#modules

1 messages · Page 425 of 1

gray yacht
#

I made a video on how to access local services with ligolo. If you'd like to see if that helps you you can DM and I'll send you the video link.

fathom pendant
#

yeah it's the same concept as the double hop section

rustic sage
barren cloud
lucid raptor
#

Can Compromised Accounts being considered IOCs?

gray yacht
#

You can DM

rustic sage
peak reef
#

.

torpid river
#

Does someone remember the module and section where it talks about how to set up evil-winrm with chisel or socks proxying?

odd scroll
#

Hi, I'm doing the PT path, just started. first time I face with question in module, the ask to find service version with banner grabbing, I use netcat (ip address) 22 , copy the service and it said wrong answer, when I revel the answer it showed "SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.1" and the service I gave was "SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u4"
why its like that? can be way that it not update? I want to know if I'm on the right way If I do well
I'm on module PT path academy > Getting started > Basic tools

cloud urchin
#

@jolly oasis Please don't post spoilers for skill assessments, just ask your question and take it to DM's if you feel you need to reveal a little more to ask your question

#

also applies to any content from modules above tier 0

jolly oasis
#

I thought I was doing that the correct way. I had spoiler tags on all my screenshots and configuration details.

cloud urchin
#

If you feel the need to reveal more info you can take it to DM's if someone offers

jolly oasis
#

Ok...can anyone point me in the right direction regarding question number 1 for Skills Assessment - Using Web Proxies?

cloud urchin
#

I'd recommend going over the Intercepting Responses section again

jolly oasis
cloud urchin
#

DM me

fathom pendant
vernal tapir
#

Hi, are you mentioning the third answer?

#

I believe the first two are easy

#

What was the command you used for the first two?

#

Nono nvm, for the third answer did you try using the last example command where it references Mask Attack?

#

And that gave nothing?

#

Are you only trying rockyou?

#

Try to use *.txt

#

For your wordlist, in the leaked-databases/ directory

#

change 'rockyou.txt' to '*.txt'

#
  • means it'll use every wordlist in the directory with a .txt
cloud urchin
#

Please take care not to post content from modules above tier 0

vernal tapir
#

My apologies

#

ahh yes correct

#

I used that command shown in the example before it was deleted, shown in the "Masked Attack" example

#

yeah I didn't know what else to tell ya XD all good

#

np bro

torpid moth
#

Guys i need help

vernal tapir
#

With what?

shut shell
#

in the span of 1 minute? dam

icy silo
#

Dude what yall yapping about

cloud urchin
icy silo
#

Bro ain't no one care

cloud urchin
#

K, well stay on topic here.

rustic sage
#

anyone here who has completed the Attacking WPA/WPA2 Wi-Fi Networks module? I'm stuck at what should be the easiest question (q3) of Enterprise Evil-Twin Attack section

abstract plank
#

It seems that it was a bug in crackmapexec. I solved it with another tool.

fathom pendant
#

cme is no longer maintained you should be using nxc

junior fjord
#

Facing issue:- I am facing some issue in CPTS module :- network enumeration with nmap, I have the answer but HTB not accepting it !

cloud urchin
#

Make sure there are no whitespaces etc. Maybe manually type the flag. If that doesn't work, you likely found a flag for another answer.

junior fjord
#

I have the answer ( the version of DNS )

junior fjord
cloud urchin
#

no need to dm. which section and question are you stuck on

junior fjord
#

Section :- firewall and IDS/ IPS evasion - medium lab

#

Module :-network scanning with nmap

#

I have the DNS version but, i evaded ! And found it but nt accepting

#

Can I send the scan results after Hiding answer ?

cloud urchin
#

You can try resetting the machine or changing servers or something if you think it's the box, but it's most likely you just don't have the right flag or need to manually type it.

rocky estuary
#

i'm doing the ACL DCsync section and i'm trying to do the attack using mimikatz but i'm getting this error any idea why ?

[rpc] Service : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)
ERROR kull_m_rpc_drsr_getDCBind ; RPC Exception 0x00000005 (5)

#

i tried it but i was getting incorrect password but now its working for some reason thanks

#

yup its was the flag no idea why its used in the command shown in the section

#

oh i see i think i will note both of them in case one of them failed later

faint hamlet
#

I think you should post it on #boxes and maybe dont include hashes and replace domain and ip with $DC-IP, $Domain, etc. As of now this post can be considered spoiler.

uncut frigate
#

wait is it true that you get money upon getting certified

acoustic owl
bleak thorn
#

password hack help me for a test

still rover
#

I'm having a really hard time with the "skill-assessment" section in the password attack module . Is there anyone who could help me out?

still rover
faint hamlet
woven merlin
#

If anyone has a bug bounty course, please share it.

acoustic owl
woven merlin
#

Brother, I am new to group E, so how long have you been learning hacking?

acoustic owl
#

You'll never finish learning. So it doesn't matter when you start. It will be a life's work

woven merlin
#

Yes, I know that hacking changes with time. There is no end to learning here.

#

But how many years have you been in this hacking world?

nova berry
#

the academy boxes are too slow or crashing and wont work properly , whats the issue ?

#

@admin ?

acoustic owl
nova berry
#

even twice and thrice

#

i cant ssh

acoustic owl
compact patrolBOT
steep tapir
#

Im doing the module hashcat and there is an optional question to "crack" the ntlmv2 hash and you got a list with different ntlm hashes.. I read somewhere that the ntlm hash is the base for the ntlmv2 but i can't seem to find the answer that I'm look for. Can some explain me how to do this with the right commands?

nova knot
#

i've found a ticket and unable to crack it, ad module cross-forest trust abuse windows section: $krb5tgs$23$mssqlsvc$FREIGHTLOGISTICS.LOCAL$MSSQLsvc/sql01.freightlogstics:1433@FREIGHTLOGISTICS.LOCAL$D8F7EB318............<rest of encrypted data>

steep tapir
#

I know.. but if do a hashcat -a 0 -m 5600 ntlmv2hash ntlhash-list it doesn't find the one i'm looking for

#

I will have another shot in finding the answer :).. thankz for the input

sage oyster
#

hi all, someone got problems with RBCD from Linux module in Kerberos Attacks ?

plain charm
nova knot
#

🥲 i was using 18200 ig so i used hashcat --help and then switched to 13200

nova knot
plain charm
#

I think it will be 13100. but it worked anyway

nova knot
#

yeap 13100

plain charm
#

Always check the hash mode with hashid -m HASH

nova knot
#

smtg on 18... didn't work and on 13... worked

nova knot
#

thanks!!

plain charm
#

welcome

dark hedge
signal berry
#

Hi!
I'm currently doing Password attacks/Credential Hunting in Linux , trying to discover the user Will's password. In the module there is extensive explaining on using LaZagne, especially concerning the decrypting of some firefox credentials i've found. however, LaZagne is not on the target (or the other tools discussed in the module) AND there is no file transfer mentioned in the module / in the cheat sheet to get it on the target. am i wrong to think i should do file transfer (eg via python server) to my target to check this or should i stay in bounds of the module ?

#

perfect ! then i know what to do , thank you 🙂

mortal torrent
#

Guys how do i hack?

signal berry
#

got the password 🥳

languid junco
#

Hey guys

jolly hemlock
#

I'm trying to complete the answer in the section parameter analysis in the attacking web application with fuff module

#

it doesn't have any hint nor it does have any output after the command 😭

#

after running ffuf it just gives no output

#

i appreciate a little help guys

steep canyon
#

ATTACKING COMMON APPLICATIONS: Attacking WordPress

Problem: While trying to follow the guide I am not getting the username of john to have the password of firebird1, when navigating to the /wp-admin/ of blog.inlanefreight.local and trying the username combo it says john is not registered. Is the box messed up or am I fundamentally messing something up? Suggestions?

Figured it out: The online walkthrough information does not apply to the questions, only the process. Hope this helps someone ..

dawn dagger
#

I have been bashing my head against the wall now for some time and I don't see what I'm doing wrong.
Module: Abusing HTTP Misconfigurations
Section: Host Header Web Cache Poisoning

For the lab I have succesfully found which overwrite host header that is unkeyed and updates the url in login form to point to interactsh.local:port. I have verified with a bogus login try that log in requests are sent to interactsh. However the admin never seems to try login so a request with the password is never sent.

What could I potentially missed?

south marten
#

hello, do u know why im getting this error using minimakts, im in pass the ticket windows module

terse river
#

🤔

rustic sage
south marten
#

okay. i was missing a :

#

ahahha, thanks, i think im turning crazy

modest lichen
#

hey guys , am struggling with password attacks skills assessment " What is the NTLM hash of NEXURA\Administrator?" am trying to get into the network and i tried to make a list with possible usernames with the provided password + i made a list for other possible passwords , are there any hints? thanks

modest lichen
#

Got it, can you help me with it?

wide narwhal
#

Hey guys, using Kali Linux 2025.2, I now getting an error if I try using NetExec as "kali" user (regular user) with this error :

┌──(kali㉿kali)-[~]
└─$ nxc
Traceback (most recent call last):
  File "/home/kali/.local/bin/nxc", line 5, in <module>
    from nxc.netexec import main
ModuleNotFoundError: No module named 'nxc'
```|
Meaning Netexec binary is not being found, so I have to switch to ROOT user : 

┌──(kali㉿kali)-[~]
└─$ sudo su
[sudo] password for kali:
┌──(root㉿kali)-[/home/kali]
└─# nxc
usage: nxc [-h] [--version] [-t THREADS] [--timeout TIMEOUT] [--jitter INTERVAL] [--verbose] [--debug] [--no-progress] [--log LOG] [-6] [--dns-server DNS_SERVER] [--dns-tcp] [--dns-timeout DNS_TIMEOUT] {ldap,wmi,vnc,winrm,smb,ssh,rdp,nfs,ftp,mssql} ...

 .   .
.|   |.     _   _          _     _____
||   ||    | \ | |   ___  | |_  | ____| __  __   ___    ___
\\( )//    |  \| |  / _ \ | __| |  _|   \ \/ /  / _ \  / __|
.=[ ]=.    | |\  | |  __/ | |_  | |___   >  <  |  __/ | (__

/ /˙-˙\ \ || _| ___| _| |_| /_/_\ _| _|

Are you experiencing the same thing since the new update ?
#

To make sure I tried to reinstall it as regular user but same behavior, gotta switch to ROOT to use it. It's not a big deal but I'm just curious cuz I've been using it as reg user in the past

#

If I recall properly, Nxc was already installed with Kali Linux. Then I tried to reinstall it following the installation procedure on their wiki

pipx install git+https://github.com/Pennyw0rth/NetExec
#

I also tried to install it from the Kali linux using apt

#

I'll try again,

#

Yea, I think I might have mismatched both env

#

apt / pipx

#

I did not run the "pipx" command as root. When I try to install through "apt", system says "Netexec already installed"

#

Yes, I'm going to try that, cheers

split pine
#

Hey guys, I am stuck at module/password Attacks , section/Writing Custom Wordlists and Rules. Can anybody here give me some help with that? I'm having a really hard time with this

#

I am using that but it's not working, I tried it and generated more than 5000 words, and it tried all of those combinations but still not being able to crack. I think that the problem must be with wordlist being generated. I don't know for sure

light idol
#

hi

#

can someone help

#

i am a student i bought htb academy but i didnt know you cant share them after solving a question

#

they banned me how can i get my account back

#

@everyone

cloud urchin
#

Don't ping the entire server please, thanks.

#

Your only recourse is contacting support on the site, or email, no support for the website is provided on discord.

compact patrolBOT
light idol
#

is there any chances that my account can get back

cloud urchin
#

Did you read my message?

light idol
#

yes

#

i mailed them but got no response

cloud urchin
#

be patient, it's the weekend

light idol
#

its just i was prepping for cpts and this happend and i bought subscription from my savings

cloud urchin
#

No one on Discord can help, only support

light idol
#

just asking you guys that something like this gets fixed or not

cloud urchin
#

Don't know and this also isn't the channel to discuss

light idol
#

ok thanks

astral steppe
#

||have done it alone but looked at the guided solution, it uses the rockyou.txt wordlist, how/why would this be a presumed wordlist to use? Or is it just a convenience for this lab. As trying this way myself was much faster than the wordlist/hashcat command I'd used the first time round||

#

Question regarding IPMI footprinting lab^

#

Ah fair, guessing this is touched on in the password cracking module?

#

noted, cheers mate, nice 1

south marten
#

hello, i have a question about pass the ticket ( linux)

#

i have acces with root and nows i need to copy the ccache of julio, and i dont know how to do it

cloud urchin
#

@south marten Please take care not to post content from modules above tier 0

south marten
#

yes, i already list /tmp , but i dont know what i need to do now

#

the exercice copy this ccache

#

cp /tmp/krb5cc_647401106_I8I133 . // i dont know from where he got I8I133 .

#

okay, i do it

#

but, btw, from where he got _I... in the activity, only curious

rocky dirge
#

Can someone help me with the Password Attack Skills Assessment? If anyone can help me, I'd really appreciate it. DM me if you're interested.

#

Im stuck

severe violet
#

Hello All! I am working my way through the Linux Fundamentals and need help understanding STDIN, STDOUT, and STDERR for Terminal. I learn best by applying operations to use cases, so what on earth are these actually used for?

fathom pendant
#

STDIN; input, literally what you type and hit enter
STDOUT; the regular output, not errors, of the program you're running
STDERR; the error output, i.e. permission denied errors, file not found, etc

#

they are already predefined in linux, you don't need to manually specify or do anything

#

stdin will always be the input;
stdout will always be the (non-error) output;
stderr will always be the error output

marsh thorn
#

Hi

severe violet
fathom pendant
#

yes

#

it's why you don't really ever want to put your password on the same line as your command

#

and you input the pw after

limpid wadi
#

👋

fathom pendant
# limpid wadi 👋

this isn't #general if you have a question about an academy module, ask it. Otherwise read and follow the instructions in #welcome to gain access to general and the rest of the server

crude halo
#

has anyone had this hashcat error? cant seem to fix it.

fathom pendant
latent condor
#

Hello.... I'm just a kid who got termux can someone enlighten me cuz i got many errors 😭

fathom pendant
latent condor
#

I thought I'd learn to protect myself

fathom pendant
#

read and follow instructions in #welcome to gain access to more of the server, you'll need an htb account

fathom pendant
#

it's just a terminal multiplexer meaning it allows you to split the screen up within the session

#

but again sounds like it has nothing to do with htb academy learning modules :)

latent condor
#

I saw "red team" and clicked discord 🤷🏽‍♂️

fathom pendant
#

and i'm telling you how to gain access to more of the server

#

If you read #welcome it explains that this server is about the Hack The Box website and it's various services

thin citrus
#

I am working on the skills assessments Advanced SQL, got all the users information and can make a secretkey from the provided java script based on email + something + email. But it not working. Tried to decompile with fernflower but got the following error: java.util.zip.ZipException: zip END header not found Can someone help me?

acoustic owl
rocky dirge
#

Can someone please help me, I'm lost. I'm in the Password Attacks module in Skills Assessments and I can't get past the DMZ and I don't understand what to do. If someone can help me, please send me a DM. I would appreciate it. Thank you very much.

crude halo
primal eagle
fathom pendant
primal eagle
#

mean

fathom pendant
#

Eh

primal eagle
#

kidding

fathom pendant
#

I wouldn't rely on one tool all the time, it leaves you in the dark when it stops working

primal eagle
#

yea, of course

uneven cave
#

hey anyone have completed the python3 module ?
The type of foo from question 1 is <class 'set'>. What is the type of x_coordinate?

its answer is tuple but still showing me incorrect!

i have tried <class 'tuple'> too but still didn't work!

#

x_coordinate = (42,) this is the code snippet!

#

x_coordinate = (42,)

print(type(x_coordinate))
<class 'tuple'>

#

i don't know why it is showing me that it is the incorrect answer?

lofty depot
#

I've been struggling with the Firewall and IDS/IPS Evasion - Hard Lab for over an hour in my own box, but like I'm pretty sure I'm doing what I should be. I spawn a Pwnbox, run the same command as in my own VM, works immediately. ok cool lol

sacred lynx
#

Im struggling with the first task of the final assessments of introductions to assembly language .
I all ready disassemble the binary with objdump
Then I rewrite the code and added the loop to
Decode the stack using the rbx and xor .
I used rdx to iterate the stack then call rsp to run it but nothing happened im not quite sure what im supposed to do in the task

uneven cave
tawny veldt
#

Hi, I'm stuck on "Skills Assessment Using Web Proxies", task 3. I'm fuzzing the final ||hash|| and re-encoding it in the correct order 3 > 2 > 1, but it's still not working.

#

I'm not sure what I'm doing wrong or why it doesn't seem to work, any help would be appreciated. prayge

fathom pendant
tawny veldt
fathom pendant
#

200 just means page exists, and yeah the page exists.

tawny veldt
#

Now I have more problems sadglas

fathom pendant
#

Oof

tawny veldt
fathom pendant
#

Been a minute since I've done it tbh

tawny veldt
fathom pendant
#

Likely a case of what i mentioned earlier, you messed up one of the steps or don't have it set up right

tawny veldt
#

I don't see it, but if it exists, the problem could be related to the value=? ||When I submit the request, the tool sends a very different payload than the one I originally configured.||

fathom pendant
#

I.e. if your payload is sending the md4 hash of what you put in, it's gonna send the hash - not what you input

tawny veldt
#

Ok, I'll try something following what you say

tawny veldt
#

Well I tried sadglas

#

Oh, I'm blind, it's just to answers more closely as you say catlurk

#

Thx anyways :))

fathom pendant
hidden ruin
#

Hi

fathom pendant
hidden ruin
#

Just wanted to say hi

fathom pendant
#

yes and i'm informing you that this channel isn't for idle chatter :) it's for help with the htb academy modules, assuming you came from just searching "hacking" in the server search

opal cape
#

Hello. In the "File Uploads Attack" skill assessment. I'm looking for an upload.php file in the source code to use for xxe exploit. All I see is submit.php. I've managed to upload the svg and get the base64 encoded message but it doesn't show me any directory where images are uploaded. I'm using the correct php file right?

fathom pendant
#

it should be near the top of the file; alongside how it renames the uploaded file

opal cape
fathom pendant
#

yes

opal cape
#

I'm not seeing any "target_dir"

#

I see <title>

#

Oh wait

#

I'm looking at html output

fathom pendant
opal cape
#

Does having the /contact directory matter in that xml xxe exploit?

#

I have to hit the gym before it closes. I'll try after and get back to you @fathom pendant

fathom pendant
#

why not just ask for the submit.php

#

also the module is above t0 iirc so let's try not to spoil

somber bison
#

I am kind of clueless as to what to do right now on nmap enumeration page 6

#

I got the htb flag but its not wrong someone told me theres a different flag and now im just stumped

fathom pendant
#

what's the name of the section

#

connect to the port via netcat

#

remember that servers may output a statuscode then the response

#

i.e. 220 [banner here]

somber bison
fathom pendant
#

no

somber bison
#

yeah thats what i meant

#

thanks wizard man

#

wait no

somber bison
# fathom pendant no

this is wrong question i meant to say page 7 with using nse and scripts to find flag

#

i found the flag twice and apparently its the flag for the OTHER page

somber bison
#

no no i did page 6 already

fathom pendant
#

also please for the love of god say the name of the section not just "page N"

fathom pendant
#

it'll help others help you in the future

somber bison
fathom pendant
#

that's the hint

#

you may need to reread the section to understand what it means

somber bison
#

okay

fathom pendant
#

the example command will get you somewhat closer to what i mean

#

also: nmap may not enumerate everything, you may need to manually search through

somber bison
#

Is that hinting at netcat

fathom pendant
#

eh the script may not pull the info; but can point in the right direction

somber bison
#

I found the flag

#

it was wrong i thought i was tweaking then i figured out i just needed the } thingy

#

thanks marcie and zerodaybug

glad narwhal
#

any ideas how to fix? I'm on Oracle TNS

fathom pendant
#

i'm assuming you went to install sqlplus

#

that sh file regularly breaks and doesn't always go through everything

glad narwhal
#

ok i'll try again and report back

fathom pendant
#

i suggest going through line by line instead of copying it as a .sh file and running with sudo

glad narwhal
#

ok

#

Still nothing:

#

according to the script it seems to have downloaded

fathom pendant
#

yeah you'll just need to run through the script line by line

glad narwhal
#

Corrected Syntax

fathom pendant
#

it's a pain in the ass

#

also instantclient isn't sqlplus :) it's just one of the libs for it

glad narwhal
#

Ok i'll try line by line thank you for the help thus far

fathom pendant
#

(also Odat is in the parrot repository now)

glad narwhal
#

it worked line-by-line huge thank you

#

Roger

tawdry palm
#

is there any way to download files from the pwnbox to host machine?

#

it makes it hard as obviously its on a seperate network to my host machiune

fathom pendant
#

? you mean from the in-browser vm to your own system? or are you referring to using a vm on your own system

#

pwnbox is the term exclusively for the in-browser htb vm

signal hound
#

Hi im trying to do "attacking enterprise networks" without the guide
Im at the point where i have "hporter" credentials after dumping lsa
Im trying to access shares with smbclient but i get logon failure
Same when i try to use winrm
Any reason why?

soft moon
#

I not sure what I am doing wrong with the password attacks module, do have to priv esc again do Administrator??
section Attacking Windows Credential Manager

signal hound
#

You need to bypass the UAC

soft moon
#

ok thanks I will have to search up on how to do that hahaha

wooden seal
soft moon
#

sure I have a feeling I should of done the windows priv esc before this module hahahaha

wooden seal
#

i did it before too xD

soft moon
#

dammmmmm

wooden seal
soft moon
#

yeah I saw the module also mentioned other tools

wooden seal
soft moon
signal hound
#

Anyone down to dm me about attacking enterprise networks?

soft moon
#

sounds like pain but good luck joemda

wooden seal
soft moon
#

well I try my hardest as I love learning
plus this dopamine is up there with driving fast

#

the only issue is I could never realistically use these skills unless I obtain a pentester job so its good fun

wooden seal
soft moon
#

such a goofy way to get to power shell cheers @rustic sage and @wooden seal

wooden seal
soft moon
#

but you know what be helpful having it in x64 instead of x86 hahahhaha
(was messing around and testing...)

wooden seal
soft moon
#

brain absolutely fried

wooden seal
#

bro hes messing around lmao

tawdry palm
soft moon
#

oh I used locate and went to dir and the cp the x64 ver

#

was just thinking to myself and testing

wooden seal
soft moon
#

Its ok I also didnt see the hint and it was the same on HTB but you guys gave me some links xD

wooden seal
wooden seal
soft moon
#

yes I am just messing and waiting for the transfer

wooden seal
#

sadglas you are insane

soft moon
#

or I live on a big fuck off rock

#

hahahaha

wooden seal
naive sage
soft moon
#

its a joke

naive sage
#

dang, learning has become a joke.

soft moon
#

:U its you I've see mr cybersimon around the teams
before I joined 1

whole stag
#

I'm having a hard time with the "skill-assessment" section in the password attack module . Is there anyone who could help me out?

soft moon
#

de way

soft moon
#

see what I have to put up with @wooden seal

whole stag
#

@wooden seal Can I DM you?

wooden seal
wooden seal
wooden seal
#

@naive sagethis guy @soft moon is chaotic

soft moon
#

what do you mean

wooden seal
soft moon
#

good

#

its a needed as everyone has a little crazy inside, its up to the individual to display it or not xD

wooden seal
#

@whole stagare u dming me? i am waiting (i m about to hop in game) lol

naive sage
wooden seal
soft moon
#

I mean, no IT job and really let me go hahahaha

long igloo
#

Guys, I'm currently doing the PenTester job role path. Do you recommend me giving it 2 loops before trying CPTS? I had 0 knowledge before, started with it, I can handle some easy/low medium boxes and I'm taking a bit of notes, but my idea was running it again after finishing, going full blind and documentating everything.

soft moon
long igloo
#

Thank you!

naive sage
wooden seal
soft moon
#

nice free tips xD
noted

naive sage
long igloo
#

I just did 8 of the full path, I'm following the exact order of the path

soft moon
naive sage
#

gets you good grasp over general fundamentalist knowledge of things.

long igloo
#

Sorry, with 0 knowledge I meant 0 red-teaming knowledge, I finished a degree on Sysadmin, no work experience but plenty of knowledge

naive sage
#

YOU GOTTA BE CLEAR GNG. kek

wanton mural
#

i have a question , in hackthebox academy when i buy student subsciption , i will have access to all tier 2 modules and cbbh and cpts and soc l1 paths , so my question is this :

in modules i know that there will be theoritical part which explain to me the moudule or topic , and there is something called interactive which has the htb icon , is this interactive a machine ? or just a questions ?

naive sage
wanton mural
#

like is this a machine like htb machines ? or just a question to apply my knowledge ?

wooden seal
wooden seal
naive sage
wanton mural
wanton mural
wanton mural
#

but this machines doesno't require a separate subscription right ?

#

like i have access to this machines since it is inside the mudules right ?

long igloo
wooden seal
long igloo
#

Just be careful and don't run pwnbox and the vpn on your vm at the same time, otherwise the vpn will "overlap" and pings will stop working :P spent 2h thinking why my pings didn't reach the target and it was bc pwnbox was up AFTER my vm connection, so it overrided

wanton mural
long igloo
wooden seal
#

it gives access to CPTS CBBH AND CDSA and tier 2 modules

long igloo
#

for the rest of boxes you would need to purchase VIP on labs

#

but the exercises inside the modules require no extra sub

#

if u need any extra help about it, i'm on the same page, student subscription doing the CPTS path :P

wanton mural
#

mmm i got it , so when i purchase the student subscription i have access to the modules and only the retired or active boex inside the paths i have access to since iam student which are cbbh and cpts and soc l1

long igloo
#

Yup, your student subscription covers:
All modules up to Tier2
Full pach CBBH CPTS (not sure about the soc l1 didn't see it)
Unlimited PWNBox usage inside academy modules

#

But that's for the academy part of HTB, labs is other site, other subscription... also it's other "scope"

wanton mural
long igloo
#

alrighty that's nice

wanton mural
long igloo
#

So, if you unlock a module (via cubes or via your student/any other sub), you can do ALL the interactive exercises inside with no extra cost, as you already unlocked it

wanton mural
long igloo
#

No.

#

You only unlock modules on Academy with the student plan, so you have access to the interactive exercises INSIDE academy, nothing outside it.

wanton mural
#

and does interactive exercises consist of machines like htb ?

long igloo
#

Some of the interactive exercises are app.hackthebox.com retired machines, but they are INSIDE academy, not on the other website. Imagine the machine Nibbles, it's retired but it's on one academy module. You can do it in academy since you have the plan, but if you wanted to do it through app.hackthebox.com you won't be able to do it. Understand?

long igloo
wanton mural
#

thank you so much for explaining

long igloo
#

no problem mate :P

wanton mural
#

so i get it now , some of interactive exercises is machines but i only can do it in academy not the htb if it is retired . :)

long igloo
#

Yuppity yup.

naive sage
wanton mural
naive sage
#

if you want to practice more you can search up box in Academy x HTB Labs or 0xdf's blog.

wanton mural
#

thanks mate

long igloo
#

FINALLY i ended footprinting module it has been a pain

naive sage
#

That module is 1000% worth it ngl.

long igloo
#

yeah, but running it for the first time with 0 prior knowledge took longer than expected

soft moon
#

I struggle on the footprinting module too but it made sense and really enjoyed it

long igloo
#

anyways i feel like i learnt a lot, when I do the second loop on it I will feel really good, but it's because each time I didn't understand something, or never saw it, started researching about the services etc etc so I have a clue of where I was

naive sage
signal lava
#

Answer seems to be incorrect, however, I am 100% sure of the command

#

The one on Index Number

#

Okay answer worked. My index command was running on another instance 😂

#

Thx 😉

soft moon
#

god mimikatz was painful but got the onedrive password with it hahahaha

desert widget
soft moon
#

I havent done web proxies before you got it Anon

waxen totem
desert widget
#

I tried that but the community version of burp suite dont allow me to brute force

waxen totem
#

it's called intruder

crystal edge
#

Hello everyone, how can i become ethical hacker from scratch ? I'm 18 now and I'm also confused which path should i choose in cybersecurity? Can anyone guide me

compact patrolBOT
waxen totem
dark hedge
#

@crystal edge

jolly hemlock
#

section - virtual hosts I'm stuck at the question idk if im using wrong command

#

but the results aren't showing

jolly hemlock
#

same happened with ffuf yesterday but tried restarting pawnbox

#

now this information gathering 😭

silk lagoon
#

@jolly hemlock what’s the question

jolly hemlock
#

bruteforce vhosts on the target system. what is the full subdomain that is prefixed with "web"? answer using full domain, e.g."x.inlanefreight.htb"

silk lagoon
#

Dm me your payload

jolly hemlock
#

okay

glacial siren
#

Hi guy I'm new

waxen totem
glacial siren
#

💀 dang

waxen totem
desert widget
#

I am not able to complete the question

plain charm
desert widget
#

Burp suite is not allowing me to fuzzz

plain charm
#

It should. Did you follow the modules instructions

desert widget
#

Yupp

plain charm
#

You can DM

desert widget
#

check DM

median kraken
#

Hi everyone, I encountered some problems while playing Prolab Rastalabs. Which channel should I ask or communicate on? It's not related to spoilers, but rather a special situation that is confusing me

compact patrolBOT
fathom pendant
#

^

#

if you believe it to be a technical error and not a skill issue

median kraken
#

thanks

normal kite
#

Hi

thick steppe
#

Hi, I am doing the windows fundamentals, and here is the question I am stuck on

#

Identify one of the non-standard update services running on the host. Submit the full name of the service executable (not the DisplayName) as your answer.

#

I put this from an llm , what did I do wrong

Get-Service | Where-Object {$_.Status -eq "Running"}

#

am I doing something wrong

#

can someone help please

#

@waxen totem can u help please

fathom pendant
#

what makes you think you're doing something wrong?

fathom pendant
thick steppe
#

there are soo many non standard ones and whatever one I put it says wrong

fathom pendant
#

wdym so many "non standard"

fathom pendant
#

it shows all running services

thick steppe
#

ok let me try something else

fathom pendant
#

you don't need to necessarily try something else

#

but you need to understand what "non standard" means

#

non standard => not baked into windows by default

#

i.e. wsus is standard, it's in windows

thick steppe
fathom pendant
#

also consider that if it's running in a vm, then the tool pack is standard

thick steppe
#

which is weird

#

oh

fathom pendant
#

also

formal arch
#

Hi everyone, I'm working on the "Active Directory Enumeration & Attacks" room on HTB Academy, and I'm a bit stuck.

I already clicked "Spawn Machine", but I'm not sure how to find the IP address for the ATTACK01 or MS01 machines. I want to connect via SSH or RDP as the htb-student user, but I don't see any IP listed.

Can anyone help me figure out where to find the IP or how to properly connect?

Thanks in advance!

fathom pendant
fathom pendant
#

there should be a button that says "click here to spawn target"

formal arch
#

i didn't found it

fathom pendant
#

also, not a room -- rooms are THM, modules and sections are htb academy, boxes are main platform

fathom pendant
#

spawn machine spawns the in-browser vm

thick steppe
#

and still not working, there is no way I can distinguise update and non updates if there is no name

fathom pendant
#

because you can't chain the -eq

#

also $_.Status is the status property

thick steppe
#

Seems like I am the dumbest guy on this server since I cant answer a question as simple as this one FeelsBadMan

formal arch
# fathom pendant spawn machine spawns the in-browser vm

Hi MarcieLee,
Thanks for your help!
I couldn’t find the “click here to spawn target” button you mentioned. The only thing I see is my workstation.
Could you please clarify if that is the target machine or how I can get the IP addresses to connect?
Thanks again!

formal arch
#

Connecting via SSH
We can connect to the provided Parrot Linux attack host using the command, then enter the provided password when prompted. there is not nay password or username

thick steppe
#

the spawn target button

fathom pendant
#

what is the name of the section at the top of the page

thick steppe
formal arch
#

i cant find it

fathom pendant
#

"the first one" isn't descriptive

thick steppe
#

u see there is an tartgt spawn where there is an ip

fathom pendant
formal arch
fathom pendant
#

because there are sections that are just reading, without practical elements

fathom pendant
#

if there isn't a practical element, there won't be a spawn target button

formal arch
#

i am working "Initial Enumeration of the Domain"

fathom pendant
#

also the password would be the same as the rdp one

formal arch
thick steppe
fathom pendant
#

=_=

ivory flame
#

Hey guys, i just finished up getting started module - public exploits section in the pentester job role path. The question in that section revolves around searching exploit either using Metasploit or Searchsploit on a vulnerable plugin. My question is, since the plugin used is very much disclosed when I open the web, how do I gather info on what plugins does the web use if they are not disclosed? Are there any scanners out there that can do that?

fathom pendant
#

where the questions are

#

as was stated earlier

fathom pendant
#

and the answer regarding if there are scanners that do that, there's wpscan for wordpress instances

dark hedge
thick steppe
#

marci, what do I do to differenciate update ones and non update ones

fathom pendant
waxen totem
thick steppe
#

none of the description specifically mention that if its update or not

fathom pendant
#

also sometimes the name can allude to it being an update program

#

i.e. someprogramupdater.exe

formal arch
# fathom pendant =_=

Hi MarcieLee,
Thank you so much for your quick and helpful responses! I really appreciate your patience and guidance—it means a lot to me as I’m learning and working through this. Your support makes a big difference. Thanks again from the bottom of my heart!

ivory flame
#

I see, i got ahead of myself haha. But if the webapp is made using Springboot or Django for example. Are there any universal tool that can scan the plugins? Like a swiss army knife for vulnerable plugins?

fathom pendant
#

lol no

waxen totem
#

Recall there was a tool also mentioned in attacking common services kek for scanning other CMSs like Joomla

fathom pendant
ivory flame
dark hedge
#

pretty sure those are just frameworks

ivory flame
#

anyways thank you guys

dark hedge
#

WordPress is a CMS

fathom pendant
mortal mural
#

btw
do u need to have a specific role inorder to type in htb - off-topic

ivory flame
#

noted

fathom pendant
thick steppe
#

and thats it

dark hedge
#

probably some manual enum can find any kind of plugins/templates in use

fathom pendant
#

literally reread what i said; the exe may also have the word "update" in it

thick steppe
fathom pendant
thick steppe
#

screenshot will be many so no point

fathom pendant
#

add | fl to the end

waxen totem
#

| Select -Property Name,Desc or something also might help

ivory flame
#

seems that WPscan didn't output any plugins. But i managed to find that the vulnerable plugin is in the webapp by manually modifying the URL (start searching from /wp-content/plugins) and curl-ing

dark hedge
#

been a while but i think you need to pass your API token to WPScan if you want it to do a thorough scan

ivory flame
#

i see. so it's not an entirely "free" tool is it

fathom pendant
#

it's free

thick steppe
fathom pendant
dark hedge
#

it is free, until you run out of API calls

#

but they replenish every month

fathom pendant
#

and unless you're attacking a bunch of wp websites, you're not running out

ivory flame
#

That's good to know. First time trying out 'attacks' on WP. I haven't had any WP challs in any previous CTF encounters haha

#

thanks again guys

fathom pendant
#

you can also use statements within the object braces ({})

#

{( $_.prop1 -comparitor "value" -and $_.sameorotherprop -comparitor "value2")}

#
final sparrow
#

Damn

thick steppe
#

yk the problem is, Idk what I am doing is correct and I dont get results so I go crazy

fathom pendant
thick steppe
#

with no way of veryfing if I am right

fathom pendant
#

well once you start limiting what you see, like utilizing more filters, you can easily find it

#

-Contains is better than -Like

fathom pendant
#

also how you can verify what ones are and aren't windows standard: google

#

"what is <service name here>"

#

and the AI overview may save you time
"<service> is a Windows Service"

#

with -like you may need to do "*value*"

#

doing some testing it seems like some portions really dislike -contains of -like

somber knoll
#

HAVING ISSUES WITH vpn file no progress after this
using parrot os on VMware

sage void
#

I’m using snaffler.exe on the password attacks module is there something I’m missing or incantation I’m missing ?

fathom pendant
#
  1. the "freezing" is normal behavior
somber knoll
fathom pendant
#

it's meant to do that; you just open a new terminal and you'll see you're connected to the vpn

#

sudo killall openvpn

fathom pendant
somber knoll
#

but let me try

fathom pendant
#

well i'm seeing in that output tun1 meaning that tun0 already existed so it incremented to tun1

#

unless you're running another vpn program in the vm

somber knoll
#

nope

somber knoll
#

@fathom pendant

fathom pendant
#

cool now run it again and it should give tun0 if not just restart the vm and do it again

somber knoll
#

got tun0 but the freeze

desert widget
#

is there any advantage of using ZAP over BURP? I have professional version of burp!

#

I was thinking of skipping the ZAP thing

fathom pendant
#

just open a new terminal and you're good to go

somber knoll
#

but another poped up 🥲

fathom pendant
fathom pendant
somber knoll
# fathom pendant ?

nothing got it figured thank you so much for the help i have been banging my head trying to connect it in my ubuntu machine

fathom pendant
#

good luck

heady fiber
#

Hi. Looking for some advice on the Password Attacks module. I am on the skills assessment and I can't progress from the first box. I don't know if I am meant to escalate privilege on the first box (DMZ01) or try to move directly to JUMP01. Apologies if this is the wrong place to post - let me know where if not.

south marten
heady fiber
# south marten hello, you found the h... credentials in DMZ01?

yes, but where they suggest doesn't seem to be accessible from the DMZ. I tried using the creds to escalate locally or log on to the jump box but I don't know what i am missing. (For one thing I don't know what I am meant to do about rdp - I went as far as trying to compile standalone versions of xfreerdp and rdesktop but couldn't get them to work)

south marten
#

feel free to open dm

heady fiber
south marten
#

okay, if you have more problems feel fre to open dm

heady fiber
#

Thanks a lot. Will do

paper hull
#

any experience with web scraping?

young gale
#

As this user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?

Password Attacks
Credential Hunting in Network Shares

need help to do this, i got the creds for the previous question but i cannot find the password of a domain admin

young gale
south marten
#

you prove different patterns?

young gale
south marten
young gale
south marten
#

okay

#

'passw' maybe is not the good keyword

young gale
south marten
#

read again the question, you can found 3 keywords

clear seal
#

Curious, anyone here with AT&T? lol

oak nova
#

Hello everyone. I am struggling with this question? Android Apps & Development/Native Code/What is the name of the function that returns the string inside the cpp file? (Format: FunctionName()).

MY answer— return stringFromJNI() is wrong. Please help me get this one roadbump in otherwise pretty straightforward module. Thanks.

glad finch
#

Hi! I am trying to make the splunk exercises on the soc path and I get this message: "Unable to load app list. Refresh the page to try again."

median ocean
#

hii

storm elk
cloud urchin
#

@young gale Please take care not to post content from modues above tier 0

opal cape
cloud urchin
# opal cape What if I have a question about File Upload Attacks skill assesment?

Then you simply ask your question without revealing content from the skill assessment. Also make sure not to spoil info from skill assessments especially, anyone who has done them knows what to do and doesn't need context. You can also DM someone if they give you permission if you feel like you need to reveal a little more.

opal cape
cloud urchin
#

@thorny karma Please take care not to spoilt content from modules above tier 0

opal cape
#

Anybody have any suggestions?

thorny karma
median ocean
#

Yo, can you help me out?

opal cape
#

Hey ill ask once more. Ok so im trying to upload my .svg to get the encoded64 of upload.php. yesterday I ran intruder with the a wordlist that had permutations of svg. I got one that worked. I had to log off, I didnt save. I'm running the same way today and intruder just gives me only images allowed with every permutation. What's going on?

#

This is for the File Upload Attacks skills assessment

spiral spoke
opal cape
#

Im doing the exact same process and every itteration of svg is returning only images allowed. I have no idea what's going on. I'm also using GIF8 above my php echo request in the content.

#

My steps were upload legit jpg, capture request. Replace content with php hello world. Send to intruder set the position to shell.php. add my wordlist payload with different permutations of .svg and then run intruder

#

What did I miss thats not giving me upload successful like yesterday?

quasi wave
#

hi guys I'm gonna do the last question of the skills assessment for pivoting, tunneling, and port forwarding module again

#

I'll let you guys know if I need help

lime cosmos
#

i think i need the creds to access to the spawned machine (ip: 10.129.90.149)

spiral spoke
spiral spoke
cloud urchin
#

@lime cosmos Please take care not to post content from modules above tier 0

#

@median gale Please take care not to post content from modules above tier 0

quasi wave
#

hi guys I'm doing the last question of the skills assessment for pivoting, tunneling, and port forwarding and I actually think I'm gonna do it right this time

#

but I'll post on here if I have any trouble

#

I think I see how to do it

opal cape
barren cloud
west wedge
#

Is there anyway around the account restrictions popup when trying to RDP to the Administrator account for the Pass the Hash exercises in the Password Attacks module? It says to RDP to the host and provides a user/hash but I get an "Account restrictions are preventing is user from signing in" response, but I was able to do this module previously

spiral spoke
fathom pendant
# west wedge

doesn't the section directly tell you how to do that if not i know one of the modules/sections prior to getting to that point does

west wedge
dim ridge
#

Anyone else done Command Injection Module recently? I'm finding the questions and answers a bit odd, and its not accepting the answer you'd expect

odd scroll
#

HI, Starting point > Pentesting Basics > Service scanning
I have mission to scan with nmap and give the service of the port 8080 .
I tried so much scans, and so much versions, and banner grabbing, I have tun0 in the netweork, This is the thired time Im restart the target machine to get new IP
nmap -sV -Pn (target ip) -p8080 and nothing
Please help?

fathom pendant
fathom pendant
dim ridge
#

But it doesn't accept it

fathom pendant
odd scroll
#

I know, but It filtered

fathom pendant
odd scroll
fathom pendant
#

it requires a dash

dim ridge
#

as in as a command injection

opal cape
odd scroll
#

This is what I get

fathom pendant
# odd scroll

are you running the pwnbox and your vm at the same time?

odd scroll
#

ammm I dont think

#

I use VPN conection

fathom pendant
odd scroll
#

Im use my kali on VMware

fathom pendant
#

try restarting your kali and doing it again?

#

otherwise i'd reach out to support ¯_(ツ)_/¯

odd scroll
#

OK

fathom pendant
#

i just checked the other day and it worked just fine for me

odd scroll
#

I will try

fathom pendant
#

also to be clear when i say pwnbox i'm referring to this window

#

if you hit "start instance" that starts the pwnbox

odd scroll
#

No Im just revel the target machine IP

#

"click here to spwan bla bla bla"

fathom pendant
#

ye

odd scroll
#

So I clickek

fathom pendant
#

just kinda going over all the bases

odd scroll
#

To get IP .

fathom pendant
#

as "these are common problems"

dim ridge
#

thanks again @fathom pendant

quasi wave
#

hi so for the last question of skills assessment for pivoting, tunneling, and port forwarding module, I am able to reach second pivot, including IP on subnet on the second pivot that the third pivot is also on. however, I am unable to reach the third pivot. I know the third pivot is theoretically reachable because I can rdp from double pivot into triple pivot. However, I cannot reach third pivot from attack box.

#

on local machine in my kali vm

#

can someone help me out with this?

#

I know its theoretically possible to reach it by LOL

odd scroll
quasi wave
#

and then can get it to reach it

fathom pendant
odd scroll
#

@fathom pendant untill today I used VPN and everything work fine

fathom pendant
#

check shares

quasi wave
opal cape
#

@fathom pendant hey so yesterday if you remember I was asking about the uploads.php directory for the file uploads skill assessment. I had to log off and didnt save which svg payload worked. I'm running intruder again today but its not returning any file successfully uploaded. I'm getting only images are allowed for each permutation of .svg.jpg

quasi wave
#

wait got ping to work from local machine

odd scroll
#

After restarting my Kali
same reply
wrong answer 😦

fathom pendant
odd scroll
#

How I can reach out the support?

#

what is "ig" ? sorry 🙄

#

Its all new for me

opal cape
#

It'll will bring up support and they will respond via chat

odd scroll
#

Oh thanks!

median gale
odd scroll
#

messgage them ?

median gale
#

reach it

odd scroll
opal cape
#

@fathom pendant u able to see my question?

odd scroll
#

Oh nooo wait I can't @median gale

median gale
#

I dont think you are connected with the vpn

odd scroll
#

OMG but Im in the scope.

median gale
#

ip a what ip does your tun0 int have?

odd scroll
#

I try to restart the target IP three times, and 1 time my kali

fathom pendant
fathom pendant
# odd scroll

you can try changing vpn regions and spawning a new target

median gale
#

Are you using the wrong vpn file ? Changed region and used the vpn from the last region?

fathom pendant
#

at this point you have all the ways to get it to work, don't forget about Content-Type:

odd scroll
#

There is defferent between this VPN file

#

To this?

fathom pendant
#

no

#

but still change vpn regions; and reset the target

quasi wave
#

I fixed it sorry I almost spoiled something but I deleted it.

#

but now I can reach from attack box

odd scroll
#

It worked !

quasi wave
#

hi I found the open port on the final target for the last question of pivoting, tunneling, and port forwarding. I found one way to log in but I don't think that will get me the flag. I am trying to crack the password for the suspected username using a tool from a previous section. can I DM someone to make sure I'm doing the right thing?

fathom pendant
quasi wave
#

before I saw your message

#

but thanks anyways I actually solved it myself this time

fathom pendant
#

@opal cape please don't reveal info about the skill assessment

#

The format is a valid image filetype, you don't need to do any shenanigans with it

opal cape
#

Anyways thanks

proud tusk
#

Hello can I have some help for HTB CDSA in skill assessment for Suricata pls?

#

I found a TCP segement where the data is interesting, with execution of powershell command but I don't find the flag...

frail steeple
#

hi. I'm stuck on the Password Attacks skill assessment and can't really get anywhere else. i've found the passwords for the other users but can't find where to use them. is there anybody i can dm?

wide path
#

Hello, as lot of people, I am stuck at Credential Hunting in Network Shares from the Password Attacks module. I cannot find the domain admin password in the shares. I already used the tools and tried different word pattern to search with. Can someone help me please ?

scenic current
#

Anyone having issues with the AI in InfoSec final assessment? I seem stuck at 88% no matter how I tweak my parameters. I'm Using MultinomialNB like in the spam classifier and have run out of ideas.

south marten
fathom pendant
#

@proud tusk don't dm people without permission. This is the channel to ask about module related questions

waxen totem
#

Well technically ssh only needs one command and it's also easier to remember for me

#

and you can do it straight from the ssh session you would already have open

cloud urchin
#

It's good to have multiple ways of doing the same thing in case something doesn't work.

waxen totem
#

you can do it all in one command

#

Also if you learn enough you can simply do stuff like:

ssh -w 100:any htb-student@10.0.0.0

which creates a tunnel to device tun100
-# basically a VPN, keep in mind that you'd have to setup the tunnel interface so it's not REALLY 1 command but it's a really nice connection, almost as if you're in the same network.

#

And yet it's the only one that I kept using during the SA of that module 9730zerothink

#

multiple hops with chisel and ssh is just much harder

#

-# this was before I learned about the ssh tunnel trick

#

I've tried it, have had some issues with it, moved on

fathom pendant
waxen totem
fathom pendant
#

ah

#

¯_(ツ)_/¯

quasi wave
waxen totem
quasi wave
waxen totem
quasi wave
#

That’s my take

#

Including maybe ligolo? I don’t know

waxen totem
quasi wave
#

Or is routing everything through tor just a bad idea?

#

And if not how do you be stealthy using ligolo?

#

Like for red team stuff

#

Just with a tls cert?

waxen totem
waxen totem
#

also routing traffic through tor still isn't anonymous either as whoever's in control of the end nodes can control the traffic

quasi wave
#

True

#

So do you believe in tor over vpn?

#

Ok got it

spiral spoke
#

Hi! I'm in Dynamic Port Forwarding with SSH and SOCKS Tunneling section

Is it normal that the 172.16.5.19 doesn't have the RDP port open? if yes, how I supposed to get connected to the RDP port just as the module ask? apensive

waxen totem
vast crest
#

I can't get the deobfuscation of the Crack into HTB for the life of me. 🤣 🤣

desert mesa
#

#cdsa Module: Finding Windows Evils
Problem: Was trying process injection through PID spoofing . Wanted to inject cmd.exe process into spoolsv.exe but child Process get created underneath powershell Every time i enter given commands.
Conclutions : i am missing something but even though after rereading multiple time, i am not getting it. Facing same issue on my local lab and htb's lab.

cloud urchin
#

It doesn't even look like you're getting past spawning the new instance of powershell to me. Maybe try opening your first PS with -ep bypass then running the rest of the command in that first window.

#

it looks like the rest of the commands aren't getting passed into the new session

north bramble
#

Hello. Stuck on Attacking common applications - wordpress.

msf6 exploit(unix/webapp/wp_admin_shell_upload) > run
[] Started reverse TCP handler on 10.10.16.34:4444
[
] Authenticating with WordPress using <REDACTED>
[+] Authenticated with WordPress
[] Preparing payload...
[
] Uploading payload...
[-] Exploit aborted due to failure: unexpected-reply: Failed to upload the payload
[*] Exploit completed, but no session was created.

besides this, editing the 404.php -> Unable to communicate back with site to check for fatal errors, so the PHP change was reverted. You will need to upload your PHP file change by some other means, such as by using SFTP.

HELP

sour plaza
#

has anyone finished the FFUF module? during the skills assessment, I found the page that says "You don't have access" but the answer is incorrect?

weary verge
#

Sir i am an 18 year old teenager , i want to lear cybersecurity and ethical hacking can anyone please guide me towards my first path of this journey as i don't know anything about this and i am keen to learn from your experience and guidance . Thank you

compact patrolBOT
jolly hemlock
#

guys im stuck at section Web Archives where im stuck at unable to load that snapshot as it just directs to other date showing add about godaddy

prisma pumice
young ember
signal hound
#

Hi im trying to use ligolo for double pivoting in attacking enterprise networks
But When i add another interface ligolo-double, adding the routes and starting the tunnel
Its like i cant reach the first pivot network and everything just collapse
Am i doing something wrong?

warped hawk
#

Hello everyone! I am struggling a bit with the XPath injection module. I think I am missing something, and I find difficult to even confirming the XPath Injection in some sections. Are there any good man willing to help me out, please? Thank you in advance 🙂

shell harbor
glad parcel
#

Please 🙂

autumn pilot
#

please read the #rules and do not engage in illicit stuff

shell harbor
autumn pilot
shell harbor
#

ty peepocowboylove

austere hound
#

hello!did you solve it? Also i don t reach it through the Dynamic port forwarding after tunneling with ssh -D. 77 hosts up, and 5.19 seems down.

deft veldt
#

Hello, for Abusing HTTP Misconfiguration: Premature Session Population (Auth Bypass), the flag is missing, I was able to bypass the admin but no flag or username found. Maybe rabbithole or something?

fervent iris
#

can i request a feature of search engine within the owned modules?
because a lot of the times i find my self losing details of a specific topic, but i don't remember in which module/section i read it before, a search engine dedicated to the modules will be an absolute savior

#

by search engine i mean an information retrieval system, like elastic search from microsoft

soft moon
#

new to hacking?

#

well so am I xD
but almost hitting 50% on CPTS

pliant patio
#

hi, im currently stuck on the skill assessment password attack. need some hint to move forward. i've got the password for ||betty||, ||william|| and some admin pass that does not work on the server where I got it from which is the ||jump server||.

soft moon
warped girder
pliant patio
#

thanks. will try that. i've also been spidering that ||file server|| like a headless chicken as it doesn't produce anything.

vale spear
#

hi guys i m doing the file uploads attacks - client side validation . I ve just uploaded the .jepg file and change it to shell.php , accordingly to what i ve learned in the course , but i received file uploaded correctly inside the burp request, but when i go inside the browser, i can t find my web shell , how come ?

waxen totem
# vale spear

Not sure if this was mentioned in that section but looks like content type is still image/jpeg
-# cant recall exactly which section mentions the MIME type but try to change it

vale spear
#

Inside this session it says it doesn t matter the content type

soft moon
#

Password Attacks = https://academy.hackthebox.com/module/147/section/1334
could I get some assistance with the last question
||I've tried a few flags with snaffle on a RDP session||
||then I am currently trying to search with the user jbader on evil-winrm/ while using netexec to find domain admin||
||am I heading towards the wrong direction?||

#

is this good or nah bit of a time waste?

#

damm really hmmmmm tonight is not the good night hahahaha

#

cheers this is good confidence boost, as its pulling a ton of files hahahaha

#

yeah I had to extend the time a few times, even reset it hahahaha

#

have you joined a team yet 0daybug?

craggy edge
#

"Defender has been disabled"

#

The spawned box:

dark hedge
craggy edge
rancid coyote
#

how to access general?

#

ty

wild sage
#

and did you read the source code?

#

upload.php isn't the "source"

vale spear
#

Not really, i ve chosen the other way

soft moon
#

brooo kill me I feel so dumb then again I use to work for a silly helpdesk company and it would suprise me its in that location...

young gale
#

Using David's hash, perform a Pass the Hash attack to connect to the shared folder \DC01\david and read the file david.txt.

I have the hash, I just don't know how I would connect

#

i used /pth command, but it doesnt show any files anywhere

#
xfreerdp3 /u:david /pth:**HASH FOUND** /v:10.129.180.31 /timeout:9999 /dynamic-resolution +clipboard
signal lava
#

Hi all, a quick question: when I am on a module, how and where can I see machines related to this module ?

wild sage
#

When you complete the module, it will give a list of related machines in the bottom left hand corner

rustic sage
#

Hello Can you recommend some courses for beginners?

signal lava
rustic sage
#

where can I find it?

wild sage
#

It will give you a tree of machines

rustic sage
wild sage
#

That was for white rabbit, you should look at HTB Academy and make an account. Then, go to Paths and click skill paths, it will give some modules if your completely new to IT/Cyber

bright shore
#

anyone know how to solve the second question on citrix breakout?

hasty mango
#

Is there any good hackers online I have a few questions if you wouldn’t mind

dark hedge
#

sorry, no hackers online

#

go ahead and ask your question

shy tapir
#

Do any one know how i can abb a student ID to hack the box

dark hedge
vernal tapir
odd scroll
#

Hi everyone Im on Getting Started > Service Scanning
last question about SMB service
They ask log in with bob user , Hint says "bob use weak passwords"
I wonder , should I guess? maybe there is option to brute force but the thing is we didn't learn this tool on this module, I should necessary have this background ?
I try to think from POV of person who dont have background and donst know what is brute force
I missing something?

safe star
#

@odd scroll they give you the password

south marten
odd scroll
#

I saw something like "bob | welcome1" under the SMB > SHARE explanation, but I tried this password it dosnt worked

tropic wind
#

very confused what im doing wrng here

opal basalt
odd scroll
#

Thanks I succeed

tropic wind
#

ah okay thanks

ionic notch
#

Hey

#

Does anyone got any good Token Grabbers?

opal basalt
fervent forge
#

Are there modules that teach about software security or malware analysis other than "Introduction to Malware Analysis"?

south marten
odd scroll
#

It worked thanks

tropic wind
#

I copied the id_rsa file back to home machine and I am struggling to SSH into root, I tried cleaning up the file and ensuring newline at the end but I cannot get it to work

dark hedge
tropic wind
hasty mango
#

I was wondering is there a way to put a mirror on a phone without having the phone in my hand

safe star
#

scp is promising

minor hinge
#

Is it normal for the HTB Challenges inside "Password Attacks" module to be so slow like its so hardcore frustrating sometimes. ? Does not matter if I run it on your pwnbox or my kali. Can't say I enjoy challenges who are that slow to react on anything. Do you have an idea what VPN I could use best if im from germany. I know there are like 5 or 6 for EU but maybe some are better than other VPN connections

cold star
thin citrus
#

I am working in Advanced Deserialization Attacks - Example 1: JSON. I used the provided script of the course but there is no VM to debug the app. In the screenshot I see only "$type":"System.Windows.Data.ObjectDataProvider, PresentationFramework","ObjectType":"System.Diagnostics.Process, System, Vers" Can someone help to get reverse shell and explain me this chapter. It's quite vague this section

minor hinge
cold star
stuck hollow
#

may i help? i you want dm

south marten
#

module?

fathom pendant
#

it's not really that hard lmao

#

just not many people do the modules that are outside of the job-role paths

stuck hollow
#

crackmapexec is deprecated, netexec has full support. may be thats why ppeople dont do it and is not s important

dark hedge
fathom pendant
dark hedge
#

source: i have completed it with nxc

stuck hollow
dark hedge
#

also it's part of the CAPE path, a handful of people have completed it already but are simply not online

gaunt forge
#

i wish linux privesc skills assement was fixed 😭 im sitting at 99.8% on cpts completion

dark hedge
fathom pendant
gaunt forge
#

i created a ticket a while ago

fathom pendant
#

reach back out

#

also wdym by "been down" as in, you can't spawn it?

gaunt forge
#

no it will spawn, its a super weird issue where it disconnects you and each time you ssh back into it its a slightly different environment with different files

#

you only get 20 seconds about in each one. i havent checked back in a few days, im spawning it rn

fathom pendant
#

and you've tried cycling through different vpns?

gaunt forge
#

and on the pwnbox

#

yeah its still not working

#

actually its been down since the 2nd, or maybe before. thats just when i created my ticket

fathom pendant
gaunt forge
#

your not getting disconnected after a little bit?

#

I didnt try eu vpns, i only tried all the us ones

#

yeah your right, eu works just fine

ripe turtle
#

عرب؟ 💀💀💀💀💀💀💀

odd scroll
#

HI all , starting point > web enumeration
I get that robot.txt can be useful, but they didnt explain where and how to find this file

south marten
#

I think

#

Btw, I think you get the url with gobuster

plain charm
#

Anyone stuck at Windows Privilege Escalation module's Pillaging section's last question? Its asking for Administrator Hash, which I got. But its not accepting the Hash( I tried different variations like pasting the full user:rid:lm:nt::: typed the NT hash manually, Used the full string without :::) but nothing seems to accept. anybody faced with this issue?

odd scroll
#

@south marten NO , only this

south marten
#

?

odd scroll
#

sorry I dont understand

fathom pendant
odd scroll
#

oh ok ok

fathom pendant
#

it's not a location that changes

south marten
#

Is not here?

fathom pendant
#

module ips are 10.129.x.x

south marten
#

True hahhah

odd scroll
#

I tried no succuss

south marten
fathom pendant
#

you don't generally need to scan for robots.txt

#

you can even use the --script http-enum with nmap

south marten
#

You are trying gobuster With the IP of the example

fathom pendant
#

^

#

in general you don't use the example IPs

odd scroll
#

hahaha OK

#

Sorry its new to me

south marten
#

Start the machine and use the ip

odd scroll
south marten
#

Yea, is it

odd scroll
#

thanks . How I preform access to robot.txt? First I tried write it in the URL , than I saw the cheatshet and I tried through CLI

#

Nothing work , and I tried with or without the port number

fathom pendant
odd scroll
#

I tried to specigy the port number only on the web, but not here

#

thanks! it hepled!

fathom pendant
#

when given an IP and port the PORT is important

slim locust
#

Investigate the USN Journal located at "C:\Users\johndoe\Desktop\kapefiles\ntfs%5C%5C.%5CC%3A$Extend$UsnJrnl%3A$J" to determine how "advanced_ip_scanner.exe" was introduced to the compromised system. Enter the name of the associated process as your answer. Answer format: _.exe

I got into time explorer after converting the journal to a csv. I try to look right before the "advanced_ip_scanner.exe" and I see nothing.

The moduleis Introduction to Digital Forensics in the SOC path section "Practical Scenario"