#modules

1 messages · Page 434 of 1

worthy sorrel
#

Okay great

wide hedge
worthy sorrel
#

Shoot

wide hedge
#

What is the function of file=filename?

worthy sorrel
#

To define which file you want if it is available it will download it otherwise not i guess

river grove
#

Hey guys, Im not sure where to write about boxes being down. Im doing Blind SQL Injection skills assesment and the database went offline. I reset the machine several times. I wrote in erratum but I dont want to wait several days to get help. Im paying a lot of money for this service. Now it works again

fathom pendant
#

For future reference, if someone says no to dm, then you call them an asshole. You're less likely to receive help

worthy sorrel
#

Don’t act like one so noone will call you that

fathom pendant
#

How was me saying no to a dm me being an asshole? Mind you, I said no after you already dmed and before I saw you ask

tired flax
#

In Exploiting internal Web Applications I in the Advanced XSS and CSRF Exploitation module I have found the secrete table but listing it's contents returns a 500 error. The same "select all" query on the other table works perfectly fine... Anyone can help with this?

worthy sorrel
fathom pendant
worthy sorrel
#

Sorry my mistake for what i did you enjoy your day let me enjoy mine…

fathom pendant
#

What module is this for anyway? If its not directly related (i.e. a module is telling you to do this/giving instructions) then it's better for #programming or #red-team

wild sage
#

You have half the answer right there. You need to curl the download.php of that website to get the flag. Go back and look at the curl commands

civic fiber
#

for other module like Using the Metasploit Frameworkseem is ok for me.

#

Can someone from Hackthebox solve this issues?

fathom pendant
#

the shells and payloads module has the jump box you start with via rdp; that has all the tools you'll need

fathom pendant
#

the 10.129 ip is your jump host

civic fiber
#

for few days now. On Monday is ok for me.

fathom pendant
#

try changing vpn regions

civic fiber
supple dragon
civic fiber
fathom pendant
civic fiber
#

I mean some lab is ok for me.

#

I had problem only this module Shells & Payloads.

fathom pendant
#

if changing vpn regions doesn't help reach out to support on the website

civic fiber
#

FeelsBadMan is very annoy me. I just want to review before taking exam.

upbeat swift
#

Anyone have solved the artificial lab I’m stuck on smth wanna know it

fathom pendant
meager phoenix
#

Hi, im working on the Password Attacks: Credential Hunting in Network Shares and am struggling with the 2nd question (As this user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?)

Ive managed to find jbader's details but not sure how to proceed from here, ive run Snaffler but was just overwhelmed by the amt of output it gives lol

fathom pendant
meager phoenix
fathom pendant
worthy sorrel
#

You can try man spider and nxc but they didn’t worked for me

tropic wind
#

https://academy.hackthebox.com/module/116/section/1466
I have the login for the user, i accessed the SQL server but wasnt finding anything, i found two .txt files in ftp with the second one signifying that if i can upload a file i can access it, but i don't know how to get to upload

meager phoenix
worthy sorrel
#

If you look harder they are actually in front you your eyes

#

Just look at what looks suspicious

#

Dm i’ll give u a little hint

tropic wind
fathom pendant
#

there's multiple "proper" ways to do it

#

one being "Get-Content" nxc smb has a pattern option

worthy sorrel
#

Anybody who can help a little regarding password attacks skill assessment got password in file01 but to get on jump01 server getting no idea and nmap just showing rdp which is not possible

#

Any little hint would be helpful

tired flax
grizzled schooner
meager phoenix
grizzled schooner
#

quick question on

Attacking Common Services | Attacking SMB if anyone has a second, please @ with replies

grizzled schooner
#

I want to say that the module is being a little whacky --> used the pw list given in resources and no results are being returned for the user they're asking for... I've let it run a couple of times, and additionally reset the machine as well

icy egret
#

guys need help with this

"Check Carlos' crontab, and look for keytabs to which Carlos has access. Try to get the credentials of the user svc_workstations and use them to authenticate via SSH. Submit the flag.txt in svc_workstations' home directory."

I did find AES hash , but not able to find the password for the svc_workstation. Yes I found the second keytab, but i am lost. Helppp

fathom pendant
#

iirc they give a website you can use to crack some hashes

#

i think crackstation? it's been a hot minute

faint geode
fathom pendant
#

@azure mantle this isn't the server for that

fleet charm
#

I'm having a bit of a problem. Im unable to complete the skill assessment for Web Fuzzing. I've got the flag, but one of the questions is asking for a url, and it won't accept the url even though that is where I ended up finding the flag

fleet charm
#

oh, fair enough

#

Thank you for the help!

fathom pendant
#

np; plenty of people get hung up on that

opal cape
#

Hey if anybody has done the miscellaneous techniques module in Windows Priv Escalation Module, which account is the question referring to? i have the hashes for all but none work as the answer

#

am i using the wrong wordlist with hashcat? is rockyou not enough?

visual marsh
scenic basin
#

Hello

odd scroll
#

Hi . I want to start this machine. Where I get link to download update VPN file ?

slate zinc
#

remember to pick the correct vpn too

odd scroll
#

thanks!

opal cape
#

can anybody lend a hand on windows privilege escalation module?

limpid bay
#

Hey

wild valve
#

it's the footpriting module

#

section imap/pop3

#

i can't find that flag and the admin mail can someone help me

opal cape
wild valve
#

no

wild valve
opal cape
wild valve
#

did i use the openssl client

#

yes

opal cape
#

and you logged in with given robin:robin creds?

wild valve
#

robin ¿¿¿¿¿

#

it's not in this section the user robin

opal cape
#

wym? they give it to you

#

its robin:robin

wild valve
#

it's just the example

full patio
#

Can anyone help with:
The packet capture contains cleartext credit card information. What is the number that was transmitted?

From https://academy.hackthebox.com/module/147/section/3715 - Credential Hunting in Network Traffic

I've got Wireshark open and I've used Pcredz, but can't see it anywhere. ||I know the Hint says to use Regex||, but I'm not sure how to apply that in Wireshark.

opal cape
#

"In the SMTP section, we have found the user robin. Another member of our team was able to find out that the user also uses his username as a password (robin:robin). We can use these credentials and try them to interact with the IMAP/POP3 services."

wild valve
#

ahhh

opal cape
#

@wild valve thats what it says at the end of the notes

wild valve
#

sorry

opal cape
#

np

full patio
wide path
#

Hello, I am doing AD Enumeration & Attacks and I just finished assessment part 2 but i have a question regarding the flag about inveigh if I can DM someone

safe star
#

that part never made sense to me if im thinking about the same part

safe bramble
#

Guys curl doesn't work on my pwnbox, wtf is wrong, it shows nothing

fathom pendant
#

that's not useful or helpful for us to diagnose anything at all

uneven shale
#

A

wide path
odd scroll
#

Hi, Im right now doing the machine TwoMillions
after I tried every exploit under the name "nginx" withour success , I turned into video explaination
He saw the redirect from the IP number to hostname and than he does something I dont understand
It was very quick and I never learned this before
He uddate somewhere the resolve of the IP number to the HOST NAME like DNS does, but where he go
What is this pleace
and also Why he does that?

#

"bla bla bla put this in... now the scan with nmap should work bla bla because that why, dont you see how.."

#

Please help , can someone explain me? 🤷‍♀️ prayge

#

He said "If I have the hostname there" where is "there"
and second after that he refresh the website and he got valid page 🤔

opal cape
odd scroll
#

Oh.. But why ordinary DNS dosnt work this case?

wild sage
#

Basically what he is saying is, if you're unable to connect to the website through your machine. You have to add the ip address and the name associated with it to your /etc/hosts file. That file is read by your linux to basically say "Hey, this IP address is this website" and when you enter either the IP address or the Domain Name. It will be able to find it.

odd scroll
#

thats what I dont understand, first time I do something like that

wild sage
#

If it's a private website, DNS won't be able to find it or know it

odd scroll
#

ohhhh

#

Its something that happened a lot on CTF ? or chakkanges ?

opal cape
#

yeah anyone else having trouble using xfreerdp right now? or is it just me?

odd scroll
#

You help me thank for you reply and your time, It not obvious

odd scroll
#

helped

opal cape
# wide path what is your problem ?

im literally trying to connect to this machine in the Windows Priv escalation, WIndows Server Module. Xfreerdp keeps failing. Ive tried to use different region and VPN server. Even tried refreshing target IP

wide path
#

what's your command ?

opal cape
#

xfreerdp /v:10.129.150.46 /u:htb-student /p:HTB_@cademy_stdnt!

#

it keeps throwing me "[ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
"

#

I was just using xfreerdp in the previous module without problem. Thats why im wondering if there is an issue internally for this one specifcally

wild sage
#

Did you forget ' ' for the password?

#

so /p:'PASSWORD'

#

also if you want a bigger RDP screen use /dynamic-resolution

opal cape
#

yes i have the password above, ive been using the same command for the past modules in Windows Priv Escalation so theres no reason i cant get in.

#

im gonna move onto the next one "Windows Desktop Versions". If it works then its a problem with the Windows Server Module

opal cape
#

Yeah guys the other modules allow xfreerdp connections the Windows Server module in Windows Priv Escalation is having issues

jolly oasis
#

Does anyone have a quick second to help me with the final question on Attacking Web Applications with Ffuf > Skills Assessment - Web Fuzzing? I've found the parameters correctly and am fuzzing values. Pretty sure my commands are right but I'm not getting results that would indicate a valid value.

opal cape
#

NVM guys i literally missed the Note in the module that said "Note: If gives you errors, try using rdesktop -u htb-student -p HTB_@cademy_stdnt! [IP Address]"

#

smh

vocal oriole
#

Hello guys! Im new here so i dont know if this is the right channel to talk about this but i will give it a shot. I ve been working on the WiFi penetration testing basics lately and i encountered a problem regarding a question. Could anyone help me with that?

wild valve
#

hi

#

i cant turn the hash into the password

fathom pendant
#

separator unmatched means you copy/pasted the hash incorrectly

wild valve
#

how can i do it correctly ?

fathom pendant
#

you just copy/paste as it's shown, you don't add anything to it

#

it helps as well to know what module and section you're on

cloud urchin
#

it can also be because you're using the wrong mode with the hash

blazing loom
#

In the "Information Gathering - Web Edition" module, in the section "Creepy Crawlies", there is a script called ReconSpider.py. This script is downloaded from HTB rather than a tool on github. (Though there is a tool on github with the same name, but it is not the same). Is this script just a demo of what can be done with regard to recon? Or is this a script that we should save and have access to for future recon (such as the exam or future boxes)?

fathom pendant
#

it's pretty nifty and useful

sharp siren
#

Hi everyone I need to help in intro to whitebox skill assessment 2 (patch) module? Anyone here complete it?

#

I patched using different ways but I can't pass the test

wild valve
#

can someone pls crack the hash for me

fathom pendant
#

7300 is ipmi so i'm gonna assume the footprinting module. ipmi section

wild valve
#

@rustic sage just helped me

#

what a goat

#

can someone help me LC_peepo_shy

#

it's the dns section

#

same module

#

ok

#

i will try

wooden orbit
#

Hi everyone I need to help, I try to install de SO recommend for HTB but when I execute the SO, the machine have a issue,the installation gets stuck and I have an error

#

does anyone know how to fix it

fathom pendant
hollow kernel
#

With dnsenum

#

Its any way to accelerate the proces?
With the script in bash it take too much times too

fathom pendant
#

I mean you can probably script with dig, but it'd take a while

wild sage
#

Recon can take a while, same with fuzzing. Just sometimes gotta sit there and let it run

#

Best time to stretch

waxen totem
#

The lab for this was pretty stupid the logrot only worked 1/20 times when I did it

halcyon dagger
#

Thanks for sharing bro!; I have the same f68king question - WHY ISN'T THE INTENDED METHOD WORKING. HACK THE BOX PLEASE FIX THIS! - I spent 5-6 hours on this one question.

cloud urchin
#

Sometimes there are issues with modules. If you believe that's the case you can report it in #1234357888114364508. Pretty much every time I ran into something like that though I found I wasn't doing something right.

trail forum
#

hey im on the first lab for the linux enumeration lab. i feel like its not straight forward at all how they made the lab. could someone help me out real quick? i would really appreciate it.

cloud urchin
#

best to state exactly which module, section, and question you're on

trail forum
#

ok. im on the environment enumeration section, linux enumeration module, and im on the "Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer." question. i think they changed the way the answer is found because the forums i found with how to get the answer arent correct.

cloud urchin
#

linux enumeration isn't a module. is this linux fundamentals?

trail forum
#

oh, thats my bad. the module is Linux Privilege Escalation

#

got it confused

cloud urchin
#

ok send me a dm

visual fractal
#

Im confused about Reflected XSS exploitation. Say you found a POST request that takes your name and imedaietly returns it and you were able to inject JS in it.

What could you do to exploit that?

visual fractal
#

please

charred mountain
#

Hi Guys, should I use this channel for doubts about a specific exercise of Password Attack module?

cloud urchin
#

yeah this channel is for talking about the modules. you can follow instructions in #welcome to gain access to most other channels in the server too.

waxen totem
chilly echo
icy cairn
#

Hello

chilly night
#

am i supposed to run the linux and windows vm inside of the proxmox environment vm? referring to the first 3 modules (virtualization linux windows)

#

or do i run them in oracle

cloud urchin
#

best to say the specific module and section. but i've never heard of that setup. people generally just run a windows machine with a vm.

wary wren
#

In attacking common services in this drupal question Work through all of the examples in this section and gain RCE multiple ways via the various Drupal instances on the target host. When you are done, submit the contents of the flag.txt file in the /var/www/drupal.inlanefreight.local directory. Even tho i enabled that php filter module it doesnt seem to show

waxen totem
#

Deleteing this cos it contains spoilers, just ask for help and talk in DMs

past halo
#

who can help with Skill Assessment Password Attacks dm me pls

hardy trout
#

Where should I start with coding

waxen totem
#

start simple, for instance a simple command line adder, then slowly make more complex projects, keep it related to stuff you're interested in and passionate about

ivory flame
#

Hey, guys. Im currently doing Question number 2 on the Cracking Protected Archives of the Password Attacks module. I've found the flag.txt inside the VHD, but when I submit the contents, it's stated as wrong

acoustic owl
ivory flame
#

Okay, thank you

zenith depot
#

Does anyone else’s hashcat be bugging out

desert magnet
#

hi, I have the problem with module INTRODUCTION TO RED TEAMING AI section Manipulating the Model,
first two question, that are affirmitive sentences, requiers to submit an answer but does not specify what needst to be submited, and I'm stuck with this questions

fleet charm
# hardy trout Where should I start with coding

Considering you're in the HackTheBox discord server, decide what wrappers you might want for the cli tools you use, and figure out how to make those wrappers in bash or powershell. This could be something like making a script that allows you to run a single command that only takes a single domain parameter which runs ffuf for you with whatever predefined parameters you generally want to include when you do dns scanning. Or maybe you want to do vhost scanning and want to be able to quickly give the domain name once instead of manually writing out the headers. Then as you progress, you can expand that to maybe create wrappers for multiple tools, where you run a set of tools in an automated sequence.

Maybe this is not how you should go about starting with coding, but you might learn some things, and would be doing so within a setting that is directly releveant to your interests, which is usually a good hack to stay on task and be more motivated to learn and experiment

sterile solstice
#

need some help please :). I'm doing the 'Identify SSRF' section of the 'Server-Side Attacks' (https://academy.hackthebox.com/module/145/section/1295) and I can't see to get the answer to the question. I have found the 3 ports that are open, and I've tried to browse them, but I get nothing so I can't find the flag. Is anyone able to help?

mellow rapids
#

Hi everyone! Wanted to reach out since I am have been stuck for a couple of days on one of the File Upload Attack questions in the module. So I was able to edit the code on the client side using DOM then I intercepted the request and used Burp after doing the extension fuzz.

#

Also tried changing the values for the file to the injection using a couple of extension formats for the payload and none work.

#

Revise the source code as well for to review the js executing in the backend to see what type of filters. The interesting thing is that I was able to successfully upload the file but on the src= url --> it was changing the format to data:image/png/base64/

#

Does any one know if I need to deobfuscate the min.js file to see if there is more blacklist filtering meaning if its not an image file it will change the value from profile_images/file.type ?

wooden seal
#

thanks

wooden seal
#

Mods, i have founded some pastebin link (containing htb academy writeups above tier 0) you guys want link to take it down maybe?

autumn pilot
#

You can use /spoiler

pliant comet
#

hello i need some help on Skills Assessment - Web Fuzzing

heres the question im stuck on

#

||One of the pages you will identify should say 'You don't have access!'. What is the full page URL?||
heres my problem im looking at the page that says the key word needed and have put the full page URL yet the answer is comming incorrect

azure turtle
#

remmina is literally the best for windows RDP. how come xfreerdp is so laggy?

warm tartan
#

Hi, i have some issues with the RDP on module Passwords Attacks - "Pass the Ticket (PtT) from Windows" : [09:09:00:593] [6777:6778] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_LOGON_FAILURE [0xC000006D] from server
[09:09:00:593] [6777:6778] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_LOGON_FAILURE [0x00020014]
[09:09:00:593] [6777:6778] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[09:09:00:593] [6777:6778] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1
The creds are good : xfreerdp /u:Administrator /p:AnotherC0mpl3xP4$$ /v:10.129.84.166 +clipboard

#

okay with remmina works...why not

sacred rock
sacred rock
warm tartan
odd scroll
#

Usually how long it take?

grizzled schooner
#

I'm actually completely lost on Attacking Common Services | Attacking SQL

I have no idea where to even start... Used mssql, and can't access anything, tried xp_cmdshell etc and nothing is working lol - SQL is one of my weakest spots and I could really use a nudge

fathom pendant
odd scroll
#

thanks

grizzled schooner
#

thanks

grizzled schooner
# fathom pendant stealing hashes

Bit confused, tried to set it up like the module shows, and responder is just stuck on listening for events, but from what I have tried on the sql side I'm not really able to do anything

fathom pendant
#

use the right interface that can be called to :)

grizzled schooner
#

tun0?

fathom pendant
#

xp..dirtree

grizzled schooner
#

yeah that's what I did

#

oh okay nevermind

#

I thought you had to do dirtree before responder not after

zinc mantle
#

Hey, can anyone provide a hint for the skill assessment for NTLM relay. I am on question three but I am a bit stuck. I have got backup01 access, have my own machine account but I am stuck trying to get the password for sqlftp?

fathom pendant
grizzled schooner
#

lmao

#

Should rockyou work to crack this though? I think I found the right hash, but nothing seems to be cracking it? figured I'm either looking at the wrong one, or I'm doing something wrong

fathom pendant
#

i don't recall if that module has a wordlist

grizzled schooner
#

Just a bit lost - I have the output from responder, but I can't get the hash to crack

#

I have

mssqlsvc::WIN-02:<hash>:<Should be NTLM>:<Super long hash>

But running both hashes through hashcat don't give me anything

fathom pendant
grizzled schooner
#

when I do mode 5600 [googled for NetNTLMv2 mode] it doesn't load any hashes lol

#

nevermind - didn't know the format had to be the whole responder output

pale sparrow
#

Hey anyone know why hashcat is getting bug out on using pdf hash I tried there pdf example hash it give seprator mismatch error or token length exeption 🥲

#

I need help

#

Anyone can help me

#

Hello

#

Anyone here

cloud urchin
#

no need to spam, be patient

grizzled schooner
grizzled schooner
native turtle
#

anyone have problem with spawning targets?

grizzled schooner
#

additionally double-checked to see who I could impersonate and the mssqlsvc account isn't listed

#

-- nevermind apparently it just wants to work now?

granite wedge
#

Easiest rooms for newbie or academy? To start...

grizzled schooner
#

rooms being...? Boxes?

upbeat dust
#

hi

#

i keep getting wrong answer no matter what

#

can some one just give me the answer

#

?

dusty ledge
olive juniper
#

Hi all, I'm stuck on this Android Fundamentals module question:

Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test)

I made the device, but my answer is never correct, any help would be appreciated.

iron parcel
#

Hello, can i have a nudge for Skills Assessment - Password Attacks

fathom pendant
wild valve
#

pls module footpriting section dns

#

since yesterday i can't find it

#

and i have to finish this module today to keep my rhythm

violet crow
#

Are there all levels of Hacking learning s available on this platform? from beginner to expert?

or like only advanced and expert?

wild valve
#

in labs there is rank?s

granite wedge
#

@wild valve maybe scan all the vhosts?

wild valve
granite wedge
#

Maybe rev DNS?

#

nmap -sL ip/24 | grep 203 ?

#

@wild valve

main light
#

Guys im new to this what i got a hp pc horrible slow what should i do

granite wedge
silk lagoon
#

“Wordlist that contains more internal subdomains”

wild valve
#

subdomains-top1million-110000.txt ?

silk lagoon
#

There’s another one that is more targeted for this question

willow gull
wild valve
#

he said horrible pc

#

and you think dual boot is the solution

#

he will lag more

#

cause windows is stupid

willow gull
wild valve
#

you think but not

fiery maple
#

Hey I'm doing this artificial linux machine, but I can't comprehend what to do I did nmap then I see http open but in the web browser it doesn't works please help

silk lagoon
tired flax
#

Someone out there can help me out one Advanced XSS and CSRF Exploitation , the skill assessment?
Im stuck on first part

wild valve
# silk lagoon It’s within seclists/DNS

i only have this bitquark-subdomains-top100000.txt deepmagic.com-prefixes-top50000.txt fierce-hostlist.txt namelist.txt shubs-subdomains.txt subdomains-top1million-110000.txt tlds.txt
bug-bounty-program-subdomains-trickest-inventory.txt deepmagic.com-prefixes-top500.txt italian-subdomains.txt README.md sortedcombined-knock-dnsrecon-fierce-reconng.txt subdomains-top1million-20000.txt
combined_subdomains.txt dns-Jhaddix.txt n0kovo_subdomains.txt shubs-stackoverflow.txt subdomains-spanish.txt subdomains-top1million-5000.txt

silk lagoon
#

It’s one of those

#

And the size isn’t that big

#

Check for the one that has more internal subdomains

wild valve
#

so i use ffuf ?

silk lagoon
#

For what

fiery maple
#

could someone help me in the module artificial linux easy please

silk lagoon
fathom pendant
fathom pendant
#

ls -lSr can sort by size (ascending)

past halo
fathom pendant
past halo
#

okay thank you

sick depot
#

Can anyone help with this question on the using crackmapexec skills assessment Gain access to the DEV01 and submit the contents of the flag located in C:\Users\Administrator\Desktop\flag.txt.

quasi tapir
#

hello, i need help on password attacks skills assessments, i managed to rdp to jump01 trough the user bd** and i have the crendential for st and the 2 passwords of hw** but i don't know how to escalate or to move to dc01

hollow kernel
#

Hi im in the question of imap/pop3
Figure out the exacto organization name from the IMAP/POP3 services and submit it as the answer
I put this information and doesnt work i don't understund why im putting the exacly organization name

hollow kernel
snow spoke
tall imp
hollow kernel
#

Footprinting but i solved thanks you

tall imp
#

If you have any other questions, please write to me privately.

tired flax
#

some can help me in the module Advanced XSS and CSRF Exploitation in the skill assessment

sterile solstice
#

need some help please :). I'm doing the 'Identify SSRF' section of the 'Server-Side Attacks' (https://academy.hackthebox.com/module/145/section/1295) and I can't see to get the answer to the question. I have found the 3 ports that are open, and I've tried to browse them, but I get nothing so I can't find the flag. Is anyone able to help?

sterile solstice
#

sent

stone zephyr
#

currently doing the AD set, does anyone have a quick and easy way to get host names & ip addresses at once?

#

i.e less messy than nmap

stuck hollow
#

but i always use nmap

round marten
#

get-netcomputer/ldap to dump computer names then a script to resolve them in DNS work?

fathom pendant
#

Means you need an admin to dump

cinder tree
#

Why is my nmap -p- -sV take so long to scan

stuck hollow
cinder tree
#

I preciate the info king

#

Thank u bro

#

Do you run each individually

wary wren
#

can anyone help me in this Work through all of the examples in this section and gain RCE multiple ways via the various Drupal instances on the target host. When you are done, submit the contents of the flag.txt file in the /var/www/drupal.inlanefreight.local directory.

#

I dont seem to find PHP code while making a basic page

#

ya but i dont get that option

#

Okayy but i dont get that php code option

#

Plguin is also enabled

hasty radish
#

I just finished my eJPT, instead of feeling happy I realised I know nothing 😂

fathom pendant
#

yeah eJPT is bottom of the barrel next to CEH and Pentest+

sick depot
#

Can anyone help with this question on the using crackmapexec skills assessment Gain access to the DEV01 and submit the contents of the flag located in C:\Users\Administrator\Desktop\flag.txt.

fathom pendant
#

also they aren't really contradictory

sterile path
#

I think I get it

#

ones for the directory, the other is for the file right?

fathom pendant
#

basically

wicked hemlock
#

THIS -P- -SV IS TAKING FOREVER

fathom pendant
#

well yeah -p- is scanning all ports

#

:)

#

and -sV runs a version grabbing command

wicked hemlock
#

then why is the guy on the starting point official writeup doing it

fathom pendant
#

try adding -sT to the command

sterile path
wicked hemlock
cloud urchin
fathom pendant
#

looks like you're doing ban evasion :)

wicked hemlock
#

yea i got banned a year ago for a little troll

#

but lets not focus on that rn

sterile path
#

lol

fathom pendant
#

looks like it's expired anyway

sterile path
#

thanks for the help btw

wicked hemlock
fathom pendant
#

dm

wicked hemlock
#

sec

fathom pendant
#

this isn't the right channel

#

read and follow #welcome to access more of the server

rain mirage
#

While Footprinting dns , what can I do with a txt record and in the most cases the dns is dug to discover more domain and sub domain right ? @fathom pendant

chilly night
#

im trying to download the windows developer os from the module "windows"it keeps getting corrupted and it says on the windows site downloads are currently not allowed

does anyone know anything about this?

rain mirage
#

Cos I'm rn doing the Footprinting -easy and I came across dns,ssh,ftp the gole is to find the flag.txt which probably will be in the ssh . So to connect to it i will be needing credentials , I don't see how dns will come to picture .

cloud urchin
chilly night
#

setting up

#

you can still download the developer zip from teh link int he guide, but for me its jsut corrupted.

and on the windows site it says they arent allowing downloads for it right now

shadow canyon
#

hello need to know something

cloud urchin
fleet charm
#

EDIT2: It was 2-way IPS on the router

EDIT: tried to run it on the parrotbox, and it worked fine. It would seem that there is something on my end catching the request and filtering it. Might be something on my router

sql injection - union injection. Whenever I try to construct an injection, following the same or similar format from the article, the request just hangs. Anyone know what might be up with that?

sterile solstice
rain mirage
sterile solstice
#

no problem

#

was it dns related? i dont remember

rain mirage
pale pond
#

I am receiving the error below when running ntlmrelayx.py

[(‘SSL routines’, ‘’, ‘no protocols available’)]

Command:

``root@ubuntu:~# sudo ntlmrelayx.py -t mssql://INLANEFREIGHT\NPORTS@172.16.117.60 -smb2support -socks -debug`

sacred ermine
#

I guess in the module Windows Lateral Movement the section SMB needs to be reviewed, seems the lab is broken, I even uploaded the bin on host SRV02 but that's not even working and as I have seen through the chat, many people have complained about it not working

sacred ermine
#

not via sudo, that should help

#

its mentioned in the course as well afaik

pale pond
#

Thank you!

wild oriole
#

Hello guys, I am facing issue hen connecting RDP into Windows hosts, the UI is too small I bearly can see the PowerShell output.
Connecting from an external monitor 4K/Mac M1

sacred ermine
scenic basin
#

Hello

wild oriole
steel shadow
#

B

sacred rock
#

It is in the works still, not yet available.

rustic sage
#

Hello i need help

fossil jacinth
#

In File Transfers > Windows File Transfer Methods - The Astaroth attack link points to Page Not Found
Instead of /en/security/blog it should be /en-us/security/blog

sacred rock
sick depot
#

Has anyone completed the using crackmapexec module

rustic sage
#

I'm not sure if this is the right place, apologies if it isn't

But do the prices change to CAD if you're in Canada or is it USD? I was looking into VIP plus

twilit cape
#

can anyone explain me what a index is

rain hawk
opaque cosmos
#

hello i am doing Windows Event Logs & Finding Evil mini-module badgeMini-Module
Page 2
Analyzing Evil With Sysmon & Event Logs Replicate the Unmanaged PowerShell attack described in this section and provide the SHA256 hash of clrjit.dll that spoolsv.exe will load as your answer. "C:\Tools\Sysmon" and "C:\Tools\PSInject" on the spawned target contain everything you need. got the answer ||8D09CE35C987EADCF01686BB559920951B0116985FE4FEB5A488A6A8F7C4BDB9||
saying incorrect

#

pls help

prisma dawn
#

Now our client wants to know if it is possible to find out the version of the running services. Identify the version of service our client was talking about and submit the flag as the answer

Anyone with solution with this please help

#

This is from enumeration

#

LaB3 hard

prisma dawn
#

@snow spoke have tried nmap -sV -sS "T2 or T4" -Pn target IP

snow spoke
#

send me a PM ^

prisma dawn
#

@snow spoke also -D RND:5

snow spoke
# opaque cosmos pls help

I dont mind trying to assist but I havent done that module yet. I imagine 2 minds are better than one! send me a PM

dim ridge
rough comet
#

Hi folks. Can someone please help me with the Skills Assesment for "Wifi Penetration Basics"?

#

On question 2. I keep getting this error
: Packets contained no EAPOL data; unable to process this AP.

#

I already tried to || de-auth clients and re-run airdump || That did not work. I also reset the Lab.

rough comet
boreal sparrow
#

i see the build number but not in the format they show (edit: found it, not sure why it's called build number though)

humble wraith
#

Anybody here notice that in the Using Web Proxies section of the Bug Bounty Hunter course they tend to just explain how to use a pre-scripted tool, then teach nothing about how to actually exploit a vulnerability found by them? The questions at the end of each section are usually solved by information that is entirely separate from the module and its getting frustrating having to look up some guide for every single question to find that the answer is usually "yeah that tool is broken, you gotta use this other tool that they didn't teach about at all actually"

#

I'm looking at you, OWASP ZAP HUD

modest lichen
#

have anyone had problems with the victim machine in the Linux Privilage Escalition Module? i can't even write 2 commands before freezing

zenith magnet
#

I needed help with the running sqlmap on an http requests section of the sqlmap essentials module, specifically the question "What's the contents of table flag2? (Case #2)
"

blazing pagoda
#

hi guys i'm having problem with zap during the Intercepting Web Requests module, i don't know why the instruments doesnt appear also if hud is enabled and more general to solve that part of module

sick depot
#

Does anyone know why my account wont work on hthe hrb forum

cloud urchin
#

The forum was sunset and replaced with Discord

#

You can gain access to more channels for discussion by following the rules in #welcome.

sick depot
#

Ok thanks

limpid siren
#

I am stuck in the info gathering- web edition module's last ATQ, it says to "give the full domain to mail records for facebook.com" but when I enter the domain that I'm getting after doing

dig facebook.com MX

It shows incorrect answer. Maybe the mail server was updated anyone knows the old one so I could pass on with this section

#

okay I did it again it passed😭

round marten
#

do may some1 can help me out with the second flag on DACL-2 for the Skill Assessment? I am quite far, but a little thing is missing right now. Since I don't won't to spoil anything, feel free to send me a DM.

somber gust
#

Password Attacks - Skills Assessment. I'm in DMZ01, used the chisel to make the pivot. with ||proxychains -q nmap -sT -Pn 172.16.119.11 --open -p 5985||, i've found the service ||wsman||. In the machine DMZ01 I can only ping ||172.16.119.11||. Can anyone give me a light?

humble wraith
blazing pagoda
celest chasm
#

hey i need help

humble wraith
celest chasm
#

im kinda new to HTB, I'm having trouble with the Metasploit learning stuff in HTB Can I get any help

#

ik the metasploit stuff but its the server

humble wraith
#

what are you working on?

celest chasm
#

im working on metasploit but then i set up or run a target and i cant get meterpreter session open on the target

#

i have the vpn up in running but yet again i try to gain access to the target machine the (HTB) it doesnt work idk why

#

i need help please

humble wraith
#

What is the module name?

#

I am also new to HTB, so I may not be much help

blazing pagoda
humble wraith
#

ok!

celest chasm
#

can someone help me like seriouslu

hollow kernel
#

Hi im in the oracle of footprinting module
I have a problem it doesnt work odat.py because the py import asyncore and in the new pyhton modules was eliminated

snow spoke
celest chasm
#

pm?

snow spoke
tall imp
# hollow kernel Hi im in the oracle of footprinting module I have a problem it doesnt work odat....

Según las fuentes, ODAT (Oracle Database Attacking Tool) es una herramienta de prueba de penetración de código abierto escrita en Python. Está diseñada para enumerar y explotar vulnerabilidades en bases de datos Oracle, incluyendo inyección SQL, ejecución remota de código y escalada de privilegios.

Los pasos para configurar ODAT en un entorno como el Pwnbox o un sistema similar, tal como se describen en las fuentes, son los siguientes:

  • Descargar los paquetes instantclient-basic-linux.x64 y instantclient-sqlplus-linux.x64 de Oracle.
  • Crear un directorio /opt/oracle y descomprimir ambos archivos ZIP en él.
  • Configurar las variables de entorno LD_LIBRARY_PATH y PATH para incluir la ruta del cliente instantáneo de Oracle.
  • Clonar el repositorio de ODAT desde GitHub (git clone https://github.com/quentinhardy/odat.git).
  • Navegar al directorio odat/ e instalar las dependencias de Python:
    • pip install python-libnmap.
    • git submodule init y git submodule update.
    • pip3 install cx_Oracle.
    • sudo apt-get install python3-scapy -y.
    • sudo pip3 install colorlog termcolor passlib python-libnmap.
    • sudo apt-get install build-essential libgmp-dev -y.
    • pip3 install pycryptodome.
  • Después de la instalación, se puede verificar si ODAT funciona correctamente ejecutando odat.py -h.
hollow kernel
#

I deleted all the functions of tnspoison and it worked

#

In the code

tall imp
chilly night
#

backui

lunar oracle
waxen totem
#

It only worked for me when using the builtin ZAP browser

#

though it still did have its own issues

lunar oracle
waxen totem
sacred ermine
sage oyster
#

there is someone who completed wifi basics module ? i have a question

cloud urchin
sacred ermine
#

the second question:
Use any tool to get a shell on SRV02 using the service Application Layer Gateway Service (ALG) and read the flag located at C:\Flags\serviceflag.txt

The problem is,, the user that suppose to connect to smb share is not connecting, instead the machine$ does it, and the problem is always that it cannot find the file, but when I uploaded the file on host srv02, it was not giving such error with FILE_ERR_NOT_FOUND was something similar

so instead, it just was not giving any results, no revshell no nothing

devout delta
#

Dear Guys,

Need your help with Login Brute Force Skill assessment section 2 , I am stuck at the FTP user identification there are so many username in username anarchy can you plesae help me with the right username file .txt so i can save some time

sacred ermine
cloud urchin
sacred ermine
cloud urchin
sacred ermine
cloud urchin
#

Please take care not to spoil content from modules above tier 0

sacred ermine
#

oh, alright, my bad

#

so you basically, hosting the SMB share, where you provide the destination file of your revshell that is in the SMB

cloud urchin
#

I'd suggest going back over the commands to ensure you're running the correct command and correct syntax in the order it shows

sacred ermine
cloud urchin
#

you were missing a lot of steps

sacred ermine
meager zealot
#

@everyone
I am just gettin started and am in the setting up module. I was downloaded parrotos image and got it on vm. and then setted up debian.
the academy said:

"""The operating system will now begin installing, and when it completes, the virtual machine will automatically restart. Upon reboot, we’ll be prompted to enter the encryption passphrase we created earlier to unlock the encrypted system and proceed with booting."""

However, I wasn't asked for the passphrase, or asked me to log in anywhere. (I did create one, and the system did reboot). and now I dont know what to do. Help please

river grove
#

Hey guys, im doing Error-Based SQL Injection in Advanced SQL Injections and i got the password link but htb sais its not correct. Would appreciate if someone can check whats wrong 🙂

cloud urchin
#

@brittle bridge This server isn't for you to advertise in like that. This channel is specifically for discussion of the various modules on Academy. Please familiarize yourself with the #rules and follow the instructions in #welcome to gain access to more appropriate channels like #ai-ml-llms.

brittle bridge
#

Oh sorry I won’t repeat

clever geyser
#

Hi everyone,
I have added the ip and subdomains and domain to the /etc/hosts file but, not able to access it via my kali. but, its accessible via pwnbox. idk why is that

#

(I had to add them to /etc/hosts in pwnbox too)

cloud urchin
#

Are you using the pwnbox and your VPN at the same time?

#

If so, don't. They use the same IP and it will cause network conflicts and is likely the reason you're having issues (if you use both at the same time that is.)

silver sapphire
#

Hey, I have very limited webshell on windows machine but I am not able to make any connection like download file, make reverse shell. Any ideas why? What could cause that?

waxen totem
devout delta
waxen totem
devout delta
chilly night
#

why vpn servers so laggy

devout delta
#

A slight of the help to which folder to look for the username that will be a great great help

waxen totem
devout delta
#

I am on the server I am at the Flag section trying to crack the FTP username @waxen totem

waxen totem
#

you're on the part when you already have access is what I'm asking?

devout delta
#

I am at this section , I have the username and password for the SSH Account, now i am trying for the FTP

#

The Flag is kept at the FTP server as the server is open , I am trying via medusa and Hydra , O M Lord its too much time consuming specifically for the working professional-- I don't know why HTB did this a list of 10 was also good but they kept tons of list

#

@waxen totem ,

waxen totem
#

Wait I'm confused, you're at the skill assessment section right?

chilly night
#

is there some sort of event on, these servers are cooked. when does it finish

devout delta
waxen totem
waxen totem
devout delta
chrome dawn
#

Hello all, in the module Active Directory Enumeration - Visualizing Data - Nodes, there is a question regarding Sarah being a local admin somewhere. Has anyone run bloodhound community and got the actual result? I know I could use the provided zip file but I wanted to get the result from SharpHound and visualize it in bloodhound-ce

clever geyser
#

this has been running for 20+ minutes now wtff

#

Information Gathering - Web Edition
Skill Assessment

#

nothing found w fuzzing either

hexed crow
#

hello everyone
can anyone help me getting correct format of answer of below question?
"Use WMI to find the serial number of the system."
i got the answer but it is not submitting.
I'm in windows fundamental module of course information security

clever geyser
devout chasm
#

Hi

flat current
#

Guys, I can't type in general catalog. Is it happening with everyone ?

waxen totem
quaint kindle
#

Hi everyone

#

@clever geyser hi

golden saddle
#

am i doing something wrong its stopping due to errors?:
module:Password attacks

golden saddle
golden saddle
#

yea it worked now i had to reset the targetr

devout delta
#

#modules : I cleared the Login Brute Force , If any one need help drop me a DM

limber fog
#

Hello all!
I am currently doing the FFUF module, and I am having issues making FFUF work (from Exegol), as it is quite slow. Does anyone know how to fix that ?
Additionally, I ran 2 fuzzing to the same endpoint with the same wordlist, and had different output. How can I fix these inconsistencies ?
Thank you

#

Command used was ffuf -w <wordlist>:FUFF http://<domain>:<port>/FUZZ

wild oriole
limber fog
#

Ok thx, I assumed it was all 404 not found pages, but how can I fix this & improve the request rate

clever geyser
#

File Upload Attacks: Blacklist Filters

I am able to upload the shell but, its not getting executed. someone pls help

limber fog
clever geyser
#

(I tried both web shells and reverse shells)

#

none is getting executed

limber river
# clever geyser

try to find a better extension , I don't think that web application does actually run .php8

clever geyser
wild oriole
# clever geyser

Getting status code = 200, means it's allowed by the filter, not allowed by the server

wild oriole
clever geyser
#

turns out, server wasnt executing reverse shell + I was choosing the wrong extension

#

(web shell >>)

limber fog
#

Demonstration of the WTF:

wild oriole
# limber fog

If the website is working, then try change the VPN location

limber fog
#

I'll try thanks

limber river
#

should we mention @ SERIOUS RULE BREAK in this case

daring ember
#

Hi there!
Have recently started this, "Detecting Windows Attacks with Splunk"
After completing, "Detecting Password Spraying", I realized what might be a good way to detect Password BruteForce (which is different from Password Spraying)
Any idea on it ?
Or help/suggestion ?

bright coral
regal creek
#

hey guys hows it going? I'm stuck on the Footprinting IPMI room
I found the username but cannot crack the hash as they recommended

it says the hash is the wrong format

But that is what metasploit gave me. Any help?

#

its not letting me paste the images here

#

basically metasploit finds the hash and saves it to a txt, but hashcat says the format is wrong

#

i tried it with the rockyou.txt wordlist also

alpine ingot
#

I'm having an issue with the socksoverrdp room, have been stuck on this for hours.
When i go into the first pivot and run the SocksoverRdpserver.exe it does not actually open the connection. The proxifier does not allow me to pick up anything and 3389 tcp connection is not found using netstat.

regal creek
#

$hashcat -m 7300 ipmihash.txt -a 3 ?1?1?1?1?1?1?1?1 -1 ?d?u
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 3.1+debian Linux, None+Asserts, RELOC, SPIR, LLVM 15.0.6, SLEEF, POCL_DEBUG) - Platform #1 [The pocl project]

  • Device #1: pthread--0x000, 1435/2935 MB (512 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashfile 'ipmihash.txt' on line 1 (10.129...af3b990f28939926054451ad4a7ce337): Token length exception

  • Token length exception: 1/1 hashes
    This error happens if the wrong hash type is specified, if the hashes are
    malformed, or if input is otherwise not as expected (for example, if the
    --username option is used but no username is present)

No hashes loaded.

Started: Sun Jul 13 16:20:30 2025
Stopped: Sun Jul 13 16:20:31 2025

#

$hashcat -m 7300 ipmihash.txt /usr/share/wordlists/rockyou.txt
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 3.1+debian Linux, None+Asserts, RELOC, SPIR, LLVM 15.0.6, SLEEF, POCL_DEBUG) - Platform #1 [The pocl project]

  • Device #1: pthread--0x000, 1435/2935 MB (512 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashfile 'ipmihash.txt' on line 1 (10.129...af3b990f28939926054451ad4a7ce337): Token length exception

  • Token length exception: 1/1 hashes
    This error happens if the wrong hash type is specified, if the hashes are
    malformed, or if input is otherwise not as expected (for example, if the
    --username option is used but no username is present)

No hashes loaded.

Started: Sun Jul 13 16:21:23 2025
Stopped: Sun Jul 13 16:21:23 2025
┌─[✗]─[user@parrot]─[~/Documents]
└──╼ $cat ipmihash.txt
10.129.202.5 admin:d5a308ce82250000739e28fedfa17c4ec322de043a20d16671d30c3ea5f68341d1d33a98394386a9a123456789abcdefa123456789abcdef140561646d696e:125f1c9daf3b990f28939926054451ad4a7ce337

#

These are the two I tried with hashcat that returned an error

bright coral
regal creek
#

└──╼ $hashcat -m 7300 ipmihash.txt -a 3 ?1?1?1?1?1?1?1?1 -1 ?d?u
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 3.1+debian Linux, None+Asserts, RELOC, SPIR, LLVM 15.0.6, SLEEF, POCL_DEBUG) - Platform #1 [The pocl project]

  • Device #1: pthread--0x000, 1435/2935 MB (512 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashfile 'ipmihash.txt' on line 1 (admin:...af3b990f28939926054451ad4a7ce337): Token length exception

  • Token length exception: 1/1 hashes
    This error happens if the wrong hash type is specified, if the hashes are
    malformed, or if input is otherwise not as expected (for example, if the
    --username option is used but no username is present)

No hashes loaded.

Started: Sun Jul 13 16:32:11 2025
Stopped: Sun Jul 13 16:32:12 2025

#

$cat ipmihash.txt
admin:d5a308ce82250000739e28fedfa17c4ec322de043a20d16671d30c3ea5f68341d1d33a98394386a9a123456789abcdefa123456789abcdef140561646d696e:125f1c9daf3b990f28939926054451ad4a7ce337
┌─[user@parrot]─[~/Documents]
└──╼ $hashcat -m 7300 ipmihash.txt /usr/share/wordlists/rockyou.txt
hashcat (v6.2.6) starting

OpenCL API (OpenCL 3.0 PoCL 3.1+debian Linux, None+Asserts, RELOC, SPIR, LLVM 15.0.6, SLEEF, POCL_DEBUG) - Platform #1 [The pocl project]

  • Device #1: pthread--0x000, 1435/2935 MB (512 MB allocatable), 4MCU

Minimum password length supported by kernel: 0
Maximum password length supported by kernel: 256

Hashfile 'ipmihash.txt' on line 1 (admin:...af3b990f28939926054451ad4a7ce337): Token length exception

  • Token length exception: 1/1 hashes
    This error happens if the wrong hash type is specified, if the hashes are
    malformed, or if input is otherwise not as expected (for example, if the
    --username option is used but no username is present)

No hashes loaded.

bright coral
regal creek
#

ok i'll take a look

#

i feel dumb

#

thx for the help

daring ember
hexed kestrel
#

Hey! currently on WEB ATTACKS > Bypassing Basic Authentication

the explanation states $ curl -i -X OPTIONS http://SERVER_IP:PORT/ should give a response with the Allow: header

however, when I try this I get a response identical to what I get when I do a normal GET request. no Allow: header.

Anyone know why? 😅

#

also, manually just trying all the HTTP methods in the way that should solve the challenge is... not working

#

(through burp ofc)

#

top is with -X OPTIONS, bottom is -X GET

bright coral
fathom pendant
#

sometimes OPTIONS just doesn't work

valid gate
#

yes. having trouble installing the 2 dependencies libfuse3-4 and libruby3.3 for the dislocker portion of the cracking password protected archives

hexed kestrel
# fathom pendant sometimes OPTIONS just doesn't work

I am aware, but the challenge at the bottom states " Try to use what you learned in this section to access the 'reset.php' page and delete all files. Once all files are deleted, you should get the flag. "

anyway, I've tried the methods listed in the section (need change a method to bypass auth, as demonstrated earlier in the section) and none of them yield a result. not sure what else there was to be learned from the section...

fathom pendant
#

but you're likely overlooking something; i.e. if you change from POST to GET you have to change the request

#

i.e. GET uses /endpoint.php?key1=value1&key2=value2

#

POST uses the data portion to assign the values

hexed kestrel
#

from the section:

"Once we change POST to HEAD and forward the request, we will see that we no longer get a login prompt or a 401 Unauthorized page and get an empty output instead, as expected with a HEAD request. If we go back to the File Manager web application, we will see that all files have indeed been deleted, meaning that we successfully triggered the Reset functionality without having admin access or any credentials: "

The entire solution offered was essentially just demonstrating insecure web server configs allowing for HTTP verb tampering because of something like:
<Limit GET POST> Require valid-user </Limit>

#

after trying the same thing demonstrated in the section (on, at least visually, the same webpage as the section), with all the mentioned methods, none of them had any effect. so I'm kinda lost on what to do, the solution is not what was discussed in the section, at least I don't think so

hexed kestrel
hexed kestrel
valid gate
#

for the dislocker portion of the Cracking Protected Archives module, has anybody found a fix for this?

fathom pendant
#

try adding --fix-broken

#

it literally tells you what to try

valid gate
#

I tried that but no change. I was having trouble trying to manually install the dependencies too.

fathom pendant
#

is your system up-to-date?

valid gate
#

yea

#

I ran apt-get update and apt-get upgrade and rebooted

fathom pendant
#

apt-get is also a deprecated method, it's all been condensed down to apt (this doesn't change functionality)

#

you can also try sudo apt install aptitude
sudo aptitude install dislocker

valid gate
#

ahh okay I didn't know that, thanks. I'll try this now

#

no dice...

#

tried --fix-broken install without any packages specified too with no luck

#

for the exam is there a recommended OS to use? I'm just using a kali VM with all the extra tools we need added but there have been times I needed to go back and use the pwnbox instead

alpine ingot
#

Can i get some help on the socksoverRDP pivot section

valid gate
#

pwnbox worked for the dislocker part

indigo roost
worthy sorrel
worthy sorrel
#

Then try installing dislocker

indigo roost
# alpine ingot bruhh

||funny stuff when u see it work just lmk if it does work for u cuz it did for me||

alpine ingot
#

I will do it later and let you know how it goes

neat shore
#

can someone help me? i can't find the password for the second question.

i try

C:\Users\mendres> notepad .\resultados.txt
PS C:\Users\mendres> $shares = "C:\Company", "C:\Finance", "C:\HR", "C:\IT", "C:\Marketing", "C:\Sales"
$results = foreach ($share in $shares) {Get-ChildItem -Path $share -Recurse -Include .txt,.log,.ini,.cfg,.ps1,.bat -ErrorAction SilentlyContinue |

Select-String -Pattern 'domain', 'admin', 'password', 'cred' Encoding UTF8}
$results | Tee-Object -FilePath resultados.txt

and spiderman

tribal inlet
runic fog
#

is there a reason anytime I left click the instance thinks I'm right clicking

clear seal
#

Just finished the sql injection module!

west arrow
#

Hello, on the "Linux Priviledge Escalation" First page where we have to enumerate and find the flag.
I greped for the flag format and got it, but before that was hours trying to find it, and nothing.

What is the approach we are meant to have for this? Because i couldn't find any "Interesting files" or it would of taken me days and days

tranquil fulcrum
#

how far into the pentester curriculum should i start to try doing active and retired boxes on htb main

#

fyi i'm 32% in

cloud urchin
royal leaf
#

Yoo

cloud urchin
#

@astral bear This isn't the channel for such discussion. Please read the #rules and follow the instructions in #welcome to gain access to more appropriate channels.

tranquil fulcrum
cloud urchin
# tranquil fulcrum i'm planning on getting some practice doing active and retired boxes for the cpt...

The path can take a long time to complete. Boxes aren't always going to have things in the scope of the path so you may find yourself spending more time researching other things you won't see in the exam. The path is all you need. I'd recommend going through the path and ensuring you have a strong understanding of everything in it. Do AEN blind at the end as a capstone. After completing the path if you really want to practice Ippsec has an unofficial playlist of boxes you can do.

#

This is just my opinion and you may be better off doing it your way, so don't take what I say as gospel.

royal leaf
#

How do I gain access to other channels

cloud urchin
royal leaf
#

Sorry daddy nuts lemme go read

hollow kernel
tired flax
#

Would anyone be able to provide some guidance?
Module: HTTPS/TLS Attacks
Chapter: POODLE & BEAST
Question: Construct a valid SSL 3.0 padding of the plaintext bytes "AABBCCDDEEFF". Use the byte 00 for any byte that can be an arbitrary value. Provide the padded plaintext without spaces. Assume the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA is used.

I'm just a little bit lost on what the actual quesiton is wanting you to do. I've tried following the examples, but I'm not getting the vulnerable and not-vulnerable responses. Is there a specific host I'm meant to be testing against?

cloud urchin
hollow kernel
#

Ok

#

When i go to general it says done reading check out modules

cloud urchin
#

the certification channels are probably better to ask in for your question i guess

#

this channel is for talk about the modules themselves

tribal inlet
tired bough
#

hey im sorta stuck. the Mass IDOR enum in the web attacks module I cant seem to get working. when i go to the employee documents, click documents and click either invoice or report, the PDF file is blank (not sure if this is supposed to be the case). Im trying to follow the example adding uid=2 but nothing shows under documents like its supposed to. when I run the curl examples i get nothing returned so im a tad confused

#

i tweeked the bash script and got no downloads

#

any ideas?

#

its also REALLY slow

#

wait nvm had my regex wrong

rain mirage
#

module = footprinting lab hard

i have been trying to find the 1st credentials and i tried every thing that came to mind . any hints ?

fathom pendant
#

did you check UDP?

rain mirage
#

ya ...

fathom pendant
#

are you sure?

#

sounds right

#

:) don't assume versioning may be correct

#

you were taught everything you need to know

#

deleting bc spoiler 😉

rain mirage
#

man...

plain bridge
#

Hello, im relatively new to cyber and im trying to learn the linux fundamentals module however im stuck on this question ( How many services are listening on the target system on all interfaces? (Not on localhost and IPv4 only) ) I have tried so many commands and I don't seem to get the right answer is there any guidance anyone could give me?

waxen totem
plain bridge
waxen totem
plain bridge
#

Thank you for your help.

digital pendant
#

is this intentional not to allow time extensions to skills assessment labs?

on SQLi Fundamentals in CPTS Skills Assessment section.

cloud urchin
#

not a flaw, yeah it's intentional it's just a docker container that spins up publicly

digital pendant
#

ah okay thanks

cloud urchin
#

they die after a certain amount of time but you can just respawn it

#

it's not like it affects progress or anything

digital pendant
#

maybe im just lazy but I like to keep extending till im done in my session, which in this case included some scripts pointing at the IP

#

Lots of effort changing one line.... sigh /s

cloud urchin
hasty radish
#

Oh am really sorry I thought I was in general

rough comet
#

can someone please help me withe Q3 of "Wi-Fi Basic Pentesting" final assesment? I found the password for BSSID D8:D6:3D:EB:29:D5. But I cannot connect using the 3 letters SSID that is being shown .

#

I believe is due the SSID. But I can't find it using the given tools.

#

I even inspected the pcap and still nothing.

cloud urchin
rough comet
#

I reverse engineer (found a spoiler) that let me connect. But I am not able to find that.

cloud urchin
#

so you're connected?

rough comet
#

I am starting to believe, there's an issue with the exercise

rough comet
#

But I could not find or understand the "why"

#

I cannot find the correct SSID via tools

cloud urchin
#

how did you connect to the SSID if you can't find the SSID

rough comet
#

I've spent two days for far on this exercise.

cloud urchin
#

DM me

rough comet
icy egret
#

can anyone help me with this?

Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio.

i did cp the ccache and export as KRB5CCNAME = <filename>

and when i did klist it showed that ticket is correct.

when i am doing smbclient it is giving me - Connection to dc01 failed (Error NT_STATUS_NOT_FOUND)

#

I tride 2 tickets. same issue

cloud urchin
#

kerberos attacks require the kdc, typicall the dc, to be resolvable

icy egret
#

i used dc01 . no successss

rough comet
#

If you don't, the tools may give you weird errors due DNS name resolution issues, like SuperNuts said

icy egret
#

trying, thanks

rough comet
#

something like this

#

test with ping, using the name

icy egret
#

where can i learn more about working with dns name resolution? why it gives wierd errors? i had same issue with one module which required to add all ip's i found to the etc hosts. still confused what is matter to add to hosts ? Sorry if it is simple thing.

rough comet
#

I suggest doing that before

#

If you don't fully understand these simple things, you will struggle with any AD attack

#

DNS resolution is vital for AD

icy egret
#

i am doing the CPTS modules by order it showed me and i did not reach to AD module yet. Is learning that way confuses?

rough comet
#

CPTS assumes some basic knowledge

icy egret
rough comet
#

then return to CPTS once done

icy egret
#

thanksss

rough comet
#

np, best wishes

frosty crescent
#

Whenever a module says to use crackmapexec would I be wrong to rather use netexec instead

autumn pilot
#

nope

fathom pendant
frosty crescent
#

Ok that's what I assumed

icy egret
#

@fathom pendant can i DM you?

#

hello

fathom pendant
icy egret
#

password attack module

icy egret
# rough comet

did add the IP and domain to hosts and when i try to smb , its just processing without showing any success.

#

can i share screenshots here?

acoustic owl
#

Yes, that's what it means

#

But I wouldn't rely on these times. Sometimes you need more time, sometimes less.

acoustic owl
icy egret
#

okayy

#

done

acoustic owl
icy egret
#

just noticed

bright spire
#

Are there any ways to gain cubes aside from purchasing them? Money is tight this week, but id love to do some modules.

hollow whale
#

Guys who know a good smtp

storm elk
livid coral
#

Hi. I have trouble finding an answer for Advanced Command Obfuscation.
Find the output of the following command using one of the techniques you learned in this section: find /usr/share/ | grep root | grep mysql | tail -n 1.
I have tried reversing turing to basee64, changed the special characters with printenv's. Can somebody please help

tired flax
#

Would anyone be able to provide some guidance?
Module: HTTPS/TLS Attacks
Chapter: POODLE & BEAST
Question: Construct a valid SSL 3.0 padding of the plaintext bytes "AABBCCDDEEFF". Use the byte 00 for any byte that can be an arbitrary value. Provide the padded plaintext without spaces. Assume the cipher suite TLS_RSA_WITH_AES_128_CBC_SHA is used.

I'm just a little bit lost on what the actual quesiton is wanting you to do. I've tried following the examples, but I'm not getting the vulnerable and not-vulnerable responses. Is there a specific host I'm meant to be testing against?

forest fulcrum
#

hello all, I am currently on the SCCM Auditing module in the CAPE path, the lab machines are not showing the output they are supposed to show via sccmhunter
is anyone else currently doing the same module?

pulsar berry
#

yo dudes! I'm currently working on the Active Directory Trust Attacks - Skills Assessment, and I'm stuck on Question 2. I think I’ve figured out the attack path, but I just can’t get it to work as expected. Is anyone available for a quick chat so I can explain what I’ve tried and maybe get some guidance? Appreciate any help, thanks!

sick depot
#

can anyone help me run bloodhound via crackmap i cant get it work from pwn box

supple dragon
buoyant shale
#

Hello guys, i am with the OSINT module and i have to answer the next question: Investigate the website and find the bucket name of AWS that the company used and submit it as the answer. (Format: sub.domain.tld); with "the website" i understand that is inlanefreight but i was searching around an hour and i cannot find anything, can you help me? thanks!

eager siren
#

Hello guys am at LLM OUTPUT ATTACKS module i am currently stuck on Cross side scripting 2 i can exploit, but i can only retreave the chat cookie i decode but nothing that can resemble an admin cookie any help?

unkempt fern
#

Hi

clever geyser
#

someone help me with File Upload Attacks - Skill Assessment

I got the initial XXE but, unable to upload shell...

#

I am using :.phtm.jpg with image/png mime type and also the file type signature of a png file

#

but it still says "Only images are allowed"

sick sphinx
gray yacht
vagrant shuttle
#

Hi has anyone managed to complete the optional challenges for PtT from linux ?

#

i followed the steps but i can't get the final command to run

muted grove
#

damn i just discovered reflective C# loading in powershell my life just changed

spare fossil
#

module: Introduction to Digital Forensics/Introduction to Digital Forensics/Analyzing with Timeline Explorer what file is being ingested there ? there's bit of disconnect. not sure how we arrived at having that file being ingested

muted grove
#

i can drop a mini procdump in memory now, thats so cool like wtff

lavish marten
gray yacht
lavish marten
#

i have credentials of ||mathew, i saw that mathew has WriteOwner over Netowork Admins, but i cannot connect to windows to use powerview||

gray yacht
vagrant shuttle
lavish marten
#

on port 13389

gray yacht
lavish marten
#

thanks

clever geyser
daring ember
worn aurora
#

Good morning,

Wondering if someone could DM me for help with SQLMap Essentials, Attack Tuning Case 6

alpine ingot
#

So on the SocksOverRDP room on the pivoting module, i got the pivot set up, it lets me rdp into the 2nd pivot but it cancels the connection due to either connectivity issues or "data encryption"

I have tried spamming the reconnect to the RDP session and i can get to the login screen but it keeps dropping.

icy egret
#

Use the LINUX01$ Kerberos ticket to read the flag found in \DC01\linux01. Submit the contents as your response (the flag starts with Us1nG_).

guys , i need help with this question.

i have found keytab which belong to LINUX01$

also i switched to root from svc_workstations user.

when i tried to
root@linux01:~# kinit LINUX01$@INLANEFREIGHT.HTB -k -t /etc/krb5.keytab
kinit: Keytab contains no suitable keys for LINUX01INLANEFREIGHT.HTB@INLANEFREIGHT.HTB while getting initial credentials

any help?

fleet charm
#

EDIT: in the interest of not spoiling things, had problems with popping a reverse shell and figured it out.

grizzled schooner
late agate
#

hi

cloud urchin
# late agate hi

Hi, welcome. Please make sure to read the #rules and follow the instructions in #welcome to gain access to other channels like #general which is more appropriate for greetings. This channel is dedicated to discuss the various modules on HTB's Academy platform.

grizzled schooner
#

Looking for some help with Attacking Common Services | Attacking DNS

Trying to use subbrute for DNS info and I get the following output

``└─$ ./subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt
/home/aria/Desktop/HTB Tools/subbrute/./subbrute.py:462: SyntaxWarning: invalid escape sequence '.'
permute_filter = re.compile("^[a-zA-Z0-9]{" + str(self.permute_len) + "}.")
/home/aria/Desktop/HTB Tools/subbrute/dnslib/lex.py:148: SyntaxWarning: invalid escape sequence '.'

l = WordLexer(r'abc "def\100\x3d. ghi" jkl')
^Czsh: killed ./subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt``

pine dagger
#

Its funny how many people don't read rule #8.

acoustic owl
pine dagger
#

I've got myself set to no messages without being friends, and I ignore people who I dont know adding me. I feel a little guilty as they are looking for help, but they should post in here first. 😦

#

How did you get a Serious Rule Break? lol

acoustic owl
#

You don't have to feel guilty. You've helped a lot of people.

acoustic owl
pine dagger
#

ah

#

I thought it was that you had done it 😄

midnight creek
#

Hi everyone!
I am currently stuck at the Pasword Attacks Skill Assessment from CPTS - just like many more before me as I saw when checking this channel 😅
I had a look at MarciLee's hints, though they didnt quit get me there yet. Currently at b*.
Someone up for a dm?

lament estuary
#

bro same problem here with build number did you crack it

echo roost
#

Windows Lateral Movement - Skill assessment - Q2 - What's the content of the flag located at C:\Users\Arturo\Desktop\flag.txt there is no flag on Arturo's desktop. Is the box messed up?

lament estuary
#

any one completed android fundamentals kind of ran into trouble with AVD build number problem

#

uff finally

fathom pendant
#

Do not share direct answers @lament estuary

flint palm
rain palm
#

Hey everyone. I just joined this server. I’ve been curious about cybersecurity lately and wanted to know more about it.

fathom pendant
#

hi @rain palm this isn't #general ; i suggest reading and following #welcome instructions to gain access to more of the server

iron sigil
#

Hey MarcieLee. I am starting Live engagement in Shells and Payloads but I am having trouble spawning target. It just won't spawn. When I try to spawn a target, it goes back to "click here to spawn the target system" after a few seconds. Any suggestions on what I should do? I tried refreshing the page and logging out and logging back in.

fathom pendant
iron sigil
#

Ohk. Thank you for the clarification

shadow phoenix
#

Hi, I'm stuck in the "Reading and Writing Files" section of the "Advanced SQL Injections" module. I managed to generate the file in the path /var/lib/postgresql/proof.txt by exploiting the SQLi vulnerability in the account registration function. According to the lab's statement, to retrieve the flag I must run the "serverInfo.sh" script located on the server where the vulnerable web application and PostgreSQL are running. However, when I run the script, I can't get the content of the flag because the flag is located in a file within the "root" directory. However, the user I'm connecting to the server with doesn't have the privileges to run this script with elevated privileges, and the script's content doesn't seem to contain any vulnerability that could be exploited to perform a vertical escalation of privileges. Could anyone give me a clue, please?

stone zephyr
#

Ive just got done with the pentest path AD module, safe to say my brain is fried any my notes are massive. Does anyone have any recommendations for a 'best practice' methodology when approaching an AD box? really looking to condense everything down

fickle crystal
#

quick question guys for the FTP module in attacking common services
do you get the port on port 21 or 2121 ?

#

because i dont get either of those even with diffferent flags

#

am i doing something wrong or

autumn citrus
#

Hello i am new in hacking can someone help me

#

Give me a challenge on hack the box or try hack me to try as a beginner

cloud urchin
tropic trout
#

This file transfers module is killing my attention span

tulip minnow
#

hi

#

did anyone face an issue in privilege escalation module

#

Where they got access to user 2 but it’s asking for a password to run Sudo -l, and it says NOPASS?

tropic trout
#

you mean "sudo -l" right?

tulip minnow
#

Sorry yes

#

did u face this issue in the module ? When I was at user 1 going to user 2 it said no pass but now I’m in user 2 writing sudo -l it says it needs a password

#

😵‍💫?

tropic trout
#

I haven't gone through that module yet, still in file transfers, but in my experience the labs in HTB Academy are usually not at fault, I would verify that you are doing what they are asking for!

waxen totem
fathom pendant
oak wraith
#

Hello there, I am studying for CWEE and I'm stuck on the 'Introduction to NoSQL Injection' module, Skill Assessment 2. Do you have any advice or hints? I've really put a lot of effort into this, and I want to understand and solve what I'm missing in this part.

azure turtle
#

sorry random person for the ping but why does this work and the other completely crashes the server?

fathom pendant
sacred furnace
#

I'm doing the Password Attacks module and I'm having trouble completing the Pass the Certificate section. Having a hard time getting the CSR with the provided tools specifically. Let me know if you think you can help so I can DM and not risk any spoilers here.

vernal bobcat
#

I’m stuck on the ARTIFICIAL lab when I try running the reverse shell can anyone help me in DMs I don’t wanna spoil it for people who haven’t done it yet in here

vernal bobcat
#

Won’t let me on my phone

waxen totem
cloud urchin
#

i had a heck of a time verifying my cert on mobile

#

i ended up using a computer

vernal bobcat
#

Very bad layout on phone just says use your laptop or computer to play htb no code

storm elk
#

Use your phone in landscape mode when trying to identify

waxen totem
jaunty nimbus
#

guys im currently completing Information Security Foundations module

#

Im at VPS task

#

could somehere explain if i need to buy that VPS service or no?

waxen totem
#

Outside of the Mac modules(because you'd need a Mac), no module will ask you to spend money for tools

jaunty nimbus
#

Thank you

#

Sorry I’m new to this

#

One last question

#

I will doing this modules and eventually getting a certification on hack the box land me a job

waxen totem
#

Unfortunately that even with certifications there is no guarantee in landing a job, that's a whole other skill in itself which noone really teaches, there are places that can help you get a job but will you get a job from a certification alone? probably not

jaunty nimbus
#

I have a degree in computer security too

waxen totem
#

That probably helps but like I said: there is no guarantee that you'll get a job based on achievements alone, you'd have to be able to prove your skills to an employer and they'd have to like you

rotund pasture
#

Hi, i'm stuck in the module "Abusing Foreign Groups & ACL Principals" with the sentinal user, can somebody help?

jaunty nimbus
#

What do these security interviews look like

#

I have never gotten one

fleet charm
#

Cheat sheet in file upload attacks module has a broken link for Web Content-Types

sacred rock
digital pendant
#

Can I get a nudge on SQLMap Skills Assessment please, don't want to spoil the fun for others nor do I want to hit see solution, but ive spent a good few hours returning to my notes, running payloads, comparing results.

#

Am I wasting my time with the|| SQL Error from the 500~|| I didn't see anything injectable in rest of the site so I'm back to this

shadow phoenix
#

Hi, I'm stuck in the "Reading and Writing Files" section of the "Advanced SQL Injections" module. I managed to generate the file in the path /var/lib/postgresql/proof.txt by exploiting the SQLi vulnerability in the account registration function. According to the lab's statement, to retrieve the flag I must run the "serverInfo.sh" script located on the server where the vulnerable web application and PostgreSQL are running. However, when I run the script, I can't get the content of the flag because the flag is located in a file within the "root" directory. However, the user I'm connecting to the server with doesn't have the privileges to run this script with elevated privileges, and the script's content doesn't seem to contain any vulnerability that could be exploited to perform a vertical escalation of privileges. Could anyone give me a clue, please?

lavish marten
#

hello, does anyone has issues with the labs ? im on DACL 2 , but doesnt works RDP..

regal totem
#

Hello, anyone available to help in dms on the Subdomain Bruteforcing module? I can't find the right subdomain for the life of me

desert magnet
jade lotus
fathom pendant
#

Alongside the --append-domain option

jade lotus
#

need to exclude that ?

fathom pendant
#

No

#

--append-domain doesnt take arguments afaik

jade lotus
#

still dont get it sorry ^_^Uu the command is wrong then ?

tired flax
# fathom pendant No

Hello there, I think the skill assessment of HTTPs/TLS Attacks is broken, doing a get to any request takes to long

jade lotus
#

i tryed with fuff and is working , but still dont know why dont with gobuster 😦

fathom pendant
fathom pendant
#

--append-domain is just a boolean switch true/false

grizzled schooner
#

Working on Attacking Common Services | Attacking DNS I can't get subbrute to run, and when I try using something like gobuster, I don't get any returned results. Anyone have a second to help diag?

#

`` permute_filter = re.compile("^[a-zA-Z0-9]{" + str(self.permute_len) + "}.")
/home/aria/Desktop/HTB Tools/subbrute/dnslib/lex.py:148: SyntaxWarning: invalid escape sequence '.'

l = WordLexer(r'abc "def\100\x3d. ghi" jkl')
Warning: No nameservers found, trying fallback list.``

~~~~~~~~^^ File "/home/aria/Desktop/HTB Tools/subbrute/./subbrute.py", line 422, in run response = self.check(hostname, query_type, timeout_retries) File "/home/aria/Desktop/HTB Tools/subbrute/./subbrute.py", line 342, in check resp = self.resolver.query(host) File "/home/aria/Desktop/HTB Tools/subbrute/./subbrute.py", line 57, in query name_server = self.get_ns() File "/home/aria/Desktop/HTB Tools/subbrute/./subbrute.py", line 107, in get_ns ret = self.nameservers[self.pos] ~~~~~~~~~~~~~~~~^^^^^^^^^^ IndexError: list index out of range ^Czsh: killed ./subbrute.py inlanefreight.htb -s names.txt -r resolvers.txt

Edit User error, forgot to add the domain into resolvers.txt

tired flax
compact patrolBOT
fathom pendant
cerulean fractal
#

What's the actual purpose of target machine at the end of every material in advanced deserialization? I don't see dnspy/ilspy installed and the machine doesnn't have internet connection to download the .net material

acoustic owl
grizzled schooner
#

I haven't done them, nor do I know what that module is about, but could you use rdp?

amber heath
#

Hey, i just finished the SQLi skill assessment and i wanna ask a question without spoiling anything. Anyone i can DM?

compact dome
#

Hello.
Anyone available who resolved first step "Advanced XSS and CSRF Exploitation" Skills Assessment? I have an ||open redirect||, I || uploaded file which normally can bypass CORS/SOP by using <meta> to redirect to the admin page|| but it doens't work when I deliver a payload with the ||open redirect to my html.txt file with content-type:text/html (redirection works for me but not for the bot ...)||

echo roost
gray yacht
echo roost
leaden island
#

yo guys

#

im on ACL enum section

#

i transfered over chisel and connected to 172.16.5.0 network through SOCKS

#

i want to run bloodhound-python to enumerate DC however

#

it dosent work

#
└─$ proxychains bloodhound-python -u htb-student -p "Academy_student_AD!" -dc 172.16.5.5 -d inlanefreight.local -c all
ProxyChains-3.1 (http://proxychains.sf.net)
INFO: BloodHound.py for BloodHound LEGACY (BloodHound 4.2 and 4.3)
Traceback (most recent call last):
  File "/home/haji/.local/bin/bloodhound-python", line 8, in <module>
    sys.exit(main())
             ^^^^^^
  File "/home/haji/.local/lib/python3.12/site-packages/bloodhound/__init__.py", line 314, in main
    ad.dns_resolve(domain=args.domain, options=args)
  File "/home/haji/.local/lib/python3.12/site-packages/bloodhound/ad/domain.py", line 705, in dns_resolve
    q = self.dnsresolver.query(query, 'SRV', tcp=self.dns_tcp)
        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/home/haji/.local/lib/python3.12/site-packages/dns/resolver.py", line 898, in query
    raise NoNameservers(request=request, errors=errors)
dns.resolver.NoNameservers: All nameservers failed to answer the query _ldap._tcp.pdc._msdcs.inlanefreight.local. IN SRV: Server 127.0.0.53 UDP port 53 answered SERVFAIL

#

im missing something here i believe

#

i made sure pivot is working

grizzled schooner
#

I'm back to subbrute not working correctly... Anyone have a second? I'm not sure what I'm doing wrong

fathom pendant
#

is the names.txt and resolvers.txt in the same directory you're launching from

grizzled schooner
#

Yeah, when I put inlanefreight.htb in the resolvers file like the lab mentions, nothing really happens... It did once, and then I had to run to a meeting, came back, launched again and it doesn't want to work

#

Not sure if this will help any..

Warning: Fewer than 16 resolvers per process, consider adding more nameservers to resolvers.txt. Warning: No nameservers found, trying fallback list. Process lookup-3: Traceback (most recent call last): File "/usr/lib/python3.13/multiprocessing/process.py", line 313, in _bootstrap self.run() ~~~~~~~~^^ File "/home/aria/Desktop/HTB Tools/subbrute/subbrute.py", line 422, in run response = self.check(hostname, query_type, timeout_retries) File "/home/aria/Desktop/HTB Tools/subbrute/subbrute.py", line 342, in check resp = self.resolver.query(host) File "/home/aria/Desktop/HTB Tools/subbrute/subbrute.py", line 57, in query name_server = self.get_ns() File "/home/aria/Desktop/HTB Tools/subbrute/subbrute.py", line 107, in get_ns ret = self.nameservers[self.pos] ~~~~~~~~~~~~~~~~^^^^^^^^^^ IndexError: list index out of range

fathom pendant
#

put the ip in the resolvers file

#

not the hostname

grizzled schooner
#

I thought that the hostname goes into resolvers? At least that's what the module had shown lol

grizzled schooner
supple dragon
muted valley
#

Is there any CTF labs for beginners for llm

zinc mantle
#

Can someone DM me about "NTLM relay attack" skills assessment, question 3. I have tried the accounts I have access over but am still unable to read the shares on SQL03. I must be doing something wrong but can't work out what

gray yacht
rustic sage
#

Hey does anyone know what loopback addressing is used for?

#

In networking

rain mirage
rain mirage
#

and there is no vpn required for this module .. what am i missing?

rain mirage
#

probably yes cos i can access it via browser ... but cant figure what

fathom pendant
rain mirage
south marten
#

hello, im doing Attacking Common Services , and im in the ftp part, i really need to wait a hour to have the credentials?lol

#

💀

sacred rock
south marten
#

the dont say me anithink and i say "I won't be able to connect this way."

#

and yea, i was able.

jade lotus
hexed oyster
#

Struggling a bit on 'Web Service & API Attacks -> Server Side Request Forgery". I'm able to trigger the SSRF back to my computer, but the web app becomes completely unresponsive if I try to request something from the server itself. Am I making some obvious mistake?

jade lotus
#

2º one 10 june 2017 there isnt snapshot

formal briar
#

struggling on this question : What are the contents of flag.txt on Administrator's desktop? from the section pass the certificate

sacred rock
#

Which URL are you searching for?

jade lotus
sacred rock
#

Well, there you go, that is not correct, check the section again.

jade lotus
#

maybe was another url ?

#

wich section ?

sacred rock
sacred rock
jade lotus
#

i see a screenshot that search for www.hackthebox.com in year 2017 and no nsnapshot in 10 th june i need to search for subdomain or something ?

sacred rock
jade lotus
#

thats the url i know from this page ^_^Uu

sacred rock
#

Well, maybe the first version of the website didn't had that url

jade lotus
#

:/

#

then why i can still see snapshots from other days before ?

sacred rock
#

open the last image from the section in another tab and check the url, it's not www.hackthebox.com

raven kelp
#

Your legacy HTB Academy account is still unverified. this error is continuesly popping even after verifying email

sacred rock
#

contact support

jade lotus
#

Okay, I see it now, but the question was referring to Hack The Box, it's a bit ambiguous to be honest. Thank you very much

sacred rock
raven kelp
fathom pendant
compact patrolBOT
fathom pendant
#

@raven kelp

sacred rock
# formal briar pls

I think there's a lot of hints for that question from previous students, search for those here in this channel (CTRL+F) and see if you can progress

limpid siren
# jade lotus

The old url for htb is given in that section look closely at the attachment image in it

gaunt junco
#

Hi everyone, where i can ask questions about season machine Outbound?

tropic wind
pallid geyser
#

guys im doing command injection module and in this question: Try using the remaining three injection operators (new-line, &, |), and see how each works and how the output differs. Which of them only shows the output of the injected command?

I found the answer that is new-line and in burpsuite i url encoded everything and it worked. But how i answer the question, i typed new-line NEW-LINE New-Line and nothing

sharp peak
pallid geyser
#

Ohhhh thx thx for the tip

sharp peak
#

I also got caught with this so that's why I remembered

pallid geyser
#

i found it but the answer format its incorrect i dont know

sacred rock
shy scaffold
#

where do we chat bro i have a question for a box

feral basin
#

Hi guys, I am on Debugging with GDB module from Intro to Assembly Language. when i run the gdb binary ... it crashes with Segmentaion fault error. Have a look at attached picture.

#

I am running Parrot OS VM in a Virtual Box VM on Macbook

azure turtle
fathom pendant
#

well with echo; you'd have to make sure to echo it with single quotes

#

so bash doesn't try and interpret it as a variable call

#

or escaping the $ with \ so echo ... \$_GET

icy grotto
#

I'm at the attacking thick client applications and am just confused on what is supposed to be going on or happening

cloud urchin
waxen totem
#

That's illegal, we cant help you no matter how noble your intentions

sand rose
#

Hello guys. I have a question about the Active Directory Module. I'm in the section "Initial Enumeration of the Domain". I ssh'd into it as needed, and I used fping on a range of ip addresses. One of the IP Addresses I did an NMap scan on and I see from DNS records that there is a Domain name (<Redacted>.LOCAL and <Redacted.LOCAL0). I tried typing in both of those Domain names and the answer is incorrect. The question for reference is "From your scans, what is the "commonName" of host 172.16.5.5. Is that not the domain name or am I typing it in wrong? I did both caps and no caps for the answer and no luck.

#

Nvm... I'm blind. Its funny how 3 minutes after sending that I immediately figure out my issue. Whoops. xP

blazing loom
#

I'm in "Windows File Transfer Methods" section in the "File Transfers" module. I'm trying to run wsgidav However when I run it with the command given in the module I get this error: OSError: No socket could be created -- (('0.0.0.0', 80): [Errno 98] Address already in use). When I try to kill any process on port 80, it kills the pwnbox altogether. Any pointers? Is this possible to run on a different port? I tried that but then got errors on the Windows side of things.

waxen totem
blazing loom
snow spoke
waxen totem
#

Or try net use

blazing loom
#

Oh but after closing that window it shows so I guess that works

waxen totem
blazing loom
#

Thanks for the help!