pwnbox does it automatically?

fathom pendant
prisma wing
#

i think i did everything alright but it didnt worked

#

i used the xfreerdp

#

but it didnt worked

hasty maple
signal hound
#

Hello guys
How do i calculate CVSS in sysreptor
For example in the documentation and reporting module they rate LLMNR and all other attacks as 9.5
When i ask chatgpt it says 8.1
When searching google it says 3.8

cloud urchin
#

Use a CVSS calculator

crimson leaf
#

Cvss can also be a little debatable when applying it to certain issues. Sometimes it requires further context before you can accurately map it, which obviously, Google or chatgpt may not have

signal hound
#

Is it a problem if i get the CVSS score a little bit off?

cloud urchin
#

did you try googling it

spring flicker
#

If you clear the file at $HISTFILE that should remove your history, though you may need to restart your shell if you don't want back search or autocomplete to show previous results for that session.

novel parrot
spring flicker
#

Hey all, trying to wrap my head conceptually around the ExtraSIDs attack in the AD module. Was wondering if someone could sanity check me - LLMs and Google searches are giving me somewhat contradicting feedback which is why I'm escalating to fellow humans πŸ˜‰

You have access to the KRBTGT account hash for a child domain. You know the SID of the Enterprise Admins group in the parent domain. You forge a new ticket for a user that includes the SID for the Enterprise Admins group using the child's KRBTGT. This is where I get confused. If I present the forged ticket to the parent domain, am I doing an AS_REQ exchange and getting back a TGT that I can use broadly - or am I using constrained delegation (via S4U2Proxy) where I am presenting a KRB_TGS_REQ with my foged ticket and getting back the KRB_TGS_REP for a specific service whose SPN I know? Or am I fundamentally off base?

novel parrot
#

it says there to find a sqli

novel parrot
#

can anyone hlep me

cloud urchin
rocky burrow
#

i am having trouble in the bug bounty path, Introduction to web Applications module in the common WEB vulnerabilities exercise with ( To which of the above categories does public vulnerability 'CVE-2014-6271' belongs to) to my understanding it is one of the above listed exploits in the exercise : SQL(i) ,Malicious file upload, Broken Authentication/Access Control, Command Injection. however evrytime i enter these as an answer i get 'Error Incorrect answer' does anyone have any clue?

novel parrot
raven furnace
#

Guys, help this command doesn't seem to work in user enumeration in Broken Authentication

ffuf -ic -c -u http://94.237.55.43:35563/index.php -X POST -d "username=FUZZ&password=dsads" -w /usr/share/wordlists/SecLists/Usernames/xato-net-10-million-usernames.txt -fs 2970

onyx saddle
#

helllo

#

if i want to take penetration tester learning path, how much does it cost ? ( no cpts exam ) just the content.

teal sentinel
dreamy python
#

Hey can someone help me with some basics ?

pure barn
raven furnace
#

I have just passed the all request using ffuf -request req and it worked

raven furnace
#

thanks bro

pure barn
#

chill

dreamy python
#

Can I get personal assistance here ?

cloud urchin
fathom pendant
#

you can get the cubes for the course ~ 1mo plat and 1mo gold
or if you have an academic email ~ $8/mo which grants access to the t2 and below modules

#

or if you are truly insane buying the cubes outright which is generally more expensive

onyx saddle
fathom pendant
#

yep

clear coral
#

I'm doing the Interacting WIth Users exercise in the Windows Privilege Escalation module, but the version of Responder on my Attack Machine doesn't seem to have the -r flag or the -f flag. Any have an idea why that might be?

rocky burrow
#

hello

cloud urchin
rocky burrow
#

anyone doing bug bounty

cloud urchin
rocky burrow
#

i am having trouble in the bug bounty path, Introduction to web Applications module in the common WEB vulnerabilities exercise with ( To which of the above categories does public vulnerability 'CVE-2014-6271' belongs to) to my understanding it is one of the above listed exploits in the exercise : SQL(i) ,Malicious file upload, Broken Authentication/Access Control, Command Injection. however evrytime i enter these as an answer i get 'Error Incorrect answer' does anyone have any clue?

opal basin
#

Hi, I'm looking for a module to learn about networks and firewalls so that in the future I can launch an antiDDoS system

cloud urchin
#

There's an introduction to network module I believe, but nothing about building an anti-ddos system

mortal vector
raw hornet
#

Hello, how are you? Can someone please help me with the final part of the DACL I module? I only need the last two points to finish. I entered the WS01 machine with LAPS and extracted SAM, SYSTEM. I extracted Jose's hash, but that isn't the one. The exercise says that the machine it accesses is WS01, but I don't know if there is another machine or how to extract Jose's hash. Can someone please help me. Thanks.

hardy sandal
#

Doing WordPress module and on my skills assessment part but uh, for some reason it says the remote site is up but not running wordpress when it is

#

yh i'm sort of confused.. this problem wasn't occuring during the other sections

hardy sandal
#

nevermind, figured it out. Had to add ip and sub to my hosts

valid swan
#

Can someone help in getting started module Im stuck on smb enumeration question

rugged flax
#

Is there any way to quickly download a section's VPN connection file in a VM? because navigating through the browser to that same module and having to log into my htb account in the browser in my VM is painfully slow every time and it doesn't help that my VM's browser is laggy as heck.

Or if anyone knows an easy way to transfer files to the VM that would help

valid swan
#

How does one get to Welcome1 please help I dont get how to get it without bruteforcing?

cloud urchin
rugged flax
#

Just wondering if that's how that works

cloud urchin
#

I doubt it

tawdry palm
#

has anyone had an issue when all otehr boxes work fine connection wise but i cant connect to the windows skill assesment 1 box?

acoustic vector
#

Can someone check https://academy.hackthebox.com/module/81/section/789 and let me know if the FTP file transfer is correct? The question says "What was the filename of the image that contained a certain Transformer Leader? (name.filetype)" but I'm getting a pic of a dog and it's not taking the file name

leaden rampart
#

Academy Module - "Footprinting" > "Oracle TNS"
The target machine is not stable. Sometimes it is reachable and sometimes it is not. The issue is there since yesterday.

acoustic vector
raw hornet
#

Hello, how are you? Can someone please help me with the final part of the DACL I module? I only need the last two points to finish. I entered the WS01 machine with LAPS and extracted SAM, SYSTEM. I extracted Jose's hash, but that isn't the one. The exercise says that the machine it accesses is WS01, but I don't know if there is another machine or how to extract Jose's hash. Can someone please help me. Thanks.

gray yacht
tawdry palm
#

skills assesment 2 works fine

#

just not 1

wary wren
#

anyone did htb password attacks new skills assessment

wise sapphire
sharp horizon
#

Hello, is there an issue with HTB where the flag is visible on PWNbox but not from a locally hosted machine? or vice versa?

wary wren
#

anyone did htb password attacks new skills assessment
Can i get some hint

stuck hollow
wary wren
tawdry palm
#

can someone just check if they can access windows priv esc skills assesment 1 box

#

please

stuck hollow
#

can you dm me? will try to help you

leaden rampart
fathom pendant
#

the pre-filled answer isn't the password

#

reach out to support @leaden rampart

leaden rampart
#

how do i create ticket to support? is it via the chatbot?

stuck hollow
#

awesome!

fathom pendant
#

whenever modules get updated, due to how the backend works -- when sections get updated the old answer is pre-filled if you did it previously, and the answer is then nonsense with the update

#

no

#

you'll just have to readjust notes to account for it

leaden rampart
fathom pendant
#

Β―_(ツ)_/Β―

#

i'm not staff

south blaze
#

hey gang, I am trying to solve a module and will need a hint "Attacking Windows Credential Manager new lab". Is this the right room to ask for hint?

dense lava
#

Please, anyone for NoSQL Injection Skills Assessment II, at the second injection point but cant find a payload.

wary wren
#

hey can anyone help me in password attack new skill assessment

thin citrus
#

Hi everyone, I am working on Whitebox Attacks - SECTION: Skills Assessment, got auth bypass but race conditions does not work. Can someone DM me so I can share my turbo intruder script.

stuck wolf
#

Hello, i'm still having issues with module 77 section 726, i've tried resetting host multiple times, but always get the "host seems down" response from nmap

#

okay thats weird, i tried running the scan from the pwnbox on the website instead of my own linux system, and it worked. could it be something wrong with my vpn config?

storm raptor
#

Hi, I've an issue to connecte me at module "Navigation" in "Linux fundamentals". I can't do the exercises because when I connect to the user ssh, I can connect but there is absolutely nothing. I don't understand what's going on. Please can someone DM me?

vague cedar
stuck hollow
storm raptor
stuck wolf
wary wren
#

Oh soryy

wary wren
shadow latch
#

I have a doubt, if for example i gained administrative access to an application, and this application have a funcionality that i can abuse to gain RCE, it could be reported as a finding?

dark hedge
#

if it's built-in, that's not really a finding

#

the RCE i mean

shadow latch
#

the thing is that built-in funcionality is not designed to execute RCE, but i can abuse it to obtain RCE

dark hedge
#

i would document that under impact

waxen totem
#

You mean like an admin can upload a php file that can be used as a webshell?

#

not really a finding
-# imo findings should only be stuff like misconfigs or outdated software that has a bunch of vulnerabilities, an inherent permission isn't really a finding cos how would they mitigate against it?

dark hedge
#

if it's something well-known like getting admin access to wordpress where you can put PHP code in a 404 page to run commands on the host

#

that's just the consequence of being admin

shadow latch
#

i reported just the finding that allowed me to gain admin access

#

thanks for help

dark hedge
#

you are welcome to document the impact of having admin access due to the vuln (which you should)

sleek finch
dark hedge
shadow latch
#

so i will write the explanation of the impact in the finding that allowed me to gain admin access

dark hedge
#

yea, you have to. that's part of the report

shadow latch
#

i understand

#

thanks for help man, have a good day

faint hamlet
frank dagger
#

Can some1 help me with 2million?

waxen totem
signal hound
#

Hi
Does evil-wimrm automatically bypass UAC?

#

Because i noticed in one of the labs that powershell using RDP didnt let me access a folder but evil-winrm did

waxen totem
rocky estuary
#

i just finished doing the password attack > pass the certificate section and i was getting the error below when doing the ESC8 attack

AttributeError: module 'OpenSSL.crypto' has no attribute 'PKCS12'

for anyone having this issue you can try to downgrade pyOpenSSL and cryptography to these version that fixed it for me

pip uninstall pyOpenSSL cryptography -y
pip install pyOpenSSL==23.1.1 cryptography==39.0.1

ebon briar
#

@compact patrol Need a bit of help. My identify command is throwing an error, says to contact a mod/admin.

#

@urban sage would you be able to assist with an error i'm getting from identify command?

echo cosmos
#

Hey everyone. The Password Attacks module was updated recently and I have some questions regarding the new section "Attacking Windows Credential Manager". I managed to answer the question and get the answer the intended way (by bypassing UAC), however, what other way is there? Is it saving the .crd file and transferring it onto my own Windows machine and using mimikatz there?

signal hound
ebon briar
#

@fathom pendant Hello, would you be willing to assist with an error i'm getting when using the identify command in botcommands channel? it says to contact an admin/moderator.

echo cosmos
#

Also, does anybody know how to make mimikatz work on Windows 11? I get "ERROR kuhl_m_sekurlsa_acquireLSA ; Login List" and according to one reddit thread it might be due to the credential guard feature.

quaint cliff
#

am i the only one having lag spike on the vpn?

#

im on EU1

ebon briar
golden plume
#

Hii , does wifi penetration testing basics comes in any job role path ? I can't seem to find
But when I searched that term in discord , a result said it is under CWEE like that

echo cosmos
faint hamlet
#

maybe use ls -force, as it may be hidden?

echo cosmos
#

like there is no folder named "Protect" nor "Credentials" for some reason

echo cosmos
quaint cliff
hidden urchin
#

hey guys in password attack module -> cracking password protected file , in the question we got the encrypted file but with the rockyou password list it will take foreever to crack the password which list we have to use in this πŸ™‚

hidden urchin
errant chasm
#

Hello there

echo cosmos
faint hamlet
storm raptor
#

Hi, I've an issue to connecte me at module "Navigation" in "Linux fundamentals". I can't do the exercises because when I connect to the user ssh, I can connect but there is absolutely nothing. I don't understand what's going on. Please can someone DM me?

bitter umbra
echo cosmos
main ridge
#

Hi. In the Linux Privilege Escalation module, Python Library Hijacking section is said that given this file

htb-student@lpenix:~$ ls -l mem_status.py

-rwsrwxr-x 1 root mrb3n 188 Dec 13 20:13 mem_status.py

So we can execute this script with the privileges of another user, in our case, as root. We also have permission to view the script and read its contents.

Is this correct? Python is interpreted and it does not inherit the setuid from the script, so we wouldn't be able to execute it as root

fathom pendant
#

-rwsrwxr-x
Read write [set execute] on the user octal permission means it will run in the context of the owner of the file

fathom pendant
#

Try adding those lines to the os library, see if that makes a difference

livid mural
#

this question in the Using Web Proxies- Proxying tools module: Try running 'auxiliary/scanner/http/http_put' in Metasploit on any website, while routing the traffic through Burp. Once you view the requests sent, what is the last line in the request? This question has me so confused because I have scanned like 20 websites and I keep getting the same response for metaploit> File doesn't seem to exist. The upload probably failed

fathom pendant
#

It's asking what the response looks like

#

I.e. route through burpsuite proxy

livid mural
#

burp ins't giving me any responses

fathom pendant
#

And check what the request looks like there

#

Also, not response* request

#

'What is the last line of the request'

livid mural
#

lol damn

#

I was completely overthinking

#

thank you my friend!

#

have to read more carefully

main ridge
# fathom pendant Try adding those lines to the os library, see if that makes a difference

I think I didn't understand you..

In the module they're using sudo to execute the file, so technically it's not the setuid bit, but sudo which is giving the superuser privileges

sudo /usr/bin/python3 mem_status.py

Here https://unix.stackexchange.com/questions/364/allow-setuid-on-shell-scripts#2910 it's explained that "Linux ignores the setuidΒΉ bit on all interpreted executables (i.e. executables starting with a #! line)."

And the code of mem_status.py is

import psutil

available_memory = psutil.virtual_memory().available * 100 / psutil.virtual_memory().total

print(f"Available memory: {round(available_memory, 2)}%")```

So that suid is being ignored, it's `sudo` what gives privileges to the execution. Am I missing something? I'm not trying just to solve question in the section, but to understand how is this working
fathom pendant
#

so; i use ligolo-ng as my pivoting tool of choice, I got tired of doing sudo proxy ... so i set the suid bit and made sure it was on root owner, the reason for this is because root is needed to create and manage interfaces (i'm sure there's some setcap thing for it, i was too lazy to google) -- i no longer had to run sudo to get it to work how i needed it to. While it may "ignore" the suid; it still does what it does in a root context

#

i.e. it elevates it's privileges where needed

dark hedge
#

this script is an interpreted executable, not an actual binary like ligolo-ng's proxy is, so it's not going to inherit the SUID

#

sudo is indeed what elevates the privileges in this case

#

though i'm not sure if SUID allows you to bypass any whitelisted commands in the sudoers file

fathom pendant
#

it depends; it doesn't inherit the suid - yes- but it still can perform things in a root context iirc

severe pawn
#

hi

dark hedge
#

can you give an example

main ridge
dark hedge
#

because i was testing this earlier, and i couldn't get my script to run as root despite it having SUID set

gray yacht
#

Please do not send unsolicited DMs (Rule #8). I do not mind helping out and taking things to DM, however, let's start the conversation in this channel first then take it to DMs after the written consent is given.

fathom pendant
# dark hedge can you give an example

i'm unable to find an example, and i am probably wrong. it seems more of the focus is on utilizing the libraries over the actual suid bit of python scripts

fathom pendant
#

yeah it appears python 3, or at least 3.11+ has some built in protections

#

even when trying to manually bruteforce (os.seteuid(0)) with the root suid bit set, it gives permission denied

dark hedge
#

this also happens if you try to run a bash script with SUID bit set

#
β”Œβ”€[Sun Jun 08]─[11:12:04]─[calculac0re@pwnbox-nix]─[~]
└──╼ [β˜…]$ ls -la test.sh && cat $_
-rwsr-xr-x 1 root root 16 Jun  8 11:11 test.sh
#!/bin/bash

id
β”Œβ”€[Sun Jun 08]─[11:12:18]─[calculac0re@pwnbox-nix]─[~]
└──╼ [β˜…]$ ./test.sh
uid=1000(calculac0re) gid=1003(calculac0re) groups=1003(calculac0re),24(cdrom),25(floppy),27(sudo),29(audio),30(dip),44(video),46(plugdev),106(netdev),112(bluetooth),1000(lpadmin),1001(scanner),1002(docker)
fathom pendant
#

reading into it, it happens with any interpreted scripts

#

so you'd have to suid python and not the script

#

hmm even then

tame basalt
#

I'm doing the OpenVAS Skills Assessment, but for some reason the "target" i spawn, doesn't have 8080 open?
Restarted it multiple times, of cause I did a nmap of it first, ssh and postgreql ports open.

Reminder: OpenVAS can be accessed at https://< IP >:8080. The OpenVAS credentials are: htb-student:HTB_@cademy_student!. You may also use these credentials to SSH into the target VM to configure OpenVAS.

Does that mean I gotta set it up first, or optional?

https://academy.hackthebox.com/module/108/section/1516

fathom pendant
#

is it not http?

#

it's been a hot minute

#

but also give it a few minutes

tame basalt
tame basalt
rustic sage
#

can someone help me

fathom pendant
#

@rustic sage this isn't that kind of server, i'm sorry that happened but this isn't a hacker4hire server

rustic sage
#

Oh ok

fathom pendant
storm prism
#

Hi im New, i am on phone and i am learning Python on phone am i gonna get Better when i got PC and install linux?

fathom pendant
#

yes

solid python
#

Not in this server bud

ancient niche
#

Good Afternoon guys someone had completed the module AI the last exercise?

mighty valve
#

hey guys, I am doing the linux priv esc module and im on the logrotate section. I got log rotten to trigger my reverse shell payload but i am not getting a connection back. I've been stuck for a few hours now, would appreciate a point in the right direction

fathom pendant
mighty valve
fathom pendant
#

well yes, but also shells made in this way are notoriously unstable

#

also by "moving the file" i'm referring to copying the file you're meant to read to a readable directory πŸ˜‰

mighty valve
#

ah got u, ill give it a go, thanks

safe mango
#

Currently doing the SOC Fundamentals in Introductionto the Elastic stack, however for some I can not ping the target I spawned, tried both vpns tcp and udp, tried the pwbox as well.

wary wren
#

Anyome knows how many questions are changed in new password attack updated version

#

Ik new sections are added i was in pass the hash then it got updated i see all checked in my previous pages

gray yacht
fallow shore
#

hi i cant complete the web archives sections cause wayback machines had issues with url or snapshot that werent available ? someone can help me ?

storm elk
#

The domain wasn’t always .com

fallow shore
#

hae try .eu .org ...

#

i always have bad redirect

cloud urchin
#

try in a private window with all add-ons disabled

rotund sequoia
#

Not sure if I should post it here, how do you guys structure your notes for each of the modules? (I'm using obsidian btw).

#

I do it this way btw (using Footprinting module as an example).

digital sigil
#

Personally I usually do one document per module with h1 for sub modukes (like host based enumeration in your example) and then h2 for the sub chapters and so on

But tbh, it doesn't really matter as long as you feel you have control

#

You way is a fair way to do it, but I often feel in larger obsidian repos it starts getting hard to find things again

rotund sequoia
#

Yeah your way seems pretty good as well, guess I just like to subdivide my notes, since I use to use OneNote.

novel parrot
#

on wordpress hacking skill assesment

#

theres this "Note: You need to have a knowledge about how in Linux DNS mapping is done when the name server is missing." idk what that means, do i just create a name for it on etc/hosts or what

heavy shore
stuck wolf
#

Anyone able to help me out rq? I'm working on the public exploits section in the "getting started" module, and i was wondering if anyone could tell me if im on the right path

stuck wolf
fallow shore
stuck wolf
#

however i cant seem to find it in metasploit, though i found the github site

#

so i was wondering if i need to find another exploit or if thats the one they want me to use?

cloud urchin
stuck wolf
stuck wolf
cloud urchin
#

Have you tried visiting the website?

stuck wolf
storm raptor
#

Hi, I've an issue to connecte me at module "Navigation" in "Linux fundamentals". I can't do the exercises because when I connect to the user ssh, I can connect but there is absolutely nothing. I don't understand what's going on. Please can someone DM me?

stuck wolf
#

@cloud urchin i finally did it hacktheflag . i struggled with finding the flag because i forgot to change to the correct port πŸ€¦β€β™‚οΈ

cloud urchin
#

great job! now you know the port thing in the future

stuck wolf
#

yes, thanks :)

bright shore
#

Idk about you guys but the lab on windows priv esc on bypassing UAC does not work properly: Follow the steps in this section to obtain a reverse shell connection with normal user privileges and another which bypasses UAC. Submit the contents of flag.txt on the sarah user's Desktop when finished.

#

Tried resetting the lab multiple times and running C:\Windows\SysWOW64\SystemPropertiesAdvanced.exe with no avail

cloud urchin
#

there is no "pass the certificate" module

#

best to specify which module and section

buoyant torrent
#

just follow the techniques in the module step by step and you'll be able to connect with evil-winrm

rustic sage
#

Hi

terse sedge
#

I'm in Password attacks - Cracking protected archives. I can't download and install dislocker with sudo apt-get install dislocker There are some errors, and can't find it after with locate dislocker Anyone else having issues with it?

#

yes, but I can't see where it installed to.

tardy summit
#

Im currently doing the Skills Assessment for "Windows Lateral Movement".
Im on the WSUS update part and trying to push a reverse shell update to ||backup||. While doing so, i wanted to check if the reverse shell itself works and realized it only works from "support" but not from "wsus". I have a remote port forwarding established on "support" and the reverse shell is having port 9090 on 172.30.0.40 as the target to connect back. I now thought this would either work when being executed from both machines or neither. Now it somehow just works from one. netstat -ano on "support" seems to listen on all interfaces TCP 0.0.0.0:9090 0.0.0.0:0 LISTENING 2220. Any ideas what went wrong?

buoyant torrent
#

did you add the necessary configuration of /etc/hosts ?

drowsy portal
#

Hey I scanned a certain network and found several open ports, how can I exploit them? anyone?

cloud urchin
drowsy portal
cloud urchin
#

You'll need to provide a lot more relevant information if you want help.

summer bronze
#

Hiii

cloud urchin
summer bronze
#

Done

cloud urchin
#

You didn't actually verify

tawdry palm
#

Could someone please try connect to windows priv esc skills assesment 1 box I’ve been trying for days , changed vpns , used pwn box and even tried a new computer and still nothing. Every other box works fine

terse sedge
#

@rustic sage Still not working. Unless it's installing in a way that I can't see.

hoary whale
#

Hey

tawdry palm
#

If someone could help me jt would be great

summer bronze
#

How do I learn cybersecurity from scratch