#modules

1 messages · Page 441 of 1

devout lily
#

nono i wrote the text and used AI to get informations

fathom pendant
#

It's why I linked it back to being RunAs

#

Because if youre familiar enough with windows

#

Runas does basically the same thing

devout lily
fathom pendant
#

Then relate it to something outside of tech

#

¯_(ツ)_/¯

#

You want to be able to look at your notes some time down the line and still be able to actually understand it

ancient coyote
#

Def can attest to this^ I like to copy exact quotes from what I read then hand write with my surface pen in the margins what I relate it too

#

unpopular opinion I also love OneNote becasue you can search hand writing, and screenshot text

grizzled crypt
#

Can someone help with a module? Trying to learn and review the Linux directories

#

I've got a hour to spare

ancient coyote
#

I can try to help!

grizzled crypt
#

Care if I voice call

ancient coyote
#

Whats the question my friend also working on modules so I can give hints and guidance as you need

grizzled crypt
#

Can you join General Chit Chat

#

Im running on Hotspot lol

#

Basically, it's about the directories

sharp notch
#

is setting up a vps required for academy modules or can i work through without setup

elder matrix
#

setting up a vpn while inside a virtualbox/vmware machine is advised

#

its too easy to do..so you might as well do it

sharp notch
#

vps not vpn

#

but yes i think i have a subscription to airvpn i might throw it on my vm seeing i havent yet

elder matrix
#

i dont use a vps and im done with the cpts path

ancient coyote
#

When do you plan on taking it?

sharp notch
#

when should i setup a vps and proxmax

elder matrix
#

what and what?

#

whoever told you you need those for CPTS are super wrong

sharp notch
#

i can use that to download tools and my github repositories over new machines i have to deploy right

#

nah im reading the getting started skillset right now

elder matrix
#

just load the tools in a kali/parrot vm

sharp notch
#

yes i can apt install but i think with a vps i can make it install abunch at once? not too sure

elder matrix
#

the notes, just dump em on your desktop. use obsidian to read/edit them just like you would on a browser

sharp notch
#

yuh i write my notes from lessons in notepad and categorize

elder matrix
#

just use kali via virtualbox, download your tools as you need them, no need for those wannabe tools.. no one does that

sharp notch
#

i guess i can look through the getting started path again to setup custom things and servers after to test on my own vm and such

elder matrix
#

a text file....you need a serious upgrade like obsidian or joplin

sharp notch
#

why

elder matrix
#

okay then... just go on with your journey and figure out why im telling you all this by youself

sharp notch
#

well you mentioned it whats a benefit of obsidian

elder matrix
#

obsidian, for me, the BEST note taking app EVER

sharp notch
#

seems so complicated

#

how did you dump all them into it by writing or download the sheet

elder matrix
#

thats from my desktop

elder matrix
fathom pendant
# sharp notch

Obsidian allows you to use markdown and tagging to enhance your searching for content

elder matrix
#

i had to delete lol i saw some nasty stuff

sharp notch
#

so im outdated essentially

fathom pendant
#

Eh

#

Use whatever works best for you

sharp notch
#

i believe in tech-memory loss

#

so writing it down as i go helps lol

fathom pendant
#

Some mad lads have used excel

sharp notch
#

yeah idk how that would work lol

fathom pendant
elder matrix
# sharp notch

from my perspective, i dont how you would make it work with that..

sharp notch
#

yeah i mean these are notes from the getting started module so it has basic commands , nibbles walk through, theory i can scroll through

elder matrix
#

just like how an excell file would work haha

sharp notch
#

i guess drop downs would be nice to see the organization better

#

maybe ill give it a shot

elder matrix
sharp notch
#

im gonna go down cpts path too once i finish this

#

i use a 2024 m3 macbook lol

#

i run vbox kali whenever i wanna practice

#

?

olive peak
#

Is there anyone I can get a second opinion for AD enum SA part II

potent sandal
#

where i can ask questions about retired machines ?

cloud urchin
#

#boxes. You'll need to follow the instructions in #welcome to gain access.

potent sandal
#

@cloud urchin Thanks 1 year here on discord and first time gain access... a true hacker .-.

grizzled crypt
#

any one able to help walk through or just chat while doing a HTB module

tall aspen
#

I wonder if a hacker from hackthebox academy ever hacked hackthebox
a true movie plottwist

#

prayge i need to lock in on htb

eager spindle
#

I searched the website and found "reg add" to no avail

kindred cipher
#

What you guys think is the best way

  1. Doing skill path after skill path
    Or
  2. Tier 0 Fundamental -> Easy -> Medium -> ….
    Tier 1 Fundamental -> …..
    Etc.
storm elk
#

@kindred cipher if you're after a specific "job path" - it might just be best to follow those modules in order

#

start with the fundamentals and then work from there

fathom pendant
kindred cipher
fathom pendant
kindred cipher
#

I think the fundamentals are enough. Just wanna be more than enough, you know what I meant?

inland oak
cosmic sequoia
#

Please

silk lagoon
waxen totem
#

@cosmic sequoia That's not what this server is about, please read #rules

keen cargo
#

Hello I m enrol in the "Android Fundamentals" Module, but I m stuck at 'Android Emulators
' second question that ask for the build number for (Pixel 3a API 34 Google APIs') device, I launch the device from android studio then settings -> about -> build number, but didn't work. do I missing something ???

eternal saffron
#

help me with linux fundamentals

#

files and directories

#

section

novel matrix
#

same

eternal saffron
#

and i just found some name of config files

#

excellent certificate there

haughty fiber
#

pivoting, tunneling and port forwading stuck on icmp tunneling with SOCKS. ./ptunnel-ng: error while loading shared libraries: libcrypto.so.3: cannot open shared object file: No such file or directory This error when ruunning ptunnel on pivot

deep hemlock
#

maintenance ?

#

Hi

winged steeple
#

In advanced deserialization skills assessment, im struggling to find the load() function within the app, I know how to exploit it just can't find it, any ideas on how I can go about finding it?

torn fiber
#

yeah eta 1 hour in the site

fathom pendant
#

i just use the autoroute feature in the newer versions of ligolo

#

¯_(ツ)_/¯

#

i don't recall having connection problems ¯_(ツ)_/¯

#

I hope that for the most part you were working on AEN blind, and only looked into it when you got stuck with some pivoting

#

it isn't relevant to the situation

#

just hoping that you're working on it blind, to help further your methodology and test your notes

deep pier
#

Is it possible to not SSH into a machine properly?

fathom pendant
#

?

#

you either succeed or don't in ssh

wooden seal
#

can someone tell me the ligolo-ng command to access RDP port (of internal IP 172.16.8.*) on my host

vestal jasper
#

hi, on AD Enumeration & Attacks - Skills Assessment Part I, I can't have a revshell using the webshell I just have "Unable to connect to the remote server" when I try to download the revshell from my python webserver, I also tried to start an smb but it still doesnt work, anyone have an idea ?

jade finch
#

hi does anyone have Credential Hunting in Network Shares guide for pentesting module i am really stuck can anyone help

wooden seal
#

can i dm? its not working for rdp

left gate
#

learned that the hard way

pulsar rapids
#

Hey sorry im new and wanted to ask how to find the path to the htb student mail. does anyone have a clue???

latent garnet
storm elk
#

hey you were muted by the bot automatically 🙂

latent garnet
#

Yo Bros

storm elk
#

whats up @latent garnet

latent garnet
storm elk
#

If you wanna chat about random stuff, you'd need to follow the three steps of #welcome and identify your account 🙂 other than that, if you have module related questions, this is the place to be

latent garnet
#

Got it, thanks for the heads-up! I’ll go through the steps in #welcome and get my account identified. Appreciate the help! 😊

#

@storm elk Hey, how can I get access to chat in the general channel?

storm elk
#

I litterally told you buddy

#

3 steps

elder matrix
storm elk
#

yeah, the bot here doesn't like it

elder matrix
#

we should have a drink me and the bot

storm elk
elder matrix
#

"hey! relax!" (south park reference)

#

new episode tomo.

#

back to hacking the exam !!!

storm elk
#

good luck

terse bloom
#

Hello, cannot connect to xfreerdp3 in Password Attacks --> PtT (Linux) after configuring the krb5.conf and proxychains as shown in the module. I get connection certificate auth failure

#

Nvm despite the certificate failure it takes a bit long to load... With rdp. Why is it always when I write in this chat, I find the solution myself 5 seconds later... ONLY when I type here bro wtf 🙁

quartz ravine
#

could someone help me with a command which is gettign an error

#

im following along with the junior cyber modules

#

im on wokring with web services

#

and im trying to enter this command

storm elk
#

put it in a code block @quartz ravine

quartz ravine
#

i cant post it

storm elk
#

with

the backticks

quartz ravine
#

sorry where?

wooden seal
#

select text after typing then there will be something like this <> select it

quartz ravine
#

says content blocked by server

storm elk
#

why are you adding square brackets?

quartz ravine
#

says to

#

tried on my kali vm and it says file unrecognised and on pwnbox it wont even let me do the command

storm elk
#

I think its an error to be honest

#

just do curl -I http://localhost:8080

quartz ravine
#

just said couldnt connect to server

#

when i type it in kali vm

#

i get zsh: unknwon file attribute: h

eternal saffron
#

help me the module linux fundamentals

#

files and directories

#

i had scanned them but all saying incorrect answer

#

@storm elk

ivory musk
#

finished the AD module on the cpts path. I'm not very happy with that module. while the basic methodology was good, there were too many contemporary CVEs from 2014-2021 introduced as bleeding edge, and the focus wasn't well enough on covering the basics. Also the labs were slightly messy requiring information from previous steps etc. I think that module should be cleaned up and partially reimplemented, but that's just me. as a side note I did learn quite a bit.

main flame
#

in windows fundamental module there is a question : What system user has full control over the c:\users directory? and i used the command icacls c:/users and the output was : Everyone:(OI)(CI)(RX) NT AUTHORITY\SYSTEM:(OI)(CI)(F) BUILTIN\Administrators:(OI)(CI)(F) WS01\bob.smith:(OI)(CI)(F) BUILTIN\Users:(OI)(CI)(RX) what is the right answer ?

quartz ravine
#

found more luck removing all brackets and "-I"

#

so just curl followed by the localhost address

#

no brackets no -I

#

the I seemed to be interfering with my kali VM

#

i'd suggest posting saying to ignore that entire section tbh

#

unless im missing something.

pulsar rapids
eternal saffron
#

@storm elk @cunning canopy help me the module first question of linux fundamentals section files and directories

#

is there no mod

storm elk
#

We're not obligated to help you @eternal saffron

#

ask your question here and someone will help]

sonic seal
#

I'm trying to complete the section Introduction of Android Application Static Analysis Module. But the button "Install App" doesn't work, what am I doing wrong?

eternal saffron
#

they need to assign

dusk holly
eternal saffron
#

where sir

frozen willow
#

What do i do if for some reason it doesnt let me input the password when connecting to the target?

dusk holly
eternal saffron
dusk holly
#

you said first question of linux privilege escalation right ?

eternal saffron
#

no sir of find files and directories section

#

of linux fundamentals

eternal saffron
vocal schooner
#

Hello, i have the same error like yesterday, i want to send my .zip file (in the xfreepbx session) to my local machine. So i started an temporary smb server authentified by user and password 'test' but my copy file doesn't work... Someone could help me ?

fathom pendant
dull solar
#

Does 'performance' also include not registering the right answer.

dusk holly
fathom pendant
eternal saffron
#

i tried them but a got output but ain't matching the answer

dull solar
fathom pendant
fathom pendant
dull solar
fathom pendant
#

and the section?

dull solar
#

Internet Architecture

thorny cedar
#

Hi, I’m currently working on the “Windows Attacks & Defense” module on HTB Academy.
I’m trying to connect via RDP to [ip] (ACADEMY-WINATTKDEF-WS01) with user "bob" and password "Slavi123", as instructed in the module.
However, I keep getting an “invalid credentials” error when attempting to log in.
The instance is running, I’m connected to the HTB VPN, and the IP address is correct.
Could someone help me figure out what’s going wrong?

frozen willow
#

if it says connection closed it means i failed with the password ,no?

fathom pendant
vocal schooner
#

didn't know that thank you !

fathom pendant
#

i tend to use /dynamic-resolution instead of /w /h

frozen willow
#

but it says that it still has 90 min left

fathom pendant
#

i also throw in /cert:ignore and sometimes (for paranoia sake) +clipboard

#

i believe you can also pass in an argument to define the keyboard layout

#

@dusk holly we don't share answers around here, even if the module is t0.

dusk holly
eternal saffron
fathom pendant
dusk holly
eternal saffron
#

let me try again

dusk holly
#

do not give full path

#

only file name

fathom pendant
#

Spawn instance -> starts the in-browser virtual machine that connects to the vpn, this is notably not the target

#

if your commandline/terminal starts with htb-ac-[some numbers]@somestring -> you're not ssh into the target, iirc they have you ssh with the username htb-student and some credentials

quartz ravine
#

i need help on the question + 0 Find a way to start a simple HTTP server inside Pwnbox or your local VM using "php". Submit the command that starts the web server on the localhost (127.0.0.1) on port 8080.

full echo
quartz ravine
#

why is "php -S 127.0.0.1:8080"

#

not right

#

please ignore me

eternal saffron
quartz ravine
#

i am stupid

#

i found issue as typing it

#

i've been typing it wrong from the start and ive been looking ofr help for nearly half an hour

#

im gonna lose my mind.

dusk holly
eternal saffron
#

sure

full echo
robust ledge
#

Can anyone please help with the Information Gathering - Web edition, Virtual hosts module please? As you can see in the image, I modify the /etc/hosts file to include the provided domain, then try the gobuster command, verifying that inlanefreight.htb:55969 does indeed work with curl, and that I do have connection with the machine with ping, but for some reason gobuster is unable to connect?

final kite
#

i cant seem to get connections or whatever always this error impacket-ntlmrelayx -t http://10.129.28.237/certsrv/certfnsh.asp --adcs -smb2support --template KerberosAuthentication
Impacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies

[] Protocol Client MSSQL loaded..
[
] Protocol Client SMTP loaded..
[] Protocol Client LDAPS loaded..
[
] Protocol Client LDAP loaded..
[] Protocol Client DCSYNC loaded..
[
] Protocol Client IMAPS loaded..
[] Protocol Client IMAP loaded..
[
] Protocol Client RPC loaded..
[] Protocol Client SMB loaded..
[
] Protocol Client HTTPS loaded..
[] Protocol Client HTTP loaded..
[
] Running in relay mode to single host
[] Setting up SMB Server on port 445
[
] Setting up HTTP Server on port 80
[] Setting up WCF Server on port 9389
[
] Setting up RAW Server on port 6666
[*] Multirelay disabled

[] Servers started, waiting for connections
[
] SMBD-Thread-5 (process_request_thread): Received connection from 10.129.28.237, attacking target http://10.129.28.237
[-] Authenticating against http://10.129.28.237 as INLANEFREIGHT/CA01$ FAILED
[] All targets processed!
[
] SMBD-Thread-6 (process_request_thread): Connection from 10.129.28.237 controlled, but there are no more targets left!
[] All targets processed!
[
] SMBD-Thread-7 (process_request_thread): Connection from 10.129.28.237 controlled, but there are no more targets left!
[] All targets processed!
[
] SMBD-Thread-8 (process_request_thread): Connection from 10.129.28.237 controlled, but there are no more targets left!
[] All targets processed!
[
] SMBD-Thread-9 (process_request_thread): Connection from 10.129.28.237 controlled, but there are no more targets left!

#

can someone just point me is it the correct way even or i should do it from jpinkman credentials and find administrators ones from there

sonic seal
fathom pendant
#

also try resetting the target and adjusting your /etc/hosts file to match

fathom pendant
robust ledge
#

I just can't figure it out

full echo
robust ledge
#

Yeah I'll try

fathom pendant
full echo
robust ledge
#

Didn't work ._.

#

Tried with a different machine as well

#

It's a public address so ya'll could try I guess lol

#

94.237.49.23:59688

final kite
fathom pendant
robust ledge
#

I also did try that before but got zero results, I'll try it again though

full echo
robust ledge
#

Tried it with and without

fathom pendant
full echo
fathom pendant
#

they'll still need the port after the <IPv4>:port

robust ledge
#

Running it now

sonic seal
full echo
fathom pendant
#

@robust ledge careful sharing screenshots

#

as they may be spoilers

robust ledge
#

Oh, mb, the reason I was sharing was because there were literally thousands of those results, but I can see why

#

Yeah that's what I'll do, it just seems weird for there to be so many

#

Thank you

#

Thank you again 🙂

#

Ahh I hate that it translated to that automatically

#

The smiley

#

:)

#

Well it's late for me so ima head out but thank you for the help @cunning canopy @fathom pendant ! See ya guys

sonic seal
devout lily
#

Hi everyone, i have just captured the first flag on privilege escalation section of getting started module, can someone help me with the second one?

#

i think to use linpeas.sh on the compromised host, is it correct?

pulsar needle
#

Skills Assessment - File Upload Attacks
I cannot seem to find where the upload directory is, I tried everything; looked at source code including soruce code of scripts, the 2 php files and dirb direcotry busting but cannot figure it out.

fathom pendant
pulsar needle
fathom pendant
#

think of ways you can leak source code

#

there are ways detailed in the module

reef axle
#

Hello, I have a question for server side attacks, its a general query, when i Inject {{77}} --> 49 means twig template engine, also in same input field i inject {{7'7'}} --> 7777777 which means jinja2 engine tempalte is used, so which one is correct. and more perfect, how to identify.

fathom pendant
#

or alternatively, escape the * with a backslash \ so \* for every *

reef axle
#

Hello, I have a question for server side attacks, its a general query, when i Inject {{7\7}} --> 49 means twig template engine, also in same input field i inject {{7\ '7'}} --> 7777777 which means jinja2 engine tempalte is used, so which one is correct. and more perfect, how to identify.

wild sage
#

If you get 77777777 after you do the ssti command it's jinja

#

Follow the ssti chart

reef axle
#

but i also get 49

#

so ignore the 49

#

if getting 777777

wild sage
#

If it was twig it would still produce 49

#

If you've done the twig module try the code for jinja and it should come back as 49

reef axle
#

In Jinja, the result will be 7777777, while in Twig, the result will be 49. Im using both the payloads given in module and I'm getting both the answers

wild sage
#

Which module is it

reef axle
#

Server Side Attacks -> Exploiting Jinja2

silver ocean
#

I need some assistance in setting up droopescan can some help?

#
Traceback (most recent call last):
  File "/opt/cpts/attackingCommonApplication/droopscan/droopescan/.droopescan/bin/droopescan", line 3, in <module>
    from dscan import droopescan
  File "/opt/cpts/attackingCommonApplication/droopscan/droopescan/.droopescan/lib/python3.13/site-packages/dscan/droopescan.py", line 4, in <module>                                                                                                      
    from cement.core import backend, foundation, controller, handler
  File "/opt/cpts/attackingCommonApplication/droopscan/droopescan/.droopescan/lib/python3.13/site-packages/cement/core/foundation.py", line 8, in <module>                                                                                                
    from ..core import output, extension, arg, controller, meta, cache, mail
  File "/opt/cpts/attackingCommonApplication/droopscan/droopescan/.droopescan/lib/python3.13/site-packages/cement/core/extension.py", line 8, in <module>                                                                                                 
    from imp import reload  # pragma: no cover
    ^^^^^^^^^^^^^^^^^^^^^^
ModuleNotFoundError: No module named 'imp'

reef axle
fathom pendant
reef axle
#

I'm getting both the 49 and 7777777 using both the given payloads

silver ocean
#

@fathom pendant I tried it:

┌──(.droopescan)─(kali㉿kali)-[/opt/cpts/attackingCommonApplication/droopscan/droopescan]
└─$ pip install imp
ERROR: Could not find a version that satisfies the requirement imp (from versions: none)
ERROR: No matching distribution found for imp

wild sage
reef axle
#

yes after getting 49 i get 7777777, Alright so its Jinja2

#

Okay 👍

drowsy raptor
#

Oopsie

#

@silver ocean

#

use importlib instead

fathom pendant
#

droopescan is an old tool; so many things likely changed as well

silver ocean
silver ocean
fathom pendant
#

you'd have to edit the droopescan code

silver ocean
#

whatPOGGERS

fathom pendant
#

idk however if there's a droopescan available in your distribution's repositories

drowsy raptor
#

yup

fathom pendant
#

¯_(ツ)_/¯

drowsy raptor
#

ask chatgpt to do it tbh

#

or get an updated version if any

fathom pendant
#

the alternative is using a venv to run it in a downgraded environment

silver ocean
fathom pendant
drowsy raptor
#

oh

fathom pendant
#

aside from the readme which was last year

silver ocean
fathom pendant
#

venvs allow you to run downgraded versions of python

drowsy raptor
#

in venv is better and less complicated

fathom pendant
#

also did you run pip install droopescan or install from source

#

this is an important distinction

fathom pendant
drowsy raptor
#

oh

#

my bad, sleepy as usual lol

fathom pendant
#

this version (From pip) is exactly 4 years old today LMAO

drowsy raptor
#

python3.11 -m venv myenv is a better option, idk if that's the right syntax but something along those lines

#

syntax is either that or pyenv or something to run a downgraded interpreter

fathom pendant
#

view the webpage http://ip:port; if you want to know how it's a webpage -- scan with
sudo nmap <ip> -p <port>

devout lily
#

Getting started - Privilege escalation
I captured the first flag, can anyone help me with the second one? 🙏

fathom pendant
devout lily
fathom pendant
#

linpeas is a nightmare for noobs; it outputs a LOT of useless junk

#

i suggest just looking around; trying different things

#

hidden is the keyword here, linux files are 'hidden' if they're prefixed with a . these are also known as dot-files

#

you can see them if you list all items with ls

wild cosmos
#

How to access htb cloud pro lab cyclone and what's the price

devout lily
#

ok got it, the only way the section talks about is to use enumeration scripts like linpeas

fathom pendant
devout lily
fathom pendant
fathom pendant
devout lily
wild cosmos
#

Ok

fathom pendant
fathom pendant
drowsy raptor
fathom pendant
#

ls --help

wild cosmos
#

Thank @fathom pendant

devout lily
fathom pendant
eternal saffron
#

what is the type of the service of the "dconf.service"

#

linux fundamentals

fathom pendant
eternal saffron
#

so now i ask it in erratum

fathom pendant
eternal saffron
#

yeah posted

urban ore
#

Yall, I lost my tab, how do I do this again? I’m so sorry yall😭

quartz ravine
#

.

fathom pendant
fathom pendant
#

but it still should be fixed imho

wheat silo
#

Wasn't sure which config file needed the default realm specified

broken gulch
#

oh thank god

#

the windows machine they have linked on the Windows section is a pain to work with

#

keep trying to edit my host machine and VM to enable WSL2 but it keeps failing

fathom pendant
#

@wheat silo, try not to spoil things. And as far as kerberos is concerned: krb5.conf is the file

humble ferry
#

Hello, im currently solving the Skill Assessment from Password Attacks (https://academy.hackthebox.com/module/147/section/1356) and i gained a foothold on the DMZ01, but im unsure what can be my next step. I only have ping to the DC01. I also use linPeas to look for a way to escalate privileges.

Can anyone give a some hint about how to proceed? ill hide the username to avoid any spoiler:

fathom pendant
#

also: sometimes windows doesn't respond to pings'

spiral yarrow
#

Any help In NoSQL Injection SA II?

humble ferry
# fathom pendant history is a powerful teacher

Ive been taking notes for each section of this module, but im unsure which seection can help me remind how to procee. Im currently trying to enumerate valid domain usernames using kerbrute. Is there any particular section that you could recommend me to take a look at?

light shore
#

Hello. I am new to htb, and attempting to do the active directory fundamentals guided lab part 1. I cant even get through
the first step 😂🤦🏾‍♀️

oblique plume
#

I am working on the Bypassing Captive Portals module and am stuck on the lab for MAC address spoofing. I did some initial recon and mapped out MAC addresses to IP address mappings for connected clients. Initially I showed no connecting clients, but performed a broadcast deauthentication against the AP to force the clients to reconnect. After building out my list, I have tried spoofing my MAC address to any of the MAC addresses of the clients. After spoofing I updated my IP address to the IP address associated with the MAC address and adding the default route (sudo route add default gw <IP> wlan1) I can no longer connect to the captive portal. I did some monitoring of the network and see lots of dropped packets for the MAC address I am spoofing. The other clients show that their frame counts aren't increasing, so I swapped my spoofed MAC with one of the other MAC addresses with similar results. As soon as I spoof and change my IP I note lots of lost frames and the inability to connect to the captive portal.

I've tried using the automated tool, but that just tries to spoof the MAC address of the AP so doesn't work at all. Any help is appreciated!

light shore
#

introduction to active directory

#

the guided lab part 1

#

i started the instance, it's the step of accessing the AD that im struggling with. Im attempting to follow the instructions to to open the ADUC on the MMC, or even the GUI, but im not finding it within the instance. I may just be looking in the wrong place

#

Yes I spawned that as well

fathom pendant
light shore
#

Howd you get to server manager? I even did a search for it, and nothing came up

#

I dont have the option to attach media to my message in here. I clicked the + and it only says "use apps". So i cant upload the screenshot i took

last musk
#

Can you help me with the Active Directory Enumeration & Attacks Privileged Access module I cant for the life of me figure it out the question is: What other user in the domain has CanPSRemote rights to a host?

#

I only get one user that is incorrect

fathom pendant
#

bloodhound is helpful

#

if you don't find the data initially, running sharphound a second time may yield the info

last musk
#

Is there any way to do it without bloodhound?

fathom pendant
#

yes, but it's a bit more involved, and does utilize PowerView/PowerSploit

last musk
#

Thanks 🙂

reef sonnet
#

is certipy supposed to give vulnerable certificate template to ESC8 on password attacks, pass the certificate module?

fathom pendant
#

No

merry stone
#

is there anyone i can dm to ask something about Web Service & API Attacks / Local File Inclusion (LFI)
I already solved it but just wondering why something worked and something didn't

abstract talon
#

Hey guys, I am having a problem trying to RDP into a target from the pwnbox. It is about AD Administration: Guided Lab Part I. I googled and found 2 posts (reddit and hack the box forum), but neither could provide answeres. Maybe somebody here can help or nudge me into helpful resources. The Problem is that the RDP window is a blackscreen.

#

This is Academy

storm elk
pale lagoon
#

Where I can ask question about billing

boreal sparrow
#

just dm me yo credit card info its no biggy g

fervent dirge
#

Are there any other newcomers to HTBA who have to look up the solutions to almost every single question? 😆
I've started at the lowest of the lowest modules for the basics, but I'm still not even close to how they complete the tasks in Solutions. NootLikeThis
Is the idea that I should be understanding how to complete tasks from the course material? Or am I expected to do a lot of research external to HTB?

grizzled crypt
#

Im getting off the bus soon. So, I was going to ask anyone if they were able to help me or walk me through the actual commands on the Linux fundemental

#

shoot me a message and I will be at the place soon it would be reallly helpful

devout lily
#

Getting started - Privilege escalation
Hi everyone, i dont really find a way to capture the second flag, can anyone guide me?

fathom pendant
fathom pendant
devout lily
ancient coyote
#

8 hour estimate for Password Attacks module is insane imo

devout lily
#

i dont know where to search

fathom pendant
#

Think about the protocol you used to connect

uncut crown
#

Has anyone had trouble with the Web Archiving part of the information gathering - web edition module? I looked in the forums and found that HTB started as an .eu website, so that helped with the first question, but the second question has me in a chokehold. lol

#

When I go to find it, it just shows redirects and no actual archived pages.

#

apparently, I wasn't using the /en. lol! Thank you! It's the little things, huh? 🙂

deep pier
#

A question if i use the virtual machine provided by HTB do I have do a procedure where I link it to my own setup?

rose laurel
#

French ?

rose laurel
#

Ah okay plus aide me hacker

chilly cosmos
ancient coyote
#

are you connected to the vpn

opaque stump
ancient coyote
#

is the machine on, and its the right IP?

opaque stump
#

this is the IP correct "Target(s): 10.129.229.244 (ACADEMY-LTMOV-SRV01)" ?

ancient coyote
#

try without grep maybe, your limiting what you see

opaque stump
#

nothing going on

#

and this is my user list

#

I am sorry I did not know

#

where should I seek assistance then and how ?

#

got it

ancient coyote
#

Dang now Im having issues, Permission Denied after entering ssh creds into lab machine for Password Attacks (Pass the Ticket (PtT) from Linux) IP is correct, domain added to hosts, password is correct, username is correct, what am i missing ?

opaque stump
#

I need help in Q3 , windows lateral movement : RDP ? I am spraying passwords is not working ?

deep pier
#

Can anyone tell me if I have to download the configuration file to use the virtual machine or can I just spawn it and start attacking or do a whole procedure to do it in my own setup

pearl furnace
#

Hey guys, I could use some help in the knowledge check section of the getting started module. I've gotten into the admin page, and was trying to find a way to execute a reverse shell like previously in the module. The only thing I've found that would work is that admins can edit the html of each page in the portal and update them to go live, but the reverse shell provided in the module doesn't quite work and searching for something that would work online isn't getting the job done either unfortunately. Could someone point me in the direction of some resources that would help me find the html I need to execute the shell?

deep pier
#

I did that but it said there was no route to connect

#

Ok

ancient coyote
#

I wonder if the maintenance window is an issue rn

#

3 peaople having connection issues at the same time

deep pier
#

Ye that is true

#

I managed to log in so probably luck on my side today 😁

#

What does it mean when the question says name of the network interface that MTU is set to 1500

fathom pendant
#

MTU is the Maximum Transmission Unit (aka how fast it can send/receieve data per packet)

#

so it's asking for the network interface that has the MTU value of 1500

#

breaking down the question into it's core components is useful in answering them. :)

deep pier
#

Marcie is there a command to find the network interface i think thats the bit thats confusing me

fathom pendant
#

ip a <-- (this used to be ifconfig, but has been replaced by the ip command suite)

deep pier
#

Ty

#

I did yay

#

Ir

#

Ty for the help marcie

fathom pendant
#

iirc the module provides a list of commands and a brief description

#

i'd first take a look into that list whenever you run into something you don't quite get yet before jumping to the discord.

deep pier
#

I looked at the list but I dont think ip a is on the list

fathom pendant
#

ip might be

deep pier
#

This was linux fundamental

fathom pendant
#

but also quick google searches can be your friend

#

"how do I do X in linux" was and still is a generally frequent google query of mine

deep pier
#

True I did that but it was saying I should do ip link and the network interface

#

Problem was that I didn't know the network interface

fathom pendant
#

ip is the underlying command

#

everything after that is the arguments

#

some commands follow a simple command some_verb some_options_related_to_verb

#

where the some_verb always follows the command

#

there's also the robust man pages

#

man <command> will typically bring up a manual page that you can scroll through and look for what you may need in the command options

#

and if you need a quick (usually common) command reference, <command> --help (or -h) will get you in the right direction

ancient coyote
deep pier
#

I see ok thank for the help marcie

#

🙂

fathom pendant
ancient coyote
#

two @s?

fathom pendant
#

yes; the username itself is a literal username

ancient coyote
#

yeah

fathom pendant
#

domain joined linux

#

ssh "user@domain"@ip/hostname

ancient coyote
#

oh my

#

I feel so dumb

fathom pendant
#

subheading: Linux auth via port forward

ancient coyote
#

Thanks Marcie

fathom pendant
#

i wasn't sure so i did a double check

indigo mirage
#

Hello, could you please help me with this:

#

How may I get the ip??

fathom pendant
indigo mirage
#

ahhh

#

ajajajajjajaj my mistake

#

thanks!

sharp notch
#

huh? lol

fathom pendant
#

they didn't get banned lol

#

they got automodded and silenced for 2 hours

sharp notch
#

oh lol just saw this

fathom pendant
#

because slurs aren't accepted, no matter the context

sharp notch
#

professional and poignant

#

idk what poignant means but i heard it before

#

looked up poignant, thats not the correct word for the phrase..

fathom pendant
#

2 - b

sharp notch
#

oh i stand corrected then

#

very nice

bright aurora
#

Who can help with “Outbound”?😭 It seems like an easy level, but I’m stuck. Can someone give me a hint for the user flag?

elder matrix
#

poigant is derived from poignard... which means dagger

sharp notch
#

was training a new kid at work today just graduated already knows how to do some things and has his own tools

elder matrix
#

i use other peoples tools LOL

fathom pendant
#

:)

elder matrix
#

this is sparta

#

good night my friends.

sharp notch
#

slowly taking my time with this fundamentals module

abstract lance
#

Can Eny help me hack my phone

fathom pendant
#

that's not what this server is about even if we believed you on your word that it's your phone

#

i suggest reading the #rules and #welcome channel of servers you join to learn what they're about

abstract lance
#

It’s mine I just want to hack screen time

fathom pendant
#

unless you're a child and under strict rules, screen time really doesn't matter

#

and even then: not what this server is about

rapid skiff
#

Hello

abstract lance
#

Hey

rapid skiff
#

I'm new and I'm here to learn

#

This goku is incredible

#

I miss watching anime

#

I didn't think this place would be this active. It's very nice.

jaunty portal
#

Hi everyone, I'm trying to complete the Documentation & Reporting module. When doing the Documentation & Reporting Practice Lab questions, I can't for the life of me load the bloodhound files from the parrot box into bloodhound. I tried with bloodhounce-ce from the latest kali version, and on the pwnbox but I get errors on both. If someone is able to help me out that would be great. Is it something with the parrot box's version of bloodhound-python?

rapid skiff
fathom pendant
jaunty portal
#

i also tried pivoting through the parrot box with chisel and ssh -D to run bloodhound-ce-python from kali, but i couldn't send any data with proxychains so idk if thats getting blocked or something

fathom pendant
#

Legacy being the non-ce

jaunty portal
fathom pendant
#

Yep

jaunty portal
#

ok i'll give that a try, thanks

#

the bloodhound ecosystem is wack

fathom pendant
#

Evil-winrm has an upload/download feature

#

Nxc also has a collector built in

jaunty portal
#

Do you have a recommended way to have bloodhound-legacy and ce installed on kali at the same time? I guess the answer would be docker or something?

fathom pendant
#

Well ce is docker now

#

When I say legacy, im referring specifically to the pre-docker ce version

jaunty portal
#

interesting. I have bhce installed without docker/with apt because i heard that the newest kali release ships an updated version. I guess the solution is to just install legacy and have ce in a container.

hardy spire
jaunty portal
hardy spire
#

Oh okie.

toxic cradle
#

im in nmap labs in the first lab we have to find a service which we tell abt os or should we get the os in the nmap result

devout timber
#

Y

cerulean idol
#

Is this the right place to provide small english fixes / recommendations to academy questions?

cloud urchin
icy dirge
#

My Academy target (IP: 10.129.17.143) is accepting connections on port 22, but SSH hangs at expecting SSH2_MSG_KEX_ECDH_REPLY. I’ve tried multiple IPs and confirmed my local system is fine. Please check if the instance is broken or overloaded.

heavy dome
#

hello, i'm trying to pass the skills assessment of WIN lateral movements but i can't find the entry breach; i've tried both rdp,wmi,smb,winrm,ssh but i can't figure out where i'm going wrong or what i'm not seeing. any help?

opal shuttle
merry stone
#

is there anyone i can dm to ask something about Web Service & API Attacks / Local File Inclusion (LFI)
I already solved it but just wondering why something worked and something didn't

cloud urchin
#

@digital pendant Please take care not to spoil content from modules above tier 0

#

RDP != WinRM

digital pendant
#

Hard to ask for help isn't it without specifying what is the problem, how would you ask for help so I can understand the protocol

#

the discrepancy that I mentioned in my comment, is that a bug or a feature? I wasn't talking about RDP there either it was winrm. Remote Management Users group not Remote Desktop Users Group

cloud urchin
#

Anyone who has done the content knows it already and doesn't need an explanation. If you feel like you need to reveal a little more you should ask to take it to DM's.

eager spindle
#

You can't connect to the file share because it's not secure. This share requires the obsolete SMB1 protocol, which is unsafe and could expose your system to attack.
Your system requires SMB2 or higher. For more info on resolving this issue, see: https://go.microsoft.com/fwlink/?linkid=852747 Please help me how to solve this problem

Discover SMBv1 protocol changes in Windows Server and Windows, explore alternatives for legacy compatibility, and learn best practices.

boreal vessel
#

Need a DM for this pls.

wooden glade
sage granite
#

I cant sub to the academy, i have sub on labs already

storm elk
spiral scarab
#

Hello, in the Documentation & Reporting module they mention that changing the color for the command and output to be a nice addition. Any ideas on how to do that on Sysreptor?

toxic cradle
heavy dome
#

hello, i'm trying to pass the skills assessment Q1 of CAPE module WIN lateral movements but i can't find the entry breach; i've tried both rdp,wmi,smb,winrm,ssh but i can't figure out where i'm going wrong or what i'm not seeing. any help?

pulsar rapids
#

Morning guys, i have a bit of a problem. So i cant install packages and apps with "apt" its crazy and there are a lot of dependencies that are either being withheld or just not upgraded. is it a me problem or is something wrong with the PWNbox?

opal shuttle
pulsar rapids
#

screenshot?

#

sudo apt install discord
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
E: Unable to locate package discord

#

can u see this, isnt it meant to fetch all the dependencies for discird and then download?

opal shuttle
opal shuttle
#

that's y

#

in apt record there is nothing named discord...

#

download discord from their official site for linux

#

it will give you .deb file

#

apt install ./thatdebFile ...chatgpt will help you

bold niche
jolly spruce
#

If anybody could help me with the exercise in module 144, section 3079 of academy, I'd really appreciate it

#

I just can't get the ReconSpider script to run properly

#

Based on a search, others have encountered similar problems it seems

#

But even their fixes don't work for me

opal shuttle
#

there is an error in that thing

#

try downloading and exploring manually

jolly spruce
#

Alright, thank you

bold sun
#

I have been struggling hard with the Androud fundamentals course, but only the model number question at the end. I am sure you all know the one... my laptop usually freezes and crashes when trying to run all of the processes. Please someone just dm me to answer. just the one time. I have had no problems with any other module and, coupled with all of the Reddit threads on this, I feel that not nearly enough info or something is given to solve this one question...

digital pendant
#

What to do if the input is exactly as you have written and WITH the format provided matching and the solution also saying the same (well answer hidden but underlines the two CVEs expected)

idk what else to do.

#

written in YYYY-12345

opal shuttle
#

I also faced this problem

digital pendant
#

thank you have dmd 🙂

#

resolved ;- was a copy paste issue, typing each number back out worked

latent frigate
#

Hello,

Module: Broken Authentication
Submodule: Brute-Forcing Password
Question: What is the password of the user 'admin'?

I am trying to generate a wordlist with the following regex command, but I get no password from this list that matches the answer. Can someone give me a help, please?
grep '[[:upper:]]' /usr/share/wordlists/rockyou.txt | grep '[[:lower:]]' | grep '[[:digit:]]' | grep -E '^.{0,12}$'

Then I am sending this command to brute-force:
||ffuf -w wordlis -u http://94.237.50.221:55698/index.php -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "username=admin&password=FUZZ" -fr "Invalid username or password."||

rain mirage
#

the module is : PASSWORD ATTACKS
Network Services
the command :
netexec winrm 10.129.99.133 -u garbage/network-services/username.list -p garbage/network-services/password.list

and im not getting any op , no error no credentials

#

Any hints ?

wooden seal
#

Password attacks
sec : pass the cert
ntlmrelayx doesnt creating dc01 file instead giving a b64 content of certificate

terse bloom
#

Sup people, is it just me or scanning through pivoting ssh -D and proxychains using nmap on AD machines is giga slow? Password attacks skills assessment

wooden seal
#

and use ligolo-ng for pivoting its best

terse bloom
terse bloom
#

the problem is that it hasn't been shown in the module, only the slow version

wooden seal
jolly raptor
#

Tryna complete the shells and payloads module but my AV keeps blocking the payload oneliners, all my notes got destroyed - times are tough rn

terse bloom
wooden seal
gusty cobalt
#

"The UACME project maintains a list of UAC bypasses, including information on the affected Windows build number, the technique used,"

bold sun
#

I have been struggling hard with the Androud fundamentals course, but only the model number question at the end. I am sure you all know the one... my laptop usually freezes and crashes when trying to run all of the processes. Please someone just dm me to answer. just the one time. I have had no problems with any other module and, coupled with all of the Reddit threads on this, I feel that not nearly enough info or something is given to solve this one question...

plush bloom
bold sun
#

I am.... 🙁

median warren
#

Guys on prompt injection i have successfully banned the CEO on skill assessment, but there is no flag shown.

analog carbon
#

Guys can help me on Module 307: LLM Output Attacks, Section 3590? Specifically question 2 Im strunggling. Tried to do .html markdown and host it and use a python webserver to host the file for uploading but failing 😐 to get the history chat

rain mirage
rustic sage
#

just wanted to ask a small question, im on bash modules in junior cybersecurity analyst. I'm on the category Arithmetic. I'm a little confused on one of the demos and would appreciate some clarification.

#

#!/bin/bash

increase=1
decrease=1

echo "Addition: 10 + 10 = $((10 + 10))"
echo "Subtraction: 10 - 10 = $((10 - 10))"
echo "Multiplication: 10 * 10 = $((10 * 10))"
echo "Division: 10 / 10 = $((10 / 10))"
echo "Modulus: 10 % 4 = $((10 % 4))"

((increase++))
echo "Increase Variable: $increase"

((decrease--))
echo "Decrease Variable: $decrease"

#

it says this, however would i be right by saying i wouldnt need the words, for example:

echo $((10 + 10))

median warren
gray yacht
rustic sage
#

could someone confirm or deny? were the words just as like an explanantion for them or would i actually have to put the whole thing "echo "Addition: 10 + 10 = $((10 + 10))"" and not just "echo $((10 + 10))"

#

never mind i get it

#

brackets just do the mathmatical equation, the sentence before that would be displayed as text

cedar yew
#

Hello all, i need help

Module: ADCS attacks
Session: esc4
Question: Abuse the ESC4 misconfiguration to impersonate the Administrator account. What is the value of the flag file at C:\Users\molly\Desktop\flag.txt?

My Problem:

İ have Molly NTLM hash but i cant connect server i already try evilw-winrm, xfreerdp3, wmiexec, and i use ccache file but i cant connect how can i fix this

Thank you for help

rustic sage
#

With this Bash Script:

#!/bin/bash

increase=1
decrease=1

echo "Addition: 10 + 10 = $((10 + 10))"
echo "Subtraction: 10 - 10 = $((10 - 10))"
echo "Multiplication: 10 * 10 = $((10 * 10))"
echo "Division: 10 / 10 = $((10 / 10))"
echo "Modulus: 10 % 4 = $((10 % 4))"

((increase++))
echo "Increase Variable: $increase"

((decrease--))
echo "Decrease Variable: $decrease"

why do i get displayed

Increase Variable: 2
Decrease Variable: 0

#

is it because the ++ means +1+1 so prints 2, then -- means -1-1 so prints 0?

coarse tide
#

Hello,
I got a reverse shell in the Editor Machine. But after that, i stucked! There are two users, oliver & root. I stucked finding creds or escalate to oliver.
Anyone give me hint for this ?

finite sable
#

guys, I need help

#

Navigate to the bottom of this section and click on Click here to spawn the target system!
Now, navigate to http://[Target IP]:5601, click on the side navigation toggle, and click on "Discover". Then, click on the calendar icon, specify "last 15 years", and click on "Apply".
Hunt 1: Create a KQL query to hunt for "Lateral Tool Transfer" to C:\Users\Public. Enter the content of the user.name field in the document that is related to a transferred tool that starts with "r" as your answer.

#

Just How???

rain mirage
shadow sedge
#

im doing the skill assessment of shells and payloads module, but when i connect with rdb i cant find any browser to interact with the targets (maybe it is in front of me but i need to sleep)

teal arrow
#

Has anyone come across an issue with rdp not loading?

storm elk
#

Just press enter @teal arrow

wheat silo
storm elk
shadow sedge
#

i need to stop using gui fr

#

HAHAHAAHAHA

wheat silo
#

Yeah I had the same issue doing that one

coarse tide
storm elk
#

All good

wheat silo
#

Does anyone know why creds that work with netexec are giving me an error when trying to view a share with smbclient, I copy-pasted the password into the prompt and keep getting the error session setup failed: NT_STATUS_LOGON_FAILURE

torn fiber
#

module:shells and payload module
submodule:the live engagement section
it seem that i cannot find a browser to access the tomcat server(ip address of first host) and add the credential to look what is inside the website. i have enumerate the host. can i get a hint please.

#

on first host

plain charm
#

did you try port scan? on the foorthold machine?

torn fiber
#

i rdp into the foothold machine and started enumeration for host 1. i have not done on that for foothold machine

gray yacht
torn fiber
#

i got the answer in forum thank you

austere forge
#

Module: Broken Authentication
Submodule: Authentication Bypass via Parameter Modification

I sent the request to intruder and I tested from 1 to 200 but I dont get en id that has admin privileges

#

Some have more ideas to test?

devout lily
#

Hi everyone, searchsploit is for vulnerability or exploits research?

wheat silo
#

You can also use google and a lot of those results will be on exploit-db as well

devout lily
wheat silo
devout lily
deep hemlock
#

hello
RDP and SOCKS Tunneling with SocksOverRDP

on this can i do the pivoting using ligolo

wheat silo
devout lily
#

on the example in the dedicated section there is search exploit eternalblue, is this a vulnerability or something else?

modern imp
#

nmap module - service enumeration, I have the flag but its not working

wheat silo
devout lily
#

"Once we have Metasploit running, we can search for our target application with the search exploit command. For example, we can search for the SMB vulnerability we identified previously: msf6 > search exploit eternalblue" this is the text about that command, it says that eternalblue is a vulnerability

heavy dome
#

Hello! Module: Windows Lateral Movement - Skills Assessment Q1: i can have any hit!!! 😭

wheat silo
devout lily
wheat silo
devout lily
#

perfect, thank you

wheat silo
#

no problem

modern imp
heavy dome
# gray yacht nmap

RDP no standard port but i cant Connect; ssh no have my know host and i cant Connect. Smb can read ipc$ but no interessant file… probaly i can Connect in rdp but my command wrong

gray yacht
#

I'd enumerate all of them. I also deleted that because spoiler tags do nothing and that content is over Tier 0.

plain charm
#

try with nmap -sU if not done yet

teal arrow
#

Hey some help grasping this concept:
When using an LDAP filter this comes userAccountControl:1.2.840.113556.1.4.803:=32
How are LDAP OID's relative to UserAccountControl flags? I'm seeing the list for both but I'm not seeing the correlation.

plain charm
teal arrow
#

Active Directory Enumeration Attacks - Living off the land

plain charm
#

What was the command? and what was it for?

final kite
#

File "/usr/lib/python3.13/threading.py", line 1043, in _bootstrap_inner
self.run()
~~~~~~~~^^
File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattack.py", line 42, in run
ADCSAttack._run(self)
~~~~~~~~~~~~~~~^^^^^^
File "/usr/lib/python3/dist-packages/impacket/examples/ntlmrelayx/attacks/httpattacks/adcsattack.py", line 61, in _run
response = self.client.getresponse()
File "/usr/lib/python3.13/http/client.py", line 1430, in getresponse
response.begin()
~~~~~~~~~~~~~~^^
File "/usr/lib/python3.13/http/client.py", line 331, in begin
version, status, reason = self._read_status()
~~~~~~~~~~~~~~~~~^^
File "/usr/lib/python3.13/http/client.py", line 292, in _read_status
line = str(self.fp.readline(_MAXLINE + 1), "iso-8859-1")
~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^
File "/usr/lib/python3.13/socket.py", line 719, in readinto
return self._sock.recv_into(b)
~~~~~~~~~~~~~~~~~~~~^^^
ConnectionResetError: [Errno 104] Connection reset by peer

teal arrow
#

@plain charm

opal shuttle
#

pls remove this...dont spoil content above tier 0

heavy dome
deep hemlock
#

hello
RDP and SOCKS Tunneling with SocksOverRDP

on this can i do the pivoting using ligolo

plain charm
plain charm
spiral cove
#

can anyone help me with 'Bypassing Other Blacklisted Characters' and the question: Use what you learned in this section to find name of the user in the '/home' folder. What user did you find?. its been kicking my arse for weeks

deep hemlock
plain charm
#

Hm. I remember doing with the SocksOverRDP tool. didn't faced any issues

#

I wasn't aware of the ligolo-ng and finished the module with the mentioned tools. was painful though.

spiral cove
#

for some reason when i use burp and i set the proxy in firefox, i then go to the target ip address but the page doesnt load. i am using the HTB academy vpn

median skiff
#

can someone help with question 5 on Windows Privilege Escalation - Pillaging? I got the latest SAM SECURITY and SYSTEM files but secretsdump.py is giving me an error when I try to extract the hashes from them

plain charm
#

Its best practice but be mindful of that -sU scans take the longest time. can use other tools like rustscan for speed if you like

plain charm
median skiff
plain charm
#

or pull the latest version from github

plain charm
median skiff
#

The answer is always "blow on the cartridge and reboot" 🤣

spiral cove
plain charm
final kite
median skiff
# plain charm well, sometimes, as you will see in next modules, this answer will also not enou...

you called it... is xfreerdp not working for anyone else?

[11:48:28:600] [7139:7140] [INFO][com.freerdp.crypto] - creating directory [/home/htb-ac-79581/.config/freerdp/certs]
[11:48:28:600] [7139:7140] [INFO][com.freerdp.crypto] - created directory [/home/htb-ac-79581/.config/freerdp/server]
[11:48:28:610] [7139:7140] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]
plain charm
median skiff
#

adding /cert:ignore /dynamic-resolution /log-level:DEBUG did not work either.

#

I'm using the parrotbox

cloud urchin
#

always best to include the module and section you're on.

median skiff
#

module is Windows Privilege Escalation - Windows Server

cloud urchin
#

what's the command you used

#

i'm guessing you didn't wrap the password in quotes or something

limber schooner
#

Hi guys

#

I need a help who can

acoustic owl
#

What do you need help with?

warped hawk
#

Can anyone help me with the Abusing HTTP Misconfigurations hard skills assessment? I can't make the admin trigger my XSS payload..I suppose that the issue might be related to the Host header, but I am struggling to find a solution..

storm elk
cloud urchin
#

@median warren Please take care to not post content from modules above tier 0

cloud urchin
teal arrow
#

Active Directory Enumeration - Kerberos from Linux
Question: Retrieve the TGS ticket for the SAPService account. Crack the ticket offline and submit the password as your answer.
After I log in to through ssh
I seem to be needing some kind of password to execute:
GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend (Provided in the module)

Can I get a little nudge as to where to find these credentials.

#

Gotcha, genuine question though, why would it not be mentioned in the section, is there something that I need to run in order to obtain them? Or was the purpose to reference the old section? I was thinking maybe I overlooked something.

#

thanks!

lost beacon
#

when i run dirtypip exploit i got this error

./exploit-1: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.33' not found (required by ./exploit-1)

#

AEN last box last flag

#

MGMT01 hostname

plain charm
#

compiling the binary IN the target may resolve the conflicting library version. happened with me though

plain charm
#

compile the binary in VICTIM and execute there should solve

lost beacon
teal arrow
#

Anyone recognize this error, the hash won't print:
[-] Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)

lost beacon
#

it works thanks alot @plain charm

plain charm
sick stump
#

hey guys im working on shell and payloads module in cpts path, and for the question asking version of powershell by using $Psversiontable under the section Anatomy of the shell, for some reason it keeps saying the version is wrong, although its the correct one listed using the cmd.

can someone help me with this or am i missing something?

#

I didnt even notice he wanted the edition not the version facepalm

#

💔 oh well, thanks 🙏

fathom pendant
humble ferry
#

Hello, im currently doing the skill assessment from the module Passwords Attacks, but i need some help. I dont want to write spoiler so i can say that i found some credentials from a Safe Database. But im unsure on how to proceed with this account since i dont have connection to the DC01 from my attackbox even when im using proxychains and it worked great to get the prevoiusly mentioned crdentials.

fathom pendant
#

pivot

#

i used ligolo-ng as my pivoting tool of choice, but the underlying commands should still work no matter the pivot

terse bloom
#

Anyone experiencing some issues? My lab has been spawning for 5 minutes

sick stump
#

please confront your husband, would genuinely give you a better outcome, and you cant request illegal stuff here

#

@fathom pendant

storm elk
#

This isn’t hacker for hire

fathom pendant
sick stump
vapid maple
#

Hello everyone, I have been working on the Logrotate reverse shell for the last few hours. I have found the writeable log, copied over and complied logrotten and it just sits there. I dont get anything on my nc. what could I be doing wrong? Ive even forced a log to be written

tropic prawn
#

hello. someone to help . SQLMAp essential module . Flag8 and flag 10 !!

vapid maple
sick stump
median skiff
# cloud urchin what's the command you used

back at it now and still getting the same error:

[15:04:22:191] [7800:7801] [ERROR][com.freerdp.core] - transport_connect_tls:freerdp_set_last_error_ex ERRCONNECT_TLS_CONNECT_FAILED [0x00020008]```
#

didn't even get the chance to enter the password so (no) quotes isnt the issue

echo roost
#

use /sec:tls

#

my command xfreerdp /u:htb-student /p:'HTB_@cademy_stdnt!' /v:$ip /d:inlanefreight /dynamic-resolution /drive:/home/saulgoodman/htb/,share /bpp:8 /compression -themes -wallpaper /clipboard /audio-mode:0 /auto-reconnect -glyph-cache /sec:tls

#

You probably don't need the audio, themes,and wallpaper options

median skiff
#

working when I use rdesktop -u htb-student -p HTB_@cademy_stdnt! 10.129.85.56:3389 so I believe the old version of windows I'm trying to connect to in the module has compatibility issues

#

appreciate the help!

echo roost
#

rdesktop is depricated but still works

red cypress
#

this should be okay

#

also use xfreerdp

median skiff
#

/cert:ignore didn't work with xfreerdp

red cypress
#

no way..

median skiff
#

nor did tls-seclevel:0

red cypress
#

one sec

echo roost
#

try /sec:tls

median skiff
#

in the Windows Privilege Escalation - Windows Server module

red cypress
#

xfreerdp /v:[ip_address] /u:[username] /p:[password] /cert:ignore

#

you did type like this?
it doesnt matter the module.. the command remains the same

#

check man for cert ignore..in xfreerdp
that could also be of some help..since it could also mean that the syntax might have changed.

median skiff
#

exactly like that

#

didnt work

red cypress
#

did you do a sudo?

echo roost
#

did /sec:tls work?

fathom pendant
#

sudo isn't required for xfreerdp

median skiff
echo roost
#

weird

median skiff
#

will just use rdesktop to finish this module out. Sometimes the VMs don't cooperate with me 🙁

red cypress
#

try restarting the machine..

echo roost
#

should work with any of the above commands

red cypress
#

i mean the windows

silver ocean
#

I am into thick client pentesting...how do I modify .class code?

red cypress
#

xfeerdp /u:htb-student /p:HTB_@cademy_stdnt! /v:10.129.151.78 /cert:ignore
this is what i use and it works..

echo roost
#

same here

silver ocean
echo roost
wise grove
#

Is there a reason the academy targets go down every minute for like 3 minutes? It's almost impossible to complete with this lag.

silver ocean
rustic sage
#

hi, im currently doing the junior cybersecurity analyst modules. MY end goal is to be a pentester. Would going onto the penetration tester modules after this be okay? Or jumping too fast. Also would doing boxes be good thing to start doing or should I gain more knowledge first? Thanks.

echo roost
#

Sorry, I deleted my posts and I do not unfortunately.

silver ocean
#

not a big deal

bitter junco
fathom pendant
red cypress
rustic sage
cloud urchin
#

This isn't the server for that

red cypress
fathom pendant
#

@hoary cloud not what the server is about

bitter junco
rustic sage
bitter junco
#

u will have decent fundamentals to go to boxes after that

hoary cloud
bitter junco
wise grove
# fathom pendant Change vpn regions

Tried with 3 other VPN's. This is very discouraging and frankly next to impossible to complete. I'm spending way more time waiting for target to receive a ping than actually working

fathom pendant
compact patrolBOT
fathom pendant
#

All else fails. Try using the in-browser vm

fathom pendant
hoary cloud
fathom pendant
rustic sage
#

im doijg the first path for fundamental knowledge

fathom pendant
#

If you still want to learn ethical (legal) hacking; you can sign up for an HTB account and look into https://academy.hackthebox.com, theres plenty of free modules to teach you the basics

drowsy vector
#

Hi, I am currently working on AEN Lateral Movement & Privilege Escalation Post-Exploitation.

I am using ligolo to pivot and whenever I create a double pivot so that I can connect to the next target, DC01 keeps crashing.

bitter junco
red cypress
fathom pendant
red cypress
#

after that either CPTS or CBBH

bitter junco
#

but for sure would do cpts first path not cbbh

fathom pendant
fathom pendant
#

The web modules are just coincidental, not really a measure of the differences

hoary cloud
bitter junco
fathom pendant
bitter junco
#

so i would say cpts path is just wider scope

fathom pendant
bitter junco
#

and cbbh traets as u said about webpart

bitter junco
fathom pendant
#

It all depends on what the individual is more interested in

hoary cloud
#

Ethical hacker must know penetration testing and bug bounty ?

fathom pendant
hoary cloud
fathom pendant
#

Ethical just means within the bounds of legality

#

I.e. bug bounties have explicit scopes

#

Penetration tests have scopes as well, and typically detail legacy systems to treat with care or avoid

#

I.e. a legacy server that would crash if you pinged it as normal

cloud urchin
rich obsidian
#

Working through the Oracle TNS section in the enumeration module in the pentest pathway, I see that I need to install odat and they give a bash script that looks like it installs some oracle software (maybe not related to odat) then it does the whole git clone of the repository for odat. Firstly, this script doesn't use virtual environments at all so it has me sweating a python library conflict on the VM I am piecing together for the test. Secondly, you can install the tool with apt install now. Should I run the first half of the bash script for the oracle software then disregard their git install and use apt install?

fathom pendant
#

For installing the python libraries via pip/pip3; --break-system-packages

fathom pendant
rich obsidian
fathom pendant
rich obsidian
fathom pendant
#

You'll still need to install sqlplus though

opal shuttle
#

👀

drowsy vector
inner owl
#

who can help me

bitter junco
#

timedatectl set-ntp off
sudo rdate -n 10.129.205.35

#

hearing voices seeing things 😅

rich obsidian
tall imp
#

PS C:\Tools> Get-DomainUser -SPN -Domain FREIGHTLOGISTICS.LOCAL | select SamAccountName
Exception calling "FindAll" with "0" argument(s): "A referral was returned from the server.
"
At C:\tools\PowerView.ps1:5253 char:20

  •         else { $Results = $UserSearcher.FindAll() }
    
  •                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [], MethodInvocationException
    • FullyQualifiedErrorId : DirectoryServicesCOMException

Active Directory Enumeration & Attacks --->
Attacking Domain Trusts - Cross-Forest Trust Abuse - from Windows
It's strange because it should work, it should come out, but I get that error.

#

I think it's a module failure.

knotty oriole
#

Working on AD skills assessment part 2 and I'm at the part where you're supposed to || run mimikatz to get the mssqlsvc cleartext password ||, but I always get null in this field. I've copied the steps exactly from the solution and tried switching vpn regions to no avail. Any help?

#

I'm able to get it from other tools, but I would really like to understand why the first method isn't working.

obtuse mantle
#

HI

#

Hi

#

can anyone help me in Exercise script

#

?

tall imp
#

I should get this : Get-DomainUser -SPN -Domain FREIGHTLOGISTICS.LOCAL | select SamAccountName

Copiar
samaccountname


krbtgt -------> But I get this:; Exception calling "FindAll" with "0" argument(s): "A referral was returned from the server.
"
At C:\tools\PowerView.ps1:5253 char:20

  •         else { $Results = $UserSearcher.FindAll() }
    
  •                ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [], MethodInvocationException
    • FullyQualifiedErrorId : DirectoryServicesCOMException
rustic sage
#

If i want to get into pentesting (ethical hacker) should i do junior cybersecurity analyst or Information Security Foundations? They're both at 30% as they crossover a lot i guess. Which would you go with? I'm going to go onto pen tester after.

knotty oriole
tall imp
#

@knotty oriole need you help please

knotty oriole
#

In the active directory section this is a module called "kerberos double hop problem" that will tell you exactly why this happens and how to solve it.

fathom pendant
knotty oriole
#

@fathom pendant Working on AD skills assessment part 2 and I'm at the part where you're supposed to || run mimikatz to get the mssqlsvc cleartext password ||, but I always get null in this field. I've copied the steps exactly from the solution and tried switching vpn regions to no avail. Any help? I'm able to get it from other tools, but I would really like to understand why the first method isn't working.

echo rune
#

I’m on the password attacks spraying,stuffing, and defaults and I’m trying the reccommended solution but it won’t work, wondering if it is broken?

#

It’s definitely broken, I tried logging in from different instances to the MySQL server and then looked at the walkthrough and tried the solution, it didn’t work. But then I type the credentials into the answer field and it worked. Fix this htb staff. I was getting very worked up on this.

fathom pendant
#

i had 0 issues logging in via the intended method

echo rune
#

Oh that makes sense, I tried it from the attack machine and not the target machine

fathom pendant
#

mysql -u <username> -p -> paste password -> logged

echo rune
#

I just went through all the other files on the target machine first and then kept trying credentials from the default creds but must have mistyped it after frustration when I tried that.

fathom pendant
#

this channel isn't an lfg channel

random aspen
#

sorry

fathom pendant
#

@random aspen are you referring to the Starting Point Machines? (Those aren't CTFs)

random aspen
#

oh

#

they aren't , i was referring to them

fathom pendant
#

I suggest reading the #welcome instructions on connecting your account to the server to be able to access channels like #starting-point

random aspen
#

oh

#

i just joined this server, i would have done that it's just that htb is down for me

fathom pendant
random aspen
#

@fathom pendant Dms

fathom pendant
#

i'm not staff so i can't help with anything; also if it's unrelated to server moderations it's helpful to know what the dm is regarding

rich obsidian
# fathom pendant Its rarely used

I did run into two "hiccups" when I started using the tools. Odat must be run with elevated privileges to provide the password guesser module, and I did get the shared library error with sqlplus, but the command they had listed to repair it worked perfectly.

fathom pendant
#

yeah that's why the apt install method is kinda meh

#

because it requires elevated privileges whereas the source install method you just run as user and you're good

rich obsidian
fathom pendant
#

i just mean that in the grand scheme of things; installing from source >>>> installing from apt

#

you run into far less issues that way

grizzled crypt
#

anyone down to help me with a module

cloud urchin
#

just ask your question here

grizzled crypt
#

oh my goodness, im trying to do some walk-thru basically to help learn the commands and fundementals of linux

random aspen
#

same

#

Where do i find the answer to the htb-students mail?

#

i can't find anywhere

fathom pendant
random aspen
#

oh

#

thanks i got it

#

also what does it mean when it says what shell does the htb-student use?

novel matrix
random aspen
#

ok

#

i'm 💤

rich obsidian
random aspen
#

i need help with this question "what is the name of the network interface where the MTU is set to 1500' how do i find it

#

does it have something to do with the ip command?

cloud urchin
#

did you try it and look?

random aspen
#

i look at the help screen

#

and everything's all over the place, wait one sec

cloud urchin
#

also always best to mention the section you're on too

random aspen
#

system information

#

on linux fundamentals

#

just starting

cloud urchin
#

so there are a few commands that show it, i'd recommending trying them out to see what you can find. also google and chatgpt can be great to provide commands that find x or whatever.

random aspen
#

thanks i got it

rich obsidian
# random aspen just starting

Really recommend you get used to googling or chatgpting first, then come here. You will get at least two times the learning experience if go read the additional material to understand what is actually going on

rich obsidian
torpid grail
#

Someone else is having trouble getting into the LAB

cloud urchin
torpid grail
grizzled crypt
#

So if I want to find files with the .log from the directory i know its ls -la what

grizzled crypt
#

How many files exist on the system that have the ".log" file extension

#

that's the question

#

so im trying ls -la

rich obsidian
#

then you should probably try to "find" them

#

get it?

viscid bolt
#

Anyone do the skills assessment for kerberos attacks module on CAPE?

deep fjord
#

Hi everyone
Im new to this field just started several months ago and im aiming for the OSCP any advices ?

cloud urchin
rich obsidian
grizzled crypt
#

can anyone join a voice chat

cloud urchin
#

no only identified people

#

identified/verified

grizzled crypt
#

really

#

Whats the command for locating Total Packages

#

Linux Fundemental

#

wanna finish this section before hitting the hay

#

File Descriptors and Redirections

#

Under Linux Fundamentals

waxen totem
#

You sure about that? 02Clown

grizzled crypt
#

Wild can you educate me on this

#

please? Im trying to get the jist of it

idle latch
#

Im a begginer can someone explain how Linux works

drowsy raptor
south rampart
#

i need help with filter contents with the first question

#

on Linux fundamentals

rich obsidian
#

It must be the time of night, that's like 5 people in a row asking questions about linux fundamentals.

drowsy musk
#

@haughty furnace have you tried the "/opt/useful/seclists/Discovery/Web-Content/common.txt" wordlist from the module / have you been able to fuzz through it without the sesh expiring

cloud urchin
#

This field requires a lot of self study

haughty furnace
fathom pendant
#

you don't have to create a whole new list

#

i.e. your -u may look like http://web.site/FUZZ.html